Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
QDucAhFhA9.elf

Overview

General Information

Sample name:QDucAhFhA9.elf
renamed because original name is a hash value
Original sample name:c308a09ef991bc198f4501964ac545c37fdd977940eb98afd955ce715774c597.elf
Analysis ID:1598696
MD5:f35dc2d049000545febf88fe7df3ad4f
SHA1:e283c34b76aeec35081fb8e7a3eb623955048c5f
SHA256:c308a09ef991bc198f4501964ac545c37fdd977940eb98afd955ce715774c597
Tags:elfNomadPandaRedFoxtrotuser-JAMESWT_MHT
Infos:

Detection

Score:52
Range:0 - 100
Whitelisted:false

Signatures

Multi AV Scanner detection for submitted file
Uses known network protocols on non-standard ports
Contains symbols related to standard C library sleeps (sometimes used to evade sandboxing)
Creates hidden files and/or directories
Executes commands using a shell command-line interpreter
Executes the "grep" command used to find patterns in files or piped streams
Executes the "systemctl" command used for controlling the systemd system and service manager
Sample has stripped symbol table
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

Joe Sandbox version:42.0.0 Malachite
Analysis ID:1598696
Start date and time:2025-01-24 16:40:07 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 10m 42s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:QDucAhFhA9.elf
renamed because original name is a hash value
Original Sample Name:c308a09ef991bc198f4501964ac545c37fdd977940eb98afd955ce715774c597.elf
Detection:MAL
Classification:mal52.troj.linELF@0/3@2/0
Cookbook Comments:
  • Analysis time extended to 480s due to sleep detection in submitted sample
  • Max analysis timeout: 600s exceeded, the analysis took too long
Command:/tmp/QDucAhFhA9.elf
PID:5418
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:

Standard Error:cat: '/root/.mozilla/firefox/*release/prefs.js': No such file or directory
cat: '/root/.mozilla/firefox/*default/prefs.js': No such file or directory
cat: '/root/.mozilla/firefox/*release/prefs.js': No such file or directory
cat: '/root/.mozilla/firefox/*default/prefs.js': No such file or directory
cat: '/root/.mozilla/firefox/*release/prefs.js': No such file or directory
cat: '/root/.mozilla/firefox/*default/prefs.js': No such file or directory
  • system is lnxubuntu20
  • QDucAhFhA9.elf (PID: 5418, Parent: 5340, MD5: f35dc2d049000545febf88fe7df3ad4f) Arguments: /tmp/QDucAhFhA9.elf
    • sh (PID: 5419, Parent: 5418, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "systemctl enable ssl-key >/dev/null 2>/dev/null"
      • sh New Fork (PID: 5420, Parent: 5419)
      • systemctl (PID: 5420, Parent: 5419, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl enable ssl-key
    • QDucAhFhA9.elf New Fork (PID: 5424, Parent: 5418)
      • sh (PID: 5429, Parent: 5424, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "cat $HOME/.mozilla/firefox/*release/prefs.js | grep network.proxy.ssl"
        • sh New Fork (PID: 5430, Parent: 5429)
        • cat (PID: 5430, Parent: 5429, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /root/.mozilla/firefox/*release/prefs.js
        • sh New Fork (PID: 5431, Parent: 5429)
        • grep (PID: 5431, Parent: 5429, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep network.proxy.ssl
      • sh (PID: 5432, Parent: 5424, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "cat $HOME/.mozilla/firefox/*default/prefs.js | grep network.proxy.ssl"
        • sh New Fork (PID: 5433, Parent: 5432)
        • cat (PID: 5433, Parent: 5432, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /root/.mozilla/firefox/*default/prefs.js
        • sh New Fork (PID: 5434, Parent: 5432)
        • grep (PID: 5434, Parent: 5432, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep network.proxy.ssl
      • sh (PID: 5435, Parent: 5424, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "cat /etc/profile | grep https_proxy"
        • sh New Fork (PID: 5436, Parent: 5435)
        • cat (PID: 5436, Parent: 5435, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /etc/profile
        • sh New Fork (PID: 5437, Parent: 5435)
        • grep (PID: 5437, Parent: 5435, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep https_proxy
      • sh (PID: 5485, Parent: 5424, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "cat $HOME/.mozilla/firefox/*release/prefs.js | grep network.proxy.ssl"
        • sh New Fork (PID: 5486, Parent: 5485)
        • cat (PID: 5486, Parent: 5485, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /root/.mozilla/firefox/*release/prefs.js
        • sh New Fork (PID: 5487, Parent: 5485)
        • grep (PID: 5487, Parent: 5485, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep network.proxy.ssl
      • sh (PID: 5488, Parent: 5424, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "cat $HOME/.mozilla/firefox/*default/prefs.js | grep network.proxy.ssl"
        • sh New Fork (PID: 5489, Parent: 5488)
        • cat (PID: 5489, Parent: 5488, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /root/.mozilla/firefox/*default/prefs.js
        • sh New Fork (PID: 5490, Parent: 5488)
        • grep (PID: 5490, Parent: 5488, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep network.proxy.ssl
      • sh (PID: 5491, Parent: 5424, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "cat /etc/profile | grep https_proxy"
        • sh New Fork (PID: 5492, Parent: 5491)
        • cat (PID: 5492, Parent: 5491, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /etc/profile
        • sh New Fork (PID: 5493, Parent: 5491)
        • grep (PID: 5493, Parent: 5491, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep https_proxy
      • sh (PID: 5517, Parent: 5424, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "cat $HOME/.mozilla/firefox/*release/prefs.js | grep network.proxy.ssl"
        • sh New Fork (PID: 5518, Parent: 5517)
        • cat (PID: 5518, Parent: 5517, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /root/.mozilla/firefox/*release/prefs.js
        • sh New Fork (PID: 5519, Parent: 5517)
        • grep (PID: 5519, Parent: 5517, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep network.proxy.ssl
      • sh (PID: 5520, Parent: 5424, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "cat $HOME/.mozilla/firefox/*default/prefs.js | grep network.proxy.ssl"
        • sh New Fork (PID: 5521, Parent: 5520)
        • cat (PID: 5521, Parent: 5520, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /root/.mozilla/firefox/*default/prefs.js
        • sh New Fork (PID: 5522, Parent: 5520)
        • grep (PID: 5522, Parent: 5520, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep network.proxy.ssl
      • sh (PID: 5525, Parent: 5424, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "cat /etc/profile | grep https_proxy"
        • sh New Fork (PID: 5526, Parent: 5525)
        • cat (PID: 5526, Parent: 5525, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /etc/profile
        • sh New Fork (PID: 5527, Parent: 5525)
        • grep (PID: 5527, Parent: 5525, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep https_proxy
      • sh (PID: 5549, Parent: 5424, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "cat $HOME/.mozilla/firefox/*release/prefs.js | grep network.proxy.ssl"
        • sh New Fork (PID: 5550, Parent: 5549)
        • cat (PID: 5550, Parent: 5549, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /root/.mozilla/firefox/*release/prefs.js
        • sh New Fork (PID: 5551, Parent: 5549)
        • grep (PID: 5551, Parent: 5549, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep network.proxy.ssl
      • sh (PID: 5553, Parent: 5424, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "cat $HOME/.mozilla/firefox/*default/prefs.js | grep network.proxy.ssl"
        • sh New Fork (PID: 5554, Parent: 5553)
        • cat (PID: 5554, Parent: 5553, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /root/.mozilla/firefox/*default/prefs.js
        • sh New Fork (PID: 5555, Parent: 5553)
        • grep (PID: 5555, Parent: 5553, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep network.proxy.ssl
      • sh (PID: 5556, Parent: 5424, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "cat /etc/profile | grep https_proxy"
        • sh New Fork (PID: 5557, Parent: 5556)
        • cat (PID: 5557, Parent: 5556, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /etc/profile
        • sh New Fork (PID: 5558, Parent: 5556)
        • grep (PID: 5558, Parent: 5556, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep https_proxy
      • sh (PID: 5586, Parent: 5424, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "cat $HOME/.mozilla/firefox/*release/prefs.js | grep network.proxy.ssl"
        • sh New Fork (PID: 5587, Parent: 5586)
        • cat (PID: 5587, Parent: 5586, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /root/.mozilla/firefox/*release/prefs.js
        • sh New Fork (PID: 5588, Parent: 5586)
        • grep (PID: 5588, Parent: 5586, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep network.proxy.ssl
      • sh (PID: 5591, Parent: 5424, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "cat $HOME/.mozilla/firefox/*default/prefs.js | grep network.proxy.ssl"
        • sh New Fork (PID: 5592, Parent: 5591)
        • cat (PID: 5592, Parent: 5591, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /root/.mozilla/firefox/*default/prefs.js
        • sh New Fork (PID: 5593, Parent: 5591)
        • grep (PID: 5593, Parent: 5591, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep network.proxy.ssl
      • sh (PID: 5594, Parent: 5424, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "cat /etc/profile | grep https_proxy"
        • sh New Fork (PID: 5595, Parent: 5594)
        • cat (PID: 5595, Parent: 5594, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /etc/profile
        • sh New Fork (PID: 5596, Parent: 5594)
        • grep (PID: 5596, Parent: 5594, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep https_proxy
      • sh (PID: 5616, Parent: 5424, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "cat $HOME/.mozilla/firefox/*release/prefs.js | grep network.proxy.ssl"
        • sh New Fork (PID: 5617, Parent: 5616)
        • cat (PID: 5617, Parent: 5616, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /root/.mozilla/firefox/*release/prefs.js
        • sh New Fork (PID: 5618, Parent: 5616)
        • grep (PID: 5618, Parent: 5616, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep network.proxy.ssl
      • sh (PID: 5619, Parent: 5424, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "cat $HOME/.mozilla/firefox/*default/prefs.js | grep network.proxy.ssl"
        • sh New Fork (PID: 5620, Parent: 5619)
        • cat (PID: 5620, Parent: 5619, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /root/.mozilla/firefox/*default/prefs.js
        • sh New Fork (PID: 5621, Parent: 5619)
        • grep (PID: 5621, Parent: 5619, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep network.proxy.ssl
      • sh (PID: 5622, Parent: 5424, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "cat /etc/profile | grep https_proxy"
        • sh New Fork (PID: 5623, Parent: 5622)
        • cat (PID: 5623, Parent: 5622, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /etc/profile
        • sh New Fork (PID: 5624, Parent: 5622)
        • grep (PID: 5624, Parent: 5622, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep https_proxy
      • sh (PID: 5650, Parent: 5424, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "cat $HOME/.mozilla/firefox/*release/prefs.js | grep network.proxy.ssl"
        • sh New Fork (PID: 5651, Parent: 5650)
        • cat (PID: 5651, Parent: 5650, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /root/.mozilla/firefox/*release/prefs.js
        • sh New Fork (PID: 5652, Parent: 5650)
        • grep (PID: 5652, Parent: 5650, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep network.proxy.ssl
      • sh (PID: 5653, Parent: 5424, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "cat $HOME/.mozilla/firefox/*default/prefs.js | grep network.proxy.ssl"
        • sh New Fork (PID: 5654, Parent: 5653)
        • cat (PID: 5654, Parent: 5653, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /root/.mozilla/firefox/*default/prefs.js
        • sh New Fork (PID: 5655, Parent: 5653)
        • grep (PID: 5655, Parent: 5653, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep network.proxy.ssl
      • sh (PID: 5656, Parent: 5424, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "cat /etc/profile | grep https_proxy"
        • sh New Fork (PID: 5657, Parent: 5656)
        • cat (PID: 5657, Parent: 5656, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /etc/profile
        • sh New Fork (PID: 5658, Parent: 5656)
        • grep (PID: 5658, Parent: 5656, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep https_proxy
      • sh (PID: 5702, Parent: 5424, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "cat $HOME/.mozilla/firefox/*release/prefs.js | grep network.proxy.ssl"
        • sh New Fork (PID: 5703, Parent: 5702)
        • cat (PID: 5703, Parent: 5702, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /root/.mozilla/firefox/*release/prefs.js
        • sh New Fork (PID: 5704, Parent: 5702)
        • grep (PID: 5704, Parent: 5702, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep network.proxy.ssl
      • sh (PID: 5705, Parent: 5424, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "cat $HOME/.mozilla/firefox/*default/prefs.js | grep network.proxy.ssl"
        • sh New Fork (PID: 5706, Parent: 5705)
        • cat (PID: 5706, Parent: 5705, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /root/.mozilla/firefox/*default/prefs.js
        • sh New Fork (PID: 5707, Parent: 5705)
        • grep (PID: 5707, Parent: 5705, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep network.proxy.ssl
      • sh (PID: 5708, Parent: 5424, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "cat /etc/profile | grep https_proxy"
        • sh New Fork (PID: 5709, Parent: 5708)
        • cat (PID: 5709, Parent: 5708, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /etc/profile
        • sh New Fork (PID: 5710, Parent: 5708)
        • grep (PID: 5710, Parent: 5708, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep https_proxy
      • sh (PID: 5730, Parent: 5424, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "cat $HOME/.mozilla/firefox/*release/prefs.js | grep network.proxy.ssl"
        • sh New Fork (PID: 5731, Parent: 5730)
        • cat (PID: 5731, Parent: 5730, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /root/.mozilla/firefox/*release/prefs.js
        • sh New Fork (PID: 5732, Parent: 5730)
        • grep (PID: 5732, Parent: 5730, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep network.proxy.ssl
      • sh (PID: 5733, Parent: 5424, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "cat $HOME/.mozilla/firefox/*default/prefs.js | grep network.proxy.ssl"
        • sh New Fork (PID: 5734, Parent: 5733)
        • cat (PID: 5734, Parent: 5733, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /root/.mozilla/firefox/*default/prefs.js
        • sh New Fork (PID: 5735, Parent: 5733)
        • grep (PID: 5735, Parent: 5733, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep network.proxy.ssl
      • sh (PID: 5736, Parent: 5424, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "cat /etc/profile | grep https_proxy"
        • sh New Fork (PID: 5737, Parent: 5736)
        • cat (PID: 5737, Parent: 5736, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /etc/profile
        • sh New Fork (PID: 5738, Parent: 5736)
        • grep (PID: 5738, Parent: 5736, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep https_proxy
      • sh (PID: 5759, Parent: 5424, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "cat $HOME/.mozilla/firefox/*release/prefs.js | grep network.proxy.ssl"
        • sh New Fork (PID: 5760, Parent: 5759)
        • cat (PID: 5760, Parent: 5759, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /root/.mozilla/firefox/*release/prefs.js
        • sh New Fork (PID: 5761, Parent: 5759)
        • grep (PID: 5761, Parent: 5759, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep network.proxy.ssl
      • sh (PID: 5762, Parent: 5424, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "cat $HOME/.mozilla/firefox/*default/prefs.js | grep network.proxy.ssl"
        • sh New Fork (PID: 5763, Parent: 5762)
        • cat (PID: 5763, Parent: 5762, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /root/.mozilla/firefox/*default/prefs.js
        • sh New Fork (PID: 5764, Parent: 5762)
        • grep (PID: 5764, Parent: 5762, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep network.proxy.ssl
      • sh (PID: 5765, Parent: 5424, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "cat /etc/profile | grep https_proxy"
        • sh New Fork (PID: 5766, Parent: 5765)
        • cat (PID: 5766, Parent: 5765, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /etc/profile
        • sh New Fork (PID: 5767, Parent: 5765)
        • grep (PID: 5767, Parent: 5765, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep https_proxy
      • sh (PID: 5789, Parent: 5424, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "cat $HOME/.mozilla/firefox/*release/prefs.js | grep network.proxy.ssl"
        • sh New Fork (PID: 5790, Parent: 5789)
        • cat (PID: 5790, Parent: 5789, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /root/.mozilla/firefox/*release/prefs.js
        • sh New Fork (PID: 5791, Parent: 5789)
        • grep (PID: 5791, Parent: 5789, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep network.proxy.ssl
      • sh (PID: 5792, Parent: 5424, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "cat $HOME/.mozilla/firefox/*default/prefs.js | grep network.proxy.ssl"
        • sh New Fork (PID: 5793, Parent: 5792)
        • cat (PID: 5793, Parent: 5792, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /root/.mozilla/firefox/*default/prefs.js
        • sh New Fork (PID: 5794, Parent: 5792)
        • grep (PID: 5794, Parent: 5792, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep network.proxy.ssl
      • sh (PID: 5795, Parent: 5424, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "cat /etc/profile | grep https_proxy"
        • sh New Fork (PID: 5796, Parent: 5795)
        • cat (PID: 5796, Parent: 5795, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /etc/profile
        • sh New Fork (PID: 5797, Parent: 5795)
        • grep (PID: 5797, Parent: 5795, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep https_proxy
      • sh (PID: 5823, Parent: 5424, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "cat $HOME/.mozilla/firefox/*release/prefs.js | grep network.proxy.ssl"
        • sh New Fork (PID: 5824, Parent: 5823)
        • cat (PID: 5824, Parent: 5823, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /root/.mozilla/firefox/*release/prefs.js
        • sh New Fork (PID: 5825, Parent: 5823)
        • grep (PID: 5825, Parent: 5823, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep network.proxy.ssl
      • sh (PID: 5826, Parent: 5424, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "cat $HOME/.mozilla/firefox/*default/prefs.js | grep network.proxy.ssl"
        • sh New Fork (PID: 5827, Parent: 5826)
        • cat (PID: 5827, Parent: 5826, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /root/.mozilla/firefox/*default/prefs.js
        • sh New Fork (PID: 5828, Parent: 5826)
        • grep (PID: 5828, Parent: 5826, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep network.proxy.ssl
      • sh (PID: 5829, Parent: 5424, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "cat /etc/profile | grep https_proxy"
        • sh New Fork (PID: 5830, Parent: 5829)
        • cat (PID: 5830, Parent: 5829, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /etc/profile
        • sh New Fork (PID: 5831, Parent: 5829)
        • grep (PID: 5831, Parent: 5829, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep https_proxy
  • systemd New Fork (PID: 5422, Parent: 5421)
  • snapd-env-generator (PID: 5422, Parent: 5421, MD5: 3633b075f40283ec938a2a6a89671b0e) Arguments: /usr/lib/systemd/system-environment-generators/snapd-env-generator
  • cleanup
No yara matches
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: QDucAhFhA9.elfVirustotal: Detection: 51%Perma Link
Source: QDucAhFhA9.elfReversingLabs: Detection: 44%

