Loading ...

Play interactive tourEdit tour

Linux Analysis Report seWzsbHlCC

Overview

General Information

Sample Name:seWzsbHlCC
Analysis ID:528748
MD5:4a3e4fcf840711d95a782a1aa01a3758
SHA1:1debbe3bda8a84261eee99edc5f672165a44813d
SHA256:8797bac4f4912bf412e4dc586f0747c0161de7b3ebd0e680eb814be4e20a7b39
Tags:32armelfmirai
Infos:

Detection

Mirai
Score:88
Range:0 - 100
Whitelisted:false

Signatures

Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)
Yara detected Mirai
Sample tries to kill many processes (SIGKILL)
Deletes all firewall rules
Connects to many ports of the same IP (likely port scanning)
Sample deletes itself
Sample is packed with UPX
Uses known network protocols on non-standard ports
Deletes security-related log files
Sample reads /proc/mounts (often used for finding a writable filesystem)
Executes the "kill" or "pkill" command typically used to terminate processes
Sample contains only a LOAD segment without any section mappings
Reads CPU information from /sys indicative of miner or evasive malware
Yara signature match
Executes the "grep" command used to find patterns in files or piped streams
Uses the "uname" system call to query kernel version information (possible evasion)
Enumerates processes within the "proc" file system
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Detected TCP or UDP traffic on non-standard ports
Sample listens on a socket
Sample tries to kill a process (SIGKILL)
Deletes log files
Creates hidden files and/or directories
Executes the "iptables" command used for managing IP filtering and manipulation
Sample tries to set the executable flag
Executes commands using a shell command-line interpreter
Executes the "rm" command used to delete files or directories

Classification

Analysis Advice

All HTTP servers contacted by the sample do not answer. Likely the sample is an old dropper which does no longer work
Static ELF header machine description suggests that the sample might only run correctly on MIPS or ARM architectures
Static ELF header machine description suggests that the sample might not execute correctly on this machine

General Information

Joe Sandbox Version:34.0.0 Boulder Opal
Analysis ID:528748
Start date:25.11.2021
Start time:18:28:37
Joe Sandbox Product:CloudBasic
Overall analysis duration:0h 10m 10s
Hypervisor based Inspection enabled:false
Report type:light
Sample file name:seWzsbHlCC
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Detection:MAL
Classification:mal88.spre.troj.evad.lin@0/9@2/0
Warnings:
Show All
  • Connection to analysis system has been lost, crash info: Unknown
  • TCP Packets have been reduced to 100
  • Report size exceeded maximum capacity and may have missing network information.
  • VT rate limit hit for: /opt/package/joesandbox/database/analysis/528748/sample/seWzsbHlCC

Process Tree

  • system is lnxubuntu20
  • seWzsbHlCC (PID: 5271, Parent: 5122, MD5: 5ebfcae4fe2471fcc5695c2394773ff1) Arguments: /tmp/seWzsbHlCC
    • seWzsbHlCC New Fork (PID: 5275, Parent: 5271)
      • seWzsbHlCC New Fork (PID: 5280, Parent: 5275)
        • seWzsbHlCC New Fork (PID: 5282, Parent: 5280)
          • sh (PID: 5284, Parent: 5282, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "rm -rf /tmp/* /var/* /var/run/* /var/tmp/*"
            • sh New Fork (PID: 5286, Parent: 5284)
            • rm (PID: 5286, Parent: 5284, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -rf /tmp/config-err-dHT8bZ /tmp/dmesgtail.log /tmp/seWzsbHlCC /tmp/snap.lxd /tmp/ssh-hOQ5FjG2iVgO /tmp/systemd-private-ec795e01d534441298b2bf519e4c51fc-ModemManager.service-c4RYFi /tmp/systemd-private-ec795e01d534441298b2bf519e4c51fc-colord.service-gKIF8e /tmp/systemd-private-ec795e01d534441298b2bf519e4c51fc-fwupd.service-gB0a9f /tmp/systemd-private-ec795e01d534441298b2bf519e4c51fc-switcheroo-control.service-APWnLg /tmp/systemd-private-ec795e01d534441298b2bf519e4c51fc-systemd-logind.service-IofUpj /tmp/systemd-private-ec795e01d534441298b2bf519e4c51fc-systemd-resolved.service-AfPZzg /tmp/systemd-private-ec795e01d534441298b2bf519e4c51fc-upower.service-x0xO0i /tmp/vmware-root_721-4290559889 /var/backups /var/cache /var/crash /var/lib /var/local /var/lock /var/log /var/mail /var/metrics /var/opt /var/run /var/snap /var/spool /var/tmp /var/run/NetworkManager /var/run/acpid.pid /var/run/acpid.socket /var/run/apport.lock /var/run/avahi-daemon /var/run/blkid /var/run/cloud-init /var/run/console-setup /var/run/crond.pid /var/run/crond.reboot /var/run/cryptsetup /var/run/cups /var/run/dbus /var/run/dmeventd-client /var/run/dmeventd-server /var/run/gdm3 /var/run/gdm3.pid /var/run/initctl /var/run/initramfs /var/run/irqbalance /var/run/lock /var/run/log /var/run/lvm /var/run/mlocate.daily.lock /var/run/mono-xsp4 /var/run/mono-xsp4.pid /var/run/motd.d /var/run/mount /var/run/multipathd.pid /var/run/netns /var/run/network /var/run/screen /var/run/sendsigs.omit.d /var/run/shm /var/run/snapd /var/run/snapd-snap.socket /var/run/snapd.socket /var/run/speech-dispatcher /var/run/spice-vdagentd /var/run/sshd /var/run/sshd.pid /var/run/sudo /var/run/systemd /var/run/tmpfiles.d /var/run/udev /var/run/udisks2 /var/run/unattended-upgrades.lock /var/run/user /var/run/utmp /var/run/uuidd /var/run/vmware /var/tmp/systemd-private-ec795e01d534441298b2bf519e4c51fc-ModemManager.service-J6Q1Te /var/tmp/systemd-private-ec795e01d534441298b2bf519e4c51fc-colord.service-srP90f /var/tmp/systemd-private-ec795e01d534441298b2bf519e4c51fc-fwupd.service-biJ0Gi /var/tmp/systemd-private-ec795e01d534441298b2bf519e4c51fc-switcheroo-control.service-1jIxdj /var/tmp/systemd-private-ec795e01d534441298b2bf519e4c51fc-systemd-logind.service-llmWag /var/tmp/systemd-private-ec795e01d534441298b2bf519e4c51fc-systemd-resolved.service-X16eHh /var/tmp/systemd-private-ec795e01d534441298b2bf519e4c51fc-upower.service-GpSnaf
          • sh (PID: 5293, Parent: 5282, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "rm -rf /var/log/wtmp"
            • sh New Fork (PID: 5295, Parent: 5293)
            • rm (PID: 5295, Parent: 5293, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -rf /var/log/wtmp
          • sh (PID: 5296, Parent: 5282, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "rm -rf /tmp/*"
            • sh New Fork (PID: 5298, Parent: 5296)
            • rm (PID: 5298, Parent: 5296, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -rf /tmp/*
          • sh (PID: 5299, Parent: 5282, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "rm -rf /bin/netstat"
            • sh New Fork (PID: 5301, Parent: 5299)
            • rm (PID: 5301, Parent: 5299, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -rf /bin/netstat
          • sh (PID: 5302, Parent: 5282, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "iptables -F"
            • sh New Fork (PID: 5304, Parent: 5302)
            • iptables (PID: 5304, Parent: 5302, MD5: 1ab05fef765b6342cdfadaa5275b33af) Arguments: iptables -F
          • sh (PID: 5308, Parent: 5282, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "pkill -9 busybox"
            • sh New Fork (PID: 5310, Parent: 5308)
            • pkill (PID: 5310, Parent: 5308, MD5: fa96a75a08109d8842e4865b2907d51f) Arguments: pkill -9 busybox
          • sh (PID: 5317, Parent: 5282, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "pkill -9 perl"
            • sh New Fork (PID: 5319, Parent: 5317)
            • pkill (PID: 5319, Parent: 5317, MD5: fa96a75a08109d8842e4865b2907d51f) Arguments: pkill -9 perl
          • sh (PID: 5320, Parent: 5282, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "pkill -9 python"
            • sh New Fork (PID: 5322, Parent: 5320)
            • pkill (PID: 5322, Parent: 5320, MD5: fa96a75a08109d8842e4865b2907d51f) Arguments: pkill -9 python
          • sh (PID: 5325, Parent: 5282, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "service iptables stop"
            • sh New Fork (PID: 5327, Parent: 5325)
            • service (PID: 5327, Parent: 5325, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: service iptables stop
              • service New Fork (PID: 5328, Parent: 5327)
              • basename (PID: 5328, Parent: 5327, MD5: 3283660e59f128df18bec9b96fbd4d41) Arguments: basename /usr/sbin/service
              • service New Fork (PID: 5329, Parent: 5327)
              • basename (PID: 5329, Parent: 5327, MD5: 3283660e59f128df18bec9b96fbd4d41) Arguments: basename /usr/sbin/service
              • service New Fork (PID: 5330, Parent: 5327)
              • systemctl (PID: 5330, Parent: 5327, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl --quiet is-active multi-user.target
              • service New Fork (PID: 5331, Parent: 5327)
                • service New Fork (PID: 5332, Parent: 5331)
                • systemctl (PID: 5332, Parent: 5331, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl list-unit-files --full --type=socket
                • service New Fork (PID: 5333, Parent: 5331)
                • sed (PID: 5333, Parent: 5331, MD5: 885062561f66aa1d4af4c54b9e7cc81a) Arguments: sed -ne s/\\.socket\\s*[a-z]*\\s*$/.socket/p
            • systemctl (PID: 5327, Parent: 5325, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl stop iptables.service
          • sh (PID: 5334, Parent: 5282, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "/sbin/iptables -F; /sbin/iptables -X"
            • sh New Fork (PID: 5336, Parent: 5334)
            • iptables (PID: 5336, Parent: 5334, MD5: 1ab05fef765b6342cdfadaa5275b33af) Arguments: /sbin/iptables -F
            • sh New Fork (PID: 5337, Parent: 5334)
            • iptables (PID: 5337, Parent: 5334, MD5: 1ab05fef765b6342cdfadaa5275b33af) Arguments: /sbin/iptables -X
          • sh (PID: 5338, Parent: 5282, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "service firewalld stop"
            • sh New Fork (PID: 5340, Parent: 5338)
            • service (PID: 5340, Parent: 5338, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: service firewalld stop
              • service New Fork (PID: 5341, Parent: 5340)
              • basename (PID: 5341, Parent: 5340, MD5: 3283660e59f128df18bec9b96fbd4d41) Arguments: basename /usr/sbin/service
              • service New Fork (PID: 5342, Parent: 5340)
              • basename (PID: 5342, Parent: 5340, MD5: 3283660e59f128df18bec9b96fbd4d41) Arguments: basename /usr/sbin/service
              • service New Fork (PID: 5343, Parent: 5340)
              • systemctl (PID: 5343, Parent: 5340, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl --quiet is-active multi-user.target
              • service New Fork (PID: 5344, Parent: 5340)
                • service New Fork (PID: 5345, Parent: 5344)
                • systemctl (PID: 5345, Parent: 5344, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl list-unit-files --full --type=socket
                • service New Fork (PID: 5346, Parent: 5344)
                • sed (PID: 5346, Parent: 5344, MD5: 885062561f66aa1d4af4c54b9e7cc81a) Arguments: sed -ne s/\\.socket\\s*[a-z]*\\s*$/.socket/p
            • systemctl (PID: 5340, Parent: 5338, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl stop firewalld.service
          • sh (PID: 5349, Parent: 5282, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "rm -rf ~/.bash_history"
            • sh New Fork (PID: 5351, Parent: 5349)
            • rm (PID: 5351, Parent: 5349, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -rf /root/.bash_history
          • sh (PID: 5352, Parent: 5282, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "history -c"
  • systemd New Fork (PID: 5382, Parent: 1)
  • whoopsie (PID: 5382, Parent: 1, MD5: d3a6915d0e7398fb4c89a037c13959c8) Arguments: /usr/bin/whoopsie -f
  • systemd New Fork (PID: 5407, Parent: 1)
  • sshd (PID: 5407, Parent: 1, MD5: dbca7a6bbf7bf57fedac243d4b2cb340) Arguments: /usr/sbin/sshd -t
  • systemd New Fork (PID: 5408, Parent: 1)
  • sshd (PID: 5408, Parent: 1, MD5: dbca7a6bbf7bf57fedac243d4b2cb340) Arguments: /usr/sbin/sshd -D
  • gdm3 New Fork (PID: 5413, Parent: 1320)
  • Default (PID: 5413, Parent: 1320, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /etc/gdm3/PrimeOff/Default
  • gdm3 New Fork (PID: 5414, Parent: 1320)
  • Default (PID: 5414, Parent: 1320, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /etc/gdm3/PrimeOff/Default
  • systemd New Fork (PID: 5417, Parent: 1)
  • accounts-daemon (PID: 5417, Parent: 1, MD5: 01a899e3fb5e7e434bea1290255a1f30) Arguments: /usr/lib/accountsservice/accounts-daemon
  • systemd New Fork (PID: 5446, Parent: 1860)
  • pulseaudio (PID: 5446, Parent: 1860, MD5: 0c3b4c789d8ffb12b25507f27e14c186) Arguments: /usr/bin/pulseaudio --daemonize=no --log-target=journal
  • systemd New Fork (PID: 5471, Parent: 1)
  • gpu-manager (PID: 5471, Parent: 1, MD5: 8fae9dd5dd67e1f33d873089c2fd8761) Arguments: /usr/bin/gpu-manager --log /var/log/gpu-manager.log
    • sh (PID: 5472, Parent: 5471, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /etc/modprobe.d/*.conf"
      • sh New Fork (PID: 5473, Parent: 5472)
      • grep (PID: 5473, Parent: 5472, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep -G ^blacklist.*nvidia[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
    • sh (PID: 5474, Parent: 5471, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /lib/modprobe.d/*.conf"
      • sh New Fork (PID: 5475, Parent: 5474)
      • grep (PID: 5475, Parent: 5474, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep -G ^blacklist.*nvidia[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
    • sh (PID: 5476, Parent: 5471, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /etc/modprobe.d/*.conf"
      • sh New Fork (PID: 5477, Parent: 5476)
      • grep (PID: 5477, Parent: 5476, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep -G ^blacklist.*radeon[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
    • sh (PID: 5478, Parent: 5471, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /lib/modprobe.d/*.conf"
      • sh New Fork (PID: 5479, Parent: 5478)
      • grep (PID: 5479, Parent: 5478, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep -G ^blacklist.*radeon[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
    • sh (PID: 5480, Parent: 5471, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "grep -G \"^blacklist.*amdgpu[[:space:]]*$\" /etc/modprobe.d/*.conf"
      • sh New Fork (PID: 5481, Parent: 5480)
      • grep (PID: 5481, Parent: 5480, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep -G ^blacklist.*amdgpu[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
    • sh (PID: 5482, Parent: 5471, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "grep -G \"^blacklist.*amdgpu[[:space:]]*$\" /lib/modprobe.d/*.conf"
      • sh New Fork (PID: 5483, Parent: 5482)
      • grep (PID: 5483, Parent: 5482, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep -G ^blacklist.*amdgpu[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
    • sh (PID: 5484, Parent: 5471, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "grep -G \"^blacklist.*nouveau[[:space:]]*$\" /etc/modprobe.d/*.conf"
      • sh New Fork (PID: 5485, Parent: 5484)
      • grep (PID: 5485, Parent: 5484, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep -G ^blacklist.*nouveau[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
    • sh (PID: 5486, Parent: 5471, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "grep -G \"^blacklist.*nouveau[[:space:]]*$\" /lib/modprobe.d/*.conf"
      • sh New Fork (PID: 5487, Parent: 5486)
      • grep (PID: 5487, Parent: 5486, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep -G ^blacklist.*nouveau[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
  • systemd New Fork (PID: 5488, Parent: 1)
  • generate-config (PID: 5488, Parent: 1, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /usr/share/gdm/generate-config
    • pkill (PID: 5489, Parent: 5488, MD5: fa96a75a08109d8842e4865b2907d51f) Arguments: pkill --signal HUP --uid gdm dconf-service
  • systemd New Fork (PID: 5492, Parent: 1)
  • gdm-wait-for-drm (PID: 5492, Parent: 1, MD5: 82043ba752c6930b4e6aaea2f7747545) Arguments: /usr/lib/gdm3/gdm-wait-for-drm
  • fusermount (PID: 5494, Parent: 2038, MD5: 576a1b135c82bdcbc97a91acea900566) Arguments: fusermount -u -q -z -- /run/user/1000/gvfs
  • systemd New Fork (PID: 5502, Parent: 1)
  • systemd-user-runtime-dir (PID: 5502, Parent: 1, MD5: d55f4b0847f88131dbcfb07435178e54) Arguments: /lib/systemd/systemd-user-runtime-dir stop 1000
  • systemd New Fork (PID: 5510, Parent: 1)
  • gdm3 (PID: 5510, Parent: 1, MD5: 2492e2d8d34f9377e3e530a61a15674f) Arguments: /usr/sbin/gdm3
  • systemd New Fork (PID: 5554, Parent: 1)
  • gpu-manager (PID: 5554, Parent: 1, MD5: 8fae9dd5dd67e1f33d873089c2fd8761) Arguments: /usr/bin/gpu-manager --log /var/log/gpu-manager.log
    • sh (PID: 5555, Parent: 5554, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /etc/modprobe.d/*.conf"
      • sh New Fork (PID: 5556, Parent: 5555)
      • grep (PID: 5556, Parent: 5555, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep -G ^blacklist.*nvidia[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
    • sh (PID: 5557, Parent: 5554, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /lib/modprobe.d/*.conf"
      • sh New Fork (PID: 5558, Parent: 5557)
      • grep (PID: 5558, Parent: 5557, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep -G ^blacklist.*nvidia[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
    • sh (PID: 5559, Parent: 5554, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /etc/modprobe.d/*.conf"
      • sh New Fork (PID: 5560, Parent: 5559)
      • grep (PID: 5560, Parent: 5559, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep -G ^blacklist.*radeon[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
    • sh (PID: 5561, Parent: 5554, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /lib/modprobe.d/*.conf"
      • sh New Fork (PID: 5562, Parent: 5561)
      • grep (PID: 5562, Parent: 5561, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep -G ^blacklist.*radeon[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
    • sh (PID: 5563, Parent: 5554, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "grep -G \"^blacklist.*amdgpu[[:space:]]*$\" /etc/modprobe.d/*.conf"
      • sh New Fork (PID: 5564, Parent: 5563)
      • grep (PID: 5564, Parent: 5563, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep -G ^blacklist.*amdgpu[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
    • sh (PID: 5565, Parent: 5554, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "grep -G \"^blacklist.*amdgpu[[:space:]]*$\" /lib/modprobe.d/*.conf"
      • sh New Fork (PID: 5566, Parent: 5565)
      • grep (PID: 5566, Parent: 5565, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep -G ^blacklist.*amdgpu[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
    • sh (PID: 5568, Parent: 5554, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "grep -G \"^blacklist.*nouveau[[:space:]]*$\" /etc/modprobe.d/*.conf"
      • sh New Fork (PID: 5569, Parent: 5568)
      • grep (PID: 5569, Parent: 5568, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep -G ^blacklist.*nouveau[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
    • sh (PID: 5570, Parent: 5554, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "grep -G \"^blacklist.*nouveau[[:space:]]*$\" /lib/modprobe.d/*.conf"
      • sh New Fork (PID: 5571, Parent: 5570)
      • grep (PID: 5571, Parent: 5570, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep -G ^blacklist.*nouveau[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
  • systemd New Fork (PID: 5572, Parent: 1)
  • generate-config (PID: 5572, Parent: 1, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /usr/share/gdm/generate-config
    • pkill (PID: 5573, Parent: 5572, MD5: fa96a75a08109d8842e4865b2907d51f) Arguments: pkill --signal HUP --uid gdm dconf-service
  • systemd New Fork (PID: 5576, Parent: 1)
  • gdm-wait-for-drm (PID: 5576, Parent: 1, MD5: 82043ba752c6930b4e6aaea2f7747545) Arguments: /usr/lib/gdm3/gdm-wait-for-drm
  • systemd New Fork (PID: 5582, Parent: 1)
  • gdm3 (PID: 5582, Parent: 1, MD5: 2492e2d8d34f9377e3e530a61a15674f) Arguments: /usr/sbin/gdm3
  • cleanup

