Loading ...

Play interactive tourEdit tour

Analysis Report sshins

Overview

General Information

Sample Name:sshins
Analysis ID:355141
MD5:38fb322cc6d09a6ab85784ede56bc5a7
SHA1:f7d95a887a51fe97ce64a93a40196b2cccaa80d8
SHA256:ab9cc4ee82aa6f57ba2a113aab905c33e278c969399db4188d0ea5942ad3bb7d

Detection

Score:56
Range:0 - 100
Whitelisted:false

Signatures

Multi AV Scanner detection for submitted file
Creates /etc/ld.so.preload
Sample is packed with UPX
Enumerates processes within the "proc" file system
Executes commands using a shell command-line interpreter
Executes the "grep" command used to find patterns in files or piped streams
Executes the "systemctl" command used for controlling the systemd system and service manager
Reads CPU information from /proc indicative of miner or evasive malware
Reads system information from the proc file system
Sample contains only a LOAD segment without any section mappings
Sample listens on a socket
Uses the "uname" system call to query kernel version information (possible evasion)
Writes ELF files to disk
Yara signature match

Classification

Startup

  • system is lnxubuntu1
  • sshins (PID: 4579, Parent: 4519, MD5: 38fb322cc6d09a6ab85784ede56bc5a7) Arguments: /tmp/sshins
    • sshins New Fork (PID: 4583, Parent: 4579)
    • sh (PID: 4583, Parent: 4579, MD5: e02ea3c3450d44126c46d658fa9e654c) Arguments: /bin/sh -c "/etc/init.d/sshd restart"
      • sh New Fork (PID: 4587, Parent: 4583)
    • sshins New Fork (PID: 4593, Parent: 4579)
    • sh (PID: 4593, Parent: 4579, MD5: e02ea3c3450d44126c46d658fa9e654c) Arguments: /bin/sh -c "/etc/rc.d/sshd restart"
      • sh New Fork (PID: 4601, Parent: 4593)
    • sshins New Fork (PID: 4609, Parent: 4579)
    • sh (PID: 4609, Parent: 4579, MD5: e02ea3c3450d44126c46d658fa9e654c) Arguments: /bin/sh -c "service ssh restart"
      • sh New Fork (PID: 4619, Parent: 4609)
      • service (PID: 4619, Parent: 4609, MD5: 81c4fe604ec67916db7b223725e5a9c6) Arguments: /bin/sh /usr/sbin/service ssh restart
        • service New Fork (PID: 4626, Parent: 4619)
        • basename (PID: 4626, Parent: 4619, MD5: fd7bba8b11b99ec7559f30226c79a729) Arguments: basename /usr/sbin/service
        • service New Fork (PID: 4636, Parent: 4619)
        • basename (PID: 4636, Parent: 4619, MD5: fd7bba8b11b99ec7559f30226c79a729) Arguments: basename /usr/sbin/service
        • service New Fork (PID: 4646, Parent: 4619)
        • which (PID: 4646, Parent: 4619, MD5: e942f154ef9d9974366551d2d231d936) Arguments: /bin/sh /usr/bin/which initctl
        • service New Fork (PID: 4653, Parent: 4619)
        • initctl (PID: 4653, Parent: 4619, MD5: 8829ab02d00aa4f3145e93d258e2c2b5) Arguments: initctl version
        • service New Fork (PID: 4654, Parent: 4619)
        • grep (PID: 4654, Parent: 4619, MD5: fc9b0a0ff848b35b3716768695bf2427) Arguments: grep -q upstart
        • service New Fork (PID: 4673, Parent: 4619)
        • systemctl (PID: 4673, Parent: 4619, MD5: b08096235b8c90203e17721264b5ce40) Arguments: systemctl --quiet is-active multi-user.target
      • systemctl (PID: 4619, Parent: 4609, MD5: b08096235b8c90203e17721264b5ce40) Arguments: systemctl restart ssh.service
    • sshins New Fork (PID: 4737, Parent: 4579)
    • sh (PID: 4737, Parent: 4579, MD5: e02ea3c3450d44126c46d658fa9e654c) Arguments: /bin/sh -c "systemctl restart ssh"
      • sh New Fork (PID: 4738, Parent: 4737)
      • systemctl (PID: 4738, Parent: 4737, MD5: b08096235b8c90203e17721264b5ce40) Arguments: systemctl restart ssh
    • sshins New Fork (PID: 4765, Parent: 4579)
    • sh (PID: 4765, Parent: 4579, MD5: e02ea3c3450d44126c46d658fa9e654c) Arguments: /bin/sh -c "systemctl restart sshd.service"
      • sh New Fork (PID: 4766, Parent: 4765)
      • systemctl (PID: 4766, Parent: 4765, MD5: b08096235b8c90203e17721264b5ce40) Arguments: systemctl restart sshd.service
  • systemd New Fork (PID: 4694, Parent: 1)
  • sshd (PID: 4694, Parent: 1, MD5: 661b2a2da3b6c7d7ef41d0b9da1caa3b) Arguments: /usr/sbin/sshd -D
    • sshd New Fork (PID: 4736, Parent: 4694)
      • sshd New Fork (PID: 4793, Parent: 4736)
      • dash (PID: 4793, Parent: 4736, MD5: e02ea3c3450d44126c46d658fa9e654c) Arguments: sh -c "/bin/df 2>/dev/null"
        • dash New Fork (PID: 4794, Parent: 4793)
        • df (PID: 4794, Parent: 4793, MD5: ba5b0b1786d40908a09a8eefa68688d3) Arguments: /bin/df
  • systemd New Fork (PID: 4755, Parent: 1)
  • sshd (PID: 4755, Parent: 1, MD5: 661b2a2da3b6c7d7ef41d0b9da1caa3b) Arguments: /usr/sbin/sshd -D
    • sshd New Fork (PID: 4764, Parent: 4755)
  • systemd New Fork (PID: 4770, Parent: 1)
  • sshd (PID: 4770, Parent: 1, MD5: 661b2a2da3b6c7d7ef41d0b9da1caa3b) Arguments: /usr/sbin/sshd -D
    • sshd New Fork (PID: 4792, Parent: 4770)
      • sshd New Fork (PID: 4811, Parent: 4792)
      • dash (PID: 4811, Parent: 4792, MD5: e02ea3c3450d44126c46d658fa9e654c) Arguments: sh -c "/bin/df 2>/dev/null"
        • dash New Fork (PID: 4812, Parent: 4811)
        • df (PID: 4812, Parent: 4811, MD5: ba5b0b1786d40908a09a8eefa68688d3) Arguments: /bin/df
  • cleanup

