Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
amd64.elf

Overview

General Information

Sample name:amd64.elf
Analysis ID:1543411
MD5:460bfe2f3c4ec8d67282cded7ce12215
SHA1:206da96eeae36e8133c9f459a21244693cf58b73
SHA256:6ee4ae55ebc3cc41ecc3a0f713ef44cd680320bb8ef9916cefc9f88b61ea7724
Tags:elfuser-abuse_ch
Infos:

Detection

Score:48
Range:0 - 100
Whitelisted:false

Signatures

Multi AV Scanner detection for submitted file
Executes the "rm" command used to delete files or directories
Sample has stripped symbol table
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1543411
Start date and time:2024-10-27 20:18:03 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 5m 40s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:amd64.elf
Detection:MAL
Classification:mal48.linELF@0/0@0/0
  • Some HTTP raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
  • VT rate limit hit for: amd64.elf
Command:/tmp/amd64.elf
PID:6264
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:

Standard Error:2024/10/27 14:19:14 Forking
2024/10/27 14:19:14 Connecting to 156.234.42.40:80
2024/10/27 14:19:17 Successfully connnected 156.234.42.40:80
  • system is lnxubuntu20
  • amd64.elf (PID: 6264, Parent: 6187, MD5: 460bfe2f3c4ec8d67282cded7ce12215) Arguments: /tmp/amd64.elf
    • exe (PID: 6269, Parent: 6264, MD5: 460bfe2f3c4ec8d67282cded7ce12215) Arguments: /proc/self/exe
  • dash New Fork (PID: 6276, Parent: 4332)
  • rm (PID: 6276, Parent: 4332, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.81eTWBWmI7 /tmp/tmp.o9DTYjt50x /tmp/tmp.si5gMoxVnA
  • dash New Fork (PID: 6277, Parent: 4332)
  • rm (PID: 6277, Parent: 4332, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.81eTWBWmI7 /tmp/tmp.o9DTYjt50x /tmp/tmp.si5gMoxVnA
  • cleanup
No yara matches
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: amd64.elfReversingLabs: Detection: 15%
Source: unknownTCP traffic detected without corresponding DNS query: 156.234.42.40
Source: unknownTCP traffic detected without corresponding DNS query: 156.234.42.40
Source: unknownTCP traffic detected without corresponding DNS query: 156.234.42.40
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 156.234.42.40
Source: unknownTCP traffic detected without corresponding DNS query: 156.234.42.40
Source: unknownTCP traffic detected without corresponding DNS query: 156.234.42.40
Source: unknownTCP traffic detected without corresponding DNS query: 156.234.42.40
Source: unknownTCP traffic detected without corresponding DNS query: 156.234.42.40
Source: unknownTCP traffic detected without corresponding DNS query: 156.234.42.40
Source: unknownTCP traffic detected without corresponding DNS query: 156.234.42.40
Source: unknownTCP traffic detected without corresponding DNS query: 156.234.42.40
Source: unknownTCP traffic detected without corresponding DNS query: 156.234.42.40
Source: unknownTCP traffic detected without corresponding DNS query: 156.234.42.40
Source: unknownTCP traffic detected without corresponding DNS query: 156.234.42.40
Source: unknownTCP traffic detected without corresponding DNS query: 156.234.42.40
Source: unknownTCP traffic detected without corresponding DNS query: 156.234.42.40
Source: unknownTCP traffic detected without corresponding DNS query: 156.234.42.40
Source: unknownTCP traffic detected without corresponding DNS query: 34.249.145.219
Source: unknownTCP traffic detected without corresponding DNS query: 156.234.42.40
Source: unknownTCP traffic detected without corresponding DNS query: 156.234.42.40
Source: unknownTCP traffic detected without corresponding DNS query: 156.234.42.40
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 156.234.42.40
Source: unknownTCP traffic detected without corresponding DNS query: 156.234.42.40
Source: unknownTCP traffic detected without corresponding DNS query: 156.234.42.40
Source: unknownTCP traffic detected without corresponding DNS query: 156.234.42.40
Source: unknownTCP traffic detected without corresponding DNS query: 156.234.42.40
Source: unknownTCP traffic detected without corresponding DNS query: 156.234.42.40
Source: unknownTCP traffic detected without corresponding DNS query: 156.234.42.40
Source: unknownTCP traffic detected without corresponding DNS query: 156.234.42.40
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 156.234.42.40
Source: unknownTCP traffic detected without corresponding DNS query: 156.234.42.40
Source: unknownTCP traffic detected without corresponding DNS query: 156.234.42.40
Source: unknownTCP traffic detected without corresponding DNS query: 156.234.42.40
Source: unknownTCP traffic detected without corresponding DNS query: 156.234.42.40
Source: unknownTCP traffic detected without corresponding DNS query: 156.234.42.40
Source: unknownTCP traffic detected without corresponding DNS query: 156.234.42.40
Source: unknownTCP traffic detected without corresponding DNS query: 156.234.42.40
Source: unknownTCP traffic detected without corresponding DNS query: 156.234.42.40
Source: unknownTCP traffic detected without corresponding DNS query: 156.234.42.40
Source: unknownTCP traffic detected without corresponding DNS query: 156.234.42.40
Source: unknownTCP traffic detected without corresponding DNS query: 156.234.42.40
Source: unknownTCP traffic detected without corresponding DNS query: 156.234.42.40
Source: unknownTCP traffic detected without corresponding DNS query: 156.234.42.40
Source: unknownTCP traffic detected without corresponding DNS query: 156.234.42.40
Source: unknownTCP traffic detected without corresponding DNS query: 156.234.42.40
Source: unknownTCP traffic detected without corresponding DNS query: 156.234.42.40
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39256
Source: unknownNetwork traffic detected: HTTP traffic on port 39256 -> 443
Source: ELF static info symbol of initial sample.symtab present: no
Source: classification engineClassification label: mal48.linELF@0/0@0/0
Source: ELF file sectionSubmission: amd64.elf
Source: /usr/bin/dash (PID: 6276)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.81eTWBWmI7 /tmp/tmp.o9DTYjt50x /tmp/tmp.si5gMoxVnAJump to behavior
Source: /usr/bin/dash (PID: 6277)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.81eTWBWmI7 /tmp/tmp.o9DTYjt50x /tmp/tmp.si5gMoxVnAJump to behavior
Source: submitted sampleStderr: 2024/10/27 14:19:14 Forking2024/10/27 14:19:14 Connecting to 156.234.42.40:802024/10/27 14:19:17 Successfully connnected 156.234.42.40:80: exit code = 0
Source: /proc/self/exe (PID: 6269)Queries kernel information via 'uname': Jump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
File Deletion
OS Credential Dumping1
Security Software Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1543411 Sample: amd64.elf Startdate: 27/10/2024 Architecture: LINUX Score: 48 15 156.234.42.40, 47284, 80 XIAOZHIYUN1-AS-APICIDCNETWORKUS Seychelles 2->15 17 109.202.202.202, 80 INIT7CH Switzerland 2->17 19 2 other IPs or domains 2->19 21 Multi AV Scanner detection for submitted file 2->21 7 amd64.elf 2->7         started        9 dash rm 2->9         started        11 dash rm 2->11         started        signatures3 process4 process5 13 amd64.elf exe 7->13         started       