Networking

barindex
Source: unknownNetwork traffic detected: HTTP traffic on port 50084 -> 3128
Source: unknownNetwork traffic detected: HTTP traffic on port 50086 -> 3128
Source: unknownNetwork traffic detected: HTTP traffic on port 50090 -> 3128
Source: unknownNetwork traffic detected: HTTP traffic on port 50092 -> 3128
Source: unknownNetwork traffic detected: HTTP traffic on port 50096 -> 3128
Source: unknownNetwork traffic detected: HTTP traffic on port 50098 -> 3128
Source: unknownNetwork traffic detected: HTTP traffic on port 50102 -> 3128
Source: unknownNetwork traffic detected: HTTP traffic on port 50104 -> 3128
Source: unknownNetwork traffic detected: HTTP traffic on port 50108 -> 3128
Source: unknownNetwork traffic detected: HTTP traffic on port 50110 -> 3128
Source: unknownNetwork traffic detected: HTTP traffic on port 50114 -> 3128
Source: unknownNetwork traffic detected: HTTP traffic on port 50116 -> 3128
Source: unknownNetwork traffic detected: HTTP traffic on port 50120 -> 3128
Source: unknownNetwork traffic detected: HTTP traffic on port 50122 -> 3128
Source: unknownNetwork traffic detected: HTTP traffic on port 50126 -> 3128
Source: unknownNetwork traffic detected: HTTP traffic on port 50128 -> 3128
Source: unknownNetwork traffic detected: HTTP traffic on port 50132 -> 3128
Source: unknownNetwork traffic detected: HTTP traffic on port 50134 -> 3128
Source: unknownNetwork traffic detected: HTTP traffic on port 50138 -> 3128
Source: unknownNetwork traffic detected: HTTP traffic on port 50140 -> 3128
Source: unknownNetwork traffic detected: HTTP traffic on port 50144 -> 3128
Source: unknownNetwork traffic detected: HTTP traffic on port 50146 -> 3128
Source: unknownNetwork traffic detected: HTTP traffic on port 50150 -> 3128
Source: unknownNetwork traffic detected: HTTP traffic on port 50152 -> 3128
Source: unknownTCP traffic detected without corresponding DNS query: 95.179.223.245
Source: unknownTCP traffic detected without corresponding DNS query: 95.179.223.245
Source: unknownTCP traffic detected without corresponding DNS query: 95.179.223.245
Source: unknownTCP traffic detected without corresponding DNS query: 95.179.223.245
Source: unknownTCP traffic detected without corresponding DNS query: 95.179.223.245
Source: unknownTCP traffic detected without corresponding DNS query: 95.179.223.245
Source: unknownTCP traffic detected without corresponding DNS query: 95.179.223.245
Source: unknownTCP traffic detected without corresponding DNS query: 95.179.223.245
Source: unknownTCP traffic detected without corresponding DNS query: 95.179.223.245
Source: unknownTCP traffic detected without corresponding DNS query: 95.179.223.245
Source: unknownTCP traffic detected without corresponding DNS query: 95.179.223.245
Source: unknownTCP traffic detected without corresponding DNS query: 95.179.223.245
Source: unknownTCP traffic detected without corresponding DNS query: 95.179.223.245
Source: unknownTCP traffic detected without corresponding DNS query: 95.179.223.245
Source: unknownTCP traffic detected without corresponding DNS query: 95.179.223.245
Source: unknownTCP traffic detected without corresponding DNS query: 95.179.223.245
Source: unknownTCP traffic detected without corresponding DNS query: 95.179.223.245
Source: unknownTCP traffic detected without corresponding DNS query: 95.179.223.245
Source: unknownTCP traffic detected without corresponding DNS query: 95.179.223.245
Source: unknownTCP traffic detected without corresponding DNS query: 95.179.223.245
Source: unknownTCP traffic detected without corresponding DNS query: 95.179.223.245
Source: unknownTCP traffic detected without corresponding DNS query: 95.179.223.245
Source: unknownTCP traffic detected without corresponding DNS query: 95.179.223.245
Source: unknownTCP traffic detected without corresponding DNS query: 95.179.223.245
Source: unknownTCP traffic detected without corresponding DNS query: 95.179.223.245
Source: unknownTCP traffic detected without corresponding DNS query: 95.179.223.245
Source: unknownTCP traffic detected without corresponding DNS query: 95.179.223.245
Source: unknownTCP traffic detected without corresponding DNS query: 95.179.223.245
Source: unknownTCP traffic detected without corresponding DNS query: 95.179.223.245
Source: unknownTCP traffic detected without corresponding DNS query: 95.179.223.245
Source: unknownTCP traffic detected without corresponding DNS query: 95.179.223.245
Source: unknownTCP traffic detected without corresponding DNS query: 95.179.223.245
Source: unknownTCP traffic detected without corresponding DNS query: 95.179.223.245
Source: unknownTCP traffic detected without corresponding DNS query: 95.179.223.245
Source: unknownTCP traffic detected without corresponding DNS query: 95.179.223.245
Source: unknownTCP traffic detected without corresponding DNS query: 95.179.223.245
Source: global trafficDNS traffic detected: DNS query: daisy.ubuntu.com
Source: unknownNetwork traffic detected: HTTP traffic on port 59730 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 59778 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 59748
Source: unknownNetwork traffic detected: HTTP traffic on port 59724 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 59778
Source: unknownNetwork traffic detected: HTTP traffic on port 59760 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 59766
Source: unknownNetwork traffic detected: HTTP traffic on port 59784 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 59736
Source: unknownNetwork traffic detected: HTTP traffic on port 59766 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 59724
Source: unknownNetwork traffic detected: HTTP traffic on port 59748 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 59730
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 59784
Source: unknownNetwork traffic detected: HTTP traffic on port 59742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 59754
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 59742
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 59772
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 59760
Source: unknownNetwork traffic detected: HTTP traffic on port 59736 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 59754 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 59772 -> 443
Source: ELF static info symbol of initial sample.symtab present: no
Source: classification engineClassification label: mal52.troj.linELF@0/3@2/0
Source: /tmp/QDucAhFhA9.elf (PID: 5418)Directory: /root/.configJump to behavior
Source: /tmp/QDucAhFhA9.elf (PID: 5419)Shell command executed: sh -c "systemctl enable ssl-key >/dev/null 2>/dev/null"Jump to behavior
Source: /tmp/QDucAhFhA9.elf (PID: 5429)Shell command executed: sh -c "cat $HOME/.mozilla/firefox/*release/prefs.js | grep network.proxy.ssl"Jump to behavior
Source: /tmp/QDucAhFhA9.elf (PID: 5432)Shell command executed: sh -c "cat $HOME/.mozilla/firefox/*default/prefs.js | grep network.proxy.ssl"Jump to behavior
Source: /tmp/QDucAhFhA9.elf (PID: 5435)Shell command executed: sh -c "cat /etc/profile | grep https_proxy"Jump to behavior
Source: /tmp/QDucAhFhA9.elf (PID: 5485)Shell command executed: sh -c "cat $HOME/.mozilla/firefox/*release/prefs.js | grep network.proxy.ssl"Jump to behavior
Source: /tmp/QDucAhFhA9.elf (PID: 5488)Shell command executed: sh -c "cat $HOME/.mozilla/firefox/*default/prefs.js | grep network.proxy.ssl"Jump to behavior
Source: /tmp/QDucAhFhA9.elf (PID: 5491)Shell command executed: sh -c "cat /etc/profile | grep https_proxy"Jump to behavior
Source: /tmp/QDucAhFhA9.elf (PID: 5517)Shell command executed: sh -c "cat $HOME/.mozilla/firefox/*release/prefs.js | grep network.proxy.ssl"Jump to behavior
Source: /tmp/QDucAhFhA9.elf (PID: 5520)Shell command executed: sh -c "cat $HOME/.mozilla/firefox/*default/prefs.js | grep network.proxy.ssl"Jump to behavior
Source: /tmp/QDucAhFhA9.elf (PID: 5525)Shell command executed: sh -c "cat /etc/profile | grep https_proxy"Jump to behavior
Source: /tmp/QDucAhFhA9.elf (PID: 5549)Shell command executed: sh -c "cat $HOME/.mozilla/firefox/*release/prefs.js | grep network.proxy.ssl"Jump to behavior
Source: /tmp/QDucAhFhA9.elf (PID: 5553)Shell command executed: sh -c "cat $HOME/.mozilla/firefox/*default/prefs.js | grep network.proxy.ssl"Jump to behavior
Source: /tmp/QDucAhFhA9.elf (PID: 5556)Shell command executed: sh -c "cat /etc/profile | grep https_proxy"Jump to behavior
Source: /tmp/QDucAhFhA9.elf (PID: 5586)Shell command executed: sh -c "cat $HOME/.mozilla/firefox/*release/prefs.js | grep network.proxy.ssl"Jump to behavior
Source: /tmp/QDucAhFhA9.elf (PID: 5591)Shell command executed: sh -c "cat $HOME/.mozilla/firefox/*default/prefs.js | grep network.proxy.ssl"Jump to behavior
Source: /tmp/QDucAhFhA9.elf (PID: 5594)Shell command executed: sh -c "cat /etc/profile | grep https_proxy"Jump to behavior
Source: /tmp/QDucAhFhA9.elf (PID: 5616)Shell command executed: sh -c "cat $HOME/.mozilla/firefox/*release/prefs.js | grep network.proxy.ssl"Jump to behavior
Source: /tmp/QDucAhFhA9.elf (PID: 5619)Shell command executed: sh -c "cat $HOME/.mozilla/firefox/*default/prefs.js | grep network.proxy.ssl"Jump to behavior
Source: /tmp/QDucAhFhA9.elf (PID: 5622)Shell command executed: sh -c "cat /etc/profile | grep https_proxy"Jump to behavior
Source: /tmp/QDucAhFhA9.elf (PID: 5650)Shell command executed: sh -c "cat $HOME/.mozilla/firefox/*release/prefs.js | grep network.proxy.ssl"Jump to behavior
Source: /tmp/QDucAhFhA9.elf (PID: 5653)Shell command executed: sh -c "cat $HOME/.mozilla/firefox/*default/prefs.js | grep network.proxy.ssl"Jump to behavior
Source: /tmp/QDucAhFhA9.elf (PID: 5656)Shell command executed: sh -c "cat /etc/profile | grep https_proxy"Jump to behavior
Source: /tmp/QDucAhFhA9.elf (PID: 5702)Shell command executed: sh -c "cat $HOME/.mozilla/firefox/*release/prefs.js | grep network.proxy.ssl"Jump to behavior
Source: /tmp/QDucAhFhA9.elf (PID: 5705)Shell command executed: sh -c "cat $HOME/.mozilla/firefox/*default/prefs.js | grep network.proxy.ssl"Jump to behavior
Source: /tmp/QDucAhFhA9.elf (PID: 5708)Shell command executed: sh -c "cat /etc/profile | grep https_proxy"Jump to behavior
Source: /tmp/QDucAhFhA9.elf (PID: 5730)Shell command executed: sh -c "cat $HOME/.mozilla/firefox/*release/prefs.js | grep network.proxy.ssl"Jump to behavior
Source: /tmp/QDucAhFhA9.elf (PID: 5733)Shell command executed: sh -c "cat $HOME/.mozilla/firefox/*default/prefs.js | grep network.proxy.ssl"Jump to behavior
Source: /tmp/QDucAhFhA9.elf (PID: 5736)Shell command executed: sh -c "cat /etc/profile | grep https_proxy"Jump to behavior
Source: /tmp/QDucAhFhA9.elf (PID: 5759)Shell command executed: sh -c "cat $HOME/.mozilla/firefox/*release/prefs.js | grep network.proxy.ssl"Jump to behavior
Source: /tmp/QDucAhFhA9.elf (PID: 5762)Shell command executed: sh -c "cat $HOME/.mozilla/firefox/*default/prefs.js | grep network.proxy.ssl"Jump to behavior
Source: /tmp/QDucAhFhA9.elf (PID: 5765)Shell command executed: sh -c "cat /etc/profile | grep https_proxy"Jump to behavior
Source: /tmp/QDucAhFhA9.elf (PID: 5789)Shell command executed: sh -c "cat $HOME/.mozilla/firefox/*release/prefs.js | grep network.proxy.ssl"Jump to behavior
Source: /tmp/QDucAhFhA9.elf (PID: 5792)Shell command executed: sh -c "cat $HOME/.mozilla/firefox/*default/prefs.js | grep network.proxy.ssl"Jump to behavior
Source: /tmp/QDucAhFhA9.elf (PID: 5795)Shell command executed: sh -c "cat /etc/profile | grep https_proxy"Jump to behavior
Source: /tmp/QDucAhFhA9.elf (PID: 5823)Shell command executed: sh -c "cat $HOME/.mozilla/firefox/*release/prefs.js | grep network.proxy.ssl"Jump to behavior
Source: /tmp/QDucAhFhA9.elf (PID: 5826)Shell command executed: sh -c "cat $HOME/.mozilla/firefox/*default/prefs.js | grep network.proxy.ssl"Jump to behavior
Source: /tmp/QDucAhFhA9.elf (PID: 5829)Shell command executed: sh -c "cat /etc/profile | grep https_proxy"Jump to behavior
Source: /bin/sh (PID: 5431)Grep executable: /usr/bin/grep -> grep network.proxy.sslJump to behavior
Source: /bin/sh (PID: 5434)Grep executable: /usr/bin/grep -> grep network.proxy.sslJump to behavior
Source: /bin/sh (PID: 5437)Grep executable: /usr/bin/grep -> grep https_proxyJump to behavior
Source: /bin/sh (PID: 5487)Grep executable: /usr/bin/grep -> grep network.proxy.sslJump to behavior
Source: /bin/sh (PID: 5490)Grep executable: /usr/bin/grep -> grep network.proxy.sslJump to behavior
Source: /bin/sh (PID: 5493)Grep executable: /usr/bin/grep -> grep https_proxyJump to behavior
Source: /bin/sh (PID: 5519)Grep executable: /usr/bin/grep -> grep network.proxy.sslJump to behavior
Source: /bin/sh (PID: 5522)Grep executable: /usr/bin/grep -> grep network.proxy.sslJump to behavior
Source: /bin/sh (PID: 5527)Grep executable: /usr/bin/grep -> grep https_proxyJump to behavior
Source: /bin/sh (PID: 5551)Grep executable: /usr/bin/grep -> grep network.proxy.sslJump to behavior
Source: /bin/sh (PID: 5555)Grep executable: /usr/bin/grep -> grep network.proxy.sslJump to behavior
Source: /bin/sh (PID: 5558)Grep executable: /usr/bin/grep -> grep https_proxyJump to behavior
Source: /bin/sh (PID: 5588)Grep executable: /usr/bin/grep -> grep network.proxy.sslJump to behavior
Source: /bin/sh (PID: 5593)Grep executable: /usr/bin/grep -> grep network.proxy.sslJump to behavior
Source: /bin/sh (PID: 5596)Grep executable: /usr/bin/grep -> grep https_proxyJump to behavior
Source: /bin/sh (PID: 5618)Grep executable: /usr/bin/grep -> grep network.proxy.sslJump to behavior
Source: /bin/sh (PID: 5621)Grep executable: /usr/bin/grep -> grep network.proxy.sslJump to behavior
Source: /bin/sh (PID: 5624)Grep executable: /usr/bin/grep -> grep https_proxyJump to behavior
Source: /bin/sh (PID: 5652)Grep executable: /usr/bin/grep -> grep network.proxy.sslJump to behavior
Source: /bin/sh (PID: 5655)Grep executable: /usr/bin/grep -> grep network.proxy.sslJump to behavior
Source: /bin/sh (PID: 5658)Grep executable: /usr/bin/grep -> grep https_proxyJump to behavior
Source: /bin/sh (PID: 5704)Grep executable: /usr/bin/grep -> grep network.proxy.sslJump to behavior
Source: /bin/sh (PID: 5707)Grep executable: /usr/bin/grep -> grep network.proxy.sslJump to behavior
Source: /bin/sh (PID: 5710)Grep executable: /usr/bin/grep -> grep https_proxyJump to behavior
Source: /bin/sh (PID: 5732)Grep executable: /usr/bin/grep -> grep network.proxy.sslJump to behavior
Source: /bin/sh (PID: 5735)Grep executable: /usr/bin/grep -> grep network.proxy.sslJump to behavior
Source: /bin/sh (PID: 5738)Grep executable: /usr/bin/grep -> grep https_proxyJump to behavior
Source: /bin/sh (PID: 5761)Grep executable: /usr/bin/grep -> grep network.proxy.sslJump to behavior
Source: /bin/sh (PID: 5764)Grep executable: /usr/bin/grep -> grep network.proxy.sslJump to behavior
Source: /bin/sh (PID: 5767)Grep executable: /usr/bin/grep -> grep https_proxyJump to behavior
Source: /bin/sh (PID: 5791)Grep executable: /usr/bin/grep -> grep network.proxy.sslJump to behavior
Source: /bin/sh (PID: 5794)Grep executable: /usr/bin/grep -> grep network.proxy.sslJump to behavior
Source: /bin/sh (PID: 5797)Grep executable: /usr/bin/grep -> grep https_proxyJump to behavior
Source: /bin/sh (PID: 5825)Grep executable: /usr/bin/grep -> grep network.proxy.sslJump to behavior
Source: /bin/sh (PID: 5828)Grep executable: /usr/bin/grep -> grep network.proxy.sslJump to behavior
Source: /bin/sh (PID: 5831)Grep executable: /usr/bin/grep -> grep https_proxyJump to behavior
Source: /bin/sh (PID: 5420)Systemctl executable: /usr/bin/systemctl -> systemctl enable ssl-keyJump to behavior
Source: submitted sampleStderr: cat: '/root/.mozilla/firefox/*release/prefs.js': No such file or directorycat: '/root/.mozilla/firefox/*default/prefs.js': No such file or directorycat: '/root/.mozilla/firefox/*release/prefs.js': No such file or directorycat: '/root/.mozilla/firefox/*default/prefs.js': No such file or directorycat: '/root/.mozilla/firefox/*release/prefs.js': No such file or directorycat: '/root/.mozilla/firefox/*default/prefs.js': No such file or directory: exit code = 0