Yara Overview

Initial Sample

SourceRuleDescriptionAuthorStrings
sshinsSUSP_ELF_LNX_UPX_Compressed_FileDetects a suspicious ELF binary with UPX compressionFlorian Roth
  • 0xc764:$s1: PROT_EXEC|PROT_WRITE failed.
  • 0xc7d3:$s2: $Id: UPX
  • 0xc784:$s3: $Info: This file is packed with the UPX executable packer

Signature Overview

Click to jump to signature section

Show All Signature Results

AV Detection:

barindex
Multi AV Scanner detection for submitted fileShow sources
Source: sshinsReversingLabs: Detection: 12%
Source: /usr/sbin/sshd (PID: 4736)Reads CPU info from proc file: /proc/cpuinfoJump to behavior
Source: /usr/sbin/sshd (PID: 4792)Reads CPU info from proc file: /proc/cpuinfoJump to behavior
Source: /usr/sbin/sshd (PID: 4694)Socket: 0.0.0.0::22Jump to behavior
Source: /usr/sbin/sshd (PID: 4694)Socket: [::]::22Jump to behavior
Source: /usr/sbin/sshd (PID: 4755)Socket: [::]::22Jump to behavior
Source: /usr/sbin/sshd (PID: 4770)Socket: [::]::22Jump to behavior
Source: unknownTCP traffic detected without corresponding DNS query: 176.111.174.26
Source: unknownTCP traffic detected without corresponding DNS query: 176.111.174.26
Source: unknownTCP traffic detected without corresponding DNS query: 176.111.174.26
Source: unknownTCP traffic detected without corresponding DNS query: 176.111.174.26
Source: unknownTCP traffic detected without corresponding DNS query: 176.111.174.26
Source: unknownTCP traffic detected without corresponding DNS query: 176.111.174.26
Source: unknownTCP traffic detected without corresponding DNS query: 176.111.174.26
Source: unknownTCP traffic detected without corresponding DNS query: 176.111.174.26
Source: unknownTCP traffic detected without corresponding DNS query: 176.111.174.26
Source: unknownTCP traffic detected without corresponding DNS query: 176.111.174.26
Source: unknownTCP traffic detected without corresponding DNS query: 176.111.174.26
Source: unknownTCP traffic detected without corresponding DNS query: 176.111.174.26
Source: unknownTCP traffic detected without corresponding DNS query: 176.111.174.26
Source: unknownTCP traffic detected without corresponding DNS query: 176.111.174.26
Source: unknownTCP traffic detected without corresponding DNS query: 176.111.174.26
Source: unknownTCP traffic detected without corresponding DNS query: 176.111.174.26
Source: unknownTCP traffic detected without corresponding DNS query: 176.111.174.26
Source: unknownTCP traffic detected without corresponding DNS query: 176.111.174.26
Source: unknownTCP traffic detected without corresponding DNS query: 176.111.174.26
Source: unknownTCP traffic detected without corresponding DNS query: 176.111.174.26
Source: unknownTCP traffic detected without corresponding DNS query: 176.111.174.26
Source: unknownTCP traffic detected without corresponding DNS query: 176.111.174.26
Source: unknownTCP traffic detected without corresponding DNS query: 176.111.174.26
Source: unknownTCP traffic detected without corresponding DNS query: 176.111.174.26
Source: unknownTCP traffic detected without corresponding DNS query: 176.111.174.26
Source: unknownTCP traffic detected without corresponding DNS query: 176.111.174.26
Source: unknownTCP traffic detected without corresponding DNS query: 176.111.174.26
Source: unknownTCP traffic detected without corresponding DNS query: 176.111.174.26
Source: unknownTCP traffic detected without corresponding DNS query: 176.111.174.26
Source: unknownTCP traffic detected without corresponding DNS query: 176.111.174.26
Source: sshinsString found in binary or memory: http://upx.sf.net
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 43450
Source: unknownNetwork traffic detected: HTTP traffic on port 43448 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 43450 -> 443
Source: LOAD without section mappingsProgram segment: 0x400000
Source: sshins, type: SAMPLEMatched rule: SUSP_ELF_LNX_UPX_Compressed_File date = 2018-12-12, author = Florian Roth, description = Detects a suspicious ELF binary with UPX compression, reference = Internal Research, score = 038ff8b2fef16f8ee9d70e6c219c5f380afe1a21761791e8cbda21fa4d09fdb4
Source: classification engineClassification label: mal56.evad.lin@0/8@0/0

Data Obfuscation:

barindex
Sample is packed with UPXShow sources
Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
Source: initial sampleString containing UPX found: $Id: UPX 3.96 Copyright (C) 1996-2020 the UPX Team. All Rights Reserved. $

