Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
zone.x86_64.elf

Overview

General Information

Sample name:zone.x86_64.elf
Analysis ID:1546569
MD5:a37d645e921d2b4fcefc60b0dbec3ff7
SHA1:0b8996c0ea01fb84ba3cfced6c0a731774cd2984
SHA256:ac6cf9cb11f0bb979419e054da589b4f049e05db5bd650d6a3475f7b6f5c0fce
Tags:elfuser-abuse_ch
Infos:

Detection

Score:24
Range:0 - 100
Whitelisted:false

Signatures

Sample is packed with UPX
ELF contains segments with high entropy indicating compressed/encrypted content
Executes commands using a shell command-line interpreter
Executes the "grep" command used to find patterns in files or piped streams
Reads CPU information from /sys indicative of miner or evasive malware
Reads system information from the proc file system
Sample contains only a LOAD segment without any section mappings
Sample listens on a socket
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1546569
Start date and time:2024-11-01 05:47:08 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 6m 5s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:zone.x86_64.elf
Detection:SUS
Classification:sus24.evad.linELF@0/0@0/0
  • Some HTTP raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
Command:/tmp/zone.x86_64.elf
PID:6238
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
main:{"arch":"amd64","flags":["L","X","R"],"local":"192.168.2.23","mac":"00505698912c","tag":"","uptime":0,"version":"2.0.29"}[1;40;36m23:47:51 connected to 38.60.221.177:80[0m
[1;40;37m23:48:01 info modified by handshake:{"arch":"amd64","connected":1730436472,"flags":["L","X","R"],"ip":"173.254.250.82","local":"192.168.2.23","mac":"00505698912c_173.254.250.82","tag":"","uptime":0,"version":"2.0.29"}[0m
Standard Error:2024/10/31 23:48:01 timeout: 2m0s
2024/10/31 23:48:01 [*] get job
2024/10/31 23:48:01 timeout: 2m0s
2024/10/31 23:48:01 timeout: 2m0s
2024/10/31 23:48:01 timeout: 2m0s
2024/10/31 23:48:01 timeout: 2m0s
2024/10/31 23:48:01 timeout: 2m0s
  • system is lnxubuntu20
  • zone.x86_64.elf (PID: 6238, Parent: 6148, MD5: a37d645e921d2b4fcefc60b0dbec3ff7) Arguments: /tmp/zone.x86_64.elf
    • zone.x86_64.elf (PID: 6242, Parent: 6238, MD5: a37d645e921d2b4fcefc60b0dbec3ff7) Arguments: /tmp/zone.x86_64.elf -b
      • bash (PID: 6254, Parent: 6242, MD5: 7063c3930affe123baecd3b340f1ad2c) Arguments: /bin/bash -c uptime
      • uptime (PID: 6254, Parent: 6242, MD5: 3ad70d8e33316ac713bf25c2ddf2fb14) Arguments: uptime
      • bash (PID: 6255, Parent: 6242, MD5: 7063c3930affe123baecd3b340f1ad2c) Arguments: bash -c "cat /proc/net/dev |grep ens160 |awk '{print $2}'"
        • bash New Fork (PID: 6256, Parent: 6255)
        • cat (PID: 6256, Parent: 6255, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /proc/net/dev
        • bash New Fork (PID: 6257, Parent: 6255)
        • grep (PID: 6257, Parent: 6255, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep ens160
        • bash New Fork (PID: 6258, Parent: 6255)
        • awk (PID: 6258, Parent: 6255, MD5: 7e9b2ed1272331cfbd2aac2e5eb3f84b) Arguments: awk "{print $2}"
      • bash (PID: 6259, Parent: 6242, MD5: 7063c3930affe123baecd3b340f1ad2c) Arguments: bash -c "cat /proc/net/dev |grep ens160 |awk '{print $10}'"
        • bash New Fork (PID: 6261, Parent: 6259)
        • cat (PID: 6261, Parent: 6259, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /proc/net/dev
        • bash New Fork (PID: 6262, Parent: 6259)
        • grep (PID: 6262, Parent: 6259, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep ens160
        • bash New Fork (PID: 6263, Parent: 6259)
        • awk (PID: 6263, Parent: 6259, MD5: 7e9b2ed1272331cfbd2aac2e5eb3f84b) Arguments: awk "{print $10}"
      • bash (PID: 6305, Parent: 6242, MD5: 7063c3930affe123baecd3b340f1ad2c) Arguments: bash -c "cat /proc/net/dev |grep ens160 |awk '{print $2}'"
        • bash New Fork (PID: 6306, Parent: 6305)
        • cat (PID: 6306, Parent: 6305, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /proc/net/dev
        • bash New Fork (PID: 6307, Parent: 6305)
        • grep (PID: 6307, Parent: 6305, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep ens160
        • bash New Fork (PID: 6308, Parent: 6305)
        • awk (PID: 6308, Parent: 6305, MD5: 7e9b2ed1272331cfbd2aac2e5eb3f84b) Arguments: awk "{print $2}"
      • bash (PID: 6309, Parent: 6242, MD5: 7063c3930affe123baecd3b340f1ad2c) Arguments: bash -c "cat /proc/net/dev |grep ens160 |awk '{print $10}'"
        • bash New Fork (PID: 6310, Parent: 6309)
        • cat (PID: 6310, Parent: 6309, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /proc/net/dev
        • bash New Fork (PID: 6311, Parent: 6309)
        • grep (PID: 6311, Parent: 6309, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep ens160
        • bash New Fork (PID: 6312, Parent: 6309)
        • awk (PID: 6312, Parent: 6309, MD5: 7e9b2ed1272331cfbd2aac2e5eb3f84b) Arguments: awk "{print $10}"
      • bash (PID: 6342, Parent: 6242, MD5: 7063c3930affe123baecd3b340f1ad2c) Arguments: bash -c "cat /proc/net/dev |grep ens160 |awk '{print $2}'"
        • bash New Fork (PID: 6343, Parent: 6342)
        • cat (PID: 6343, Parent: 6342, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /proc/net/dev
        • bash New Fork (PID: 6344, Parent: 6342)
        • grep (PID: 6344, Parent: 6342, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep ens160
        • bash New Fork (PID: 6345, Parent: 6342)
        • awk (PID: 6345, Parent: 6342, MD5: 7e9b2ed1272331cfbd2aac2e5eb3f84b) Arguments: awk "{print $2}"
      • bash (PID: 6346, Parent: 6242, MD5: 7063c3930affe123baecd3b340f1ad2c) Arguments: bash -c "cat /proc/net/dev |grep ens160 |awk '{print $10}'"
        • bash New Fork (PID: 6347, Parent: 6346)
        • cat (PID: 6347, Parent: 6346, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /proc/net/dev
        • bash New Fork (PID: 6348, Parent: 6346)
        • grep (PID: 6348, Parent: 6346, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep ens160
        • bash New Fork (PID: 6349, Parent: 6346)
        • awk (PID: 6349, Parent: 6346, MD5: 7e9b2ed1272331cfbd2aac2e5eb3f84b) Arguments: awk "{print $10}"
  • cleanup
No yara matches
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results
Source: /usr/bin/uptime (PID: 6254)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
Source: /tmp/zone.x86_64.elf (PID: 6242)Socket: [::]:14820Jump to behavior
Source: unknownTCP traffic detected without corresponding DNS query: 38.60.221.177
Source: unknownTCP traffic detected without corresponding DNS query: 38.60.221.177
Source: unknownTCP traffic detected without corresponding DNS query: 38.60.221.177
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 38.60.221.177
Source: unknownTCP traffic detected without corresponding DNS query: 38.60.221.177
Source: unknownTCP traffic detected without corresponding DNS query: 38.60.221.177
Source: unknownTCP traffic detected without corresponding DNS query: 38.60.221.177
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 38.60.221.177
Source: unknownTCP traffic detected without corresponding DNS query: 38.60.221.177
Source: unknownTCP traffic detected without corresponding DNS query: 38.60.221.177
Source: unknownTCP traffic detected without corresponding DNS query: 38.60.221.177
Source: unknownTCP traffic detected without corresponding DNS query: 38.60.221.177
Source: unknownTCP traffic detected without corresponding DNS query: 38.60.221.177
Source: unknownTCP traffic detected without corresponding DNS query: 38.60.221.177
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 38.60.221.177
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 38.60.221.177
Source: unknownTCP traffic detected without corresponding DNS query: 38.60.221.177
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 38.60.221.177
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 38.60.221.177
Source: unknownTCP traffic detected without corresponding DNS query: 38.60.221.177
Source: unknownTCP traffic detected without corresponding DNS query: 38.60.221.177
Source: unknownTCP traffic detected without corresponding DNS query: 38.60.221.177
Source: unknownTCP traffic detected without corresponding DNS query: 38.60.221.177
Source: unknownTCP traffic detected without corresponding DNS query: 38.60.221.177
Source: unknownTCP traffic detected without corresponding DNS query: 38.60.221.177
Source: unknownTCP traffic detected without corresponding DNS query: 38.60.221.177
Source: unknownTCP traffic detected without corresponding DNS query: 38.60.221.177
Source: unknownTCP traffic detected without corresponding DNS query: 38.60.221.177
Source: unknownTCP traffic detected without corresponding DNS query: 38.60.221.177
Source: unknownTCP traffic detected without corresponding DNS query: 38.60.221.177
Source: unknownTCP traffic detected without corresponding DNS query: 38.60.221.177
Source: zone.x86_64.elfString found in binary or memory: http://upx.sf.net
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
Source: LOAD without section mappingsProgram segment: 0x400000
Source: classification engineClassification label: sus24.evad.linELF@0/0@0/0

