Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
zone.i686.elf

Overview

General Information

Sample name:zone.i686.elf
Analysis ID:1546573
MD5:7c5af0d55f90e9090314da8046588691
SHA1:72ee43da29549f382e7ce64167617a2eccb20a1f
SHA256:6790fe9eca0f27c35c6419a31ab432566514e3272d9528fff959788716b04ca2
Tags:elfuser-abuse_ch
Infos:

Detection

Score:23
Range:0 - 100
Whitelisted:false

Signatures

Sample is packed with UPX
ELF contains segments with high entropy indicating compressed/encrypted content
Executes commands using a shell command-line interpreter
Executes the "grep" command used to find patterns in files or piped streams
Reads CPU information from /sys indicative of miner or evasive malware
Reads system information from the proc file system
Sample contains only a LOAD segment without any section mappings
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1546573
Start date and time:2024-11-01 06:07:09 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 6m 0s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:zone.i686.elf
Detection:SUS
Classification:sus23.evad.linELF@0/0@0/0
  • Some HTTP raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
Command:/tmp/zone.i686.elf
PID:6232
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
main:{"arch":"386","flags":["L","I","R"],"local":"192.168.2.23","mac":"00505698912c","tag":"","uptime":0,"version":"2.0.30"}[1;40;36m00:07:54 connected to 38.60.221.177:80[0m
[1;40;37m00:08:04 info modified by handshake:{"arch":"386","connected":1730437675,"flags":["L","I","R"],"ip":"173.254.250.82","local":"192.168.2.23","mac":"00505698912c_173.254.250.82","tag":"","uptime":0,"version":"2.0.30"}[0m
Standard Error:2024/11/01 00:08:04 timeout: 2m0s
2024/11/01 00:08:04 [*] get job
2024/11/01 00:08:04 timeout: 2m0s
2024/11/01 00:08:04 timeout: 2m0s
2024/11/01 00:08:05 timeout: 2m0s
  • system is lnxubuntu20
  • zone.i686.elf (PID: 6232, Parent: 6156, MD5: 7c5af0d55f90e9090314da8046588691) Arguments: /tmp/zone.i686.elf
    • zone.i686.elf (PID: 6236, Parent: 6232, MD5: 7c5af0d55f90e9090314da8046588691) Arguments: /tmp/zone.i686.elf -b
      • bash (PID: 6246, Parent: 6236, MD5: 7063c3930affe123baecd3b340f1ad2c) Arguments: /bin/bash -c uptime
      • uptime (PID: 6246, Parent: 6236, MD5: 3ad70d8e33316ac713bf25c2ddf2fb14) Arguments: uptime
      • bash (PID: 6247, Parent: 6236, MD5: 7063c3930affe123baecd3b340f1ad2c) Arguments: bash -c "cat /proc/net/dev |grep ens160 |awk '{print $2}'"
        • bash New Fork (PID: 6248, Parent: 6247)
        • cat (PID: 6248, Parent: 6247, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /proc/net/dev
        • bash New Fork (PID: 6249, Parent: 6247)
        • grep (PID: 6249, Parent: 6247, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep ens160
        • bash New Fork (PID: 6250, Parent: 6247)
        • awk (PID: 6250, Parent: 6247, MD5: 7e9b2ed1272331cfbd2aac2e5eb3f84b) Arguments: awk "{print $2}"
      • bash (PID: 6251, Parent: 6236, MD5: 7063c3930affe123baecd3b340f1ad2c) Arguments: bash -c "cat /proc/net/dev |grep ens160 |awk '{print $10}'"
        • bash New Fork (PID: 6252, Parent: 6251)
        • cat (PID: 6252, Parent: 6251, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /proc/net/dev
        • bash New Fork (PID: 6253, Parent: 6251)
        • grep (PID: 6253, Parent: 6251, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep ens160
        • bash New Fork (PID: 6254, Parent: 6251)
        • awk (PID: 6254, Parent: 6251, MD5: 7e9b2ed1272331cfbd2aac2e5eb3f84b) Arguments: awk "{print $10}"
      • bash (PID: 6300, Parent: 6236, MD5: 7063c3930affe123baecd3b340f1ad2c) Arguments: bash -c "cat /proc/net/dev |grep ens160 |awk '{print $2}'"
        • bash New Fork (PID: 6301, Parent: 6300)
        • cat (PID: 6301, Parent: 6300, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /proc/net/dev
        • bash New Fork (PID: 6302, Parent: 6300)
        • grep (PID: 6302, Parent: 6300, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep ens160
        • bash New Fork (PID: 6303, Parent: 6300)
        • awk (PID: 6303, Parent: 6300, MD5: 7e9b2ed1272331cfbd2aac2e5eb3f84b) Arguments: awk "{print $2}"
      • bash (PID: 6304, Parent: 6236, MD5: 7063c3930affe123baecd3b340f1ad2c) Arguments: bash -c "cat /proc/net/dev |grep ens160 |awk '{print $10}'"
