Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
.i.elf

Overview

General Information

Sample name:.i.elf
Analysis ID:1561769
MD5:e5940168886f77e0511035238d976b0a
SHA1:ebe648b8cbd999844e725915e00aad00011a9f4c
SHA256:c92d81d7adca77fda2be2826610ac3fbd0d35bfc917534397dd8660621a2b471
Tags:elfuser-abuse_ch
Infos:

Detection

Score:68
Range:0 - 100
Whitelisted:false

Signatures

Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Executes the "iptables" command to insert, remove and/or manipulate rules
Opens /proc/net/* files useful for finding connected devices and routers
Sample deletes itself
Creates hidden files and/or directories
ELF contains segments with high entropy indicating compressed/encrypted content
Enumerates processes within the "proc" file system
Executes commands using a shell command-line interpreter
Executes the "iptables" command used for managing IP filtering and manipulation
Reads the 'hosts' file potentially containing internal network hosts
Sample contains only a LOAD segment without any section mappings
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1561769
Start date and time:2024-11-24 08:52:05 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 5m 4s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:.i.elf
Detection:MAL
Classification:mal68.spre.evad.linELF@0/1@56/0
  • Excluded IPs from analysis (whitelisted): 212.138.170.134
  • Excluded domains from analysis (whitelisted): pool.ntp.org
  • VT rate limit hit for: .i.elf
Command:/tmp/.i.elf
PID:6228
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:

Standard Error:iptables v1.8.4 (legacy): Couldn't load target `CWMP_CR':No such file or directory

Try `iptables -h' or 'iptables --help' for more information.
iptables: No chain/target/match by that name.
  • system is lnxubuntu20
  • .i.elf (PID: 6228, Parent: 6153, MD5: 5ebfcae4fe2471fcc5695c2394773ff1) Arguments: /tmp/.i.elf
    • .i.elf New Fork (PID: 6230, Parent: 6228)
      • .i.elf New Fork (PID: 6234, Parent: 6230)
      • sh (PID: 6234, Parent: 6230, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -c "iptables -A INPUT -p tcp --destination-port 23 -j DROP"
        • sh New Fork (PID: 6238, Parent: 6234)
        • iptables (PID: 6238, Parent: 6234, MD5: 1ab05fef765b6342cdfadaa5275b33af) Arguments: iptables -A INPUT -p tcp --destination-port 23 -j DROP
      • .i.elf New Fork (PID: 6246, Parent: 6230)
      • sh (PID: 6246, Parent: 6230, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -c "iptables -A INPUT -p tcp --destination-port 7547 -j DROP"
        • sh New Fork (PID: 6251, Parent: 6246)
        • iptables (PID: 6251, Parent: 6246, MD5: 1ab05fef765b6342cdfadaa5275b33af) Arguments: iptables -A INPUT -p tcp --destination-port 7547 -j DROP
      • .i.elf New Fork (PID: 6252, Parent: 6230)
      • sh (PID: 6252, Parent: 6230, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -c "iptables -A INPUT -p tcp --destination-port 5555 -j DROP"
        • sh New Fork (PID: 6257, Parent: 6252)
        • iptables (PID: 6257, Parent: 6252, MD5: 1ab05fef765b6342cdfadaa5275b33af) Arguments: iptables -A INPUT -p tcp --destination-port 5555 -j DROP
      • .i.elf New Fork (PID: 6258, Parent: 6230)
      • sh (PID: 6258, Parent: 6230, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -c "iptables -A INPUT -p tcp --destination-port 5358 -j DROP"
        • sh New Fork (PID: 6263, Parent: 6258)
        • iptables (PID: 6263, Parent: 6258, MD5: 1ab05fef765b6342cdfadaa5275b33af) Arguments: iptables -A INPUT -p tcp --destination-port 5358 -j DROP
      • .i.elf New Fork (PID: 6264, Parent: 6230)
      • sh (PID: 6264, Parent: 6230, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -c "iptables -D INPUT -j CWMP_CR"
        • sh New Fork (PID: 6269, Parent: 6264)
        • iptables (PID: 6269, Parent: 6264, MD5: 1ab05fef765b6342cdfadaa5275b33af) Arguments: iptables -D INPUT -j CWMP_CR
      • .i.elf New Fork (PID: 6272, Parent: 6230)
      • sh (PID: 6272, Parent: 6230, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -c "iptables -X CWMP_CR"
        • sh New Fork (PID: 6277, Parent: 6272)
        • iptables (PID: 6277, Parent: 6272, MD5: 1ab05fef765b6342cdfadaa5275b33af) Arguments: iptables -X CWMP_CR
      • .i.elf New Fork (PID: 6278, Parent: 6230)
      • sh (PID: 6278, Parent: 6230, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -c "iptables -I INPUT -p udp --dport 27986 -j ACCEPT"
        • sh New Fork (PID: 6283, Parent: 6278)
        • iptables (PID: 6283, Parent: 6278, MD5: 1ab05fef765b6342cdfadaa5275b33af) Arguments: iptables -I INPUT -p udp --dport 27986 -j ACCEPT
  • cleanup
No yara matches
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: .i.elfAvira: detected
Source: .i.elfReversingLabs: Detection: 57%

