Linux
Analysis Report
zone.arm.elf
Overview
General Information
Sample name: | zone.arm.elf |
Analysis ID: | 1545579 |
MD5: | a77c391a6e462618ccbbbf1aa4e326af |
SHA1: | ffbc08f31c24c57d44f6e081443ec2d1d75607f5 |
SHA256: | 61ba334fece8115debc5170dfeb680881a93d1cd3610cac61e59c912fc63a7fc |
Tags: | elfuser-abuse_ch |
Infos: |
Detection
Score: | 24 |
Range: | 0 - 100 |
Whitelisted: | false |
Signatures
Classification
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1545579 |
Start date and time: | 2024-10-30 17:36:35 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 6m 12s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultlinuxfilecookbook.jbs |
Analysis system description: | Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11) |
Analysis Mode: | default |
Sample name: | zone.arm.elf |
Detection: | SUS |
Classification: | sus24.evad.linELF@0/0@4/0 |
- VT rate limit hit for: zone.arm.elf
Command: | /tmp/zone.arm.elf |
PID: | 6206 |
Exit Code: | 0 |
Exit Code Info: | |
Killed: | False |
Standard Output: | main:{"arch":"arm","flags":["L","A","R"],"local":"192.168.2.23","mac":"00505698912c","tag":"","uptime":0,"version":"2.0.34"}[1;40;36m11:37:20 connected to 38.60.221.32:80[0m [1;40;36m11:37:30 menet.Receive:EOF[0m |
Standard Error: |
- system is lnxubuntu20
- zone.arm.elf New Fork (PID: 6211, Parent: 6206)
- zone.arm.elf New Fork (PID: 6227, Parent: 6211)
- zone.arm.elf New Fork (PID: 6231, Parent: 6211)
- bash New Fork (PID: 6234, Parent: 6231)
- bash New Fork (PID: 6235, Parent: 6231)
- bash New Fork (PID: 6236, Parent: 6231)
- zone.arm.elf New Fork (PID: 6237, Parent: 6211)
- bash New Fork (PID: 6239, Parent: 6237)
- bash New Fork (PID: 6240, Parent: 6237)
- bash New Fork (PID: 6241, Parent: 6237)
- zone.arm.elf New Fork (PID: 6293, Parent: 6211)
- bash New Fork (PID: 6295, Parent: 6293)
- bash New Fork (PID: 6296, Parent: 6293)
- bash New Fork (PID: 6297, Parent: 6293)
- zone.arm.elf New Fork (PID: 6298, Parent: 6211)
- bash New Fork (PID: 6300, Parent: 6298)
- bash New Fork (PID: 6301, Parent: 6298)
- bash New Fork (PID: 6302, Parent: 6298)
- zone.arm.elf New Fork (PID: 6332, Parent: 6211)
- bash New Fork (PID: 6334, Parent: 6332)
- bash New Fork (PID: 6335, Parent: 6332)
- bash New Fork (PID: 6336, Parent: 6332)
- zone.arm.elf New Fork (PID: 6337, Parent: 6211)
- cleanup
Click to jump to signature section
Source: | Reads CPU info from /sys: | Jump to behavior | ||
Source: | Reads CPU info from /sys: | Jump to behavior |
Source: | Reads hosts file: | Jump to behavior |
Source: | Socket: | Jump to behavior |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | DNS traffic detected: |
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | Program segment: |
Source: | Classification label: |
Data Obfuscation |
---|
Source: | String containing UPX found: | ||
Source: | String containing UPX found: | ||
Source: | String containing UPX found: |
Source: | Shell command executed: | Jump to behavior |
Source: | Grep executable: | Jump to behavior | ||
Source: | Grep executable: | Jump to behavior | ||