Data Obfuscation

barindex
Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
Source: initial sampleString containing UPX found: $Id: UPX 4.24 Copyright (C) 1996-2024 the UPX Team. All Rights Reserved. $
Source: /tmp/zone.x86_64.elf (PID: 6254)Shell command executed: /bin/bash -c uptimeJump to behavior
Source: /usr/bin/bash (PID: 6257)Grep executable: /usr/bin/grep -> grep ens160Jump to behavior
Source: /usr/bin/bash (PID: 6262)Grep executable: /usr/bin/grep -> grep ens160Jump to behavior
Source: /usr/bin/bash (PID: 6307)Grep executable: /usr/bin/grep -> grep ens160Jump to behavior
Source: /usr/bin/bash (PID: 6311)Grep executable: /usr/bin/grep -> grep ens160Jump to behavior
Source: /usr/bin/bash (PID: 6344)Grep executable: /usr/bin/grep -> grep ens160Jump to behavior
Source: /usr/bin/bash (PID: 6348)Grep executable: /usr/bin/grep -> grep ens160Jump to behavior
Source: /tmp/zone.x86_64.elf (PID: 6238)Reads from proc file: /proc/statJump to behavior
Source: /tmp/zone.x86_64.elf (PID: 6242)Reads from proc file: /proc/statJump to behavior
Source: /tmp/zone.x86_64.elf (PID: 6242)Reads from proc file: /proc/sys/net/core/somaxconnJump to behavior
Source: /usr/bin/bash (PID: 6258)Awk executable: /usr/bin/awk -> awk "{print $2}"Jump to behavior
Source: /usr/bin/bash (PID: 6263)Awk executable: /usr/bin/awk -> awk "{print $10}"Jump to behavior
Source: /usr/bin/bash (PID: 6308)Awk executable: /usr/bin/awk -> awk "{print $2}"Jump to behavior
Source: /usr/bin/bash (PID: 6312)Awk executable: /usr/bin/awk -> awk "{print $10}"Jump to behavior
Source: /usr/bin/bash (PID: 6345)Awk executable: /usr/bin/awk -> awk "{print $2}"Jump to behavior
Source: /usr/bin/bash (PID: 6349)Awk executable: /usr/bin/awk -> awk "{print $10}"Jump to behavior
Source: submitted sampleStderr: 2024/10/31 23:48:01 timeout: 2m0s2024/10/31 23:48:01 [*] get job2024/10/31 23:48:01 timeout: 2m0s2024/10/31 23:48:01 timeout: 2m0s2024/10/31 23:48:01 timeout: 2m0s2024/10/31 23:48:01 timeout: 2m0s2024/10/31 23:48:01 timeout: 2m0s: exit code = 0
Source: zone.x86_64.elfSubmission file: segment LOAD with 7.8145 entropy (max. 8.0)
Source: zone.x86_64.elfSubmission file: segment LOAD with 7.9999 entropy (max. 8.0)
Source: /usr/bin/uptime (PID: 6254)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
Source: /bin/bash (PID: 6254)Queries kernel information via 'uname': Jump to behavior
Source: /usr/bin/bash (PID: 6255)Queries kernel information via 'uname': Jump to behavior
Source: /usr/bin/bash (PID: 6259)Queries kernel information via 'uname': Jump to behavior
Source: /usr/bin/bash (PID: 6305)Queries kernel information via 'uname': Jump to behavior
Source: /usr/bin/bash (PID: 6309)Queries kernel information via 'uname': Jump to behavior
Source: /usr/bin/bash (PID: 6342)Queries kernel information via 'uname': Jump to behavior
Source: /usr/bin/bash (PID: 6346)Queries kernel information via 'uname': Jump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity Information1
Scripting
Valid Accounts1
Command and Scripting Interpreter
1
Scripting
Path Interception11
Obfuscated Files or Information
OS Credential Dumping1
Security Software Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS Memory2
System Information Discovery
Remote Desktop ProtocolData from Removable Media1
Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1546569 Sample: zone.x86_64.elf Startdate: 01/11/2024 Architecture: LINUX Score: 24 39 109.202.202.202, 80 INIT7CH Switzerland 2->39 41 38.60.221.177, 39342, 39344, 80 COGENT-174US United States 2->41 43 2 other IPs or domains 2->43 45 Sample is packed with UPX 2->45 9 zone.x86_64.elf 2->9         started        signatures3 process4 process5 11 zone.x86_64.elf zone.x86_64.elf 9->11         started        process6 13 zone.x86_64.elf bash 11->13         started        15 zone.x86_64.elf bash 11->15         started        17 zone.x86_64.elf bash 11->17         started        19 4 other processes 11->19 process7 21 bash cat 13->21         started        23 bash grep 13->23         started        25 bash awk 13->25         started        27 bash cat 15->27         started        29 bash grep 15->29         started        31 bash awk 15->31         started        33 bash cat 17->33         started        35 2 other processes 17->35 37 9 other processes 19->37
SourceDetectionScannerLabelLink
zone.x86_64.elf5%ReversingLabs
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
http://upx.sf.net0%URL Reputationsafe
http://upx.sf.net0%URL Reputationsafe
No contacted domains info
NameSourceMaliciousAntivirus DetectionReputation
http://upx.sf.netzone.x86_64.elftrue
  • URL Reputation: safe
  • URL Reputation: safe
unknown
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs
IPDomainCountryFlagASNASN NameMalicious
38.60.221.177
unknownUnited States
174COGENT-174USfalse
109.202.202.202
unknownSwitzerland
13030INIT7CHfalse
91.189.91.43
unknownUnited Kingdom
41231CANONICAL-ASGBfalse
91.189.91.42
unknownUnited Kingdom
41231CANONICAL-ASGBfalse
MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
  • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
91.189.91.43armv6l.elfGet hashmaliciousGafgyt, MiraiBrowse
    m68k.elfGet hashmaliciousGafgyt, MiraiBrowse
      i686.elfGet hashmaliciousGafgyt, MiraiBrowse
        boatnet.arm.elfGet hashmaliciousMiraiBrowse
          armv5l.elfGet hashmaliciousGafgyt, MiraiBrowse
            .i.elfGet hashmaliciousUnknownBrowse
              harm4.elfGet hashmaliciousUnknownBrowse
                shngijernbh.mips.elfGet hashmaliciousGafgyt, MiraiBrowse
                  shngijernbh.ppc.elfGet hashmaliciousGafgyt, MiraiBrowse
                    linux_mips.elfGet hashmaliciousChaosBrowse
                      91.189.91.42armv6l.elfGet hashmaliciousGafgyt, MiraiBrowse
                        m68k.elfGet hashmaliciousGafgyt, MiraiBrowse
                          i686.elfGet hashmaliciousGafgyt, MiraiBrowse
                            armv4l.elfGet hashmaliciousGafgyt, MiraiBrowse
                              boatnet.arm.elfGet hashmaliciousMiraiBrowse
                                armv5l.elfGet hashmaliciousGafgyt, MiraiBrowse
                                  .i.elfGet hashmaliciousUnknownBrowse
                                    harm4.elfGet hashmaliciousUnknownBrowse
                                      shngijernbh.mips.elfGet hashmaliciousGafgyt, MiraiBrowse
                                        shngijernbh.ppc.elfGet hashmaliciousGafgyt, MiraiBrowse
                                          No context
                                          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                          CANONICAL-ASGBarmv6l.elfGet hashmaliciousGafgyt, MiraiBrowse
                                          • 91.189.91.42
                                          m68k.elfGet hashmaliciousGafgyt, MiraiBrowse
                                          • 91.189.91.42
                                          i686.elfGet hashmaliciousGafgyt, MiraiBrowse
                                          • 91.189.91.42
                                          armv4l.elfGet hashmaliciousGafgyt, MiraiBrowse
                                          • 91.189.91.42
