Source: /usr/bin/pgrep (PID: 6234) | Reads CPU info from /sys: /sys/devices/system/cpu/online | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6244) | Reads CPU info from /sys: /sys/devices/system/cpu/online | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6248) | Reads CPU info from /sys: /sys/devices/system/cpu/online | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6345) | Reads CPU info from /sys: /sys/devices/system/cpu/online | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6359) | Reads CPU info from /sys: /sys/devices/system/cpu/online | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | Reads CPU info from /sys: /sys/devices/system/cpu/online | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6385) | Reads CPU info from /sys: /sys/devices/system/cpu/online | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6397) | Reads CPU info from /sys: /sys/devices/system/cpu/online | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6410) | Reads CPU info from /sys: /sys/devices/system/cpu/online | |
Source: /usr/bin/pgrep (PID: 6422) | Reads CPU info from /sys: /sys/devices/system/cpu/online | |
Source: /usr/bin/pgrep (PID: 6436) | Reads CPU info from /sys: /sys/devices/system/cpu/online | |
Source: /usr/bin/pgrep (PID: 6448) | Reads CPU info from /sys: /sys/devices/system/cpu/online | |
Source: /usr/bin/pgrep (PID: 6460) | Reads CPU info from /sys: /sys/devices/system/cpu/online | |
Source: /usr/bin/pgrep (PID: 6473) | Reads CPU info from /sys: /sys/devices/system/cpu/online | |
Source: /usr/bin/pgrep (PID: 6486) | Reads CPU info from /sys: /sys/devices/system/cpu/online | |
Source: /usr/bin/pgrep (PID: 6500) | Reads CPU info from /sys: /sys/devices/system/cpu/online | |
Source: /usr/bin/pgrep (PID: 6512) | Reads CPU info from /sys: /sys/devices/system/cpu/online | |
Source: /usr/bin/pgrep (PID: 6526) | Reads CPU info from /sys: /sys/devices/system/cpu/online | |
Source: /usr/bin/pgrep (PID: 6538) | Reads CPU info from /sys: /sys/devices/system/cpu/online | |
Source: /usr/bin/pgrep (PID: 6551) | Reads CPU info from /sys: /sys/devices/system/cpu/online | |
Source: /usr/bin/pgrep (PID: 6563) | Reads CPU info from /sys: /sys/devices/system/cpu/online | |
Source: /usr/bin/pgrep (PID: 6578) | Reads CPU info from /sys: /sys/devices/system/cpu/online | |
Source: /usr/bin/pgrep (PID: 6590) | Reads CPU info from /sys: /sys/devices/system/cpu/online | |
Source: /usr/bin/pgrep (PID: 6606) | Reads CPU info from /sys: /sys/devices/system/cpu/online | |
Source: na.elf, type: SAMPLE | Matched rule: Linux_Trojan_Dofloo_ac3333d1 severity = 100, os = linux, arch_context = x86, creation_date = 2022-01-05, scan_context = file, memory, reference = 04664dc5ea14ddff5301e66c46d6795f1582c148b5cb621248424d015245c95e, license = Elastic License v2, threat_name = Linux.Trojan.Dofloo, fingerprint = a8f360e2a545e65b5f9f2273715c1a5008a0fe4f88f6e14becd6e69158aab409, id = ac3333d1-df88-459b-a411-00b4fc947f3f, last_modified = 2022-01-26 |
Source: 6230.1.0000000000401000.00000000004f9000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Hacktool_Flooder_1a4eb229 reference_sample = bf6f3ffaf94444a09b69cbd4c8c0224d7eb98eb41514bdc3f58c1fb90ac0e705, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Hacktool.Flooder, fingerprint = de076ef23c2669512efc00ddfe926ef04f8ad939061c69131a0ef9a743639371, id = 1a4eb229-a194-46a5-8e93-370a40ba999b, last_modified = 2021-09-16 |
Source: 6230.1.0000000000401000.00000000004f9000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Hacktool_Flooder_f454ec10 severity = 100, os = linux, arch_context = x86, creation_date = 2022-01-05, scan_context = file, memory, reference = 0297e1ad6e180af85256a175183102776212d324a2ce0c4f32e8a44a2e2e9dad, license = Elastic License v2, threat_name = Linux.Hacktool.Flooder, fingerprint = 2ae5e2c3190a4ce5d238efdb10ac0520987425fb7af52246b6bf948abd0259da, id = f454ec10-7a67-4717-9e95-fecb7c357566, last_modified = 2022-01-26 |