Source: | Grep executable: | Jump to behavior | ||
Source: | Grep executable: | Jump to behavior | ||
Source: | Grep executable: | Jump to behavior | ||
Source: | Grep executable: | Jump to behavior |
Source: | Reads from proc file: | Jump to behavior | ||
Source: | Reads from proc file: | Jump to behavior | ||
Source: | Reads from proc file: | Jump to behavior |
Source: | Awk executable: | Jump to behavior | ||
Source: | Awk executable: | Jump to behavior | ||
Source: | Awk executable: | Jump to behavior | ||
Source: | Awk executable: | Jump to behavior | ||
Source: | Awk executable: | Jump to behavior | ||
Source: | Awk executable: | Jump to behavior |
Source: | Submission file: | ||
Source: | Submission file: |
Source: | Reads CPU info from /sys: | Jump to behavior | ||
Source: | Reads CPU info from /sys: | Jump to behavior |
Source: | Queries kernel information via 'uname': | Jump to behavior | ||
Source: | Queries kernel information via 'uname': | Jump to behavior | ||
Source: | Queries kernel information via 'uname': | Jump to behavior | ||
Source: | Queries kernel information via 'uname': | Jump to behavior | ||
Source: | Queries kernel information via 'uname': | Jump to behavior | ||
Source: | Queries kernel information via 'uname': | Jump to behavior | ||
Source: | Queries kernel information via 'uname': | Jump to behavior | ||
Source: | Queries kernel information via 'uname': | Jump to behavior | ||
Source: | Queries kernel information via 'uname': | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 1 Scripting | Valid Accounts | 1 Command and Scripting Interpreter | 1 Scripting | Path Interception | 11 Obfuscated Files or Information | OS Credential Dumping | 11 Security Software Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Rootkit | LSASS Memory | 1 File and Directory Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | 2 System Information Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | 2 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
3% | ReversingLabs |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | URL Reputation | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
column.mrbasic.com | 38.60.221.32 | true | false | unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
true |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
38.60.221.32 | column.mrbasic.com | United States | 174 | COGENT-174US | false | |
109.202.202.202 | unknown | Switzerland | 13030 | INIT7CH | false | |
91.189.91.43 | unknown | United Kingdom | 41231 | CANONICAL-ASGB | false | |
91.189.91.42 | unknown | United Kingdom | 41231 | CANONICAL-ASGB | false |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
109.202.202.202 | Get hash | malicious | Unknown | Browse |
| |
91.189.91.43 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Xmrig | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
91.189.91.42 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Xmrig | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
CANONICAL-ASGB | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Xmrig | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