Persistence and Installation Behavior:

barindex
Creates /etc/ld.so.preloadShow sources
Source: /tmp/sshins (PID: 4579)Created: /etc/ld.so.preloadJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/22/taskJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/22/fdJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/22/map_filesJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/22/fdinfoJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/22/nsJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/22/netJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/22/environJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/22/auxvJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/22/statusJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/22/personalityJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/22/limitsJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/22/schedJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/22/autogroupJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/22/commJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/22/syscallJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/22/cmdlineJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/22/cmdlineJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/22/statJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/22/statmJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/22/mapsJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/22/numa_mapsJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/22/memJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/22/cwdJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/22/rootJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/22/exeJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/22/mountsJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/22/mountinfoJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/22/mountstatsJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/22/clear_refsJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/22/smapsJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/22/pagemapJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/22/attrJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/22/wchanJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/22/stackJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/22/schedstatJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/22/cpusetJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/22/cgroupJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/22/oom_scoreJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/22/oom_adjJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/22/oom_score_adjJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/22/loginuidJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/22/sessionidJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/22/coredump_filterJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/22/ioJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/22/uid_mapJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/22/gid_mapJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/22/projid_mapJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/22/setgroupsJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/22/timersJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/23/taskJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/23/fdJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/23/map_filesJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/23/fdinfoJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/23/nsJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/23/netJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/23/environJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/23/auxvJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/23/statusJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/23/personalityJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/23/limitsJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/23/schedJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/23/autogroupJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/23/commJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/23/syscallJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/23/cmdlineJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/23/cmdlineJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/23/statJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/23/statmJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/23/mapsJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/23/numa_mapsJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/23/memJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/23/cwdJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/23/rootJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/23/exeJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/23/mountsJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/23/mountinfoJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/23/mountstatsJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/23/clear_refsJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/23/smapsJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/23/pagemapJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/23/attrJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/23/wchanJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/23/stackJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/23/schedstatJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/23/cpusetJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/23/cgroupJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/23/oom_scoreJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/23/oom_adjJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/23/oom_score_adjJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/23/loginuidJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/23/sessionidJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/23/coredump_filterJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/23/ioJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/23/uid_mapJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/23/gid_mapJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/23/projid_mapJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/23/setgroupsJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/23/timersJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/24/taskJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/24/fdJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/24/map_filesJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/24/fdinfoJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/24/nsJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/24/netJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/24/environJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/24/auxvJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/24/statusJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/24/personalityJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/24/limitsJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/24/schedJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/24/autogroupJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/24/commJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/24/syscallJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/24/cmdlineJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/24/cmdlineJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/24/statJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/24/statmJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/24/mapsJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/24/numa_mapsJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/24/memJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/24/cwdJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/24/rootJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/24/exeJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/24/mountsJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/24/mountinfoJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/24/mountstatsJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/24/clear_refsJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/24/smapsJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/24/pagemapJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/24/attrJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/24/wchanJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/24/stackJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/24/schedstatJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/24/cpusetJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/24/cgroupJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/24/oom_scoreJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/24/oom_adjJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/24/oom_score_adjJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/24/loginuidJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/24/sessionidJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/24/coredump_filterJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/24/ioJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/24/uid_mapJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/24/gid_mapJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/24/projid_mapJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/24/setgroupsJump to behavior
Source: /usr/sbin/sshd (PID: 4792)File opened: /proc/24/timersJump to behavior
Source: /tmp/sshins (PID: 4583)Shell command executed: /bin/sh -c "/etc/init.d/sshd restart"Jump to behavior
Source: /tmp/sshins (PID: 4593)Shell command executed: /bin/sh -c "/etc/rc.d/sshd restart"Jump to behavior
Source: /tmp/sshins (PID: 4609)Shell command executed: /bin/sh -c "service ssh restart"Jump to behavior
Source: /tmp/sshins (PID: 4737)Shell command executed: /bin/sh -c "systemctl restart ssh"Jump to behavior
Source: /tmp/sshins (PID: 4765)Shell command executed: /bin/sh -c "systemctl restart sshd.service"Jump to behavior
Source: /usr/sbin/service (PID: 4654)Grep executable: /bin/grep -> grep -q upstartJump to behavior
Source: /usr/sbin/service (PID: 4619)Systemctl executable: /bin/systemctl -> systemctl restart ssh.serviceJump to behavior
Source: /usr/sbin/service (PID: 4673)Systemctl executable: /bin/systemctl -> systemctl --quiet is-active multi-user.targetJump to behavior
Source: /bin/sh (PID: 4738)Systemctl executable: /bin/systemctl -> systemctl restart sshJump to behavior
Source: /bin/sh (PID: 4766)Systemctl executable: /bin/systemctl -> systemctl restart sshd.serviceJump to behavior
Source: /usr/sbin/sshd (PID: 4736)Reads from proc file: /proc/cpuinfoJump to behavior
Source: /usr/sbin/sshd (PID: 4736)Reads from proc file: /proc/meminfoJump to behavior
Source: /usr/sbin/sshd (PID: 4792)Reads from proc file: /proc/cpuinfoJump to behavior
Source: /usr/sbin/sshd (PID: 4792)Reads from proc file: /proc/meminfoJump to behavior
Source: /tmp/sshins (PID: 4579)File written: /lib64/libs.soJump to dropped file
Source: submitted sampleStderr: [+] Installing 64 bits version/bin/sh: 1: /etc/init.d/sshd: not found/bin/sh: 1: /etc/rc.d/sshd: not found: exit code = 0
Source: /usr/sbin/sshd (PID: 4736)Reads CPU info from proc file: /proc/cpuinfoJump to behavior
Source: /usr/sbin/sshd (PID: 4792)Reads CPU info from proc file: /proc/cpuinfoJump to behavior
Source: /usr/sbin/sshd (PID: 4736)Queries kernel information via 'uname': Jump to behavior
Source: /bin/df (PID: 4794)Queries kernel information via 'uname': Jump to behavior
Source: /usr/sbin/sshd (PID: 4792)Queries kernel information via 'uname': Jump to behavior
Source: /bin/df (PID: 4812)Queries kernel information via 'uname': Jump to behavior

