Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
SecuriteInfo.com.Other.Malware-gen.3200.4135.elf

Overview

General Information

Sample name:SecuriteInfo.com.Other.Malware-gen.3200.4135.elf
Analysis ID:1431159
MD5:cef396530992f79dea5d6d8209fc8ee7
SHA1:cdaa0b93d9299a00b90edb4b617a9f89c3aa322f
SHA256:5c21a3451c7f4bcb6737a8904efc7ea9ee10b3994f324b2ece1610883c2394f1
Tags:elf
Infos:

Detection

Mirai
Score:100
Range:0 - 100
Whitelisted:false

Signatures

Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Yara detected Mirai
Connects to many ports of the same IP (likely port scanning)
Drops files in suspicious directories
Executes itself again with its parent PID as an argument (indicative of hampering debugging)
Executes the "crontab" command typically for achieving persistence
Performs DNS TXT record lookups
Sample tries to persist itself using System V runlevels
Sample tries to persist itself using cron
Sample tries to set files in /etc globally writable
Tries to resolve many domain names, but no domain seems valid
Uses dynamic DNS services
Creates hidden files and/or directories
Detected TCP or UDP traffic on non-standard ports
ELF contains segments with high entropy indicating compressed/encrypted content
Executes commands using a shell command-line interpreter
Executes the "rm" command used to delete files or directories
Executes the "systemctl" command used for controlling the systemd system and service manager
Sample and/or dropped files contains symbols with suspicious names
Sample contains only a LOAD segment without any section mappings
Sample tries to set the executable flag
Uses the "uname" system call to query kernel version information (possible evasion)
Writes ELF files to disk
Writes shell script file to disk with an unusual file extension

Classification

Analysis Advice

Static ELF header machine description suggests that the sample might not execute correctly on this machine.
Static ELF header machine description suggests that the sample might only run correctly on MIPS or ARM architectures.
Joe Sandbox version:40.0.0 Tourmaline
Analysis ID:1431159
Start date and time:2024-04-24 16:34:24 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 5m 30s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:SecuriteInfo.com.Other.Malware-gen.3200.4135.elf
Detection:MAL
Classification:mal100.troj.evad.linELF@0/8@17/0
  • VT rate limit hit for: SecuriteInfo.com.Other.Malware-gen.3200.4135.elf
Command:/tmp/SecuriteInfo.com.Other.Malware-gen.3200.4135.elf
PID:6208
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
goodluck
Standard Error:
  • system is lnxubuntu20
  • SecuriteInfo.com.Other.Malware-gen.3200.4135.elf (PID: 6208, Parent: 6125, MD5: 5ebfcae4fe2471fcc5695c2394773ff1) Arguments: /tmp/SecuriteInfo.com.Other.Malware-gen.3200.4135.elf
    • cp (PID: 6210, Parent: 6208, MD5: 40f10ae7ea3e44218d1a8c306f79c83f) Arguments: cp -f /usr/bin/qemu-arm /var/tmp/nginx_kel
    • sh (PID: 6212, Parent: 6208, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "mount -o bind /tmp/nginx_server /proc/6208/ > /dev/null 2>&1"
      • sh New Fork (PID: 6214, Parent: 6212)
      • mount (PID: 6214, Parent: 6212, MD5: 92b20aa8b155ecd3ba9414aa477ef565) Arguments: mount -o bind /tmp/nginx_server /proc/6208/
    • SecuriteInfo.com.Other.Malware-gen.3200.4135.elf New Fork (PID: 6227, Parent: 6208)
      • SecuriteInfo.com.Other.Malware-gen.3200.4135.elf New Fork (PID: 6241, Parent: 6227)
        • sh (PID: 6248, Parent: 6241, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "ln -sf /etc/init.d/dnsconfig /etc/rcS.d/S99dnsconfig > /dev/null 2>&1"
          • sh New Fork (PID: 6269, Parent: 6248)
          • ln (PID: 6269, Parent: 6248, MD5: e933cf05571f62c0157d4e2dfcaea282) Arguments: ln -sf /etc/init.d/dnsconfig /etc/rcS.d/S99dnsconfig
        • sh (PID: 6273, Parent: 6241, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "ln -sf /etc/init.d/dnsconfig /etc/rc.d/S99dnsconfig > /dev/null 2>&1"
          • sh New Fork (PID: 6295, Parent: 6273)
          • ln (PID: 6295, Parent: 6273, MD5: e933cf05571f62c0157d4e2dfcaea282) Arguments: ln -sf /etc/init.d/dnsconfig /etc/rc.d/S99dnsconfig
        • sh (PID: 6302, Parent: 6241, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "ln -sf /etc/init.d/dnsconfig /etc/rc0.d/S99dnsconfig > /dev/null 2>&1"
          • sh New Fork (PID: 6304, Parent: 6302)
          • ln (PID: 6304, Parent: 6302, MD5: e933cf05571f62c0157d4e2dfcaea282) Arguments: ln -sf /etc/init.d/dnsconfig /etc/rc0.d/S99dnsconfig
        • sh (PID: 6305, Parent: 6241, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "ln -sf /etc/init.d/dnsconfig /etc/rc1.d/S99dnsconfig > /dev/null 2>&1"
          • sh New Fork (PID: 6318, Parent: 6305)
          • ln (PID: 6318, Parent: 6305, MD5: e933cf05571f62c0157d4e2dfcaea282) Arguments: ln -sf /etc/init.d/dnsconfig /etc/rc1.d/S99dnsconfig
        • sh (PID: 6319, Parent: 6241, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "ln -sf /etc/init.d/dnsconfig /etc/rc2.d/S99dnsconfig > /dev/null 2>&1"
          • sh New Fork (PID: 6324, Parent: 6319)
          • ln (PID: 6324, Parent: 6319, MD5: e933cf05571f62c0157d4e2dfcaea282) Arguments: ln -sf /etc/init.d/dnsconfig /etc/rc2.d/S99dnsconfig
        • sh (PID: 6336, Parent: 6241, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "ln -sf /etc/init.d/dnsconfig /etc/rc3.d/S99dnsconfig > /dev/null 2>&1"
          • sh New Fork (PID: 6339, Parent: 6336)
          • ln (PID: 6339, Parent: 6336, MD5: e933cf05571f62c0157d4e2dfcaea282) Arguments: ln -sf /etc/init.d/dnsconfig /etc/rc3.d/S99dnsconfig
        • sh (PID: 6340, Parent: 6241, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "ln -sf /etc/init.d/dnsconfig /etc/rc4.d/S99dnsconfig > /dev/null 2>&1"
          • sh New Fork (PID: 6342, Parent: 6340)
          • ln (PID: 6342, Parent: 6340, MD5: e933cf05571f62c0157d4e2dfcaea282) Arguments: ln -sf /etc/init.d/dnsconfig /etc/rc4.d/S99dnsconfig
        • sh (PID: 6343, Parent: 6241, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "ln -sf /etc/init.d/dnsconfig /etc/rc5.d/S99dnsconfig > /dev/null 2>&1"
          • sh New Fork (PID: 6345, Parent: 6343)
          • ln (PID: 6345, Parent: 6343, MD5: e933cf05571f62c0157d4e2dfcaea282) Arguments: ln -sf /etc/init.d/dnsconfig /etc/rc5.d/S99dnsconfig
        • sh (PID: 6346, Parent: 6241, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "ln -sf /etc/init.d/dnsconfig /etc/rc6.d/S99dnsconfig > /dev/null 2>&1"
          • sh New Fork (PID: 6348, Parent: 6346)
          • ln (PID: 6348, Parent: 6346, MD5: e933cf05571f62c0157d4e2dfcaea282) Arguments: ln -sf /etc/init.d/dnsconfig /etc/rc6.d/S99dnsconfig
        • sh (PID: 6349, Parent: 6241, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "ln -sf /etc/rc.d/init.d/dnsconfigs /etc/rc.d/S99dnsconfigs > /dev/null 2>&1"
          • sh New Fork (PID: 6353, Parent: 6349)
          • ln (PID: 6353, Parent: 6349, MD5: e933cf05571f62c0157d4e2dfcaea282) Arguments: ln -sf /etc/rc.d/init.d/dnsconfigs /etc/rc.d/S99dnsconfigs
        • sh (PID: 6355, Parent: 6241, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "ln -sf /etc/rc.d/init.d/dnsconfigs /etc/rc0.d/S99dnsconfigs > /dev/null 2>&1"
          • sh New Fork (PID: 6359, Parent: 6355)
          • ln (PID: 6359, Parent: 6355, MD5: e933cf05571f62c0157d4e2dfcaea282) Arguments: ln -sf /etc/rc.d/init.d/dnsconfigs /etc/rc0.d/S99dnsconfigs
        • sh (PID: 6361, Parent: 6241, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "ln -sf /etc/rc.d/init.d/dnsconfigs /etc/rc1.d/S99dnsconfigs > /dev/null 2>&1"
          • sh New Fork (PID: 6363, Parent: 6361)
          • ln (PID: 6363, Parent: 6361, MD5: e933cf05571f62c0157d4e2dfcaea282) Arguments: ln -sf /etc/rc.d/init.d/dnsconfigs /etc/rc1.d/S99dnsconfigs
        • sh (PID: 6364, Parent: 6241, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "ln -sf /etc/rc.d/init.d/dnsconfigs /etc/rc2.d/S99dnsconfigs > /dev/null 2>&1"
          • sh New Fork (PID: 6366, Parent: 6364)
          • ln (PID: 6366, Parent: 6364, MD5: e933cf05571f62c0157d4e2dfcaea282) Arguments: ln -sf /etc/rc.d/init.d/dnsconfigs /etc/rc2.d/S99dnsconfigs
        • sh (PID: 6367, Parent: 6241, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "ln -sf /etc/rc.d/init.d/dnsconfigs /etc/rc3.d/S99dnsconfigs > /dev/null 2>&1"
          • sh New Fork (PID: 6373, Parent: 6367)
          • ln (PID: 6373, Parent: 6367, MD5: e933cf05571f62c0157d4e2dfcaea282) Arguments: ln -sf /etc/rc.d/init.d/dnsconfigs /etc/rc3.d/S99dnsconfigs
        • sh (PID: 6374, Parent: 6241, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "ln -sf /etc/rc.d/init.d/dnsconfigs /etc/rc4.d/S99dnsconfigs > /dev/null 2>&1"
          • sh New Fork (PID: 6376, Parent: 6374)
          • ln (PID: 6376, Parent: 6374, MD5: e933cf05571f62c0157d4e2dfcaea282) Arguments: ln -sf /etc/rc.d/init.d/dnsconfigs /etc/rc4.d/S99dnsconfigs
        • sh (PID: 6377, Parent: 6241, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "ln -sf /etc/rc.d/init.d/dnsconfigs /etc/rc5.d/S99dnsconfigs > /dev/null 2>&1"
          • sh New Fork (PID: 6379, Parent: 6377)
          • ln (PID: 6379, Parent: 6377, MD5: e933cf05571f62c0157d4e2dfcaea282) Arguments: ln -sf /etc/rc.d/init.d/dnsconfigs /etc/rc5.d/S99dnsconfigs
        • sh (PID: 6380, Parent: 6241, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "ln -sf /etc/rc.d/init.d/dnsconfigs /etc/rc6.d/S99dnsconfigs > /dev/null 2>&1"
          • sh New Fork (PID: 6382, Parent: 6380)
          • ln (PID: 6382, Parent: 6380, MD5: e933cf05571f62c0157d4e2dfcaea282) Arguments: ln -sf /etc/rc.d/init.d/dnsconfigs /etc/rc6.d/S99dnsconfigs
      • sh (PID: 6245, Parent: 6227, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "crontab /var/tmp/.recoverys"
        • sh New Fork (PID: 6270, Parent: 6245)
        • crontab (PID: 6270, Parent: 6245, MD5: 66e521d421ac9b407699061bf21806f5) Arguments: crontab /var/tmp/.recoverys
      • sh (PID: 6297, Parent: 6227, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "systemctl daemon-reload > /dev/null 2>&1"
        • sh New Fork (PID: 6301, Parent: 6297)
        • systemctl (PID: 6301, Parent: 6297, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl daemon-reload
      • sh (PID: 6334, Parent: 6227, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "systemctl enable dnsconfigs.service > /dev/null 2>&1"
        • sh New Fork (PID: 6337, Parent: 6334)
        • systemctl (PID: 6337, Parent: 6334, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl enable dnsconfigs.service
      • sh (PID: 6357, Parent: 6227, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "systemctl start dnsconfigs.service > /dev/null 2>&1"
        • sh New Fork (PID: 6360, Parent: 6357)
        • systemctl (PID: 6360, Parent: 6357, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl start dnsconfigs.service
  • udisksd New Fork (PID: 6226, Parent: 799)
  • dumpe2fs (PID: 6226, Parent: 799, MD5: 5c66f7d8f7681a40562cf049ad4b72b4) Arguments: dumpe2fs -h /dev/dm-0
  • udisksd New Fork (PID: 6272, Parent: 799)
  • dumpe2fs (PID: 6272, Parent: 799, MD5: 5c66f7d8f7681a40562cf049ad4b72b4) Arguments: dumpe2fs -h /dev/dm-0
  • udisksd New Fork (PID: 6300, Parent: 799)
  • dumpe2fs (PID: 6300, Parent: 799, MD5: 5c66f7d8f7681a40562cf049ad4b72b4) Arguments: dumpe2fs -h /dev/dm-0
  • systemd New Fork (PID: 6322, Parent: 6321)
  • snapd-env-generator (PID: 6322, Parent: 6321, MD5: 3633b075f40283ec938a2a6a89671b0e) Arguments: /usr/lib/systemd/system-environment-generators/snapd-env-generator
  • systemd New Fork (PID: 6352, Parent: 6351)
  • snapd-env-generator (PID: 6352, Parent: 6351, MD5: 3633b075f40283ec938a2a6a89671b0e) Arguments: /usr/lib/systemd/system-environment-generators/snapd-env-generator
  • systemd New Fork (PID: 6369, Parent: 1)
  • dash New Fork (PID: 6392, Parent: 4331)
  • rm (PID: 6392, Parent: 4331, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.W12VpjdjU0 /tmp/tmp.9MZwt69YkC /tmp/tmp.q0ZKQX1Uze
  • dash New Fork (PID: 6393, Parent: 4331)
  • cat (PID: 6393, Parent: 4331, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /tmp/tmp.W12VpjdjU0
  • dash New Fork (PID: 6394, Parent: 4331)
  • head (PID: 6394, Parent: 4331, MD5: fd96a67145172477dd57131396fc9608) Arguments: head -n 10
  • dash New Fork (PID: 6395, Parent: 4331)
  • tr (PID: 6395, Parent: 4331, MD5: fbd1402dd9f72d8ebfff00ce7c3a7bb5) Arguments: tr -d \\000-\\011\\013\\014\\016-\\037
  • dash New Fork (PID: 6396, Parent: 4331)
  • cut (PID: 6396, Parent: 4331, MD5: d8ed0ea8f22c0de0f8692d4d9f1759d3) Arguments: cut -c -80
  • dash New Fork (PID: 6397, Parent: 4331)
  • cat (PID: 6397, Parent: 4331, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /tmp/tmp.W12VpjdjU0
  • dash New Fork (PID: 6398, Parent: 4331)
  • head (PID: 6398, Parent: 4331, MD5: fd96a67145172477dd57131396fc9608) Arguments: head -n 10
  • dash New Fork (PID: 6399, Parent: 4331)
  • tr (PID: 6399, Parent: 4331, MD5: fbd1402dd9f72d8ebfff00ce7c3a7bb5) Arguments: tr -d \\000-\\011\\013\\014\\016-\\037
  • dash New Fork (PID: 6400, Parent: 4331)
  • cut (PID: 6400, Parent: 4331, MD5: d8ed0ea8f22c0de0f8692d4d9f1759d3) Arguments: cut -c -80
  • dash New Fork (PID: 6401, Parent: 4331)
  • rm (PID: 6401, Parent: 4331, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.W12VpjdjU0 /tmp/tmp.9MZwt69YkC /tmp/tmp.q0ZKQX1Uze
  • systemd New Fork (PID: 6446, Parent: 1)
  • nginx_kel (PID: 6446, Parent: 1, MD5: 5ebfcae4fe2471fcc5695c2394773ff1) Arguments: /var/tmp/nginx_kel sv
  • systemd New Fork (PID: 6491, Parent: 1)
  • nginx_kel (PID: 6491, Parent: 1, MD5: 5ebfcae4fe2471fcc5695c2394773ff1) Arguments: /var/tmp/nginx_kel sv
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
MiraiMirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.mirai
SourceRuleDescriptionAuthorStrings
6208.1.00007fbc50017000.00007fbc50083000.r-x.sdmpJoeSecurity_Mirai_9Yara detected MiraiJoe Security
    6227.1.00007fbc50017000.00007fbc50083000.r-x.sdmpJoeSecurity_Mirai_9Yara detected MiraiJoe Security
      6293.1.00007fbc50017000.00007fbc50083000.r-x.sdmpJoeSecurity_Mirai_9Yara detected MiraiJoe Security
        6241.1.00007fbc50017000.00007fbc50083000.r-x.sdmpJoeSecurity_Mirai_9Yara detected MiraiJoe Security
          No Snort rule has matched

          Click to jump to signature section

          Show All Signature Results

          AV Detection

          barindex
          Source: SecuriteInfo.com.Other.Malware-gen.3200.4135.elfAvira: detected
          Source: SecuriteInfo.com.Other.Malware-gen.3200.4135.elfReversingLabs: Detection: 47%
          Source: unknownHTTPS traffic detected: 54.171.230.55:443 -> 192.168.2.23:33608 version: TLS 1.2

          Networking

          barindex
          Source: global trafficTCP traffic: 147.78.12.176 ports 0,1,2,24150,4,5
          Source: unknownDNS traffic detected: query: 60da859e8a.ignorelist.com replaycode: Name error (3)
          Source: unknownDNS traffic detected: query: 60da859e8a.websersaiosnginxo.ru replaycode: Name error (3)
          Source: unknownDNS traffic detected: query: 60da859e8a.strangled.net replaycode: Name error (3)
          Source: unknownDNS traffic detected: query: 60da859e8a.ddnsfree.com replaycode: Name error (3)
          Source: unknownDNS traffic detected: query: 60da859e8a.mooo.com replaycode: Name error (3)
          Source: unknownDNS traffic detected: query: 60da859e8a.nl replaycode: Name error (3)
          Source: unknownDNS traffic detected: query: 60da859e8a.ru replaycode: Name error (3)
          Source: unknownDNS traffic detected: query: 60da859e8a.chickenkiller.com replaycode: Name error (3)
          Source: unknownDNS traffic detected: query: 60da859e8a.adminpanel.oss replaycode: Name error (3)
          Source: unknownDNS traffic detected: query: 60da859e8a.geek replaycode: Name error (3)
          Source: unknownDNS traffic detected: query: 60da859e8a.oss replaycode: Name error (3)
          Source: unknownDNS traffic detected: query: 60da859e8a.accesscam.org replaycode: Name error (3)
          Source: unknownDNS traffic detected: query: 60da859e8a.duckdns.org replaycode: Name error (3)
          Source: unknownDNS traffic detected: query: 60da859e8a.casacam.net replaycode: Name error (3)
          Source: unknownDNS query: name: 60da859e8a.admincs.duckdns.org
          Source: unknownDNS query: name: 60da859e8a.duckdns.org
          Source: global trafficTCP traffic: 192.168.2.23:57328 -> 147.78.12.176:24150
          Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
          Source: unknownTCP traffic detected without corresponding DNS query: 147.78.12.176
          Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
          Source: unknownTCP traffic detected without corresponding DNS query: 147.78.12.176
          Source: unknownTCP traffic detected without corresponding DNS query: 147.78.12.176
          Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
          Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
          Source: unknownTCP traffic detected without corresponding DNS query: 147.78.12.176
          Source: unknownTCP traffic detected without corresponding DNS query: 147.78.12.176
          Source: unknownTCP traffic detected without corresponding DNS query: 147.78.12.176
          Source: unknownTCP traffic detected without corresponding DNS query: 147.78.12.176
          Source: unknownTCP traffic detected without corresponding DNS query: 147.78.12.176
          Source: unknownTCP traffic detected without corresponding DNS query: 147.78.12.176
          Source: unknownTCP traffic detected without corresponding DNS query: 147.78.12.176
          Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
          Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
          Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
          Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
          Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
          Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
          Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
          Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
          Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
          Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
          Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
          Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
          Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
          Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
          Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
          Source: unknownTCP traffic detected without corresponding DNS query: 147.78.12.176
          Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
          Source: unknownTCP traffic detected without corresponding DNS query: 147.78.12.176
          Source: unknownTCP traffic detected without corresponding DNS query: 147.78.12.176
          Source: unknownTCP traffic detected without corresponding DNS query: 147.78.12.176
          Source: unknownTCP traffic detected without corresponding DNS query: 147.78.12.176
          Source: unknownTCP traffic detected without corresponding DNS query: 147.78.12.176
          Source: unknownTCP traffic detected without corresponding DNS query: 147.78.12.176
          Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
          Source: unknownTCP traffic detected without corresponding DNS query: 147.78.12.176
          Source: unknownTCP traffic detected without corresponding DNS query: 147.78.12.176
          Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
          Source: unknownTCP traffic detected without corresponding DNS query: 147.78.12.176
          Source: unknownTCP traffic detected without corresponding DNS query: 147.78.12.176
          Source: unknownTCP traffic detected without corresponding DNS query: 147.78.12.176
          Source: unknownTCP traffic detected without corresponding DNS query: 147.78.12.176
          Source: unknownTCP traffic detected without corresponding DNS query: 147.78.12.176
          Source: unknownTCP traffic detected without corresponding DNS query: 147.78.12.176
          Source: unknownTCP traffic detected without corresponding DNS query: 147.78.12.176
          Source: unknownTCP traffic detected without corresponding DNS query: 147.78.12.176
          Source: unknownTCP traffic detected without corresponding DNS query: 147.78.12.176
          Source: global trafficDNS traffic detected: DNS query: 60da859e8a.dontargetme.nl
          Source: global trafficDNS traffic detected: DNS query: 60da859e8a.websersaiosnginxo.ru
          Source: global trafficDNS traffic detected: DNS query: 60da859e8a.adminpanel.oss
          Source: global trafficDNS traffic detected: DNS query: 60da859e8a.admincs.duckdns.org
          Source: global trafficDNS traffic detected: DNS query: 60da859e8a.session.geek
          Source: global trafficDNS traffic detected: DNS query: 60da859e8a.duckdns.org
          Source: global trafficDNS traffic detected: DNS query: 60da859e8a.geek
          Source: global trafficDNS traffic detected: DNS query: 60da859e8a.oss
          Source: global trafficDNS traffic detected: DNS query: 60da859e8a.chickenkiller.com
          Source: global trafficDNS traffic detected: DNS query: 60da859e8a.accesscam.org
          Source: global trafficDNS traffic detected: DNS query: 60da859e8a.casacam.net
          Source: global trafficDNS traffic detected: DNS query: 60da859e8a.ddnsfree.com
          Source: global trafficDNS traffic detected: DNS query: 60da859e8a.mooo.com
          Source: global trafficDNS traffic detected: DNS query: 60da859e8a.strangled.net
          Source: global trafficDNS traffic detected: DNS query: 60da859e8a.ignorelist.com
          Source: global trafficDNS traffic detected: DNS query: 60da859e8a.ru
          Source: global trafficDNS traffic detected: DNS query: 60da859e8a.nl
          Source: nginx_kel.16.drString found in binary or memory: https://qemu.org
          Source: nginx_kel.16.drString found in binary or memory: https://qemu.org/contribute/report-a-bug
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 33608
          Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 33608 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
          Source: unknownHTTPS traffic detected: 54.171.230.55:443 -> 192.168.2.23:33608 version: TLS 1.2
          Source: nginx_kel.16.drELF static info symbol of dropped file: QMPCapability_lookup
          Source: nginx_kel.16.drELF static info symbol of dropped file: _ZNSt8__detail15_List_node_base7_M_hookEPS0_
          Source: nginx_kel.16.drELF static info symbol of dropped file: _ZNSt8__detail15_List_node_base9_M_unhookEv
          Source: nginx_kel.16.drELF static info symbol of dropped file: arm_register_el_change_hook
          Source: nginx_kel.16.drELF static info symbol of dropped file: arm_register_pre_el_change_hook
          Source: LOAD without section mappingsProgram segment: 0x8000
          Source: classification engineClassification label: mal100.troj.evad.linELF@0/8@17/0