Hooking and other Techniques for Hiding and Protection

barindex
Source: unknownNetwork traffic detected: HTTP traffic on port 50084 -> 3128
Source: unknownNetwork traffic detected: HTTP traffic on port 50086 -> 3128
Source: unknownNetwork traffic detected: HTTP traffic on port 50090 -> 3128
Source: unknownNetwork traffic detected: HTTP traffic on port 50092 -> 3128
Source: unknownNetwork traffic detected: HTTP traffic on port 50096 -> 3128
Source: unknownNetwork traffic detected: HTTP traffic on port 50098 -> 3128
Source: unknownNetwork traffic detected: HTTP traffic on port 50102 -> 3128
Source: unknownNetwork traffic detected: HTTP traffic on port 50104 -> 3128
Source: unknownNetwork traffic detected: HTTP traffic on port 50108 -> 3128
Source: unknownNetwork traffic detected: HTTP traffic on port 50110 -> 3128
Source: unknownNetwork traffic detected: HTTP traffic on port 50114 -> 3128
Source: unknownNetwork traffic detected: HTTP traffic on port 50116 -> 3128
Source: unknownNetwork traffic detected: HTTP traffic on port 50120 -> 3128
Source: unknownNetwork traffic detected: HTTP traffic on port 50122 -> 3128
Source: unknownNetwork traffic detected: HTTP traffic on port 50126 -> 3128
Source: unknownNetwork traffic detected: HTTP traffic on port 50128 -> 3128
Source: unknownNetwork traffic detected: HTTP traffic on port 50132 -> 3128
Source: unknownNetwork traffic detected: HTTP traffic on port 50134 -> 3128
Source: unknownNetwork traffic detected: HTTP traffic on port 50138 -> 3128
Source: unknownNetwork traffic detected: HTTP traffic on port 50140 -> 3128
Source: unknownNetwork traffic detected: HTTP traffic on port 50144 -> 3128
Source: unknownNetwork traffic detected: HTTP traffic on port 50146 -> 3128
Source: unknownNetwork traffic detected: HTTP traffic on port 50150 -> 3128
Source: unknownNetwork traffic detected: HTTP traffic on port 50152 -> 3128
Source: ELF symbol in initial sampleSymbol name: sleep
Source: /tmp/QDucAhFhA9.elf (PID: 5418)Queries kernel information via 'uname': Jump to behavior
Source: /tmp/QDucAhFhA9.elf (PID: 5424)Queries kernel information via 'uname': Jump to behavior
Source: QDucAhFhA9.elfBinary or memory string: cat /proc/scsi/scsi | grep -i -E 'VMWare|VirtualBox'
Source: QDucAhFhA9.elfBinary or memory string: @Maincat /proc/scsi/scsi | grep -i -E 'VMWare|VirtualBox'CONNECT %s:%d HTTP/1.1
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity Information1
Scripting
Valid AccountsWindows Management Instrumentation1
Systemd Service
1
Systemd Service
1
Virtualization/Sandbox Evasion
OS Credential Dumping11
Security Software Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/Job1
Scripting
Boot or Logon Initialization Scripts1
Hidden Files and Directories
LSASS Memory1
Virtualization/Sandbox Evasion
Remote Desktop ProtocolData from Removable Media1
Non-Standard Port
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Non-Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture2
Application Layer Protocol
Traffic DuplicationData Destruction
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1598696 Sample: QDucAhFhA9.elf Startdate: 24/01/2025 Architecture: LINUX Score: 52 45 95.179.223.245, 443, 59724, 59730 AS-CHOOPAUS Netherlands 2->45 47 daisy.ubuntu.com 2->47 49 Multi AV Scanner detection for submitted file 2->49 51 Uses known network protocols on non-standard ports 2->51 9 QDucAhFhA9.elf 2->9         started        11 systemd snapd-env-generator 2->11         started        signatures3 process4 process5 13 QDucAhFhA9.elf 9->13         started        15 QDucAhFhA9.elf sh 9->15         started        process6 17 QDucAhFhA9.elf sh 13->17         started        19 QDucAhFhA9.elf sh 13->19         started        21 QDucAhFhA9.elf sh 13->21         started        25 33 other processes 13->25 23 sh systemctl 15->23         started        process7 27 sh cat 17->27         started        29 sh grep 17->29         started        31 sh cat 19->31         started        33 sh grep 19->33         started        41 2 other processes 21->41 35 sh cat 25->35         started        37 sh cat 25->37         started        39 sh cat 25->39         started        43 63 other processes 25->43
SourceDetectionScannerLabelLink
QDucAhFhA9.elf52%VirustotalBrowse
QDucAhFhA9.elf45%ReversingLabsLinux.Trojan.Generic
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
daisy.ubuntu.com
162.213.35.24
truefalse
    high
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    95.179.223.245
    unknownNetherlands
    20473AS-CHOOPAUSfalse
    No context
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    daisy.ubuntu.comarm6.elfGet hashmaliciousUnknownBrowse
    • 162.213.35.25
    ppc.elfGet hashmaliciousMirai, MoobotBrowse
    • 162.213.35.24
    arm-20250124-1346.elfGet hashmaliciousMirai, MoobotBrowse
    • 162.213.35.25
    arm6-20250124-1345.elfGet hashmaliciousMirai, MoobotBrowse
    • 162.213.35.24
    mips-20250124-1345.elfGet hashmaliciousMirai, MoobotBrowse
    • 162.213.35.25
    sh4.elfGet hashmaliciousMirai, MoobotBrowse
    • 162.213.35.24
    spc.elfGet hashmaliciousMirai, MoobotBrowse
    • 162.213.35.25
    ppc.elfGet hashmaliciousMirai, MoobotBrowse
    • 162.213.35.25
    mips.elfGet hashmaliciousMirai, MoobotBrowse
    • 162.213.35.25
    arm6.elfGet hashmaliciousMirai, MoobotBrowse
    • 162.213.35.24
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    AS-CHOOPAUShttp://home45insurance.blogspot.comGet hashmaliciousUnknownBrowse
    • 45.63.66.114
    XClient.exeGet hashmaliciousXWormBrowse
    • 45.32.153.7
    https://metameaskloginr.webflow.io/Get hashmaliciousUnknownBrowse
    • 155.138.141.200
    l.jsGet hashmaliciousUnknownBrowse
    • 149.248.58.85
    l.jsGet hashmaliciousUnknownBrowse
    • 149.248.58.85
    rad59AD5.dllGet hashmaliciousUnknownBrowse
    • 149.248.58.85
    rad59AD5.dllGet hashmaliciousUnknownBrowse
    • 149.248.58.85
    http://jlolaw.comGet hashmaliciousCAPTCHA Scam ClickFixBrowse
    • 137.220.56.63
    ti.co.exeGet hashmaliciousI2PRATBrowse
    • 216.128.184.123
    lolz.exeGet hashmaliciousXmrigBrowse
    • 192.248.189.11
    No context
    No context
    Process:/tmp/QDucAhFhA9.elf
    File Type:data
    Category:dropped
    Size (bytes):32
    Entropy (8bit):0.3997900666170139
    Encrypted:false
    SSDEEP:3:kl1l:s
    MD5:637949C0C07A5E23745A7A5786AA43EC
    SHA1:31BBAAEE02CB197B915B67F90A53A479ED10DCC5
    SHA-256:9F1D358D5A7999AC6DD9C8B3A727620DAEFE11E7D79834D499233398BE2BB968
    SHA-512:2994278E49DEB6A19D062778C90AE0B14D86E4F058F877E8B87CCCF8E76DD9F3ECB72FCA1B8D7486FD887649819D9188A4037DB163004619B1E3C2C96621ABD5
    Malicious:false
    Reputation:low
    Preview:................................
    Process:/usr/lib/systemd/system-environment-generators/snapd-env-generator
    File Type:ASCII text
    Category:dropped
    Size (bytes):76
    Entropy (8bit):3.7627880354948586
    Encrypted:false
    SSDEEP:3:+M4VMPQnMLmPQ9JEcwwbn:+M4m4MixcZb
    MD5:D86A1F5765F37989EB0EC3837AD13ECC
    SHA1:D749672A734D9DEAFD61DCA501C6929EC431B83E
    SHA-256:85889AB8222C947C58BE565723AE603CC1A0BD2153B6B11E156826A21E6CCD45
    SHA-512:338C4B776FDCC2D05E869AE1F9DB64E6E7ECC4C621AB45E51DD07C73306BACBAD7882BE8D3ACF472CAEB30D4E5367F8793D3E006694184A68F74AC943A4B7C07
    Malicious:false
    Reputation:high, very likely benign file
    Preview:PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/bin.
    Process:/tmp/QDucAhFhA9.elf
    File Type:ASCII text
    Category:dropped
    Size (bytes):147
    Entropy (8bit):4.768033370826599
    Encrypted:false
    SSDEEP:3:zMZa77Gv+2AMzdK+NjJNtXKLwt5wuPXEZs1v2rSkQmWA1+DRvn:z8Iz2AMzdK+LjH5bJlkLQmWA4Rv
    MD5:84F8846E95DB3AEF2A99442203553BFD
    SHA1:F2CCED0FEE0E49E2CC35B1707E945B1114D65A01
    SHA-256:E7547BC29AFDD231E13CFDCD8C3FE10716AC1EDF7C11288E635AC671396A6FE2
    SHA-512:03E2E21068A892847C9BF8121C1D91CF1F2F4093F8DA341C7DE3A4639352EA90CDF27F4A2F5A872A466E41A1BDA38EAC6D9A536EB0D90190338F3C5925DFD3A8
    Malicious:false
    Reputation:low
    Preview:[Unit].Description=ssl-key..[Service].ExecStart=/bin/ssl-key.Restart=on-abort.RestartSec=2.KillSignal=SIGINT..[Install].WantedBy=multi-user.target.
    File type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, for GNU/Linux 2.6.32, BuildID[sha1]=3e04bdf21e1410359ef0bd0d3bbee2447e79fb7c, stripped
    Entropy (8bit):5.9172323500469055
    TrID:
    • ELF Executable and Linkable format (Linux) (4029/14) 49.77%
    • ELF Executable and Linkable format (generic) (4004/1) 49.46%
    • Lumena CEL bitmap (63/63) 0.78%
    File name:QDucAhFhA9.elf
    File size:69'488 bytes
    MD5:f35dc2d049000545febf88fe7df3ad4f
    SHA1:e283c34b76aeec35081fb8e7a3eb623955048c5f
    SHA256:c308a09ef991bc198f4501964ac545c37fdd977940eb98afd955ce715774c597
    SHA512:25fb977b8b84be534952577f1ebce95b32bbab7d49239aa7e808ddb070a7e1bfe153b3e223a54851e084c887a45927517a4c7992d5f169f9fd2a48c1ef805ba4
    SSDEEP:768:CqCl1U6zVbI8g3JVNYrWMCa6cOycS48gtdzIAQaxhO7t1f06UKU7CQnQ/+M:CqCHUOhg37K1Ca6cO0WfQ0haUv7VS+M
    TLSH:4F632A03B7D0C8B9C0C4CA7486DFE1569E7878D48327117F394ABB0D3965AA56F1EA23
    File Content Preview:.ELF..............>.......@.....@.......0...........@.8...@.............@.......@.@.....@.@.....................................8.......8.@.....8.@...............................................@.......@....................... .............8.......8.`....

