Linux
Analysis Report
xd.sh4.elf
Overview
General Information
Sample name: | xd.sh4.elf |
Analysis ID: | 1654967 |
MD5: | 36584cff9e8b6f567ccbec876174ed0e |
SHA1: | a1527c38535889a395d57101ce8e6731099ae9fa |
SHA256: | 4cba27a0b9f0fa526fad50047b72767853b55ad5bda6636469046486835bd9bc |
Tags: | elfuser-abuse_ch |
Infos: |
Detection
Score: | 100 |
Range: | 0 - 100 |
Signatures
Classification
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1654967 |
Start date and time: | 2025-04-02 20:47:24 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 59s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultlinuxfilecookbook.jbs |
Analysis system description: | Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11) |
Analysis Mode: | default |
Sample name: | xd.sh4.elf |
Detection: | MAL |
Classification: | mal100.spre.troj.evad.linELF@0/16@0/0 |
- Connection to analysis system has been lost, crash info: Unknown
- VT rate limit hit for: http://213.209.129.92/d/xd.arm7;chmod
- system is lnxubuntu20
- xd.sh4.elf New Fork (PID: 5417, Parent: 5414)
- xd.sh4.elf New Fork (PID: 5419, Parent: 5414)
- xd.sh4.elf New Fork (PID: 5421, Parent: 5414)
- xd.sh4.elf New Fork (PID: 5423, Parent: 5421)
- xd.sh4.elf New Fork (PID: 5425, Parent: 5421)
- xd.sh4.elf New Fork (PID: 5427, Parent: 5421)
- xd.sh4.elf New Fork (PID: 5430, Parent: 5421)
- systemd New Fork (PID: 5449, Parent: 1)
- systemd New Fork (PID: 5465, Parent: 1)
- systemd New Fork (PID: 5466, Parent: 1)
- systemd New Fork (PID: 5472, Parent: 1)
- systemd New Fork (PID: 5473, Parent: 1)
- systemd New Fork (PID: 5474, Parent: 1)
- systemd New Fork (PID: 5525, Parent: 1)
- systemd New Fork (PID: 5528, Parent: 1)
- systemd New Fork (PID: 5529, Parent: 1)
- systemd New Fork (PID: 5531, Parent: 1)
- systemd New Fork (PID: 5532, Parent: 1)
- systemd New Fork (PID: 5533, Parent: 1)
- systemd New Fork (PID: 5534, Parent: 2935)
- systemd New Fork (PID: 5535, Parent: 1)
- gdm3 New Fork (PID: 5536, Parent: 1400)
- gdm3 New Fork (PID: 5537, Parent: 1400)
- gdm3 New Fork (PID: 5538, Parent: 1400)
- systemd New Fork (PID: 5539, Parent: 1)
- systemd New Fork (PID: 5541, Parent: 1)
- systemd New Fork (PID: 5543, Parent: 1)
- systemd New Fork (PID: 5544, Parent: 1)
- gpu-manager New Fork (PID: 5545, Parent: 5544)
- sh New Fork (PID: 5546, Parent: 5545)
- gpu-manager New Fork (PID: 5547, Parent: 5544)
- sh New Fork (PID: 5548, Parent: 5547)
- gpu-manager New Fork (PID: 5549, Parent: 5544)
- sh New Fork (PID: 5550, Parent: 5549)
- gpu-manager New Fork (PID: 5551, Parent: 5544)
- sh New Fork (PID: 5552, Parent: 5551)
- gpu-manager New Fork (PID: 5553, Parent: 5544)
- sh New Fork (PID: 5554, Parent: 5553)
- gpu-manager New Fork (PID: 5555, Parent: 5544)
- sh New Fork (PID: 5556, Parent: 5555)
- gpu-manager New Fork (PID: 5557, Parent: 5544)
- sh New Fork (PID: 5558, Parent: 5557)
- gpu-manager New Fork (PID: 5559, Parent: 5544)
- sh New Fork (PID: 5560, Parent: 5559)
- systemd New Fork (PID: 5561, Parent: 1)
- generate-config New Fork (PID: 5562, Parent: 5561)
- systemd New Fork (PID: 5563, Parent: 1)
- systemd (deleted) New Fork (PID: 5564, Parent: 1)
- systemd (deleted) New Fork (PID: 5568, Parent: 1)
- systemd (deleted) New Fork (PID: 5577, Parent: 1)
- systemd (deleted) New Fork (PID: 5578, Parent: 1)
- systemd (deleted) New Fork (PID: 5579, Parent: 1)
- systemd (deleted) New Fork (PID: 5585, Parent: 1)
- gvfsd-fuse New Fork (PID: 5586, Parent: 3122)
- systemd (deleted) New Fork (PID: 5592, Parent: 2935)
- systemd (deleted) New Fork (PID: 5593, Parent: 2935)
- systemd (deleted) New Fork (PID: 5594, Parent: 2935)
- systemd (deleted) New Fork (PID: 5595, Parent: 2935)
- systemd (deleted) New Fork (PID: 5596, Parent: 1)
- gpu-manager New Fork (PID: 5598, Parent: 5596)
- gpu-manager New Fork (PID: 5599, Parent: 5596)
- gpu-manager New Fork (PID: 5600, Parent: 5596)
- gpu-manager New Fork (PID: 5601, Parent: 5596)
- gpu-manager New Fork (PID: 5602, Parent: 5596)
- gpu-manager New Fork (PID: 5603, Parent: 5596)
- gpu-manager New Fork (PID: 5604, Parent: 5596)
- gpu-manager New Fork (PID: 5605, Parent: 5596)
- systemd (deleted) New Fork (PID: 5597, Parent: 2935)
- systemd (deleted) New Fork (PID: 5606, Parent: 1)
- systemd (deleted) New Fork (PID: 5607, Parent: 1)
- gpu-manager New Fork (PID: 5608, Parent: 5607)
- gpu-manager New Fork (PID: 5609, Parent: 5607)
- gpu-manager New Fork (PID: 5610, Parent: 5607)
- gpu-manager New Fork (PID: 5611, Parent: 5607)
- gpu-manager New Fork (PID: 5612, Parent: 5607)
- gpu-manager New Fork (PID: 5613, Parent: 5607)
- gpu-manager New Fork (PID: 5614, Parent: 5607)
- gpu-manager New Fork (PID: 5615, Parent: 5607)
- systemd (deleted) New Fork (PID: 5616, Parent: 1)
- systemd (deleted) New Fork (PID: 5617, Parent: 1)
- gpu-manager New Fork (PID: 5618, Parent: 5617)
- gpu-manager New Fork (PID: 5619, Parent: 5617)
- gpu-manager New Fork (PID: 5620, Parent: 5617)
- gpu-manager New Fork (PID: 5621, Parent: 5617)
- gpu-manager New Fork (PID: 5622, Parent: 5617)
- gpu-manager New Fork (PID: 5623, Parent: 5617)
- gpu-manager New Fork (PID: 5624, Parent: 5617)
- gpu-manager New Fork (PID: 5625, Parent: 5617)
- systemd (deleted) New Fork (PID: 5626, Parent: 1)
- systemd (deleted) New Fork (PID: 5627, Parent: 1)
- gpu-manager New Fork (PID: 5628, Parent: 5627)
- gpu-manager New Fork (PID: 5629, Parent: 5627)
- gpu-manager New Fork (PID: 5630, Parent: 5627)
- gpu-manager New Fork (PID: 5631, Parent: 5627)
- gpu-manager New Fork (PID: 5632, Parent: 5627)
- gpu-manager New Fork (PID: 5633, Parent: 5627)
- gpu-manager New Fork (PID: 5634, Parent: 5627)
- gpu-manager New Fork (PID: 5635, Parent: 5627)
- systemd (deleted) New Fork (PID: 5636, Parent: 1)
- systemd (deleted) New Fork (PID: 5637, Parent: 1)
- gpu-manager New Fork (PID: 5638, Parent: 5637)
- gpu-manager New Fork (PID: 5639, Parent: 5637)
- gpu-manager New Fork (PID: 5640, Parent: 5637)
- gpu-manager New Fork (PID: 5641, Parent: 5637)
- gpu-manager New Fork (PID: 5642, Parent: 5637)
- gpu-manager New Fork (PID: 5643, Parent: 5637)
- gpu-manager New Fork (PID: 5644, Parent: 5637)
- gpu-manager New Fork (PID: 5645, Parent: 5637)
- systemd (deleted) New Fork (PID: 5646, Parent: 1)
- systemd (deleted) New Fork (PID: 5647, Parent: 1)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
Mirai | Mirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world. | No Attribution |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Mirai_9 | Yara detected Mirai | Joe Security | ||
JoeSecurity_Mirai_5 | Yara detected Mirai | Joe Security | ||
JoeSecurity_Mirai_8 | Yara detected Mirai | Joe Security | ||
Linux_Trojan_Gafgyt_28a2fe0c | unknown | unknown |
| |
Linux_Trojan_Gafgyt_ea92cca8 | unknown | unknown |
| |
Click to see the 2 entries |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Mirai_9 | Yara detected Mirai | Joe Security | ||
JoeSecurity_Mirai_5 | Yara detected Mirai | Joe Security | ||
JoeSecurity_Mirai_8 | Yara detected Mirai | Joe Security | ||
Linux_Trojan_Gafgyt_28a2fe0c | unknown | unknown |
| |
Linux_Trojan_Gafgyt_ea92cca8 | unknown | unknown |
| |
Click to see the 72 entries |
- • AV Detection
- • Bitcoin Miner
- • Networking
- • System Summary
- • Persistence and Installation Behavior
- • Hooking and other Techniques for Hiding and Protection
- • Malware Analysis System Evasion
- • Stealing of Sensitive Information
- • Remote Access Functionality
Click to jump to signature section
AV Detection |
---|
Source: | Avira: |
Source: | Virustotal: | Perma Link | ||
Source: | ReversingLabs: |
Source: | Reads CPU info from /sys: | Jump to behavior | ||
Source: | Reads CPU info from /sys: | Jump to behavior |
Source: | TCP traffic: |
Source: | Socket: | Jump to behavior | ||
Source: | Socket: | Jump to behavior | ||
Source: | Socket: | Jump to behavior | ||
Source: | Socket: | Jump to behavior | ||
Source: | Socket: | Jump to behavior | ||
Source: | Socket: | Jump to behavior |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | String found in binary or memory: |
System Summary |
---|
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior |
Source: | .symtab present: |
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior |
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Classification label: |
Persistence and Installation Behavior |
---|
Source: | File: | Jump to behavior |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Source: | Shell command executed: | Jump to behavior | ||
Source: | Shell command executed: | Jump to behavior | ||
Source: | Shell command executed: | Jump to behavior | ||
