Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
ssa.elf

Overview

General Information

Sample name:ssa.elf
Analysis ID:1587321
MD5:bfdb94bee37b0e7705691ce092aa9884
SHA1:1572dbd674abc131f94eb99867808dd15ac8d84f
SHA256:f603f667217b42a92ebf6b4dbec5aab922290915673e1b49f8244a72231f13e2
Tags:elfuser-abuse_ch
Infos:

Detection

Score:80
Range:0 - 100
Whitelisted:false

Signatures

Antivirus / Scanner detection for submitted sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Machine Learning detection for sample
Sample tries to persist itself using cron
Sample tries to set files in /etc globally writable
Writes identical ELF files to multiple locations
Creates hidden files and/or directories
Executes the "rm" command used to delete files or directories
Sample tries to set the executable flag
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Writes ELF files to disk
Yara signature match

Classification

Joe Sandbox version:42.0.0 Malachite
Analysis ID:1587321
Start date and time:2025-01-10 07:07:06 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 6m 37s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:ssa.elf
Detection:MAL
Classification:mal80.troj.linELF@0/43@0/0
  • VT rate limit hit for: http://cf0.pw/0/etc/cron.hourly/0
  • VT rate limit hit for: https://translationproject.org/team/
  • VT rate limit hit for: https://wiki.xiph.org/MIME_Types_and_File_Extensions
  • VT rate limit hit for: https://wiki.xiph.org/MIME_Types_and_File_Extensions.oga
  • VT rate limit hit for: https://wiki.xiph.org/MIME_Types_and_File_Extensions.ogv
Command:/tmp/ssa.elf
PID:6278
Exit Code:
Exit Code Info:
Killed:True
Standard Output:

Standard Error:
  • system is lnxubuntu20
  • dash New Fork (PID: 6249, Parent: 4331)
  • rm (PID: 6249, Parent: 4331, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.61DXa86J11 /tmp/tmp.Z31iyKedgj /tmp/tmp.6ukCyQKaFl
  • dash New Fork (PID: 6250, Parent: 4331)
  • rm (PID: 6250, Parent: 4331, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.61DXa86J11 /tmp/tmp.Z31iyKedgj /tmp/tmp.6ukCyQKaFl
  • ssa.elf (PID: 6278, Parent: 6179, MD5: bfdb94bee37b0e7705691ce092aa9884) Arguments: /tmp/ssa.elf
    • ssa.elf New Fork (PID: 6281, Parent: 6278)
    • filesZIILS (PID: 6281, Parent: 6278, MD5: bfdb94bee37b0e7705691ce092aa9884) Arguments: /tmp/ssa.elf
      • fileqph2w9 (PID: 6287, Parent: 6281, MD5: bfdb94bee37b0e7705691ce092aa9884) Arguments: /tmp/ssa.elf
        • file9xgtsA (PID: 6290, Parent: 6287, MD5: bfdb94bee37b0e7705691ce092aa9884) Arguments: /tmp/ssa.elf
          • fileFTsWOP (PID: 6310, Parent: 6290, MD5: bfdb94bee37b0e7705691ce092aa9884) Arguments: /tmp/ssa.elf
            • fileY0Ofem (PID: 6313, Parent: 6310, MD5: bfdb94bee37b0e7705691ce092aa9884) Arguments: /tmp/ssa.elf
              • filewZ3vJw (PID: 6316, Parent: 6313, MD5: bfdb94bee37b0e7705691ce092aa9884) Arguments: /tmp/ssa.elf
                • file6dYPaN (PID: 6320, Parent: 6316, MD5: bfdb94bee37b0e7705691ce092aa9884) Arguments: /tmp/ssa.elf
                  • file3voGS3 (PID: 6325, Parent: 6320, MD5: bfdb94bee37b0e7705691ce092aa9884) Arguments: /tmp/ssa.elf
                    • filecLo1bv (PID: 6330, Parent: 6325, MD5: bfdb94bee37b0e7705691ce092aa9884) Arguments: /tmp/ssa.elf
                      • filek7i3uP (PID: 6333, Parent: 6330, MD5: bfdb94bee37b0e7705691ce092aa9884) Arguments: /tmp/ssa.elf
                        • fileFAvB93 (PID: 6336, Parent: 6333, MD5: bfdb94bee37b0e7705691ce092aa9884) Arguments: /tmp/ssa.elf
                          • fileAyj87h (PID: 6340, Parent: 6336, MD5: bfdb94bee37b0e7705691ce092aa9884) Arguments: /tmp/ssa.elf
                            • filelpjDaB (PID: 6343, Parent: 6340, MD5: bfdb94bee37b0e7705691ce092aa9884) Arguments: /tmp/ssa.elf
                              • fileiIcyzN (PID: 6346, Parent: 6343, MD5: bfdb94bee37b0e7705691ce092aa9884) Arguments: /tmp/ssa.elf
                                • file0exOS4 (PID: 6351, Parent: 6346, MD5: bfdb94bee37b0e7705691ce092aa9884) Arguments: /tmp/ssa.elf
                                  • fileVXRF8s (PID: 6354, Parent: 6351, MD5: bfdb94bee37b0e7705691ce092aa9884) Arguments: /tmp/ssa.elf
                                    • filepfbdRG (PID: 6359, Parent: 6354, MD5: bfdb94bee37b0e7705691ce092aa9884) Arguments: /tmp/ssa.elf
                                      • fileFBsYn2 (PID: 6362, Parent: 6359, MD5: bfdb94bee37b0e7705691ce092aa9884) Arguments: /tmp/ssa.elf
                                        • fileYWlxCh (PID: 6367, Parent: 6362, MD5: bfdb94bee37b0e7705691ce092aa9884) Arguments: /tmp/ssa.elf
                                          • fileT2tUzC (PID: 6372, Parent: 6367, MD5: bfdb94bee37b0e7705691ce092aa9884) Arguments: /tmp/ssa.elf
                                            • file30mPH0 (PID: 6375, Parent: 6372, MD5: bfdb94bee37b0e7705691ce092aa9884) Arguments: /tmp/ssa.elf
                                              • filelqfWgf (PID: 6379, Parent: 6375, MD5: bfdb94bee37b0e7705691ce092aa9884) Arguments: /tmp/ssa.elf
                                                • fileg1aioy (PID: 6382, Parent: 6379, MD5: bfdb94bee37b0e7705691ce092aa9884) Arguments: /tmp/ssa.elf
                                                  • fileLAS8lK (PID: 6387, Parent: 6382, MD5: bfdb94bee37b0e7705691ce092aa9884) Arguments: /tmp/ssa.elf
                                                    • filegFEB67 (PID: 6390, Parent: 6387, MD5: bfdb94bee37b0e7705691ce092aa9884) Arguments: /tmp/ssa.elf
                                                      • fileR5OlIm (PID: 6393, Parent: 6390, MD5: bfdb94bee37b0e7705691ce092aa9884) Arguments: /tmp/ssa.elf
                                                        • fileqhyxmA (PID: 6397, Parent: 6393, MD5: bfdb94bee37b0e7705691ce092aa9884) Arguments: /tmp/ssa.elf
                                                          • fileyst50V (PID: 6406, Parent: 6397, MD5: bfdb94bee37b0e7705691ce092aa9884) Arguments: /tmp/ssa.elf
                                                            • filezmxBFz (PID: 6409, Parent: 6406, MD5: bfdb94bee37b0e7705691ce092aa9884) Arguments: /tmp/ssa.elf
  • cleanup
SourceRuleDescriptionAuthorStrings
ssa.elfLinux_Trojan_Ladvix_db41f9d2unknownunknown
  • 0x14b7:$a: C0 49 89 C4 74 45 45 85 ED 7E 26 48 89 C3 41 8D 45 FF 4D 8D 7C
SourceRuleDescriptionAuthorStrings
6278.1.000055676b66b000.000055676b66d000.r-x.sdmpLinux_Trojan_Ladvix_db41f9d2unknownunknown
  • 0x14b7:$a: C0 49 89 C4 74 45 45 85 ED 7E 26 48 89 C3 41 8D 45 FF 4D 8D 7C
6278.1.000055676cb52000.000055676cb73000.rw-.sdmpLinux_Trojan_Ladvix_db41f9d2unknownunknown
  • 0x9c27:$a: C0 49 89 C4 74 45 45 85 ED 7E 26 48 89 C3 41 8D 45 FF 4D 8D 7C
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: ssa.elfAvira: detected
Source: ssa.elfVirustotal: Detection: 59%Perma Link
Source: ssa.elfReversingLabs: Detection: 65%
Source: ssa.elfJoe Sandbox ML: detected
Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: ssa.elf, 6278.1.000055676cb52000.000055676cb73000.rw-.sdmpString found in binary or memory: http://cf0.pw/0/etc/cron.hourly/0
Source: ssa.elf, 6278.1.00007f7ab7c24000.00007f7ab7c47000.rw-.sdmpString found in binary or memory: https://gnu.org/licenses/gpl.html
Source: ssa.elf, 6278.1.00007f7ab7c24000.00007f7ab7c47000.rw-.sdmpString found in binary or memory: https://translationproject.org/team/
Source: ssa.elf, 6278.1.00007f7ab7c24000.00007f7ab7c47000.rw-.sdmpString found in binary or memory: https://wiki.xiph.org/MIME_Types_and_File_Extensions
Source: ssa.elf, 6278.1.00007f7ab7c24000.00007f7ab7c47000.rw-.sdmpString found in binary or memory: https://wiki.xiph.org/MIME_Types_and_File_Extensions.oga
Source: ssa.elf, 6278.1.00007f7ab7c24000.00007f7ab7c47000.rw-.sdmpString found in binary or memory: https://wiki.xiph.org/MIME_Types_and_File_Extensions.ogv
Source: ssa.elf, 6278.1.00007f7ab7c24000.00007f7ab7c47000.rw-.sdmpString found in binary or memory: https://www.gnu.org/gethelp/
Source: ssa.elf, 6278.1.00007f7ab7c24000.00007f7ab7c47000.rw-.sdmpString found in binary or memory: https://www.gnu.org/software/coreutils/
Source: ssa.elf, 6278.1.00007f7ab7c24000.00007f7ab7c47000.rw-.sdmpString found in binary or memory: https://www.gnu.org/software/coreutils/Report
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443

System Summary

barindex
Source: ssa.elf, type: SAMPLEMatched rule: Linux_Trojan_Ladvix_db41f9d2 Author: unknown
Source: 6278.1.000055676b66b000.000055676b66d000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 Author: unknown
Source: 6278.1.000055676cb52000.000055676cb73000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 Author: unknown
Source: ssa.elf, type: SAMPLEMatched rule: Linux_Trojan_Ladvix_db41f9d2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Ladvix, fingerprint = d0aaa680e81f44cc555bf7799d33fce66f172563788afb2ad0fb16d3e460e8c6, id = db41f9d2-aa5c-4d26-b8ba-cece44eddca8, last_modified = 2021-09-16
Source: 6278.1.000055676b66b000.000055676b66d000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Ladvix, fingerprint = d0aaa680e81f44cc555bf7799d33fce66f172563788afb2ad0fb16d3e460e8c6, id = db41f9d2-aa5c-4d26-b8ba-cece44eddca8, last_modified = 2021-09-16
Source: 6278.1.000055676cb52000.000055676cb73000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Ladvix, fingerprint = d0aaa680e81f44cc555bf7799d33fce66f172563788afb2ad0fb16d3e460e8c6, id = db41f9d2-aa5c-4d26-b8ba-cece44eddca8, last_modified = 2021-09-16
Source: classification engineClassification label: mal80.troj.linELF@0/43@0/0