        • bash New Fork (PID: 6305, Parent: 6304)
        • cat (PID: 6305, Parent: 6304, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /proc/net/dev
        • bash New Fork (PID: 6306, Parent: 6304)
        • grep (PID: 6306, Parent: 6304, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep ens160
        • bash New Fork (PID: 6307, Parent: 6304)
        • awk (PID: 6307, Parent: 6304, MD5: 7e9b2ed1272331cfbd2aac2e5eb3f84b) Arguments: awk "{print $10}"
      • bash (PID: 6337, Parent: 6236, MD5: 7063c3930affe123baecd3b340f1ad2c) Arguments: bash -c "cat /proc/net/dev |grep ens160 |awk '{print $2}'"
        • bash New Fork (PID: 6338, Parent: 6337)
        • cat (PID: 6338, Parent: 6337, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /proc/net/dev
        • bash New Fork (PID: 6339, Parent: 6337)
        • grep (PID: 6339, Parent: 6337, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep ens160
        • bash New Fork (PID: 6340, Parent: 6337)
        • awk (PID: 6340, Parent: 6337, MD5: 7e9b2ed1272331cfbd2aac2e5eb3f84b) Arguments: awk "{print $2}"
      • bash (PID: 6341, Parent: 6236, MD5: 7063c3930affe123baecd3b340f1ad2c) Arguments: bash -c "cat /proc/net/dev |grep ens160 |awk '{print $10}'"
        • bash New Fork (PID: 6342, Parent: 6341)
        • cat (PID: 6342, Parent: 6341, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /proc/net/dev
        • bash New Fork (PID: 6343, Parent: 6341)
        • grep (PID: 6343, Parent: 6341, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep ens160
        • bash New Fork (PID: 6344, Parent: 6341)
        • awk (PID: 6344, Parent: 6341, MD5: 7e9b2ed1272331cfbd2aac2e5eb3f84b) Arguments: awk "{print $10}"
  • cleanup
No yara matches
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results
Source: /usr/bin/uptime (PID: 6246)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
Source: unknownTCP traffic detected without corresponding DNS query: 38.60.221.177
Source: unknownTCP traffic detected without corresponding DNS query: 38.60.221.177
Source: unknownTCP traffic detected without corresponding DNS query: 38.60.221.177
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 38.60.221.177
Source: unknownTCP traffic detected without corresponding DNS query: 38.60.221.177
Source: unknownTCP traffic detected without corresponding DNS query: 38.60.221.177
Source: unknownTCP traffic detected without corresponding DNS query: 38.60.221.177
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 38.60.221.177
Source: unknownTCP traffic detected without corresponding DNS query: 38.60.221.177
Source: unknownTCP traffic detected without corresponding DNS query: 38.60.221.177
Source: unknownTCP traffic detected without corresponding DNS query: 38.60.221.177
Source: unknownTCP traffic detected without corresponding DNS query: 38.60.221.177
Source: unknownTCP traffic detected without corresponding DNS query: 38.60.221.177
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 38.60.221.177
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 38.60.221.177
Source: unknownTCP traffic detected without corresponding DNS query: 38.60.221.177
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 38.60.221.177
Source: unknownTCP traffic detected without corresponding DNS query: 38.60.221.177
Source: unknownTCP traffic detected without corresponding DNS query: 38.60.221.177
Source: unknownTCP traffic detected without corresponding DNS query: 38.60.221.177
Source: unknownTCP traffic detected without corresponding DNS query: 38.60.221.177
Source: unknownTCP traffic detected without corresponding DNS query: 38.60.221.177
Source: unknownTCP traffic detected without corresponding DNS query: 38.60.221.177
Source: unknownTCP traffic detected without corresponding DNS query: 38.60.221.177
Source: unknownTCP traffic detected without corresponding DNS query: 38.60.221.177
Source: unknownTCP traffic detected without corresponding DNS query: 38.60.221.177
Source: unknownTCP traffic detected without corresponding DNS query: 38.60.221.177
Source: unknownTCP traffic detected without corresponding DNS query: 38.60.221.177
Source: unknownTCP traffic detected without corresponding DNS query: 38.60.221.177
