Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
bluefish-data_2.2.12-1.1_all(1).deb

Overview

General Information

Sample name:bluefish-data_2.2.12-1.1_all(1).deb
Analysis ID:1543714
MD5:f3b0147686843cf4b09551c626bdd77d
SHA1:4f9f4570ba5e21f859744b4f20122b30235dfb02
SHA256:1e6b6f39d9384307e8110aafcaa9323412abf9084391448b2b10b5c0c19527b7
Infos:

Detection

Score:3
Range:0 - 100
Whitelisted:false

Signatures

Creates hidden files and/or directories
Executes the "rm" command used to delete files or directories
Reads the 'hosts' file potentially containing internal network hosts
Sample tries to set the executable flag
Tries to resolve domain names, but no domain seems valid (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1543714
Start date and time:2024-10-28 09:50:08 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 6m 14s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 16.04 x64 (Kernel 4.4.0-116, Firefox 88.0, Document Viewer 3.18.2, LibreOffice 5.1.6.2, OpenJDK 1.8.0_171)
Analysis Mode:default
Sample name:bluefish-data_2.2.12-1.1_all(1).deb
Detection:CLEAN
Classification:clean3.linDEB@0/7@8/0
  • Excluded IPs from analysis (whitelisted): 185.125.188.54, 185.125.188.55, 185.125.188.59, 185.125.188.58
  • Excluded domains from analysis (whitelisted): api.snapcraft.io
  • VT rate limit hit for: bluefish-data_2.2.12-1.1_all(1).deb
Command:xdg-open "/tmp/bluefish-data_2.2.12-1.1_all(1).deb"
PID:4686
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:

Standard Error:(gnome-software:4772): GsPlugin-WARNING **: could not lookup cached macaroon: Error calling StartServiceByName for org.freedesktop.secrets: Timeout was reached

(gnome-software:4772): IBUS-WARNING **: The owner of /home/james/.config/ibus/bus is not root!