Persistence and Installation Behavior

barindex
Source: /tmp/ssa.elf (PID: 6278)File: /etc/cron.hourly/0Jump to behavior
Source: /tmp/ssa.elf (PID: 6278)File: /etc/cron.hourly/0 (bits: uv usr: rwx grp: rwx all: rwx)Jump to behavior
Source: /tmp/filezmxBFz (PID: 6409)File with SHA-256 3E622D164B9019C69007C48BCE7AF738062D0C6C3B4D6B5B3A5A71CFBBDBCB7E written: /tmp/fileQ6PloQJump to dropped file
Source: /tmp/fileyst50V (PID: 6406)File with SHA-256 3E622D164B9019C69007C48BCE7AF738062D0C6C3B4D6B5B3A5A71CFBBDBCB7E written: /tmp/filezmxBFzJump to dropped file
Source: /tmp/file6MzccC (PID: 6438)File with SHA-256 3E622D164B9019C69007C48BCE7AF738062D0C6C3B4D6B5B3A5A71CFBBDBCB7E written: /tmp/filePxLHKYJump to dropped file
Source: /tmp/filecLo1bv (PID: 6330)File with SHA-256 3E622D164B9019C69007C48BCE7AF738062D0C6C3B4D6B5B3A5A71CFBBDBCB7E written: /tmp/filek7i3uPJump to dropped file
Source: /tmp/fileVXRF8s (PID: 6354)File with SHA-256 3E622D164B9019C69007C48BCE7AF738062D0C6C3B4D6B5B3A5A71CFBBDBCB7E written: /tmp/filepfbdRGJump to dropped file
Source: /tmp/filelqfWgf (PID: 6379)File with SHA-256 3E622D164B9019C69007C48BCE7AF738062D0C6C3B4D6B5B3A5A71CFBBDBCB7E written: /tmp/fileg1aioyJump to dropped file
Source: /tmp/fileWWcCKb (PID: 6417)File with SHA-256 3E622D164B9019C69007C48BCE7AF738062D0C6C3B4D6B5B3A5A71CFBBDBCB7E written: /tmp/file7pm3GpJump to dropped file
Source: /tmp/fileqhyxmA (PID: 6397)File with SHA-256 3E622D164B9019C69007C48BCE7AF738062D0C6C3B4D6B5B3A5A71CFBBDBCB7E written: /tmp/fileyst50VJump to dropped file
Source: /tmp/filepfbdRG (PID: 6359)File with SHA-256 3E622D164B9019C69007C48BCE7AF738062D0C6C3B4D6B5B3A5A71CFBBDBCB7E written: /tmp/fileFBsYn2Jump to dropped file
Source: /tmp/filepbk33b (PID: 6430)File with SHA-256 3E622D164B9019C69007C48BCE7AF738062D0C6C3B4D6B5B3A5A71CFBBDBCB7E written: /tmp/filevSAJrqJump to dropped file
Source: /tmp/fileAyj87h (PID: 6340)File with SHA-256 3E622D164B9019C69007C48BCE7AF738062D0C6C3B4D6B5B3A5A71CFBBDBCB7E written: /tmp/filelpjDaBJump to dropped file
Source: /tmp/fileYWlxCh (PID: 6367)File with SHA-256 3E622D164B9019C69007C48BCE7AF738062D0C6C3B4D6B5B3A5A71CFBBDBCB7E written: /tmp/fileT2tUzCJump to dropped file
Source: /tmp/file6dYPaN (PID: 6320)File with SHA-256 3E622D164B9019C69007C48BCE7AF738062D0C6C3B4D6B5B3A5A71CFBBDBCB7E written: /tmp/file3voGS3Jump to dropped file
Source: /tmp/fileFBsYn2 (PID: 6362)File with SHA-256 3E622D164B9019C69007C48BCE7AF738062D0C6C3B4D6B5B3A5A71CFBBDBCB7E written: /tmp/fileYWlxChJump to dropped file
Source: /tmp/filePxLHKY (PID: 6442)File with SHA-256 3E622D164B9019C69007C48BCE7AF738062D0C6C3B4D6B5B3A5A71CFBBDBCB7E written: /tmp/filebJHN4hJump to dropped file
Source: /tmp/fileJuQrAG (PID: 6450)File with SHA-256 3E622D164B9019C69007C48BCE7AF738062D0C6C3B4D6B5B3A5A71CFBBDBCB7E written: /tmp/fileCsunoXJump to dropped file
Source: /tmp/file30mPH0 (PID: 6375)File with SHA-256 3E622D164B9019C69007C48BCE7AF738062D0C6C3B4D6B5B3A5A71CFBBDBCB7E written: /tmp/filelqfWgfJump to dropped file
Source: /tmp/fileFTsWOP (PID: 6310)File with SHA-256 3E622D164B9019C69007C48BCE7AF738062D0C6C3B4D6B5B3A5A71CFBBDBCB7E written: /tmp/fileY0OfemJump to dropped file
Source: /tmp/fileqph2w9 (PID: 6287)File with SHA-256 3E622D164B9019C69007C48BCE7AF738062D0C6C3B4D6B5B3A5A71CFBBDBCB7E written: /tmp/file9xgtsAJump to dropped file
Source: /tmp/file3voGS3 (PID: 6325)File with SHA-256 3E622D164B9019C69007C48BCE7AF738062D0C6C3B4D6B5B3A5A71CFBBDBCB7E written: /tmp/filecLo1bvJump to dropped file
Source: /tmp/fileT2tUzC (PID: 6372)File with SHA-256 3E622D164B9019C69007C48BCE7AF738062D0C6C3B4D6B5B3A5A71CFBBDBCB7E written: /tmp/file30mPH0Jump to dropped file
Source: /tmp/fileg1aioy (PID: 6382)File with SHA-256 3E622D164B9019C69007C48BCE7AF738062D0C6C3B4D6B5B3A5A71CFBBDBCB7E written: /tmp/fileLAS8lKJump to dropped file
Source: /tmp/fileQ6PloQ (PID: 6414)File with SHA-256 3E622D164B9019C69007C48BCE7AF738062D0C6C3B4D6B5B3A5A71CFBBDBCB7E written: /tmp/fileWWcCKbJump to dropped file
Source: /tmp/filecprMtT (PID: 6427)File with SHA-256 3E622D164B9019C69007C48BCE7AF738062D0C6C3B4D6B5B3A5A71CFBBDBCB7E written: /tmp/filepbk33bJump to dropped file
Source: /tmp/filevSAJrq (PID: 6433)File with SHA-256 3E622D164B9019C69007C48BCE7AF738062D0C6C3B4D6B5B3A5A71CFBBDBCB7E written: /tmp/file6MzccCJump to dropped file
Source: /tmp/filek7i3uP (PID: 6333)File with SHA-256 3E622D164B9019C69007C48BCE7AF738062D0C6C3B4D6B5B3A5A71CFBBDBCB7E written: /tmp/fileFAvB93Jump to dropped file
Source: /tmp/filegFEB67 (PID: 6390)File with SHA-256 3E622D164B9019C69007C48BCE7AF738062D0C6C3B4D6B5B3A5A71CFBBDBCB7E written: /tmp/fileR5OlImJump to dropped file
Source: /tmp/file5qrfjk (PID: 6459)File with SHA-256 3E622D164B9019C69007C48BCE7AF738062D0C6C3B4D6B5B3A5A71CFBBDBCB7E written: /tmp/fileO7mQVzJump to dropped file
Source: /tmp/fileLAS8lK (PID: 6387)File with SHA-256 3E622D164B9019C69007C48BCE7AF738062D0C6C3B4D6B5B3A5A71CFBBDBCB7E written: /tmp/filegFEB67Jump to dropped file
Source: /tmp/file9xgtsA (PID: 6290)File with SHA-256 3E622D164B9019C69007C48BCE7AF738062D0C6C3B4D6B5B3A5A71CFBBDBCB7E written: /tmp/fileFTsWOPJump to dropped file
Source: /tmp/fileFAvB93 (PID: 6336)File with SHA-256 3E622D164B9019C69007C48BCE7AF738062D0C6C3B4D6B5B3A5A71CFBBDBCB7E written: /tmp/fileAyj87hJump to dropped file
Source: /tmp/fileiIcyzN (PID: 6346)File with SHA-256 3E622D164B9019C69007C48BCE7AF738062D0C6C3B4D6B5B3A5A71CFBBDBCB7E written: /tmp/file0exOS4Jump to dropped file
Source: /tmp/filesZIILS (PID: 6281)File with SHA-256 3E622D164B9019C69007C48BCE7AF738062D0C6C3B4D6B5B3A5A71CFBBDBCB7E written: /tmp/fileqph2w9Jump to dropped file
Source: /tmp/filewZ3vJw (PID: 6316)File with SHA-256 3E622D164B9019C69007C48BCE7AF738062D0C6C3B4D6B5B3A5A71CFBBDBCB7E written: /tmp/file6dYPaNJump to dropped file
Source: /tmp/file7pm3Gp (PID: 6423)File with SHA-256 3E622D164B9019C69007C48BCE7AF738062D0C6C3B4D6B5B3A5A71CFBBDBCB7E written: /tmp/filecprMtTJump to dropped file
Source: /tmp/fileR5OlIm (PID: 6393)File with SHA-256 3E622D164B9019C69007C48BCE7AF738062D0C6C3B4D6B5B3A5A71CFBBDBCB7E written: /tmp/fileqhyxmAJump to dropped file
Source: /tmp/filebJHN4h (PID: 6447)File with SHA-256 3E622D164B9019C69007C48BCE7AF738062D0C6C3B4D6B5B3A5A71CFBBDBCB7E written: /tmp/fileJuQrAGJump to dropped file
Source: /tmp/file0exOS4 (PID: 6351)File with SHA-256 3E622D164B9019C69007C48BCE7AF738062D0C6C3B4D6B5B3A5A71CFBBDBCB7E written: /tmp/fileVXRF8sJump to dropped file
Source: /tmp/fileCsunoX (PID: 6455)File with SHA-256 3E622D164B9019C69007C48BCE7AF738062D0C6C3B4D6B5B3A5A71CFBBDBCB7E written: /tmp/file5qrfjkJump to dropped file
Source: /tmp/fileY0Ofem (PID: 6313)File with SHA-256 3E622D164B9019C69007C48BCE7AF738062D0C6C3B4D6B5B3A5A71CFBBDBCB7E written: /tmp/filewZ3vJwJump to dropped file
Source: /tmp/filelpjDaB (PID: 6343)File with SHA-256 3E622D164B9019C69007C48BCE7AF738062D0C6C3B4D6B5B3A5A71CFBBDBCB7E written: /tmp/fileiIcyzNJump to dropped file
Source: /tmp/ssa.elf (PID: 6278)Directory: /tmp/.X11-unixJump to behavior
Source: /tmp/ssa.elf (PID: 6278)Directory: /tmp/.Test-unixJump to behavior
Source: /tmp/ssa.elf (PID: 6278)Directory: /tmp/.font-unixJump to behavior
Source: /tmp/ssa.elf (PID: 6278)Directory: /tmp/.ICE-unixJump to behavior
Source: /tmp/ssa.elf (PID: 6278)Directory: /tmp/.Jump to behavior
Source: /tmp/ssa.elf (PID: 6278)Directory: /tmp/..Jump to behavior
Source: /tmp/ssa.elf (PID: 6278)Directory: /tmp/.XIM-unixJump to behavior
Source: /tmp/ssa.elf (PID: 6278)Directory: /tmp/.xfsm-ICE-S33I80Jump to behavior
Source: /tmp/filesZIILS (PID: 6281)Directory: /tmp/.X11-unixJump to behavior
Source: /tmp/filesZIILS (PID: 6281)Directory: /tmp/.Test-unixJump to behavior
Source: /tmp/filesZIILS (PID: 6281)Directory: /tmp/.font-unixJump to behavior
Source: /tmp/filesZIILS (PID: 6281)Directory: /tmp/.ICE-unixJump to behavior
Source: /tmp/filesZIILS (PID: 6281)Directory: /tmp/.Jump to behavior
Source: /tmp/filesZIILS (PID: 6281)Directory: /tmp/..Jump to behavior
Source: /tmp/filesZIILS (PID: 6281)Directory: /tmp/.XIM-unixJump to behavior
Source: /tmp/filesZIILS (PID: 6281)Directory: /tmp/.xfsm-ICE-S33I80Jump to behavior
Source: /tmp/fileqph2w9 (PID: 6287)Directory: /tmp/.X11-unixJump to behavior
Source: /tmp/fileqph2w9 (PID: 6287)Directory: /tmp/.Test-unixJump to behavior
Source: /tmp/fileqph2w9 (PID: 6287)Directory: /tmp/.font-unixJump to behavior
Source: /tmp/fileqph2w9 (PID: 6287)Directory: /tmp/.ICE-unixJump to behavior
Source: /tmp/fileqph2w9 (PID: 6287)Directory: /tmp/.Jump to behavior
Source: /tmp/fileqph2w9 (PID: 6287)Directory: /tmp/..Jump to behavior
Source: /tmp/fileqph2w9 (PID: 6287)Directory: /tmp/.XIM-unixJump to behavior
Source: /tmp/fileqph2w9 (PID: 6287)Directory: /tmp/.xfsm-ICE-S33I80Jump to behavior
Source: /tmp/file9xgtsA (PID: 6290)Directory: /tmp/.X11-unixJump to behavior
Source: /tmp/file9xgtsA (PID: 6290)Directory: /tmp/.Test-unixJump to behavior
Source: /tmp/file9xgtsA (PID: 6290)Directory: /tmp/.font-unixJump to behavior
Source: /tmp/file9xgtsA (PID: 6290)Directory: /tmp/.ICE-unixJump to behavior
Source: /tmp/file9xgtsA (PID: 6290)Directory: /tmp/.Jump to behavior
Source: /tmp/file9xgtsA (PID: 6290)Directory: /tmp/..Jump to behavior
Source: /tmp/file9xgtsA (PID: 6290)Directory: /tmp/.XIM-unixJump to behavior
Source: /tmp/file9xgtsA (PID: 6290)Directory: /tmp/.xfsm-ICE-S33I80Jump to behavior
Source: /tmp/fileFTsWOP (PID: 6310)Directory: /tmp/.X11-unixJump to behavior
Source: /tmp/fileFTsWOP (PID: 6310)Directory: /tmp/.Test-unixJump to behavior
Source: /tmp/fileFTsWOP (PID: 6310)Directory: /tmp/.font-unixJump to behavior
Source: /tmp/fileFTsWOP (PID: 6310)Directory: /tmp/.ICE-unixJump to behavior
Source: /tmp/fileFTsWOP (PID: 6310)Directory: /tmp/.Jump to behavior
Source: /tmp/fileFTsWOP (PID: 6310)Directory: /tmp/..Jump to behavior
Source: /tmp/fileFTsWOP (PID: 6310)Directory: /tmp/.XIM-unixJump to behavior
Source: /tmp/fileFTsWOP (PID: 6310)Directory: /tmp/.xfsm-ICE-S33I80Jump to behavior
Source: /tmp/fileY0Ofem (PID: 6313)Directory: /tmp/.X11-unixJump to behavior
Source: /tmp/fileY0Ofem (PID: 6313)Directory: /tmp/.Test-unixJump to behavior
Source: /tmp/fileY0Ofem (PID: 6313)Directory: /tmp/.font-unixJump to behavior
Source: /tmp/fileY0Ofem (PID: 6313)Directory: /tmp/.ICE-unixJump to behavior
Source: /tmp/fileY0Ofem (PID: 6313)Directory: /tmp/.Jump to behavior
Source: /tmp/fileY0Ofem (PID: 6313)Directory: /tmp/..Jump to behavior
Source: /tmp/fileY0Ofem (PID: 6313)Directory: /tmp/.XIM-unixJump to behavior
Source: /tmp/fileY0Ofem (PID: 6313)Directory: /tmp/.xfsm-ICE-S33I80Jump to behavior
Source: /tmp/filewZ3vJw (PID: 6316)Directory: /tmp/.X11-unixJump to behavior
Source: /tmp/filewZ3vJw (PID: 6316)Directory: /tmp/.Test-unixJump to behavior
Source: /tmp/filewZ3vJw (PID: 6316)Directory: /tmp/.font-unixJump to behavior
Source: /tmp/filewZ3vJw (PID: 6316)Directory: /tmp/.ICE-unixJump to behavior
Source: /tmp/filewZ3vJw (PID: 6316)Directory: /tmp/.Jump to behavior
Source: /tmp/filewZ3vJw (PID: 6316)Directory: /tmp/..Jump to behavior
Source: /tmp/filewZ3vJw (PID: 6316)Directory: /tmp/.XIM-unixJump to behavior
Source: /tmp/filewZ3vJw (PID: 6316)Directory: /tmp/.xfsm-ICE-S33I80Jump to behavior
Source: /tmp/file6dYPaN (PID: 6320)Directory: /tmp/.X11-unixJump to behavior
Source: /tmp/file6dYPaN (PID: 6320)Directory: /tmp/.Test-unixJump to behavior
Source: /tmp/file6dYPaN (PID: 6320)Directory: /tmp/.font-unixJump to behavior
Source: /tmp/file6dYPaN (PID: 6320)Directory: /tmp/.ICE-unixJump to behavior
Source: /tmp/file6dYPaN (PID: 6320)Directory: /tmp/.Jump to behavior
Source: /tmp/file6dYPaN (PID: 6320)Directory: /tmp/..Jump to behavior
Source: /tmp/file6dYPaN (PID: 6320)Directory: /tmp/.XIM-unixJump to behavior
Source: /tmp/file6dYPaN (PID: 6320)Directory: /tmp/.xfsm-ICE-S33I80Jump to behavior
Source: /tmp/file3voGS3 (PID: 6325)Directory: /tmp/.X11-unixJump to behavior
Source: /tmp/file3voGS3 (PID: 6325)Directory: /tmp/.Test-unixJump to behavior
Source: /tmp/file3voGS3 (PID: 6325)Directory: /tmp/.font-unixJump to behavior
Source: /tmp/file3voGS3 (PID: 6325)Directory: /tmp/.ICE-unixJump to behavior
Source: /tmp/file3voGS3 (PID: 6325)Directory: /tmp/.Jump to behavior
Source: /tmp/file3voGS3 (PID: 6325)Directory: /tmp/..Jump to behavior
Source: /tmp/file3voGS3 (PID: 6325)Directory: /tmp/.XIM-unixJump to behavior
Source: /tmp/file3voGS3 (PID: 6325)Directory: /tmp/.xfsm-ICE-S33I80Jump to behavior
Source: /tmp/filecLo1bv (PID: 6330)Directory: /tmp/.X11-unixJump to behavior
Source: /tmp/filecLo1bv (PID: 6330)Directory: /tmp/.Test-unixJump to behavior
Source: /tmp/filecLo1bv (PID: 6330)Directory: /tmp/.font-unixJump to behavior
Source: /tmp/filecLo1bv (PID: 6330)Directory: /tmp/.ICE-unixJump to behavior
Source: /tmp/filecLo1bv (PID: 6330)Directory: /tmp/.Jump to behavior
Source: /tmp/filecLo1bv (PID: 6330)Directory: /tmp/..Jump to behavior
Source: /tmp/filecLo1bv (PID: 6330)Directory: /tmp/.XIM-unixJump to behavior
Source: /tmp/filecLo1bv (PID: 6330)Directory: /tmp/.xfsm-ICE-S33I80Jump to behavior
Source: /tmp/filek7i3uP (PID: 6333)Directory: /tmp/.X11-unixJump to behavior
Source: /tmp/filek7i3uP (PID: 6333)Directory: /tmp/.Test-unixJump to behavior
Source: /tmp/filek7i3uP (PID: 6333)Directory: /tmp/.font-unixJump to behavior
Source: /tmp/filek7i3uP (PID: 6333)Directory: /tmp/.ICE-unixJump to behavior
Source: /tmp/filek7i3uP (PID: 6333)Directory: /tmp/.Jump to behavior
Source: /tmp/filek7i3uP (PID: 6333)Directory: /tmp/..Jump to behavior
Source: /tmp/filek7i3uP (PID: 6333)Directory: /tmp/.XIM-unixJump to behavior
Source: /tmp/filek7i3uP (PID: 6333)Directory: /tmp/.xfsm-ICE-S33I80Jump to behavior
Source: /tmp/fileFAvB93 (PID: 6336)Directory: /tmp/.X11-unixJump to behavior
Source: /tmp/fileFAvB93 (PID: 6336)Directory: /tmp/.Test-unixJump to behavior
Source: /tmp/fileFAvB93 (PID: 6336)Directory: /tmp/.font-unixJump to behavior
Source: /tmp/fileFAvB93 (PID: 6336)Directory: /tmp/.ICE-unixJump to behavior
Source: /tmp/fileFAvB93 (PID: 6336)Directory: /tmp/.Jump to behavior
Source: /tmp/fileFAvB93 (PID: 6336)Directory: /tmp/..Jump to behavior
Source: /tmp/fileFAvB93 (PID: 6336)Directory: /tmp/.XIM-unixJump to behavior
Source: /tmp/fileFAvB93 (PID: 6336)Directory: /tmp/.xfsm-ICE-S33I80Jump to behavior
Source: /tmp/fileAyj87h (PID: 6340)Directory: /tmp/.X11-unixJump to behavior
Source: /tmp/fileAyj87h (PID: 6340)Directory: /tmp/.Test-unixJump to behavior
Source: /tmp/fileAyj87h (PID: 6340)Directory: /tmp/.font-unixJump to behavior
Source: /tmp/fileAyj87h (PID: 6340)Directory: /tmp/.ICE-unixJump to behavior
Source: /tmp/fileAyj87h (PID: 6340)Directory: /tmp/.Jump to behavior
Source: /tmp/fileAyj87h (PID: 6340)Directory: /tmp/..Jump to behavior
Source: /tmp/fileAyj87h (PID: 6340)Directory: /tmp/.XIM-unixJump to behavior
Source: /tmp/fileAyj87h (PID: 6340)Directory: /tmp/.xfsm-ICE-S33I80Jump to behavior
Source: /tmp/filelpjDaB (PID: 6343)Directory: /tmp/.X11-unixJump to behavior
Source: /tmp/filelpjDaB (PID: 6343)Directory: /tmp/.Test-unixJump to behavior
Source: /tmp/filelpjDaB (PID: 6343)Directory: /tmp/.font-unixJump to behavior
Source: /tmp/filelpjDaB (PID: 6343)Directory: /tmp/.ICE-unixJump to behavior
Source: /tmp/filelpjDaB (PID: 6343)Directory: /tmp/.Jump to behavior
Source: /tmp/filelpjDaB (PID: 6343)Directory: /tmp/..Jump to behavior
Source: /tmp/filelpjDaB (PID: 6343)Directory: /tmp/.XIM-unixJump to behavior
Source: /tmp/filelpjDaB (PID: 6343)Directory: /tmp/.xfsm-ICE-S33I80Jump to behavior
Source: /tmp/fileiIcyzN (PID: 6346)Directory: /tmp/.X11-unixJump to behavior
Source: /tmp/fileiIcyzN (PID: 6346)Directory: /tmp/.Test-unixJump to behavior
Source: /tmp/fileiIcyzN (PID: 6346)Directory: /tmp/.font-unixJump to behavior
Source: /tmp/fileiIcyzN (PID: 6346)Directory: /tmp/.ICE-unixJump to behavior
Source: /tmp/fileiIcyzN (PID: 6346)Directory: /tmp/.Jump to behavior
Source: /tmp/fileiIcyzN (PID: 6346)Directory: /tmp/..Jump to behavior
Source: /tmp/fileiIcyzN (PID: 6346)Directory: /tmp/.XIM-unixJump to behavior
Source: /tmp/fileiIcyzN (PID: 6346)Directory: /tmp/.xfsm-ICE-S33I80Jump to behavior
Source: /tmp/file0exOS4 (PID: 6351)Directory: /tmp/.X11-unixJump to behavior
Source: /tmp/file0exOS4 (PID: 6351)Directory: /tmp/.Test-unixJump to behavior
Source: /tmp/file0exOS4 (PID: 6351)Directory: /tmp/.font-unixJump to behavior
Source: /tmp/file0exOS4 (PID: 6351)Directory: /tmp/.ICE-unixJump to behavior
Source: /tmp/file0exOS4 (PID: 6351)Directory: /tmp/.Jump to behavior
Source: /tmp/file0exOS4 (PID: 6351)Directory: /tmp/..Jump to behavior
Source: /tmp/file0exOS4 (PID: 6351)Directory: /tmp/.XIM-unixJump to behavior
Source: /tmp/file0exOS4 (PID: 6351)Directory: /tmp/.xfsm-ICE-S33I80Jump to behavior
Source: /tmp/fileVXRF8s (PID: 6354)Directory: /tmp/.X11-unixJump to behavior
Source: /tmp/fileVXRF8s (PID: 6354)Directory: /tmp/.Test-unixJump to behavior
Source: /tmp/fileVXRF8s (PID: 6354)Directory: /tmp/.font-unixJump to behavior
Source: /tmp/fileVXRF8s (PID: 6354)Directory: /tmp/.ICE-unixJump to behavior
Source: /tmp/fileVXRF8s (PID: 6354)Directory: /tmp/.Jump to behavior
Source: /tmp/fileVXRF8s (PID: 6354)Directory: /tmp/..Jump to behavior
Source: /tmp/fileVXRF8s (PID: 6354)Directory: /tmp/.XIM-unixJump to behavior
Source: /tmp/fileVXRF8s (PID: 6354)Directory: /tmp/.xfsm-ICE-S33I80Jump to behavior
Source: /tmp/filepfbdRG (PID: 6359)Directory: /tmp/.X11-unixJump to behavior
Source: /tmp/filepfbdRG (PID: 6359)Directory: /tmp/.Test-unixJump to behavior
Source: /tmp/filepfbdRG (PID: 6359)Directory: /tmp/.font-unixJump to behavior
Source: /tmp/filepfbdRG (PID: 6359)Directory: /tmp/.ICE-unixJump to behavior
Source: /tmp/filepfbdRG (PID: 6359)Directory: /tmp/.Jump to behavior
Source: /tmp/filepfbdRG (PID: 6359)Directory: /tmp/..Jump to behavior
Source: /tmp/filepfbdRG (PID: 6359)Directory: /tmp/.XIM-unixJump to behavior
Source: /tmp/filepfbdRG (PID: 6359)Directory: /tmp/.xfsm-ICE-S33I80Jump to behavior
Source: /tmp/fileFBsYn2 (PID: 6362)Directory: /tmp/.X11-unixJump to behavior
Source: /tmp/fileFBsYn2 (PID: 6362)Directory: /tmp/.Test-unixJump to behavior
Source: /tmp/fileFBsYn2 (PID: 6362)Directory: /tmp/.font-unixJump to behavior
Source: /tmp/fileFBsYn2 (PID: 6362)Directory: /tmp/.ICE-unixJump to behavior
Source: /tmp/fileFBsYn2 (PID: 6362)Directory: /tmp/.Jump to behavior
Source: /tmp/fileFBsYn2 (PID: 6362)Directory: /tmp/..Jump to behavior
Source: /tmp/fileFBsYn2 (PID: 6362)Directory: /tmp/.XIM-unixJump to behavior
Source: /tmp/fileFBsYn2 (PID: 6362)Directory: /tmp/.xfsm-ICE-S33I80Jump to behavior
Source: /tmp/fileYWlxCh (PID: 6367)Directory: /tmp/.X11-unixJump to behavior
Source: /tmp/fileYWlxCh (PID: 6367)Directory: /tmp/.Test-unixJump to behavior
Source: /tmp/fileYWlxCh (PID: 6367)Directory: /tmp/.font-unixJump to behavior
Source: /tmp/fileYWlxCh (PID: 6367)Directory: /tmp/.ICE-unixJump to behavior
Source: /tmp/fileYWlxCh (PID: 6367)Directory: /tmp/.Jump to behavior
Source: /tmp/fileYWlxCh (PID: 6367)Directory: /tmp/..Jump to behavior
Source: /tmp/fileYWlxCh (PID: 6367)Directory: /tmp/.XIM-unixJump to behavior
Source: /tmp/fileYWlxCh (PID: 6367)Directory: /tmp/.xfsm-ICE-S33I80Jump to behavior
Source: /tmp/fileT2tUzC (PID: 6372)Directory: /tmp/.X11-unixJump to behavior
Source: /tmp/fileT2tUzC (PID: 6372)Directory: /tmp/.Test-unixJump to behavior
Source: /tmp/fileT2tUzC (PID: 6372)Directory: /tmp/.font-unixJump to behavior
Source: /tmp/fileT2tUzC (PID: 6372)Directory: /tmp/.ICE-unixJump to behavior
Source: /tmp/fileT2tUzC (PID: 6372)Directory: /tmp/.Jump to behavior
Source: /tmp/fileT2tUzC (PID: 6372)Directory: /tmp/..Jump to behavior
Source: /tmp/fileT2tUzC (PID: 6372)Directory: /tmp/.XIM-unixJump to behavior
Source: /tmp/fileT2tUzC (PID: 6372)Directory: /tmp/.xfsm-ICE-S33I80Jump to behavior
Source: /tmp/file30mPH0 (PID: 6375)Directory: /tmp/.X11-unixJump to behavior
Source: /tmp/file30mPH0 (PID: 6375)Directory: /tmp/.Test-unixJump to behavior
Source: /tmp/file30mPH0 (PID: 6375)Directory: /tmp/.font-unixJump to behavior
Source: /tmp/file30mPH0 (PID: 6375)Directory: /tmp/.ICE-unixJump to behavior
Source: /tmp/file30mPH0 (PID: 6375)Directory: /tmp/.Jump to behavior