Yara Overview

Initial Sample

SourceRuleDescriptionAuthorStrings
seWzsbHlCCSUSP_ELF_LNX_UPX_Compressed_FileDetects a suspicious ELF binary with UPX compressionFlorian Roth
  • 0xb6c8:$s1: PROT_EXEC|PROT_WRITE failed.
  • 0xb737:$s2: $Id: UPX
  • 0xb6e8:$s3: $Info: This file is packed with the UPX executable packer

PCAP (Network Traffic)

SourceRuleDescriptionAuthorStrings
dump.pcapJoeSecurity_Mirai_12Yara detected MiraiJoe Security

    Jbx Signature Overview

    Click to jump to signature section

    Show All Signature Results
    Source: /usr/bin/pkill (PID: 5310)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
    Source: /usr/bin/pkill (PID: 5319)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
    Source: /usr/bin/pkill (PID: 5322)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
    Source: /usr/bin/pulseaudio (PID: 5446)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
    Source: /usr/bin/pkill (PID: 5489)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
    Source: /usr/bin/pkill (PID: 5573)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior

    Networking:

    barindex
    Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)Show sources
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 61.219.57.213:23 -> 192.168.2.23:53708
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 61.219.57.213:23 -> 192.168.2.23:53708
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 77.87.103.137:23 -> 192.168.2.23:47396
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 77.87.103.137:23 -> 192.168.2.23:47396
    Source: TrafficSnort IDS: 716 INFO TELNET access 194.143.250.195:23 -> 192.168.2.23:41828
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 61.219.57.213:23 -> 192.168.2.23:54054
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 61.219.57.213:23 -> 192.168.2.23:54054
    Source: TrafficSnort IDS: 716 INFO TELNET access 178.207.239.204:23 -> 192.168.2.23:45398
    Source: TrafficSnort IDS: 716 INFO TELNET access 178.207.239.204:23 -> 192.168.2.23:45468
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 76.169.48.96:23 -> 192.168.2.23:50794
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 76.169.48.96:23 -> 192.168.2.23:50794
    Source: TrafficSnort IDS: 716 INFO TELNET access 178.207.239.204:23 -> 192.168.2.23:45490
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 77.87.103.137:23 -> 192.168.2.23:47822
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 77.87.103.137:23 -> 192.168.2.23:47822
    Source: TrafficSnort IDS: 716 INFO TELNET access 178.207.239.204:23 -> 192.168.2.23:45522
    Source: TrafficSnort IDS: 716 INFO TELNET access 178.207.239.204:23 -> 192.168.2.23:45554
    Source: TrafficSnort IDS: 716 INFO TELNET access 178.207.239.204:23 -> 192.168.2.23:45580
    Source: TrafficSnort IDS: 716 INFO TELNET access 178.207.239.204:23 -> 192.168.2.23:45620
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 61.219.57.213:23 -> 192.168.2.23:54472
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 61.219.57.213:23 -> 192.168.2.23:54472
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 85.146.97.48:23 -> 192.168.2.23:46744
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 85.146.97.48:23 -> 192.168.2.23:46744
    Source: TrafficSnort IDS: 716 INFO TELNET access 178.207.239.204:23 -> 192.168.2.23:45676
    Source: TrafficSnort IDS: 716 INFO TELNET access 112.220.106.138:23 -> 192.168.2.23:41804
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 77.87.103.137:23 -> 192.168.2.23:48002
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 77.87.103.137:23 -> 192.168.2.23:48002
    Source: TrafficSnort IDS: 716 INFO TELNET access 178.207.239.204:23 -> 192.168.2.23:45724
    Source: TrafficSnort IDS: 716 INFO TELNET access 178.207.239.204:23 -> 192.168.2.23:45788
    Source: TrafficSnort IDS: 716 INFO TELNET access 178.207.239.204:23 -> 192.168.2.23:45882
    Source: TrafficSnort IDS: 716 INFO TELNET access 178.207.239.204:23 -> 192.168.2.23:45928
    Source: TrafficSnort IDS: 716 INFO TELNET access 178.207.239.204:23 -> 192.168.2.23:45994
    Source: TrafficSnort IDS: 716 INFO TELNET access 175.194.147.65:23 -> 192.168.2.23:43294
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 76.169.48.96:23 -> 192.168.2.23:51298
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 76.169.48.96:23 -> 192.168.2.23:51298
    Source: TrafficSnort IDS: 716 INFO TELNET access 178.207.239.204:23 -> 192.168.2.23:46030
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 61.219.57.213:23 -> 192.168.2.23:54838
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 61.219.57.213:23 -> 192.168.2.23:54838
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 77.87.103.137:23 -> 192.168.2.23:48334
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 77.87.103.137:23 -> 192.168.2.23:48334
    Source: TrafficSnort IDS: 716 INFO TELNET access 194.143.250.195:23 -> 192.168.2.23:42712
    Source: TrafficSnort IDS: 716 INFO TELNET access 178.207.239.204:23 -> 192.168.2.23:46070
    Source: TrafficSnort IDS: 716 INFO TELNET access 178.207.239.204:23 -> 192.168.2.23:46116
    Source: TrafficSnort IDS: 2027973 ET EXPLOIT HiSilicon DVR - Default Telnet Root Password Inbound 192.168.2.23:43186 -> 83.139.79.220:23
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 219.241.49.161:23 -> 192.168.2.23:47276
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 219.241.49.161:23 -> 192.168.2.23:47276
    Source: TrafficSnort IDS: 716 INFO TELNET access 178.207.239.204:23 -> 192.168.2.23:46168
    Source: TrafficSnort IDS: 716 INFO TELNET access 178.207.239.204:23 -> 192.168.2.23:46192
    Deletes all firewall rulesShow sources
    Source: /bin/sh (PID: 5304)Args: iptables -F
    Connects to many ports of the same IP (likely port scanning)Show sources
    Source: global trafficTCP traffic: 194.85.250.141 ports 45601,0,1,4,5,6
    Uses known network protocols on non-standard portsShow sources
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43188
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43194
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43206
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43214
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43222
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43236
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43246
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43254
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43264
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43272
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43282
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43290
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43296
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43304
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43314
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43318
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43322
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43326
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43334
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43342
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43352
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43370
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43390
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43408
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43422
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43438
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43452
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43462
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57916
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57924
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57932
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57948
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57964
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57976
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57998
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 58022
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 58042
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 58068
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 58092
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 58116
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 58136
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 58150
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 58164
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 58172
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 58180
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 58184
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 58192
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 58198
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 58210
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 58218
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 58222
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 58228
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 58234
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 58238
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 58242
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 58248
    Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
    Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
    Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
    Source: global trafficTCP traffic: 192.168.2.23:53396 -> 194.85.250.141:45601
    Source: /tmp/seWzsbHlCC (PID: 5278)Socket: 0.0.0.0::23
    Source: /usr/sbin/sshd (PID: 5408)Socket: 0.0.0.0::22
    Source: /usr/sbin/sshd (PID: 5408)Socket: [::]::22
    Source: /bin/sh (PID: 5336)Iptables executable: /sbin/iptables -> /sbin/iptables -F
    Source: /bin/sh (PID: 5337)Iptables executable: /sbin/iptables -> /sbin/iptables -X
    Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
    Source: unknownTCP traffic detected without corresponding DNS query: 185.174.86.135
    Source: unknownTCP traffic detected without corresponding DNS query: 147.145.201.135
    Source: unknownTCP traffic detected without corresponding DNS query: 101.172.161.173
    Source: unknownTCP traffic detected without corresponding DNS query: 165.249.86.132
    Source: unknownTCP traffic detected without corresponding DNS query: 157.68.78.60
    Source: unknownTCP traffic detected without corresponding DNS query: 85.105.184.86
    Source: unknownTCP traffic detected without corresponding DNS query: 77.124.17.46
    Source: unknownTCP traffic detected without corresponding DNS query: 206.204.80.87
    Source: unknownTCP traffic detected without corresponding DNS query: 216.148.132.203
    Source: unknownTCP traffic detected without corresponding DNS query: 207.140.150.1
    Source: unknownTCP traffic detected without corresponding DNS query: 109.215.13.121
    Source: unknownTCP traffic detected without corresponding DNS query: 95.23.32.192
    Source: unknownTCP traffic detected without corresponding DNS query: 144.148.82.187
    Source: unknownTCP traffic detected without corresponding DNS query: 41.147.213.38
    Source: unknownTCP traffic detected without corresponding DNS query: 17.179.94.217
    Source: unknownTCP traffic detected without corresponding DNS query: 48.121.4.250
    Source: unknownTCP traffic detected without corresponding DNS query: 170.171.137.68
    Source: unknownTCP traffic detected without corresponding DNS query: 122.35.156.9
    Source: unknownTCP traffic detected without corresponding DNS query: 123.183.200.233
    Source: unknownTCP traffic detected without corresponding DNS query: 90.131.136.159
    Source: unknownTCP traffic detected without corresponding DNS query: 140.154.149.1
    Source: unknownTCP traffic detected without corresponding DNS query: 35.75.90.209
    Source: unknownTCP traffic detected without corresponding DNS query: 206.177.180.146
    Source: unknownTCP traffic detected without corresponding DNS query: 113.184.204.137
    Source: unknownTCP traffic detected without corresponding DNS query: 34.121.250.0
    Source: unknownTCP traffic detected without corresponding DNS query: 65.22.59.61
    Source: unknownTCP traffic detected without corresponding DNS query: 111.196.65.29
    Source: unknownTCP traffic detected without corresponding DNS query: 114.93.66.26
    Source: unknownTCP traffic detected without corresponding DNS query: 66.4.96.250
    Source: unknownTCP traffic detected without corresponding DNS query: 120.142.202.163
    Source: unknownTCP traffic detected without corresponding DNS query: 44.196.192.32
    Source: unknownTCP traffic detected without corresponding DNS query: 1.45.214.176
    Source: unknownTCP traffic detected without corresponding DNS query: 88.123.62.136
    Source: unknownTCP traffic detected without corresponding DNS query: 123.12.14.8
    Source: unknownTCP traffic detected without corresponding DNS query: 60.173.87.20
    Source: unknownTCP traffic detected without corresponding DNS query: 148.216.197.233
    Source: unknownTCP traffic detected without corresponding DNS query: 62.26.241.157
    Source: unknownTCP traffic detected without corresponding DNS query: 180.19.155.94
    Source: unknownTCP traffic detected without corresponding DNS query: 185.140.46.7
    Source: unknownTCP traffic detected without corresponding DNS query: 152.64.186.78
    Source: unknownTCP traffic detected without corresponding DNS query: 67.187.89.149
    Source: unknownTCP traffic detected without corresponding DNS query: 141.115.0.49
    Source: unknownTCP traffic detected without corresponding DNS query: 9.137.234.67
    Source: unknownTCP traffic detected without corresponding DNS query: 156.47.130.141
    Source: unknownTCP traffic detected without corresponding DNS query: 165.146.155.109
    Source: unknownTCP traffic detected without corresponding DNS query: 218.132.15.181
    Source: unknownTCP traffic detected without corresponding DNS query: 119.7.98.20
    Source: unknownTCP traffic detected without corresponding DNS query: 163.148.235.64
    Source: unknownTCP traffic detected without corresponding DNS query: 169.231.176.193
    Source: unknownTCP traffic detected without corresponding DNS query: 209.108.255.11
    Source: seWzsbHlCCString found in binary or memory: http://upx.sf.net
    Source: unknownDNS traffic detected: queries for: daisy.ubuntu.com