          Persistence and Installation Behavior

          barindex
          Source: /bin/sh (PID: 6270)Crontab executable: /usr/bin/crontab -> crontab /var/tmp/.recoverysJump to behavior
          Source: /usr/bin/ln (PID: 6269)File: /etc/rcS.d/S99dnsconfig -> /etc/init.d/dnsconfigJump to behavior
          Source: /usr/bin/ln (PID: 6295)File: /etc/rc.d/S99dnsconfig -> /etc/init.d/dnsconfigJump to behavior
          Source: /usr/bin/ln (PID: 6304)File: /etc/rc0.d/S99dnsconfig -> /etc/init.d/dnsconfigJump to behavior
          Source: /usr/bin/ln (PID: 6318)File: /etc/rc1.d/S99dnsconfig -> /etc/init.d/dnsconfigJump to behavior
          Source: /usr/bin/ln (PID: 6324)File: /etc/rc2.d/S99dnsconfig -> /etc/init.d/dnsconfigJump to behavior
          Source: /usr/bin/ln (PID: 6339)File: /etc/rc3.d/S99dnsconfig -> /etc/init.d/dnsconfigJump to behavior
          Source: /usr/bin/ln (PID: 6342)File: /etc/rc4.d/S99dnsconfig -> /etc/init.d/dnsconfigJump to behavior
          Source: /usr/bin/ln (PID: 6345)File: /etc/rc5.d/S99dnsconfig -> /etc/init.d/dnsconfigJump to behavior
          Source: /usr/bin/ln (PID: 6348)File: /etc/rc6.d/S99dnsconfig -> /etc/init.d/dnsconfigJump to behavior
          Source: /usr/bin/ln (PID: 6353)File: /etc/rc.d/S99dnsconfigs -> /etc/rc.d/init.d/dnsconfigsJump to behavior
          Source: /usr/bin/ln (PID: 6359)File: /etc/rc0.d/S99dnsconfigs -> /etc/rc.d/init.d/dnsconfigsJump to behavior
          Source: /usr/bin/ln (PID: 6363)File: /etc/rc1.d/S99dnsconfigs -> /etc/rc.d/init.d/dnsconfigsJump to behavior
          Source: /usr/bin/ln (PID: 6366)File: /etc/rc2.d/S99dnsconfigs -> /etc/rc.d/init.d/dnsconfigsJump to behavior
          Source: /usr/bin/ln (PID: 6373)File: /etc/rc3.d/S99dnsconfigs -> /etc/rc.d/init.d/dnsconfigsJump to behavior
          Source: /usr/bin/ln (PID: 6376)File: /etc/rc4.d/S99dnsconfigs -> /etc/rc.d/init.d/dnsconfigsJump to behavior
          Source: /usr/bin/ln (PID: 6379)File: /etc/rc5.d/S99dnsconfigs -> /etc/rc.d/init.d/dnsconfigsJump to behavior
          Source: /usr/bin/ln (PID: 6382)File: /etc/rc6.d/S99dnsconfigs -> /etc/rc.d/init.d/dnsconfigsJump to behavior
          Source: /usr/bin/crontab (PID: 6270)File: /var/spool/cron/crontabs/tmp.pn4SlkJump to behavior
          Source: /usr/bin/crontab (PID: 6270)File: /var/spool/cron/crontabs/rootJump to behavior
          Source: /tmp/SecuriteInfo.com.Other.Malware-gen.3200.4135.elf (PID: 6241)File: /etc/init.d/dnsconfig (bits: - usr: rx grp: rx all: rwx)Jump to behavior
          Source: /tmp/SecuriteInfo.com.Other.Malware-gen.3200.4135.elf (PID: 6227)File: /var/tmp/.recoverysJump to behavior
          Source: /usr/bin/crontab (PID: 6270)Directory: /var/tmp/.recoverysJump to behavior
          Source: /tmp/SecuriteInfo.com.Other.Malware-gen.3200.4135.elf (PID: 6212)Shell command executed: sh -c "mount -o bind /tmp/nginx_server /proc/6208/ > /dev/null 2>&1"Jump to behavior
          Source: /tmp/SecuriteInfo.com.Other.Malware-gen.3200.4135.elf (PID: 6248)Shell command executed: sh -c "ln -sf /etc/init.d/dnsconfig /etc/rcS.d/S99dnsconfig > /dev/null 2>&1"Jump to behavior
          Source: /tmp/SecuriteInfo.com.Other.Malware-gen.3200.4135.elf (PID: 6273)Shell command executed: sh -c "ln -sf /etc/init.d/dnsconfig /etc/rc.d/S99dnsconfig > /dev/null 2>&1"Jump to behavior
          Source: /tmp/SecuriteInfo.com.Other.Malware-gen.3200.4135.elf (PID: 6302)Shell command executed: sh -c "ln -sf /etc/init.d/dnsconfig /etc/rc0.d/S99dnsconfig > /dev/null 2>&1"Jump to behavior
          Source: /tmp/SecuriteInfo.com.Other.Malware-gen.3200.4135.elf (PID: 6305)Shell command executed: sh -c "ln -sf /etc/init.d/dnsconfig /etc/rc1.d/S99dnsconfig > /dev/null 2>&1"Jump to behavior
          Source: /tmp/SecuriteInfo.com.Other.Malware-gen.3200.4135.elf (PID: 6319)Shell command executed: sh -c "ln -sf /etc/init.d/dnsconfig /etc/rc2.d/S99dnsconfig > /dev/null 2>&1"Jump to behavior
          Source: /tmp/SecuriteInfo.com.Other.Malware-gen.3200.4135.elf (PID: 6336)Shell command executed: sh -c "ln -sf /etc/init.d/dnsconfig /etc/rc3.d/S99dnsconfig > /dev/null 2>&1"Jump to behavior
          Source: /tmp/SecuriteInfo.com.Other.Malware-gen.3200.4135.elf (PID: 6340)Shell command executed: sh -c "ln -sf /etc/init.d/dnsconfig /etc/rc4.d/S99dnsconfig > /dev/null 2>&1"Jump to behavior
          Source: /tmp/SecuriteInfo.com.Other.Malware-gen.3200.4135.elf (PID: 6343)Shell command executed: sh -c "ln -sf /etc/init.d/dnsconfig /etc/rc5.d/S99dnsconfig > /dev/null 2>&1"Jump to behavior
          Source: /tmp/SecuriteInfo.com.Other.Malware-gen.3200.4135.elf (PID: 6346)Shell command executed: sh -c "ln -sf /etc/init.d/dnsconfig /etc/rc6.d/S99dnsconfig > /dev/null 2>&1"Jump to behavior
          Source: /tmp/SecuriteInfo.com.Other.Malware-gen.3200.4135.elf (PID: 6349)Shell command executed: sh -c "ln -sf /etc/rc.d/init.d/dnsconfigs /etc/rc.d/S99dnsconfigs > /dev/null 2>&1"Jump to behavior
          Source: /tmp/SecuriteInfo.com.Other.Malware-gen.3200.4135.elf (PID: 6355)Shell command executed: sh -c "ln -sf /etc/rc.d/init.d/dnsconfigs /etc/rc0.d/S99dnsconfigs > /dev/null 2>&1"Jump to behavior
          Source: /tmp/SecuriteInfo.com.Other.Malware-gen.3200.4135.elf (PID: 6361)Shell command executed: sh -c "ln -sf /etc/rc.d/init.d/dnsconfigs /etc/rc1.d/S99dnsconfigs > /dev/null 2>&1"Jump to behavior
          Source: /tmp/SecuriteInfo.com.Other.Malware-gen.3200.4135.elf (PID: 6364)Shell command executed: sh -c "ln -sf /etc/rc.d/init.d/dnsconfigs /etc/rc2.d/S99dnsconfigs > /dev/null 2>&1"Jump to behavior
          Source: /tmp/SecuriteInfo.com.Other.Malware-gen.3200.4135.elf (PID: 6367)Shell command executed: sh -c "ln -sf /etc/rc.d/init.d/dnsconfigs /etc/rc3.d/S99dnsconfigs > /dev/null 2>&1"Jump to behavior
          Source: /tmp/SecuriteInfo.com.Other.Malware-gen.3200.4135.elf (PID: 6374)Shell command executed: sh -c "ln -sf /etc/rc.d/init.d/dnsconfigs /etc/rc4.d/S99dnsconfigs > /dev/null 2>&1"Jump to behavior
          Source: /tmp/SecuriteInfo.com.Other.Malware-gen.3200.4135.elf (PID: 6377)Shell command executed: sh -c "ln -sf /etc/rc.d/init.d/dnsconfigs /etc/rc5.d/S99dnsconfigs > /dev/null 2>&1"Jump to behavior
          Source: /tmp/SecuriteInfo.com.Other.Malware-gen.3200.4135.elf (PID: 6380)Shell command executed: sh -c "ln -sf /etc/rc.d/init.d/dnsconfigs /etc/rc6.d/S99dnsconfigs > /dev/null 2>&1"Jump to behavior
          Source: /tmp/SecuriteInfo.com.Other.Malware-gen.3200.4135.elf (PID: 6245)Shell command executed: sh -c "crontab /var/tmp/.recoverys"Jump to behavior
          Source: /tmp/SecuriteInfo.com.Other.Malware-gen.3200.4135.elf (PID: 6297)Shell command executed: sh -c "systemctl daemon-reload > /dev/null 2>&1"Jump to behavior
          Source: /tmp/SecuriteInfo.com.Other.Malware-gen.3200.4135.elf (PID: 6334)Shell command executed: sh -c "systemctl enable dnsconfigs.service > /dev/null 2>&1"Jump to behavior
          Source: /tmp/SecuriteInfo.com.Other.Malware-gen.3200.4135.elf (PID: 6357)Shell command executed: sh -c "systemctl start dnsconfigs.service > /dev/null 2>&1"Jump to behavior
          Source: /tmp/SecuriteInfo.com.Other.Malware-gen.3200.4135.elf (PID: 6244)Shell command executed: sh -c "mount -o bind /tmp/nginx_server /proc/6240/ > /dev/null 2>&1"Jump to behavior
          Source: /usr/bin/dash (PID: 6392)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.W12VpjdjU0 /tmp/tmp.9MZwt69YkC /tmp/tmp.q0ZKQX1UzeJump to behavior
          Source: /usr/bin/dash (PID: 6401)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.W12VpjdjU0 /tmp/tmp.9MZwt69YkC /tmp/tmp.q0ZKQX1UzeJump to behavior
          Source: /bin/sh (PID: 6301)Systemctl executable: /usr/bin/systemctl -> systemctl daemon-reloadJump to behavior
          Source: /bin/sh (PID: 6337)Systemctl executable: /usr/bin/systemctl -> systemctl enable dnsconfigs.serviceJump to behavior
          Source: /bin/sh (PID: 6360)Systemctl executable: /usr/bin/systemctl -> systemctl start dnsconfigs.serviceJump to behavior
          Source: /tmp/SecuriteInfo.com.Other.Malware-gen.3200.4135.elf (PID: 6227)File: /var/tmp/nginx_kel (bits: - usr: rx grp: rx all: rwx)Jump to behavior
          Source: /tmp/SecuriteInfo.com.Other.Malware-gen.3200.4135.elf (PID: 6241)File: /etc/init.d/dnsconfig (bits: - usr: rx grp: rx all: rwx)Jump to behavior
          Source: /bin/cp (PID: 6210)File written: /var/tmp/nginx_kelJump to dropped file
          Source: /tmp/SecuriteInfo.com.Other.Malware-gen.3200.4135.elf (PID: 6241)Writes shell script file to disk with an unusual file extension: /etc/init.d/dnsconfigJump to dropped file