Spreading

barindex
Source: /tmp/.i.elf (PID: 6228)Opens: /proc/net/routeJump to behavior

Networking

barindex
Source: /bin/sh (PID: 6238)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -A INPUT -p tcp --destination-port 23 -j DROPJump to behavior
Source: /bin/sh (PID: 6251)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -A INPUT -p tcp --destination-port 7547 -j DROPJump to behavior
Source: /bin/sh (PID: 6257)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -A INPUT -p tcp --destination-port 5555 -j DROPJump to behavior
Source: /bin/sh (PID: 6263)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -A INPUT -p tcp --destination-port 5358 -j DROPJump to behavior
Source: /bin/sh (PID: 6269)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -D INPUT -j CWMP_CRJump to behavior
Source: /bin/sh (PID: 6277)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -X CWMP_CRJump to behavior
Source: /bin/sh (PID: 6283)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -I INPUT -p udp --dport 27986 -j ACCEPTJump to behavior
Source: /bin/sh (PID: 6238)Iptables executable: /usr/sbin/iptables -> iptables -A INPUT -p tcp --destination-port 23 -j DROPJump to behavior
Source: /bin/sh (PID: 6251)Iptables executable: /usr/sbin/iptables -> iptables -A INPUT -p tcp --destination-port 7547 -j DROPJump to behavior
Source: /bin/sh (PID: 6257)Iptables executable: /usr/sbin/iptables -> iptables -A INPUT -p tcp --destination-port 5555 -j DROPJump to behavior
Source: /bin/sh (PID: 6263)Iptables executable: /usr/sbin/iptables -> iptables -A INPUT -p tcp --destination-port 5358 -j DROPJump to behavior
Source: /bin/sh (PID: 6269)Iptables executable: /usr/sbin/iptables -> iptables -D INPUT -j CWMP_CRJump to behavior
Source: /bin/sh (PID: 6277)Iptables executable: /usr/sbin/iptables -> iptables -X CWMP_CRJump to behavior
Source: /bin/sh (PID: 6283)Iptables executable: /usr/sbin/iptables -> iptables -I INPUT -p udp --dport 27986 -j ACCEPTJump to behavior
Source: /tmp/.i.elf (PID: 6230)Reads hosts file: /etc/hostsJump to behavior
Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 127.0.0.1
Source: unknownUDP traffic detected without corresponding DNS query: 127.0.0.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 127.0.0.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 127.0.0.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 127.0.0.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 127.0.0.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 127.0.0.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 127.0.0.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficDNS traffic detected: DNS query: router.utorrent.com
Source: global trafficDNS traffic detected: DNS query: router.bittorrent.com
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
Source: LOAD without section mappingsProgram segment: 0x10000
Source: classification engineClassification label: mal68.spre.evad.linELF@0/1@56/0

Persistence and Installation Behavior

barindex
Source: /bin/sh (PID: 6238)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -A INPUT -p tcp --destination-port 23 -j DROPJump to behavior
Source: /bin/sh (PID: 6251)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -A INPUT -p tcp --destination-port 7547 -j DROPJump to behavior
Source: /bin/sh (PID: 6257)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -A INPUT -p tcp --destination-port 5555 -j DROPJump to behavior
Source: /bin/sh (PID: 6263)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -A INPUT -p tcp --destination-port 5358 -j DROPJump to behavior
Source: /bin/sh (PID: 6269)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -D INPUT -j CWMP_CRJump to behavior
Source: /bin/sh (PID: 6277)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -X CWMP_CRJump to behavior
Source: /bin/sh (PID: 6283)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -I INPUT -p udp --dport 27986 -j ACCEPTJump to behavior
Source: /tmp/.i.elf (PID: 6230)Directory: /tmp/.pJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/6230/fdJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/1582/cmdlineJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/1582/fdJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/3088/cmdlineJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/230/cmdlineJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/231/cmdlineJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/110/cmdlineJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/1579/cmdlineJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/1579/fdJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/232/cmdlineJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/111/cmdlineJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/1699/cmdlineJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/1699/fdJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/233/cmdlineJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/112/cmdlineJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/1698/cmdlineJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/1698/fdJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/1335/cmdlineJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/1335/fdJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/234/cmdlineJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/113/cmdlineJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/2302/cmdlineJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/2302/fdJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/1576/cmdlineJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/1576/fdJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/1334/cmdlineJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/1334/fdJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/235/cmdlineJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/114/cmdlineJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/236/cmdlineJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/115/cmdlineJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/237/cmdlineJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/116/cmdlineJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/117/cmdlineJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/910/cmdlineJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/118/cmdlineJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/119/cmdlineJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/912/cmdlineJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/912/fdJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/2307/cmdlineJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/2307/fdJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/10/cmdlineJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/918/cmdlineJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/918/fdJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/11/cmdlineJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/12/cmdlineJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/13/cmdlineJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/14/cmdlineJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/15/cmdlineJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/16/cmdlineJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/17/cmdlineJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/18/cmdlineJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/1594/cmdlineJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/1594/fdJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/120/cmdlineJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/1349/cmdlineJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/1349/fdJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/121/cmdlineJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/243/cmdlineJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/122/cmdlineJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/1/cmdlineJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/1/fdJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/123/cmdlineJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/2/cmdlineJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/124/cmdlineJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/3/cmdlineJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/125/cmdlineJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/4/cmdlineJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/1586/cmdlineJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/1586/fdJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/1465/cmdlineJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/1465/fdJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/1344/cmdlineJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/1344/fdJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/126/cmdlineJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/248/cmdlineJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/127/cmdlineJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/6/cmdlineJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/1463/cmdlineJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/1463/fdJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/249/cmdlineJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/128/cmdlineJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/800/cmdlineJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/800/fdJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/801/cmdlineJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/801/fdJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/9/cmdlineJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/20/cmdlineJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/1900/cmdlineJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/1900/fdJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/21/cmdlineJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/22/cmdlineJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/23/cmdlineJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/24/cmdlineJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/25/cmdlineJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/26/cmdlineJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/27/cmdlineJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/6137/cmdlineJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/28/cmdlineJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/29/cmdlineJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/491/cmdlineJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/491/fdJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/250/cmdlineJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/251/cmdlineJump to behavior
Source: /tmp/.i.elf (PID: 6230)File opened: /proc/130/cmdlineJump to behavior
Source: /tmp/.i.elf (PID: 6234)Shell command executed: /bin/sh -c "iptables -A INPUT -p tcp --destination-port 23 -j DROP"Jump to behavior
Source: /tmp/.i.elf (PID: 6246)Shell command executed: /bin/sh -c "iptables -A INPUT -p tcp --destination-port 7547 -j DROP"Jump to behavior
Source: /tmp/.i.elf (PID: 6252)Shell command executed: /bin/sh -c "iptables -A INPUT -p tcp --destination-port 5555 -j DROP"Jump to behavior
Source: /tmp/.i.elf (PID: 6258)Shell command executed: /bin/sh -c "iptables -A INPUT -p tcp --destination-port 5358 -j DROP"Jump to behavior
Source: /tmp/.i.elf (PID: 6264)Shell command executed: /bin/sh -c "iptables -D INPUT -j CWMP_CR"Jump to behavior
Source: /tmp/.i.elf (PID: 6272)Shell command executed: /bin/sh -c "iptables -X CWMP_CR"Jump to behavior
Source: /tmp/.i.elf (PID: 6278)Shell command executed: /bin/sh -c "iptables -I INPUT -p udp --dport 27986 -j ACCEPT"Jump to behavior
Source: /bin/sh (PID: 6238)Iptables executable: /usr/sbin/iptables -> iptables -A INPUT -p tcp --destination-port 23 -j DROPJump to behavior
Source: /bin/sh (PID: 6251)Iptables executable: /usr/sbin/iptables -> iptables -A INPUT -p tcp --destination-port 7547 -j DROPJump to behavior
Source: /bin/sh (PID: 6257)Iptables executable: /usr/sbin/iptables -> iptables -A INPUT -p tcp --destination-port 5555 -j DROPJump to behavior
Source: /bin/sh (PID: 6263)Iptables executable: /usr/sbin/iptables -> iptables -A INPUT -p tcp --destination-port 5358 -j DROPJump to behavior
Source: /bin/sh (PID: 6269)Iptables executable: /usr/sbin/iptables -> iptables -D INPUT -j CWMP_CRJump to behavior
Source: /bin/sh (PID: 6277)Iptables executable: /usr/sbin/iptables -> iptables -X CWMP_CRJump to behavior
Source: /bin/sh (PID: 6283)Iptables executable: /usr/sbin/iptables -> iptables -I INPUT -p udp --dport 27986 -j ACCEPTJump to behavior
Source: submitted sampleStderr: iptables v1.8.4 (legacy): Couldn't load target `CWMP_CR':No such file or directoryTry `iptables -h' or 'iptables --help' for more information.iptables: No chain/target/match by that name.: exit code = 0