COGENT-174US | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
CANONICAL-ASGB | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Xmrig | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
INIT7CH | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Xmrig | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
File type: | |
Entropy (8bit): | 7.999917019134998 |
TrID: |
|
File name: | zone.arm.elf |
File size: | 2'972'700 bytes |
MD5: | a77c391a6e462618ccbbbf1aa4e326af |
SHA1: | ffbc08f31c24c57d44f6e081443ec2d1d75607f5 |
SHA256: | 61ba334fece8115debc5170dfeb680881a93d1cd3610cac61e59c912fc63a7fc |
SHA512: | 3cb4abad617b2748c16143fea055ee3455eaca672e224be90398fda8b0bd0846f3e0415b65c52806e46d4f93a8c59c0921632d3f086623ce7fe5d629527d7dfd |
SSDEEP: | 49152:VEqogX7kJRMT310OfID0ZwI5XdqwgLCHsgsdDZcP0zvvkS+w6scJUqYSYyvdQHWR:9okk3kaOfIgZwnVpgsdDc0vvjQsc2Vi9 |
TLSH: | 09D533FC9955E0B9F83074F419D21A5DBE9186F260D33CCA4E142245BABD7A7EEC890C |
File Content Preview: | .ELF..............(.....lH..4...........4. .............................@............................Z-..Z-.........Q.td.............................8..UPX!............X.O.....e..........?.E.h;....#..$....<.]0`tG.%]q..!.....2.*.....AG.k9..I1.x....Vh.\H... |
ELF header | |
---|---|
Class: | |
Data: | |
Version: | |
Machine: | |
Version Number: | |
Type: | |
OS/ABI: | |
ABI Version: | 0 |
Entry Point Address: | |
Flags: | |
ELF Header Size: | 52 |
Program Header Offset: | 52 |
Program Header Size: | 32 |
Number of Program Headers: | 3 |
Section Header Offset: | 0 |
Section Header Size: | 0 |
Number of Section Headers: | 0 |
Header String Table Index: | 0 |
Type | Offset | Virtual Address | Physical Address | File Size | Memory Size | Entropy | Flags | Flags Description | Align | Prog Interpreter | Section Mappings |
---|---|---|---|---|---|---|---|---|---|---|---|
LOAD | 0x0 | 0x10000 | 0x10000 | 0x1000 | 0xe7f640 | 7.8904 | 0x6 | RW | 0x10000 | ||
LOAD | 0x0 | 0xe90000 | 0xe90000 | 0x2d5ae5 | 0x2d5ae5 | 7.9999 | 0x5 | R E | 0x10000 | ||
GNU_STACK | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0.0000 | 0x6 | RW | 0x4 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 30, 2024 17:37:18.449419975 CET | 43928 | 443 | 192.168.2.23 | 91.189.91.42 |
Oct 30, 2024 17:37:20.311325073 CET | 59014 | 80 | 192.168.2.23 | 38.60.221.32 |
Oct 30, 2024 17:37:20.319149971 CET | 80 | 59014 | 38.60.221.32 | 192.168.2.23 |
Oct 30, 2024 17:37:20.319195986 CET | 59014 | 80 | 192.168.2.23 | 38.60.221.32 |
Oct 30, 2024 17:37:20.332570076 CET | 59014 | 80 | 192.168.2.23 | 38.60.221.32 |
Oct 30, 2024 17:37:20.341219902 CET | 80 | 59014 | 38.60.221.32 | 192.168.2.23 |
Oct 30, 2024 17:37:21.438013077 CET | 80 | 59014 | 38.60.221.32 | 192.168.2.23 |
Oct 30, 2024 17:37:21.438144922 CET | 59014 | 80 | 192.168.2.23 | 38.60.221.32 |
Oct 30, 2024 17:37:21.467426062 CET | 59014 | 80 | 192.168.2.23 | 38.60.221.32 |
Oct 30, 2024 17:37:21.476058006 CET | 80 | 59014 | 38.60.221.32 | 192.168.2.23 |
Oct 30, 2024 17:37:21.484566927 CET | 59014 | 80 | 192.168.2.23 | 38.60.221.32 |