Source: unknownTCP traffic detected without corresponding DNS query: 38.60.221.177
Source: zone.i686.elfString found in binary or memory: http://upx.sf.net
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
Source: LOAD without section mappingsProgram segment: 0x8048000
Source: classification engineClassification label: sus23.evad.linELF@0/0@0/0

Data Obfuscation

barindex
Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
Source: initial sampleString containing UPX found: $Id: UPX 4.24 Copyright (C) 1996-2024 the UPX Team. All Rights Reserved. $
Source: /tmp/zone.i686.elf (PID: 6246)Shell command executed: /bin/bash -c uptimeJump to behavior
Source: /usr/bin/bash (PID: 6249)Grep executable: /usr/bin/grep -> grep ens160Jump to behavior
Source: /usr/bin/bash (PID: 6253)Grep executable: /usr/bin/grep -> grep ens160Jump to behavior
Source: /usr/bin/bash (PID: 6302)Grep executable: /usr/bin/grep -> grep ens160Jump to behavior
Source: /usr/bin/bash (PID: 6306)Grep executable: /usr/bin/grep -> grep ens160Jump to behavior
Source: /usr/bin/bash (PID: 6339)Grep executable: /usr/bin/grep -> grep ens160Jump to behavior
Source: /usr/bin/bash (PID: 6343)Grep executable: /usr/bin/grep -> grep ens160Jump to behavior
Source: /tmp/zone.i686.elf (PID: 6232)Reads from proc file: /proc/statJump to behavior
Source: /tmp/zone.i686.elf (PID: 6236)Reads from proc file: /proc/statJump to behavior
Source: /tmp/zone.i686.elf (PID: 6236)Reads from proc file: /proc/sys/net/core/somaxconnJump to behavior
Source: /usr/bin/bash (PID: 6250)Awk executable: /usr/bin/awk -> awk "{print $2}"Jump to behavior
Source: /usr/bin/bash (PID: 6254)Awk executable: /usr/bin/awk -> awk "{print $10}"Jump to behavior
Source: /usr/bin/bash (PID: 6303)Awk executable: /usr/bin/awk -> awk "{print $2}"Jump to behavior
Source: /usr/bin/bash (PID: 6307)Awk executable: /usr/bin/awk -> awk "{print $10}"Jump to behavior
Source: /usr/bin/bash (PID: 6340)Awk executable: /usr/bin/awk -> awk "{print $2}"Jump to behavior
Source: /usr/bin/bash (PID: 6344)Awk executable: /usr/bin/awk -> awk "{print $10}"Jump to behavior
Source: submitted sampleStderr: 2024/11/01 00:08:04 timeout: 2m0s2024/11/01 00:08:04 [*] get job2024/11/01 00:08:04 timeout: 2m0s2024/11/01 00:08:04 timeout: 2m0s2024/11/01 00:08:05 timeout: 2m0s: exit code = 0
Source: zone.i686.elfSubmission file: segment LOAD with 7.8938 entropy (max. 8.0)
Source: zone.i686.elfSubmission file: segment LOAD with 7.9999 entropy (max. 8.0)
Source: /usr/bin/uptime (PID: 6246)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
Source: /bin/bash (PID: 6246)Queries kernel information via 'uname': Jump to behavior
Source: /usr/bin/bash (PID: 6247)Queries kernel information via 'uname': Jump to behavior
Source: /usr/bin/bash (PID: 6251)Queries kernel information via 'uname': Jump to behavior
Source: /usr/bin/bash (PID: 6300)Queries kernel information via 'uname': Jump to behavior
Source: /usr/bin/bash (PID: 6304)Queries kernel information via 'uname': Jump to behavior
Source: /usr/bin/bash (PID: 6337)Queries kernel information via 'uname': Jump to behavior
Source: /usr/bin/bash (PID: 6341)Queries kernel information via 'uname': Jump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity Information1
Scripting
Valid Accounts1
Command and Scripting Interpreter
1
Scripting
Path Interception11
Obfuscated Files or Information
OS Credential Dumping1
Security Software Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS Memory2
System Information Discovery
Remote Desktop ProtocolData from Removable Media1
Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1546573 Sample: zone.i686.elf Startdate: 01/11/2024 Architecture: LINUX Score: 23 39 109.202.202.202, 80 INIT7CH Switzerland 2->39 41 38.60.221.177, 39340, 39342, 80 COGENT-174US United States 2->41 43 2 other IPs or domains 2->43 45 Sample is packed with UPX 2->45 9 zone.i686.elf 2->9         started        signatures3 process4 process5 11 zone.i686.elf zone.i686.elf 9->11         started        process6 13 zone.i686.elf bash 11->13         started        15 zone.i686.elf bash 11->15         started        17 zone.i686.elf bash 11->17         started        19 4 other processes 11->19 process7 21 bash cat 13->21         started        23 bash grep 13->23         started        25 bash awk 13->25         started        27 bash cat 15->27         started        29 bash grep 15->29         started        31 bash awk 15->31         started        33 bash cat 17->33         started        35 2 other processes 17->35 37 9 other processes 19->37
