Linux Analysis Report chinaz
Overview
General Information
Sample Name: | chinaz |
Analysis ID: | 550994 |
MD5: | b1a249a0f2e9627d460e2b86f190e51d |
SHA1: | 7b1438586dd7c8b93285ffc774283e8fab1b82f2 |
SHA256: | 2c5ef8e33e43c4a6da2f7a2bde0d5027d344491b43dcf88c5201a3f332ccec30 |
Infos: |
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Signatures
Classification
General Information |
---|
Joe Sandbox Version: | 34.0.0 Boulder Opal |
Analysis ID: | 550994 |
Start date: | 11.01.2022 |
Start time: | 17:51:58 |
Joe Sandbox Product: | CloudBasic |
Overall analysis duration: | 0h 6m 6s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Sample file name: | chinaz |
Cookbook file name: | defaultlinuxfilecookbook.jbs |
Analysis system description: | Ubuntu Linux 16.04 x64 (Kernel 4.4.0-116, Firefox 59.0, Document Viewer 3.18.2, LibreOffice 5.1.6.2, OpenJDK 1.8.0_171) |
Analysis Mode: | default |
Detection: | MAL |
Classification: | mal100.troj.evad.lin@0/11@0/0 |
Process Tree |
---|
|
Yara Overview |
---|
Initial Sample |
---|
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
CN_disclosed_20180208_lsls | Detects malware from disclosed CN malware set | Florian Roth |
|
Dropped Files |
---|
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
CN_disclosed_20180208_lsls | Detects malware from disclosed CN malware set | Florian Roth |
|
Memory Dumps |
---|
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
CN_disclosed_20180208_lsls | Detects malware from disclosed CN malware set | Florian Roth |
| |
CN_disclosed_20180208_lsls | Detects malware from disclosed CN malware set | Florian Roth |
| |
CN_disclosed_20180208_lsls | Detects malware from disclosed CN malware set | Florian Roth |
| |
CN_disclosed_20180208_lsls | Detects malware from disclosed CN malware set | Florian Roth |
| |
CN_disclosed_20180208_lsls | Detects malware from disclosed CN malware set | Florian Roth |
| |
Click to see the 4 entries |
Jbx Signature Overview |
---|
Click to jump to signature section
AV Detection: |
---|
Antivirus / Scanner detection for submitted sample | Show sources |
Source: | Avira: |
Multi AV Scanner detection for submitted file | Show sources |
Source: | Virustotal: | Perma Link | ||
Source: | ReversingLabs: |
Antivirus detection for dropped file | Show sources |
Source: | Avira: |
Machine Learning detection for dropped file | Show sources |
Source: | Joe Sandbox ML: |
Machine Learning detection for sample | Show sources |
Source: | Joe Sandbox ML: |
Source: | Reads CPU info from /sys: | Jump to behavior |
Networking: |
---|
Executes the "iptables" command to insert, remove and/or manipulate rules | Show sources |
Source: | Iptables executable using switch for changing the iptables rules: | Jump to behavior |
Source: | Iptables executable: | Jump to behavior | ||
Source: | Iptables executable: | Jump to behavior |
Source: | String found in binary or memory: |
System Summary: |
---|
Malicious sample detected (through community Yara rule) | Show sources |
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | .symtab present: |
Source: | Classification label: |
Persistence and Installation Behavior: |
---|
Sample tries to persist itself using System V runlevels | Show sources |
Source: | File: | Jump to behavior | ||
Source: | File: | Jump to behavior | ||
Source: | File: | Jump to behavior | ||
Source: | File: | Jump to behavior | ||
Source: | File: | Jump to behavior | ||
Source: | File: | Jump to behavior | ||
Source: | File: | Jump to behavior | ||
Source: | File: | Jump to behavior | ||
Source: | File: | Jump to behavior | ||
Source: | File: | Jump to behavior | ||
Source: | File: | Jump to behavior | ||
Source: | File: | Jump to behavior | ||
Source: | File: | Jump to behavior | ||
Source: | File: | Jump to behavior | ||
Source: | File: | Jump to behavior |
Sample tries to persist itself using cron | Show sources |
Source: | File: | Jump to behavior | ||
Source: | File: | Jump to behavior |
Executes the "iptables" command to insert, remove and/or manipulate rules | Show sources |