Oct 30, 2024 17:37:21.494404078 CET | 80 | 59014 | 38.60.221.32 | 192.168.2.23 |
Oct 30, 2024 17:37:23.433626890 CET | 80 | 59014 | 38.60.221.32 | 192.168.2.23 |
Oct 30, 2024 17:37:23.433751106 CET | 59014 | 80 | 192.168.2.23 | 38.60.221.32 |
Oct 30, 2024 17:37:23.674196959 CET | 80 | 59014 | 38.60.221.32 | 192.168.2.23 |
Oct 30, 2024 17:37:23.716700077 CET | 59014 | 80 | 192.168.2.23 | 38.60.221.32 |
Oct 30, 2024 17:37:23.824696064 CET | 42836 | 443 | 192.168.2.23 | 91.189.91.43 |
Oct 30, 2024 17:37:25.360486031 CET | 42516 | 80 | 192.168.2.23 | 109.202.202.202 |
Oct 30, 2024 17:37:38.670623064 CET | 43928 | 443 | 192.168.2.23 | 91.189.91.42 |
Oct 30, 2024 17:37:38.926636934 CET | 59014 | 80 | 192.168.2.23 | 38.60.221.32 |
Oct 30, 2024 17:37:38.932255030 CET | 80 | 59014 | 38.60.221.32 | 192.168.2.23 |
Oct 30, 2024 17:37:50.956908941 CET | 42836 | 443 | 192.168.2.23 | 91.189.91.43 |
Oct 30, 2024 17:37:54.028505087 CET | 59014 | 80 | 192.168.2.23 | 38.60.221.32 |
Oct 30, 2024 17:37:54.033890963 CET | 80 | 59014 | 38.60.221.32 | 192.168.2.23 |
Oct 30, 2024 17:37:55.052424908 CET | 42516 | 80 | 192.168.2.23 | 109.202.202.202 |
Oct 30, 2024 17:38:09.130511045 CET | 59014 | 80 | 192.168.2.23 | 38.60.221.32 |
Oct 30, 2024 17:38:09.292313099 CET | 80 | 59014 | 38.60.221.32 | 192.168.2.23 |
Oct 30, 2024 17:38:19.624905109 CET | 43928 | 443 | 192.168.2.23 | 91.189.91.42 |
Oct 30, 2024 17:38:24.292310953 CET | 59014 | 80 | 192.168.2.23 | 38.60.221.32 |
Oct 30, 2024 17:38:24.301768064 CET | 80 | 59014 | 38.60.221.32 | 192.168.2.23 |
Oct 30, 2024 17:38:39.334203959 CET | 59014 | 80 | 192.168.2.23 | 38.60.221.32 |
Oct 30, 2024 17:38:39.339797020 CET | 80 | 59014 | 38.60.221.32 | 192.168.2.23 |
Oct 30, 2024 17:40:01.612385035 CET | 59016 | 80 | 192.168.2.23 | 38.60.221.32 |
Oct 30, 2024 17:40:01.617750883 CET | 80 | 59016 | 38.60.221.32 | 192.168.2.23 |
Oct 30, 2024 17:40:01.617846966 CET | 59016 | 80 | 192.168.2.23 | 38.60.221.32 |
Oct 30, 2024 17:40:01.627152920 CET | 59016 | 80 | 192.168.2.23 | 38.60.221.32 |
Oct 30, 2024 17:40:01.632498026 CET | 80 | 59016 | 38.60.221.32 | 192.168.2.23 |
Oct 30, 2024 17:40:02.658349037 CET | 80 | 59016 | 38.60.221.32 | 192.168.2.23 |
Oct 30, 2024 17:40:02.658452988 CET | 59016 | 80 | 192.168.2.23 | 38.60.221.32 |
Oct 30, 2024 17:40:02.672435045 CET | 59016 | 80 | 192.168.2.23 | 38.60.221.32 |
Oct 30, 2024 17:40:02.677970886 CET | 80 | 59016 | 38.60.221.32 | 192.168.2.23 |
Oct 30, 2024 17:40:02.678642988 CET | 59016 | 80 | 192.168.2.23 | 38.60.221.32 |
Oct 30, 2024 17:40:02.683947086 CET | 80 | 59016 | 38.60.221.32 | 192.168.2.23 |
Oct 30, 2024 17:40:03.024701118 CET | 80 | 59016 | 38.60.221.32 | 192.168.2.23 |
Oct 30, 2024 17:40:03.024795055 CET | 59016 | 80 | 192.168.2.23 | 38.60.221.32 |
Oct 30, 2024 17:40:12.903003931 CET | 59016 | 80 | 192.168.2.23 | 38.60.221.32 |
Oct 30, 2024 17:40:12.908778906 CET | 80 | 59016 | 38.60.221.32 | 192.168.2.23 |
Oct 30, 2024 17:40:12.908838987 CET | 59016 | 80 | 192.168.2.23 | 38.60.221.32 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 30, 2024 17:37:20.200969934 CET | 56885 | 53 | 192.168.2.23 | 1.1.1.1 |