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
amd64.elf16%ReversingLabsLinux.Hacktool.RevhellMarte
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs
IPDomainCountryFlagASNASN NameMalicious
34.249.145.219
unknownUnited States
16509AMAZON-02USfalse
156.234.42.40
unknownSeychelles
136800XIAOZHIYUN1-AS-APICIDCNETWORKUSfalse
109.202.202.202
unknownSwitzerland
13030INIT7CHfalse
91.189.91.42
unknownUnited Kingdom
41231CANONICAL-ASGBfalse
MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
34.249.145.219mpsl.elfGet hashmaliciousUnknownBrowse
    nklarm6.elfGet hashmaliciousUnknownBrowse
      bot.m68k.elfGet hashmaliciousMirai, OkiruBrowse
        YIztve8dU8.elfGet hashmaliciousMiraiBrowse
          bot.x86_64.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
            boatnet.arm7.elfGet hashmaliciousMiraiBrowse
              x.rar.elfGet hashmaliciousUnknownBrowse
                Demon.arm4.elfGet hashmaliciousGafgyt, MiraiBrowse
                  la.bot.arm7.elfGet hashmaliciousUnknownBrowse
                    i.elfGet hashmaliciousMiraiBrowse
                      109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
                      • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
                      91.189.91.42.i.elfGet hashmaliciousUnknownBrowse
                        na.elfGet hashmaliciousUnknownBrowse
                          parm6.elfGet hashmaliciousUnknownBrowse
                            debug.dbg.elfGet hashmaliciousMiraiBrowse
                              na.elfGet hashmaliciousUnknownBrowse
                                arm5.elfGet hashmaliciousUnknownBrowse
                                  linux_amd64.elfGet hashmaliciousChaosBrowse
                                    linux_mips_softfloat.elfGet hashmaliciousChaosBrowse
                                      linux_mips64_softfloat.elfGet hashmaliciousChaosBrowse
                                        tftp.elfGet hashmaliciousUnknownBrowse
                                          No context
                                          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                          CANONICAL-ASGB.i.elfGet hashmaliciousUnknownBrowse
                                          • 91.189.91.42
                                          na.elfGet hashmaliciousUnknownBrowse
                                          • 91.189.91.42
                                          parm6.elfGet hashmaliciousUnknownBrowse
                                          • 91.189.91.42
                                          debug.dbg.elfGet hashmaliciousMiraiBrowse
                                          • 91.189.91.42
                                          na.elfGet hashmaliciousUnknownBrowse
                                          • 91.189.91.42
                                          arm5.elfGet hashmaliciousUnknownBrowse
                                          • 91.189.91.42
                                          linux_amd64.elfGet hashmaliciousChaosBrowse
                                          • 91.189.91.42
                                          linux_mips_softfloat.elfGet hashmaliciousChaosBrowse
                                          • 91.189.91.42
                                          linux_mips64_softfloat.elfGet hashmaliciousChaosBrowse
                                          • 91.189.91.42
                                          tftp.elfGet hashmaliciousUnknownBrowse
                                          • 91.189.91.42
                                          INIT7CH.i.elfGet hashmaliciousUnknownBrowse
                                          • 109.202.202.202
                                          na.elfGet hashmaliciousUnknownBrowse
                                          • 109.202.202.202
                                          parm6.elfGet hashmaliciousUnknownBrowse
                                          • 109.202.202.202
                                          debug.dbg.elfGet hashmaliciousMiraiBrowse
                                          • 109.202.202.202
                                          na.elfGet hashmaliciousUnknownBrowse
                                          • 109.202.202.202
                                          arm5.elfGet hashmaliciousUnknownBrowse
                                          • 109.202.202.202
                                          linux_amd64.elfGet hashmaliciousChaosBrowse
                                          • 109.202.202.202
                                          linux_mips_softfloat.elfGet hashmaliciousChaosBrowse
                                          • 109.202.202.202
                                          linux_mips64_softfloat.elfGet hashmaliciousChaosBrowse
                                          • 109.202.202.202
                                          tftp.elfGet hashmaliciousUnknownBrowse
                                          • 109.202.202.202