    System Summary:

    barindex
    Sample tries to kill many processes (SIGKILL)Show sources
    Source: /tmp/seWzsbHlCC (PID: 5278)SIGKILL sent: pid: 658, result: successful
    Source: /tmp/seWzsbHlCC (PID: 5278)SIGKILL sent: pid: 720, result: successful
    Source: /tmp/seWzsbHlCC (PID: 5278)SIGKILL sent: pid: 759, result: successful
    Source: /tmp/seWzsbHlCC (PID: 5278)SIGKILL sent: pid: 772, result: successful
    Source: /tmp/seWzsbHlCC (PID: 5278)SIGKILL sent: pid: 789, result: successful
    Source: /tmp/seWzsbHlCC (PID: 5278)SIGKILL sent: pid: 800, result: successful
    Source: /tmp/seWzsbHlCC (PID: 5278)SIGKILL sent: pid: 904, result: successful
    Source: /tmp/seWzsbHlCC (PID: 5278)SIGKILL sent: pid: 936, result: successful
    Source: /tmp/seWzsbHlCC (PID: 5278)SIGKILL sent: pid: 1320, result: successful
    Source: /tmp/seWzsbHlCC (PID: 5278)SIGKILL sent: pid: 1334, result: successful
    Source: /tmp/seWzsbHlCC (PID: 5278)SIGKILL sent: pid: 1335, result: successful
    Source: /tmp/seWzsbHlCC (PID: 5278)SIGKILL sent: pid: 1389, result: successful
    Source: /tmp/seWzsbHlCC (PID: 5278)SIGKILL sent: pid: 1809, result: successful
    Source: /tmp/seWzsbHlCC (PID: 5278)SIGKILL sent: pid: 1872, result: successful
    Source: /tmp/seWzsbHlCC (PID: 5278)SIGKILL sent: pid: 1888, result: successful
    Source: /tmp/seWzsbHlCC (PID: 5278)SIGKILL sent: pid: 2048, result: successful
    Source: LOAD without section mappingsProgram segment: 0x8000
    Source: seWzsbHlCC, type: SAMPLEMatched rule: SUSP_ELF_LNX_UPX_Compressed_File date = 2018-12-12, author = Florian Roth, description = Detects a suspicious ELF binary with UPX compression, reference = Internal Research, score = 038ff8b2fef16f8ee9d70e6c219c5f380afe1a21761791e8cbda21fa4d09fdb4
    Source: /tmp/seWzsbHlCC (PID: 5278)SIGKILL sent: pid: 658, result: successful
    Source: /tmp/seWzsbHlCC (PID: 5278)SIGKILL sent: pid: 720, result: successful
    Source: /tmp/seWzsbHlCC (PID: 5278)SIGKILL sent: pid: 759, result: successful
    Source: /tmp/seWzsbHlCC (PID: 5278)SIGKILL sent: pid: 772, result: successful
    Source: /tmp/seWzsbHlCC (PID: 5278)SIGKILL sent: pid: 789, result: successful
    Source: /tmp/seWzsbHlCC (PID: 5278)SIGKILL sent: pid: 800, result: successful
    Source: /tmp/seWzsbHlCC (PID: 5278)SIGKILL sent: pid: 904, result: successful
    Source: /tmp/seWzsbHlCC (PID: 5278)SIGKILL sent: pid: 936, result: successful
    Source: /tmp/seWzsbHlCC (PID: 5278)SIGKILL sent: pid: 1320, result: successful
    Source: /tmp/seWzsbHlCC (PID: 5278)SIGKILL sent: pid: 1334, result: successful
    Source: /tmp/seWzsbHlCC (PID: 5278)SIGKILL sent: pid: 1335, result: successful
    Source: /tmp/seWzsbHlCC (PID: 5278)SIGKILL sent: pid: 1389, result: successful
    Source: /tmp/seWzsbHlCC (PID: 5278)SIGKILL sent: pid: 1809, result: successful
    Source: /tmp/seWzsbHlCC (PID: 5278)SIGKILL sent: pid: 1872, result: successful
    Source: /tmp/seWzsbHlCC (PID: 5278)SIGKILL sent: pid: 1888, result: successful
    Source: /tmp/seWzsbHlCC (PID: 5278)SIGKILL sent: pid: 2048, result: successful
    Source: classification engineClassification label: mal88.spre.troj.evad.lin@0/9@2/0

    Data Obfuscation:

    barindex
    Sample is packed with UPXShow sources
    Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
    Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
    Source: initial sampleString containing UPX found: $Id: UPX 3.94 Copyright (C) 1996-2017 the UPX Team. All Rights Reserved. $

    Persistence and Installation Behavior:

    barindex
    Deletes all firewall rulesShow sources
    Source: /bin/sh (PID: 5304)Args: iptables -F
    Sample reads /proc/mounts (often used for finding a writable filesystem)Show sources
    Source: /bin/fusermount (PID: 5494)File: /proc/5494/mountsJump to behavior
    Source: /bin/sh (PID: 5310)Pkill executable: /usr/bin/pkill -> pkill -9 busybox
    Source: /bin/sh (PID: 5319)Pkill executable: /usr/bin/pkill -> pkill -9 perl
    Source: /bin/sh (PID: 5322)Pkill executable: /usr/bin/pkill -> pkill -9 python
    Source: /usr/share/gdm/generate-config (PID: 5489)Pkill executable: /usr/bin/pkill -> pkill --signal HUP --uid gdm dconf-service
    Source: /usr/share/gdm/generate-config (PID: 5573)Pkill executable: /usr/bin/pkill -> pkill --signal HUP --uid gdm dconf-service
    Source: /bin/sh (PID: 5473)Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nvidia[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
    Source: /bin/sh (PID: 5475)Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nvidia[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
    Source: /bin/sh (PID: 5477)Grep executable: /usr/bin/grep -> grep -G ^blacklist.*radeon[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
    Source: /bin/sh (PID: 5479)Grep executable: /usr/bin/grep -> grep -G ^blacklist.*radeon[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
    Source: /bin/sh (PID: 5481)Grep executable: /usr/bin/grep -> grep -G ^blacklist.*amdgpu[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
    Source: /bin/sh (PID: 5483)Grep executable: /usr/bin/grep -> grep -G ^blacklist.*amdgpu[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
    Source: /bin/sh (PID: 5485)Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nouveau[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
    Source: /bin/sh (PID: 5487)Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nouveau[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
    Source: /bin/sh (PID: 5556)Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nvidia[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
    Source: /bin/sh (PID: 5558)Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nvidia[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
    Source: /bin/sh (PID: 5560)Grep executable: /usr/bin/grep -> grep -G ^blacklist.*radeon[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
    Source: /bin/sh (PID: 5562)Grep executable: /usr/bin/grep -> grep -G ^blacklist.*radeon[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
    Source: /bin/sh (PID: 5564)Grep executable: /usr/bin/grep -> grep -G ^blacklist.*amdgpu[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
    Source: /bin/sh (PID: 5566)Grep executable: /usr/bin/grep -> grep -G ^blacklist.*amdgpu[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
    Source: /bin/sh (PID: 5569)Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nouveau[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
    Source: /bin/sh (PID: 5571)Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nouveau[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/5382/status
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/5382/cmdline
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/3088/status
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/3088/cmdline
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/230/status
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/230/cmdline
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/110/status
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/110/cmdline
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/231/status
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/231/cmdline
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/111/status
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/111/cmdline
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/232/status
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/232/cmdline
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/112/status
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/112/cmdline
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/233/status
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/233/cmdline
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/1699/status
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/1699/cmdline
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/113/status
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/113/cmdline
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/234/status
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/234/cmdline
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/114/status
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/114/cmdline
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/235/status
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/235/cmdline
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/1334/status
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/1334/cmdline
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/115/status
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/115/cmdline
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/236/status
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/236/cmdline
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/116/status
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/116/cmdline
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/237/status
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/237/cmdline
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/117/status
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/117/cmdline
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/118/status
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/118/cmdline
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/910/status
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/910/cmdline
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/119/status
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/119/cmdline
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/912/status
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/912/cmdline
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/10/status
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/10/cmdline
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/11/status
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/11/cmdline
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/918/status
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/918/cmdline
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/12/status
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/12/cmdline
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/5152/status
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/5152/cmdline
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/13/status
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/13/cmdline
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/14/status
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/14/cmdline
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/15/status
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/15/cmdline
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/16/status
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/16/cmdline
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/17/status
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/17/cmdline
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/18/status
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/18/cmdline
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/120/status
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/120/cmdline
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/121/status
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/121/cmdline
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/1349/status
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/1349/cmdline
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/1/status
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/1/cmdline
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/122/status
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/122/cmdline
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/243/status
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/243/cmdline
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/123/status
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/123/cmdline
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/2/status
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/2/cmdline
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/124/status
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/124/cmdline
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/3/status
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/3/cmdline
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/4/status
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/4/cmdline
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/125/status
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/125/cmdline
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/126/status
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/126/cmdline
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/1344/status
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/1344/cmdline
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/127/status
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/127/cmdline
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/6/status
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/6/cmdline
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/248/status
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/248/cmdline
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/128/status
    Source: /usr/bin/pkill (PID: 5573)File opened: /proc/128/cmdline
    Source: /usr/bin/whoopsie (PID: 5382)Directory: /nonexistent/.cacheJump to behavior
    Source: /bin/sh (PID: 5336)Iptables executable: /sbin/iptables -> /sbin/iptables -F
    Source: /bin/sh (PID: 5337)Iptables executable: /sbin/iptables -> /sbin/iptables -X
    Source: /usr/bin/whoopsie (PID: 5382)File: /var/crash (bits: gv usr: rwx grp: rwx all: rwx)Jump to behavior
    Source: /usr/sbin/gdm3 (PID: 5510)File: /var/run/gdm3 (bits: - usr: -x grp: x all: rwx)Jump to behavior
    Source: /usr/sbin/gdm3 (PID: 5510)File: /var/log/gdm3 (bits: - usr: -x grp: x all: rwx)Jump to behavior
    Source: /usr/sbin/gdm3 (PID: 5582)File: /var/run/gdm3 (bits: - usr: -x grp: x all: rwx)Jump to behavior
    Source: /usr/sbin/gdm3 (PID: 5582)File: /var/log/gdm3 (bits: - usr: -x grp: x all: rwx)Jump to behavior
    Source: /tmp/seWzsbHlCC (PID: 5284)Shell command executed: sh -c "rm -rf /tmp/* /var/* /var/run/* /var/tmp/*"
    Source: /tmp/seWzsbHlCC (PID: 5293)Shell command executed: sh -c "rm -rf /var/log/wtmp"
    Source: /tmp/seWzsbHlCC (PID: 5296)Shell command executed: sh -c "rm -rf /tmp/*"
    Source: /tmp/seWzsbHlCC (PID: 5299)Shell command executed: sh -c "rm -rf /bin/netstat"
    Source: /tmp/seWzsbHlCC (PID: 5302)Shell command executed: sh -c "iptables -F"
    Source: /tmp/seWzsbHlCC (PID: 5308)Shell command executed: sh -c "pkill -9 busybox"
    Source: /tmp/seWzsbHlCC (PID: 5317)Shell command executed: sh -c "pkill -9 perl"
    Source: /tmp/seWzsbHlCC (PID: 5320)Shell command executed: sh -c "pkill -9 python"
    Source: /tmp/seWzsbHlCC (PID: 5325)Shell command executed: sh -c "service iptables stop"
    Source: /tmp/seWzsbHlCC (PID: 5334)Shell command executed: sh -c "/sbin/iptables -F; /sbin/iptables -X"
    Source: /tmp/seWzsbHlCC (PID: 5338)Shell command executed: sh -c "service firewalld stop"
    Source: /tmp/seWzsbHlCC (PID: 5349)Shell command executed: sh -c "rm -rf ~/.bash_history"
    Source: /tmp/seWzsbHlCC (PID: 5352)Shell command executed: sh -c "history -c"
    Source: /usr/bin/gpu-manager (PID: 5472)Shell command executed: sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /etc/modprobe.d/*.conf"
    Source: /usr/bin/gpu-manager (PID: 5474)Shell command executed: sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /lib/modprobe.d/*.conf"
    Source: /usr/bin/gpu-manager (PID: 5476)Shell command executed: sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /etc/modprobe.d/*.conf"
    Source: /usr/bin/gpu-manager (PID: 5478)Shell command executed: sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /lib/modprobe.d/*.conf"
    Source: /usr/bin/gpu-manager (PID: 5480)Shell command executed: sh -c "grep -G \"^blacklist.*amdgpu[[:space:]]*$\" /etc/modprobe.d/*.conf"
    Source: /usr/bin/gpu-manager (PID: 5482)Shell command executed: sh -c "grep -G \"^blacklist.*amdgpu[[:space:]]*$\" /lib/modprobe.d/*.conf"
    Source: /usr/bin/gpu-manager (PID: 5484)Shell command executed: sh -c "grep -G \"^blacklist.*nouveau[[:space:]]*$\" /etc/modprobe.d/*.conf"
    Source: /usr/bin/gpu-manager (PID: 5486)Shell command executed: sh -c "grep -G \"^blacklist.*nouveau[[:space:]]*$\" /lib/modprobe.d/*.conf"
    Source: /usr/bin/gpu-manager (PID: 5555)Shell command executed: sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /etc/modprobe.d/*.conf"
    Source: /usr/bin/gpu-manager (PID: 5557)Shell command executed: sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /lib/modprobe.d/*.conf"
    Source: /usr/bin/gpu-manager (PID: 5559)Shell command executed: sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /etc/modprobe.d/*.conf"
    Source: /usr/bin/gpu-manager (PID: 5561)Shell command executed: sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /lib/modprobe.d/*.conf"
    Source: /usr/bin/gpu-manager (PID: 5563)Shell command executed: sh -c "grep -G \"^blacklist.*amdgpu[[:space:]]*$\" /etc/modprobe.d/*.conf"
    Source: /usr/bin/gpu-manager (PID: 5565)Shell command executed: sh -c "grep -G \"^blacklist.*amdgpu[[:space:]]*$\" /lib/modprobe.d/*.conf"
    Source: /usr/bin/gpu-manager (PID: 5568)Shell command executed: sh -c "grep -G \"^blacklist.*nouveau[[:space:]]*$\" /etc/modprobe.d/*.conf"
    Source: /usr/bin/gpu-manager (PID: 5570)Shell command executed: sh -c "grep -G \"^blacklist.*nouveau[[:space:]]*$\" /lib/modprobe.d/*.conf"
    Source: /bin/sh (PID: 5286)Rm executable: /usr/bin/rm -> rm -rf /tmp/config-err-dHT8bZ /tmp/dmesgtail.log /tmp/seWzsbHlCC /tmp/snap.lxd /tmp/ssh-hOQ5FjG2iVgO /tmp/systemd-private-ec795e01d534441298b2bf519e4c51fc-ModemManager.service-c4RYFi /tmp/systemd-private-ec795e01d534441298b2bf519e4c51fc-colord.service-gKIF8e /tmp/systemd-private-ec795e01d534441298b2bf519e4c51fc-fwupd.service-gB0a9f /tmp/systemd-private-ec795e01d534441298b2bf519e4c51fc-switcheroo-control.service-APWnLg /tmp/systemd-private-ec795e01d534441298b2bf519e4c51fc-systemd-logind.service-IofUpj /tmp/systemd-private-ec795e01d534441298b2bf519e4c51fc-systemd-resolved.service-AfPZzg /tmp/systemd-private-ec795e01d534441298b2bf519e4c51fc-upower.service-x0xO0i /tmp/vmware-root_721-4290559889 /var/backups /var/cache /var/crash /var/lib /var/local /var/lock /var/log /var/mail /var/metrics /var/opt /var/run /var/snap /var/spool /var/tmp /var/run/NetworkManager /var/run/acpid.pid /var/run/acpid.socket /var/run/apport.lock /var/run/avahi-daemon /var/run/blkid /var/run/cloud-init /var/run/console-setup /var/run/crond.pid /var/run/crond.reboot /var/run/cryptsetup /var/run/cups /var/run/dbus /var/run/dmeventd-client /var/run/dmeventd-server /var/run/gdm3 /var/run/gdm3.pid /var/run/initctl /var/run/initramfs /var/run/irqbalance /var/run/lock /var/run/log /var/run/lvm /var/run/mlocate.daily.lock /var/run/mono-xsp4 /var/run/mono-xsp4.pid /var/run/motd.d /var/run/mount /var/run/multipathd.pid /var/run/netns /var/run/network /var/run/screen /var/run/sendsigs.omit.d /var/run/shm /var/run/snapd /var/run/snapd-snap.socket /var/run/snapd.socket /var/run/speech-dispatcher /var/run/spice-vdagentd /var/run/sshd /var/run/sshd.pid /var/run/sudo /var/run/systemd /var/run/tmpfiles.d /var/run/udev /var/run/udisks2 /var/run/unattended-upgrades.lock /var/run/user /var/run/utmp /var/run/uuidd /var/run/vmware /var/tmp/systemd-private-ec795e01d534441298b2bf519e4c51fc-ModemManager.service-J6Q1Te /var/tmp/systemd-private-ec795e01d534441298b2bf519e4c51fc-colord.service-srP90f /var/tmp/systemd-private-ec795e01d534441298b2bf519e4c51fc-fwupd.service-biJ0Gi /var/tmp/systemd-private-ec795e01d534441298b2bf519e4c51fc-switcheroo-control.service-1jIxdj /var/tmp/systemd-private-ec795e01d534441298b2bf519e4c51fc-systemd-logind.service-llmWag /var/tmp/systemd-private-ec795e01d534441298b2bf519e4c51fc-systemd-resolved.service-X16eHh /var/tmp/systemd-private-ec795e01d534441298b2bf519e4c51fc-upower.service-GpSnaf
    Source: /bin/sh (PID: 5295)Rm executable: /usr/bin/rm -> rm -rf /var/log/wtmp
    Source: /bin/sh (PID: 5298)Rm executable: /usr/bin/rm -> rm -rf /tmp/*
    Source: /bin/sh (PID: 5301)Rm executable: /usr/bin/rm -> rm -rf /bin/netstat
    Source: /bin/sh (PID: 5351)Rm executable: /usr/bin/rm -> rm -rf /root/.bash_history
    Source: /usr/bin/gpu-manager (PID: 5554)Log file created: /var/log/gpu-manager.logJump to dropped file
    Source: /usr/sbin/service (PID: 5333)Sed executable: /usr/bin/sed -> sed -ne s/\\.socket\\s*[a-z]*\\s*$/.socket/p
    Source: /usr/sbin/service (PID: 5346)Sed executable: /usr/bin/sed -> sed -ne s/\\.socket\\s*[a-z]*\\s*$/.socket/p

    Hooking and other Techniques for Hiding and Protection:

    barindex
    Sample deletes itselfShow sources
    Source: /usr/bin/rm (PID: 5286)File: /tmp/seWzsbHlCCJump to behavior
    Uses known network protocols on non-standard portsShow sources
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43188
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43194
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43206
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43214
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43222
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43236
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43246
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43254
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43264
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43272
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43282
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43290
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43296
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43304
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43314
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43318
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43322
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43326
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43334
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43342
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43352
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43370
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43390
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43408
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43422
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43438
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43452
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43462
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57916
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57924
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57932
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57948
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57964
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57976
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57998
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 58022
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 58042
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 58068
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 58092
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 58116
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 58136
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 58150
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 58164
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 58172
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 58180
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 58184
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 58192
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 58198
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 58210
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 58218
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 58222
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 58228
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 58234
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 58238
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 58242
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 58248