Source: /tmp/file30mPH0 (PID: 6375)Directory: /tmp/..Jump to behavior
Source: /tmp/file30mPH0 (PID: 6375)Directory: /tmp/.XIM-unixJump to behavior
Source: /tmp/file30mPH0 (PID: 6375)Directory: /tmp/.xfsm-ICE-S33I80Jump to behavior
Source: /tmp/filelqfWgf (PID: 6379)Directory: /tmp/.X11-unixJump to behavior
Source: /tmp/filelqfWgf (PID: 6379)Directory: /tmp/.Test-unixJump to behavior
Source: /tmp/filelqfWgf (PID: 6379)Directory: /tmp/.font-unixJump to behavior
Source: /tmp/filelqfWgf (PID: 6379)Directory: /tmp/.ICE-unixJump to behavior
Source: /tmp/filelqfWgf (PID: 6379)Directory: /tmp/.Jump to behavior
Source: /tmp/filelqfWgf (PID: 6379)Directory: /tmp/..Jump to behavior
Source: /tmp/filelqfWgf (PID: 6379)Directory: /tmp/.XIM-unixJump to behavior
Source: /tmp/filelqfWgf (PID: 6379)Directory: /tmp/.xfsm-ICE-S33I80Jump to behavior
Source: /tmp/fileg1aioy (PID: 6382)Directory: /tmp/.X11-unixJump to behavior
Source: /tmp/fileg1aioy (PID: 6382)Directory: /tmp/.Test-unixJump to behavior
Source: /tmp/fileg1aioy (PID: 6382)Directory: /tmp/.font-unixJump to behavior
Source: /tmp/fileg1aioy (PID: 6382)Directory: /tmp/.ICE-unixJump to behavior
Source: /tmp/fileg1aioy (PID: 6382)Directory: /tmp/.Jump to behavior
Source: /tmp/fileg1aioy (PID: 6382)Directory: /tmp/..Jump to behavior
Source: /tmp/fileg1aioy (PID: 6382)Directory: /tmp/.XIM-unixJump to behavior
Source: /tmp/fileg1aioy (PID: 6382)Directory: /tmp/.xfsm-ICE-S33I80Jump to behavior
Source: /tmp/fileLAS8lK (PID: 6387)Directory: /tmp/.X11-unixJump to behavior
Source: /tmp/fileLAS8lK (PID: 6387)Directory: /tmp/.Test-unixJump to behavior
Source: /tmp/fileLAS8lK (PID: 6387)Directory: /tmp/.font-unixJump to behavior
Source: /tmp/fileLAS8lK (PID: 6387)Directory: /tmp/.ICE-unixJump to behavior
Source: /tmp/fileLAS8lK (PID: 6387)Directory: /tmp/.Jump to behavior
Source: /tmp/fileLAS8lK (PID: 6387)Directory: /tmp/..Jump to behavior
Source: /tmp/fileLAS8lK (PID: 6387)Directory: /tmp/.XIM-unixJump to behavior
Source: /tmp/fileLAS8lK (PID: 6387)Directory: /tmp/.xfsm-ICE-S33I80Jump to behavior
Source: /tmp/filegFEB67 (PID: 6390)Directory: /tmp/.X11-unixJump to behavior
Source: /tmp/filegFEB67 (PID: 6390)Directory: /tmp/.Test-unixJump to behavior
Source: /tmp/filegFEB67 (PID: 6390)Directory: /tmp/.font-unixJump to behavior
Source: /tmp/filegFEB67 (PID: 6390)Directory: /tmp/.ICE-unixJump to behavior
Source: /tmp/filegFEB67 (PID: 6390)Directory: /tmp/.Jump to behavior
Source: /tmp/filegFEB67 (PID: 6390)Directory: /tmp/..Jump to behavior
Source: /tmp/filegFEB67 (PID: 6390)Directory: /tmp/.XIM-unixJump to behavior
Source: /tmp/filegFEB67 (PID: 6390)Directory: /tmp/.xfsm-ICE-S33I80Jump to behavior
Source: /tmp/fileR5OlIm (PID: 6393)Directory: /tmp/.X11-unixJump to behavior
Source: /tmp/fileR5OlIm (PID: 6393)Directory: /tmp/.Test-unixJump to behavior
Source: /tmp/fileR5OlIm (PID: 6393)Directory: /tmp/.font-unixJump to behavior
Source: /tmp/fileR5OlIm (PID: 6393)Directory: /tmp/.ICE-unixJump to behavior
Source: /tmp/fileR5OlIm (PID: 6393)Directory: /tmp/.Jump to behavior
Source: /tmp/fileR5OlIm (PID: 6393)Directory: /tmp/..Jump to behavior
Source: /tmp/fileR5OlIm (PID: 6393)Directory: /tmp/.XIM-unixJump to behavior
Source: /tmp/fileR5OlIm (PID: 6393)Directory: /tmp/.xfsm-ICE-S33I80Jump to behavior
Source: /tmp/fileqhyxmA (PID: 6397)Directory: /tmp/.X11-unixJump to behavior
Source: /tmp/fileqhyxmA (PID: 6397)Directory: /tmp/.Test-unixJump to behavior
Source: /tmp/fileqhyxmA (PID: 6397)Directory: /tmp/.font-unixJump to behavior
Source: /tmp/fileqhyxmA (PID: 6397)Directory: /tmp/.ICE-unixJump to behavior
Source: /tmp/fileqhyxmA (PID: 6397)Directory: /tmp/.Jump to behavior
Source: /tmp/fileqhyxmA (PID: 6397)Directory: /tmp/..Jump to behavior
Source: /tmp/fileqhyxmA (PID: 6397)Directory: /tmp/.XIM-unixJump to behavior
Source: /tmp/fileqhyxmA (PID: 6397)Directory: /tmp/.xfsm-ICE-S33I80Jump to behavior
Source: /tmp/fileyst50V (PID: 6406)Directory: /tmp/.X11-unixJump to behavior
Source: /tmp/fileyst50V (PID: 6406)Directory: /tmp/.Test-unixJump to behavior
Source: /tmp/fileyst50V (PID: 6406)Directory: /tmp/.font-unixJump to behavior
Source: /tmp/fileyst50V (PID: 6406)Directory: /tmp/.ICE-unixJump to behavior
Source: /tmp/fileyst50V (PID: 6406)Directory: /tmp/.Jump to behavior
Source: /tmp/fileyst50V (PID: 6406)Directory: /tmp/..Jump to behavior
Source: /tmp/fileyst50V (PID: 6406)Directory: /tmp/.XIM-unixJump to behavior
Source: /tmp/fileyst50V (PID: 6406)Directory: /tmp/.xfsm-ICE-S33I80Jump to behavior
Source: /tmp/filezmxBFz (PID: 6409)Directory: /tmp/.X11-unixJump to behavior
Source: /tmp/filezmxBFz (PID: 6409)Directory: /tmp/.Test-unixJump to behavior
Source: /tmp/filezmxBFz (PID: 6409)Directory: /tmp/.font-unixJump to behavior
Source: /tmp/filezmxBFz (PID: 6409)Directory: /tmp/.ICE-unixJump to behavior
Source: /tmp/filezmxBFz (PID: 6409)Directory: /tmp/.Jump to behavior
Source: /tmp/filezmxBFz (PID: 6409)Directory: /tmp/..Jump to behavior
Source: /tmp/filezmxBFz (PID: 6409)Directory: /tmp/.XIM-unixJump to behavior
Source: /tmp/filezmxBFz (PID: 6409)Directory: /tmp/.xfsm-ICE-S33I80Jump to behavior
Source: /tmp/fileQ6PloQ (PID: 6414)Directory: /tmp/.X11-unixJump to behavior
Source: /tmp/fileQ6PloQ (PID: 6414)Directory: /tmp/.Test-unixJump to behavior
Source: /tmp/fileQ6PloQ (PID: 6414)Directory: /tmp/.font-unixJump to behavior
Source: /tmp/fileQ6PloQ (PID: 6414)Directory: /tmp/.ICE-unixJump to behavior
Source: /tmp/fileQ6PloQ (PID: 6414)Directory: /tmp/.Jump to behavior
Source: /tmp/fileQ6PloQ (PID: 6414)Directory: /tmp/..Jump to behavior
Source: /tmp/fileQ6PloQ (PID: 6414)Directory: /tmp/.XIM-unixJump to behavior
Source: /tmp/fileQ6PloQ (PID: 6414)Directory: /tmp/.xfsm-ICE-S33I80Jump to behavior
Source: /tmp/fileWWcCKb (PID: 6417)Directory: /tmp/.X11-unixJump to behavior
Source: /tmp/fileWWcCKb (PID: 6417)Directory: /tmp/.Test-unixJump to behavior
Source: /tmp/fileWWcCKb (PID: 6417)Directory: /tmp/.font-unixJump to behavior
Source: /tmp/fileWWcCKb (PID: 6417)Directory: /tmp/.ICE-unixJump to behavior
Source: /tmp/fileWWcCKb (PID: 6417)Directory: /tmp/.Jump to behavior
Source: /tmp/fileWWcCKb (PID: 6417)Directory: /tmp/..Jump to behavior
Source: /tmp/fileWWcCKb (PID: 6417)Directory: /tmp/.XIM-unixJump to behavior
Source: /tmp/fileWWcCKb (PID: 6417)Directory: /tmp/.xfsm-ICE-S33I80Jump to behavior
Source: /tmp/file7pm3Gp (PID: 6423)Directory: /tmp/.X11-unixJump to behavior
Source: /tmp/file7pm3Gp (PID: 6423)Directory: /tmp/.Test-unixJump to behavior
Source: /tmp/file7pm3Gp (PID: 6423)Directory: /tmp/.font-unixJump to behavior
Source: /tmp/file7pm3Gp (PID: 6423)Directory: /tmp/.ICE-unixJump to behavior
Source: /tmp/file7pm3Gp (PID: 6423)Directory: /tmp/.Jump to behavior
Source: /tmp/file7pm3Gp (PID: 6423)Directory: /tmp/..Jump to behavior
Source: /tmp/file7pm3Gp (PID: 6423)Directory: /tmp/.XIM-unixJump to behavior
Source: /tmp/file7pm3Gp (PID: 6423)Directory: /tmp/.xfsm-ICE-S33I80Jump to behavior
Source: /tmp/filecprMtT (PID: 6427)Directory: /tmp/.X11-unixJump to behavior
Source: /tmp/filecprMtT (PID: 6427)Directory: /tmp/.Test-unixJump to behavior
Source: /tmp/filecprMtT (PID: 6427)Directory: /tmp/.font-unixJump to behavior
Source: /tmp/filecprMtT (PID: 6427)Directory: /tmp/.ICE-unixJump to behavior
Source: /tmp/filecprMtT (PID: 6427)Directory: /tmp/.Jump to behavior
Source: /tmp/filecprMtT (PID: 6427)Directory: /tmp/..Jump to behavior
Source: /tmp/filecprMtT (PID: 6427)Directory: /tmp/.XIM-unixJump to behavior
Source: /tmp/filecprMtT (PID: 6427)Directory: /tmp/.xfsm-ICE-S33I80Jump to behavior
Source: /tmp/filepbk33b (PID: 6430)Directory: /tmp/.X11-unixJump to behavior
Source: /tmp/filepbk33b (PID: 6430)Directory: /tmp/.Test-unixJump to behavior
Source: /tmp/filepbk33b (PID: 6430)Directory: /tmp/.font-unixJump to behavior
Source: /tmp/filepbk33b (PID: 6430)Directory: /tmp/.ICE-unixJump to behavior
Source: /tmp/filepbk33b (PID: 6430)Directory: /tmp/.Jump to behavior
Source: /tmp/filepbk33b (PID: 6430)Directory: /tmp/..Jump to behavior
Source: /tmp/filepbk33b (PID: 6430)Directory: /tmp/.XIM-unixJump to behavior
Source: /tmp/filepbk33b (PID: 6430)Directory: /tmp/.xfsm-ICE-S33I80Jump to behavior
Source: /tmp/filevSAJrq (PID: 6433)Directory: /tmp/.X11-unixJump to behavior
Source: /tmp/filevSAJrq (PID: 6433)Directory: /tmp/.Test-unixJump to behavior
Source: /tmp/filevSAJrq (PID: 6433)Directory: /tmp/.font-unixJump to behavior
Source: /tmp/filevSAJrq (PID: 6433)Directory: /tmp/.ICE-unixJump to behavior
Source: /tmp/filevSAJrq (PID: 6433)Directory: /tmp/.Jump to behavior
Source: /tmp/filevSAJrq (PID: 6433)Directory: /tmp/..Jump to behavior
Source: /tmp/filevSAJrq (PID: 6433)Directory: /tmp/.XIM-unixJump to behavior
Source: /tmp/filevSAJrq (PID: 6433)Directory: /tmp/.xfsm-ICE-S33I80Jump to behavior
Source: /tmp/file6MzccC (PID: 6438)Directory: /tmp/.X11-unixJump to behavior
Source: /tmp/file6MzccC (PID: 6438)Directory: /tmp/.Test-unixJump to behavior
Source: /tmp/file6MzccC (PID: 6438)Directory: /tmp/.font-unixJump to behavior
Source: /tmp/file6MzccC (PID: 6438)Directory: /tmp/.ICE-unixJump to behavior
Source: /tmp/file6MzccC (PID: 6438)Directory: /tmp/.Jump to behavior
Source: /tmp/file6MzccC (PID: 6438)Directory: /tmp/..Jump to behavior
Source: /tmp/file6MzccC (PID: 6438)Directory: /tmp/.XIM-unixJump to behavior
Source: /tmp/file6MzccC (PID: 6438)Directory: /tmp/.xfsm-ICE-S33I80Jump to behavior
Source: /tmp/filePxLHKY (PID: 6442)Directory: /tmp/.X11-unixJump to behavior
Source: /tmp/filePxLHKY (PID: 6442)Directory: /tmp/.Test-unixJump to behavior
Source: /tmp/filePxLHKY (PID: 6442)Directory: /tmp/.font-unixJump to behavior
Source: /tmp/filePxLHKY (PID: 6442)Directory: /tmp/.ICE-unixJump to behavior
Source: /tmp/filePxLHKY (PID: 6442)Directory: /tmp/.Jump to behavior
Source: /tmp/filePxLHKY (PID: 6442)Directory: /tmp/..Jump to behavior
Source: /tmp/filePxLHKY (PID: 6442)Directory: /tmp/.XIM-unixJump to behavior
Source: /tmp/filePxLHKY (PID: 6442)Directory: /tmp/.xfsm-ICE-S33I80Jump to behavior
Source: /tmp/filebJHN4h (PID: 6447)Directory: /tmp/.X11-unixJump to behavior
Source: /tmp/filebJHN4h (PID: 6447)Directory: /tmp/.Test-unixJump to behavior
Source: /tmp/filebJHN4h (PID: 6447)Directory: /tmp/.font-unixJump to behavior
Source: /tmp/filebJHN4h (PID: 6447)Directory: /tmp/.ICE-unixJump to behavior
Source: /tmp/filebJHN4h (PID: 6447)Directory: /tmp/.Jump to behavior
Source: /tmp/filebJHN4h (PID: 6447)Directory: /tmp/..Jump to behavior
Source: /tmp/filebJHN4h (PID: 6447)Directory: /tmp/.XIM-unixJump to behavior
Source: /tmp/filebJHN4h (PID: 6447)Directory: /tmp/.xfsm-ICE-S33I80Jump to behavior
Source: /tmp/fileJuQrAG (PID: 6450)Directory: /tmp/.X11-unixJump to behavior
Source: /tmp/fileJuQrAG (PID: 6450)Directory: /tmp/.Test-unixJump to behavior
Source: /tmp/fileJuQrAG (PID: 6450)Directory: /tmp/.font-unixJump to behavior
Source: /tmp/fileJuQrAG (PID: 6450)Directory: /tmp/.ICE-unixJump to behavior
Source: /tmp/fileJuQrAG (PID: 6450)Directory: /tmp/.Jump to behavior
Source: /tmp/fileJuQrAG (PID: 6450)Directory: /tmp/..Jump to behavior
Source: /tmp/fileJuQrAG (PID: 6450)Directory: /tmp/.XIM-unixJump to behavior
Source: /tmp/fileJuQrAG (PID: 6450)Directory: /tmp/.xfsm-ICE-S33I80Jump to behavior
Source: /tmp/fileCsunoX (PID: 6455)Directory: /tmp/.X11-unixJump to behavior
Source: /tmp/fileCsunoX (PID: 6455)Directory: /tmp/.Test-unixJump to behavior
Source: /tmp/fileCsunoX (PID: 6455)Directory: /tmp/.font-unixJump to behavior
Source: /tmp/fileCsunoX (PID: 6455)Directory: /tmp/.ICE-unixJump to behavior
Source: /tmp/fileCsunoX (PID: 6455)Directory: /tmp/.Jump to behavior
Source: /tmp/fileCsunoX (PID: 6455)Directory: /tmp/..Jump to behavior
Source: /tmp/fileCsunoX (PID: 6455)Directory: /tmp/.XIM-unixJump to behavior
Source: /tmp/fileCsunoX (PID: 6455)Directory: /tmp/.xfsm-ICE-S33I80Jump to behavior
Source: /tmp/file5qrfjk (PID: 6459)Directory: /tmp/.X11-unixJump to behavior
Source: /tmp/file5qrfjk (PID: 6459)Directory: /tmp/.Test-unixJump to behavior
Source: /tmp/file5qrfjk (PID: 6459)Directory: /tmp/.font-unixJump to behavior
Source: /tmp/file5qrfjk (PID: 6459)Directory: /tmp/.ICE-unixJump to behavior
Source: /tmp/file5qrfjk (PID: 6459)Directory: /tmp/.Jump to behavior
Source: /tmp/file5qrfjk (PID: 6459)Directory: /tmp/..Jump to behavior
Source: /tmp/file5qrfjk (PID: 6459)Directory: /tmp/.XIM-unixJump to behavior
Source: /tmp/file5qrfjk (PID: 6459)Directory: /tmp/.xfsm-ICE-S33I80Jump to behavior
Source: /tmp/fileO7mQVz (PID: 6462)Directory: /tmp/.X11-unixJump to behavior
Source: /tmp/fileO7mQVz (PID: 6462)Directory: /tmp/.Test-unixJump to behavior
Source: /tmp/fileO7mQVz (PID: 6462)Directory: /tmp/.font-unixJump to behavior
Source: /tmp/fileO7mQVz (PID: 6462)Directory: /tmp/.ICE-unixJump to behavior
Source: /usr/bin/dash (PID: 6249)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.61DXa86J11 /tmp/tmp.Z31iyKedgj /tmp/tmp.6ukCyQKaFlJump to behavior
Source: /usr/bin/dash (PID: 6250)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.61DXa86J11 /tmp/tmp.Z31iyKedgj /tmp/tmp.6ukCyQKaFlJump to behavior
Source: /tmp/ssa.elf (PID: 6278)File: /etc/cron.hourly/0 (bits: uv usr: rwx grp: rwx all: rwx)Jump to behavior
Source: /tmp/ssa.elf (PID: 6278)File: <invalid fd (-1)> (bits: uv usr: rwx grp: rwx all: rwx)Jump to behavior
Source: /tmp/ssa.elf (PID: 6278)File written: /tmp/filesZIILSJump to dropped file
Source: /tmp/filesZIILS (PID: 6281)File written: /tmp/fileqph2w9Jump to dropped file
Source: /tmp/fileqph2w9 (PID: 6287)File written: /tmp/file9xgtsAJump to dropped file
Source: /tmp/file9xgtsA (PID: 6290)File written: /tmp/fileFTsWOPJump to dropped file
Source: /tmp/fileFTsWOP (PID: 6310)File written: /tmp/fileY0OfemJump to dropped file
Source: /tmp/fileY0Ofem (PID: 6313)File written: /tmp/filewZ3vJwJump to dropped file
Source: /tmp/filewZ3vJw (PID: 6316)File written: /tmp/file6dYPaNJump to dropped file
Source: /tmp/file6dYPaN (PID: 6320)File written: /tmp/file3voGS3Jump to dropped file
Source: /tmp/file3voGS3 (PID: 6325)File written: /tmp/filecLo1bvJump to dropped file
Source: /tmp/filecLo1bv (PID: 6330)File written: /tmp/filek7i3uPJump to dropped file
Source: /tmp/filek7i3uP (PID: 6333)File written: /tmp/fileFAvB93Jump to dropped file
Source: /tmp/fileFAvB93 (PID: 6336)File written: /tmp/fileAyj87hJump to dropped file
Source: /tmp/fileAyj87h (PID: 6340)File written: /tmp/filelpjDaBJump to dropped file
Source: /tmp/filelpjDaB (PID: 6343)File written: /tmp/fileiIcyzNJump to dropped file
Source: /tmp/fileiIcyzN (PID: 6346)File written: /tmp/file0exOS4Jump to dropped file
Source: /tmp/file0exOS4 (PID: 6351)File written: /tmp/fileVXRF8sJump to dropped file
Source: /tmp/fileVXRF8s (PID: 6354)File written: /tmp/filepfbdRGJump to dropped file
Source: /tmp/filepfbdRG (PID: 6359)File written: /tmp/fileFBsYn2Jump to dropped file
Source: /tmp/fileFBsYn2 (PID: 6362)File written: /tmp/fileYWlxChJump to dropped file
Source: /tmp/fileYWlxCh (PID: 6367)File written: /tmp/fileT2tUzCJump to dropped file
Source: /tmp/fileT2tUzC (PID: 6372)File written: /tmp/file30mPH0Jump to dropped file
Source: /tmp/file30mPH0 (PID: 6375)File written: /tmp/filelqfWgfJump to dropped file
Source: /tmp/filelqfWgf (PID: 6379)File written: /tmp/fileg1aioyJump to dropped file
Source: /tmp/fileg1aioy (PID: 6382)File written: /tmp/fileLAS8lKJump to dropped file
Source: /tmp/fileLAS8lK (PID: 6387)File written: /tmp/filegFEB67Jump to dropped file
Source: /tmp/filegFEB67 (PID: 6390)File written: /tmp/fileR5OlImJump to dropped file
Source: /tmp/fileR5OlIm (PID: 6393)File written: /tmp/fileqhyxmAJump to dropped file
Source: /tmp/fileqhyxmA (PID: 6397)File written: /tmp/fileyst50VJump to dropped file
Source: /tmp/fileyst50V (PID: 6406)File written: /tmp/filezmxBFzJump to dropped file
Source: /tmp/filezmxBFz (PID: 6409)File written: /tmp/fileQ6PloQJump to dropped file
Source: /tmp/fileQ6PloQ (PID: 6414)File written: /tmp/fileWWcCKbJump to dropped file
Source: /tmp/fileWWcCKb (PID: 6417)File written: /tmp/file7pm3GpJump to dropped file
Source: /tmp/file7pm3Gp (PID: 6423)File written: /tmp/filecprMtTJump to dropped file
Source: /tmp/filecprMtT (PID: 6427)File written: /tmp/filepbk33bJump to dropped file
Source: /tmp/filepbk33b (PID: 6430)File written: /tmp/filevSAJrqJump to dropped file
Source: /tmp/filevSAJrq (PID: 6433)File written: /tmp/file6MzccCJump to dropped file
Source: /tmp/file6MzccC (PID: 6438)File written: /tmp/filePxLHKYJump to dropped file
Source: /tmp/filePxLHKY (PID: 6442)File written: /tmp/filebJHN4hJump to dropped file
Source: /tmp/filebJHN4h (PID: 6447)File written: /tmp/fileJuQrAGJump to dropped file
Source: /tmp/fileJuQrAG (PID: 6450)File written: /tmp/fileCsunoXJump to dropped file
Source: /tmp/fileCsunoX (PID: 6455)File written: /tmp/file5qrfjkJump to dropped file
Source: /tmp/file5qrfjk (PID: 6459)File written: /tmp/fileO7mQVzJump to dropped file
Source: /tmp/fileO7mQVz (PID: 6462)File written: /tmp/file9bUHKOJump to dropped file
Source: ssa.elf, 6278.1.000055676cb52000.000055676cb73000.rw-.sdmpBinary or memory string: vmware-root_721-4290559889=G
Source: ssa.elf, 6278.1.000055676cb52000.000055676cb73000.rw-.sdmpBinary or memory string: vmware-root_721-4290559889
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
File and Directory Permissions Modification
OS Credential Dumping1
Security Software Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network Medium1
Data Manipulation
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Hidden Files and Directories
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
File Deletion
Security Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveSteganographyAutomated ExfiltrationData Encrypted for Impact
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1587321 Sample: ssa.elf Startdate: 10/01/2025 Architecture: LINUX Score: 80 77 109.202.202.202, 80 INIT7CH Switzerland 2->77 79 91.189.91.42, 443 CANONICAL-ASGB United Kingdom 2->79 81 91.189.91.43, 443 CANONICAL-ASGB United Kingdom 2->81 91 Malicious sample detected (through community Yara rule) 2->91 93 Antivirus / Scanner detection for submitted sample 2->93 95 Multi AV Scanner detection for submitted file 2->95 97 Machine Learning detection for sample 2->97 15 dash rm ssa.elf 2->15         started        19 dash rm 2->19         started        signatures3 process4 file5 75 /tmp/filesZIILS, ELF 15->75 dropped 83 Sample tries to set files in /etc globally writable 15->83 85 Sample tries to persist itself using cron 15->85 21 ssa.elf filesZIILS 15->21         started        signatures6 process7 file8 61 /tmp/fileqph2w9, ELF 21->61 dropped 99 Writes identical ELF files to multiple locations 21->99 25 filesZIILS fileqph2w9 21->25         started        signatures9 process10 file11 67 /tmp/file9xgtsA, ELF 25->67 dropped 105 Writes identical ELF files to multiple locations 25->105 29 fileqph2w9 file9xgtsA 25->29         started        signatures12 process13 file14 71 /tmp/fileFTsWOP, ELF 29->71 dropped 109 Writes identical ELF files to multiple locations 29->109 33 file9xgtsA fileFTsWOP 29->33         started        signatures15 process16 file17 57 /tmp/fileY0Ofem, ELF 33->57 dropped 87 Writes identical ELF files to multiple locations 33->87 37 fileFTsWOP fileY0Ofem 33->37         started        signatures18 process19 file20 63 /tmp/filewZ3vJw, ELF 37->63 dropped 101 Writes identical ELF files to multiple locations 37->101 41 fileY0Ofem filewZ3vJw 37->41         started        signatures21 process22 file23 69 /tmp/file6dYPaN, ELF 41->69 dropped 107 Writes identical ELF files to multiple locations 41->107 45 filewZ3vJw file6dYPaN 41->45         started        signatures24 process25 file26 73 /tmp/file3voGS3, ELF 45->73 dropped 111 Writes identical ELF files to multiple locations 45->111 49 file6dYPaN file3voGS3 45->49         started        signatures27 process28 file29 59 /tmp/filecLo1bv, ELF 49->59 dropped 89 Writes identical ELF files to multiple locations 49->89 53 file3voGS3 filecLo1bv 49->53         started        signatures30 process31 file32 65 /tmp/filek7i3uP, ELF 53->65 dropped 103 Writes identical ELF files to multiple locations 53->103 signatures33