Source: /usr/sbin/uplugplay, type: DROPPED | Matched rule: Linux_Trojan_Dofloo_ac3333d1 severity = 100, os = linux, arch_context = x86, creation_date = 2022-01-05, scan_context = file, memory, reference = 04664dc5ea14ddff5301e66c46d6795f1582c148b5cb621248424d015245c95e, license = Elastic License v2, threat_name = Linux.Trojan.Dofloo, fingerprint = a8f360e2a545e65b5f9f2273715c1a5008a0fe4f88f6e14becd6e69158aab409, id = ac3333d1-df88-459b-a411-00b4fc947f3f, last_modified = 2022-01-26 |
Source: /usr/bin/pidof (PID: 6240) | Directory: //. | Jump to behavior |
Source: /usr/bin/pidof (PID: 6254) | Directory: //. | Jump to behavior |
Source: /usr/bin/pidof (PID: 6351) | Directory: //. | Jump to behavior |
Source: /usr/bin/pidof (PID: 6363) | Directory: //. | Jump to behavior |
Source: /usr/bin/pidof (PID: 6377) | Directory: //. | Jump to behavior |
Source: /usr/bin/pidof (PID: 6389) | Directory: //. | Jump to behavior |
Source: /usr/bin/pidof (PID: 6401) | Directory: //. | Jump to behavior |
Source: /usr/bin/pidof (PID: 6414) | Directory: //. | |
Source: /usr/bin/pidof (PID: 6428) | Directory: //. | |
Source: /usr/bin/pidof (PID: 6440) | Directory: //. | |
Source: /usr/bin/pidof (PID: 6452) | Directory: //. | |
Source: /usr/bin/pidof (PID: 6464) | Directory: //. | |
Source: /usr/bin/pidof (PID: 6478) | Directory: //. | |
Source: /usr/bin/pidof (PID: 6490) | Directory: //. | |
Source: /usr/bin/pidof (PID: 6504) | Directory: //. | |
Source: /usr/bin/pidof (PID: 6518) | Directory: //. | |
Source: /usr/bin/pidof (PID: 6530) | Directory: //. | |
Source: /usr/bin/pidof (PID: 6542) | Directory: //. | |
Source: /usr/bin/pidof (PID: 6555) | Directory: //. | |
Source: /usr/bin/pidof (PID: 6569) | Directory: //. | |
Source: /usr/bin/pidof (PID: 6582) | Directory: //. | |
Source: /usr/bin/pidof (PID: 6594) | Directory: //. | |
Source: /usr/bin/pidof (PID: 6615) | Directory: //. | |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/1582/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/1582/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/3088/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/3088/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/230/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/230/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/110/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/110/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/231/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/231/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/111/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/111/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/232/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/232/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/1579/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/1579/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/112/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/112/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/233/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/233/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/1699/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/1699/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/113/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/113/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/234/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/234/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/1335/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/1335/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/1698/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/1698/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/114/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/114/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/235/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/235/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/1334/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/1334/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/1576/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/1576/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/2302/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