    ELF header

    Class:ELF64
    Data:2's complement, little endian
    Version:1 (current)
    Machine:Advanced Micro Devices X86-64
    Version Number:0x1
    Type:EXEC (Executable file)
    OS/ABI:UNIX - System V
    ABI Version:0
    Entry Point Address:0x401c90
    Flags:0x0
    ELF Header Size:64
    Program Header Offset:64
    Program Header Size:56
    Number of Program Headers:9
    Section Header Offset:67632
    Section Header Size:64
    Number of Section Headers:29
    Header String Table Index:28
    NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
    NULL0x00x00x00x00x0000
    .interpPROGBITS0x4002380x2380x1c0x00x2A001
    .note.ABI-tagNOTE0x4002540x2540x200x00x2A004
    .note.gnu.build-idNOTE0x4002740x2740x240x00x2A004
    .gnu.hashGNU_HASH0x4002980x2980x28c0x00x2A508
    .dynsymDYNSYM0x4005280x5280x7980x180x2A618
    .dynstrSTRTAB0x400cc00xcc00x32c0x00x2A001
    .gnu.versionVERSYM0x400fec0xfec0xa20x20x2A502
    .gnu.version_rVERNEED0x4010900x10900xd00x00x2A658
    .rela.dynRELA0x4011600x11600x7200x180x2A508
    .rela.pltRELA0x4018800x18800x180x180x42AI5248
    .initPROGBITS0x4018980x18980x1a0x00x6AX004
    .pltPROGBITS0x4018c00x18c00x200x100x6AX0016
    .plt.gotPROGBITS0x4018e00x18e00x2600x00x6AX008
    .textPROGBITS0x401b400x1b400x96f00x00x6AX0016
    .finiPROGBITS0x40b2300xb2300x90x00x6AX004
    .rodataPROGBITS0x40b2400xb2400xcb30x00x2A0032
    .eh_frame_hdrPROGBITS0x40bef40xbef40x7ac0x00x2A004
    .eh_framePROGBITS0x40c6a00xc6a00x294c0x00x2A008
    .gcc_except_tablePROGBITS0x40efec0xefec0xb60x00x2A001
    .init_arrayINIT_ARRAY0x60fb380xfb380x80x00x3WA008
    .fini_arrayFINI_ARRAY0x60fb400xfb400x80x00x3WA008
    .jcrPROGBITS0x60fb480xfb480x80x00x3WA008
    .dynamicDYNAMIC0x60fb500xfb500x2300x100x3WA608
    .gotPROGBITS0x60fd800xfd800x2800x80x3WA008
    .dataPROGBITS0x6100000x100000x6f00x00x3WA0032
    .bssNOBITS0x6106f00x106f00x100x00x3WA008
    .commentPROGBITS0x00x106f00x350x10x30MS001
    .shstrtabSTRTAB0x00x107250x1050x00x0001
    TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
    PHDR0x400x4000400x4000400x1f80x1f81.88760x5R E0x8
    INTERP0x2380x4002380x4002380x1c0x1c3.94080x4R 0x1/lib64/ld-linux-x86-64.so.2.interp
    LOAD0x00x4000000x4000000xf0a20xf0a26.20100x5R E0x200000.interp .note.ABI-tag .note.gnu.build-id .gnu.hash .dynsym .dynstr .gnu.version .gnu.version_r .rela.dyn .rela.plt .init .plt .plt.got .text .fini .rodata .eh_frame_hdr .eh_frame .gcc_except_table
    LOAD0xfb380x60fb380x60fb380xbb80xbc84.18660x6RW 0x200000.init_array .fini_array .jcr .dynamic .got .data .bss
    DYNAMIC0xfb500x60fb500x60fb500x2300x2301.55150x6RW 0x8.dynamic
    NOTE0x2540x4002540x4002540x440x443.39310x4R 0x4.note.ABI-tag .note.gnu.build-id
    GNU_EH_FRAME0xbef40x40bef40x40bef40x7ac0x7ac5.12920x4R 0x4.eh_frame_hdr
    GNU_STACK0x00x00x00x00x00.00000x6RW 0x10
    GNU_RELRO0xfb380x60fb380x60fb380x4c80x4c80.89040x4R 0x1.init_array .fini_array .jcr .dynamic .got
    TypeMetaValueTag
    DT_NEEDEDsharedliblibdl.so.20x1
    DT_NEEDEDsharedliblibpthread.so.00x1
    DT_NEEDEDsharedliblibstdc++.so.60x1
    DT_NEEDEDsharedliblibgcc_s.so.10x1
    DT_NEEDEDsharedliblibc.so.60x1
    DT_INITvalue0x4018980xc
    DT_FINIvalue0x40b2300xd
    DT_INIT_ARRAYvalue0x60fb380x19
    DT_INIT_ARRAYSZbytes80x1b
    DT_FINI_ARRAYvalue0x60fb400x1a
    DT_FINI_ARRAYSZbytes80x1c
    DT_GNU_HASHvalue0x4002980x6ffffef5
    DT_STRTABvalue0x400cc00x5
    DT_SYMTABvalue0x4005280x6
    DT_STRSZbytes8120xa
    DT_SYMENTbytes240xb
    DT_DEBUGvalue0x00x15
    DT_PLTGOTvalue0x60fd800x3
    DT_PLTRELSZbytes240x2
    DT_PLTRELpltrelDT_RELA0x14
    DT_JMPRELvalue0x4018800x17
    DT_RELAvalue0x4011600x7
    DT_RELASZbytes18240x8
    DT_RELAENTbytes240x9
    DT_BIND_NOWvalue0x00x18
    DT_FLAGS_1value0x10x6ffffffb
    DT_VERNEEDvalue0x4010900x6ffffffe
    DT_VERNEEDNUMvalue50x6fffffff
    DT_VERSYMvalue0x400fec0x6ffffff0
    DT_NULLvalue0x00x0
    NameVersion Info NameVersion Info File NameSection NameValueSizeSymbol TypeSymbol BindSymbol VisibilityNdx
    .dynsym0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
    _ITM_deregisterTMCloneTable.dynsym0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
    _ITM_registerTMCloneTable.dynsym0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
    _Jv_RegisterClasses.dynsym0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
    _Unwind_ResumeGCC_3.0libgcc_s.so.1.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    _ZdaPvGLIBCXX_3.4libstdc++.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    _ZdlPvGLIBCXX_3.4libstdc++.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    _ZnamGLIBCXX_3.4libstdc++.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    _ZnwmGLIBCXX_3.4libstdc++.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    __gmon_start__.dynsym0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
    __gxx_personality_v0CXXABI_1.3libstdc++.so.6.dynsym0x4018d00FUNC<unknown>DEFAULTSHN_UNDEF
    __libc_start_mainGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    __memcpy_chkGLIBC_2.3.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    __realpath_chkGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    __snprintf_chkGLIBC_2.3.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    __sprintf_chkGLIBC_2.3.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    __stack_chk_failGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    __strcat_chkGLIBC_2.3.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    __strcpy_chkGLIBC_2.3.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    __xstat64GLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    accessGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    atoiGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    closeGLIBC_2.2.5libpthread.so.0.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    connectGLIBC_2.2.5libpthread.so.0.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    dlopenGLIBC_2.2.5libdl.so.2.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    dlsymGLIBC_2.2.5libdl.so.2.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    exitGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    fcloseGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    feofGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    fgetsGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    fopenGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    forkGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    freadGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    freeGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    fwriteGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    getenvGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    gethostbynameGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    gethostnameGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    getpwuidGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    getuidGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    inet_addrGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    inet_ntoaGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    ioctlGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    mallocGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    memcmpGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    mkdirGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    mmapGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    munmapGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    open64GLIBC_2.2.5libpthread.so.0.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    pcloseGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    pollGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    popenGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    randGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    readGLIBC_2.2.5libpthread.so.0.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    reallocGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    recvGLIBC_2.2.5libpthread.so.0.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    recvfromGLIBC_2.2.5libpthread.so.0.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    removeGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    renameGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    sem_closeGLIBC_2.2.5libpthread.so.0.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    sem_openGLIBC_2.2.5libpthread.so.0.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    sem_unlinkGLIBC_2.2.5libpthread.so.0.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    sendGLIBC_2.2.5libpthread.so.0.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    sendtoGLIBC_2.2.5libpthread.so.0.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    setsidGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    setsockoptGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    shutdownGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    signalGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    sleepGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    socketGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    srandGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    strcatGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    strchrGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    strcmpGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    strcpyGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    strstrGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    systemGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    timeGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    timesGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    unlinkGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    writeGLIBC_2.2.5libpthread.so.0.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    TimestampSource PortDest PortSource IPDest IP
    Jan 24, 2025 16:40:55.248323917 CET500843128192.168.2.1310.242.174.74
    Jan 24, 2025 16:40:55.253365993 CET31285008410.242.174.74192.168.2.13
    Jan 24, 2025 16:40:55.253424883 CET500843128192.168.2.1310.242.174.74
    Jan 24, 2025 16:40:55.254533052 CET500843128192.168.2.1310.242.174.74
    Jan 24, 2025 16:40:55.259344101 CET31285008410.242.174.74192.168.2.13
    Jan 24, 2025 16:41:16.628112078 CET31285008410.242.174.74192.168.2.13
    Jan 24, 2025 16:41:16.628595114 CET500843128192.168.2.1310.242.174.74
    Jan 24, 2025 16:41:16.629287004 CET500863128192.168.2.1310.242.174.74
    Jan 24, 2025 16:41:16.633511066 CET31285008410.242.174.74192.168.2.13
    Jan 24, 2025 16:41:16.634131908 CET31285008610.242.174.74192.168.2.13
    Jan 24, 2025 16:41:16.634222984 CET500863128192.168.2.1310.242.174.74
    Jan 24, 2025 16:41:16.634751081 CET500863128192.168.2.1310.242.174.74
    Jan 24, 2025 16:41:16.639539003 CET31285008610.242.174.74192.168.2.13
    Jan 24, 2025 16:41:38.054188013 CET31285008610.242.174.74192.168.2.13
    Jan 24, 2025 16:41:38.054424047 CET500863128192.168.2.1310.242.174.74
    Jan 24, 2025 16:41:38.055083990 CET59724443192.168.2.1395.179.223.245
    Jan 24, 2025 16:41:38.055182934 CET4435972495.179.223.245192.168.2.13
    Jan 24, 2025 16:41:38.055264950 CET59724443192.168.2.1395.179.223.245
    Jan 24, 2025 16:41:38.059354067 CET31285008610.242.174.74192.168.2.13
    Jan 24, 2025 16:41:38.126249075 CET59724443192.168.2.1395.179.223.245
    Jan 24, 2025 16:41:38.126331091 CET4435972495.179.223.245192.168.2.13
    Jan 24, 2025 16:41:38.126398087 CET4435972495.179.223.245192.168.2.13
    Jan 24, 2025 16:41:39.423604965 CET500903128192.168.2.1310.242.174.74
    Jan 24, 2025 16:41:39.428993940 CET31285009010.242.174.74192.168.2.13
    Jan 24, 2025 16:41:39.429081917 CET500903128192.168.2.1310.242.174.74
    Jan 24, 2025 16:41:39.429457903 CET500903128192.168.2.1310.242.174.74
    Jan 24, 2025 16:41:39.434526920 CET31285009010.242.174.74192.168.2.13
    Jan 24, 2025 16:42:00.802484989 CET31285009010.242.174.74192.168.2.13
    Jan 24, 2025 16:42:00.802777052 CET500903128192.168.2.1310.242.174.74
    Jan 24, 2025 16:42:00.803406954 CET500923128192.168.2.1310.242.174.74
    Jan 24, 2025 16:42:00.808571100 CET31285009010.242.174.74192.168.2.13
    Jan 24, 2025 16:42:00.809165955 CET31285009210.242.174.74192.168.2.13
    Jan 24, 2025 16:42:00.809253931 CET500923128192.168.2.1310.242.174.74
    Jan 24, 2025 16:42:00.809600115 CET500923128192.168.2.1310.242.174.74
    Jan 24, 2025 16:42:00.814461946 CET31285009210.242.174.74192.168.2.13
    Jan 24, 2025 16:42:22.239166021 CET31285009210.242.174.74192.168.2.13
    Jan 24, 2025 16:42:22.239367008 CET500923128192.168.2.1310.242.174.74
    Jan 24, 2025 16:42:22.240130901 CET59730443192.168.2.1395.179.223.245
    Jan 24, 2025 16:42:22.240225077 CET4435973095.179.223.245192.168.2.13
    Jan 24, 2025 16:42:22.240402937 CET59730443192.168.2.1395.179.223.245
    Jan 24, 2025 16:42:22.246185064 CET31285009210.242.174.74192.168.2.13
    Jan 24, 2025 16:42:22.276268005 CET59730443192.168.2.1395.179.223.245
    Jan 24, 2025 16:42:22.276294947 CET4435973095.179.223.245192.168.2.13
    Jan 24, 2025 16:42:22.276388884 CET4435973095.179.223.245192.168.2.13
    Jan 24, 2025 16:42:23.512836933 CET500963128192.168.2.1310.242.174.74
    Jan 24, 2025 16:42:23.520698071 CET31285009610.242.174.74192.168.2.13
    Jan 24, 2025 16:42:23.520786047 CET500963128192.168.2.1310.242.174.74
    Jan 24, 2025 16:42:23.521178961 CET500963128192.168.2.1310.242.174.74
    Jan 24, 2025 16:42:23.528882027 CET31285009610.242.174.74192.168.2.13
    Jan 24, 2025 16:42:44.893918991 CET31285009610.242.174.74192.168.2.13
    Jan 24, 2025 16:42:44.894066095 CET500963128192.168.2.1310.242.174.74
    Jan 24, 2025 16:42:44.894066095 CET500963128192.168.2.1310.242.174.74
    Jan 24, 2025 16:42:44.894570112 CET500983128192.168.2.1310.242.174.74
    Jan 24, 2025 16:42:44.899158955 CET31285009610.242.174.74192.168.2.13
    Jan 24, 2025 16:42:44.899452925 CET31285009810.242.174.74192.168.2.13
    Jan 24, 2025 16:42:44.899514914 CET500983128192.168.2.1310.242.174.74
    Jan 24, 2025 16:42:44.899820089 CET500983128192.168.2.1310.242.174.74
    Jan 24, 2025 16:42:44.904620886 CET31285009810.242.174.74192.168.2.13
    Jan 24, 2025 16:43:06.270699978 CET31285009810.242.174.74192.168.2.13
    Jan 24, 2025 16:43:06.270880938 CET500983128192.168.2.1310.242.174.74
    Jan 24, 2025 16:43:06.271548986 CET59736443192.168.2.1395.179.223.245
    Jan 24, 2025 16:43:06.271579027 CET4435973695.179.223.245192.168.2.13
    Jan 24, 2025 16:43:06.271645069 CET59736443192.168.2.1395.179.223.245
    Jan 24, 2025 16:43:06.275691032 CET31285009810.242.174.74192.168.2.13
    Jan 24, 2025 16:43:06.297411919 CET59736443192.168.2.1395.179.223.245
    Jan 24, 2025 16:43:06.297441959 CET4435973695.179.223.245192.168.2.13
    Jan 24, 2025 16:43:06.297560930 CET4435973695.179.223.245192.168.2.13
    Jan 24, 2025 16:43:07.562648058 CET501023128192.168.2.1310.242.174.74
    Jan 24, 2025 16:43:07.571299076 CET31285010210.242.174.74192.168.2.13
    Jan 24, 2025 16:43:07.571389914 CET501023128192.168.2.1310.242.174.74
    Jan 24, 2025 16:43:07.571877003 CET501023128192.168.2.1310.242.174.74