Source: | Iptables executable using switch for changing the iptables rules: | Jump to behavior |
Source: | File written: | Jump to dropped file |
Source: | Shell script file created: | Jump to dropped file |
Source: | Reads from proc file: | Jump to behavior |
Source: | Systemctl executable: | Jump to behavior | ||
Source: | Systemctl executable: | Jump to behavior |
Source: | Iptables executable: | Jump to behavior | ||
Source: | Iptables executable: | Jump to behavior |
Source: | Rm executable: | Jump to behavior |
Source: | Touch executable: | Jump to behavior |
Source: | Writes shell script file to disk with an unusual file extension: | Jump to dropped file |
Hooking and other Techniques for Hiding and Protection: |
---|
Drops files in suspicious directories | Show sources |
Source: | File: | Jump to dropped file | ||
Source: | File: | |||
Source: | File: | |||
Source: | File: | |||
Source: | File: | Jump to dropped file | ||
Source: | File: | Jump to dropped file | ||
Source: | File: | Jump to dropped file |
Sample deletes itself | Show sources |
Source: | File: | Jump to behavior |
Drops invisible ELF files | Show sources |
Source: | ELF file: | Jump to dropped file |
Source: | Modprobe: | Jump to behavior |
Source: | Reads CPU info from /sys: | Jump to behavior |
Source: | Queries kernel information via 'uname': | Jump to behavior | ||
Source: | Queries kernel information via 'uname': | Jump to behavior | ||
Source: | Queries kernel information via 'uname': | Jump to behavior | ||
Source: | Queries kernel information via 'uname': | Jump to behavior | ||
Source: | Queries kernel information via 'uname': | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Mitre Att&ck Matrix |
---|
Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Exfiltration | Command and Control | Network Effects | Remote Service Effects | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Valid Accounts | Scripting1 | Systemd Service1 | Systemd Service1 | Masquerading1 | OS Credential Dumping | Security Software Discovery11 | Remote Services | Data from Local System | Exfiltration Over Other Network Medium | Data Obfuscation | Eavesdrop on Insecure Network Communication | Remotely Track Device Without Authorization | Modify System Partition |
Default Accounts | At (Linux)2 | Kernel Modules and Extensions1 | Kernel Modules and Extensions1 | Scripting1 | LSASS Memory | System Information Discovery2 | Remote Desktop Protocol | Data from Removable Media | Exfiltration Over Bluetooth | Junk Data | Exploit SS7 to Redirect Phone Calls/SMS | Remotely Wipe Data Without Authorization | Device Lockout |
Domain Accounts | At (Linux) | At (Linux)2 | At (Linux)2 | Hidden Files and Directories1 | Security Account Manager | System Network Configuration Discovery1 | SMB/Windows Admin Shares | Data from Network Shared Drive | Automated Exfiltration | Steganography | Exploit SS7 to Track Device Location | Obtain Device Cloud Backups | Delete Device Data |
Local Accounts | At (Windows) | Logon Script (Mac) | Logon Script (Mac) | Indicator Removal on Host1 | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | Scheduled Transfer | Protocol Impersonation | SIM Card Swap | Carrier Billing Fraud | |
Cloud Accounts | Cron | Network Logon Script | Network Logon Script | File Deletion11 | LSA Secrets | Remote System Discovery | SSH | Keylogging | Data Transfer Size Limits | Fallback Channels | Manipulate Device Communication | Manipulate App Store Rankings or Ratings |
Malware Configuration |
---|
No configs have been found |
---|
Behavior Graph |
---|
Antivirus, Machine Learning and Genetic Malware Detection |
---|
Initial Sample |
---|
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
60% | Virustotal | Browse | ||
72% | ReversingLabs | Linux.Trojan.XorDDoS | ||
100% | Avira | LINUX/ChinaZ.qeofi | ||
100% | Joe Sandbox ML |
Dropped Files |
---|
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Avira | LINUX/ChinaZ.qeofi | ||
100% | Joe Sandbox ML | |||
5% | Virustotal | Browse | ||