/2302/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/115/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/115/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/236/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/236/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/116/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/116/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/237/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/237/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/117/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/117/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/118/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/118/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/910/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/910/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/119/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/119/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/912/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/912/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/10/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/10/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/2307/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/2307/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/11/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/11/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/918/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/918/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/12/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/12/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/13/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/13/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/14/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/14/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/15/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/15/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/16/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/16/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/17/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/17/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/18/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/18/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/1594/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/1594/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/120/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/120/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/121/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/121/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/1349/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/1349/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/1/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/1/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/122/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/122/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/243/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/243/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/123/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/123/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/2/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/2/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/124/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/124/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/3/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/3/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/4/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/4/cmdline | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/125/status | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | File opened: /proc/125/cmdline | Jump to behavior |
Source: /tmp/na.elf (PID: 6233) | Shell command executed: sh -c "pgrep na.elf" | Jump to behavior |
Source: /tmp/na.elf (PID: 6239) | Shell command executed: sh -c "pidof na.elf" | Jump to behavior |
Source: /tmp/na.elf (PID: 6243) | Shell command executed: sh -c "pgrep uplugplay" | Jump to behavior |
Source: /tmp/na.elf (PID: 6247) | Shell command executed: sh -c "pgrep upnpsetup" | Jump to behavior |
Source: /tmp/na.elf (PID: 6253) | Shell command executed: sh -c "pidof upnpsetup" | Jump to behavior |
Source: /tmp/na.elf (PID: 6256) | Shell command executed: sh -c "systemctl daemon-reload" | Jump to behavior |
Source: /tmp/na.elf (PID: 6272) | Shell command executed: sh -c "systemctl enable uplugplay.service" | Jump to behavior |
Source: /tmp/na.elf (PID: 6280) | Shell command executed: sh -c "systemctl start uplugplay.service" | Jump to behavior |
Source: /tmp/na.elf (PID: 6324) | Shell command executed: sh -c "crontab -l" | Jump to behavior |
Source: /tmp/na.elf (PID: 6331) | Shell command executed: sh -c "crontab task.cron" | Jump to behavior |
Source: /tmp/na.elf (PID: 6336) | Shell command executed: sh -c "crontab -l" | Jump to behavior |
Source: /tmp/na.elf (PID: 6340) | Shell command executed: sh -c "/usr/sbin/uplugplay -Dcomsvc" | Jump to behavior |
Source: /tmp/na.elf (PID: 6344) | Shell command executed: sh -c "pgrep /usr/sbin/uplugplay" | Jump to behavior |
Source: /tmp/na.elf (PID: 6350) | Shell command executed: sh -c "pidof /usr/sbin/uplugplay" | Jump to behavior |
Source: /tmp/na.elf (PID: 6354) | Shell command executed: sh -c "/usr/sbin/uplugplay -Dcomsvc" | Jump to behavior |
Source: /tmp/na.elf (PID: 6358) | Shell command executed: sh -c "pgrep /usr/sbin/uplugplay" | Jump to behavior |
Source: /tmp/na.elf (PID: 6362) | Shell command executed: sh -c "pidof /usr/sbin/uplugplay" | Jump to behavior |
Source: /tmp/na.elf (PID: 6368) | Shell command executed: sh -c "/usr/sbin/uplugplay -Dcomsvc" | Jump to behavior |
Source: /tmp/na.elf (PID: 6372) | Shell command executed: sh -c "pgrep /usr/sbin/uplugplay" | Jump to behavior |
Source: /tmp/na.elf (PID: 6376) | Shell command executed: sh -c "pidof /usr/sbin/uplugplay" | Jump to behavior |
Source: /tmp/na.elf (PID: 6380) | Shell command executed: sh -c "/usr/sbin/uplugplay -Dcomsvc" | Jump to behavior |
Source: /tmp/na.elf (PID: 6384) | Shell command executed: sh -c "pgrep /usr/sbin/uplugplay" | Jump to behavior |
Source: /tmp/na.elf (PID: 6388) | Shell command executed: sh -c "pidof /usr/sbin/uplugplay" | Jump to behavior |
Source: /tmp/na.elf (PID: 6392) | Shell command executed: sh -c "/usr/sbin/uplugplay -Dcomsvc" | Jump to behavior |
Source: /tmp/na.elf (PID: 6396) | Shell command executed: sh -c "pgrep /usr/sbin/uplugplay" | Jump to behavior |
Source: /tmp/na.elf (PID: 6400) | Shell command executed: sh -c "pidof /usr/sbin/uplugplay" | Jump to behavior |
Source: /tmp/na.elf (PID: 6405) | Shell command executed: sh -c "/usr/sbin/uplugplay -Dcomsvc" | |
Source: /tmp/na.elf (PID: 6409) | Shell command executed: sh -c "pgrep /usr/sbin/uplugplay" | |
Source: /tmp/na.elf (PID: 6413) | Shell command executed: sh -c "pidof /usr/sbin/uplugplay" | |
Source: /tmp/na.elf (PID: 6417) | Shell command executed: sh -c "/usr/sbin/uplugplay -Dcomsvc" | |
Source: /tmp/na.elf (PID: 6421) | Shell command executed: sh -c "pgrep /usr/sbin/uplugplay" | |
Source: /tmp/na.elf (PID: 6427) | Shell command executed: sh -c "pidof /usr/sbin/uplugplay" | |
Source: /tmp/na.elf (PID: 6431) | Shell command executed: sh -c "/usr/sbin/uplugplay -Dcomsvc" | |
Source: /tmp/na.elf (PID: 6435) | Shell command executed: sh -c "pgrep /usr/sbin/uplugplay" | |
Source: /tmp/na.elf (PID: 6439) | Shell command executed: sh -c "pidof /usr/sbin/uplugplay" | |
Source: /tmp/na.elf (PID: 6443) | Shell command executed: sh -c "/usr/sbin/uplugplay -Dcomsvc" | |
Source: /tmp/na.elf (PID: 6447) | Shell command executed: sh -c "pgrep /usr/sbin/uplugplay" | |
Source: /tmp/na.elf (PID: 6451) | Shell command executed: sh -c "pidof /usr/sbin/uplugplay" | |
Source: /tmp/na.elf (PID: 6455) | Shell command executed: sh -c "/usr/sbin/uplugplay -Dcomsvc" | |
Source: /tmp/na.elf (PID: 6459) | Shell command executed: sh -c "pgrep /usr/sbin/uplugplay" | |
Source: /tmp/na.elf (PID: 6463) | Shell command executed: sh -c "pidof /usr/sbin/uplugplay" | |