                                          XIAOZHIYUN1-AS-APICIDCNETWORKUSmips.elfGet hashmaliciousUnknownBrowse
                                          • 156.253.103.110
                                          botnet.arm7.elfGet hashmaliciousMirai, MoobotBrowse
                                          • 156.234.199.252
                                          OREN Engine Stores Requisition 4th quarter OREN-ES-2024-010 & OREN-ES-2024-011.exeGet hashmaliciousFormBookBrowse
                                          • 156.234.28.94
                                          garm7.elfGet hashmaliciousMiraiBrowse
                                          • 156.234.199.242
                                          nsharm5.elfGet hashmaliciousMiraiBrowse
                                          • 156.226.225.200
                                          garm7.elfGet hashmaliciousMiraiBrowse
                                          • 156.241.59.10
                                          la.bot.sh4.elfGet hashmaliciousUnknownBrowse
                                          • 103.120.27.179
                                          la.bot.arm.elfGet hashmaliciousUnknownBrowse
                                          • 103.43.15.119
                                          armv4l.elfGet hashmaliciousUnknownBrowse
                                          • 23.235.167.118
                                          m68k.elfGet hashmaliciousUnknownBrowse
                                          • 154.210.135.159
                                          AMAZON-02USparm6.elfGet hashmaliciousUnknownBrowse
                                          • 54.171.230.55
                                          SecuriteInfo.com.Win64.Malware-gen.13500.20938.exeGet hashmaliciousPython Stealer, Exela StealerBrowse
                                          • 45.112.123.227
                                          file.exeGet hashmaliciousStealc, VidarBrowse
                                          • 3.168.2.115
                                          x86.elfGet hashmaliciousMirai, MoobotBrowse
                                          • 108.152.61.228
                                          x86_64.elfGet hashmaliciousMirai, MoobotBrowse
                                          • 157.175.218.20
                                          hidakibest.arm7.elfGet hashmaliciousGafgyt, MiraiBrowse
                                          • 54.247.62.1
                                          hidakibest.sparc.elfGet hashmaliciousGafgyt, MiraiBrowse
                                          • 34.243.160.129
                                          la.bot.arm.elfGet hashmaliciousUnknownBrowse
                                          • 63.33.134.59
                                          splmpsl.elfGet hashmaliciousUnknownBrowse
                                          • 13.253.106.222
                                          nabarm7.elfGet hashmaliciousUnknownBrowse
                                          • 3.120.49.213
                                          No context
                                          No context
                                          No created / dropped files found
                                          File type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, Go BuildID=5HrN8z8RLXAJS5wwqZwt/YbeArWA_BB4FZrMpgoTi/JqviPRvD9-5yOCGlxBmi/uq7pzT7WXGwu4bZ097mg, stripped
                                          Entropy (8bit):6.149775708920118
                                          TrID:
                                          • ELF Executable and Linkable format (Linux) (4029/14) 49.77%
                                          • ELF Executable and Linkable format (generic) (4004/1) 49.46%
                                          • Lumena CEL bitmap (63/63) 0.78%
                                          File name:amd64.elf
                                          File size:8'876'184 bytes
                                          MD5:460bfe2f3c4ec8d67282cded7ce12215
                                          SHA1:206da96eeae36e8133c9f459a21244693cf58b73
                                          SHA256:6ee4ae55ebc3cc41ecc3a0f713ef44cd680320bb8ef9916cefc9f88b61ea7724
                                          SHA512:d89f32d4a2929d0000b8729f430abe4a4f131c934c16757b242a7a2ebdd5c178443f9d4616a2c3bcfd48679601404ab62ca7d5531e7fd9c4d661dbf099050380
                                          SSDEEP:98304:2b6jIMC9bXHFx8SeFu8Y4ASgS5rEkCG78/mCW+:2L956SeQ4Ar9ki
                                          TLSH:3E963947ECA104E4C0ADD63085629262BFB27C895B3477D72B90B72C3FB6BD0AA75750
                                          File Content Preview:.ELF..............>.....@.F.....@...................@.8...@.............@.......@.@.....@.@.....P.......P.................................@.......@.....d.......d.................................@.......@......1<......1<......................@<......@|....