11% | Metadefender | Browse | ||
14% | ReversingLabs | Linux.Trojan.XorDDoS |
Domains |
---|
No Antivirus matches |
---|
URLs |
---|
No Antivirus matches |
---|
Domains and IPs |
---|
Contacted Domains |
---|
No contacted domains info |
---|
URLs from Memory and Binaries |
---|
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high |
Contacted IPs |
---|
No contacted IP infos |
---|
Runtime Messages |
---|
Command: | /tmp/chinaz |
Exit Code: | 0 |
Exit Code Info: | |
Killed: | False |
Standard Output: | |
Standard Error: |
Joe Sandbox View / Context |
---|
Created / dropped Files |
---|
Process: | /tmp/chinaz |
File Type: | |
Category: | dropped |
Size (bytes): | 223 |
Entropy (8bit): | 4.756432444291805 |
Encrypted: | false |
SSDEEP: | 6:htiy4Mrm9lVNy28XbCVP270gJdUiynrgns:RjwVNfGbWPirSR |
MD5: | B791B087B1795E3674A9AA765C76FC04 |
SHA1: | B53F478234AE97F3CDBF2E7FE7EC68D687FEB7C1 |
SHA-256: | 1C1E9B69CF8021BF7CE1F60DCAA2D31C1E21ED4B6E474F3571DA81FFD5A9B69E |
SHA-512: | 2DCC2E478C51CF8118306FD5C744AAD7147E368CBC4329DB1CC5FAC52088A7F3354079AE2B582B270495789E4FB4591538EC88BB5EA40EEC646F360BAC33BBB2 |
Malicious: | true |
Antivirus: | |
Joe Sandbox View: | |
Reputation: | low |
Preview: |
|
Process: | /tmp/chinaz |
File Type: | |
Category: | dropped |
Size (bytes): | 355 |
Entropy (8bit): | 5.348956811098055 |
Encrypted: | false |
SSDEEP: | 6:hUtoFdU9uMw2DjnnsKheJjU5DjBE21YJvmNeMwh2L5DjR1DzRIjupa6MzEupq4:6tw23mjcXBEMO12L5rzujupazEupN |
MD5: | 9B4D23AB68C5E489F8F51068A78C66A0 |
SHA1: | 3823D3B8745D5349C20A2B6D37FE68975E36A388 |
SHA-256: | DE7BB3CD3B506B4928A9695379DDEB476F4952BFD55CEE8B52D89DE3058E929D |
SHA-512: | 45503211B41982A588ADFAD90E139659F4321DDE4C5DC45E2FF22D040F6E655552B3602B3D87A684113F1679F100664FACF8EBB59703163A690B9762AC78AB5A |
Malicious: | true |
Yara Hits: |
|
Antivirus: |
|
Reputation: | low |
Preview: |
|
Process: | /usr/lib/insserv/insserv |
File Type: | |
Category: | dropped |
Size (bytes): | 1380 |
Entropy (8bit): | 4.6286085863457025 |
Encrypted: | false |
SSDEEP: | 24:KcR684NIwOkJVARL9Eg3U3PX2xRmbUtOeAyh1ZFDSYpY3dOUwZlY:VR6843OkjARLq0U3PX2xYwtOQh1vDTp8 |
MD5: | 5B62F52693F19BAD0D1373AB955F17B8 |
SHA1: | 3865ED303BD83951D0D69D87A6290F120A937C2E |
SHA-256: | 9026F82085CF03BE408767439E4FD595F266FE6F11ECC4A3AF7F0555ED358196 |
SHA-512: | E0015AA580EAAFFF64D59F666FDC91280AAC50C10D5189A13B376E3C9DC71A0FE019D7EE05351F1136F65F5F1CAE6C58D781CBA2E073D57E323629BF5137BE25 |
Malicious: | true |
Reputation: | moderate, very likely benign file |
Preview: |
|
Process: | /usr/lib/insserv/insserv |
File Type: | |
Category: | dropped |
Size (bytes): | 1747 |
Entropy (8bit): | 4.765110587196196 |
Encrypted: | false |
SSDEEP: | 48:ZurDNySAzo1kyE27ZGme/9/n2U5X+/9/n2U5Xo/9/n2U5X8h/9/n2U5XM:+DWo1PE27keU5eeU5YeU54eU58 |
MD5: | 4E7BE4A340D737727E65CDB7153FF44A |
SHA1: | 64E177AFB49715C86F913EA61CAAE0F78AB5ADCB |
SHA-256: | 4FF28A9681F87884DE918FF330799ACD6EBD90D9CDECC9B7D36C0A60302EF123 |
SHA-512: | 82658FD873201E0FC8774A1594D0FFF81DB94A0AD163D7DB06E26B28C33756EB0A5F730288768A0293D99430B4C290EE5BF701B66306885B7652CA080AFA7A50 |
Malicious: | true |
Reputation: | low |
Preview: |
|
Process: | /usr/lib/insserv/insserv |
File Type: | |
Category: | dropped |
Size (bytes): | 1690 |
Entropy (8bit): | 4.52194295219339 |
Encrypted: | false |
SSDEEP: | 48:3Yu8rBj1G4GJ/suwT2UKGhuw2zOsuwK2UPOiNQh/4uwHFn2U5wT:M1iUJeZU1cU0 |
MD5: | 7897338A208ABF2E5C95E7994A24F8C8 |
SHA1: | 185E660978A050BD66B62C6AF44695251A373390 |
SHA-256: | 7143B8292EB1C2476411ECA94A4A67E5A166C9FB916724B3458247D1C0E1F5CB |
SHA-512: | F322DB116C7DE93E68D9709B8E2CE8163BC1E0BEB264D5D178815DB839FFB3E88AF4C17B4095BFB60A579B103CE48D67B1A257CA3394FCFD46FDA97A473C2632 |
Malicious: | true |
Reputation: | low |
Preview: |
|
Process: | /tmp/chinaz |
File Type: | |
Category: | dropped |
Size (bytes): | 1315556 |
Entropy (8bit): | 6.3900573752414855 |
Encrypted: | false |
SSDEEP: | 24576:8kUpotcUSzgtPLdOEG0V0JRzFB3ywyUZ1N2AhNdhBjh+hnPlVVW0Mk7t69Kx/ti8:MoKXwZOK0TFBCwy8P2AhNdhBjh+hnPlP |
MD5: | B1A249A0F2E9627D460E2B86F190E51D |