Hooking and other Techniques for Hiding and Protection

barindex
Source: /tmp/.i.elf (PID: 6230)File: /tmp/.i.elfJump to behavior
Source: .i.elfSubmission file: segment LOAD with 7.9915 entropy (max. 8.0)
Source: /tmp/.i.elf (PID: 6228)Queries kernel information via 'uname': Jump to behavior
Source: /tmp/.i.elf (PID: 6230)Queries kernel information via 'uname': Jump to behavior
Source: .i.elf, 6228.1.000055e983883000.000055e983a11000.rw-.sdmpBinary or memory string: U!/etc/qemu-binfmt/arm
Source: .i.elf, 6228.1.00007ffd8673b000.00007ffd8675c000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-arm/tmp/.i.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/.i.elf
Source: .i.elf, 6228.1.000055e983883000.000055e983a11000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/arm
Source: .i.elf, 6228.1.00007ffd8673b000.00007ffd8675c000.rw-.sdmpBinary or memory string: /usr/bin/qemu-arm
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity Information1
Scripting
Valid AccountsWindows Management Instrumentation1
Scripting
Path Interception1
Hidden Files and Directories
1
OS Credential Dumping
11
Security Software Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Obfuscated Files or Information
LSASS Memory1
File and Directory Discovery
Remote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
File Deletion
Security Account Manager1
Remote System Discovery
SMB/Windows Admin SharesData from Network Shared Drive2
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDS1
System Network Configuration Discovery
Distributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1561769 Sample: .i.elf Startdate: 24/11/2024 Architecture: LINUX Score: 68 38 109.202.202.202, 80 INIT7CH Switzerland 2->38 40 91.189.91.42, 443 CANONICAL-ASGB United Kingdom 2->40 42 3 other IPs or domains 2->42 44 Antivirus / Scanner detection for submitted sample 2->44 46 Multi AV Scanner detection for submitted file 2->46 9 .i.elf 2->9         started        signatures3 process4 signatures5 50 Opens /proc/net/* files useful for finding connected devices and routers 9->50 12 .i.elf 9->12         started        process6 signatures7 52 Sample deletes itself 12->52 15 .i.elf sh 12->15         started        17 .i.elf sh 12->17         started        19 .i.elf sh 12->19         started        21 4 other processes 12->21 process8 process9 23 sh iptables 15->23         started        26 sh iptables 17->26         started        28 sh iptables 19->28         started        30 sh iptables 21->30         started        32 sh iptables 21->32         started        34 sh iptables 21->34         started        36 sh iptables 21->36         started        signatures10 48 Executes the "iptables" command to insert, remove and/or manipulate rules 23->48
SourceDetectionScannerLabelLink
.i.elf58%ReversingLabsLinux.Infostealer.Berbew
.i.elf100%AviraEXP/ELF.Agent.H.2
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
router.bittorrent.com
unknown
unknownfalse
    high
    router.utorrent.com
    unknown
    unknownfalse
      high
      • No. of IPs < 25%
      • 25% < No. of IPs < 50%
      • 50% < No. of IPs < 75%
      • 75% < No. of IPs
      IPDomainCountryFlagASNASN NameMalicious
      109.202.202.202
      unknownSwitzerland
      13030INIT7CHfalse
      91.189.91.43
      unknownUnited Kingdom
      41231CANONICAL-ASGBfalse
      91.189.91.42
      unknownUnited Kingdom
      41231CANONICAL-ASGBfalse
      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
      109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
      • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
      91.189.91.43arm6.nn.elfGet hashmaliciousMirai, OkiruBrowse
        .i.elfGet hashmaliciousUnknownBrowse
          m68k.nn.elfGet hashmaliciousMirai, OkiruBrowse
            arm6.nn.elfGet hashmaliciousMirai, OkiruBrowse
              .i.elfGet hashmaliciousUnknownBrowse
                arm6.nn.elfGet hashmaliciousMirai, OkiruBrowse
                  .i.elfGet hashmaliciousUnknownBrowse
                    sshd.elfGet hashmaliciousUnknownBrowse
                      sshd.elfGet hashmaliciousUnknownBrowse
                        Mozi.m.elfGet hashmaliciousUnknownBrowse
                          91.189.91.42arm6.nn.elfGet hashmaliciousMirai, OkiruBrowse
                            .i.elfGet hashmaliciousUnknownBrowse
                              m68k.nn.elfGet hashmaliciousMirai, OkiruBrowse
                                arm6.nn.elfGet hashmaliciousMirai, OkiruBrowse
                                  .i.elfGet hashmaliciousUnknownBrowse
                                    arm6.nn.elfGet hashmaliciousMirai, OkiruBrowse
                                      .i.elfGet hashmaliciousUnknownBrowse
                                        sshd.elfGet hashmaliciousUnknownBrowse
                                          sshd.elfGet hashmaliciousUnknownBrowse
                                            Mozi.m.elfGet hashmaliciousUnknownBrowse
                                              No context
                                              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                              CANONICAL-ASGBarm6.nn.elfGet hashmaliciousMirai, OkiruBrowse
                                              • 91.189.91.42
                                              .i.elfGet hashmaliciousUnknownBrowse
                                              • 91.189.91.42
                                              m68k.nn.elfGet hashmaliciousMirai, OkiruBrowse
                                              • 91.189.91.42
                                              arm6.nn.elfGet hashmaliciousMirai, OkiruBrowse
                                              • 91.189.91.42
                                              .i.elfGet hashmaliciousUnknownBrowse
                                              • 91.189.91.42
                                              arm6.nn.elfGet hashmaliciousMirai, OkiruBrowse
                                              • 91.189.91.42
                                              .i.elfGet hashmaliciousUnknownBrowse
                                              • 91.189.91.42
                                              sshd.elfGet hashmaliciousUnknownBrowse
                                              • 91.189.91.42
                                              sshd.elfGet hashmaliciousUnknownBrowse
                                              • 91.189.91.42
                                              Mozi.m.elfGet hashmaliciousUnknownBrowse
                                              • 91.189.91.42
                                              CANONICAL-ASGBarm6.nn.elfGet hashmaliciousMirai, OkiruBrowse
                                              • 91.189.91.42
                                              .i.elfGet hashmaliciousUnknownBrowse
                                              • 91.189.91.42
                                              m68k.nn.elfGet hashmaliciousMirai, OkiruBrowse
                                              • 91.189.91.42
                                              arm6.nn.elfGet hashmaliciousMirai, OkiruBrowse
                                              • 91.189.91.42
                                              .i.elfGet hashmaliciousUnknownBrowse
                                              • 91.189.91.42
                                              arm6.nn.elfGet hashmaliciousMirai, OkiruBrowse
                                              • 91.189.91.42
                                              .i.elfGet hashmaliciousUnknownBrowse
                                              • 91.189.91.42
                                              sshd.elfGet hashmaliciousUnknownBrowse
                                              • 91.189.91.42
                                              sshd.elfGet hashmaliciousUnknownBrowse
                                              • 91.189.91.42
                                              Mozi.m.elfGet hashmaliciousUnknownBrowse
                                              • 91.189.91.42
                                              INIT7CHarm6.nn.elfGet hashmaliciousMirai, OkiruBrowse
                                              • 109.202.202.202
                                              .i.elfGet hashmaliciousUnknownBrowse
                                              • 109.202.202.202
                                              m68k.nn.elfGet hashmaliciousMirai, OkiruBrowse
                                              • 109.202.202.202
                                              arm6.nn.elfGet hashmaliciousMirai, OkiruBrowse
                                              • 109.202.202.202
                                              .i.elfGet hashmaliciousUnknownBrowse
                                              • 109.202.202.202
                                              arm6.nn.elfGet hashmaliciousMirai, OkiruBrowse
                                              • 109.202.202.202
                                              .i.elfGet hashmaliciousUnknownBrowse
                                              • 109.202.202.202
                                              sshd.elfGet hashmaliciousUnknownBrowse
                                              • 109.202.202.202
                                              sshd.elfGet hashmaliciousUnknownBrowse
                                              • 109.202.202.202
                                              Mozi.m.elfGet hashmaliciousUnknownBrowse
                                              • 109.202.202.202
                                              No context
                                              No context
                                              Process:/tmp/.i.elf
                                              File Type:data
                                              Category:dropped
                                              Size (bytes):12
                                              Entropy (8bit):3.2516291673878226
                                              Encrypted:false
                                              SSDEEP:3:TgLxl:TgLj
                                              MD5:E4B87097E4B36E14500B9CE57C45EA25
                                              SHA1:DE3D58C12CA45D58E41455D0B693AF835D7F7361
                                              SHA-256:7AD8A46FA4EADA251D0628721EEA0DE6EA917EC6B820146172179FFA68FC44A8
                                              SHA-512:53CD8469E5F84281D446318E05BBA7B4A0D93FBF7567B663E875E9BBE95453E83E1C233140DBEBFC50C64F981CF1C007A1A573C508AE676BBE78F07C38DA4D43
                                              Malicious:false
                                              Reputation:low
                                              Preview:/tmp/.i.elf.
                                              File type:ELF 32-bit LSB executable, ARM, EABI5 version 1 (GNU/Linux), statically linked, no section header
                                              Entropy (8bit):7.990822940503946
                                              TrID:
                                              • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                              File name:.i.elf
                                              File size:80'280 bytes
                                              MD5:e5940168886f77e0511035238d976b0a
                                              SHA1:ebe648b8cbd999844e725915e00aad00011a9f4c
                                              SHA256:c92d81d7adca77fda2be2826610ac3fbd0d35bfc917534397dd8660621a2b471
                                              SHA512:a5631261114adfb213db5009a11dd1254030b4045151922c3ff029eac0ee7cc14b1a83c2343d99e43cb90267e1a1604b15da950180a02f6302e387986d96dc31
                                              SSDEEP:1536:87vbq1lGAXSEYQjbChaAU2yU23M51DjZgSQAvcYkFtZTjzBhta:8D+CAXFYQChaAUk5ljnQsso
                                              TLSH:A47312E017B517CC1371A8353BED205E9128223972AE35302E97529DF957703BAB2DBE
                                              File Content Preview:.ELF..............(......'..4...........4. ...(......................7...7.............................................c........................i..........?.E.h;....#..$..O.%.......y.A.U"......-R..e....<l>=).!...O........u.....`o..*ziy"......R..~@....x2'_