SourceDetectionScannerLabelLink
zone.i686.elf5%ReversingLabs
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
http://upx.sf.net0%URL Reputationsafe
http://upx.sf.net0%URL Reputationsafe
No contacted domains info
NameSourceMaliciousAntivirus DetectionReputation
http://upx.sf.netzone.i686.elftrue
  • URL Reputation: safe
  • URL Reputation: safe
unknown
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs
IPDomainCountryFlagASNASN NameMalicious
38.60.221.177
unknownUnited States
174COGENT-174USfalse
109.202.202.202
unknownSwitzerland
13030INIT7CHfalse
91.189.91.43
unknownUnited Kingdom
41231CANONICAL-ASGBfalse
91.189.91.42
unknownUnited Kingdom
41231CANONICAL-ASGBfalse
MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
  • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
91.189.91.43armv6l.elfGet hashmaliciousGafgyt, MiraiBrowse
    m68k.elfGet hashmaliciousGafgyt, MiraiBrowse
      i686.elfGet hashmaliciousGafgyt, MiraiBrowse
        boatnet.arm.elfGet hashmaliciousMiraiBrowse
          armv5l.elfGet hashmaliciousGafgyt, MiraiBrowse
            .i.elfGet hashmaliciousUnknownBrowse
              harm4.elfGet hashmaliciousUnknownBrowse
                shngijernbh.mips.elfGet hashmaliciousGafgyt, MiraiBrowse
                  shngijernbh.ppc.elfGet hashmaliciousGafgyt, MiraiBrowse
                    linux_mips.elfGet hashmaliciousChaosBrowse
                      91.189.91.42armv6l.elfGet hashmaliciousGafgyt, MiraiBrowse
                        m68k.elfGet hashmaliciousGafgyt, MiraiBrowse
                          i686.elfGet hashmaliciousGafgyt, MiraiBrowse
                            armv4l.elfGet hashmaliciousGafgyt, MiraiBrowse
                              boatnet.arm.elfGet hashmaliciousMiraiBrowse
                                armv5l.elfGet hashmaliciousGafgyt, MiraiBrowse
                                  .i.elfGet hashmaliciousUnknownBrowse
                                    harm4.elfGet hashmaliciousUnknownBrowse
                                      shngijernbh.mips.elfGet hashmaliciousGafgyt, MiraiBrowse
                                        shngijernbh.ppc.elfGet hashmaliciousGafgyt, MiraiBrowse
                                          No context
                                          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                          CANONICAL-ASGBarmv6l.elfGet hashmaliciousGafgyt, MiraiBrowse
                                          • 91.189.91.42
                                          m68k.elfGet hashmaliciousGafgyt, MiraiBrowse
                                          • 91.189.91.42
                                          i686.elfGet hashmaliciousGafgyt, MiraiBrowse
                                          • 91.189.91.42
                                          armv4l.elfGet hashmaliciousGafgyt, MiraiBrowse
                                          • 91.189.91.42
                                          boatnet.arm.elfGet hashmaliciousMiraiBrowse
                                          • 91.189.91.42
                                          armv5l.elfGet hashmaliciousGafgyt, MiraiBrowse
                                          • 91.189.91.42
                                          boatnet.m68k.elfGet hashmaliciousMiraiBrowse
                                          • 185.125.190.26
                                          .i.elfGet hashmaliciousUnknownBrowse
                                          • 91.189.91.42
                                          harm4.elfGet hashmaliciousUnknownBrowse
                                          • 91.189.91.42
                                          shngijernbh.mips.elfGet hashmaliciousGafgyt, MiraiBrowse
                                          • 91.189.91.42
                                          CANONICAL-ASGBarmv6l.elfGet hashmaliciousGafgyt, MiraiBrowse
                                          • 91.189.91.42
                                          m68k.elfGet hashmaliciousGafgyt, MiraiBrowse