Mitre Att&ck Matrix

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsScripting1Systemd Service1Systemd Service1Process Injection1OS Credential Dumping1Security Software Discovery1Remote ServicesData from Local SystemExfiltration Over Other Network MediumEncrypted Channel1Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsProcess Injection1Scripting1LSASS MemorySystem Information Discovery2Remote Desktop ProtocolData from Removable MediaExfiltration Over BluetoothApplication Layer Protocol1Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or Information1Security Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationSteganographyExploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data

Behavior Graph

Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 355141 Sample: sshins Startdate: 19/02/2021 Architecture: LINUX Score: 56 61 176.111.174.26, 43450, 443 WILWAWPL Russian Federation 2->61 63 Multi AV Scanner detection for submitted file 2->63 65 Sample is packed with UPX 2->65 9 sshins 2->9         started        13 systemd sshd 2->13         started        15 systemd sshd 2->15         started        17 systemd sshd 2->17         started        signatures3 process4 file5 59 /etc/ld.so.preload, ASCII 9->59 dropped 67 Creates /etc/ld.so.preload 9->67 19 sshins sh 9->19         started        21 sshins sh 9->21         started        23 sshins sh 9->23         started        31 2 other processes 9->31 25 sshd 13->25         started        27 sshd 15->27         started        29 sshd 17->29         started        signatures6 process7 process8 33 sh service systemctl 19->33         started        35 sh systemctl 21->35         started        37 sh systemctl 23->37         started        39 sshd dash 25->39         started        41 sshd dash 27->41         started        43 sh 31->43         started        45 sh 31->45         started        process9 47 service initctl 33->47         started        49 service basename 33->49         started        51 service basename 33->51         started        57 3 other processes 33->57 53 dash df 39->53         started        55 dash df 41->55         started       

Antivirus, Machine Learning and Genetic Malware Detection

Initial Sample

SourceDetectionScannerLabelLink
sshins7%VirustotalBrowse
sshins13%ReversingLabsLinux.Trojan.Generic

Dropped Files

No Antivirus matches

Domains

No Antivirus matches

URLs

No Antivirus matches

Domains and IPs

Contacted Domains

No contacted domains info

URLs from Memory and Binaries

NameSourceMaliciousAntivirus DetectionReputation
http://upx.sf.netsshinsfalse
    high

    Contacted IPs

    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs

    Public

    IPDomainCountryFlagASNASN NameMalicious
    176.111.174.26
    unknownRussian Federation
    201305WILWAWPLfalse

    General Information

    Joe Sandbox Version:31.0.0 Emerald
    Analysis ID:355141
    Start date:19.02.2021
    Start time:03:42:20
    Joe Sandbox Product:CloudBasic
    Overall analysis duration:0h 4m 39s
    Hypervisor based Inspection enabled:false
    Report type:full
    Sample file name:sshins
    Cookbook file name:defaultlinuxfilecookbook.jbs
    Analysis system description:Ubuntu Linux 16.04 x64 (Kernel 4.4.0-116, Firefox 59.0, Document Viewer 3.18.2, LibreOffice 5.1.6.2, OpenJDK 1.8.0_171)
    Analysis Mode:default
    Detection:MAL
    Classification:mal56.evad.lin@0/8@0/0


    Runtime Messages

    Command:/tmp/sshins
    Exit Code:0
    Exit Code Info:
    Killed:False
    Standard Output:
    [+] Architecture 64 bits
    [+] Control 176.111.174.26:443
    [+] Poll interval 600
    [+] GUID 2f953bde-5de5226c-74fec1f7-76ea9a0a
    [+] Creating ld.so.preload
    [+] Done; restarting service...
    Standard Error:[+] Installing 64 bits version
    /bin/sh: 1: /etc/init.d/sshd: not found
    /bin/sh: 1: /etc/rc.d/sshd: not found

    Joe Sandbox View / Context

    IPs

    No context

    Domains

    No context

    ASN

    MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
    WILWAWPLeinL2PPa4E.exeGet hashmaliciousBrowse
    • 176.111.174.14
    8US9TvrlsZ.exeGet hashmaliciousBrowse
    • 176.111.174.14
    KZ34gNt1UT.exeGet hashmaliciousBrowse
    • 176.111.174.14
    SecuriteInfo.com.Trojan.PackedNET.535.15264.exeGet hashmaliciousBrowse
    • 176.111.174.14
    SecuriteInfo.com.Trojan.PackedNET.535.2299.exeGet hashmaliciousBrowse
    • 176.111.174.14
    1vU1ZhnEFU.exeGet hashmaliciousBrowse
    • 176.111.174.35
    TfF8Ijj0iQ.exeGet hashmaliciousBrowse
    • 176.111.174.35
    siBFQqOUA9.exeGet hashmaliciousBrowse
    • 176.111.174.35
    JvZn6FOUdq.exeGet hashmaliciousBrowse
    • 176.111.174.35
    l6fH3VMf5Y.exeGet hashmaliciousBrowse
    • 176.111.174.35
    Documentaci#U00f3n.docGet hashmaliciousBrowse
    • 176.111.174.185