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
ssa.elf59%VirustotalBrowse
ssa.elf66%ReversingLabsLinux.Trojan.Ladvix
ssa.elf100%AviraLINUX/Ladvix.rqfxr
ssa.elf100%Joe Sandbox ML
SourceDetectionScannerLabelLink
/tmp/file0exOS418%ReversingLabsLinux.Trojan.Generic
/tmp/file30mPH018%ReversingLabsLinux.Trojan.Generic
/tmp/file3voGS318%ReversingLabsLinux.Trojan.Generic
/tmp/file5qrfjk18%ReversingLabsLinux.Trojan.Generic
/tmp/file6MzccC18%ReversingLabsLinux.Trojan.Generic
/tmp/file6dYPaN18%ReversingLabsLinux.Trojan.Generic
/tmp/file7pm3Gp18%ReversingLabsLinux.Trojan.Generic
/tmp/file9xgtsA18%ReversingLabsLinux.Trojan.Generic
/tmp/fileAyj87h18%ReversingLabsLinux.Trojan.Generic
/tmp/fileCsunoX18%ReversingLabsLinux.Trojan.Generic
/tmp/fileFAvB9318%ReversingLabsLinux.Trojan.Generic
/tmp/fileFBsYn218%ReversingLabsLinux.Trojan.Generic
/tmp/fileFTsWOP18%ReversingLabsLinux.Trojan.Generic
/tmp/fileJuQrAG18%ReversingLabsLinux.Trojan.Generic
/tmp/fileLAS8lK18%ReversingLabsLinux.Trojan.Generic
/tmp/fileO7mQVz18%ReversingLabsLinux.Trojan.Generic
/tmp/filePxLHKY18%ReversingLabsLinux.Trojan.Generic
/tmp/fileQ6PloQ18%ReversingLabsLinux.Trojan.Generic
/tmp/fileR5OlIm18%ReversingLabsLinux.Trojan.Generic
/tmp/fileT2tUzC18%ReversingLabsLinux.Trojan.Generic
/tmp/fileVXRF8s18%ReversingLabsLinux.Trojan.Generic
/tmp/fileWWcCKb18%ReversingLabsLinux.Trojan.Generic
/tmp/fileY0Ofem18%ReversingLabsLinux.Trojan.Generic
/tmp/fileYWlxCh18%ReversingLabsLinux.Trojan.Generic
/tmp/filebJHN4h18%ReversingLabsLinux.Trojan.Generic
/tmp/filecLo1bv18%ReversingLabsLinux.Trojan.Generic
/tmp/filecprMtT18%ReversingLabsLinux.Trojan.Generic
/tmp/fileg1aioy18%ReversingLabsLinux.Trojan.Generic
/tmp/filegFEB6718%ReversingLabsLinux.Trojan.Generic
/tmp/fileiIcyzN18%ReversingLabsLinux.Trojan.Generic
/tmp/filek7i3uP18%ReversingLabsLinux.Trojan.Generic
/tmp/filelpjDaB18%ReversingLabsLinux.Trojan.Generic
/tmp/filelqfWgf18%ReversingLabsLinux.Trojan.Generic
/tmp/filepbk33b18%ReversingLabsLinux.Trojan.Generic
/tmp/filepfbdRG18%ReversingLabsLinux.Trojan.Generic
/tmp/fileqhyxmA18%ReversingLabsLinux.Trojan.Generic
/tmp/fileqph2w918%ReversingLabsLinux.Trojan.Generic
/tmp/filesZIILS21%ReversingLabsLinux.Trojan.Multiverze
/tmp/filevSAJrq18%ReversingLabsLinux.Trojan.Generic
/tmp/filewZ3vJw18%ReversingLabsLinux.Trojan.Generic
/tmp/fileyst50V18%ReversingLabsLinux.Trojan.Generic
/tmp/filezmxBFz18%ReversingLabsLinux.Trojan.Generic
No Antivirus matches
SourceDetectionScannerLabelLink
https://wiki.xiph.org/MIME_Types_and_File_Extensions.oga0%Avira URL Cloudsafe
https://wiki.xiph.org/MIME_Types_and_File_Extensions0%Avira URL Cloudsafe
https://wiki.xiph.org/MIME_Types_and_File_Extensions.ogv0%Avira URL Cloudsafe
https://translationproject.org/team/0%Avira URL Cloudsafe
http://cf0.pw/0/etc/cron.hourly/00%Avira URL Cloudsafe
No contacted domains info
NameSourceMaliciousAntivirus DetectionReputation
https://www.gnu.org/software/coreutils/ssa.elf, 6278.1.00007f7ab7c24000.00007f7ab7c47000.rw-.sdmpfalse
    high
    https://gnu.org/licenses/gpl.htmlssa.elf, 6278.1.00007f7ab7c24000.00007f7ab7c47000.rw-.sdmpfalse
      high
      https://wiki.xiph.org/MIME_Types_and_File_Extensionsssa.elf, 6278.1.00007f7ab7c24000.00007f7ab7c47000.rw-.sdmpfalse
      • Avira URL Cloud: safe
      unknown
      http://cf0.pw/0/etc/cron.hourly/0ssa.elf, 6278.1.000055676cb52000.000055676cb73000.rw-.sdmpfalse
      • Avira URL Cloud: safe
      unknown
      https://www.gnu.org/gethelp/ssa.elf, 6278.1.00007f7ab7c24000.00007f7ab7c47000.rw-.sdmpfalse
        high
        https://www.gnu.org/software/coreutils/Reportssa.elf, 6278.1.00007f7ab7c24000.00007f7ab7c47000.rw-.sdmpfalse
          high
          https://translationproject.org/team/ssa.elf, 6278.1.00007f7ab7c24000.00007f7ab7c47000.rw-.sdmpfalse
          • Avira URL Cloud: safe
          unknown
          https://wiki.xiph.org/MIME_Types_and_File_Extensions.ogassa.elf, 6278.1.00007f7ab7c24000.00007f7ab7c47000.rw-.sdmpfalse
          • Avira URL Cloud: safe
          unknown
          https://wiki.xiph.org/MIME_Types_and_File_Extensions.ogvssa.elf, 6278.1.00007f7ab7c24000.00007f7ab7c47000.rw-.sdmpfalse
          • Avira URL Cloud: safe
          unknown
          • No. of IPs < 25%
          • 25% < No. of IPs < 50%
          • 50% < No. of IPs < 75%
          • 75% < No. of IPs
          IPDomainCountryFlagASNASN NameMalicious
          109.202.202.202
          unknownSwitzerland
          13030INIT7CHfalse
          91.189.91.43
          unknownUnited Kingdom
          41231CANONICAL-ASGBfalse
          91.189.91.42
          unknownUnited Kingdom
          41231CANONICAL-ASGBfalse
          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
          109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
          • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
          91.189.91.43main_arm.elfGet hashmaliciousMiraiBrowse
            arm7.elfGet hashmaliciousMiraiBrowse
              12.elfGet hashmaliciousUnknownBrowse
                2.elfGet hashmaliciousUnknownBrowse
                  fenty.arm7.elfGet hashmaliciousMiraiBrowse
                    armv4eb.elfGet hashmaliciousUnknownBrowse
                      12.elfGet hashmaliciousUnknownBrowse
                        2.elfGet hashmaliciousUnknownBrowse
                          fenty.arm7.elfGet hashmaliciousMiraiBrowse
                            fenty.arm6.elfGet hashmaliciousMiraiBrowse
                              91.189.91.42main_arm.elfGet hashmaliciousMiraiBrowse
                                arm7.elfGet hashmaliciousMiraiBrowse
                                  12.elfGet hashmaliciousUnknownBrowse
                                    2.elfGet hashmaliciousUnknownBrowse
                                      fenty.arm7.elfGet hashmaliciousMiraiBrowse
                                        armv4eb.elfGet hashmaliciousUnknownBrowse
                                          12.elfGet hashmaliciousUnknownBrowse
                                            2.elfGet hashmaliciousUnknownBrowse
                                              fenty.arm7.elfGet hashmaliciousMiraiBrowse
                                                fenty.arm6.elfGet hashmaliciousMiraiBrowse
                                                  No context
                                                  MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                  CANONICAL-ASGBmain_arm.elfGet hashmaliciousMiraiBrowse
                                                  • 91.189.91.42
                                                  arm7.elfGet hashmaliciousMiraiBrowse
                                                  • 91.189.91.42
                                                  main_sh4.elfGet hashmaliciousMiraiBrowse
                                                  • 185.125.190.26
                                                  12.elfGet hashmaliciousUnknownBrowse
                                                  • 91.189.91.42
                                                  2.elfGet hashmaliciousUnknownBrowse
                                                  • 91.189.91.42
                                                  fenty.arm4.elfGet hashmaliciousMiraiBrowse
                                                  • 185.125.190.26
                                                  fenty.arm7.elfGet hashmaliciousMiraiBrowse
                                                  • 91.189.91.42
                                                  armv4eb.elfGet hashmaliciousUnknownBrowse
                                                  • 91.189.91.42
                                                  Space.x86.elfGet hashmaliciousUnknownBrowse
                                                  • 185.125.190.26
                                                  12.elfGet hashmaliciousUnknownBrowse
                                                  • 91.189.91.42
                                                  CANONICAL-ASGBmain_arm.elfGet hashmaliciousMiraiBrowse
                                                  • 91.189.91.42
                                                  arm7.elfGet hashmaliciousMiraiBrowse
                                                  • 91.189.91.42
                                                  main_sh4.elfGet hashmaliciousMiraiBrowse
                                                  • 185.125.190.26
                                                  12.elfGet hashmaliciousUnknownBrowse
                                                  • 91.189.91.42
                                                  2.elfGet hashmaliciousUnknownBrowse
                                                  • 91.189.91.42
                                                  fenty.arm4.elfGet hashmaliciousMiraiBrowse
                                                  • 185.125.190.26
                                                  fenty.arm7.elfGet hashmaliciousMiraiBrowse
                                                  • 91.189.91.42
                                                  armv4eb.elfGet hashmaliciousUnknownBrowse
                                                  • 91.189.91.42
                                                  Space.x86.elfGet hashmaliciousUnknownBrowse
                                                  • 185.125.190.26
                                                  12.elfGet hashmaliciousUnknownBrowse
                                                  • 91.189.91.42
                                                  INIT7CHmain_arm.elfGet hashmaliciousMiraiBrowse
                                                  • 109.202.202.202
                                                  arm7.elfGet hashmaliciousMiraiBrowse
                                                  • 109.202.202.202
                                                  12.elfGet hashmaliciousUnknownBrowse
                                                  • 109.202.202.202
                                                  2.elfGet hashmaliciousUnknownBrowse
                                                  • 109.202.202.202
                                                  fenty.arm7.elfGet hashmaliciousMiraiBrowse
                                                  • 109.202.202.202
                                                  armv4eb.elfGet hashmaliciousUnknownBrowse
                                                  • 109.202.202.202
                                                  12.elfGet hashmaliciousUnknownBrowse
                                                  • 109.202.202.202
                                                  2.elfGet hashmaliciousUnknownBrowse
                                                  • 109.202.202.202
                                                  fenty.arm7.elfGet hashmaliciousMiraiBrowse
                                                  • 109.202.202.202
                                                  fenty.arm6.elfGet hashmaliciousMiraiBrowse
                                                  • 109.202.202.202
                                                  No context
                                                  No context
                                                  Process:/tmp/fileiIcyzN
                                                  File Type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, for GNU/Linux 2.6.24, BuildID[sha1]=f734b08716b0c60e4484df4c0a290d79e6359a9b, not stripped
                                                  Category:dropped
                                                  Size (bytes):15885
                                                  Entropy (8bit):3.635273202542929
                                                  Encrypted:false
                                                  SSDEEP:192:GxXYSFnkHS6qvVxq3H/SdXazE/mfCFwS10f5CnxzD:VSFnkHWVxYz8ZV
                                                  MD5:46B09BE8C88B2336194BDC117006F098
                                                  SHA1:D42F2A8E5747DC4263A28D4D3B810BFC1CE7FF28
                                                  SHA-256:3E622D164B9019C69007C48BCE7AF738062D0C6C3B4D6B5B3A5A71CFBBDBCB7E
                                                  SHA-512:9F200F31C3ACF9A2E0CF3CD4526595F3BB88A847D19CD61F92FE0219086C46237228362E7DC4379C99F6BEB31EA464BB02661B555294C994337B522C0794F4CB
                                                  Malicious:true
                                                  Antivirus:
                                                  • Antivirus: ReversingLabs, Detection: 18%
                                                  Reputation:low
                                                  Preview:.ELF..............>.....e.@.....@........"..........@.8...@.............@.......@.@.....@.@.....................................8.......8.@.....8.@...............................................@.......@....................... .......................`.......`....................... .............(.......(.`.....(.`.....................................T.......T.@.....T.@.....D.......D...............P.td....x.......x.@.....x.@.....\.......\...............Q.td....................................................R.td..............`.......`............................./lib64/ld-linux-x86-64.so.2.............GNU.............................GNU..4......D..L.).y.5......................................3...........................8.......................@.......................J...............................................................................................$.......................p........................................................................... ...................[.......
                                                  Process:/tmp/fileT2tUzC
                                                  File Type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, for GNU/Linux 2.6.24, BuildID[sha1]=f734b08716b0c60e4484df4c0a290d79e6359a9b, not stripped
                                                  Category:dropped
                                                  Size (bytes):15885
                                                  Entropy (8bit):3.635273202542929
                                                  Encrypted:false
                                                  SSDEEP:192:GxXYSFnkHS6qvVxq3H/SdXazE/mfCFwS10f5CnxzD:VSFnkHWVxYz8ZV
                                                  MD5:46B09BE8C88B2336194BDC117006F098
                                                  SHA1:D42F2A8E5747DC4263A28D4D3B810BFC1CE7FF28
                                                  SHA-256:3E622D164B9019C69007C48BCE7AF738062D0C6C3B4D6B5B3A5A71CFBBDBCB7E
                                                  SHA-512:9F200F31C3ACF9A2E0CF3CD4526595F3BB88A847D19CD61F92FE0219086C46237228362E7DC4379C99F6BEB31EA464BB02661B555294C994337B522C0794F4CB
                                                  Malicious:true
                                                  Antivirus:
                                                  • Antivirus: ReversingLabs, Detection: 18%
                                                  Reputation:low
                                                  Preview:.ELF..............>.....e.@.....@........"..........@.8...@.............@.......@.@.....@.@.....................................8.......8.@.....8.@...............................................@.......@....................... .......................`.......`....................... .............(.......(.`.....(.`.....................................T.......T.@.....T.@.....D.......D...............P.td....x.......x.@.....x.@.....\.......\...............Q.td....................................................R.td..............`.......`............................./lib64/ld-linux-x86-64.so.2.............GNU.............................GNU..4......D..L.).y.5......................................3...........................8.......................@.......................J...............................................................................................$.......................p........................................................................... ...................[.......
                                                  Process:/tmp/file6dYPaN
                                                  File Type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, for GNU/Linux 2.6.24, BuildID[sha1]=f734b08716b0c60e4484df4c0a290d79e6359a9b, not stripped
                                                  Category:dropped
                                                  Size (bytes):15885
                                                  Entropy (8bit):3.635273202542929
                                                  Encrypted:false
                                                  SSDEEP:192:GxXYSFnkHS6qvVxq3H/SdXazE/mfCFwS10f5CnxzD:VSFnkHWVxYz8ZV
                                                  MD5:46B09BE8C88B2336194BDC117006F098
                                                  SHA1:D42F2A8E5747DC4263A28D4D3B810BFC1CE7FF28
                                                  SHA-256:3E622D164B9019C69007C48BCE7AF738062D0C6C3B4D6B5B3A5A71CFBBDBCB7E
                                                  SHA-512:9F200F31C3ACF9A2E0CF3CD4526595F3BB88A847D19CD61F92FE0219086C46237228362E7DC4379C99F6BEB31EA464BB02661B555294C994337B522C0794F4CB
                                                  Malicious:true
                                                  Antivirus:
                                                  • Antivirus: ReversingLabs, Detection: 18%
                                                  Reputation:low
                                                  Preview:.ELF..............>.....e.@.....@........"..........@.8...@.............@.......@.@.....@.@.....................................8.......8.@.....8.@...............................................@.......@....................... .......................`.......`....................... .............(.......(.`.....(.`.....................................T.......T.@.....T.@.....D.......D...............P.td....x.......x.@.....x.@.....\.......\...............Q.td....................................................R.td..............`.......`............................./lib64/ld-linux-x86-64.so.2.............GNU.............................GNU..4......D..L.).y.5......................................3...........................8.......................@.......................J...............................................................................................$.......................p........................................................................... ...................[.......
                                                  Process:/tmp/fileCsunoX
                                                  File Type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, for GNU/Linux 2.6.24, BuildID[sha1]=f734b08716b0c60e4484df4c0a290d79e6359a9b, not stripped
                                                  Category:dropped
                                                  Size (bytes):15885
                                                  Entropy (8bit):3.635273202542929
                                                  Encrypted:false
                                                  SSDEEP:192:GxXYSFnkHS6qvVxq3H/SdXazE/mfCFwS10f5CnxzD:VSFnkHWVxYz8ZV
                                                  MD5:46B09BE8C88B2336194BDC117006F098
                                                  SHA1:D42F2A8E5747DC4263A28D4D3B810BFC1CE7FF28
                                                  SHA-256:3E622D164B9019C69007C48BCE7AF738062D0C6C3B4D6B5B3A5A71CFBBDBCB7E
                                                  SHA-512:9F200F31C3ACF9A2E0CF3CD4526595F3BB88A847D19CD61F92FE0219086C46237228362E7DC4379C99F6BEB31EA464BB02661B555294C994337B522C0794F4CB
                                                  Malicious:true
                                                  Antivirus:
                                                  • Antivirus: ReversingLabs, Detection: 18%
                                                  Reputation:low
                                                  Preview:.ELF..............>.....e.@.....@........"..........@.8...@.............@.......@.@.....@.@.....................................8.......8.@.....8.@...............................................@.......@....................... .......................`.......`....................... .............(.......(.`.....(.`.....................................T.......T.@.....T.@.....D.......D...............P.td....x.......x.@.....x.@.....\.......\...............Q.td....................................................R.td..............`.......`............................./lib64/ld-linux-x86-64.so.2.............GNU.............................GNU..4......D..L.).y.5......................................3...........................8.......................@.......................J...............................................................................................$.......................p........................................................................... ...................[.......
                                                  Process:/tmp/filevSAJrq
                                                  File Type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, for GNU/Linux 2.6.24, BuildID[sha1]=f734b08716b0c60e4484df4c0a290d79e6359a9b, not stripped
                                                  Category:dropped
                                                  Size (bytes):15885
                                                  Entropy (8bit):3.635273202542929
                                                  Encrypted:false
                                                  SSDEEP:192:GxXYSFnkHS6qvVxq3H/SdXazE/mfCFwS10f5CnxzD:VSFnkHWVxYz8ZV
                                                  MD5:46B09BE8C88B2336194BDC117006F098
                                                  SHA1:D42F2A8E5747DC4263A28D4D3B810BFC1CE7FF28
                                                  SHA-256:3E622D164B9019C69007C48BCE7AF738062D0C6C3B4D6B5B3A5A71CFBBDBCB7E
                                                  SHA-512:9F200F31C3ACF9A2E0CF3CD4526595F3BB88A847D19CD61F92FE0219086C46237228362E7DC4379C99F6BEB31EA464BB02661B555294C994337B522C0794F4CB
                                                  Malicious:true
                                                  Antivirus:
                                                  • Antivirus: ReversingLabs, Detection: 18%
                                                  Reputation:low
                                                  Preview:.ELF..............>.....e.@.....@........"..........@.8...@.............@.......@.@.....@.@.....................................8.......8.@.....8.@...............................................@.......@....................... .......................`.......`....................... .............(.......(.`.....(.`.....................................T.......T.@.....T.@.....D.......D...............P.td....x.......x.@.....x.@.....\.......\...............Q.td....................................................R.td..............`.......`............................./lib64/ld-linux-x86-64.so.2.............GNU.............................GNU..4......D..L.).y.5......................................3...........................8.......................@.......................J...............................................................................................$.......................p........................................................................... ...................[.......
                                                  Process:/tmp/filewZ3vJw
                                                  File Type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, for GNU/Linux 2.6.24, BuildID[sha1]=f734b08716b0c60e4484df4c0a290d79e6359a9b, not stripped
                                                  Category:dropped
                                                  Size (bytes):15885
                                                  Entropy (8bit):3.635273202542929
                                                  Encrypted:false
                                                  SSDEEP:192:GxXYSFnkHS6qvVxq3H/SdXazE/mfCFwS10f5CnxzD:VSFnkHWVxYz8ZV
                                                  MD5:46B09BE8C88B2336194BDC117006F098
                                                  SHA1:D42F2A8E5747DC4263A28D4D3B810BFC1CE7FF28
                                                  SHA-256:3E622D164B9019C69007C48BCE7AF738062D0C6C3B4D6B5B3A5A71CFBBDBCB7E
                                                  SHA-512:9F200F31C3ACF9A2E0CF3CD4526595F3BB88A847D19CD61F92FE0219086C46237228362E7DC4379C99F6BEB31EA464BB02661B555294C994337B522C0794F4CB
                                                  Malicious:true
                                                  Antivirus:
                                                  • Antivirus: ReversingLabs, Detection: 18%
                                                  Reputation:low
                                                  Preview:.ELF..............>.....e.@.....@........"..........@.8...@.............@.......@.@.....@.@.....................................8.......8.@.....8.@...............................................@.......@....................... .......................`.......`....................... .............(.......(.`.....(.`.....................................T.......T.@.....T.@.....D.......D...............P.td....x.......x.@.....x.@.....\.......\...............Q.td....................................................R.td..............`.......`............................./lib64/ld-linux-x86-64.so.2.............GNU.............................GNU..4......D..L.).y.5......................................3...........................8.......................@.......................J...............................................................................................$.......................p........................................................................... ...................[.......
                                                  Process:/tmp/fileWWcCKb
                                                  File Type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, for GNU/Linux 2.6.24, BuildID[sha1]=f734b08716b0c60e4484df4c0a290d79e6359a9b, not stripped
                                                  Category:dropped
                                                  Size (bytes):15885
                                                  Entropy (8bit):3.635273202542929
                                                  Encrypted:false
                                                  SSDEEP:192:GxXYSFnkHS6qvVxq3H/SdXazE/mfCFwS10f5CnxzD:VSFnkHWVxYz8ZV
                                                  MD5:46B09BE8C88B2336194BDC117006F098
                                                  SHA1:D42F2A8E5747DC4263A28D4D3B810BFC1CE7FF28
                                                  SHA-256:3E622D164B9019C69007C48BCE7AF738062D0C6C3B4D6B5B3A5A71CFBBDBCB7E
                                                  SHA-512:9F200F31C3ACF9A2E0CF3CD4526595F3BB88A847D19CD61F92FE0219086C46237228362E7DC4379C99F6BEB31EA464BB02661B555294C994337B522C0794F4CB
                                                  Malicious:true
                                                  Antivirus:
                                                  • Antivirus: ReversingLabs, Detection: 18%
                                                  Reputation:low
                                                  Preview:.ELF..............>.....e.@.....@........"..........@.8...@.............@.......@.@.....@.@.....................................8.......8.@.....8.@...............................................@.......@....................... .......................`.......`....................... .............(.......(.`.....(.`.....................................T.......T.@.....T.@.....D.......D...............P.td....x.......x.@.....x.@.....\.......\...............Q.td....................................................R.td..............`.......`............................./lib64/ld-linux-x86-64.so.2.............GNU.............................GNU..4......D..L.).y.5......................................3...........................8.......................@.......................J...............................................................................................$.......................p........................................................................... ...................[.......
                                                  Process:/tmp/fileO7mQVz
                                                  File Type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, for GNU/Linux 2.6.24, BuildID[sha1]=f734b08716b0c60e4484df4c0a290d79e6359a9b, not stripped
                                                  Category:dropped
                                                  Size (bytes):14168
                                                  Entropy (8bit):3.714446937662275
                                                  Encrypted:false
                                                  SSDEEP:192:GxXYSFnkHS6qvVxq3H/SdXazE/mfCFwS10f5Ct:VSFnkHWVxYz8ZF
                                                  MD5:69F010D9D8CC46C76DA93E5EA16F6E14
                                                  SHA1:AFED244606EC18844712CB1721DA36CB0D27CE4B
                                                  SHA-256:31044A2CD2DA6F2A86ADA177C125FA5F2CA58C0E2BFCD928EF26EE3B812AFE21
                                                  SHA-512:FD7A287DCE38A26063BF1456153F378675485F564B651283BFA27B02E0F96C84D53107A18F61ED1537A1729DE57A33816E823C47C63983D000ADFCCE3BD76AE4
                                                  Malicious:true
                                                  Reputation:low
                                                  Preview:.ELF..............>.....e.@.....@........"..........@.8...@.............@.......@.@.....@.@.....................................8.......8.@.....8.@...............................................@.......@....................... .......................`.......`....................... .............(.......(.`.....(.`.....................................T.......T.@.....T.@.....D.......D...............P.td....x.......x.@.....x.@.....\.......\...............Q.td....................................................R.td..............`.......`............................./lib64/ld-linux-x86-64.so.2.............GNU.............................GNU..4......D..L.).y.5......................................3...........................8.......................@.......................J...............................................................................................$.......................p........................................................................... ...................[.......
                                                  Process:/tmp/fileqph2w9
                                                  File Type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, for GNU/Linux 2.6.24, BuildID[sha1]=f734b08716b0c60e4484df4c0a290d79e6359a9b, not stripped
                                                  Category:dropped
                                                  Size (bytes):15885
                                                  Entropy (8bit):3.635273202542929
                                                  Encrypted:false
                                                  SSDEEP:192:GxXYSFnkHS6qvVxq3H/SdXazE/mfCFwS10f5CnxzD:VSFnkHWVxYz8ZV
                                                  MD5:46B09BE8C88B2336194BDC117006F098
                                                  SHA1:D42F2A8E5747DC4263A28D4D3B810BFC1CE7FF28
                                                  SHA-256:3E622D164B9019C69007C48BCE7AF738062D0C6C3B4D6B5B3A5A71CFBBDBCB7E
                                                  SHA-512:9F200F31C3ACF9A2E0CF3CD4526595F3BB88A847D19CD61F92FE0219086C46237228362E7DC4379C99F6BEB31EA464BB02661B555294C994337B522C0794F4CB
                                                  Malicious:true
                                                  Antivirus:
                                                  • Antivirus: ReversingLabs, Detection: 18%
                                                  Reputation:low
                                                  Preview:.ELF..............>.....e.@.....@........"..........@.8...@.............@.......@.@.....@.@.....................................8.......8.@.....8.@...............................................@.......@....................... .......................`.......`....................... .............(.......(.`.....(.`.....................................T.......T.@.....T.@.....D.......D...............P.td....x.......x.@.....x.@.....\.......\...............Q.td....................................................R.td..............`.......`............................./lib64/ld-linux-x86-64.so.2.............GNU.............................GNU..4......D..L.).y.5......................................3...........................8.......................@.......................J...............................................................................................$.......................p........................................................................... ...................[.......
                                                  Process:/tmp/fileFAvB93
                                                  File Type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, for GNU/Linux 2.6.24, BuildID[sha1]=f734b08716b0c60e4484df4c0a290d79e6359a9b, not stripped
                                                  Category:dropped
                                                  Size (bytes):15885
                                                  Entropy (8bit):3.635273202542929
                                                  Encrypted:false
                                                  SSDEEP:192:GxXYSFnkHS6qvVxq3H/SdXazE/mfCFwS10f5CnxzD:VSFnkHWVxYz8ZV
                                                  MD5:46B09BE8C88B2336194BDC117006F098
                                                  SHA1:D42F2A8E5747DC4263A28D4D3B810BFC1CE7FF28
                                                  SHA-256:3E622D164B9019C69007C48BCE7AF738062D0C6C3B4D6B5B3A5A71CFBBDBCB7E
                                                  SHA-512:9F200F31C3ACF9A2E0CF3CD4526595F3BB88A847D19CD61F92FE0219086C46237228362E7DC4379C99F6BEB31EA464BB02661B555294C994337B522C0794F4CB
                                                  Malicious:true
                                                  Antivirus:
                                                  • Antivirus: ReversingLabs, Detection: 18%
                                                  Preview:.ELF..............>.....e.@.....@........"..........@.8...@.............@.......@.@.....@.@.....................................8.......8.@.....8.@...............................................@.......@....................... .......................`.......`....................... .............(.......(.`.....(.`.....................................T.......T.@.....T.@.....D.......D...............P.td....x.......x.@.....x.@.....\.......\...............Q.td....................................................R.td..............`.......`............................./lib64/ld-linux-x86-64.so.2.............GNU.............................GNU..4......D..L.).y.5......................................3...........................8.......................@.......................J...............................................................................................$.......................p........................................................................... ...................[.......
                                                  Process:/tmp/fileJuQrAG
                                                  File Type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, for GNU/Linux 2.6.24, BuildID[sha1]=f734b08716b0c60e4484df4c0a290d79e6359a9b, not stripped
                                                  Category:dropped
                                                  Size (bytes):15885
                                                  Entropy (8bit):3.635273202542929
                                                  Encrypted:false
                                                  SSDEEP:192:GxXYSFnkHS6qvVxq3H/SdXazE/mfCFwS10f5CnxzD:VSFnkHWVxYz8ZV
                                                  MD5:46B09BE8C88B2336194BDC117006F098
                                                  SHA1:D42F2A8E5747DC4263A28D4D3B810BFC1CE7FF28
                                                  SHA-256:3E622D164B9019C69007C48BCE7AF738062D0C6C3B4D6B5B3A5A71CFBBDBCB7E
                                                  SHA-512:9F200F31C3ACF9A2E0CF3CD4526595F3BB88A847D19CD61F92FE0219086C46237228362E7DC4379C99F6BEB31EA464BB02661B555294C994337B522C0794F4CB
                                                  Malicious:true
                                                  Antivirus:
                                                  • Antivirus: ReversingLabs, Detection: 18%
                                                  Preview:.ELF..............>.....e.@.....@........"..........@.8...@.............@.......@.@.....@.@.....................................8.......8.@.....8.@...............................................@.......@....................... .......................`.......`....................... .............(.......(.`.....(.`.....................................T.......T.@.....T.@.....D.......D...............P.td....x.......x.@.....x.@.....\.......\...............Q.td....................................................R.td..............`.......`............................./lib64/ld-linux-x86-64.so.2.............GNU.............................GNU..4......D..L.).y.5......................................3...........................8.......................@.......................J...............................................................................................$.......................p........................................................................... ...................[.......
                                                  Process:/tmp/filek7i3uP
                                                  File Type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, for GNU/Linux 2.6.24, BuildID[sha1]=f734b08716b0c60e4484df4c0a290d79e6359a9b, not stripped
                                                  Category:dropped
                                                  Size (bytes):15885
                                                  Entropy (8bit):3.635273202542929
                                                  Encrypted:false
                                                  SSDEEP:192:GxXYSFnkHS6qvVxq3H/SdXazE/mfCFwS10f5CnxzD:VSFnkHWVxYz8ZV
                                                  MD5:46B09BE8C88B2336194BDC117006F098
                                                  SHA1:D42F2A8E5747DC4263A28D4D3B810BFC1CE7FF28
                                                  SHA-256:3E622D164B9019C69007C48BCE7AF738062D0C6C3B4D6B5B3A5A71CFBBDBCB7E
                                                  SHA-512:9F200F31C3ACF9A2E0CF3CD4526595F3BB88A847D19CD61F92FE0219086C46237228362E7DC4379C99F6BEB31EA464BB02661B555294C994337B522C0794F4CB