(gnome-software:4772): GsPlugin-WARNING **: Failed to get Ubuntu review statistics: Got status code Cannot resolve hostname from reviews.ubuntu.com
  • system is lnxubuntu1
  • exo-open (PID: 4746, Parent: 4686, MD5: 39c5fa78f1cb3d950b9944f784018d3a) Arguments: exo-open /tmp/bluefish-data_2.2.12-1.1_all(1).deb
    • exo-open New Fork (PID: 4754, Parent: 4746)
    • dbus-launch (PID: 4754, Parent: 4746, MD5: e4a469f27d130d783c21ce9c1c4456c3) Arguments: dbus-launch --autolaunch=11ced2f07072c6ae389b731c5cc84014 --binary-syntax --close-stderr
    • exo-open New Fork (PID: 4767, Parent: 4746)
      • exo-open New Fork (PID: 4772, Parent: 4767)
      • gnome-software (PID: 4772, Parent: 1656, MD5: 8676fce47b3f3e8c729aaaa8c935c235) Arguments: gnome-software --local-filename=/tmp/bluefish-data_2.2.12-1.1_all(1).deb
        • dbus-launch (PID: 4789, Parent: 4772, MD5: e4a469f27d130d783c21ce9c1c4456c3) Arguments: dbus-launch --autolaunch=11ced2f07072c6ae389b731c5cc84014 --binary-syntax --close-stderr
        • dpkg-deb (PID: 4945, Parent: 4772, MD5: 6833acbbb76db8e5a5f14dd5073929af) Arguments: /usr/bin/dpkg-deb --showformat=${Package}\\n${Version}\\n${Installed-Size}\\n${Homepage}\\n${Description} -W /tmp/bluefish-data_2.2.12-1.1_all(1).deb
          • dpkg-deb New Fork (PID: 4946, Parent: 4945)
          • dpkg-deb New Fork (PID: 4947, Parent: 4945)
          • dpkg-deb New Fork (PID: 4948, Parent: 4945)
          • tar (PID: 4948, Parent: 4945, MD5: dbc4507f4db5b41f7358b28bce65a15d) Arguments: tar -x -m -f - --warning=no-timestamp
          • dpkg-deb New Fork (PID: 4976, Parent: 4945)
          • rm (PID: 4976, Parent: 4945, MD5: b79876063d894c449856cca508ecca7f) Arguments: rm -rf -- /tmp/dpkg-deb.YO0WnW
        • dpkg (PID: 5004, Parent: 4772, MD5: 7084d55d63a41425e1a2c1adcced4f14) Arguments: /usr/bin/dpkg --print-foreign-architectures
        • dpkg (PID: 5005, Parent: 4772, MD5: 7084d55d63a41425e1a2c1adcced4f14) Arguments: /usr/bin/dpkg --print-foreign-architectures
  • systemd New Fork (PID: 4887, Parent: 1)
  • fwupd (PID: 4887, Parent: 1, MD5: 4d2507b12cd401bed306a719c3c7b863) Arguments: /usr/lib/x86_64-linux-gnu/fwupd/fwupd
  • cleanup
No yara matches
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: /usr/bin/gnome-software (PID: 4772)Reads hosts file: /etc/hostsJump to behavior
Source: unknownDNS traffic detected: query: reviews.ubuntu.com replaycode: Name error (3)
Source: global trafficDNS traffic detected: DNS query: reviews.ubuntu.com
Source: control.59.drString found in binary or memory: http://bluefish.openoffice.nl
Source: classification engineClassification label: clean3.linDEB@0/7@8/0
Source: /usr/bin/exo-open (PID: 4746)Directory: /home/james/.XauthorityJump to behavior
Source: /usr/bin/exo-open (PID: 4746)Directory: /home/james/.cacheJump to behavior
Source: /usr/bin/dbus-launch (PID: 4754)Directory: /home/james/.XauthorityJump to behavior
Source: /usr/bin/gnome-software (PID: 4772)Directory: /home/james/.XauthorityJump to behavior
Source: /usr/bin/gnome-software (PID: 4772)Directory: /home/james/.XauthorityJump to behavior
Source: /usr/bin/gnome-software (PID: 4772)Directory: /home/james/.Xdefaults-ubuntuJump to behavior
Source: /usr/bin/gnome-software (PID: 4772)Directory: /home/james/.cacheJump to behavior
Source: /usr/bin/dbus-launch (PID: 4789)Directory: /home/james/.XauthorityJump to behavior
Source: /bin/tar (PID: 4948)Directory: ./.Jump to behavior
Source: /usr/bin/dpkg (PID: 5004)Directory: /home/james/.dpkg.cfgJump to behavior
Source: /usr/bin/dpkg (PID: 5005)Directory: /home/james/.dpkg.cfgJump to behavior
Source: /usr/lib/x86_64-linux-gnu/fwupd/fwupd (PID: 4887)Directory: /root/.cacheJump to behavior
Source: /usr/bin/dpkg-deb (PID: 4976)Rm executable: /bin/rm -> rm -rf -- /tmp/dpkg-deb.YO0WnWJump to behavior
Source: /bin/tar (PID: 4948)File: ./. (bits: - usr: rx grp: rx all: rwx)Jump to behavior
Source: submitted sampleStderr: (gnome-software:4772): GsPlugin-WARNING **: could not lookup cached macaroon: Error calling StartServiceByName for org.freedesktop.secrets: Timeout was reached(gnome-software:4772): IBUS-WARNING **: The owner of /home/james/.config/ibus/bus is not root!(gnome-software:4772): GsPlugin-WARNING **: Failed to get Ubuntu review statistics: Got status code Cannot resolve hostname from reviews.ubuntu.com: exit code = 0
Source: /usr/bin/exo-open (PID: 4746)Queries kernel information via 'uname': Jump to behavior
Source: /usr/bin/dbus-launch (PID: 4754)Queries kernel information via 'uname': Jump to behavior
Source: /usr/bin/gnome-software (PID: 4772)Queries kernel information via 'uname': Jump to behavior
Source: /usr/bin/dbus-launch (PID: 4789)Queries kernel information via 'uname': Jump to behavior
Source: /usr/lib/x86_64-linux-gnu/fwupd/fwupd (PID: 4887)Queries kernel information via 'uname': Jump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
File and Directory Permissions Modification
OS Credential Dumping1
Security Software Discovery
Remote ServicesData from Local System1
Non-Application Layer Protocol
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Hidden Files and Directories
LSASS Memory1
File and Directory Discovery
Remote Desktop ProtocolData from Removable Media1
Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
File Deletion
Security Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveSteganographyAutomated ExfiltrationData Encrypted for Impact
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1543714 Sample: bluefish-data_2.2.12-1.1_al... Startdate: 28/10/2024 Architecture: LINUX Score: 3 35 reviews.ubuntu.com 2->35 9 exo-open 2->9         started        11 systemd fwupd 2->11         started        process3 process4 13 exo-open 9->13         started        15 exo-open dbus-launch 9->15         started        process5 17 exo-open gnome-software 13->17         started        process6 19 gnome-software dpkg-deb 17->19         started        21 gnome-software dbus-launch 17->21         started        23 gnome-software dpkg 17->23         started        25 gnome-software dpkg 17->25         started        process7 27 dpkg-deb tar 19->27         started        29 dpkg-deb rm 19->29         started        31 dpkg-deb 19->31         started        33 dpkg-deb 19->33         started       