                                          ELF header

                                          Class:ELF64
                                          Data:2's complement, little endian
                                          Version:1 (current)
                                          Machine:Advanced Micro Devices X86-64
                                          Version Number:0x1
                                          Type:EXEC (Executable file)
                                          OS/ABI:UNIX - System V
                                          ABI Version:0
                                          Entry Point Address:0x46e840
                                          Flags:0x0
                                          ELF Header Size:64
                                          Program Header Offset:64
                                          Program Header Size:56
                                          Number of Program Headers:6
                                          Section Header Offset:400
                                          Section Header Size:64
                                          Number of Section Headers:14
                                          Header String Table Index:13
                                          NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                          NULL0x00x00x00x00x0000
                                          .textPROGBITS0x4010000x10000x3c21950x00x6AX0032
                                          .rodataPROGBITS0x7c40000x3c40000x1dfa8e0x00x2A0032
                                          .typelinkPROGBITS0x9a3aa00x5a3aa00x31140x00x2A0032
                                          .itablinkPROGBITS0x9a6bc00x5a6bc00x1ef80x00x2A0032
                                          .gosymtabPROGBITS0x9a8ab80x5a8ab80x00x00x2A001
                                          .gopclntabPROGBITS0x9a8ac00x5a8ac00x28c0180x00x2A0032
                                          .go.buildinfoPROGBITS0xc350000x8350000x5800x00x3WA0016
                                          .noptrdataPROGBITS0xc355800x8355800x30a420x00x3WA0032
                                          .dataPROGBITS0xc65fe00x865fe00x10bb00x00x3WA0032
                                          .bssNOBITS0xc76ba00x876ba00x627500x00x3WA0032
                                          .noptrbssNOBITS0xcd93000x8d93000xe4700x00x3WA0032
                                          .note.go.buildidNOTE0x400f9c0xf9c0x640x00x2A004
                                          .shstrtabSTRTAB0x00x8770000x980x00x0001
                                          TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                          PHDR0x400x4000400x4000400x1500x1501.69220x4R 0x1000
                                          NOTE0xf9c0x400f9c0x400f9c0x640x645.29820x4R 0x4.note.go.buildid
                                          LOAD0x00x4000000x4000000x3c31950x3c31956.13550x5R E0x1000.text .note.go.buildid
                                          LOAD0x3c40000x7c40000x7c40000x470ad80x470ad85.60900x4R 0x1000.rodata .typelink .itablink .gosymtab .gopclntab
                                          LOAD0x8350000xc350000xc350000x41ba00xb27705.13650x6RW 0x1000.go.buildinfo .noptrdata .data .bss .noptrbss
                                          GNU_STACK0x00x00x00x00x00.00000x6RW 0x8
                                          TimestampSource PortDest PortSource IPDest IP
                                          Oct 27, 2024 20:19:15.979701996 CET4728480192.168.2.23156.234.42.40
                                          Oct 27, 2024 20:19:15.985588074 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:19:15.985663891 CET4728480192.168.2.23156.234.42.40
                                          Oct 27, 2024 20:19:15.986895084 CET4728480192.168.2.23156.234.42.40
                                          Oct 27, 2024 20:19:15.992415905 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:19:16.570689917 CET43928443192.168.2.2391.189.91.42
                                          Oct 27, 2024 20:19:16.947041988 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:19:16.947298050 CET4728480192.168.2.23156.234.42.40
                                          Oct 27, 2024 20:19:16.947329998 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:19:16.947401047 CET4728480192.168.2.23156.234.42.40
                                          Oct 27, 2024 20:19:17.005073071 CET4728480192.168.2.23156.234.42.40
                                          Oct 27, 2024 20:19:17.009911060 CET4728480192.168.2.23156.234.42.40
                                          Oct 27, 2024 20:19:17.010440111 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:19:17.015388966 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:19:17.314460039 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:19:17.314632893 CET4728480192.168.2.23156.234.42.40
                                          Oct 27, 2024 20:19:17.319303989 CET4728480192.168.2.23156.234.42.40
                                          Oct 27, 2024 20:19:17.323739052 CET4728480192.168.2.23156.234.42.40
                                          Oct 27, 2024 20:19:17.324985027 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:19:17.329458952 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:19:17.627741098 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:19:17.628057957 CET4728480192.168.2.23156.234.42.40