SHA1: | 7B1438586DD7C8B93285FFC774283E8FAB1B82F2 |
SHA-256: | 2C5EF8E33E43C4A6DA2F7A2BDE0D5027D344491B43DCF88C5201A3F332CCEC30 |
SHA-512: | 4B4EE9E06E7FFFB5D34F68FBC7F575AB5504BDEC3C11A3570FE9F8C85199BCC029BCF15CB89CAD7DFB1A24CC963B9C89DEE20349C12414F95C28062A39B83D58 |
Malicious: | true |
Reputation: | low |
Preview: |
|
Process: | /usr/share/apport/apport-checkreports |
File Type: | |
Category: | dropped |
Size (bytes): | 14915 |
Entropy (8bit): | 4.694665867199824 |
Encrypted: | false |
SSDEEP: | 96:1Im4p8CDUKWw4b/sspgX1AE/DKz+E+8n1Hh8vwfEYe1KPIBd4YXrM:1zCD6w4b/ssf3+E+8newfEYegPIPhbM |
MD5: | 26A3A8DAB6EE5B015362B9B2D3720350 |
SHA1: | 8A3628E77409889D197926938BC2E88B766D7EFD |
SHA-256: | 85B8DEC8A8AD539B531052B76A0D4AFA453445D4367A7DD23BF217BE8536BAF8 |
SHA-512: | 8D9B23C41C4CEDE0344A5382B7388E12A9228C5A56406C149B68DF340A0FE5A51144AB18AD6F7A585E1DE3FB04605EB985948C0FD1C61D1534074FBABCC3A9AA |
Malicious: | false |
Reputation: | low |
Preview: |
|
Process: | /usr/share/apport/apport-gtk |
File Type: | |
Category: | dropped |
Size (bytes): | 47094 |
Entropy (8bit): | 4.515770717587538 |
Encrypted: | false |
SSDEEP: | 768:5r21XXfYKGWB5lrG9GIaXzIRspIUc/x/O/R/vw2sCY9dby1DFK59vPUaG0k:5r21XXfYKGWB5lrG9GIaXzIRspIUc/xM |
MD5: | D26F83931D5226DF3F84F2F39A925BD7 |
SHA1: | 8D2A3DDAD6234D6AB9E4060AD9DEE1678467BA2F |
SHA-256: | 2A484CBB8C467138294EDC036C4353DA4738786AEE27C16BAFF8471A10A83A62 |
SHA-512: | B77A0FF36A1D510D57B47BA2D8D288ABC230681D4804C338C3AF935360C4186C0EB1B50AE22355F2E71BBF29911BBD31D8BFB9145E442D03E32D235C16EF348C |
Malicious: | false |
Reputation: | low |
Preview: |
|
Static File Info |
---|
General | |
---|---|
File type: | |
Entropy (8bit): | 6.3900573752414855 |
TrID: |
|
File name: | chinaz |
File size: | 1315556 |
MD5: | b1a249a0f2e9627d460e2b86f190e51d |
SHA1: | 7b1438586dd7c8b93285ffc774283e8fab1b82f2 |
SHA256: | 2c5ef8e33e43c4a6da2f7a2bde0d5027d344491b43dcf88c5201a3f332ccec30 |
SHA512: | 4b4ee9e06e7fffb5d34f68fbc7f575ab5504bdec3c11a3570fe9f8c85199bcc029bcf15cb89cad7dfb1a24cc963b9c89dee20349c12414f95c28062a39b83d58 |
SSDEEP: | 24576:8kUpotcUSzgtPLdOEG0V0JRzFB3ywyUZ1N2AhNdhBjh+hnPlVVW0Mk7t69Kx/ti8:MoKXwZOK0TFBCwy8P2AhNdhBjh+hnPlP |
File Content Preview: | .ELF........................4...........4. ...(.....................................................................................D...D...............................L...........Q.td........................................GNU............................ |
Static ELF Info |
---|
ELF header | |
---|---|
Class: | |
Data: | |
Version: | |
Machine: | |
Version Number: | |
Type: | |
OS/ABI: | |
ABI Version: | |
Entry Point Address: | |
Flags: | |
ELF Header Size: | |
Program Header Offset: | |
Program Header Size: | |
Number of Program Headers: | |
Section Header Offset: | |
Section Header Size: | |
Number of Section Headers: | |
Header String Table Index: |
Sections |
---|
Name | Type | Address | Offset | Size | EntSize | Flags | Flags Description | Link | Info | Align |
---|---|---|---|---|---|---|---|---|---|---|
NULL | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0 | 0 | 0 | ||
.note.ABI-tag | NOTE | 0x80480d4 | 0xd4 | 0x20 | 0x0 | 0x2 | A | 0 | 0 | 4 |
.note.gnu.build-id | NOTE | 0x80480f4 | 0xf4 | 0x24 | 0x0 | 0x2 | A | 0 | 0 | 4 |
.rel.plt | REL | 0x8048118 | 0x118 | 0x38 | 0x8 | 0x2 | A | 0 | 5 | 4 |
.init | PROGBITS | 0x8048150 | 0x150 | 0x30 | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.plt | PROGBITS | 0x8048180 | 0x180 | 0x70 | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.text | PROGBITS | 0x80481f0 | 0x1f0 | 0xf3bfc | 0x0 | 0x6 | AX | 0 | 0 | 16 |
__libc_freeres_fn | PROGBITS | 0x813bdf0 | 0xf3df0 | 0x1838 | 0x0 | 0x6 | AX | 0 | 0 | 16 |
__libc_thread_freeres_fn | PROGBITS | 0x813d630 | 0xf5630 | 0x1fa | 0x0 | 0x6 | AX | 0 | 0 | 16 |
.fini | PROGBITS | 0x813d82c | 0xf582c | 0x1c | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.rodata | PROGBITS | 0x813d860 | 0xf5860 | 0x1d5e4 | 0x0 | 0x2 | A | 0 | 0 | 32 |