                                                  Malicious:true
                                                  Antivirus:
                                                  • Antivirus: ReversingLabs, Detection: 18%
                                                  Preview:.ELF..............>.....e.@.....@........"..........@.8...@.............@.......@.@.....@.@.....................................8.......8.@.....8.@...............................................@.......@....................... .......................`.......`....................... .............(.......(.`.....(.`.....................................T.......T.@.....T.@.....D.......D...............P.td....x.......x.@.....x.@.....\.......\...............Q.td....................................................R.td..............`.......`............................./lib64/ld-linux-x86-64.so.2.............GNU.............................GNU..4......D..L.).y.5......................................3...........................8.......................@.......................J...............................................................................................$.......................p........................................................................... ...................[.......
                                                  Process:/tmp/filepfbdRG
                                                  File Type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, for GNU/Linux 2.6.24, BuildID[sha1]=f734b08716b0c60e4484df4c0a290d79e6359a9b, not stripped
                                                  Category:dropped
                                                  Size (bytes):15885
                                                  Entropy (8bit):3.635273202542929
                                                  Encrypted:false
                                                  SSDEEP:192:GxXYSFnkHS6qvVxq3H/SdXazE/mfCFwS10f5CnxzD:VSFnkHWVxYz8ZV
                                                  MD5:46B09BE8C88B2336194BDC117006F098
                                                  SHA1:D42F2A8E5747DC4263A28D4D3B810BFC1CE7FF28
                                                  SHA-256:3E622D164B9019C69007C48BCE7AF738062D0C6C3B4D6B5B3A5A71CFBBDBCB7E
                                                  SHA-512:9F200F31C3ACF9A2E0CF3CD4526595F3BB88A847D19CD61F92FE0219086C46237228362E7DC4379C99F6BEB31EA464BB02661B555294C994337B522C0794F4CB
                                                  Malicious:true
                                                  Antivirus:
                                                  • Antivirus: ReversingLabs, Detection: 18%
                                                  Preview:.ELF..............>.....e.@.....@........"..........@.8...@.............@.......@.@.....@.@.....................................8.......8.@.....8.@...............................................@.......@....................... .......................`.......`....................... .............(.......(.`.....(.`.....................................T.......T.@.....T.@.....D.......D...............P.td....x.......x.@.....x.@.....\.......\...............Q.td....................................................R.td..............`.......`............................./lib64/ld-linux-x86-64.so.2.............GNU.............................GNU..4......D..L.).y.5......................................3...........................8.......................@.......................J...............................................................................................$.......................p........................................................................... ...................[.......
                                                  Process:/tmp/file9xgtsA
                                                  File Type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, for GNU/Linux 2.6.24, BuildID[sha1]=f734b08716b0c60e4484df4c0a290d79e6359a9b, not stripped
                                                  Category:dropped
                                                  Size (bytes):15885
                                                  Entropy (8bit):3.635273202542929
                                                  Encrypted:false
                                                  SSDEEP:192:GxXYSFnkHS6qvVxq3H/SdXazE/mfCFwS10f5CnxzD:VSFnkHWVxYz8ZV
                                                  MD5:46B09BE8C88B2336194BDC117006F098
                                                  SHA1:D42F2A8E5747DC4263A28D4D3B810BFC1CE7FF28
                                                  SHA-256:3E622D164B9019C69007C48BCE7AF738062D0C6C3B4D6B5B3A5A71CFBBDBCB7E
                                                  SHA-512:9F200F31C3ACF9A2E0CF3CD4526595F3BB88A847D19CD61F92FE0219086C46237228362E7DC4379C99F6BEB31EA464BB02661B555294C994337B522C0794F4CB
                                                  Malicious:true
                                                  Antivirus:
                                                  • Antivirus: ReversingLabs, Detection: 18%
                                                  Preview:.ELF..............>.....e.@.....@........"..........@.8...@.............@.......@.@.....@.@.....................................8.......8.@.....8.@...............................................@.......@....................... .......................`.......`....................... .............(.......(.`.....(.`.....................................T.......T.@.....T.@.....D.......D...............P.td....x.......x.@.....x.@.....\.......\...............Q.td....................................................R.td..............`.......`............................./lib64/ld-linux-x86-64.so.2.............GNU.............................GNU..4......D..L.).y.5......................................3...........................8.......................@.......................J...............................................................................................$.......................p........................................................................... ...................[.......
                                                  Process:/tmp/filebJHN4h
                                                  File Type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, for GNU/Linux 2.6.24, BuildID[sha1]=f734b08716b0c60e4484df4c0a290d79e6359a9b, not stripped
                                                  Category:dropped
                                                  Size (bytes):15885
                                                  Entropy (8bit):3.635273202542929
                                                  Encrypted:false
                                                  SSDEEP:192:GxXYSFnkHS6qvVxq3H/SdXazE/mfCFwS10f5CnxzD:VSFnkHWVxYz8ZV
                                                  MD5:46B09BE8C88B2336194BDC117006F098
                                                  SHA1:D42F2A8E5747DC4263A28D4D3B810BFC1CE7FF28
                                                  SHA-256:3E622D164B9019C69007C48BCE7AF738062D0C6C3B4D6B5B3A5A71CFBBDBCB7E
                                                  SHA-512:9F200F31C3ACF9A2E0CF3CD4526595F3BB88A847D19CD61F92FE0219086C46237228362E7DC4379C99F6BEB31EA464BB02661B555294C994337B522C0794F4CB
                                                  Malicious:true
                                                  Antivirus:
                                                  • Antivirus: ReversingLabs, Detection: 18%
                                                  Preview:.ELF..............>.....e.@.....@........"..........@.8...@.............@.......@.@.....@.@.....................................8.......8.@.....8.@...............................................@.......@....................... .......................`.......`....................... .............(.......(.`.....(.`.....................................T.......T.@.....T.@.....D.......D...............P.td....x.......x.@.....x.@.....\.......\...............Q.td....................................................R.td..............`.......`............................./lib64/ld-linux-x86-64.so.2.............GNU.............................GNU..4......D..L.).y.5......................................3...........................8.......................@.......................J...............................................................................................$.......................p........................................................................... ...................[.......
                                                  Process:/tmp/fileg1aioy
                                                  File Type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, for GNU/Linux 2.6.24, BuildID[sha1]=f734b08716b0c60e4484df4c0a290d79e6359a9b, not stripped
                                                  Category:dropped
                                                  Size (bytes):15885
                                                  Entropy (8bit):3.635273202542929
                                                  Encrypted:false
                                                  SSDEEP:192:GxXYSFnkHS6qvVxq3H/SdXazE/mfCFwS10f5CnxzD:VSFnkHWVxYz8ZV
                                                  MD5:46B09BE8C88B2336194BDC117006F098
                                                  SHA1:D42F2A8E5747DC4263A28D4D3B810BFC1CE7FF28
                                                  SHA-256:3E622D164B9019C69007C48BCE7AF738062D0C6C3B4D6B5B3A5A71CFBBDBCB7E
                                                  SHA-512:9F200F31C3ACF9A2E0CF3CD4526595F3BB88A847D19CD61F92FE0219086C46237228362E7DC4379C99F6BEB31EA464BB02661B555294C994337B522C0794F4CB
                                                  Malicious:true
                                                  Antivirus:
                                                  • Antivirus: ReversingLabs, Detection: 18%
                                                  Preview:.ELF..............>.....e.@.....@........"..........@.8...@.............@.......@.@.....@.@.....................................8.......8.@.....8.@...............................................@.......@....................... .......................`.......`....................... .............(.......(.`.....(.`.....................................T.......T.@.....T.@.....D.......D...............P.td....x.......x.@.....x.@.....\.......\...............Q.td....................................................R.td..............`.......`............................./lib64/ld-linux-x86-64.so.2.............GNU.............................GNU..4......D..L.).y.5......................................3...........................8.......................@.......................J...............................................................................................$.......................p........................................................................... ...................[.......
                                                  Process:/tmp/file5qrfjk
                                                  File Type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, for GNU/Linux 2.6.24, BuildID[sha1]=f734b08716b0c60e4484df4c0a290d79e6359a9b, not stripped
                                                  Category:dropped
                                                  Size (bytes):15885
                                                  Entropy (8bit):3.635273202542929
                                                  Encrypted:false
                                                  SSDEEP:192:GxXYSFnkHS6qvVxq3H/SdXazE/mfCFwS10f5CnxzD:VSFnkHWVxYz8ZV
                                                  MD5:46B09BE8C88B2336194BDC117006F098
                                                  SHA1:D42F2A8E5747DC4263A28D4D3B810BFC1CE7FF28
                                                  SHA-256:3E622D164B9019C69007C48BCE7AF738062D0C6C3B4D6B5B3A5A71CFBBDBCB7E
                                                  SHA-512:9F200F31C3ACF9A2E0CF3CD4526595F3BB88A847D19CD61F92FE0219086C46237228362E7DC4379C99F6BEB31EA464BB02661B555294C994337B522C0794F4CB
                                                  Malicious:true
                                                  Antivirus:
                                                  • Antivirus: ReversingLabs, Detection: 18%
                                                  Preview:.ELF..............>.....e.@.....@........"..........@.8...@.............@.......@.@.....@.@.....................................8.......8.@.....8.@...............................................@.......@....................... .......................`.......`....................... .............(.......(.`.....(.`.....................................T.......T.@.....T.@.....D.......D...............P.td....x.......x.@.....x.@.....\.......\...............Q.td....................................................R.td..............`.......`............................./lib64/ld-linux-x86-64.so.2.............GNU.............................GNU..4......D..L.).y.5......................................3...........................8.......................@.......................J...............................................................................................$.......................p........................................................................... ...................[.......
                                                  Process:/tmp/file6MzccC
                                                  File Type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, for GNU/Linux 2.6.24, BuildID[sha1]=f734b08716b0c60e4484df4c0a290d79e6359a9b, not stripped
                                                  Category:dropped
                                                  Size (bytes):15885
                                                  Entropy (8bit):3.635273202542929
                                                  Encrypted:false
                                                  SSDEEP:192:GxXYSFnkHS6qvVxq3H/SdXazE/mfCFwS10f5CnxzD:VSFnkHWVxYz8ZV
                                                  MD5:46B09BE8C88B2336194BDC117006F098
                                                  SHA1:D42F2A8E5747DC4263A28D4D3B810BFC1CE7FF28
                                                  SHA-256:3E622D164B9019C69007C48BCE7AF738062D0C6C3B4D6B5B3A5A71CFBBDBCB7E
                                                  SHA-512:9F200F31C3ACF9A2E0CF3CD4526595F3BB88A847D19CD61F92FE0219086C46237228362E7DC4379C99F6BEB31EA464BB02661B555294C994337B522C0794F4CB
                                                  Malicious:true
                                                  Antivirus:
                                                  • Antivirus: ReversingLabs, Detection: 18%
                                                  Preview:.ELF..............>.....e.@.....@........"..........@.8...@.............@.......@.@.....@.@.....................................8.......8.@.....8.@...............................................@.......@....................... .......................`.......`....................... .............(.......(.`.....(.`.....................................T.......T.@.....T.@.....D.......D...............P.td....x.......x.@.....x.@.....\.......\...............Q.td....................................................R.td..............`.......`............................./lib64/ld-linux-x86-64.so.2.............GNU.............................GNU..4......D..L.).y.5......................................3...........................8.......................@.......................J...............................................................................................$.......................p........................................................................... ...................[.......
                                                  Process:/tmp/filezmxBFz
                                                  File Type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, for GNU/Linux 2.6.24, BuildID[sha1]=f734b08716b0c60e4484df4c0a290d79e6359a9b, not stripped
                                                  Category:dropped
                                                  Size (bytes):15885
                                                  Entropy (8bit):3.635273202542929
                                                  Encrypted:false
                                                  SSDEEP:192:GxXYSFnkHS6qvVxq3H/SdXazE/mfCFwS10f5CnxzD:VSFnkHWVxYz8ZV
                                                  MD5:46B09BE8C88B2336194BDC117006F098
                                                  SHA1:D42F2A8E5747DC4263A28D4D3B810BFC1CE7FF28
                                                  SHA-256:3E622D164B9019C69007C48BCE7AF738062D0C6C3B4D6B5B3A5A71CFBBDBCB7E
                                                  SHA-512:9F200F31C3ACF9A2E0CF3CD4526595F3BB88A847D19CD61F92FE0219086C46237228362E7DC4379C99F6BEB31EA464BB02661B555294C994337B522C0794F4CB
                                                  Malicious:true
                                                  Antivirus:
                                                  • Antivirus: ReversingLabs, Detection: 18%
                                                  Preview:.ELF..............>.....e.@.....@........"..........@.8...@.............@.......@.@.....@.@.....................................8.......8.@.....8.@...............................................@.......@....................... .......................`.......`....................... .............(.......(.`.....(.`.....................................T.......T.@.....T.@.....D.......D...............P.td....x.......x.@.....x.@.....\.......\...............Q.td....................................................R.td..............`.......`............................./lib64/ld-linux-x86-64.so.2.............GNU.............................GNU..4......D..L.).y.5......................................3...........................8.......................@.......................J...............................................................................................$.......................p........................................................................... ...................[.......
                                                  Process:/tmp/filegFEB67
                                                  File Type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, for GNU/Linux 2.6.24, BuildID[sha1]=f734b08716b0c60e4484df4c0a290d79e6359a9b, not stripped
                                                  Category:dropped
                                                  Size (bytes):15885
                                                  Entropy (8bit):3.635273202542929
                                                  Encrypted:false
                                                  SSDEEP:192:GxXYSFnkHS6qvVxq3H/SdXazE/mfCFwS10f5CnxzD:VSFnkHWVxYz8ZV
                                                  MD5:46B09BE8C88B2336194BDC117006F098
                                                  SHA1:D42F2A8E5747DC4263A28D4D3B810BFC1CE7FF28
                                                  SHA-256:3E622D164B9019C69007C48BCE7AF738062D0C6C3B4D6B5B3A5A71CFBBDBCB7E
                                                  SHA-512:9F200F31C3ACF9A2E0CF3CD4526595F3BB88A847D19CD61F92FE0219086C46237228362E7DC4379C99F6BEB31EA464BB02661B555294C994337B522C0794F4CB
                                                  Malicious:true
                                                  Antivirus:
                                                  • Antivirus: ReversingLabs, Detection: 18%
                                                  Preview:.ELF..............>.....e.@.....@........"..........@.8...@.............@.......@.@.....@.@.....................................8.......8.@.....8.@...............................................@.......@....................... .......................`.......`....................... .............(.......(.`.....(.`.....................................T.......T.@.....T.@.....D.......D...............P.td....x.......x.@.....x.@.....\.......\...............Q.td....................................................R.td..............`.......`............................./lib64/ld-linux-x86-64.so.2.............GNU.............................GNU..4......D..L.).y.5......................................3...........................8.......................@.......................J...............................................................................................$.......................p........................................................................... ...................[.......
                                                  Process:/tmp/fileYWlxCh
                                                  File Type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, for GNU/Linux 2.6.24, BuildID[sha1]=f734b08716b0c60e4484df4c0a290d79e6359a9b, not stripped
                                                  Category:dropped
                                                  Size (bytes):15885
                                                  Entropy (8bit):3.635273202542929
                                                  Encrypted:false
                                                  SSDEEP:192:GxXYSFnkHS6qvVxq3H/SdXazE/mfCFwS10f5CnxzD:VSFnkHWVxYz8ZV
                                                  MD5:46B09BE8C88B2336194BDC117006F098
                                                  SHA1:D42F2A8E5747DC4263A28D4D3B810BFC1CE7FF28
                                                  SHA-256:3E622D164B9019C69007C48BCE7AF738062D0C6C3B4D6B5B3A5A71CFBBDBCB7E
                                                  SHA-512:9F200F31C3ACF9A2E0CF3CD4526595F3BB88A847D19CD61F92FE0219086C46237228362E7DC4379C99F6BEB31EA464BB02661B555294C994337B522C0794F4CB
                                                  Malicious:true
                                                  Antivirus:
                                                  • Antivirus: ReversingLabs, Detection: 18%
                                                  Preview:.ELF..............>.....e.@.....@........"..........@.8...@.............@.......@.@.....@.@.....................................8.......8.@.....8.@...............................................@.......@....................... .......................`.......`....................... .............(.......(.`.....(.`.....................................T.......T.@.....T.@.....D.......D...............P.td....x.......x.@.....x.@.....\.......\...............Q.td....................................................R.td..............`.......`............................./lib64/ld-linux-x86-64.so.2.............GNU.............................GNU..4......D..L.).y.5......................................3...........................8.......................@.......................J...............................................................................................$.......................p........................................................................... ...................[.......
                                                  Process:/tmp/file0exOS4
                                                  File Type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, for GNU/Linux 2.6.24, BuildID[sha1]=f734b08716b0c60e4484df4c0a290d79e6359a9b, not stripped
                                                  Category:dropped
                                                  Size (bytes):15885
                                                  Entropy (8bit):3.635273202542929
                                                  Encrypted:false
                                                  SSDEEP:192:GxXYSFnkHS6qvVxq3H/SdXazE/mfCFwS10f5CnxzD:VSFnkHWVxYz8ZV
                                                  MD5:46B09BE8C88B2336194BDC117006F098
                                                  SHA1:D42F2A8E5747DC4263A28D4D3B810BFC1CE7FF28
                                                  SHA-256:3E622D164B9019C69007C48BCE7AF738062D0C6C3B4D6B5B3A5A71CFBBDBCB7E
                                                  SHA-512:9F200F31C3ACF9A2E0CF3CD4526595F3BB88A847D19CD61F92FE0219086C46237228362E7DC4379C99F6BEB31EA464BB02661B555294C994337B522C0794F4CB
                                                  Malicious:true
                                                  Antivirus:
                                                  • Antivirus: ReversingLabs, Detection: 18%
                                                  Preview:.ELF..............>.....e.@.....@........"..........@.8...@.............@.......@.@.....@.@.....................................8.......8.@.....8.@...............................................@.......@....................... .......................`.......`....................... .............(.......(.`.....(.`.....................................T.......T.@.....T.@.....D.......D...............P.td....x.......x.@.....x.@.....\.......\...............Q.td....................................................R.td..............`.......`............................./lib64/ld-linux-x86-64.so.2.............GNU.............................GNU..4......D..L.).y.5......................................3...........................8.......................@.......................J...............................................................................................$.......................p........................................................................... ...................[.......
                                                  Process:/tmp/fileQ6PloQ
                                                  File Type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, for GNU/Linux 2.6.24, BuildID[sha1]=f734b08716b0c60e4484df4c0a290d79e6359a9b, not stripped
                                                  Category:dropped
                                                  Size (bytes):15885
                                                  Entropy (8bit):3.635273202542929
                                                  Encrypted:false
                                                  SSDEEP:192:GxXYSFnkHS6qvVxq3H/SdXazE/mfCFwS10f5CnxzD:VSFnkHWVxYz8ZV
                                                  MD5:46B09BE8C88B2336194BDC117006F098
                                                  SHA1:D42F2A8E5747DC4263A28D4D3B810BFC1CE7FF28
                                                  SHA-256:3E622D164B9019C69007C48BCE7AF738062D0C6C3B4D6B5B3A5A71CFBBDBCB7E
                                                  SHA-512:9F200F31C3ACF9A2E0CF3CD4526595F3BB88A847D19CD61F92FE0219086C46237228362E7DC4379C99F6BEB31EA464BB02661B555294C994337B522C0794F4CB
                                                  Malicious:true
                                                  Antivirus:
                                                  • Antivirus: ReversingLabs, Detection: 18%
                                                  Preview:.ELF..............>.....e.@.....@........"..........@.8...@.............@.......@.@.....@.@.....................................8.......8.@.....8.@...............................................@.......@....................... .......................`.......`....................... .............(.......(.`.....(.`.....................................T.......T.@.....T.@.....D.......D...............P.td....x.......x.@.....x.@.....\.......\...............Q.td....................................................R.td..............`.......`............................./lib64/ld-linux-x86-64.so.2.............GNU.............................GNU..4......D..L.).y.5......................................3...........................8.......................@.......................J...............................................................................................$.......................p........................................................................... ...................[.......
                                                  Process:/tmp/fileFTsWOP
                                                  File Type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, for GNU/Linux 2.6.24, BuildID[sha1]=f734b08716b0c60e4484df4c0a290d79e6359a9b, not stripped
                                                  Category:dropped
                                                  Size (bytes):15885
                                                  Entropy (8bit):3.635273202542929
                                                  Encrypted:false
                                                  SSDEEP:192:GxXYSFnkHS6qvVxq3H/SdXazE/mfCFwS10f5CnxzD:VSFnkHWVxYz8ZV
                                                  MD5:46B09BE8C88B2336194BDC117006F098
                                                  SHA1:D42F2A8E5747DC4263A28D4D3B810BFC1CE7FF28
                                                  SHA-256:3E622D164B9019C69007C48BCE7AF738062D0C6C3B4D6B5B3A5A71CFBBDBCB7E
                                                  SHA-512:9F200F31C3ACF9A2E0CF3CD4526595F3BB88A847D19CD61F92FE0219086C46237228362E7DC4379C99F6BEB31EA464BB02661B555294C994337B522C0794F4CB
                                                  Malicious:true
                                                  Antivirus:
                                                  • Antivirus: ReversingLabs, Detection: 18%
                                                  Preview:.ELF..............>.....e.@.....@........"..........@.8...@.............@.......@.@.....@.@.....................................8.......8.@.....8.@...............................................@.......@....................... .......................`.......`....................... .............(.......(.`.....(.`.....................................T.......T.@.....T.@.....D.......D...............P.td....x.......x.@.....x.@.....\.......\...............Q.td....................................................R.td..............`.......`............................./lib64/ld-linux-x86-64.so.2.............GNU.............................GNU..4......D..L.).y.5......................................3...........................8.......................@.......................J...............................................................................................$.......................p........................................................................... ...................[.......
                                                  Process:/tmp/fileFBsYn2
                                                  File Type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, for GNU/Linux 2.6.24, BuildID[sha1]=f734b08716b0c60e4484df4c0a290d79e6359a9b, not stripped
                                                  Category:dropped
                                                  Size (bytes):15885
                                                  Entropy (8bit):3.635273202542929
                                                  Encrypted:false
                                                  SSDEEP:192:GxXYSFnkHS6qvVxq3H/SdXazE/mfCFwS10f5CnxzD:VSFnkHWVxYz8ZV
                                                  MD5:46B09BE8C88B2336194BDC117006F098
                                                  SHA1:D42F2A8E5747DC4263A28D4D3B810BFC1CE7FF28
                                                  SHA-256:3E622D164B9019C69007C48BCE7AF738062D0C6C3B4D6B5B3A5A71CFBBDBCB7E
                                                  SHA-512:9F200F31C3ACF9A2E0CF3CD4526595F3BB88A847D19CD61F92FE0219086C46237228362E7DC4379C99F6BEB31EA464BB02661B555294C994337B522C0794F4CB
                                                  Malicious:true
                                                  Antivirus:
                                                  • Antivirus: ReversingLabs, Detection: 18%
                                                  Preview:.ELF..............>.....e.@.....@........"..........@.8...@.............@.......@.@.....@.@.....................................8.......8.@.....8.@...............................................@.......@....................... .......................`.......`....................... .............(.......(.`.....(.`.....................................T.......T.@.....T.@.....D.......D...............P.td....x.......x.@.....x.@.....\.......\...............Q.td....................................................R.td..............`.......`............................./lib64/ld-linux-x86-64.so.2.............GNU.............................GNU..4......D..L.).y.5......................................3...........................8.......................@.......................J...............................................................................................$.......................p........................................................................... ...................[.......
                                                  Process:/tmp/filePxLHKY
                                                  File Type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, for GNU/Linux 2.6.24, BuildID[sha1]=f734b08716b0c60e4484df4c0a290d79e6359a9b, not stripped
                                                  Category:dropped
                                                  Size (bytes):15885
                                                  Entropy (8bit):3.635273202542929
                                                  Encrypted:false
                                                  SSDEEP:192:GxXYSFnkHS6qvVxq3H/SdXazE/mfCFwS10f5CnxzD:VSFnkHWVxYz8ZV
                                                  MD5:46B09BE8C88B2336194BDC117006F098
                                                  SHA1:D42F2A8E5747DC4263A28D4D3B810BFC1CE7FF28
                                                  SHA-256:3E622D164B9019C69007C48BCE7AF738062D0C6C3B4D6B5B3A5A71CFBBDBCB7E
                                                  SHA-512:9F200F31C3ACF9A2E0CF3CD4526595F3BB88A847D19CD61F92FE0219086C46237228362E7DC4379C99F6BEB31EA464BB02661B555294C994337B522C0794F4CB
                                                  Malicious:true
                                                  Antivirus:
                                                  • Antivirus: ReversingLabs, Detection: 18%
                                                  Preview:.ELF..............>.....e.@.....@........"..........@.8...@.............@.......@.@.....@.@.....................................8.......8.@.....8.@...............................................@.......@....................... .......................`.......`....................... .............(.......(.`.....(.`.....................................T.......T.@.....T.@.....D.......D...............P.td....x.......x.@.....x.@.....\.......\...............Q.td....................................................R.td..............`.......`............................./lib64/ld-linux-x86-64.so.2.............GNU.............................GNU..4......D..L.).y.5......................................3...........................8.......................@.......................J...............................................................................................$.......................p........................................................................... ...................[.......
                                                  Process:/tmp/file3voGS3
                                                  File Type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, for GNU/Linux 2.6.24, BuildID[sha1]=f734b08716b0c60e4484df4c0a290d79e6359a9b, not stripped
                                                  Category:dropped
                                                  Size (bytes):15885
                                                  Entropy (8bit):3.635273202542929
                                                  Encrypted:false
                                                  SSDEEP:192:GxXYSFnkHS6qvVxq3H/SdXazE/mfCFwS10f5CnxzD:VSFnkHWVxYz8ZV
                                                  MD5:46B09BE8C88B2336194BDC117006F098
                                                  SHA1:D42F2A8E5747DC4263A28D4D3B810BFC1CE7FF28
                                                  SHA-256:3E622D164B9019C69007C48BCE7AF738062D0C6C3B4D6B5B3A5A71CFBBDBCB7E
                                                  SHA-512:9F200F31C3ACF9A2E0CF3CD4526595F3BB88A847D19CD61F92FE0219086C46237228362E7DC4379C99F6BEB31EA464BB02661B555294C994337B522C0794F4CB
                                                  Malicious:true
                                                  Antivirus:
                                                  • Antivirus: ReversingLabs, Detection: 18%
                                                  Preview:.ELF..............>.....e.@.....@........"..........@.8...@.............@.......@.@.....@.@.....................................8.......8.@.....8.@...............................................@.......@....................... .......................`.......`....................... .............(.......(.`.....(.`.....................................T.......T.@.....T.@.....D.......D...............P.td....x.......x.@.....x.@.....\.......\...............Q.td....................................................R.td..............`.......`............................./lib64/ld-linux-x86-64.so.2.............GNU.............................GNU..4......D..L.).y.5......................................3...........................8.......................@.......................J...............................................................................................$.......................p........................................................................... ...................[.......
                                                  Process:/tmp/file7pm3Gp
                                                  File Type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, for GNU/Linux 2.6.24, BuildID[sha1]=f734b08716b0c60e4484df4c0a290d79e6359a9b, not stripped
                                                  Category:dropped
                                                  Size (bytes):15885
                                                  Entropy (8bit):3.635273202542929
                                                  Encrypted:false
                                                  SSDEEP:192:GxXYSFnkHS6qvVxq3H/SdXazE/mfCFwS10f5CnxzD:VSFnkHWVxYz8ZV
                                                  MD5:46B09BE8C88B2336194BDC117006F098
                                                  SHA1:D42F2A8E5747DC4263A28D4D3B810BFC1CE7FF28
                                                  SHA-256:3E622D164B9019C69007C48BCE7AF738062D0C6C3B4D6B5B3A5A71CFBBDBCB7E
                                                  SHA-512:9F200F31C3ACF9A2E0CF3CD4526595F3BB88A847D19CD61F92FE0219086C46237228362E7DC4379C99F6BEB31EA464BB02661B555294C994337B522C0794F4CB
                                                  Malicious:true
                                                  Antivirus:
                                                  • Antivirus: ReversingLabs, Detection: 18%