    Jan 24, 2025 16:43:07.576761961 CET31285010210.242.174.74192.168.2.13
    Jan 24, 2025 16:43:28.943111897 CET31285010210.242.174.74192.168.2.13
    Jan 24, 2025 16:43:28.943552017 CET501023128192.168.2.1310.242.174.74
    Jan 24, 2025 16:43:28.947962999 CET501043128192.168.2.1310.242.174.74
    Jan 24, 2025 16:43:28.948503017 CET31285010210.242.174.74192.168.2.13
    Jan 24, 2025 16:43:28.952877045 CET31285010410.242.174.74192.168.2.13
    Jan 24, 2025 16:43:28.952933073 CET501043128192.168.2.1310.242.174.74
    Jan 24, 2025 16:43:28.959321022 CET501043128192.168.2.1310.242.174.74
    Jan 24, 2025 16:43:28.964199066 CET31285010410.242.174.74192.168.2.13
    Jan 24, 2025 16:43:50.336117983 CET31285010410.242.174.74192.168.2.13
    Jan 24, 2025 16:43:50.336282015 CET501043128192.168.2.1310.242.174.74
    Jan 24, 2025 16:43:50.336903095 CET59742443192.168.2.1395.179.223.245
    Jan 24, 2025 16:43:50.336937904 CET4435974295.179.223.245192.168.2.13
    Jan 24, 2025 16:43:50.336981058 CET59742443192.168.2.1395.179.223.245
    Jan 24, 2025 16:43:50.341116905 CET31285010410.242.174.74192.168.2.13
    Jan 24, 2025 16:43:50.384141922 CET59742443192.168.2.1395.179.223.245
    Jan 24, 2025 16:43:50.384161949 CET4435974295.179.223.245192.168.2.13
    Jan 24, 2025 16:43:50.384233952 CET4435974295.179.223.245192.168.2.13
    Jan 24, 2025 16:43:51.899048090 CET501083128192.168.2.1310.242.174.74
    Jan 24, 2025 16:43:51.904486895 CET31285010810.242.174.74192.168.2.13
    Jan 24, 2025 16:43:51.904541969 CET501083128192.168.2.1310.242.174.74
    Jan 24, 2025 16:43:51.906996965 CET501083128192.168.2.1310.242.174.74
    Jan 24, 2025 16:43:51.912612915 CET31285010810.242.174.74192.168.2.13
    Jan 24, 2025 16:44:13.504590988 CET31285010810.242.174.74192.168.2.13
    Jan 24, 2025 16:44:13.504753113 CET501083128192.168.2.1310.242.174.74
    Jan 24, 2025 16:44:13.506217957 CET501103128192.168.2.1310.242.174.74
    Jan 24, 2025 16:44:13.509494066 CET31285010810.242.174.74192.168.2.13
    Jan 24, 2025 16:44:13.511053085 CET31285011010.242.174.74192.168.2.13
    Jan 24, 2025 16:44:13.511099100 CET501103128192.168.2.1310.242.174.74
    Jan 24, 2025 16:44:13.511962891 CET501103128192.168.2.1310.242.174.74
    Jan 24, 2025 16:44:13.516741037 CET31285011010.242.174.74192.168.2.13
    Jan 24, 2025 16:44:34.915396929 CET31285011010.242.174.74192.168.2.13
    Jan 24, 2025 16:44:34.915555954 CET501103128192.168.2.1310.242.174.74
    Jan 24, 2025 16:44:34.916043043 CET59748443192.168.2.1395.179.223.245
    Jan 24, 2025 16:44:34.916079044 CET4435974895.179.223.245192.168.2.13
    Jan 24, 2025 16:44:34.916122913 CET59748443192.168.2.1395.179.223.245
    Jan 24, 2025 16:44:34.920466900 CET31285011010.242.174.74192.168.2.13
    Jan 24, 2025 16:44:34.943896055 CET59748443192.168.2.1395.179.223.245
    Jan 24, 2025 16:44:34.943913937 CET4435974895.179.223.245192.168.2.13
    Jan 24, 2025 16:44:34.943974018 CET4435974895.179.223.245192.168.2.13
    Jan 24, 2025 16:44:36.212800026 CET501143128192.168.2.1310.242.174.74
    Jan 24, 2025 16:44:36.218028069 CET31285011410.242.174.74192.168.2.13
    Jan 24, 2025 16:44:36.218087912 CET501143128192.168.2.1310.242.174.74
    Jan 24, 2025 16:44:36.218493938 CET501143128192.168.2.1310.242.174.74
    Jan 24, 2025 16:44:36.223373890 CET31285011410.242.174.74192.168.2.13
    Jan 24, 2025 16:44:57.603097916 CET31285011410.242.174.74192.168.2.13
    Jan 24, 2025 16:44:57.603319883 CET501143128192.168.2.1310.242.174.74
    Jan 24, 2025 16:44:57.606688976 CET501163128192.168.2.1310.242.174.74
    Jan 24, 2025 16:44:57.608288050 CET31285011410.242.174.74192.168.2.13
    Jan 24, 2025 16:44:57.611541033 CET31285011610.242.174.74192.168.2.13
    Jan 24, 2025 16:44:57.611651897 CET501163128192.168.2.1310.242.174.74
    Jan 24, 2025 16:44:57.612579107 CET501163128192.168.2.1310.242.174.74
    Jan 24, 2025 16:44:57.617300987 CET31285011610.242.174.74192.168.2.13
    Jan 24, 2025 16:45:19.006062031 CET31285011610.242.174.74192.168.2.13
    Jan 24, 2025 16:45:19.006267071 CET501163128192.168.2.1310.242.174.74
    Jan 24, 2025 16:45:19.006777048 CET59754443192.168.2.1395.179.223.245
    Jan 24, 2025 16:45:19.006891966 CET4435975495.179.223.245192.168.2.13
    Jan 24, 2025 16:45:19.006966114 CET59754443192.168.2.1395.179.223.245
    Jan 24, 2025 16:45:19.011482954 CET31285011610.242.174.74192.168.2.13
    Jan 24, 2025 16:45:19.033123970 CET59754443192.168.2.1395.179.223.245
    Jan 24, 2025 16:45:19.033143044 CET4435975495.179.223.245192.168.2.13
    Jan 24, 2025 16:45:19.033186913 CET4435975495.179.223.245192.168.2.13
    Jan 24, 2025 16:45:20.277235031 CET501203128192.168.2.1310.242.174.74
    Jan 24, 2025 16:45:20.284634113 CET31285012010.242.174.74192.168.2.13
    Jan 24, 2025 16:45:20.284706116 CET501203128192.168.2.1310.242.174.74
    Jan 24, 2025 16:45:20.285152912 CET501203128192.168.2.1310.242.174.74
    Jan 24, 2025 16:45:20.289941072 CET31285012010.242.174.74192.168.2.13
    Jan 24, 2025 16:45:41.729353905 CET31285012010.242.174.74192.168.2.13
    Jan 24, 2025 16:45:41.729747057 CET501203128192.168.2.1310.242.174.74
    Jan 24, 2025 16:45:41.730639935 CET501223128192.168.2.1310.242.174.74
    Jan 24, 2025 16:45:41.736372948 CET31285012010.242.174.74192.168.2.13
    Jan 24, 2025 16:45:41.737103939 CET31285012210.242.174.74192.168.2.13
    Jan 24, 2025 16:45:41.737207890 CET501223128192.168.2.1310.242.174.74
    Jan 24, 2025 16:45:41.737932920 CET501223128192.168.2.1310.242.174.74
    Jan 24, 2025 16:45:41.745259047 CET31285012210.242.174.74192.168.2.13
    Jan 24, 2025 16:46:03.119945049 CET31285012210.242.174.74192.168.2.13
    Jan 24, 2025 16:46:03.120173931 CET501223128192.168.2.1310.242.174.74
    Jan 24, 2025 16:46:03.120908976 CET59760443192.168.2.1395.179.223.245
    Jan 24, 2025 16:46:03.120956898 CET4435976095.179.223.245192.168.2.13
    Jan 24, 2025 16:46:03.121032953 CET59760443192.168.2.1395.179.223.245
    Jan 24, 2025 16:46:03.125021935 CET31285012210.242.174.74192.168.2.13
    Jan 24, 2025 16:46:03.167469978 CET59760443192.168.2.1395.179.223.245
    Jan 24, 2025 16:46:03.167493105 CET4435976095.179.223.245192.168.2.13
    Jan 24, 2025 16:46:03.220202923 CET59760443192.168.2.1395.179.223.245
    Jan 24, 2025 16:46:03.220227957 CET4435976095.179.223.245192.168.2.13
    Jan 24, 2025 16:46:46.163830996 CET4435976095.179.223.245192.168.2.13
    Jan 24, 2025 16:46:46.166059971 CET59760443192.168.2.1395.179.223.245
    Jan 24, 2025 16:46:48.174217939 CET59760443192.168.2.1395.179.223.245
    Jan 24, 2025 16:46:48.174252987 CET4435976095.179.223.245192.168.2.13
    Jan 24, 2025 16:46:48.174808979 CET501263128192.168.2.1310.242.174.74
    Jan 24, 2025 16:46:48.179842949 CET31285012610.242.174.74192.168.2.13
    Jan 24, 2025 16:46:48.179919004 CET501263128192.168.2.1310.242.174.74
    Jan 24, 2025 16:46:48.180480003 CET501263128192.168.2.1310.242.174.74
    Jan 24, 2025 16:46:48.185347080 CET31285012610.242.174.74192.168.2.13
    Jan 24, 2025 16:47:09.572217941 CET31285012610.242.174.74192.168.2.13
    Jan 24, 2025 16:47:09.572458029 CET501263128192.168.2.1310.242.174.74
    Jan 24, 2025 16:47:09.577615976 CET31285012610.242.174.74192.168.2.13
    Jan 24, 2025 16:47:09.581083059 CET501283128192.168.2.1310.242.174.74
    Jan 24, 2025 16:47:09.585998058 CET31285012810.242.174.74192.168.2.13
    Jan 24, 2025 16:47:09.586075068 CET501283128192.168.2.1310.242.174.74
    Jan 24, 2025 16:47:09.588253021 CET501283128192.168.2.1310.242.174.74
    Jan 24, 2025 16:47:09.594079971 CET31285012810.242.174.74192.168.2.13
    Jan 24, 2025 16:47:30.946399927 CET31285012810.242.174.74192.168.2.13
    Jan 24, 2025 16:47:30.946688890 CET501283128192.168.2.1310.242.174.74
    Jan 24, 2025 16:47:30.950336933 CET59766443192.168.2.1395.179.223.245
    Jan 24, 2025 16:47:30.950397015 CET4435976695.179.223.245192.168.2.13
    Jan 24, 2025 16:47:30.950455904 CET59766443192.168.2.1395.179.223.245
    Jan 24, 2025 16:47:30.951596022 CET31285012810.242.174.74192.168.2.13
    Jan 24, 2025 16:47:30.993480921 CET59766443192.168.2.1395.179.223.245
    Jan 24, 2025 16:47:30.993560076 CET4435976695.179.223.245192.168.2.13
    Jan 24, 2025 16:47:30.993628979 CET4435976695.179.223.245192.168.2.13
    Jan 24, 2025 16:47:32.274646997 CET501323128192.168.2.1310.242.174.74
    Jan 24, 2025 16:47:32.283993959 CET31285013210.242.174.74192.168.2.13
    Jan 24, 2025 16:47:32.284095049 CET501323128192.168.2.1310.242.174.74
    Jan 24, 2025 16:47:32.284511089 CET501323128192.168.2.1310.242.174.74
    Jan 24, 2025 16:47:32.293524027 CET31285013210.242.174.74192.168.2.13
    Jan 24, 2025 16:47:53.689030886 CET31285013210.242.174.74192.168.2.13
    Jan 24, 2025 16:47:53.689398050 CET501323128192.168.2.1310.242.174.74
    Jan 24, 2025 16:47:53.689774036 CET501343128192.168.2.1310.242.174.74
    Jan 24, 2025 16:47:53.694346905 CET31285013210.242.174.74192.168.2.13
    Jan 24, 2025 16:47:53.694596052 CET31285013410.242.174.74192.168.2.13
    Jan 24, 2025 16:47:53.694649935 CET501343128192.168.2.1310.242.174.74
    Jan 24, 2025 16:47:53.695256948 CET501343128192.168.2.1310.242.174.74
    Jan 24, 2025 16:47:53.701102972 CET31285013410.242.174.74192.168.2.13
    Jan 24, 2025 16:48:15.055866003 CET31285013410.242.174.74192.168.2.13
    Jan 24, 2025 16:48:15.056101084 CET501343128192.168.2.1310.242.174.74
    Jan 24, 2025 16:48:15.056755066 CET59772443192.168.2.1395.179.223.245
    Jan 24, 2025 16:48:15.056767941 CET4435977295.179.223.245192.168.2.13
    Jan 24, 2025 16:48:15.056822062 CET59772443192.168.2.1395.179.223.245
    Jan 24, 2025 16:48:15.061069965 CET31285013410.242.174.74192.168.2.13
    Jan 24, 2025 16:48:15.093153954 CET59772443192.168.2.1395.179.223.245
    Jan 24, 2025 16:48:15.093167067 CET4435977295.179.223.245192.168.2.13
    Jan 24, 2025 16:48:15.093199015 CET4435977295.179.223.245192.168.2.13
    Jan 24, 2025 16:48:16.513664961 CET501383128192.168.2.1310.242.174.74
    Jan 24, 2025 16:48:16.519037962 CET31285013810.242.174.74192.168.2.13
    Jan 24, 2025 16:48:16.519207001 CET501383128192.168.2.1310.242.174.74
    Jan 24, 2025 16:48:16.519572973 CET501383128192.168.2.1310.242.174.74
    Jan 24, 2025 16:48:16.524777889 CET31285013810.242.174.74192.168.2.13
    Jan 24, 2025 16:48:37.886246920 CET31285013810.242.174.74192.168.2.13
    Jan 24, 2025 16:48:37.886461973 CET501383128192.168.2.1310.242.174.74
    Jan 24, 2025 16:48:37.887352943 CET501403128192.168.2.1310.242.174.74
    Jan 24, 2025 16:48:37.891398907 CET31285013810.242.174.74192.168.2.13
    Jan 24, 2025 16:48:37.894433975 CET31285014010.242.174.74192.168.2.13
    Jan 24, 2025 16:48:37.894501925 CET501403128192.168.2.1310.242.174.74
    Jan 24, 2025 16:48:37.895569086 CET501403128192.168.2.1310.242.174.74
    Jan 24, 2025 16:48:37.903037071 CET31285014010.242.174.74192.168.2.13
    Jan 24, 2025 16:48:59.260603905 CET31285014010.242.174.74192.168.2.13
    Jan 24, 2025 16:48:59.260847092 CET501403128192.168.2.1310.242.174.74
    Jan 24, 2025 16:48:59.262170076 CET59778443192.168.2.1395.179.223.245
    Jan 24, 2025 16:48:59.262192965 CET4435977895.179.223.245192.168.2.13
    Jan 24, 2025 16:48:59.262264967 CET59778443192.168.2.1395.179.223.245
    Jan 24, 2025 16:48:59.265712976 CET31285014010.242.174.74192.168.2.13
    Jan 24, 2025 16:48:59.307538033 CET59778443192.168.2.1395.179.223.245
    Jan 24, 2025 16:48:59.307560921 CET4435977895.179.223.245192.168.2.13
    Jan 24, 2025 16:48:59.307719946 CET4435977895.179.223.245192.168.2.13
    Jan 24, 2025 16:49:01.159353018 CET501443128192.168.2.1310.242.174.74
    Jan 24, 2025 16:49:01.166342974 CET31285014410.242.174.74192.168.2.13
    Jan 24, 2025 16:49:01.166435957 CET501443128192.168.2.1310.242.174.74
    Jan 24, 2025 16:49:01.168773890 CET501443128192.168.2.1310.242.174.74
    Jan 24, 2025 16:49:01.173890114 CET31285014410.242.174.74192.168.2.13
    Jan 24, 2025 16:49:22.542049885 CET31285014410.242.174.74192.168.2.13
    Jan 24, 2025 16:49:22.542557001 CET501443128192.168.2.1310.242.174.74
    Jan 24, 2025 16:49:22.543489933 CET501463128192.168.2.1310.242.174.74
    Jan 24, 2025 16:49:22.547605991 CET31285014410.242.174.74192.168.2.13
    Jan 24, 2025 16:49:22.548561096 CET31285014610.242.174.74192.168.2.13
    Jan 24, 2025 16:49:22.548650980 CET501463128192.168.2.1310.242.174.74
    Jan 24, 2025 16:49:22.549211979 CET501463128192.168.2.1310.242.174.74
    Jan 24, 2025 16:49:22.553976059 CET31285014610.242.174.74192.168.2.13
    Jan 24, 2025 16:49:43.917047977 CET31285014610.242.174.74192.168.2.13
    Jan 24, 2025 16:49:43.917395115 CET501463128192.168.2.1310.242.174.74
    Jan 24, 2025 16:49:43.918239117 CET59784443192.168.2.1395.179.223.245
    Jan 24, 2025 16:49:43.918299913 CET4435978495.179.223.245192.168.2.13
    Jan 24, 2025 16:49:43.918376923 CET59784443192.168.2.1395.179.223.245
    Jan 24, 2025 16:49:43.922230005 CET31285014610.242.174.74192.168.2.13
    Jan 24, 2025 16:49:43.952965021 CET59784443192.168.2.1395.179.223.245
    Jan 24, 2025 16:49:43.953006983 CET4435978495.179.223.245192.168.2.13
    Jan 24, 2025 16:49:43.953073025 CET4435978495.179.223.245192.168.2.13
    Jan 24, 2025 16:49:45.201165915 CET501503128192.168.2.1310.242.174.74
    Jan 24, 2025 16:49:45.207925081 CET31285015010.242.174.74192.168.2.13
    Jan 24, 2025 16:49:45.208180904 CET501503128192.168.2.1310.242.174.74
    Jan 24, 2025 16:49:45.208724022 CET501503128192.168.2.1310.242.174.74
    Jan 24, 2025 16:49:45.213516951 CET31285015010.242.174.74192.168.2.13
    Jan 24, 2025 16:50:06.573745966 CET31285015010.242.174.74192.168.2.13
    Jan 24, 2025 16:50:06.574167967 CET501503128192.168.2.1310.242.174.74
    Jan 24, 2025 16:50:06.575301886 CET501523128192.168.2.1310.242.174.74
    Jan 24, 2025 16:50:06.579400063 CET31285015010.242.174.74192.168.2.13
    Jan 24, 2025 16:50:06.580693007 CET31285015210.242.174.74192.168.2.13
    Jan 24, 2025 16:50:06.580764055 CET501523128192.168.2.1310.242.174.74
    Jan 24, 2025 16:50:06.581598043 CET501523128192.168.2.1310.242.174.74
    Jan 24, 2025 16:50:06.587372065 CET31285015210.242.174.74192.168.2.13
    TimestampSource PortDest PortSource IPDest IP
    Jan 24, 2025 16:43:39.484874964 CET4459453192.168.2.138.8.8.8
    Jan 24, 2025 16:43:39.484965086 CET4251553192.168.2.138.8.8.8
    Jan 24, 2025 16:43:39.491394997 CET53425158.8.8.8192.168.2.13
    Jan 24, 2025 16:43:39.492399931 CET53445948.8.8.8192.168.2.13
    TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
    Jan 24, 2025 16:43:39.484874964 CET192.168.2.138.8.8.80x4046Standard query (0)daisy.ubuntu.comA (IP address)IN (0x0001)false
    Jan 24, 2025 16:43:39.484965086 CET192.168.2.138.8.8.80xb6bbStandard query (0)daisy.ubuntu.com28IN (0x0001)false
    TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
    Jan 24, 2025 16:43:39.492399931 CET8.8.8.8192.168.2.130x4046No error (0)daisy.ubuntu.com162.213.35.24A (IP address)IN (0x0001)false
    Jan 24, 2025 16:43:39.492399931 CET8.8.8.8192.168.2.130x4046No error (0)daisy.ubuntu.com162.213.35.25A (IP address)IN (0x0001)false
    Session IDSource IPSource PortDestination IPDestination Port
    0192.168.2.135008410.242.174.743128
    TimestampBytes transferredDirectionData
    Jan 24, 2025 16:40:55.254533052 CET77OUTCONNECT 95.179.223.245:443 HTTP/1.1
    Host: 95.179.223.245:443


