IOC Report

loading gif

Files

File Path
Type
Category
Malicious
HuuyISbqrL
ELF 32-bit LSB executable, Intel 80386, version 1 (GNU/Linux), statically linked, for GNU/Linux 2.6.18, BuildID[sha1]=307edfa923d9ff7e3793ec8771ab90f5343cb21e, stripped
initial sample
malicious
/etc/cron.hourly/cron.sh
POSIX shell script, ASCII text executable
dropped
malicious
/etc/init.d/.chinaz{1636583395
POSIX shell script, ASCII text executable
dropped
malicious
/tmp/.chinaz{1636583395
ELF 32-bit LSB executable, Intel 80386, version 1 (GNU/Linux), statically linked, for GNU/Linux 2.6.18, BuildID[sha1]=307edfa923d9ff7e3793ec8771ab90f5343cb21e, stripped
dropped
malicious
/memfd:snapd-env-generator (deleted)
ASCII text
dropped
clean

Processes

Path
Cmdline
Malicious
/tmp/HuuyISbqrL
/tmp/HuuyISbqrL
clean
/tmp/HuuyISbqrL
n/a
clean
/tmp/HuuyISbqrL
n/a
clean
/tmp/HuuyISbqrL
n/a
clean
/tmp/HuuyISbqrL
n/a
clean
/tmp/HuuyISbqrL
n/a
clean
/tmp/HuuyISbqrL
n/a
clean
/usr/sbin/update-rc.d
update-rc.d HuuyISbqrL remove
clean
/usr/sbin/update-rc.d
n/a
clean
/usr/bin/systemctl
systemctl daemon-reload
clean
/tmp/HuuyISbqrL
n/a
clean
/tmp/HuuyISbqrL
n/a
clean
/tmp/HuuyISbqrL
n/a
clean
/tmp/HuuyISbqrL
n/a
clean
/usr/sbin/update-rc.d
update-rc.d .chinaz{1636583395 defaults
clean
/usr/sbin/update-rc.d
n/a
clean
/usr/bin/systemctl
systemctl daemon-reload
clean
/tmp/HuuyISbqrL
n/a
clean
/bin/sh
sh -c "sed -i '/\\/etc\\/cron.hourly\\/cron.sh/d' /etc/crontab && echo '*/3 * * * * root /etc/cron.hourly/cron.sh' >> /etc/crontab"
clean
/bin/sh
n/a
clean
/usr/bin/sed
sed -i /\\/etc\\/cron.hourly\\/cron.sh/d /etc/crontab
clean
/tmp/HuuyISbqrL
n/a
clean
/bin/sh
sh -c "rm -rf /etc/resolv.conf"
clean
/bin/sh
n/a
clean
/usr/bin/rm
rm -rf /etc/resolv.conf
clean
/tmp/HuuyISbqrL
n/a
clean
/bin/sh
sh -c whoami
clean
/bin/sh
n/a
clean
/usr/bin/whoami
whoami
clean
/tmp/HuuyISbqrL
n/a
clean
/bin/sh
sh -c "iptables --flush"
clean
/bin/sh
n/a
clean
/usr/sbin/iptables
iptables --flush
clean
/tmp/HuuyISbqrL
n/a
clean
/bin/sh
sh -c whoami
clean
/bin/sh
n/a
clean
/usr/bin/whoami
whoami
clean
/tmp/HuuyISbqrL
n/a
clean
/bin/sh
sh -c "touch /home/root/ConfigDatecz"
clean
/bin/sh
n/a
clean
/usr/bin/touch
touch /home/root/ConfigDatecz
clean
/tmp/HuuyISbqrL
n/a
clean
/bin/sh
sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"
clean
/bin/sh
n/a
clean
/usr/sbin/iptables
iptables -A OUTPUT -p tcp --dport 0 -j DROP
clean
/usr/lib/systemd/systemd
n/a
clean
/usr/lib/systemd/system-environment-generators/snapd-env-generator
/usr/lib/systemd/system-environment-generators/snapd-env-generator
clean
/usr/lib/systemd/systemd
n/a
clean
/usr/lib/systemd/system-environment-generators/snapd-env-generator
/usr/lib/systemd/system-environment-generators/snapd-env-generator
clean
There are 39 hidden processes, click here to show them.

URLs

Name
IP
Malicious
http://www.gnu.org/software/libc/bugs.html
unknown
clean

IPs

IP
Domain
Country
Malicious
109.202.202.202
unknown
Switzerland
clean
91.189.91.43
unknown
United Kingdom
clean
91.189.91.42
unknown
United Kingdom
clean