                                          boatnet.arm.elfGet hashmaliciousMiraiBrowse
                                          • 91.189.91.42
                                          armv5l.elfGet hashmaliciousGafgyt, MiraiBrowse
                                          • 91.189.91.42
                                          boatnet.m68k.elfGet hashmaliciousMiraiBrowse
                                          • 185.125.190.26
                                          .i.elfGet hashmaliciousUnknownBrowse
                                          • 91.189.91.42
                                          harm4.elfGet hashmaliciousUnknownBrowse
                                          • 91.189.91.42
                                          shngijernbh.mips.elfGet hashmaliciousGafgyt, MiraiBrowse
                                          • 91.189.91.42
                                          CANONICAL-ASGBarmv6l.elfGet hashmaliciousGafgyt, MiraiBrowse
                                          • 91.189.91.42
                                          m68k.elfGet hashmaliciousGafgyt, MiraiBrowse
                                          • 91.189.91.42
                                          i686.elfGet hashmaliciousGafgyt, MiraiBrowse
                                          • 91.189.91.42
                                          armv4l.elfGet hashmaliciousGafgyt, MiraiBrowse
                                          • 91.189.91.42
                                          boatnet.arm.elfGet hashmaliciousMiraiBrowse
                                          • 91.189.91.42
                                          armv5l.elfGet hashmaliciousGafgyt, MiraiBrowse
                                          • 91.189.91.42
                                          boatnet.m68k.elfGet hashmaliciousMiraiBrowse
                                          • 185.125.190.26
                                          .i.elfGet hashmaliciousUnknownBrowse
                                          • 91.189.91.42
                                          harm4.elfGet hashmaliciousUnknownBrowse
                                          • 91.189.91.42
                                          shngijernbh.mips.elfGet hashmaliciousGafgyt, MiraiBrowse
                                          • 91.189.91.42
                                          INIT7CHarmv6l.elfGet hashmaliciousGafgyt, MiraiBrowse
                                          • 109.202.202.202
                                          m68k.elfGet hashmaliciousGafgyt, MiraiBrowse
                                          • 109.202.202.202
                                          i686.elfGet hashmaliciousGafgyt, MiraiBrowse
                                          • 109.202.202.202
                                          armv4l.elfGet hashmaliciousGafgyt, MiraiBrowse
                                          • 109.202.202.202
                                          boatnet.arm.elfGet hashmaliciousMiraiBrowse
                                          • 109.202.202.202
                                          armv5l.elfGet hashmaliciousGafgyt, MiraiBrowse
                                          • 109.202.202.202
                                          .i.elfGet hashmaliciousUnknownBrowse
                                          • 109.202.202.202
                                          harm4.elfGet hashmaliciousUnknownBrowse
                                          • 109.202.202.202
                                          shngijernbh.mips.elfGet hashmaliciousGafgyt, MiraiBrowse
                                          • 109.202.202.202
                                          shngijernbh.ppc.elfGet hashmaliciousGafgyt, MiraiBrowse
                                          • 109.202.202.202
                                          COGENT-174USNF_Payment_Ref_FAN930276.exeGet hashmaliciousFormBookBrowse
                                          • 38.88.82.56
                                          71Ah2iqq3g.dllGet hashmaliciousAmadeyBrowse
                                          • 45.93.20.135
                                          71Ah2iqq3g.dllGet hashmaliciousAmadeyBrowse
                                          • 45.93.20.135
                                          1nnlXctdko.dllGet hashmaliciousAmadeyBrowse
                                          • 45.93.20.135
                                          HT9324-25 1x40HC LDHFCLDEHAM29656 MRSU5087674.exeGet hashmaliciousFormBookBrowse
                                          • 154.23.181.7
                                          18in SPA-198-2024.exeGet hashmaliciousFormBookBrowse
                                          • 38.88.82.56
                                          WARUNKI UMOWY-pdf.bat.exeGet hashmaliciousFormBook, GuLoaderBrowse
                                          • 38.88.82.56
                                          bszYGSIHuU.exeGet hashmaliciousUnknownBrowse
                                          • 38.180.123.95
                                          819614 - Midways Freight Ltd.xlsmGet hashmaliciousUnknownBrowse
                                          • 143.244.56.49
                                          wZU2edEGL3.elfGet hashmaliciousUnknownBrowse
                                          • 38.60.72.192
                                          No context
                                          No context
                                          No created / dropped files found
                                          File type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, no section header
                                          Entropy (8bit):7.999938356321077
                                          TrID:
                                          • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
                                          • ELF Executable and Linkable format (generic) (4004/1) 49.84%
                                          File name:zone.x86_64.elf
                                          File size:3'419'156 bytes
                                          MD5:a37d645e921d2b4fcefc60b0dbec3ff7
                                          SHA1:0b8996c0ea01fb84ba3cfced6c0a731774cd2984
                                          SHA256:ac6cf9cb11f0bb979419e054da589b4f049e05db5bd650d6a3475f7b6f5c0fce
                                          SHA512:e3d6fd6b280ac850346e667db7d91150ae7acfaeda4b21d90dc43c0320a379ac24bcaca8298fb4355245791330cb686a4fd4e964b25104c03704adf461fb0cbf
                                          SSDEEP:98304:8e1ceEQAx+UDo2TfwA8vLKNNyGiG1pdPTRmwQgpy:WeEuuo2UoyG7rdPW
                                          TLSH:18F5332F60EB55FECBB67D910C562638F7EDC560412A58C929C62CAF9097F7F172A200
                                          File Content Preview:.ELF..............>.............@...................@.8...........................@.......@...............................................X.......X......*4......*4.............Q.td....................................................!.jzUPX!............@.Y

