Loading ...

Play interactive tourEdit tour

Linux Analysis Report 1Zn1o0ho0d

Overview

General Information

Sample Name:1Zn1o0ho0d
Analysis ID:517072
MD5:7cd969c5a935efb39614b9e088682e2d
SHA1:142387e6dddad723345106a8a2d4bbc96527387c
SHA256:e46d2e7b074443218de80066a68ae9e146f8d8fdd22b624f619d7f486e4036b8
Tags:32armelfmirai
Infos:

Detection

Mirai
Score:72
Range:0 - 100
Whitelisted:false

Signatures

Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)
Yara detected Mirai
Multi AV Scanner detection for submitted file
Sample is packed with UPX
Uses known network protocols on non-standard ports
Sample contains only a LOAD segment without any section mappings
Yara signature match
Deletes log files
Uses the "uname" system call to query kernel version information (possible evasion)
Enumerates processes within the "proc" file system
Executes commands using a shell command-line interpreter
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Detected TCP or UDP traffic on non-standard ports
Sample listens on a socket
Sample tries to kill a process (SIGKILL)

Classification

Analysis Advice

Static ELF header machine description suggests that the sample might only run correctly on MIPS or ARM architectures
All HTTP servers contacted by the sample do not answer. Likely the sample is an old dropper which does no longer work
Static ELF header machine description suggests that the sample might not execute correctly on this machine

General Information

Joe Sandbox Version:34.0.0 Boulder Opal
Analysis ID:517072
Start date:07.11.2021
Start time:00:06:07
Joe Sandbox Product:CloudBasic
Overall analysis duration:0h 6m 56s
Hypervisor based Inspection enabled:false
Report type:light
Sample file name:1Zn1o0ho0d
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Detection:MAL
Classification:mal72.troj.evad.lin@0/57@0/0
Warnings:
Show All
  • Report size exceeded maximum capacity and may have missing network information.
  • TCP Packets have been reduced to 100

Process Tree

  • system is lnxubuntu20
  • systemd New Fork (PID: 5216, Parent: 1)
  • logrotate (PID: 5216, Parent: 1, MD5: ff9f6831debb63e53a31ff8057143af6) Arguments: /usr/sbin/logrotate /etc/logrotate.conf
    • gzip (PID: 5295, Parent: 5216, MD5: beef4e1f54ec90564d2acd57c0b0c897) Arguments: /bin/gzip
    • sh (PID: 5296, Parent: 5216, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "\n\t\tinvoke-rc.d --quiet cups restart > /dev/null\n" logrotate_script "/var/log/cups/*log "
      • sh New Fork (PID: 5297, Parent: 5296)
      • invoke-rc.d (PID: 5297, Parent: 5296, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: invoke-rc.d --quiet cups restart
        • runlevel (PID: 5298, Parent: 5297, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: /sbin/runlevel
        • systemctl (PID: 5299, Parent: 5297, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl --quiet is-enabled cups.service
        • ls (PID: 5303, Parent: 5297, MD5: e7793f15c2ff7e747b4bc7079f5cd4f7) Arguments: ls /etc/rc[S2345].d/S[0-9][0-9]cups
        • systemctl (PID: 5305, Parent: 5297, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl --quiet is-active cups.service
    • gzip (PID: 5306, Parent: 5216, MD5: beef4e1f54ec90564d2acd57c0b0c897) Arguments: /bin/gzip
    • sh (PID: 5307, Parent: 5216, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c /usr/lib/rsyslog/rsyslog-rotate logrotate_script /var/log/syslog
      • sh New Fork (PID: 5308, Parent: 5307)
      • rsyslog-rotate (PID: 5308, Parent: 5307, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /usr/lib/rsyslog/rsyslog-rotate
        • systemctl (PID: 5309, Parent: 5308, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl kill -s HUP rsyslog.service
    • gzip (PID: 5310, Parent: 5216, MD5: beef4e1f54ec90564d2acd57c0b0c897) Arguments: /bin/gzip
    • gzip (PID: 5311, Parent: 5216, MD5: beef4e1f54ec90564d2acd57c0b0c897) Arguments: /bin/gzip
    • sh (PID: 5312, Parent: 5216, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c /usr/lib/rsyslog/rsyslog-rotate logrotate_script /var/log/mail.info/var/log/mail.warn/var/log/mail.err/var/log/mail.log/var/log/daemon.log/var/log/kern.log/var/log/auth.log/var/log/user.log/var/log/lpr.log/var/log/cron.log/var/log/debug/var/log/messages
      • sh New Fork (PID: 5313, Parent: 5312)
      • rsyslog-rotate (PID: 5313, Parent: 5312, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /usr/lib/rsyslog/rsyslog-rotate
        • systemctl (PID: 5314, Parent: 5313, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl kill -s HUP rsyslog.service
  • systemd New Fork (PID: 5217, Parent: 1)
  • install (PID: 5217, Parent: 1, MD5: 55e2520049dc6a62e8c94732e36cdd54) Arguments: /usr/bin/install -d -o man -g man -m 0755 /var/cache/man
  • systemd New Fork (PID: 5294, Parent: 1)
  • find (PID: 5294, Parent: 1, MD5: b68ef002f84cc54dd472238ba7df80ab) Arguments: /usr/bin/find /var/cache/man -type f -name *.gz -atime +6 -delete
  • systemd New Fork (PID: 5300, Parent: 1)
  • mandb (PID: 5300, Parent: 1, MD5: 1dda5ea0027ecf1c2db0f5a3de7e6941) Arguments: /usr/bin/mandb --quiet
  • systemd New Fork (PID: 5362, Parent: 1)
  • sshd (PID: 5362, Parent: 1, MD5: dbca7a6bbf7bf57fedac243d4b2cb340) Arguments: /usr/sbin/sshd -t
  • systemd New Fork (PID: 5363, Parent: 1)
  • sshd (PID: 5363, Parent: 1, MD5: dbca7a6bbf7bf57fedac243d4b2cb340) Arguments: /usr/sbin/sshd -D
  • cleanup

Yara Overview

Initial Sample

SourceRuleDescriptionAuthorStrings
1Zn1o0ho0dSUSP_ELF_LNX_UPX_Compressed_FileDetects a suspicious ELF binary with UPX compressionFlorian Roth
  • 0x7c94:$s1: PROT_EXEC|PROT_WRITE failed.
  • 0x7d03:$s2: $Id: UPX
  • 0x7cb4:$s3: $Info: This file is packed with the UPX executable packer

PCAP (Network Traffic)

SourceRuleDescriptionAuthorStrings
dump.pcapJoeSecurity_Mirai_12Yara detected MiraiJoe Security

    Jbx Signature Overview

    Click to jump to signature section

    Show All Signature Results

    AV Detection:

    barindex
    Multi AV Scanner detection for submitted fileShow sources
    Source: 1Zn1o0ho0dVirustotal: Detection: 44%Perma Link
    Source: 1Zn1o0ho0dReversingLabs: Detection: 42%

    Networking:

    barindex
    Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)Show sources
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 59.12.94.81:23 -> 192.168.2.23:35958
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 59.12.94.81:23 -> 192.168.2.23:35958
    Source: TrafficSnort IDS: 716 INFO TELNET access 178.207.60.252:23 -> 192.168.2.23:36596
    Source: TrafficSnort IDS: 404 ICMP Destination Unreachable Protocol Unreachable 188.150.3.143: -> 192.168.2.23:
    Source: TrafficSnort IDS: 716 INFO TELNET access 178.207.60.252:23 -> 192.168.2.23:36614
    Source: TrafficSnort IDS: 716 INFO TELNET access 178.207.60.252:23 -> 192.168.2.23:36632
    Source: TrafficSnort IDS: 716 INFO TELNET access 178.207.60.252:23 -> 192.168.2.23:36652
    Source: TrafficSnort IDS: 716 INFO TELNET access 178.207.60.252:23 -> 192.168.2.23:36668
    Source: TrafficSnort IDS: 716 INFO TELNET access 178.207.60.252:23 -> 192.168.2.23:36676
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 59.12.94.81:23 -> 192.168.2.23:36062
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 59.12.94.81:23 -> 192.168.2.23:36062
    Source: TrafficSnort IDS: 716 INFO TELNET access 178.207.60.252:23 -> 192.168.2.23:36682
    Source: TrafficSnort IDS: 716 INFO TELNET access 178.207.60.252:23 -> 192.168.2.23:36708
    Source: TrafficSnort IDS: 716 INFO TELNET access 178.207.60.252:23 -> 192.168.2.23:36742
    Source: TrafficSnort IDS: 716 INFO TELNET access 178.207.60.252:23 -> 192.168.2.23:36754
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 59.12.94.81:23 -> 192.168.2.23:36164
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 59.12.94.81:23 -> 192.168.2.23:36164
    Source: TrafficSnort IDS: 716 INFO TELNET access 58.26.108.34:23 -> 192.168.2.23:36142
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 116.74.111.43:23 -> 192.168.2.23:42378
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 116.74.111.43:23 -> 192.168.2.23:42388
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 116.74.111.43:23 -> 192.168.2.23:42392
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 59.12.94.81:23 -> 192.168.2.23:36214
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 59.12.94.81:23 -> 192.168.2.23:36214
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 116.74.111.43:23 -> 192.168.2.23:42400
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 116.74.111.43:23 -> 192.168.2.23:42406
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 116.74.111.43:23 -> 192.168.2.23:42410
    Source: TrafficSnort IDS: 716 INFO TELNET access 216.7.155.6:23 -> 192.168.2.23:52632
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 116.74.111.43:23 -> 192.168.2.23:42422
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 116.74.111.43:23 -> 192.168.2.23:42434
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 116.74.111.43:23 -> 192.168.2.23:42452
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 116.74.111.43:23 -> 192.168.2.23:42458
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 59.12.94.81:23 -> 192.168.2.23:36276
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 59.12.94.81:23 -> 192.168.2.23:36276
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 120.210.16.54:23 -> 192.168.2.23:40236
    Source: TrafficSnort IDS: 716 INFO TELNET access 58.26.108.34:23 -> 192.168.2.23:36266
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 120.210.16.54:23 -> 192.168.2.23:40256
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 120.210.16.54:23 -> 192.168.2.23:40274
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 59.12.94.81:23 -> 192.168.2.23:36340
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 59.12.94.81:23 -> 192.168.2.23:36340
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 120.210.16.54:23 -> 192.168.2.23:40280
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 120.210.16.54:23 -> 192.168.2.23:40286
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 120.210.16.54:23 -> 192.168.2.23:40312
    Source: TrafficSnort IDS: 716 INFO TELNET access 221.206.242.157:23 -> 192.168.2.23:43416
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 120.210.16.54:23 -> 192.168.2.23:40324
    Source: TrafficSnort IDS: 716 INFO TELNET access 216.7.155.6:23 -> 192.168.2.23:52778
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 120.210.16.54:23 -> 192.168.2.23:40330
    Source: TrafficSnort IDS: 716 INFO TELNET access 221.206.242.157:23 -> 192.168.2.23:43444
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 59.12.94.81:23 -> 192.168.2.23:36394
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 59.12.94.81:23 -> 192.168.2.23:36394
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 120.210.16.54:23 -> 192.168.2.23:40344
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 120.210.16.54:23 -> 192.168.2.23:40356
    Source: TrafficSnort IDS: 716 INFO TELNET access 221.206.242.157:23 -> 192.168.2.23:43452
    Source: TrafficSnort IDS: 716 INFO TELNET access 221.206.242.157:23 -> 192.168.2.23:43472
    Source: TrafficSnort IDS: 716 INFO TELNET access 221.206.242.157:23 -> 192.168.2.23:43478
    Source: TrafficSnort IDS: 716 INFO TELNET access 221.206.242.157:23 -> 192.168.2.23:43484
    Source: TrafficSnort IDS: 716 INFO TELNET access 58.26.108.34:23 -> 192.168.2.23:36396
    Source: TrafficSnort IDS: 716 INFO TELNET access 221.206.242.157:23 -> 192.168.2.23:43492
    Source: TrafficSnort IDS: 716 INFO TELNET access 221.206.242.157:23 -> 192.168.2.23:43496
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 59.12.94.81:23 -> 192.168.2.23:36446
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 59.12.94.81:23 -> 192.168.2.23:36446
    Source: TrafficSnort IDS: 716 INFO TELNET access 221.206.242.157:23 -> 192.168.2.23:43512
    Source: TrafficSnort IDS: 716 INFO TELNET access 221.206.242.157:23 -> 192.168.2.23:43520
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 223.205.167.95:23 -> 192.168.2.23:46894
    Source: TrafficSnort IDS: 716 INFO TELNET access 61.151.249.211:23 -> 192.168.2.23:37298
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 69.173.224.203:23 -> 192.168.2.23:43142
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 69.173.224.203:23 -> 192.168.2.23:43142
    Source: TrafficSnort IDS: 716 INFO TELNET access 216.7.155.6:23 -> 192.168.2.23:52936
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 45.228.16.21:23 -> 192.168.2.23:33976
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 45.228.16.21:23 -> 192.168.2.23:33976
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 61.151.249.211:23 -> 192.168.2.23:37298
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 69.173.224.203:23 -> 192.168.2.23:43154
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 69.173.224.203:23 -> 192.168.2.23:43154
    Source: TrafficSnort IDS: 716 INFO TELNET access 61.151.249.211:23 -> 192.168.2.23:37322
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 69.173.224.203:23 -> 192.168.2.23:43166
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 69.173.224.203:23 -> 192.168.2.23:43166
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 61.151.249.211:23 -> 192.168.2.23:37322
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 69.173.224.203:23 -> 192.168.2.23:43184
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 69.173.224.203:23 -> 192.168.2.23:43184
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 218.108.66.54:23 -> 192.168.2.23:59728
    Source: TrafficSnort IDS: 716 INFO TELNET access 122.140.245.150:23 -> 192.168.2.23:56786
    Source: TrafficSnort IDS: 716 INFO TELNET access 58.26.108.34:23 -> 192.168.2.23:36556
    Source: TrafficSnort IDS: 716 INFO TELNET access 122.140.245.150:23 -> 192.168.2.23:56838
    Source: TrafficSnort IDS: 716 INFO TELNET access 61.151.249.211:23 -> 192.168.2.23:37374
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 61.151.249.211:23 -> 192.168.2.23:37374
    Source: TrafficSnort IDS: 716 INFO TELNET access 122.140.245.150:23 -> 192.168.2.23:56852
    Source: TrafficSnort IDS: 716 INFO TELNET access 61.151.249.211:23 -> 192.168.2.23:37414
    Source: TrafficSnort IDS: 716 INFO TELNET access 122.140.245.150:23 -> 192.168.2.23:56874
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 118.163.235.60:23 -> 192.168.2.23:53434
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 118.163.235.60:23 -> 192.168.2.23:53434
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 61.151.249.211:23 -> 192.168.2.23:37414
    Source: TrafficSnort IDS: 716 INFO TELNET access 122.140.245.150:23 -> 192.168.2.23:56888
    Source: TrafficSnort IDS: 716 INFO TELNET access 122.140.245.150:23 -> 192.168.2.23:56904
    Source: TrafficSnort IDS: 716 INFO TELNET access 61.151.249.211:23 -> 192.168.2.23:37448
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 59.12.94.81:23 -> 192.168.2.23:36678
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 59.12.94.81:23 -> 192.168.2.23:36678
    Source: TrafficSnort IDS: 716 INFO TELNET access 122.140.245.150:23 -> 192.168.2.23:56930
    Source: TrafficSnort IDS: 716 INFO TELNET access 122.140.245.150:23 -> 192.168.2.23:56942
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 61.151.249.211:23 -> 192.168.2.23:37448
    Source: TrafficSnort IDS: 716 INFO TELNET access 122.140.245.150:23 -> 192.168.2.23:56950
    Source: TrafficSnort IDS: 716 INFO TELNET access 216.7.155.6:23 -> 192.168.2.23:53122
    Source: TrafficSnort IDS: 716 INFO TELNET access 61.151.249.211:23 -> 192.168.2.23:37504
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 118.163.235.60:23 -> 192.168.2.23:53514
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 118.163.235.60:23 -> 192.168.2.23:53514
    Source: TrafficSnort IDS: 716 INFO TELNET access 122.140.245.150:23 -> 192.168.2.23:56964
    Source: TrafficSnort IDS: 404 ICMP Destination Unreachable Protocol Unreachable 98.11.20.73: -> 192.168.2.23:
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 61.151.249.211:23 -> 192.168.2.23:37504
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 14.169.69.75:23 -> 192.168.2.23:44530
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 14.169.69.75:23 -> 192.168.2.23:44530
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 45.228.16.21:23 -> 192.168.2.23:34190
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 45.228.16.21:23 -> 192.168.2.23:34190
    Source: TrafficSnort IDS: 716 INFO TELNET access 61.151.249.211:23 -> 192.168.2.23:37530
    Source: TrafficSnort IDS: 716 INFO TELNET access 58.26.108.34:23 -> 192.168.2.23:36726
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 61.151.249.211:23 -> 192.168.2.23:37530
    Source: TrafficSnort IDS: 716 INFO TELNET access 61.151.249.211:23 -> 192.168.2.23:37552
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 118.163.235.60:23 -> 192.168.2.23:53570
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 118.163.235.60:23 -> 192.168.2.23:53570
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 61.151.249.211:23 -> 192.168.2.23:37552
    Source: TrafficSnort IDS: 716 INFO TELNET access 61.151.249.211:23 -> 192.168.2.23:37598
    Source: TrafficSnort IDS: 716 INFO TELNET access 222.222.173.171:23 -> 192.168.2.23:41814
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 14.247.229.197:23 -> 192.168.2.23:35102
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 14.247.229.197:23 -> 192.168.2.23:35102
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 61.151.249.211:23 -> 192.168.2.23:37598
    Source: TrafficSnort IDS: 716 INFO TELNET access 222.222.173.171:23 -> 192.168.2.23:41880
    Source: TrafficSnort IDS: 716 INFO TELNET access 61.151.249.211:23 -> 192.168.2.23:37718
    Source: TrafficSnort IDS: 716 INFO TELNET access 81.70.244.145:23 -> 192.168.2.23:44124
    Source: TrafficSnort IDS: 716 INFO TELNET access 153.151.190.73:23 -> 192.168.2.23:51398
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 118.163.235.60:23 -> 192.168.2.23:53684
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 118.163.235.60:23 -> 192.168.2.23:53684
    Source: TrafficSnort IDS: 716 INFO TELNET access 223.244.252.47:23 -> 192.168.2.23:59778
    Source: TrafficSnort IDS: 716 INFO TELNET access 222.222.173.171:23 -> 192.168.2.23:41994
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 61.151.249.211:23 -> 192.168.2.23:37718
    Source: TrafficSnort IDS: 716 INFO TELNET access 216.7.155.6:23 -> 192.168.2.23:53442
    Source: TrafficSnort IDS: 716 INFO TELNET access 153.151.190.73:23 -> 192.168.2.23:51498
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 223.244.252.47:23 -> 192.168.2.23:59778
    Source: TrafficSnort IDS: 716 INFO TELNET access 59.20.239.131:23 -> 192.168.2.23:41100
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 123.21.164.54:23 -> 192.168.2.23:37482
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 123.21.164.54:23 -> 192.168.2.23:37482
    Source: TrafficSnort IDS: 716 INFO TELNET access 42.63.24.62:23 -> 192.168.2.23:49516
    Source: TrafficSnort IDS: 716 INFO TELNET access 222.222.173.171:23 -> 192.168.2.23:42092
    Source: TrafficSnort IDS: 716 INFO TELNET access 223.244.252.47:23 -> 192.168.2.23:59928
    Source: TrafficSnort IDS: 716 INFO TELNET access 153.151.190.73:23 -> 192.168.2.23:51612
    Source: TrafficSnort IDS: 716 INFO TELNET access 58.26.108.34:23 -> 192.168.2.23:37168
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 42.63.24.62:23 -> 192.168.2.23:49516
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 42.63.24.62:23 -> 192.168.2.23:49516
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 223.244.252.47:23 -> 192.168.2.23:59928
    Source: TrafficSnort IDS: 716 INFO TELNET access 222.222.173.171:23 -> 192.168.2.23:42174
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 14.169.69.75:23 -> 192.168.2.23:45012
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 14.169.69.75:23 -> 192.168.2.23:45012
    Source: TrafficSnort IDS: 716 INFO TELNET access 153.151.190.73:23 -> 192.168.2.23:51694
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 118.163.235.60:23 -> 192.168.2.23:54006
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 118.163.235.60:23 -> 192.168.2.23:54006
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 202.151.73.246:23 -> 192.168.2.23:52194
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 202.151.73.246:23 -> 192.168.2.23:52194
    Source: TrafficSnort IDS: 716 INFO TELNET access 223.244.252.47:23 -> 192.168.2.23:60074
    Source: TrafficSnort IDS: 716 INFO TELNET access 222.222.173.171:23 -> 192.168.2.23:42282
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 45.228.16.21:23 -> 192.168.2.23:34734
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 45.228.16.21:23 -> 192.168.2.23:34734
    Source: TrafficSnort IDS: 716 INFO TELNET access 78.30.39.60:23 -> 192.168.2.23:38986
    Source: TrafficSnort IDS: 716 INFO TELNET access 166.155.150.155:23 -> 192.168.2.23:38542
    Source: TrafficSnort IDS: 716 INFO TELNET access 153.151.190.73:23 -> 192.168.2.23:51820
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 223.244.252.47:23 -> 192.168.2.23:60074
    Source: TrafficSnort IDS: 716 INFO TELNET access 119.178.234.29:23 -> 192.168.2.23:56028
    Uses known network protocols on non-standard portsShow sources
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 35930
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 35932
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 35934
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 35936
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 35940
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 35946
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 35954
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 35960
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 35962
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 35964
    Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
    Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
    Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
    Source: global trafficTCP traffic: 192.168.2.23:53546 -> 45.61.184.103:1312
    Source: /tmp/1Zn1o0ho0d (PID: 5329)Socket: 0.0.0.0::0
    Source: /tmp/1Zn1o0ho0d (PID: 5335)Socket: 0.0.0.0::0
    Source: /usr/sbin/sshd (PID: 5363)Socket: 0.0.0.0::22
    Source: /usr/sbin/sshd (PID: 5363)Socket: [::]::22
    Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
    Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
    Source: unknownTCP traffic detected without corresponding DNS query: 45.61.184.103
    Source: unknownTCP traffic detected without corresponding DNS query: 19.144.151.212
    Source: unknownTCP traffic detected without corresponding DNS query: 1.156.101.49
    Source: unknownTCP traffic detected without corresponding DNS query: 40.147.72.91
    Source: unknownTCP traffic detected without corresponding DNS query: 209.203.206.212
    Source: unknownTCP traffic detected without corresponding DNS query: 82.184.240.109
    Source: unknownTCP traffic detected without corresponding DNS query: 112.213.151.155
    Source: unknownTCP traffic detected without corresponding DNS query: 94.224.236.78
    Source: unknownTCP traffic detected without corresponding DNS query: 146.253.39.205
    Source: unknownTCP traffic detected without corresponding DNS query: 158.74.71.229
    Source: unknownTCP traffic detected without corresponding DNS query: 38.236.176.204
    Source: unknownTCP traffic detected without corresponding DNS query: 195.19.16.11
    Source: unknownTCP traffic detected without corresponding DNS query: 89.216.24.175
    Source: unknownTCP traffic detected without corresponding DNS query: 242.195.215.219
    Source: unknownTCP traffic detected without corresponding DNS query: 172.168.60.98
    Source: unknownTCP traffic detected without corresponding DNS query: 89.11.92.97
    Source: unknownTCP traffic detected without corresponding DNS query: 36.62.213.26
    Source: unknownTCP traffic detected without corresponding DNS query: 213.158.52.104
    Source: unknownTCP traffic detected without corresponding DNS query: 170.64.194.116
    Source: unknownTCP traffic detected without corresponding DNS query: 84.174.175.114
    Source: unknownTCP traffic detected without corresponding DNS query: 146.147.140.118
    Source: unknownTCP traffic detected without corresponding DNS query: 113.201.32.205
    Source: unknownTCP traffic detected without corresponding DNS query: 171.204.159.164
    Source: unknownTCP traffic detected without corresponding DNS query: 158.142.241.45
    Source: unknownTCP traffic detected without corresponding DNS query: 58.159.20.247
    Source: unknownTCP traffic detected without corresponding DNS query: 250.177.247.139
    Source: unknownTCP traffic detected without corresponding DNS query: 221.108.158.190
    Source: unknownTCP traffic detected without corresponding DNS query: 84.14.81.112
    Source: unknownTCP traffic detected without corresponding DNS query: 76.216.50.56
    Source: unknownTCP traffic detected without corresponding DNS query: 185.27.46.90
    Source: unknownTCP traffic detected without corresponding DNS query: 178.211.126.126
    Source: unknownTCP traffic detected without corresponding DNS query: 62.8.172.188
    Source: unknownTCP traffic detected without corresponding DNS query: 53.126.99.214
    Source: unknownTCP traffic detected without corresponding DNS query: 165.140.65.130
    Source: unknownTCP traffic detected without corresponding DNS query: 223.215.75.244
    Source: unknownTCP traffic detected without corresponding DNS query: 221.42.145.178
    Source: unknownTCP traffic detected without corresponding DNS query: 194.26.94.41
    Source: unknownTCP traffic detected without corresponding DNS query: 37.138.101.243
    Source: unknownTCP traffic detected without corresponding DNS query: 72.98.96.27
    Source: unknownTCP traffic detected without corresponding DNS query: 218.203.211.166
    Source: unknownTCP traffic detected without corresponding DNS query: 243.247.240.222
    Source: unknownTCP traffic detected without corresponding DNS query: 153.114.232.183
    Source: unknownTCP traffic detected without corresponding DNS query: 39.228.186.44
    Source: unknownTCP traffic detected without corresponding DNS query: 223.90.174.102
    Source: unknownTCP traffic detected without corresponding DNS query: 248.159.48.135
    Source: unknownTCP traffic detected without corresponding DNS query: 136.58.3.105
    Source: unknownTCP traffic detected without corresponding DNS query: 23.60.50.185
    Source: unknownTCP traffic detected without corresponding DNS query: 120.112.118.222
    Source: unknownTCP traffic detected without corresponding DNS query: 75.116.81.194
    Source: 1Zn1o0ho0dString found in binary or memory: http://upx.sf.net
    Source: LOAD without section mappingsProgram segment: 0x8000
    Source: 1Zn1o0ho0d, type: SAMPLEMatched rule: SUSP_ELF_LNX_UPX_Compressed_File date = 2018-12-12, author = Florian Roth, description = Detects a suspicious ELF binary with UPX compression, reference = Internal Research, score = 038ff8b2fef16f8ee9d70e6c219c5f380afe1a21761791e8cbda21fa4d09fdb4
    Source: /tmp/1Zn1o0ho0d (PID: 5335)SIGKILL sent: pid: 936, result: successful
    Source: classification engineClassification label: mal72.troj.evad.lin@0/57@0/0
    Source: 1Zn1o0ho0dJoe Sandbox Cloud Basic: Detection: clean Score: 0Perma Link