Source: /tmp/na.elf (PID: 6468) | Shell command executed: sh -c "/usr/sbin/uplugplay -Dcomsvc" | |
Source: /tmp/na.elf (PID: 6472) | Shell command executed: sh -c "pgrep /usr/sbin/uplugplay" | |
Source: /tmp/na.elf (PID: 6477) | Shell command executed: sh -c "pidof /usr/sbin/uplugplay" | |
Source: /tmp/na.elf (PID: 6481) | Shell command executed: sh -c "/usr/sbin/uplugplay -Dcomsvc" | |
Source: /tmp/na.elf (PID: 6485) | Shell command executed: sh -c "pgrep /usr/sbin/uplugplay" | |
Source: /tmp/na.elf (PID: 6489) | Shell command executed: sh -c "pidof /usr/sbin/uplugplay" | |
Source: /tmp/na.elf (PID: 6493) | Shell command executed: sh -c "/usr/sbin/uplugplay -Dcomsvc" | |
Source: /tmp/na.elf (PID: 6499) | Shell command executed: sh -c "pgrep /usr/sbin/uplugplay" | |
Source: /tmp/na.elf (PID: 6503) | Shell command executed: sh -c "pidof /usr/sbin/uplugplay" | |
Source: /tmp/na.elf (PID: 6507) | Shell command executed: sh -c "/usr/sbin/uplugplay -Dcomsvc" | |
Source: /tmp/na.elf (PID: 6511) | Shell command executed: sh -c "pgrep /usr/sbin/uplugplay" | |
Source: /tmp/na.elf (PID: 6517) | Shell command executed: sh -c "pidof /usr/sbin/uplugplay" | |
Source: /tmp/na.elf (PID: 6519) | Shell command executed: sh -c "/usr/sbin/uplugplay -Dcomsvc" | |
Source: /tmp/na.elf (PID: 6525) | Shell command executed: sh -c "pgrep /usr/sbin/uplugplay" | |
Source: /tmp/na.elf (PID: 6529) | Shell command executed: sh -c "pidof /usr/sbin/uplugplay" | |
Source: /tmp/na.elf (PID: 6533) | Shell command executed: sh -c "/usr/sbin/uplugplay -Dcomsvc" | |
Source: /tmp/na.elf (PID: 6537) | Shell command executed: sh -c "pgrep /usr/sbin/uplugplay" | |
Source: /tmp/na.elf (PID: 6541) | Shell command executed: sh -c "pidof /usr/sbin/uplugplay" | |
Source: /tmp/na.elf (PID: 6546) | Shell command executed: sh -c "/usr/sbin/uplugplay -Dcomsvc" | |
Source: /tmp/na.elf (PID: 6550) | Shell command executed: sh -c "pgrep /usr/sbin/uplugplay" | |
Source: /tmp/na.elf (PID: 6554) | Shell command executed: sh -c "pidof /usr/sbin/uplugplay" | |
Source: /tmp/na.elf (PID: 6558) | Shell command executed: sh -c "/usr/sbin/uplugplay -Dcomsvc" | |
Source: /tmp/na.elf (PID: 6562) | Shell command executed: sh -c "pgrep /usr/sbin/uplugplay" | |
Source: /tmp/na.elf (PID: 6566) | Shell command executed: sh -c "pidof /usr/sbin/uplugplay" | |
Source: /tmp/na.elf (PID: 6571) | Shell command executed: sh -c "/usr/sbin/uplugplay -Dcomsvc" | |
Source: /tmp/na.elf (PID: 6577) | Shell command executed: sh -c "pgrep /usr/sbin/uplugplay" | |
Source: /tmp/na.elf (PID: 6581) | Shell command executed: sh -c "pidof /usr/sbin/uplugplay" | |
Source: /tmp/na.elf (PID: 6585) | Shell command executed: sh -c "/usr/sbin/uplugplay -Dcomsvc" | |
Source: /tmp/na.elf (PID: 6589) | Shell command executed: sh -c "pgrep /usr/sbin/uplugplay" | |
Source: /tmp/na.elf (PID: 6593) | Shell command executed: sh -c "pidof /usr/sbin/uplugplay" | |
Source: /tmp/na.elf (PID: 6600) | Shell command executed: sh -c "/usr/sbin/uplugplay -Dcomsvc" | |
Source: /tmp/na.elf (PID: 6604) | Shell command executed: sh -c "pgrep /usr/sbin/uplugplay" | |
Source: /tmp/na.elf (PID: 6610) | Shell command executed: sh -c "pidof /usr/sbin/uplugplay" | |
Source: /bin/sh (PID: 6234) | Pgrep executable: /usr/bin/pgrep -> pgrep na.elf | Jump to behavior |
Source: /bin/sh (PID: 6244) | Pgrep executable: /usr/bin/pgrep -> pgrep uplugplay | Jump to behavior |
Source: /bin/sh (PID: 6248) | Pgrep executable: /usr/bin/pgrep -> pgrep upnpsetup | Jump to behavior |
Source: /bin/sh (PID: 6345) | Pgrep executable: /usr/bin/pgrep -> pgrep /usr/sbin/uplugplay | Jump to behavior |
Source: /bin/sh (PID: 6359) | Pgrep executable: /usr/bin/pgrep -> pgrep /usr/sbin/uplugplay | Jump to behavior |
Source: /bin/sh (PID: 6373) | Pgrep executable: /usr/bin/pgrep -> pgrep /usr/sbin/uplugplay | Jump to behavior |
Source: /bin/sh (PID: 6385) | Pgrep executable: /usr/bin/pgrep -> pgrep /usr/sbin/uplugplay | Jump to behavior |
Source: /bin/sh (PID: 6397) | Pgrep executable: /usr/bin/pgrep -> pgrep /usr/sbin/uplugplay | Jump to behavior |