          Hooking and other Techniques for Hiding and Protection

          barindex
          Source: /tmp/SecuriteInfo.com.Other.Malware-gen.3200.4135.elf (PID: 6241)File: /etc/init.d/dnsconfigJump to dropped file
          Source: SecuriteInfo.com.Other.Malware-gen.3200.4135.elfSubmission file: segment LOAD with 7.6392 entropy (max. 8.0)
          Source: SecuriteInfo.com.Other.Malware-gen.3200.4135.elfSubmission file: segment LOAD with 7.7426 entropy (max. 8.0)
          Source: /tmp/SecuriteInfo.com.Other.Malware-gen.3200.4135.elf (PID: 6208)Queries kernel information via 'uname': Jump to behavior
          Source: /var/tmp/nginx_kel (PID: 6446)Queries kernel information via 'uname': Jump to behavior
          Source: /var/tmp/nginx_kel (PID: 6491)Queries kernel information via 'uname': Jump to behavior
          Source: nginx_kel.16.drBinary or memory string: qemu_dcache_linesize_log
          Source: nginx_kel.16.drBinary or memory string: qemu_opts_set_defaults
          Source: nginx_kel.16.drBinary or memory string: /build/qemu-rbeYHu/qemu-4.2/target/arm/internals.h
          Source: nginx_kel.16.drBinary or memory string: _TRACE_QEMU_MEMALIGN_DSTATE
          Source: nginx_kel.16.drBinary or memory string: /build/qemu-rbeYHu/qemu-4.2/include/hw/core/cpu.hError: Bad gdb register numbering for '%s', expected %d got %d%d@%zu.%06zu:gdbstub_op_exiting notifying exit with code=0x%02x
          Source: nginx_kel.16.drBinary or memory string: qemu_thread_naming
          Source: nginx_kel.16.drBinary or memory string: qemu_opt_foreach
          Source: nginx_kel.16.drBinary or memory string: qemu_getauxval
          Source: nginx_kel.16.drBinary or memory string: LORSA_EL1LOREA_EL1LORN_EL1LORC_EL1LORID_EL1CFP_RCTXDVP_RCTXCPP_RCTXCFPRCTXDVPRCTXCPPRCTXZCR_EL3ZCR_EL2ZCR_EL1DBGDRARDBGDSARMDRAR_EL1MDSCR_EL1MDCCSR_EL0OSLAR_EL1OSLSR_EL1OSDLR_EL1DBGVCRDBGVCR32_EL2MDCCINT_EL1SCR_EL3SCRSDER32_EL3SDERMVBARTTBR0_EL3TCR_EL3ELR_EL3ESR_EL3FAR_EL3SPSR_EL3CPTR_EL3TPIDR_EL3AMAIR_EL3AFSR0_EL3AFSR1_EL3TLBI_ALLE3ISTLBI_VAE3ISTLBI_VALE3ISTLBI_ALLE3TLBI_VAE3TLBI_VALE3HCR2HCR_EL2HCRHACR_EL2ELR_EL2ESR_EL2HIFARSPSR_EL2SP_EL2CPTR_EL2HMAIR1AMAIR_EL2HAMAIR1AFSR0_EL2AFSR1_EL2VTCRVTCR_EL2VTTBRVTTBR_EL2SCTLR_EL2TPIDR_EL2TTBR0_EL2HTTBRTLBIALLNSNHTLBIALLNSNHISTLBIALLHTLBIALLHISTLBIMVAHTLBIMVAHISTLBI_ALLE2TLBI_VAE2TLBI_VALE2TLBI_ALLE2ISTLBI_VAE2ISTLBI_VALE2ISMDCR_EL2HPFARHPFAR_EL2HSTR_EL2CNTHCTL_EL2CNTVOFF_EL2CNTVOFFCNTHP_CVAL_EL2CNTHP_CVALCNTHP_TVAL_EL2CNTHP_CTL_EL2NZCVDAIFFPCRFPSRDCZID_EL0DC_ZVACURRENTELIC_IALLUISIC_IALLUIC_IVAUDC_IVACDC_ISWDC_CVACDC_CSWDC_CVAUDC_CIVACDC_CISWTLBI_VMALLE1ISTLBI_VAE1ISTLBI_ASIDE1ISTLBI_VAAE1ISTLBI_VALE1ISTLBI_VAALE1ISTLBI_VMALLE1TLBI_VAE1TLBI_ASIDE1TLBI_VAAE1TLBI_VALE1TLBI_VAALE1TLBI_IPAS2E1ISTLBI_IPAS2LE1ISTLBI_ALLE1ISTLBI_VMALLS12E1ISTLBI_IPAS2E1TLBI_IPAS2LE1TLBI_ALLE1TLBI_VMALLS12E1TLBIMVALISTLBIMVAALISTLBIMVALTLBIMVAALTLBIMVALHTLBIMVALHISTLBIIPAS2TLBIIPAS2ISTLBIIPAS2LTLBIIPAS2LISICIALLUISBPIALLUISICIALLUICIMVAUBPIALLBPIMVADCIMVACDCISWDCCMVACDCCSWDCCMVAUDCCIMVACDCCISWDACRELR_EL1SPSR_EL1SP_EL0SP_EL1SPSelFPEXC32_EL2DACR32_EL2IFSR32_EL2SPSR_IRQSPSR_ABTSPSR_UNDSPSR_FIQMDCR_EL3SDCRAMAIR0TTBR0TTBR1C9_READBUFFERTC_DCACHETCI_DCACHEBXSRIICRCDCRPIRPDRCIDCRCDSRC15_IMPDEFXSCALE_CPARXSCALE_AUXCRXSCALE_LOCK_ICACHE_LINEXSCALE_UNLOCK_ICACHEXSCALE_DCACHE_LOCKXSCALE_UNLOCK_DCACHEDFSRTICONFIGIMAXIMINTHREADIDTI925T_STATUSOMAP_CACHEMAINTC9TTBCR2ESR_EL1TTBR0_EL1TTBR1_EL1TCR_EL1TTBCRIFSRDFARFAR_EL1DATA_APINSN_APDATA_EXT_APINSN_EXT_APDCACHE_CFGICACHE_CFG946_PRBS0946_PRBS1946_PRBS2946_PRBS3946_PRBS4946_PRBS5946_PRBS6946_PRBS7DRBARDRSRDRACRRGNRCNTFRQ_EL0CNTVCT_EL0TPIDR_EL0TPIDRURWTPIDRRO_EL0TPIDRUROTPIDR_EL1TPIDRPRWTEECRTEEHBRPMOVSSETPMOVSSET_EL0TLBIALLISTLBIMVAISTLBIASIDISTLBIMVAAISNOPPMCNTENSETPMCNTENSET_EL0PMCNTENCLRPMCNTENCLR_EL0PMOVSRPMOVSCLR_EL0PMSWINCPMSWINC_EL0PMSELRPMSELR_EL0PMCCNTRPMCCNTR_EL0PMCCFILTRPMCCFILTR_EL0PMXEVTYPERPMXEVTYPER_EL0PMXEVCNTRPMXEVCNTR_EL0PMUSERENRPMUSERENR_EL0PMINTENSETPMINTENSET_EL1PMINTENCLRPMINTENCLR_EL1CCSIDRCSSELRAIDRAFSR0_EL1AFSR1_EL1MAIR_EL1ISR_EL1ITLBIALLITLBIMVAITLBIASIDDTLBIALLDTLBIMVADTLBIASIDTLBIMVAAMVA_prefetchISBDSBDMBWFARCPACRWFI_v6DLOCKDOWNILOCKDOWNPRRRNMRRWFI_v5TLB_LOCKDOWNFCSEIDRFCSEIDR_SCONTEXTIDR_EL1CONTEXTIDR_S/build/qemu-rbeYHu/qemu-4.2/target/arm/helper.cRegister redefined: cp=%d %d bit crn=%d crm=%d opc1=%d opc2=%d, was %s, now %s
          Source: nginx_kel.16.drBinary or memory string: qemu_opt_get_size_del
          Source: nginx_kel.16.drBinary or memory string: qemu_free_stack
          Source: nginx_kel.16.drBinary or memory string: qemu_free_irqs
          Source: nginx_kel.16.drBinary or memory string: qemu_devices_reset
          Source: nginx_kel.16.drBinary or memory string: qemu_file_monitor_dispatch
          Source: nginx_kel.16.drBinary or memory string: qemu_sem_timedwait
          Source: nginx_kel.16.drBinary or memory string: qemu_set_option
          Source: nginx_kel.16.drBinary or memory string: qemu_trace_opts
          Source: nginx_kel.16.drBinary or memory string: qemu_dup
          Source: nginx_kel.16.drBinary or memory string: _TRACE_QEMU_FILE_MONITOR_REMOVE_WATCH_DSTATE
          Source: nginx_kel.16.drBinary or memory string: get_prop_pcielinkwidthset_prop_pcielinkwidthget_prop_pcielinkspeedset_prop_pcielinkspeedcreate_link_propertyget_sizeset_sizeqdev_prop_check_globalsqdev_prop_set_ptrqdev_prop_finderror_set_from_qdev_prop_errorset_prop_arraylenset_prop_arraylenget_uuidset_uuidget_pci_host_devaddrget_pci_host_devaddrset_pci_host_devaddrset_blocksizeset_pci_devfnget_enumset_enumget_macset_macget_stringset_stringrelease_stringget_int64set_int64get_uint64set_uint64get_int32set_int32get_uint32set_uint32get_uint16set_uint16get_uint8set_uint8get_boolset_boolprop_get_bit64qdev_get_prop_mask64prop_set_bit64prop_get_bitqdev_get_prop_maskprop_set_bitqdev_prop_allow_set_link_before_realizeqdev_prop_set_after_realize/build/qemu-rbeYHu/qemu-4.2/hw/core/bus.c%s.%dbus == sysbus_get_default()hotplug-handlerbus->parentbus_get_realizedbus_set_realizedqbus_initfnqbus_finalizebus_unparentbus_unparentbus_class_initqbus_createqbus_realizeqbus_realize/build/qemu-rbeYHu/qemu-4.2/hw/core/irq.cqemu_allocate_irq/build/qemu-rbeYHu/qemu-4.2/hw/core/hotplug.chotplug_handler_unplughotplug_handler_unplug_requesthotplug_handler_plughotplug_handler_pre_plug/build/qemu-rbeYHu/qemu-4.2/hw/core/cpu.cObtaining memory mappings is unsupported on this CPU.Expected key=value format, found %s.%d@%zu.%06zu:guest_cpu_reset cpu=%p
          Source: nginx_kel.16.drBinary or memory string: /build/qemu-rbeYHu/qemu-4.2/tcg/tcg-op-gvec.coprsz % 8 == 0 && oprsz <= (8 << SIMD_OPRSZ_BITS)maxsz % 8 == 0 && maxsz <= (8 << SIMD_MAXSZ_BITS)data == sextract32(data, 0, SIMD_DATA_BITS)vece <= (in_32 ? MO_32 : MO_64)in_32 == NULL || in_64 == NULLg->fno != NULLfn != NULLtcg_gen_gvec_cmptcg_gen_gvec_cmp
          Source: nginx_kel.16.drBinary or memory string: qemu: Unsupported ARM syscall: 0x%x
          Source: nginx_kel.16.drBinary or memory string: qemu_guest_getrandom
          Source: nginx_kel.16.drBinary or memory string: qemu_config_write
          Source: nginx_kel.16.drBinary or memory string: /usr/lib/x86_64-linux-gnu/qemu
          Source: nginx_kel.16.drBinary or memory string: /build/qemu-rbeYHu/qemu-4.2/util/qemu-thread-posix.c
          Source: nginx_kel.16.drBinary or memory string: qemu_rec_mutex_lock_func
          Source: nginx_kel.16.drBinary or memory string: /build/qemu-rbeYHu/qemu-4.2/qobject/qjson.c
          Source: nginx_kel.16.drBinary or memory string: qemu_opts_free
          Source: nginx_kel.16.drBinary or memory string: qemu_ld_i32
          Source: nginx_kel.16.drBinary or memory string: _TRACE_QEMU_CO_MUTEX_UNLOCK_RETURN_DSTATE
          Source: nginx_kel.16.drBinary or memory string: qemu_glog_domains == NULL
          Source: nginx_kel.16.drBinary or memory string: opt->desc && opt->desc->type == QEMU_OPT_BOOL
          Source: nginx_kel.16.drBinary or memory string: *errp == NULL%s: %sCould not open '%s'errp && *errperror_free_or_aborterror_append_hinterror_setv%s:%d:warning: info: !loc->prevcur_loc == loc && loc->prevprintedqemu_glog_domains == NULLG_MESSAGES_DEBUG/build/qemu-rbeYHu/qemu-4.2/util/qemu-error.cfname || cur_loc->kind == LOC_FILEerror_initwarn_report_once_conderror_report_once_condloc_set_fileloc_restoreloc_poploc_push_restoreThere is no option group '%s' %s = "%s"
          Source: nginx_kel.16.drBinary or memory string: qemu_try_memalign
          Source: nginx_kel.16.drBinary or memory string: /build/qemu-rbeYHu/qemu-4.2/tcg/optimize.c
          Source: nginx_kel.16.drBinary or memory string: /build/qemu-rbeYHu/qemu-4.2/linux-user/signal.c%d@%zu.%06zu:user_queue_signal env=%p signal %d
          Source: nginx_kel.16.drBinary or memory string: complete tracesqemu_set_dfilter_rangesqemu_set_log_filenameqemu_set_lognew->n_buckets != old->n_buckets/build/qemu-rbeYHu/qemu-4.2/util/qht.cqht_do_resize_resetqht_init
          Source: nginx_kel.16.drBinary or memory string: _TRACE_QEMU_MUTEX_LOCK_EVENT
          Source: nginx_kel.16.drBinary or memory string: qemu_cond_timedwait_impl
          Source: nginx_kel.16.drBinary or memory string: qemu_opts_from_qdict
          Source: nginx_kel.16.drBinary or memory string: /build/qemu-rbeYHu/qemu-4.2/accel/tcg/cpu-exec.cTrace %d: %p [%08x/%08x/%#x] %s
          Source: nginx_kel.16.drBinary or memory string: qemu: %s: %s
          Source: nginx_kel.16.drBinary or memory string: qemu_file_monitor_enable_watch
          Source: nginx_kel.16.drBinary or memory string: qemu_allocate_irqs
          Source: nginx_kel.16.drBinary or memory string: qemu_set_tty_echo
          Source: nginx_kel.16.drBinary or memory string: _TRACE_QEMU_ANON_RAM_FREE_DSTATE
          Source: nginx_kel.16.drBinary or memory string: qemu_vfprintf
          Source: nginx_kel.16.drBinary or memory string: /build/qemu-rbeYHu/qemu-4.2/target/arm/cpu.h
          Source: nginx_kel.16.drBinary or memory string: qemu_print_log_usage
          Source: nginx_kel.16.drBinary or memory string: qemu_pipe
          Source: nginx_kel.16.drBinary or memory string: qemu_str_to_log_mask
          Source: nginx_kel.16.drBinary or memory string: qemu_opt_get_size
          Source: nginx_kel.16.drBinary or memory string: _TRACE_QEMU_FILE_MONITOR_DISPATCH_DSTATE
          Source: nginx_kel.16.drBinary or memory string: _TRACE_QEMU_MUTEX_LOCK_DSTATE
          Source: nginx_kel.16.drBinary or memory string: /build/qemu-rbeYHu/qemu-4.2/util/qht.c
          Source: nginx_kel.16.drBinary or memory string: /build/qemu-rbeYHu/qemu-4.2/util/mmap-alloc.c
          Source: nginx_kel.16.drBinary or memory string: _ZN16QEMUDisassemblerD2Ev
          Source: nginx_kel.16.drBinary or memory string: /build/qemu-rbeYHu/qemu-4.2/target/arm/cpu.c
          Source: nginx_kel.16.drBinary or memory string: qemu_sem_destroy
          Source: nginx_kel.16.drBinary or memory string: qemu.sstep
          Source: nginx_kel.16.drBinary or memory string: _TRACE_QEMU_MUTEX_LOCKED_EVENT
          Source: nginx_kel.16.drBinary or memory string: _TRACE_QEMU_CO_MUTEX_UNLOCK_RETURN_EVENT
          Source: nginx_kel.16.drBinary or memory string: qemu_init_exec_dir
          Source: nginx_kel.16.drBinary or memory string: _TRACE_QEMU_VFIO_FIND_MAPPING_DSTATE
          Source: nginx_kel.16.drBinary or memory string: QEMU_AES_set_encrypt_key
          Source: nginx_kel.16.drBinary or memory string: qemu_strnlen
          Source: nginx_kel.16.drBinary or memory string: !err != !*obj!(err && *list)uint8_tuint16_tuint32_tobj && lookupInvalid parameter '%s'/build/qemu-rbeYHu/qemu-4.2/qapi/qapi-visit-core.cv->type != VISITOR_OUTPUT || v->complete%d@%zu.%06zu:visit_complete v=%p opaque=%p
          Source: nginx_kel.16.drBinary or memory string: qemu_config_parse_qdict
          Source: nginx_kel.16.drBinary or memory string: %d@%zu.%06zu:qemu_mutex_lock waiting on mutex %p (%s:%d)
          Source: nginx_kel.16.drBinary or memory string: Unknown QEMU_IFLA_BR type %d
          Source: nginx_kel.16.drBinary or memory string: qemu_opts_del
          Source: nginx_kel.16.drBinary or memory string: qemu_opt_get_number_helper
          Source: nginx_kel.16.drBinary or memory string: MbP?/build/qemu-rbeYHu/qemu-4.2/util/range.c
          Source: nginx_kel.16.drBinary or memory string: qemu_opt_unset
          Source: nginx_kel.16.drBinary or memory string: qemu_guest_random_seed_main
          Source: nginx_kel.16.drBinary or memory string: /build/qemu-rbeYHu/qemu-4.2/target/arm/translate-vfp.inc.c
          Source: nginx_kel.16.drBinary or memory string: qemu_opts_to_qdict_filtered
          Source: nginx_kel.16.drBinary or memory string: cpu_common_initfncpu_common_parse_featurescpu_common_parse_featurescpu_common_resetcpu_common_get_memory_mappingcpu_common_realizefncpu_class_initcpu_class_by_namecpu_class_by_namecpu_resetcpu_dump_statisticscpu_dump_statecpu_get_crash_infocpu_write_elf64_notecpu_write_elf64_qemunotecpu_write_elf32_notecpu_write_elf32_qemunotecpu_get_memory_mappingcpu_paging_enabledcpu_by_arch_idinfo->name != NULL!enumerating_typeschild<tm_yeartm_montm_mdaytm_hourtm_mintm_sectype->parent_type != NULLtarget_type!obj || obj->base.refcnt%s::%sti->instance_size == 0ti->abstract!ti->instance_init!ti->instance_post_init!ti->instance_finalize!ti->num_interfacestype->abstract == falsesize >= type->instance_sizeinfo->parent!object_compat_props[1]!object_compat_props[0]missing object type '%s'(null)obj->ref > 0obj->ref == 0Property '.%s' not foundbooleanuintcan't apply global %s.%s=%s: container/objectschild<%s>user-creatableinvalid object type: %sobject type '%s' is abstractlink<%s>partsDevice '%s' not foundstruct tmlink%s/build/qemu-rbeYHu/qemu-4.2/qom/object.cRegistering `%s' which already exists
          Source: nginx_kel.16.drBinary or memory string: See <https://qemu.org/contribute/report-a-bug> for how to report bugs.
          Source: nginx_kel.16.drBinary or memory string: qemu: Unsupported SemiHosting SWI 0x%02x
          Source: nginx_kel.16.drBinary or memory string: qemufpa
          Source: nginx_kel.16.drBinary or memory string: /build/qemu-rbeYHu/qemu-4.2/qom/object_interfaces.c
          Source: nginx_kel.16.drBinary or memory string: qemu_real_host_page_mask
          Source: nginx_kel.16.drBinary or memory string: qemu_fprintf
          Source: nginx_kel.16.drBinary or memory string: Unknown QEMU_IFLA_TUN type %d
          Source: nginx_kel.16.drBinary or memory string: qemu_uuid_is_null
          Source: nginx_kel.16.drBinary or memory string: qemu_ram_munmap
          Source: nginx_kel.16.drBinary or memory string: os_mem_prealloc: failed to install signal handleros_mem_prealloc: Insufficient free host memory pages available to allocate guest RAMos_mem_prealloc: failed to reinstall signal handlerfailed to allocate memory for stackfailed to set up stack guard pageCannot open pid fileCannot stat fileCannot lock pid fileFailed to truncate pid fileFailed to write pid filef != -1/var%s/%s!exec_dir[0]/proc/self/exetouch_pages/proc/%d/cmdlinecannot block signalscannot fork child processcannot unblock signalsqemu_forkos_mem_preallocqemu_init_exec_dirqemu_set_cloexecsocket_set_fast_reuseqemu_set_nonblockqemu_set_blockqemu_write_pidfileqemu: %s: %s
          Source: nginx_kel.16.drBinary or memory string: qemu: missing argument for option '%s'
          Source: nginx_kel.16.drBinary or memory string: qemu_add_opts
          Source: nginx_kel.16.drBinary or memory string: %d@%zu.%06zu:qemu_anon_ram_alloc size %zu ptr %p
          Source: nginx_kel.16.drBinary or memory string: qemu_coroutine_yield
          Source: nginx_kel.16.drBinary or memory string: /build/qemu-rbeYHu/qemu-4.2/linux-user/elfload.c
          Source: nginx_kel.16.drBinary or memory string: _TRACE_QEMU_ANON_RAM_ALLOC_DSTATE
          Source: nginx_kel.16.drBinary or memory string: driveinvalid option name: %s%63[^.].%63[^.].%63[^=]%ncan't parse: "%s"there is no %s "%s" defined# qemu config file
          Source: nginx_kel.16.drBinary or memory string: qemu_vfio_ram_block_added
          Source: nginx_kel.16.drBinary or memory string: qemu_open
          Source: nginx_kel.16.drBinary or memory string: QEMU_DFILTER
          Source: nginx_kel.16.drBinary or memory string: opt->desc && opt->desc->type == QEMU_OPT_NUMBER
          Source: nginx_kel.16.drBinary or memory string: qemu_opt_has_help_opt
          Source: nginx_kel.16.drBinary or memory string: qemu_thread_joinqemu_thread_createqemu_event_waitqemu_event_resetqemu_event_setqemu_event_destroyqemu_sem_waitqemu_sem_waitqemu_sem_timedwaitqemu_sem_timedwaitqemu_sem_postqemu_sem_postqemu_sem_destroyqemu_sem_destroyqemu_sem_initqemu_cond_timedwait_implqemu_cond_timedwait_implqemu_cond_wait_implqemu_cond_wait_implqemu_cond_broadcastqemu_cond_broadcastqemu_cond_signalqemu_cond_signalqemu_cond_destroyqemu_cond_destroyqemu_cond_initqemu_rec_mutex_initqemu_mutex_unlock_implqemu_mutex_unlock_implqemu_mutex_trylock_implqemu_mutex_trylock_implqemu_mutex_lock_implqemu_mutex_lock_implqemu_mutex_destroyqemu_mutex_destroyqemu_mutex_init/build/qemu-rbeYHu/qemu-4.2/util/envlist.cenvlist != NULLenvlist_free/build/qemu-rbeYHu/qemu-4.2/util/path.cQEMU_MODULE_DIR%s/..Debian 1:4.2-3ubuntu6.17/var/run/qemu/%s.so%s/%s%sQTAILQ_EMPTY(&dso_init_list)Failed to open module: %s
          Source: nginx_kel.16.drBinary or memory string: [%63s "%63[^"]"][%63[^]]] %63s = "%1023[^"]" %63s = ""no group definedparse errorerror reading file%s.Unknown option '%s' for [%s]Unused option '%s' for [%s]%s.%uemulated machineaccelaccelerator listkernel_irqchipuse KVM in-kernel irqchipkvm_shadow_memKVM shadow MMU sizekernelLinux kernel image fileinitrdLinux initial ramdisk fileLinux kernel command lineLinux kernel device tree filedumpdtbphandle_startdt_compatibledump-guest-coremem-mergefirmwarefirmware imageiommusuppress-vmdescaes-key-wrapdea-key-wraploadparm/build/qemu-rbeYHu/qemu-4.2/util/qemu-config.cran out of space in drive_config_groupsran out of space in vm_config_groups[%s] section (index %u) does not consist of keys[%s] section doesn't support the option '%s'Dump current dtb to a file and quitThe first phandle ID we may generate dynamicallyOverrides the "compatible" property of the dt root nodeInclude guest memory in a core dumpenable/disable memory merge supportSet on/off to enable/disable usbSet on/off to enable/disable Intel IOMMU (VT-d)Set on to disable self-describing migrationenable/disable AES key wrapping using the CPACF wrapping keyenable/disable DEA key wrapping using the CPACF wrapping keyUp to 8 chars in set of [A-Za-z0-9. ](lower case chars converted to upper case) to pass to machine loader, boot manager, and guest kernelqobject_unref_implqobject_typeconfig_parse_qdict_sectionqmp_query_command_line_optionsqemu_find_opts_singletonfind_listValue '%s' is too large for parameter '%s'/build/qemu-rbeYHu/qemu-4.2/util/qemu-option.cValue '%s' is out of range for parameter '%s'a non-negative number below 2^64Optional suffix k, M, G, T, P or E means kilo-, mega-, giga-, tera-, peta-
          Source: nginx_kel.16.drBinary or memory string: qemu_cond_wait_func
          Source: nginx_kel.16.drBinary or memory string: qemu_opts_reset
          Source: nginx_kel.16.drBinary or memory string: qemu_vfree
          Source: nginx_kel.16.drBinary or memory string: _TRACE_QEMU_VFIO_RAM_BLOCK_ADDED_EVENT
          Source: nginx_kel.16.drBinary or memory string: /build/qemu-rbeYHu/qemu-4.2/qapi/string-output-visitor.c
          Source: nginx_kel.16.drBinary or memory string: _TRACE_QEMU_VFREE_EVENT
          Source: nginx_kel.16.drBinary or memory string: QEMU_RESERVED_VA
          Source: nginx_kel.16.drBinary or memory string: /build/qemu-rbeYHu/qemu-4.2/target/arm/translate.h
          Source: nginx_kel.16.drBinary or memory string: /build/qemu-rbeYHu/qemu-4.2/hw/core/cpu.c
          Source: nginx_kel.16.drBinary or memory string: -(addr | TARGET_PAGE_MASK) >= size/build/qemu-rbeYHu/qemu-4.2/accel/tcg/user-exec.cqemu:%s received signal outside vCPU context @ pc=0x%lx
          Source: nginx_kel.16.drBinary or memory string: qemu_cond_timedwait_func
          Source: nginx_kel.16.drBinary or memory string: qemu_mutex_lock_func
          Source: nginx_kel.16.drBinary or memory string: /build/qemu-rbeYHu/qemu-4.2/util/error.c
          Source: nginx_kel.16.drBinary or memory string: %02hhx%02hhx%02hhx%02hhx-%02hhx%02hhx-%02hhx%02hhx-%02hhx%02hhx-%02hhx%02hhx%02hhx%02hhx%02hhx%02hhx/build/qemu-rbeYHu/qemu-4.2/util/rcu.crcu_reader.ctr == 0call_rcurcu_register_threadInvalid rangeBad range specifier!is_daemonized()Bad logfile format: %sout_asmtrace:Log items (comma separated):
          Source: nginx_kel.16.drBinary or memory string: qemu_ld_i64
          Source: nginx_kel.16.drBinary or memory string: /build/qemu-rbeYHu/qemu-4.2/qobject/qbool.c
          Source: nginx_kel.16.drBinary or memory string: QEMU_SET_ENV=var1=val2,var2=val2 QEMU_UNSET_ENV=LD_PRELOAD,LD_DEBUG
          Source: nginx_kel.16.drBinary or memory string: qemu_add_drive_opts
          Source: nginx_kel.16.drBinary or memory string: Unknown QEMU_IFLA_BRPORT type %d
          Source: nginx_kel.16.drBinary or memory string: /build/qemu-rbeYHu/qemu-4.2/target/arm/translate.c
          Source: nginx_kel.16.drBinary or memory string: _TRACE_QEMU_VFIO_NEW_MAPPING_EVENT
          Source: nginx_kel.16.drBinary or memory string: qemu_%s_%s_%d.core
          Source: nginx_kel.16.drBinary or memory string: qemu.Supported
          Source: nginx_kel.16.drBinary or memory string: %d@%zu.%06zu:qemu_anon_ram_free ptr %p size %zu
          Source: nginx_kel.16.drBinary or memory string: /build/qemu-rbeYHu/qemu-4.2/linux-user/arm/target_cpu.h
          Source: nginx_kel.16.drBinary or memory string: cpu_write_elf32_qemunote
          Source: nginx_kel.16.drBinary or memory string: qemu.sstep:
          Source: nginx_kel.16.drBinary or memory string: %d@%zu.%06zu:qemu_mutex_locked taken mutex %p (%s:%d)
          Source: nginx_kel.16.drBinary or memory string: qemu_unlock_fd
          Source: nginx_kel.16.drBinary or memory string: qemu.sstep=
          Source: nginx_kel.16.drBinary or memory string: qemu_strtou64
          Source: nginx_kel.16.drBinary or memory string: qemu_icache_linesize_log
          Source: nginx_kel.16.drBinary or memory string: _TRACE_QEMU_FILE_MONITOR_ENABLE_WATCH_EVENT
          Source: nginx_kel.16.drBinary or memory string: QEMU_UNSET_ENV environment variables to set and unset
          Source: nginx_kel.16.drBinary or memory string: qemu_opts_set
          Source: nginx_kel.16.drBinary or memory string: trace_event_name!((uintptr_t)addr & ~qemu_real_host_page_mask)/build/qemu-rbeYHu/qemu-4.2/util/osdep.c!(size & ~qemu_real_host_page_mask)Failed to open /dev/null for OFD lock probing: %s
          Source: nginx_kel.16.drBinary or memory string: qemu_get_cpu
          Source: nginx_kel.16.drBinary or memory string: _TRACE_QEMU_VFIO_DMA_MAP_DSTATE
          Source: nginx_kel.16.drBinary or memory string: tcg_gen_qemu_st_i32
          Source: nginx_kel.16.drBinary or memory string: _ZTI16QEMUDisassembler
          Source: nginx_kel.16.drBinary or memory string: qemu_opts_validate
          Source: nginx_kel.16.drBinary or memory string: qemu_opt_get
          Source: nginx_kel.16.drBinary or memory string: qemu_config_parse
          Source: nginx_kel.16.drBinary or memory string: QEMU_CPU
          Source: nginx_kel.16.drBinary or memory string: More information on the QEMU project at <https://qemu.org>.Reserved virtual address too big
          Source: nginx_kel.16.drBinary or memory string: _TRACE_QEMU_MUTEX_UNLOCK_DSTATE
          Source: nginx_kel.16.drBinary or memory string: _TRACE_QEMU_VFIO_NEW_MAPPING_DSTATE
          Source: nginx_kel.16.drBinary or memory string: /build/qemu-rbeYHu/qemu-4.2/hw/core/hotplug.c
          Source: nginx_kel.16.drBinary or memory string: !((uintptr_t)addr & ~qemu_real_host_page_mask)
          Source: nginx_kel.16.drBinary or memory string: _TRACE_QEMU_CO_MUTEX_UNLOCK_ENTRY_EVENT
          Source: nginx_kel.16.drBinary or memory string: qemu_cpu_is_self
          Source: nginx_kel.16.drBinary or memory string: /build/qemu-rbeYHu/qemu-4.2/util/cacheinfo.c
          Source: nginx_kel.16.drBinary or memory string: _TRACE_QEMU_FILE_MONITOR_ADD_WATCH_EVENT
          Source: nginx_kel.16.drBinary or memory string: set_labelmov_i32movi_i32setcond_i32movcond_i32ld8u_i32ld8s_i32ld16u_i32ld16s_i32st8_i32st16_i32add_i32sub_i32mul_i32div2_i32divu2_i32xor_i32shl_i32shr_i32sar_i32rotl_i32rotr_i32deposit_i32sextract_i32extract2_i32brcond_i32add2_i32sub2_i32mulu2_i32muls2_i32muluh_i32mulsh_i32brcond2_i32setcond2_i32ext8s_i32ext16s_i32ext8u_i32ext16u_i32bswap16_i32bswap32_i32not_i32neg_i32andc_i32orc_i32eqv_i32nand_i32nor_i32mov_i64movi_i64setcond_i64movcond_i64ld8u_i64ld8s_i64ld16u_i64ld16s_i64ld32u_i64ld32s_i64st8_i64st16_i64st32_i64add_i64sub_i64mul_i64div2_i64divu2_i64xor_i64rotl_i64rotr_i64deposit_i64sextract_i64extract2_i64ext_i32_i64extu_i32_i64extrl_i64_i32extrh_i64_i32brcond_i64ext8s_i64ext16s_i64ext32s_i64ext8u_i64ext16u_i64ext32u_i64bswap16_i64bswap32_i64bswap64_i64not_i64neg_i64andc_i64orc_i64eqv_i64nand_i64nor_i64add2_i64sub2_i64mulu2_i64muls2_i64insn_startexit_tbgoto_tbgoto_ptrplugin_cb_startplugin_cb_endqemu_ld_i32qemu_st_i32qemu_ld_i64qemu_st_i64mov_vecdupi_vecdup_vecdup2_vecld_vecst_vecdupm_vecmul_vecneg_vecabs_vecssadd_vecusadd_vecsssub_vecussub_vecsmin_vecumin_vecsmax_vecumax_vecand_vecxor_vecandc_vecorc_vecnot_vecshli_vecshri_vecsari_vecshls_vecshrs_vecsars_vecshlv_vecshrv_vecsarv_veccmp_vecbitsel_veccmpsel_veclast_genericx86_shufps_vecx86_vpblendvb_vecx86_blend_vecx86_packss_vecx86_packus_vecx86_psrldq_vecx86_vperm2i128_vecx86_punpckl_vecx86_punpckh_vecUnrecognized operation %d in do_constant_folding.
          Source: nginx_kel.16.drBinary or memory string: ?/build/qemu-rbeYHu/qemu-4.2/util/unicode.c
          Source: nginx_kel.16.drBinary or memory string: gdbstub: Bad syscall format string '%s'cmd->handler && cmd->cmdvCont;c;C;s;SText=%08x;Data=%08x;Bss=%08xENABLE=%x,NOIRQ=%x,NOTIMER=%xQEMU: Terminated via GDBstubE14E22PacketSize=%x;qXfer:features:read+;multiprocess+halted running%s %s [%s]CPU#%d [%s]target.xml<architecture></architecture><xi:include href="</target>E00p%02x.%02xT%02xthread:%s;m%sQC%sT02W%02xS%02x%08x/%xX%02xsocketacceptsetsockoptmax_pid < UINT32_MAXo.t0l?L?L0L?s0L,L:s0L,L0L,L,o0?.l0qemu.sstep:sThreadInfofThreadInfoThreadExtraInfo,OffsetsSupported:Xfer:features:read:s:l,l0Attached:Attachedqemu.Supportedqemu.sstepbitsqemu.sstepqemu.sstep=Cont?ContAttach;Kill;
          Source: nginx_kel.16.drBinary or memory string: _TRACE_QEMU_FILE_MONITOR_NEW_DSTATE
          Source: nginx_kel.16.drBinary or memory string: qemu_loglevel
          Source: nginx_kel.16.drBinary or memory string: qemu_find_opts_err
          Source: nginx_kel.16.drBinary or memory string: qemu_opts_do_parse
          Source: nginx_kel.16.drBinary or memory string: qemu_fdatasync
          Source: nginx_kel.16.drBinary or memory string: /build/qemu-rbeYHu/qemu-4.2/util/cutils.c
          Source: nginx_kel.16.drBinary or memory string: /build/qemu-rbeYHu/qemu-4.2/util/module.c
          Source: nginx_kel.16.drBinary or memory string: QEMU_AES_set_decrypt_key
          Source: nginx_kel.16.drBinary or memory string: do_recip_sqrt_estimateround_to_infsoftfloat_to_vfp_compare/build/qemu-rbeYHu/qemu-4.2/target/arm/cpu.cThe 'host' CPU type can only be used with KVMAArch64 CPUs must have both VFP and Neon or neither!tcg_enabled() || no_aa32 || cpu_isar_feature(arm_div, cpu)!tcg_enabled() || no_aa32 || cpu_isar_feature(jazelle, cpu)!(arm_feature(env, ARM_FEATURE_VFP) && arm_feature(env, ARM_FEATURE_XSCALE))This CPU requires a smaller page size than the system is usingPMSAv7 MPU #regions invalid %us%02d=%08x s%02d=%08x d%02d=%016lx
          Source: nginx_kel.16.drBinary or memory string: /build/qemu-rbeYHu/qemu-4.2/exec.c-cpu option cannot be emptyunable to find CPU model '%s'qemu: fatal: parse_cpu_optioncpu_exec_realizefncpu_exec_unrealizefn/build/qemu-rbeYHu/qemu-4.2/tcg/i386/tcg-target.inc.c/build/qemu-rbeYHu/qemu-4.2/tcg/tcg.caligned < tcg_init_ctx.code_gen_buffer + sizesize <= s->code_gen_buffer_sizes->tb_jmp_reset_offset[which] == offOP after optimization and liveness analysis:
          Source: nginx_kel.16.drBinary or memory string: qemu_vfio_do_mapping
          Source: nginx_kel.16.drBinary or memory string: qemu_file_monitor_event
          Source: nginx_kel.16.drBinary or memory string: qemu_mprotect_rwx
          Source: nginx_kel.16.drBinary or memory string: _TRACE_QEMU_COROUTINE_TERMINATE_DSTATE
          Source: nginx_kel.16.drBinary or memory string: qemu_rec_mutex_trylock_func
          Source: nginx_kel.16.drBinary or memory string: Cannot get random bytes: %s/build/qemu-rbeYHu/qemu-4.2/crypto/random-gnutls.cqcrypto_random_bytesUnable to initialize GNUTLS library: %s/build/qemu-rbeYHu/qemu-4.2/crypto/init.cqcrypto_init%d@%zu.%06zu:visit_free v=%p
          Source: nginx_kel.16.drBinary or memory string: _TRACE_QEMU_SYSTEM_POWERDOWN_REQUEST_DSTATE
          Source: nginx_kel.16.drBinary or memory string: /build/qemu-rbeYHu/qemu-4.2/target/arm/vfp_helper.c
          Source: nginx_kel.16.drBinary or memory string: uleb128_encode_smallparse_uintqemu_strtou64qemu_strtoi64qemu_strtoulqemu_strtolqemu_strtouicheck_strtox_errorqemu_strtoido_strtosz/build/qemu-rbeYHu/qemu-4.2/util/cutils.c(unsigned) base <= 36 && base != 1ep >= nptrmul >= 0n <= 0x3fff%s not in [0, %d]%0.3g %sBKiMiGiTiPiEi
          Source: nginx_kel.16.drBinary or memory string: qemu_set_block
          Source: nginx_kel.16.drBinary or memory string: /build/qemu-rbeYHu/qemu-4.2/linux-user/mmap.c
          Source: nginx_kel.16.drBinary or memory string: qemu_thread_atexit_add
          Source: nginx_kel.16.drBinary or memory string: tcg_gen_qemu_ld_i32
          Source: nginx_kel.16.drBinary or memory string: /build/qemu-rbeYHu/qemu-4.2/qobject/json-streamer.c
          Source: nginx_kel.16.drBinary or memory string: marvell,xscaleintel,sa1100arm,arm11mpcorearm,arm1176arm,arm1136arm,arm946arm,arm926iwmmxt%s-arm-cpuv8M SAU #regions invalid %uqemu,unknownarm,cortex-a15arm,cortex-a9arm,cortex-a8arm,cortex-a7arm,arm1026NS unpriv-threadR%02d=%08xXPSR=%08x %c%c%c%c %c %s%s
          Source: nginx_kel.16.drBinary or memory string: qemu_sem_init
          Source: nginx_kel.16.drBinary or memory string: qemu_fork
          Source: nginx_kel.16.drBinary or memory string: qemu_ram_mmap
          Source: nginx_kel.16.drBinary or memory string: sextract64extract64deposit64/build/qemu-rbeYHu/qemu-4.2/fpu/softfloat.c!parm->arm_althp
          Source: nginx_kel.16.drBinary or memory string: qemu:%s received signal outside vCPU context @ pc=0x%lx
          Source: nginx_kel.16.drBinary or memory string: /build/qemu-rbeYHu/qemu-4.2/target/arm/tlb_helper.c
          Source: nginx_kel.16.drBinary or memory string: helper_v7m_vlldmhelper_v7m_vlstmhelper_v7m_preserve_fp_statehelper_v7m_blxnshelper_v7m_bxns/build/qemu-rbeYHu/qemu-4.2/trace/control-internal.h/build/qemu-rbeYHu/qemu-4.2/trace/control-target.ctrace_event_get_state_static(ev)%d@%zu.%06zu:guest_cpu_enter cpu=%p
          Source: nginx_kel.16.drBinary or memory string: qemu: unknown option '%s'
          Source: nginx_kel.16.drBinary or memory string: /build/qemu-rbeYHu/qemu-4.2/hw/core/qdev-properties.c
          Source: nginx_kel.16.drBinary or memory string: qemu_mutex_lock_iothread_impl
          Source: nginx_kel.16.drBinary or memory string: qemu_sem_wait
          Source: nginx_kel.16.drBinary or memory string: QEMU_RAND_SEED
          Source: nginx_kel.16.drBinary or memory string: /build/qemu-rbeYHu/qemu-4.2/target/arm/op_helper.c
          Source: nginx_kel.16.drBinary or memory string: qemu_register_reset
          Source: nginx_kel.16.drBinary or memory string: /build/qemu-rbeYHu/qemu-4.2/util/path.c
          Source: nginx_kel.16.drBinary or memory string: ?/build/qemu-rbeYHu/qemu-4.2/util/qsp.cType Object Call site%*s Wait Time (s) Count Average (us)
          Source: nginx_kel.16.drBinary or memory string: qemu_cond_init
          Source: nginx_kel.16.drBinary or memory string: _ZN16QEMUDisassembler13ProcessOutputEPKN4vixl11InstructionE
          Source: nginx_kel.16.drBinary or memory string: _TRACE_QEMU_ANON_RAM_FREE_EVENT
          Source: nginx_kel.16.drBinary or memory string: 16QEMUDisassembler
          Source: nginx_kel.16.drBinary or memory string: /build/qemu-rbeYHu/qemu-4.2/util/guest-random.c
          Source: nginx_kel.16.drBinary or memory string: host_start || host_sizeInvalid PT_INTERP entryMultiple PT_INTERP entriescannot mmap brkv7mlv8lv5lv4lmmap stack/usr/lib/libc.so.1/usr/lib/ld.so.1unable to get current timestamp: %s/build/qemu-rbeYHu/qemu-4.2/linux-user/elfload.cReserved 0x%lx bytes of guest address space
          Source: nginx_kel.16.drBinary or memory string: qemu_uuid_parse
          Source: nginx_kel.16.drBinary or memory string: _TRACE_QEMU_FILE_MONITOR_REMOVE_WATCH_EVENT
          Source: nginx_kel.16.drBinary or memory string: qemu: fatal:
          Source: nginx_kel.16.drBinary or memory string: qemu_strtol
          Source: nginx_kel.16.drBinary or memory string: qemu_irq_split
          Source: nginx_kel.16.drBinary or memory string: qemu_strtoi
          Source: nginx_kel.16.drBinary or memory string: Copyright (c) 2003-2019 Fabrice Bellard and the QEMU Project developers
          Source: nginx_kel.16.drBinary or memory string: /build/qemu-rbeYHu/qemu-4.2/disas/arm.c
          Source: nginx_kel.16.drBinary or memory string: _TRACE_QEMU_AIO_COROUTINE_ENTER_DSTATE
          Source: nginx_kel.16.drBinary or memory string: 'Vd.%%s, {'Vn.16b, v%d.16b}, 'Vmb, v%d.16b, v%d.16b, v%d.16b}, '/build/qemu-rbeYHu/qemu-4.2/hw/core/qdev.cobject_dynamic_cast(OBJECT(dev), TYPE_SYS_BUS_DEVICE)Unknown device '%s' for bus '%s'Unknown device '%s' for default sysbusInitialization of device %s failed: gpio_list->num_out == 0 || !namegpio_list->num_in == 0 || !namen >= 0 && n < gpio_list->num_inDevice '%s' does not support hotpluggingDevice %s is not migratable, but --only-migratable was specifiedchild[%d]hotpluggabledev->canonical_pathsys-bus-device!dev->realizedunnamed-gpio-in%s[%u]unnamed-gpio-out%s[%d]hotpluggedlegacy-%sparent_bus/machine/unattachednon-qdev-gpio[*]device[%d]qdev_get_legacy_propertydevice_get_realizedcheck_only_migratabledevice_set_realizeddevice_get_hotpluggabledevice_get_hotpluggeddevice_initfndevice_post_initdevice_finalizedevice_unparentdevice_class_initdevice_class_base_initdevice_resetqdev_alias_all_propertiesqdev_get_dev_pathqdev_get_gpio_in_namedqdev_init_gpio_out_namedqdev_init_gpio_in_named_with_opaqueqdev_init_nofailqdev_reset_all_fnqbus_reset_oneqdev_hotplug_allowedqdev_get_machine_hotplug_handlerqdev_set_legacy_instance_idqdev_try_createqdev_get_vmsd/build/qemu-rbeYHu/qemu-4.2/hw/core/qdev-properties.cAttempt to set link property '%s' on device '%s' (type '%s') after it was realizedprop->info == &qdev_prop_bit64Attempt to set property '%s' on device '%s' (type '%s') after it was realizedAttempt to set property '%s' on anonymous device (type '%s') after it was realizedProperty %s.%s doesn't take value %ld (minimum: %ld, maximum: %ld)Property %s.%s doesn't take value '%ld', it's not a power of 2array size property %s may not be set more than oncestrncmp(name, PROP_ARRAY_LEN_PREFIX, strlen(PROP_ARRAY_LEN_PREFIX)) == 0Property '%s.%s' can't take value '%s', it's in useProperty '%s.%s' doesn't take value '%s'Property '%s.%s' can't find value '%s'prop && prop->info == &qdev_prop_ptrglobal %s.%s has invalid class nameoff/auto/bar0/bar1/bar2/bar3/bar4/bar5UUID (aka GUID) or "auto" for random value (default)Address (bus/device/function) of the host device, example: 04:10.0A power of two between 512 and 32768Slot and optional function number, example: 06.0 or 06FDC drive type, 144/288/120/none/autoLogical CHS translation algorithm, auto/none/lba/large/rechsError handling policy, report/ignore/enospc/stop/autoEthernet 6-byte MAC Address, example: 52:54:00:12:34:56%02x:%02x:%02x:%02x:%02x:%02x%04x:%02x:%02x.%0drc == sizeof(buffer) - 1prop->info == &qdev_prop_bit<unset>%02x.%xlen-Parameter '%s' expects %spci_devfn%x.%x%nglobal %s.%s=%s not usedPCIELinkWidth1/2/4/8/12/16/32PCIELinkSpeed2_5/5/8/16OffAutoPCIBARFdcDriveTypeBiosAtaTranslationBlockdevOnErrorLostTickPolicyOnOffAutoon/off/autoon/off
          Source: nginx_kel.16.drBinary or memory string: qemu_system_powerdown_request
          Source: nginx_kel.16.drBinary or memory string: qemu_strtod
          Source: nginx_kel.16.drBinary or memory string: attempt to add duplicate property '%s' to class (type '%s')attempt to add duplicate property '%s' to object (type '%s')Insufficient permission to perform this operationInvalid parameter type for '%s', expected: %sProperty %s on %s is not '%s' enum typechild object is already parentedPath '%s' does not uniquely identify an objectobject_class_property_set_descriptionobject_resolve_path_typeobject_get_canonical_path_componentobject_resolve_linkobject_property_add_childobject_property_get_enumobject_property_get_uintobject_property_get_intqobject_typeobject_property_get_boolobject_property_get_linkobject_property_get_strqobject_unref_implobject_property_setobject_property_getobject_property_delobject_class_property_findobject_property_findobject_class_property_addobject_property_addobject_finalizeobject_unrefobject_set_propvobject_new_with_propvobject_new_with_typetype_is_ancestortype_initializetype_initializeobject_initialize_with_typeobject_set_accelerator_compat_propsobject_set_machine_compat_propstype_get_parentobject_type_get_instance_sizetype_table_addtype_newtype_register/build/qemu-rbeYHu/qemu-4.2/qom/container.cparts != NULL && parts[0] != NULL && !parts[0][0]container_get/build/qemu-rbeYHu/qemu-4.2/qom/object_interfaces.cobject type '%s' isn't supported by object-addList of user creatable objects:object '%s' is in use, can not be deletedqdictqom-typeParameter '%s' is missing %s=<%s> - %s%s options:
          Source: nginx_kel.16.drBinary or memory string: qemu_lock_fd_test
          Source: nginx_kel.16.drBinary or memory string: /build/qemu-rbeYHu/qemu-4.2/stubs/monitor.c