                                          • 91.189.91.42
                                          i686.elfGet hashmaliciousGafgyt, MiraiBrowse
                                          • 91.189.91.42
                                          armv4l.elfGet hashmaliciousGafgyt, MiraiBrowse
                                          • 91.189.91.42
                                          boatnet.arm.elfGet hashmaliciousMiraiBrowse
                                          • 91.189.91.42
                                          armv5l.elfGet hashmaliciousGafgyt, MiraiBrowse
                                          • 91.189.91.42
                                          boatnet.m68k.elfGet hashmaliciousMiraiBrowse
                                          • 185.125.190.26
                                          .i.elfGet hashmaliciousUnknownBrowse
                                          • 91.189.91.42
                                          harm4.elfGet hashmaliciousUnknownBrowse
                                          • 91.189.91.42
                                          shngijernbh.mips.elfGet hashmaliciousGafgyt, MiraiBrowse
                                          • 91.189.91.42
                                          INIT7CHarmv6l.elfGet hashmaliciousGafgyt, MiraiBrowse
                                          • 109.202.202.202
                                          m68k.elfGet hashmaliciousGafgyt, MiraiBrowse
                                          • 109.202.202.202
                                          i686.elfGet hashmaliciousGafgyt, MiraiBrowse
                                          • 109.202.202.202
                                          armv4l.elfGet hashmaliciousGafgyt, MiraiBrowse
                                          • 109.202.202.202
                                          boatnet.arm.elfGet hashmaliciousMiraiBrowse
                                          • 109.202.202.202
                                          armv5l.elfGet hashmaliciousGafgyt, MiraiBrowse
                                          • 109.202.202.202
                                          .i.elfGet hashmaliciousUnknownBrowse
                                          • 109.202.202.202
                                          harm4.elfGet hashmaliciousUnknownBrowse
                                          • 109.202.202.202
                                          shngijernbh.mips.elfGet hashmaliciousGafgyt, MiraiBrowse
                                          • 109.202.202.202
                                          shngijernbh.ppc.elfGet hashmaliciousGafgyt, MiraiBrowse
                                          • 109.202.202.202
                                          COGENT-174USNF_Payment_Ref_FAN930276.exeGet hashmaliciousFormBookBrowse
                                          • 38.88.82.56
                                          71Ah2iqq3g.dllGet hashmaliciousAmadeyBrowse
                                          • 45.93.20.135
                                          71Ah2iqq3g.dllGet hashmaliciousAmadeyBrowse
                                          • 45.93.20.135
                                          1nnlXctdko.dllGet hashmaliciousAmadeyBrowse
                                          • 45.93.20.135
                                          HT9324-25 1x40HC LDHFCLDEHAM29656 MRSU5087674.exeGet hashmaliciousFormBookBrowse
                                          • 154.23.181.7
                                          18in SPA-198-2024.exeGet hashmaliciousFormBookBrowse
                                          • 38.88.82.56
                                          WARUNKI UMOWY-pdf.bat.exeGet hashmaliciousFormBook, GuLoaderBrowse
                                          • 38.88.82.56
                                          bszYGSIHuU.exeGet hashmaliciousUnknownBrowse
                                          • 38.180.123.95
                                          819614 - Midways Freight Ltd.xlsmGet hashmaliciousUnknownBrowse
                                          • 143.244.56.49
                                          wZU2edEGL3.elfGet hashmaliciousUnknownBrowse
                                          • 38.60.72.192
                                          No context