Oct 30, 2024 17:37:20.201539993 CET | 41864 | 53 | 192.168.2.23 | 1.1.1.1 |
Oct 30, 2024 17:37:20.293669939 CET | 53 | 56885 | 1.1.1.1 | 192.168.2.23 |
Oct 30, 2024 17:37:20.296878099 CET | 53 | 41864 | 1.1.1.1 | 192.168.2.23 |
Oct 30, 2024 17:40:01.482477903 CET | 45389 | 53 | 192.168.2.23 | 1.1.1.1 |
Oct 30, 2024 17:40:01.483192921 CET | 39680 | 53 | 192.168.2.23 | 1.1.1.1 |
Oct 30, 2024 17:40:01.589154959 CET | 53 | 45389 | 1.1.1.1 | 192.168.2.23 |
Oct 30, 2024 17:40:01.607887983 CET | 53 | 39680 | 1.1.1.1 | 192.168.2.23 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Oct 30, 2024 17:37:20.200969934 CET | 192.168.2.23 | 1.1.1.1 | 0xd4c5 | Standard query (0) | 28 | IN (0x0001) | false | |
Oct 30, 2024 17:37:20.201539993 CET | 192.168.2.23 | 1.1.1.1 | 0xe4d8 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 30, 2024 17:40:01.482477903 CET | 192.168.2.23 | 1.1.1.1 | 0x8f77 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 30, 2024 17:40:01.483192921 CET | 192.168.2.23 | 1.1.1.1 | 0x65e9 | Standard query (0) | 28 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Oct 30, 2024 17:37:20.296878099 CET | 1.1.1.1 | 192.168.2.23 | 0xe4d8 | No error (0) | 38.60.221.32 | A (IP address) | IN (0x0001) | false | ||
Oct 30, 2024 17:40:01.589154959 CET | 1.1.1.1 | 192.168.2.23 | 0x8f77 | No error (0) | 38.60.221.32 | A (IP address) | IN (0x0001) | false |
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
0 | 192.168.2.23 | 59014 | 38.60.221.32 | 80 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 30, 2024 17:37:20.332570076 CET | 255 | OUT | |
Oct 30, 2024 17:37:21.438013077 CET | 1230 | IN | |
Oct 30, 2024 17:37:21.467426062 CET | 76 | OUT | |
Oct 30, 2024 17:37:21.484566927 CET | 215 | OUT | |
Oct 30, 2024 17:37:23.433626890 CET | 36 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
1 | 192.168.2.23 | 59016 | 38.60.221.32 | 80 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 30, 2024 17:40:01.627152920 CET | 255 | OUT | |
Oct 30, 2024 17:40:02.658349037 CET | 1230 | IN | |
Oct 30, 2024 17:40:02.672435045 CET | 76 | OUT | |
Oct 30, 2024 17:40:02.678642988 CET | 215 | OUT | |
Oct 30, 2024 17:40:03.024701118 CET | 237 | IN |
System Behavior
Start time (UTC): | 16:37:17 |
Start date (UTC): | 30/10/2024 |
Path: | /tmp/zone.arm.elf |
Arguments: | /tmp/zone.arm.elf |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 16:37:18 |
Start date (UTC): | 30/10/2024 |
Path: | /tmp/zone.arm.elf |
Arguments: | - |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 16:37:18 |
Start date (UTC): | 30/10/2024 |
Path: | /tmp/zone.arm.elf |
Arguments: | /tmp/zone.arm.elf -b |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 16:37:19 |
Start date (UTC): | 30/10/2024 |
Path: | /tmp/zone.arm.elf |
Arguments: | - |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 16:37:19 |
Start date (UTC): | 30/10/2024 |
Path: | /bin/bash |
Arguments: | /bin/bash -c uptime |
File size: | 1183448 bytes |
MD5 hash: | 7063c3930affe123baecd3b340f1ad2c |