__libc_subfreeres | PROGBITS | 0x815ae44 | 0x112e44 | 0x34 | 0x0 | 0x2 | A | 0 | 0 | 4 |
__libc_atexit | PROGBITS | 0x815ae78 | 0x112e78 | 0x4 | 0x0 | 0x2 | A | 0 | 0 | 4 |
__libc_thread_subfreeres | PROGBITS | 0x815ae7c | 0x112e7c | 0x8 | 0x0 | 0x2 | A | 0 | 0 | 4 |
.stapsdt.base | PROGBITS | 0x815ae84 | 0x112e84 | 0x1 | 0x0 | 0x2 | A | 0 | 0 | 1 |
.eh_frame | PROGBITS | 0x815ae88 | 0x112e88 | 0x2843c | 0x0 | 0x2 | A | 0 | 0 | 4 |
.gcc_except_table | PROGBITS | 0x81832c4 | 0x13b2c4 | 0x4010 | 0x0 | 0x2 | A | 0 | 0 | 4 |
.tdata | PROGBITS | 0x81882d4 | 0x13f2d4 | 0x14 | 0x0 | 0x403 | WAT | 0 | 0 | 4 |
.tbss | NOBITS | 0x81882e8 | 0x13f2e8 | 0x38 | 0x0 | 0x403 | WAT | 0 | 0 | 4 |
.ctors | PROGBITS | 0x81882e8 | 0x13f2e8 | 0x28 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.dtors | PROGBITS | 0x8188310 | 0x13f310 | 0xc | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.jcr | PROGBITS | 0x818831c | 0x13f31c | 0x4 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.data.rel.ro | PROGBITS | 0x8188320 | 0x13f320 | 0xca0 | 0x0 | 0x3 | WA | 0 | 0 | 32 |
.got | PROGBITS | 0x8188fc0 | 0x13ffc0 | 0xa4 | 0x4 | 0x3 | WA | 0 | 0 | 4 |
.got.plt | PROGBITS | 0x8189064 | 0x140064 | 0x28 | 0x4 | 0x3 | WA | 0 | 0 | 4 |
.data | PROGBITS | 0x81890a0 | 0x1400a0 | 0x9b4 | 0x0 | 0x3 | WA | 0 | 0 | 32 |
.bss | NOBITS | 0x8189a60 | 0x140a54 | 0xbb1c | 0x0 | 0x3 | WA | 0 | 0 | 32 |
__libc_freeres_ptrs | NOBITS | 0x819557c | 0x140a54 | 0x18 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.note.stapsdt | NOTE | 0x0 | 0x140a54 | 0x23c | 0x0 | 0x0 | 0 | 0 | 4 | |
.comment | PROGBITS | 0x0 | 0x140c90 | 0x2d | 0x1 | 0x30 | MS | 0 | 0 | 1 |
.shstrtab | STRTAB | 0x0 | 0x140cbd | 0x14e | 0x0 | 0x0 | 0 | 0 | 1 |
Program Segments |
---|
Type | Offset | Virtual Address | Physical Address | File Size | Memory Size | Entropy | Flags | Flags Description | Align | Prog Interpreter | Section Mappings |
---|---|---|---|---|---|---|---|---|---|---|---|
LOAD | 0x0 | 0x8048000 | 0x8048000 | 0x13f2d4 | 0x13f2d4 | 3.5669 | 0x5 | R E | 0x1000 | .note.ABI-tag .note.gnu.build-id .rel.plt .init .plt .text __libc_freeres_fn __libc_thread_freeres_fn .fini .rodata __libc_subfreeres __libc_atexit __libc_thread_subfreeres .stapsdt.base .eh_frame .gcc_except_table | |
LOAD | 0x13f2d4 | 0x81882d4 | 0x81882d4 | 0x1780 | 0xd2c0 | 2.8979 | 0x6 | RW | 0x1000 | .ctors .dtors .jcr .data.rel.ro .got .got.plt .data .bss __libc_freeres_ptrs | |
NOTE | 0xd4 | 0x80480d4 | 0x80480d4 | 0x44 | 0x44 | 2.5077 | 0x4 | R | 0x4 | .note.ABI-tag .note.gnu.build-id | |
TLS | 0x13f2d4 | 0x81882d4 | 0x81882d4 | 0x14 | 0x4c | 1.3966 | 0x4 | R | 0x4 | ||
GNU_STACK | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0.0000 | 0x6 | RW | 0x4 |
Network Behavior |
---|
No network behavior found |
---|
System Behavior |
---|
General |
---|
Start time: | 17:52:33 |
Start date: | 11/01/2022 |
Path: | /tmp/chinaz |
Arguments: | /tmp/chinaz |
File size: | 1315556 bytes |
MD5 hash: | b1a249a0f2e9627d460e2b86f190e51d |
General |
---|
Start time: | 17:52:33 |
Start date: | 11/01/2022 |
Path: | /tmp/chinaz |
Arguments: | n/a |
File size: | 1315556 bytes |
MD5 hash: | b1a249a0f2e9627d460e2b86f190e51d |
General |
---|
Start time: | 17:52:33 |
Start date: | 11/01/2022 |
Path: | /tmp/chinaz |
Arguments: | n/a |
File size: | 1315556 bytes |
MD5 hash: | b1a249a0f2e9627d460e2b86f190e51d |
General |
---|
Start time: | 17:52:33 |
Start date: | 11/01/2022 |
Path: | /tmp/chinaz |
Arguments: | n/a |
File size: | 1315556 bytes |
MD5 hash: | b1a249a0f2e9627d460e2b86f190e51d |
General |
---|
Start time: | 17:52:33 |
Start date: | 11/01/2022 |
Path: | /tmp/chinaz |
Arguments: | n/a |
File size: | 1315556 bytes |
MD5 hash: | b1a249a0f2e9627d460e2b86f190e51d |
General |
---|
Start time: | 17:52:33 |
Start date: | 11/01/2022 |
Path: | /tmp/chinaz |
Arguments: | n/a |
File size: | 1315556 bytes |
MD5 hash: | b1a249a0f2e9627d460e2b86f190e51d |
General |
---|
Start time: | 17:52:33 |
Start date: | 11/01/2022 |
Path: | /tmp/chinaz |
Arguments: | n/a |
File size: | 1315556 bytes |
MD5 hash: | b1a249a0f2e9627d460e2b86f190e51d |
General |
---|