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
bluefish-data_2.2.12-1.1_all(1).deb0%ReversingLabs
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
reviews.ubuntu.com
unknown
unknownfalse
    unknown
    NameSourceMaliciousAntivirus DetectionReputation
    http://bluefish.openoffice.nlcontrol.59.drfalse
      unknown
      No contacted IP infos
      No context
      No context
      No context
      No context
      No context
      Process:/usr/bin/gnome-software
      File Type:data
      Category:dropped
      Size (bytes):2
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:3::
      MD5:C4103F122D27677C9DB144CAE1394A66
      SHA1:1489F923C4DCA729178B3E3233458550D8DDDF29
      SHA-256:96A296D224F285C67BEE93C30F8A309157F0DAA35DC5B87E410B78630A09CFC7
      SHA-512:5EA71DC6D0B4F57BF39AADD07C208C35F06CD2BAC5FDE210397F70DE11D439C62EC1CDF3183758865FD387FCEA0BADA2F6C37A4A17851DD1D78FEFE6F204EE54
      Malicious:false
      Reputation:moderate, very likely benign file
      Preview:..
      Process:/usr/bin/gnome-software
      File Type:SQLite 3.x database, last written using SQLite version 3011000, page size 1024, file counter 1, database pages 3, cookie 0x1, schema 4, UTF-8, version-valid-for 1
      Category:dropped
      Size (bytes):12288
      Entropy (8bit):1.8137112654833607
      Encrypted:false
      SSDEEP:96:5WtpHVGjjKopHVGjIKopHVGj4KopHVGjz:6HVGjDHVGjuHVGjeHVGjz
      MD5:05D33ECA3AA5CBC65852527223C7F6DD
      SHA1:A731EF942D48F6B76F551FC6C8EEDCE3AAAE0117
      SHA-256:65C96D2253A4E620FEB9F5709E5C2ACA2E5D6E1CA5371802E230CF41D36DC49D
      SHA-512:B513C92C7B93F72E8AA997491773BB23F072BD15BB58582D69A3DCD7D91360A96038042E001E6C3755FA7576B092F8E2D0B9DC3395F6566BD89CBF45190AC393
      Malicious:false
      Reputation:low
      Preview:SQLite format 3......@ .........................................................................-.......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................%%..Qtablereview_statsreview_stats.CREATE TABLE review_stats (package_name TEXT PRIMARY KEY,one_star_count INTEGER DEFAULT 0,two_star_count INTEGER DEFAULT 0,three_star_count INTEGER DEFAULT 0,four_star_count INTEGER DEFAULT 0,five_star_count INTEGER DEFAULT 0)7...K%..indexsqlite_autoindex_review_stat
      Process:/usr/bin/gnome-software
      File Type:SQLite Rollback Journal
      Category:dropped
      Size (bytes):7208
      Entropy (8bit):2.1830879500652727
      Encrypted:false
      SSDEEP:96:7eiekOWtpHVGjx/xKopHVGjMpAmKopHVGj1:7j3tHVGjhFHVGjH4HVGj1
      MD5:7F0B97BFBD8BEE75041CD538A16CEE93
      SHA1:0C62C0C467FB8B5BB40FEAD8CF7B43F7E595FEA1
      SHA-256:CBF96A442BBD4CC1B2A3719C45DE98BAE9BE78DD9EF98D91C36E4847FD08E5AA
      SHA-512:17185C49DA1D44312096EA3EFD6F7C822C3B3B43C9440EFC401EB57552FA931182D25741EBF49809C4E6215BC9ABE30AE8C53E00D5C0F8783CDB9545DCE6CEE9
      Malicious:false
      Reputation:low
      Preview:.... .c......./..................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................... .c.....4...........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
      Process:/bin/tar
      File Type:ASCII text
      Category:dropped