Source: | Shell command executed: | Jump to behavior | ||
Source: | Shell command executed: | Jump to behavior | ||
Source: | Shell command executed: | Jump to behavior | ||
Source: | Shell command executed: | Jump to behavior | ||
Source: | Shell command executed: | Jump to behavior |
Source: | Grep executable: | Jump to behavior | ||
Source: | Grep executable: | Jump to behavior | ||
Source: | Grep executable: | Jump to behavior | ||
Source: | Grep executable: | Jump to behavior | ||
Source: | Grep executable: | Jump to behavior | ||
Source: | Grep executable: | Jump to behavior | ||
Source: | Grep executable: | Jump to behavior | ||
Source: | Grep executable: | Jump to behavior |
Source: | Pkill executable: | Jump to behavior |
Source: | File: | Jump to behavior | ||
Source: | File: | Jump to behavior |
Source: | Log file created: | |||
Source: | Log file created: | |||
Source: | Log file created: | |||
Source: | Log file created: | |||
Source: | Log file created: | |||
Source: | Log file created: | Jump to dropped file |
Hooking and other Techniques for Hiding and Protection |
---|
Source: | File: | Jump to behavior | ||
Source: | File: | Jump to behavior | ||
Source: | File: | Jump to behavior | ||
Source: | File: | Jump to behavior |
Source: | Truncated file: | Jump to behavior | ||
Source: | Truncated file: | Jump to behavior | ||
Source: | Truncated file: | Jump to behavior | ||
Source: | Truncated file: | Jump to behavior | ||
Source: | Truncated file: | Jump to behavior | ||
Source: | Truncated file: | Jump to behavior |
Source: | Reads CPU info from /sys: | Jump to behavior | ||
Source: | Reads CPU info from /sys: | Jump to behavior |
Source: | Queries kernel information via 'uname': | Jump to behavior | ||
Source: | Queries kernel information via 'uname': | Jump to behavior | ||
Source: | Queries kernel information via 'uname': | Jump to behavior | ||
Source: | Queries kernel information via 'uname': | Jump to behavior | ||
Source: | Queries kernel information via 'uname': | Jump to behavior | ||
Source: | Queries kernel information via 'uname': | Jump to behavior | ||
Source: | Queries kernel information via 'uname': | Jump to behavior | ||
Source: | Queries kernel information via 'uname': | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Stealing of Sensitive Information |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Remote Access Functionality |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 1 Scripting | Valid Accounts | Windows Management Instrumentation | 1 Scripting | Path Interception | 1 File and Directory Permissions Modification | 1 OS Credential Dumping | 11 Security Software Discovery | Remote Services | Data from Local System | 1 Non-Standard Port | Exfiltration Over Other Network Medium | 1 Service Stop |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | 1 Disable or Modify Tools | LSASS Memory | 1 File and Directory Discovery | Remote Desktop Protocol | Data from Removable Media | Junk Data | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | 1 Indicator Removal | Security Account Manager | 1 System Information Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | Steganography | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | 1 File Deletion | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | Protocol Impersonation | Traffic Duplication | Data Destruction |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
63% | Virustotal | Browse | ||
64% | ReversingLabs | Linux.Trojan.Mirai | ||
100% | Avira | LINUX/Mirai.bonb |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
18.23.138.219 | unknown | United States | 3 | MIT-GATEWAYSUS | false | |
1.131.92.134 | unknown | Australia | 1221 | ASN-TELSTRATelstraCorporationLtdAU | false | |
9.140.25.126 | unknown | United States | 3356 | LEVEL3US | false | |
203.142.155.151 | unknown | Australia | 9443 | VOCUS-RETAIL-AUVocusRetailAU | false | |
76.36.89.203 | unknown | United States | 18494 | CENTURYLINK-LEGACY-EMBARQ-WRBGUS | false | |
71.117.0.55 | unknown | United States | 701 | UUNETUS | false | |
191.46.129.2 | unknown | Brazil | 7738 | TelemarNorteLesteSABR | false | |
35.224.125.126 | unknown | United States | 15169 | GOOGLEUS | false | |
211.212.76.94 | unknown | Korea Republic of | 9318 | SKB-ASSKBroadbandCoLtdKR | false | |
141.163.163.151 | unknown | United Kingdom | 786 | JANETJiscServicesLimitedGB | false | |
253.249.54.108 | unknown | Reserved | unknown | unknown | false | |
157.230.181.161 | unknown | United States | 14061 | DIGITALOCEAN-ASNUS | false | |
107.64.221.118 | unknown | United States | 7018 | ATT-INTERNET4US | false | |
148.127.109.169 | unknown | United States | 18819 | ENTERGY-CORP-US | false | |
223.51.198.111 | unknown | Korea Republic of | 9644 | SKTELECOM-NET-ASSKTelecomKR | false | |
193.185.140.67 | unknown | Finland | 719 | ELISA-ASHelsinkiFinlandEU | false | |
98.91.152.18 | unknown | United States | 11351 | TWC-11351-NORTHEASTUS | false | |
91.26.168.171 | unknown | Germany | 3320 | DTAGInternetserviceprovideroperationsDE | false | |
113.68.200.52 | unknown | China | 4134 | CHINANET-BACKBONENo31Jin-rongStreetCN | false | |
254.24.37.146 | unknown | Reserved | unknown | unknown | false | |
152.39.57.159 | unknown | United States | 81 | NCRENUS | false | |
248.78.199.92 | unknown | Reserved | unknown | unknown | false | |
222.108.206.164 | unknown | Korea Republic of | 4766 | KIXS-AS-KRKoreaTelecomKR | false | |
240.50.47.31 | unknown | Reserved | unknown | unknown | false | |
178.183.191.180 | unknown | Poland | 5588 | GTSCEGTSCentralEuropeAntelGermanyCZ | false | |
188.59.192.117 | unknown | Turkey | 16135 | TURKCELL-ASTurkcellASTR | false | |
103.238.148.44 | unknown | Malaysia | 45595 | PKTELECOM-AS-PKPakistanTelecomCompanyLimitedPK | false | |
203.207.159.169 | unknown | China | 17964 | DXTNETBeijingDian-Xin-TongNetworkTechnologiesCoLtd | false | |
206.95.116.52 | unknown | United States | 3549 | LVLT-3549US | false | |
123.64.13.116 | unknown | China | 9394 | CTTNETChinaTieTongTelecommunicationsCorporationCN | false | |
156.194.25.68 | unknown | Egypt | 8452 | TE-ASTE-ASEG | false | |
82.108.164.163 | unknown | United Kingdom | 4589 | EASYNETEasynetGlobalServicesEU | false | |
136.104.164.124 | unknown | United States | 60311 | ONEFMCH | false | |
128.4.151.94 | unknown | United States | 2 | UDEL-DCNUS | false | |
175.74.49.93 | unknown | China | 9394 | CTTNETChinaTieTongTelecommunicationsCorporationCN | false | |
84.245.129.125 | unknown | Germany | 20676 | PLUSNETDE | false | |
71.248.210.125 | unknown | United States | 701 | UUNETUS | false | |
90.242.7.190 | unknown | United Kingdom | 5378 | VodafoneGB | false | |
149.228.162.41 | unknown | Germany | 702 | UUNETUS | false | |
255.162.237.222 | unknown | Reserved | unknown | unknown | false | |
195.55.88.62 | unknown | Spain | 3352 | TELEFONICA_DE_ESPANAES | false | |
19.209.19.163 | unknown | United States | 3 | MIT-GATEWAYSUS | false | |
172.246.152.35 | unknown | United States | 18978 | ENZUINC-US | false | |
161.153.127.76 | unknown | United States | 9328 | DATACOM-AUDATACOMSYSTEMSAUPTYLTDAU | false | |
120.204.67.235 | unknown | China | 24400 | CMNET-V4SHANGHAI-AS-APShanghaiMobileCommunicationsCoLt | false | |
165.17.51.26 | unknown | unknown | 37284 | Aljeel-netLY | false | |
57.94.92.1 | unknown | Belgium | 51964 | ORANGE-BUSINESS-SERVICES-IPSN-ASNFR | false | |
199.55.214.174 | unknown | United States | 398192 | ARDOT-NET-01US | false | |
9.73.33.143 | unknown | United States | 3356 | LEVEL3US | false | |
152.177.102.169 | unknown | United States | 701 | UUNETUS | false | |
5.167.247.165 | unknown | Russian Federation | 51604 | EKAT-ASRU | false | |
219.78.245.146 | unknown | Hong Kong | 4760 | HKTIMS-APHKTLimitedHK | false | |
251.155.56.22 | unknown | Reserved | unknown | unknown | false | |
182.226.239.207 | unknown | Korea Republic of | 17858 | POWERVIS-AS-KRLGPOWERCOMMKR | false | |
19.196.15.45 | unknown | United States | 3 | MIT-GATEWAYSUS | false | |
211.68.251.108 | unknown | China | 4538 | ERX-CERNET-BKBChinaEducationandResearchNetworkCenter | false | |
217.172.131.73 | unknown | United Kingdom | 33854 | HOSTIT-AS-NNGB | false | |
5.124.236.196 | unknown | Iran (ISLAMIC Republic Of) | 44244 | IRANCELL-ASIR | false | |
105.85.237.206 | unknown | Egypt | 36992 | ETISALAT-MISREG | false | |
125.213.204.39 | unknown | Afghanistan | 17411 | IO-GLOBAL-APIoGlobalServicesPvtLimitedAF | false | |
162.1.112.64 | unknown | United States | 27353 | IUHEALTH-ASNUS | false | |
183.157.118.198 | unknown | China | 4134 | CHINANET-BACKBONENo31Jin-rongStreetCN | false | |