    Data Obfuscation:

    barindex
    Sample is packed with UPXShow sources
    Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
    Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
    Source: initial sampleString containing UPX found: $Id: UPX 3.94 Copyright (C) 1996-2017 the UPX Team. All Rights Reserved. $
    Source: /tmp/1Zn1o0ho0d (PID: 5335)File opened: /proc/491/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5335)File opened: /proc/793/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5335)File opened: /proc/772/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5335)File opened: /proc/796/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5335)File opened: /proc/774/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5335)File opened: /proc/797/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5335)File opened: /proc/777/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5335)File opened: /proc/799/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5335)File opened: /proc/658/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5335)File opened: /proc/912/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5335)File opened: /proc/759/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5335)File opened: /proc/936/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5335)File opened: /proc/918/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5335)File opened: /proc/1/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5335)File opened: /proc/761/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5335)File opened: /proc/785/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5335)File opened: /proc/884/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5335)File opened: /proc/720/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5335)File opened: /proc/721/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5335)File opened: /proc/788/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5335)File opened: /proc/789/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5335)File opened: /proc/800/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5335)File opened: /proc/801/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5335)File opened: /proc/847/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5335)File opened: /proc/904/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5329)File opened: /proc/2033/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5329)File opened: /proc/1582/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5329)File opened: /proc/2275/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5329)File opened: /proc/1612/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5329)File opened: /proc/1579/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5329)File opened: /proc/1699/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5329)File opened: /proc/1335/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5329)File opened: /proc/1698/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5329)File opened: /proc/2028/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5329)File opened: /proc/1334/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5329)File opened: /proc/1576/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5329)File opened: /proc/2302/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5329)File opened: /proc/3236/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5329)File opened: /proc/2025/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5329)File opened: /proc/2146/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5329)File opened: /proc/912/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5329)File opened: /proc/759/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5329)File opened: /proc/2307/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5329)File opened: /proc/918/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5329)File opened: /proc/1594/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5329)File opened: /proc/2285/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5329)File opened: /proc/2281/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5329)File opened: /proc/1349/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5329)File opened: /proc/1/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5329)File opened: /proc/1623/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5329)File opened: /proc/761/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5329)File opened: /proc/1622/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5329)File opened: /proc/884/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5329)File opened: /proc/1983/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5329)File opened: /proc/2038/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5329)File opened: /proc/1586/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5329)File opened: /proc/1465/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5329)File opened: /proc/1344/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5329)File opened: /proc/1860/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5329)File opened: /proc/1463/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5329)File opened: /proc/2156/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5329)File opened: /proc/800/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5329)File opened: /proc/801/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5329)File opened: /proc/1629/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5329)File opened: /proc/1627/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5329)File opened: /proc/1900/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5329)File opened: /proc/5200/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5329)File opened: /proc/5201/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5329)File opened: /proc/491/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5329)File opened: /proc/2294/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5329)File opened: /proc/2050/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5329)File opened: /proc/1877/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5329)File opened: /proc/772/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5329)File opened: /proc/1633/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5329)File opened: /proc/1599/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5329)File opened: /proc/1632/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5329)File opened: /proc/1477/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5329)File opened: /proc/774/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5329)File opened: /proc/1476/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5329)File opened: /proc/1872/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5329)File opened: /proc/2048/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5329)File opened: /proc/1475/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5329)File opened: /proc/2289/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5329)File opened: /proc/777/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5329)File opened: /proc/5038/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5329)File opened: /proc/658/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5329)File opened: /proc/1639/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5329)File opened: /proc/4503/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5329)File opened: /proc/1638/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5329)File opened: /proc/2208/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5329)File opened: /proc/2180/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5329)File opened: /proc/5331/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5329)File opened: /proc/1809/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5329)File opened: /proc/1494/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5329)File opened: /proc/1890/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5329)File opened: /proc/2063/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5329)File opened: /proc/2062/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5329)File opened: /proc/1888/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5329)File opened: /proc/1886/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5329)File opened: /proc/1489/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5329)File opened: /proc/785/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5329)File opened: /proc/1642/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5329)File opened: /proc/788/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5329)File opened: /proc/789/fd
    Source: /tmp/1Zn1o0ho0d (PID: 5329)File opened: /proc/5329/fd
    Source: /usr/sbin/logrotate (PID: 5296)Shell command executed: sh -c "\n\t\tinvoke-rc.d --quiet cups restart > /dev/null\n" logrotate_script "/var/log/cups/*log "
    Source: /usr/sbin/logrotate (PID: 5307)Shell command executed: sh -c /usr/lib/rsyslog/rsyslog-rotate logrotate_script /var/log/syslog
    Source: /usr/sbin/logrotate (PID: 5312)Shell command executed: sh -c /usr/lib/rsyslog/rsyslog-rotate logrotate_script /var/log/mail.info/var/log/mail.warn/var/log/mail.err/var/log/mail.log/var/log/daemon.log/var/log/kern.log/var/log/auth.log/var/log/user.log/var/log/lpr.log/var/log/cron.log/var/log/debug/var/log/messages

    Hooking and other Techniques for Hiding and Protection:

    barindex
    Uses known network protocols on non-standard portsShow sources
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 35930
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 35932
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 35934
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 35936
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 35940
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 35946
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 35954
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 35960
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 35962
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 35964
    Source: /usr/sbin/logrotate (PID: 5216)Truncated file: /var/log/cups/access_log.1Jump to behavior
    Source: /usr/sbin/logrotate (PID: 5216)Truncated file: /var/log/syslog.1Jump to behavior
    Source: /usr/sbin/logrotate (PID: 5216)Truncated file: /var/log/kern.log.1Jump to behavior
    Source: /usr/sbin/logrotate (PID: 5216)Truncated file: /var/log/auth.log.1Jump to behavior
    Source: /usr/bin/find (PID: 5294)Queries kernel information via 'uname':
    Source: /tmp/1Zn1o0ho0d (PID: 5327)Queries kernel information via 'uname':
    Source: 5300.20.drBinary or memory string: -9915837702310A--gzvmware kernel module
    Source: 5300.20.drBinary or memory string: -1116261022170A--gzQEMU User Emulator
    Source: 5300.20.drBinary or memory string: qemu-or1k
    Source: 5300.20.drBinary or memory string: qemu-riscv64
    Source: 5300.20.drBinary or memory string: {cqemu
    Source: 5300.20.drBinary or memory string: qemu-arm
    Source: 5300.20.drBinary or memory string: (qemu
    Source: 5300.20.drBinary or memory string: qemu-tilegx
    Source: 5300.20.drBinary or memory string: qemu-hppa
    Source: 5300.20.drBinary or memory string: q{rqemu%
    Source: 5300.20.drBinary or memory string: )qemu
    Source: 5300.20.drBinary or memory string: vmware-toolbox-cmd
    Source: 5300.20.drBinary or memory string: qemu-ppc
    Source: 5300.20.drBinary or memory string: Tqemu9
    Source: 1Zn1o0ho0d, 5327.1.000000007c8b21e6.000000009461895e.rw-.sdmpBinary or memory string: m}U!/etc/qemu-binfmt/arm
    Source: 5300.20.drBinary or memory string: qemu-aarch64_be
    Source: 5300.20.drBinary or memory string: 0qemu9
    Source: 5300.20.drBinary or memory string: qemu-sparc64
    Source: 5300.20.drBinary or memory string: qemu-mips64
    Source: 5300.20.drBinary or memory string: vV:qemu9
    Source: 5300.20.drBinary or memory string: qemu-ppc64le
    Source: 5300.20.drBinary or memory string: <glib::param::uint64Glib::Param::UInt643pm315820097650A--gzWrapper for uint64 parameters in GLibx86_64-linux-gnu-ld.gold-1116112426130B--gzThe GNU ELF linkerprinter-profile-1115804162510A--gzProfile using X-Rite ColorMunki and Argyll CMSgrub-fstest-1116214898500A--gzdebug tool for GRUB filesystem driversxdg-user-dir-1115483406210A--gzFind an XDG user dirkmodsign-1115569251480A--gzKernel module signing toolsensible-editor-1115739932820A--gzsensible editing, paging, and web browsingminesMines6615854478170Cgnome-mines-gzinputattach-1115708189280A--gzattach a serial line to an input-layer devicegapplication-1116155671180A--gzD-Bus application launcherip-tunnel-8815816145190A--gztunnel configurationkoi8rxterm-1116140167530A--gzX terminal emulator for KOI8-R environmentsfoo2hiperc-wrapper-1115804162510A-tgzConvert Postscript into a HIPERC printer streamcryptsetup-reencrypt-8816002888050A--gztool for offline LUKS device re-encryptionsyndaemon-1115861716810A--gza program that monitors keyboard activity and disables the touchpad when the keyboard is being used.gslj-1115980290200B--gzFormat and print text for LaserJet printer using ghostscriptfile2brl-1115757179490A--gzTranslate an xml or a text file into an embosser-ready braille filexfdesktop-settings-1115793419820A--gzDesktop settings for Xfceua-1115856013570B--gzManage Ubuntu Advantage services from Canonicallatin4-7715812813670B--gzISO 8859-4 character set encoded in octal, decimal, and hexadecimalsane-genesys-5516003468200A--gzSANE backend for GL646, GL841, GL843, GL847 and GL124 based USB flatbed scannerspdftohtml-1115853266670A--gzprogram to convert PDF files into HTML, XML and PNG imagesbluetooth-sendto-1116015653360A--gzGTK application for transferring files over Bluetoothqemu-ppc64-1116261022170B--gzQEMU User Emulatorcache_metadata_size-8815811608350A--gzEstimate the size of the metadata device needed for a given configuration.net::dbus::exporterNet::DBus::Exporter3pm315773746310A--gzExport object methods and signals to the bussane-pint-5516003468200A--gzSANE backend for scanners that use the PINT device driverbpf-helpers7-7715812813670A--gzlist of eBPF helper functionsfull-4415812813670A--gzalways full devicelogin-1115906478670A--gzbegin session on the systemcups-snmp-8815877390340A--gzcups snmp backend (deprecated)ordchr-3am315728089600A--gzconvert characters to strings and vice versasosreport-1116092694050A--gzCollect and package diagnostic and support datatop-1115827827270A--gzdisplay Linux processesuri::_punycodeURI::_punycode3pm315811897880A--gzencodes Unicode string in Punycodettytty4tty1systemd-localed-8816268940210B--gzLocale bus mechanismlvmsadc-8815816289110
    Source: 5300.20.drBinary or memory string: vmware
    Source: 5300.20.drBinary or memory string: qemu-cris
    Source: 5300.20.drBinary or memory string: libvmtools
    Source: 5300.20.drBinary or memory string: qemu-m68k
    Source: 5300.20.drBinary or memory string: qemu-xtensa
    Source: 5300.20.drBinary or memory string: 9qemu
    Source: 5300.20.drBinary or memory string: qemu-sh4
    Source: 5300.20.drBinary or memory string: Dprezip-bin-1116269780060A--gzprefix zip delta word list compressor/decompressornameif-8815490444730A--gzname network interfaces based on MAC addressesxdg-user-dirs-update-1115483406210A--gzUpdate XDG user dir configurationip-link-8815816145190A--gznetwork device configurationhpsa-4415812813670A--gzHP Smart Array SCSI driverhd4-4415812813670A--gzMFM/IDE hard disk devicessane-canon630u-5516003468200A--gzSANE backend for the Canon 630u USB flatbed scannersg_copy_results-8815825816070A--gzsend SCSI RECEIVE COPY RESULTS command (XCOPY related)grub-macbless-8816214898500A--gzbless a mac file/directoryntfstruncate-8815568625640A-tgztruncate a file on an NTFS volumelessfile-1115936459130B--gz"input preprocessor" for less.sane-artec-5516003468200A--gzSANE backend for Artec flatbed scannersrmdir-1115676799200A--gzremove empty directoriessystemd-networkd-wait-online.service-8816268940210A--gzWait for network to come onlinemkfs.ntfs-8815568625640B-tgzcreate an NTFS file systemsg_inq-8815825816070A--gzissue SCSI INQUIRY command and/or decode its responseradattr.so-8815955079440Cpppd-radattr-gzc_rehash-1ssl116164130370B--gzCreate symbolic links to files named by the hash valuestc-htb-8815816145190A--gzHierarchy Token Bucketgvfs-open-1115868766090A--gzsg_rbuf-8815825816070A--gzreads data using SCSI READ BUFFER commandglib-compile-schemas-1116155671180A--gzGSettings schema compileropenssl-srp-1ssl116164130370B--gzmaintain SRP password fileopenssl-rehash-1ssl116164130370B--gzCreate symbolic links to files named by the hash valueslibvmtools-3315837702310A--gzvmware shared librarypasswd5-5515906478670A--gzthe password filenet::dbus::dumperNet::DBus::Dumper3pm315773746310A--gzStringify Net::DBus objects suitable for printingsane-hp4200-5516003468200A--gzSANE backend for Hewlett-Packard 4200 scannersposixoptions-7715812813670A--gzoptional parts of the POSIX standardnetworkmanager.confNetworkManager.conf5516002723180A--gzNetworkManager configuration fileownership-8815771238010A--gzCompaq ownership tag retrieveroakdecode-1115804162510A--gzDecode an OAKT printer stream into human readable form.gvfs-save-1115868766090A--gzmkfs.minix-8815953177680A--gzmake a Minix filesystemuri7-7715812813670A--gzuniform resource identifier (URI), including a URL or URNedit-1115714399500B--gzexecute programs via entries in the mailcap filegit-diff-files-1116148628880A--gzCompares files in the working tree and the index.ldaprc-5516136581350Cldap.conf-gzpactl-1116219586470A--gzControl a running PulseAudio sound servertempfile-1115756848240A--gzcreate a temporary file in a safe mannerhp-check-1115857238880A--gzDependency/Vers
    Source: 1Zn1o0ho0d, 5327.1.000000007c8b21e6.000000009461895e.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/arm
    Source: 5300.20.drBinary or memory string: .qemu{
    Source: 5300.20.drBinary or memory string: qemu-ppc64abi32
    Source: 5300.20.drBinary or memory string: qemu-ppc64
    Source: 5300.20.drBinary or memory string: qemu-i386
    Source: 5300.20.drBinary or memory string: qemu-x86_64
    Source: 5300.20.drBinary or memory string: H~6\nqemu*q
    Source: 5300.20.drBinary or memory string: @qemu
    Source: 5300.20.drBinary or memory string: Fqqemu
    Source: 5300.20.drBinary or memory string: N4qemu
    Source: 5300.20.drBinary or memory string: ~6\nqemu*q
    Source: 5300.20.drBinary or memory string: qemu-mips64el
    Source: 5300.20.drBinary or memory string: hqemu
    Source: 5300.20.drBinary or memory string: &mqemu
    Source: 5300.20.drBinary or memory string: $qemu
    Source: 5300.20.drBinary or memory string: qemu-sparc
    Source: 5300.20.drBinary or memory string: qemu-microblaze
    Source: 5300.20.drBinary or memory string: qemu-user
    Source: 5300.20.drBinary or memory string: qemu-aarch64
    Source: 5300.20.drBinary or memory string: qemu-sh4eb
    Source: 5300.20.drBinary or memory string: iqemu
    Source: 5300.20.drBinary or memory string: qemu-mipsel
    Source: 5300.20.drBinary or memory string: qemuP`
    Source: 5300.20.drBinary or memory string: qemu-alpha
    Source: 1Zn1o0ho0d, 5327.1.000000009573088f.00000000c9a6208a.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-arm/tmp/1Zn1o0ho0dSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/1Zn1o0ho0d
    Source: 5300.20.drBinary or memory string: qemu-microblazeel
    Source: 5300.20.drBinary or memory string: \qemu
    Source: 5300.20.drBinary or memory string: qemu-xtensaeb
    Source: 5300.20.drBinary or memory string: qemu-mipsn32el
    Source: 5300.20.drBinary or memory string: SAqemu
    Source: 5300.20.drBinary or memory string: Vqemu
    Source: 5300.20.drBinary or memory string: qemu-mipsn32
    Source: 5300.20.drBinary or memory string: qemuAU
    Source: 5300.20.drBinary or memory string: qemu-riscv32
    Source: 5300.20.drBinary or memory string: qemu-sparc32plus
    Source: 5300.20.drBinary or memory string: 7,qemu
    Source: 5300.20.drBinary or memory string: qemu-s390x
    Source: 5300.20.drBinary or memory string: vmware-checkvm
    Source: 5300.20.drBinary or memory string: qemu-nios2
    Source: 5300.20.drBinary or memory string: qemu-armeb
    Source: 5300.20.drBinary or memory string: -4415868968400A--gzVMware SVGA video driver
    Source: 5300.20.drBinary or memory string: 7xml::parser::style::streamXML::Parser::Style::Stream3pm315701248990A--gzStream style for XML::Parsersystemd-timedated-8816268940210B--gzTime and date bus mechanismxfce4-keyboard-settings-1115867081120A--gzKeyboard settings for Xfcepygettext2-1115841026830B--gzPython equivalent of xgettext(1)sudoedit-8816110660620B--gzexecute a command as another userintro7-7715812813670A--gzintroduction to overview and miscellany sectionsprof-1115812813670A--gzread and display shared object profiling datadhclient.conf-5516219398220A--gzDHCP client configuration filepam_group-8815953742440A--gzPAM module for group accesssystemd-ask-password-1116268940210A--gzQuery the user for a system passwordupdate-dictcommon-hunspell-8815422954860A--gzrebuild hunspell database and emacsen stuffqemu-nios2-1116261022170B--gzQEMU User Emulatorlwp::useragentLWP::UserAgent3pm315750405830A--gzWeb user agent classgpgcompose-1115838662460A--gzGenerate a stream of OpenPGP packetsecho-1115676799200A--gzdisplay a line of textio::socket::ssl::utilsIO::Socket::SSL::Utils3pm315817106800A--gz- loading, storing, creating certificates and keyscurl-1116268709580A--gztransfer a URLgetcap-8815819434600A--gzexamine file capabilitieszegrep-1115762517060B--gzsearch possibly compressed files for a regular expressiongrub-syslinux2cfg-1116214898500A--gztransform syslinux config into grub.cfgrtc-4415812813670A--gzreal-time clockglib::codegenGlib::CodeGen3pm315820097650A--gzcode generation utilities for Glib-based bindings.wpa_cli-8816146062790A--gzWPA command line clientiso_8859_3-7715812813670B--gzISO 8859-3 character set encoded in octal, decimal, and hexadecimaliso_8859-9-7715812813670A-tgzISO 8859-9 character set encoded in octal, decimal, and hexadecimallvextend-8815816289110A--gzAdd space to a logical volumeresolvectl-1116268940210A--gzResolve domain names, IPV4 and IPv6 addresses, DNS resource records, and services; introspect and reconfigure the DNS resolverchgrp-1115676799200A--gzchange group ownershipsystemd-cgls-1116268940210A--gzRecursively show control group contentspygettext3.8-1113852085880A--gzPython equivalent of xgettext(1)ping4-8815804258830B--gzsend ICMP ECHO_REQUEST to network hostsidmapwb-8816000845410A--gzwinbind ID mapping plugin for cifs-utilsapturl-gtk-8815799493830B--gzgraphical apt-protocol interpreting package installersane-epsonds-5516003468200A--gzSANE backend for EPSON ESC/I-2 scannersgvfs-monitor-file-1115868766090A--gzrstart-1115829564830A--gza sample implementation of a Remote Start clientgit-stage-1116148628880A--gzAdd file contents to the staging areatc-pedit-8815816145190A--gzgeneric packet editor actioniptables-save-881582899
    Source: 5300.20.drBinary or memory string: I_qemu
    Source: 1Zn1o0ho0d, 5327.1.000000009573088f.00000000c9a6208a.rw-.sdmpBinary or memory string: /usr/bin/qemu-arm
    Source: 5300.20.drBinary or memory string: -1116261022170B--gzQEMU User Emulator
    Source: 5300.20.drBinary or memory string: -3315837702310A--gzvmware shared library
    Source: 5300.20.drBinary or memory string: qemu-mips
    Source: 5300.20.drBinary or memory string: qemuj\
    Source: 5300.20.drBinary or memory string: {qemuQ&
    Source: 5300.20.drBinary or memory string: Wgnome-text-editor-111629209547491759146B--gztext editor for the GNOME Desktopx11::protocol::connection::filehandleX11::Protocol::Connection::FileHandle3pm314314075500A--gzPerl module base class for FileHandle-based X11 connectionshtbHTB8815816145190Ctc-htb-gzcifscreds-1116000845410A--gzmanage NTLM credentials in kernel keyringiwconfig-8815490049440A--gzconfigure a wireless network interfaceossl_store-file-7ssl716164130370A--gzThe store 'file' scheme loadertc-stab-8815816145190A--gzGeneric size table manipulationsnotifier-7715877390340A--gzcups notification interfaceqemu-arm-1116261022170B--gzQEMU User EmulatorgemfileGemfile5516263767190Cgemfile2.7-gzglib::object::subclassGlib::Object::Subclass3pm315820097650A--gzregister a perl class as a GObject classnetcat-111612200165426646725B--gzarbitrary TCP and UDP connections and listensdpkg::changelog::parseDpkg::Changelog::Parse3perl315849439740A--gzgeneric changelog parser for dpkg-parsechangelogmpris-proxy-1116243432320A--gzBluetooth mpris-proxybundle-pristine2.7-1116263767190A--gzRestores installed gems to their pristine conditionfsck.ext3-8815816604980B--gzcheck a Linux ext2/ext3/ext4 file systemvolname-1115625752510A--gzreturn volume nameiso-8859-9-7715812813670B--gzISO 8859-9 character set encoded in octal, decimal, and hexadecimalheadhead1HEAD1psd-4415812813670A--gzdriver for SCSI disk driveschrt-1115953177680A--gzmanipulate the real-time attributes of a processvcs-4415812813670A--gzvirtual console memorygit-upload-archive-1116148628880A--gzSend archive back to git-archivenet::dbus::binding::message::errorNet::DBus::Binding::Message::Error3pm315773746310A--gza message encoding a method call errorpkcs11.conf-5516097870510A--gzConfiguration files for PKCS#11 modulessfill-1115227593860A--gzsecure free disk and inode space wiper (secure_deletion toolkit)ldattach-8815953177680A--gzattach a line discipline to a serial linethin_restore-8815811608350A--gzrestore thin provisioning metadata file to device or file.phar.phar7.4-1116254980150B--gzPHAR (PHP archive) command line toolbundle-outdated2.7-1116263767190A--gzList installed gems with newer versions availablemail::addressMail::Address3pm315640244160A--gzparse mail addressesopenssl-ca-1ssl116164130370B--gzsample minimal CA applicationchardet3-1115765858900A--gzuniversal character encoding detectorerb2.7-1116263767190A--gzRuby Templatingchktrust-1115826667350A--gzCheck the trust of a PE executable.sg_raw-8815825816070A--gzsend arbitrary SCSI command to a devicegvfs-trash-1115868766090A--gzintro1-1115812813670A--gzintroduction to user commandsmailcap-5515714399500A--gzmetamail capabilities filegigoloGigolo1gig
    Source: 5300.20.drBinary or memory string: vmware-xferlogs

    Stealing of Sensitive Information:

    barindex
    Yara detected MiraiShow sources
    Source: Yara matchFile source: dump.pcap, type: PCAP

    Remote Access Functionality:

    barindex
    Yara detected MiraiShow sources
    Source: Yara matchFile source: dump.pcap, type: PCAP

    Mitre Att&ck Matrix

    Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
    Valid AccountsScripting1Path InterceptionPath InterceptionScripting1OS Credential Dumping1Security Software Discovery11Remote ServicesData from Local SystemExfiltration Over Other Network MediumEncrypted Channel1Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
    Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsIndicator Removal on Host1LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over BluetoothNon-Standard Port11Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
    Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or Information1Security Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationApplication Layer Protocol1Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data

    Malware Configuration

    No configs have been found

    Behavior Graph

    Hide Legend

    Legend:

    • Process
    • Signature
    • Created File
    • DNS/IP Info
    • Is Dropped
    • Number of created Files
    • Is malicious
    • Internet
    behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 517072 Sample: 1Zn1o0ho0d Startdate: 07/11/2021 Architecture: LINUX Score: 72 70 168.253.102.103 wataniya-telecom-asDZ Algeria 2->70 72 164.117.114.31 WA-K20US United States 2->72 74 98 other IPs or domains 2->74 76 Snort IDS alert for network traffic (e.g. based on Emerging Threat rules) 2->76 78 Multi AV Scanner detection for submitted file 2->78 80 Yara detected Mirai 2->80 82 2 other signatures 2->82 10 systemd logrotate 2->10         started        12 systemd mandb 1Zn1o0ho0d 2->12         started        14 systemd install 2->14         started        16 3 other processes 2->16 signatures3 process4 process5 18 logrotate sh 10->18         started        20 logrotate sh 10->20         started        22 logrotate sh 10->22         started        30 4 other processes 10->30 24 1Zn1o0ho0d 12->24         started        26 1Zn1o0ho0d 12->26         started        28 1Zn1o0ho0d 12->28         started        process6 32 sh invoke-rc.d 18->32         started        34 sh rsyslog-rotate 20->34         started        36 sh rsyslog-rotate 22->36         started        38 1Zn1o0ho0d 24->38         started        40 1Zn1o0ho0d 24->40         started        42 1Zn1o0ho0d 26->42         started        44 1Zn1o0ho0d 26->44         started        46 1Zn1o0ho0d 26->46         started        process7 48 invoke-rc.d runlevel 32->48         started        50 invoke-rc.d systemctl 32->50         started        52 invoke-rc.d ls 32->52         started        54 invoke-rc.d systemctl 32->54         started        56 rsyslog-rotate systemctl 34->56         started        58 rsyslog-rotate systemctl 36->58         started        60 1Zn1o0ho0d 38->60         started        62 2 other processes 38->62 64 2 other processes 42->64 process8 66 1Zn1o0ho0d 60->66         started        68 1Zn1o0ho0d 60->68         started       

    Antivirus, Machine Learning and Genetic Malware Detection

    Initial Sample

    SourceDetectionScannerLabelLink
    1Zn1o0ho0d44%VirustotalBrowse
    1Zn1o0ho0d42%ReversingLabsLinux.Trojan.Mirai

    Dropped Files

    No Antivirus matches

    Domains

    No Antivirus matches

    URLs

    No Antivirus matches

    Domains and IPs

    Contacted Domains

    No contacted domains info

    URLs from Memory and Binaries

    NameSourceMaliciousAntivirus DetectionReputation
    http://upx.sf.net1Zn1o0ho0dfalse
      high

      Contacted IPs

      • No. of IPs < 25%
      • 25% < No. of IPs < 50%
      • 50% < No. of IPs < 75%
      • 75% < No. of IPs