                                              ELF header

                                              Class:ELF32
                                              Data:2's complement, little endian
                                              Version:1 (current)
                                              Machine:ARM
                                              Version Number:0x1
                                              Type:EXEC (Executable file)
                                              OS/ABI:UNIX - Linux
                                              ABI Version:0
                                              Entry Point Address:0x22718
                                              Flags:0x5000202
                                              ELF Header Size:52
                                              Program Header Offset:52
                                              Program Header Size:32
                                              Number of Program Headers:2
                                              Section Header Offset:0
                                              Section Header Size:40
                                              Number of Section Headers:0
                                              Header String Table Index:0
                                              TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                              LOAD0x00x100000x100000x137e90x137e97.99150x5R E0x10000
                                              LOAD0x6fc0x506fc0x506fc0x00x00.00000x6RW 0x10000
                                              TimestampSource PortDest PortSource IPDest IP
                                              Nov 24, 2024 08:52:50.653232098 CET43928443192.168.2.2391.189.91.42
                                              Nov 24, 2024 08:52:56.028537035 CET42836443192.168.2.2391.189.91.43
                                              Nov 24, 2024 08:52:57.564409018 CET4251680192.168.2.23109.202.202.202
                                              Nov 24, 2024 08:53:10.618479013 CET43928443192.168.2.2391.189.91.42
                                              Nov 24, 2024 08:53:22.904737949 CET42836443192.168.2.2391.189.91.43
                                              Nov 24, 2024 08:53:27.000439882 CET4251680192.168.2.23109.202.202.202
                                              Nov 24, 2024 08:53:51.572845936 CET43928443192.168.2.2391.189.91.42
                                              TimestampSource PortDest PortSource IPDest IP
                                              Nov 24, 2024 08:52:55.098813057 CET6013253192.168.2.231.1.1.1
                                              Nov 24, 2024 08:53:00.104518890 CET5445753192.168.2.238.8.8.8
                                              Nov 24, 2024 08:53:05.110275030 CET3405953192.168.2.231.1.1.1
                                              Nov 24, 2024 08:53:10.116158962 CET5683353192.168.2.23127.0.0.1
                                              Nov 24, 2024 08:53:10.262237072 CET5310353192.168.2.238.8.8.8
                                              Nov 24, 2024 08:53:15.118984938 CET4980853192.168.2.23127.0.0.1
                                              Nov 24, 2024 08:53:15.511490107 CET3788853192.168.2.231.1.1.1
                                              Nov 24, 2024 08:53:20.126302004 CET5342453192.168.2.231.1.1.1
                                              Nov 24, 2024 08:53:20.760999918 CET4435053192.168.2.238.8.8.8
                                              Nov 24, 2024 08:53:25.131931067 CET5342453192.168.2.231.1.1.1
                                              Nov 24, 2024 08:53:26.009937048 CET4435053192.168.2.238.8.8.8
                                              Nov 24, 2024 08:53:30.138047934 CET5342453192.168.2.231.1.1.1
                                              Nov 24, 2024 08:53:31.259346962 CET4435053192.168.2.238.8.8.8
                                              Nov 24, 2024 08:53:35.143995047 CET3403753192.168.2.23127.0.0.1
                                              Nov 24, 2024 08:53:35.258744001 CET5342453192.168.2.231.1.1.1
                                              Nov 24, 2024 08:53:36.508508921 CET4435053192.168.2.238.8.8.8
                                              Nov 24, 2024 08:53:40.150048018 CET5722453192.168.2.23127.0.0.1
                                              Nov 24, 2024 08:53:40.508169889 CET5342453192.168.2.231.1.1.1
                                              Nov 24, 2024 08:53:41.757905006 CET4435053192.168.2.238.8.8.8
                                              Nov 24, 2024 08:53:45.757328987 CET5342453192.168.2.231.1.1.1
                                              Nov 24, 2024 08:53:47.007160902 CET4435053192.168.2.238.8.8.8
                                              Nov 24, 2024 08:53:51.006668091 CET5342453192.168.2.231.1.1.1
                                              Nov 24, 2024 08:53:52.256515980 CET4435053192.168.2.238.8.8.8
                                              Nov 24, 2024 08:53:56.255920887 CET5342453192.168.2.231.1.1.1
                                              Nov 24, 2024 08:53:57.505773067 CET4435053192.168.2.238.8.8.8
                                              Nov 24, 2024 08:54:01.505081892 CET5342453192.168.2.231.1.1.1
                                              Nov 24, 2024 08:54:02.754970074 CET4435053192.168.2.238.8.8.8
                                              Nov 24, 2024 08:54:03.689847946 CET5676053192.168.2.23127.0.0.1
                                              Nov 24, 2024 08:54:06.754405975 CET5342453192.168.2.231.1.1.1
                                              Nov 24, 2024 08:54:08.004162073 CET4435053192.168.2.238.8.8.8
                                              Nov 24, 2024 08:54:08.695938110 CET4459953192.168.2.23127.0.0.1
                                              Nov 24, 2024 08:54:12.003628016 CET5342453192.168.2.231.1.1.1
                                              Nov 24, 2024 08:54:13.253508091 CET4435053192.168.2.238.8.8.8