          Source: nginx_kel.16.drBinary or memory string: qemu_thread_exit
          Source: nginx_kel.16.drBinary or memory string: _ZTV16QEMUDisassembler
          Source: nginx_kel.16.drBinary or memory string: qemu_thread_join
          Source: nginx_kel.16.drBinary or memory string: qemu_strtosz_metric
          Source: nginx_kel.16.drBinary or memory string: /build/qemu-rbeYHu/qemu-4.2/tcg/tcg-op.c
          Source: nginx_kel.16.drBinary or memory string: qemu_module_dummyModule is not supported by system.
          Source: nginx_kel.16.drBinary or memory string: qemu_file_monitor_remove_watch
          Source: nginx_kel.16.drBinary or memory string: /build/qemu-rbeYHu/qemu-4.2/util/log.c
          Source: nginx_kel.16.drBinary or memory string: in_asmop_optop_indfpulog MMU-related activitiespcallunimpguest_errorsnochainInvalid number to the left of %.*s/build/qemu-rbeYHu/qemu-4.2/util/log.cInvalid number to the right of %.*sshow generated host assembly code for each compiled TBtrace:PATTERN enable trace events
          Source: nginx_kel.16.drBinary or memory string: qemu_opt_iter_next
          Source: nginx_kel.16.drBinary or memory string: qemu_find_opts
          Source: nginx_kel.16.drBinary or memory string: /build/qemu-rbeYHu/qemu-4.2/qapi/qobject-output-visitor.c
          Source: nginx_kel.16.drBinary or memory string: qemu_sem_post
          Source: nginx_kel.16.drBinary or memory string: qemu_event_reset
          Source: nginx_kel.16.drBinary or memory string: qemu_anon_ram_alloc
          Source: nginx_kel.16.drBinary or memory string: _TRACE_QEMU_CO_MUTEX_LOCK_UNCONTENDED_DSTATE
          Source: nginx_kel.16.drBinary or memory string: qemu_uuid_unparse
          Source: nginx_kel.16.drBinary or memory string: !permit_abbrev || list->implied_opt_name!defaults || list->merge_listsa number*p == '='bool (on/off)Options:No options available.opts_accepts_any(opts)!errp || !*errpan identifierDuplicate ID '%s' for %s,id=id=%s%s%s=%s%s=%ld%s%s=%sopts != NULLqemu_opts_foreachqemu_opts_validateqemu_opts_validateqobject_typeqemu_opts_from_qdictqemu_opts_set_defaultsopts_parseopts_do_parseqemu_opts_createqemu_opt_foreachqemu_opt_set_numberqemu_opt_set_boolopt_setqemu_opt_unsetqemu_opt_get_size_helperparse_option_numberqemu_opt_get_number_helperparse_option_boolqemu_opt_get_bool_helperopt_type_to_stringqemu_opts_print_helpparse_option_sizeindex >= 0!elt[nelt-1]Parameter '%s%d' missing fragment=,s + len <= key_endkey != implied_keyInvalid parameter '%.*s'cur!*slistified == QOBJECT(qdict)Parameters '%.*s.*' used inconsistently/build/qemu-rbeYHu/qemu-4.2/util/keyval.cParameters '%s*' used inconsistentlyParameter%s '%.*s' is too longExpected '=' after parameter '%.*s'qobject_unref_implkeyval_listifykeyval_listifykeyval_parse_putqobject_typekeyval_parse_onekeyval_parse_onekeyval_parse
          Source: nginx_kel.16.drBinary or memory string: qemu_thread_is_self
          Source: nginx_kel.16.drBinary or memory string: qemu_opt_get_bool
          Source: nginx_kel.16.drBinary or memory string: qemu_opts_find
          Source: nginx_kel.16.drBinary or memory string: /build/qemu-rbeYHu/qemu-4.2/qom/container.c
          Source: nginx_kel.16.drBinary or memory string: /build/qemu-rbeYHu/qemu-4.2/qobject/qstring.c
          Source: nginx_kel.16.drBinary or memory string: qemu_log_close
          Source: nginx_kel.16.drBinary or memory string: qemu_set_irq
          Source: nginx_kel.16.drBinary or memory string: /build/qemu-rbeYHu/qemu-4.2/qobject/block-qdict.c
          Source: nginx_kel.16.drBinary or memory string: qemu_extend_irqs
          Source: nginx_kel.16.drBinary or memory string: qemu_anon_ram_free
          Source: nginx_kel.16.drBinary or memory string: /build/qemu-rbeYHu/qemu-4.2/target/arm/op_helper.c!arm_is_secure(env) && arm_current_el(env) != 3!excp_is_internal(excp)
          Source: nginx_kel.16.drBinary or memory string: /build/qemu-rbeYHu/qemu-4.2/cpus-common.c
          Source: nginx_kel.16.drBinary or memory string: # qemu config file
          Source: nginx_kel.16.drBinary or memory string: _TRACE_QEMU_SYSTEM_SHUTDOWN_REQUEST_EVENT
          Source: nginx_kel.16.drBinary or memory string: _TRACE_QEMU_COROUTINE_YIELD_EVENT
          Source: nginx_kel.16.drBinary or memory string: /build/qemu-rbeYHu/qemu-4.2/include/qemu/rcu.h
          Source: nginx_kel.16.drBinary or memory string: qemu_opt_get_size_helper
          Source: nginx_kel.16.drBinary or memory string: qemu_mutex_lock_impl
          Source: nginx_kel.16.drBinary or memory string: qemu_st_i32
          Source: nginx_kel.16.drBinary or memory string: qemu_strtod_finite
          Source: nginx_kel.16.drBinary or memory string: qemu_file_monitor_disable_watch
          Source: nginx_kel.16.drBinary or memory string: qemu_write_pidfile
          Source: nginx_kel.16.drBinary or memory string: _ZN16QEMUDisassemblerD1Ev
          Source: nginx_kel.16.drBinary or memory string: qemu_printf
          Source: nginx_kel.16.drBinary or memory string: /build/qemu-rbeYHu/qemu-4.2/util/qemu-config.c
          Source: nginx_kel.16.drBinary or memory string: qemu_find_opts_singleton
          Source: nginx_kel.16.drBinary or memory string: /build/qemu-rbeYHu/qemu-4.2/include/exec/user/thunk.h
          Source: nginx_kel.16.drBinary or memory string: /build/qemu-rbeYHu/qemu-4.2/include/qapi/qmp/qobject.h
          Source: nginx_kel.16.drBinary or memory string: %d@%zu.%06zu:qemu_memalign alignment %zu size %zu ptr %p
          Source: nginx_kel.16.drBinary or memory string: /build/qemu-rbeYHu/qemu-4.2/util/qemu-error.c
          Source: nginx_kel.16.drBinary or memory string: QEMU_STRACE
          Source: nginx_kel.16.drBinary or memory string: qemu-arm version 4.2.1 (Debian 1:4.2-3ubuntu6.17)
          Source: nginx_kel.16.drBinary or memory string: /build/qemu-rbeYHu/qemu-4.2/util/osdep.c
          Source: nginx_kel.16.drBinary or memory string: qemu_mutex_destroy
          Source: nginx_kel.16.drBinary or memory string: tcg_gen_qemu_ld_i64
          Source: nginx_kel.16.drBinary or memory string: _TRACE_QEMU_VFIO_DMA_MAP_EVENT
          Source: nginx_kel.16.drBinary or memory string: _TRACE_QEMU_MUTEX_UNLOCK_EVENT
          Source: nginx_kel.16.drBinary or memory string: qemu_st_i64
          Source: nginx_kel.16.drBinary or memory string: /build/qemu-rbeYHu/qemu-4.2/util/oslib-posix.c%d@%zu.%06zu:qemu_memalign alignment %zu size %zu ptr %p
          Source: nginx_kel.16.drBinary or memory string: Please report this to qemu-devel@nongnu.org
          Source: nginx_kel.16.drBinary or memory string: /build/qemu-rbeYHu/qemu-4.2/target/arm/helper.c
          Source: nginx_kel.16.drBinary or memory string: Unknown host QEMU_IFLA type: %d
          Source: nginx_kel.16.drBinary or memory string: qemu_module_dummy
          Source: nginx_kel.16.drBinary or memory string: sstepbits;sstep/build/qemu-rbeYHu/qemu-4.2/include/exec/user/thunk.h/build/qemu-rbeYHu/qemu-4.2/thunk.c*type_ptr < max_struct_entriesid < max_struct_entriesnb_fields > 0Invalid type 0x%x
          Source: nginx_kel.16.drBinary or memory string: _TRACE_QEMU_COROUTINE_YIELD_DSTATE
          Source: nginx_kel.16.drBinary or memory string: qemu_log_needs_buffers
          Source: nginx_kel.16.drBinary or memory string: /build/qemu-rbeYHu/qemu-4.2/accel/tcg/cpu-exec.c
          Source: nginx_kel.16.drBinary or memory string: /build/qemu-rbeYHu/qemu-4.2/accel/tcg/user-exec.c
          Source: nginx_kel.16.drBinary or memory string: regime_elaarch64_sync_64_to_32usrfiqirqsvc??????monabt??????hypund?????????sysadd_cpreg_to_hashtableadd_cpreg_to_hashtabledefine_one_arm_cp_reg_with_opaquedefine_debug_regspmevcntr_rawreadpmevcntr_rawwriteupdate_spselaccess_el3_aa32nshcr_writeregister_cp_regs_for_featuressve_zcr_get_valid_lenarm_el_is_aa64init_cpreg_listraw_writeraw_read/build/qemu-rbeYHu/qemu-4.2/target/arm/vfp_helper.c256 <= estimate && estimate < 512arm: unimplemented rounding mode: %d
          Source: nginx_kel.16.drBinary or memory string: QEMU_MODULE_DIR
          Source: nginx_kel.16.drBinary or memory string: qemu_opts_append
          Source: nginx_kel.16.drBinary or memory string: qemu_icache_linesize
          Source: nginx_kel.16.drBinary or memory string: QEMU_AES_encrypt
          Source: nginx_kel.16.drBinary or memory string: qemu_has_ofd_lock
          Source: nginx_kel.16.drBinary or memory string: qemu_close
          Source: nginx_kel.16.drBinary or memory string: tb->cflags & CF_NOCACHEqemu_mutex_iothread_locked()%-*s %-*s %-*s %s
          Source: nginx_kel.16.drBinary or memory string: /build/qemu-rbeYHu/qemu-4.2/fpu/softfloat.c
          Source: nginx_kel.16.drBinary or memory string: /build/qemu-rbeYHu/qemu-4.2/qobject/qnum.c
          Source: nginx_kel.16.drBinary or memory string: set the elf interpreter prefix to 'path'set the stack size to 'size' bytesselect CPU (-cpu help for list)sets targets environment variable (see below)unsets targets environment variable (see below)forces target process argv[0] to be 'argv0'set qemu uname release string to 'uname'set guest_base address to 'address'reserve 'size' bytes for guest virtual address spaceenable logging of specified items (use '-d help' for a list of items)filter logging based on address rangewrite logs to 'logfile' (default stderr)set the host page size to 'pagesize'Seed for pseudo-random number generator[[enable=]<pattern>][,events=<file>][,file=<file>]display version information and exitprint this helpEnv-variableArgument%-*s %-*s Description
          Source: nginx_kel.16.drBinary or memory string: _ZN16QEMUDisassemblerD0Ev
          Source: nginx_kel.16.drBinary or memory string: qemu_cond_destroy
          Source: nginx_kel.16.drBinary or memory string: qemu_opts_parse_noisily
          Source: nginx_kel.16.drBinary or memory string: module_load_file/build/qemu-rbeYHu/qemu-4.2/util/cacheinfo.c(isize & (isize - 1)) == 0(dsize & (dsize - 1)) == 0init_cache_info/build/qemu-rbeYHu/qemu-4.2/util/error.cerr && errp != &error_abort && errp != &error_fatalUnexpected error in %s() at %s:%d:
          Source: nginx_kel.16.drBinary or memory string: qemu_oom_check
          Source: nginx_kel.16.drBinary or memory string: object '%s' not founduser_creatable_delqobject_unref_impluser_creatable_add_optsuser_creatable_add_typeuser_creatable_add_typeuser_creatable_can_be_deleteduser_creatable_complete/build/qemu-rbeYHu/qemu-4.2/crypto/aes.cin && out && keyin && out && key && ivecQEMU_AES_cbc_encryptQEMU_AES_decryptQEMU_AES_encrypt
          Source: nginx_kel.16.drBinary or memory string: /build/qemu-rbeYHu/qemu-4.2/qapi/opts-visitor.c
          Source: nginx_kel.16.drBinary or memory string: qemu_uuid_unparse_strdup
          Source: nginx_kel.16.drBinary or memory string: qemu: unhandled CPU exception 0x%x - aborting
          Source: nginx_kel.16.drBinary or memory string: qemu_rec_mutex_init
          Source: nginx_kel.16.drBinary or memory string: qemu_semihosting_console_outc
          Source: nginx_kel.16.drBinary or memory string: only QEMU supports file descriptor passing
          Source: nginx_kel.16.drBinary or memory string: qemu_opt_set
          Source: nginx_kel.16.drBinary or memory string: qemu_opt_find
          Source: nginx_kel.16.drBinary or memory string: /build/qemu-rbeYHu/qemu-4.2/trace/control-internal.h
          Source: nginx_kel.16.drBinary or memory string: qemu_mprotect__osdep
          Source: nginx_kel.16.drBinary or memory string: qemu_uuid_is_equal
          Source: nginx_kel.16.drBinary or memory string: _TRACE_QEMU_VFIO_DMA_RESET_TEMPORARY_EVENT
          Source: nginx_kel.16.drBinary or memory string: qemu_read_config_file
          Source: nginx_kel.16.drBinary or memory string: _TRACE_QEMU_VFIO_DO_MAPPING_DSTATE
          Source: nginx_kel.16.drBinary or memory string: helper_access_check_cp_reghelper_access_check_cp_reghelper_mrs_bankedhelper_msr_bankedbank_numberhelper_exception_internalcpu_has_workdo_raise_exception/build/qemu-rbeYHu/qemu-4.2/target/arm/crypto_helper.cdecrypt < 2imm2 < 4helper_crypto_sm3tthelper_crypto_sm3tthelper_crypto_sha1_3reg
          Source: nginx_kel.16.drBinary or memory string: /build/qemu-rbeYHu/qemu-4.2/target/arm/crypto_helper.c
          Source: nginx_kel.16.drBinary or memory string: /build/qemu-rbeYHu/qemu-4.2/qobject/qdict.c
          Source: nginx_kel.16.drBinary or memory string: qemu_set_dfilter_ranges
          Source: nginx_kel.16.drBinary or memory string: qemu_file_monitor_add_watch
          Source: nginx_kel.16.drBinary or memory string: /build/qemu-rbeYHu/qemu-4.2/exec.c
          Source: nginx_kel.16.drBinary or memory string: qemu_strtosz_MiB
          Source: nginx_kel.16.drBinary or memory string: handle_cpu_signalprobe_accessqemu-arm version 4.2.1 (Debian 1:4.2-3ubuntu6.17)
          Source: nginx_kel.16.drBinary or memory string: /build/qemu-rbeYHu/qemu-4.2/qapi/qapi-visit-core.c
          Source: nginx_kel.16.drBinary or memory string: _TRACE_QEMU_FILE_MONITOR_DISABLE_WATCH_DSTATE
          Source: nginx_kel.16.drBinary or memory string: is_power_of_2(align)align >= pagesize/proc/self/fd/%dqemu_ram_mmap-._id_subsys_str[id]%c%s%lu%02d/build/qemu-rbeYHu/qemu-4.2/util/id.cid < ARRAY_SIZE(id_subsys_str)id_generate%s%.*f,%.*f%s(empty)%s%s%s%s%s
          Source: SecuriteInfo.com.Other.Malware-gen.3200.4135.elf, 6208.1.0000557fcedd4000.0000557fcef22000.rw-.sdmp, SecuriteInfo.com.Other.Malware-gen.3200.4135.elf, 6227.1.0000557fcedd4000.0000557fcef02000.rw-.sdmp, SecuriteInfo.com.Other.Malware-gen.3200.4135.elf, 6241.1.0000557fcedd4000.0000557fcef02000.rw-.sdmp, SecuriteInfo.com.Other.Malware-gen.3200.4135.elf, 6293.1.0000557fcedd4000.0000557fcef22000.rw-.sdmp, systemd, 6446.1.000055a0faacd000.000055a0fab0f000.rw-.sdmp, nginx_kel, 6446.1.000055a0faacd000.000055a0fab0f000.rw-.sdmp, systemd, 6491.1.00005580069e5000.0000558006a27000.rw-.sdmp, nginx_kel, 6491.1.00005580069e5000.0000558006a27000.rw-.sdmpBinary or memory string: U!/etc/qemu-binfmt/arm
          Source: nginx_kel.16.drBinary or memory string: /build/qemu-rbeYHu/qemu-4.2/thunk.c
          Source: nginx_kel.16.drBinary or memory string: qemu_strsep
          Source: nginx_kel.16.drBinary or memory string: qemu.sstepbits
          Source: nginx_kel.16.drBinary or memory string: qemu_co_mutex_unlock_return
          Source: nginx_kel.16.drBinary or memory string: QEMU_TRACE
          Source: nginx_kel.16.drBinary or memory string: qemu_opt_iter_init
          Source: nginx_kel.16.drBinary or memory string: /build/qemu-rbeYHu/qemu-4.2/include/qemu/range.h
          Source: nginx_kel.16.drBinary or memory string: qemu_mempath_getpagesize
          Source: nginx_kel.16.drBinary or memory string: arm_cpu_instance_initcpu_register_class_initarm926_initfnarm946_initfnarm1026_initfnarm1136_r2_initfnarm1136_initfnarm1176_initfnarm11mpcore_initfncortex_m0_initfnarm_v7m_cpu_exec_interruptarm_v7m_class_initcortex_m3_initfncortex_m4_initfncortex_m33_initfncortex_r5_initfncortex_r5f_initfncortex_a7_initfncortex_a8_initfncortex_a9_initfncortex_a15_initfnti925t_initfnsa1100_initfnsa1110_initfnpxa250_initfnpxa255_initfnpxa260_initfnpxa261_initfnpxa262_initfnpxa270a0_initfnpxa270a1_initfnpxa270b0_initfnpxa270b1_initfnpxa270c0_initfnpxa270c5_initfnarm_max_initfnarm_cpu_initfnarm_cpu_finalizefnarm_cpu_realizefnarm_cpu_realizefncp_reg_check_resetarm_cpu_resetarm_cpu_has_workusrfiqirqsvc??????monabt??????hypund?????????sysaarch64_cpu_dump_statearm_cpu_dump_statearm_cpu_set_pcarm_cpu_synchronize_from_tbarm_gdb_arch_namearm_disas_set_infoarm_cpu_class_initarm_get_pmuarm_set_pmuarm_get_init_svtorarm_set_init_svtorarm_cpu_post_initarm_excp_unmaskedarm_cpu_exec_interrupt<reg name="%s" bitsize="%d" group="cp_regs"/><?xml version="1.0"?></feature>/build/qemu-rbeYHu/qemu-4.2/target/arm/gdbstub.c<!DOCTYPE target SYSTEM "gdb-target.dtd"><feature name="org.qemu.gdb.arm.sys.regs">arm_gdb_get_dynamic_xmlarm_register_sysreg_for_xmlarm_gen_dynamic_xmlarm_cpu_gdb_write_registerarm_cpu_gdb_read_register/build/qemu-rbeYHu/qemu-4.2/target/arm/tlb_helper.carm_cpu_tlb_fill/build/qemu-rbeYHu/qemu-4.2/target/arm/debug_helper.c
          Source: nginx_kel.16.drBinary or memory string: qemu_opt_get_bool_helper
          Source: nginx_kel.16.drBinary or memory string: qemu_allocate_irq
          Source: nginx_kel.16.drBinary or memory string: qemu_co_mutex_lock_entry
          Source: nginx_kel.16.drBinary or memory string: Unknown QEMU_IFLA_INFO_KIND %s
          Source: nginx_kel.16.drBinary or memory string: qemu_set_log
          Source: nginx_kel.16.drBinary or memory string: tswap_siginfodo_sigprocmaskProtecting guest commpageVFS: argc is wrong%Y%m%d-%H%M%Sqemu_%s_%s_%d.coreCOREunable to dump %08x
          Source: nginx_kel.16.drBinary or memory string: QEMU_UNSET_ENV
          Source: SecuriteInfo.com.Other.Malware-gen.3200.4135.elf, 6208.1.00007fffe3a8f000.00007fffe3ab0000.rw-.sdmp, SecuriteInfo.com.Other.Malware-gen.3200.4135.elf, 6227.1.00007fffe3a8f000.00007fffe3ab0000.rw-.sdmp, SecuriteInfo.com.Other.Malware-gen.3200.4135.elf, 6241.1.00007fffe3a8f000.00007fffe3ab0000.rw-.sdmp, SecuriteInfo.com.Other.Malware-gen.3200.4135.elf, 6293.1.00007fffe3a8f000.00007fffe3ab0000.rw-.sdmpBinary or memory string: /usr/bin/qemu-arm
          Source: nginx_kel.16.drBinary or memory string: qemu_dcache_linesize
          Source: nginx_kel.16.drBinary or memory string: qemu_accept
          Source: nginx_kel.16.drBinary or memory string: qemu_log_items
          Source: nginx_kel.16.drBinary or memory string: qemu_semihosting_console_outs
          Source: nginx_kel.16.drBinary or memory string: qemu_set_hw_version
          Source: nginx_kel.16.drBinary or memory string: /build/qemu-rbeYHu/qemu-4.2/include/qapi/qmp/qobject.hQTYPE_NONE < obj->base.type && obj->base.type < QTYPE__MAXparent->class_size <= ti->class_sizetype->instance_size >= sizeof(Object)%d@%zu.%06zu:object_dynamic_cast_assert %s->%s (%s:%d:%s)
          Source: nginx_kel.16.drBinary or memory string: qemu_opts_create
          Source: nginx_kel.16.drBinary or memory string: qemu_bql_mutex_lock_func
          Source: nginx_kel.16.drBinary or memory string: qemu_system_shutdown_request
          Source: nginx_kel.16.drBinary or memory string: qemu_opt_get_del
          Source: nginx_kel.16.drBinary or memory string: _TRACE_QEMU_CO_MUTEX_LOCK_RETURN_DSTATE
          Source: nginx_kel.16.drBinary or memory string: QEMU_SINGLESTEP
          Source: nginx_kel.16.drBinary or memory string: qemu_set_log_filename
          Source: nginx_kel.16.drBinary or memory string: qemu_log
          Source: nginx_kel.16.drBinary or memory string: /build/qemu-rbeYHu/qemu-4.2/accel/tcg/translate-all.c
          Source: nginx_kel.16.drBinary or memory string: qemu_pstrcmp0
          Source: nginx_kel.16.drBinary or memory string: print_siginfo TIME_OK (clock synchronized, no leap second) TIME_INS (insert leap second) TIME_DEL (delete leap second) TIME_OOP (leap second in progress) TIME_WAIT (leap second has occurred) TIME_ERROR (clock not synchronized), si_pid=%u, si_uid=%u, si_status=%d, si_utime=%d, si_stime=%d, si_pid=%u, si_uid=%u, si_sigval=%d/build/qemu-rbeYHu/qemu-4.2/linux-user/strace.c{sun_family=AF_UNIX,sun_path="{sin_family=AF_INET,sin_port=htons(%d),sin_addr=inet_addr("%d.%d.%d.%d"){sll_family=AF_PACKET,sll_protocol=htons(0x%04x),if%d,pkttype=,sll_addr=%02x:%02x:%02x:%02x:%02x:%02x:%02x:%02x{nl_family=AF_NETLINK,nl_pid=%u,nl_groups=%u}/build/qemu-rbeYHu/qemu-4.2/linux-user/mmap.ch2g_valid(ptr)h2g_valid(host_start)ret == 0h2g_valid(host_addr)target_mremaptarget_mmapmmap_find_vma%d@%zu.%06zu:user_host_signal env=%p signal %d (target %d(
          Source: nginx_kel.16.drBinary or memory string: !(size & ~qemu_real_host_page_mask)
          Source: nginx_kel.16.drBinary or memory string: qemu_thread_create
          Source: nginx_kel.16.drBinary or memory string: mutex->initializedcond->initializedsem->initializedev->initialized/build/qemu-rbeYHu/qemu-4.2/util/qemu-thread-posix.c%d@%zu.%06zu:qemu_mutex_lock waiting on mutex %p (%s:%d)
          Source: nginx_kel.16.drBinary or memory string: /build/qemu-rbeYHu/qemu-4.2/disas.c
          Source: nginx_kel.16.drBinary or memory string: /build/qemu-rbeYHu/qemu-4.2/tcg/optimize.c/build/qemu-rbeYHu/qemu-4.2/include/qemu/bitops.hstart >= 0 && length > 0 && length <= 64 - start
          Source: nginx_kel.16.drBinary or memory string: qemu_socket
          Source: nginx_kel.16.drBinary or memory string: /build/qemu-rbeYHu/qemu-4.2/qapi/qobject-input-visitor.c
          Source: nginx_kel.16.drBinary or memory string: _TRACE_QEMU_CO_MUTEX_LOCK_ENTRY_DSTATE
          Source: nginx_kel.16.drBinary or memory string: qemu_thread_get_self
          Source: nginx_kel.16.drBinary or memory string: cpu_write_elf64_qemunote
          Source: nginx_kel.16.drBinary or memory string: qemu_vfio_dma_unmap
          Source: nginx_kel.16.drBinary or memory string: 'Vd.%%s, {'Vn.16b, v%d.16b}, 'Vmb, v%d.16b, v%d.16b, v%d.16b}, '/build/qemu-rbeYHu/qemu-4.2/hw/core/qdev.c
          Source: nginx_kel.16.drBinary or memory string: /build/qemu-rbeYHu/qemu-4.2/crypto/aes.c
          Source: nginx_kel.16.drBinary or memory string: _TRACE_QEMU_VFIO_RAM_BLOCK_ADDED_DSTATE
          Source: nginx_kel.16.drBinary or memory string: opt->desc && opt->desc->type == QEMU_OPT_SIZE
          Source: nginx_kel.16.drBinary or memory string: _TRACE_QEMU_VFIO_DMA_UNMAP_DSTATE
          Source: nginx_kel.16.drBinary or memory string: qemu,unknown
          Source: nginx_kel.16.drBinary or memory string: /build/qemu-rbeYHu/qemu-4.2/qapi/string-input-visitor.c
          Source: nginx_kel.16.drBinary or memory string: _TRACE_QEMU_FILE_MONITOR_NEW_EVENT
          Source: nginx_kel.16.drBinary or memory string: qemu_aio_coroutine_enter
          Source: nginx_kel.16.drBinary or memory string: qemu_vprintf
          Source: nginx_kel.16.drBinary or memory string: _TRACE_QEMU_FILE_MONITOR_DISABLE_WATCH_EVENT
          Source: nginx_kel.16.drBinary or memory string: QEMU_ARGV0
          Source: nginx_kel.16.drBinary or memory string: qemu_event_wait
          Source: nginx_kel.16.drBinary or memory string: opt->desc && opt->desc->type == QEMU_OPT_BOOLopt->desc && opt->desc->type == QEMU_OPT_NUMBERopt->desc && opt->desc->type == QEMU_OPT_SIZEIdentifiers consist of letters, digits, '-', '.', '_', starting with a letter.
          Source: nginx_kel.16.drBinary or memory string: QEMU_AES_cbc_encrypt
          Source: nginx_kel.16.drBinary or memory string: /build/qemu-rbeYHu/qemu-4.2/target/arm/gdbstub.c
          Source: nginx_kel.16.drBinary or memory string: /build/qemu-rbeYHu/qemu-4.2/util/keyval.c
          Source: nginx_kel.16.drBinary or memory string: qemu_stamp_fd1e84eabffe4c20c6c5b88917de012e30472846
          Source: nginx_kel.16.drBinary or memory string: qemu_opt_get_bool_del
          Source: nginx_kel.16.drBinary or memory string: Unknown host QEMU_IFLA_INFO type: %d
          Source: nginx_kel.16.drBinary or memory string: qemu_host_page_size
          Source: nginx_kel.16.drBinary or memory string: qobject_typeqdict_from_vjsonf_nofailqobject_from_vjsonf_nofailqobject_unref_implconsume_jsonconsume_jsonqobject_from_jsonv/build/qemu-rbeYHu/qemu-4.2/qobject/qobject.cQTYPE_QNULL < obj->base.type && obj->base.type < QTYPE__MAXQTYPE_NONE < x->base.type && x->base.type < QTYPE__MAX!obj->base.refcntqobject_is_equalqobject_destroyJSON parse error, stray '%s'/build/qemu-rbeYHu/qemu-4.2/qobject/json-streamer.cJSON token size limit exceededJSON token count limit exceededJSON nesting depth limit exceededg_queue_is_empty(&parser->tokens)
          Source: nginx_kel.16.drBinary or memory string: qemu_set_cloexec
          Source: nginx_kel.16.drBinary or memory string: qemu: uncaught target signal %d (%s) - %s
          Source: nginx_kel.16.drBinary or memory string: QEMU_UNAME
          Source: nginx_kel.16.drBinary or memory string: /proc/self/mapsh2g_valid(min) [stack]h2g_valid(max - 1)%ld (%s) 0%c/proc/self/%d//tmpTMPDIR%s/qemu-open.XXXXXXarg_type[0] == TYPE_PTRie->access == IOC_RWie->access == IOC_W*arg_type == TYPE_PTR*arg_type == TYPE_STRUCTse->convert[0] == NULL*field_types == TYPE_PTRVOIDhost_rt_dev_ptr != NULLtarget_rt_dev_ptr != NULLHost cmsg overflow
          Source: nginx_kel.16.drBinary or memory string: _TRACE_QEMU_COROUTINE_TERMINATE_EVENT
          Source: nginx_kel.16.drBinary or memory string: qemu_init_vcpu
          Source: nginx_kel.16.drBinary or memory string: _TRACE_QEMU_FILE_MONITOR_DISPATCH_EVENT
          Source: nginx_kel.16.drBinary or memory string: qemu_mprotect_none
          Source: nginx_kel.16.drBinary or memory string: _TRACE_QEMU_CO_MUTEX_LOCK_UNCONTENDED_EVENT
          Source: nginx_kel.16.drBinary or memory string: _TRACE_QEMU_VFIO_RAM_BLOCK_REMOVED_EVENT
          Source: nginx_kel.16.drBinary or memory string: qemu_vfio_new_mapping
          Source: nginx_kel.16.drBinary or memory string: parse_errorparse_keywordparse_stringparse_literalparse_interpolationparse_arrayqobject_unref_implqobject_typeparse_objectjson_parser_parsetoo many vcpu trace events; dropping '%s'/build/qemu-rbeYHu/qemu-4.2/trace/control.ctrace event '%s' is not traceabletrace event '%s' does not exist%d@%zu.%06zu:guest_cpu_exit cpu=%p
          Source: nginx_kel.16.drBinary or memory string: qemu_vfio_dma_reset_temporary
          Source: nginx_kel.16.drBinary or memory string: qemu_mutex_trylock_impl
          Source: nginx_kel.16.drBinary or memory string: /build/qemu-rbeYHu/qemu-4.2/trace/control-target.c
          Source: nginx_kel.16.drBinary or memory string: qemu_opt_get_number_del
          Source: nginx_kel.16.drBinary or memory string: qemu_memalign
          Source: nginx_kel.16.drBinary or memory string: qemu_opts_absorb_qdict
          Source: nginx_kel.16.drBinary or memory string: %s/qemu-open.XXXXXX
          Source: nginx_kel.16.drBinary or memory string: qemu_opts_loc_restore
          Source: nginx_kel.16.drBinary or memory string: qemu_opts_foreach
          Source: nginx_kel.16.drBinary or memory string: /build/qemu-rbeYHu/qemu-4.2/tcg/tcg-op-gvec.c
          Source: nginx_kel.16.drBinary or memory string: %s: passed inaccessible address %08x/build/qemu-rbeYHu/qemu-4.2/linux-user/arm/semihost.c%s: unexpected write to stdout failureqemu_semihosting_console_outcqemu_semihosting_console_outs
          Source: nginx_kel.16.drBinary or memory string: QEMU_AES_decrypt
          Source: nginx_kel.16.drBinary or memory string: /build/qemu-rbeYHu/qemu-4.2/tcg/i386/tcg-target.inc.c
          Source: nginx_kel.16.drBinary or memory string: _TRACE_QEMU_VFIO_FIND_MAPPING_EVENT
          Source: nginx_kel.16.drBinary or memory string: _TRACE_QEMU_CO_MUTEX_LOCK_ENTRY_EVENT
          Source: nginx_kel.16.drBinary or memory string: /build/qemu-rbeYHu/qemu-4.2/util/mmap-alloc.cWarning: requesting persistence across crashes for backend file %s failed. Proceeding without persistence, data might become corrupted in case of host crash.
          Source: nginx_kel.16.drBinary or memory string: qemu_opts_set_id
          Source: nginx_kel.16.drBinary or memory string: _TRACE_QEMU_FILE_MONITOR_ADD_WATCH_DSTATE
          Source: nginx_kel.16.drBinary or memory string: json_message_parser_flushjson_message_process_tokenJSON parse error, %spremature EOIexpected separator in dictexpecting valueexpected separator in list%lld%lluinvalid interpolation '%s'token*ptr == '"' || *ptr == '\''*ptrcan't interpolate into stringret == -ERANGEinvalid keyword '%s'key is not a string in objectmissing : in object pairMissing value in dictduplicate key/build/qemu-rbeYHu/qemu-4.2/qobject/json-parser.ctoken && token->type == JSON_LCURLYtoken && token->type == JSON_LSQUAREtoken && token->type == JSON_INTERP%.*s is not a valid Unicode characterinvalid escape sequence in stringinvalid UTF-8 sequence in stringtoken && token->type == JSON_KEYWORDctxt.err || g_queue_is_empty(ctxt.buf)
          Source: nginx_kel.16.drBinary or memory string: qemu_file_monitor_new
          Source: nginx_kel.16.drBinary or memory string: qemu_vfio_dma_map
          Source: nginx_kel.16.drBinary or memory string: qemu_write_full
          Source: nginx_kel.16.drBinary or memory string: /build/qemu-rbeYHu/qemu-4.2/hw/core/bus.c
          Source: nginx_kel.16.drBinary or memory string: qemu_madvise
          Source: nginx_kel.16.drBinary or memory string: Unknown QEMU_IFLA_INFO_SLAVE_KIND %s
          Source: nginx_kel.16.drBinary or memory string: qemu_logfile
          Source: nginx_kel.16.drBinary or memory string: qemu_strtoul
          Source: nginx_kel.16.drBinary or memory string: qemu_cond_signal
          Source: nginx_kel.16.drBinary or memory string: qemu_log_in_addr_range
          Source: nginx_kel.16.drBinary or memory string: /build/qemu-rbeYHu/qemu-4.2/include/qemu/rcu.hcc->set_pccc->has_workcpu == current_cpucc == CPU_GET_CLASS(cpu)use_icountp_rcu_reader->depth != 0rcu_read_unlockcpu_handle_debug_exceptioncpu_handle_interruptcpu_loop_exec_tbtb_add_jumpcpu_has_workcpu_execcpu_tb_execcpu_tb_execcpu_exec_step_atomic/build/qemu-rbeYHu/qemu-4.2/accel/tcg/translate-all.cptr_locked == 1 && dest->cflags & CF_INVALIDCould not allocate dynamic translator buffer
          Source: nginx_kel.16.drBinary or memory string: /build/qemu-rbeYHu/qemu-4.2/qobject/qlist.c
          Source: nginx_kel.16.drBinary or memory string: qemu_event_init
          Source: nginx_kel.16.drBinary or memory string: qemu_opt_get_number
          Source: nginx_kel.16.drBinary or memory string: QEMU_LOG_FILENAME
          Source: nginx_kel.16.drBinary or memory string: _ZTS16QEMUDisassembler
          Source: nginx_kel.16.drBinary or memory string: qemu_get_thread_id
          Source: nginx_kel.16.drBinary or memory string: /build/qemu-rbeYHu/qemu-4.2/linux-user/syscall.c
          Source: nginx_kel.16.drBinary or memory string: 9H/build/qemu-rbeYHu/qemu-4.2/target/arm/m_helper.c
          Source: nginx_kel.16.drBinary or memory string: qemu_cond_wait_impl
          Source: nginx_kel.16.drBinary or memory string: qemu_co_mutex_unlock_entry
          Source: nginx_kel.16.drBinary or memory string: %d@%zu.%06zu:qemu_mutex_unlock released mutex %p (%s:%d)
          Source: nginx_kel.16.drBinary or memory string: /build/qemu-rbeYHu/qemu-4.2/tcg/tcg-op.c%d@%zu.%06zu:guest_mem_before_trans cpu=%p info=%d
          Source: nginx_kel.16.drBinary or memory string: usage: qemu-arm [options] program [arguments...]
          Source: nginx_kel.16.drBinary or memory string: /build/qemu-rbeYHu/qemu-4.2/qobject/json-parser.c
          Source: nginx_kel.16.drBinary or memory string: /build/qemu-rbeYHu/qemu-4.2/qapi/qapi-util.c
          Source: nginx_kel.16.drBinary or memory string: qemu_get_local_state_pathname
          Source: nginx_kel.16.drBinary or memory string: qemu_lock_fd
          Source: nginx_kel.16.drBinary or memory string: qemu_irq_intercept_in
          Source: nginx_kel.16.drBinary or memory string: /usr/lib/x86_64-linux-gnu/qemuABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+-.~/build/qemu-rbeYHu/qemu-4.2/util/module.cqemu_stamp_fd1e84eabffe4c20c6c5b88917de012e30472846Failed to initialize module: %s
          Source: nginx_kel.16.drBinary or memory string: /build/qemu-rbeYHu/qemu-4.2/linux-user/arm/semihost.c
          Source: nginx_kel.16.drBinary or memory string: /build/qemu-rbeYHu/qemu-4.2/util/envlist.c
          Source: nginx_kel.16.drBinary or memory string: qemu_set_nonblock
          Source: nginx_kel.16.drBinary or memory string: _TRACE_QEMU_SYSTEM_SHUTDOWN_REQUEST_DSTATE
          Source: nginx_kel.16.drBinary or memory string: qemu_get_exec_dir
          Source: nginx_kel.16.drBinary or memory string: _TRACE_QEMU_AIO_COROUTINE_ENTER_EVENT
          Source: nginx_kel.16.drBinary or memory string: set qemu uname release string to 'uname'
          Source: nginx_kel.16.drBinary or memory string: /build/qemu-rbeYHu/qemu-4.2/linux-user/strace.c
          Source: nginx_kel.16.drBinary or memory string: _TRACE_QEMU_VFIO_DO_MAPPING_EVENT
          Source: nginx_kel.16.drBinary or memory string: QEMU_STACK_SIZE = %ld byte
          Source: nginx_kel.16.drBinary or memory string: /build/qemu-rbeYHu/qemu-4.2/include/hw/core/cpu.h
          Source: nginx_kel.16.drBinary or memory string: qemu_mutex_unlock_iothread
          Source: nginx_kel.16.drBinary or memory string: /build/qemu-rbeYHu/qemu-4.2/gdbstub.c
          Source: nginx_kel.16.drBinary or memory string: qemu_hw_version
          Source: nginx_kel.16.drBinary or memory string: qemu_coroutine_terminate
          Source: nginx_kel.16.drBinary or memory string: tcg_gen_qemu_st_i64
          Source: nginx_kel.16.drBinary or memory string: /build/qemu-rbeYHu/qemu-4.2/util/qemu-option.c
          Source: nginx_kel.16.drBinary or memory string: _TRACE_QEMU_CO_MUTEX_UNLOCK_ENTRY_DSTATE
          Source: nginx_kel.16.drBinary or memory string: qemu_opts_id
          Source: nginx_kel.16.drBinary or memory string: QEMU_STACK_SIZE
          Source: nginx_kel.16.drBinary or memory string: qemu_opt_set_bool
          Source: nginx_kel.16.drBinary or memory string: _TRACE_QEMU_VFIO_RAM_BLOCK_REMOVED_DSTATE
          Source: nginx_kel.16.drBinary or memory string: _TRACE_QEMU_VFIO_DMA_RESET_TEMPORARY_DSTATE
          Source: nginx_kel.16.drBinary or memory string: qemu_ether_ntoa
          Source: nginx_kel.16.drBinary or memory string: /build/qemu-rbeYHu/qemu-4.2/target/arm/arm-semi.c
          Source: nginx_kel.16.drBinary or memory string: MbP?/build/qemu-rbeYHu/qemu-4.2/util/range.c!range_is_empty(a) && !range_is_empty(b)!range_is_empty(data)new_l == listrange_comparerange_invariantrange_list_insertthread_rand == NULLInvalid seed number: %s/build/qemu-rbeYHu/qemu-4.2/util/guest-random.cqemu_guest_random_seed_mainqemu_guest_random_seed_thread_part2guest_user_syscall_retguest_user_syscallguest_mem_before_execguest_mem_before_transguest_cpu_resetguest_cpu_exitguest_cpu_enterqmp_job_dismissqmp_job_finalizeqmp_job_completeqmp_job_resumeqmp_job_pauseqmp_job_canceljob_completedjob_apply_verbjob_state_transitiongdbstub_err_checksum_invalidgdbstub_err_invalid_rlegdbstub_err_invalid_repeatgdbstub_err_overrungdbstub_err_garbagegdbstub_err_got_nackgdbstub_io_got_unexpectedgdbstub_io_got_ackgdbstub_io_commandgdbstub_io_binaryreplygdbstub_io_replygdbstub_hit_unknowngdbstub_hit_watchdoggdbstub_hit_io_errorgdbstub_hit_shutdowngdbstub_hit_pausedgdbstub_hit_breakgdbstub_hit_internal_errorgdbstub_hit_watchpointgdbstub_op_extra_infogdbstub_op_steppinggdbstub_op_continue_cpugdbstub_op_continuegdbstub_op_exitinggdbstub_op_startflatview_destroy_rcuflatview_destroyflatview_newmemory_region_ram_device_readmemory_region_subpage_writememory_region_subpage_readmemory_region_ops_writememory_region_ops_readmemory_notdirty_set_dirtymemory_notdirty_write_accessram_block_discard_rangefind_ram_offset_loopfind_ram_offsetdma_map_waitdma_blk_cbdma_completedma_aio_canceldma_blk_ioqemu_system_powerdown_requestqemu_system_shutdown_requestsystem_wakeup_requestrunstate_setload_filevm_state_notifyballoon_eventcpu_outcpu_ingdbstub_err_checksum_incorrectmemory_region_ram_device_writetranslate_blockexec_tb_exitexec_tb_nocacheexec_tbuser_s390x_restore_sigregsuser_queue_signaluser_host_signaluser_handle_signaluser_force_siguser_do_sigreturnuser_do_rt_sigreturnuser_setup_rt_frameuser_setup_framevisit_type_nullvisit_type_anyvisit_type_numbervisit_type_strvisit_type_boolvisit_type_sizevisit_type_int64visit_type_int32visit_type_int16visit_type_int8visit_type_uint64visit_type_uint32visit_type_uint16visit_type_uint8visit_type_intvisit_type_enumvisit_optionalvisit_end_alternatevisit_start_alternatevisit_end_listvisit_check_listvisit_next_listvisit_start_listvisit_end_structvisit_check_structvisit_start_structvisit_completevisit_freeobject_class_dynamic_cast_assertobject_dynamic_cast_assertqemu_vfio_dma_unmapqemu_vfio_dma_mapqemu_vfio_do_mappingqemu_vfio_new_mappingqemu_vfio_find_mappingqemu_vfio_ram_block_removedqemu_vfio_ram_block_addedqemu_vfio_dma_reset_temporaryqemu_mutex_unlockqemu_mutex_lockedqemu_mutex_locksocket_listenlockcnt_futex_wakelockcnt_futex_wait_resumelockcnt_futex_waitlockcnt_futex_wait_preparelockcnt_unlock_successlockcnt_unlock_attemptlockcnt_fast_path_successlockcnt_fast_path_attempthbitmap_sethbitmap_resethbitmap_iter_skip_wordsqemu_anon_ram_freeqemu_vfreeqemu_anon_ram_allocqemu_memalignqemu_co_mutex_unlock_returnqemu_co_mutex_unlock_entryqemu_co_mutex_lock_returnqemu_co_mutex_lock_entryqemu_coroutine_terminateqe
          Source: nginx_kel.16.drBinary or memory string: qemu_opt_set_number
          Source: nginx_kel.16.drBinary or memory string: /build/qemu-rbeYHu/qemu-4.2/trace/control.c
          Source: nginx_kel.16.drBinary or memory string: QEMU_GDBwait gdb connection to 'port'QEMU_LD_PREFIXQEMU_STACK_SIZEQEMU_CPUmodelQEMU_SET_ENVvar=valueQEMU_UNSET_ENVQEMU_ARGV0argv0QEMU_UNAMEunameQEMU_GUEST_BASEQEMU_RESERVED_VAQEMU_LOGitem[,...]dfilterQEMU_DFILTERrange[,...]QEMU_LOG_FILENAMElogfileQEMU_PAGESIZEsinglestepQEMU_SINGLESTEPrun in singlestep modestraceQEMU_STRACElog system callsQEMU_RAND_SEEDQEMU_TRACEQEMU_VERSION/etc/qemu-binfmt/armarm_max_reserved_va
          Source: nginx_kel.16.drBinary or memory string: qemu_init_cpu_list
          Source: nginx_kel.16.drBinary or memory string: file system may not support O_DIRECT%s: mprotect failed: %s/dev/null/dev/fdset//proc/sys/crypto/fips_enabled2.5+qemu_mprotect__osdep
          Source: nginx_kel.16.drBinary or memory string: /build/qemu-rbeYHu/qemu-4.2/util/id.c
          Source: nginx_kel.16.drBinary or memory string: init_qemu_uname_release
          Source: nginx_kel.16.drBinary or memory string: qemu_get_pid_name
          Source: nginx_kel.16.drBinary or memory string: qemu_thread_atexit_remove
          Source: nginx_kel.16.drBinary or memory string: qemu_mutex_lock
          Source: nginx_kel.16.drBinary or memory string: qemu_cpu_kick
          Source: nginx_kel.16.drBinary or memory string: _TRACE_QEMU_VFIO_DMA_UNMAP_EVENT
          Source: nginx_kel.16.drBinary or memory string: qemu_mutex_iothread_locked
          Source: nginx_kel.16.drBinary or memory string: /build/qemu-rbeYHu/qemu-4.2/qom/object.c
          Source: nginx_kel.16.drBinary or memory string: QEMU_GDB
          Source: nginx_kel.16.drBinary or memory string: qemu_opts_print_help