      Size (bytes):1064
      Entropy (8bit):4.711367082300045
      Encrypted:false
      SSDEEP:24:vpDO/gM4LLvHGgw054tI5WUgWM5g/0hQYXsHEvwsiMk:vpDO/gM4LbHGTltIQzSyQYWsk
      MD5:AC0912B8BDF42F80C5D25299D143CD22
      SHA1:DB5B50F394D02A6D026205120132AAACC2A6C68D
      SHA-256:AEC437B8D145A13165107650B3DE1C3824694300491E305BB4130DBF263D133E
      SHA-512:BB9B0A08B56839252E8BF7CB83020EF42FBD6EADAAB4AD29D90A64BCB60506A6676FED79158DCF3C9FFF61FE2FD34B14EE673EB9A02FBBB9C91F33A1670AF33F
      Malicious:false
      Reputation:low
      Preview:Package: bluefish-data.Source: bluefish.Version: 2.2.12-1.1.Architecture: all.Maintainer: Jonathan Carter <jcc@debian.org>.Installed-Size: 8087.Section: web.Priority: optional.Homepage: http://bluefish.openoffice.nl.Description: advanced Gtk+ text editor (data). Bluefish is a powerful editor targeted towards programmers and web. developers, with many options to write websites, scripts and programming. code. Bluefish supports a wide variety of programming and markup languages. and has many features, e.g.. .. - Customizable code folding, auto indenting and completion. - Support for remote files operation over FTP, SFTP, HTTPS, WebDAV, etc.. - Site upload and download. - Powerful search and replace engine. - Customizable integration of external programs such as lint, make, etc. - Snippets plugin to automate often used code. - Code-aware in-line spell checking. - Zencoding or Emmet support. - Bookmarks panel. .. but is still lightweight and fast.. .. This package contains the arch
      Process:/bin/tar
      File Type:ASCII text
      Category:dropped
      Size (bytes):37217
      Entropy (8bit):5.193725989322713
      Encrypted:false
      SSDEEP:384:tPIT+LTMzM0G2ui1ml7pES2nTI5pCeuzt50mGv5XOLVHXOgXO15JWr2aEykwnVut:tc+LTIM0Jwb248rVTiRyUnt1
      MD5:47566FA13D2F9D759976F4FB78408073
      SHA1:CAF4C37B38AA4AE0192E8C45725F6B867D481B6E
      SHA-256:A0FFCA064E5527F3D0A05C4AB0AA28BFAC24D97DD6E9F801095A260BAA1B9143
      SHA-512:54E96A0F3EB4A8534AEACFC8AC75D46D0569780EA89035A3D3D15C9708051C9A57DD56DC0F3F300E5E6CAE9E4EBF6B9CB9FA513637B5CBB7610DBAA534626467
      Malicious:false
      Reputation:low
      Preview:281db4538f70e88409a7e1abb45d087e usr/share/bluefish/bflang/JQuery.bfinc.1824494834786e40af67108517914ef5 usr/share/bluefish/bflang/ada.bflang2.3d0c1c56d16b981219971ff3bfc1ed86 usr/share/bluefish/bflang/all-html.bfinc.3616d9b5a5e39064d4203c59d131d938 usr/share/bluefish/bflang/all-html5.bfinc.c35b605a7bda40763526f2392f743bc5 usr/share/bluefish/bflang/all-javascript.bfinc.5c97b771d64c6d933ae8aaad60d1522a usr/share/bluefish/bflang/all-php.bfinc.5e76f4c09beaad2024c0d7ba0a050e6e usr/share/bluefish/bflang/all-vbscript.bfinc.a236136af2a160eb8164fec10f38aec8 usr/share/bluefish/bflang/asp-vbscript.bflang2.bf4dd4498cfc4cec3633b1303f4f1fcb usr/share/bluefish/bflang/asp.bflang2.83d2e83743bec029777778e9cabfef1f usr/share/bluefish/bflang/bflang2.bflang2.eba7be59facb753b79f8db553952b0db usr/share/bluefish/bflang/c.bflang2.19583a43418bf48463cf5ca3511fa0a0 usr/share/bluefish/bflang/cfml.bflang2.d0e1f3cc344c4ad940170de55ba00215 usr/share/bluefish/bflang/chuck.bflang2.54993799667d19c5d23d4b5e