Start time: | 17:52:33 |
Start date: | 11/01/2022 |
Path: | /usr/sbin/update-rc.d |
Arguments: | /usr/bin/perl /usr/sbin/update-rc.d chinaz remove |
File size: | 14437 bytes |
MD5 hash: | e9e125904f9ed8ff4c8504a55a149005 |
General |
---|
Start time: | 17:52:33 |
Start date: | 11/01/2022 |
Path: | /usr/sbin/update-rc.d |
Arguments: | n/a |
File size: | 14437 bytes |
MD5 hash: | e9e125904f9ed8ff4c8504a55a149005 |
General |
---|
Start time: | 17:52:33 |
Start date: | 11/01/2022 |
Path: | /usr/lib/insserv/insserv |
Arguments: | /usr/lib/insserv/insserv |
File size: | 56512 bytes |
MD5 hash: | 34c11674a0b29347001640aeae7c94f1 |
General |
---|
Start time: | 17:52:34 |
Start date: | 11/01/2022 |
Path: | /usr/sbin/update-rc.d |
Arguments: | n/a |
File size: | 14437 bytes |
MD5 hash: | e9e125904f9ed8ff4c8504a55a149005 |
General |
---|
Start time: | 17:52:34 |
Start date: | 11/01/2022 |
Path: | /bin/systemctl |
Arguments: | systemctl daemon-reload |
File size: | 659848 bytes |
MD5 hash: | b08096235b8c90203e17721264b5ce40 |
General |
---|
Start time: | 17:52:33 |
Start date: | 11/01/2022 |
Path: | /tmp/chinaz |
Arguments: | n/a |
File size: | 1315556 bytes |
MD5 hash: | b1a249a0f2e9627d460e2b86f190e51d |
General |
---|
Start time: | 17:52:33 |
Start date: | 11/01/2022 |
Path: | /tmp/chinaz |
Arguments: | n/a |
File size: | 1315556 bytes |
MD5 hash: | b1a249a0f2e9627d460e2b86f190e51d |
General |
---|
Start time: | 17:52:33 |
Start date: | 11/01/2022 |
Path: | /tmp/chinaz |
Arguments: | n/a |
File size: | 1315556 bytes |
MD5 hash: | b1a249a0f2e9627d460e2b86f190e51d |
General |
---|
Start time: | 17:52:33 |
Start date: | 11/01/2022 |
Path: | /tmp/chinaz |
Arguments: | n/a |
File size: | 1315556 bytes |
MD5 hash: | b1a249a0f2e9627d460e2b86f190e51d |
General |
---|
Start time: | 17:52:33 |
Start date: | 11/01/2022 |
Path: | /usr/sbin/update-rc.d |
Arguments: | /usr/bin/perl /usr/sbin/update-rc.d .chinaz{1641923553 defaults |
File size: | 14437 bytes |
MD5 hash: | e9e125904f9ed8ff4c8504a55a149005 |
General |
---|
Start time: | 17:52:33 |
Start date: | 11/01/2022 |
Path: | /usr/sbin/update-rc.d |
Arguments: | n/a |
File size: | 14437 bytes |
MD5 hash: | e9e125904f9ed8ff4c8504a55a149005 |
General |
---|
Start time: | 17:52:33 |
Start date: | 11/01/2022 |
Path: | /usr/lib/insserv/insserv |
Arguments: | /usr/lib/insserv/insserv .chinaz{1641923553 |
File size: | 56512 bytes |
MD5 hash: | 34c11674a0b29347001640aeae7c94f1 |
General |
---|
Start time: | 17:52:34 |
Start date: | 11/01/2022 |
Path: | /usr/sbin/update-rc.d |
Arguments: | n/a |
File size: | 14437 bytes |
MD5 hash: | e9e125904f9ed8ff4c8504a55a149005 |
General |
---|
Start time: | 17:52:34 |
Start date: | 11/01/2022 |
Path: | /bin/systemctl |
Arguments: | systemctl daemon-reload |
File size: | 659848 bytes |
MD5 hash: | b08096235b8c90203e17721264b5ce40 |
General |
---|
Start time: | 17:52:33 |
Start date: | 11/01/2022 |
Path: | /tmp/chinaz |
Arguments: | n/a |
File size: | 1315556 bytes |
MD5 hash: | b1a249a0f2e9627d460e2b86f190e51d |
General |
---|
Start time: | 17:52:33 |
Start date: | 11/01/2022 |
Path: | /bin/dash |
Arguments: | sh -c "sed -i '/\\/etc\\/cron.hourly\\/cron.sh/d' /etc/crontab && echo '*/3 * * * * root /etc/cron.hourly/cron.sh' >> /etc/crontab" |
File size: | 154072 bytes |
MD5 hash: | e02ea3c3450d44126c46d658fa9e654c |
General |
---|
Start time: | 17:52:33 |
Start date: | 11/01/2022 |
Path: | /bin/dash |
Arguments: | n/a |
File size: | 154072 bytes |
MD5 hash: | e02ea3c3450d44126c46d658fa9e654c |
General |
---|
Start time: | 17:52:33 |
Start date: | 11/01/2022 |
Path: | /bin/sed |
Arguments: | sed -i /\\/etc\\/cron.hourly\\/cron.sh/d /etc/crontab |
File size: | 73424 bytes |
MD5 hash: | c1a00c583ba08e728b10f3f46f5776d6 |
General |
---|
Start time: | 17:52:33 |
Start date: | 11/01/2022 |
Path: | /tmp/chinaz |
Arguments: | n/a |
File size: | 1315556 bytes |
MD5 hash: | b1a249a0f2e9627d460e2b86f190e51d |
General |
---|
Start time: | 17:52:33 |
Start date: | 11/01/2022 |
Path: | /bin/dash |
Arguments: | sh -c "rm -rf /etc/resolv.conf" |