      Public

      IPDomainCountryFlagASNASN NameMalicious
      94.247.246.94
      unknownRussian Federation
      48532TELEPORTSPB-ASRUfalse
      168.253.102.103
      unknownAlgeria
      33779wataniya-telecom-asDZfalse
      212.94.221.136
      unknownFrance
      12409HRNETFRfalse
      72.138.89.75
      unknownCanada
      812ROGERS-COMMUNICATIONSCAfalse
      177.92.82.91
      unknownBrazil
      17222MundivoxLTDABRfalse
      221.212.237.252
      unknownChina
      4837CHINA169-BACKBONECHINAUNICOMChina169BackboneCNfalse
      38.83.177.168
      unknownUnited States
      17216DC74-ASUSfalse
      220.195.246.208
      unknownChina
      4837CHINA169-BACKBONECHINAUNICOMChina169BackboneCNfalse
      253.4.39.192
      unknownReserved
      unknownunknownfalse
      142.109.39.21
      unknownCanada
      53403MOUNT-ROYAL-COLLEGECAfalse
      136.109.129.19
      unknownUnited States
      60311ONEFMCHfalse
      76.171.25.152
      unknownUnited States
      20001TWC-20001-PACWESTUSfalse
      46.199.139.244
      unknownCyprus
      6866CYTA-NETWORKInternetServicesCYfalse
      146.42.159.67
      unknownUnited States
      197938TRAVIANGAMESDEfalse
      116.173.158.81
      unknownChina
      4837CHINA169-BACKBONECHINAUNICOMChina169BackboneCNfalse
      5.26.78.224
      unknownTurkey
      16135TURKCELL-ASTurkcellASTRfalse
      86.169.197.189
      unknownUnited Kingdom
      2856BT-UK-ASBTnetUKRegionalnetworkGBfalse
      175.122.183.152
      unknownKorea Republic of
      9318SKB-ASSKBroadbandCoLtdKRfalse
      40.232.231.63
      unknownUnited States
      4249LILLY-ASUSfalse
      158.108.239.176
      unknownThailand
      9411NONTRINET-AS-APKasetsartUniversityThailandTHfalse
      92.100.125.8
      unknownRussian Federation
      12389ROSTELECOM-ASRUfalse
      111.21.149.85
      unknownChina
      9808CMNET-GDGuangdongMobileCommunicationCoLtdCNfalse
      62.164.74.103
      unknownEuropean Union
      3215FranceTelecom-OrangeFRfalse
      96.214.8.34
      unknownUnited States
      7922COMCAST-7922USfalse
      35.75.148.43
      unknownUnited States
      16509AMAZON-02USfalse
      150.28.106.27
      unknownJapan6400CompaniaDominicanadeTelefonosSADOfalse
      188.171.85.0
      unknownSpain
      12946TELECABLESpainESfalse
      195.223.249.189
      unknownItaly
      3269ASN-IBSNAZITfalse
      122.228.142.227
      unknownChina
      134771CHINATELECOM-ZHEJIANG-WENZHOU-IDCWENZHOUZHEJIANGProvincefalse
      151.66.131.65
      unknownItaly
      1267ASN-WINDTREIUNETEUfalse
      69.111.100.175
      unknownUnited States
      7018ATT-INTERNET4USfalse
      48.127.151.199
      unknownUnited States
      2686ATGS-MMD-ASUSfalse
      183.219.95.180
      unknownChina
      9808CMNET-GDGuangdongMobileCommunicationCoLtdCNfalse
      175.151.3.87
      unknownChina
      4837CHINA169-BACKBONECHINAUNICOMChina169BackboneCNfalse
      106.97.89.34
      unknownKorea Republic of
      17853LGTELECOM-AS-KRLGTELECOMKRfalse
      177.70.86.139
      unknownBrazil
      28241ViaceuInternetLtdaBRfalse
      122.141.255.36
      unknownChina
      4837CHINA169-BACKBONECHINAUNICOMChina169BackboneCNfalse
      19.61.63.9
      unknownUnited States
      3MIT-GATEWAYSUSfalse
      20.231.37.46
      unknownUnited States
      8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
      103.55.103.150
      unknownIndia
      134287ODITEL-ASHBSTELESOFTPRIVATELIMITEDINfalse
      108.187.209.126
      unknownUnited States
      395954LEASEWEB-USA-LAX-11USfalse
      81.145.172.180
      unknownUnited Kingdom
      2856BT-UK-ASBTnetUKRegionalnetworkGBfalse
      200.104.46.31
      unknownChile
      22047VTRBANDAANCHASACLfalse
      199.13.187.26
      unknownUnited States
      1767ILIGHT-NETUSfalse
      125.50.51.101
      unknownJapan2516KDDIKDDICORPORATIONJPfalse
      154.10.23.54
      unknownKorea Republic of
      9578CJNET-ASCheiljedangCoIncKRfalse
      188.159.83.226
      unknownIran (ISLAMIC Republic Of)
      39501NGSASIRfalse
      196.203.212.60
      unknownTunisia
      37705TOPNETTNfalse
      164.117.114.31
      unknownUnited States
      10430WA-K20USfalse
      245.233.137.58
      unknownReserved
      unknownunknownfalse
      89.145.6.247
      unknownGermany
      21032TELTA-ASDEfalse
      152.223.4.199
      unknownUnited States
      30313IRSUSfalse
      208.40.58.167
      unknownUnited States
      2707FIRSTCOMM-AS1USfalse
      251.120.49.47
      unknownReserved
      unknownunknownfalse
      58.50.6.252
      unknownChina
      4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
      98.24.112.29
      unknownUnited States
      11426TWC-11426-CAROLINASUSfalse
      23.185.187.111
      unknownReserved
      395852MAYAVIRTUALUSfalse
      95.120.78.137
      unknownSpain
      3352TELEFONICA_DE_ESPANAESfalse
      27.12.165.27
      unknownChina
      4837CHINA169-BACKBONECHINAUNICOMChina169BackboneCNfalse
      108.224.250.142
      unknownUnited States
      7018ATT-INTERNET4USfalse
      167.245.159.43
      unknownUnited States
      13325STOMIUSfalse
      140.225.117.210
      unknownUnited States
      14763STKATEUSfalse
      70.3.61.223
      unknownUnited States
      10507SPCSUSfalse
      184.41.110.35
      unknownUnited States
      5778CENTURYLINK-LEGACY-EMBARQ-RCMTUSfalse
      200.13.169.205
      unknownEl Salvador
      27773MILLICOMCABLEELSALVADORSADECVSVfalse
      186.162.200.254
      unknownPeru
      21575ENTELPERUSAPEfalse
      83.58.127.193
      unknownSpain
      3352TELEFONICA_DE_ESPANAESfalse
      88.53.189.43
      unknownItaly
      3269ASN-IBSNAZITfalse
      20.113.107.40
      unknownUnited States
      8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
      133.4.126.109
      unknownJapan55384JAIST-EXPJapanAdvancedInstituteofScienceandTechnologyfalse
      5.54.192.234
      unknownGreece
      3329HOL-GRAthensGreeceGRfalse
      60.118.169.158
      unknownJapan17676GIGAINFRASoftbankBBCorpJPfalse
      1.33.224.54
      unknownJapan2514INFOSPHERENTTPCCommunicationsIncJPfalse
      74.83.24.194
      unknownUnited States
      6181FUSE-NETUSfalse
      61.131.79.82
      unknownChina
      4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
      73.161.162.133
      unknownUnited States
      7922COMCAST-7922USfalse
      91.183.209.23
      unknownBelgium
      5432PROXIMUS-ISP-ASBEfalse
      125.129.154.21
      unknownKorea Republic of
      4766KIXS-AS-KRKoreaTelecomKRfalse
      68.77.71.187
      unknownUnited States
      7018ATT-INTERNET4USfalse
      176.18.0.199
      unknownSaudi Arabia
      35819MOBILY-ASEtihadEtisalatCompanyMobilySAfalse
      39.156.253.132
      unknownChina
      9808CMNET-GDGuangdongMobileCommunicationCoLtdCNfalse
      48.87.182.58
      unknownUnited States
      2686ATGS-MMD-ASUSfalse
      201.215.141.120
      unknownChile
      22047VTRBANDAANCHASACLfalse
      139.176.251.99
      unknownChina
      8968BT-ITALIAITfalse
      190.231.134.219
      unknownArgentina
      7303TelecomArgentinaSAARfalse
      74.109.162.7
      unknownUnited States
      701UUNETUSfalse
      41.85.112.180
      unknownSouth Africa
      328418Olena-Trading-ASZAfalse
      123.25.106.121
      unknownViet Nam
      45899VNPT-AS-VNVNPTCorpVNfalse
      156.56.100.67
      unknownUnited States
      87INDIANA-ASUSfalse
      176.110.67.119
      unknownRussian Federation
      49483SKATISPRUfalse
      92.125.247.228
      unknownRussian Federation
      12389ROSTELECOM-ASRUfalse
      244.205.158.22
      unknownReserved
      unknownunknownfalse
      148.105.157.149
      unknownUnited States
      14782THEROCKETSCIENCEGROUPUSfalse
      71.66.122.189
      unknownUnited States
      10796TWC-10796-MIDWESTUSfalse
      87.188.233.62
      unknownGermany
      3320DTAGInternetserviceprovideroperationsDEfalse
      34.223.35.232
      unknownUnited States
      16509AMAZON-02USfalse
      205.228.212.51
      unknownUnited States
      5049MORGAN-ASNUSfalse
      75.46.199.141
      unknownUnited States
      7018ATT-INTERNET4USfalse
      83.97.138.69
      unknownSpain
      12946TELECABLESpainESfalse
      122.59.198.123
      unknownNew Zealand
      4771SPARKNZSparkNewZealandTradingLtdNZfalse


      Runtime Messages

      Command:/tmp/1Zn1o0ho0d
      Exit Code:0
      Exit Code Info:
      Killed:False
      Standard Output:
      Connected To CNC
      Standard Error:

      Joe Sandbox View / Context

      IPs

      MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
      62.164.74.103WQB6HkuyxCGet hashmaliciousBrowse
        35.75.148.43Af1Fnq4I4GGet hashmaliciousBrowse

          Domains

          No context

          ASN

          MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
          MundivoxLTDABRsora.arm7Get hashmaliciousBrowse
          • 177.124.236.172
          mipsGet hashmaliciousBrowse
          • 187.16.113.48
          EKDuLCqKpg.dllGet hashmaliciousBrowse
          • 187.102.147.122
          ZXuptcXTmxGet hashmaliciousBrowse
          • 177.92.82.94
          COBxDiCIPE.exeGet hashmaliciousBrowse
          • 179.191.108.58
          10.dllGet hashmaliciousBrowse
          • 179.191.108.58
          Upload_1624615171_1216115197.xlsGet hashmaliciousBrowse
          • 179.191.108.58
          Attach_356001541_2141808015.xlsGet hashmaliciousBrowse
          • 179.191.108.58
          TDCS.dllGet hashmaliciousBrowse
          • 179.191.108.58
          attach-543652551.xlsGet hashmaliciousBrowse
          • 200.142.124.146
          attach-652257188.xlsGet hashmaliciousBrowse
          • 200.142.124.146
          CaAmqz52Yk.exeGet hashmaliciousBrowse
          • 200.142.124.146
          pNadrQriqg.exeGet hashmaliciousBrowse
          • 179.191.108.58
          DmGtMcOds3.exeGet hashmaliciousBrowse
          • 179.191.108.58
          wtROGJDiTf.exeGet hashmaliciousBrowse
          • 179.191.108.58
          hFsSNJ3Bvz.exeGet hashmaliciousBrowse
          • 179.191.108.58
          opgVccK0a8.exeGet hashmaliciousBrowse
          • 200.142.124.146
          70v7Etudwj.exeGet hashmaliciousBrowse
          • 200.142.124.146
          KNJ725Xas2.exeGet hashmaliciousBrowse
          • 200.142.124.146
          ix2e10rs2C.exeGet hashmaliciousBrowse
          • 200.142.124.146
          HRNETFRRSDka7Gji5Get hashmaliciousBrowse
          • 212.94.221.131
          ROGERS-COMMUNICATIONSCAmL883e3xGwGet hashmaliciousBrowse
          • 99.243.29.47
          Tx60OCR2cNGet hashmaliciousBrowse
          • 99.251.250.119
          b3astmode.x86Get hashmaliciousBrowse
          • 99.255.49.25
          cavEG2l8fjGet hashmaliciousBrowse
          • 97.111.105.237
          sora.armGet hashmaliciousBrowse
          • 99.248.33.110
          sora.x86Get hashmaliciousBrowse
          • 97.110.251.226
          sora.mpslGet hashmaliciousBrowse
          • 99.218.74.87
          sora.x86Get hashmaliciousBrowse
          • 99.251.27.120
          sora.mipsGet hashmaliciousBrowse
          • 99.215.192.252
          arm5-20211102-0937Get hashmaliciousBrowse
          • 155.194.207.211
          BsXhIyIHzCGet hashmaliciousBrowse
          • 99.216.134.212
          aTQ4RalkUsGet hashmaliciousBrowse
          • 173.34.176.20
          uohdbohpYbGet hashmaliciousBrowse
          • 99.224.248.159
          oiHTZaiKnIGet hashmaliciousBrowse
          • 99.247.72.198
          8PRjJeUifBGet hashmaliciousBrowse
          • 99.221.167.194
          ENYxttDmO1Get hashmaliciousBrowse
          • 174.119.142.92
          7DoAjWX5uZGet hashmaliciousBrowse
          • 99.226.225.108
          arH2Af5qocGet hashmaliciousBrowse
          • 173.41.116.41
          FGVOkw9didGet hashmaliciousBrowse
          • 99.239.140.165
          mipselGet hashmaliciousBrowse
          • 99.215.192.245
          TELEPORTSPB-ASRUjJ6GK5qbZtGet hashmaliciousBrowse
          • 94.247.246.90
          8EddA0qHLYGet hashmaliciousBrowse
          • 94.247.246.88
          7bpQf4H7leGet hashmaliciousBrowse
          • 94.247.246.87
          hv1VTJx1nSGet hashmaliciousBrowse
          • 94.247.246.67
          488q2VlrrnGet hashmaliciousBrowse
          • 94.247.246.51
          GSJ1vGT2WQGet hashmaliciousBrowse
          • 94.247.246.57
          popsmoke.mpslGet hashmaliciousBrowse
          • 94.247.246.82
          wataniya-telecom-asDZmltqanainst.exeGet hashmaliciousBrowse
          • 105.235.128.86