                                          Oct 27, 2024 20:19:17.631789923 CET4728480192.168.2.23156.234.42.40
                                          Oct 27, 2024 20:19:17.637244940 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:19:17.935740948 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:19:17.935950041 CET4728480192.168.2.23156.234.42.40
                                          Oct 27, 2024 20:19:17.939918041 CET4728480192.168.2.23156.234.42.40
                                          Oct 27, 2024 20:19:17.945765972 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:19:18.244457006 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:19:18.248362064 CET4728480192.168.2.23156.234.42.40
                                          Oct 27, 2024 20:19:18.253936052 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:19:18.552531004 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:19:18.552735090 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:19:18.553949118 CET4728480192.168.2.23156.234.42.40
                                          Oct 27, 2024 20:19:18.558787107 CET4728480192.168.2.23156.234.42.40
                                          Oct 27, 2024 20:19:18.564136028 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:19:18.933782101 CET4433925634.249.145.219192.168.2.23
                                          Oct 27, 2024 20:19:18.934103966 CET39256443192.168.2.2334.249.145.219
                                          Oct 27, 2024 20:19:18.940601110 CET4433925634.249.145.219192.168.2.23
                                          Oct 27, 2024 20:19:23.863218069 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:19:23.866970062 CET4728480192.168.2.23156.234.42.40
                                          Oct 27, 2024 20:19:23.872391939 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:19:29.170975924 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:19:29.176151037 CET4728480192.168.2.23156.234.42.40
                                          Oct 27, 2024 20:19:29.181624889 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:19:34.480731964 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:19:34.489434004 CET4728480192.168.2.23156.234.42.40
                                          Oct 27, 2024 20:19:34.495136023 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:19:35.768062115 CET4251680192.168.2.23109.202.202.202
                                          Oct 27, 2024 20:19:37.815826893 CET43928443192.168.2.2391.189.91.42
                                          Oct 27, 2024 20:19:39.795120955 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:19:39.801372051 CET4728480192.168.2.23156.234.42.40
                                          Oct 27, 2024 20:19:39.807457924 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:19:45.111067057 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:19:45.115282059 CET4728480192.168.2.23156.234.42.40
                                          Oct 27, 2024 20:19:45.120654106 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:19:50.419955969 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:19:50.425484896 CET4728480192.168.2.23156.234.42.40
                                          Oct 27, 2024 20:19:50.432473898 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:19:55.732363939 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:19:55.738223076 CET4728480192.168.2.23156.234.42.40
                                          Oct 27, 2024 20:19:55.743808985 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:20:01.044022083 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:20:01.051336050 CET4728480192.168.2.23156.234.42.40
                                          Oct 27, 2024 20:20:01.056803942 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:20:06.355689049 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:20:06.362624884 CET4728480192.168.2.23156.234.42.40
                                          Oct 27, 2024 20:20:06.375228882 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:20:11.673441887 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:20:11.681526899 CET4728480192.168.2.23156.234.42.40
                                          Oct 27, 2024 20:20:11.692600965 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:20:16.992574930 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:20:17.000276089 CET4728480192.168.2.23156.234.42.40
                                          Oct 27, 2024 20:20:17.012921095 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:20:18.770003080 CET43928443192.168.2.2391.189.91.42
                                          Oct 27, 2024 20:20:22.312519073 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:20:22.320111990 CET4728480192.168.2.23156.234.42.40
                                          Oct 27, 2024 20:20:22.328388929 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:20:27.627552032 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:20:27.633295059 CET4728480192.168.2.23156.234.42.40
                                          Oct 27, 2024 20:20:27.642999887 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:20:32.941436052 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:20:32.947277069 CET4728480192.168.2.23156.234.42.40