    JA3 Fingerprints

    No context

    Dropped Files

    No context

    Created / dropped Files

    /etc/ld.so.preload
    Process:/tmp/sshins
    File Type:ASCII text, with no line terminators
    Category:dropped
    Size (bytes):15
    Entropy (8bit):3.2402239289418526
    Encrypted:false
    SSDEEP:3:8GiWKn:8jWK
    MD5:DFC3B49CEF9126A9D3E9EF7D6021D99D
    SHA1:CD707240DA9FC02C30B63EF96C53042129A1DA97
    SHA-256:B5E29BDB105AE0E76D75C3D3959954C4F6610CD39AAA8F3AA852DD624E662480
    SHA-512:AB9F6672FD291351E277D3B6A536B3EE591784149DEB48B7238740484028BF1F4B9AD209A8864AB5874D5268ED5858A6CD79B9C0B237986DEF510BFE11D5033A
    Malicious:true
    Reputation:low
    Preview: /lib64/libs.so
    /lib64/libs.so
    Process:/tmp/sshins
    File Type:ELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, stripped
    Category:dropped
    Size (bytes):31048
    Entropy (8bit):5.80292070479781
    Encrypted:false
    SSDEEP:384:QQI/dEZm0gbbpDIf1mT7ipvGS0dk0n7msrmO/B8tMJh/Y/pJgLa0Mp8L:QR0wNIPf0dkY+SBUMJh/QgLa1G
    MD5:3953CF31046FED0945442918B8D5A0E9
    SHA1:3B5D8333B4E3FD6532632A00944B6FD95C574DE6
    SHA-256:74F48A8E25550B29AFF665D5CF506162B0D749F8D7E24F362DD05D5519F2B2D2
    SHA-512:29288668219428A099EB40B563007092B51261B9D40CB27D1F5507C567FEB573CDD1949E17095F068FFE8963E0CD4DC0B6B7FD2EBD42311CA4530A1346B8D405
    Malicious:false
    Reputation:low
    Preview: .ELF..............>.............@...................@.8...@..................................... S...... S.......................^.......n.......n..............x .......................^.......n.......n......@.......@...............Q.td....................................................W...2...........................0.......................................!....................................... ...........+...................1.......#..............................."...............'.......%...........................................(...................*.................................../...)...$...........&...,...................-................................................................................................................................................................................................................o...............n.......w...............u.......w...............u.......w...............u.......w...............v.......w..............%v.......w......
    /proc/4694/oom_score_adj
    Process:/usr/sbin/sshd
    File Type:ASCII text
    Category:dropped
    Size (bytes):6
    Entropy (8bit):1.7924812503605778
    Encrypted:false
    SSDEEP:3:ptn:Dn
    MD5:CBF282CC55ED0792C33D10003D1F760A
    SHA1:007DD8BD75468E6B7ABA4285E9B267202C7EAEED
    SHA-256:FCDBAB99FCC0F4409E5F9D7D6FC497780288B4C441698126BB62832412774D22
    SHA-512:4643A8675D213C7DA35CC0C2BFB3B6F20324F9C48AEA7BA79F470615698C9A0CEFDA45CAA1957FC29110EE746BC8458AB8AB1E43EB513912A5E1E8858812CC00
    Malicious:false
    Reputation:moderate, very likely benign file
    Preview: -1000.
    /proc/4755/oom_score_adj
    Process:/usr/sbin/sshd
    File Type:ASCII text
    Category:dropped
    Size (bytes):6
    Entropy (8bit):1.7924812503605778
    Encrypted:false
    SSDEEP:3:ptn:Dn
    MD5:CBF282CC55ED0792C33D10003D1F760A
    SHA1:007DD8BD75468E6B7ABA4285E9B267202C7EAEED
    SHA-256:FCDBAB99FCC0F4409E5F9D7D6FC497780288B4C441698126BB62832412774D22
    SHA-512:4643A8675D213C7DA35CC0C2BFB3B6F20324F9C48AEA7BA79F470615698C9A0CEFDA45CAA1957FC29110EE746BC8458AB8AB1E43EB513912A5E1E8858812CC00
    Malicious:false
    Reputation:moderate, very likely benign file
    Preview: -1000.
    /proc/4770/oom_score_adj
    Process:/usr/sbin/sshd
    File Type:ASCII text
    Category:dropped
    Size (bytes):6
    Entropy (8bit):1.7924812503605778
    Encrypted:false
    SSDEEP:3:ptn:Dn
    MD5:CBF282CC55ED0792C33D10003D1F760A
    SHA1:007DD8BD75468E6B7ABA4285E9B267202C7EAEED
    SHA-256:FCDBAB99FCC0F4409E5F9D7D6FC497780288B4C441698126BB62832412774D22
    SHA-512:4643A8675D213C7DA35CC0C2BFB3B6F20324F9C48AEA7BA79F470615698C9A0CEFDA45CAA1957FC29110EE746BC8458AB8AB1E43EB513912A5E1E8858812CC00
    Malicious:false
    Reputation:moderate, very likely benign file
    Preview: -1000.
    /run/sshd.pid
    Process:/usr/sbin/sshd
    File Type:ASCII text
    Category:dropped
    Size (bytes):5
    Entropy (8bit):1.9219280948873623
    Encrypted:false
    SSDEEP:3:Bv:Bv
    MD5:57434CC6AB6F61FC68FB57A03A71A846
    SHA1:878D4FCD8CFCA34C4E569791C4D80FC1BC9FDFEF
    SHA-256:EDE4DF2C6DAAAE51F8B3BEA8A57F26960CC0CB6F255E78C6C823B08ADF72BD64
    SHA-512:F505D92D85FF743B6742DFB917D10F09991EB6B04BB4CDF0E0304F540D6A20FF8D24077490ACE2CE03D24BE8ECCA00E8BBD9236344D8D30F17A5CCEDEE1A24F5
    Malicious:false
    Reputation:low
    Preview: 4770.