          Anti Debugging

          barindex
          Source: /tmp/SecuriteInfo.com.Other.Malware-gen.3200.4135.elf (PID: 6212)Process with PPID: /bin/sh -> sh -c "mount -o bind /tmp/nginx_server /proc/6208/ > /dev/null 2>&1"Jump to behavior
          Source: /tmp/SecuriteInfo.com.Other.Malware-gen.3200.4135.elf (PID: 6244)Process with PPID: /bin/sh -> sh -c "mount -o bind /tmp/nginx_server /proc/6240/ > /dev/null 2>&1"Jump to behavior

          HIPS / PFW / Operating System Protection Evasion

          barindex
          Source: TrafficDNS traffic detected: queries for: 60da859e8a.dontargetme.nl
          Source: TrafficDNS traffic detected: queries for: 60da859e8a.websersaiosnginxo.ru
          Source: TrafficDNS traffic detected: queries for: 60da859e8a.adminpanel.oss
          Source: TrafficDNS traffic detected: queries for: 60da859e8a.admincs.duckdns.org
          Source: TrafficDNS traffic detected: queries for: 60da859e8a.session.geek
          Source: TrafficDNS traffic detected: queries for: 60da859e8a.duckdns.org
          Source: TrafficDNS traffic detected: queries for: 60da859e8a.geek
          Source: TrafficDNS traffic detected: queries for: 60da859e8a.oss
          Source: TrafficDNS traffic detected: queries for: 60da859e8a.chickenkiller.com
          Source: TrafficDNS traffic detected: queries for: 60da859e8a.accesscam.org
          Source: TrafficDNS traffic detected: queries for: 60da859e8a.casacam.net
          Source: TrafficDNS traffic detected: queries for: 60da859e8a.ddnsfree.com
          Source: TrafficDNS traffic detected: queries for: 60da859e8a.mooo.com
          Source: TrafficDNS traffic detected: queries for: 60da859e8a.strangled.net
          Source: TrafficDNS traffic detected: queries for: 60da859e8a.ignorelist.com
          Source: TrafficDNS traffic detected: queries for: 60da859e8a.ru
          Source: TrafficDNS traffic detected: queries for: 60da859e8a.nl

          Stealing of Sensitive Information

          barindex
          Source: Yara matchFile source: 6208.1.00007fbc50017000.00007fbc50083000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: 6227.1.00007fbc50017000.00007fbc50083000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: 6293.1.00007fbc50017000.00007fbc50083000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: 6241.1.00007fbc50017000.00007fbc50083000.r-x.sdmp, type: MEMORY

          Remote Access Functionality

          barindex
          Source: Yara matchFile source: 6208.1.00007fbc50017000.00007fbc50083000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: 6227.1.00007fbc50017000.00007fbc50083000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: 6293.1.00007fbc50017000.00007fbc50083000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: 6241.1.00007fbc50017000.00007fbc50083000.r-x.sdmp, type: MEMORY
          ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
          Gather Victim Identity Information1
          Scripting
          Valid Accounts1
          Scheduled Task/Job
          1
          Systemd Service
          1
          Systemd Service
          21
          Masquerading
          OS Credential Dumping11
          Security Software Discovery
          Remote ServicesData from Local System1
          Encrypted Channel
          Exfiltration Over Other Network Medium1
          Data Manipulation
          CredentialsDomainsDefault AccountsScheduled Task/Job1
          Scheduled Task/Job
          1
          Scheduled Task/Job
          1
          File and Directory Permissions Modification
          LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
          Non-Standard Port
          Exfiltration Over BluetoothNetwork Denial of Service
          Email AddressesDNS ServerDomain AccountsAt1
          Scripting
          Logon Script (Windows)1
          Hidden Files and Directories
          Security Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
          Non-Application Layer Protocol
          Automated ExfiltrationData Encrypted for Impact
          Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
          Obfuscated Files or Information
          NTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture12
          Application Layer Protocol
          Traffic DuplicationData Destruction
          Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
          File Deletion
          LSA SecretsInternet Connection DiscoverySSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
          No configs have been found
          Hide Legend

          Legend:

          • Process
          • Signature
          • Created File
          • DNS/IP Info
          • Is Dropped
          • Number of created Files
          • Is malicious
          • Internet
          behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1431159 Sample: SecuriteInfo.com.Other.Malw... Startdate: 24/04/2024 Architecture: LINUX Score: 100 87 60da859e8a.duckdns.org 2->87 89 60da859e8a.admincs.duckdns.org 2->89 91 21 other IPs or domains 2->91 95 Antivirus / Scanner detection for submitted sample 2->95 97 Multi AV Scanner detection for submitted file 2->97 99 Yara detected Mirai 2->99 105 2 other signatures 2->105 10 SecuriteInfo.com.Other.Malware-gen.3200.4135.elf 2->10         started        12 udisksd dumpe2fs 2->12         started        14 udisksd dumpe2fs 2->14         started        16 16 other processes 2->16 signatures3 101 Performs DNS TXT record lookups 89->101 103 Uses dynamic DNS services 89->103 process4 process5 18 SecuriteInfo.com.Other.Malware-gen.3200.4135.elf 10->18         started        21 SecuriteInfo.com.Other.Malware-gen.3200.4135.elf 10->21         started        23 SecuriteInfo.com.Other.Malware-gen.3200.4135.elf sh 10->23         started        26 SecuriteInfo.com.Other.Malware-gen.3200.4135.elf cp 10->26         started        file6 79 /var/tmp/.recoverys, ASCII 18->79 dropped 28 SecuriteInfo.com.Other.Malware-gen.3200.4135.elf 18->28         started        32 SecuriteInfo.com.Other.Malware-gen.3200.4135.elf sh 18->32         started        34 SecuriteInfo.com.Other.Malware-gen.3200.4135.elf sh 18->34         started        42 2 other processes 18->42 36 SecuriteInfo.com.Other.Malware-gen.3200.4135.elf sh 21->36         started        38 SecuriteInfo.com.Other.Malware-gen.3200.4135.elf 21->38         started        111 Executes itself again with its parent PID as an argument (indicative of hampering debugging) 23->111 40 sh mount 23->40         started        81 /var/tmp/nginx_kel, ELF 26->81 dropped signatures7 process8 file9 85 /etc/init.d/dnsconfig, POSIX 28->85 dropped 113 Sample tries to set files in /etc globally writable 28->113 115 Drops files in suspicious directories 28->115 44 SecuriteInfo.com.Other.Malware-gen.3200.4135.elf sh 28->44         started        46 SecuriteInfo.com.Other.Malware-gen.3200.4135.elf sh 28->46         started        48 SecuriteInfo.com.Other.Malware-gen.3200.4135.elf sh 28->48         started        62 14 other processes 28->62 50 sh crontab 32->50         started        54 sh systemctl 34->54         started        117 Executes itself again with its parent PID as an argument (indicative of hampering debugging) 36->117 56 sh mount 36->56         started        58 sh systemctl 42->58         started        60 sh systemctl 42->60         started        signatures10 process11 file12 64 sh ln 44->64         started        67 sh ln 46->67         started        69 sh ln 48->69         started        83 /var/spool/cron/crontabs/tmp.pn4Slk, ASCII 50->83 dropped 107 Sample tries to persist itself using cron 50->107 109 Executes the "crontab" command typically for achieving persistence 50->109 71 sh ln 62->71         started        73 sh ln 62->73         started        75 sh ln 62->75         started        77 11 other processes 62->77 signatures13 process14 signatures15 93 Sample tries to persist itself using System V runlevels 64->93
          SourceDetectionScannerLabelLink
          SecuriteInfo.com.Other.Malware-gen.3200.4135.elf47%ReversingLabsLinux.Trojan.Wacatac
          SecuriteInfo.com.Other.Malware-gen.3200.4135.elf100%AviraLINUX/AVF.Agent.thkim
          No Antivirus matches
          No Antivirus matches
          No Antivirus matches
          NameIPActiveMaliciousAntivirus DetectionReputation
          60da859e8a.ddnsfree.com
          unknown
          unknowntrue
            unknown
            60da859e8a.adminpanel.oss
            unknown
            unknowntrue
              unknown
              60da859e8a.session.geek
              unknown
              unknowntrue
                unknown
                60da859e8a.admincs.duckdns.org
                unknown
                unknowntrue
                  unknown
                  60da859e8a.duckdns.org
                  unknown
                  unknowntrue
                    unknown
                    60da859e8a.geek
                    unknown
                    unknowntrue
                      unknown
                      60da859e8a.accesscam.org
                      unknown
                      unknowntrue
                        unknown
                        60da859e8a.nl
                        unknown
                        unknowntrue
                          unknown
                          60da859e8a.strangled.net
                          unknown
                          unknowntrue
                            unknown
                            60da859e8a.casacam.net
                            unknown
                            unknowntrue
                              unknown
                              60da859e8a.mooo.com
                              unknown
                              unknownfalse
                                high
                                60da859e8a.ignorelist.com
                                unknown
                                unknownfalse
                                  high
                                  60da859e8a.websersaiosnginxo.ru
                                  unknown
                                  unknowntrue
                                    unknown
                                    60da859e8a.ru
                                    unknown
                                    unknowntrue
                                      unknown
                                      60da859e8a.oss
                                      unknown
                                      unknowntrue
                                        unknown
                                        60da859e8a.chickenkiller.com
                                        unknown
                                        unknownfalse
                                          high
                                          60da859e8a.dontargetme.nl
                                          unknown
                                          unknowntrue
                                            unknown
                                            NameSourceMaliciousAntivirus DetectionReputation
                                            https://qemu.org/contribute/report-a-bugnginx_kel.16.drfalse
                                              high
                                              https://qemu.orgnginx_kel.16.drfalse
                                                high
                                                • No. of IPs < 25%
                                                • 25% < No. of IPs < 50%
                                                • 50% < No. of IPs < 75%
                                                • 75% < No. of IPs
                                                IPDomainCountryFlagASNASN NameMalicious
                                                129.6.15.28
                                                unknownUnited States
                                                49US-NATIONAL-INSTITUTE-OF-STANDARDS-AND-TECHNOLOGYUSfalse
                                                109.202.202.202
                                                unknownSwitzerland
                                                13030INIT7CHfalse
                                                147.78.12.176
                                                unknownUnited Kingdom
                                                9009M247GBtrue
                                                54.171.230.55
                                                unknownUnited States
                                                16509AMAZON-02USfalse
                                                91.189.91.43
                                                unknownUnited Kingdom
                                                41231CANONICAL-ASGBfalse
                                                91.189.91.42
                                                unknownUnited Kingdom
                                                41231CANONICAL-ASGBfalse
                                                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                147.78.12.176SecuriteInfo.com.Linux.Siggen.6954.6684.13146.elfGet hashmaliciousMiraiBrowse
                                                  SecuriteInfo.com.Other.Malware-gen.22921.14172.elfGet hashmaliciousMiraiBrowse
                                                    PrHBHHWE5U.elfGet hashmaliciousMiraiBrowse
                                                      54.171.230.55http://94.156.79.129/i686Get hashmaliciousUnknownBrowse
                                                        en52ai3DFV.elfGet hashmaliciousChaosBrowse
                                                          65kw6IfQdO.elfGet hashmaliciousUnknownBrowse
                                                            7Ud8fq8tJs.elfGet hashmaliciousGafgytBrowse
                                                              jb6F3H6QH4.elfGet hashmaliciousMirai, GafgytBrowse
                                                                JCC3MNVgRd.elfGet hashmaliciousGafgytBrowse
                                                                  520VcHQQj7.elfGet hashmaliciousUnknownBrowse
                                                                    eI5fTcq2no.elfGet hashmaliciousUnknownBrowse
                                                                      1HoxbBh9mb.elfGet hashmaliciousMirai, OkiruBrowse
                                                                        V06ANR64H4.elfGet hashmaliciousMirai, OkiruBrowse
                                                                          129.6.15.28SecuriteInfo.com.Linux.Siggen.6954.6684.13146.elfGet hashmaliciousMiraiBrowse
                                                                            SecuriteInfo.com.Other.Malware-gen.22921.14172.elfGet hashmaliciousMiraiBrowse
                                                                              PrHBHHWE5U.elfGet hashmaliciousMiraiBrowse
                                                                                y99ZI1Kjg8.exeGet hashmaliciousUnknownBrowse
                                                                                  QP6s4u5SZ8.exeGet hashmaliciousUnknownBrowse
                                                                                    2X3f1ykTmM.exeGet hashmaliciousKronosBrowse
                                                                                      kr.exeGet hashmaliciousKronosBrowse
                                                                                        WjmYak325l.exeGet hashmaliciousKronosBrowse
                                                                                          F75rJPKdGb.exeGet hashmaliciousKronosBrowse
                                                                                            ozJy5Zf5cf.exeGet hashmaliciousKronosBrowse
                                                                                              109.202.202.202SecuriteInfo.com.Linux.Siggen.6954.6684.13146.elfGet hashmaliciousMiraiBrowse
                                                                                                http://94.156.79.129/i686Get hashmaliciousUnknownBrowse
                                                                                                  0ADLfPX6HX.elfGet hashmaliciousUnknownBrowse
                                                                                                    PrHBHHWE5U.elfGet hashmaliciousMiraiBrowse
                                                                                                      en52ai3DFV.elfGet hashmaliciousChaosBrowse
                                                                                                        SecuriteInfo.com.Linux.Siggen.9999.198.19634.elfGet hashmaliciousMiraiBrowse
                                                                                                          o301W6jF28.elfGet hashmaliciousUnknownBrowse
                                                                                                            ZDbe9qUxF5.elfGet hashmaliciousUnknownBrowse
                                                                                                              WQiDRxwDWv.elfGet hashmaliciousUnknownBrowse
                                                                                                                65kw6IfQdO.elfGet hashmaliciousUnknownBrowse
                                                                                                                  91.189.91.43SecuriteInfo.com.Linux.Siggen.6954.6684.13146.elfGet hashmaliciousMiraiBrowse
                                                                                                                    http://94.156.79.129/i686Get hashmaliciousUnknownBrowse
                                                                                                                      0ADLfPX6HX.elfGet hashmaliciousUnknownBrowse
                                                                                                                        PrHBHHWE5U.elfGet hashmaliciousMiraiBrowse
                                                                                                                          en52ai3DFV.elfGet hashmaliciousChaosBrowse
                                                                                                                            SecuriteInfo.com.Linux.Siggen.9999.198.19634.elfGet hashmaliciousMiraiBrowse
                                                                                                                              o301W6jF28.elfGet hashmaliciousUnknownBrowse
                                                                                                                                ZDbe9qUxF5.elfGet hashmaliciousUnknownBrowse
                                                                                                                                  WQiDRxwDWv.elfGet hashmaliciousUnknownBrowse
                                                                                                                                    65kw6IfQdO.elfGet hashmaliciousUnknownBrowse
                                                                                                                                      91.189.91.42SecuriteInfo.com.Linux.Siggen.6954.6684.13146.elfGet hashmaliciousMiraiBrowse
                                                                                                                                        http://94.156.79.129/i686Get hashmaliciousUnknownBrowse
                                                                                                                                          0ADLfPX6HX.elfGet hashmaliciousUnknownBrowse
                                                                                                                                            PrHBHHWE5U.elfGet hashmaliciousMiraiBrowse
                                                                                                                                              en52ai3DFV.elfGet hashmaliciousChaosBrowse
                                                                                                                                                SecuriteInfo.com.Linux.Siggen.9999.198.19634.elfGet hashmaliciousMiraiBrowse
                                                                                                                                                  o301W6jF28.elfGet hashmaliciousUnknownBrowse
                                                                                                                                                    ZDbe9qUxF5.elfGet hashmaliciousUnknownBrowse
                                                                                                                                                      WQiDRxwDWv.elfGet hashmaliciousUnknownBrowse
                                                                                                                                                        65kw6IfQdO.elfGet hashmaliciousUnknownBrowse
                                                                                                                                                          No context
                                                                                                                                                          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                                                                                          US-NATIONAL-INSTITUTE-OF-STANDARDS-AND-TECHNOLOGYUSSecuriteInfo.com.Linux.Siggen.6954.6684.13146.elfGet hashmaliciousMiraiBrowse
                                                                                                                                                          • 129.6.15.28
                                                                                                                                                          SecuriteInfo.com.Other.Malware-gen.22921.14172.elfGet hashmaliciousMiraiBrowse
                                                                                                                                                          • 129.6.15.28
                                                                                                                                                          PrHBHHWE5U.elfGet hashmaliciousMiraiBrowse
                                                                                                                                                          • 129.6.15.28
                                                                                                                                                          vrcd941p2O.elfGet hashmaliciousMiraiBrowse
                                                                                                                                                          • 129.6.182.34
                                                                                                                                                          LsgqN88sQ4.elfGet hashmaliciousMiraiBrowse
                                                                                                                                                          • 132.163.106.84
                                                                                                                                                          wNxS15qBuw.elfGet hashmaliciousUnknownBrowse
                                                                                                                                                          • 129.6.111.194
                                                                                                                                                          SecuriteInfo.com.Win32.TrojanX-gen.22797.26187.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                          • 132.163.96.3
                                                                                                                                                          GHrwbsrdR8.elfGet hashmaliciousMiraiBrowse
                                                                                                                                                          • 129.6.51.5
                                                                                                                                                          Q3xahE8EiM.elfGet hashmaliciousMiraiBrowse
                                                                                                                                                          • 129.6.51.8
                                                                                                                                                          VLTKNhatRac.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                          • 132.163.97.2
                                                                                                                                                          CANONICAL-ASGBSecuriteInfo.com.Other.Malware-gen.31307.16494.elfGet hashmaliciousMiraiBrowse
                                                                                                                                                          • 185.125.190.26
                                                                                                                                                          SecuriteInfo.com.Linux.Siggen.6954.6684.13146.elfGet hashmaliciousMiraiBrowse
                                                                                                                                                          • 91.189.91.42
                                                                                                                                                          http://94.156.79.129/i686Get hashmaliciousUnknownBrowse
                                                                                                                                                          • 91.189.91.42
                                                                                                                                                          0ADLfPX6HX.elfGet hashmaliciousUnknownBrowse
                                                                                                                                                          • 91.189.91.42
                                                                                                                                                          PrHBHHWE5U.elfGet hashmaliciousMiraiBrowse
                                                                                                                                                          • 91.189.91.42
                                                                                                                                                          en52ai3DFV.elfGet hashmaliciousChaosBrowse
                                                                                                                                                          • 91.189.91.42
                                                                                                                                                          SecuriteInfo.com.Linux.Siggen.9999.198.19634.elfGet hashmaliciousMiraiBrowse
                                                                                                                                                          • 91.189.91.42
                                                                                                                                                          o301W6jF28.elfGet hashmaliciousUnknownBrowse
                                                                                                                                                          • 91.189.91.42
                                                                                                                                                          ZDbe9qUxF5.elfGet hashmaliciousUnknownBrowse
                                                                                                                                                          • 91.189.91.42
                                                                                                                                                          WQiDRxwDWv.elfGet hashmaliciousUnknownBrowse
                                                                                                                                                          • 91.189.91.42
                                                                                                                                                          AMAZON-02UShttps://8fq7c.eceydri.com/WK9D/Get hashmaliciousHTMLPhisherBrowse
                                                                                                                                                          • 13.226.210.57
                                                                                                                                                          http://94.156.79.129/i686Get hashmaliciousUnknownBrowse
                                                                                                                                                          • 54.171.230.55
                                                                                                                                                          http://womenofgoodworks-my.sharepoint.com/:b:/g/personal/tia_womenofgoodworks_org/EVICmRtg-CVNtsngkb8KQlgBH2LYVfumjH5s-SFbeQjN_QGet hashmaliciousHTMLPhisherBrowse
                                                                                                                                                          • 13.226.210.57
                                                                                                                                                          http://www.agilgas.com.br/wp-content/uploads/2024/04/tryythgghjhgfj.html#T0RQQ2pCOVhPSTJvNm12WEYvSGFNOUI2Q3J4bElveUFOazNibHR2QWI4SGp2aG4yU2kwVytiSzF6WjZnZXN5YUFpUTM5dmpINHlOM2JXdGVtdUM3c2UyMk1yVXROeVVDVVMzYUdOeHFWdDg9Get hashmaliciousPhisherBrowse
                                                                                                                                                          • 18.154.206.29
                                                                                                                                                          https://microloft.net/?r=8e28e856-be8d-4446-a396-cdcd78169ab8&rg=euGet hashmaliciousUnknownBrowse
                                                                                                                                                          • 52.218.120.8
                                                                                                                                                          http://gnoticiasimparciais.comGet hashmaliciousUnknownBrowse
                                                                                                                                                          • 13.227.74.36
                                                                                                                                                          https://www.linkedin.com/redir/redirect?url=https%3A%2F%2Flookerstudio%2Egoogle%2Ecom%2Fs%2FscrHqwjeA3k&urlhash=dcQj&trk=public_profile-settings_topcard-websiteGet hashmaliciousUnknownBrowse
                                                                                                                                                          • 18.155.192.106
                                                                                                                                                          SecuriteInfo.com.Program.Unwanted.5215.4772.1835.exeGet hashmaliciousPureLog StealerBrowse
                                                                                                                                                          • 216.137.39.42
                                                                                                                                                          http://p.ksrndkehqnwntyxlhgto.comGet hashmaliciousUnknownBrowse
                                                                                                                                                          • 76.223.116.242
                                                                                                                                                          SecuriteInfo.com.Program.Unwanted.5215.4772.1835.exeGet hashmaliciousPureLog StealerBrowse
                                                                                                                                                          • 18.238.85.97
                                                                                                                                                          INIT7CHSecuriteInfo.com.Linux.Siggen.6954.6684.13146.elfGet hashmaliciousMiraiBrowse
                                                                                                                                                          • 109.202.202.202
                                                                                                                                                          http://94.156.79.129/i686Get hashmaliciousUnknownBrowse
                                                                                                                                                          • 109.202.202.202
                                                                                                                                                          0ADLfPX6HX.elfGet hashmaliciousUnknownBrowse
                                                                                                                                                          • 109.202.202.202
                                                                                                                                                          PrHBHHWE5U.elfGet hashmaliciousMiraiBrowse
                                                                                                                                                          • 109.202.202.202
                                                                                                                                                          en52ai3DFV.elfGet hashmaliciousChaosBrowse
                                                                                                                                                          • 109.202.202.202
                                                                                                                                                          SecuriteInfo.com.Linux.Siggen.9999.198.19634.elfGet hashmaliciousMiraiBrowse
                                                                                                                                                          • 109.202.202.202
                                                                                                                                                          o301W6jF28.elfGet hashmaliciousUnknownBrowse
                                                                                                                                                          • 109.202.202.202
                                                                                                                                                          ZDbe9qUxF5.elfGet hashmaliciousUnknownBrowse
                                                                                                                                                          • 109.202.202.202
                                                                                                                                                          WQiDRxwDWv.elfGet hashmaliciousUnknownBrowse
                                                                                                                                                          • 109.202.202.202
                                                                                                                                                          65kw6IfQdO.elfGet hashmaliciousUnknownBrowse
                                                                                                                                                          • 109.202.202.202
                                                                                                                                                          M247GBSecuriteInfo.com.Linux.Siggen.6954.6684.13146.elfGet hashmaliciousMiraiBrowse
                                                                                                                                                          • 147.78.12.176
                                                                                                                                                          SecuriteInfo.com.Other.Malware-gen.22921.14172.elfGet hashmaliciousMiraiBrowse
                                                                                                                                                          • 147.78.12.176
                                                                                                                                                          PrHBHHWE5U.elfGet hashmaliciousMiraiBrowse
                                                                                                                                                          • 147.78.12.176
                                                                                                                                                          http://crunchersflowdigital.comGet hashmaliciousUnknownBrowse
                                                                                                                                                          • 91.202.233.192
                                                                                                                                                          957C4XK6Lt.exeGet hashmaliciousPhorpiexBrowse
                                                                                                                                                          • 91.202.233.141
                                                                                                                                                          sora.x86.elfGet hashmaliciousMiraiBrowse
                                                                                                                                                          • 38.206.71.22
                                                                                                                                                          pJNcZyhUh8.elfGet hashmaliciousMiraiBrowse
                                                                                                                                                          • 38.202.225.74
                                                                                                                                                          z1PROOFOFPAYMENT.exeGet hashmaliciousRemcosBrowse
                                                                                                                                                          • 89.249.73.162
                                                                                                                                                          3m7cmtctck.exeGet hashmaliciousPureLog Stealer, zgRATBrowse
                                                                                                                                                          • 185.221.198.248
                                                                                                                                                          g2PqnVy6cQ.elfGet hashmaliciousMirai, OkiruBrowse
                                                                                                                                                          • 193.43.20.21
                                                                                                                                                          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                                                                                          fb4726d465c5f28b84cd6d14cedd13a7http://94.156.79.129/i686Get hashmaliciousUnknownBrowse
                                                                                                                                                          • 54.171.230.55
                                                                                                                                                          EfsIiZhHxS.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                                                                                                          • 54.171.230.55
                                                                                                                                                          1mHUcsxKG6.elfGet hashmaliciousMiraiBrowse
                                                                                                                                                          • 54.171.230.55
                                                                                                                                                          uWGh63gpjU.elfGet hashmaliciousMiraiBrowse
                                                                                                                                                          • 54.171.230.55
                                                                                                                                                          BYIVZ1jcJv.elfGet hashmaliciousUnknownBrowse
                                                                                                                                                          • 54.171.230.55
                                                                                                                                                          HfcQmQis2J.elfGet hashmaliciousUnknownBrowse
                                                                                                                                                          • 54.171.230.55
                                                                                                                                                          tajma.x86_64-20240421-1028.elfGet hashmaliciousMirai, OkiruBrowse
                                                                                                                                                          • 54.171.230.55
                                                                                                                                                          1lkozpLZNX.elfGet hashmaliciousUnknownBrowse
                                                                                                                                                          • 54.171.230.55
                                                                                                                                                          9PYUxFx9pK.elfGet hashmaliciousMirai, Moobot, OkiruBrowse
                                                                                                                                                          • 54.171.230.55
                                                                                                                                                          s02RKS8Moh.elfGet hashmaliciousUnknownBrowse
                                                                                                                                                          • 54.171.230.55
                                                                                                                                                          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                                                                                          /etc/init.d/dnsconfigSecuriteInfo.com.Other.Malware-gen.31307.16494.elfGet hashmaliciousMiraiBrowse
                                                                                                                                                            SecuriteInfo.com.Linux.Siggen.6954.6684.13146.elfGet hashmaliciousMiraiBrowse
                                                                                                                                                              SecuriteInfo.com.Other.Malware-gen.22921.14172.elfGet hashmaliciousMiraiBrowse
                                                                                                                                                                PrHBHHWE5U.elfGet hashmaliciousMiraiBrowse
                                                                                                                                                                  /var/tmp/nginx_kelSecuriteInfo.com.Linux.Siggen.6954.6684.13146.elfGet hashmaliciousMiraiBrowse
                                                                                                                                                                    Process:/tmp/SecuriteInfo.com.Other.Malware-gen.3200.4135.elf
                                                                                                                                                                    File Type:POSIX shell script, ASCII text executable
                                                                                                                                                                    Category:dropped
                                                                                                                                                                    Size (bytes):1055
                                                                                                                                                                    Entropy (8bit):4.698341250256645
                                                                                                                                                                    Encrypted:false
                                                                                                                                                                    SSDEEP:24:97kNF9r4bIgxIgBfI7IDbIQ/oITskGNyv6qITbp4:9mekgCgBAEYQ9TstyOTb2
                                                                                                                                                                    MD5:DF56EA52B8CEE93884F3872D25A85DB0
                                                                                                                                                                    SHA1:2FD0C7407ED67253A807D1D01C6FFD3467EDAF8E
                                                                                                                                                                    SHA-256:A402D683E16519793B06F663163D750B4E82922CF3B18AF5A655DE41328B9BF5
                                                                                                                                                                    SHA-512:E390943755721BA7F0210439F0FC8E5E3DAAF98BA1DF923464AA547C5A7C6F941240658C8FA59270D6F73539FD8B0A04D7BDC9C407F13D9301588D5CF9AA68DA
                                                                                                                                                                    Malicious:true
                                                                                                                                                                    Joe Sandbox View:
                                                                                                                                                                    • Filename: SecuriteInfo.com.Other.Malware-gen.31307.16494.elf, Detection: malicious, Browse
                                                                                                                                                                    • Filename: SecuriteInfo.com.Linux.Siggen.6954.6684.13146.elf, Detection: malicious, Browse
                                                                                                                                                                    • Filename: SecuriteInfo.com.Other.Malware-gen.22921.14172.elf, Detection: malicious, Browse
                                                                                                                                                                    • Filename: PrHBHHWE5U.elf, Detection: malicious, Browse
                                                                                                                                                                    Reputation:low
                                                                                                                                                                    Preview:#!/bin/sh.### BEGIN INIT INFO.# Provides: asd.# Required-Start: $remote_fs $syslog.# Required-Stop: $remote_fs $syslog.# Default-Start: 2 3 4 5.# Default-Stop: 0 1 6.# Short-Description: Start asd at boot time.# Description: Enable service provided by daemon..### END INIT INFO..# Change the following to the path of your program.ASD_PATH="/var/tmp/nginx_kel"..section_enabled() {. $ASD_PATH initd &. return 0.}..section_provider() {. $ASD_PATH initd &. return 1.}..start_instance() {. $ASD_PATH initd &.}..start_service() {. $ASD_PATH initd &.}..stop_service() {. $ASD_PATH initd &.}.case "$1" in. start). echo "Starting asd". # Start command for your program. $ASD_PATH initd &. ;;. stop). echo "Stopping asd". # Stop command for your program. pkill -f $ASD_PATH. ;;. restart). echo "Restarting asd". $ASD_PATH initd &. ;;. *). echo "Usage: $0 {start
                                                                                                                                                                    Process:/tmp/SecuriteInfo.com.Other.Malware-gen.3200.4135.elf
                                                                                                                                                                    File Type:ASCII text
                                                                                                                                                                    Category:dropped
                                                                                                                                                                    Size (bytes):174
                                                                                                                                                                    Entropy (8bit):4.784414897762801
                                                                                                                                                                    Encrypted:false
                                                                                                                                                                    SSDEEP:3:zMZa7siUUnQ22AXAikA18v3muEcEn7iAev8x0gdK+Zn8OkSISkQmWA1+DRn:z8qUU1XAg8vBU7rm+ZfkHLQmWA4Rn
                                                                                                                                                                    MD5:900F683B08977636B092FCBFA1AD8A42
                                                                                                                                                                    SHA1:6D521F5C3E862F1106D9AC6A3A654E57E6814333
                                                                                                                                                                    SHA-256:71D21310D1C7DBB935F3B61311403B0EC0FA32DC73F91720365416A646C2DFB3
                                                                                                                                                                    SHA-512:50B5426500D8B5DCCB7FD71FE9A448AE1C76770890BA86C37E7DECBF2CA1F0E1CD20C50996260F37114BA2BDB16AE927E4AFAD241A51E3D22112ADA8E25604B0
                                                                                                                                                                    Malicious:false
                                                                                                                                                                    Reputation:low
                                                                                                                                                                    Preview:[Unit].Description=dnsconfigs Server Service.[Service].Type=simple.Restart=always.RestartSec=60.User=root.ExecStart=/var/tmp/nginx_kel sv.[Install].WantedBy=multi-user.target
                                                                                                                                                                    Process:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                                                                                                                                                    File Type:ASCII text
                                                                                                                                                                    Category:dropped
                                                                                                                                                                    Size (bytes):76
                                                                                                                                                                    Entropy (8bit):3.7627880354948586
                                                                                                                                                                    Encrypted:false
                                                                                                                                                                    SSDEEP:3:+M4VMPQnMLmPQ9JEcwwbn:+M4m4MixcZb
                                                                                                                                                                    MD5:D86A1F5765F37989EB0EC3837AD13ECC
                                                                                                                                                                    SHA1:D749672A734D9DEAFD61DCA501C6929EC431B83E
                                                                                                                                                                    SHA-256:85889AB8222C947C58BE565723AE603CC1A0BD2153B6B11E156826A21E6CCD45
                                                                                                                                                                    SHA-512:338C4B776FDCC2D05E869AE1F9DB64E6E7ECC4C621AB45E51DD07C73306BACBAD7882BE8D3ACF472CAEB30D4E5367F8793D3E006694184A68F74AC943A4B7C07
                                                                                                                                                                    Malicious:false
                                                                                                                                                                    Reputation:moderate, very likely benign file
                                                                                                                                                                    Preview:PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/bin.
                                                                                                                                                                    Process:/tmp/SecuriteInfo.com.Other.Malware-gen.3200.4135.elf
                                                                                                                                                                    File Type:data
                                                                                                                                                                    Category:dropped
                                                                                                                                                                    Size (bytes):10
                                                                                                                                                                    Entropy (8bit):2.321928094887362
                                                                                                                                                                    Encrypted:false
                                                                                                                                                                    SSDEEP:3:fJXRP:v
                                                                                                                                                                    MD5:4D83A945DC0C12B760F9C56CA0ECD41F
                                                                                                                                                                    SHA1:27EB4EC6DCF8DD28F6DA29ACFE1B3CBE9A7A6F7C
                                                                                                                                                                    SHA-256:6F3B88F6529096AEDB39B8DAB916DE6881E67D003A51B54CF4E3B50F200E78D6
                                                                                                                                                                    SHA-512:EB6C50DBB7F13A1D9FC51C7DF2127D568554D47C888F9FD3F57228E917145588BEA5A17D6BFEE11C232F9A4495D7EA9AF768EE37B09978D169F6EEDDD33E4297
                                                                                                                                                                    Malicious:false
                                                                                                                                                                    Reputation:low
                                                                                                                                                                    Preview:6240.6240.
                                                                                                                                                                    Process:/usr/bin/crontab
                                                                                                                                                                    File Type:ASCII text
                                                                                                                                                                    Category:dropped
                                                                                                                                                                    Size (bytes):230
                                                                                                                                                                    Entropy (8bit):5.171158457670689
                                                                                                                                                                    Encrypted:false
                                                                                                                                                                    SSDEEP:6:SUrpqoqQjEOP1K+1yOBFQ5yBAwZHGMQ5UYLtCFt3PYIa9fkQvn:8QjP86AgeHLUQbNvn
                                                                                                                                                                    MD5:7F027FEAC108B7C9723E95411890ECAF
                                                                                                                                                                    SHA1:6DC9AF55C4FB00C628D36A1EE47C686E86B01746
                                                                                                                                                                    SHA-256:960C8B57A7305F487CF1F377C0DF549BE9E37F73E850A042B385486562192A9D
                                                                                                                                                                    SHA-512:EDA31A7244CA3431D1A31D0D3056F38D2CB9F9FC6CECC815B62D6EA97CD4AE337D9E4291A05E124F426FB937F02D29D27A40390A5D3F7FC15A6054AE34C3790B
                                                                                                                                                                    Malicious:true
                                                                                                                                                                    Reputation:low
                                                                                                                                                                    Preview:# DO NOT EDIT THIS FILE - edit the master and reinstall..# (/var/tmp/.recoverys installed on Wed Apr 24 16:35:06 2024).# (Cron version -- $Id: crontab.c,v 2.13 1994/01/17 03:20:37 vixie Exp $).0 * * * * /var/tmp/nginx_kel crontab.
                                                                                                                                                                    Process:/tmp/SecuriteInfo.com.Other.Malware-gen.3200.4135.elf
                                                                                                                                                                    File Type:ASCII text
                                                                                                                                                                    Category:dropped
                                                                                                                                                                    Size (bytes):37
                                                                                                                                                                    Entropy (8bit):4.15487093296263
                                                                                                                                                                    Encrypted:false
                                                                                                                                                                    SSDEEP:3:VP3wIa98OkQvn:yIa9fkQvn
                                                                                                                                                                    MD5:ABE9A0E06459D029E0F5183965DBBF3B
                                                                                                                                                                    SHA1:7E79E16EA12FED960BCEE8EB5A9C6384FA61A2D1
                                                                                                                                                                    SHA-256:B2CFE7490D6DD2F81EDE3ED9DB30C78637F4A1E98ED746EAA00998E95D3DE384
                                                                                                                                                                    SHA-512:955AECE23C24E5B1CE32A90FA014A8A6FAC39B68707A13F56CD1BFB07C79DFC59806942732990AAF925DB5724F381827E2C35EBA21FE95CE9A760760527048CD
                                                                                                                                                                    Malicious:true
                                                                                                                                                                    Reputation:low
                                                                                                                                                                    Preview:0 * * * * /var/tmp/nginx_kel crontab.
                                                                                                                                                                    Process:/bin/cp
                                                                                                                                                                    File Type:ELF 64-bit LSB pie executable, x86-64, version 1 (GNU/Linux), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, BuildID[sha1]=7deab4eba39454c6adb03c5ea66f79a9862f42e1, for GNU/Linux 3.2.0, stripped
                                                                                                                                                                    Category:dropped
                                                                                                                                                                    Size (bytes):4956856
                                                                                                                                                                    Entropy (8bit):5.1472279074446865
                                                                                                                                                                    Encrypted:false
                                                                                                                                                                    SSDEEP:98304:844S/drfCZvsBlQEY+ZByawrOIqRU51al498KBm7RxyZWr2fXx+DbZ9qA7Yr/Wkq:w3x
                                                                                                                                                                    MD5:5EBFCAE4FE2471FCC5695C2394773FF1
                                                                                                                                                                    SHA1:BA96F97AE0B05C386C7F5D06E622A171A893EF12
                                                                                                                                                                    SHA-256:5078BCBA9D7F40253D5B52B49842D7D34D1991387C9EAE664B9A4F9DE8B17904
                                                                                                                                                                    SHA-512:AB691B6A8AB023CE0F117BD1F5DC24D1835CBBFA1886B5910DC94E5935C65B716AF5085CAC2AAA38B89B108F4BBD163B2CE60EBE8A94628FA9EC014D6F752785
                                                                                                                                                                    Malicious:false
                                                                                                                                                                    Joe Sandbox View:
                                                                                                                                                                    • Filename: SecuriteInfo.com.Linux.Siggen.6954.6684.13146.elf, Detection: malicious, Browse
                                                                                                                                                                    Reputation:low
                                                                                                                                                                    Preview:.ELF..............>..... .......@.......8.K.........@.8...@.............@.......@.......@...............................................................................................................................................................................}.......}.........................&.......&.......&......;.......;......................@.B.....@.B.....@.B.....................................8.J.....8.J.....8.J.............................................................D.......D.......................@.B.....@.B.....@.B.............................P.td.....(>......(>......(>.....D.......D...............Q.td....................................................R.td....@.B.....@.B.....@.B......"......."............../lib64/ld-linux-x86-64.so.2.............GNU.}..T..<^.oy../B.............GNU.....................................@.@.@`.kFU.......b..@...` .C.....`.@.A.P!..." . .. .... .....%$.f.@ B. .(... .@...1......`A.....D6........a.C.....D..............J....I...$Q.....
                                                                                                                                                                    File type:ELF 32-bit LSB executable, ARM, version 1 (ARM), statically linked, no section header
                                                                                                                                                                    Entropy (8bit):7.742676658464739
                                                                                                                                                                    TrID:
                                                                                                                                                                    • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                                                                                                                                                    File name:SecuriteInfo.com.Other.Malware-gen.3200.4135.elf
                                                                                                                                                                    File size:250'680 bytes
                                                                                                                                                                    MD5:cef396530992f79dea5d6d8209fc8ee7
                                                                                                                                                                    SHA1:cdaa0b93d9299a00b90edb4b617a9f89c3aa322f
                                                                                                                                                                    SHA256:5c21a3451c7f4bcb6737a8904efc7ea9ee10b3994f324b2ece1610883c2394f1
                                                                                                                                                                    SHA512:8c7ffcd35b5db373bae1ce7621c97508082aeea2ed1061a167c509d4ca13f1c9e8a30d630e550ffa48ae82c1d0742af62243cd0e93d413f21b69dffd1558fafd
                                                                                                                                                                    SSDEEP:6144:cvZy8EpPYGg9XlNAI61A6OMLf+ZBse1kZcR6:Brg9Xlh6S+8se1x6
                                                                                                                                                                    TLSH:13342387DB4C5268DA2B2439DEEAFC31F8FD019952B53BD56D683B5E118000EF86A385
                                                                                                                                                                    File Content Preview:.ELF...a..........(.....\...4...........4. ...(..........................-..........................................Q.td.............................4Y..>*.........x...x.......].............r..........D.U....<..........}......,Tg...l....,.w...H..|....9..`