      Process:/usr/lib/x86_64-linux-gnu/fwupd/fwupd
      File Type:SQLite 3.x database, last written using SQLite version 3011000, page size 1024, file counter 1, database pages 3, cookie 0x1, schema 4, UTF-8, version-valid-for 1
      Category:dropped
      Size (bytes):3072
      Entropy (8bit):1.1422572379832086
      Encrypted:false
      SSDEEP:12:HLiuWkHS51C6p08GZVMMf8J3ajJj2gT5oDGS3K:riuWUS5cDXZVIqsgTRS3
      MD5:8363D24E246DF601D7A309537767C270
      SHA1:6B92F004A6B213919893C789B38CBBF93EB2DA04
      SHA-256:24E3C058D82CDCCEEF7E556D244E06AA9EB9CE34715C879BC8E96D883444EEAD
      SHA-512:1A45D1EC6F01F3F999C1DE23FE81D8EC128A7AE28949FC9761974D611518F06C5F44529294ED589EE5E66978A6FFE794E3DAB2777A01F3010AB01FF96746DFD8
      Malicious:false
      Reputation:low
      Preview:SQLite format 3......@ .........................................................................-.......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................atablependingpending.CREATE TABLE pending (device_id TEXT PRIMARY KEY,unique_id TEXT,state INTEGER DEFAULT 0,timestamp TIMESTAMP DEFAULT CURRENT_TIMESTAMP NOT NULL,error TEXT,filename TEXT,display_name TEXT,provider TEXT,version_old TEXT,version_new TEXT)-...A...indexsqlite_autoindex_p
      Process:/usr/lib/x86_64-linux-gnu/fwupd/fwupd
      File Type:data
      Category:dropped
      Size (bytes):524
      Entropy (8bit):0.27937671757176796
      Encrypted:false
      SSDEEP:3:Eh1FlxllxFEG2l/n:Eb+/l/n
      MD5:10966F52590C99EE6AEA33C5A5535E66
      SHA1:14B55393B15936C8C8100F969161A59796AE342A
      SHA-256:7F3BA0A058BF6CD39AB7C4CE1C730983632EF7D6696F4CF99E730EFBF45655A5
      SHA-512:46280C67566F473D32EA8994380AEE12E3843BDE4DB99D9AD2F5B2BEC25EC473D943074AB0340A707906D290ACC48C08A410D9217FA90ABE7C205320010EFAF5
      Malicious:false
      Reputation:low
      Preview:.................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................. .c.....
      File type:Debian binary package (format 2.0), with control.tar.xz, data compression xz
      Entropy (8bit):7.999825201790194
      TrID:
      • Debian Linux Package (24024/1) 100.00%
      File name:bluefish-data_2.2.12-1.1_all(1).deb
      File size:2'412'364 bytes
      MD5:f3b0147686843cf4b09551c626bdd77d
      SHA1:4f9f4570ba5e21f859744b4f20122b30235dfb02
      SHA256:1e6b6f39d9384307e8110aafcaa9323412abf9084391448b2b10b5c0c19527b7
      SHA512:c73203d2fc210e5e1ffb21532cb3204ea8a55c8f72601ef8d9d930b3a62430c372d549aba83d6b0afee8d660bf43add7d1e520756c5fd681d0467bfe9731ece5
      SSDEEP:49152:yK8ucGBX5zsXtngg51KHPQ9Dftw+insblQMdE3QhkVSza2ops+e:yzg+tngg5+o9bxisZQMdR/a2o++e
      TLSH:39B533C95F93DB91E66932F51C079606FBDCB02708E6A381221E27E2BF21550BE578F4
      File Content Preview:!<arch>.debian-binary 1616548588 0 0 100644 4 `.2.0.control.tar.xz 1616548588 0 0 100644 9824 `..7zXZ......F...L...!..........]'...&.].....}....J>y...&.a<>..\p.-.&h.u^$.TK.Qdhw..5]..V.~.4..J..i:........%.mF.e<....J#.$..
      TimestampSource PortDest PortSource IPDest IP
      Oct 28, 2024 09:51:16.585254908 CET4168453192.168.2.208.8.8.8
      Oct 28, 2024 09:51:16.585254908 CET4168453192.168.2.208.8.8.8