    Static File Info

    General

    File type:ELF 64-bit LSB executable, x86-64, version 1 (GNU/Linux), statically linked, stripped
    Entropy (8bit):7.898469192826647
    TrID:
    • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
    • ELF Executable and Linkable format (generic) (4004/1) 49.84%
    File name:sshins
    File size:53368
    MD5:38fb322cc6d09a6ab85784ede56bc5a7
    SHA1:f7d95a887a51fe97ce64a93a40196b2cccaa80d8
    SHA256:ab9cc4ee82aa6f57ba2a113aab905c33e278c969399db4188d0ea5942ad3bb7d
    SHA512:b04b3a44ac2d27f11e8782c78499160a9886c4ec9f04fd29f352d107bb7960ac918d3cf4c5068452a586695fa0aa47ad470c737123e07a9b20d58192913c1fb5
    SSDEEP:1536:+eCFnFH5QJhNTG8wWJC5RYnunjG86u3Eos:ZgQhNTGkJsnjGpS6
    File Content Preview:.ELF..............>.....@.@.....@...................@.8...@.......................@.......@.....v.......v.................................@.......@.............................Q.td....................................................5-'7UPX!D....... }.. }.

    Static ELF Info

    ELF header

    Class:ELF64
    Data:2's complement, little endian
    Version:1 (current)
    Machine:Advanced Micro Devices X86-64
    Version Number:0x1
    Type:EXEC (Executable file)
    OS/ABI:UNIX - Linux
    ABI Version:0
    Entry Point Address:0x40c640
    Flags:0x0
    ELF Header Size:64
    Program Header Offset:64
    Program Header Size:56
    Number of Program Headers:3
    Section Header Offset:0
    Section Header Size:64
    Number of Section Headers:0
    Header String Table Index:0

    Program Segments

    TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeFlagsFlags DescriptionAlignProg InterpreterSection Mappings
    LOAD0x00x4000000x4000000xcf760xcf760x5R E0x1000
    LOAD0x00x40d0000x40d0000x00xf1a00x6RW 0x1000
    GNU_STACK0x00x00x00x00x00x6RW 0x10

    Network Behavior

    Network Port Distribution

    TCP Packets

    TimestampSource PortDest PortSource IPDest IP
    Feb 19, 2021 03:42:52.079957008 CET43448443192.168.2.20176.111.174.26
    Feb 19, 2021 03:42:52.190618992 CET43450443192.168.2.20176.111.174.26
    Feb 19, 2021 03:42:53.078636885 CET43448443192.168.2.20176.111.174.26
    Feb 19, 2021 03:42:53.190236092 CET43450443192.168.2.20176.111.174.26
    Feb 19, 2021 03:42:55.082031012 CET43448443192.168.2.20176.111.174.26
    Feb 19, 2021 03:42:55.194015026 CET43450443192.168.2.20176.111.174.26
    Feb 19, 2021 03:42:59.089432001 CET43448443192.168.2.20176.111.174.26
    Feb 19, 2021 03:42:59.201448917 CET43450443192.168.2.20176.111.174.26
    Feb 19, 2021 03:43:07.104274988 CET43448443192.168.2.20176.111.174.26
    Feb 19, 2021 03:43:07.216303110 CET43450443192.168.2.20176.111.174.26
    Feb 19, 2021 03:43:07.312433958 CET44343450176.111.174.26192.168.2.20
    Feb 19, 2021 03:43:07.312845945 CET43450443192.168.2.20176.111.174.26
    Feb 19, 2021 03:43:07.313451052 CET43450443192.168.2.20176.111.174.26
    Feb 19, 2021 03:43:07.608253956 CET43450443192.168.2.20176.111.174.26
    Feb 19, 2021 03:43:07.904176950 CET43450443192.168.2.20176.111.174.26
    Feb 19, 2021 03:43:08.496047020 CET43450443192.168.2.20176.111.174.26
    Feb 19, 2021 03:43:08.613449097 CET44343450176.111.174.26192.168.2.20
    Feb 19, 2021 03:43:08.613619089 CET43450443192.168.2.20176.111.174.26
    Feb 19, 2021 03:43:09.683990002 CET43450443192.168.2.20176.111.174.26
    Feb 19, 2021 03:43:10.613540888 CET44343450176.111.174.26192.168.2.20
    Feb 19, 2021 03:43:10.613814116 CET43450443192.168.2.20176.111.174.26
    Feb 19, 2021 03:43:12.055648088 CET43450443192.168.2.20176.111.174.26
    Feb 19, 2021 03:43:14.613289118 CET44343450176.111.174.26192.168.2.20
    Feb 19, 2021 03:43:14.613604069 CET43450443192.168.2.20176.111.174.26
    Feb 19, 2021 03:43:16.798963070 CET43450443192.168.2.20176.111.174.26
    Feb 19, 2021 03:43:16.895431042 CET44343450176.111.174.26192.168.2.20
    Feb 19, 2021 03:43:23.150048971 CET43448443192.168.2.20176.111.174.26
    Feb 19, 2021 03:43:36.457053900 CET44343450176.111.174.26192.168.2.20
    Feb 19, 2021 03:43:36.457360029 CET43450443192.168.2.20176.111.174.26
    Feb 19, 2021 03:43:36.553324938 CET44343450176.111.174.26192.168.2.20
    Feb 19, 2021 03:43:36.553555965 CET43450443192.168.2.20176.111.174.26
    Feb 19, 2021 03:43:36.554335117 CET43450443192.168.2.20176.111.174.26
    Feb 19, 2021 03:43:36.557060957 CET43450443192.168.2.20176.111.174.26
    Feb 19, 2021 03:43:36.649967909 CET44343450176.111.174.26192.168.2.20
    Feb 19, 2021 03:43:36.650192976 CET43450443192.168.2.20176.111.174.26
    Feb 19, 2021 03:43:36.654392004 CET44343450176.111.174.26192.168.2.20
    Feb 19, 2021 03:43:36.654594898 CET43450443192.168.2.20176.111.174.26
    Feb 19, 2021 03:43:36.746119976 CET44343450176.111.174.26192.168.2.20
    Feb 19, 2021 03:43:36.746288061 CET43450443192.168.2.20176.111.174.26
    Feb 19, 2021 03:43:36.750221968 CET44343450176.111.174.26192.168.2.20
    Feb 19, 2021 03:43:36.841834068 CET44343450176.111.174.26192.168.2.20
    Feb 19, 2021 03:43:55.209440947 CET43448443192.168.2.20176.111.174.26