                                          Oct 27, 2024 20:20:32.961118937 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:20:38.261164904 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:20:38.266890049 CET4728480192.168.2.23156.234.42.40
                                          Oct 27, 2024 20:20:38.280046940 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:20:43.586815119 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:20:43.592984915 CET4728480192.168.2.23156.234.42.40
                                          Oct 27, 2024 20:20:43.605634928 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:20:48.906358957 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:20:48.910468102 CET4728480192.168.2.23156.234.42.40
                                          Oct 27, 2024 20:20:48.922522068 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:20:54.221957922 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:20:54.230865955 CET4728480192.168.2.23156.234.42.40
                                          Oct 27, 2024 20:20:54.241355896 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:20:59.540066957 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:20:59.548432112 CET4728480192.168.2.23156.234.42.40
                                          Oct 27, 2024 20:20:59.562292099 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:21:04.862875938 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:21:04.868472099 CET4728480192.168.2.23156.234.42.40
                                          Oct 27, 2024 20:21:04.877113104 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:21:10.180104017 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:21:10.185981035 CET4728480192.168.2.23156.234.42.40
                                          Oct 27, 2024 20:21:10.193984985 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:21:15.492564917 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:21:15.496541023 CET4728480192.168.2.23156.234.42.40
                                          Oct 27, 2024 20:21:15.505809069 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:21:20.806989908 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:21:20.814822912 CET4728480192.168.2.23156.234.42.40
                                          Oct 27, 2024 20:21:20.824500084 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:21:26.123961926 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:21:26.132249117 CET4728480192.168.2.23156.234.42.40
                                          Oct 27, 2024 20:21:26.137777090 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:21:31.436824083 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:21:31.442310095 CET4728480192.168.2.23156.234.42.40
                                          Oct 27, 2024 20:21:31.447700977 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:21:36.746355057 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:21:36.752669096 CET4728480192.168.2.23156.234.42.40
                                          Oct 27, 2024 20:21:36.758184910 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:21:42.056375980 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:21:42.064810991 CET4728480192.168.2.23156.234.42.40
                                          Oct 27, 2024 20:21:42.070233107 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:21:47.369466066 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:21:47.377810001 CET4728480192.168.2.23156.234.42.40
                                          Oct 27, 2024 20:21:47.384403944 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:21:52.688469887 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:21:52.692603111 CET4728480192.168.2.23156.234.42.40
                                          Oct 27, 2024 20:21:52.700001001 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:21:57.999087095 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:21:58.007428885 CET4728480192.168.2.23156.234.42.40
                                          Oct 27, 2024 20:21:58.013149023 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:22:03.312458992 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:22:03.316643000 CET4728480192.168.2.23156.234.42.40
                                          Oct 27, 2024 20:22:03.322031975 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:22:08.849164009 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:22:08.850135088 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:22:08.850172997 CET4728480192.168.2.23156.234.42.40
                                          Oct 27, 2024 20:22:08.853240967 CET4728480192.168.2.23156.234.42.40
                                          Oct 27, 2024 20:22:08.858731985 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:22:14.157617092 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:22:14.157855034 CET4728480192.168.2.23156.234.42.40
                                          Oct 27, 2024 20:22:14.163192034 CET4728480192.168.2.23156.234.42.40
                                          Oct 27, 2024 20:22:14.168476105 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:22:19.467905998 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:22:19.468214989 CET4728480192.168.2.23156.234.42.40
                                          Oct 27, 2024 20:22:19.474610090 CET4728480192.168.2.23156.234.42.40
                                          Oct 27, 2024 20:22:19.480129957 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:22:24.779839993 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:22:24.789163113 CET4728480192.168.2.23156.234.42.40