                                              Nov 24, 2024 08:54:17.252886057 CET5342453192.168.2.231.1.1.1
                                              Nov 24, 2024 08:54:18.502697945 CET4435053192.168.2.238.8.8.8
                                              Nov 24, 2024 08:54:22.502188921 CET5342453192.168.2.231.1.1.1
                                              Nov 24, 2024 08:54:23.715500116 CET4435053192.168.2.238.8.8.8
                                              Nov 24, 2024 08:54:27.751661062 CET5342453192.168.2.231.1.1.1
                                              Nov 24, 2024 08:54:28.720730066 CET5682153192.168.2.23127.0.0.1
                                              Nov 24, 2024 08:54:28.751303911 CET4435053192.168.2.238.8.8.8
                                              Nov 24, 2024 08:54:33.000777006 CET5342453192.168.2.231.1.1.1
                                              Nov 24, 2024 08:54:33.726414919 CET3584453192.168.2.23127.0.0.1
                                              Nov 24, 2024 08:54:34.000637054 CET4435053192.168.2.238.8.8.8
                                              Nov 24, 2024 08:54:38.250138044 CET5342453192.168.2.231.1.1.1
                                              Nov 24, 2024 08:54:39.249844074 CET4435053192.168.2.238.8.8.8
                                              Nov 24, 2024 08:54:43.499247074 CET5342453192.168.2.231.1.1.1
                                              Nov 24, 2024 08:54:44.499090910 CET4435053192.168.2.238.8.8.8
                                              Nov 24, 2024 08:54:48.748518944 CET5342453192.168.2.231.1.1.1
                                              Nov 24, 2024 08:54:49.748399973 CET4435053192.168.2.238.8.8.8
                                              Nov 24, 2024 08:54:53.997936964 CET5342453192.168.2.231.1.1.1
                                              Nov 24, 2024 08:54:54.997869015 CET4435053192.168.2.238.8.8.8
                                              Nov 24, 2024 08:54:59.247051954 CET5342453192.168.2.231.1.1.1
                                              Nov 24, 2024 08:55:04.496413946 CET5342453192.168.2.231.1.1.1
                                              Nov 24, 2024 08:55:09.745681047 CET3549253192.168.2.238.8.8.8
                                              Nov 24, 2024 08:55:14.995167971 CET3882153192.168.2.231.1.1.1
                                              Nov 24, 2024 08:55:20.244345903 CET3526753192.168.2.238.8.8.8
                                              TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                              Nov 24, 2024 08:52:55.098813057 CET192.168.2.231.1.1.10x613fStandard query (0)router.utorrent.comA (IP address)IN (0x0001)false
                                              Nov 24, 2024 08:53:00.104518890 CET192.168.2.238.8.8.80x613fStandard query (0)router.utorrent.comA (IP address)IN (0x0001)false
                                              Nov 24, 2024 08:53:05.110275030 CET192.168.2.231.1.1.10x613fStandard query (0)router.utorrent.comA (IP address)IN (0x0001)false
                                              Nov 24, 2024 08:53:10.116158962 CET192.168.2.23127.0.0.10x335cStandard query (0)router.utorrent.comA (IP address)IN (0x0001)false
                                              Nov 24, 2024 08:53:10.262237072 CET192.168.2.238.8.8.80x613fStandard query (0)router.utorrent.comA (IP address)IN (0x0001)false
                                              Nov 24, 2024 08:53:15.118984938 CET192.168.2.23127.0.0.10x335cStandard query (0)router.utorrent.comA (IP address)IN (0x0001)false
                                              Nov 24, 2024 08:53:15.511490107 CET192.168.2.231.1.1.10x613fStandard query (0)router.utorrent.comA (IP address)IN (0x0001)false
                                              Nov 24, 2024 08:53:20.126302004 CET192.168.2.231.1.1.10x8d3bStandard query (0)router.bittorrent.comA (IP address)IN (0x0001)false
                                              Nov 24, 2024 08:53:20.760999918 CET192.168.2.238.8.8.80x613fStandard query (0)router.utorrent.comA (IP address)IN (0x0001)false
                                              Nov 24, 2024 08:53:25.131931067 CET192.168.2.231.1.1.10x8d3bStandard query (0)router.bittorrent.comA (IP address)IN (0x0001)false
                                              Nov 24, 2024 08:53:26.009937048 CET192.168.2.238.8.8.80x613fStandard query (0)router.utorrent.comA (IP address)IN (0x0001)false
                                              Nov 24, 2024 08:53:30.138047934 CET192.168.2.231.1.1.10x8d3bStandard query (0)router.bittorrent.comA (IP address)IN (0x0001)false
                                              Nov 24, 2024 08:53:31.259346962 CET192.168.2.238.8.8.80x613fStandard query (0)router.utorrent.comA (IP address)IN (0x0001)false
                                              Nov 24, 2024 08:53:35.143995047 CET192.168.2.23127.0.0.10xb9b9Standard query (0)router.bittorrent.comA (IP address)IN (0x0001)false
                                              Nov 24, 2024 08:53:35.258744001 CET192.168.2.231.1.1.10x8d3bStandard query (0)router.bittorrent.comA (IP address)IN (0x0001)false
                                              Nov 24, 2024 08:53:36.508508921 CET192.168.2.238.8.8.80x613fStandard query (0)router.utorrent.comA (IP address)IN (0x0001)false
                                              Nov 24, 2024 08:53:40.150048018 CET192.168.2.23127.0.0.10xb9b9Standard query (0)router.bittorrent.comA (IP address)IN (0x0001)false
                                              Nov 24, 2024 08:53:40.508169889 CET192.168.2.231.1.1.10x8d3bStandard query (0)router.bittorrent.comA (IP address)IN (0x0001)false
                                              Nov 24, 2024 08:53:41.757905006 CET192.168.2.238.8.8.80x613fStandard query (0)router.utorrent.comA (IP address)IN (0x0001)false
                                              Nov 24, 2024 08:53:45.757328987 CET192.168.2.231.1.1.10x8d3bStandard query (0)router.bittorrent.comA (IP address)IN (0x0001)false
                                              Nov 24, 2024 08:53:47.007160902 CET192.168.2.238.8.8.80x613fStandard query (0)router.utorrent.comA (IP address)IN (0x0001)false