                                          ELF header

                                          Class:ELF64
                                          Data:2's complement, little endian
                                          Version:1 (current)
                                          Machine:Advanced Micro Devices X86-64
                                          Version Number:0x1
                                          Type:EXEC (Executable file)
                                          OS/ABI:UNIX - System V
                                          ABI Version:0
                                          Entry Point Address:0x18c16a8
                                          Flags:0x0
                                          ELF Header Size:64
                                          Program Header Offset:64
                                          Program Header Size:56
                                          Number of Program Headers:3
                                          Section Header Offset:0
                                          Section Header Size:0
                                          Number of Section Headers:0
                                          Header String Table Index:0
                                          TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                          LOAD0x00x4000000x4000000x10000x117f2807.81450x6RW 0x1000
                                          LOAD0x00x15800000x15800000x342ab60x342ab67.99990x5R E0x1000
                                          GNU_STACK0x00x00x00x00x00.00000x6RW 0x8
                                          TimestampSource PortDest PortSource IPDest IP
                                          Nov 1, 2024 05:47:51.139904022 CET3934280192.168.2.2338.60.221.177
                                          Nov 1, 2024 05:47:51.145075083 CET803934238.60.221.177192.168.2.23
                                          Nov 1, 2024 05:47:51.145154953 CET3934280192.168.2.2338.60.221.177
                                          Nov 1, 2024 05:47:51.146893024 CET3934280192.168.2.2338.60.221.177
                                          Nov 1, 2024 05:47:51.152342081 CET803934238.60.221.177192.168.2.23
                                          Nov 1, 2024 05:47:52.059530973 CET43928443192.168.2.2391.189.91.42
                                          Nov 1, 2024 05:47:52.087129116 CET803934238.60.221.177192.168.2.23
                                          Nov 1, 2024 05:47:52.087291002 CET3934280192.168.2.2338.60.221.177
                                          Nov 1, 2024 05:47:52.091079950 CET3934280192.168.2.2338.60.221.177
                                          Nov 1, 2024 05:47:52.095946074 CET803934238.60.221.177192.168.2.23
                                          Nov 1, 2024 05:47:52.097345114 CET3934280192.168.2.2338.60.221.177
                                          Nov 1, 2024 05:47:52.102250099 CET803934238.60.221.177192.168.2.23
                                          Nov 1, 2024 05:47:52.391104937 CET803934238.60.221.177192.168.2.23
                                          Nov 1, 2024 05:47:52.391172886 CET3934280192.168.2.2338.60.221.177
                                          Nov 1, 2024 05:47:57.690771103 CET42836443192.168.2.2391.189.91.43
                                          Nov 1, 2024 05:47:59.226527929 CET4251680192.168.2.23109.202.202.202
                                          Nov 1, 2024 05:48:02.109805107 CET3934280192.168.2.2338.60.221.177
                                          Nov 1, 2024 05:48:02.112999916 CET3934280192.168.2.2338.60.221.177
                                          Nov 1, 2024 05:48:02.114761114 CET803934238.60.221.177192.168.2.23
                                          Nov 1, 2024 05:48:02.116223097 CET3934280192.168.2.2338.60.221.177
                                          Nov 1, 2024 05:48:02.117885113 CET803934238.60.221.177192.168.2.23
                                          Nov 1, 2024 05:48:02.121108055 CET803934238.60.221.177192.168.2.23
                                          Nov 1, 2024 05:48:02.740669012 CET803934238.60.221.177192.168.2.23
                                          Nov 1, 2024 05:48:02.740891933 CET3934280192.168.2.2338.60.221.177
                                          Nov 1, 2024 05:48:02.741185904 CET803934238.60.221.177192.168.2.23
                                          Nov 1, 2024 05:48:02.741216898 CET803934238.60.221.177192.168.2.23
                                          Nov 1, 2024 05:48:02.741281033 CET3934280192.168.2.2338.60.221.177
                                          Nov 1, 2024 05:48:02.741291046 CET3934280192.168.2.2338.60.221.177
                                          Nov 1, 2024 05:48:02.747684956 CET3934280192.168.2.2338.60.221.177
                                          Nov 1, 2024 05:48:02.752460957 CET803934238.60.221.177192.168.2.23
                                          Nov 1, 2024 05:48:13.304596901 CET43928443192.168.2.2391.189.91.42
                                          Nov 1, 2024 05:48:17.911978960 CET3934280192.168.2.2338.60.221.177
                                          Nov 1, 2024 05:48:17.917037964 CET803934238.60.221.177192.168.2.23
                                          Nov 1, 2024 05:48:23.543140888 CET42836443192.168.2.2391.189.91.43
                                          Nov 1, 2024 05:48:29.686369896 CET4251680192.168.2.23109.202.202.202
                                          Nov 1, 2024 05:48:33.013870001 CET3934280192.168.2.2338.60.221.177
                                          Nov 1, 2024 05:48:33.018984079 CET803934238.60.221.177192.168.2.23
                                          Nov 1, 2024 05:48:48.115664005 CET3934280192.168.2.2338.60.221.177
                                          Nov 1, 2024 05:48:48.120744944 CET803934238.60.221.177192.168.2.23
                                          Nov 1, 2024 05:48:54.258987904 CET43928443192.168.2.2391.189.91.42
                                          Nov 1, 2024 05:49:03.217719078 CET3934280192.168.2.2338.60.221.177
                                          Nov 1, 2024 05:49:03.222743988 CET803934238.60.221.177192.168.2.23
                                          Nov 1, 2024 05:49:14.736121893 CET42836443192.168.2.2391.189.91.43
                                          Nov 1, 2024 05:49:18.319577932 CET3934280192.168.2.2338.60.221.177
                                          Nov 1, 2024 05:49:18.327369928 CET803934238.60.221.177192.168.2.23
                                          Nov 1, 2024 05:49:33.421381950 CET3934280192.168.2.2338.60.221.177
                                          Nov 1, 2024 05:49:33.426835060 CET803934238.60.221.177192.168.2.23