                                          No context
                                          No created / dropped files found
                                          File type:ELF 32-bit LSB executable, Intel 80386, version 1 (GNU/Linux), statically linked, no section header
                                          Entropy (8bit):7.999922744718376
                                          TrID:
                                          • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                          File name:zone.i686.elf
                                          File size:3'136'268 bytes
                                          MD5:7c5af0d55f90e9090314da8046588691
                                          SHA1:72ee43da29549f382e7ce64167617a2eccb20a1f
                                          SHA256:6790fe9eca0f27c35c6419a31ab432566514e3272d9528fff959788716b04ca2
                                          SHA512:67e8fbdcc4b329e41346e8bd9960781395c6cae1bf855c99d54c5e2653462799fbfbbe41d3424339dedd077483dd33408702a2fde51d04a2f18e087b5c9c3b9f
                                          SSDEEP:49152:DRh7n+7kFSbwLtTmmTbtFqUwFO3g63pxu70S9NuO6uqF2mKIMg1hZHcS1VA77orV:DRh7c6SbMAm3tWON3C71vj6uAKAnRA/o
                                          TLSH:BBE53329BC0BC69D910B3B93F01EE32EA1588752CD49D885DFDF4EC7089A58C6A9C46D
                                          File Content Preview:.ELF........................4...........4. ..................................................0...0..../.../.........Q.td..............................o.UPX!............L.Q.....t..........?.E.h;....#..|`d2...j.....z.Y.~\{?.J..21.9....../.M.F.......J..e.$..

                                          ELF header

                                          Class:ELF32
                                          Data:2's complement, little endian
                                          Version:1 (current)
                                          Machine:Intel 80386
                                          Version Number:0x1
                                          Type:EXEC (Executable file)
                                          OS/ABI:UNIX - Linux
                                          ABI Version:0
                                          Entry Point Address:0x919f6b8
                                          Flags:0x0
                                          ELF Header Size:52
                                          Program Header Offset:52
                                          Program Header Size:32
                                          Number of Program Headers:3
                                          Section Header Offset:0
                                          Section Header Size:0
                                          Number of Section Headers:0
                                          Header String Table Index:0
                                          TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                          LOAD0x00x80480000x80480000x10000xe5a8a07.89380x6RW 0x1000
                                          LOAD0x00x8ea30000x8ea30000x2fd9a20x2fd9a27.99990x5R E0x1000
                                          GNU_STACK0x00x00x00x00x00.00000x6RW 0x4
                                          TimestampSource PortDest PortSource IPDest IP
                                          Nov 1, 2024 06:07:54.301177025 CET3934080192.168.2.2338.60.221.177
                                          Nov 1, 2024 06:07:54.454927921 CET803934038.60.221.177192.168.2.23
                                          Nov 1, 2024 06:07:54.455008984 CET3934080192.168.2.2338.60.221.177
                                          Nov 1, 2024 06:07:54.457596064 CET3934080192.168.2.2338.60.221.177
                                          Nov 1, 2024 06:07:54.462505102 CET803934038.60.221.177192.168.2.23
                                          Nov 1, 2024 06:07:55.169378996 CET43928443192.168.2.2391.189.91.42
                                          Nov 1, 2024 06:07:55.374274015 CET803934038.60.221.177192.168.2.23
                                          Nov 1, 2024 06:07:55.374331951 CET3934080192.168.2.2338.60.221.177