61.103.199.165 | unknown | Korea Republic of | 9457 | DREAMX-ASDREAMLINECOKR | false | |
86.126.217.138 | unknown | Romania | 8708 | RCS-RDS73-75DrStaicoviciRO | false | |
171.47.160.33 | unknown | China | 4134 | CHINANET-BACKBONENo31Jin-rongStreetCN | false | |
19.210.11.41 | unknown | United States | 3 | MIT-GATEWAYSUS | false | |
46.97.23.38 | unknown | Romania | 12302 | VODAFONE_ROCharlesdeGaullenr15RO | false | |
63.124.114.177 | unknown | United States | 701 | UUNETUS | false | |
174.37.177.44 | unknown | United States | 36351 | SOFTLAYERUS | false | |
116.212.11.48 | unknown | Korea Republic of | 45361 | JCN-AS-KRUlsanJung-AngBroadcastingNetworkKR | false | |
40.24.14.62 | unknown | United States | 4249 | LILLY-ASUS | false | |
173.93.73.222 | unknown | United States | 11426 | TWC-11426-CAROLINASUS | false | |
254.129.63.29 | unknown | Reserved | unknown | unknown | false | |
195.15.230.248 | unknown | Switzerland | 12350 | VTX-NETWORKCH | false | |
118.59.160.166 | unknown | Korea Republic of | 4766 | KIXS-AS-KRKoreaTelecomKR | false | |
79.176.182.81 | unknown | Israel | 8551 | BEZEQ-INTERNATIONAL-ASBezeqintInternetBackboneIL | false | |
105.132.203.33 | unknown | Morocco | 6713 | IAM-ASMA | false | |
213.209.129.92 | unknown | Germany | 42821 | RAPIDNET-DEHaunstetterStr19DE | false | |
19.57.167.43 | unknown | United States | 3 | MIT-GATEWAYSUS | false | |
9.7.255.81 | unknown | United States | 3356 | LEVEL3US | false | |
211.153.203.5 | unknown | China | 4847 | CNIX-APChinaNetworksInter-ExchangeCN | false | |
178.177.6.54 | unknown | Russian Federation | 25159 | SONICDUO-ASRU | false | |
98.134.53.71 | unknown | United States | 8473 | BAHNHOFhttpwwwbahnhofnetSE | false | |
44.233.241.155 | unknown | United States | 16509 | AMAZON-02US | false | |
188.179.236.76 | unknown | Denmark | 3292 | TDCTDCASDK | false | |
192.143.250.212 | unknown | South Africa | 37611 | AfrihostZA | false | |
107.226.200.178 | unknown | United States | 7018 | ATT-INTERNET4US | false | |
81.46.48.249 | unknown | Spain | 3352 | TELEFONICA_DE_ESPANAES | false | |
172.143.133.21 | unknown | United States | 7018 | ATT-INTERNET4US | false | |
40.96.18.177 | unknown | United States | 8075 | MICROSOFT-CORP-MSN-AS-BLOCKUS | false | |
189.36.212.25 | unknown | Brazil | 28296 | AcessaTelecomunicacoesLtdaBR | false | |
85.53.45.253 | unknown | Spain | 12479 | UNI2-ASES | false | |
70.182.246.7 | unknown | United States | 22773 | ASN-CXA-ALL-CCI-22773-RDCUS | false | |
208.198.22.217 | unknown | United States | 1699 | ANS-1699-ASUS | false | |
205.228.153.136 | unknown | United States | 5049 | MORGAN-ASNUS | false | |
135.6.73.133 | unknown | United States | 10455 | LUCENT-CIOUS | false | |
117.135.21.34 | unknown | China | 24400 | CMNET-V4SHANGHAI-AS-APShanghaiMobileCommunicationsCoLt | false | |
82.100.126.238 | unknown | Sweden | 13189 | LIDEROLideroNetworkSE | false | |
126.184.106.140 | unknown | Japan | 17676 | GIGAINFRASoftbankBBCorpJP | false | |
123.4.226.190 | unknown | China | 4837 | CHINA169-BACKBONECHINAUNICOMChina169BackboneCN | false |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
VOCUS-RETAIL-AUVocusRetailAU | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
MIT-GATEWAYSUS | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | HTMLPhisher, Invisible JS, Tycoon2FA | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | HTMLPhisher, Invisible JS, Tycoon2FA | Browse |
| ||
Get hash | malicious | HTMLPhisher, Invisible JS, Tycoon2FA | Browse |
| ||
Get hash | malicious | HTMLPhisher, Invisible JS, Tycoon2FA | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
ASN-TELSTRATelstraCorporationLtdAU | Get hash | malicious | Mirai | Browse |
| |
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
LEVEL3US | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
|
Process: | /usr/bin/pulseaudio |
File Type: | |
Category: | dropped |
Size (bytes): | 10 |
Entropy (8bit): | 2.9219280948873623 |
Encrypted: | false |
SSDEEP: | 3:5bkPn:pkP |
MD5: | FF001A15CE15CF062A3704CEA2991B5F |
SHA1: | B06F6855F376C3245B82212AC73ADED55DFE5DEF |
SHA-256: | C54830B41ECFA1B6FBDC30397188DDA86B7B200E62AEAC21AE694A6192DCC38A |
SHA-512: | 65EBF7C31F6F65713CE01B38A112E97D0AE64A6BD1DA40CE4C1B998F10CD3912EE1A48BB2B279B24493062118AAB3B8753742E2AF28E56A31A7AAB27DE80E7BF |
Malicious: | false |
Reputation: | moderate, very likely benign file |
Preview: |
Process: | /usr/bin/pulseaudio |
File Type: | |
Category: | dropped |
Size (bytes): | 18 |
Entropy (8bit): | 3.4613201402110088 |
Encrypted: | false |
SSDEEP: | 3:5bkrIZsXvn:pkckv |
MD5: | 28FE6435F34B3367707BB1C5D5F6B430 |
SHA1: | EB8FE2D16BD6BBCCE106C94E4D284543B2573CF6 |
SHA-256: | 721A37C69E555799B41D308849E8F8125441883AB021B723FED90A9B744F36C0 |
SHA-512: | 6B6AB7C0979629D0FEF6BE47C5C6BCC367EDD0AAE3FC973F4DE2FD5F0A819C89E7656DB65D453B1B5398E54012B27EDFE02894AD87A7E0AF3A9C5F2EB24A9919 |
Malicious: | false |
Reputation: | moderate, very likely benign file |
Preview: |
Process: | /usr/sbin/gdm3 |
File Type: | |
Category: | dropped |
Size (bytes): | 5 |
Entropy (8bit): | 1.9219280948873623 |
Encrypted: | false |
SSDEEP: | 3:FTJ:pJ |
MD5: | 4B9EDCD22341DC5841FE35D9AF9FBFCD |
SHA1: | B3D207B03F3BCBD22B804091508A87436CF78E75 |
SHA-256: | 052D7B13CA45AB68E519E638363A53C402216FD7B7197EBB5330F6B3CB095C9E |
SHA-512: | 8DC2C15DBD211BA7C43E735BF65ABD1E76BF3666BF748373AB039BCA44F415BA311DF163513B8B0ED948EBE67AF7FC28B9267905867725E1E474AC75A56D3631 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | /usr/bin/pulseaudio |
File Type: | |
Category: | dropped |
Size (bytes): | 5 |
Entropy (8bit): | 1.9219280948873623 |
Encrypted: | false |
SSDEEP: | 3:FWJ:a |
MD5: | 395BDAB1FC170F96F672C88702BECDEA |
SHA1: | 128FCC0C1B3F505A98B2C8AA132339F8876306CB |
SHA-256: | B44E28E841A10AACF47A89058990C3903E52A000316740F965F486EC6867CC84 |
SHA-512: | 5B80C2E6058C5BC393A3E3C1D52A55D0A49394BE530419872D3E7058000EDDBED05C297FEBD1AAA92AC35D5E16FE0E726EF672FB675419BE716221B31F6C58BF |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | /usr/bin/gpu-manager |
File Type: | |
Category: | dropped |
Size (bytes): | 25 |
Entropy (8bit): | 2.7550849518197795 |
Encrypted: | false |
SSDEEP: | 3:JoT/V9fDVbn:M/V3n |
MD5: | 078760523943E160756979906B85FB5E |
SHA1: | 0962643266F4C5537F7D125046F28F21D6DD0C89 |
SHA-256: | 048416AC7A9A99690B8B53718CD39F32F637B55CC8DD8E67E58E5AEF060DD41C |
SHA-512: | DEFAAE8F8B54C61A716A0B0B4884358FEB8EB44DFEA01AAA5A687FDA7182792B7DEBB34AA840672EB3B40EB59FD0186749E08E47D181786C7FAA8C8F73F0104D |
Malicious: | false |
Reputation: | moderate, very likely benign file |
Preview: |
Process: | /usr/bin/gpu-manager |
File Type: | |
Category: | dropped |
Size (bytes): | 1371 |
Entropy (8bit): | 4.8296848499188485 |
Encrypted: | false |
SSDEEP: | 24:wPXXX9uV6BNu3WDF3GF3XFFxFFed2uk2HUvJlfWkpPpx7uvvAdow9555cJz:wPXXXe6vejpeC2HUR5WkpPpcvAdow95O |
MD5: | 3AF77E630DA00B3BE24F4E8AA5D78B13 |
SHA1: | BCF2D99E002F6DE2413A183227B011CFBEF5673D |
SHA-256: | EB1CBBA20845237B4409274D693FEAE13F835274DA3337B7A9D14F4D7FDF9DEA |
SHA-512: | 8524B1E8A761F962B32F396812099B9B0B2DCF3C9FCA8605424753CFCFF4DC67EDC5EE1D8C91B9C0ED7FAE6BB1E752898B8D514B7C421D1839D6FEDA609C593C |
Malicious: | false |
Reputation: | moderate, very likely benign file |
Preview: |
File type: | |
Entropy (8bit): | 6.777625438824355 |
TrID: |
|
File name: | xd.sh4.elf |
File size: | 83'248 bytes |
MD5: | 36584cff9e8b6f567ccbec876174ed0e |
SHA1: | a1527c38535889a395d57101ce8e6731099ae9fa |
SHA256: | 4cba27a0b9f0fa526fad50047b72767853b55ad5bda6636469046486835bd9bc |
SHA512: | 4bdef0384a810ef1b821655949e51906105600433597bc8e545a0f1ed94d0c330c295b1172f609188f700619d88cd63abb36dc6656d289d14c843689ad8ed4c4 |
SSDEEP: | 1536:S/awroKM0wtC0BYvzL3GgSPGkXv9fs3IYuSyGKKOX+S0upFC69uxAdyQ:SCwnl0KP38GkVf+bw6OYupFoAsQ |
TLSH: | 3B83BE72D0A8AE68C682467475D8DD3A9F2391C412973EF6A6D0C76A6443EEDF404FF0 |
File Content Preview: | .ELF..............*.......@.4....C......4. ...(...............@...@..8...8...............@...@B..@B.`...t(..........Q.td............................././"O.n........#.*@........#.*@.....o&O.n...l..............................././.../.a"O.!...n...a.b("...q. |
ELF header | |
---|---|
Class: | |
Data: | |
Version: | |
Machine: | |
Version Number: | |
Type: | |
OS/ABI: | |
ABI Version: | 0 |
Entry Point Address: | |
Flags: | |
ELF Header Size: | 52 |
Program Header Offset: | 52 |
Program Header Size: | 32 |
Number of Program Headers: | 3 |
Section Header Offset: | 82848 |
Section Header Size: | 40 |
Number of Section Headers: | 10 |