File size: | 154072 bytes |
MD5 hash: | e02ea3c3450d44126c46d658fa9e654c |
General |
---|
Start time: | 17:52:33 |
Start date: | 11/01/2022 |
Path: | /bin/dash |
Arguments: | n/a |
File size: | 154072 bytes |
MD5 hash: | e02ea3c3450d44126c46d658fa9e654c |
General |
---|
Start time: | 17:52:33 |
Start date: | 11/01/2022 |
Path: | /bin/rm |
Arguments: | rm -rf /etc/resolv.conf |
File size: | 60272 bytes |
MD5 hash: | b79876063d894c449856cca508ecca7f |
General |
---|
Start time: | 17:52:33 |
Start date: | 11/01/2022 |
Path: | /tmp/chinaz |
Arguments: | n/a |
File size: | 1315556 bytes |
MD5 hash: | b1a249a0f2e9627d460e2b86f190e51d |
General |
---|
Start time: | 17:52:33 |
Start date: | 11/01/2022 |
Path: | /bin/dash |
Arguments: | sh -c whoami |
File size: | 154072 bytes |
MD5 hash: | e02ea3c3450d44126c46d658fa9e654c |
General |
---|
Start time: | 17:52:33 |
Start date: | 11/01/2022 |
Path: | /bin/dash |
Arguments: | n/a |
File size: | 154072 bytes |
MD5 hash: | e02ea3c3450d44126c46d658fa9e654c |
General |
---|
Start time: | 17:52:33 |
Start date: | 11/01/2022 |
Path: | /usr/bin/whoami |
Arguments: | whoami |
File size: | 27312 bytes |
MD5 hash: | a88b7850f1cdbf532f14069816273b63 |
General |
---|
Start time: | 17:52:33 |
Start date: | 11/01/2022 |
Path: | /tmp/chinaz |
Arguments: | n/a |
File size: | 1315556 bytes |
MD5 hash: | b1a249a0f2e9627d460e2b86f190e51d |
General |
---|
Start time: | 17:52:33 |
Start date: | 11/01/2022 |
Path: | /bin/dash |
Arguments: | sh -c whoami |
File size: | 154072 bytes |
MD5 hash: | e02ea3c3450d44126c46d658fa9e654c |
General |
---|
Start time: | 17:52:33 |
Start date: | 11/01/2022 |
Path: | /bin/dash |
Arguments: | n/a |
File size: | 154072 bytes |
MD5 hash: | e02ea3c3450d44126c46d658fa9e654c |
General |
---|
Start time: | 17:52:33 |
Start date: | 11/01/2022 |
Path: | /usr/bin/whoami |
Arguments: | whoami |
File size: | 27312 bytes |
MD5 hash: | a88b7850f1cdbf532f14069816273b63 |
General |
---|
Start time: | 17:52:33 |
Start date: | 11/01/2022 |
Path: | /tmp/chinaz |
Arguments: | n/a |
File size: | 1315556 bytes |
MD5 hash: | b1a249a0f2e9627d460e2b86f190e51d |
General |
---|
Start time: | 17:52:33 |
Start date: | 11/01/2022 |
Path: | /bin/dash |
Arguments: | sh -c "iptables --flush" |
File size: | 154072 bytes |
MD5 hash: | e02ea3c3450d44126c46d658fa9e654c |
General |
---|
Start time: | 17:52:33 |
Start date: | 11/01/2022 |
Path: | /bin/dash |
Arguments: | n/a |
File size: | 154072 bytes |
MD5 hash: | e02ea3c3450d44126c46d658fa9e654c |
General |
---|
Start time: | 17:52:33 |
Start date: | 11/01/2022 |
Path: | /sbin/iptables |
Arguments: | iptables --flush |
File size: | 13 bytes |
MD5 hash: | e986504da7dab031032b3d3eac5b643e |
General |
---|
Start time: | 17:52:33 |
Start date: | 11/01/2022 |
Path: | /sbin/iptables |
Arguments: | n/a |
File size: | 13 bytes |
MD5 hash: | e986504da7dab031032b3d3eac5b643e |
General |
---|
Start time: | 17:52:33 |
Start date: | 11/01/2022 |
Path: | /sbin/modprobe |
Arguments: | /sbin/modprobe ip_tables |
File size: | 0 bytes |
MD5 hash: | unknown |
General |
---|
Start time: | 17:52:33 |
Start date: | 11/01/2022 |
Path: | /tmp/chinaz |
Arguments: | n/a |
File size: | 1315556 bytes |
MD5 hash: | b1a249a0f2e9627d460e2b86f190e51d |
General |
---|
Start time: | 17:52:33 |
Start date: | 11/01/2022 |
Path: | /bin/dash |
Arguments: | sh -c "touch /home/root/ConfigDatecz" |
File size: | 154072 bytes |
MD5 hash: | e02ea3c3450d44126c46d658fa9e654c |
General |
---|
Start time: | 17:52:33 |
Start date: | 11/01/2022 |
Path: | /bin/dash |
Arguments: | n/a |
File size: | 154072 bytes |
MD5 hash: | e02ea3c3450d44126c46d658fa9e654c |
General |
---|
Start time: | 17:52:33 |
Start date: | 11/01/2022 |
Path: | /usr/bin/touch |
Arguments: | touch /home/root/ConfigDatecz |
File size: | 10 bytes |
MD5 hash: | 1f168f69957c0fffbdd62556ad215f3c |
General |
---|
Start time: | 17:52:33 |
Start date: | 11/01/2022 |
Path: | /tmp/chinaz |
Arguments: | n/a |
File size: | 1315556 bytes |
MD5 hash: | b1a249a0f2e9627d460e2b86f190e51d |