    Session IDSource IPSource PortDestination IPDestination Port
    1192.168.2.135008610.242.174.743128
    TimestampBytes transferredDirectionData
    Jan 24, 2025 16:41:16.634751081 CET73OUTCONNECT 65.20.101.19:443 HTTP/1.1
    Host: 65.20.101.19:443


    Session IDSource IPSource PortDestination IPDestination Port
    2192.168.2.135009010.242.174.743128
    TimestampBytes transferredDirectionData
    Jan 24, 2025 16:41:39.429457903 CET77OUTCONNECT 95.179.223.245:443 HTTP/1.1
    Host: 95.179.223.245:443


    Session IDSource IPSource PortDestination IPDestination Port
    3192.168.2.135009210.242.174.743128
    TimestampBytes transferredDirectionData
    Jan 24, 2025 16:42:00.809600115 CET73OUTCONNECT 65.20.101.19:443 HTTP/1.1
    Host: 65.20.101.19:443


    Session IDSource IPSource PortDestination IPDestination Port
    4192.168.2.135009610.242.174.743128
    TimestampBytes transferredDirectionData
    Jan 24, 2025 16:42:23.521178961 CET77OUTCONNECT 95.179.223.245:443 HTTP/1.1
    Host: 95.179.223.245:443


    Session IDSource IPSource PortDestination IPDestination Port
    5192.168.2.135009810.242.174.743128
    TimestampBytes transferredDirectionData
    Jan 24, 2025 16:42:44.899820089 CET73OUTCONNECT 65.20.101.19:443 HTTP/1.1
    Host: 65.20.101.19:443


    Session IDSource IPSource PortDestination IPDestination Port
    6192.168.2.135010210.242.174.743128
    TimestampBytes transferredDirectionData
    Jan 24, 2025 16:43:07.571877003 CET77OUTCONNECT 95.179.223.245:443 HTTP/1.1
    Host: 95.179.223.245:443


    Session IDSource IPSource PortDestination IPDestination Port
    7192.168.2.135010410.242.174.743128
    TimestampBytes transferredDirectionData
    Jan 24, 2025 16:43:28.959321022 CET73OUTCONNECT 65.20.101.19:443 HTTP/1.1
    Host: 65.20.101.19:443


    Session IDSource IPSource PortDestination IPDestination Port
    8192.168.2.135010810.242.174.743128
    TimestampBytes transferredDirectionData
    Jan 24, 2025 16:43:51.906996965 CET77OUTCONNECT 95.179.223.245:443 HTTP/1.1
    Host: 95.179.223.245:443


    Session IDSource IPSource PortDestination IPDestination Port
    9192.168.2.135011010.242.174.743128
    TimestampBytes transferredDirectionData
    Jan 24, 2025 16:44:13.511962891 CET73OUTCONNECT 65.20.101.19:443 HTTP/1.1
    Host: 65.20.101.19:443


    Session IDSource IPSource PortDestination IPDestination Port
    10192.168.2.135011410.242.174.743128
    TimestampBytes transferredDirectionData
    Jan 24, 2025 16:44:36.218493938 CET77OUTCONNECT 95.179.223.245:443 HTTP/1.1
    Host: 95.179.223.245:443


    Session IDSource IPSource PortDestination IPDestination Port
    11192.168.2.135011610.242.174.743128
    TimestampBytes transferredDirectionData
    Jan 24, 2025 16:44:57.612579107 CET73OUTCONNECT 65.20.101.19:443 HTTP/1.1
    Host: 65.20.101.19:443


    Session IDSource IPSource PortDestination IPDestination Port
    12192.168.2.135012010.242.174.743128
    TimestampBytes transferredDirectionData
    Jan 24, 2025 16:45:20.285152912 CET77OUTCONNECT 95.179.223.245:443 HTTP/1.1
    Host: 95.179.223.245:443


    Session IDSource IPSource PortDestination IPDestination Port
    13192.168.2.135012210.242.174.743128
    TimestampBytes transferredDirectionData
    Jan 24, 2025 16:45:41.737932920 CET73OUTCONNECT 65.20.101.19:443 HTTP/1.1
    Host: 65.20.101.19:443


    Session IDSource IPSource PortDestination IPDestination Port
    14192.168.2.135012610.242.174.743128
    TimestampBytes transferredDirectionData
    Jan 24, 2025 16:46:48.180480003 CET77OUTCONNECT 95.179.223.245:443 HTTP/1.1
    Host: 95.179.223.245:443


    Session IDSource IPSource PortDestination IPDestination Port
    15192.168.2.135012810.242.174.743128
    TimestampBytes transferredDirectionData
    Jan 24, 2025 16:47:09.588253021 CET73OUTCONNECT 65.20.101.19:443 HTTP/1.1
    Host: 65.20.101.19:443


    Session IDSource IPSource PortDestination IPDestination Port
    16192.168.2.135013210.242.174.743128
    TimestampBytes transferredDirectionData
    Jan 24, 2025 16:47:32.284511089 CET77OUTCONNECT 95.179.223.245:443 HTTP/1.1
    Host: 95.179.223.245:443


    Session IDSource IPSource PortDestination IPDestination Port
    17192.168.2.135013410.242.174.743128
    TimestampBytes transferredDirectionData
    Jan 24, 2025 16:47:53.695256948 CET73OUTCONNECT 65.20.101.19:443 HTTP/1.1
    Host: 65.20.101.19:443


    Session IDSource IPSource PortDestination IPDestination Port
    18192.168.2.135013810.242.174.743128
    TimestampBytes transferredDirectionData
    Jan 24, 2025 16:48:16.519572973 CET77OUTCONNECT 95.179.223.245:443 HTTP/1.1
    Host: 95.179.223.245:443


    Session IDSource IPSource PortDestination IPDestination Port
    19192.168.2.135014010.242.174.743128
    TimestampBytes transferredDirectionData
    Jan 24, 2025 16:48:37.895569086 CET73OUTCONNECT 65.20.101.19:443 HTTP/1.1
    Host: 65.20.101.19:443


    Session IDSource IPSource PortDestination IPDestination Port
    20192.168.2.135014410.242.174.743128
    TimestampBytes transferredDirectionData
    Jan 24, 2025 16:49:01.168773890 CET77OUTCONNECT 95.179.223.245:443 HTTP/1.1
    Host: 95.179.223.245:443


    Session IDSource IPSource PortDestination IPDestination Port
    21192.168.2.135014610.242.174.743128
    TimestampBytes transferredDirectionData
    Jan 24, 2025 16:49:22.549211979 CET73OUTCONNECT 65.20.101.19:443 HTTP/1.1
    Host: 65.20.101.19:443


    Session IDSource IPSource PortDestination IPDestination Port
    22192.168.2.135015010.242.174.743128
    TimestampBytes transferredDirectionData
    Jan 24, 2025 16:49:45.208724022 CET77OUTCONNECT 95.179.223.245:443 HTTP/1.1
    Host: 95.179.223.245:443


    Session IDSource IPSource PortDestination IPDestination Port
    23192.168.2.135015210.242.174.743128
    TimestampBytes transferredDirectionData
    Jan 24, 2025 16:50:06.581598043 CET73OUTCONNECT 65.20.101.19:443 HTTP/1.1
    Host: 65.20.101.19:443


    System Behavior

    Start time (UTC):15:40:54
    Start date (UTC):24/01/2025
    Path:/tmp/QDucAhFhA9.elf
    Arguments:/tmp/QDucAhFhA9.elf
    File size:69488 bytes
    MD5 hash:f35dc2d049000545febf88fe7df3ad4f

    Start time (UTC):15:40:54
    Start date (UTC):24/01/2025
    Path:/tmp/QDucAhFhA9.elf
    Arguments:-
    File size:69488 bytes
    MD5 hash:f35dc2d049000545febf88fe7df3ad4f

    Start time (UTC):15:40:54
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:sh -c "systemctl enable ssl-key >/dev/null 2>/dev/null"
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:40:54
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:-
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:40:54
    Start date (UTC):24/01/2025
    Path:/usr/bin/systemctl
    Arguments:systemctl enable ssl-key
    File size:996584 bytes
    MD5 hash:4deddfb6741481f68aeac522cc26ff4b

    Start time (UTC):15:40:54
    Start date (UTC):24/01/2025
    Path:/tmp/QDucAhFhA9.elf
    Arguments:-
    File size:69488 bytes
    MD5 hash:f35dc2d049000545febf88fe7df3ad4f

    Start time (UTC):15:40:54
    Start date (UTC):24/01/2025
    Path:/tmp/QDucAhFhA9.elf
    Arguments:-
    File size:69488 bytes
    MD5 hash:f35dc2d049000545febf88fe7df3ad4f

    Start time (UTC):15:40:54
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:sh -c "cat $HOME/.mozilla/firefox/*release/prefs.js | grep network.proxy.ssl"
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:40:54
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:-
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:40:54
    Start date (UTC):24/01/2025
    Path:/usr/bin/cat
    Arguments:cat /root/.mozilla/firefox/*release/prefs.js
    File size:43416 bytes
    MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

    Start time (UTC):15:40:54
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:-
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:40:54
    Start date (UTC):24/01/2025
    Path:/usr/bin/grep
    Arguments:grep network.proxy.ssl
    File size:199136 bytes
    MD5 hash:1e6ebb9dd094f774478f72727bdba0f5