Header String Table Index: | 9 |
Name | Type | Address | Offset | Size | EntSize | Flags | Flags Description | Link | Info | Align |
---|---|---|---|---|---|---|---|---|---|---|
NULL | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0 | 0 | 0 | ||
.init | PROGBITS | 0x400094 | 0x94 | 0x30 | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.text | PROGBITS | 0x4000e0 | 0xe0 | 0x111c0 | 0x0 | 0x6 | AX | 0 | 0 | 32 |
.fini | PROGBITS | 0x4112a0 | 0x112a0 | 0x24 | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.rodata | PROGBITS | 0x4112c4 | 0x112c4 | 0x2610 | 0x0 | 0x2 | A | 0 | 0 | 4 |
.ctors | PROGBITS | 0x424000 | 0x14000 | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.dtors | PROGBITS | 0x424008 | 0x14008 | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.data | PROGBITS | 0x424014 | 0x14014 | 0x34c | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.bss | NOBITS | 0x424360 | 0x14360 | 0x2514 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.shstrtab | STRTAB | 0x0 | 0x14360 | 0x3e | 0x0 | 0x0 | 0 | 0 | 1 |
Type | Offset | Virtual Address | Physical Address | File Size | Memory Size | Entropy | Flags | Flags Description | Align | Prog Interpreter | Section Mappings |
---|---|---|---|---|---|---|---|---|---|---|---|
LOAD | 0x0 | 0x400000 | 0x400000 | 0x138d4 | 0x138d4 | 6.9034 | 0x5 | R E | 0x10000 | .init .text .fini .rodata | |
LOAD | 0x14000 | 0x424000 | 0x424000 | 0x360 | 0x2874 | 2.6684 | 0x6 | RW | 0x10000 | .ctors .dtors .data .bss | |
GNU_STACK | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0.0000 | 0x7 | RWE | 0x4 |
Download Network PCAP: filtered – full
- Total Packets: 144
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Apr 2, 2025 20:48:13.469352007 CEST | 56002 | 5466 | 192.168.2.13 | 213.209.129.92 |
Apr 2, 2025 20:48:13.558988094 CEST | 37944 | 23 | 192.168.2.13 | 152.177.102.169 |
Apr 2, 2025 20:48:13.559037924 CEST | 37944 | 23 | 192.168.2.13 | 148.127.109.169 |
Apr 2, 2025 20:48:13.559083939 CEST | 37944 | 23 | 192.168.2.13 | 199.55.214.174 |
Apr 2, 2025 20:48:13.559102058 CEST | 37944 | 23 | 192.168.2.13 | 173.93.73.222 |
Apr 2, 2025 20:48:13.559112072 CEST | 37944 | 23 | 192.168.2.13 | 182.226.239.207 |
Apr 2, 2025 20:48:13.559124947 CEST | 37944 | 23 | 192.168.2.13 | 240.50.47.31 |
Apr 2, 2025 20:48:13.559137106 CEST | 37944 | 23 | 192.168.2.13 | 222.108.206.164 |
Apr 2, 2025 20:48:13.559174061 CEST | 37944 | 23 | 192.168.2.13 | 141.163.163.151 |
Apr 2, 2025 20:48:13.559174061 CEST | 37944 | 23 | 192.168.2.13 | 1.131.92.134 |
Apr 2, 2025 20:48:13.559180975 CEST | 37944 | 23 | 192.168.2.13 | 254.24.37.146 |
Apr 2, 2025 20:48:13.559257984 CEST | 37944 | 23 | 192.168.2.13 | 223.51.198.111 |
Apr 2, 2025 20:48:13.559258938 CEST | 37944 | 23 | 192.168.2.13 | 118.59.160.166 |
Apr 2, 2025 20:48:13.559261084 CEST | 37944 | 23 | 192.168.2.13 | 121.14.215.75 |
Apr 2, 2025 20:48:13.559437037 CEST | 37944 | 23 | 192.168.2.13 | 205.228.153.136 |
Apr 2, 2025 20:48:13.559446096 CEST | 37944 | 23 | 192.168.2.13 | 36.235.188.75 |
Apr 2, 2025 20:48:13.559446096 CEST | 37944 | 23 | 192.168.2.13 | 61.103.199.165 |
Apr 2, 2025 20:48:13.559459925 CEST | 37944 | 23 | 192.168.2.13 | 149.103.43.192 |
Apr 2, 2025 20:48:13.559482098 CEST | 37944 | 23 | 192.168.2.13 | 162.1.112.64 |
Apr 2, 2025 20:48:13.559485912 CEST | 37944 | 23 | 192.168.2.13 | 183.157.118.198 |
Apr 2, 2025 20:48:13.559504986 CEST | 37944 | 23 | 192.168.2.13 | 113.182.54.166 |
Apr 2, 2025 20:48:13.559572935 CEST | 37944 | 23 | 192.168.2.13 | 164.136.54.216 |
Apr 2, 2025 20:48:13.559590101 CEST | 37944 | 23 | 192.168.2.13 | 35.224.125.126 |
Apr 2, 2025 20:48:13.559628963 CEST | 37944 | 23 | 192.168.2.13 | 2.194.62.141 |
Apr 2, 2025 20:48:13.559632063 CEST | 37944 | 23 | 192.168.2.13 | 195.228.30.59 |
Apr 2, 2025 20:48:13.559632063 CEST | 37944 | 23 | 192.168.2.13 | 140.239.185.170 |
Apr 2, 2025 20:48:13.559634924 CEST | 37944 | 23 | 192.168.2.13 | 107.226.200.178 |
Apr 2, 2025 20:48:13.559637070 CEST | 37944 | 23 | 192.168.2.13 | 103.238.148.44 |
Apr 2, 2025 20:48:13.559645891 CEST | 37944 | 23 | 192.168.2.13 | 90.242.7.190 |
Apr 2, 2025 20:48:13.559663057 CEST | 37944 | 23 | 192.168.2.13 | 148.103.192.36 |
Apr 2, 2025 20:48:13.559669971 CEST | 37944 | 23 | 192.168.2.13 | 193.185.140.67 |
Apr 2, 2025 20:48:13.559734106 CEST | 37944 | 23 | 192.168.2.13 | 84.245.129.125 |
Apr 2, 2025 20:48:13.559736967 CEST | 37944 | 23 | 192.168.2.13 | 157.230.181.161 |
Apr 2, 2025 20:48:13.559740067 CEST | 37944 | 23 | 192.168.2.13 | 82.108.164.163 |
Apr 2, 2025 20:48:13.559751034 CEST | 37944 | 23 | 192.168.2.13 | 53.198.36.54 |
Apr 2, 2025 20:48:13.559760094 CEST | 37944 | 23 | 192.168.2.13 | 9.73.33.143 |
Apr 2, 2025 20:48:13.559834003 CEST | 37944 | 23 | 192.168.2.13 | 178.183.191.180 |
Apr 2, 2025 20:48:13.559834957 CEST | 37944 | 23 | 192.168.2.13 | 216.173.227.244 |
Apr 2, 2025 20:48:13.559858084 CEST | 37944 | 23 | 192.168.2.13 | 98.91.152.18 |
Apr 2, 2025 20:48:13.559875965 CEST | 37944 | 23 | 192.168.2.13 | 159.46.115.179 |
Apr 2, 2025 20:48:13.559876919 CEST | 37944 | 23 | 192.168.2.13 | 183.241.135.71 |
Apr 2, 2025 20:48:13.559899092 CEST | 37944 | 23 | 192.168.2.13 | 195.55.88.62 |
Apr 2, 2025 20:48:13.559936047 CEST | 37944 | 23 | 192.168.2.13 | 67.210.168.0 |
Apr 2, 2025 20:48:13.559936047 CEST | 37944 | 23 | 192.168.2.13 | 192.143.250.212 |
Apr 2, 2025 20:48:13.559964895 CEST | 37944 | 23 | 192.168.2.13 | 188.59.192.117 |
Apr 2, 2025 20:48:13.559964895 CEST | 37944 | 23 | 192.168.2.13 | 166.189.13.125 |
Apr 2, 2025 20:48:13.560015917 CEST | 37944 | 23 | 192.168.2.13 | 175.74.49.93 |
Apr 2, 2025 20:48:13.560024023 CEST | 37944 | 23 | 192.168.2.13 | 149.228.162.41 |
Apr 2, 2025 20:48:13.560035944 CEST | 37944 | 23 | 192.168.2.13 | 180.56.191.19 |
Apr 2, 2025 20:48:13.560066938 CEST | 37944 | 23 | 192.168.2.13 | 208.198.22.217 |
Apr 2, 2025 20:48:13.560080051 CEST | 37944 | 23 | 192.168.2.13 | 171.47.160.33 |
Apr 2, 2025 20:48:13.560096025 CEST | 37944 | 23 | 192.168.2.13 | 161.153.127.76 |
Apr 2, 2025 20:48:13.560117960 CEST | 37944 | 23 | 192.168.2.13 | 219.78.245.146 |
Apr 2, 2025 20:48:13.560136080 CEST | 37944 | 23 | 192.168.2.13 | 19.168.214.115 |
Apr 2, 2025 20:48:13.560165882 CEST | 37944 | 23 | 192.168.2.13 | 174.37.177.44 |
Apr 2, 2025 20:48:13.560193062 CEST | 37944 | 23 | 192.168.2.13 | 153.148.197.55 |
Apr 2, 2025 20:48:13.560194016 CEST | 37944 | 23 | 192.168.2.13 | 123.64.13.116 |
Apr 2, 2025 20:48:13.560209036 CEST | 37944 | 23 | 192.168.2.13 | 136.104.164.124 |
Apr 2, 2025 20:48:13.560209036 CEST | 37944 | 23 | 192.168.2.13 | 240.193.177.97 |
Apr 2, 2025 20:48:13.560234070 CEST | 37944 | 23 | 192.168.2.13 | 19.209.19.163 |
Apr 2, 2025 20:48:13.560235023 CEST | 37944 | 23 | 192.168.2.13 | 217.172.131.73 |
Apr 2, 2025 20:48:13.560236931 CEST | 37944 | 23 | 192.168.2.13 | 19.210.11.41 |
Apr 2, 2025 20:48:13.560250044 CEST | 37944 | 23 | 192.168.2.13 | 97.169.178.141 |
Apr 2, 2025 20:48:13.560265064 CEST | 37944 | 23 | 192.168.2.13 | 120.204.67.235 |
Apr 2, 2025 20:48:13.560277939 CEST | 37944 | 23 | 192.168.2.13 | 156.195.254.51 |
Apr 2, 2025 20:48:13.560295105 CEST | 37944 | 23 | 192.168.2.13 | 117.135.21.34 |
Apr 2, 2025 20:48:13.560295105 CEST | 37944 | 23 | 192.168.2.13 | 116.212.11.48 |
Apr 2, 2025 20:48:13.560301065 CEST | 37944 | 23 | 192.168.2.13 | 253.249.54.108 |
Apr 2, 2025 20:48:13.560303926 CEST | 37944 | 23 | 192.168.2.13 | 91.26.168.171 |
Apr 2, 2025 20:48:13.560303926 CEST | 37944 | 23 | 192.168.2.13 | 84.59.18.151 |
Apr 2, 2025 20:48:13.560333014 CEST | 37944 | 23 | 192.168.2.13 | 93.227.83.65 |
Apr 2, 2025 20:48:13.560340881 CEST | 37944 | 23 | 192.168.2.13 | 125.213.204.39 |
Apr 2, 2025 20:48:13.560353041 CEST | 37944 | 23 | 192.168.2.13 | 156.194.25.68 |
Apr 2, 2025 20:48:13.560379982 CEST | 37944 | 23 | 192.168.2.13 | 187.36.36.0 |
Apr 2, 2025 20:48:13.560400963 CEST | 37944 | 23 | 192.168.2.13 | 172.246.152.35 |
Apr 2, 2025 20:48:13.560442924 CEST | 37944 | 23 | 192.168.2.13 | 70.182.246.7 |
Apr 2, 2025 20:48:13.560442924 CEST | 37944 | 23 | 192.168.2.13 | 71.248.210.125 |
Apr 2, 2025 20:48:13.560447931 CEST | 37944 | 23 | 192.168.2.13 | 189.36.212.25 |
Apr 2, 2025 20:48:13.560447931 CEST | 37944 | 23 | 192.168.2.13 | 81.46.48.249 |
Apr 2, 2025 20:48:13.560451984 CEST | 37944 | 23 | 192.168.2.13 | 211.68.251.108 |
Apr 2, 2025 20:48:13.560451984 CEST | 37944 | 23 | 192.168.2.13 | 126.184.106.140 |
Apr 2, 2025 20:48:13.560487032 CEST | 37944 | 23 | 192.168.2.13 | 46.97.23.38 |
Apr 2, 2025 20:48:13.560487032 CEST | 37944 | 23 | 192.168.2.13 | 125.67.199.137 |
