Source: wH04DSYf6g, 5278.1.00000000a41ba199.00000000d55ef298.rw-.sdmp | String found in binary or memory: http://dummy.zero/cgi-bin/prometei.cgi |
Source: wH04DSYf6g, 5278.1.00000000a41ba199.00000000d55ef298.rw-.sdmp | String found in binary or memory: http://mkhkjxgchtfgu7uhofxzgoawntfzrkdccymveektqgpxrpjb72oq.b32.i2p/cgi-bin/prometei.cgi |
Source: wH04DSYf6g, 5278.1.00000000a41ba199.00000000d55ef298.rw-.sdmp | String found in binary or memory: http://p3.feefreepool.net/cgi-bin/prometei.cgi |
Source: wH04DSYf6g, 5278.1.00000000a41ba199.00000000d55ef298.rw-.sdmp | String found in binary or memory: http://p3.feefreepool.net/cgi-bin/prometei.cgihttp://dummy.zero/cgi-bin/prometei.cgihttps://gb7ni5rg |
Source: wH04DSYf6g, uplugplay.40.dr | String found in binary or memory: http://upx.sf.net |
Source: wH04DSYf6g, 5278.1.00000000a41ba199.00000000d55ef298.rw-.sdmp | String found in binary or memory: https://gb7ni5rgeexdcncj.onion/cgi-bin/prometei.cgi |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/5147/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/5147/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/1582/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/1582/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/3088/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/3088/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/230/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/230/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/110/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/110/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/231/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/231/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/111/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/111/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/232/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/232/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/1579/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/1579/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/112/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/112/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/233/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/233/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/1699/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/1699/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/113/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/113/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/234/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/234/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/1335/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/1335/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/1698/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/1698/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/114/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/114/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/235/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/235/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/1334/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/1334/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/1576/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/1576/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/2302/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/2302/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/115/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/115/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/236/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/236/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/116/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/116/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/237/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/237/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/117/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/117/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/118/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/118/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/910/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/910/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/119/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/119/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/912/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/912/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/10/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/10/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/2307/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/2307/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/11/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/11/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/918/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/918/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/12/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/12/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/5273/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/5273/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/13/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/13/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/14/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/14/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/15/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/15/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/5155/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/5155/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/16/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/16/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/17/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/17/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/18/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/18/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/5037/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/5037/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/1594/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/1594/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/120/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/120/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/121/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/121/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/1349/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/1349/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/1/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/1/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/122/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/122/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/243/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/243/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/123/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/123/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/2/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 5299) | File opened: /proc/2/cmdline | Jump to behavior |