Source: /bin/sh (PID: 6410) | Pgrep executable: /usr/bin/pgrep -> pgrep /usr/sbin/uplugplay | |
Source: /bin/sh (PID: 6422) | Pgrep executable: /usr/bin/pgrep -> pgrep /usr/sbin/uplugplay | |
Source: /bin/sh (PID: 6436) | Pgrep executable: /usr/bin/pgrep -> pgrep /usr/sbin/uplugplay | |
Source: /bin/sh (PID: 6448) | Pgrep executable: /usr/bin/pgrep -> pgrep /usr/sbin/uplugplay | |
Source: /bin/sh (PID: 6460) | Pgrep executable: /usr/bin/pgrep -> pgrep /usr/sbin/uplugplay | |
Source: /bin/sh (PID: 6473) | Pgrep executable: /usr/bin/pgrep -> pgrep /usr/sbin/uplugplay | |
Source: /bin/sh (PID: 6486) | Pgrep executable: /usr/bin/pgrep -> pgrep /usr/sbin/uplugplay | |
Source: /bin/sh (PID: 6500) | Pgrep executable: /usr/bin/pgrep -> pgrep /usr/sbin/uplugplay | |
Source: /bin/sh (PID: 6512) | Pgrep executable: /usr/bin/pgrep -> pgrep /usr/sbin/uplugplay | |
Source: /bin/sh (PID: 6526) | Pgrep executable: /usr/bin/pgrep -> pgrep /usr/sbin/uplugplay | |
Source: /bin/sh (PID: 6538) | Pgrep executable: /usr/bin/pgrep -> pgrep /usr/sbin/uplugplay | |
Source: /bin/sh (PID: 6551) | Pgrep executable: /usr/bin/pgrep -> pgrep /usr/sbin/uplugplay | |
Source: /bin/sh (PID: 6563) | Pgrep executable: /usr/bin/pgrep -> pgrep /usr/sbin/uplugplay | |
Source: /bin/sh (PID: 6578) | Pgrep executable: /usr/bin/pgrep -> pgrep /usr/sbin/uplugplay | |
Source: /bin/sh (PID: 6590) | Pgrep executable: /usr/bin/pgrep -> pgrep /usr/sbin/uplugplay | |
Source: /bin/sh (PID: 6606) | Pgrep executable: /usr/bin/pgrep -> pgrep /usr/sbin/uplugplay | |
Source: /usr/bin/pgrep (PID: 6234) | Reads CPU info from /sys: /sys/devices/system/cpu/online | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6244) | Reads CPU info from /sys: /sys/devices/system/cpu/online | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6248) | Reads CPU info from /sys: /sys/devices/system/cpu/online | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6345) | Reads CPU info from /sys: /sys/devices/system/cpu/online | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6359) | Reads CPU info from /sys: /sys/devices/system/cpu/online | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6373) | Reads CPU info from /sys: /sys/devices/system/cpu/online | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6385) | Reads CPU info from /sys: /sys/devices/system/cpu/online | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6397) | Reads CPU info from /sys: /sys/devices/system/cpu/online | Jump to behavior |
Source: /usr/bin/pgrep (PID: 6410) | Reads CPU info from /sys: /sys/devices/system/cpu/online | |
Source: /usr/bin/pgrep (PID: 6422) | Reads CPU info from /sys: /sys/devices/system/cpu/online | |
Source: /usr/bin/pgrep (PID: 6436) | Reads CPU info from /sys: /sys/devices/system/cpu/online | |
Source: /usr/bin/pgrep (PID: 6448) | Reads CPU info from /sys: /sys/devices/system/cpu/online | |
Source: /usr/bin/pgrep (PID: 6460) | Reads CPU info from /sys: /sys/devices/system/cpu/online | |
Source: /usr/bin/pgrep (PID: 6473) | Reads CPU info from /sys: /sys/devices/system/cpu/online | |
Source: /usr/bin/pgrep (PID: 6486) | Reads CPU info from /sys: /sys/devices/system/cpu/online | |
Source: /usr/bin/pgrep (PID: 6500) | Reads CPU info from /sys: /sys/devices/system/cpu/online | |
Source: /usr/bin/pgrep (PID: 6512) | Reads CPU info from /sys: /sys/devices/system/cpu/online | |
Source: /usr/bin/pgrep (PID: 6526) | Reads CPU info from /sys: /sys/devices/system/cpu/online | |
Source: /usr/bin/pgrep (PID: 6538) | Reads CPU info from /sys: /sys/devices/system/cpu/online | |
Source: /usr/bin/pgrep (PID: 6551) | Reads CPU info from /sys: /sys/devices/system/cpu/online | |
Source: /usr/bin/pgrep (PID: 6563) | Reads CPU info from /sys: /sys/devices/system/cpu/online | |
Source: /usr/bin/pgrep (PID: 6578) | Reads CPU info from /sys: /sys/devices/system/cpu/online | |
Source: /usr/bin/pgrep (PID: 6590) | Reads CPU info from /sys: /sys/devices/system/cpu/online | |
Source: /usr/bin/pgrep (PID: 6606) | Reads CPU info from /sys: /sys/devices/system/cpu/online | |