    Malware Analysis System Evasion:

    barindex
    Deletes security-related log filesShow sources
    Source: /usr/bin/rm (PID: 5295)Truncated file: /var/log/wtmpJump to behavior
    Source: /usr/bin/pkill (PID: 5310)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
    Source: /usr/bin/pkill (PID: 5319)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
    Source: /usr/bin/pkill (PID: 5322)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
    Source: /usr/bin/pulseaudio (PID: 5446)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
    Source: /usr/bin/pkill (PID: 5489)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
    Source: /usr/bin/pkill (PID: 5573)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
    Source: /tmp/seWzsbHlCC (PID: 5271)Queries kernel information via 'uname':
    Source: /usr/bin/whoopsie (PID: 5382)Queries kernel information via 'uname':
    Source: /usr/bin/pulseaudio (PID: 5446)Queries kernel information via 'uname':
    Source: /usr/bin/gpu-manager (PID: 5471)Queries kernel information via 'uname':
    Source: /usr/bin/gpu-manager (PID: 5554)Queries kernel information via 'uname':
    Source: /usr/bin/rm (PID: 5295)Truncated file: /var/log/wtmpJump to behavior
    Source: /usr/bin/gpu-manager (PID: 5471)Truncated file: /var/log/gpu-manager.log
    Source: /usr/bin/gpu-manager (PID: 5554)Truncated file: /var/log/gpu-manager.log
    Source: seWzsbHlCC, 5271.1.00000000360bfc1e.00000000b0787897.rw-.sdmp, seWzsbHlCC, 5273.1.00000000360bfc1e.00000000b0787897.rw-.sdmp, seWzsbHlCC, 5275.1.00000000360bfc1e.00000000b0787897.rw-.sdmp, seWzsbHlCC, 5278.1.00000000360bfc1e.00000000b0787897.rw-.sdmp, seWzsbHlCC, 5280.1.00000000360bfc1e.00000000b0787897.rw-.sdmp, seWzsbHlCC, 5282.1.00000000360bfc1e.00000000b0787897.rw-.sdmpBinary or memory string: Vx86_64/usr/bin/qemu-arm/tmp/seWzsbHlCCSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/seWzsbHlCC
    Source: seWzsbHlCC, 5271.1.000000006c8a81d0.000000004040623b.rw-.sdmp, seWzsbHlCC, 5273.1.000000006c8a81d0.000000004040623b.rw-.sdmp, seWzsbHlCC, 5275.1.000000006c8a81d0.000000004040623b.rw-.sdmp, seWzsbHlCC, 5278.1.000000006c8a81d0.000000004040623b.rw-.sdmp, seWzsbHlCC, 5280.1.000000006c8a81d0.000000004040623b.rw-.sdmp, seWzsbHlCC, 5282.1.000000006c8a81d0.000000004040623b.rw-.sdmpBinary or memory string: U!/etc/qemu-binfmt/arm
    Source: seWzsbHlCC, 5278.1.000000004040623b.00000000812fe279.rw-.sdmpBinary or memory string: /usr/bin/vmtoolsd
    Source: seWzsbHlCC, 5278.1.000000004040623b.00000000812fe279.rw-.sdmpBinary or memory string: !/proc/1586/exe0!/usr/bin/vmtoolsd1P
    Source: seWzsbHlCC, 5271.1.000000006c8a81d0.000000004040623b.rw-.sdmp, seWzsbHlCC, 5273.1.000000006c8a81d0.000000004040623b.rw-.sdmp, seWzsbHlCC, 5275.1.000000006c8a81d0.000000004040623b.rw-.sdmp, seWzsbHlCC, 5278.1.000000006c8a81d0.000000004040623b.rw-.sdmp, seWzsbHlCC, 5280.1.000000006c8a81d0.000000004040623b.rw-.sdmp, seWzsbHlCC, 5282.1.000000006c8a81d0.000000004040623b.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/arm
    Source: seWzsbHlCC, 5271.1.00000000360bfc1e.00000000b0787897.rw-.sdmp, seWzsbHlCC, 5273.1.00000000360bfc1e.00000000b0787897.rw-.sdmp, seWzsbHlCC, 5275.1.00000000360bfc1e.00000000b0787897.rw-.sdmp, seWzsbHlCC, 5278.1.00000000360bfc1e.00000000b0787897.rw-.sdmp, seWzsbHlCC, 5280.1.00000000360bfc1e.00000000b0787897.rw-.sdmp, seWzsbHlCC, 5282.1.00000000360bfc1e.00000000b0787897.rw-.sdmpBinary or memory string: /usr/bin/qemu-arm

    Stealing of Sensitive Information:

    barindex
    Yara detected MiraiShow sources
    Source: Yara matchFile source: dump.pcap, type: PCAP

    Remote Access Functionality:

    barindex
    Yara detected MiraiShow sources
    Source: Yara matchFile source: dump.pcap, type: PCAP

    Mitre Att&ck Matrix

    Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
    Valid AccountsCommand and Scripting Interpreter1Path InterceptionPath InterceptionFile and Directory Permissions Modification1OS Credential Dumping1Security Software Discovery11Remote ServicesData from Local SystemExfiltration Over Other Network MediumEncrypted Channel1Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
    Default AccountsScripting1Boot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsDisable or Modify Tools1LSASS MemorySystem Network Configuration Discovery1Remote Desktop ProtocolData from Removable MediaExfiltration Over BluetoothNon-Standard Port11Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
    Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Scripting1Security Account ManagerFile and Directory Discovery1SMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationNon-Application Layer Protocol1Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
    Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Hidden Files and Directories1NTDSSystem Information Discovery1Distributed Component Object ModelInput CaptureScheduled TransferApplication Layer Protocol2SIM Card SwapCarrier Billing Fraud
    Cloud AccountsCronNetwork Logon ScriptNetwork Logon ScriptObfuscated Files or Information1LSA SecretsRemote System DiscoverySSHKeyloggingData Transfer Size LimitsFallback ChannelsManipulate Device CommunicationManipulate App Store Rankings or Ratings
    Replication Through Removable MediaLaunchdRc.commonRc.commonDisable or Modify System Firewall1Cached Domain CredentialsSystem Owner/User DiscoveryVNCGUI Input CaptureExfiltration Over C2 ChannelMultiband CommunicationJamming or Denial of ServiceAbuse Accessibility Features
    External Remote ServicesScheduled TaskStartup ItemsStartup ItemsIndicator Removal on Host11DCSyncNetwork SniffingWindows Remote ManagementWeb Portal CaptureExfiltration Over Alternative ProtocolCommonly Used PortRogue Wi-Fi Access PointsData Encrypted for Impact
    Drive-by CompromiseCommand and Scripting InterpreterScheduled Task/JobScheduled Task/JobFile Deletion11Proc FilesystemNetwork Service ScanningShared WebrootCredential API HookingExfiltration Over Symmetric Encrypted Non-C2 ProtocolApplication Layer ProtocolDowngrade to Insecure ProtocolsGenerate Fraudulent Advertising Revenue

    Malware Configuration

    No configs have been found

    Behavior Graph

    Hide Legend

    Legend:

    • Process
    • Signature
    • Created File
    • DNS/IP Info
    • Is Dropped
    • Number of created Files
    • Is malicious
    • Internet
    behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 528748 Sample: seWzsbHlCC Startdate: 25/11/2021 Architecture: LINUX Score: 88 108 98.19.126.248 WINDSTREAMUS United States 2->108 110 200.83.48.33, 23 VTRBANDAANCHASACL Chile 2->110 112 99 other IPs or domains 2->112 114 Snort IDS alert for network traffic (e.g. based on Emerging Threat rules) 2->114 116 Yara detected Mirai 2->116 118 Connects to many ports of the same IP (likely port scanning) 2->118 120 2 other signatures 2->120 13 seWzsbHlCC 2->13         started        15 systemd gpu-manager 2->15         started        17 systemd gpu-manager 2->17         started        19 15 other processes 2->19 signatures3 process4 signatures5 22 seWzsbHlCC 13->22         started        24 seWzsbHlCC 13->24         started        26 gpu-manager sh 15->26         started        28 gpu-manager sh 15->28         started        30 gpu-manager sh 15->30         started        34 5 other processes 15->34 32 gpu-manager sh 17->32         started        36 7 other processes 17->36 122 Sample reads /proc/mounts (often used for finding a writable filesystem) 19->122 38 2 other processes 19->38 process6 process7 40 seWzsbHlCC 22->40         started        42 seWzsbHlCC 22->42         started        45 sh grep 26->45         started        47 sh grep 28->47         started        49 sh grep 30->49         started        51 sh grep 32->51         started        53 sh grep 34->53         started        55 4 other processes 34->55 57 7 other processes 36->57 signatures8 59 seWzsbHlCC 40->59         started        130 Sample tries to kill many processes (SIGKILL) 42->130 process9 process10 61 seWzsbHlCC sh 59->61         started        63 seWzsbHlCC sh 59->63         started        65 seWzsbHlCC sh 59->65         started        67 10 other processes 59->67 process11 69 sh rm 61->69         started        72 sh rm 63->72         started        74 sh iptables 65->74         started        76 sh service systemctl 67->76         started        78 sh service systemctl 67->78         started        80 sh rm 67->80         started        82 7 other processes 67->82 signatures12 124 Sample deletes itself 69->124 126 Deletes security-related log files 72->126 128 Deletes all firewall rules 74->128 84 service 76->84         started        86 service basename 76->86         started        88 service basename 76->88         started        90 service systemctl 76->90         started        92 service 78->92         started        94 service basename 78->94         started        96 service basename 78->96         started        98 service systemctl 78->98         started        process13 process14 100 service systemctl 84->100         started        102 service sed 84->102         started        104 service systemctl 92->104         started        106 service sed 92->106         started       

    Antivirus, Machine Learning and Genetic Malware Detection

    Initial Sample

    No Antivirus matches

    Dropped Files

    No Antivirus matches

    Domains

    No Antivirus matches

    URLs

    No Antivirus matches

    Domains and IPs

    Contacted Domains

    NameIPActiveMaliciousAntivirus DetectionReputation
    daisy.ubuntu.com
    162.213.33.132
    truefalse
      high

      URLs from Memory and Binaries

      NameSourceMaliciousAntivirus DetectionReputation
      http://upx.sf.netseWzsbHlCCfalse
        high

        Contacted IPs

        • No. of IPs < 25%
        • 25% < No. of IPs < 50%
        • 50% < No. of IPs < 75%
        • 75% < No. of IPs

        Public

        IPDomainCountryFlagASNASN NameMalicious
        125.42.146.103
        unknownChina
        4837CHINA169-BACKBONECHINAUNICOMChina169BackboneCNfalse
        70.181.35.187
        unknownUnited States
        22773ASN-CXA-ALL-CCI-22773-RDCUSfalse
        207.202.194.215
        unknownUnited States
        2044IINET-2044USfalse
        78.161.56.209
        unknownTurkey
        9121TTNETTRfalse
        1.183.129.29
        unknownChina
        4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
        154.157.137.159
        unknownKenya
        36926CKL1-ASNKEfalse
        129.140.169.249
        unknownMalawi
        37440Airtel-MWfalse
        63.198.166.79
        unknownUnited States
        7018ATT-INTERNET4USfalse
        181.213.135.162
        unknownBrazil
        28573CLAROSABRfalse
        190.73.147.200
        unknownVenezuela
        8048CANTVServiciosVenezuelaVEfalse
        2.93.45.7
        unknownRussian Federation
        8402CORBINA-ASOJSCVimpelcomRUfalse
        188.74.238.42
        unknownRomania
        60741MIZA-ASROfalse
        37.248.66.119
        unknownPoland
        8374PLUSNETPlusnetworkoperatorinPolandPLfalse
        151.93.49.118
        unknownItaly
        1267ASN-WINDTREIUNETEUfalse
        8.28.61.5
        unknownUnited States
        64279TFSLAOCUSfalse
        200.83.48.33
        unknownChile
        22047VTRBANDAANCHASACLfalse
        155.254.17.225
        unknownUnited States
        397423TIER-NETUSfalse
        19.187.8.243
        unknownUnited States
        3MIT-GATEWAYSUSfalse
        150.217.104.194
        unknownItaly
        137ASGARRConsortiumGARREUfalse
        122.105.197.216
        unknownAustralia
        4804MPX-ASMicroplexPTYLTDAUfalse
        179.254.251.220
        unknownBrazil
        8167BrasilTelecomSA-FilialDistritoFederalBRfalse
        98.19.126.248
        unknownUnited States
        7029WINDSTREAMUSfalse
        93.87.57.223
        unknownSerbia
        8400TELEKOM-ASRSfalse
        99.177.214.190
        unknownUnited States
        7018ATT-INTERNET4USfalse
        165.139.128.251
        unknownUnited States
        11686ENAUSfalse
        47.207.214.207
        unknownUnited States
        5650FRONTIER-FRTRUSfalse
        169.97.116.2
        unknownUnited States
        37611AfrihostZAfalse
        184.242.62.164
        unknownUnited States
        10507SPCSUSfalse
        115.165.146.158
        unknownJapan9365ITSCOMitscommunicationsIncJPfalse
        182.134.184.52
        unknownChina
        4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
        86.73.60.242
        unknownFrance
        15557LDCOMNETFRfalse
        47.166.238.203
        unknownUnited States
        5650FRONTIER-FRTRUSfalse
        216.81.216.18
        unknownUnited States
        11320LIGHTEDGE-AS-02USfalse
        110.132.116.231
        unknownJapan9824JTCL-JP-ASJupiterTelecommunicationCoLtdJPfalse
        5.127.54.104
        unknownIran (ISLAMIC Republic Of)
        44244IRANCELL-ASIRfalse
        18.45.73.155
        unknownUnited States
        3MIT-GATEWAYSUSfalse
        112.54.85.168
        unknownChina
        24444CMNET-V4SHANDONG-AS-APShandongMobileCommunicationCompanyfalse
        174.207.243.210
        unknownUnited States
        22394CELLCOUSfalse
        207.48.168.24
        unknownUnited States
        3561CENTURYLINK-LEGACY-SAVVISUSfalse
        1.141.94.214
        unknownAustralia
        1221ASN-TELSTRATelstraCorporationLtdAUfalse
        206.89.242.95
        unknownUnited States
        3549LVLT-3549USfalse
        74.221.73.184
        unknownUnited States
        29979PWN-ASBLKUSfalse
        38.83.60.43
        unknownUnited States
        174COGENT-174USfalse
        46.161.206.75
        unknownSyrian Arab Republic
        29256INT-PDN-STE-ASSTEPDNInternalASSYfalse
        171.84.126.231
        unknownChina
        4808CHINA169-BJChinaUnicomBeijingProvinceNetworkCNfalse
        112.140.228.143
        unknownKorea Republic of
        18318SPEEDON-AS-KRLGHelloVisionCorpKRfalse
        166.59.141.111
        unknownUnited States
        3377MCI-ASNUSfalse
        20.220.220.250
        unknownUnited States
        8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
        177.201.217.219
        unknownBrazil
        8167BrasilTelecomSA-FilialDistritoFederalBRfalse
        42.134.246.139
        unknownChina
        4249LILLY-ASUSfalse
        43.11.77.239
        unknownJapan4249LILLY-ASUSfalse
        93.254.32.66
        unknownGermany
        3320DTAGInternetserviceprovideroperationsDEfalse
        35.59.121.11
        unknownUnited States
        36375UMICH-AS-5USfalse
        39.223.215.28
        unknownIndonesia
        23693TELKOMSEL-ASN-IDPTTelekomunikasiSelularIDfalse
        65.92.251.70
        unknownCanada
        577BACOMCAfalse
        63.182.214.13
        unknownUnited States
        1239SPRINTLINKUSfalse
        135.174.27.61
        unknownUnited States
        14962NCR-252USfalse
        124.57.70.69
        unknownKorea Republic of
        17858POWERVIS-AS-KRLGPOWERCOMMKRfalse
        122.32.33.208
        unknownKorea Republic of
        17858POWERVIS-AS-KRLGPOWERCOMMKRfalse
        44.44.171.245
        unknownUnited States
        7377UCSDUSfalse
        197.222.122.203
        unknownEgypt
        37069MOBINILEGfalse
        205.173.0.246
        unknownUnited States
        21633DOI-NBC-NETUSfalse
        202.41.22.160
        unknownIndia
        10225NETTLINX-IN-APNettlinxLimitedINfalse
        163.112.152.93
        unknownFrance
        17816CHINA169-GZChinaUnicomIPnetworkChina169Guangdongprovifalse
        19.52.128.103
        unknownUnited States
        3MIT-GATEWAYSUSfalse
        57.157.134.55
        unknownBelgium
        2686ATGS-MMD-ASUSfalse
        210.74.100.133
        unknownChina
        4808CHINA169-BJChinaUnicomBeijingProvinceNetworkCNfalse
        223.216.178.39
        unknownJapan4713OCNNTTCommunicationsCorporationJPfalse
        174.127.145.127
        unknownUnited States
        11404AS-WAVE-1USfalse
        203.14.250.15
        unknownAustralia
        9328DATACOM-AUDATACOMSYSTEMSAUPTYLTDAUfalse
        39.85.149.204
        unknownChina
        4837CHINA169-BACKBONECHINAUNICOMChina169BackboneCNfalse
        220.221.217.83
        unknownJapan4713OCNNTTCommunicationsCorporationJPfalse
        32.135.39.52
        unknownUnited States
        2686ATGS-MMD-ASUSfalse
        210.115.6.130
        unknownKorea Republic of
        4766KIXS-AS-KRKoreaTelecomKRfalse
        144.187.229.91
        unknownUnited States
        22562CSC-IGN-EMEAUSfalse
        72.46.16.140
        unknownUnited States
        62833HUDSONFIBERNETUSfalse
        208.236.99.194
        unknownUnited States
        4208THE-ISERV-COMPANYUSfalse
        96.94.23.175
        unknownUnited States
        7922COMCAST-7922USfalse
        40.62.7.72
        unknownUnited States
        4249LILLY-ASUSfalse
        117.157.129.101
        unknownChina
        9808CMNET-GDGuangdongMobileCommunicationCoLtdCNfalse
        58.51.227.57
        unknownChina
        4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
        176.83.195.186
        unknownSpain
        3352TELEFONICA_DE_ESPANAESfalse
        131.2.49.7
        unknownUnited States
        61458GOBIERNOAUTONOMOMUNICIPALDELAPAZBOfalse
        20.130.139.144
        unknownUnited States
        8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
        104.15.73.68
        unknownUnited States
        7018ATT-INTERNET4USfalse
        47.53.48.241
        unknownUnited States
        30722VODAFONE-IT-ASNITfalse
        125.32.16.88
        unknownChina
        4837CHINA169-BACKBONECHINAUNICOMChina169BackboneCNfalse
        134.197.162.8
        unknownUnited States
        3851NSHE-NEVADANETUSfalse
        146.181.229.218
        unknownUnited States
        786JANETJiscServicesLimitedGBfalse
        78.253.216.102
        unknownFrance
        12322PROXADFRfalse
        178.141.254.107
        unknownRussian Federation
        44677MTS-KRV-ASRUfalse
        108.7.134.33
        unknownUnited States
        701UUNETUSfalse
        143.183.65.250
        unknownUnited States
        4983INTEL-SC-ASUSfalse
        4.209.69.186
        unknownUnited States
        3356LEVEL3USfalse
        187.129.233.71
        unknownMexico
        28283AdylnetTelecomBRfalse
        160.120.31.151
        unknownCote D'ivoire
        29571ORANGE-COTE-IVOIRECIfalse
        216.227.170.102
        unknownUnited States
        174COGENT-174USfalse
        153.47.23.88
        unknownUnited States
        19512LYONDELLUSfalse
        205.153.15.235
        unknownUnited States
        209CENTURYLINK-US-LEGACY-QWESTUSfalse
        34.99.239.143
        unknownUnited States
        15169GOOGLEUSfalse