Source: /usr/sbin/logrotate (PID: 5259) | Shell command executed: sh -c "\n\t\tinvoke-rc.d --quiet cups restart > /dev/null\n" logrotate_script "/var/log/cups/*log " | Jump to behavior |
Source: /usr/sbin/logrotate (PID: 5268) | Shell command executed: sh -c /usr/lib/rsyslog/rsyslog-rotate logrotate_script /var/log/syslog | Jump to behavior |
Source: /tmp/wH04DSYf6g (PID: 5281) | Shell command executed: sh -c "pgrep wH04DSYf6g" | Jump to behavior |
Source: /tmp/wH04DSYf6g (PID: 5286) | Shell command executed: sh -c "pidof wH04DSYf6g" | Jump to behavior |
Source: /tmp/wH04DSYf6g (PID: 5290) | Shell command executed: sh -c "pgrep uplugplay" | Jump to behavior |
Source: /tmp/wH04DSYf6g (PID: 5294) | Shell command executed: sh -c "pidof uplugplay" | Jump to behavior |
Source: /tmp/wH04DSYf6g (PID: 5298) | Shell command executed: sh -c "pgrep upnpsetup" | Jump to behavior |
Source: /tmp/wH04DSYf6g (PID: 5304) | Shell command executed: sh -c "pidof upnpsetup" | Jump to behavior |
Source: /tmp/wH04DSYf6g (PID: 5306) | Shell command executed: sh -c "systemctl daemon-reload" | Jump to behavior |
Source: /tmp/wH04DSYf6g (PID: 5313) | Shell command executed: sh -c "systemctl enable uplugplay.service" | Jump to behavior |
Source: /tmp/wH04DSYf6g (PID: 5329) | Shell command executed: sh -c "systemctl start uplugplay.service" | Jump to behavior |
Source: /usr/sbin/uplugplay (PID: 5345) | Shell command executed: sh -c "/usr/sbin/uplugplay -Dcomsvc" | Jump to behavior |
Source: /usr/sbin/uplugplay (PID: 5402) | Shell command executed: sh -c "cat /proc/cpuinfo" | Jump to behavior |
Source: /usr/sbin/uplugplay (PID: 5408) | Shell command executed: sh -c "dmidecode --type baseboard" | Jump to behavior |
Source: /usr/sbin/uplugplay (PID: 5412) | Shell command executed: sh -c "dmidecode --type baseboard" | Jump to behavior |
Source: /usr/sbin/uplugplay (PID: 5416) | Shell command executed: sh -c "dmidecode --type baseboard" | Jump to behavior |
Source: /usr/sbin/uplugplay (PID: 5420) | Shell command executed: sh -c "dmidecode --type baseboard" | Jump to behavior |
Source: /usr/sbin/uplugplay (PID: 5424) | Shell command executed: sh -c "dmidecode --type baseboard" | Jump to behavior |
Source: /usr/sbin/uplugplay (PID: 5428) | Shell command executed: sh -c "dmidecode --type baseboard" | Jump to behavior |
Source: /usr/sbin/uplugplay (PID: 5432) | Shell command executed: sh -c dmidecode | Jump to behavior |
Source: /usr/sbin/uplugplay (PID: 5436) | Shell command executed: sh -c "cat /etc/os-release" | Jump to behavior |
Source: /usr/sbin/uplugplay (PID: 5440) | Shell command executed: sh -c uptime | Jump to behavior |
Source: /usr/sbin/uplugplay (PID: 5446) | Shell command executed: sh -c "uname -a" | Jump to behavior |
Source: 5263.22.dr | Binary or memory string: -9915837702310A--gzvmware kernel module |
Source: 5263.22.dr | Binary or memory string: -1116261022170A--gzQEMU User Emulator |
Source: 5263.22.dr | Binary or memory string: qemu-or1k |
Source: 5263.22.dr | Binary or memory string: qemu-riscv64 |
Source: 5263.22.dr | Binary or memory string: {cqemu |
Source: 5263.22.dr | Binary or memory string: qemu-arm |
Source: 5263.22.dr | Binary or memory string: (qemu |
Source: 5263.22.dr | Binary or memory string: qemu-tilegx |
Source: 5263.22.dr | Binary or memory string: qemu-hppa |
Source: 5263.22.dr | Binary or memory string: q{rqemu% |
Source: 5263.22.dr | Binary or memory string: )qemu |
Source: 5263.22.dr | Binary or memory string: vmware-toolbox-cmd |
Source: 5263.22.dr | Binary or memory string: qemu-ppc |
Source: 5263.22.dr | Binary or memory string: Tqemu9 |
Source: 5263.22.dr | Binary or memory string: qemu-aarch64_be |
Source: 5263.22.dr | Binary or memory string: 0qemu9 |
Source: 5263.22.dr | Binary or memory string: qemu-sparc64 |
Source: 5263.22.dr | Binary or memory string: qemu-mips64 |
Source: 5263.22.dr | Binary or memory string: vV:qemu9 |
Source: 5263.22.dr | Binary or memory string: qemu-ppc64le |
Source: 5263.22.dr | Binary or memory string: <glib::param::uint64Glib::Param::UInt643pm315820097650A--gzWrapper for uint64 parameters in GLibx86_64-linux-gnu-ld.gold-1116112426130B--gzThe GNU ELF linkerprinter-profile-1115804162510A--gzProfile using X-Rite ColorMunki and Argyll CMSgrub-fstest-1116214898500A--gzdebug tool for GRUB filesystem driversxdg-user-dir-1115483406210A--gzFind an XDG user dirkmodsign-1115569251480A--gzKernel module signing toolsensible-editor-1115739932820A--gzsensible editing, paging, and web browsingminesMines6615854478170Cgnome-mines-gzinputattach-1115708189280A--gzattach a serial line to an input-layer devicegapplication-1116155671180A--gzD-Bus application launcherip-tunnel-8815816145190A--gztunnel configurationkoi8rxterm-1116140167530A--gzX terminal emulator for KOI8-R environmentsfoo2hiperc-wrapper-1115804162510A-tgzConvert Postscript into a HIPERC printer streamcryptsetup-reencrypt-8816002888050A--gztool for offline LUKS device re-encryptionsyndaemon-1115861716810A--gza program that monitors keyboard activity and disables the touchpad when the keyboard is being used.gslj-1115980290200B--gzFormat and print text for LaserJet printer using ghostscriptfile2brl-1115757179490A--gzTranslate an xml or a text file into an embosser-ready braille filexfdesktop-settings-1115793419820A--gzDesktop settings for Xfceua-1115856013570B--gzManage Ubuntu Advantage services from Canonicallatin4-7715812813670B--gzISO 8859-4 character set encoded in octal, decimal, and hexadecimalsane-genesys-5516003468200A--gzSANE backend for GL646, GL841, GL843, GL847 and GL124 based USB flatbed scannerspdftohtml-1115853266670A--gzprogram to convert PDF files into HTML, XML and PNG imagesbluetooth-sendto-1116015653360A--gzGTK application for transferring files over Bluetoothqemu-ppc64-1116261022170B--gzQEMU User Emulatorcache_metadata_size-8815811608350A--gzEstimate the size of the metadata device needed for a given configuration.net::dbus::exporterNet::DBus::Exporter3pm315773746310A--gzExport object methods and signals to the bussane-pint-5516003468200A--gzSANE backend for scanners that use the PINT device driverbpf-helpers7-7715812813670A--gzlist of eBPF helper functionsfull-4415812813670A--gzalways full devicelogin-1115906478670A--gzbegin session on the systemcups-snmp-8815877390340A--gzcups snmp backend (deprecated)ordchr-3am315728089600A--gzconvert characters to strings and vice versasosreport-1116092694050A--gzCollect and package diagnostic and support datatop-111582782727 |