General |
---|
Start time: | 17:52:33 |
Start date: | 11/01/2022 |
Path: | /bin/dash |
Arguments: | sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP" |
File size: | 154072 bytes |
MD5 hash: | e02ea3c3450d44126c46d658fa9e654c |
General |
---|
Start time: | 17:52:33 |
Start date: | 11/01/2022 |
Path: | /bin/dash |
Arguments: | n/a |
File size: | 154072 bytes |
MD5 hash: | e02ea3c3450d44126c46d658fa9e654c |
General |
---|
Start time: | 17:52:33 |
Start date: | 11/01/2022 |
Path: | /sbin/iptables |
Arguments: | iptables -A OUTPUT -p tcp --dport 0 -j DROP |
File size: | 13 bytes |
MD5 hash: | e986504da7dab031032b3d3eac5b643e |
General |
---|
Start time: | 17:52:34 |
Start date: | 11/01/2022 |
Path: | /sbin/upstart |
Arguments: | n/a |
File size: | 0 bytes |
MD5 hash: | unknown |
General |
---|
Start time: | 17:52:34 |
Start date: | 11/01/2022 |
Path: | /bin/sh |
Arguments: | /bin/sh -e /proc/self/fd/9 |
File size: | 4 bytes |
MD5 hash: | e02ea3c3450d44126c46d658fa9e654c |
General |
---|
Start time: | 17:52:34 |
Start date: | 11/01/2022 |
Path: | /bin/sh |
Arguments: | n/a |
File size: | 4 bytes |
MD5 hash: | e02ea3c3450d44126c46d658fa9e654c |
General |
---|
Start time: | 17:52:34 |
Start date: | 11/01/2022 |
Path: | /bin/date |
Arguments: | date |
File size: | 68464 bytes |
MD5 hash: | 54903b613f9019bfca9f5d28a4fff34e |
General |
---|
Start time: | 17:52:34 |
Start date: | 11/01/2022 |
Path: | /bin/sh |
Arguments: | n/a |
File size: | 4 bytes |
MD5 hash: | e02ea3c3450d44126c46d658fa9e654c |
General |
---|
Start time: | 17:52:34 |
Start date: | 11/01/2022 |
Path: | /usr/share/apport/apport-checkreports |
Arguments: | /usr/bin/python3 /usr/share/apport/apport-checkreports --system |
File size: | 1269 bytes |
MD5 hash: | 1a7d84ebc34df04e55ca3723541f48c9 |
General |
---|
Start time: | 17:52:35 |
Start date: | 11/01/2022 |
Path: | /sbin/upstart |
Arguments: | n/a |
File size: | 0 bytes |
MD5 hash: | unknown |
General |
---|
Start time: | 17:52:35 |
Start date: | 11/01/2022 |
Path: | /bin/sh |
Arguments: | /bin/sh -e /proc/self/fd/9 |
File size: | 4 bytes |
MD5 hash: | e02ea3c3450d44126c46d658fa9e654c |
General |
---|
Start time: | 17:52:35 |
Start date: | 11/01/2022 |
Path: | /bin/sh |
Arguments: | n/a |
File size: | 4 bytes |
MD5 hash: | e02ea3c3450d44126c46d658fa9e654c |
General |
---|
Start time: | 17:52:35 |
Start date: | 11/01/2022 |
Path: | /bin/date |
Arguments: | date |
File size: | 68464 bytes |
MD5 hash: | 54903b613f9019bfca9f5d28a4fff34e |
General |
---|
Start time: | 17:52:35 |
Start date: | 11/01/2022 |
Path: | /bin/sh |
Arguments: | n/a |
File size: | 4 bytes |
MD5 hash: | e02ea3c3450d44126c46d658fa9e654c |
General |
---|
Start time: | 17:52:35 |
Start date: | 11/01/2022 |
Path: | /usr/share/apport/apport-gtk |
Arguments: | /usr/bin/python3 /usr/share/apport/apport-gtk |
File size: | 23806 bytes |
MD5 hash: | ec58a49a30ef6a29406a204f28cc7d87 |
General |
---|
Start time: | 17:52:35 |
Start date: | 11/01/2022 |
Path: | /sbin/upstart |
Arguments: | n/a |
File size: | 0 bytes |
MD5 hash: | unknown |
General |
---|
Start time: | 17:52:35 |
Start date: | 11/01/2022 |
Path: | /bin/sh |
Arguments: | /bin/sh -e /proc/self/fd/9 |
File size: | 4 bytes |
MD5 hash: | e02ea3c3450d44126c46d658fa9e654c |
General |
---|
Start time: | 17:52:35 |
Start date: | 11/01/2022 |
Path: | /bin/sh |
Arguments: | n/a |
File size: | 4 bytes |
MD5 hash: | e02ea3c3450d44126c46d658fa9e654c |
General |
---|
Start time: | 17:52:35 |
Start date: | 11/01/2022 |
Path: | /bin/date |
Arguments: | date |
File size: | 68464 bytes |
MD5 hash: | 54903b613f9019bfca9f5d28a4fff34e |
General |
---|
Start time: | 17:52:35 |
Start date: | 11/01/2022 |
Path: | /bin/sh |
Arguments: | n/a |
File size: | 4 bytes |
MD5 hash: | e02ea3c3450d44126c46d658fa9e654c |
General |
---|
Start time: | 17:52:35 |
Start date: | 11/01/2022 |
Path: | /usr/share/apport/apport-gtk |
Arguments: | /usr/bin/python3 /usr/share/apport/apport-gtk |
File size: | 23806 bytes |
MD5 hash: | ec58a49a30ef6a29406a204f28cc7d87 |