                                          Oct 27, 2024 20:22:24.794692039 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:22:30.179282904 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:22:30.188332081 CET4728480192.168.2.23156.234.42.40
                                          Oct 27, 2024 20:22:30.193707943 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:22:35.493220091 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:22:35.500065088 CET4728480192.168.2.23156.234.42.40
                                          Oct 27, 2024 20:22:35.505774021 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:22:40.805279970 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:22:40.814157963 CET4728480192.168.2.23156.234.42.40
                                          Oct 27, 2024 20:22:40.821182966 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:22:46.120927095 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:22:46.128353119 CET4728480192.168.2.23156.234.42.40
                                          Oct 27, 2024 20:22:46.133924007 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:22:51.433274031 CET8047284156.234.42.40192.168.2.23
                                          Oct 27, 2024 20:22:51.442158937 CET4728480192.168.2.23156.234.42.40
                                          Oct 27, 2024 20:22:51.447596073 CET8047284156.234.42.40192.168.2.23
                                          Session IDSource IPSource PortDestination IPDestination Port
                                          0192.168.2.2347284156.234.42.4080
                                          TimestampBytes transferredDirectionData
                                          Oct 27, 2024 20:19:15.986895084 CET47OUTData Raw: 53 53 48 2d 76 32 2e 35 2e 35 2d 32 2d 67 65 37 63 35 32 65 35 2d 6c 69 6e 75 78 5f 61 6d 64 36 34 0d 0a
                                          Data Ascii: SSH-v2.5.5-2-ge7c52e5-linux_amd64
                                          Oct 27, 2024 20:19:16.947041988 CET33INData Raw: 53 53 48 2d 32 2e 30 2d 4f 70 65 6e 53 53 48 5f 38 2e 30 0d 0a
                                          Data Ascii: SSH-2.0-OpenSSH_8.0
                                          Oct 27, 2024 20:19:16.947329998 CET732INData Raw: 00 00 02 cc 08 14 ce 33 e4 fb de 03 56 9f 37 54 38 7c b3 09 a9 0a 00 00 00 be 63 75 72 76 65 32 35 35 31 39 2d 73 68 61 32 35 36 2c 63 75 72 76 65 32 35 35 31 39 2d 73 68 61 32 35 36 40 6c 69 62 73 73 68 2e 6f 72 67 2c 65 63 64 68 2d 73 68 61 32
                                          Data Ascii: 3V7T8|curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group14-sha256,diffie-hellman-group14-sha1,kex-strict-s-v00@openssh.comssh-ed25519laes128-g
                                          Oct 27, 2024 20:19:17.005073071 CET1132OUTData Raw: 00 00 04 5c 0d 14 31 33 0c 0c d8 69 8d ef ce f4 97 72 4a f4 ed 19 00 00 00 c9 63 75 72 76 65 32 35 35 31 39 2d 73 68 61 32 35 36 2c 63 75 72 76 65 32 35 35 31 39 2d 73 68 61 32 35 36 40 6c 69 62 73 73 68 2e 6f 72 67 2c 65 63 64 68 2d 73 68 61 32
                                          Data Ascii: \13irJcurve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group14-sha256,diffie-hellman-group14-sha1,ext-info-c,kex-strict-c-v00@openssh.comrsa-sha2-256
                                          Oct 27, 2024 20:19:17.009911060 CET60OUTData Raw: 00 00 00 2c 06 1e 00 00 00 20 83 2a 30 e4 3a e5 26 0c da 82 85 4e e3 d2 cc 2b 1c 01 30 af 84 97 63 26 82 f4 ef 9c 44 53 02 1e 87 fe 07 0f 57 36
                                          Data Ascii: , *0:&N+0c&DSW6
                                          Oct 27, 2024 20:19:17.314460039 CET480INData Raw: 00 00 00 bc 08 1f 00 00 00 33 00 00 00 0b 73 73 68 2d 65 64 32 35 35 31 39 00 00 00 20 f5 c3 ed ff 63 d4 4f 9d 51 17 65 b5 f6 9c 89 43 cb 76 0c 8d 21 e3 f6 cb cf 8c 81 69 4e 43 26 53 00 00 00 20 b1 ce 74 25 54 bd 2e 02 f5 e2 8a f9 92 93 bd d3 0f
                                          Data Ascii: 3ssh-ed25519 cOQeCv!iNC&S t%T.=&1ca?\Sssh-ed25519@+~(Dp*&Q-SX_l4cskAxag(:ADL=%'mIJ}.0c&9NfV|z[
                                          Oct 27, 2024 20:19:17.319303989 CET28OUTData Raw: 00 00 00 0c 0a 15 34 07 b7 d2 5e 67 e4 b5 d9 65
                                          Data Ascii: 4^ge
                                          Oct 27, 2024 20:19:17.323739052 CET64OUTData Raw: 00 00 00 20 45 4e 0c a3 61 7f 70 77 0d 46 67 8f d3 ed bd 51 d1 59 18 cf ef 02 de c4 33 7a 0b 88 e0 74 87 98 d1 78 a2 57 8f 76 73 e3 4b 23 31 49 d5 82 00 48
                                          Data Ascii: ENapwFgQY3ztxWvsK#1IH
                                          Oct 27, 2024 20:19:17.627741098 CET64INData Raw: 00 00 00 20 f9 7c 4e 17 9c 4e 68 3d e0 d6 53 cb 61 e9 a7 f6 7e 45 b4 bc 80 e4 0d 8c 04 76 34 16 01 fc 2d 2b fa f4 c2 04 96 bd 07 f7 5d 1e 36 ef e5 85 45 99
                                          Data Ascii: |NNh=Sa~Ev4-+]6E
                                          Oct 27, 2024 20:19:17.631789923 CET96OUTData Raw: 00 00 00 40 e9 45 e0 88 41 52 8e de 74 34 53 cb 0d 69 1d d9 c2 ef 78 f3 50 1d da be 3f 53 8a 03 be b5 fb 86 29 a3 91 ad e0 a2 04 52 bd 10 e1 d4 c3 a2 f2 32 26 5e 8a a9 cd 5c 98 c7 8d 54 cd cb c0 7a bf 5c d4 81 bc fc ea 03 5e d8 2a 1e 63 be 42 2e
                                          Data Ascii: @EARt4SixP?S)R2&^\Tz\^*cB.IK