Apr 2, 2025 20:48:13.560518026 CEST | 37944 | 23 | 192.168.2.13 | 63.124.114.177 |
Apr 2, 2025 20:48:13.560518026 CEST | 37944 | 23 | 192.168.2.13 | 255.162.237.222 |
Apr 2, 2025 20:48:13.560535908 CEST | 37944 | 23 | 192.168.2.13 | 248.118.227.61 |
Apr 2, 2025 20:48:13.560538054 CEST | 37944 | 23 | 192.168.2.13 | 203.142.155.151 |
Apr 2, 2025 20:48:13.560559034 CEST | 37944 | 23 | 192.168.2.13 | 165.17.51.26 |
Apr 2, 2025 20:48:13.560574055 CEST | 37944 | 23 | 192.168.2.13 | 5.167.247.165 |
Apr 2, 2025 20:48:13.560574055 CEST | 37944 | 23 | 192.168.2.13 | 85.53.45.253 |
Apr 2, 2025 20:48:13.560585976 CEST | 37944 | 23 | 192.168.2.13 | 246.63.127.141 |
Apr 2, 2025 20:48:13.560606003 CEST | 37944 | 23 | 192.168.2.13 | 188.179.236.76 |
Apr 2, 2025 20:48:13.560619116 CEST | 37944 | 23 | 192.168.2.13 | 135.6.73.133 |
Apr 2, 2025 20:48:13.560633898 CEST | 37944 | 23 | 192.168.2.13 | 5.124.236.196 |
Apr 2, 2025 20:48:13.560643911 CEST | 37944 | 23 | 192.168.2.13 | 19.201.255.15 |
Apr 2, 2025 20:48:13.560672998 CEST | 37944 | 23 | 192.168.2.13 | 100.26.252.183 |
Apr 2, 2025 20:48:13.560683012 CEST | 37944 | 23 | 192.168.2.13 | 161.35.166.234 |
Apr 2, 2025 20:48:13.560694933 CEST | 37944 | 23 | 192.168.2.13 | 115.181.131.63 |
Apr 2, 2025 20:48:13.560745001 CEST | 37944 | 23 | 192.168.2.13 | 150.225.10.74 |
Apr 2, 2025 20:48:13.560749054 CEST | 37944 | 23 | 192.168.2.13 | 116.135.254.140 |
Apr 2, 2025 20:48:13.560759068 CEST | 37944 | 23 | 192.168.2.13 | 248.78.199.92 |
Apr 2, 2025 20:48:13.560786963 CEST | 37944 | 23 | 192.168.2.13 | 40.140.105.76 |
Apr 2, 2025 20:48:13.560792923 CEST | 37944 | 23 | 192.168.2.13 | 178.177.6.54 |
Apr 2, 2025 20:48:13.560794115 CEST | 37944 | 23 | 192.168.2.13 | 123.4.226.190 |
Apr 2, 2025 20:48:13.560801983 CEST | 37944 | 23 | 192.168.2.13 | 115.126.66.101 |
Apr 2, 2025 20:48:13.560826063 CEST | 37944 | 23 | 192.168.2.13 | 254.129.63.29 |
Apr 2, 2025 20:48:13.560826063 CEST | 37944 | 23 | 192.168.2.13 | 86.126.217.138 |
Apr 2, 2025 20:48:13.560827017 CEST | 37944 | 23 | 192.168.2.13 | 44.233.241.155 |
Apr 2, 2025 20:48:13.560827971 CEST | 37944 | 23 | 192.168.2.13 | 19.57.167.43 |
Apr 2, 2025 20:48:13.560832024 CEST | 37944 | 23 | 192.168.2.13 | 76.36.89.203 |
Apr 2, 2025 20:48:13.560832024 CEST | 37944 | 23 | 192.168.2.13 | 57.94.92.1 |
Apr 2, 2025 20:48:13.560867071 CEST | 37944 | 23 | 192.168.2.13 | 195.15.230.248 |
Apr 2, 2025 20:48:13.560867071 CEST | 37944 | 23 | 192.168.2.13 | 34.0.146.151 |
Apr 2, 2025 20:48:13.560888052 CEST | 37944 | 23 | 192.168.2.13 | 251.155.56.22 |
Apr 2, 2025 20:48:13.560900927 CEST | 37944 | 23 | 192.168.2.13 | 35.200.160.203 |
Apr 2, 2025 20:48:13.560900927 CEST | 37944 | 23 | 192.168.2.13 | 79.176.182.81 |
Apr 2, 2025 20:48:13.560900927 CEST | 37944 | 23 | 192.168.2.13 | 9.7.255.81 |
Apr 2, 2025 20:48:13.560909986 CEST | 37944 | 23 | 192.168.2.13 | 113.203.34.23 |
Apr 2, 2025 20:48:13.560909986 CEST | 37944 | 23 | 192.168.2.13 | 65.80.242.225 |
Apr 2, 2025 20:48:13.560920954 CEST | 37944 | 23 | 192.168.2.13 | 105.132.203.33 |
Apr 2, 2025 20:48:13.560935974 CEST | 37944 | 23 | 192.168.2.13 | 128.4.151.94 |
Apr 2, 2025 20:48:13.561013937 CEST | 37944 | 23 | 192.168.2.13 | 146.183.234.233 |
Apr 2, 2025 20:48:13.561054945 CEST | 37944 | 23 | 192.168.2.13 | 222.150.112.61 |
Apr 2, 2025 20:48:13.561055899 CEST | 37944 | 23 | 192.168.2.13 | 107.64.221.118 |
Apr 2, 2025 20:48:13.561057091 CEST | 37944 | 23 | 192.168.2.13 | 113.68.200.52 |
Apr 2, 2025 20:48:13.561067104 CEST | 37944 | 23 | 192.168.2.13 | 152.39.57.159 |
Apr 2, 2025 20:48:13.561080933 CEST | 37944 | 23 | 192.168.2.13 | 172.143.133.21 |
Apr 2, 2025 20:48:13.561101913 CEST | 37944 | 23 | 192.168.2.13 | 103.173.83.138 |
Apr 2, 2025 20:48:13.561148882 CEST | 37944 | 23 | 192.168.2.13 | 211.153.203.5 |
Apr 2, 2025 20:48:13.561186075 CEST | 37944 | 23 | 192.168.2.13 | 206.95.116.52 |
Apr 2, 2025 20:48:13.561189890 CEST | 37944 | 23 | 192.168.2.13 | 211.212.76.94 |
Apr 2, 2025 20:48:13.561202049 CEST | 37944 | 23 | 192.168.2.13 | 41.209.185.137 |
Apr 2, 2025 20:48:13.561204910 CEST | 37944 | 23 | 192.168.2.13 | 191.56.125.48 |
Apr 2, 2025 20:48:13.561214924 CEST | 37944 | 23 | 192.168.2.13 | 71.117.0.55 |
Apr 2, 2025 20:48:13.561223984 CEST | 37944 | 23 | 192.168.2.13 | 47.188.59.32 |
Apr 2, 2025 20:48:13.561242104 CEST | 37944 | 23 | 192.168.2.13 | 19.196.15.45 |
Apr 2, 2025 20:48:13.561245918 CEST | 37944 | 23 | 192.168.2.13 | 82.100.126.238 |
Apr 2, 2025 20:48:13.561259985 CEST | 37944 | 23 | 192.168.2.13 | 40.96.18.177 |
Apr 2, 2025 20:48:13.561273098 CEST | 37944 | 23 | 192.168.2.13 | 40.24.14.62 |
Apr 2, 2025 20:48:13.561275959 CEST | 37944 | 23 | 192.168.2.13 | 98.134.53.71 |
Apr 2, 2025 20:48:13.561285019 CEST | 37944 | 23 | 192.168.2.13 | 191.46.129.2 |
Apr 2, 2025 20:48:13.561288118 CEST | 37944 | 23 | 192.168.2.13 | 203.207.159.169 |
Apr 2, 2025 20:48:13.561292887 CEST | 37944 | 23 | 192.168.2.13 | 9.140.25.126 |
Apr 2, 2025 20:48:13.561292887 CEST | 37944 | 23 | 192.168.2.13 | 44.64.134.60 |
Apr 2, 2025 20:48:13.561295033 CEST | 37944 | 23 | 192.168.2.13 | 198.189.238.131 |
Apr 2, 2025 20:48:13.561295033 CEST | 37944 | 23 | 192.168.2.13 | 18.23.138.219 |
Apr 2, 2025 20:48:13.561307907 CEST | 37944 | 23 | 192.168.2.13 | 105.85.237.206 |
Apr 2, 2025 20:48:13.721949100 CEST | 5466 | 56002 | 213.209.129.92 | 192.168.2.13 |
Timestamp | Source IP | Dest IP | Checksum | Code | Type |
---|---|---|---|---|---|
Apr 2, 2025 20:48:13.797626972 CEST | 192.168.1.1 | 192.168.2.13 | a7c8 | (Time to live exceeded in transit) | Time Exceeded |
Apr 2, 2025 20:48:58.306484938 CEST | 192.168.2.13 | 192.168.2.1 | 8279 | (Port unreachable) | Destination Unreachable |
Apr 2, 2025 20:50:18.321701050 CEST | 192.168.2.13 | 192.168.2.1 | 8279 | (Port unreachable) | Destination Unreachable |
System Behavior
Start time (UTC): | 18:48:08 |
Start date (UTC): | 02/04/2025 |
Path: | /tmp/xd.sh4.elf |
Arguments: | /tmp/xd.sh4.elf |
File size: | 4139976 bytes |
MD5 hash: | 8943e5f8f8c280467b4472c15ae93ba9 |
Start time (UTC): | 18:48:08 |
Start date (UTC): | 02/04/2025 |
Path: | /tmp/xd.sh4.elf |
Arguments: | - |
File size: | 4139976 bytes |
MD5 hash: | 8943e5f8f8c280467b4472c15ae93ba9 |
Start time (UTC): | 18:48:09 |
Start date (UTC): | 02/04/2025 |
Path: | /tmp/xd.sh4.elf |
Arguments: | - |
File size: | 4139976 bytes |
MD5 hash: | 8943e5f8f8c280467b4472c15ae93ba9 |
Start time (UTC): | 18:48:09 |
Start date (UTC): | 02/04/2025 |
Path: | /tmp/xd.sh4.elf |
Arguments: | - |
File size: | 4139976 bytes |
MD5 hash: | 8943e5f8f8c280467b4472c15ae93ba9 |
Start time (UTC): | 18:48:09 |
Start date (UTC): | 02/04/2025 |
Path: | /tmp/xd.sh4.elf |
Arguments: | - |
File size: | 4139976 bytes |
MD5 hash: | 8943e5f8f8c280467b4472c15ae93ba9 |
Start time (UTC): | 18:48:12 |
Start date (UTC): | 02/04/2025 |
Path: | /tmp/xd.sh4.elf |
Arguments: | - |
File size: | 4139976 bytes |
MD5 hash: | 8943e5f8f8c280467b4472c15ae93ba9 |
Start time (UTC): | 18:48:12 |
Start date (UTC): | 02/04/2025 |
Path: | /tmp/xd.sh4.elf |
Arguments: | - |
File size: | 4139976 bytes |
MD5 hash: | 8943e5f8f8c280467b4472c15ae93ba9 |
Start time (UTC): | 18:48:12 |
Start date (UTC): | 02/04/2025 |
Path: | /tmp/xd.sh4.elf |
Arguments: | - |
File size: | 4139976 bytes |
MD5 hash: | 8943e5f8f8c280467b4472c15ae93ba9 |
Start time (UTC): | 18:48:23 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/lib/systemd/systemd |
Arguments: | - |
File size: | 1620224 bytes |
MD5 hash: | 9b2bec7092a40488108543f9334aab75 |
Start time (UTC): | 18:48:23 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/bin/journalctl |
Arguments: | /usr/bin/journalctl --smart-relinquish-var |
File size: | 80120 bytes |
MD5 hash: | bf3a987344f3bacafc44efd882abda8b |
Start time (UTC): | 18:48:23 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/lib/systemd/systemd |
Arguments: | - |
File size: | 1620224 bytes |
MD5 hash: | 9b2bec7092a40488108543f9334aab75 |
Start time (UTC): | 18:48:23 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/lib/systemd/systemd |
Arguments: | - |
File size: | 1620224 bytes |
MD5 hash: | 9b2bec7092a40488108543f9334aab75 |
Start time (UTC): | 18:48:23 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/lib/systemd/systemd |
Arguments: | - |
File size: | 1620224 bytes |
MD5 hash: | 9b2bec7092a40488108543f9334aab75 |
Start time (UTC): | 18:48:23 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/lib/systemd/systemd |
Arguments: | - |
File size: | 1620224 bytes |
MD5 hash: | 9b2bec7092a40488108543f9334aab75 |
Start time (UTC): | 18:48:23 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/lib/systemd/systemd |