                                          Nov 1, 2024 05:49:48.523438931 CET3934280192.168.2.2338.60.221.177
                                          Nov 1, 2024 05:49:48.528532982 CET803934238.60.221.177192.168.2.23
                                          Nov 1, 2024 05:50:02.737680912 CET3934280192.168.2.2338.60.221.177
                                          Nov 1, 2024 05:50:02.738454103 CET3934280192.168.2.2338.60.221.177
                                          Nov 1, 2024 05:50:02.742830038 CET803934238.60.221.177192.168.2.23
                                          Nov 1, 2024 05:50:02.743832111 CET803934238.60.221.177192.168.2.23
                                          Nov 1, 2024 05:50:02.743905067 CET3934280192.168.2.2338.60.221.177
                                          Nov 1, 2024 05:50:32.081644058 CET3934480192.168.2.2338.60.221.177
                                          Nov 1, 2024 05:50:32.086604118 CET803934438.60.221.177192.168.2.23
                                          Nov 1, 2024 05:50:32.086699963 CET3934480192.168.2.2338.60.221.177
                                          Nov 1, 2024 05:50:32.088749886 CET3934480192.168.2.2338.60.221.177
                                          Nov 1, 2024 05:50:32.093549967 CET803934438.60.221.177192.168.2.23
                                          Nov 1, 2024 05:50:33.030997038 CET803934438.60.221.177192.168.2.23
                                          Nov 1, 2024 05:50:33.031073093 CET3934480192.168.2.2338.60.221.177
                                          Nov 1, 2024 05:50:33.037270069 CET3934480192.168.2.2338.60.221.177
                                          Nov 1, 2024 05:50:33.042226076 CET803934438.60.221.177192.168.2.23
                                          Nov 1, 2024 05:50:33.187935114 CET3934480192.168.2.2338.60.221.177
                                          Nov 1, 2024 05:50:33.193347931 CET803934438.60.221.177192.168.2.23
                                          Nov 1, 2024 05:50:33.193413019 CET3934480192.168.2.2338.60.221.177
                                          Session IDSource IPSource PortDestination IPDestination Port
                                          0192.168.2.233934238.60.221.17780
                                          TimestampBytes transferredDirectionData
                                          Nov 1, 2024 05:47:51.146893024 CET255OUTData Raw: 16 03 01 00 ee 01 00 00 ea 03 03 a0 b2 c3 78 2e ae 29 04 1e d2 ac d6 a9 d1 88 80 01 b1 3f f6 88 fc c0 05 d6 1b 15 16 d0 35 d6 b7 20 81 50 7c dd 22 9a ca ea 0b 14 8e b7 8d 99 5f 54 82 45 f8 ab 17 7b f3 d3 93 80 ba 03 1d 93 57 03 00 26 c0 2b c0 2f
                                          Data Ascii: x.)?5 P|"_TE{W&+/,0/5{+3&$ vp`E|MR`Fe;]-'
                                          Nov 1, 2024 05:47:52.087129116 CET1230INData Raw: 16 03 03 00 7a 02 00 00 76 03 03 db 77 87 3d 03 f3 22 6e 28 14 37 ec 73 09 c3 92 be 55 3e ff a1 16 69 2d d5 3a e7 cb 12 8e ce cb 20 81 50 7c dd 22 9a ca ea 0b 14 8e b7 8d 99 5f 54 82 45 f8 ab 17 7b f3 d3 93 80 ba 03 1d 93 57 03 13 01 00 00 2e 00
                                          Data Ascii: zvw="n(7sU>i-: P|"_TE{W.+3$ 4_`S3+.sV70X/T/$5I^n]JR3UpHb;$Ka7|qv#b;uHw&:^p*gkG)
                                          Nov 1, 2024 05:47:52.091079950 CET76OUTData Raw: 14 03 03 00 01 01 17 03 03 00 35 91 1e ad db 4b 60 a9 62 9b 81 19 5b 54 6b 60 f7 b9 6c 0b ae a4 ef 39 a1 8c a9 21 07 e2 67 ac e3 1b 6a 6c e9 fd 8c 3e a5 9c 9b bc 80 7e 0e ab 33 a8 df fc d6 05
                                          Data Ascii: 5K`b[Tk`l9!gjl>~3
                                          Nov 1, 2024 05:47:52.097345114 CET215OUTData Raw: 17 03 03 00 c6 2c 6b a7 af 4e 4b 10 f7 ad 19 4f 9c c0 0e 72 7e 81 9c 12 9a 07 40 57 a7 e7 0f 52 af ea 8e 83 bd ed ff 32 3b 22 2f 9c 27 ba 95 2b 50 e5 04 a0 07 39 e2 f3 12 a6 63 41 c8 c8 54 ae c0 c6 af 1c 26 06 97 c4 8c 97 7e 3a dc a6 f3 9b 7f 45
                                          Data Ascii: ,kNKOr~@WR2;"/'+P9cAT&~:E8n+y=2Zjk~W"(O382-_"A1K(c^qw`Lq-#;su0VT|vcsaXd
                                          Nov 1, 2024 05:47:52.391104937 CET237INData Raw: 17 03 03 00 dc 16 23 04 8d c3 90 27 b5 0b 55 71 dc 32 81 88 70 9b 4b 4b d7 17 dd 9b 68 91 be 2b f6 5a 7e 6b d6 a2 c1 b5 87 a0 67 15 36 df f3 95 ab 6a e3 5e 99 58 d3 6c 4b 4c b7 81 d2 f8 be ed bc ac 92 a9 16 67 dc 0b 15 79 1a c5 c3 5f 5d 36 8e 1c
                                          Data Ascii: #'Uq2pKKh+Z~kg6j^XlKLgy_]6,.E@Hd]}jJA;T2KDO!73M$%#TH-X|dkBGE51Jq|.oJJD2rf,~:iVYBv~<S?q<Mq|
                                          Nov 1, 2024 05:48:02.109805107 CET196OUTData Raw: 17 03 03 00 b3 6c bc f4 3c 9b ae b3 c1 58 91 46 4e 28 05 0c 30 cc e7 67 30 ae 0f b6 c4 d0 69 9b 55 68 a3 b2 38 7e b3 d6 da b9 84 5d 7f 8a a9 a4 01 38 fe 5e ee 71 a9 08 e3 5c 86 a2 01 17 06 9d 57 20 fd 44 07 60 79 5c 22 bf ff 04 d9 ec a4 de 41 ad
                                          Data Ascii: l<XFN(0g0iUh8~]8^q\W D`y\"A<Ise'z|.9_mE,0J,:os-loqV\HdlM`FsW;Pg
                                          Nov 1, 2024 05:48:02.112999916 CET388OUTData Raw: 17 03 03 01 73 2c dc b2 95 08 92 71 60 74 c4 8c 2f a5 a0 59 67 37 45 74 e9 b1 02 64 27 e9 f1 2f 46 29 58 62 f3 50 b2 32 60 25 fb 76 ac 62 e0 f9 ba 51 4a 6f 73 0b f4 d3 c8 b7 ac b7 75 80 e6 5d 53 01 93 be 5d 78 22 06 aa d7 0a 9e c4 43 18 c7 5e 65
                                          Data Ascii: s,q`t/Yg7Etd'/F)XbP2`%vbQJosu]S]x"C^egfq<"zQEEUgqUd"r]^W%o_O_kNMOm\4Q?`Ux#n)yzWu"d-NF*a@(!r Q5TG
                                          Nov 1, 2024 05:48:02.116223097 CET198OUTData Raw: 17 03 03 00 b5 3a 85 7f 18 6d 62 43 01 bd db 68 35 9f 28 ef 1c f1 6e 48 e9 f8 61 82 b4 57 3e 4b 26 1c 97 cc d6 8a 5a e0 85 86 a9 42 b3 9d 31 81 26 64 ae d1 f4 1b 2c 1c c3 76 a8 b2 7c 5e 79 50 9d b2 3b 57 60 45 5b 47 c7 c7 09 48 6a 7d 0a a8 a5 d8
                                          Data Ascii: :mbCh5(nHaW>K&ZB1&d,v|^yP;W`E[GHj}W_P,~gArVj:k%.$W#$jT:td{1*KRKe}_B$j{_K
                                          Nov 1, 2024 05:48:02.740669012 CET317INData Raw: 17 03 03 01 2c ea 8e 39 6d 27 15 c3 66 c6 81 1a 59 8e 71 49 03 38 7b f7 89 2c 6a 28 f5 e0 28 18 9e 5a 5c 67 c1 90 9e 24 ff 04 2d 48 b7 f4 bd b6 8c c3 5f c2 36 2e 8b 2e bf 47 5d 60 be 57 cc 90 8f b1 3c 14 7a c7 8f d1 03 45 7a 0d 67 34 cb af 9a b5
                                          Data Ascii: ,9m'fYqI8{,j((Z\g$-H_6..G]`W<zEzg4=va1bBIfBNU=e'Y{0CKgM-K#Yj"4/Kbejg;:PWTG6\gG\19~]x'Em/']x8v+
                                          Nov 1, 2024 05:48:02.741185904 CET196INData Raw: 17 03 03 00 b3 a6 d5 ca 42 cd 8e 6b 26 c4 22 ee 4a 57 36 8b 78 46 5f 37 77 b2 49 91 8f d7 25 46 4c c1 be 3b 36 c1 b5 60 20 5f d3 c3 67 57 94 27 95 67 d5 6a 68 b7 59 14 c4 98 51 71 5f 95 46 57 4e e2 30 c6 33 01 5f 84 d3 ac 36 dd 33 b9 2c 39 1f 8e
                                          Data Ascii: Bk&"JW6xF_7wI%FL;6` _gW'gjhYQq_FWN03_63,9NI5tu1eXpXrvrKJUMu&O4xb@E]P5>'#*X