          JA3 Fingerprints

          No context

          Dropped Files

          No context

          Created / dropped Files

          /proc/5363/oom_score_adj
          Process:/usr/sbin/sshd
          File Type:ASCII text
          Category:dropped
          Size (bytes):6
          Entropy (8bit):1.7924812503605778
          Encrypted:false
          SSDEEP:3:ptn:Dn
          MD5:CBF282CC55ED0792C33D10003D1F760A
          SHA1:007DD8BD75468E6B7ABA4285E9B267202C7EAEED
          SHA-256:FCDBAB99FCC0F4409E5F9D7D6FC497780288B4C441698126BB62832412774D22
          SHA-512:4643A8675D213C7DA35CC0C2BFB3B6F20324F9C48AEA7BA79F470615698C9A0CEFDA45CAA1957FC29110EE746BC8458AB8AB1E43EB513912A5E1E8858812CC00
          Malicious:false
          Reputation:high, very likely benign file
          Preview: -1000.
          /run/sshd.pid
          Process:/usr/sbin/sshd
          File Type:ASCII text
          Category:dropped
          Size (bytes):5
          Entropy (8bit):1.9219280948873623
          Encrypted:false
          SSDEEP:3:DTWv:Po
          MD5:8C860A10AEE8D3784E2C15B2F713F88C
          SHA1:16474DDF36C7BBEE868CF794185342CDFA76E744
          SHA-256:DC4E490E080F690198F7C015FD79AC89180E167C0681CA057DA27C25F2C1E044
          SHA-512:2386BB3E431769603F7C7C41D786A3562DB5A62C687456C997CF526C7C0463C147704ED87A1DFE6A3560D93A965A51C4459C1393575010D89EA6126DAEC1346E
          Malicious:false
          Reputation:low
          Preview: 5363.
          /var/cache/man/5300
          Process:/usr/bin/mandb
          File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
          Category:dropped
          Size (bytes):622592
          Entropy (8bit):4.657516417799966
          Encrypted:false
          SSDEEP:6144:rb7cWWov4H5N80nuDSyvxYCWZ0/VmpRELAR/QuU/MzUCl1NZ:H4WWoGgvSiOp2kl
          MD5:0C99179B6C5CFE82203424AD7DAD0D8F
          SHA1:CAC50B64B1352723FF8F58BB1B103B93C396539B
          SHA-256:CEC6859D12C6A981ACA4D7C88F6E62E9616FB4D765C4A52147A7DA7BAD4F2420
          SHA-512:4226FDE9F558FFEF2107C330DB942E7E665C51C520A840221541AD255D0995AF64101C69D42C4BD43037364CC4D152851625A53DC56CC188DC28A3DC8C5602F6
          Malicious:false
          Reputation:moderate, very likely benign file
          Preview: .W.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
          /var/cache/man/cs/5300
          Process:/usr/bin/mandb
          File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
          Category:dropped
          Size (bytes):16384
          Entropy (8bit):1.6070136442091312
          Encrypted:false
          SSDEEP:48:bhVGQeUzGLIsWUMZJ5CggJHtheYdiKNHTlJ8NK:bhVGaGLIWMZXZgxeYtzll
          MD5:D0CA2EBA9E7A17D4680AA9DDC5F88946
          SHA1:270F443EFF85209052AE8FFA86660AFB0FAAD39B
          SHA-256:9504DC65F8B4E057D0939FA3B2C640FC703D0290EE19381836BAA5EB3EFBADBD
          SHA-512:9F999B0467E396E78A91F0BFE56E191DB9D9AFA6DC47858F3427CB44A39D5A13A206542A471CE15C8851674A234B9A7A49AAB7E6D5AF8D080BBC99C2BA3C56D8
          Malicious:false
          Reputation:moderate, very likely benign file
          Preview: .W..............................@......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
          /var/cache/man/cs/index.db.Onw9QX
          Process:/usr/bin/mandb
          File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
          Category:dropped
          Size (bytes):16384
          Entropy (8bit):0.45676214072558463
          Encrypted:false
          SSDEEP:12:Ey20ypjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjj3:bh
          MD5:EE429C7E8B222AFF73C611A8C358B661
          SHA1:DA353E80DCF1195F259CCBC32D39F5923710453F
          SHA-256:BDAAC26D90701E063943763B7CBD9204B6F0007C6F1BCA3C7B4FE3B09CDF6091
          SHA-512:DC651AF7AEB4A64C63986100E416A7DA4782678497B73F1CE42536DE02DB9E4115748881A56B86EC5B12E34C9FDF829BD194BEA7790FDCA7B2F5178A24930809
          Malicious:false
          Reputation:moderate, very likely benign file
          Preview: .W..............................@......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
          /var/cache/man/da/5300
          Process:/usr/bin/mandb
          File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
          Category:dropped
          Size (bytes):16384
          Entropy (8bit):2.24195239843379
          Encrypted:false
          SSDEEP:96:bhHY2DzMnpU0QMiloesQdUTn3WVE0UnknJfsWdv0SBpEVvsb6eZeGfRL+:dYKM+oagn3WW5nkniWdv0SAVE6eZee6
          MD5:4DF08004EE4C5384C02376841F2B50BC
          SHA1:C02E58212CA012913390B4C1CCD64DD3353009EE
          SHA-256:F4D6A62A734E2844B99F3AD0EB480373AFBE56B29C0CFC9C70D9DFDF19D95C02
          SHA-512:6146001CA7028F58595235F244AE8FC4ECAEA3E95C83276514FC704E91B7596678E74CDE9963D680F2493F9C04AFDEBC4DB5094E2AB7C1A949E9378307AE0116
          Malicious:false
          Reputation:moderate, very likely benign file
          Preview: .W..............................@......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
          /var/cache/man/da/index.db.FoOYaW
          Process:/usr/bin/mandb
          File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
          Category:dropped
          Size (bytes):16384
          Entropy (8bit):0.45676214072558463
          Encrypted:false
          SSDEEP:12:Ey20ypjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjj3:bh
          MD5:EE429C7E8B222AFF73C611A8C358B661
          SHA1:DA353E80DCF1195F259CCBC32D39F5923710453F
          SHA-256:BDAAC26D90701E063943763B7CBD9204B6F0007C6F1BCA3C7B4FE3B09CDF6091
          SHA-512:DC651AF7AEB4A64C63986100E416A7DA4782678497B73F1CE42536DE02DB9E4115748881A56B86EC5B12E34C9FDF829BD194BEA7790FDCA7B2F5178A24930809
          Malicious:false
          Reputation:moderate, very likely benign file
          Preview: .W..............................@......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
          /var/cache/man/de/5300
          Process:/usr/bin/mandb
          File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
          Category:dropped
          Size (bytes):45056
          Entropy (8bit):4.16308917006812
          Encrypted:false
          SSDEEP:768:gMGrknsA3KVtOOcmGMrTJDEEf5RPOH/iVDdtq5:/GrkncXD+qwH/GLq
          MD5:43F277369443EBC4DF558940CC383C81
          SHA1:F9A8BDDCF57AE12FC0E04D6C1C6EF1066995817A
          SHA-256:A4039029DD3E83F746E70009F20A1E8E788101944B494F13ADD0660220D14F84
          SHA-512:E852317CCA9B4FD5CAEC15E91F6D54DB4D8DA396666153B96E2502253AC67816BB4BD13A2653FE1A4AD846471B249A84298C3F26A16E13382AA28BA2EBDD858A
          Malicious:false
          Preview: .W.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
          /var/cache/man/de/index.db.QGw5IY
          Process:/usr/bin/mandb
          File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
          Category:dropped
          Size (bytes):45056
          Entropy (8bit):0.20558603354177746
          Encrypted:false
          SSDEEP:12:Ey20ypjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjj3:bh
          MD5:55880A8B73FD160B73198E09A21C83DB
          SHA1:5EB780702D2501747AF46F7525EF5C635EC5E64C
          SHA-256:66BD4C98AF40E2E208AC102ACD0F555A6C118E7258D91B833BE1D53EBFFB7BBB
          SHA-512:388924B8CAE80CCA6CA8E5109D0239A963A66CC0454450223EC7FB2A188F6F05E49632E535DC06E49DF6D007B221AA6B3D5F23C80203BCC861FF95EFA10AC1F9
          Malicious:false
          Preview: .W..............................@......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
          /var/cache/man/es/5300
          Process:/usr/bin/mandb
          File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
          Category:dropped
          Size (bytes):20480
          Entropy (8bit):2.469907427008948
          Encrypted:false
          SSDEEP:96:bhj9SeW/8iDdO/tktuGWTaZxzn3zbHGc2WjAXGBCgfd6Dgzs30z8ztvpWF4DXst:99PGo9Tmn3zbNBSw/fd6Oz8ztQSDXo
          MD5:3DBF4FF017D406F407BFBC2011BCAE9E
          SHA1:FF64864ACA18DFA7869715CE8AA5ECC3DABA54B6
          SHA-256:640C040F364061A5825E913682798C9BC8E1081088894D3FEB2C3EC39D02A379
          SHA-512:3DCC8F432487C532A1F69D321EB57EFE5CFE65AA3C99B81EA1A56613F8F460EA9ED7D2031615F2E60A3F2EE279D411848E5387CC8B8D5F28D8F8D0055D72489B
          Malicious:false
          Preview: .W..............................P......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
          /var/cache/man/es/index.db.dgcKLV
          Process:/usr/bin/mandb
          File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
          Category:dropped
          Size (bytes):20480
          Entropy (8bit):0.3847690842836057
          Encrypted:false
          SSDEEP:12:Ey20ypjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjj3:bh
          MD5:F0B902DEA5EF122A0B1F0F496DDC781B
          SHA1:90176D320A9C3601787D53CC346DC743367D53F1
          SHA-256:CFD64D42263C5D323AF423FC09CDB5DDB2F914114B87BAB6566EAB1020F15DE0
          SHA-512:3A5BC0E51D53A12E65441FB98E1201DC434C42DB389CFCA4C96FF65C2413CF9B06B29CC39A48BD3FDC61F4896396813E54B9C2CE404EF35AC33B35377E718874
          Malicious:false
          Preview: .W..............................@......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
          /var/cache/man/fi/5300
          Process:/usr/bin/mandb
          File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
          Category:dropped
          Size (bytes):16384
          Entropy (8bit):0.5882948808594274
          Encrypted:false
          SSDEEP:12:Ey20yaajjjjjjjjjjjjjjjjjjjjjjjjjjGjjjjjjjjjjjjjjjjjjjjjjjjjjjjjp:bhjz+9Ab
          MD5:09F6ED1A60B8A4203EA97CF5926C6AFF
          SHA1:C28F4E393D55AD057E3C7608741904B796F67076
          SHA-256:56664D61D0BB8BF34CCA28C73CB314CB73EA1C4FAC64D2208B43F63C009FC855
          SHA-512:476EAE37D827C8BB322213799AB52DBE8FA43274DB3447BC5FEDFED64ECCEAF2C11DA375FDA09B37977D03CA1910E22443B22A3EEA875CE6F3BC698F8ADCC0E2
          Malicious:false
          Preview: .W..............................@......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
          /var/cache/man/fi/index.db.W1gZ9W
          Process:/usr/bin/mandb
          File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
          Category:dropped
          Size (bytes):16384
          Entropy (8bit):0.45676214072558463
          Encrypted:false
          SSDEEP:12:Ey20ypjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjj3:bh
          MD5:EE429C7E8B222AFF73C611A8C358B661
          SHA1:DA353E80DCF1195F259CCBC32D39F5923710453F
          SHA-256:BDAAC26D90701E063943763B7CBD9204B6F0007C6F1BCA3C7B4FE3B09CDF6091
          SHA-512:DC651AF7AEB4A64C63986100E416A7DA4782678497B73F1CE42536DE02DB9E4115748881A56B86EC5B12E34C9FDF829BD194BEA7790FDCA7B2F5178A24930809
          Malicious:false
          Preview: .W..............................@......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
          /var/cache/man/fr.ISO8859-1/5300
          Process:/usr/bin/mandb
          File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
          Category:dropped
          Size (bytes):16384
          Entropy (8bit):0.9312184489410064
          Encrypted:false
          SSDEEP:12:Ey20yIpyjjjjjjjjjjjjjjjjjjjjjjjjXjjjjjjjjjjjjjjjjjjjjjjjjjjjjGz7:bhbpFi043WmkN2GmGufUeDDx+yxrq3
          MD5:43ADE2E40B8B5A0DFA0A155FC9A02F7F
          SHA1:3D04BDFFD0E2A8433150C87D334014099336A5C5
          SHA-256:81E48EE4653A5E6F25C33133F24F045EB1EB2CC6724ECE0C5336612AB711273E
          SHA-512:C9C5C436A0E986A39CE3FA1CAF15A92D509F4450744BAE0283204B58CDD6FE9B8EEB8D3E2CAFB4B1ACB46729317FFAEFE86B0DD2D60472CAB30B204CC2003B03
          Malicious:false
          Preview: .W..............................@......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
          /var/cache/man/fr.ISO8859-1/index.db.uzjeWY
          Process:/usr/bin/mandb
          File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
          Category:dropped
          Size (bytes):16384
          Entropy (8bit):0.45676214072558463
          Encrypted:false
          SSDEEP:12:Ey20ypjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjj3:bh
          MD5:EE429C7E8B222AFF73C611A8C358B661
          SHA1:DA353E80DCF1195F259CCBC32D39F5923710453F
          SHA-256:BDAAC26D90701E063943763B7CBD9204B6F0007C6F1BCA3C7B4FE3B09CDF6091
          SHA-512:DC651AF7AEB4A64C63986100E416A7DA4782678497B73F1CE42536DE02DB9E4115748881A56B86EC5B12E34C9FDF829BD194BEA7790FDCA7B2F5178A24930809
          Malicious:false
          Preview: .W..............................@......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
          /var/cache/man/fr.UTF-8/5300
          Process:/usr/bin/mandb
          File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
          Category:dropped
          Size (bytes):16384
          Entropy (8bit):0.9312184489410064
          Encrypted:false
          SSDEEP:12:Ey20yIpyjjjjjjjjjjjjjjjjjjjjjjjjXjjjjjjjjjjjjjjjjjjjjjjjjjjjjGz7:bhbpFi043WmkN2GmGufUeDDx+yxrq3
          MD5:43ADE2E40B8B5A0DFA0A155FC9A02F7F
          SHA1:3D04BDFFD0E2A8433150C87D334014099336A5C5
          SHA-256:81E48EE4653A5E6F25C33133F24F045EB1EB2CC6724ECE0C5336612AB711273E
          SHA-512:C9C5C436A0E986A39CE3FA1CAF15A92D509F4450744BAE0283204B58CDD6FE9B8EEB8D3E2CAFB4B1ACB46729317FFAEFE86B0DD2D60472CAB30B204CC2003B03
          Malicious:false
          Preview: .W..............................@......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
          /var/cache/man/fr.UTF-8/index.db.WXxpwV
          Process:/usr/bin/mandb
          File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
          Category:dropped
          Size (bytes):16384
          Entropy (8bit):0.45676214072558463
          Encrypted:false
          SSDEEP:12:Ey20ypjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjj3:bh
          MD5:EE429C7E8B222AFF73C611A8C358B661
          SHA1:DA353E80DCF1195F259CCBC32D39F5923710453F
          SHA-256:BDAAC26D90701E063943763B7CBD9204B6F0007C6F1BCA3C7B4FE3B09CDF6091
          SHA-512:DC651AF7AEB4A64C63986100E416A7DA4782678497B73F1CE42536DE02DB9E4115748881A56B86EC5B12E34C9FDF829BD194BEA7790FDCA7B2F5178A24930809
          Malicious:false
          Preview: .W..............................@......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
          /var/cache/man/fr/5300
          Process:/usr/bin/mandb
          File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
          Category:dropped
          Size (bytes):40960
          Entropy (8bit):3.8302677941620926
          Encrypted:false
          SSDEEP:768:A4VX6Bd+dla5HmdT8qHl87BaIPay4uz8HksyHnwNO:A4ROd+dStM83PavyHC
          MD5:7A052312252F87BF6BE0F2A7518CE338
          SHA1:8DF54AE5912234E4FCD10CC9338B943CDA07B0BB
          SHA-256:8F7B2A71FCFE0C95CD34635429EB16BB0C81F170F6DCAFF8BF58DDB42D1DCE46
          SHA-512:D5107E6C9E93A31B396EE8116BF9ADD46665F155BB66D33CAFFE574940E5468302105FA10C16562192035E1BCB6E523A1ADC2075ABC70CA6E50E1B3220A7E982
          Malicious:false
          Preview: .W.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
          /var/cache/man/fr/index.db.7Jfu6Y
          Process:/usr/bin/mandb
          File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
          Category:dropped
          Size (bytes):40960
          Entropy (8bit):0.22208993462959856
          Encrypted:false
          SSDEEP:12:Ey20ypjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjj3:bh
          MD5:425CB57CD9B42556C8089FE7A7A3E495
          SHA1:4F33F9A9897218FDED958FD8F8D7AF7CD8BC48F3
          SHA-256:85E01EFF2AC0C83C827E118D5CE2CD1E1A19E059688B6E0D09CB3CC131F065D3
          SHA-512:8C7D4DACF5C5C5C4B78775048427AF99ED8057590AA3A69FD5B3F875B6DDD249A6DB0AF3A51BB96A7F629D1017B272317583A8DFF89FB3968FFE2F246F040F33
          Malicious:false
          Preview: .W..............................@......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
          /var/cache/man/hu/5300
          Process:/usr/bin/mandb
          File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
          Category:dropped
          Size (bytes):16384
          Entropy (8bit):0.9419610786280751
          Encrypted:false
          SSDEEP:24:bh04IR9rYz9kvNQFl46MdnqfPE9eTuF0Ce:bhXIHakVQmnqXqeT/Ce
          MD5:18F02B57872A97DE1E82FF5348A5AF1B
          SHA1:52F332343B120B1C950AC02B3C923556C70DC62A
          SHA-256:5C605DE68B3E05754698485F73413F4052AEA8C3AAE6012AC6416B3B6B056DF7
          SHA-512:E33A8412F52D26BDE55E4D72E0D9D09EB777F4B882F5BB1C4625AB392EE321D6ACD8795001BF50CCDACFAC131A1263B1398F208799F753554C43349136EB8BEC
          Malicious:false
          Preview: .W..............................@......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
          /var/cache/man/hu/index.db.QlkYJY
          Process:/usr/bin/mandb
          File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
          Category:dropped
          Size (bytes):16384
          Entropy (8bit):0.45676214072558463
          Encrypted:false
          SSDEEP:12:Ey20ypjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjj3:bh
          MD5:EE429C7E8B222AFF73C611A8C358B661
          SHA1:DA353E80DCF1195F259CCBC32D39F5923710453F
          SHA-256:BDAAC26D90701E063943763B7CBD9204B6F0007C6F1BCA3C7B4FE3B09CDF6091
          SHA-512:DC651AF7AEB4A64C63986100E416A7DA4782678497B73F1CE42536DE02DB9E4115748881A56B86EC5B12E34C9FDF829BD194BEA7790FDCA7B2F5178A24930809
          Malicious:false
          Preview: .W..............................@......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
          /var/cache/man/id/5300
          Process:/usr/bin/mandb
          File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
          Category:dropped
          Size (bytes):16384
          Entropy (8bit):1.309811236154278
          Encrypted:false
          SSDEEP:48:bhESUeDVrWTVd5ekRv/KSmGWqR0VouC4btU8IzTC74ExJKGtII:bhEVeBqTVdAcn3Iowl4UBtx
          MD5:3AFDA1B0F729816929FF7A6628D776D5
          SHA1:5982940A5782F11AEB5BF859C055DE3FEFBDF5DB
          SHA-256:77809D5F38F6D96A2E8BA9BE0DFBB16C10B6B1FF7D2BA1DD5FB9437F73C47E7F
          SHA-512:6D4CE03475C68EDC0AE928E7F65BB8C06198721146A1266F55455AF3D5E24F44A569E007C0DC44BC7745C1573DBC7F02B8C4094F9BD97FAF6A0B5894BE0E07E5
          Malicious:false
          Preview: .W..............................@......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
          /var/cache/man/id/index.db.ynpWnW
          Process:/usr/bin/mandb
          File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
          Category:dropped
          Size (bytes):16384
          Entropy (8bit):0.45676214072558463
          Encrypted:false
          SSDEEP:12:Ey20ypjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjj3:bh
          MD5:EE429C7E8B222AFF73C611A8C358B661
          SHA1:DA353E80DCF1195F259CCBC32D39F5923710453F
          SHA-256:BDAAC26D90701E063943763B7CBD9204B6F0007C6F1BCA3C7B4FE3B09CDF6091
          SHA-512:DC651AF7AEB4A64C63986100E416A7DA4782678497B73F1CE42536DE02DB9E4115748881A56B86EC5B12E34C9FDF829BD194BEA7790FDCA7B2F5178A24930809
          Malicious:false
          Preview: .W..............................@......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
          /var/cache/man/index.db.I1I3AY
          Process:/usr/bin/mandb
          File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
          Category:dropped
          Size (bytes):622592
          Entropy (8bit):0.022159377425242585
          Encrypted:false
          SSDEEP:12:Ey20ypjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjj3:bh
          MD5:2E442DBA85DEDFDCB07090FDF9DE90D0
          SHA1:02658086E93854D13D82B1F0D80F4B78D26DCA51
          SHA-256:62406BFE7657964E490DE65A0007F7C1D59B62B2B9AD35BA55BA219673378848
          SHA-512:FDBBA0DEF310CF7DBF448CFB6E5C9CDCEFBF6A0CAEB26CA3AFA91A388FBA10A9E77BCC27CA9B0AEA2A7B67F964849E147FB44862C7394C2C7CDCB572C06FCB05
          Malicious:false
          Preview: .W..............................@......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
          /var/cache/man/it/5300
          Process:/usr/bin/mandb
          File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
          Category:dropped
          Size (bytes):20480
          Entropy (8bit):3.3621193886235408
          Encrypted:false
          SSDEEP:384:Jtp0q5d98n3SaMfhtxfmbMy+HseeNwoMbHf:JDd9QSBf
          MD5:B228DE097081AF360D337CF8C8FF2C6F
          SHA1:7DD2C4640925B225F98014566F73C35F4E960940
          SHA-256:1056CECADA78542B173EE469C9BEAF61F81298EBBD21B54EA6EE449028E18B3F
          SHA-512:F61D7F9040E452C4B1B77F3657BE4252475C3BF23D78EED903A5E55FA97BA0571BA3AD90DBA7F77C334DF5B721F909B12720515034421A4AAB0450D1D43B32E4
          Malicious:false
          Preview: .W..............................P......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
          /var/cache/man/it/index.db.Exq1YX
          Process:/usr/bin/mandb
          File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
          Category:dropped
          Size (bytes):20480
          Entropy (8bit):0.3847690842836057
          Encrypted:false
          SSDEEP:12:Ey20ypjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjj3:bh
          MD5:F0B902DEA5EF122A0B1F0F496DDC781B
          SHA1:90176D320A9C3601787D53CC346DC743367D53F1
          SHA-256:CFD64D42263C5D323AF423FC09CDB5DDB2F914114B87BAB6566EAB1020F15DE0
          SHA-512:3A5BC0E51D53A12E65441FB98E1201DC434C42DB389CFCA4C96FF65C2413CF9B06B29CC39A48BD3FDC61F4896396813E54B9C2CE404EF35AC33B35377E718874
          Malicious:false
          Preview: .W..............................@......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
          /var/cache/man/ja/5300
          Process:/usr/bin/mandb
          File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
          Category:dropped
          Size (bytes):20480
          Entropy (8bit):3.667488020062395
          Encrypted:false
          SSDEEP:192:CF4pPRfAgFn35FF1veUMjGiEGBuPhiB0PUKwA+U:5PRfAgFn35MSeAPUjN
          MD5:D3CD7D67F8155491493BB7235FB9AA57
          SHA1:5A7AE62A7AFE50EFCCED06CBD56AE2A0A284EFF3
          SHA-256:6958349ECA637F99AABC419B5E402CFB50BC5B8867F31BCB67F064F47A209929
          SHA-512:1168BF697CDE563F7D82A71EAE1CD496EA81D178B26F87EAAF2EDEED13274B1E3500CE1C981647717598495EBE1FF8F8AC54AD33547506E566C925D7002F5CFF
          Malicious:false
          Preview: .W..............................P......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
          /var/cache/man/ja/index.db.JI89oW
          Process:/usr/bin/mandb
          File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
          Category:dropped
          Size (bytes):20480
          Entropy (8bit):0.3847690842836057
          Encrypted:false
          SSDEEP:12:Ey20ypjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjj3:bh
          MD5:F0B902DEA5EF122A0B1F0F496DDC781B
          SHA1:90176D320A9C3601787D53CC346DC743367D53F1
          SHA-256:CFD64D42263C5D323AF423FC09CDB5DDB2F914114B87BAB6566EAB1020F15DE0
          SHA-512:3A5BC0E51D53A12E65441FB98E1201DC434C42DB389CFCA4C96FF65C2413CF9B06B29CC39A48BD3FDC61F4896396813E54B9C2CE404EF35AC33B35377E718874
          Malicious:false
          Preview: .W..............................@......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
          /var/cache/man/ko/5300
          Process:/usr/bin/mandb
          File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
          Category:dropped
          Size (bytes):16384
          Entropy (8bit):0.7847786157292606
          Encrypted:false
          SSDEEP:12:Ey20yYn0jjjjjjjjjjjjjjjjjjjjjjjjjjGjjjjjjjjjjjjjjjjjjjjjjjjjmjj7:bhXYznMk31RFe6f
          MD5:FBA25855E1C99D8F87E8AC13E2E2ECB1
          SHA1:D99351AC40D6CC4C9BE54E0E018C44A9A88983D7
          SHA-256:C0E18ED1CEFF427FD4D57D1B79CE1AF7320AC8453BAF8A0349C08267464C4D71
          SHA-512:0969DF6506E083A4995A18518BC3C4472157E7790EEC26C08221B0FC6DE9C7DA0ADB11CF92C56BC35B89BC60447F3D991F935E352552B58FB9BD1D4B2579FBB0
          Malicious:false
          Preview: .W..............................@......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
          /var/cache/man/ko/index.db.swYhLW
          Process:/usr/bin/mandb
          File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
          Category:dropped
          Size (bytes):16384
          Entropy (8bit):0.45676214072558463
          Encrypted:false
          SSDEEP:12:Ey20ypjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjj3:bh
          MD5:EE429C7E8B222AFF73C611A8C358B661
          SHA1:DA353E80DCF1195F259CCBC32D39F5923710453F
          SHA-256:BDAAC26D90701E063943763B7CBD9204B6F0007C6F1BCA3C7B4FE3B09CDF6091
          SHA-512:DC651AF7AEB4A64C63986100E416A7DA4782678497B73F1CE42536DE02DB9E4115748881A56B86EC5B12E34C9FDF829BD194BEA7790FDCA7B2F5178A24930809
          Malicious:false
          Preview: .W..............................@......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