                                          System Behavior

                                          Start time (UTC):19:19:14
                                          Start date (UTC):27/10/2024
                                          Path:/tmp/amd64.elf
                                          Arguments:/tmp/amd64.elf
                                          File size:8876184 bytes
                                          MD5 hash:460bfe2f3c4ec8d67282cded7ce12215

                                          Start time (UTC):19:19:14
                                          Start date (UTC):27/10/2024
                                          Path:/tmp/amd64.elf
                                          Arguments:-
                                          File size:8876184 bytes
                                          MD5 hash:460bfe2f3c4ec8d67282cded7ce12215

                                          Start time (UTC):19:19:14
                                          Start date (UTC):27/10/2024
                                          Path:/proc/self/exe
                                          Arguments:/proc/self/exe
                                          File size:8876184 bytes
                                          MD5 hash:460bfe2f3c4ec8d67282cded7ce12215

                                          Start time (UTC):19:19:17
                                          Start date (UTC):27/10/2024
                                          Path:/usr/bin/dash
                                          Arguments:-
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                          Start time (UTC):19:19:17
                                          Start date (UTC):27/10/2024
                                          Path:/usr/bin/rm
                                          Arguments:rm -f /tmp/tmp.81eTWBWmI7 /tmp/tmp.o9DTYjt50x /tmp/tmp.si5gMoxVnA
                                          File size:72056 bytes
                                          MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                          Start time (UTC):19:19:17
                                          Start date (UTC):27/10/2024
                                          Path:/usr/bin/dash
                                          Arguments:-
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                          Start time (UTC):19:19:17
                                          Start date (UTC):27/10/2024
                                          Path:/usr/bin/rm
                                          Arguments:rm -f /tmp/tmp.81eTWBWmI7 /tmp/tmp.o9DTYjt50x /tmp/tmp.si5gMoxVnA
                                          File size:72056 bytes
                                          MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b