      Oct 28, 2024 09:51:16.827763081 CET53416848.8.8.8192.168.2.20
      Oct 28, 2024 09:51:16.828702927 CET53416848.8.8.8192.168.2.20
      Oct 28, 2024 09:51:16.828989983 CET4946953192.168.2.208.8.8.8
      Oct 28, 2024 09:51:16.828989983 CET4946953192.168.2.208.8.8.8
      Oct 28, 2024 09:51:16.836492062 CET53494698.8.8.8192.168.2.20
      Oct 28, 2024 09:51:16.850305080 CET53494698.8.8.8192.168.2.20
      Oct 28, 2024 09:51:41.888442993 CET4201253192.168.2.208.8.8.8
      Oct 28, 2024 09:51:41.888442993 CET4201253192.168.2.208.8.8.8
      Oct 28, 2024 09:51:41.909545898 CET53420128.8.8.8192.168.2.20
      Oct 28, 2024 09:51:41.910207033 CET53420128.8.8.8192.168.2.20
      Oct 28, 2024 09:51:41.910430908 CET6030753192.168.2.208.8.8.8
      Oct 28, 2024 09:51:41.910522938 CET6030753192.168.2.208.8.8.8
      Oct 28, 2024 09:51:41.935436964 CET53603078.8.8.8192.168.2.20
      Oct 28, 2024 09:51:41.935879946 CET53603078.8.8.8192.168.2.20
      TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
      Oct 28, 2024 09:51:16.585254908 CET192.168.2.208.8.8.80xbdabStandard query (0)reviews.ubuntu.comA (IP address)IN (0x0001)false
      Oct 28, 2024 09:51:16.585254908 CET192.168.2.208.8.8.80x3c4eStandard query (0)reviews.ubuntu.com28IN (0x0001)false
      Oct 28, 2024 09:51:16.828989983 CET192.168.2.208.8.8.80xb991Standard query (0)reviews.ubuntu.comA (IP address)IN (0x0001)false
      Oct 28, 2024 09:51:16.828989983 CET192.168.2.208.8.8.80x3ce3Standard query (0)reviews.ubuntu.com28IN (0x0001)false
      Oct 28, 2024 09:51:41.888442993 CET192.168.2.208.8.8.80xacc4Standard query (0)reviews.ubuntu.comA (IP address)IN (0x0001)false
      Oct 28, 2024 09:51:41.888442993 CET192.168.2.208.8.8.80x5681Standard query (0)reviews.ubuntu.com28IN (0x0001)false
      Oct 28, 2024 09:51:41.910430908 CET192.168.2.208.8.8.80x5a63Standard query (0)reviews.ubuntu.comA (IP address)IN (0x0001)false
      Oct 28, 2024 09:51:41.910522938 CET192.168.2.208.8.8.80x5853Standard query (0)reviews.ubuntu.com28IN (0x0001)false
      TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
      Oct 28, 2024 09:51:16.827763081 CET8.8.8.8192.168.2.200xbdabName error (3)reviews.ubuntu.comnonenoneA (IP address)IN (0x0001)false
      Oct 28, 2024 09:51:16.828702927 CET8.8.8.8192.168.2.200x3c4eName error (3)reviews.ubuntu.comnonenone28IN (0x0001)false
      Oct 28, 2024 09:51:16.836492062 CET8.8.8.8192.168.2.200xb991Name error (3)reviews.ubuntu.comnonenoneA (IP address)IN (0x0001)false
      Oct 28, 2024 09:51:16.850305080 CET8.8.8.8192.168.2.200x3ce3Name error (3)reviews.ubuntu.comnonenone28IN (0x0001)false
      Oct 28, 2024 09:51:41.909545898 CET8.8.8.8192.168.2.200x5681Name error (3)reviews.ubuntu.comnonenone28IN (0x0001)false
      Oct 28, 2024 09:51:41.910207033 CET8.8.8.8192.168.2.200xacc4Name error (3)reviews.ubuntu.comnonenoneA (IP address)IN (0x0001)false
      Oct 28, 2024 09:51:41.935436964 CET8.8.8.8192.168.2.200x5a63Name error (3)reviews.ubuntu.comnonenoneA (IP address)IN (0x0001)false
      Oct 28, 2024 09:51:41.935879946 CET8.8.8.8192.168.2.200x5853Name error (3)reviews.ubuntu.comnonenone28IN (0x0001)false