          /var/cache/man/nl/5300
          Process:/usr/bin/mandb
          File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
          Category:dropped
          Size (bytes):16384
          Entropy (8bit):2.554204221242331
          Encrypted:false
          SSDEEP:192:H8Y5a2oquB2aCYn3lvu3whjXVobdbs7dq1KJGbtf0Hoa:hoquYaCYn3Q8jXqbdbs7dGbKHoa
          MD5:27FED1CA8EB0101C459D9A617C833293
          SHA1:503B2A3E33FE79FF2CD58F831ED33DB358849BEA
          SHA-256:C3033C4F7CF0D6108611EF5A62CA893F98EE6463DDCFF7100D3BAFDEB0036D9E
          SHA-512:7BD630F5E0C5A91C34D2E48D0053923C9F2F5BAA07D21FDA79E60F3AFDF759E594E6639562C1F3EE68DD080D417009DC3AFB7DA534E3B8C29FF7B10438C3FD4E
          Malicious:false
          Preview: .W..............................@......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
          /var/cache/man/nl/index.db.sJMmVV
          Process:/usr/bin/mandb
          File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
          Category:dropped
          Size (bytes):16384
          Entropy (8bit):0.45676214072558463
          Encrypted:false
          SSDEEP:12:Ey20ypjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjj3:bh
          MD5:EE429C7E8B222AFF73C611A8C358B661
          SHA1:DA353E80DCF1195F259CCBC32D39F5923710453F
          SHA-256:BDAAC26D90701E063943763B7CBD9204B6F0007C6F1BCA3C7B4FE3B09CDF6091
          SHA-512:DC651AF7AEB4A64C63986100E416A7DA4782678497B73F1CE42536DE02DB9E4115748881A56B86EC5B12E34C9FDF829BD194BEA7790FDCA7B2F5178A24930809
          Malicious:false
          Preview: .W..............................@......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
          /var/cache/man/pl/5300
          Process:/usr/bin/mandb
          File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
          Category:dropped
          Size (bytes):20480
          Entropy (8bit):2.880948418505059
          Encrypted:false
          SSDEEP:192:7Sf8026LXqn3ZTV6pXAmA44BRqvc3X3GVAjvAk/AvdWjWftxA:E802uXqn3/6pxARqr8kdWjW1
          MD5:37CEBCD3F5BF6322785FFF568EE33131
          SHA1:201298C827C77C60CD314BF721DC4C27EF95BD64
          SHA-256:012C5597C5DD8654EB14432AFCEFD9B131F2CE75AD21488991A5A688929AAEA6
          SHA-512:CCC8A8CCF4ACA332CAF610155DE9E7C4A12D1C45C98D20766B86098A3D2EF332189F159E3956944CD302DF652FE7A6F0D07CA39CBE7DF4A655D3211452487582
          Malicious:false
          Preview: .W..............................P......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
          /var/cache/man/pl/index.db.u4IrDY
          Process:/usr/bin/mandb
          File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
          Category:dropped
          Size (bytes):20480
          Entropy (8bit):0.3847690842836057
          Encrypted:false
          SSDEEP:12:Ey20ypjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjj3:bh
          MD5:F0B902DEA5EF122A0B1F0F496DDC781B
          SHA1:90176D320A9C3601787D53CC346DC743367D53F1
          SHA-256:CFD64D42263C5D323AF423FC09CDB5DDB2F914114B87BAB6566EAB1020F15DE0
          SHA-512:3A5BC0E51D53A12E65441FB98E1201DC434C42DB389CFCA4C96FF65C2413CF9B06B29CC39A48BD3FDC61F4896396813E54B9C2CE404EF35AC33B35377E718874
          Malicious:false
          Preview: .W..............................@......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
          /var/cache/man/pt/5300
          Process:/usr/bin/mandb
          File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
          Category:dropped
          Size (bytes):20480
          Entropy (8bit):2.4110695640960995
          Encrypted:false
          SSDEEP:192:mva8yGn35+0+eo8TAnBW4VppKP8qtRJI:Sa8Rn35+peo8T8V/fqlI
          MD5:782FF89B6FA5932F7019AF9CF3F82E43
          SHA1:2ECE8DC134E3A292E2545AA2DCD24114A5FC5749
          SHA-256:01E77D9235C524F2A61EA03953607C13831C391A5B9AB0D9094F9C38F0EEB02E
          SHA-512:2305BEC024CA5D8B43267F5487B02081A0A746B73608E11217D19C91AD857B6A5D8E935194AC4228DA3A5383086E60D593095309E64BAF38841A6E32D7EA7805
          Malicious:false
          Preview: .W..............................P......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
          /var/cache/man/pt/index.db.vwLmmW
          Process:/usr/bin/mandb
          File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
          Category:dropped
          Size (bytes):20480
          Entropy (8bit):0.3847690842836057
          Encrypted:false
          SSDEEP:12:Ey20ypjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjj3:bh
          MD5:F0B902DEA5EF122A0B1F0F496DDC781B
          SHA1:90176D320A9C3601787D53CC346DC743367D53F1
          SHA-256:CFD64D42263C5D323AF423FC09CDB5DDB2F914114B87BAB6566EAB1020F15DE0
          SHA-512:3A5BC0E51D53A12E65441FB98E1201DC434C42DB389CFCA4C96FF65C2413CF9B06B29CC39A48BD3FDC61F4896396813E54B9C2CE404EF35AC33B35377E718874
          Malicious:false
          Preview: .W..............................@......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
          /var/cache/man/pt_BR/5300
          Process:/usr/bin/mandb
          File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
          Category:dropped
          Size (bytes):16384
          Entropy (8bit):1.7510008687365202
          Encrypted:false
          SSDEEP:48:bhX6G+IwvnUZe4Gv/KSmGROqAQAuSe0dDOfInYbmucrm3QEAvJBFIz:bhq5bnUY4Gn3P+/Z1tvJDQ
          MD5:A11F5E85A2A07AF84255570AE29318FB
          SHA1:D06BF25E5FD4A17BCF7C5BD77ACD747F0FE181E8
          SHA-256:8FFA8BC408B254217275A622D054853CB72B08409A11AA49C4C664C0DABFB62F
          SHA-512:059F3CBC93750B68942D88EDD4AD2531B2291CEC421EB903280B9105010D1C8AD70F9F3CFA1B1A50D5110DCBFDB807A6E7A3F9EBC9A48AC8C3A49DEC4B6B3899
          Malicious:false
          Preview: .W..............................@......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
          /var/cache/man/pt_BR/index.db.CT6JfW
          Process:/usr/bin/mandb
          File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
          Category:dropped
          Size (bytes):16384
          Entropy (8bit):0.45676214072558463
          Encrypted:false
          SSDEEP:12:Ey20ypjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjj3:bh
          MD5:EE429C7E8B222AFF73C611A8C358B661
          SHA1:DA353E80DCF1195F259CCBC32D39F5923710453F
          SHA-256:BDAAC26D90701E063943763B7CBD9204B6F0007C6F1BCA3C7B4FE3B09CDF6091
          SHA-512:DC651AF7AEB4A64C63986100E416A7DA4782678497B73F1CE42536DE02DB9E4115748881A56B86EC5B12E34C9FDF829BD194BEA7790FDCA7B2F5178A24930809
          Malicious:false
          Preview: .W..............................@......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
          /var/cache/man/ru/5300
          Process:/usr/bin/mandb
          File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
          Category:dropped
          Size (bytes):24576
          Entropy (8bit):3.440634655325007
          Encrypted:false
          SSDEEP:384:SpjHrhEon3PRekEF3PS6y13Vi6w5TlmmcOB:Q3hNEk23MuxrB
          MD5:DF5C1114538C5D8EA1EE929FFAC24E3C
          SHA1:B6331AF77566B63EA8204BE85F5DC99FAF51479E
          SHA-256:F238C75DAD82E10AB011A9BF79775B2A5F5889644A5A06835933340845A08555
          SHA-512:9514A424CC2A9290F749F527F515B35E45C6A829CB3930DBFB39DC9D70A684640A31686EC77258FF285FE89B6DD44BB01A478848FF9B3EBD764741A6F7856704
          Malicious:false
          Preview: .W..............................`......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
          /var/cache/man/ru/index.db.2a8RLX
          Process:/usr/bin/mandb
          File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
          Category:dropped
          Size (bytes):24576
          Entropy (8bit):0.3337394253577246
          Encrypted:false
          SSDEEP:12:Ey20ypjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjj3:bh
          MD5:5B66CE03BFE548DEE335E0518E4E0554
          SHA1:65397845DC679AA972454B0FF237A513C0F490CB
          SHA-256:C38BB21B1D92166794DC09807C9A55B67B0A760C684FEEDD0C931F8415DD6D29
          SHA-512:A31C3D23F25607333250443490F0EE295BB702B46A636905FD413E8AEAA8ED23AAB42106868D2938718555C9DEEFB69FB416CAF5228A422F64D6CA8DB438FEE8
          Malicious:false
          Preview: .W..............................@......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
          /var/cache/man/sl/5300
          Process:/usr/bin/mandb
          File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
          Category:dropped
          Size (bytes):16384
          Entropy (8bit):0.8558400366712392
          Encrypted:false
          SSDEEP:12:Ey20y8jjjjjjjjjjjjjjjjjjjjjjjjjjGjjjKuV0jjjjjjjjjjjjjjjjjjjjjjje:bhaVZjx6ot7m13SmZQs
          MD5:67697BEA7C23E4805A82FE9755BB3CAE
          SHA1:14ACAFF0BECBDB116E4C0BC329E59DEF68CF46D1
          SHA-256:553DA7FF76999B7CCC4450498B11E6BD98B3B1E5FF81D82A53568F84B0D270D5
          SHA-512:D966DD6430003E708C6EE10764DC072A1ED0A252E6E1C822CBD28271A2EDD4B1F61C7F9AA7D1D442D6175791A104A365DE25B9C2598500AE705C9250C8BA46A1
          Malicious:false
          Preview: .W..............................@......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
          /var/cache/man/sl/index.db.gqQzfW
          Process:/usr/bin/mandb
          File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
          Category:dropped
          Size (bytes):16384
          Entropy (8bit):0.45676214072558463
          Encrypted:false
          SSDEEP:12:Ey20ypjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjj3:bh
          MD5:EE429C7E8B222AFF73C611A8C358B661
          SHA1:DA353E80DCF1195F259CCBC32D39F5923710453F
          SHA-256:BDAAC26D90701E063943763B7CBD9204B6F0007C6F1BCA3C7B4FE3B09CDF6091
          SHA-512:DC651AF7AEB4A64C63986100E416A7DA4782678497B73F1CE42536DE02DB9E4115748881A56B86EC5B12E34C9FDF829BD194BEA7790FDCA7B2F5178A24930809
          Malicious:false
          Preview: .W..............................@......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
          /var/cache/man/sr/5300
          Process:/usr/bin/mandb
          File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
          Category:dropped
          Size (bytes):16384
          Entropy (8bit):1.3868484511023333
          Encrypted:false
          SSDEEP:48:bhLSUCt/WFekRv/KSmGWqApnEVyfNsu+tBNGg2PgULLE2vRy2QwfoQEDiR2e3iRj:bhLVC48cn3Vu2FtBv7AtboQIqb3qwK
          MD5:0DD75ECC81E4E564EA56A57FF32A24D3
          SHA1:859C0FE5F86A2C5A32BAD7920787BE845F34C4FB
          SHA-256:DB778B175D19DEFA4180D0B12D675AD0B8B22CC4BB77702D9EC8510F894EB3B1
          SHA-512:7B0C56A76797383527509F8036EB4911F8925E7ACC005CDC3269F0A43231479E3A0A9887BF4D2979F05CBFE18324997DEF715FDA6921EEF827B385C9D902C708
          Malicious:false
          Preview: .W..............................@......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
          /var/cache/man/sr/index.db.J0vZPY
          Process:/usr/bin/mandb
          File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
          Category:dropped
          Size (bytes):16384
          Entropy (8bit):0.45676214072558463
          Encrypted:false
          SSDEEP:12:Ey20ypjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjj3:bh
          MD5:EE429C7E8B222AFF73C611A8C358B661
          SHA1:DA353E80DCF1195F259CCBC32D39F5923710453F
          SHA-256:BDAAC26D90701E063943763B7CBD9204B6F0007C6F1BCA3C7B4FE3B09CDF6091
          SHA-512:DC651AF7AEB4A64C63986100E416A7DA4782678497B73F1CE42536DE02DB9E4115748881A56B86EC5B12E34C9FDF829BD194BEA7790FDCA7B2F5178A24930809
          Malicious:false
          Preview: .W..............................@......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
          /var/cache/man/sv/5300
          Process:/usr/bin/mandb
          File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
          Category:dropped
          Size (bytes):16384
          Entropy (8bit):2.5432558448090097
          Encrypted:false
          SSDEEP:96:bhk/+fz7b9ldxbe2Vn3iwkVJIB0D6c6aZ4+1Wrzbxpl4/tMe1:imrn9lHbe2Vn3iwKhD6cvTAbl4/tMe
          MD5:D97454D6B1F39F39966A809BCA3D9647
          SHA1:276931CED8F34B7651C1BDFC8522FF0560E2C377
          SHA-256:DCB8CE7F4F21595D851100F315C56B717541DB898AEB9ED9C0CCC9FF217A5801
          SHA-512:3E014F3EA8EEE79B87726EDA6291AC2D0BD9B22803EE848F61CA2AAD39D5FB87704410C57C648EE4AF8A1B78EFB0D766524F6DB750208C9BAC346079FD8EE69E
          Malicious:false
          Preview: .W..............................@......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
          /var/cache/man/sv/index.db.GflUYW
          Process:/usr/bin/mandb
          File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
          Category:dropped
          Size (bytes):16384
          Entropy (8bit):0.45676214072558463
          Encrypted:false
          SSDEEP:12:Ey20ypjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjj3:bh
          MD5:EE429C7E8B222AFF73C611A8C358B661
          SHA1:DA353E80DCF1195F259CCBC32D39F5923710453F
          SHA-256:BDAAC26D90701E063943763B7CBD9204B6F0007C6F1BCA3C7B4FE3B09CDF6091
          SHA-512:DC651AF7AEB4A64C63986100E416A7DA4782678497B73F1CE42536DE02DB9E4115748881A56B86EC5B12E34C9FDF829BD194BEA7790FDCA7B2F5178A24930809
          Malicious:false
          Preview: .W..............................@......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
          /var/cache/man/tr/5300
          Process:/usr/bin/mandb
          File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
          Category:dropped
          Size (bytes):16384
          Entropy (8bit):1.7558188637474321
          Encrypted:false
          SSDEEP:96:bhWV1OIM7cn3UZiPU1wywyoEpJmz6W2Mzgg:YDOL4n3fPvywrzgMU
          MD5:5F905B930E7310E72BC3DF5C50F8E579
          SHA1:50B1AD3115F095C743CB26F87ECCE406FAC3523B
          SHA-256:1DB72BA77CA01F25CA9768999825D8F97F5ED4D00E17C9130D6F7CDE34130270
          SHA-512:A6066F4DF4097DB93673CD156BBE5F910C3F64D01E1671E481BC9FBDD720DBD6F8CEF337E20404F7C6AE97B2FA1F5E67088041ACBB6EA85D6758924D5740D06C
          Malicious:false
          Preview: .W..............................@......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
          /var/cache/man/tr/index.db.VD2vNZ
          Process:/usr/bin/mandb
          File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
          Category:dropped
          Size (bytes):16384
          Entropy (8bit):0.45676214072558463
          Encrypted:false
          SSDEEP:12:Ey20ypjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjj3:bh
          MD5:EE429C7E8B222AFF73C611A8C358B661
          SHA1:DA353E80DCF1195F259CCBC32D39F5923710453F
          SHA-256:BDAAC26D90701E063943763B7CBD9204B6F0007C6F1BCA3C7B4FE3B09CDF6091
          SHA-512:DC651AF7AEB4A64C63986100E416A7DA4782678497B73F1CE42536DE02DB9E4115748881A56B86EC5B12E34C9FDF829BD194BEA7790FDCA7B2F5178A24930809
          Malicious:false
          Preview: .W..............................@......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
          /var/cache/man/zh_CN/5300
          Process:/usr/bin/mandb
          File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
          Category:dropped
          Size (bytes):16384
          Entropy (8bit):2.6210042560348144
          Encrypted:false
          SSDEEP:48:bh5roGafX8XKu5YIoBHtF2YekDsv/KSmGWNmA/y0uJNI/oyjaOUUfEHKn9nnjoEJ:bhdoLfX8N9oBNF2XFn3UD/9FZiy0aoN
          MD5:39398A15564A55EB7BFE895D7668A5A3
          SHA1:28DA677435B87176E08AFABBF8B51F7B93E22948
          SHA-256:A4C0216476E357ED3A23E71333DBE7DE91E04370EF049032EE8E47BB1EDBD83B
          SHA-512:B4E69212338C742F8C83194552078A86E4BED59375D82563C0B4059B7E0D6A58D6317151AB1F2A6FB20D2FF6DB7C550DF6A6984B2BB873A111D58AF9AEB7D95E
          Malicious:false
          Preview: .W..............................@......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
          /var/cache/man/zh_CN/index.db.RhMtYV
          Process:/usr/bin/mandb
          File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
          Category:dropped
          Size (bytes):16384
          Entropy (8bit):0.45676214072558463
          Encrypted:false
          SSDEEP:12:Ey20ypjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjj3:bh
          MD5:EE429C7E8B222AFF73C611A8C358B661
          SHA1:DA353E80DCF1195F259CCBC32D39F5923710453F
          SHA-256:BDAAC26D90701E063943763B7CBD9204B6F0007C6F1BCA3C7B4FE3B09CDF6091
          SHA-512:DC651AF7AEB4A64C63986100E416A7DA4782678497B73F1CE42536DE02DB9E4115748881A56B86EC5B12E34C9FDF829BD194BEA7790FDCA7B2F5178A24930809
          Malicious:false
          Preview: .W..............................@......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
          /var/cache/man/zh_TW/5300
          Process:/usr/bin/mandb
          File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
          Category:dropped
          Size (bytes):16384
          Entropy (8bit):1.0170167917961734
          Encrypted:false
          SSDEEP:24:bhAvIZuF4ptmpzf50dhOv8WvxjMMhFmMKxevOfOots+:bhDi4p+ahOhFFKxewj
          MD5:1FC5F2B98E5BC25B10373353D91B86B1
          SHA1:D848DA35B0731328195D59C1E996B95C4952F1F9
          SHA-256:509FAD18B4454CD70D974755F6156D4A5FA9B960AB9FF468D1FC350F0B64F379
          SHA-512:95BC2E289EDE5D9A3F56C9D8AE9DD13D9379BE2ABF8927CDABBE92B9F57A8EB667E9C08E4DFD82BF9F1F57118CE6E495722ADA2668AFF4FA0540F46C0A6D5138
          Malicious:false
          Preview: .W..............................@......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
          /var/cache/man/zh_TW/index.db.8WFIUY
          Process:/usr/bin/mandb
          File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
          Category:dropped
          Size (bytes):16384
          Entropy (8bit):0.45676214072558463
          Encrypted:false
          SSDEEP:12:Ey20ypjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjj3:bh
          MD5:EE429C7E8B222AFF73C611A8C358B661
          SHA1:DA353E80DCF1195F259CCBC32D39F5923710453F
          SHA-256:BDAAC26D90701E063943763B7CBD9204B6F0007C6F1BCA3C7B4FE3B09CDF6091
          SHA-512:DC651AF7AEB4A64C63986100E416A7DA4782678497B73F1CE42536DE02DB9E4115748881A56B86EC5B12E34C9FDF829BD194BEA7790FDCA7B2F5178A24930809
          Malicious:false
          Preview: .W..............................@......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
          /var/lib/logrotate/status.tmp
          Process:/usr/sbin/logrotate
          File Type:ASCII text
          Category:dropped
          Size (bytes):1603
          Entropy (8bit):4.7948380606970415
          Encrypted:false
          SSDEEP:48:UdrqJFNsr0DPK5Npq4pNtJNcsXNU3N6NA5n5xdtNq4wNZNDNU1LN3o9N4qJNCNqQ:hrtwm4ptxe3MmbA4wTteJYDnCA5eC9kR
          MD5:8F24260307868E44DB6907B970544C10
          SHA1:BE4E8249292AE7D2E0150E1FA60BF4F205866BD1
          SHA-256:C25CEEBE193150F8DE086C777781D1933D260878761ACAC046A0E1054D0FE705
          SHA-512:225A212318BBBE61E89A36D14D67EF8814450F00DAA7641E0C8C968750122552022EC0D671B360365099DC44D6BD8F39DAA614BAE430571571308DE6184469B0
          Malicious:false
          Preview: logrotate state -- version 2."/var/log/syslog" 2021-11-7-0:6:40."/var/log/dpkg.log" 2021-11-6-23:6:14."/var/log/speech-dispatcher/debug-flite" 2021-8-20-13:0:0."/var/log/unattended-upgrades/unattended-upgrades.log" 2021-11-6-23:6:14."/var/log/unattended-upgrades/unattended-upgrades-shutdown.log" 2021-9-17-9:23:29."/var/log/auth.log" 2021-11-7-0:6:40."/var/log/apt/term.log" 2021-11-6-23:6:14."/var/log/ppp-connect-errors" 2021-8-20-13:0:0."/var/log/apport.log" 2021-9-17-9:23:29."/var/log/speech-dispatcher/speech-dispatcher-protocol.log" 2021-8-20-13:0:0."/var/log/apt/history.log" 2021-11-6-23:6:14."/var/log/boot.log" 2021-8-20-13:0:0."/var/log/alternatives.log" 2021-9-17-9:23:29."/var/log/lightdm/*.log" 2021-8-20-13:0:0."/var/log/mail.log" 2021-8-20-13:0:0."/var/log/debug" 2021-8-20-13:0:0."/var/log/kern.log" 2021-11-7-0:6:40."/var/log/cups/access_log" 2021-11-7-0:6:40."/var/log/ufw.log" 2021-8-20-13:0:0."/var/log/speech-dispatcher/speech-dispatcher.log" 2021-8-20-13:0:0."/var/log/daemon
          /var/log/auth.log.1.gz
          Process:/bin/gzip
          File Type:gzip compressed data, last modified: Fri Sep 17 09:23:57 2021, from Unix
          Category:dropped
          Size (bytes):204
          Entropy (8bit):6.922137841844236
          Encrypted:false
          SSDEEP:6:XQelkpPc1usIRV8yOI6w/XDQximFtHassaLyBn:XLl9IRV8y6w/UxiYtZsaOn
          MD5:2F6A7144B926296144698133822B3306
          SHA1:504BACCB3CFAD4D1F0B8C762B51C11EE9E4763BC
          SHA-256:2CAF9CAD85BE60CCD515E587651357C7A673F32886D720F640175B0985DF2488
          SHA-512:4FD7812A5281EF87336BE7489DC55BC65D7D25924DBD307F27D4B77B7FD5B0896D40EB56DDA4D4F47ABC4F7EDBDADFF5150B3D745A5464A2CDFEFC05CF227F4B
          Malicious:false
          Preview: .....^Da....;..1..{..ZH|".q....<E.$zQ.1......B..B..a....C..F?i..N.Gi$...XP..!z.-!.r..\`.D..z.....x&R...".D....d2....^....h.A...B=..J....y...T.Uy"[+.z(.SV.8.Gd.qg.F]d...{C.Z.....b.......... b.e...
          /var/log/cups/access_log.1.gz
          Process:/bin/gzip
          File Type:gzip compressed data, last modified: Sat Nov 6 23:06:14 2021, from Unix
          Category:dropped
          Size (bytes):196
          Entropy (8bit):6.942391285386545
          Encrypted:false
          SSDEEP:6:XRlamjD+dVX46UvAqAsLxhtJA1ocU2gJP3dA3n:XXFDQXPPs7jA1ocU2gNdA3n
          MD5:81670C36C00700D4FDCA64EBEAD642A7
          SHA1:AB0C37D63AE1FDF36162C1E9B39167642F889614
          SHA-256:E718AEF48784FAB9F08AE5F38CABE8BF710FAABE1C0B61D44A710945ED97AF8E
          SHA-512:1BFBD7A9E8ACF1D7F8134BAB51B83E508C720B882A32A5DF85EE927BCE031930337733422244D730D31C8448769CD68C07AB665E4122AC173BA625CC0C07B88B
          Malicious:false
          Preview: ....f..a......0......jj. ..,NJ..q.Z"..Oz..%89`B...x..T.y..@._yA.=R....."...=.v...4-P8.mM..' ..4+.r....n.A;..Wn....Ji..h..vf..|..rz...0.K.-{...E.Ug.6?...!...\. )3h..v....H..>....Q..>../*...
          /var/log/kern.log.1.gz
          Process:/bin/gzip
          File Type:gzip compressed data, last modified: Fri Sep 17 09:23:55 2021, from Unix
          Category:dropped
          Size (bytes):469
          Entropy (8bit):7.5768873987938745
          Encrypted:false
          SSDEEP:12:XZbo1W/RS0OvdMgotEDnowb0dXF6awDA0kbWEogMeA:XZbgWZoviHEDnQXFO7krj2
          MD5:BE2907D385A629290947B37CB5939E31
          SHA1:D28A077D7C9009808F7AE5C0D8812B2E21E22AFA
          SHA-256:7EB5B429F62B57696F969054B02023F26C1E3759243AB776C671F567C1C46A33
          SHA-512:A507DFCA472AA6C14CA4DAAA29C3A72E063FDD6EF9905AB7CE7311C6864541F18FF83F50EA8F7EC2760DF5854632D2A14D85860901A3DA800E9A163ECDE38650
          Malicious:false
          Preview: .....^Da...... ....>..M:..r ..0.........}.2..q...c.7.....s....D.*.*9:.^...3.^._.1.2V...[;)4..........b.....@...M!.....5.?.x.......d..q..`{..M.uc0...k<.. =.f...].....`.._.j<...u...u5.G......`.<../...,J/.m.xEQ...r..e4...?..,.F~.h.|.v.cH%....9......G.+?...".*3BA.y8..$r.g..6{1.9.:v7._.*y..E.I..M\......R..E.PPl.]..| n*X..B.\.*X.,...9...Wv....K.'rQ.2...Mh.6.w7....T.%....*..&...].v..>.7\..'Y%x...!..p.....(V.$.L,..<..v......i.#.?p od....
          /var/log/syslog.1.gz
          Process:/bin/gzip
          File Type:gzip compressed data, last modified: Sat Nov 6 23:06:14 2021, from Unix
          Category:dropped
          Size (bytes):2972
          Entropy (8bit):7.924927177417405
          Encrypted:false
          SSDEEP:48:Xnkx7cyXwbEIsL4j/3rZC4iAxMPLWV13jdhN6h0kwji3nYCLW7aJyGk0rzHFxzun:3gcyXwzsL4DrVPMDWDP8wjYY57aJyQzG
          MD5:6C6886FD66F72E0A99D8E6E5F32BAE03
          SHA1:C8A08142E1D3F861A6CF0C779616A49C634741D1
          SHA-256:DA6A080D12F8C029E0C7F1289A64BC76709A025689E1D1E3DECB142C4E1D5915
          SHA-512:CE8E2E41DDAEE9FD75BAE6B8F787D0BEB9CB7F877A4DA1EE931FF7D13D62FE70A4BDBDC34A7A7730C9A04B64ED524960F944EA9344970FAC236627930C4AE69A
          Malicious:false
          Preview: ....f..a...\is...._...'...}hF....v..%.m=..DB.+.`.R......eY.@Jr./>d.y...<$.2<..}......s.c..{..I.G7,.'1E......@Y.MA|..<ft.....+.N..h.x.%~....iQd...-..m.\.Y.|_.B.../_.I..a.S.hA.....G.&g....I>.C.G.2...H..A\.4.S......D.8!\r}6.8.B.0!......G.%.A~.Q...........F.^s...L.{.."....Zr..X>.......i.E.E.r.......8O.S X*TXs.....t..N...I.Nc:A))0@`.r.0.5K.0..&.G.7^....D....7.T.F'..;..6k8....$.E.Mf.O(.JP_K.5.C9.+05'`h>....!.....A...[.B!..`....(...]......."w.Z..-.b.J.eR..AH.$/dmP..L...sM.....L..7...5.em.E..C..C..:.s.6.M.....>....V......*(.a)..>.b.%..)}Cy.J.........h..>.Q....l.~.V.......1d._..'q.p>)SB..pA.c~..I.j.`.2.V..,.Z.IX..~....O.........7b..#.04.].o.......\....._".x...h=.T.,7....8.a.i.6.}..W...f8&.1=..X..>r5..]p.c......&..bF...J5'_...v.m..?.x.....^.c..OV..+.....G.]...oL.....}~?........./..}....3b..MF.y.s.9Zr.u..p..tU+8..,E=.{=..G.4.-..g@..D-...dJ....m...c.Q.)e.Z&.~..M.{.l....9...% .....+..Ra+;...mGWE.P)Y..0..,...j..."N. ....8I..0dP..38BS.@...4.t..)$ ...<..A..X..1-...K.