    Start time (UTC):15:40:54
    Start date (UTC):24/01/2025
    Path:/tmp/QDucAhFhA9.elf
    Arguments:-
    File size:69488 bytes
    MD5 hash:f35dc2d049000545febf88fe7df3ad4f

    Start time (UTC):15:40:54
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:sh -c "cat $HOME/.mozilla/firefox/*default/prefs.js | grep network.proxy.ssl"
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:40:54
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:-
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:40:54
    Start date (UTC):24/01/2025
    Path:/usr/bin/cat
    Arguments:cat /root/.mozilla/firefox/*default/prefs.js
    File size:43416 bytes
    MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

    Start time (UTC):15:40:54
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:-
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:40:54
    Start date (UTC):24/01/2025
    Path:/usr/bin/grep
    Arguments:grep network.proxy.ssl
    File size:199136 bytes
    MD5 hash:1e6ebb9dd094f774478f72727bdba0f5

    Start time (UTC):15:40:54
    Start date (UTC):24/01/2025
    Path:/tmp/QDucAhFhA9.elf
    Arguments:-
    File size:69488 bytes
    MD5 hash:f35dc2d049000545febf88fe7df3ad4f

    Start time (UTC):15:40:54
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:sh -c "cat /etc/profile | grep https_proxy"
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:40:54
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:-
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:40:54
    Start date (UTC):24/01/2025
    Path:/usr/bin/cat
    Arguments:cat /etc/profile
    File size:43416 bytes
    MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

    Start time (UTC):15:40:54
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:-
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:40:54
    Start date (UTC):24/01/2025
    Path:/usr/bin/grep
    Arguments:grep https_proxy
    File size:199136 bytes
    MD5 hash:1e6ebb9dd094f774478f72727bdba0f5

    Start time (UTC):15:41:38
    Start date (UTC):24/01/2025
    Path:/tmp/QDucAhFhA9.elf
    Arguments:-
    File size:69488 bytes
    MD5 hash:f35dc2d049000545febf88fe7df3ad4f

    Start time (UTC):15:41:38
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:sh -c "cat $HOME/.mozilla/firefox/*release/prefs.js | grep network.proxy.ssl"
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:41:38
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:-
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:41:38
    Start date (UTC):24/01/2025
    Path:/usr/bin/cat
    Arguments:cat /root/.mozilla/firefox/*release/prefs.js
    File size:43416 bytes
    MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

    Start time (UTC):15:41:38
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:-
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:41:38
    Start date (UTC):24/01/2025
    Path:/usr/bin/grep
    Arguments:grep network.proxy.ssl
    File size:199136 bytes
    MD5 hash:1e6ebb9dd094f774478f72727bdba0f5

    Start time (UTC):15:41:38
    Start date (UTC):24/01/2025
    Path:/tmp/QDucAhFhA9.elf
    Arguments:-
    File size:69488 bytes
    MD5 hash:f35dc2d049000545febf88fe7df3ad4f

    Start time (UTC):15:41:38
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:sh -c "cat $HOME/.mozilla/firefox/*default/prefs.js | grep network.proxy.ssl"
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:41:38
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:-
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:41:38
    Start date (UTC):24/01/2025
    Path:/usr/bin/cat
    Arguments:cat /root/.mozilla/firefox/*default/prefs.js
    File size:43416 bytes
    MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

    Start time (UTC):15:41:38
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:-
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:41:38
    Start date (UTC):24/01/2025
    Path:/usr/bin/grep
    Arguments:grep network.proxy.ssl
    File size:199136 bytes
    MD5 hash:1e6ebb9dd094f774478f72727bdba0f5

    Start time (UTC):15:41:38
    Start date (UTC):24/01/2025
    Path:/tmp/QDucAhFhA9.elf
    Arguments:-
    File size:69488 bytes
    MD5 hash:f35dc2d049000545febf88fe7df3ad4f

    Start time (UTC):15:41:38
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:sh -c "cat /etc/profile | grep https_proxy"
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:41:38
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:-
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:41:38
    Start date (UTC):24/01/2025
    Path:/usr/bin/cat
    Arguments:cat /etc/profile
    File size:43416 bytes
    MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

    Start time (UTC):15:41:38
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:-
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:41:38
    Start date (UTC):24/01/2025
    Path:/usr/bin/grep
    Arguments:grep https_proxy
    File size:199136 bytes
    MD5 hash:1e6ebb9dd094f774478f72727bdba0f5

    Start time (UTC):15:42:22
    Start date (UTC):24/01/2025
    Path:/tmp/QDucAhFhA9.elf
    Arguments:-
    File size:69488 bytes
    MD5 hash:f35dc2d049000545febf88fe7df3ad4f

    Start time (UTC):15:42:22
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:sh -c "cat $HOME/.mozilla/firefox/*release/prefs.js | grep network.proxy.ssl"
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:42:22
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:-
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:42:22
    Start date (UTC):24/01/2025
    Path:/usr/bin/cat
    Arguments:cat /root/.mozilla/firefox/*release/prefs.js
    File size:43416 bytes
    MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

    Start time (UTC):15:42:22
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:-
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:42:22
    Start date (UTC):24/01/2025
    Path:/usr/bin/grep
    Arguments:grep network.proxy.ssl
    File size:199136 bytes
    MD5 hash:1e6ebb9dd094f774478f72727bdba0f5

    Start time (UTC):15:42:22
    Start date (UTC):24/01/2025
    Path:/tmp/QDucAhFhA9.elf
    Arguments:-
    File size:69488 bytes
    MD5 hash:f35dc2d049000545febf88fe7df3ad4f

    Start time (UTC):15:42:22
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:sh -c "cat $HOME/.mozilla/firefox/*default/prefs.js | grep network.proxy.ssl"
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:42:22
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:-
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:42:22
    Start date (UTC):24/01/2025
    Path:/usr/bin/cat
    Arguments:cat /root/.mozilla/firefox/*default/prefs.js
    File size:43416 bytes
    MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

    Start time (UTC):15:42:22
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:-
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:42:22
    Start date (UTC):24/01/2025
    Path:/usr/bin/grep
    Arguments:grep network.proxy.ssl
    File size:199136 bytes
    MD5 hash:1e6ebb9dd094f774478f72727bdba0f5

    Start time (UTC):15:42:23
    Start date (UTC):24/01/2025
    Path:/tmp/QDucAhFhA9.elf
    Arguments:-
    File size:69488 bytes
    MD5 hash:f35dc2d049000545febf88fe7df3ad4f

    Start time (UTC):15:42:23
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:sh -c "cat /etc/profile | grep https_proxy"
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:42:23
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:-
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:42:23
    Start date (UTC):24/01/2025
    Path:/usr/bin/cat
    Arguments:cat /etc/profile
    File size:43416 bytes
    MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

    Start time (UTC):15:42:23
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:-
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:42:23
    Start date (UTC):24/01/2025
    Path:/usr/bin/grep
    Arguments:grep https_proxy
    File size:199136 bytes
    MD5 hash:1e6ebb9dd094f774478f72727bdba0f5

    Start time (UTC):15:43:06
    Start date (UTC):24/01/2025
    Path:/tmp/QDucAhFhA9.elf
    Arguments:-
    File size:69488 bytes
    MD5 hash:f35dc2d049000545febf88fe7df3ad4f

    Start time (UTC):15:43:06
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:sh -c "cat $HOME/.mozilla/firefox/*release/prefs.js | grep network.proxy.ssl"
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:43:06
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:-
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:43:06
    Start date (UTC):24/01/2025
    Path:/usr/bin/cat
    Arguments:cat /root/.mozilla/firefox/*release/prefs.js
    File size:43416 bytes
    MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

    Start time (UTC):15:43:06
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:-
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:43:06
    Start date (UTC):24/01/2025
    Path:/usr/bin/grep
    Arguments:grep network.proxy.ssl
    File size:199136 bytes
    MD5 hash:1e6ebb9dd094f774478f72727bdba0f5

    Start time (UTC):15:43:06
    Start date (UTC):24/01/2025
    Path:/tmp/QDucAhFhA9.elf
    Arguments:-
    File size:69488 bytes
    MD5 hash:f35dc2d049000545febf88fe7df3ad4f

    Start time (UTC):15:43:06
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:sh -c "cat $HOME/.mozilla/firefox/*default/prefs.js | grep network.proxy.ssl"
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:43:06
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:-
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:43:06
    Start date (UTC):24/01/2025
    Path:/usr/bin/cat
    Arguments:cat /root/.mozilla/firefox/*default/prefs.js
    File size:43416 bytes
    MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

    Start time (UTC):15:43:06
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:-
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:43:07
    Start date (UTC):24/01/2025
    Path:/usr/bin/grep
    Arguments:grep network.proxy.ssl
    File size:199136 bytes
    MD5 hash:1e6ebb9dd094f774478f72727bdba0f5

    Start time (UTC):15:43:07
    Start date (UTC):24/01/2025
    Path:/tmp/QDucAhFhA9.elf
    Arguments:-
    File size:69488 bytes
    MD5 hash:f35dc2d049000545febf88fe7df3ad4f

    Start time (UTC):15:43:07
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:sh -c "cat /etc/profile | grep https_proxy"
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:43:07
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:-
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:43:07
    Start date (UTC):24/01/2025
    Path:/usr/bin/cat
    Arguments:cat /etc/profile
    File size:43416 bytes
    MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

    Start time (UTC):15:43:07
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:-
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:43:07
    Start date (UTC):24/01/2025
    Path:/usr/bin/grep
    Arguments:grep https_proxy
    File size:199136 bytes
    MD5 hash:1e6ebb9dd094f774478f72727bdba0f5

    Start time (UTC):15:43:51
    Start date (UTC):24/01/2025
    Path:/tmp/QDucAhFhA9.elf
    Arguments:-
    File size:69488 bytes
    MD5 hash:f35dc2d049000545febf88fe7df3ad4f

    Start time (UTC):15:43:51
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:sh -c "cat $HOME/.mozilla/firefox/*release/prefs.js | grep network.proxy.ssl"
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:43:51
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:-
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:43:51
    Start date (UTC):24/01/2025
    Path:/usr/bin/cat
    Arguments:cat /root/.mozilla/firefox/*release/prefs.js
    File size:43416 bytes
    MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

    Start time (UTC):15:43:51
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:-
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:43:51
    Start date (UTC):24/01/2025
    Path:/usr/bin/grep
    Arguments:grep network.proxy.ssl
    File size:199136 bytes
    MD5 hash:1e6ebb9dd094f774478f72727bdba0f5

    Start time (UTC):15:43:51
    Start date (UTC):24/01/2025
    Path:/tmp/QDucAhFhA9.elf
    Arguments:-
    File size:69488 bytes
    MD5 hash:f35dc2d049000545febf88fe7df3ad4f

    Start time (UTC):15:43:51
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:sh -c "cat $HOME/.mozilla/firefox/*default/prefs.js | grep network.proxy.ssl"
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:43:51
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:-
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:43:51
    Start date (UTC):24/01/2025
    Path:/usr/bin/cat
    Arguments:cat /root/.mozilla/firefox/*default/prefs.js
    File size:43416 bytes
    MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

    Start time (UTC):15:43:51
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:-
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:43:51
    Start date (UTC):24/01/2025
    Path:/usr/bin/grep
    Arguments:grep network.proxy.ssl
    File size:199136 bytes
    MD5 hash:1e6ebb9dd094f774478f72727bdba0f5

    Start time (UTC):15:43:51
    Start date (UTC):24/01/2025
    Path:/tmp/QDucAhFhA9.elf
    Arguments:-
    File size:69488 bytes
    MD5 hash:f35dc2d049000545febf88fe7df3ad4f

    Start time (UTC):15:43:51
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:sh -c "cat /etc/profile | grep https_proxy"
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:43:51
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:-
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:43:51
    Start date (UTC):24/01/2025
    Path:/usr/bin/cat
    Arguments:cat /etc/profile
    File size:43416 bytes
    MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

    Start time (UTC):15:43:51
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:-
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:43:51
    Start date (UTC):24/01/2025
    Path:/usr/bin/grep
    Arguments:grep https_proxy
    File size:199136 bytes
    MD5 hash:1e6ebb9dd094f774478f72727bdba0f5

    Start time (UTC):15:44:35
    Start date (UTC):24/01/2025
    Path:/tmp/QDucAhFhA9.elf
    Arguments:-
    File size:69488 bytes
    MD5 hash:f35dc2d049000545febf88fe7df3ad4f

    Start time (UTC):15:44:35
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:sh -c "cat $HOME/.mozilla/firefox/*release/prefs.js | grep network.proxy.ssl"
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:44:35
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:-
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:44:35
    Start date (UTC):24/01/2025
    Path:/usr/bin/cat
    Arguments:cat /root/.mozilla/firefox/*release/prefs.js
    File size:43416 bytes
    MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

    Start time (UTC):15:44:35
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:-
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:44:35
    Start date (UTC):24/01/2025
    Path:/usr/bin/grep
    Arguments:grep network.proxy.ssl
    File size:199136 bytes
    MD5 hash:1e6ebb9dd094f774478f72727bdba0f5

    Start time (UTC):15:44:35
    Start date (UTC):24/01/2025
    Path:/tmp/QDucAhFhA9.elf
    Arguments:-
    File size:69488 bytes
    MD5 hash:f35dc2d049000545febf88fe7df3ad4f

    Start time (UTC):15:44:35
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:sh -c "cat $HOME/.mozilla/firefox/*default/prefs.js | grep network.proxy.ssl"
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:44:35
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:-
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:44:35
    Start date (UTC):24/01/2025
    Path:/usr/bin/cat
    Arguments:cat /root/.mozilla/firefox/*default/prefs.js
    File size:43416 bytes
    MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

    Start time (UTC):15:44:35
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:-
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:44:35
    Start date (UTC):24/01/2025
    Path:/usr/bin/grep
    Arguments:grep network.proxy.ssl
    File size:199136 bytes
    MD5 hash:1e6ebb9dd094f774478f72727bdba0f5

    Start time (UTC):15:44:35
    Start date (UTC):24/01/2025
    Path:/tmp/QDucAhFhA9.elf
    Arguments:-
    File size:69488 bytes
    MD5 hash:f35dc2d049000545febf88fe7df3ad4f

    Start time (UTC):15:44:35
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:sh -c "cat /etc/profile | grep https_proxy"
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:44:35
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:-
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:44:35
    Start date (UTC):24/01/2025
    Path:/usr/bin/cat
    Arguments:cat /etc/profile
    File size:43416 bytes
    MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

    Start time (UTC):15:44:35
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:-
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:44:35
    Start date (UTC):24/01/2025
    Path:/usr/bin/grep
    Arguments:grep https_proxy
    File size:199136 bytes
    MD5 hash:1e6ebb9dd094f774478f72727bdba0f5

    Start time (UTC):15:45:19
    Start date (UTC):24/01/2025
    Path:/tmp/QDucAhFhA9.elf
    Arguments:-
    File size:69488 bytes
    MD5 hash:f35dc2d049000545febf88fe7df3ad4f

    Start time (UTC):15:45:19
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:sh -c "cat $HOME/.mozilla/firefox/*release/prefs.js | grep network.proxy.ssl"
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:45:19
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:-
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:45:19
    Start date (UTC):24/01/2025
    Path:/usr/bin/cat
    Arguments:cat /root/.mozilla/firefox/*release/prefs.js
    File size:43416 bytes
    MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