Arguments: | - |
File size: | 1620224 bytes |
MD5 hash: | 9b2bec7092a40488108543f9334aab75 |
Start time (UTC): | 18:48:37 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/lib/systemd/systemd |
Arguments: | - |
File size: | 1620224 bytes |
MD5 hash: | 9b2bec7092a40488108543f9334aab75 |
Start time (UTC): | 18:48:37 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/lib/systemd/systemd |
Arguments: | - |
File size: | 1620224 bytes |
MD5 hash: | 9b2bec7092a40488108543f9334aab75 |
Start time (UTC): | 18:48:37 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/lib/systemd/systemd |
Arguments: | - |
File size: | 1620224 bytes |
MD5 hash: | 9b2bec7092a40488108543f9334aab75 |
Start time (UTC): | 18:48:37 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/lib/systemd/systemd |
Arguments: | - |
File size: | 1620224 bytes |
MD5 hash: | 9b2bec7092a40488108543f9334aab75 |
Start time (UTC): | 18:48:37 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/lib/systemd/systemd |
Arguments: | - |
File size: | 1620224 bytes |
MD5 hash: | 9b2bec7092a40488108543f9334aab75 |
Start time (UTC): | 18:48:37 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/lib/systemd/systemd |
Arguments: | - |
File size: | 1620224 bytes |
MD5 hash: | 9b2bec7092a40488108543f9334aab75 |
Start time (UTC): | 18:48:37 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/lib/systemd/systemd |
Arguments: | - |
File size: | 1620224 bytes |
MD5 hash: | 9b2bec7092a40488108543f9334aab75 |
Start time (UTC): | 18:48:37 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/bin/pulseaudio |
Arguments: | /usr/bin/pulseaudio --daemonize=no --log-target=journal |
File size: | 100832 bytes |
MD5 hash: | 0c3b4c789d8ffb12b25507f27e14c186 |
Start time (UTC): | 18:48:37 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/lib/systemd/systemd |
Arguments: | - |
File size: | 1620224 bytes |
MD5 hash: | 9b2bec7092a40488108543f9334aab75 |
Start time (UTC): | 18:48:37 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/sbin/gdm3 |
Arguments: | - |
File size: | 453296 bytes |
MD5 hash: | 2492e2d8d34f9377e3e530a61a15674f |
Start time (UTC): | 18:48:37 |
Start date (UTC): | 02/04/2025 |
Path: | /etc/gdm3/PrimeOff/Default |
Arguments: | /etc/gdm3/PrimeOff/Default |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 18:48:37 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/sbin/gdm3 |
Arguments: | - |
File size: | 453296 bytes |
MD5 hash: | 2492e2d8d34f9377e3e530a61a15674f |
Start time (UTC): | 18:48:37 |
Start date (UTC): | 02/04/2025 |
Path: | /etc/gdm3/PrimeOff/Default |
Arguments: | /etc/gdm3/PrimeOff/Default |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 18:48:37 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/sbin/gdm3 |
Arguments: | - |
File size: | 453296 bytes |
MD5 hash: | 2492e2d8d34f9377e3e530a61a15674f |
Start time (UTC): | 18:48:37 |
Start date (UTC): | 02/04/2025 |
Path: | /etc/gdm3/PrimeOff/Default |
Arguments: | /etc/gdm3/PrimeOff/Default |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 18:48:38 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/lib/systemd/systemd |
Arguments: | - |
File size: | 1620224 bytes |
MD5 hash: | 9b2bec7092a40488108543f9334aab75 |
Start time (UTC): | 18:48:38 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/lib/systemd/systemd |
Arguments: | - |
File size: | 1620224 bytes |
MD5 hash: | 9b2bec7092a40488108543f9334aab75 |
Start time (UTC): | 18:48:38 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/lib/systemd/systemd |
Arguments: | - |
File size: | 1620224 bytes |
MD5 hash: | 9b2bec7092a40488108543f9334aab75 |
Start time (UTC): | 18:48:39 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/lib/systemd/systemd |
Arguments: | - |
File size: | 1620224 bytes |
MD5 hash: | 9b2bec7092a40488108543f9334aab75 |
Start time (UTC): | 18:48:39 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/bin/gpu-manager |
Arguments: | /usr/bin/gpu-manager --log /var/log/gpu-manager.log |
File size: | 76616 bytes |
MD5 hash: | 8fae9dd5dd67e1f33d873089c2fd8761 |
Start time (UTC): | 18:48:39 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/bin/gpu-manager |
Arguments: | - |
File size: | 76616 bytes |
MD5 hash: | 8fae9dd5dd67e1f33d873089c2fd8761 |
Start time (UTC): | 18:48:39 |
Start date (UTC): | 02/04/2025 |
Path: | /bin/sh |
Arguments: | sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /etc/modprobe.d/*.conf" |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 18:48:39 |
Start date (UTC): | 02/04/2025 |
Path: | /bin/sh |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 18:48:39 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/bin/grep |
Arguments: | grep -G ^blacklist.*nvidia[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf |
File size: | 199136 bytes |
MD5 hash: | 1e6ebb9dd094f774478f72727bdba0f5 |
Start time (UTC): | 18:48:39 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/bin/gpu-manager |
Arguments: | - |
File size: | 76616 bytes |
MD5 hash: | 8fae9dd5dd67e1f33d873089c2fd8761 |
Start time (UTC): | 18:48:39 |
Start date (UTC): | 02/04/2025 |
Path: | /bin/sh |
Arguments: | sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /lib/modprobe.d/*.conf" |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 18:48:39 |
Start date (UTC): | 02/04/2025 |
Path: | /bin/sh |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 18:48:39 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/bin/grep |
Arguments: | grep -G ^blacklist.*nvidia[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf |
File size: | 199136 bytes |
MD5 hash: | 1e6ebb9dd094f774478f72727bdba0f5 |
Start time (UTC): | 18:48:39 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/bin/gpu-manager |
Arguments: | - |
File size: | 76616 bytes |
MD5 hash: | 8fae9dd5dd67e1f33d873089c2fd8761 |
Start time (UTC): | 18:48:39 |
Start date (UTC): | 02/04/2025 |
Path: | /bin/sh |
Arguments: | sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /etc/modprobe.d/*.conf" |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 18:48:39 |
Start date (UTC): | 02/04/2025 |
Path: | /bin/sh |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 18:48:39 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/bin/grep |
Arguments: | grep -G ^blacklist.*radeon[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf |
File size: | 199136 bytes |
MD5 hash: | 1e6ebb9dd094f774478f72727bdba0f5 |
Start time (UTC): | 18:48:39 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/bin/gpu-manager |
Arguments: | - |
File size: | 76616 bytes |
MD5 hash: | 8fae9dd5dd67e1f33d873089c2fd8761 |
Start time (UTC): | 18:48:39 |
Start date (UTC): | 02/04/2025 |
Path: | /bin/sh |
Arguments: | sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /lib/modprobe.d/*.conf" |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 18:48:39 |
Start date (UTC): | 02/04/2025 |
Path: | /bin/sh |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 18:48:39 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/bin/grep |
Arguments: | grep -G ^blacklist.*radeon[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf |
File size: | 199136 bytes |
MD5 hash: | 1e6ebb9dd094f774478f72727bdba0f5 |
Start time (UTC): | 18:48:39 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/bin/gpu-manager |
Arguments: | - |
File size: | 76616 bytes |
MD5 hash: | 8fae9dd5dd67e1f33d873089c2fd8761 |
Start time (UTC): | 18:48:39 |
Start date (UTC): | 02/04/2025 |
Path: | /bin/sh |
Arguments: | sh -c "grep -G \"^blacklist.*amdgpu[[:space:]]*$\" /etc/modprobe.d/*.conf" |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 18:48:39 |
Start date (UTC): | 02/04/2025 |
Path: | /bin/sh |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 18:48:39 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/bin/grep |
Arguments: | grep -G ^blacklist.*amdgpu[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf |
File size: | 199136 bytes |
MD5 hash: | 1e6ebb9dd094f774478f72727bdba0f5 |
Start time (UTC): | 18:48:39 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/bin/gpu-manager |
Arguments: | - |
File size: | 76616 bytes |
MD5 hash: | 8fae9dd5dd67e1f33d873089c2fd8761 |
Start time (UTC): | 18:48:39 |
Start date (UTC): | 02/04/2025 |
Path: | /bin/sh |
Arguments: | sh -c "grep -G \"^blacklist.*amdgpu[[:space:]]*$\" /lib/modprobe.d/*.conf" |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 18:48:39 |
Start date (UTC): | 02/04/2025 |
Path: | /bin/sh |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 18:48:39 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/bin/grep |