                                                  Preview:.ELF..............>.....e.@.....@........"..........@.8...@.............@.......@.@.....@.@.....................................8.......8.@.....8.@...............................................@.......@....................... .......................`.......`....................... .............(.......(.`.....(.`.....................................T.......T.@.....T.@.....D.......D...............P.td....x.......x.@.....x.@.....\.......\...............Q.td....................................................R.td..............`.......`............................./lib64/ld-linux-x86-64.so.2.............GNU.............................GNU..4......D..L.).y.5......................................3...........................8.......................@.......................J...............................................................................................$.......................p........................................................................... ...................[.......
                                                  Process:/tmp/filelqfWgf
                                                  File Type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, for GNU/Linux 2.6.24, BuildID[sha1]=f734b08716b0c60e4484df4c0a290d79e6359a9b, not stripped
                                                  Category:dropped
                                                  Size (bytes):15885
                                                  Entropy (8bit):3.635273202542929
                                                  Encrypted:false
                                                  SSDEEP:192:GxXYSFnkHS6qvVxq3H/SdXazE/mfCFwS10f5CnxzD:VSFnkHWVxYz8ZV
                                                  MD5:46B09BE8C88B2336194BDC117006F098
                                                  SHA1:D42F2A8E5747DC4263A28D4D3B810BFC1CE7FF28
                                                  SHA-256:3E622D164B9019C69007C48BCE7AF738062D0C6C3B4D6B5B3A5A71CFBBDBCB7E
                                                  SHA-512:9F200F31C3ACF9A2E0CF3CD4526595F3BB88A847D19CD61F92FE0219086C46237228362E7DC4379C99F6BEB31EA464BB02661B555294C994337B522C0794F4CB
                                                  Malicious:true
                                                  Antivirus:
                                                  • Antivirus: ReversingLabs, Detection: 18%
                                                  Preview:.ELF..............>.....e.@.....@........"..........@.8...@.............@.......@.@.....@.@.....................................8.......8.@.....8.@...............................................@.......@....................... .......................`.......`....................... .............(.......(.`.....(.`.....................................T.......T.@.....T.@.....D.......D...............P.td....x.......x.@.....x.@.....\.......\...............Q.td....................................................R.td..............`.......`............................./lib64/ld-linux-x86-64.so.2.............GNU.............................GNU..4......D..L.).y.5......................................3...........................8.......................@.......................J...............................................................................................$.......................p........................................................................... ...................[.......
                                                  Process:/tmp/fileLAS8lK
                                                  File Type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, for GNU/Linux 2.6.24, BuildID[sha1]=f734b08716b0c60e4484df4c0a290d79e6359a9b, not stripped
                                                  Category:dropped
                                                  Size (bytes):15885
                                                  Entropy (8bit):3.635273202542929
                                                  Encrypted:false
                                                  SSDEEP:192:GxXYSFnkHS6qvVxq3H/SdXazE/mfCFwS10f5CnxzD:VSFnkHWVxYz8ZV
                                                  MD5:46B09BE8C88B2336194BDC117006F098
                                                  SHA1:D42F2A8E5747DC4263A28D4D3B810BFC1CE7FF28
                                                  SHA-256:3E622D164B9019C69007C48BCE7AF738062D0C6C3B4D6B5B3A5A71CFBBDBCB7E
                                                  SHA-512:9F200F31C3ACF9A2E0CF3CD4526595F3BB88A847D19CD61F92FE0219086C46237228362E7DC4379C99F6BEB31EA464BB02661B555294C994337B522C0794F4CB
                                                  Malicious:true
                                                  Antivirus:
                                                  • Antivirus: ReversingLabs, Detection: 18%
                                                  Preview:.ELF..............>.....e.@.....@........"..........@.8...@.............@.......@.@.....@.@.....................................8.......8.@.....8.@...............................................@.......@....................... .......................`.......`....................... .............(.......(.`.....(.`.....................................T.......T.@.....T.@.....D.......D...............P.td....x.......x.@.....x.@.....\.......\...............Q.td....................................................R.td..............`.......`............................./lib64/ld-linux-x86-64.so.2.............GNU.............................GNU..4......D..L.).y.5......................................3...........................8.......................@.......................J...............................................................................................$.......................p........................................................................... ...................[.......
                                                  Process:/tmp/filelpjDaB
                                                  File Type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, for GNU/Linux 2.6.24, BuildID[sha1]=f734b08716b0c60e4484df4c0a290d79e6359a9b, not stripped
                                                  Category:dropped
                                                  Size (bytes):15885
                                                  Entropy (8bit):3.635273202542929
                                                  Encrypted:false
                                                  SSDEEP:192:GxXYSFnkHS6qvVxq3H/SdXazE/mfCFwS10f5CnxzD:VSFnkHWVxYz8ZV
                                                  MD5:46B09BE8C88B2336194BDC117006F098
                                                  SHA1:D42F2A8E5747DC4263A28D4D3B810BFC1CE7FF28
                                                  SHA-256:3E622D164B9019C69007C48BCE7AF738062D0C6C3B4D6B5B3A5A71CFBBDBCB7E
                                                  SHA-512:9F200F31C3ACF9A2E0CF3CD4526595F3BB88A847D19CD61F92FE0219086C46237228362E7DC4379C99F6BEB31EA464BB02661B555294C994337B522C0794F4CB
                                                  Malicious:true
                                                  Antivirus:
                                                  • Antivirus: ReversingLabs, Detection: 18%
                                                  Preview:.ELF..............>.....e.@.....@........"..........@.8...@.............@.......@.@.....@.@.....................................8.......8.@.....8.@...............................................@.......@....................... .......................`.......`....................... .............(.......(.`.....(.`.....................................T.......T.@.....T.@.....D.......D...............P.td....x.......x.@.....x.@.....\.......\...............Q.td....................................................R.td..............`.......`............................./lib64/ld-linux-x86-64.so.2.............GNU.............................GNU..4......D..L.).y.5......................................3...........................8.......................@.......................J...............................................................................................$.......................p........................................................................... ...................[.......
                                                  Process:/tmp/filecLo1bv
                                                  File Type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, for GNU/Linux 2.6.24, BuildID[sha1]=f734b08716b0c60e4484df4c0a290d79e6359a9b, not stripped
                                                  Category:dropped
                                                  Size (bytes):15885
                                                  Entropy (8bit):3.635273202542929
                                                  Encrypted:false
                                                  SSDEEP:192:GxXYSFnkHS6qvVxq3H/SdXazE/mfCFwS10f5CnxzD:VSFnkHWVxYz8ZV
                                                  MD5:46B09BE8C88B2336194BDC117006F098
                                                  SHA1:D42F2A8E5747DC4263A28D4D3B810BFC1CE7FF28
                                                  SHA-256:3E622D164B9019C69007C48BCE7AF738062D0C6C3B4D6B5B3A5A71CFBBDBCB7E
                                                  SHA-512:9F200F31C3ACF9A2E0CF3CD4526595F3BB88A847D19CD61F92FE0219086C46237228362E7DC4379C99F6BEB31EA464BB02661B555294C994337B522C0794F4CB
                                                  Malicious:true
                                                  Antivirus:
                                                  • Antivirus: ReversingLabs, Detection: 18%
                                                  Preview:.ELF..............>.....e.@.....@........"..........@.8...@.............@.......@.@.....@.@.....................................8.......8.@.....8.@...............................................@.......@....................... .......................`.......`....................... .............(.......(.`.....(.`.....................................T.......T.@.....T.@.....D.......D...............P.td....x.......x.@.....x.@.....\.......\...............Q.td....................................................R.td..............`.......`............................./lib64/ld-linux-x86-64.so.2.............GNU.............................GNU..4......D..L.).y.5......................................3...........................8.......................@.......................J...............................................................................................$.......................p........................................................................... ...................[.......
                                                  Process:/tmp/fileAyj87h
                                                  File Type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, for GNU/Linux 2.6.24, BuildID[sha1]=f734b08716b0c60e4484df4c0a290d79e6359a9b, not stripped
                                                  Category:dropped
                                                  Size (bytes):15885
                                                  Entropy (8bit):3.635273202542929
                                                  Encrypted:false
                                                  SSDEEP:192:GxXYSFnkHS6qvVxq3H/SdXazE/mfCFwS10f5CnxzD:VSFnkHWVxYz8ZV
                                                  MD5:46B09BE8C88B2336194BDC117006F098
                                                  SHA1:D42F2A8E5747DC4263A28D4D3B810BFC1CE7FF28
                                                  SHA-256:3E622D164B9019C69007C48BCE7AF738062D0C6C3B4D6B5B3A5A71CFBBDBCB7E
                                                  SHA-512:9F200F31C3ACF9A2E0CF3CD4526595F3BB88A847D19CD61F92FE0219086C46237228362E7DC4379C99F6BEB31EA464BB02661B555294C994337B522C0794F4CB
                                                  Malicious:true
                                                  Antivirus:
                                                  • Antivirus: ReversingLabs, Detection: 18%
                                                  Preview:.ELF..............>.....e.@.....@........"..........@.8...@.............@.......@.@.....@.@.....................................8.......8.@.....8.@...............................................@.......@....................... .......................`.......`....................... .............(.......(.`.....(.`.....................................T.......T.@.....T.@.....D.......D...............P.td....x.......x.@.....x.@.....\.......\...............Q.td....................................................R.td..............`.......`............................./lib64/ld-linux-x86-64.so.2.............GNU.............................GNU..4......D..L.).y.5......................................3...........................8.......................@.......................J...............................................................................................$.......................p........................................................................... ...................[.......
                                                  Process:/tmp/file30mPH0
                                                  File Type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, for GNU/Linux 2.6.24, BuildID[sha1]=f734b08716b0c60e4484df4c0a290d79e6359a9b, not stripped
                                                  Category:dropped
                                                  Size (bytes):15885
                                                  Entropy (8bit):3.635273202542929
                                                  Encrypted:false
                                                  SSDEEP:192:GxXYSFnkHS6qvVxq3H/SdXazE/mfCFwS10f5CnxzD:VSFnkHWVxYz8ZV
                                                  MD5:46B09BE8C88B2336194BDC117006F098
                                                  SHA1:D42F2A8E5747DC4263A28D4D3B810BFC1CE7FF28
                                                  SHA-256:3E622D164B9019C69007C48BCE7AF738062D0C6C3B4D6B5B3A5A71CFBBDBCB7E
                                                  SHA-512:9F200F31C3ACF9A2E0CF3CD4526595F3BB88A847D19CD61F92FE0219086C46237228362E7DC4379C99F6BEB31EA464BB02661B555294C994337B522C0794F4CB
                                                  Malicious:true
                                                  Antivirus:
                                                  • Antivirus: ReversingLabs, Detection: 18%
                                                  Preview:.ELF..............>.....e.@.....@........"..........@.8...@.............@.......@.@.....@.@.....................................8.......8.@.....8.@...............................................@.......@....................... .......................`.......`....................... .............(.......(.`.....(.`.....................................T.......T.@.....T.@.....D.......D...............P.td....x.......x.@.....x.@.....\.......\...............Q.td....................................................R.td..............`.......`............................./lib64/ld-linux-x86-64.so.2.............GNU.............................GNU..4......D..L.).y.5......................................3...........................8.......................@.......................J...............................................................................................$.......................p........................................................................... ...................[.......
                                                  Process:/tmp/filecprMtT
                                                  File Type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, for GNU/Linux 2.6.24, BuildID[sha1]=f734b08716b0c60e4484df4c0a290d79e6359a9b, not stripped
                                                  Category:dropped
                                                  Size (bytes):15885
                                                  Entropy (8bit):3.635273202542929
                                                  Encrypted:false
                                                  SSDEEP:192:GxXYSFnkHS6qvVxq3H/SdXazE/mfCFwS10f5CnxzD:VSFnkHWVxYz8ZV
                                                  MD5:46B09BE8C88B2336194BDC117006F098
                                                  SHA1:D42F2A8E5747DC4263A28D4D3B810BFC1CE7FF28
                                                  SHA-256:3E622D164B9019C69007C48BCE7AF738062D0C6C3B4D6B5B3A5A71CFBBDBCB7E
                                                  SHA-512:9F200F31C3ACF9A2E0CF3CD4526595F3BB88A847D19CD61F92FE0219086C46237228362E7DC4379C99F6BEB31EA464BB02661B555294C994337B522C0794F4CB
                                                  Malicious:true
                                                  Antivirus:
                                                  • Antivirus: ReversingLabs, Detection: 18%
                                                  Preview:.ELF..............>.....e.@.....@........"..........@.8...@.............@.......@.@.....@.@.....................................8.......8.@.....8.@...............................................@.......@....................... .......................`.......`....................... .............(.......(.`.....(.`.....................................T.......T.@.....T.@.....D.......D...............P.td....x.......x.@.....x.@.....\.......\...............Q.td....................................................R.td..............`.......`............................./lib64/ld-linux-x86-64.so.2.............GNU.............................GNU..4......D..L.).y.5......................................3...........................8.......................@.......................J...............................................................................................$.......................p........................................................................... ...................[.......
                                                  Process:/tmp/fileVXRF8s
                                                  File Type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, for GNU/Linux 2.6.24, BuildID[sha1]=f734b08716b0c60e4484df4c0a290d79e6359a9b, not stripped
                                                  Category:dropped
                                                  Size (bytes):15885
                                                  Entropy (8bit):3.635273202542929
                                                  Encrypted:false
                                                  SSDEEP:192:GxXYSFnkHS6qvVxq3H/SdXazE/mfCFwS10f5CnxzD:VSFnkHWVxYz8ZV
                                                  MD5:46B09BE8C88B2336194BDC117006F098
                                                  SHA1:D42F2A8E5747DC4263A28D4D3B810BFC1CE7FF28
                                                  SHA-256:3E622D164B9019C69007C48BCE7AF738062D0C6C3B4D6B5B3A5A71CFBBDBCB7E
                                                  SHA-512:9F200F31C3ACF9A2E0CF3CD4526595F3BB88A847D19CD61F92FE0219086C46237228362E7DC4379C99F6BEB31EA464BB02661B555294C994337B522C0794F4CB
                                                  Malicious:true
                                                  Antivirus:
                                                  • Antivirus: ReversingLabs, Detection: 18%
                                                  Preview:.ELF..............>.....e.@.....@........"..........@.8...@.............@.......@.@.....@.@.....................................8.......8.@.....8.@...............................................@.......@....................... .......................`.......`....................... .............(.......(.`.....(.`.....................................T.......T.@.....T.@.....D.......D...............P.td....x.......x.@.....x.@.....\.......\...............Q.td....................................................R.td..............`.......`............................./lib64/ld-linux-x86-64.so.2.............GNU.............................GNU..4......D..L.).y.5......................................3...........................8.......................@.......................J...............................................................................................$.......................p........................................................................... ...................[.......
                                                  Process:/tmp/fileR5OlIm
                                                  File Type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, for GNU/Linux 2.6.24, BuildID[sha1]=f734b08716b0c60e4484df4c0a290d79e6359a9b, not stripped
                                                  Category:dropped
                                                  Size (bytes):15885
                                                  Entropy (8bit):3.635273202542929
                                                  Encrypted:false
                                                  SSDEEP:192:GxXYSFnkHS6qvVxq3H/SdXazE/mfCFwS10f5CnxzD:VSFnkHWVxYz8ZV
                                                  MD5:46B09BE8C88B2336194BDC117006F098
                                                  SHA1:D42F2A8E5747DC4263A28D4D3B810BFC1CE7FF28
                                                  SHA-256:3E622D164B9019C69007C48BCE7AF738062D0C6C3B4D6B5B3A5A71CFBBDBCB7E
                                                  SHA-512:9F200F31C3ACF9A2E0CF3CD4526595F3BB88A847D19CD61F92FE0219086C46237228362E7DC4379C99F6BEB31EA464BB02661B555294C994337B522C0794F4CB
                                                  Malicious:true
                                                  Antivirus:
                                                  • Antivirus: ReversingLabs, Detection: 18%
                                                  Preview:.ELF..............>.....e.@.....@........"..........@.8...@.............@.......@.@.....@.@.....................................8.......8.@.....8.@...............................................@.......@....................... .......................`.......`....................... .............(.......(.`.....(.`.....................................T.......T.@.....T.@.....D.......D...............P.td....x.......x.@.....x.@.....\.......\...............Q.td....................................................R.td..............`.......`............................./lib64/ld-linux-x86-64.so.2.............GNU.............................GNU..4......D..L.).y.5......................................3...........................8.......................@.......................J...............................................................................................$.......................p........................................................................... ...................[.......
                                                  Process:/tmp/filesZIILS
                                                  File Type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, for GNU/Linux 2.6.24, BuildID[sha1]=f734b08716b0c60e4484df4c0a290d79e6359a9b, not stripped
                                                  Category:dropped
                                                  Size (bytes):15885
                                                  Entropy (8bit):3.635273202542929
                                                  Encrypted:false
                                                  SSDEEP:192:GxXYSFnkHS6qvVxq3H/SdXazE/mfCFwS10f5CnxzD:VSFnkHWVxYz8ZV
                                                  MD5:46B09BE8C88B2336194BDC117006F098
                                                  SHA1:D42F2A8E5747DC4263A28D4D3B810BFC1CE7FF28
                                                  SHA-256:3E622D164B9019C69007C48BCE7AF738062D0C6C3B4D6B5B3A5A71CFBBDBCB7E
                                                  SHA-512:9F200F31C3ACF9A2E0CF3CD4526595F3BB88A847D19CD61F92FE0219086C46237228362E7DC4379C99F6BEB31EA464BB02661B555294C994337B522C0794F4CB
                                                  Malicious:true
                                                  Antivirus:
                                                  • Antivirus: ReversingLabs, Detection: 18%
                                                  Preview:.ELF..............>.....e.@.....@........"..........@.8...@.............@.......@.@.....@.@.....................................8.......8.@.....8.@...............................................@.......@....................... .......................`.......`....................... .............(.......(.`.....(.`.....................................T.......T.@.....T.@.....D.......D...............P.td....x.......x.@.....x.@.....\.......\...............Q.td....................................................R.td..............`.......`............................./lib64/ld-linux-x86-64.so.2.............GNU.............................GNU..4......D..L.).y.5......................................3...........................8.......................@.......................J...............................................................................................$.......................p........................................................................... ...................[.......
                                                  Process:/tmp/ssa.elf
                                                  File Type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, for GNU/Linux 2.6.24, BuildID[sha1]=f734b08716b0c60e4484df4c0a290d79e6359a9b, not stripped
                                                  Category:dropped
                                                  Size (bytes):15884
                                                  Entropy (8bit):3.6350474814062426
                                                  Encrypted:false
                                                  SSDEEP:192:GxXYSFnkHS6qvVxq3H/SdXazE/mfCFwS10f5CnxzC:VSFnkHWVxYz8ZQ
                                                  MD5:85496FED6902EC507930356F00302C5A
                                                  SHA1:FB7EF2B0F9CCDAEAABBFD3F087E2F1FF5C943FAE
                                                  SHA-256:5E80767AE990B6DF553F5E1516144065E4246D75BF9355BD0271A3CCF58F63A5
                                                  SHA-512:90182C79FB1F754BE5227A636573E8D8534BE950E0EAE19E1830F7B85A0CA42EBD069D86EAE5AD0037063506C7E63B2C4DC92BA101E9652E441F06AD6C7BD661
                                                  Malicious:true
                                                  Antivirus:
                                                  • Antivirus: ReversingLabs, Detection: 21%
                                                  Preview:.ELF..............>.....e.@.....@........"..........@.8...@.............@.......@.@.....@.@.....................................8.......8.@.....8.@...............................................@.......@....................... .......................`.......`....................... .............(.......(.`.....(.`.....................................T.......T.@.....T.@.....D.......D...............P.td....x.......x.@.....x.@.....\.......\...............Q.td....................................................R.td..............`.......`............................./lib64/ld-linux-x86-64.so.2.............GNU.............................GNU..4......D..L.).y.5......................................3...........................8.......................@.......................J...............................................................................................$.......................p........................................................................... ...................[.......
                                                  Process:/tmp/filepbk33b
                                                  File Type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, for GNU/Linux 2.6.24, BuildID[sha1]=f734b08716b0c60e4484df4c0a290d79e6359a9b, not stripped
                                                  Category:dropped
                                                  Size (bytes):15885
                                                  Entropy (8bit):3.635273202542929
                                                  Encrypted:false
                                                  SSDEEP:192:GxXYSFnkHS6qvVxq3H/SdXazE/mfCFwS10f5CnxzD:VSFnkHWVxYz8ZV
                                                  MD5:46B09BE8C88B2336194BDC117006F098
                                                  SHA1:D42F2A8E5747DC4263A28D4D3B810BFC1CE7FF28
                                                  SHA-256:3E622D164B9019C69007C48BCE7AF738062D0C6C3B4D6B5B3A5A71CFBBDBCB7E
                                                  SHA-512:9F200F31C3ACF9A2E0CF3CD4526595F3BB88A847D19CD61F92FE0219086C46237228362E7DC4379C99F6BEB31EA464BB02661B555294C994337B522C0794F4CB
                                                  Malicious:true
                                                  Antivirus:
                                                  • Antivirus: ReversingLabs, Detection: 18%
                                                  Preview:.ELF..............>.....e.@.....@........"..........@.8...@.............@.......@.@.....@.@.....................................8.......8.@.....8.@...............................................@.......@....................... .......................`.......`....................... .............(.......(.`.....(.`.....................................T.......T.@.....T.@.....D.......D...............P.td....x.......x.@.....x.@.....\.......\...............Q.td....................................................R.td..............`.......`............................./lib64/ld-linux-x86-64.so.2.............GNU.............................GNU..4......D..L.).y.5......................................3...........................8.......................@.......................J...............................................................................................$.......................p........................................................................... ...................[.......
                                                  Process:/tmp/fileY0Ofem
                                                  File Type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, for GNU/Linux 2.6.24, BuildID[sha1]=f734b08716b0c60e4484df4c0a290d79e6359a9b, not stripped
                                                  Category:dropped
                                                  Size (bytes):15885
                                                  Entropy (8bit):3.635273202542929
                                                  Encrypted:false
                                                  SSDEEP:192:GxXYSFnkHS6qvVxq3H/SdXazE/mfCFwS10f5CnxzD:VSFnkHWVxYz8ZV
                                                  MD5:46B09BE8C88B2336194BDC117006F098
                                                  SHA1:D42F2A8E5747DC4263A28D4D3B810BFC1CE7FF28
                                                  SHA-256:3E622D164B9019C69007C48BCE7AF738062D0C6C3B4D6B5B3A5A71CFBBDBCB7E
                                                  SHA-512:9F200F31C3ACF9A2E0CF3CD4526595F3BB88A847D19CD61F92FE0219086C46237228362E7DC4379C99F6BEB31EA464BB02661B555294C994337B522C0794F4CB
                                                  Malicious:true
                                                  Antivirus:
                                                  • Antivirus: ReversingLabs, Detection: 18%
                                                  Preview:.ELF..............>.....e.@.....@........"..........@.8...@.............@.......@.@.....@.@.....................................8.......8.@.....8.@...............................................@.......@....................... .......................`.......`....................... .............(.......(.`.....(.`.....................................T.......T.@.....T.@.....D.......D...............P.td....x.......x.@.....x.@.....\.......\...............Q.td....................................................R.td..............`.......`............................./lib64/ld-linux-x86-64.so.2.............GNU.............................GNU..4......D..L.).y.5......................................3...........................8.......................@.......................J...............................................................................................$.......................p........................................................................... ...................[.......
                                                  Process:/tmp/fileqhyxmA
                                                  File Type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, for GNU/Linux 2.6.24, BuildID[sha1]=f734b08716b0c60e4484df4c0a290d79e6359a9b, not stripped
                                                  Category:dropped
                                                  Size (bytes):15885
                                                  Entropy (8bit):3.635273202542929
                                                  Encrypted:false
                                                  SSDEEP:192:GxXYSFnkHS6qvVxq3H/SdXazE/mfCFwS10f5CnxzD:VSFnkHWVxYz8ZV
                                                  MD5:46B09BE8C88B2336194BDC117006F098
                                                  SHA1:D42F2A8E5747DC4263A28D4D3B810BFC1CE7FF28
                                                  SHA-256:3E622D164B9019C69007C48BCE7AF738062D0C6C3B4D6B5B3A5A71CFBBDBCB7E
                                                  SHA-512:9F200F31C3ACF9A2E0CF3CD4526595F3BB88A847D19CD61F92FE0219086C46237228362E7DC4379C99F6BEB31EA464BB02661B555294C994337B522C0794F4CB
                                                  Malicious:true
                                                  Antivirus:
                                                  • Antivirus: ReversingLabs, Detection: 18%
                                                  Preview:.ELF..............>.....e.@.....@........"..........@.8...@.............@.......@.@.....@.@.....................................8.......8.@.....8.@...............................................@.......@....................... .......................`.......`....................... .............(.......(.`.....(.`.....................................T.......T.@.....T.@.....D.......D...............P.td....x.......x.@.....x.@.....\.......\...............Q.td....................................................R.td..............`.......`............................./lib64/ld-linux-x86-64.so.2.............GNU.............................GNU..4......D..L.).y.5......................................3...........................8.......................@.......................J...............................................................................................$.......................p........................................................................... ...................[.......
                                                  Process:/tmp/fileyst50V
                                                  File Type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, for GNU/Linux 2.6.24, BuildID[sha1]=f734b08716b0c60e4484df4c0a290d79e6359a9b, not stripped
                                                  Category:dropped
                                                  Size (bytes):15885
                                                  Entropy (8bit):3.635273202542929
                                                  Encrypted:false
                                                  SSDEEP:192:GxXYSFnkHS6qvVxq3H/SdXazE/mfCFwS10f5CnxzD:VSFnkHWVxYz8ZV
                                                  MD5:46B09BE8C88B2336194BDC117006F098
                                                  SHA1:D42F2A8E5747DC4263A28D4D3B810BFC1CE7FF28
                                                  SHA-256:3E622D164B9019C69007C48BCE7AF738062D0C6C3B4D6B5B3A5A71CFBBDBCB7E
                                                  SHA-512:9F200F31C3ACF9A2E0CF3CD4526595F3BB88A847D19CD61F92FE0219086C46237228362E7DC4379C99F6BEB31EA464BB02661B555294C994337B522C0794F4CB
                                                  Malicious:true
                                                  Antivirus:
                                                  • Antivirus: ReversingLabs, Detection: 18%
                                                  Preview:.ELF..............>.....e.@.....@........"..........@.8...@.............@.......@.@.....@.@.....................................8.......8.@.....8.@...............................................@.......@....................... .......................`.......`....................... .............(.......(.`.....(.`.....................................T.......T.@.....T.@.....D.......D...............P.td....x.......x.@.....x.@.....\.......\...............Q.td....................................................R.td..............`.......`............................./lib64/ld-linux-x86-64.so.2.............GNU.............................GNU..4......D..L.).y.5......................................3...........................8.......................@.......................J...............................................................................................$.......................p........................................................................... ...................[.......
                                                  File type:ELF 64-bit LSB pie executable, x86-64, version 1 (SYSV), for GNU/Linux 3.2.0, BuildID[sha1]=a5bdb209387e06cba305d4d5db76c52b7cb6ea26, dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, no section header
                                                  Entropy (8bit):4.160129975683097
                                                  TrID:
                                                  • ELF Executable and Linkable format (Linux) (4029/14) 49.77%
                                                  • ELF Executable and Linkable format (generic) (4004/1) 49.46%
                                                  • Lumena CEL bitmap (63/63) 0.78%
                                                  File name:ssa.elf
                                                  File size:22'295 bytes
                                                  MD5:bfdb94bee37b0e7705691ce092aa9884
                                                  SHA1:1572dbd674abc131f94eb99867808dd15ac8d84f
                                                  SHA256:f603f667217b42a92ebf6b4dbec5aab922290915673e1b49f8244a72231f13e2
                                                  SHA512:5db4d75d5ac05b5b892794a88ada5818c1e876a34259f486adfc5c4a295ea62ce75af306c49ed1c8778be9ea2e62e7d64c37fce641671e10cc22261d9a499747
                                                  SSDEEP:192:RnxzjwsWskaDanX6JENuZYhz0h+fcfLBj4xXYSFnkHS6qvVxq3H/SdXazE/mfCFn:BWskamFsqGhR9j/SFnkHWVxYz8ZB
                                                  TLSH:A9A2B88BF6528E7EC4D8C334445B853425B7B870EB12A3373A4865B51E8275C2F1EB6B
                                                  File Content Preview:.ELF..............>.....P.......@...................@.8...@.............@.......@.......@.......................................8.......8.......8...............................................................0.......0......... ....................... ....