                                          Nov 1, 2024 06:07:55.380732059 CET3934080192.168.2.2338.60.221.177
                                          Nov 1, 2024 06:07:55.385528088 CET803934038.60.221.177192.168.2.23
                                          Nov 1, 2024 06:07:55.386884928 CET3934080192.168.2.2338.60.221.177
                                          Nov 1, 2024 06:07:55.391697884 CET803934038.60.221.177192.168.2.23
                                          Nov 1, 2024 06:07:55.812824011 CET803934038.60.221.177192.168.2.23
                                          Nov 1, 2024 06:07:55.813039064 CET3934080192.168.2.2338.60.221.177
                                          Nov 1, 2024 06:08:00.544735909 CET42836443192.168.2.2391.189.91.43
                                          Nov 1, 2024 06:08:02.080368996 CET4251680192.168.2.23109.202.202.202
                                          Nov 1, 2024 06:08:05.400369883 CET3934080192.168.2.2338.60.221.177
                                          Nov 1, 2024 06:08:05.403745890 CET3934080192.168.2.2338.60.221.177
                                          Nov 1, 2024 06:08:05.405683994 CET803934038.60.221.177192.168.2.23
                                          Nov 1, 2024 06:08:05.407049894 CET3934080192.168.2.2338.60.221.177
                                          Nov 1, 2024 06:08:05.408546925 CET803934038.60.221.177192.168.2.23
                                          Nov 1, 2024 06:08:05.411849022 CET803934038.60.221.177192.168.2.23
                                          Nov 1, 2024 06:08:06.015183926 CET803934038.60.221.177192.168.2.23
                                          Nov 1, 2024 06:08:06.015283108 CET3934080192.168.2.2338.60.221.177
                                          Nov 1, 2024 06:08:06.015490055 CET803934038.60.221.177192.168.2.23
                                          Nov 1, 2024 06:08:06.015536070 CET3934080192.168.2.2338.60.221.177
                                          Nov 1, 2024 06:08:06.018639088 CET803934038.60.221.177192.168.2.23
                                          Nov 1, 2024 06:08:06.018675089 CET3934080192.168.2.2338.60.221.177
                                          Nov 1, 2024 06:08:16.926419020 CET43928443192.168.2.2391.189.91.42
                                          Nov 1, 2024 06:08:21.021864891 CET3934080192.168.2.2338.60.221.177
                                          Nov 1, 2024 06:08:21.026783943 CET803934038.60.221.177192.168.2.23
                                          Nov 1, 2024 06:08:27.164999008 CET42836443192.168.2.2391.189.91.43
                                          Nov 1, 2024 06:08:33.308139086 CET4251680192.168.2.23109.202.202.202
                                          Nov 1, 2024 06:08:36.123652935 CET3934080192.168.2.2338.60.221.177
                                          Nov 1, 2024 06:08:36.331706047 CET803934038.60.221.177192.168.2.23
                                          Nov 1, 2024 06:08:51.333559990 CET3934080192.168.2.2338.60.221.177
                                          Nov 1, 2024 06:08:51.338534117 CET803934038.60.221.177192.168.2.23
                                          Nov 1, 2024 06:08:57.880697966 CET43928443192.168.2.2391.189.91.42
                                          Nov 1, 2024 06:09:06.583368063 CET3934080192.168.2.2338.60.221.177
                                          Nov 1, 2024 06:09:06.589126110 CET803934038.60.221.177192.168.2.23
                                          Nov 1, 2024 06:09:21.685369968 CET3934080192.168.2.2338.60.221.177
                                          Nov 1, 2024 06:09:21.690227032 CET803934038.60.221.177192.168.2.23
                                          Nov 1, 2024 06:09:36.787163019 CET3934080192.168.2.2338.60.221.177
                                          Nov 1, 2024 06:09:36.792213917 CET803934038.60.221.177192.168.2.23
                                          Nov 1, 2024 06:09:51.889115095 CET3934080192.168.2.2338.60.221.177
                                          Nov 1, 2024 06:09:51.894047976 CET803934038.60.221.177192.168.2.23
                                          Nov 1, 2024 06:10:06.009001017 CET3934080192.168.2.2338.60.221.177
                                          Nov 1, 2024 06:10:06.010993004 CET3934080192.168.2.2338.60.221.177