Arguments: | grep -G ^blacklist.*amdgpu[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf |
File size: | 199136 bytes |
MD5 hash: | 1e6ebb9dd094f774478f72727bdba0f5 |
Start time (UTC): | 18:48:39 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/bin/gpu-manager |
Arguments: | - |
File size: | 76616 bytes |
MD5 hash: | 8fae9dd5dd67e1f33d873089c2fd8761 |
Start time (UTC): | 18:48:39 |
Start date (UTC): | 02/04/2025 |
Path: | /bin/sh |
Arguments: | sh -c "grep -G \"^blacklist.*nouveau[[:space:]]*$\" /etc/modprobe.d/*.conf" |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 18:48:39 |
Start date (UTC): | 02/04/2025 |
Path: | /bin/sh |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 18:48:39 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/bin/grep |
Arguments: | grep -G ^blacklist.*nouveau[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf |
File size: | 199136 bytes |
MD5 hash: | 1e6ebb9dd094f774478f72727bdba0f5 |
Start time (UTC): | 18:48:39 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/bin/gpu-manager |
Arguments: | - |
File size: | 76616 bytes |
MD5 hash: | 8fae9dd5dd67e1f33d873089c2fd8761 |
Start time (UTC): | 18:48:39 |
Start date (UTC): | 02/04/2025 |
Path: | /bin/sh |
Arguments: | sh -c "grep -G \"^blacklist.*nouveau[[:space:]]*$\" /lib/modprobe.d/*.conf" |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 18:48:40 |
Start date (UTC): | 02/04/2025 |
Path: | /bin/sh |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 18:48:40 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/bin/grep |
Arguments: | grep -G ^blacklist.*nouveau[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf |
File size: | 199136 bytes |
MD5 hash: | 1e6ebb9dd094f774478f72727bdba0f5 |
Start time (UTC): | 18:48:40 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/lib/systemd/systemd |
Arguments: | - |
File size: | 1620224 bytes |
MD5 hash: | 9b2bec7092a40488108543f9334aab75 |
Start time (UTC): | 18:48:40 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/share/gdm/generate-config |
Arguments: | /usr/share/gdm/generate-config |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 18:48:40 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/share/gdm/generate-config |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 18:48:40 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/bin/pkill |
Arguments: | pkill --signal HUP --uid gdm dconf-service |
File size: | 30968 bytes |
MD5 hash: | fa96a75a08109d8842e4865b2907d51f |
Start time (UTC): | 18:48:41 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/lib/systemd/systemd |
Arguments: | - |
File size: | 1620224 bytes |
MD5 hash: | 9b2bec7092a40488108543f9334aab75 |
Start time (UTC): | 18:48:41 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/lib/gdm3/gdm-wait-for-drm |
Arguments: | /usr/lib/gdm3/gdm-wait-for-drm |
File size: | 14640 bytes |
MD5 hash: | 82043ba752c6930b4e6aaea2f7747545 |
Start time (UTC): | 18:48:52 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/lib/systemd/systemd (deleted) |
Arguments: | - |
File size: | 1620224 bytes |
MD5 hash: | 9b2bec7092a40488108543f9334aab75 |
Start time (UTC): | 18:48:52 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/sbin/gdm3 |
Arguments: | /usr/sbin/gdm3 |
File size: | 453296 bytes |
MD5 hash: | 2492e2d8d34f9377e3e530a61a15674f |
Start time (UTC): | 18:48:52 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/lib/systemd/systemd (deleted) |
Arguments: | - |
File size: | 1620224 bytes |
MD5 hash: | 9b2bec7092a40488108543f9334aab75 |
Start time (UTC): | 18:48:52 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/lib/systemd/systemd (deleted) |
Arguments: | - |
File size: | 1620224 bytes |
MD5 hash: | 9b2bec7092a40488108543f9334aab75 |
Start time (UTC): | 18:48:52 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/lib/systemd/systemd (deleted) |
Arguments: | - |
File size: | 1620224 bytes |
MD5 hash: | 9b2bec7092a40488108543f9334aab75 |
Start time (UTC): | 18:48:52 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/lib/systemd/systemd (deleted) |
Arguments: | - |
File size: | 1620224 bytes |
MD5 hash: | 9b2bec7092a40488108543f9334aab75 |
Start time (UTC): | 18:48:52 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/lib/systemd/systemd (deleted) |
Arguments: | - |
File size: | 1620224 bytes |
MD5 hash: | 9b2bec7092a40488108543f9334aab75 |
Start time (UTC): | 18:49:12 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/libexec/gvfsd-fuse |
Arguments: | - |
File size: | 47632 bytes |
MD5 hash: | d18fbf1cbf8eb57b17fac48b7b4be933 |
Start time (UTC): | 18:49:12 |
Start date (UTC): | 02/04/2025 |
Path: | /bin/fusermount |
Arguments: | fusermount -u -q -z -- /run/user/1000/gvfs |
File size: | 39144 bytes |
MD5 hash: | 576a1b135c82bdcbc97a91acea900566 |
Start time (UTC): | 18:49:36 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/lib/systemd/systemd (deleted) |
Arguments: | - |
File size: | 1620224 bytes |
MD5 hash: | 9b2bec7092a40488108543f9334aab75 |
Start time (UTC): | 18:49:37 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/lib/systemd/systemd (deleted) |
Arguments: | - |
File size: | 1620224 bytes |
MD5 hash: | 9b2bec7092a40488108543f9334aab75 |
Start time (UTC): | 18:49:37 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/lib/systemd/systemd (deleted) |
Arguments: | - |
File size: | 1620224 bytes |
MD5 hash: | 9b2bec7092a40488108543f9334aab75 |
Start time (UTC): | 18:49:37 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/lib/systemd/systemd (deleted) |
Arguments: | - |
File size: | 1620224 bytes |
MD5 hash: | 9b2bec7092a40488108543f9334aab75 |
Start time (UTC): | 18:49:37 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/lib/systemd/systemd (deleted) |
Arguments: | - |
File size: | 1620224 bytes |
MD5 hash: | 9b2bec7092a40488108543f9334aab75 |
Start time (UTC): | 18:49:37 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/bin/gpu-manager |
Arguments: | /usr/bin/gpu-manager --log /var/log/gpu-manager.log |
File size: | 76616 bytes |
MD5 hash: | 8fae9dd5dd67e1f33d873089c2fd8761 |
Start time (UTC): | 18:49:37 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/bin/gpu-manager |
Arguments: | - |
File size: | 76616 bytes |
MD5 hash: | 8fae9dd5dd67e1f33d873089c2fd8761 |
Start time (UTC): | 18:49:37 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/bin/gpu-manager |
Arguments: | - |
File size: | 76616 bytes |
MD5 hash: | 8fae9dd5dd67e1f33d873089c2fd8761 |
Start time (UTC): | 18:49:37 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/bin/gpu-manager |
Arguments: | - |
File size: | 76616 bytes |
MD5 hash: | 8fae9dd5dd67e1f33d873089c2fd8761 |
Start time (UTC): | 18:49:37 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/bin/gpu-manager |
Arguments: | - |
File size: | 76616 bytes |
MD5 hash: | 8fae9dd5dd67e1f33d873089c2fd8761 |
Start time (UTC): | 18:49:37 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/bin/gpu-manager |
Arguments: | - |
File size: | 76616 bytes |
MD5 hash: | 8fae9dd5dd67e1f33d873089c2fd8761 |
Start time (UTC): | 18:49:37 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/bin/gpu-manager |
Arguments: | - |
File size: | 76616 bytes |
MD5 hash: | 8fae9dd5dd67e1f33d873089c2fd8761 |
Start time (UTC): | 18:49:37 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/bin/gpu-manager |
Arguments: | - |
File size: | 76616 bytes |
MD5 hash: | 8fae9dd5dd67e1f33d873089c2fd8761 |
Start time (UTC): | 18:49:37 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/bin/gpu-manager |
Arguments: | - |
File size: | 76616 bytes |
MD5 hash: | 8fae9dd5dd67e1f33d873089c2fd8761 |
Start time (UTC): | 18:49:37 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/lib/systemd/systemd (deleted) |
Arguments: | - |
File size: | 1620224 bytes |
MD5 hash: | 9b2bec7092a40488108543f9334aab75 |
Start time (UTC): | 18:49:38 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/lib/systemd/systemd (deleted) |
Arguments: | - |
File size: | 1620224 bytes |
MD5 hash: | 9b2bec7092a40488108543f9334aab75 |
Start time (UTC): | 18:49:39 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/lib/systemd/systemd (deleted) |
Arguments: | - |
File size: | 1620224 bytes |
MD5 hash: | 9b2bec7092a40488108543f9334aab75 |
Start time (UTC): | 18:49:39 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/bin/gpu-manager |
Arguments: | /usr/bin/gpu-manager --log /var/log/gpu-manager.log |
File size: | 76616 bytes |
MD5 hash: | 8fae9dd5dd67e1f33d873089c2fd8761 |
Start time (UTC): | 18:49:39 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/bin/gpu-manager |
Arguments: | - |
File size: | 76616 bytes |