        Joe Sandbox View / Context

        IPs

        MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
        151.93.49.118e4phNkmjAJGet hashmaliciousBrowse

          Domains

          MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
          daisy.ubuntu.comarm7-20211121-1750Get hashmaliciousBrowse
          • 162.213.33.132
          x86-20211121-1750Get hashmaliciousBrowse
          • 162.213.33.132
          arm-20211121-1750Get hashmaliciousBrowse
          • 162.213.33.108
          t99LTv3hiBGet hashmaliciousBrowse
          • 162.213.33.108
          wPLf38GLbnGet hashmaliciousBrowse
          • 162.213.33.132
          E4lCZiGLyrGet hashmaliciousBrowse
          • 162.213.33.108
          fYRxyPYc8jGet hashmaliciousBrowse
          • 162.213.33.132
          mLh9jwpikqGet hashmaliciousBrowse
          • 162.213.33.132
          XLKPMXNVFzGet hashmaliciousBrowse
          • 162.213.33.108
          mpslGet hashmaliciousBrowse
          • 162.213.33.108
          x86Get hashmaliciousBrowse
          • 162.213.33.108
          mipsGet hashmaliciousBrowse
          • 162.213.33.132
          arm7Get hashmaliciousBrowse
          • 162.213.33.108
          armGet hashmaliciousBrowse
          • 162.213.33.108
          HFRMJ1PUdKGet hashmaliciousBrowse
          • 162.213.33.108
          LPywXJs5ANGet hashmaliciousBrowse
          • 162.213.33.132
          Jyw7E6XVyVGet hashmaliciousBrowse
          • 162.213.33.132
          YSq7Yxaw94Get hashmaliciousBrowse
          • 162.213.33.132
          IJ1I2bAXnSGet hashmaliciousBrowse
          • 162.213.33.132
          gEozNq7ILxGet hashmaliciousBrowse
          • 162.213.33.132

          ASN

          MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
          CHINA169-BACKBONECHINAUNICOMChina169BackboneCNarm7Get hashmaliciousBrowse
          • 1.191.108.186
          armGet hashmaliciousBrowse
          • 121.28.150.58
          TDJjjFDkG4Get hashmaliciousBrowse
          • 113.230.107.33
          or4ypx7EryGet hashmaliciousBrowse
          • 101.68.23.10
          aljU2bjDwOGet hashmaliciousBrowse
          • 119.180.233.246
          KEn71AQ430Get hashmaliciousBrowse
          • 101.19.160.131
          pwY5ozOzpYGet hashmaliciousBrowse
          • 112.132.41.170
          Ljm7n1QDZeGet hashmaliciousBrowse
          • 125.44.36.116
          Jx35I5pwgdGet hashmaliciousBrowse
          • 61.161.163.133
          HXSFwEhM8mGet hashmaliciousBrowse
          • 120.15.222.152
          meerkat.arm7Get hashmaliciousBrowse
          • 125.211.65.53
          meerkat.x86Get hashmaliciousBrowse
          • 39.82.208.155
          oQANZnrt9dGet hashmaliciousBrowse
          • 124.163.221.209
          KWDww9OWghGet hashmaliciousBrowse
          • 125.39.128.140
          y8CYO3E0MFGet hashmaliciousBrowse
          • 220.192.165.211
          Akiru.arm7Get hashmaliciousBrowse
          • 121.30.41.210
          Akiru.armGet hashmaliciousBrowse
          • 116.133.14.218
          HLiQSIwlY7Get hashmaliciousBrowse
          • 153.7.216.250
          aZsszSGIEVGet hashmaliciousBrowse
          • 123.232.160.20
          TwikaSb2s6Get hashmaliciousBrowse
          • 115.52.253.248
          ASN-CXA-ALL-CCI-22773-RDCUSl8np4x8FGLGet hashmaliciousBrowse
          • 184.186.97.253
          aljU2bjDwOGet hashmaliciousBrowse
          • 184.181.236.223
          KEn71AQ430Get hashmaliciousBrowse
          • 184.185.142.96
          pwY5ozOzpYGet hashmaliciousBrowse
          • 98.175.159.215
          Ljm7n1QDZeGet hashmaliciousBrowse
          • 174.65.31.255
          Jx35I5pwgdGet hashmaliciousBrowse
          • 174.76.96.7
          meerkat.arm7Get hashmaliciousBrowse
          • 164.168.234.168
          KWDww9OWghGet hashmaliciousBrowse
          • 70.181.35.199
          aZsszSGIEVGet hashmaliciousBrowse
          • 98.184.102.0
          sora.x86Get hashmaliciousBrowse
          • 68.8.171.134
          NQsLN1nOONGet hashmaliciousBrowse
          • 98.187.110.186
          B67M2Q6NeKGet hashmaliciousBrowse
          • 98.187.110.188
          c0az1l4js3001lsk4xd9n.arm-20211124-0850Get hashmaliciousBrowse
          • 68.0.198.69
          x86_64-20211124-0649Get hashmaliciousBrowse
          • 68.109.156.176
          arm-20211124-0649Get hashmaliciousBrowse
          • 68.4.59.95
          arm6-20211124-0649Get hashmaliciousBrowse
          • 70.178.43.31
          jLvGTP8xikGet hashmaliciousBrowse
          • 98.186.255.228
          psI4iJBgiAGet hashmaliciousBrowse
          • 98.168.188.216
          zxIlLJKaukGet hashmaliciousBrowse
          • 72.212.53.113
          z0r0.x86Get hashmaliciousBrowse
          • 24.234.228.113

          JA3 Fingerprints

          No context

          Dropped Files

          No context

          Created / dropped Files

          /home/saturnino/.config/pulse/ee49dfd4fa47433baee88884e2d7de7c-default-sink
          Process:/usr/bin/pulseaudio
          File Type:ASCII text
          Category:dropped
          Size (bytes):10
          Entropy (8bit):2.9219280948873623
          Encrypted:false
          SSDEEP:3:5bkPn:pkP
          MD5:FF001A15CE15CF062A3704CEA2991B5F
          SHA1:B06F6855F376C3245B82212AC73ADED55DFE5DEF
          SHA-256:C54830B41ECFA1B6FBDC30397188DDA86B7B200E62AEAC21AE694A6192DCC38A
          SHA-512:65EBF7C31F6F65713CE01B38A112E97D0AE64A6BD1DA40CE4C1B998F10CD3912EE1A48BB2B279B24493062118AAB3B8753742E2AF28E56A31A7AAB27DE80E7BF
          Malicious:false
          Reputation:moderate, very likely benign file
          Preview: auto_null.
          /home/saturnino/.config/pulse/ee49dfd4fa47433baee88884e2d7de7c-default-source
          Process:/usr/bin/pulseaudio
          File Type:ASCII text
          Category:dropped
          Size (bytes):18
          Entropy (8bit):3.4613201402110088
          Encrypted:false
          SSDEEP:3:5bkrIZsXvn:pkckv
          MD5:28FE6435F34B3367707BB1C5D5F6B430
          SHA1:EB8FE2D16BD6BBCCE106C94E4D284543B2573CF6
          SHA-256:721A37C69E555799B41D308849E8F8125441883AB021B723FED90A9B744F36C0
          SHA-512:6B6AB7C0979629D0FEF6BE47C5C6BCC367EDD0AAE3FC973F4DE2FD5F0A819C89E7656DB65D453B1B5398E54012B27EDFE02894AD87A7E0AF3A9C5F2EB24A9919
          Malicious:false
          Reputation:moderate, very likely benign file
          Preview: auto_null.monitor.
          /proc/5408/oom_score_adj
          Process:/usr/sbin/sshd
          File Type:ASCII text
          Category:dropped
          Size (bytes):6
          Entropy (8bit):1.7924812503605778
          Encrypted:false
          SSDEEP:3:ptn:Dn
          MD5:CBF282CC55ED0792C33D10003D1F760A
          SHA1:007DD8BD75468E6B7ABA4285E9B267202C7EAEED
          SHA-256:FCDBAB99FCC0F4409E5F9D7D6FC497780288B4C441698126BB62832412774D22
          SHA-512:4643A8675D213C7DA35CC0C2BFB3B6F20324F9C48AEA7BA79F470615698C9A0CEFDA45CAA1957FC29110EE746BC8458AB8AB1E43EB513912A5E1E8858812CC00
          Malicious:false
          Reputation:high, very likely benign file
          Preview: -1000.
          /run/sshd.pid
          Process:/usr/sbin/sshd
          File Type:ASCII text
          Category:dropped
          Size (bytes):5
          Entropy (8bit):2.321928094887362
          Encrypted:false
          SSDEEP:3:E3v:E3v
          MD5:0BE520D99530BBA5C73589931A7285F6
          SHA1:AB4844E657DB95D0813D4A6947608894835CFF55
          SHA-256:730C50DA4C1A692C53478AAF119272CB220377D13DC420B57D25ACD5BA02BB0A
          SHA-512:B7DB6AAE5EC96AC7CF2B41D7A55B5E32FC5A24FBAABA0C6E829F833C9FDA597DBEFCAEE72E8003B6562EF2A88AC480AF345999497A2B94BE80B8CE8B52DB3312
          Malicious:false
          Reputation:low
          Preview: 5408.
          /run/systemd/resolve/stub-resolv.conf
          Process:/tmp/seWzsbHlCC
          File Type:ASCII text
          Category:dropped
          Size (bytes):38
          Entropy (8bit):3.3918926446809334
          Encrypted:false
          SSDEEP:3:KkZRAkd:KaAu
          MD5:C7EA09D26E26605227076E0514A33038
          SHA1:C3F9736E9AF7BD0885578859A50B205C8FA5FC8E
          SHA-256:7E8AD76E0D200E93918CA2E93C99FF8ECD02071953BF1479819DB3AC0DBB6D07
          SHA-512:17D0088725EB9991E9EB82E8A3DE0878E45E6F394BBC2AD260AA59C786FF0AD565E145E21256425D1C0ABE15F3ECB402EBB0A6A5E1C2D5BA7A4D95EC93A2861F
          Malicious:false
          Reputation:moderate, very likely benign file
          Preview: nameserver 8.8.8.8.nameserver 8.8.4.4.
          /run/user/1000/pulse/pid
          Process:/usr/bin/pulseaudio
          File Type:ASCII text
          Category:dropped
          Size (bytes):5
          Entropy (8bit):1.9219280948873623
          Encrypted:false
          SSDEEP:3:E1v:E1v
          MD5:6E8DD5F0924CE30B35AEAED9C61A5ADD
          SHA1:1208595C4CA7CD0E6980DD4C17DB3965CD6DFBB3
          SHA-256:DC19BDFF69BBF08AFC8FC0C584CBFCD3315D3AAB266D7F97564E71CE74D2774C
          SHA-512:353092740BF752D54D1A451EA5C41A87029B9A5784571F191433028BCDC810D5F4B86493F16C1D83A178776CE5B7B5FE7392B076CD32ECF362C1F2520239539E
          Malicious:false
          Reputation:low
          Preview: 5446.
          /var/log/gpu-manager.log
          Process:/usr/bin/gpu-manager
          File Type:ASCII text
          Category:dropped
          Size (bytes):1515
          Entropy (8bit):4.825813629825568
          Encrypted:false
          SSDEEP:24:wPXXX9uV6BNu3WDF3GF3XFFxFFed2uk2HUvJlfWkpPpx7uvvAdow9555Ro7uRkoT:wPXXXe6vejpeC2HUR5WkpPpcvAdow959
          MD5:7B48386106F00126E44F428D0193E1ED
          SHA1:75F652293B2DE03A845A73B678A5CB7E9701A9F4
          SHA-256:9F60B5D0D5C6F6CB3892E1687D16333F36E3BD450713B00FDF0B2BB90EC7312C
          SHA-512:57D0856EC65558B4A843A4696B644AC3E80B3EA0E6EC1C2FAC7A00015B96EBB2CC30967EB8DEFC3E648E59AC6882F6A4F69468D4B6CD0FD60F9F343C206DBFBC
          Malicious:false
          Preview: log_file: /var/log/gpu-manager.log.last_boot_file: /var/lib/ubuntu-drivers-common/last_gfx_boot.new_boot_file: /var/lib/ubuntu-drivers-common/last_gfx_boot.can't access /run/u-d-c-nvidia-was-loaded file.can't get module info via kmodcan't access /opt/amdgpu-pro/bin/amdgpu-pro-px.Looking for nvidia modules in /lib/modules/5.4.0-72-generic/kernel.Looking for nvidia modules in /lib/modules/5.4.0-72-generic/updates/dkms.Looking for amdgpu modules in /lib/modules/5.4.0-72-generic/kernel.Looking for amdgpu modules in /lib/modules/5.4.0-72-generic/updates/dkms.Is nvidia loaded? no.Was nvidia unloaded? no.Is nvidia blacklisted? no.Is intel loaded? no.Is radeon loaded? no.Is radeon blacklisted? no.Is amdgpu loaded? no.Is amdgpu blacklisted? no.Is amdgpu versioned? no.Is amdgpu pro stack? no.Is nouveau loaded? no.Is nouveau blacklisted? no.Is nvidia kernel module available? no.Is amdgpu kernel module available? no.Vendor/Device Id: 15ad:405.BusID "PCI:0@0:15:0".Is boot vga? yes.Error: can't acce
          /var/run/gdm3.pid
          Process:/usr/sbin/gdm3
          File Type:ASCII text
          Category:dropped
          Size (bytes):5
          Entropy (8bit):1.9219280948873623
          Encrypted:false
          SSDEEP:3:Fd/n:n/n
          MD5:5DE88F8B8A42BF20A95C7C449C13D8DE
          SHA1:42E07D8ECA0D77F8445F835510C1C634DC89E74F
          SHA-256:F9615512F25BC98071A42105AA4A18C4FD1E77EE6B8E7B63B60BAB517DC0114A
          SHA-512:5E1C807B5E7CA6E7A27545BE9418C1954AF3DCA07DE61C9768FCC333A13D646D116DF3B4197B1E106B5C0920DA6FB96FBF83C2F0081937163F22B2FA484661DE
          Malicious:false
          Preview: 5582.