                                          Session IDSource IPSource PortDestination IPDestination Port
                                          1192.168.2.233934438.60.221.17780
                                          TimestampBytes transferredDirectionData
                                          Nov 1, 2024 05:50:32.088749886 CET255OUTData Raw: 16 03 01 00 ee 01 00 00 ea 03 03 d2 16 c1 70 35 08 42 a2 a2 4c d8 87 72 ed 67 3c dd bf 91 8b c9 c9 fb 00 8a a9 cf 56 d8 88 8f 9e 20 54 16 d9 1c 09 fa cb 08 98 79 5f 41 a8 f0 5c 36 4a 5d 72 6c 4e a6 cd 20 6b c8 05 07 07 a8 7d 41 00 26 c0 2b c0 2f
                                          Data Ascii: p5BLrg<V Ty_A\6J]rlN k}A&+/,0/5{+3&$ CTCD)g
                                          Nov 1, 2024 05:50:33.030997038 CET1230INData Raw: 16 03 03 00 7a 02 00 00 76 03 03 b7 51 dc 41 b4 5e 49 de 41 f1 15 5c f0 ae d9 0a aa 6a e8 cb 55 88 07 18 7a 07 71 5f 11 51 b2 18 20 54 16 d9 1c 09 fa cb 08 98 79 5f 41 a8 f0 5c 36 4a 5d 72 6c 4e a6 cd 20 6b c8 05 07 07 a8 7d 41 13 01 00 00 2e 00
                                          Data Ascii: zvQA^IA\jUzq_Q Ty_A\6J]rlN k}A.+3$ =r]7=DuU8CK)[k*lVd~v.kv\u`!$Ej:L \?[kb:Ty^Bw]VE/h#u#m3WKc
                                          Nov 1, 2024 05:50:33.037270069 CET76OUTData Raw: 14 03 03 00 01 01 17 03 03 00 35 ae 7c 1f df 2f c9 44 8a e8 21 53 dd 27 ea 3b 7c 8a 1a 25 c8 25 68 c3 d6 60 04 77 87 e9 13 26 a2 52 9d 42 9c d7 ea b9 fa b5 85 67 fb fc 9e 3c f0 81 34 13 dc 50
                                          Data Ascii: 5|/D!S';|%%h`w&RBg<4P


                                          System Behavior

                                          Start time (UTC):04:47:49
                                          Start date (UTC):01/11/2024
                                          Path:/tmp/zone.x86_64.elf
                                          Arguments:/tmp/zone.x86_64.elf
                                          File size:3419156 bytes
                                          MD5 hash:a37d645e921d2b4fcefc60b0dbec3ff7

                                          Start time (UTC):04:47:49
                                          Start date (UTC):01/11/2024
                                          Path:/tmp/zone.x86_64.elf
                                          Arguments:-
                                          File size:3419156 bytes
                                          MD5 hash:a37d645e921d2b4fcefc60b0dbec3ff7

                                          Start time (UTC):04:47:49
                                          Start date (UTC):01/11/2024
                                          Path:/tmp/zone.x86_64.elf
                                          Arguments:/tmp/zone.x86_64.elf -b
                                          File size:3419156 bytes
                                          MD5 hash:a37d645e921d2b4fcefc60b0dbec3ff7