                                                                                                                                                                    ELF header

                                                                                                                                                                    Class:ELF32
                                                                                                                                                                    Data:2's complement, little endian
                                                                                                                                                                    Version:1 (current)
                                                                                                                                                                    Machine:ARM
                                                                                                                                                                    Version Number:0x1
                                                                                                                                                                    Type:EXEC (Executable file)
                                                                                                                                                                    OS/ABI:ARM - ABI
                                                                                                                                                                    ABI Version:0
                                                                                                                                                                    Entry Point Address:0xcc85c
                                                                                                                                                                    Flags:0x2
                                                                                                                                                                    ELF Header Size:52
                                                                                                                                                                    Program Header Offset:52
                                                                                                                                                                    Program Header Size:32
                                                                                                                                                                    Number of Program Headers:3
                                                                                                                                                                    Section Header Offset:0
                                                                                                                                                                    Section Header Size:40
                                                                                                                                                                    Number of Section Headers:0
                                                                                                                                                                    Header String Table Index:0
                                                                                                                                                                    TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                                                                                                                                    LOAD0x00x80000x80000x10000x82dd47.63920x6RW 0x8000
                                                                                                                                                                    LOAD0x00x900000x900000x3d1f90x3d1f97.74260x5R E0x8000
                                                                                                                                                                    GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
                                                                                                                                                                    TimestampSource PortDest PortSource IPDest IP
                                                                                                                                                                    Apr 24, 2024 16:35:07.027575016 CEST43928443192.168.2.2391.189.91.42
                                                                                                                                                                    Apr 24, 2024 16:35:07.683053970 CEST5732824150192.168.2.23147.78.12.176
                                                                                                                                                                    Apr 24, 2024 16:35:07.795464993 CEST33608443192.168.2.2354.171.230.55
                                                                                                                                                                    Apr 24, 2024 16:35:08.687414885 CEST5732824150192.168.2.23147.78.12.176
                                                                                                                                                                    Apr 24, 2024 16:35:10.703049898 CEST5732824150192.168.2.23147.78.12.176
                                                                                                                                                                    Apr 24, 2024 16:35:12.398806095 CEST42836443192.168.2.2391.189.91.43
                                                                                                                                                                    Apr 24, 2024 16:35:13.678714037 CEST4251680192.168.2.23109.202.202.202
                                                                                                                                                                    Apr 24, 2024 16:35:14.958496094 CEST5732824150192.168.2.23147.78.12.176
                                                                                                                                                                    Apr 24, 2024 16:35:16.055675030 CEST5733024150192.168.2.23147.78.12.176
                                                                                                                                                                    Apr 24, 2024 16:35:17.070272923 CEST5733024150192.168.2.23147.78.12.176
                                                                                                                                                                    Apr 24, 2024 16:35:19.085979939 CEST5733024150192.168.2.23147.78.12.176
                                                                                                                                                                    Apr 24, 2024 16:35:19.757775068 CEST5733224150192.168.2.23147.78.12.176
                                                                                                                                                                    Apr 24, 2024 16:35:20.781727076 CEST5733224150192.168.2.23147.78.12.176
                                                                                                                                                                    Apr 24, 2024 16:35:22.797486067 CEST5733224150192.168.2.23147.78.12.176
                                                                                                                                                                    Apr 24, 2024 16:35:22.893548965 CEST33608443192.168.2.2354.171.230.55
                                                                                                                                                                    Apr 24, 2024 16:35:23.189999104 CEST4433360854.171.230.55192.168.2.23
                                                                                                                                                                    Apr 24, 2024 16:35:23.191494942 CEST4433360854.171.230.55192.168.2.23
                                                                                                                                                                    Apr 24, 2024 16:35:23.191541910 CEST4433360854.171.230.55192.168.2.23
                                                                                                                                                                    Apr 24, 2024 16:35:23.191569090 CEST4433360854.171.230.55192.168.2.23
                                                                                                                                                                    Apr 24, 2024 16:35:23.191605091 CEST4433360854.171.230.55192.168.2.23
                                                                                                                                                                    Apr 24, 2024 16:35:23.191629887 CEST33608443192.168.2.2354.171.230.55
                                                                                                                                                                    Apr 24, 2024 16:35:23.191631079 CEST33608443192.168.2.2354.171.230.55
                                                                                                                                                                    Apr 24, 2024 16:35:23.191631079 CEST33608443192.168.2.2354.171.230.55
                                                                                                                                                                    Apr 24, 2024 16:35:23.191648960 CEST4433360854.171.230.55192.168.2.23
                                                                                                                                                                    Apr 24, 2024 16:35:23.191741943 CEST4433360854.171.230.55192.168.2.23
                                                                                                                                                                    Apr 24, 2024 16:35:23.191752911 CEST33608443192.168.2.2354.171.230.55
                                                                                                                                                                    Apr 24, 2024 16:35:23.191754103 CEST33608443192.168.2.2354.171.230.55
                                                                                                                                                                    Apr 24, 2024 16:35:23.191787004 CEST33608443192.168.2.2354.171.230.55
                                                                                                                                                                    Apr 24, 2024 16:35:23.192687035 CEST33608443192.168.2.2354.171.230.55
                                                                                                                                                                    Apr 24, 2024 16:35:23.488989115 CEST4433360854.171.230.55192.168.2.23
                                                                                                                                                                    Apr 24, 2024 16:35:23.489124060 CEST33608443192.168.2.2354.171.230.55
                                                                                                                                                                    Apr 24, 2024 16:35:23.489501953 CEST33608443192.168.2.2354.171.230.55
                                                                                                                                                                    Apr 24, 2024 16:35:23.785764933 CEST4433360854.171.230.55192.168.2.23
                                                                                                                                                                    Apr 24, 2024 16:35:23.785800934 CEST4433360854.171.230.55192.168.2.23
                                                                                                                                                                    Apr 24, 2024 16:35:23.785923004 CEST33608443192.168.2.2354.171.230.55
                                                                                                                                                                    Apr 24, 2024 16:35:23.785923958 CEST33608443192.168.2.2354.171.230.55
                                                                                                                                                                    Apr 24, 2024 16:35:23.787225008 CEST33608443192.168.2.2354.171.230.55
                                                                                                                                                                    Apr 24, 2024 16:35:24.083259106 CEST4433360854.171.230.55192.168.2.23
                                                                                                                                                                    Apr 24, 2024 16:35:24.083312988 CEST4433360854.171.230.55192.168.2.23
                                                                                                                                                                    Apr 24, 2024 16:35:24.083415031 CEST33608443192.168.2.2354.171.230.55
                                                                                                                                                                    Apr 24, 2024 16:35:24.083415985 CEST33608443192.168.2.2354.171.230.55
                                                                                                                                                                    Apr 24, 2024 16:35:26.988893986 CEST5733224150192.168.2.23147.78.12.176
                                                                                                                                                                    Apr 24, 2024 16:35:28.012712002 CEST43928443192.168.2.2391.189.91.42
                                                                                                                                                                    Apr 24, 2024 16:35:28.262605906 CEST5733424150192.168.2.23147.78.12.176
                                                                                                                                                                    Apr 24, 2024 16:35:29.292591095 CEST5733424150192.168.2.23147.78.12.176
                                                                                                                                                                    Apr 24, 2024 16:35:31.308373928 CEST5733424150192.168.2.23147.78.12.176
                                                                                                                                                                    Apr 24, 2024 16:35:35.435851097 CEST5733424150192.168.2.23147.78.12.176
                                                                                                                                                                    Apr 24, 2024 16:35:36.632967949 CEST5733624150192.168.2.23147.78.12.176
                                                                                                                                                                    Apr 24, 2024 16:35:37.643346071 CEST5733624150192.168.2.23147.78.12.176
                                                                                                                                                                    Apr 24, 2024 16:35:38.251359940 CEST42836443192.168.2.2391.189.91.43
                                                                                                                                                                    Apr 24, 2024 16:35:39.659075022 CEST5733624150192.168.2.23147.78.12.176
                                                                                                                                                                    Apr 24, 2024 16:35:43.882474899 CEST5733624150192.168.2.23147.78.12.176
                                                                                                                                                                    Apr 24, 2024 16:35:44.394520998 CEST4251680192.168.2.23109.202.202.202
                                                                                                                                                                    Apr 24, 2024 16:35:44.805401087 CEST5733824150192.168.2.23147.78.12.176
                                                                                                                                                                    Apr 24, 2024 16:35:45.834223032 CEST5733824150192.168.2.23147.78.12.176
                                                                                                                                                                    Apr 24, 2024 16:35:47.849895000 CEST5733824150192.168.2.23147.78.12.176
                                                                                                                                                                    Apr 24, 2024 16:35:52.073318958 CEST5733824150192.168.2.23147.78.12.176
                                                                                                                                                                    Apr 24, 2024 16:35:53.056260109 CEST5734024150192.168.2.23147.78.12.176
                                                                                                                                                                    Apr 24, 2024 16:35:54.057058096 CEST5734024150192.168.2.23147.78.12.176
                                                                                                                                                                    Apr 24, 2024 16:35:56.072782040 CEST5734024150192.168.2.23147.78.12.176
                                                                                                                                                                    Apr 24, 2024 16:36:00.264215946 CEST5734024150192.168.2.23147.78.12.176
                                                                                                                                                                    Apr 24, 2024 16:36:01.461327076 CEST5734224150192.168.2.23147.78.12.176
                                                                                                                                                                    Apr 24, 2024 16:36:02.471858025 CEST5734224150192.168.2.23147.78.12.176
                                                                                                                                                                    Apr 24, 2024 16:36:04.487556934 CEST5734224150192.168.2.23147.78.12.176
                                                                                                                                                                    Apr 24, 2024 16:36:08.711071014 CEST5734224150192.168.2.23147.78.12.176
                                                                                                                                                                    Apr 24, 2024 16:36:08.966972113 CEST43928443192.168.2.2391.189.91.42
                                                                                                                                                                    Apr 24, 2024 16:36:09.635462046 CEST5734424150192.168.2.23147.78.12.176
                                                                                                                                                                    Apr 24, 2024 16:36:10.662741899 CEST5734424150192.168.2.23147.78.12.176
                                                                                                                                                                    Apr 24, 2024 16:36:12.678468943 CEST5734424150192.168.2.23147.78.12.176
                                                                                                                                                                    Apr 24, 2024 16:36:16.901966095 CEST5734424150192.168.2.23147.78.12.176
                                                                                                                                                                    Apr 24, 2024 16:36:17.852740049 CEST5734624150192.168.2.23147.78.12.176
                                                                                                                                                                    Apr 24, 2024 16:36:18.853581905 CEST5734624150192.168.2.23147.78.12.176
                                                                                                                                                                    Apr 24, 2024 16:36:20.869415045 CEST5734624150192.168.2.23147.78.12.176
                                                                                                                                                                    Apr 24, 2024 16:36:25.092705011 CEST5734624150192.168.2.23147.78.12.176
                                                                                                                                                                    Apr 24, 2024 16:36:26.197412968 CEST5734824150192.168.2.23147.78.12.176
                                                                                                                                                                    Apr 24, 2024 16:36:27.204509974 CEST5734824150192.168.2.23147.78.12.176
                                                                                                                                                                    Apr 24, 2024 16:36:29.220093966 CEST5734824150192.168.2.23147.78.12.176
                                                                                                                                                                    Apr 24, 2024 16:36:29.444118977 CEST42836443192.168.2.2391.189.91.43
                                                                                                                                                                    Apr 24, 2024 16:36:33.283544064 CEST5734824150192.168.2.23147.78.12.176
                                                                                                                                                                    Apr 24, 2024 16:36:34.461404085 CEST5735024150192.168.2.23147.78.12.176
                                                                                                                                                                    Apr 24, 2024 16:36:35.491240978 CEST5735024150192.168.2.23147.78.12.176
                                                                                                                                                                    Apr 24, 2024 16:36:37.506917000 CEST5735024150192.168.2.23147.78.12.176
                                                                                                                                                                    Apr 24, 2024 16:36:41.730326891 CEST5735024150192.168.2.23147.78.12.176
                                                                                                                                                                    Apr 24, 2024 16:36:42.684119940 CEST5735224150192.168.2.23147.78.12.176
                                                                                                                                                                    Apr 24, 2024 16:36:43.714062929 CEST5735224150192.168.2.23147.78.12.176
                                                                                                                                                                    Apr 24, 2024 16:36:45.729811907 CEST5735224150192.168.2.23147.78.12.176
                                                                                                                                                                    Apr 24, 2024 16:36:49.921248913 CEST5735224150192.168.2.23147.78.12.176
                                                                                                                                                                    Apr 24, 2024 16:36:51.021585941 CEST5735424150192.168.2.23147.78.12.176
                                                                                                                                                                    Apr 24, 2024 16:36:52.032989979 CEST5735424150192.168.2.23147.78.12.176
                                                                                                                                                                    Apr 24, 2024 16:36:54.048589945 CEST5735424150192.168.2.23147.78.12.176
                                                                                                                                                                    Apr 24, 2024 16:36:58.112071037 CEST5735424150192.168.2.23147.78.12.176
                                                                                                                                                                    Apr 24, 2024 16:36:59.289858103 CEST5735624150192.168.2.23147.78.12.176
                                                                                                                                                                    Apr 24, 2024 16:36:59.920569897 CEST5735824150192.168.2.23147.78.12.176
                                                                                                                                                                    Apr 24, 2024 16:37:00.927683115 CEST5735824150192.168.2.23147.78.12.176
                                                                                                                                                                    Apr 24, 2024 16:37:02.943403006 CEST5735824150192.168.2.23147.78.12.176
                                                                                                                                                                    Apr 24, 2024 16:37:07.070839882 CEST5735824150192.168.2.23147.78.12.176
                                                                                                                                                                    Apr 24, 2024 16:37:08.250730038 CEST5736024150192.168.2.23147.78.12.176
                                                                                                                                                                    Apr 24, 2024 16:37:09.278485060 CEST5736024150192.168.2.23147.78.12.176
                                                                                                                                                                    Apr 24, 2024 16:37:11.294282913 CEST5736024150192.168.2.23147.78.12.176
                                                                                                                                                                    Apr 24, 2024 16:37:15.517633915 CEST5736024150192.168.2.23147.78.12.176
                                                                                                                                                                    TimestampSource PortDest PortSource IPDest IP
                                                                                                                                                                    Apr 24, 2024 16:35:07.265264988 CEST58303123192.168.2.23129.6.15.28
                                                                                                                                                                    Apr 24, 2024 16:35:07.481437922 CEST12358303129.6.15.28192.168.2.23
                                                                                                                                                                    Apr 24, 2024 16:35:07.498583078 CEST4944153192.168.2.238.8.4.4
                                                                                                                                                                    Apr 24, 2024 16:35:07.679660082 CEST53494418.8.4.4192.168.2.23
                                                                                                                                                                    Apr 24, 2024 16:35:15.726646900 CEST5112753192.168.2.23114.114.114.114
                                                                                                                                                                    Apr 24, 2024 16:35:16.055278063 CEST5351127114.114.114.114192.168.2.23
                                                                                                                                                                    Apr 24, 2024 16:35:19.431058884 CEST4532753192.168.2.23168.138.12.137
                                                                                                                                                                    Apr 24, 2024 16:35:19.757328033 CEST5345327168.138.12.137192.168.2.23
                                                                                                                                                                    Apr 24, 2024 16:35:28.012902021 CEST5888553192.168.2.238.8.4.4
                                                                                                                                                                    Apr 24, 2024 16:35:28.261620998 CEST53588858.8.4.4192.168.2.23
                                                                                                                                                                    Apr 24, 2024 16:35:36.460109949 CEST5601053192.168.2.23134.195.4.2
                                                                                                                                                                    Apr 24, 2024 16:35:36.632240057 CEST5356010134.195.4.2192.168.2.23
                                                                                                                                                                    Apr 24, 2024 16:35:44.650834084 CEST4588853192.168.2.231.0.0.1
                                                                                                                                                                    Apr 24, 2024 16:35:44.805025101 CEST53458881.0.0.1192.168.2.23
                                                                                                                                                                    Apr 24, 2024 16:35:52.841372967 CEST3839753192.168.2.23192.3.165.37
                                                                                                                                                                    Apr 24, 2024 16:35:53.055862904 CEST5338397192.3.165.37192.168.2.23
                                                                                                                                                                    Apr 24, 2024 16:36:01.288350105 CEST4499953192.168.2.23134.195.4.2
                                                                                                                                                                    Apr 24, 2024 16:36:01.460830927 CEST5344999134.195.4.2192.168.2.23
                                                                                                                                                                    Apr 24, 2024 16:36:09.479188919 CEST5407553192.168.2.231.0.0.1
                                                                                                                                                                    Apr 24, 2024 16:36:09.634666920 CEST53540751.0.0.1192.168.2.23
                                                                                                                                                                    Apr 24, 2024 16:36:17.669835091 CEST5024653192.168.2.238.8.4.4
                                                                                                                                                                    Apr 24, 2024 16:36:17.852420092 CEST53502468.8.4.4192.168.2.23
                                                                                                                                                                    Apr 24, 2024 16:36:25.860651970 CEST5972953192.168.2.23114.114.114.114
                                                                                                                                                                    Apr 24, 2024 16:36:26.197000027 CEST5359729114.114.114.114192.168.2.23
                                                                                                                                                                    Apr 24, 2024 16:36:34.307513952 CEST5308153192.168.2.231.0.0.1
                                                                                                                                                                    Apr 24, 2024 16:36:34.461061954 CEST53530811.0.0.1192.168.2.23
                                                                                                                                                                    Apr 24, 2024 16:36:42.498414993 CEST4385053192.168.2.238.8.4.4
                                                                                                                                                                    Apr 24, 2024 16:36:42.683537960 CEST53438508.8.4.4192.168.2.23
                                                                                                                                                                    Apr 24, 2024 16:36:50.689234018 CEST3537253192.168.2.23114.114.114.114
                                                                                                                                                                    Apr 24, 2024 16:36:51.021306992 CEST5335372114.114.114.114192.168.2.23
                                                                                                                                                                    Apr 24, 2024 16:36:59.136035919 CEST4056153192.168.2.231.0.0.1
                                                                                                                                                                    Apr 24, 2024 16:36:59.289354086 CEST53405611.0.0.1192.168.2.23
                                                                                                                                                                    Apr 24, 2024 16:36:59.764678001 CEST3285753192.168.2.231.0.0.1
                                                                                                                                                                    Apr 24, 2024 16:36:59.920195103 CEST53328571.0.0.1192.168.2.23
                                                                                                                                                                    Apr 24, 2024 16:37:08.094878912 CEST4893653192.168.2.231.1.1.1
                                                                                                                                                                    Apr 24, 2024 16:37:08.250333071 CEST53489361.1.1.1192.168.2.23
                                                                                                                                                                    TimestampSource IPDest IPChecksumCodeType
                                                                                                                                                                    Apr 24, 2024 16:35:19.430511951 CEST185.229.188.209192.168.2.235feb(Host unreachable)Destination Unreachable
                                                                                                                                                                    Apr 24, 2024 16:36:59.764338017 CEST185.229.188.211192.168.2.235feb(Host unreachable)Destination Unreachable
                                                                                                                                                                    TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                                                                                                                                                    Apr 24, 2024 16:35:07.498583078 CEST192.168.2.238.8.4.40x0Standard query (0)60da859e8a.dontargetme.nl16IN (0x0001)false
                                                                                                                                                                    Apr 24, 2024 16:35:15.726646900 CEST192.168.2.23114.114.114.1140x0Standard query (0)60da859e8a.websersaiosnginxo.ru16IN (0x0001)false
                                                                                                                                                                    Apr 24, 2024 16:35:19.431058884 CEST192.168.2.23168.138.12.1370x0Standard query (0)60da859e8a.adminpanel.oss16IN (0x0001)false
                                                                                                                                                                    Apr 24, 2024 16:35:28.012902021 CEST192.168.2.238.8.4.40x0Standard query (0)60da859e8a.admincs.duckdns.org16IN (0x0001)false
                                                                                                                                                                    Apr 24, 2024 16:35:36.460109949 CEST192.168.2.23134.195.4.20x0Standard query (0)60da859e8a.session.geek16IN (0x0001)false
                                                                                                                                                                    Apr 24, 2024 16:35:44.650834084 CEST192.168.2.231.0.0.10x0Standard query (0)60da859e8a.duckdns.org16IN (0x0001)false
                                                                                                                                                                    Apr 24, 2024 16:35:52.841372967 CEST192.168.2.23192.3.165.370x0Standard query (0)60da859e8a.geek16IN (0x0001)false
                                                                                                                                                                    Apr 24, 2024 16:36:01.288350105 CEST192.168.2.23134.195.4.20x0Standard query (0)60da859e8a.oss16IN (0x0001)false
                                                                                                                                                                    Apr 24, 2024 16:36:09.479188919 CEST192.168.2.231.0.0.10x0Standard query (0)60da859e8a.chickenkiller.com16IN (0x0001)false
                                                                                                                                                                    Apr 24, 2024 16:36:17.669835091 CEST192.168.2.238.8.4.40x0Standard query (0)60da859e8a.accesscam.org16IN (0x0001)false
                                                                                                                                                                    Apr 24, 2024 16:36:25.860651970 CEST192.168.2.23114.114.114.1140x0Standard query (0)60da859e8a.casacam.net16IN (0x0001)false
                                                                                                                                                                    Apr 24, 2024 16:36:34.307513952 CEST192.168.2.231.0.0.10x0Standard query (0)60da859e8a.ddnsfree.com16IN (0x0001)false
                                                                                                                                                                    Apr 24, 2024 16:36:42.498414993 CEST192.168.2.238.8.4.40x0Standard query (0)60da859e8a.mooo.com16IN (0x0001)false
                                                                                                                                                                    Apr 24, 2024 16:36:50.689234018 CEST192.168.2.23114.114.114.1140x0Standard query (0)60da859e8a.strangled.net16IN (0x0001)false
                                                                                                                                                                    Apr 24, 2024 16:36:59.136035919 CEST192.168.2.231.0.0.10x0Standard query (0)60da859e8a.ignorelist.com16IN (0x0001)false
                                                                                                                                                                    Apr 24, 2024 16:36:59.764678001 CEST192.168.2.231.0.0.10x0Standard query (0)60da859e8a.ru16IN (0x0001)false
                                                                                                                                                                    Apr 24, 2024 16:37:08.094878912 CEST192.168.2.231.1.1.10x0Standard query (0)60da859e8a.nl16IN (0x0001)false
                                                                                                                                                                    TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                                                                                                                                                    Apr 24, 2024 16:35:07.679660082 CEST8.8.4.4192.168.2.230x0No error (0)60da859e8a.dontargetme.nlTXT (Text strings)IN (0x0001)false
                                                                                                                                                                    Apr 24, 2024 16:35:16.055278063 CEST114.114.114.114192.168.2.230x0Name error (3)60da859e8a.websersaiosnginxo.runonenone16IN (0x0001)false
                                                                                                                                                                    Apr 24, 2024 16:35:19.757328033 CEST168.138.12.137192.168.2.230x0Name error (3)60da859e8a.adminpanel.ossnonenone16IN (0x0001)false
                                                                                                                                                                    Apr 24, 2024 16:35:28.261620998 CEST8.8.4.4192.168.2.230x0No error (0)60da859e8a.admincs.duckdns.orgTXT (Text strings)IN (0x0001)false
                                                                                                                                                                    Apr 24, 2024 16:35:36.632240057 CEST134.195.4.2192.168.2.230x0No error (0)60da859e8a.session.geekTXT (Text strings)IN (0x0001)false
                                                                                                                                                                    Apr 24, 2024 16:35:44.805025101 CEST1.0.0.1192.168.2.230x0Name error (3)60da859e8a.duckdns.orgnonenone16IN (0x0001)false
                                                                                                                                                                    Apr 24, 2024 16:35:53.055862904 CEST192.3.165.37192.168.2.230x0Name error (3)60da859e8a.geeknonenone16IN (0x0001)false
                                                                                                                                                                    Apr 24, 2024 16:36:01.460830927 CEST134.195.4.2192.168.2.230x0Name error (3)60da859e8a.ossnonenone16IN (0x0001)false
                                                                                                                                                                    Apr 24, 2024 16:36:09.634666920 CEST1.0.0.1192.168.2.230x0Name error (3)60da859e8a.chickenkiller.comnonenone16IN (0x0001)false
                                                                                                                                                                    Apr 24, 2024 16:36:17.852420092 CEST8.8.4.4192.168.2.230x0Name error (3)60da859e8a.accesscam.orgnonenone16IN (0x0001)false
                                                                                                                                                                    Apr 24, 2024 16:36:26.197000027 CEST114.114.114.114192.168.2.230x0Name error (3)60da859e8a.casacam.netnonenone16IN (0x0001)false
                                                                                                                                                                    Apr 24, 2024 16:36:34.461061954 CEST1.0.0.1192.168.2.230x0Name error (3)60da859e8a.ddnsfree.comnonenone16IN (0x0001)false
                                                                                                                                                                    Apr 24, 2024 16:36:42.683537960 CEST8.8.4.4192.168.2.230x0Name error (3)60da859e8a.mooo.comnonenone16IN (0x0001)false
                                                                                                                                                                    Apr 24, 2024 16:36:51.021306992 CEST114.114.114.114192.168.2.230x0Name error (3)60da859e8a.strangled.netnonenone16IN (0x0001)false
                                                                                                                                                                    Apr 24, 2024 16:36:59.289354086 CEST1.0.0.1192.168.2.230x0Name error (3)60da859e8a.ignorelist.comnonenone16IN (0x0001)false
                                                                                                                                                                    Apr 24, 2024 16:36:59.920195103 CEST1.0.0.1192.168.2.230x0Name error (3)60da859e8a.runonenone16IN (0x0001)false
                                                                                                                                                                    Apr 24, 2024 16:37:08.250333071 CEST1.1.1.1192.168.2.230x0Name error (3)60da859e8a.nlnonenone16IN (0x0001)false
                                                                                                                                                                    TimestampSource IPSource PortDest IPDest PortSubjectIssuerNot BeforeNot AfterJA3 SSL Client FingerprintJA3 SSL Client Digest
                                                                                                                                                                    Apr 24, 2024 16:35:23.191741943 CEST54.171.230.55443192.168.2.2333608CN=motd.ubuntu.com CN=R3, O=Let's Encrypt, C=USCN=R3, O=Let's Encrypt, C=US CN=ISRG Root X1, O=Internet Security Research Group, C=USThu Mar 07 10:27:55 CET 2024 Fri Sep 04 02:00:00 CEST 2020Wed Jun 05 11:27:54 CEST 2024 Mon Sep 15 18:00:00 CEST 2025771,4866-4867-4865-49196-49200-163-159-52393-52392-52394-49327-49325-49315-49311-49245-49249-49239-49235-49195-49199-162-158-49326-49324-49314-49310-49244-49248-49238-49234-49188-49192-107-106-49267-49271-196-195-49187-49191-103-64-49266-49270-190-189-49162-49172-57-56-136-135-49161-49171-51-50-69-68-157-49313-49309-49233-156-49312-49308-49232-61-192-60-186-53-132-47-65-255,0-11-10-35-22-23-13-43-45-51,29-23-30-25-24,0-1-2fb4726d465c5f28b84cd6d14cedd13a7
                                                                                                                                                                    CN=R3, O=Let's Encrypt, C=USCN=ISRG Root X1, O=Internet Security Research Group, C=USFri Sep 04 02:00:00 CEST 2020Mon Sep 15 18:00:00 CEST 2025

                                                                                                                                                                    System Behavior

                                                                                                                                                                    Start time (UTC):14:35:05
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/tmp/SecuriteInfo.com.Other.Malware-gen.3200.4135.elf
                                                                                                                                                                    Arguments:/tmp/SecuriteInfo.com.Other.Malware-gen.3200.4135.elf
                                                                                                                                                                    File size:4956856 bytes
                                                                                                                                                                    MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                                                                                                                                    Start time (UTC):14:35:05
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/tmp/SecuriteInfo.com.Other.Malware-gen.3200.4135.elf
                                                                                                                                                                    Arguments:-
                                                                                                                                                                    File size:4956856 bytes
                                                                                                                                                                    MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                                                                                                                                    Start time (UTC):14:35:05
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/bin/cp
                                                                                                                                                                    Arguments:cp -f /usr/bin/qemu-arm /var/tmp/nginx_kel
                                                                                                                                                                    File size:153976 bytes
                                                                                                                                                                    MD5 hash:40f10ae7ea3e44218d1a8c306f79c83f

                                                                                                                                                                    Start time (UTC):14:35:05
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/tmp/SecuriteInfo.com.Other.Malware-gen.3200.4135.elf
                                                                                                                                                                    Arguments:-
                                                                                                                                                                    File size:4956856 bytes
                                                                                                                                                                    MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                                                                                                                                    Start time (UTC):14:35:05
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/bin/sh
                                                                                                                                                                    Arguments:sh -c "mount -o bind /tmp/nginx_server /proc/6208/ > /dev/null 2>&1"
                                                                                                                                                                    File size:129816 bytes
                                                                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                                                                    Start time (UTC):14:35:05
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/bin/sh
                                                                                                                                                                    Arguments:-
                                                                                                                                                                    File size:129816 bytes
                                                                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                                                                    Start time (UTC):14:35:05
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/usr/bin/mount
                                                                                                                                                                    Arguments:mount -o bind /tmp/nginx_server /proc/6208/
                                                                                                                                                                    File size:55528 bytes
                                                                                                                                                                    MD5 hash:92b20aa8b155ecd3ba9414aa477ef565

                                                                                                                                                                    Start time (UTC):14:35:05
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/tmp/SecuriteInfo.com.Other.Malware-gen.3200.4135.elf
                                                                                                                                                                    Arguments:-
                                                                                                                                                                    File size:4956856 bytes
                                                                                                                                                                    MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                                                                                                                                    Start time (UTC):14:35:05
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/tmp/SecuriteInfo.com.Other.Malware-gen.3200.4135.elf
                                                                                                                                                                    Arguments:-
                                                                                                                                                                    File size:4956856 bytes
                                                                                                                                                                    MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                                                                                                                                    Start time (UTC):14:35:05
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/tmp/SecuriteInfo.com.Other.Malware-gen.3200.4135.elf
                                                                                                                                                                    Arguments:-
                                                                                                                                                                    File size:4956856 bytes
                                                                                                                                                                    MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                                                                                                                                    Start time (UTC):14:35:05
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/bin/sh
                                                                                                                                                                    Arguments:sh -c "ln -sf /etc/init.d/dnsconfig /etc/rcS.d/S99dnsconfig > /dev/null 2>&1"
                                                                                                                                                                    File size:129816 bytes
                                                                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                                                                    Start time (UTC):14:35:05
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/bin/sh
                                                                                                                                                                    Arguments:-
                                                                                                                                                                    File size:129816 bytes
                                                                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                                                                    Start time (UTC):14:35:05
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/usr/bin/ln
                                                                                                                                                                    Arguments:ln -sf /etc/init.d/dnsconfig /etc/rcS.d/S99dnsconfig
                                                                                                                                                                    File size:76160 bytes
                                                                                                                                                                    MD5 hash:e933cf05571f62c0157d4e2dfcaea282

                                                                                                                                                                    Start time (UTC):14:35:06
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/tmp/SecuriteInfo.com.Other.Malware-gen.3200.4135.elf
                                                                                                                                                                    Arguments:-
                                                                                                                                                                    File size:4956856 bytes
                                                                                                                                                                    MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                                                                                                                                    Start time (UTC):14:35:06
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/bin/sh
                                                                                                                                                                    Arguments:sh -c "ln -sf /etc/init.d/dnsconfig /etc/rc.d/S99dnsconfig > /dev/null 2>&1"
                                                                                                                                                                    File size:129816 bytes
                                                                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                                                                    Start time (UTC):14:35:06
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/bin/sh
                                                                                                                                                                    Arguments:-
                                                                                                                                                                    File size:129816 bytes
                                                                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                                                                    Start time (UTC):14:35:06
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/usr/bin/ln
                                                                                                                                                                    Arguments:ln -sf /etc/init.d/dnsconfig /etc/rc.d/S99dnsconfig
                                                                                                                                                                    File size:76160 bytes
                                                                                                                                                                    MD5 hash:e933cf05571f62c0157d4e2dfcaea282

                                                                                                                                                                    Start time (UTC):14:35:06
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/tmp/SecuriteInfo.com.Other.Malware-gen.3200.4135.elf
                                                                                                                                                                    Arguments:-
                                                                                                                                                                    File size:4956856 bytes
                                                                                                                                                                    MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                                                                                                                                    Start time (UTC):14:35:06
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/bin/sh
                                                                                                                                                                    Arguments:sh -c "ln -sf /etc/init.d/dnsconfig /etc/rc0.d/S99dnsconfig > /dev/null 2>&1"
                                                                                                                                                                    File size:129816 bytes
                                                                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                                                                    Start time (UTC):14:35:06
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/bin/sh
                                                                                                                                                                    Arguments:-
                                                                                                                                                                    File size:129816 bytes
                                                                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                                                                    Start time (UTC):14:35:06
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/usr/bin/ln
                                                                                                                                                                    Arguments:ln -sf /etc/init.d/dnsconfig /etc/rc0.d/S99dnsconfig
                                                                                                                                                                    File size:76160 bytes
                                                                                                                                                                    MD5 hash:e933cf05571f62c0157d4e2dfcaea282

                                                                                                                                                                    Start time (UTC):14:35:07
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/tmp/SecuriteInfo.com.Other.Malware-gen.3200.4135.elf
                                                                                                                                                                    Arguments:-
                                                                                                                                                                    File size:4956856 bytes
                                                                                                                                                                    MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                                                                                                                                    Start time (UTC):14:35:07
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/bin/sh
                                                                                                                                                                    Arguments:sh -c "ln -sf /etc/init.d/dnsconfig /etc/rc1.d/S99dnsconfig > /dev/null 2>&1"
                                                                                                                                                                    File size:129816 bytes
                                                                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                                                                    Start time (UTC):14:35:07
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/bin/sh
                                                                                                                                                                    Arguments:-
                                                                                                                                                                    File size:129816 bytes
                                                                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                                                                    Start time (UTC):14:35:07
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/usr/bin/ln
                                                                                                                                                                    Arguments:ln -sf /etc/init.d/dnsconfig /etc/rc1.d/S99dnsconfig
                                                                                                                                                                    File size:76160 bytes
                                                                                                                                                                    MD5 hash:e933cf05571f62c0157d4e2dfcaea282