          Static File Info

          General

          File type:ELF 32-bit LSB executable, ARM, version 1 (ARM), statically linked, stripped
          Entropy (8bit):7.977062127211769
          TrID:
          • ELF Executable and Linkable format (generic) (4004/1) 100.00%
          File name:seWzsbHlCC
          File size:48788
          MD5:4a3e4fcf840711d95a782a1aa01a3758
          SHA1:1debbe3bda8a84261eee99edc5f672165a44813d
          SHA256:8797bac4f4912bf412e4dc586f0747c0161de7b3ebd0e680eb814be4e20a7b39
          SHA512:3c978fc2340be0aa980be1302d14d5f9c37c6fc762c1ed579c018410003d45a524f600affca34ebe604a1887e2cf4d186df0836c01d03783a0e2fbee1bf3a6bf
          SSDEEP:768:3UTrAuYC4Ut7wwfhcYIeXrGgkoJBSwrauyOgYfZDAK+/BVZUUMK+P3FKxUOphDl7:3On4Utwch5Gm70/6UL+P3FK6QhR5yz1S
          File Content Preview:.ELF...a..........(......+..4...........4. ...(.........................................@o..@o..@o..................Q.td............................t.6.UPX!....................S..........?.E.h;.}...^..........f.+....E.....~.....*.....k.#..^.8......Nf3p2f.

          Static ELF Info

          ELF header

          Class:ELF32
          Data:2's complement, little endian
          Version:1 (current)
          Machine:ARM
          Version Number:0x1
          Type:EXEC (Executable file)
          OS/ABI:ARM - ABI
          ABI Version:0
          Entry Point Address:0x12bf8
          Flags:0x2
          ELF Header Size:52
          Program Header Offset:52
          Program Header Size:32
          Number of Program Headers:3
          Section Header Offset:0
          Section Header Size:40
          Number of Section Headers:0
          Header String Table Index:0

          Program Segments

          TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
          LOAD0x00x80000x80000xbda70xbda74.03640x5R E0x8000
          LOAD0x6f400x36f400x36f400x00x00.00000x6RW 0x8000
          GNU_STACK0x00x00x00x00x00.00000x7RWE0x4

          Network Behavior

          Network Port Distribution

          TCP Packets

          TimestampSource PortDest PortSource IPDest IP
          Nov 25, 2021 18:29:22.738009930 CET5194523192.168.2.23185.174.86.135
          Nov 25, 2021 18:29:22.738338947 CET5194523192.168.2.23147.145.201.135
          Nov 25, 2021 18:29:22.738367081 CET5194523192.168.2.23101.172.161.173
          Nov 25, 2021 18:29:22.738379002 CET5194523192.168.2.23165.249.86.132
          Nov 25, 2021 18:29:22.738379955 CET5194523192.168.2.23157.68.78.60
          Nov 25, 2021 18:29:22.738406897 CET5194523192.168.2.2385.105.184.86
          Nov 25, 2021 18:29:22.738418102 CET5194523192.168.2.2377.124.17.46
          Nov 25, 2021 18:29:22.738425016 CET5194523192.168.2.23206.204.80.87
          Nov 25, 2021 18:29:22.738451958 CET5194523192.168.2.23216.148.132.203
          Nov 25, 2021 18:29:22.738451958 CET5194523192.168.2.23207.140.150.1
          Nov 25, 2021 18:29:22.738462925 CET5194523192.168.2.23109.215.13.121
          Nov 25, 2021 18:29:22.738466978 CET5194523192.168.2.2395.23.32.192
          Nov 25, 2021 18:29:22.738476038 CET5194523192.168.2.23144.148.82.187
          Nov 25, 2021 18:29:22.738491058 CET5194523192.168.2.2341.147.213.38
          Nov 25, 2021 18:29:22.738522053 CET5194523192.168.2.2317.179.94.217
          Nov 25, 2021 18:29:22.738532066 CET5194523192.168.2.2348.121.4.250
          Nov 25, 2021 18:29:22.738532066 CET5194523192.168.2.23170.171.137.68
          Nov 25, 2021 18:29:22.738533974 CET5194523192.168.2.23122.35.156.9
          Nov 25, 2021 18:29:22.738537073 CET5194523192.168.2.23123.183.200.233
          Nov 25, 2021 18:29:22.738538027 CET5194523192.168.2.2390.131.136.159
          Nov 25, 2021 18:29:22.738539934 CET5194523192.168.2.23140.154.149.1
          Nov 25, 2021 18:29:22.738539934 CET5194523192.168.2.2335.75.90.209
          Nov 25, 2021 18:29:22.738543987 CET5194523192.168.2.23206.177.180.146
          Nov 25, 2021 18:29:22.738552094 CET5194523192.168.2.23113.184.204.137
          Nov 25, 2021 18:29:22.738552094 CET5194523192.168.2.2334.121.250.0
          Nov 25, 2021 18:29:22.738549948 CET5194523192.168.2.2365.22.59.61
          Nov 25, 2021 18:29:22.738559961 CET5194523192.168.2.23111.196.65.29
          Nov 25, 2021 18:29:22.738564014 CET5194523192.168.2.23114.93.66.26
          Nov 25, 2021 18:29:22.738570929 CET5194523192.168.2.2367.41.210.145
          Nov 25, 2021 18:29:22.738599062 CET5194523192.168.2.2366.4.96.250
          Nov 25, 2021 18:29:22.738621950 CET5194523192.168.2.23120.142.202.163
          Nov 25, 2021 18:29:22.738630056 CET5194523192.168.2.2344.196.192.32
          Nov 25, 2021 18:29:22.738641977 CET5194523192.168.2.231.45.214.176
          Nov 25, 2021 18:29:22.738656998 CET5194523192.168.2.2388.123.62.136
          Nov 25, 2021 18:29:22.738663912 CET5194523192.168.2.23123.12.14.8
          Nov 25, 2021 18:29:22.738708019 CET5194523192.168.2.2360.173.87.20
          Nov 25, 2021 18:29:22.738717079 CET5194523192.168.2.23148.216.197.233
          Nov 25, 2021 18:29:22.738720894 CET5194523192.168.2.23124.110.17.122
          Nov 25, 2021 18:29:22.738759041 CET5194523192.168.2.2362.26.241.157
          Nov 25, 2021 18:29:22.738766909 CET5194523192.168.2.23180.19.155.94
          Nov 25, 2021 18:29:22.738790989 CET5194523192.168.2.23185.140.46.7
          Nov 25, 2021 18:29:22.738791943 CET5194523192.168.2.23152.64.186.78
          Nov 25, 2021 18:29:22.738796949 CET5194523192.168.2.2367.187.89.149
          Nov 25, 2021 18:29:22.738810062 CET5194523192.168.2.23141.115.0.49
          Nov 25, 2021 18:29:22.738810062 CET5194523192.168.2.239.137.234.67
          Nov 25, 2021 18:29:22.738815069 CET5194523192.168.2.23156.47.130.141
          Nov 25, 2021 18:29:22.738825083 CET5194523192.168.2.23165.146.155.109
          Nov 25, 2021 18:29:22.738831043 CET5194523192.168.2.23218.132.15.181
          Nov 25, 2021 18:29:22.738845110 CET5194523192.168.2.23119.7.98.20
          Nov 25, 2021 18:29:22.738851070 CET5194523192.168.2.23163.148.235.64
          Nov 25, 2021 18:29:22.738868952 CET5194523192.168.2.23169.231.176.193
          Nov 25, 2021 18:29:22.738878965 CET5194523192.168.2.23209.108.255.11
          Nov 25, 2021 18:29:22.738893986 CET5194523192.168.2.23223.202.100.106
          Nov 25, 2021 18:29:22.738898039 CET5194523192.168.2.2367.129.186.224
          Nov 25, 2021 18:29:22.738907099 CET5194523192.168.2.2392.14.167.206
          Nov 25, 2021 18:29:22.738918066 CET5194523192.168.2.2324.254.57.219
          Nov 25, 2021 18:29:22.738920927 CET5194523192.168.2.2366.172.126.103
          Nov 25, 2021 18:29:22.738931894 CET5194523192.168.2.2382.198.185.12
          Nov 25, 2021 18:29:22.738946915 CET5194523192.168.2.23139.71.57.227
          Nov 25, 2021 18:29:22.738962889 CET5194523192.168.2.2360.152.190.24
          Nov 25, 2021 18:29:22.738971949 CET5194523192.168.2.23220.151.161.255
          Nov 25, 2021 18:29:22.738998890 CET5194523192.168.2.23156.246.86.115
          Nov 25, 2021 18:29:22.739015102 CET5194523192.168.2.23160.231.49.58
          Nov 25, 2021 18:29:22.739032984 CET5194523192.168.2.2312.64.58.107
          Nov 25, 2021 18:29:22.739047050 CET5194523192.168.2.2346.175.67.250
          Nov 25, 2021 18:29:22.739053965 CET5194523192.168.2.23103.217.87.176
          Nov 25, 2021 18:29:22.739063978 CET5194523192.168.2.2370.137.182.23
          Nov 25, 2021 18:29:22.739067078 CET5194523192.168.2.2318.80.251.148
          Nov 25, 2021 18:29:22.739075899 CET5194523192.168.2.23103.205.115.250
          Nov 25, 2021 18:29:22.739090919 CET5194523192.168.2.23131.79.135.103
          Nov 25, 2021 18:29:22.739092112 CET5194523192.168.2.23222.5.203.146
          Nov 25, 2021 18:29:22.739103079 CET5194523192.168.2.2378.27.194.242
          Nov 25, 2021 18:29:22.739113092 CET5194523192.168.2.23160.76.90.251
          Nov 25, 2021 18:29:22.739147902 CET5194523192.168.2.2345.253.7.171
          Nov 25, 2021 18:29:22.739157915 CET5194523192.168.2.2393.124.174.154
          Nov 25, 2021 18:29:22.739167929 CET5194523192.168.2.23148.245.174.83
          Nov 25, 2021 18:29:22.739176989 CET5194523192.168.2.23183.115.201.180
          Nov 25, 2021 18:29:22.739188910 CET5194523192.168.2.23112.32.188.203
          Nov 25, 2021 18:29:22.739201069 CET5194523192.168.2.234.118.78.34
          Nov 25, 2021 18:29:22.739219904 CET5194523192.168.2.23204.114.190.79
          Nov 25, 2021 18:29:22.739222050 CET5194523192.168.2.23131.54.118.129
          Nov 25, 2021 18:29:22.739228010 CET5194523192.168.2.23167.124.247.128
          Nov 25, 2021 18:29:22.739238024 CET5194523192.168.2.235.49.91.39
          Nov 25, 2021 18:29:22.739262104 CET5194523192.168.2.2373.75.255.161
          Nov 25, 2021 18:29:22.739269972 CET5194523192.168.2.2366.40.200.211
          Nov 25, 2021 18:29:22.739279032 CET5194523192.168.2.2388.241.104.44
          Nov 25, 2021 18:29:22.739304066 CET5194523192.168.2.23133.193.36.130
          Nov 25, 2021 18:29:22.739309072 CET5194523192.168.2.23169.246.70.213
          Nov 25, 2021 18:29:22.739322901 CET5194523192.168.2.2358.159.179.9
          Nov 25, 2021 18:29:22.739330053 CET5194523192.168.2.2361.111.58.44
          Nov 25, 2021 18:29:22.739340067 CET5194523192.168.2.23156.195.210.238
          Nov 25, 2021 18:29:22.739362955 CET5194523192.168.2.23102.162.13.134
          Nov 25, 2021 18:29:22.739378929 CET5194523192.168.2.23114.133.239.235
          Nov 25, 2021 18:29:22.739389896 CET5194523192.168.2.2320.208.22.242
          Nov 25, 2021 18:29:22.739392996 CET5194523192.168.2.23133.204.145.61
          Nov 25, 2021 18:29:22.739408016 CET5194523192.168.2.2392.211.166.54
          Nov 25, 2021 18:29:22.739409924 CET5194523192.168.2.23200.216.96.192
          Nov 25, 2021 18:29:22.739418983 CET5194523192.168.2.23188.101.74.102
          Nov 25, 2021 18:29:22.739432096 CET5194523192.168.2.23175.102.63.209
          Nov 25, 2021 18:29:22.739439011 CET5194523192.168.2.23102.140.18.230

          DNS Queries

          TimestampSource IPDest IPTrans IDOP CodeNameTypeClass
          Nov 25, 2021 18:30:11.517456055 CET192.168.2.238.8.8.80x808eStandard query (0)daisy.ubuntu.comA (IP address)IN (0x0001)
          Nov 25, 2021 18:30:11.518490076 CET192.168.2.238.8.8.80xbc8dStandard query (0)daisy.ubuntu.com28IN (0x0001)

          DNS Answers

          TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClass
          Nov 25, 2021 18:30:11.549971104 CET8.8.8.8192.168.2.230x808eNo error (0)daisy.ubuntu.com162.213.33.132A (IP address)IN (0x0001)
          Nov 25, 2021 18:30:11.549971104 CET8.8.8.8192.168.2.230x808eNo error (0)daisy.ubuntu.com162.213.33.108A (IP address)IN (0x0001)

          System Behavior

          General

          Start time:18:29:21
          Start date:25/11/2021
          Path:/tmp/seWzsbHlCC
          Arguments:/tmp/seWzsbHlCC
          File size:4956856 bytes
          MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

          General

          Start time:18:29:22
          Start date:25/11/2021
          Path:/tmp/seWzsbHlCC
          Arguments:n/a
          File size:4956856 bytes
          MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

          General

          Start time:18:29:22
          Start date:25/11/2021
          Path:/tmp/seWzsbHlCC
          Arguments:n/a
          File size:4956856 bytes
          MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

          General

          Start time:18:29:22
          Start date:25/11/2021
          Path:/tmp/seWzsbHlCC
          Arguments:n/a
          File size:4956856 bytes
          MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

          General

          Start time:18:29:22
          Start date:25/11/2021
          Path:/tmp/seWzsbHlCC
          Arguments:n/a
          File size:4956856 bytes
          MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

          General

          Start time:18:29:22
          Start date:25/11/2021
          Path:/tmp/seWzsbHlCC
          Arguments:n/a
          File size:4956856 bytes
          MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

          General

          Start time:18:29:22
          Start date:25/11/2021
          Path:/tmp/seWzsbHlCC
          Arguments:n/a
          File size:4956856 bytes
          MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

          General

          Start time:18:29:22
          Start date:25/11/2021
          Path:/bin/sh
          Arguments:sh -c "rm -rf /tmp/* /var/* /var/run/* /var/tmp/*"
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:18:29:22
          Start date:25/11/2021
          Path:/bin/sh
          Arguments:n/a
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:18:29:22
          Start date:25/11/2021
          Path:/usr/bin/rm
          Arguments:rm -rf /tmp/config-err-dHT8bZ /tmp/dmesgtail.log /tmp/seWzsbHlCC /tmp/snap.lxd /tmp/ssh-hOQ5FjG2iVgO /tmp/systemd-private-ec795e01d534441298b2bf519e4c51fc-ModemManager.service-c4RYFi /tmp/systemd-private-ec795e01d534441298b2bf519e4c51fc-colord.service-gKIF8e /tmp/systemd-private-ec795e01d534441298b2bf519e4c51fc-fwupd.service-gB0a9f /tmp/systemd-private-ec795e01d534441298b2bf519e4c51fc-switcheroo-control.service-APWnLg /tmp/systemd-private-ec795e01d534441298b2bf519e4c51fc-systemd-logind.service-IofUpj /tmp/systemd-private-ec795e01d534441298b2bf519e4c51fc-systemd-resolved.service-AfPZzg /tmp/systemd-private-ec795e01d534441298b2bf519e4c51fc-upower.service-x0xO0i /tmp/vmware-root_721-4290559889 /var/backups /var/cache /var/crash /var/lib /var/local /var/lock /var/log /var/mail /var/metrics /var/opt /var/run /var/snap /var/spool /var/tmp /var/run/NetworkManager /var/run/acpid.pid /var/run/acpid.socket /var/run/apport.lock /var/run/avahi-daemon /var/run/blkid /var/run/cloud-init /var/run/console-setup /var/run/crond.pid /var/run/crond.reboot /var/run/cryptsetup /var/run/cups /var/run/dbus /var/run/dmeventd-client /var/run/dmeventd-server /var/run/gdm3 /var/run/gdm3.pid /var/run/initctl /var/run/initramfs /var/run/irqbalance /var/run/lock /var/run/log /var/run/lvm /var/run/mlocate.daily.lock /var/run/mono-xsp4 /var/run/mono-xsp4.pid /var/run/motd.d /var/run/mount /var/run/multipathd.pid /var/run/netns /var/run/network /var/run/screen /var/run/sendsigs.omit.d /var/run/shm /var/run/snapd /var/run/snapd-snap.socket /var/run/snapd.socket /var/run/speech-dispatcher /var/run/spice-vdagentd /var/run/sshd /var/run/sshd.pid /var/run/sudo /var/run/systemd /var/run/tmpfiles.d /var/run/udev /var/run/udisks2 /var/run/unattended-upgrades.lock /var/run/user /var/run/utmp /var/run/uuidd /var/run/vmware /var/tmp/systemd-private-ec795e01d534441298b2bf519e4c51fc-ModemManager.service-J6Q1Te /var/tmp/systemd-private-ec795e01d534441298b2bf519e4c51fc-colord.service-srP90f /var/tmp/systemd-private-ec795e01d534441298b2bf519e4c51fc-fwupd.service-biJ0Gi /var/tmp/systemd-private-ec795e01d534441298b2bf519e4c51fc-switcheroo-control.service-1jIxdj /var/tmp/systemd-private-ec795e01d534441298b2bf519e4c51fc-systemd-logind.service-llmWag /var/tmp/systemd-private-ec795e01d534441298b2bf519e4c51fc-systemd-resolved.service-X16eHh /var/tmp/systemd-private-ec795e01d534441298b2bf519e4c51fc-upower.service-GpSnaf
          File size:72056 bytes
          MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