    System Behavior

    General

    Start time:03:42:49
    Start date:19/02/2021
    Path:/tmp/sshins
    Arguments:/tmp/sshins
    File size:53368 bytes
    MD5 hash:38fb322cc6d09a6ab85784ede56bc5a7

    General

    Start time:03:42:49
    Start date:19/02/2021
    Path:/tmp/sshins
    Arguments:n/a
    File size:53368 bytes
    MD5 hash:38fb322cc6d09a6ab85784ede56bc5a7

    General

    Start time:03:42:49
    Start date:19/02/2021
    Path:/bin/sh
    Arguments:/bin/sh -c "/etc/init.d/sshd restart"
    File size:4 bytes
    MD5 hash:e02ea3c3450d44126c46d658fa9e654c

    General

    Start time:03:42:49
    Start date:19/02/2021
    Path:/bin/sh
    Arguments:n/a
    File size:4 bytes
    MD5 hash:e02ea3c3450d44126c46d658fa9e654c

    General

    Start time:03:42:49
    Start date:19/02/2021
    Path:/tmp/sshins
    Arguments:n/a
    File size:53368 bytes
    MD5 hash:38fb322cc6d09a6ab85784ede56bc5a7

    General

    Start time:03:42:49
    Start date:19/02/2021
    Path:/bin/sh
    Arguments:/bin/sh -c "/etc/rc.d/sshd restart"
    File size:4 bytes
    MD5 hash:e02ea3c3450d44126c46d658fa9e654c

    General

    Start time:03:42:49
    Start date:19/02/2021
    Path:/bin/sh
    Arguments:n/a
    File size:4 bytes
    MD5 hash:e02ea3c3450d44126c46d658fa9e654c

    General

    Start time:03:42:49
    Start date:19/02/2021
    Path:/tmp/sshins
    Arguments:n/a
    File size:53368 bytes
    MD5 hash:38fb322cc6d09a6ab85784ede56bc5a7

    General

    Start time:03:42:49
    Start date:19/02/2021
    Path:/bin/sh
    Arguments:/bin/sh -c "service ssh restart"
    File size:4 bytes
    MD5 hash:e02ea3c3450d44126c46d658fa9e654c

    General

    Start time:03:42:49
    Start date:19/02/2021
    Path:/bin/sh
    Arguments:n/a
    File size:4 bytes
    MD5 hash:e02ea3c3450d44126c46d658fa9e654c

    General

    Start time:03:42:49
    Start date:19/02/2021
    Path:/usr/sbin/service
    Arguments:/bin/sh /usr/sbin/service ssh restart
    File size:10057 bytes
    MD5 hash:81c4fe604ec67916db7b223725e5a9c6

    General

    Start time:03:42:49
    Start date:19/02/2021
    Path:/usr/sbin/service
    Arguments:n/a
    File size:10057 bytes
    MD5 hash:81c4fe604ec67916db7b223725e5a9c6

    General

    Start time:03:42:49
    Start date:19/02/2021
    Path:/usr/bin/basename
    Arguments:basename /usr/sbin/service
    File size:31408 bytes
    MD5 hash:fd7bba8b11b99ec7559f30226c79a729

    General

    Start time:03:42:49
    Start date:19/02/2021
    Path:/usr/sbin/service
    Arguments:n/a
    File size:10057 bytes
    MD5 hash:81c4fe604ec67916db7b223725e5a9c6

    General

    Start time:03:42:49
    Start date:19/02/2021
    Path:/usr/bin/basename
    Arguments:basename /usr/sbin/service
    File size:31408 bytes
    MD5 hash:fd7bba8b11b99ec7559f30226c79a729

    General

    Start time:03:42:49
    Start date:19/02/2021
    Path:/usr/sbin/service
    Arguments:n/a
    File size:10057 bytes
    MD5 hash:81c4fe604ec67916db7b223725e5a9c6

    General

    Start time:03:42:49
    Start date:19/02/2021
    Path:/usr/bin/which
    Arguments:/bin/sh /usr/bin/which initctl
    File size:10 bytes
    MD5 hash:e942f154ef9d9974366551d2d231d936

    General

    Start time:03:42:49
    Start date:19/02/2021
    Path:/usr/sbin/service
    Arguments:n/a
    File size:10057 bytes
    MD5 hash:81c4fe604ec67916db7b223725e5a9c6

    General

    Start time:03:42:49
    Start date:19/02/2021
    Path:/sbin/initctl
    Arguments:initctl version
    File size:214216 bytes
    MD5 hash:8829ab02d00aa4f3145e93d258e2c2b5

    General

    Start time:03:42:49
    Start date:19/02/2021
    Path:/usr/sbin/service
    Arguments:n/a
    File size:10057 bytes
    MD5 hash:81c4fe604ec67916db7b223725e5a9c6

    General

    Start time:03:42:49
    Start date:19/02/2021
    Path:/bin/grep
    Arguments:grep -q upstart
    File size:211224 bytes
    MD5 hash:fc9b0a0ff848b35b3716768695bf2427

    General

    Start time:03:42:49
    Start date:19/02/2021
    Path:/usr/sbin/service
    Arguments:n/a
    File size:10057 bytes
    MD5 hash:81c4fe604ec67916db7b223725e5a9c6

    General

    Start time:03:42:49
    Start date:19/02/2021
    Path:/bin/systemctl
    Arguments:systemctl --quiet is-active multi-user.target
    File size:659848 bytes
    MD5 hash:b08096235b8c90203e17721264b5ce40

    General

    Start time:03:42:49
    Start date:19/02/2021
    Path:/bin/systemctl
    Arguments:systemctl restart ssh.service
    File size:659848 bytes
    MD5 hash:b08096235b8c90203e17721264b5ce40