                                          Start time (UTC):04:47:50
                                          Start date (UTC):01/11/2024
                                          Path:/tmp/zone.x86_64.elf
                                          Arguments:-
                                          File size:3419156 bytes
                                          MD5 hash:a37d645e921d2b4fcefc60b0dbec3ff7

                                          Start time (UTC):04:47:50
                                          Start date (UTC):01/11/2024
                                          Path:/bin/bash
                                          Arguments:/bin/bash -c uptime
                                          File size:1183448 bytes
                                          MD5 hash:7063c3930affe123baecd3b340f1ad2c

                                          Start time (UTC):04:47:50
                                          Start date (UTC):01/11/2024
                                          Path:/usr/bin/uptime
                                          Arguments:uptime
                                          File size:14568 bytes
                                          MD5 hash:3ad70d8e33316ac713bf25c2ddf2fb14

                                          Start time (UTC):04:47:50
                                          Start date (UTC):01/11/2024
                                          Path:/tmp/zone.x86_64.elf
                                          Arguments:-
                                          File size:3419156 bytes
                                          MD5 hash:a37d645e921d2b4fcefc60b0dbec3ff7

                                          Start time (UTC):04:47:50
                                          Start date (UTC):01/11/2024
                                          Path:/usr/bin/bash
                                          Arguments:bash -c "cat /proc/net/dev |grep ens160 |awk '{print $2}'"
                                          File size:1183448 bytes
                                          MD5 hash:7063c3930affe123baecd3b340f1ad2c

                                          Start time (UTC):04:47:50
                                          Start date (UTC):01/11/2024
                                          Path:/usr/bin/bash
                                          Arguments:-
                                          File size:1183448 bytes
                                          MD5 hash:7063c3930affe123baecd3b340f1ad2c

                                          Start time (UTC):04:47:50
                                          Start date (UTC):01/11/2024
                                          Path:/usr/bin/cat
                                          Arguments:cat /proc/net/dev
                                          File size:43416 bytes
                                          MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

                                          Start time (UTC):04:47:50
                                          Start date (UTC):01/11/2024
                                          Path:/usr/bin/bash
                                          Arguments:-
                                          File size:1183448 bytes
                                          MD5 hash:7063c3930affe123baecd3b340f1ad2c

                                          Start time (UTC):04:47:50
                                          Start date (UTC):01/11/2024
                                          Path:/usr/bin/grep
                                          Arguments:grep ens160
                                          File size:199136 bytes
                                          MD5 hash:1e6ebb9dd094f774478f72727bdba0f5

                                          Start time (UTC):04:47:50
                                          Start date (UTC):01/11/2024
                                          Path:/usr/bin/bash
                                          Arguments:-
                                          File size:1183448 bytes
                                          MD5 hash:7063c3930affe123baecd3b340f1ad2c

                                          Start time (UTC):04:47:50
                                          Start date (UTC):01/11/2024
                                          Path:/usr/bin/awk
                                          Arguments:awk "{print $2}"
                                          File size:711136 bytes
                                          MD5 hash:7e9b2ed1272331cfbd2aac2e5eb3f84b

                                          Start time (UTC):04:47:50
                                          Start date (UTC):01/11/2024
                                          Path:/tmp/zone.x86_64.elf
                                          Arguments:-
                                          File size:3419156 bytes
                                          MD5 hash:a37d645e921d2b4fcefc60b0dbec3ff7

                                          Start time (UTC):04:47:50
                                          Start date (UTC):01/11/2024
                                          Path:/usr/bin/bash
                                          Arguments:bash -c "cat /proc/net/dev |grep ens160 |awk '{print $10}'"
                                          File size:1183448 bytes
                                          MD5 hash:7063c3930affe123baecd3b340f1ad2c

                                          Start time (UTC):04:47:50
                                          Start date (UTC):01/11/2024
                                          Path:/usr/bin/bash
                                          Arguments:-
                                          File size:1183448 bytes
                                          MD5 hash:7063c3930affe123baecd3b340f1ad2c

                                          Start time (UTC):04:47:50
                                          Start date (UTC):01/11/2024
                                          Path:/usr/bin/cat
                                          Arguments:cat /proc/net/dev
                                          File size:43416 bytes
                                          MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

                                          Start time (UTC):04:47:50
                                          Start date (UTC):01/11/2024
                                          Path:/usr/bin/bash
                                          Arguments:-
                                          File size:1183448 bytes
                                          MD5 hash:7063c3930affe123baecd3b340f1ad2c

                                          Start time (UTC):04:47:50
                                          Start date (UTC):01/11/2024
                                          Path:/usr/bin/grep
                                          Arguments:grep ens160
                                          File size:199136 bytes
                                          MD5 hash:1e6ebb9dd094f774478f72727bdba0f5

                                          Start time (UTC):04:47:50
                                          Start date (UTC):01/11/2024
                                          Path:/usr/bin/bash
                                          Arguments:-
                                          File size:1183448 bytes
                                          MD5 hash:7063c3930affe123baecd3b340f1ad2c

                                          Start time (UTC):04:47:50
                                          Start date (UTC):01/11/2024
                                          Path:/usr/bin/awk
                                          Arguments:awk "{print $10}"
                                          File size:711136 bytes
                                          MD5 hash:7e9b2ed1272331cfbd2aac2e5eb3f84b

                                          Start time (UTC):04:48:50
                                          Start date (UTC):01/11/2024
                                          Path:/tmp/zone.x86_64.elf
                                          Arguments:-
                                          File size:3419156 bytes
                                          MD5 hash:a37d645e921d2b4fcefc60b0dbec3ff7

                                          Start time (UTC):04:48:50
                                          Start date (UTC):01/11/2024
                                          Path:/usr/bin/bash
                                          Arguments:bash -c "cat /proc/net/dev |grep ens160 |awk '{print $2}'"
                                          File size:1183448 bytes
                                          MD5 hash:7063c3930affe123baecd3b340f1ad2c

                                          Start time (UTC):04:48:50
                                          Start date (UTC):01/11/2024
                                          Path:/usr/bin/bash
                                          Arguments:-
                                          File size:1183448 bytes
                                          MD5 hash:7063c3930affe123baecd3b340f1ad2c

                                          Start time (UTC):04:48:50
                                          Start date (UTC):01/11/2024
                                          Path:/usr/bin/cat
                                          Arguments:cat /proc/net/dev
                                          File size:43416 bytes
                                          MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

                                          Start time (UTC):04:48:50
                                          Start date (UTC):01/11/2024
                                          Path:/usr/bin/bash
                                          Arguments:-
                                          File size:1183448 bytes
                                          MD5 hash:7063c3930affe123baecd3b340f1ad2c

                                          Start time (UTC):04:48:50
                                          Start date (UTC):01/11/2024
                                          Path:/usr/bin/grep
                                          Arguments:grep ens160
                                          File size:199136 bytes
                                          MD5 hash:1e6ebb9dd094f774478f72727bdba0f5

                                          Start time (UTC):04:48:50
                                          Start date (UTC):01/11/2024
                                          Path:/usr/bin/bash
                                          Arguments:-
                                          File size:1183448 bytes
                                          MD5 hash:7063c3930affe123baecd3b340f1ad2c