          Static File Info

          General

          File type:ELF 32-bit LSB executable, ARM, EABI4 version 1 (GNU/Linux), statically linked, stripped
          Entropy (8bit):7.976984659938551
          TrID:
          • ELF Executable and Linkable format (generic) (4004/1) 100.00%
          File name:1Zn1o0ho0d
          File size:48696
          MD5:7cd969c5a935efb39614b9e088682e2d
          SHA1:142387e6dddad723345106a8a2d4bbc96527387c
          SHA256:e46d2e7b074443218de80066a68ae9e146f8d8fdd22b624f619d7f486e4036b8
          SHA512:937f9143ad20e7c33dfd78ff6f12dc3a4eccd68c1419699793f53b94a075abbdc2291b7ce0d673fdaead3ac791e4c58d7a8db7ed89e6b1defca46ddf65e075d2
          SSDEEP:768:aK7y1XGO1LCNgukEkvwtqPnH7u83nc0iFe9q3UELWt/iw+kvBGg6+fYtrBHb:E12O1LCNguovDPH7TcrlLWhiw+kvBGgG
          File Content Preview:.ELF..............(.........4...........4. ...(......................................... b.. b.. b..................Q.td...............................OUPX!........p...p.......h..........?.E.h;....#..$...o......=..B.*...5N&"a..mk.c.........}<.....M.Q....[

          Static ELF Info

          ELF header

          Class:ELF32
          Data:2's complement, little endian
          Version:1 (current)
          Machine:ARM
          Version Number:0x1
          Type:EXEC (Executable file)
          OS/ABI:UNIX - Linux
          ABI Version:0
          Entry Point Address:0xf1a0
          Flags:0x4000002
          ELF Header Size:52
          Program Header Offset:52
          Program Header Size:32
          Number of Program Headers:3
          Section Header Offset:0
          Section Header Size:40
          Number of Section Headers:0
          Header String Table Index:0

          Program Segments

          TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
          LOAD0x00x80000x80000x838d0x838d4.04150x5R E0x8000
          LOAD0x62200x262200x262200x00x00.00000x6RW 0x8000
          GNU_STACK0x00x00x00x00x00.00000x7RWE0x4