    General

    Start time:03:42:49
    Start date:19/02/2021
    Path:/tmp/sshins
    Arguments:n/a
    File size:53368 bytes
    MD5 hash:38fb322cc6d09a6ab85784ede56bc5a7

    General

    Start time:03:42:49
    Start date:19/02/2021
    Path:/bin/sh
    Arguments:/bin/sh -c "systemctl restart ssh"
    File size:4 bytes
    MD5 hash:e02ea3c3450d44126c46d658fa9e654c

    General

    Start time:03:42:49
    Start date:19/02/2021
    Path:/bin/sh
    Arguments:n/a
    File size:4 bytes
    MD5 hash:e02ea3c3450d44126c46d658fa9e654c

    General

    Start time:03:42:49
    Start date:19/02/2021
    Path:/bin/systemctl
    Arguments:systemctl restart ssh
    File size:659848 bytes
    MD5 hash:b08096235b8c90203e17721264b5ce40

    General

    Start time:03:42:49
    Start date:19/02/2021
    Path:/tmp/sshins
    Arguments:n/a
    File size:53368 bytes
    MD5 hash:38fb322cc6d09a6ab85784ede56bc5a7

    General

    Start time:03:42:49
    Start date:19/02/2021
    Path:/bin/sh
    Arguments:/bin/sh -c "systemctl restart sshd.service"
    File size:4 bytes
    MD5 hash:e02ea3c3450d44126c46d658fa9e654c

    General

    Start time:03:42:49
    Start date:19/02/2021
    Path:/bin/sh
    Arguments:n/a
    File size:4 bytes
    MD5 hash:e02ea3c3450d44126c46d658fa9e654c

    General

    Start time:03:42:49
    Start date:19/02/2021
    Path:/bin/systemctl
    Arguments:systemctl restart sshd.service
    File size:659848 bytes
    MD5 hash:b08096235b8c90203e17721264b5ce40

    General

    Start time:03:42:49
    Start date:19/02/2021
    Path:/lib/systemd/systemd
    Arguments:n/a
    File size:0 bytes
    MD5 hash:00000000000000000000000000000000

    General

    Start time:03:42:49
    Start date:19/02/2021
    Path:/usr/sbin/sshd
    Arguments:/usr/sbin/sshd -D
    File size:791024 bytes
    MD5 hash:661b2a2da3b6c7d7ef41d0b9da1caa3b

    General

    Start time:03:42:49
    Start date:19/02/2021
    Path:/usr/sbin/sshd
    Arguments:n/a
    File size:791024 bytes
    MD5 hash:661b2a2da3b6c7d7ef41d0b9da1caa3b

    General

    Start time:03:42:51
    Start date:19/02/2021
    Path:/usr/sbin/sshd
    Arguments:n/a
    File size:791024 bytes
    MD5 hash:661b2a2da3b6c7d7ef41d0b9da1caa3b

    General

    Start time:03:42:51
    Start date:19/02/2021
    Path:/bin/dash
    Arguments:sh -c "/bin/df 2>/dev/null"
    File size:154072 bytes
    MD5 hash:e02ea3c3450d44126c46d658fa9e654c

    General

    Start time:03:42:51
    Start date:19/02/2021
    Path:/bin/dash
    Arguments:n/a
    File size:154072 bytes
    MD5 hash:e02ea3c3450d44126c46d658fa9e654c

    General

    Start time:03:42:51
    Start date:19/02/2021
    Path:/bin/df
    Arguments:/bin/df
    File size:97912 bytes
    MD5 hash:ba5b0b1786d40908a09a8eefa68688d3

    General

    Start time:03:42:49
    Start date:19/02/2021
    Path:/lib/systemd/systemd
    Arguments:n/a
    File size:0 bytes
    MD5 hash:00000000000000000000000000000000

    General

    Start time:03:42:49
    Start date:19/02/2021
    Path:/usr/sbin/sshd
    Arguments:/usr/sbin/sshd -D
    File size:791024 bytes
    MD5 hash:661b2a2da3b6c7d7ef41d0b9da1caa3b

    General

    Start time:03:42:49
    Start date:19/02/2021
    Path:/usr/sbin/sshd
    Arguments:n/a
    File size:791024 bytes
    MD5 hash:661b2a2da3b6c7d7ef41d0b9da1caa3b

    General

    Start time:03:42:49
    Start date:19/02/2021
    Path:/lib/systemd/systemd
    Arguments:n/a
    File size:0 bytes
    MD5 hash:00000000000000000000000000000000

    General

    Start time:03:42:49
    Start date:19/02/2021
    Path:/usr/sbin/sshd
    Arguments:/usr/sbin/sshd -D
    File size:791024 bytes
    MD5 hash:661b2a2da3b6c7d7ef41d0b9da1caa3b

    General

    Start time:03:42:49
    Start date:19/02/2021
    Path:/usr/sbin/sshd
    Arguments:n/a
    File size:791024 bytes
    MD5 hash:661b2a2da3b6c7d7ef41d0b9da1caa3b

    General

    Start time:03:42:51
    Start date:19/02/2021
    Path:/usr/sbin/sshd
    Arguments:n/a
    File size:791024 bytes
    MD5 hash:661b2a2da3b6c7d7ef41d0b9da1caa3b

    General

    Start time:03:42:51
    Start date:19/02/2021
    Path:/bin/dash
    Arguments:sh -c "/bin/df 2>/dev/null"
    File size:154072 bytes
    MD5 hash:e02ea3c3450d44126c46d658fa9e654c

    General

    Start time:03:42:51
    Start date:19/02/2021
    Path:/bin/dash
    Arguments:n/a
    File size:154072 bytes
    MD5 hash:e02ea3c3450d44126c46d658fa9e654c

    General

    Start time:03:42:51
    Start date:19/02/2021
    Path:/bin/df
    Arguments:/bin/df
    File size:97912 bytes
    MD5 hash:ba5b0b1786d40908a09a8eefa68688d3