Start time (UTC): | 16:37:19 |
Start date (UTC): | 30/10/2024 |
Path: | /usr/bin/uptime |
Arguments: | uptime |
File size: | 14568 bytes |
MD5 hash: | 3ad70d8e33316ac713bf25c2ddf2fb14 |
Start time (UTC): | 16:37:19 |
Start date (UTC): | 30/10/2024 |
Path: | /tmp/zone.arm.elf |
Arguments: | - |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 16:37:19 |
Start date (UTC): | 30/10/2024 |
Path: | /usr/bin/bash |
Arguments: | bash -c "cat /proc/net/dev |grep ens160 |awk '{print $2}'" |
File size: | 1183448 bytes |
MD5 hash: | 7063c3930affe123baecd3b340f1ad2c |
Start time (UTC): | 16:37:19 |
Start date (UTC): | 30/10/2024 |
Path: | /usr/bin/bash |
Arguments: | - |
File size: | 1183448 bytes |
MD5 hash: | 7063c3930affe123baecd3b340f1ad2c |
Start time (UTC): | 16:37:19 |
Start date (UTC): | 30/10/2024 |
Path: | /usr/bin/cat |
Arguments: | cat /proc/net/dev |
File size: | 43416 bytes |
MD5 hash: | 7e9d213e404ad3bb82e4ebb2e1f2c1b3 |
Start time (UTC): | 16:37:19 |
Start date (UTC): | 30/10/2024 |
Path: | /usr/bin/bash |
Arguments: | - |
File size: | 1183448 bytes |
MD5 hash: | 7063c3930affe123baecd3b340f1ad2c |
Start time (UTC): | 16:37:19 |
Start date (UTC): | 30/10/2024 |
Path: | /usr/bin/grep |
Arguments: | grep ens160 |
File size: | 199136 bytes |
MD5 hash: | 1e6ebb9dd094f774478f72727bdba0f5 |
Start time (UTC): | 16:37:19 |
Start date (UTC): | 30/10/2024 |
Path: | /usr/bin/bash |
Arguments: | - |
File size: | 1183448 bytes |
MD5 hash: | 7063c3930affe123baecd3b340f1ad2c |
Start time (UTC): | 16:37:19 |
Start date (UTC): | 30/10/2024 |
Path: | /usr/bin/awk |
Arguments: | awk "{print $2}" |
File size: | 711136 bytes |
MD5 hash: | 7e9b2ed1272331cfbd2aac2e5eb3f84b |
Start time (UTC): | 16:37:19 |
Start date (UTC): | 30/10/2024 |
Path: | /tmp/zone.arm.elf |
Arguments: | - |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 16:37:19 |
Start date (UTC): | 30/10/2024 |
Path: | /usr/bin/bash |
Arguments: | bash -c "cat /proc/net/dev |grep ens160 |awk '{print $10}'" |
File size: | 1183448 bytes |
MD5 hash: | 7063c3930affe123baecd3b340f1ad2c |
Start time (UTC): | 16:37:19 |
Start date (UTC): | 30/10/2024 |
Path: | /usr/bin/bash |
Arguments: | - |
File size: | 1183448 bytes |
MD5 hash: | 7063c3930affe123baecd3b340f1ad2c |
Start time (UTC): | 16:37:19 |
Start date (UTC): | 30/10/2024 |
Path: | /usr/bin/cat |
Arguments: | cat /proc/net/dev |
File size: | 43416 bytes |
MD5 hash: | 7e9d213e404ad3bb82e4ebb2e1f2c1b3 |
Start time (UTC): | 16:37:19 |
Start date (UTC): | 30/10/2024 |
Path: | /usr/bin/bash |
Arguments: | - |
File size: | 1183448 bytes |
MD5 hash: | 7063c3930affe123baecd3b340f1ad2c |
Start time (UTC): | 16:37:19 |
Start date (UTC): | 30/10/2024 |
Path: | /usr/bin/grep |
Arguments: | grep ens160 |
File size: | 199136 bytes |
MD5 hash: | 1e6ebb9dd094f774478f72727bdba0f5 |
Start time (UTC): | 16:37:19 |
Start date (UTC): | 30/10/2024 |
Path: | /usr/bin/bash |
Arguments: | - |
File size: | 1183448 bytes |
MD5 hash: | 7063c3930affe123baecd3b340f1ad2c |
Start time (UTC): | 16:37:19 |
Start date (UTC): | 30/10/2024 |