          General

          Start time:18:29:34
          Start date:25/11/2021
          Path:/tmp/seWzsbHlCC
          Arguments:n/a
          File size:4956856 bytes
          MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

          General

          Start time:18:29:34
          Start date:25/11/2021
          Path:/bin/sh
          Arguments:sh -c "rm -rf /var/log/wtmp"
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:18:29:34
          Start date:25/11/2021
          Path:/bin/sh
          Arguments:n/a
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:18:29:34
          Start date:25/11/2021
          Path:/usr/bin/rm
          Arguments:rm -rf /var/log/wtmp
          File size:72056 bytes
          MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

          General

          Start time:18:29:34
          Start date:25/11/2021
          Path:/tmp/seWzsbHlCC
          Arguments:n/a
          File size:4956856 bytes
          MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

          General

          Start time:18:29:34
          Start date:25/11/2021
          Path:/bin/sh
          Arguments:sh -c "rm -rf /tmp/*"
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:18:29:34
          Start date:25/11/2021
          Path:/bin/sh
          Arguments:n/a
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:18:29:34
          Start date:25/11/2021
          Path:/usr/bin/rm
          Arguments:rm -rf /tmp/*
          File size:72056 bytes
          MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

          General

          Start time:18:29:34
          Start date:25/11/2021
          Path:/tmp/seWzsbHlCC
          Arguments:n/a
          File size:4956856 bytes
          MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

          General

          Start time:18:29:34
          Start date:25/11/2021
          Path:/bin/sh
          Arguments:sh -c "rm -rf /bin/netstat"
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:18:29:34
          Start date:25/11/2021
          Path:/bin/sh
          Arguments:n/a
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:18:29:34
          Start date:25/11/2021
          Path:/usr/bin/rm
          Arguments:rm -rf /bin/netstat
          File size:72056 bytes
          MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

          General

          Start time:18:29:34
          Start date:25/11/2021
          Path:/tmp/seWzsbHlCC
          Arguments:n/a
          File size:4956856 bytes
          MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

          General

          Start time:18:29:34
          Start date:25/11/2021
          Path:/bin/sh
          Arguments:sh -c "iptables -F"
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:18:29:34
          Start date:25/11/2021
          Path:/bin/sh
          Arguments:n/a
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:18:29:34
          Start date:25/11/2021
          Path:/usr/sbin/iptables
          Arguments:iptables -F
          File size:99296 bytes
          MD5 hash:1ab05fef765b6342cdfadaa5275b33af

          General

          Start time:18:29:34
          Start date:25/11/2021
          Path:/tmp/seWzsbHlCC
          Arguments:n/a
          File size:4956856 bytes
          MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

          General

          Start time:18:29:34
          Start date:25/11/2021
          Path:/bin/sh
          Arguments:sh -c "pkill -9 busybox"
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:18:29:34
          Start date:25/11/2021
          Path:/bin/sh
          Arguments:n/a
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:18:29:34
          Start date:25/11/2021
          Path:/usr/bin/pkill
          Arguments:pkill -9 busybox
          File size:30968 bytes
          MD5 hash:fa96a75a08109d8842e4865b2907d51f

          General

          Start time:18:29:36
          Start date:25/11/2021
          Path:/tmp/seWzsbHlCC
          Arguments:n/a
          File size:4956856 bytes
          MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

          General

          Start time:18:29:36
          Start date:25/11/2021
          Path:/bin/sh
          Arguments:sh -c "pkill -9 perl"
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:18:29:36
          Start date:25/11/2021
          Path:/bin/sh
          Arguments:n/a
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:18:29:36
          Start date:25/11/2021
          Path:/usr/bin/pkill
          Arguments:pkill -9 perl
          File size:30968 bytes
          MD5 hash:fa96a75a08109d8842e4865b2907d51f

          General

          Start time:18:29:38
          Start date:25/11/2021
          Path:/tmp/seWzsbHlCC
          Arguments:n/a
          File size:4956856 bytes
          MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

          General

          Start time:18:29:38
          Start date:25/11/2021
          Path:/bin/sh
          Arguments:sh -c "pkill -9 python"
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:18:29:38
          Start date:25/11/2021
          Path:/bin/sh
          Arguments:n/a
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:18:29:38
          Start date:25/11/2021
          Path:/usr/bin/pkill
          Arguments:pkill -9 python
          File size:30968 bytes
          MD5 hash:fa96a75a08109d8842e4865b2907d51f

          General

          Start time:18:29:41
          Start date:25/11/2021
          Path:/tmp/seWzsbHlCC
          Arguments:n/a
          File size:4956856 bytes
          MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

          General

          Start time:18:29:41
          Start date:25/11/2021
          Path:/bin/sh
          Arguments:sh -c "service iptables stop"
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:18:29:41
          Start date:25/11/2021
          Path:/bin/sh
          Arguments:n/a
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:18:29:41
          Start date:25/11/2021
          Path:/usr/sbin/service
          Arguments:service iptables stop
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:18:29:41
          Start date:25/11/2021
          Path:/usr/sbin/service
          Arguments:n/a
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:18:29:41
          Start date:25/11/2021
          Path:/usr/bin/basename
          Arguments:basename /usr/sbin/service
          File size:39256 bytes
          MD5 hash:3283660e59f128df18bec9b96fbd4d41

          General

          Start time:18:29:41
          Start date:25/11/2021
          Path:/usr/sbin/service
          Arguments:n/a
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:18:29:41
          Start date:25/11/2021
          Path:/usr/bin/basename
          Arguments:basename /usr/sbin/service
          File size:39256 bytes
          MD5 hash:3283660e59f128df18bec9b96fbd4d41

          General

          Start time:18:29:41
          Start date:25/11/2021
          Path:/usr/sbin/service
          Arguments:n/a
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:18:29:41
          Start date:25/11/2021
          Path:/usr/bin/systemctl
          Arguments:systemctl --quiet is-active multi-user.target
          File size:996584 bytes
          MD5 hash:4deddfb6741481f68aeac522cc26ff4b

          General

          Start time:18:29:41
          Start date:25/11/2021
          Path:/usr/sbin/service
          Arguments:n/a
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:18:29:41
          Start date:25/11/2021
          Path:/usr/sbin/service
          Arguments:n/a
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:18:29:41
          Start date:25/11/2021
          Path:/usr/bin/systemctl
          Arguments:systemctl list-unit-files --full --type=socket
          File size:996584 bytes
          MD5 hash:4deddfb6741481f68aeac522cc26ff4b

          General

          Start time:18:29:41
          Start date:25/11/2021
          Path:/usr/sbin/service
          Arguments:n/a
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:18:29:41
          Start date:25/11/2021
          Path:/usr/bin/sed
          Arguments:sed -ne s/\\.socket\\s*[a-z]*\\s*$/.socket/p
          File size:121288 bytes
          MD5 hash:885062561f66aa1d4af4c54b9e7cc81a

          General

          Start time:18:29:43
          Start date:25/11/2021
          Path:/usr/bin/systemctl
          Arguments:systemctl stop iptables.service
          File size:996584 bytes
          MD5 hash:4deddfb6741481f68aeac522cc26ff4b

          General

          Start time:18:29:43
          Start date:25/11/2021
          Path:/tmp/seWzsbHlCC
          Arguments:n/a
          File size:4956856 bytes
          MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

          General

          Start time:18:29:43
          Start date:25/11/2021
          Path:/bin/sh
          Arguments:sh -c "/sbin/iptables -F; /sbin/iptables -X"
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:18:29:43
          Start date:25/11/2021
          Path:/bin/sh
          Arguments:n/a
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:18:29:43
          Start date:25/11/2021
          Path:/sbin/iptables
          Arguments:/sbin/iptables -F
          File size:99296 bytes
          MD5 hash:1ab05fef765b6342cdfadaa5275b33af

          General

          Start time:18:29:43
          Start date:25/11/2021
          Path:/bin/sh
          Arguments:n/a
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:18:29:43
          Start date:25/11/2021
          Path:/sbin/iptables
          Arguments:/sbin/iptables -X
          File size:99296 bytes
          MD5 hash:1ab05fef765b6342cdfadaa5275b33af

          General

          Start time:18:29:44
          Start date:25/11/2021
          Path:/tmp/seWzsbHlCC
          Arguments:n/a
          File size:4956856 bytes
          MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

          General

          Start time:18:29:44
          Start date:25/11/2021
          Path:/bin/sh
          Arguments:sh -c "service firewalld stop"
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:18:29:44
          Start date:25/11/2021
          Path:/bin/sh
          Arguments:n/a
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:18:29:44
          Start date:25/11/2021
          Path:/usr/sbin/service
          Arguments:service firewalld stop
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:18:29:44
          Start date:25/11/2021
          Path:/usr/sbin/service
          Arguments:n/a
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:18:29:44
          Start date:25/11/2021
          Path:/usr/bin/basename
          Arguments:basename /usr/sbin/service
          File size:39256 bytes
          MD5 hash:3283660e59f128df18bec9b96fbd4d41

          General

          Start time:18:29:44
          Start date:25/11/2021
          Path:/usr/sbin/service
          Arguments:n/a
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:18:29:44
          Start date:25/11/2021
          Path:/usr/bin/basename
          Arguments:basename /usr/sbin/service
          File size:39256 bytes
          MD5 hash:3283660e59f128df18bec9b96fbd4d41

          General

          Start time:18:29:44
          Start date:25/11/2021
          Path:/usr/sbin/service
          Arguments:n/a
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:18:29:44
          Start date:25/11/2021
          Path:/usr/bin/systemctl
          Arguments:systemctl --quiet is-active multi-user.target
          File size:996584 bytes
          MD5 hash:4deddfb6741481f68aeac522cc26ff4b

          General

          Start time:18:29:44
          Start date:25/11/2021
          Path:/usr/sbin/service
          Arguments:n/a
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:18:29:44
          Start date:25/11/2021
          Path:/usr/sbin/service
          Arguments:n/a
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:18:29:44
          Start date:25/11/2021
          Path:/usr/bin/systemctl
          Arguments:systemctl list-unit-files --full --type=socket
          File size:996584 bytes
          MD5 hash:4deddfb6741481f68aeac522cc26ff4b

          General

          Start time:18:29:44
          Start date:25/11/2021
          Path:/usr/sbin/service
          Arguments:n/a
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:18:29:44
          Start date:25/11/2021
          Path:/usr/bin/sed
          Arguments:sed -ne s/\\.socket\\s*[a-z]*\\s*$/.socket/p
          File size:121288 bytes
          MD5 hash:885062561f66aa1d4af4c54b9e7cc81a

          General

          Start time:18:29:47
          Start date:25/11/2021
          Path:/usr/bin/systemctl
          Arguments:systemctl stop firewalld.service
          File size:996584 bytes
          MD5 hash:4deddfb6741481f68aeac522cc26ff4b

          General

          Start time:18:29:47
          Start date:25/11/2021
          Path:/tmp/seWzsbHlCC
          Arguments:n/a
          File size:4956856 bytes
          MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

          General

          Start time:18:29:47
          Start date:25/11/2021
          Path:/bin/sh
          Arguments:sh -c "rm -rf ~/.bash_history"
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:18:29:48
          Start date:25/11/2021
          Path:/bin/sh
          Arguments:n/a
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:18:29:48
          Start date:25/11/2021
          Path:/usr/bin/rm
          Arguments:rm -rf /root/.bash_history
          File size:72056 bytes
          MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

          General

          Start time:18:29:48
          Start date:25/11/2021
          Path:/tmp/seWzsbHlCC
          Arguments:n/a
          File size:4956856 bytes
          MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

          General

          Start time:18:29:48
          Start date:25/11/2021
          Path:/bin/sh
          Arguments:sh -c "history -c"
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:18:30:10
          Start date:25/11/2021
          Path:/usr/lib/systemd/systemd
          Arguments:n/a
          File size:1620224 bytes
          MD5 hash:9b2bec7092a40488108543f9334aab75

          General

          Start time:18:30:10
          Start date:25/11/2021
          Path:/usr/bin/whoopsie
          Arguments:/usr/bin/whoopsie -f
          File size:68592 bytes
          MD5 hash:d3a6915d0e7398fb4c89a037c13959c8

          General

          Start time:18:30:14
          Start date:25/11/2021
          Path:/usr/lib/systemd/systemd
          Arguments:n/a
          File size:1620224 bytes
          MD5 hash:9b2bec7092a40488108543f9334aab75

          General

          Start time:18:30:14
          Start date:25/11/2021
          Path:/usr/sbin/sshd
          Arguments:/usr/sbin/sshd -t
          File size:876328 bytes
          MD5 hash:dbca7a6bbf7bf57fedac243d4b2cb340

          General

          Start time:18:30:14
          Start date:25/11/2021
          Path:/usr/lib/systemd/systemd
          Arguments:n/a
          File size:1620224 bytes
          MD5 hash:9b2bec7092a40488108543f9334aab75

          General

          Start time:18:30:14
          Start date:25/11/2021
          Path:/usr/sbin/sshd
          Arguments:/usr/sbin/sshd -D
          File size:876328 bytes
          MD5 hash:dbca7a6bbf7bf57fedac243d4b2cb340

          General

          Start time:18:30:21
          Start date:25/11/2021
          Path:/usr/sbin/gdm3
          Arguments:n/a
          File size:453296 bytes
          MD5 hash:2492e2d8d34f9377e3e530a61a15674f

          General

          Start time:18:30:21
          Start date:25/11/2021
          Path:/etc/gdm3/PrimeOff/Default
          Arguments:/etc/gdm3/PrimeOff/Default
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:18:30:21
          Start date:25/11/2021
          Path:/usr/sbin/gdm3
          Arguments:n/a
          File size:453296 bytes
          MD5 hash:2492e2d8d34f9377e3e530a61a15674f

          General

          Start time:18:30:21
          Start date:25/11/2021
          Path:/etc/gdm3/PrimeOff/Default
          Arguments:/etc/gdm3/PrimeOff/Default
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:18:30:21
          Start date:25/11/2021
          Path:/usr/lib/systemd/systemd
          Arguments:n/a
          File size:1620224 bytes
          MD5 hash:9b2bec7092a40488108543f9334aab75

          General

          Start time:18:30:21
          Start date:25/11/2021
          Path:/usr/lib/accountsservice/accounts-daemon
          Arguments:/usr/lib/accountsservice/accounts-daemon
          File size:203192 bytes
          MD5 hash:01a899e3fb5e7e434bea1290255a1f30

          General

          Start time:18:30:43
          Start date:25/11/2021
          Path:/usr/lib/systemd/systemd
          Arguments:n/a
          File size:1620224 bytes
          MD5 hash:9b2bec7092a40488108543f9334aab75

          General

          Start time:18:30:43
          Start date:25/11/2021
          Path:/usr/bin/pulseaudio
          Arguments:/usr/bin/pulseaudio --daemonize=no --log-target=journal
          File size:100832 bytes
          MD5 hash:0c3b4c789d8ffb12b25507f27e14c186

          General

          Start time:18:30:47
          Start date:25/11/2021
          Path:/usr/lib/systemd/systemd
          Arguments:n/a
          File size:1620224 bytes
          MD5 hash:9b2bec7092a40488108543f9334aab75

          General

          Start time:18:30:47
          Start date:25/11/2021
          Path:/usr/bin/gpu-manager
          Arguments:/usr/bin/gpu-manager --log /var/log/gpu-manager.log
          File size:76616 bytes
          MD5 hash:8fae9dd5dd67e1f33d873089c2fd8761

          General

          Start time:18:30:48
          Start date:25/11/2021
          Path:/usr/bin/gpu-manager
          Arguments:n/a
          File size:76616 bytes
          MD5 hash:8fae9dd5dd67e1f33d873089c2fd8761