                                              Nov 24, 2024 08:53:51.006668091 CET192.168.2.231.1.1.10x8d3bStandard query (0)router.bittorrent.comA (IP address)IN (0x0001)false
                                              Nov 24, 2024 08:53:52.256515980 CET192.168.2.238.8.8.80x613fStandard query (0)router.utorrent.comA (IP address)IN (0x0001)false
                                              Nov 24, 2024 08:53:56.255920887 CET192.168.2.231.1.1.10x8d3bStandard query (0)router.bittorrent.comA (IP address)IN (0x0001)false
                                              Nov 24, 2024 08:53:57.505773067 CET192.168.2.238.8.8.80x613fStandard query (0)router.utorrent.comA (IP address)IN (0x0001)false
                                              Nov 24, 2024 08:54:01.505081892 CET192.168.2.231.1.1.10x8d3bStandard query (0)router.bittorrent.comA (IP address)IN (0x0001)false
                                              Nov 24, 2024 08:54:02.754970074 CET192.168.2.238.8.8.80x613fStandard query (0)router.utorrent.comA (IP address)IN (0x0001)false
                                              Nov 24, 2024 08:54:03.689847946 CET192.168.2.23127.0.0.10x5d21Standard query (0)router.utorrent.comA (IP address)IN (0x0001)false
                                              Nov 24, 2024 08:54:06.754405975 CET192.168.2.231.1.1.10x8d3bStandard query (0)router.bittorrent.comA (IP address)IN (0x0001)false
                                              Nov 24, 2024 08:54:08.004162073 CET192.168.2.238.8.8.80x613fStandard query (0)router.utorrent.comA (IP address)IN (0x0001)false
                                              Nov 24, 2024 08:54:08.695938110 CET192.168.2.23127.0.0.10x5d21Standard query (0)router.utorrent.comA (IP address)IN (0x0001)false
                                              Nov 24, 2024 08:54:12.003628016 CET192.168.2.231.1.1.10x8d3bStandard query (0)router.bittorrent.comA (IP address)IN (0x0001)false
                                              Nov 24, 2024 08:54:13.253508091 CET192.168.2.238.8.8.80x613fStandard query (0)router.utorrent.comA (IP address)IN (0x0001)false
                                              Nov 24, 2024 08:54:17.252886057 CET192.168.2.231.1.1.10x8d3bStandard query (0)router.bittorrent.comA (IP address)IN (0x0001)false
                                              Nov 24, 2024 08:54:18.502697945 CET192.168.2.238.8.8.80x613fStandard query (0)router.utorrent.comA (IP address)IN (0x0001)false
                                              Nov 24, 2024 08:54:22.502188921 CET192.168.2.231.1.1.10x8d3bStandard query (0)router.bittorrent.comA (IP address)IN (0x0001)false
                                              Nov 24, 2024 08:54:23.715500116 CET192.168.2.238.8.8.80x613fStandard query (0)router.utorrent.comA (IP address)IN (0x0001)false
                                              Nov 24, 2024 08:54:27.751661062 CET192.168.2.231.1.1.10x8d3bStandard query (0)router.bittorrent.comA (IP address)IN (0x0001)false
                                              Nov 24, 2024 08:54:28.720730066 CET192.168.2.23127.0.0.10xff0fStandard query (0)router.bittorrent.comA (IP address)IN (0x0001)false
                                              Nov 24, 2024 08:54:28.751303911 CET192.168.2.238.8.8.80x613fStandard query (0)router.utorrent.comA (IP address)IN (0x0001)false
                                              Nov 24, 2024 08:54:33.000777006 CET192.168.2.231.1.1.10x8d3bStandard query (0)router.bittorrent.comA (IP address)IN (0x0001)false
                                              Nov 24, 2024 08:54:33.726414919 CET192.168.2.23127.0.0.10xff0fStandard query (0)router.bittorrent.comA (IP address)IN (0x0001)false
                                              Nov 24, 2024 08:54:34.000637054 CET192.168.2.238.8.8.80x613fStandard query (0)router.utorrent.comA (IP address)IN (0x0001)false
                                              Nov 24, 2024 08:54:38.250138044 CET192.168.2.231.1.1.10x8d3bStandard query (0)router.bittorrent.comA (IP address)IN (0x0001)false
                                              Nov 24, 2024 08:54:39.249844074 CET192.168.2.238.8.8.80x613fStandard query (0)router.utorrent.comA (IP address)IN (0x0001)false
                                              Nov 24, 2024 08:54:43.499247074 CET192.168.2.231.1.1.10x8d3bStandard query (0)router.bittorrent.comA (IP address)IN (0x0001)false
                                              Nov 24, 2024 08:54:44.499090910 CET192.168.2.238.8.8.80x613fStandard query (0)router.utorrent.comA (IP address)IN (0x0001)false
                                              Nov 24, 2024 08:54:48.748518944 CET192.168.2.231.1.1.10x8d3bStandard query (0)router.bittorrent.comA (IP address)IN (0x0001)false
                                              Nov 24, 2024 08:54:49.748399973 CET192.168.2.238.8.8.80x613fStandard query (0)router.utorrent.comA (IP address)IN (0x0001)false
                                              Nov 24, 2024 08:54:53.997936964 CET192.168.2.231.1.1.10x8d3bStandard query (0)router.bittorrent.comA (IP address)IN (0x0001)false
                                              Nov 24, 2024 08:54:54.997869015 CET192.168.2.238.8.8.80x613fStandard query (0)router.utorrent.comA (IP address)IN (0x0001)false
                                              Nov 24, 2024 08:54:59.247051954 CET192.168.2.231.1.1.10x8d3bStandard query (0)router.bittorrent.comA (IP address)IN (0x0001)false
                                              Nov 24, 2024 08:55:04.496413946 CET192.168.2.231.1.1.10x8d3bStandard query (0)router.bittorrent.comA (IP address)IN (0x0001)false
                                              Nov 24, 2024 08:55:09.745681047 CET192.168.2.238.8.8.80x8d3bStandard query (0)router.bittorrent.comA (IP address)IN (0x0001)false
                                              Nov 24, 2024 08:55:14.995167971 CET192.168.2.231.1.1.10x8d3bStandard query (0)router.bittorrent.comA (IP address)IN (0x0001)false
                                              Nov 24, 2024 08:55:20.244345903 CET192.168.2.238.8.8.80x8d3bStandard query (0)router.bittorrent.comA (IP address)IN (0x0001)false