Path: | /usr/bin/awk |
Arguments: | awk "{print $10}" |
File size: | 711136 bytes |
MD5 hash: | 7e9b2ed1272331cfbd2aac2e5eb3f84b |
Start time (UTC): | 16:38:20 |
Start date (UTC): | 30/10/2024 |
Path: | /tmp/zone.arm.elf |
Arguments: | - |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 16:38:20 |
Start date (UTC): | 30/10/2024 |
Path: | /usr/bin/bash |
Arguments: | bash -c "cat /proc/net/dev |grep ens160 |awk '{print $2}'" |
File size: | 1183448 bytes |
MD5 hash: | 7063c3930affe123baecd3b340f1ad2c |
Start time (UTC): | 16:38:20 |
Start date (UTC): | 30/10/2024 |
Path: | /usr/bin/bash |
Arguments: | - |
File size: | 1183448 bytes |
MD5 hash: | 7063c3930affe123baecd3b340f1ad2c |
Start time (UTC): | 16:38:20 |
Start date (UTC): | 30/10/2024 |
Path: | /usr/bin/cat |
Arguments: | cat /proc/net/dev |
File size: | 43416 bytes |
MD5 hash: | 7e9d213e404ad3bb82e4ebb2e1f2c1b3 |
Start time (UTC): | 16:38:20 |
Start date (UTC): | 30/10/2024 |
Path: | /usr/bin/bash |
Arguments: | - |
File size: | 1183448 bytes |
MD5 hash: | 7063c3930affe123baecd3b340f1ad2c |
Start time (UTC): | 16:38:20 |
Start date (UTC): | 30/10/2024 |
Path: | /usr/bin/grep |
Arguments: | grep ens160 |
File size: | 199136 bytes |
MD5 hash: | 1e6ebb9dd094f774478f72727bdba0f5 |
Start time (UTC): | 16:38:20 |
Start date (UTC): | 30/10/2024 |
Path: | /usr/bin/bash |
Arguments: | - |
File size: | 1183448 bytes |
MD5 hash: | 7063c3930affe123baecd3b340f1ad2c |
Start time (UTC): | 16:38:20 |
Start date (UTC): | 30/10/2024 |
Path: | /usr/bin/awk |
Arguments: | awk "{print $2}" |
File size: | 711136 bytes |
MD5 hash: | 7e9b2ed1272331cfbd2aac2e5eb3f84b |
Start time (UTC): | 16:38:20 |
Start date (UTC): | 30/10/2024 |
Path: | /tmp/zone.arm.elf |
Arguments: | - |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 16:38:20 |
Start date (UTC): | 30/10/2024 |
Path: | /usr/bin/bash |
Arguments: | bash -c "cat /proc/net/dev |grep ens160 |awk '{print $10}'" |
File size: | 1183448 bytes |
MD5 hash: | 7063c3930affe123baecd3b340f1ad2c |
Start time (UTC): | 16:38:20 |
Start date (UTC): | 30/10/2024 |
Path: | /usr/bin/bash |
Arguments: | - |
File size: | 1183448 bytes |
MD5 hash: | 7063c3930affe123baecd3b340f1ad2c |
Start time (UTC): | 16:38:20 |
Start date (UTC): | 30/10/2024 |
Path: | /usr/bin/cat |
Arguments: | cat /proc/net/dev |
File size: | 43416 bytes |
MD5 hash: | 7e9d213e404ad3bb82e4ebb2e1f2c1b3 |
Start time (UTC): | 16:38:20 |
Start date (UTC): | 30/10/2024 |
Path: | /usr/bin/bash |
Arguments: | - |
File size: | 1183448 bytes |
MD5 hash: | 7063c3930affe123baecd3b340f1ad2c |
Start time (UTC): | 16:38:20 |
Start date (UTC): | 30/10/2024 |
Path: | /usr/bin/grep |
Arguments: | grep ens160 |
File size: | 199136 bytes |
MD5 hash: | 1e6ebb9dd094f774478f72727bdba0f5 |
Start time (UTC): | 16:38:20 |
Start date (UTC): | 30/10/2024 |
Path: | /usr/bin/bash |
Arguments: | - |
File size: | 1183448 bytes |
MD5 hash: | 7063c3930affe123baecd3b340f1ad2c |
Start time (UTC): | 16:38:20 |
Start date (UTC): | 30/10/2024 |
Path: | /usr/bin/awk |
Arguments: | awk "{print $10}" |