                                          Start time (UTC):04:48:50
                                          Start date (UTC):01/11/2024
                                          Path:/usr/bin/awk
                                          Arguments:awk "{print $2}"
                                          File size:711136 bytes
                                          MD5 hash:7e9b2ed1272331cfbd2aac2e5eb3f84b

                                          Start time (UTC):04:48:50
                                          Start date (UTC):01/11/2024
                                          Path:/tmp/zone.x86_64.elf
                                          Arguments:-
                                          File size:3419156 bytes
                                          MD5 hash:a37d645e921d2b4fcefc60b0dbec3ff7

                                          Start time (UTC):04:48:50
                                          Start date (UTC):01/11/2024
                                          Path:/usr/bin/bash
                                          Arguments:bash -c "cat /proc/net/dev |grep ens160 |awk '{print $10}'"
                                          File size:1183448 bytes
                                          MD5 hash:7063c3930affe123baecd3b340f1ad2c

                                          Start time (UTC):04:48:50
                                          Start date (UTC):01/11/2024
                                          Path:/usr/bin/bash
                                          Arguments:-
                                          File size:1183448 bytes
                                          MD5 hash:7063c3930affe123baecd3b340f1ad2c

                                          Start time (UTC):04:48:50
                                          Start date (UTC):01/11/2024
                                          Path:/usr/bin/cat
                                          Arguments:cat /proc/net/dev
                                          File size:43416 bytes
                                          MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

                                          Start time (UTC):04:48:50
                                          Start date (UTC):01/11/2024
                                          Path:/usr/bin/bash
                                          Arguments:-
                                          File size:1183448 bytes
                                          MD5 hash:7063c3930affe123baecd3b340f1ad2c

                                          Start time (UTC):04:48:50
                                          Start date (UTC):01/11/2024
                                          Path:/usr/bin/grep
                                          Arguments:grep ens160
                                          File size:199136 bytes
                                          MD5 hash:1e6ebb9dd094f774478f72727bdba0f5

                                          Start time (UTC):04:48:50
                                          Start date (UTC):01/11/2024
                                          Path:/usr/bin/bash
                                          Arguments:-
                                          File size:1183448 bytes
                                          MD5 hash:7063c3930affe123baecd3b340f1ad2c

                                          Start time (UTC):04:48:50
                                          Start date (UTC):01/11/2024
                                          Path:/usr/bin/awk
                                          Arguments:awk "{print $10}"
                                          File size:711136 bytes
                                          MD5 hash:7e9b2ed1272331cfbd2aac2e5eb3f84b

                                          Start time (UTC):04:49:50
                                          Start date (UTC):01/11/2024
                                          Path:/tmp/zone.x86_64.elf
                                          Arguments:-
                                          File size:3419156 bytes
                                          MD5 hash:a37d645e921d2b4fcefc60b0dbec3ff7

                                          Start time (UTC):04:49:50
                                          Start date (UTC):01/11/2024
                                          Path:/usr/bin/bash
                                          Arguments:bash -c "cat /proc/net/dev |grep ens160 |awk '{print $2}'"
                                          File size:1183448 bytes
                                          MD5 hash:7063c3930affe123baecd3b340f1ad2c

                                          Start time (UTC):04:49:50
                                          Start date (UTC):01/11/2024
                                          Path:/usr/bin/bash
                                          Arguments:-
                                          File size:1183448 bytes
                                          MD5 hash:7063c3930affe123baecd3b340f1ad2c

                                          Start time (UTC):04:49:50
                                          Start date (UTC):01/11/2024
                                          Path:/usr/bin/cat
                                          Arguments:cat /proc/net/dev
                                          File size:43416 bytes
                                          MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

                                          Start time (UTC):04:49:50
                                          Start date (UTC):01/11/2024
                                          Path:/usr/bin/bash
                                          Arguments:-
                                          File size:1183448 bytes
                                          MD5 hash:7063c3930affe123baecd3b340f1ad2c

                                          Start time (UTC):04:49:50
                                          Start date (UTC):01/11/2024
                                          Path:/usr/bin/grep
                                          Arguments:grep ens160
                                          File size:199136 bytes
                                          MD5 hash:1e6ebb9dd094f774478f72727bdba0f5

                                          Start time (UTC):04:49:50
                                          Start date (UTC):01/11/2024
                                          Path:/usr/bin/bash
                                          Arguments:-
                                          File size:1183448 bytes
                                          MD5 hash:7063c3930affe123baecd3b340f1ad2c

                                          Start time (UTC):04:49:50
                                          Start date (UTC):01/11/2024
                                          Path:/usr/bin/awk
                                          Arguments:awk "{print $2}"
                                          File size:711136 bytes
                                          MD5 hash:7e9b2ed1272331cfbd2aac2e5eb3f84b

                                          Start time (UTC):04:49:50
                                          Start date (UTC):01/11/2024
                                          Path:/tmp/zone.x86_64.elf
                                          Arguments:-
                                          File size:3419156 bytes
                                          MD5 hash:a37d645e921d2b4fcefc60b0dbec3ff7

                                          Start time (UTC):04:49:50
                                          Start date (UTC):01/11/2024
                                          Path:/usr/bin/bash
                                          Arguments:bash -c "cat /proc/net/dev |grep ens160 |awk '{print $10}'"
                                          File size:1183448 bytes
                                          MD5 hash:7063c3930affe123baecd3b340f1ad2c

                                          Start time (UTC):04:49:50
                                          Start date (UTC):01/11/2024
                                          Path:/usr/bin/bash
                                          Arguments:-
                                          File size:1183448 bytes
                                          MD5 hash:7063c3930affe123baecd3b340f1ad2c

                                          Start time (UTC):04:49:50
                                          Start date (UTC):01/11/2024
                                          Path:/usr/bin/cat
                                          Arguments:cat /proc/net/dev
                                          File size:43416 bytes
                                          MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

                                          Start time (UTC):04:49:50
                                          Start date (UTC):01/11/2024
                                          Path:/usr/bin/bash
                                          Arguments:-
                                          File size:1183448 bytes
                                          MD5 hash:7063c3930affe123baecd3b340f1ad2c

                                          Start time (UTC):04:49:50
                                          Start date (UTC):01/11/2024
                                          Path:/usr/bin/grep
                                          Arguments:grep ens160
                                          File size:199136 bytes
                                          MD5 hash:1e6ebb9dd094f774478f72727bdba0f5

                                          Start time (UTC):04:49:50
                                          Start date (UTC):01/11/2024
                                          Path:/usr/bin/bash
                                          Arguments:-
                                          File size:1183448 bytes
                                          MD5 hash:7063c3930affe123baecd3b340f1ad2c

                                          Start time (UTC):04:49:50
                                          Start date (UTC):01/11/2024
                                          Path:/usr/bin/awk
                                          Arguments:awk "{print $10}"
                                          File size:711136 bytes
                                          MD5 hash:7e9b2ed1272331cfbd2aac2e5eb3f84b