                                              System Behavior

                                              Start time (UTC):07:52:48
                                              Start date (UTC):24/11/2024
                                              Path:/tmp/.i.elf
                                              Arguments:/tmp/.i.elf
                                              File size:4956856 bytes
                                              MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                              Start time (UTC):07:52:48
                                              Start date (UTC):24/11/2024
                                              Path:/tmp/.i.elf
                                              Arguments:-
                                              File size:4956856 bytes
                                              MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                              Start time (UTC):07:52:53
                                              Start date (UTC):24/11/2024
                                              Path:/tmp/.i.elf
                                              Arguments:-
                                              File size:4956856 bytes
                                              MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                              Start time (UTC):07:52:53
                                              Start date (UTC):24/11/2024
                                              Path:/bin/sh
                                              Arguments:/bin/sh -c "iptables -A INPUT -p tcp --destination-port 23 -j DROP"
                                              File size:129816 bytes
                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                              Start time (UTC):07:52:53
                                              Start date (UTC):24/11/2024
                                              Path:/bin/sh
                                              Arguments:-
                                              File size:129816 bytes
                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                              Start time (UTC):07:52:53
                                              Start date (UTC):24/11/2024
                                              Path:/usr/sbin/iptables
                                              Arguments:iptables -A INPUT -p tcp --destination-port 23 -j DROP
                                              File size:99296 bytes
                                              MD5 hash:1ab05fef765b6342cdfadaa5275b33af