File size: | 711136 bytes |
MD5 hash: | 7e9b2ed1272331cfbd2aac2e5eb3f84b |
Start time (UTC): | 16:39:20 |
Start date (UTC): | 30/10/2024 |
Path: | /tmp/zone.arm.elf |
Arguments: | - |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 16:39:20 |
Start date (UTC): | 30/10/2024 |
Path: | /usr/bin/bash |
Arguments: | bash -c "cat /proc/net/dev |grep ens160 |awk '{print $2}'" |
File size: | 1183448 bytes |
MD5 hash: | 7063c3930affe123baecd3b340f1ad2c |
Start time (UTC): | 16:39:20 |
Start date (UTC): | 30/10/2024 |
Path: | /usr/bin/bash |
Arguments: | - |
File size: | 1183448 bytes |
MD5 hash: | 7063c3930affe123baecd3b340f1ad2c |
Start time (UTC): | 16:39:20 |
Start date (UTC): | 30/10/2024 |
Path: | /usr/bin/cat |
Arguments: | cat /proc/net/dev |
File size: | 43416 bytes |
MD5 hash: | 7e9d213e404ad3bb82e4ebb2e1f2c1b3 |
Start time (UTC): | 16:39:20 |
Start date (UTC): | 30/10/2024 |
Path: | /usr/bin/bash |
Arguments: | - |
File size: | 1183448 bytes |
MD5 hash: | 7063c3930affe123baecd3b340f1ad2c |
Start time (UTC): | 16:39:20 |
Start date (UTC): | 30/10/2024 |
Path: | /usr/bin/grep |
Arguments: | grep ens160 |
File size: | 199136 bytes |
MD5 hash: | 1e6ebb9dd094f774478f72727bdba0f5 |
Start time (UTC): | 16:39:20 |
Start date (UTC): | 30/10/2024 |
Path: | /usr/bin/bash |
Arguments: | - |
File size: | 1183448 bytes |
MD5 hash: | 7063c3930affe123baecd3b340f1ad2c |
Start time (UTC): | 16:39:20 |
Start date (UTC): | 30/10/2024 |
Path: | /usr/bin/awk |
Arguments: | awk "{print $2}" |
File size: | 711136 bytes |
MD5 hash: | 7e9b2ed1272331cfbd2aac2e5eb3f84b |
Start time (UTC): | 16:39:20 |
Start date (UTC): | 30/10/2024 |
Path: | /tmp/zone.arm.elf |
Arguments: | - |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 16:39:20 |
Start date (UTC): | 30/10/2024 |
Path: | /usr/bin/bash |
Arguments: | bash -c "cat /proc/net/dev |grep ens160 |awk '{print $10}'" |
File size: | 1183448 bytes |
MD5 hash: | 7063c3930affe123baecd3b340f1ad2c |
Start time (UTC): | 16:39:20 |
Start date (UTC): | 30/10/2024 |
Path: | /usr/bin/bash |
Arguments: | - |
File size: | 1183448 bytes |
MD5 hash: | 7063c3930affe123baecd3b340f1ad2c |
Start time (UTC): | 16:39:20 |
Start date (UTC): | 30/10/2024 |
Path: | /usr/bin/cat |
Arguments: | cat /proc/net/dev |
File size: | 43416 bytes |
MD5 hash: | 7e9d213e404ad3bb82e4ebb2e1f2c1b3 |
Start time (UTC): | 16:39:20 |
Start date (UTC): | 30/10/2024 |
Path: | /usr/bin/bash |
Arguments: | - |
File size: | 1183448 bytes |
MD5 hash: | 7063c3930affe123baecd3b340f1ad2c |
Start time (UTC): | 16:39:20 |
Start date (UTC): | 30/10/2024 |
Path: | /usr/bin/grep |
Arguments: | grep ens160 |
File size: | 199136 bytes |
MD5 hash: | 1e6ebb9dd094f774478f72727bdba0f5 |
Start time (UTC): | 16:39:20 |
Start date (UTC): | 30/10/2024 |
Path: | /usr/bin/bash |
Arguments: | - |
File size: | 1183448 bytes |
MD5 hash: | 7063c3930affe123baecd3b340f1ad2c |
Start time (UTC): | 16:39:20 |
Start date (UTC): | 30/10/2024 |
Path: | /usr/bin/awk |
Arguments: | awk "{print $10}" |
File size: | 711136 bytes |
MD5 hash: | 7e9b2ed1272331cfbd2aac2e5eb3f84b |