      System Behavior

      Start time (UTC):08:50:45
      Start date (UTC):28/10/2024
      Path:/usr/bin/exo-open
      Arguments:exo-open /tmp/bluefish-data_2.2.12-1.1_all(1).deb
      File size:22856 bytes
      MD5 hash:39c5fa78f1cb3d950b9944f784018d3a

      Start time (UTC):08:50:45
      Start date (UTC):28/10/2024
      Path:/usr/bin/exo-open
      Arguments:-
      File size:22856 bytes
      MD5 hash:39c5fa78f1cb3d950b9944f784018d3a

      Start time (UTC):08:50:45
      Start date (UTC):28/10/2024
      Path:/usr/bin/dbus-launch
      Arguments:dbus-launch --autolaunch=11ced2f07072c6ae389b731c5cc84014 --binary-syntax --close-stderr
      File size:26616 bytes
      MD5 hash:e4a469f27d130d783c21ce9c1c4456c3

      Start time (UTC):08:50:45
      Start date (UTC):28/10/2024
      Path:/usr/bin/exo-open
      Arguments:-
      File size:22856 bytes
      MD5 hash:39c5fa78f1cb3d950b9944f784018d3a

      Start time (UTC):08:50:45
      Start date (UTC):28/10/2024
      Path:/usr/bin/exo-open
      Arguments:-
      File size:22856 bytes
      MD5 hash:39c5fa78f1cb3d950b9944f784018d3a

      Start time (UTC):08:50:45
      Start date (UTC):28/10/2024
      Path:/usr/bin/gnome-software
      Arguments:gnome-software --local-filename=/tmp/bluefish-data_2.2.12-1.1_all(1).deb
      File size:701296 bytes
      MD5 hash:8676fce47b3f3e8c729aaaa8c935c235

      Start time (UTC):08:50:45
      Start date (UTC):28/10/2024
      Path:/usr/bin/gnome-software
      Arguments:-
      File size:701296 bytes
      MD5 hash:8676fce47b3f3e8c729aaaa8c935c235

      Start time (UTC):08:50:45
      Start date (UTC):28/10/2024
      Path:/usr/bin/dbus-launch
      Arguments:dbus-launch --autolaunch=11ced2f07072c6ae389b731c5cc84014 --binary-syntax --close-stderr
      File size:26616 bytes
      MD5 hash:e4a469f27d130d783c21ce9c1c4456c3