                                                  ELF header

                                                  Class:ELF64
                                                  Data:2's complement, little endian
                                                  Version:1 (current)
                                                  Machine:Advanced Micro Devices X86-64
                                                  Version Number:0x1
                                                  Type:DYN (Shared object file)
                                                  OS/ABI:UNIX - System V
                                                  ABI Version:0
                                                  Entry Point Address:0x1350
                                                  Flags:0x0
                                                  ELF Header Size:64
                                                  Program Header Offset:64
                                                  Program Header Size:56
                                                  Number of Program Headers:9
                                                  Section Header Offset:0
                                                  Section Header Size:64
                                                  Number of Section Headers:0
                                                  Header String Table Index:0
                                                  TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                  PHDR0x400x400x400x1f80x1f81.69220x4R 0x8
                                                  INTERP0x2380x2380x2380x1c0x1c3.94080x4R 0x1/lib64/ld-linux-x86-64.so.2
                                                  LOAD0x00x00x00x1c300x1c304.93840x5R E0x200000
                                                  LOAD0x1cb00x201cb00x201cb00x4270x4303.05410x6RW 0x200000
                                                  DYNAMIC0x1cc00x201cc00x201cc00x1f00x1f01.51950x6RW 0x8
                                                  NOTE0x2540x2540x2540x440x443.39670x4R 0x4
                                                  GNU_EH_FRAME0x19600x19600x19600x640x643.53820x4R 0x4
                                                  GNU_STACK0x00x00x00x00x00.00000x6RW 0x10
                                                  GNU_RELRO0x1cb00x201cb00x201cb00x3500x3501.71500x4R 0x1
                                                  TimestampSource PortDest PortSource IPDest IP
                                                  Jan 10, 2025 07:07:53.187808037 CET43928443192.168.2.2391.189.91.42
                                                  Jan 10, 2025 07:07:58.818989038 CET42836443192.168.2.2391.189.91.43
                                                  Jan 10, 2025 07:07:59.842819929 CET4251680192.168.2.23109.202.202.202
                                                  Jan 10, 2025 07:08:14.176805973 CET43928443192.168.2.2391.189.91.42
                                                  Jan 10, 2025 07:08:24.415363073 CET42836443192.168.2.2391.189.91.43
                                                  Jan 10, 2025 07:08:30.558481932 CET4251680192.168.2.23109.202.202.202
                                                  Jan 10, 2025 07:08:55.131006956 CET43928443192.168.2.2391.189.91.42
                                                  Jan 10, 2025 07:09:15.608093977 CET42836443192.168.2.2391.189.91.43

                                                  System Behavior

                                                  Start time (UTC):06:07:49
                                                  Start date (UTC):10/01/2025
                                                  Path:/usr/bin/dash
                                                  Arguments:-
                                                  File size:129816 bytes
                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                  Start time (UTC):06:07:49
                                                  Start date (UTC):10/01/2025
                                                  Path:/usr/bin/rm
                                                  Arguments:rm -f /tmp/tmp.61DXa86J11 /tmp/tmp.Z31iyKedgj /tmp/tmp.6ukCyQKaFl
                                                  File size:72056 bytes
                                                  MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                                  Start time (UTC):06:07:49
                                                  Start date (UTC):10/01/2025
                                                  Path:/usr/bin/dash
                                                  Arguments:-
                                                  File size:129816 bytes
                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                  Start time (UTC):06:07:49
                                                  Start date (UTC):10/01/2025
                                                  Path:/usr/bin/rm
                                                  Arguments:rm -f /tmp/tmp.61DXa86J11 /tmp/tmp.Z31iyKedgj /tmp/tmp.6ukCyQKaFl
                                                  File size:72056 bytes
                                                  MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                                  Start time (UTC):06:07:53
                                                  Start date (UTC):10/01/2025
                                                  Path:/tmp/ssa.elf
                                                  Arguments:/tmp/ssa.elf
                                                  File size:22295 bytes
                                                  MD5 hash:bfdb94bee37b0e7705691ce092aa9884

                                                  Start time (UTC):06:08:00
                                                  Start date (UTC):10/01/2025
                                                  Path:/tmp/ssa.elf
                                                  Arguments:-
                                                  File size:22295 bytes
                                                  MD5 hash:bfdb94bee37b0e7705691ce092aa9884

                                                  Start time (UTC):06:08:00
                                                  Start date (UTC):10/01/2025
                                                  Path:/tmp/filesZIILS
                                                  Arguments:/tmp/ssa.elf
                                                  File size:22295 bytes
                                                  MD5 hash:bfdb94bee37b0e7705691ce092aa9884

                                                  Start time (UTC):06:08:05
                                                  Start date (UTC):10/01/2025
                                                  Path:/tmp/filesZIILS
                                                  Arguments:-
                                                  File size:22295 bytes
                                                  MD5 hash:bfdb94bee37b0e7705691ce092aa9884

                                                  Start time (UTC):06:08:05
                                                  Start date (UTC):10/01/2025
                                                  Path:/tmp/fileqph2w9
                                                  Arguments:/tmp/ssa.elf
                                                  File size:22295 bytes
                                                  MD5 hash:bfdb94bee37b0e7705691ce092aa9884

                                                  Start time (UTC):06:08:11
                                                  Start date (UTC):10/01/2025
                                                  Path:/tmp/fileqph2w9
                                                  Arguments:-
                                                  File size:22295 bytes
                                                  MD5 hash:bfdb94bee37b0e7705691ce092aa9884