                                              Start time (UTC):07:52:53
                                              Start date (UTC):24/11/2024
                                              Path:/tmp/.i.elf
                                              Arguments:-
                                              File size:4956856 bytes
                                              MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                              Start time (UTC):07:52:53
                                              Start date (UTC):24/11/2024
                                              Path:/bin/sh
                                              Arguments:/bin/sh -c "iptables -A INPUT -p tcp --destination-port 7547 -j DROP"
                                              File size:129816 bytes
                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                              Start time (UTC):07:52:53
                                              Start date (UTC):24/11/2024
                                              Path:/bin/sh
                                              Arguments:-
                                              File size:129816 bytes
                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                              Start time (UTC):07:52:53
                                              Start date (UTC):24/11/2024
                                              Path:/usr/sbin/iptables
                                              Arguments:iptables -A INPUT -p tcp --destination-port 7547 -j DROP
                                              File size:99296 bytes
                                              MD5 hash:1ab05fef765b6342cdfadaa5275b33af

                                              Start time (UTC):07:52:53
                                              Start date (UTC):24/11/2024
                                              Path:/tmp/.i.elf
                                              Arguments:-
                                              File size:4956856 bytes
                                              MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                              Start time (UTC):07:52:53
                                              Start date (UTC):24/11/2024
                                              Path:/bin/sh
                                              Arguments:/bin/sh -c "iptables -A INPUT -p tcp --destination-port 5555 -j DROP"
                                              File size:129816 bytes
                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                              Start time (UTC):07:52:53
                                              Start date (UTC):24/11/2024
                                              Path:/bin/sh
                                              Arguments:-
                                              File size:129816 bytes
                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                              Start time (UTC):07:52:53
                                              Start date (UTC):24/11/2024
                                              Path:/usr/sbin/iptables
                                              Arguments:iptables -A INPUT -p tcp --destination-port 5555 -j DROP
                                              File size:99296 bytes
                                              MD5 hash:1ab05fef765b6342cdfadaa5275b33af

                                              Start time (UTC):07:52:53
                                              Start date (UTC):24/11/2024
                                              Path:/tmp/.i.elf
                                              Arguments:-
                                              File size:4956856 bytes
                                              MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                              Start time (UTC):07:52:53
                                              Start date (UTC):24/11/2024
                                              Path:/bin/sh
                                              Arguments:/bin/sh -c "iptables -A INPUT -p tcp --destination-port 5358 -j DROP"
                                              File size:129816 bytes
                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                              Start time (UTC):07:52:53
                                              Start date (UTC):24/11/2024
                                              Path:/bin/sh
                                              Arguments:-
                                              File size:129816 bytes
                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                              Start time (UTC):07:52:53
                                              Start date (UTC):24/11/2024
                                              Path:/usr/sbin/iptables
                                              Arguments:iptables -A INPUT -p tcp --destination-port 5358 -j DROP
                                              File size:99296 bytes
                                              MD5 hash:1ab05fef765b6342cdfadaa5275b33af

                                              Start time (UTC):07:52:54
                                              Start date (UTC):24/11/2024
                                              Path:/tmp/.i.elf
                                              Arguments:-
                                              File size:4956856 bytes
                                              MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                              Start time (UTC):07:52:54
                                              Start date (UTC):24/11/2024
                                              Path:/bin/sh
                                              Arguments:/bin/sh -c "iptables -D INPUT -j CWMP_CR"
                                              File size:129816 bytes
                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                              Start time (UTC):07:52:54
                                              Start date (UTC):24/11/2024
                                              Path:/bin/sh
                                              Arguments:-
                                              File size:129816 bytes
                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                              Start time (UTC):07:52:54
                                              Start date (UTC):24/11/2024
                                              Path:/usr/sbin/iptables
                                              Arguments:iptables -D INPUT -j CWMP_CR
                                              File size:99296 bytes
                                              MD5 hash:1ab05fef765b6342cdfadaa5275b33af

                                              Start time (UTC):07:52:54
                                              Start date (UTC):24/11/2024
                                              Path:/tmp/.i.elf
                                              Arguments:-
                                              File size:4956856 bytes
                                              MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                              Start time (UTC):07:52:54
                                              Start date (UTC):24/11/2024
                                              Path:/bin/sh
                                              Arguments:/bin/sh -c "iptables -X CWMP_CR"
                                              File size:129816 bytes
                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                              Start time (UTC):07:52:54
                                              Start date (UTC):24/11/2024
                                              Path:/bin/sh
                                              Arguments:-
                                              File size:129816 bytes
                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                              Start time (UTC):07:52:54
                                              Start date (UTC):24/11/2024
                                              Path:/usr/sbin/iptables
                                              Arguments:iptables -X CWMP_CR
                                              File size:99296 bytes
                                              MD5 hash:1ab05fef765b6342cdfadaa5275b33af

                                              Start time (UTC):07:52:54
                                              Start date (UTC):24/11/2024
                                              Path:/tmp/.i.elf
                                              Arguments:-
                                              File size:4956856 bytes
                                              MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                              Start time (UTC):07:52:54
                                              Start date (UTC):24/11/2024
                                              Path:/bin/sh
                                              Arguments:/bin/sh -c "iptables -I INPUT -p udp --dport 27986 -j ACCEPT"
                                              File size:129816 bytes
                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                              Start time (UTC):07:52:54
                                              Start date (UTC):24/11/2024
                                              Path:/bin/sh
                                              Arguments:-
                                              File size:129816 bytes
                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                              Start time (UTC):07:52:54
                                              Start date (UTC):24/11/2024
                                              Path:/usr/sbin/iptables
                                              Arguments:iptables -I INPUT -p udp --dport 27986 -j ACCEPT
                                              File size:99296 bytes
                                              MD5 hash:1ab05fef765b6342cdfadaa5275b33af