                                                                                                                                                                    Start time (UTC):14:35:07
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/tmp/SecuriteInfo.com.Other.Malware-gen.3200.4135.elf
                                                                                                                                                                    Arguments:-
                                                                                                                                                                    File size:4956856 bytes
                                                                                                                                                                    MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                                                                                                                                    Start time (UTC):14:35:07
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/bin/sh
                                                                                                                                                                    Arguments:sh -c "ln -sf /etc/init.d/dnsconfig /etc/rc2.d/S99dnsconfig > /dev/null 2>&1"
                                                                                                                                                                    File size:129816 bytes
                                                                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                                                                    Start time (UTC):14:35:07
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/bin/sh
                                                                                                                                                                    Arguments:-
                                                                                                                                                                    File size:129816 bytes
                                                                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                                                                    Start time (UTC):14:35:07
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/usr/bin/ln
                                                                                                                                                                    Arguments:ln -sf /etc/init.d/dnsconfig /etc/rc2.d/S99dnsconfig
                                                                                                                                                                    File size:76160 bytes
                                                                                                                                                                    MD5 hash:e933cf05571f62c0157d4e2dfcaea282

                                                                                                                                                                    Start time (UTC):14:35:07
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/tmp/SecuriteInfo.com.Other.Malware-gen.3200.4135.elf
                                                                                                                                                                    Arguments:-
                                                                                                                                                                    File size:4956856 bytes
                                                                                                                                                                    MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                                                                                                                                    Start time (UTC):14:35:07
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/bin/sh
                                                                                                                                                                    Arguments:sh -c "ln -sf /etc/init.d/dnsconfig /etc/rc3.d/S99dnsconfig > /dev/null 2>&1"
                                                                                                                                                                    File size:129816 bytes
                                                                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                                                                    Start time (UTC):14:35:07
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/bin/sh
                                                                                                                                                                    Arguments:-
                                                                                                                                                                    File size:129816 bytes
                                                                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                                                                    Start time (UTC):14:35:07
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/usr/bin/ln
                                                                                                                                                                    Arguments:ln -sf /etc/init.d/dnsconfig /etc/rc3.d/S99dnsconfig
                                                                                                                                                                    File size:76160 bytes
                                                                                                                                                                    MD5 hash:e933cf05571f62c0157d4e2dfcaea282

                                                                                                                                                                    Start time (UTC):14:35:08
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/tmp/SecuriteInfo.com.Other.Malware-gen.3200.4135.elf
                                                                                                                                                                    Arguments:-
                                                                                                                                                                    File size:4956856 bytes
                                                                                                                                                                    MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                                                                                                                                    Start time (UTC):14:35:08
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/bin/sh
                                                                                                                                                                    Arguments:sh -c "ln -sf /etc/init.d/dnsconfig /etc/rc4.d/S99dnsconfig > /dev/null 2>&1"
                                                                                                                                                                    File size:129816 bytes
                                                                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                                                                    Start time (UTC):14:35:08
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/bin/sh
                                                                                                                                                                    Arguments:-
                                                                                                                                                                    File size:129816 bytes
                                                                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                                                                    Start time (UTC):14:35:08
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/usr/bin/ln
                                                                                                                                                                    Arguments:ln -sf /etc/init.d/dnsconfig /etc/rc4.d/S99dnsconfig
                                                                                                                                                                    File size:76160 bytes
                                                                                                                                                                    MD5 hash:e933cf05571f62c0157d4e2dfcaea282

                                                                                                                                                                    Start time (UTC):14:35:08
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/tmp/SecuriteInfo.com.Other.Malware-gen.3200.4135.elf
                                                                                                                                                                    Arguments:-
                                                                                                                                                                    File size:4956856 bytes
                                                                                                                                                                    MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                                                                                                                                    Start time (UTC):14:35:08
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/bin/sh
                                                                                                                                                                    Arguments:sh -c "ln -sf /etc/init.d/dnsconfig /etc/rc5.d/S99dnsconfig > /dev/null 2>&1"
                                                                                                                                                                    File size:129816 bytes
                                                                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                                                                    Start time (UTC):14:35:08
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/bin/sh
                                                                                                                                                                    Arguments:-
                                                                                                                                                                    File size:129816 bytes
                                                                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                                                                    Start time (UTC):14:35:08
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/usr/bin/ln
                                                                                                                                                                    Arguments:ln -sf /etc/init.d/dnsconfig /etc/rc5.d/S99dnsconfig
                                                                                                                                                                    File size:76160 bytes
                                                                                                                                                                    MD5 hash:e933cf05571f62c0157d4e2dfcaea282

                                                                                                                                                                    Start time (UTC):14:35:08
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/tmp/SecuriteInfo.com.Other.Malware-gen.3200.4135.elf
                                                                                                                                                                    Arguments:-
                                                                                                                                                                    File size:4956856 bytes
                                                                                                                                                                    MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                                                                                                                                    Start time (UTC):14:35:08
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/bin/sh
                                                                                                                                                                    Arguments:sh -c "ln -sf /etc/init.d/dnsconfig /etc/rc6.d/S99dnsconfig > /dev/null 2>&1"
                                                                                                                                                                    File size:129816 bytes
                                                                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                                                                    Start time (UTC):14:35:08
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/bin/sh
                                                                                                                                                                    Arguments:-
                                                                                                                                                                    File size:129816 bytes
                                                                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                                                                    Start time (UTC):14:35:08
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/usr/bin/ln
                                                                                                                                                                    Arguments:ln -sf /etc/init.d/dnsconfig /etc/rc6.d/S99dnsconfig
                                                                                                                                                                    File size:76160 bytes
                                                                                                                                                                    MD5 hash:e933cf05571f62c0157d4e2dfcaea282

                                                                                                                                                                    Start time (UTC):14:35:08
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/tmp/SecuriteInfo.com.Other.Malware-gen.3200.4135.elf
                                                                                                                                                                    Arguments:-
                                                                                                                                                                    File size:4956856 bytes
                                                                                                                                                                    MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                                                                                                                                    Start time (UTC):14:35:08
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/bin/sh
                                                                                                                                                                    Arguments:sh -c "ln -sf /etc/rc.d/init.d/dnsconfigs /etc/rc.d/S99dnsconfigs > /dev/null 2>&1"
                                                                                                                                                                    File size:129816 bytes
                                                                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                                                                    Start time (UTC):14:35:08
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/bin/sh
                                                                                                                                                                    Arguments:-
                                                                                                                                                                    File size:129816 bytes
                                                                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                                                                    Start time (UTC):14:35:08
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/usr/bin/ln
                                                                                                                                                                    Arguments:ln -sf /etc/rc.d/init.d/dnsconfigs /etc/rc.d/S99dnsconfigs
                                                                                                                                                                    File size:76160 bytes
                                                                                                                                                                    MD5 hash:e933cf05571f62c0157d4e2dfcaea282

                                                                                                                                                                    Start time (UTC):14:35:08
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/tmp/SecuriteInfo.com.Other.Malware-gen.3200.4135.elf
                                                                                                                                                                    Arguments:-
                                                                                                                                                                    File size:4956856 bytes
                                                                                                                                                                    MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                                                                                                                                    Start time (UTC):14:35:08
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/bin/sh
                                                                                                                                                                    Arguments:sh -c "ln -sf /etc/rc.d/init.d/dnsconfigs /etc/rc0.d/S99dnsconfigs > /dev/null 2>&1"
                                                                                                                                                                    File size:129816 bytes
                                                                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                                                                    Start time (UTC):14:35:08
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/bin/sh
                                                                                                                                                                    Arguments:-
                                                                                                                                                                    File size:129816 bytes
                                                                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                                                                    Start time (UTC):14:35:08
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/usr/bin/ln
                                                                                                                                                                    Arguments:ln -sf /etc/rc.d/init.d/dnsconfigs /etc/rc0.d/S99dnsconfigs
                                                                                                                                                                    File size:76160 bytes
                                                                                                                                                                    MD5 hash:e933cf05571f62c0157d4e2dfcaea282

                                                                                                                                                                    Start time (UTC):14:35:08
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/tmp/SecuriteInfo.com.Other.Malware-gen.3200.4135.elf
                                                                                                                                                                    Arguments:-
                                                                                                                                                                    File size:4956856 bytes
                                                                                                                                                                    MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                                                                                                                                    Start time (UTC):14:35:08
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/bin/sh
                                                                                                                                                                    Arguments:sh -c "ln -sf /etc/rc.d/init.d/dnsconfigs /etc/rc1.d/S99dnsconfigs > /dev/null 2>&1"
                                                                                                                                                                    File size:129816 bytes
                                                                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                                                                    Start time (UTC):14:35:08
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/bin/sh
                                                                                                                                                                    Arguments:-
                                                                                                                                                                    File size:129816 bytes
                                                                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                                                                    Start time (UTC):14:35:08
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/usr/bin/ln
                                                                                                                                                                    Arguments:ln -sf /etc/rc.d/init.d/dnsconfigs /etc/rc1.d/S99dnsconfigs
                                                                                                                                                                    File size:76160 bytes
                                                                                                                                                                    MD5 hash:e933cf05571f62c0157d4e2dfcaea282

                                                                                                                                                                    Start time (UTC):14:35:08
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/tmp/SecuriteInfo.com.Other.Malware-gen.3200.4135.elf
                                                                                                                                                                    Arguments:-
                                                                                                                                                                    File size:4956856 bytes
                                                                                                                                                                    MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                                                                                                                                    Start time (UTC):14:35:08
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/bin/sh
                                                                                                                                                                    Arguments:sh -c "ln -sf /etc/rc.d/init.d/dnsconfigs /etc/rc2.d/S99dnsconfigs > /dev/null 2>&1"
                                                                                                                                                                    File size:129816 bytes
                                                                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                                                                    Start time (UTC):14:35:08
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/bin/sh
                                                                                                                                                                    Arguments:-
                                                                                                                                                                    File size:129816 bytes
                                                                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                                                                    Start time (UTC):14:35:08
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/usr/bin/ln
                                                                                                                                                                    Arguments:ln -sf /etc/rc.d/init.d/dnsconfigs /etc/rc2.d/S99dnsconfigs
                                                                                                                                                                    File size:76160 bytes
                                                                                                                                                                    MD5 hash:e933cf05571f62c0157d4e2dfcaea282

                                                                                                                                                                    Start time (UTC):14:35:09
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/tmp/SecuriteInfo.com.Other.Malware-gen.3200.4135.elf
                                                                                                                                                                    Arguments:-
                                                                                                                                                                    File size:4956856 bytes
                                                                                                                                                                    MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                                                                                                                                    Start time (UTC):14:35:09
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/bin/sh
                                                                                                                                                                    Arguments:sh -c "ln -sf /etc/rc.d/init.d/dnsconfigs /etc/rc3.d/S99dnsconfigs > /dev/null 2>&1"
                                                                                                                                                                    File size:129816 bytes
                                                                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                                                                    Start time (UTC):14:35:09
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/bin/sh
                                                                                                                                                                    Arguments:-
                                                                                                                                                                    File size:129816 bytes
                                                                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                                                                    Start time (UTC):14:35:09
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/usr/bin/ln
                                                                                                                                                                    Arguments:ln -sf /etc/rc.d/init.d/dnsconfigs /etc/rc3.d/S99dnsconfigs
                                                                                                                                                                    File size:76160 bytes
                                                                                                                                                                    MD5 hash:e933cf05571f62c0157d4e2dfcaea282

                                                                                                                                                                    Start time (UTC):14:35:09
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/tmp/SecuriteInfo.com.Other.Malware-gen.3200.4135.elf
                                                                                                                                                                    Arguments:-
                                                                                                                                                                    File size:4956856 bytes
                                                                                                                                                                    MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                                                                                                                                    Start time (UTC):14:35:09
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/bin/sh
                                                                                                                                                                    Arguments:sh -c "ln -sf /etc/rc.d/init.d/dnsconfigs /etc/rc4.d/S99dnsconfigs > /dev/null 2>&1"
                                                                                                                                                                    File size:129816 bytes
                                                                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                                                                    Start time (UTC):14:35:09
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/bin/sh
                                                                                                                                                                    Arguments:-
                                                                                                                                                                    File size:129816 bytes
                                                                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                                                                    Start time (UTC):14:35:09
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/usr/bin/ln
                                                                                                                                                                    Arguments:ln -sf /etc/rc.d/init.d/dnsconfigs /etc/rc4.d/S99dnsconfigs
                                                                                                                                                                    File size:76160 bytes
                                                                                                                                                                    MD5 hash:e933cf05571f62c0157d4e2dfcaea282

                                                                                                                                                                    Start time (UTC):14:35:09
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/tmp/SecuriteInfo.com.Other.Malware-gen.3200.4135.elf
                                                                                                                                                                    Arguments:-
                                                                                                                                                                    File size:4956856 bytes
                                                                                                                                                                    MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                                                                                                                                    Start time (UTC):14:35:09
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/bin/sh
                                                                                                                                                                    Arguments:sh -c "ln -sf /etc/rc.d/init.d/dnsconfigs /etc/rc5.d/S99dnsconfigs > /dev/null 2>&1"
                                                                                                                                                                    File size:129816 bytes
                                                                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                                                                    Start time (UTC):14:35:09
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/bin/sh
                                                                                                                                                                    Arguments:-
                                                                                                                                                                    File size:129816 bytes
                                                                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                                                                    Start time (UTC):14:35:09
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/usr/bin/ln
                                                                                                                                                                    Arguments:ln -sf /etc/rc.d/init.d/dnsconfigs /etc/rc5.d/S99dnsconfigs
                                                                                                                                                                    File size:76160 bytes
                                                                                                                                                                    MD5 hash:e933cf05571f62c0157d4e2dfcaea282

                                                                                                                                                                    Start time (UTC):14:35:09
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/tmp/SecuriteInfo.com.Other.Malware-gen.3200.4135.elf
                                                                                                                                                                    Arguments:-
                                                                                                                                                                    File size:4956856 bytes
                                                                                                                                                                    MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                                                                                                                                    Start time (UTC):14:35:09
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/bin/sh
                                                                                                                                                                    Arguments:sh -c "ln -sf /etc/rc.d/init.d/dnsconfigs /etc/rc6.d/S99dnsconfigs > /dev/null 2>&1"
                                                                                                                                                                    File size:129816 bytes
                                                                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                                                                    Start time (UTC):14:35:10
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/bin/sh
                                                                                                                                                                    Arguments:-
                                                                                                                                                                    File size:129816 bytes
                                                                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                                                                    Start time (UTC):14:35:10
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/usr/bin/ln
                                                                                                                                                                    Arguments:ln -sf /etc/rc.d/init.d/dnsconfigs /etc/rc6.d/S99dnsconfigs
                                                                                                                                                                    File size:76160 bytes
                                                                                                                                                                    MD5 hash:e933cf05571f62c0157d4e2dfcaea282

                                                                                                                                                                    Start time (UTC):14:35:05
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/tmp/SecuriteInfo.com.Other.Malware-gen.3200.4135.elf
                                                                                                                                                                    Arguments:-
                                                                                                                                                                    File size:4956856 bytes
                                                                                                                                                                    MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                                                                                                                                    Start time (UTC):14:35:05
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/bin/sh
                                                                                                                                                                    Arguments:sh -c "crontab /var/tmp/.recoverys"
                                                                                                                                                                    File size:129816 bytes
                                                                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                                                                    Start time (UTC):14:35:05
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/bin/sh
                                                                                                                                                                    Arguments:-
                                                                                                                                                                    File size:129816 bytes
                                                                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                                                                    Start time (UTC):14:35:06
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/usr/bin/crontab
                                                                                                                                                                    Arguments:crontab /var/tmp/.recoverys
                                                                                                                                                                    File size:43720 bytes
                                                                                                                                                                    MD5 hash:66e521d421ac9b407699061bf21806f5

                                                                                                                                                                    Start time (UTC):14:35:06
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/tmp/SecuriteInfo.com.Other.Malware-gen.3200.4135.elf
                                                                                                                                                                    Arguments:-
                                                                                                                                                                    File size:4956856 bytes
                                                                                                                                                                    MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                                                                                                                                    Start time (UTC):14:35:06
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/bin/sh
                                                                                                                                                                    Arguments:sh -c "systemctl daemon-reload > /dev/null 2>&1"
                                                                                                                                                                    File size:129816 bytes
                                                                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                                                                    Start time (UTC):14:35:06
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/bin/sh
                                                                                                                                                                    Arguments:-
                                                                                                                                                                    File size:129816 bytes
                                                                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                                                                    Start time (UTC):14:35:06
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/usr/bin/systemctl
                                                                                                                                                                    Arguments:systemctl daemon-reload
                                                                                                                                                                    File size:996584 bytes
                                                                                                                                                                    MD5 hash:4deddfb6741481f68aeac522cc26ff4b

                                                                                                                                                                    Start time (UTC):14:35:07
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/tmp/SecuriteInfo.com.Other.Malware-gen.3200.4135.elf
                                                                                                                                                                    Arguments:-
                                                                                                                                                                    File size:4956856 bytes
                                                                                                                                                                    MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                                                                                                                                    Start time (UTC):14:35:07
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/bin/sh
                                                                                                                                                                    Arguments:sh -c "systemctl enable dnsconfigs.service > /dev/null 2>&1"
                                                                                                                                                                    File size:129816 bytes
                                                                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                                                                    Start time (UTC):14:35:07
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/bin/sh
                                                                                                                                                                    Arguments:-
                                                                                                                                                                    File size:129816 bytes
                                                                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                                                                    Start time (UTC):14:35:07
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/usr/bin/systemctl
                                                                                                                                                                    Arguments:systemctl enable dnsconfigs.service
                                                                                                                                                                    File size:996584 bytes
                                                                                                                                                                    MD5 hash:4deddfb6741481f68aeac522cc26ff4b

                                                                                                                                                                    Start time (UTC):14:35:08
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/tmp/SecuriteInfo.com.Other.Malware-gen.3200.4135.elf
                                                                                                                                                                    Arguments:-
                                                                                                                                                                    File size:4956856 bytes
                                                                                                                                                                    MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                                                                                                                                    Start time (UTC):14:35:08
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/bin/sh
                                                                                                                                                                    Arguments:sh -c "systemctl start dnsconfigs.service > /dev/null 2>&1"
                                                                                                                                                                    File size:129816 bytes
                                                                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                                                                    Start time (UTC):14:35:08
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/bin/sh
                                                                                                                                                                    Arguments:-
                                                                                                                                                                    File size:129816 bytes
                                                                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                                                                    Start time (UTC):14:35:08
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/usr/bin/systemctl
                                                                                                                                                                    Arguments:systemctl start dnsconfigs.service
                                                                                                                                                                    File size:996584 bytes
                                                                                                                                                                    MD5 hash:4deddfb6741481f68aeac522cc26ff4b

                                                                                                                                                                    Start time (UTC):14:35:05
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/tmp/SecuriteInfo.com.Other.Malware-gen.3200.4135.elf
                                                                                                                                                                    Arguments:-
                                                                                                                                                                    File size:4956856 bytes
                                                                                                                                                                    MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                                                                                                                                    Start time (UTC):14:35:05
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/tmp/SecuriteInfo.com.Other.Malware-gen.3200.4135.elf
                                                                                                                                                                    Arguments:-
                                                                                                                                                                    File size:4956856 bytes
                                                                                                                                                                    MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                                                                                                                                    Start time (UTC):14:35:05
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/bin/sh
                                                                                                                                                                    Arguments:sh -c "mount -o bind /tmp/nginx_server /proc/6240/ > /dev/null 2>&1"
                                                                                                                                                                    File size:129816 bytes
                                                                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                                                                    Start time (UTC):14:35:05
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/bin/sh
                                                                                                                                                                    Arguments:-
                                                                                                                                                                    File size:129816 bytes
                                                                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                                                                    Start time (UTC):14:35:05
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/usr/bin/mount
                                                                                                                                                                    Arguments:mount -o bind /tmp/nginx_server /proc/6240/
                                                                                                                                                                    File size:55528 bytes
                                                                                                                                                                    MD5 hash:92b20aa8b155ecd3ba9414aa477ef565

                                                                                                                                                                    Start time (UTC):14:35:06
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/tmp/SecuriteInfo.com.Other.Malware-gen.3200.4135.elf
                                                                                                                                                                    Arguments:-
                                                                                                                                                                    File size:4956856 bytes
                                                                                                                                                                    MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                                                                                                                                    Start time (UTC):14:35:05
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/usr/lib/udisks2/udisksd
                                                                                                                                                                    Arguments:-
                                                                                                                                                                    File size:483056 bytes
                                                                                                                                                                    MD5 hash:1d7ae439cc3d82fa6b127671ce037a24

                                                                                                                                                                    Start time (UTC):14:35:05
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/usr/sbin/dumpe2fs
                                                                                                                                                                    Arguments:dumpe2fs -h /dev/dm-0
                                                                                                                                                                    File size:31112 bytes
                                                                                                                                                                    MD5 hash:5c66f7d8f7681a40562cf049ad4b72b4

                                                                                                                                                                    Start time (UTC):14:35:06
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/usr/lib/udisks2/udisksd
                                                                                                                                                                    Arguments:-
                                                                                                                                                                    File size:483056 bytes
                                                                                                                                                                    MD5 hash:1d7ae439cc3d82fa6b127671ce037a24

                                                                                                                                                                    Start time (UTC):14:35:06
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/usr/sbin/dumpe2fs
                                                                                                                                                                    Arguments:dumpe2fs -h /dev/dm-0
                                                                                                                                                                    File size:31112 bytes
                                                                                                                                                                    MD5 hash:5c66f7d8f7681a40562cf049ad4b72b4

                                                                                                                                                                    Start time (UTC):14:35:06
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/usr/lib/udisks2/udisksd
                                                                                                                                                                    Arguments:-
                                                                                                                                                                    File size:483056 bytes
                                                                                                                                                                    MD5 hash:1d7ae439cc3d82fa6b127671ce037a24

                                                                                                                                                                    Start time (UTC):14:35:06
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/usr/sbin/dumpe2fs
                                                                                                                                                                    Arguments:dumpe2fs -h /dev/dm-0
                                                                                                                                                                    File size:31112 bytes
                                                                                                                                                                    MD5 hash:5c66f7d8f7681a40562cf049ad4b72b4

                                                                                                                                                                    Start time (UTC):14:35:07
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/usr/lib/systemd/systemd
                                                                                                                                                                    Arguments:-
                                                                                                                                                                    File size:1620224 bytes
                                                                                                                                                                    MD5 hash:9b2bec7092a40488108543f9334aab75

                                                                                                                                                                    Start time (UTC):14:35:07
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                                                                                                                                                    Arguments:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                                                                                                                                                    File size:22760 bytes
                                                                                                                                                                    MD5 hash:3633b075f40283ec938a2a6a89671b0e

                                                                                                                                                                    Start time (UTC):14:35:08
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/usr/lib/systemd/systemd
                                                                                                                                                                    Arguments:-
                                                                                                                                                                    File size:1620224 bytes
                                                                                                                                                                    MD5 hash:9b2bec7092a40488108543f9334aab75

                                                                                                                                                                    Start time (UTC):14:35:08
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                                                                                                                                                    Arguments:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                                                                                                                                                    File size:22760 bytes
                                                                                                                                                                    MD5 hash:3633b075f40283ec938a2a6a89671b0e

                                                                                                                                                                    Start time (UTC):14:35:09
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/usr/lib/systemd/systemd
                                                                                                                                                                    Arguments:-
                                                                                                                                                                    File size:1620224 bytes
                                                                                                                                                                    MD5 hash:9b2bec7092a40488108543f9334aab75

                                                                                                                                                                    Start time (UTC):14:35:22
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/usr/bin/dash
                                                                                                                                                                    Arguments:-
                                                                                                                                                                    File size:129816 bytes
                                                                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                                                                    Start time (UTC):14:35:22
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/usr/bin/rm
                                                                                                                                                                    Arguments:rm -f /tmp/tmp.W12VpjdjU0 /tmp/tmp.9MZwt69YkC /tmp/tmp.q0ZKQX1Uze
                                                                                                                                                                    File size:72056 bytes
                                                                                                                                                                    MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                                                                                                                                                    Start time (UTC):14:35:22
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/usr/bin/dash
                                                                                                                                                                    Arguments:-
                                                                                                                                                                    File size:129816 bytes
                                                                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                                                                    Start time (UTC):14:35:22
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/usr/bin/cat
                                                                                                                                                                    Arguments:cat /tmp/tmp.W12VpjdjU0
                                                                                                                                                                    File size:43416 bytes
                                                                                                                                                                    MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

                                                                                                                                                                    Start time (UTC):14:35:22
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/usr/bin/dash
                                                                                                                                                                    Arguments:-
                                                                                                                                                                    File size:129816 bytes
                                                                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                                                                    Start time (UTC):14:35:22
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/usr/bin/head
                                                                                                                                                                    Arguments:head -n 10
                                                                                                                                                                    File size:47480 bytes
                                                                                                                                                                    MD5 hash:fd96a67145172477dd57131396fc9608

                                                                                                                                                                    Start time (UTC):14:35:22
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/usr/bin/dash
                                                                                                                                                                    Arguments:-
                                                                                                                                                                    File size:129816 bytes
                                                                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                                                                    Start time (UTC):14:35:22
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/usr/bin/tr
                                                                                                                                                                    Arguments:tr -d \\000-\\011\\013\\014\\016-\\037
                                                                                                                                                                    File size:51544 bytes
                                                                                                                                                                    MD5 hash:fbd1402dd9f72d8ebfff00ce7c3a7bb5

                                                                                                                                                                    Start time (UTC):14:35:22
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/usr/bin/dash
                                                                                                                                                                    Arguments:-
                                                                                                                                                                    File size:129816 bytes
                                                                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                                                                    Start time (UTC):14:35:22
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/usr/bin/cut
                                                                                                                                                                    Arguments:cut -c -80
                                                                                                                                                                    File size:47480 bytes
                                                                                                                                                                    MD5 hash:d8ed0ea8f22c0de0f8692d4d9f1759d3

                                                                                                                                                                    Start time (UTC):14:35:22
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/usr/bin/dash
                                                                                                                                                                    Arguments:-
                                                                                                                                                                    File size:129816 bytes
                                                                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                                                                    Start time (UTC):14:35:22
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/usr/bin/cat
                                                                                                                                                                    Arguments:cat /tmp/tmp.W12VpjdjU0
                                                                                                                                                                    File size:43416 bytes
                                                                                                                                                                    MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

                                                                                                                                                                    Start time (UTC):14:35:22
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/usr/bin/dash
                                                                                                                                                                    Arguments:-
                                                                                                                                                                    File size:129816 bytes
                                                                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                                                                    Start time (UTC):14:35:22
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/usr/bin/head
                                                                                                                                                                    Arguments:head -n 10
                                                                                                                                                                    File size:47480 bytes
                                                                                                                                                                    MD5 hash:fd96a67145172477dd57131396fc9608

                                                                                                                                                                    Start time (UTC):14:35:22
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/usr/bin/dash
                                                                                                                                                                    Arguments:-
                                                                                                                                                                    File size:129816 bytes
                                                                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                                                                    Start time (UTC):14:35:22
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/usr/bin/tr
                                                                                                                                                                    Arguments:tr -d \\000-\\011\\013\\014\\016-\\037
                                                                                                                                                                    File size:51544 bytes
                                                                                                                                                                    MD5 hash:fbd1402dd9f72d8ebfff00ce7c3a7bb5

                                                                                                                                                                    Start time (UTC):14:35:22
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/usr/bin/dash
                                                                                                                                                                    Arguments:-
                                                                                                                                                                    File size:129816 bytes
                                                                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                                                                    Start time (UTC):14:35:22
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/usr/bin/cut
                                                                                                                                                                    Arguments:cut -c -80
                                                                                                                                                                    File size:47480 bytes
                                                                                                                                                                    MD5 hash:d8ed0ea8f22c0de0f8692d4d9f1759d3

                                                                                                                                                                    Start time (UTC):14:35:22
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/usr/bin/dash
                                                                                                                                                                    Arguments:-
                                                                                                                                                                    File size:129816 bytes
                                                                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                                                                    Start time (UTC):14:35:22
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/usr/bin/rm
                                                                                                                                                                    Arguments:rm -f /tmp/tmp.W12VpjdjU0 /tmp/tmp.9MZwt69YkC /tmp/tmp.q0ZKQX1Uze
                                                                                                                                                                    File size:72056 bytes
                                                                                                                                                                    MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                                                                                                                                                    Start time (UTC):14:36:09
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/usr/lib/systemd/systemd
                                                                                                                                                                    Arguments:-
                                                                                                                                                                    File size:1620224 bytes
                                                                                                                                                                    MD5 hash:9b2bec7092a40488108543f9334aab75

                                                                                                                                                                    Start time (UTC):14:36:09
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/var/tmp/nginx_kel
                                                                                                                                                                    Arguments:/var/tmp/nginx_kel sv
                                                                                                                                                                    File size:4956856 bytes
                                                                                                                                                                    MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                                                                                                                                    Start time (UTC):14:37:09
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/usr/lib/systemd/systemd
                                                                                                                                                                    Arguments:-
                                                                                                                                                                    File size:1620224 bytes
                                                                                                                                                                    MD5 hash:9b2bec7092a40488108543f9334aab75

                                                                                                                                                                    Start time (UTC):14:37:09
                                                                                                                                                                    Start date (UTC):24/04/2024
                                                                                                                                                                    Path:/var/tmp/nginx_kel
                                                                                                                                                                    Arguments:/var/tmp/nginx_kel sv
                                                                                                                                                                    File size:4956856 bytes
                                                                                                                                                                    MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1