    Start time (UTC):15:45:19
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:-
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:45:19
    Start date (UTC):24/01/2025
    Path:/usr/bin/grep
    Arguments:grep network.proxy.ssl
    File size:199136 bytes
    MD5 hash:1e6ebb9dd094f774478f72727bdba0f5

    Start time (UTC):15:45:19
    Start date (UTC):24/01/2025
    Path:/tmp/QDucAhFhA9.elf
    Arguments:-
    File size:69488 bytes
    MD5 hash:f35dc2d049000545febf88fe7df3ad4f

    Start time (UTC):15:45:19
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:sh -c "cat $HOME/.mozilla/firefox/*default/prefs.js | grep network.proxy.ssl"
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:45:19
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:-
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:45:19
    Start date (UTC):24/01/2025
    Path:/usr/bin/cat
    Arguments:cat /root/.mozilla/firefox/*default/prefs.js
    File size:43416 bytes
    MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

    Start time (UTC):15:45:19
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:-
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:45:19
    Start date (UTC):24/01/2025
    Path:/usr/bin/grep
    Arguments:grep network.proxy.ssl
    File size:199136 bytes
    MD5 hash:1e6ebb9dd094f774478f72727bdba0f5

    Start time (UTC):15:45:19
    Start date (UTC):24/01/2025
    Path:/tmp/QDucAhFhA9.elf
    Arguments:-
    File size:69488 bytes
    MD5 hash:f35dc2d049000545febf88fe7df3ad4f

    Start time (UTC):15:45:19
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:sh -c "cat /etc/profile | grep https_proxy"
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:45:19
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:-
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:45:19
    Start date (UTC):24/01/2025
    Path:/usr/bin/cat
    Arguments:cat /etc/profile
    File size:43416 bytes
    MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

    Start time (UTC):15:45:19
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:-
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:45:19
    Start date (UTC):24/01/2025
    Path:/usr/bin/grep
    Arguments:grep https_proxy
    File size:199136 bytes
    MD5 hash:1e6ebb9dd094f774478f72727bdba0f5

    Start time (UTC):15:46:46
    Start date (UTC):24/01/2025
    Path:/tmp/QDucAhFhA9.elf
    Arguments:-
    File size:69488 bytes
    MD5 hash:f35dc2d049000545febf88fe7df3ad4f

    Start time (UTC):15:46:46
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:sh -c "cat $HOME/.mozilla/firefox/*release/prefs.js | grep network.proxy.ssl"
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:46:46
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:-
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:46:46
    Start date (UTC):24/01/2025
    Path:/usr/bin/cat
    Arguments:cat /root/.mozilla/firefox/*release/prefs.js
    File size:43416 bytes
    MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

    Start time (UTC):15:46:46
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:-
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:46:46
    Start date (UTC):24/01/2025
    Path:/usr/bin/grep
    Arguments:grep network.proxy.ssl
    File size:199136 bytes
    MD5 hash:1e6ebb9dd094f774478f72727bdba0f5

    Start time (UTC):15:46:47
    Start date (UTC):24/01/2025
    Path:/tmp/QDucAhFhA9.elf
    Arguments:-
    File size:69488 bytes
    MD5 hash:f35dc2d049000545febf88fe7df3ad4f

    Start time (UTC):15:46:47
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:sh -c "cat $HOME/.mozilla/firefox/*default/prefs.js | grep network.proxy.ssl"
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:46:47
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:-
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:46:47
    Start date (UTC):24/01/2025
    Path:/usr/bin/cat
    Arguments:cat /root/.mozilla/firefox/*default/prefs.js
    File size:43416 bytes
    MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

    Start time (UTC):15:46:47
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:-
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:46:47
    Start date (UTC):24/01/2025
    Path:/usr/bin/grep
    Arguments:grep network.proxy.ssl
    File size:199136 bytes
    MD5 hash:1e6ebb9dd094f774478f72727bdba0f5

    Start time (UTC):15:46:47
    Start date (UTC):24/01/2025
    Path:/tmp/QDucAhFhA9.elf
    Arguments:-
    File size:69488 bytes
    MD5 hash:f35dc2d049000545febf88fe7df3ad4f

    Start time (UTC):15:46:47
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:sh -c "cat /etc/profile | grep https_proxy"
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:46:47
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:-
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:46:47
    Start date (UTC):24/01/2025
    Path:/usr/bin/cat
    Arguments:cat /etc/profile
    File size:43416 bytes
    MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

    Start time (UTC):15:46:47
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:-
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:46:47
    Start date (UTC):24/01/2025
    Path:/usr/bin/grep
    Arguments:grep https_proxy
    File size:199136 bytes
    MD5 hash:1e6ebb9dd094f774478f72727bdba0f5

    Start time (UTC):15:47:31
    Start date (UTC):24/01/2025
    Path:/tmp/QDucAhFhA9.elf
    Arguments:-
    File size:69488 bytes
    MD5 hash:f35dc2d049000545febf88fe7df3ad4f

    Start time (UTC):15:47:31
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:sh -c "cat $HOME/.mozilla/firefox/*release/prefs.js | grep network.proxy.ssl"
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:47:31
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:-
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:47:31
    Start date (UTC):24/01/2025
    Path:/usr/bin/cat
    Arguments:cat /root/.mozilla/firefox/*release/prefs.js
    File size:43416 bytes
    MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

    Start time (UTC):15:47:31
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:-
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:47:31
    Start date (UTC):24/01/2025
    Path:/usr/bin/grep
    Arguments:grep network.proxy.ssl
    File size:199136 bytes
    MD5 hash:1e6ebb9dd094f774478f72727bdba0f5

    Start time (UTC):15:47:31
    Start date (UTC):24/01/2025
    Path:/tmp/QDucAhFhA9.elf
    Arguments:-
    File size:69488 bytes
    MD5 hash:f35dc2d049000545febf88fe7df3ad4f

    Start time (UTC):15:47:31
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:sh -c "cat $HOME/.mozilla/firefox/*default/prefs.js | grep network.proxy.ssl"
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:47:31
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:-
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:47:31
    Start date (UTC):24/01/2025
    Path:/usr/bin/cat
    Arguments:cat /root/.mozilla/firefox/*default/prefs.js
    File size:43416 bytes
    MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

    Start time (UTC):15:47:31
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:-
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:47:31
    Start date (UTC):24/01/2025
    Path:/usr/bin/grep
    Arguments:grep network.proxy.ssl
    File size:199136 bytes
    MD5 hash:1e6ebb9dd094f774478f72727bdba0f5

    Start time (UTC):15:47:31
    Start date (UTC):24/01/2025
    Path:/tmp/QDucAhFhA9.elf
    Arguments:-
    File size:69488 bytes
    MD5 hash:f35dc2d049000545febf88fe7df3ad4f

    Start time (UTC):15:47:31
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:sh -c "cat /etc/profile | grep https_proxy"
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:47:31
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:-
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:47:31
    Start date (UTC):24/01/2025
    Path:/usr/bin/cat
    Arguments:cat /etc/profile
    File size:43416 bytes
    MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

    Start time (UTC):15:47:31
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:-
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:47:31
    Start date (UTC):24/01/2025
    Path:/usr/bin/grep
    Arguments:grep https_proxy
    File size:199136 bytes
    MD5 hash:1e6ebb9dd094f774478f72727bdba0f5

    Start time (UTC):15:48:15
    Start date (UTC):24/01/2025
    Path:/tmp/QDucAhFhA9.elf
    Arguments:-
    File size:69488 bytes
    MD5 hash:f35dc2d049000545febf88fe7df3ad4f

    Start time (UTC):15:48:15
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:sh -c "cat $HOME/.mozilla/firefox/*release/prefs.js | grep network.proxy.ssl"
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:48:15
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:-
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:48:15
    Start date (UTC):24/01/2025
    Path:/usr/bin/cat
    Arguments:cat /root/.mozilla/firefox/*release/prefs.js
    File size:43416 bytes
    MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

    Start time (UTC):15:48:15
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:-
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:48:15
    Start date (UTC):24/01/2025
    Path:/usr/bin/grep
    Arguments:grep network.proxy.ssl
    File size:199136 bytes
    MD5 hash:1e6ebb9dd094f774478f72727bdba0f5

    Start time (UTC):15:48:15
    Start date (UTC):24/01/2025
    Path:/tmp/QDucAhFhA9.elf
    Arguments:-
    File size:69488 bytes
    MD5 hash:f35dc2d049000545febf88fe7df3ad4f

    Start time (UTC):15:48:15
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:sh -c "cat $HOME/.mozilla/firefox/*default/prefs.js | grep network.proxy.ssl"
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:48:15
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:-
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:48:15
    Start date (UTC):24/01/2025
    Path:/usr/bin/cat
    Arguments:cat /root/.mozilla/firefox/*default/prefs.js
    File size:43416 bytes
    MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

    Start time (UTC):15:48:15
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:-
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:48:15
    Start date (UTC):24/01/2025
    Path:/usr/bin/grep
    Arguments:grep network.proxy.ssl
    File size:199136 bytes
    MD5 hash:1e6ebb9dd094f774478f72727bdba0f5

    Start time (UTC):15:48:16
    Start date (UTC):24/01/2025
    Path:/tmp/QDucAhFhA9.elf
    Arguments:-
    File size:69488 bytes
    MD5 hash:f35dc2d049000545febf88fe7df3ad4f

    Start time (UTC):15:48:16
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:sh -c "cat /etc/profile | grep https_proxy"
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:48:16
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:-
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:48:16
    Start date (UTC):24/01/2025
    Path:/usr/bin/cat
    Arguments:cat /etc/profile
    File size:43416 bytes
    MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

    Start time (UTC):15:48:16
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:-
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:48:16
    Start date (UTC):24/01/2025
    Path:/usr/bin/grep
    Arguments:grep https_proxy
    File size:199136 bytes
    MD5 hash:1e6ebb9dd094f774478f72727bdba0f5

    Start time (UTC):15:48:59
    Start date (UTC):24/01/2025
    Path:/tmp/QDucAhFhA9.elf
    Arguments:-
    File size:69488 bytes
    MD5 hash:f35dc2d049000545febf88fe7df3ad4f

    Start time (UTC):15:48:59
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:sh -c "cat $HOME/.mozilla/firefox/*release/prefs.js | grep network.proxy.ssl"
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:49:00
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:-
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:49:00
    Start date (UTC):24/01/2025
    Path:/usr/bin/cat
    Arguments:cat /root/.mozilla/firefox/*release/prefs.js
    File size:43416 bytes
    MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

    Start time (UTC):15:49:00
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:-
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:49:00
    Start date (UTC):24/01/2025
    Path:/usr/bin/grep
    Arguments:grep network.proxy.ssl
    File size:199136 bytes
    MD5 hash:1e6ebb9dd094f774478f72727bdba0f5

    Start time (UTC):15:49:00
    Start date (UTC):24/01/2025
    Path:/tmp/QDucAhFhA9.elf
    Arguments:-
    File size:69488 bytes
    MD5 hash:f35dc2d049000545febf88fe7df3ad4f

    Start time (UTC):15:49:00
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:sh -c "cat $HOME/.mozilla/firefox/*default/prefs.js | grep network.proxy.ssl"
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:49:00
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:-
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:49:00
    Start date (UTC):24/01/2025
    Path:/usr/bin/cat
    Arguments:cat /root/.mozilla/firefox/*default/prefs.js
    File size:43416 bytes
    MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

    Start time (UTC):15:49:00
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:-
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:49:00
    Start date (UTC):24/01/2025
    Path:/usr/bin/grep
    Arguments:grep network.proxy.ssl
    File size:199136 bytes
    MD5 hash:1e6ebb9dd094f774478f72727bdba0f5

    Start time (UTC):15:49:00
    Start date (UTC):24/01/2025
    Path:/tmp/QDucAhFhA9.elf
    Arguments:-
    File size:69488 bytes
    MD5 hash:f35dc2d049000545febf88fe7df3ad4f

    Start time (UTC):15:49:00
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:sh -c "cat /etc/profile | grep https_proxy"
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:49:00
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:-
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:49:00
    Start date (UTC):24/01/2025
    Path:/usr/bin/cat
    Arguments:cat /etc/profile
    File size:43416 bytes
    MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

    Start time (UTC):15:49:00
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:-
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:49:00
    Start date (UTC):24/01/2025
    Path:/usr/bin/grep
    Arguments:grep https_proxy
    File size:199136 bytes
    MD5 hash:1e6ebb9dd094f774478f72727bdba0f5

    Start time (UTC):15:49:44
    Start date (UTC):24/01/2025
    Path:/tmp/QDucAhFhA9.elf
    Arguments:-
    File size:69488 bytes
    MD5 hash:f35dc2d049000545febf88fe7df3ad4f

    Start time (UTC):15:49:44
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:sh -c "cat $HOME/.mozilla/firefox/*release/prefs.js | grep network.proxy.ssl"
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:49:44
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:-
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:49:44
    Start date (UTC):24/01/2025
    Path:/usr/bin/cat
    Arguments:cat /root/.mozilla/firefox/*release/prefs.js
    File size:43416 bytes
    MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

    Start time (UTC):15:49:44
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:-
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:49:44
    Start date (UTC):24/01/2025
    Path:/usr/bin/grep
    Arguments:grep network.proxy.ssl
    File size:199136 bytes
    MD5 hash:1e6ebb9dd094f774478f72727bdba0f5

    Start time (UTC):15:49:44
    Start date (UTC):24/01/2025
    Path:/tmp/QDucAhFhA9.elf
    Arguments:-
    File size:69488 bytes
    MD5 hash:f35dc2d049000545febf88fe7df3ad4f

    Start time (UTC):15:49:44
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:sh -c "cat $HOME/.mozilla/firefox/*default/prefs.js | grep network.proxy.ssl"
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:49:44
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:-
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:49:44
    Start date (UTC):24/01/2025
    Path:/usr/bin/cat
    Arguments:cat /root/.mozilla/firefox/*default/prefs.js
    File size:43416 bytes
    MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

    Start time (UTC):15:49:44
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:-
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:49:44
    Start date (UTC):24/01/2025
    Path:/usr/bin/grep
    Arguments:grep network.proxy.ssl
    File size:199136 bytes
    MD5 hash:1e6ebb9dd094f774478f72727bdba0f5

    Start time (UTC):15:49:44
    Start date (UTC):24/01/2025
    Path:/tmp/QDucAhFhA9.elf
    Arguments:-
    File size:69488 bytes
    MD5 hash:f35dc2d049000545febf88fe7df3ad4f

    Start time (UTC):15:49:44
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:sh -c "cat /etc/profile | grep https_proxy"
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:49:44
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:-
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:49:44
    Start date (UTC):24/01/2025
    Path:/usr/bin/cat
    Arguments:cat /etc/profile
    File size:43416 bytes
    MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

    Start time (UTC):15:49:44
    Start date (UTC):24/01/2025
    Path:/bin/sh
    Arguments:-
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:49:44
    Start date (UTC):24/01/2025
    Path:/usr/bin/grep
    Arguments:grep https_proxy
    File size:199136 bytes
    MD5 hash:1e6ebb9dd094f774478f72727bdba0f5

    Start time (UTC):15:40:54
    Start date (UTC):24/01/2025
    Path:/usr/lib/systemd/systemd
    Arguments:-
    File size:1620224 bytes
    MD5 hash:9b2bec7092a40488108543f9334aab75

    Start time (UTC):15:40:54
    Start date (UTC):24/01/2025
    Path:/usr/lib/systemd/system-environment-generators/snapd-env-generator
    Arguments:/usr/lib/systemd/system-environment-generators/snapd-env-generator
    File size:22760 bytes
    MD5 hash:3633b075f40283ec938a2a6a89671b0e