          Network Behavior

          Network Port Distribution

          TCP Packets

          TimestampSource PortDest PortSource IPDest IP
          Nov 7, 2021 00:06:52.159853935 CET42836443192.168.2.2391.189.91.43
          Nov 7, 2021 00:06:52.216753006 CET535461312192.168.2.2345.61.184.103
          Nov 7, 2021 00:06:52.225873947 CET2112323192.168.2.2319.144.151.212
          Nov 7, 2021 00:06:52.225908041 CET2112323192.168.2.231.156.101.49
          Nov 7, 2021 00:06:52.225950956 CET2112323192.168.2.2340.147.72.91
          Nov 7, 2021 00:06:52.225949049 CET2112323192.168.2.23209.203.206.212
          Nov 7, 2021 00:06:52.225955963 CET2112323192.168.2.2382.184.240.109
          Nov 7, 2021 00:06:52.225963116 CET2112323192.168.2.23112.213.151.155
          Nov 7, 2021 00:06:52.225965977 CET2112323192.168.2.2394.224.236.78
          Nov 7, 2021 00:06:52.225974083 CET2112323192.168.2.23146.253.39.205
          Nov 7, 2021 00:06:52.226005077 CET2112323192.168.2.23158.74.71.229
          Nov 7, 2021 00:06:52.226006031 CET2112323192.168.2.2338.236.176.204
          Nov 7, 2021 00:06:52.226013899 CET2112323192.168.2.23195.19.16.11
          Nov 7, 2021 00:06:52.226057053 CET2112323192.168.2.2389.216.24.175
          Nov 7, 2021 00:06:52.226068020 CET2112323192.168.2.23242.195.215.219
          Nov 7, 2021 00:06:52.226087093 CET2112323192.168.2.23172.168.60.98
          Nov 7, 2021 00:06:52.226104021 CET2112323192.168.2.2389.11.92.97
          Nov 7, 2021 00:06:52.226114988 CET2112323192.168.2.2336.62.213.26
          Nov 7, 2021 00:06:52.226125002 CET2112323192.168.2.23213.158.52.104
          Nov 7, 2021 00:06:52.226125002 CET2112323192.168.2.23170.64.194.116
          Nov 7, 2021 00:06:52.226129055 CET2112323192.168.2.2384.174.175.114
          Nov 7, 2021 00:06:52.226155043 CET2112323192.168.2.23146.147.140.118
          Nov 7, 2021 00:06:52.226156950 CET2112323192.168.2.23113.201.32.205
          Nov 7, 2021 00:06:52.226160049 CET2112323192.168.2.23171.204.159.164
          Nov 7, 2021 00:06:52.226166964 CET2112323192.168.2.23158.142.241.45
          Nov 7, 2021 00:06:52.226171017 CET2112323192.168.2.2358.159.20.247
          Nov 7, 2021 00:06:52.226174116 CET2112323192.168.2.23250.177.247.139
          Nov 7, 2021 00:06:52.226183891 CET2112323192.168.2.23221.108.158.190
          Nov 7, 2021 00:06:52.226186037 CET2112323192.168.2.2384.14.81.112
          Nov 7, 2021 00:06:52.226206064 CET2112323192.168.2.2376.216.50.56
          Nov 7, 2021 00:06:52.226227045 CET2112323192.168.2.23185.27.46.90
          Nov 7, 2021 00:06:52.226232052 CET2112323192.168.2.23178.211.126.126
          Nov 7, 2021 00:06:52.226241112 CET2112323192.168.2.2362.8.172.188
          Nov 7, 2021 00:06:52.226262093 CET2112323192.168.2.2377.210.161.233
          Nov 7, 2021 00:06:52.226269007 CET2112323192.168.2.2353.126.99.214
          Nov 7, 2021 00:06:52.226274967 CET2112323192.168.2.23165.140.65.130
          Nov 7, 2021 00:06:52.226294994 CET2112323192.168.2.23223.215.75.244
          Nov 7, 2021 00:06:52.226310968 CET2112323192.168.2.2327.239.210.24
          Nov 7, 2021 00:06:52.226310968 CET2112323192.168.2.23120.10.157.151
          Nov 7, 2021 00:06:52.226327896 CET2112323192.168.2.23221.42.145.178
          Nov 7, 2021 00:06:52.226342916 CET2112323192.168.2.23194.26.94.41
          Nov 7, 2021 00:06:52.226361990 CET2112323192.168.2.23210.3.57.125
          Nov 7, 2021 00:06:52.226368904 CET2112323192.168.2.2337.138.101.243
          Nov 7, 2021 00:06:52.226368904 CET2112323192.168.2.2372.98.96.27
          Nov 7, 2021 00:06:52.226372957 CET2112323192.168.2.23218.203.211.166
          Nov 7, 2021 00:06:52.226376057 CET2112323192.168.2.23243.247.240.222
          Nov 7, 2021 00:06:52.226402044 CET2112323192.168.2.23153.114.232.183
          Nov 7, 2021 00:06:52.226427078 CET2112323192.168.2.2339.228.186.44
          Nov 7, 2021 00:06:52.226430893 CET2112323192.168.2.23223.90.174.102
          Nov 7, 2021 00:06:52.226439953 CET2112323192.168.2.23248.159.48.135
          Nov 7, 2021 00:06:52.226459026 CET2112323192.168.2.23136.58.3.105
          Nov 7, 2021 00:06:52.226478100 CET2112323192.168.2.2323.60.50.185
          Nov 7, 2021 00:06:52.226489067 CET2112323192.168.2.23120.112.118.222
          Nov 7, 2021 00:06:52.226495028 CET2112323192.168.2.2375.116.81.194
          Nov 7, 2021 00:06:52.226499081 CET2112323192.168.2.23141.238.122.143
          Nov 7, 2021 00:06:52.226515055 CET2112323192.168.2.2376.39.36.117
          Nov 7, 2021 00:06:52.226522923 CET2112323192.168.2.23212.148.223.218
          Nov 7, 2021 00:06:52.226531982 CET2112323192.168.2.2345.136.61.69
          Nov 7, 2021 00:06:52.226533890 CET2112323192.168.2.23123.77.69.169
          Nov 7, 2021 00:06:52.226545095 CET2112323192.168.2.23197.184.208.175
          Nov 7, 2021 00:06:52.226545095 CET2112323192.168.2.23123.72.179.115
          Nov 7, 2021 00:06:52.226561069 CET2112323192.168.2.2399.140.131.118
          Nov 7, 2021 00:06:52.226564884 CET2112323192.168.2.23173.195.239.152
          Nov 7, 2021 00:06:52.226591110 CET2112323192.168.2.23112.24.115.86
          Nov 7, 2021 00:06:52.226596117 CET2112323192.168.2.2337.140.119.29
          Nov 7, 2021 00:06:52.226600885 CET2112323192.168.2.2389.149.22.77
          Nov 7, 2021 00:06:52.226624012 CET2112323192.168.2.23246.144.28.9
          Nov 7, 2021 00:06:52.226638079 CET2112323192.168.2.2313.28.3.26
          Nov 7, 2021 00:06:52.226639986 CET2112323192.168.2.23187.34.153.54
          Nov 7, 2021 00:06:52.226644993 CET2112323192.168.2.23253.240.225.217
          Nov 7, 2021 00:06:52.226653099 CET2112323192.168.2.23221.86.94.189
          Nov 7, 2021 00:06:52.226660967 CET2112323192.168.2.2390.224.240.106
          Nov 7, 2021 00:06:52.226679087 CET2112323192.168.2.23161.169.35.31
          Nov 7, 2021 00:06:52.226682901 CET2112323192.168.2.23240.106.13.12
          Nov 7, 2021 00:06:52.226690054 CET2112323192.168.2.23219.68.141.74
          Nov 7, 2021 00:06:52.226696968 CET2112323192.168.2.2324.209.181.31
          Nov 7, 2021 00:06:52.226701021 CET2112323192.168.2.23117.249.4.17
          Nov 7, 2021 00:06:52.226722002 CET2112323192.168.2.23166.76.225.193
          Nov 7, 2021 00:06:52.226725101 CET2112323192.168.2.23186.198.160.75
          Nov 7, 2021 00:06:52.226742029 CET2112323192.168.2.23244.140.165.180
          Nov 7, 2021 00:06:52.226752996 CET2112323192.168.2.23116.53.119.218
          Nov 7, 2021 00:06:52.226792097 CET2112323192.168.2.23109.29.227.172
          Nov 7, 2021 00:06:52.226794958 CET2112323192.168.2.2374.159.198.171
          Nov 7, 2021 00:06:52.226799965 CET2112323192.168.2.2380.26.240.197
          Nov 7, 2021 00:06:52.226809025 CET2112323192.168.2.23142.146.179.185
          Nov 7, 2021 00:06:52.226826906 CET2112323192.168.2.2358.64.90.75
          Nov 7, 2021 00:06:52.226831913 CET2112323192.168.2.2353.1.232.143
          Nov 7, 2021 00:06:52.226840019 CET2112323192.168.2.23109.25.127.242
          Nov 7, 2021 00:06:52.226845026 CET2112323192.168.2.2334.140.197.47
          Nov 7, 2021 00:06:52.226874113 CET2112323192.168.2.23198.1.52.225
          Nov 7, 2021 00:06:52.226875067 CET2112323192.168.2.23249.188.195.160
          Nov 7, 2021 00:06:52.226897001 CET2112323192.168.2.23163.11.5.172
          Nov 7, 2021 00:06:52.226912975 CET2112323192.168.2.23193.65.26.125
          Nov 7, 2021 00:06:52.226926088 CET2112323192.168.2.23254.93.74.228
          Nov 7, 2021 00:06:52.226933002 CET2112323192.168.2.2390.251.170.143
          Nov 7, 2021 00:06:52.226939917 CET2112323192.168.2.23189.87.45.233
          Nov 7, 2021 00:06:52.226943970 CET2112323192.168.2.2375.113.206.250
          Nov 7, 2021 00:06:52.226949930 CET2112323192.168.2.23221.40.136.212
          Nov 7, 2021 00:06:52.226963043 CET2112323192.168.2.23116.192.128.206
          Nov 7, 2021 00:06:52.226980925 CET2112323192.168.2.23170.121.45.126

          System Behavior

          General

          Start time:00:06:40
          Start date:07/11/2021
          Path:/usr/lib/systemd/systemd
          Arguments:n/a
          File size:1620224 bytes
          MD5 hash:9b2bec7092a40488108543f9334aab75

          General

          Start time:00:06:40
          Start date:07/11/2021
          Path:/usr/sbin/logrotate
          Arguments:/usr/sbin/logrotate /etc/logrotate.conf
          File size:84056 bytes
          MD5 hash:ff9f6831debb63e53a31ff8057143af6

          General

          Start time:00:06:40
          Start date:07/11/2021
          Path:/usr/sbin/logrotate
          Arguments:n/a
          File size:84056 bytes
          MD5 hash:ff9f6831debb63e53a31ff8057143af6

          General

          Start time:00:06:40
          Start date:07/11/2021
          Path:/bin/gzip
          Arguments:/bin/gzip
          File size:97496 bytes
          MD5 hash:beef4e1f54ec90564d2acd57c0b0c897

          General

          Start time:00:06:40
          Start date:07/11/2021
          Path:/usr/sbin/logrotate
          Arguments:n/a
          File size:84056 bytes
          MD5 hash:ff9f6831debb63e53a31ff8057143af6

          General

          Start time:00:06:40
          Start date:07/11/2021
          Path:/bin/sh
          Arguments:sh -c "\n\t\tinvoke-rc.d --quiet cups restart > /dev/null\n" logrotate_script "/var/log/cups/*log "
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:00:06:40
          Start date:07/11/2021
          Path:/bin/sh
          Arguments:n/a
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:00:06:40
          Start date:07/11/2021
          Path:/usr/sbin/invoke-rc.d
          Arguments:invoke-rc.d --quiet cups restart
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:00:06:40
          Start date:07/11/2021
          Path:/usr/sbin/invoke-rc.d
          Arguments:n/a
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:00:06:40
          Start date:07/11/2021
          Path:/sbin/runlevel
          Arguments:/sbin/runlevel
          File size:996584 bytes
          MD5 hash:4deddfb6741481f68aeac522cc26ff4b

          General

          Start time:00:06:41
          Start date:07/11/2021
          Path:/usr/sbin/invoke-rc.d
          Arguments:n/a
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:00:06:41
          Start date:07/11/2021
          Path:/usr/bin/systemctl
          Arguments:systemctl --quiet is-enabled cups.service
          File size:996584 bytes
          MD5 hash:4deddfb6741481f68aeac522cc26ff4b

          General

          Start time:00:06:42
          Start date:07/11/2021
          Path:/usr/sbin/invoke-rc.d
          Arguments:n/a
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:00:06:42
          Start date:07/11/2021
          Path:/usr/bin/ls
          Arguments:ls /etc/rc[S2345].d/S[0-9][0-9]cups
          File size:142144 bytes
          MD5 hash:e7793f15c2ff7e747b4bc7079f5cd4f7

          General

          Start time:00:06:42
          Start date:07/11/2021
          Path:/usr/sbin/invoke-rc.d
          Arguments:n/a
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:00:06:42
          Start date:07/11/2021
          Path:/usr/bin/systemctl
          Arguments:systemctl --quiet is-active cups.service
          File size:996584 bytes
          MD5 hash:4deddfb6741481f68aeac522cc26ff4b

          General

          Start time:00:06:42
          Start date:07/11/2021
          Path:/usr/sbin/logrotate
          Arguments:n/a
          File size:84056 bytes
          MD5 hash:ff9f6831debb63e53a31ff8057143af6

          General

          Start time:00:06:42
          Start date:07/11/2021
          Path:/bin/gzip
          Arguments:/bin/gzip
          File size:97496 bytes
          MD5 hash:beef4e1f54ec90564d2acd57c0b0c897

          General

          Start time:00:06:42
          Start date:07/11/2021
          Path:/usr/sbin/logrotate
          Arguments:n/a
          File size:84056 bytes
          MD5 hash:ff9f6831debb63e53a31ff8057143af6

          General

          Start time:00:06:42
          Start date:07/11/2021
          Path:/bin/sh
          Arguments:sh -c /usr/lib/rsyslog/rsyslog-rotate logrotate_script /var/log/syslog
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:00:06:42
          Start date:07/11/2021
          Path:/bin/sh
          Arguments:n/a
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:00:06:42
          Start date:07/11/2021
          Path:/usr/lib/rsyslog/rsyslog-rotate
          Arguments:/usr/lib/rsyslog/rsyslog-rotate
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:00:06:42
          Start date:07/11/2021
          Path:/usr/lib/rsyslog/rsyslog-rotate
          Arguments:n/a
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:00:06:42
          Start date:07/11/2021
          Path:/usr/bin/systemctl
          Arguments:systemctl kill -s HUP rsyslog.service
          File size:996584 bytes
          MD5 hash:4deddfb6741481f68aeac522cc26ff4b

          General

          Start time:00:06:43
          Start date:07/11/2021
          Path:/usr/sbin/logrotate
          Arguments:n/a
          File size:84056 bytes
          MD5 hash:ff9f6831debb63e53a31ff8057143af6

          General

          Start time:00:06:43
          Start date:07/11/2021
          Path:/bin/gzip
          Arguments:/bin/gzip
          File size:97496 bytes
          MD5 hash:beef4e1f54ec90564d2acd57c0b0c897

          General

          Start time:00:06:43
          Start date:07/11/2021
          Path:/usr/sbin/logrotate
          Arguments:n/a
          File size:84056 bytes
          MD5 hash:ff9f6831debb63e53a31ff8057143af6

          General

          Start time:00:06:43
          Start date:07/11/2021
          Path:/bin/gzip
          Arguments:/bin/gzip
          File size:97496 bytes
          MD5 hash:beef4e1f54ec90564d2acd57c0b0c897

          General

          Start time:00:06:43
          Start date:07/11/2021
          Path:/usr/sbin/logrotate
          Arguments:n/a
          File size:84056 bytes
          MD5 hash:ff9f6831debb63e53a31ff8057143af6

          General

          Start time:00:06:43
          Start date:07/11/2021
          Path:/bin/sh
          Arguments:sh -c /usr/lib/rsyslog/rsyslog-rotate logrotate_script /var/log/mail.info/var/log/mail.warn/var/log/mail.err/var/log/mail.log/var/log/daemon.log/var/log/kern.log/var/log/auth.log/var/log/user.log/var/log/lpr.log/var/log/cron.log/var/log/debug/var/log/messages
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:00:06:44
          Start date:07/11/2021
          Path:/bin/sh
          Arguments:n/a
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:00:06:44
          Start date:07/11/2021
          Path:/usr/lib/rsyslog/rsyslog-rotate
          Arguments:/usr/lib/rsyslog/rsyslog-rotate
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:00:06:44
          Start date:07/11/2021
          Path:/usr/lib/rsyslog/rsyslog-rotate
          Arguments:n/a
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:00:06:44
          Start date:07/11/2021
          Path:/usr/bin/systemctl
          Arguments:systemctl kill -s HUP rsyslog.service
          File size:996584 bytes
          MD5 hash:4deddfb6741481f68aeac522cc26ff4b

          General

          Start time:00:06:39
          Start date:07/11/2021
          Path:/usr/lib/systemd/systemd
          Arguments:n/a
          File size:1620224 bytes
          MD5 hash:9b2bec7092a40488108543f9334aab75

          General

          Start time:00:06:39
          Start date:07/11/2021
          Path:/usr/bin/install
          Arguments:/usr/bin/install -d -o man -g man -m 0755 /var/cache/man
          File size:158112 bytes
          MD5 hash:55e2520049dc6a62e8c94732e36cdd54

          General

          Start time:00:06:40
          Start date:07/11/2021
          Path:/usr/lib/systemd/systemd
          Arguments:n/a
          File size:1620224 bytes
          MD5 hash:9b2bec7092a40488108543f9334aab75

          General

          Start time:00:06:40
          Start date:07/11/2021
          Path:/usr/bin/find
          Arguments:/usr/bin/find /var/cache/man -type f -name *.gz -atime +6 -delete
          File size:320160 bytes
          MD5 hash:b68ef002f84cc54dd472238ba7df80ab

          General

          Start time:00:06:41
          Start date:07/11/2021
          Path:/usr/lib/systemd/systemd
          Arguments:n/a
          File size:1620224 bytes
          MD5 hash:9b2bec7092a40488108543f9334aab75

          General

          Start time:00:06:41
          Start date:07/11/2021
          Path:/usr/bin/mandb
          Arguments:/usr/bin/mandb --quiet
          File size:142432 bytes
          MD5 hash:1dda5ea0027ecf1c2db0f5a3de7e6941

          General

          Start time:00:06:51
          Start date:07/11/2021
          Path:/tmp/1Zn1o0ho0d
          Arguments:/tmp/1Zn1o0ho0d
          File size:4956856 bytes
          MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

          General

          Start time:00:06:51
          Start date:07/11/2021
          Path:/tmp/1Zn1o0ho0d
          Arguments:n/a
          File size:4956856 bytes
          MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

          General

          Start time:00:09:53
          Start date:07/11/2021
          Path:/tmp/1Zn1o0ho0d
          Arguments:n/a
          File size:4956856 bytes
          MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

          General

          Start time:00:09:53
          Start date:07/11/2021
          Path:/tmp/1Zn1o0ho0d
          Arguments:n/a
          File size:4956856 bytes
          MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

          General

          Start time:00:09:53
          Start date:07/11/2021
          Path:/tmp/1Zn1o0ho0d
          Arguments:n/a
          File size:4956856 bytes
          MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

          General

          Start time:00:09:58
          Start date:07/11/2021
          Path:/tmp/1Zn1o0ho0d
          Arguments:n/a
          File size:4956856 bytes
          MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

          General

          Start time:00:09:58
          Start date:07/11/2021
          Path:/tmp/1Zn1o0ho0d
          Arguments:n/a
          File size:4956856 bytes
          MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

          General

          Start time:00:09:53
          Start date:07/11/2021
          Path:/tmp/1Zn1o0ho0d
          Arguments:n/a
          File size:4956856 bytes
          MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

          General

          Start time:00:09:53
          Start date:07/11/2021
          Path:/tmp/1Zn1o0ho0d
          Arguments:n/a
          File size:4956856 bytes
          MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

          General

          Start time:00:06:51
          Start date:07/11/2021
          Path:/tmp/1Zn1o0ho0d
          Arguments:n/a
          File size:4956856 bytes
          MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

          General

          Start time:00:06:51
          Start date:07/11/2021
          Path:/tmp/1Zn1o0ho0d
          Arguments:n/a
          File size:4956856 bytes
          MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

          General

          Start time:00:06:51
          Start date:07/11/2021
          Path:/tmp/1Zn1o0ho0d
          Arguments:n/a
          File size:4956856 bytes
          MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

          General

          Start time:00:09:51
          Start date:07/11/2021
          Path:/tmp/1Zn1o0ho0d
          Arguments:n/a
          File size:4956856 bytes
          MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

          General

          Start time:00:09:51
          Start date:07/11/2021
          Path:/tmp/1Zn1o0ho0d
          Arguments:n/a
          File size:4956856 bytes
          MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

          General

          Start time:00:06:51
          Start date:07/11/2021
          Path:/tmp/1Zn1o0ho0d
          Arguments:n/a
          File size:4956856 bytes
          MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

          General

          Start time:00:06:51
          Start date:07/11/2021
          Path:/tmp/1Zn1o0ho0d
          Arguments:n/a
          File size:4956856 bytes
          MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

          General

          Start time:00:07:02
          Start date:07/11/2021
          Path:/usr/lib/systemd/systemd
          Arguments:n/a
          File size:1620224 bytes
          MD5 hash:9b2bec7092a40488108543f9334aab75

          General

          Start time:00:07:02
          Start date:07/11/2021
          Path:/usr/sbin/sshd
          Arguments:/usr/sbin/sshd -t
          File size:876328 bytes
          MD5 hash:dbca7a6bbf7bf57fedac243d4b2cb340

          General

          Start time:00:07:03
          Start date:07/11/2021
          Path:/usr/lib/systemd/systemd
          Arguments:n/a
          File size:1620224 bytes
          MD5 hash:9b2bec7092a40488108543f9334aab75

          General

          Start time:00:07:03
          Start date:07/11/2021
          Path:/usr/sbin/sshd
          Arguments:/usr/sbin/sshd -D
          File size:876328 bytes
          MD5 hash:dbca7a6bbf7bf57fedac243d4b2cb340