MD5 hash: | 8fae9dd5dd67e1f33d873089c2fd8761 |
Start time (UTC): | 18:49:39 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/bin/gpu-manager |
Arguments: | - |
File size: | 76616 bytes |
MD5 hash: | 8fae9dd5dd67e1f33d873089c2fd8761 |
Start time (UTC): | 18:49:39 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/bin/gpu-manager |
Arguments: | - |
File size: | 76616 bytes |
MD5 hash: | 8fae9dd5dd67e1f33d873089c2fd8761 |
Start time (UTC): | 18:49:39 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/bin/gpu-manager |
Arguments: | - |
File size: | 76616 bytes |
MD5 hash: | 8fae9dd5dd67e1f33d873089c2fd8761 |
Start time (UTC): | 18:49:39 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/bin/gpu-manager |
Arguments: | - |
File size: | 76616 bytes |
MD5 hash: | 8fae9dd5dd67e1f33d873089c2fd8761 |
Start time (UTC): | 18:49:39 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/bin/gpu-manager |
Arguments: | - |
File size: | 76616 bytes |
MD5 hash: | 8fae9dd5dd67e1f33d873089c2fd8761 |
Start time (UTC): | 18:49:39 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/bin/gpu-manager |
Arguments: | - |
File size: | 76616 bytes |
MD5 hash: | 8fae9dd5dd67e1f33d873089c2fd8761 |
Start time (UTC): | 18:49:39 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/bin/gpu-manager |
Arguments: | - |
File size: | 76616 bytes |
MD5 hash: | 8fae9dd5dd67e1f33d873089c2fd8761 |
Start time (UTC): | 18:49:40 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/lib/systemd/systemd (deleted) |
Arguments: | - |
File size: | 1620224 bytes |
MD5 hash: | 9b2bec7092a40488108543f9334aab75 |
Start time (UTC): | 18:49:41 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/lib/systemd/systemd (deleted) |
Arguments: | - |
File size: | 1620224 bytes |
MD5 hash: | 9b2bec7092a40488108543f9334aab75 |
Start time (UTC): | 18:49:41 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/bin/gpu-manager |
Arguments: | /usr/bin/gpu-manager --log /var/log/gpu-manager.log |
File size: | 76616 bytes |
MD5 hash: | 8fae9dd5dd67e1f33d873089c2fd8761 |
Start time (UTC): | 18:49:41 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/bin/gpu-manager |
Arguments: | - |
File size: | 76616 bytes |
MD5 hash: | 8fae9dd5dd67e1f33d873089c2fd8761 |
Start time (UTC): | 18:49:41 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/bin/gpu-manager |
Arguments: | - |
File size: | 76616 bytes |
MD5 hash: | 8fae9dd5dd67e1f33d873089c2fd8761 |
Start time (UTC): | 18:49:41 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/bin/gpu-manager |
Arguments: | - |
File size: | 76616 bytes |
MD5 hash: | 8fae9dd5dd67e1f33d873089c2fd8761 |
Start time (UTC): | 18:49:41 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/bin/gpu-manager |
Arguments: | - |
File size: | 76616 bytes |
MD5 hash: | 8fae9dd5dd67e1f33d873089c2fd8761 |
Start time (UTC): | 18:49:41 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/bin/gpu-manager |
Arguments: | - |
File size: | 76616 bytes |
MD5 hash: | 8fae9dd5dd67e1f33d873089c2fd8761 |
Start time (UTC): | 18:49:41 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/bin/gpu-manager |
Arguments: | - |
File size: | 76616 bytes |
MD5 hash: | 8fae9dd5dd67e1f33d873089c2fd8761 |
Start time (UTC): | 18:49:41 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/bin/gpu-manager |
Arguments: | - |
File size: | 76616 bytes |
MD5 hash: | 8fae9dd5dd67e1f33d873089c2fd8761 |
Start time (UTC): | 18:49:41 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/bin/gpu-manager |
Arguments: | - |
File size: | 76616 bytes |
MD5 hash: | 8fae9dd5dd67e1f33d873089c2fd8761 |
Start time (UTC): | 18:49:41 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/lib/systemd/systemd (deleted) |
Arguments: | - |
File size: | 1620224 bytes |
MD5 hash: | 9b2bec7092a40488108543f9334aab75 |
Start time (UTC): | 18:49:42 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/lib/systemd/systemd (deleted) |
Arguments: | - |
File size: | 1620224 bytes |
MD5 hash: | 9b2bec7092a40488108543f9334aab75 |
Start time (UTC): | 18:49:42 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/bin/gpu-manager |
Arguments: | /usr/bin/gpu-manager --log /var/log/gpu-manager.log |
File size: | 76616 bytes |
MD5 hash: | 8fae9dd5dd67e1f33d873089c2fd8761 |
Start time (UTC): | 18:49:42 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/bin/gpu-manager |
Arguments: | - |
File size: | 76616 bytes |
MD5 hash: | 8fae9dd5dd67e1f33d873089c2fd8761 |
Start time (UTC): | 18:49:42 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/bin/gpu-manager |
Arguments: | - |
File size: | 76616 bytes |
MD5 hash: | 8fae9dd5dd67e1f33d873089c2fd8761 |
Start time (UTC): | 18:49:42 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/bin/gpu-manager |
Arguments: | - |
File size: | 76616 bytes |
MD5 hash: | 8fae9dd5dd67e1f33d873089c2fd8761 |
Start time (UTC): | 18:49:42 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/bin/gpu-manager |
Arguments: | - |
File size: | 76616 bytes |
MD5 hash: | 8fae9dd5dd67e1f33d873089c2fd8761 |
Start time (UTC): | 18:49:42 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/bin/gpu-manager |
Arguments: | - |
File size: | 76616 bytes |
MD5 hash: | 8fae9dd5dd67e1f33d873089c2fd8761 |
Start time (UTC): | 18:49:42 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/bin/gpu-manager |
Arguments: | - |
File size: | 76616 bytes |
MD5 hash: | 8fae9dd5dd67e1f33d873089c2fd8761 |
Start time (UTC): | 18:49:42 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/bin/gpu-manager |
Arguments: | - |
File size: | 76616 bytes |
MD5 hash: | 8fae9dd5dd67e1f33d873089c2fd8761 |
Start time (UTC): | 18:49:42 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/bin/gpu-manager |
Arguments: | - |
File size: | 76616 bytes |
MD5 hash: | 8fae9dd5dd67e1f33d873089c2fd8761 |
Start time (UTC): | 18:49:43 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/lib/systemd/systemd (deleted) |
Arguments: | - |
File size: | 1620224 bytes |
MD5 hash: | 9b2bec7092a40488108543f9334aab75 |
Start time (UTC): | 18:49:44 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/lib/systemd/systemd (deleted) |
Arguments: | - |
File size: | 1620224 bytes |
MD5 hash: | 9b2bec7092a40488108543f9334aab75 |
Start time (UTC): | 18:49:44 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/bin/gpu-manager |
Arguments: | /usr/bin/gpu-manager --log /var/log/gpu-manager.log |
File size: | 76616 bytes |
MD5 hash: | 8fae9dd5dd67e1f33d873089c2fd8761 |
Start time (UTC): | 18:49:44 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/bin/gpu-manager |
Arguments: | - |
File size: | 76616 bytes |
MD5 hash: | 8fae9dd5dd67e1f33d873089c2fd8761 |
Start time (UTC): | 18:49:44 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/bin/gpu-manager |
Arguments: | - |
File size: | 76616 bytes |
MD5 hash: | 8fae9dd5dd67e1f33d873089c2fd8761 |
Start time (UTC): | 18:49:44 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/bin/gpu-manager |
Arguments: | - |
File size: | 76616 bytes |
MD5 hash: | 8fae9dd5dd67e1f33d873089c2fd8761 |
Start time (UTC): | 18:49:44 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/bin/gpu-manager |
Arguments: | - |
File size: | 76616 bytes |
MD5 hash: | 8fae9dd5dd67e1f33d873089c2fd8761 |
Start time (UTC): | 18:49:44 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/bin/gpu-manager |
Arguments: | - |
File size: | 76616 bytes |
MD5 hash: | 8fae9dd5dd67e1f33d873089c2fd8761 |
Start time (UTC): | 18:49:44 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/bin/gpu-manager |
Arguments: | - |
File size: | 76616 bytes |
MD5 hash: | 8fae9dd5dd67e1f33d873089c2fd8761 |
Start time (UTC): | 18:49:44 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/bin/gpu-manager |
Arguments: | - |
File size: | 76616 bytes |
MD5 hash: | 8fae9dd5dd67e1f33d873089c2fd8761 |
Start time (UTC): | 18:49:44 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/bin/gpu-manager |
Arguments: | - |
File size: | 76616 bytes |
MD5 hash: | 8fae9dd5dd67e1f33d873089c2fd8761 |
Start time (UTC): | 18:49:45 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/lib/systemd/systemd (deleted) |
Arguments: | - |
File size: | 1620224 bytes |
MD5 hash: | 9b2bec7092a40488108543f9334aab75 |
Start time (UTC): | 18:49:46 |
Start date (UTC): | 02/04/2025 |
Path: | /usr/lib/systemd/systemd (deleted) |
Arguments: | - |
File size: | 1620224 bytes |
MD5 hash: | 9b2bec7092a40488108543f9334aab75 |
Start time (UTC): | 18:49:46 |
Start date (UTC): | 02/04/2025 |
Path: | /bin/plymouth |
Arguments: | /bin/plymouth quit |
File size: | 51352 bytes |
MD5 hash: | 87003efd8dad470042f5e75360a8f49f |