      Start time (UTC):08:51:15
      Start date (UTC):28/10/2024
      Path:/usr/bin/gnome-software
      Arguments:-
      File size:701296 bytes
      MD5 hash:8676fce47b3f3e8c729aaaa8c935c235

      Start time (UTC):08:51:15
      Start date (UTC):28/10/2024
      Path:/usr/bin/dpkg-deb
      Arguments:/usr/bin/dpkg-deb --showformat=${Package}\\n${Version}\\n${Installed-Size}\\n${Homepage}\\n${Description} -W /tmp/bluefish-data_2.2.12-1.1_all(1).deb
      File size:34520 bytes
      MD5 hash:6833acbbb76db8e5a5f14dd5073929af

      Start time (UTC):08:51:15
      Start date (UTC):28/10/2024
      Path:/usr/bin/dpkg-deb
      Arguments:-
      File size:34520 bytes
      MD5 hash:6833acbbb76db8e5a5f14dd5073929af

      Start time (UTC):08:51:15
      Start date (UTC):28/10/2024
      Path:/usr/bin/dpkg-deb
      Arguments:-
      File size:34520 bytes
      MD5 hash:6833acbbb76db8e5a5f14dd5073929af

      Start time (UTC):08:51:15
      Start date (UTC):28/10/2024
      Path:/usr/bin/dpkg-deb
      Arguments:-
      File size:34520 bytes
      MD5 hash:6833acbbb76db8e5a5f14dd5073929af

      Start time (UTC):08:51:15
      Start date (UTC):28/10/2024
      Path:/bin/tar
      Arguments:tar -x -m -f - --warning=no-timestamp
      File size:383632 bytes
      MD5 hash:dbc4507f4db5b41f7358b28bce65a15d

      Start time (UTC):08:51:15
      Start date (UTC):28/10/2024
      Path:/usr/bin/dpkg-deb
      Arguments:-
      File size:34520 bytes
      MD5 hash:6833acbbb76db8e5a5f14dd5073929af

      Start time (UTC):08:51:15
      Start date (UTC):28/10/2024
      Path:/bin/rm
      Arguments:rm -rf -- /tmp/dpkg-deb.YO0WnW
      File size:60272 bytes
      MD5 hash:b79876063d894c449856cca508ecca7f

      Start time (UTC):08:51:41
      Start date (UTC):28/10/2024
      Path:/usr/bin/gnome-software
      Arguments:-
      File size:701296 bytes
      MD5 hash:8676fce47b3f3e8c729aaaa8c935c235

      Start time (UTC):08:51:41
      Start date (UTC):28/10/2024
      Path:/usr/bin/dpkg
      Arguments:/usr/bin/dpkg --print-foreign-architectures
      File size:278264 bytes
      MD5 hash:7084d55d63a41425e1a2c1adcced4f14

      Start time (UTC):08:51:41
      Start date (UTC):28/10/2024
      Path:/usr/bin/gnome-software
      Arguments:-
      File size:701296 bytes
      MD5 hash:8676fce47b3f3e8c729aaaa8c935c235

      Start time (UTC):08:51:41
      Start date (UTC):28/10/2024
      Path:/usr/bin/dpkg
      Arguments:/usr/bin/dpkg --print-foreign-architectures
      File size:278264 bytes
      MD5 hash:7084d55d63a41425e1a2c1adcced4f14

      Start time (UTC):08:51:10
      Start date (UTC):28/10/2024
      Path:/lib/systemd/systemd
      Arguments:-
      File size:0 bytes
      MD5 hash:unknown

      Start time (UTC):08:51:10
      Start date (UTC):28/10/2024
      Path:/usr/lib/x86_64-linux-gnu/fwupd/fwupd
      Arguments:/usr/lib/x86_64-linux-gnu/fwupd/fwupd
      File size:104656 bytes
      MD5 hash:4d2507b12cd401bed306a719c3c7b863