          General

          Start time:18:30:48
          Start date:25/11/2021
          Path:/bin/sh
          Arguments:sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /etc/modprobe.d/*.conf"
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:18:30:48
          Start date:25/11/2021
          Path:/bin/sh
          Arguments:n/a
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:18:30:48
          Start date:25/11/2021
          Path:/usr/bin/grep
          Arguments:grep -G ^blacklist.*nvidia[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
          File size:199136 bytes
          MD5 hash:1e6ebb9dd094f774478f72727bdba0f5

          General

          Start time:18:30:48
          Start date:25/11/2021
          Path:/usr/bin/gpu-manager
          Arguments:n/a
          File size:76616 bytes
          MD5 hash:8fae9dd5dd67e1f33d873089c2fd8761

          General

          Start time:18:30:48
          Start date:25/11/2021
          Path:/bin/sh
          Arguments:sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /lib/modprobe.d/*.conf"
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:18:30:48
          Start date:25/11/2021
          Path:/bin/sh
          Arguments:n/a
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:18:30:48
          Start date:25/11/2021
          Path:/usr/bin/grep
          Arguments:grep -G ^blacklist.*nvidia[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
          File size:199136 bytes
          MD5 hash:1e6ebb9dd094f774478f72727bdba0f5

          General

          Start time:18:30:48
          Start date:25/11/2021
          Path:/usr/bin/gpu-manager
          Arguments:n/a
          File size:76616 bytes
          MD5 hash:8fae9dd5dd67e1f33d873089c2fd8761

          General

          Start time:18:30:48
          Start date:25/11/2021
          Path:/bin/sh
          Arguments:sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /etc/modprobe.d/*.conf"
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:18:30:48
          Start date:25/11/2021
          Path:/bin/sh
          Arguments:n/a
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:18:30:48
          Start date:25/11/2021
          Path:/usr/bin/grep
          Arguments:grep -G ^blacklist.*radeon[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
          File size:199136 bytes
          MD5 hash:1e6ebb9dd094f774478f72727bdba0f5

          General

          Start time:18:30:48
          Start date:25/11/2021
          Path:/usr/bin/gpu-manager
          Arguments:n/a
          File size:76616 bytes
          MD5 hash:8fae9dd5dd67e1f33d873089c2fd8761

          General

          Start time:18:30:48
          Start date:25/11/2021
          Path:/bin/sh
          Arguments:sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /lib/modprobe.d/*.conf"
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:18:30:48
          Start date:25/11/2021
          Path:/bin/sh
          Arguments:n/a
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:18:30:48
          Start date:25/11/2021
          Path:/usr/bin/grep
          Arguments:grep -G ^blacklist.*radeon[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
          File size:199136 bytes
          MD5 hash:1e6ebb9dd094f774478f72727bdba0f5

          General

          Start time:18:30:48
          Start date:25/11/2021
          Path:/usr/bin/gpu-manager
          Arguments:n/a
          File size:76616 bytes
          MD5 hash:8fae9dd5dd67e1f33d873089c2fd8761

          General

          Start time:18:30:48
          Start date:25/11/2021
          Path:/bin/sh
          Arguments:sh -c "grep -G \"^blacklist.*amdgpu[[:space:]]*$\" /etc/modprobe.d/*.conf"
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:18:30:48
          Start date:25/11/2021
          Path:/bin/sh
          Arguments:n/a
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:18:30:48
          Start date:25/11/2021
          Path:/usr/bin/grep
          Arguments:grep -G ^blacklist.*amdgpu[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
          File size:199136 bytes
          MD5 hash:1e6ebb9dd094f774478f72727bdba0f5

          General

          Start time:18:30:48
          Start date:25/11/2021
          Path:/usr/bin/gpu-manager
          Arguments:n/a
          File size:76616 bytes
          MD5 hash:8fae9dd5dd67e1f33d873089c2fd8761

          General

          Start time:18:30:48
          Start date:25/11/2021
          Path:/bin/sh
          Arguments:sh -c "grep -G \"^blacklist.*amdgpu[[:space:]]*$\" /lib/modprobe.d/*.conf"
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:18:30:48
          Start date:25/11/2021
          Path:/bin/sh
          Arguments:n/a
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:18:30:48
          Start date:25/11/2021
          Path:/usr/bin/grep
          Arguments:grep -G ^blacklist.*amdgpu[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
          File size:199136 bytes
          MD5 hash:1e6ebb9dd094f774478f72727bdba0f5

          General

          Start time:18:30:48
          Start date:25/11/2021
          Path:/usr/bin/gpu-manager
          Arguments:n/a
          File size:76616 bytes
          MD5 hash:8fae9dd5dd67e1f33d873089c2fd8761

          General

          Start time:18:30:48
          Start date:25/11/2021
          Path:/bin/sh
          Arguments:sh -c "grep -G \"^blacklist.*nouveau[[:space:]]*$\" /etc/modprobe.d/*.conf"
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:18:30:48
          Start date:25/11/2021
          Path:/bin/sh
          Arguments:n/a
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:18:30:48
          Start date:25/11/2021
          Path:/usr/bin/grep
          Arguments:grep -G ^blacklist.*nouveau[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
          File size:199136 bytes
          MD5 hash:1e6ebb9dd094f774478f72727bdba0f5

          General

          Start time:18:30:48
          Start date:25/11/2021
          Path:/usr/bin/gpu-manager
          Arguments:n/a
          File size:76616 bytes
          MD5 hash:8fae9dd5dd67e1f33d873089c2fd8761

          General

          Start time:18:30:48
          Start date:25/11/2021
          Path:/bin/sh
          Arguments:sh -c "grep -G \"^blacklist.*nouveau[[:space:]]*$\" /lib/modprobe.d/*.conf"
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:18:30:48
          Start date:25/11/2021
          Path:/bin/sh
          Arguments:n/a
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:18:30:48
          Start date:25/11/2021
          Path:/usr/bin/grep
          Arguments:grep -G ^blacklist.*nouveau[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
          File size:199136 bytes
          MD5 hash:1e6ebb9dd094f774478f72727bdba0f5

          General

          Start time:18:30:50
          Start date:25/11/2021
          Path:/usr/lib/systemd/systemd
          Arguments:n/a
          File size:1620224 bytes
          MD5 hash:9b2bec7092a40488108543f9334aab75

          General

          Start time:18:30:50
          Start date:25/11/2021
          Path:/usr/share/gdm/generate-config
          Arguments:/usr/share/gdm/generate-config
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:18:30:50
          Start date:25/11/2021
          Path:/usr/share/gdm/generate-config
          Arguments:n/a
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:18:30:50
          Start date:25/11/2021
          Path:/usr/bin/pkill
          Arguments:pkill --signal HUP --uid gdm dconf-service
          File size:30968 bytes
          MD5 hash:fa96a75a08109d8842e4865b2907d51f

          General

          Start time:18:30:52
          Start date:25/11/2021
          Path:/usr/lib/systemd/systemd
          Arguments:n/a
          File size:1620224 bytes
          MD5 hash:9b2bec7092a40488108543f9334aab75

          General

          Start time:18:30:52
          Start date:25/11/2021
          Path:/usr/lib/gdm3/gdm-wait-for-drm
          Arguments:/usr/lib/gdm3/gdm-wait-for-drm
          File size:14640 bytes
          MD5 hash:82043ba752c6930b4e6aaea2f7747545

          General

          Start time:18:30:55
          Start date:25/11/2021
          Path:/usr/libexec/gvfsd-fuse
          Arguments:n/a
          File size:47632 bytes
          MD5 hash:d18fbf1cbf8eb57b17fac48b7b4be933

          General

          Start time:18:30:55
          Start date:25/11/2021
          Path:/bin/fusermount
          Arguments:fusermount -u -q -z -- /run/user/1000/gvfs
          File size:39144 bytes
          MD5 hash:576a1b135c82bdcbc97a91acea900566

          General

          Start time:18:30:55
          Start date:25/11/2021
          Path:/usr/lib/systemd/systemd
          Arguments:n/a
          File size:1620224 bytes
          MD5 hash:9b2bec7092a40488108543f9334aab75

          General

          Start time:18:30:55
          Start date:25/11/2021
          Path:/lib/systemd/systemd-user-runtime-dir
          Arguments:/lib/systemd/systemd-user-runtime-dir stop 1000
          File size:22672 bytes
          MD5 hash:d55f4b0847f88131dbcfb07435178e54

          General

          Start time:18:31:02
          Start date:25/11/2021
          Path:/usr/lib/systemd/systemd
          Arguments:n/a
          File size:1620224 bytes
          MD5 hash:9b2bec7092a40488108543f9334aab75

          General

          Start time:18:31:02
          Start date:25/11/2021
          Path:/usr/sbin/gdm3
          Arguments:/usr/sbin/gdm3
          File size:453296 bytes
          MD5 hash:2492e2d8d34f9377e3e530a61a15674f

          General

          Start time:18:32:33
          Start date:25/11/2021
          Path:/usr/lib/systemd/systemd
          Arguments:n/a
          File size:1620224 bytes
          MD5 hash:9b2bec7092a40488108543f9334aab75

          General

          Start time:18:32:33
          Start date:25/11/2021
          Path:/usr/bin/gpu-manager
          Arguments:/usr/bin/gpu-manager --log /var/log/gpu-manager.log
          File size:76616 bytes
          MD5 hash:8fae9dd5dd67e1f33d873089c2fd8761

          General

          Start time:18:32:33
          Start date:25/11/2021
          Path:/usr/bin/gpu-manager
          Arguments:n/a
          File size:76616 bytes
          MD5 hash:8fae9dd5dd67e1f33d873089c2fd8761

          General

          Start time:18:32:33
          Start date:25/11/2021
          Path:/bin/sh
          Arguments:sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /etc/modprobe.d/*.conf"
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:18:32:33
          Start date:25/11/2021
          Path:/bin/sh
          Arguments:n/a
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:18:32:33
          Start date:25/11/2021
          Path:/usr/bin/grep
          Arguments:grep -G ^blacklist.*nvidia[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
          File size:199136 bytes
          MD5 hash:1e6ebb9dd094f774478f72727bdba0f5

          General

          Start time:18:32:33
          Start date:25/11/2021
          Path:/usr/bin/gpu-manager
          Arguments:n/a
          File size:76616 bytes
          MD5 hash:8fae9dd5dd67e1f33d873089c2fd8761

          General

          Start time:18:32:33
          Start date:25/11/2021
          Path:/bin/sh
          Arguments:sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /lib/modprobe.d/*.conf"
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:18:32:33
          Start date:25/11/2021
          Path:/bin/sh
          Arguments:n/a
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:18:32:33
          Start date:25/11/2021
          Path:/usr/bin/grep
          Arguments:grep -G ^blacklist.*nvidia[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
          File size:199136 bytes
          MD5 hash:1e6ebb9dd094f774478f72727bdba0f5

          General

          Start time:18:32:33
          Start date:25/11/2021
          Path:/usr/bin/gpu-manager
          Arguments:n/a
          File size:76616 bytes
          MD5 hash:8fae9dd5dd67e1f33d873089c2fd8761

          General

          Start time:18:32:33
          Start date:25/11/2021
          Path:/bin/sh
          Arguments:sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /etc/modprobe.d/*.conf"
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:18:32:33
          Start date:25/11/2021
          Path:/bin/sh
          Arguments:n/a
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:18:32:33
          Start date:25/11/2021
          Path:/usr/bin/grep
          Arguments:grep -G ^blacklist.*radeon[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
          File size:199136 bytes
          MD5 hash:1e6ebb9dd094f774478f72727bdba0f5

          General

          Start time:18:32:34
          Start date:25/11/2021
          Path:/usr/bin/gpu-manager
          Arguments:n/a
          File size:76616 bytes
          MD5 hash:8fae9dd5dd67e1f33d873089c2fd8761

          General

          Start time:18:32:34
          Start date:25/11/2021
          Path:/bin/sh
          Arguments:sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /lib/modprobe.d/*.conf"
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:18:32:34
          Start date:25/11/2021
          Path:/bin/sh
          Arguments:n/a
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:18:32:34
          Start date:25/11/2021
          Path:/usr/bin/grep
          Arguments:grep -G ^blacklist.*radeon[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
          File size:199136 bytes
          MD5 hash:1e6ebb9dd094f774478f72727bdba0f5

          General

          Start time:18:32:34
          Start date:25/11/2021
          Path:/usr/bin/gpu-manager
          Arguments:n/a
          File size:76616 bytes
          MD5 hash:8fae9dd5dd67e1f33d873089c2fd8761

          General

          Start time:18:32:34
          Start date:25/11/2021
          Path:/bin/sh
          Arguments:sh -c "grep -G \"^blacklist.*amdgpu[[:space:]]*$\" /etc/modprobe.d/*.conf"
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:18:32:34
          Start date:25/11/2021
          Path:/bin/sh
          Arguments:n/a
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:18:32:34
          Start date:25/11/2021
          Path:/usr/bin/grep
          Arguments:grep -G ^blacklist.*amdgpu[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
          File size:199136 bytes
          MD5 hash:1e6ebb9dd094f774478f72727bdba0f5

          General

          Start time:18:32:34
          Start date:25/11/2021
          Path:/usr/bin/gpu-manager
          Arguments:n/a
          File size:76616 bytes
          MD5 hash:8fae9dd5dd67e1f33d873089c2fd8761

          General

          Start time:18:32:34
          Start date:25/11/2021
          Path:/bin/sh
          Arguments:sh -c "grep -G \"^blacklist.*amdgpu[[:space:]]*$\" /lib/modprobe.d/*.conf"
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:18:32:34
          Start date:25/11/2021
          Path:/bin/sh
          Arguments:n/a
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:18:32:34
          Start date:25/11/2021
          Path:/usr/bin/grep
          Arguments:grep -G ^blacklist.*amdgpu[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
          File size:199136 bytes
          MD5 hash:1e6ebb9dd094f774478f72727bdba0f5

          General

          Start time:18:32:34
          Start date:25/11/2021
          Path:/usr/bin/gpu-manager
          Arguments:n/a
          File size:76616 bytes
          MD5 hash:8fae9dd5dd67e1f33d873089c2fd8761

          General

          Start time:18:32:34
          Start date:25/11/2021
          Path:/bin/sh
          Arguments:sh -c "grep -G \"^blacklist.*nouveau[[:space:]]*$\" /etc/modprobe.d/*.conf"
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:18:32:35
          Start date:25/11/2021
          Path:/bin/sh
          Arguments:n/a
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:18:32:35
          Start date:25/11/2021
          Path:/usr/bin/grep
          Arguments:grep -G ^blacklist.*nouveau[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
          File size:199136 bytes
          MD5 hash:1e6ebb9dd094f774478f72727bdba0f5

          General

          Start time:18:32:35
          Start date:25/11/2021
          Path:/usr/bin/gpu-manager
          Arguments:n/a
          File size:76616 bytes
          MD5 hash:8fae9dd5dd67e1f33d873089c2fd8761

          General

          Start time:18:32:35
          Start date:25/11/2021
          Path:/bin/sh
          Arguments:sh -c "grep -G \"^blacklist.*nouveau[[:space:]]*$\" /lib/modprobe.d/*.conf"
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:18:32:35
          Start date:25/11/2021
          Path:/bin/sh
          Arguments:n/a
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:18:32:35
          Start date:25/11/2021
          Path:/usr/bin/grep
          Arguments:grep -G ^blacklist.*nouveau[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
          File size:199136 bytes
          MD5 hash:1e6ebb9dd094f774478f72727bdba0f5

          General

          Start time:18:32:35
          Start date:25/11/2021
          Path:/usr/lib/systemd/systemd
          Arguments:n/a
          File size:1620224 bytes
          MD5 hash:9b2bec7092a40488108543f9334aab75

          General

          Start time:18:32:35
          Start date:25/11/2021
          Path:/usr/share/gdm/generate-config
          Arguments:/usr/share/gdm/generate-config
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:18:32:35
          Start date:25/11/2021
          Path:/usr/share/gdm/generate-config
          Arguments:n/a
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          General

          Start time:18:32:35
          Start date:25/11/2021
          Path:/usr/bin/pkill
          Arguments:pkill --signal HUP --uid gdm dconf-service
          File size:30968 bytes
          MD5 hash:fa96a75a08109d8842e4865b2907d51f

          General

          Start time:18:32:37
          Start date:25/11/2021
          Path:/usr/lib/systemd/systemd
          Arguments:n/a
          File size:1620224 bytes
          MD5 hash:9b2bec7092a40488108543f9334aab75

          General

          Start time:18:32:37
          Start date:25/11/2021
          Path:/usr/lib/gdm3/gdm-wait-for-drm
          Arguments:/usr/lib/gdm3/gdm-wait-for-drm
          File size:14640 bytes
          MD5 hash:82043ba752c6930b4e6aaea2f7747545

          General

          Start time:18:32:47
          Start date:25/11/2021
          Path:/usr/lib/systemd/systemd
          Arguments:n/a
          File size:1620224 bytes
          MD5 hash:9b2bec7092a40488108543f9334aab75

          General

          Start time:18:32:47
          Start date:25/11/2021
          Path:/usr/sbin/gdm3
          Arguments:/usr/sbin/gdm3
          File size:453296 bytes
          MD5 hash:2492e2d8d34f9377e3e530a61a15674f