                                                  Start time (UTC):06:08:11
                                                  Start date (UTC):10/01/2025
                                                  Path:/tmp/file9xgtsA
                                                  Arguments:/tmp/ssa.elf
                                                  File size:22295 bytes
                                                  MD5 hash:bfdb94bee37b0e7705691ce092aa9884

                                                  Start time (UTC):06:08:17
                                                  Start date (UTC):10/01/2025
                                                  Path:/tmp/file9xgtsA
                                                  Arguments:-
                                                  File size:22295 bytes
                                                  MD5 hash:bfdb94bee37b0e7705691ce092aa9884

                                                  Start time (UTC):06:08:17
                                                  Start date (UTC):10/01/2025
                                                  Path:/tmp/fileFTsWOP
                                                  Arguments:/tmp/ssa.elf
                                                  File size:22295 bytes
                                                  MD5 hash:bfdb94bee37b0e7705691ce092aa9884

                                                  Start time (UTC):06:08:23
                                                  Start date (UTC):10/01/2025
                                                  Path:/tmp/fileFTsWOP
                                                  Arguments:-
                                                  File size:22295 bytes
                                                  MD5 hash:bfdb94bee37b0e7705691ce092aa9884

                                                  Start time (UTC):06:08:23
                                                  Start date (UTC):10/01/2025
                                                  Path:/tmp/fileY0Ofem
                                                  Arguments:/tmp/ssa.elf
                                                  File size:22295 bytes
                                                  MD5 hash:bfdb94bee37b0e7705691ce092aa9884

                                                  Start time (UTC):06:08:29
                                                  Start date (UTC):10/01/2025
                                                  Path:/tmp/fileY0Ofem
                                                  Arguments:-
                                                  File size:22295 bytes
                                                  MD5 hash:bfdb94bee37b0e7705691ce092aa9884

                                                  Start time (UTC):06:08:29
                                                  Start date (UTC):10/01/2025
                                                  Path:/tmp/filewZ3vJw
                                                  Arguments:/tmp/ssa.elf
                                                  File size:22295 bytes
                                                  MD5 hash:bfdb94bee37b0e7705691ce092aa9884

                                                  Start time (UTC):06:08:35
                                                  Start date (UTC):10/01/2025
                                                  Path:/tmp/filewZ3vJw
                                                  Arguments:-
                                                  File size:22295 bytes
                                                  MD5 hash:bfdb94bee37b0e7705691ce092aa9884

                                                  Start time (UTC):06:08:35
                                                  Start date (UTC):10/01/2025
                                                  Path:/tmp/file6dYPaN
                                                  Arguments:/tmp/ssa.elf
                                                  File size:22295 bytes
                                                  MD5 hash:bfdb94bee37b0e7705691ce092aa9884

                                                  Start time (UTC):06:08:40
                                                  Start date (UTC):10/01/2025
                                                  Path:/tmp/file6dYPaN
                                                  Arguments:-
                                                  File size:22295 bytes
                                                  MD5 hash:bfdb94bee37b0e7705691ce092aa9884

                                                  Start time (UTC):06:08:40
                                                  Start date (UTC):10/01/2025
                                                  Path:/tmp/file3voGS3
                                                  Arguments:/tmp/ssa.elf
                                                  File size:22295 bytes
                                                  MD5 hash:bfdb94bee37b0e7705691ce092aa9884

                                                  Start time (UTC):06:08:46
                                                  Start date (UTC):10/01/2025
                                                  Path:/tmp/file3voGS3
                                                  Arguments:-
                                                  File size:22295 bytes
                                                  MD5 hash:bfdb94bee37b0e7705691ce092aa9884

                                                  Start time (UTC):06:08:46
                                                  Start date (UTC):10/01/2025
                                                  Path:/tmp/filecLo1bv
                                                  Arguments:/tmp/ssa.elf
                                                  File size:22295 bytes
                                                  MD5 hash:bfdb94bee37b0e7705691ce092aa9884

                                                  Start time (UTC):06:08:51
                                                  Start date (UTC):10/01/2025
                                                  Path:/tmp/filecLo1bv
                                                  Arguments:-
                                                  File size:22295 bytes
                                                  MD5 hash:bfdb94bee37b0e7705691ce092aa9884

                                                  Start time (UTC):06:08:51
                                                  Start date (UTC):10/01/2025
                                                  Path:/tmp/filek7i3uP
                                                  Arguments:/tmp/ssa.elf
                                                  File size:22295 bytes
                                                  MD5 hash:bfdb94bee37b0e7705691ce092aa9884

                                                  Start time (UTC):06:08:57
                                                  Start date (UTC):10/01/2025
                                                  Path:/tmp/filek7i3uP
                                                  Arguments:-
                                                  File size:22295 bytes
                                                  MD5 hash:bfdb94bee37b0e7705691ce092aa9884

                                                  Start time (UTC):06:08:57
                                                  Start date (UTC):10/01/2025
                                                  Path:/tmp/fileFAvB93
                                                  Arguments:/tmp/ssa.elf
                                                  File size:22295 bytes
                                                  MD5 hash:bfdb94bee37b0e7705691ce092aa9884

                                                  Start time (UTC):06:09:03
                                                  Start date (UTC):10/01/2025
                                                  Path:/tmp/fileFAvB93
                                                  Arguments:-
                                                  File size:22295 bytes
                                                  MD5 hash:bfdb94bee37b0e7705691ce092aa9884

                                                  Start time (UTC):06:09:03
                                                  Start date (UTC):10/01/2025
                                                  Path:/tmp/fileAyj87h
                                                  Arguments:/tmp/ssa.elf
                                                  File size:22295 bytes
                                                  MD5 hash:bfdb94bee37b0e7705691ce092aa9884

                                                  Start time (UTC):06:09:08
                                                  Start date (UTC):10/01/2025
                                                  Path:/tmp/fileAyj87h
                                                  Arguments:-
                                                  File size:22295 bytes
                                                  MD5 hash:bfdb94bee37b0e7705691ce092aa9884

                                                  Start time (UTC):06:09:08
                                                  Start date (UTC):10/01/2025
                                                  Path:/tmp/filelpjDaB
                                                  Arguments:/tmp/ssa.elf
                                                  File size:22295 bytes
                                                  MD5 hash:bfdb94bee37b0e7705691ce092aa9884

                                                  Start time (UTC):06:09:14
                                                  Start date (UTC):10/01/2025
                                                  Path:/tmp/filelpjDaB
                                                  Arguments:-
                                                  File size:22295 bytes
                                                  MD5 hash:bfdb94bee37b0e7705691ce092aa9884

                                                  Start time (UTC):06:09:14
                                                  Start date (UTC):10/01/2025
                                                  Path:/tmp/fileiIcyzN
                                                  Arguments:/tmp/ssa.elf
                                                  File size:22295 bytes
                                                  MD5 hash:bfdb94bee37b0e7705691ce092aa9884

                                                  Start time (UTC):06:09:20
                                                  Start date (UTC):10/01/2025
                                                  Path:/tmp/fileiIcyzN
                                                  Arguments:-
                                                  File size:22295 bytes
                                                  MD5 hash:bfdb94bee37b0e7705691ce092aa9884

                                                  Start time (UTC):06:09:20
                                                  Start date (UTC):10/01/2025
                                                  Path:/tmp/file0exOS4
                                                  Arguments:/tmp/ssa.elf
                                                  File size:22295 bytes
                                                  MD5 hash:bfdb94bee37b0e7705691ce092aa9884

                                                  Start time (UTC):06:09:26
                                                  Start date (UTC):10/01/2025
                                                  Path:/tmp/file0exOS4
                                                  Arguments:-
                                                  File size:22295 bytes
                                                  MD5 hash:bfdb94bee37b0e7705691ce092aa9884

                                                  Start time (UTC):06:09:26
                                                  Start date (UTC):10/01/2025
                                                  Path:/tmp/fileVXRF8s
                                                  Arguments:/tmp/ssa.elf
                                                  File size:22295 bytes
                                                  MD5 hash:bfdb94bee37b0e7705691ce092aa9884

                                                  Start time (UTC):06:09:33
                                                  Start date (UTC):10/01/2025
                                                  Path:/tmp/fileVXRF8s
                                                  Arguments:-
                                                  File size:22295 bytes
                                                  MD5 hash:bfdb94bee37b0e7705691ce092aa9884

                                                  Start time (UTC):06:09:33
                                                  Start date (UTC):10/01/2025
                                                  Path:/tmp/filepfbdRG
                                                  Arguments:/tmp/ssa.elf
                                                  File size:22295 bytes
                                                  MD5 hash:bfdb94bee37b0e7705691ce092aa9884

                                                  Start time (UTC):06:09:38
                                                  Start date (UTC):10/01/2025
                                                  Path:/tmp/filepfbdRG
                                                  Arguments:-
                                                  File size:22295 bytes
                                                  MD5 hash:bfdb94bee37b0e7705691ce092aa9884

                                                  Start time (UTC):06:09:38
                                                  Start date (UTC):10/01/2025
                                                  Path:/tmp/fileFBsYn2
                                                  Arguments:/tmp/ssa.elf
                                                  File size:22295 bytes
                                                  MD5 hash:bfdb94bee37b0e7705691ce092aa9884

                                                  Start time (UTC):06:09:44
                                                  Start date (UTC):10/01/2025
                                                  Path:/tmp/fileFBsYn2
                                                  Arguments:-
                                                  File size:22295 bytes
                                                  MD5 hash:bfdb94bee37b0e7705691ce092aa9884

                                                  Start time (UTC):06:09:44
                                                  Start date (UTC):10/01/2025
                                                  Path:/tmp/fileYWlxCh
                                                  Arguments:/tmp/ssa.elf
                                                  File size:22295 bytes
                                                  MD5 hash:bfdb94bee37b0e7705691ce092aa9884

                                                  Start time (UTC):06:09:50
                                                  Start date (UTC):10/01/2025
                                                  Path:/tmp/fileYWlxCh
                                                  Arguments:-
                                                  File size:22295 bytes
                                                  MD5 hash:bfdb94bee37b0e7705691ce092aa9884

                                                  Start time (UTC):06:09:50
                                                  Start date (UTC):10/01/2025
                                                  Path:/tmp/fileT2tUzC
                                                  Arguments:/tmp/ssa.elf
                                                  File size:22295 bytes
                                                  MD5 hash:bfdb94bee37b0e7705691ce092aa9884

                                                  Start time (UTC):06:09:57
                                                  Start date (UTC):10/01/2025
                                                  Path:/tmp/fileT2tUzC
                                                  Arguments:-
                                                  File size:22295 bytes
                                                  MD5 hash:bfdb94bee37b0e7705691ce092aa9884

                                                  Start time (UTC):06:09:57
                                                  Start date (UTC):10/01/2025
                                                  Path:/tmp/file30mPH0
                                                  Arguments:/tmp/ssa.elf
                                                  File size:22295 bytes
                                                  MD5 hash:bfdb94bee37b0e7705691ce092aa9884

                                                  Start time (UTC):06:10:03
                                                  Start date (UTC):10/01/2025
                                                  Path:/tmp/file30mPH0
                                                  Arguments:-
                                                  File size:22295 bytes
                                                  MD5 hash:bfdb94bee37b0e7705691ce092aa9884

                                                  Start time (UTC):06:10:03
                                                  Start date (UTC):10/01/2025
                                                  Path:/tmp/filelqfWgf
                                                  Arguments:/tmp/ssa.elf
                                                  File size:22295 bytes
                                                  MD5 hash:bfdb94bee37b0e7705691ce092aa9884

                                                  Start time (UTC):06:10:08
                                                  Start date (UTC):10/01/2025
                                                  Path:/tmp/filelqfWgf
                                                  Arguments:-
                                                  File size:22295 bytes
                                                  MD5 hash:bfdb94bee37b0e7705691ce092aa9884

                                                  Start time (UTC):06:10:08
                                                  Start date (UTC):10/01/2025
                                                  Path:/tmp/fileg1aioy
                                                  Arguments:/tmp/ssa.elf
                                                  File size:22295 bytes
                                                  MD5 hash:bfdb94bee37b0e7705691ce092aa9884

                                                  Start time (UTC):06:10:16
                                                  Start date (UTC):10/01/2025
                                                  Path:/tmp/fileg1aioy
                                                  Arguments:-
                                                  File size:22295 bytes
                                                  MD5 hash:bfdb94bee37b0e7705691ce092aa9884

                                                  Start time (UTC):06:10:16
                                                  Start date (UTC):10/01/2025
                                                  Path:/tmp/fileLAS8lK
                                                  Arguments:/tmp/ssa.elf
                                                  File size:22295 bytes
                                                  MD5 hash:bfdb94bee37b0e7705691ce092aa9884

                                                  Start time (UTC):06:10:21
                                                  Start date (UTC):10/01/2025
                                                  Path:/tmp/fileLAS8lK
                                                  Arguments:-
                                                  File size:22295 bytes
                                                  MD5 hash:bfdb94bee37b0e7705691ce092aa9884

                                                  Start time (UTC):06:10:21
                                                  Start date (UTC):10/01/2025
                                                  Path:/tmp/filegFEB67
                                                  Arguments:/tmp/ssa.elf
                                                  File size:22295 bytes
                                                  MD5 hash:bfdb94bee37b0e7705691ce092aa9884

                                                  Start time (UTC):06:10:28
                                                  Start date (UTC):10/01/2025
                                                  Path:/tmp/filegFEB67
                                                  Arguments:-
                                                  File size:22295 bytes
                                                  MD5 hash:bfdb94bee37b0e7705691ce092aa9884

                                                  Start time (UTC):06:10:28
                                                  Start date (UTC):10/01/2025
                                                  Path:/tmp/fileR5OlIm
                                                  Arguments:/tmp/ssa.elf
                                                  File size:22295 bytes
                                                  MD5 hash:bfdb94bee37b0e7705691ce092aa9884

                                                  Start time (UTC):06:10:35
                                                  Start date (UTC):10/01/2025
                                                  Path:/tmp/fileR5OlIm
                                                  Arguments:-
                                                  File size:22295 bytes
                                                  MD5 hash:bfdb94bee37b0e7705691ce092aa9884

                                                  Start time (UTC):06:10:35
                                                  Start date (UTC):10/01/2025
                                                  Path:/tmp/fileqhyxmA
                                                  Arguments:/tmp/ssa.elf
                                                  File size:22295 bytes
                                                  MD5 hash:bfdb94bee37b0e7705691ce092aa9884

                                                  Start time (UTC):06:10:43
                                                  Start date (UTC):10/01/2025
                                                  Path:/tmp/fileqhyxmA
                                                  Arguments:-
                                                  File size:22295 bytes
                                                  MD5 hash:bfdb94bee37b0e7705691ce092aa9884

                                                  Start time (UTC):06:10:43
                                                  Start date (UTC):10/01/2025
                                                  Path:/tmp/fileyst50V
                                                  Arguments:/tmp/ssa.elf
                                                  File size:22295 bytes
                                                  MD5 hash:bfdb94bee37b0e7705691ce092aa9884

                                                  Start time (UTC):06:10:49
                                                  Start date (UTC):10/01/2025
                                                  Path:/tmp/fileyst50V
                                                  Arguments:-
                                                  File size:22295 bytes
                                                  MD5 hash:bfdb94bee37b0e7705691ce092aa9884

                                                  Start time (UTC):06:10:49
                                                  Start date (UTC):10/01/2025
                                                  Path:/tmp/filezmxBFz
                                                  Arguments:/tmp/ssa.elf
                                                  File size:22295 bytes
                                                  MD5 hash:bfdb94bee37b0e7705691ce092aa9884

                                                  Start time (UTC):06:10:55
                                                  Start date (UTC):10/01/2025
                                                  Path:/tmp/filezmxBFz
                                                  Arguments:-
                                                  File size:22295 bytes
                                                  MD5 hash:bfdb94bee37b0e7705691ce092aa9884

                                                  Start time (UTC):06:10:55
                                                  Start date (UTC):10/01/2025
                                                  Path:/tmp/fileQ6PloQ
                                                  Arguments:/tmp/ssa.elf
                                                  File size:22295 bytes
                                                  MD5 hash:bfdb94bee37b0e7705691ce092aa9884

                                                  Start time (UTC):06:11:01
                                                  Start date (UTC):10/01/2025
                                                  Path:/tmp/fileQ6PloQ
                                                  Arguments:-
                                                  File size:22295 bytes
                                                  MD5 hash:bfdb94bee37b0e7705691ce092aa9884

                                                  Start time (UTC):06:11:01
                                                  Start date (UTC):10/01/2025
                                                  Path:/tmp/fileWWcCKb
                                                  Arguments:/tmp/ssa.elf
                                                  File size:22295 bytes
                                                  MD5 hash:bfdb94bee37b0e7705691ce092aa9884

                                                  Start time (UTC):06:11:07
                                                  Start date (UTC):10/01/2025
                                                  Path:/tmp/fileWWcCKb
                                                  Arguments:-
                                                  File size:22295 bytes
                                                  MD5 hash:bfdb94bee37b0e7705691ce092aa9884

                                                  Start time (UTC):06:11:07
                                                  Start date (UTC):10/01/2025
                                                  Path:/tmp/file7pm3Gp
                                                  Arguments:/tmp/ssa.elf
                                                  File size:22295 bytes
                                                  MD5 hash:bfdb94bee37b0e7705691ce092aa9884

                                                  Start time (UTC):06:11:13
                                                  Start date (UTC):10/01/2025
                                                  Path:/tmp/file7pm3Gp
                                                  Arguments:-
                                                  File size:22295 bytes
                                                  MD5 hash:bfdb94bee37b0e7705691ce092aa9884

                                                  Start time (UTC):06:11:13
                                                  Start date (UTC):10/01/2025
                                                  Path:/tmp/filecprMtT
                                                  Arguments:/tmp/ssa.elf
                                                  File size:22295 bytes
                                                  MD5 hash:bfdb94bee37b0e7705691ce092aa9884

                                                  Start time (UTC):06:11:19
                                                  Start date (UTC):10/01/2025
                                                  Path:/tmp/filecprMtT
                                                  Arguments:-
                                                  File size:22295 bytes
                                                  MD5 hash:bfdb94bee37b0e7705691ce092aa9884

                                                  Start time (UTC):06:11:19
                                                  Start date (UTC):10/01/2025
                                                  Path:/tmp/filepbk33b
                                                  Arguments:/tmp/ssa.elf
                                                  File size:22295 bytes
                                                  MD5 hash:bfdb94bee37b0e7705691ce092aa9884

                                                  Start time (UTC):06:11:25
                                                  Start date (UTC):10/01/2025
                                                  Path:/tmp/filepbk33b
                                                  Arguments:-
                                                  File size:22295 bytes
                                                  MD5 hash:bfdb94bee37b0e7705691ce092aa9884

                                                  Start time (UTC):06:11:25
                                                  Start date (UTC):10/01/2025
                                                  Path:/tmp/filevSAJrq
                                                  Arguments:/tmp/ssa.elf
                                                  File size:22295 bytes
                                                  MD5 hash:bfdb94bee37b0e7705691ce092aa9884

                                                  Start time (UTC):06:11:31
                                                  Start date (UTC):10/01/2025
                                                  Path:/tmp/filevSAJrq
                                                  Arguments:-
                                                  File size:22295 bytes
                                                  MD5 hash:bfdb94bee37b0e7705691ce092aa9884

                                                  Start time (UTC):06:11:31
                                                  Start date (UTC):10/01/2025
                                                  Path:/tmp/file6MzccC
                                                  Arguments:/tmp/ssa.elf
                                                  File size:22295 bytes
                                                  MD5 hash:bfdb94bee37b0e7705691ce092aa9884

                                                  Start time (UTC):06:11:37
                                                  Start date (UTC):10/01/2025
                                                  Path:/tmp/file6MzccC
                                                  Arguments:-
                                                  File size:22295 bytes
                                                  MD5 hash:bfdb94bee37b0e7705691ce092aa9884

                                                  Start time (UTC):06:11:37
                                                  Start date (UTC):10/01/2025
                                                  Path:/tmp/filePxLHKY
                                                  Arguments:/tmp/ssa.elf
                                                  File size:22295 bytes
                                                  MD5 hash:bfdb94bee37b0e7705691ce092aa9884

                                                  Start time (UTC):06:11:43
                                                  Start date (UTC):10/01/2025
                                                  Path:/tmp/filePxLHKY
                                                  Arguments:-
                                                  File size:22295 bytes
                                                  MD5 hash:bfdb94bee37b0e7705691ce092aa9884

                                                  Start time (UTC):06:11:43
                                                  Start date (UTC):10/01/2025
                                                  Path:/tmp/filebJHN4h
                                                  Arguments:/tmp/ssa.elf
                                                  File size:22295 bytes
                                                  MD5 hash:bfdb94bee37b0e7705691ce092aa9884

                                                  Start time (UTC):06:11:49
                                                  Start date (UTC):10/01/2025
                                                  Path:/tmp/filebJHN4h
                                                  Arguments:-
                                                  File size:22295 bytes
                                                  MD5 hash:bfdb94bee37b0e7705691ce092aa9884

                                                  Start time (UTC):06:11:49
                                                  Start date (UTC):10/01/2025
                                                  Path:/tmp/fileJuQrAG
                                                  Arguments:/tmp/ssa.elf
                                                  File size:22295 bytes
                                                  MD5 hash:bfdb94bee37b0e7705691ce092aa9884

                                                  Start time (UTC):06:11:55
                                                  Start date (UTC):10/01/2025
                                                  Path:/tmp/fileJuQrAG
                                                  Arguments:-
                                                  File size:22295 bytes
                                                  MD5 hash:bfdb94bee37b0e7705691ce092aa9884

                                                  Start time (UTC):06:11:55
                                                  Start date (UTC):10/01/2025
                                                  Path:/tmp/fileCsunoX
                                                  Arguments:/tmp/ssa.elf
                                                  File size:22295 bytes
                                                  MD5 hash:bfdb94bee37b0e7705691ce092aa9884

                                                  Start time (UTC):06:12:03
                                                  Start date (UTC):10/01/2025
                                                  Path:/tmp/fileCsunoX
                                                  Arguments:-
                                                  File size:22295 bytes
                                                  MD5 hash:bfdb94bee37b0e7705691ce092aa9884

                                                  Start time (UTC):06:12:03
                                                  Start date (UTC):10/01/2025
                                                  Path:/tmp/file5qrfjk
                                                  Arguments:/tmp/ssa.elf
                                                  File size:22295 bytes
                                                  MD5 hash:bfdb94bee37b0e7705691ce092aa9884

                                                  Start time (UTC):06:12:09
                                                  Start date (UTC):10/01/2025
                                                  Path:/tmp/file5qrfjk
                                                  Arguments:-
                                                  File size:22295 bytes
                                                  MD5 hash:bfdb94bee37b0e7705691ce092aa9884

                                                  Start time (UTC):06:12:09
                                                  Start date (UTC):10/01/2025
                                                  Path:/tmp/fileO7mQVz
                                                  Arguments:/tmp/ssa.elf
                                                  File size:22295 bytes
                                                  MD5 hash:bfdb94bee37b0e7705691ce092aa9884