                                          Nov 1, 2024 06:10:06.013938904 CET803934038.60.221.177192.168.2.23
                                          Nov 1, 2024 06:10:06.016149044 CET803934038.60.221.177192.168.2.23
                                          Nov 1, 2024 06:10:06.016205072 CET3934080192.168.2.2338.60.221.177
                                          Nov 1, 2024 06:10:35.372864962 CET3934280192.168.2.2338.60.221.177
                                          Nov 1, 2024 06:10:35.377775908 CET803934238.60.221.177192.168.2.23
                                          Nov 1, 2024 06:10:35.377866983 CET3934280192.168.2.2338.60.221.177
                                          Nov 1, 2024 06:10:35.383233070 CET3934280192.168.2.2338.60.221.177
                                          Nov 1, 2024 06:10:35.388127089 CET803934238.60.221.177192.168.2.23
                                          Nov 1, 2024 06:10:36.329771042 CET803934238.60.221.177192.168.2.23
                                          Nov 1, 2024 06:10:36.330127001 CET3934280192.168.2.2338.60.221.177
                                          Nov 1, 2024 06:10:36.336493015 CET3934280192.168.2.2338.60.221.177
                                          Nov 1, 2024 06:10:36.341275930 CET803934238.60.221.177192.168.2.23
                                          Nov 1, 2024 06:10:36.380841970 CET3934280192.168.2.2338.60.221.177
                                          Nov 1, 2024 06:10:36.386054993 CET803934238.60.221.177192.168.2.23
                                          Nov 1, 2024 06:10:36.386107922 CET3934280192.168.2.2338.60.221.177
                                          Session IDSource IPSource PortDestination IPDestination Port
                                          0192.168.2.233934038.60.221.17780
                                          TimestampBytes transferredDirectionData
                                          Nov 1, 2024 06:07:54.457596064 CET255OUTData Raw: 16 03 01 00 ee 01 00 00 ea 03 03 4a af 09 f7 44 e6 02 76 dd 40 4c d3 f9 f1 f3 45 78 a5 b5 08 fa d4 e5 be 5d 53 ea b6 9c ac a2 a9 20 68 e8 05 89 3f da ed 92 84 c0 db 41 3c d6 d5 2d fc bf 06 ab 76 9d 8e 21 f1 ba 1b 58 1d 66 43 72 00 26 cc a9 cc a8
                                          Data Ascii: JDv@LEx]S h?A<-v!XfCr&+/,0/5{+3&$ sCPHT0~;Zv
                                          Nov 1, 2024 06:07:55.374274015 CET1230INData Raw: 16 03 03 00 7a 02 00 00 76 03 03 88 e2 bd 4b 85 12 c5 9d 48 3f f8 23 be 6c 4e c3 c6 59 70 04 2f c6 40 14 a5 d1 df 71 fe a0 1a fa 20 68 e8 05 89 3f da ed 92 84 c0 db 41 3c d6 d5 2d fc bf 06 ab 76 9d 8e 21 f1 ba 1b 58 1d 66 43 72 13 03 00 00 2e 00
                                          Data Ascii: zvKH?#lNYp/@q h?A<-v!XfCr.+3$ g_WyWTwqCMf4J]reupmPR;gj"DFO~_/eC"o3~jeXKj?Lu5
                                          Nov 1, 2024 06:07:55.380732059 CET76OUTData Raw: 14 03 03 00 01 01 17 03 03 00 35 2a ad fe 85 b0 5e 80 6f 8f 84 75 f9 a1 63 96 3e 26 cf d8 23 17 8a 51 8b 26 32 88 81 9b 6c 4e 1a e3 78 be ee 74 71 f0 3c 37 94 dd 2a 70 3f b9 e4 0f f3 9c cd 4f
                                          Data Ascii: 5*^ouc>&#Q&2lNxtq<7*p?O
                                          Nov 1, 2024 06:07:55.386884928 CET215OUTData Raw: 17 03 03 00 c6 15 8b a5 7b f2 37 be 26 82 c0 a4 6c e6 ca 19 12 c1 15 ec b6 91 34 ff be e3 74 6f 34 17 24 90 c7 01 0e cd ea c9 0e 2c 27 35 b3 81 b6 fb 7d 76 79 79 8f 94 32 a8 f0 a1 8d 0b ca d9 25 87 00 b1 07 ab 6b 45 42 c4 ed d0 22 22 bf 21 2d b9
                                          Data Ascii: {7&l4to4$,'5}vyy2%kEB""!-H/V</z:#7gOSf+%)c5H?x23y,_5w~e=[]3WwEu
                                          Nov 1, 2024 06:07:55.812824011 CET237INData Raw: 17 03 03 00 dc c5 f4 c7 28 b2 4a ad 70 2a 5e c2 7c ba b3 60 13 f0 66 66 b8 31 e9 39 4d 06 92 ce f7 b3 0c c8 ff 81 8d 50 af 35 02 c0 c1 c1 5d 24 14 1d f1 49 9c d5 9b f3 95 a0 df 12 10 cc 57 a6 0c 2e 6c 42 e2 8f 2e 89 92 92 93 92 ea 21 d0 83 38 7e
                                          Data Ascii: (Jp*^|`ff19MP5]$IW.lB.!8~@-21lVt/+x36/ibaq&+6y?Yqpz_1d3R2:)nirhdvluIk%%uy@LQak:De
                                          Nov 1, 2024 06:08:05.400369883 CET196OUTData Raw: 17 03 03 00 b3 83 9a ee 7c 52 2a fe 99 d5 91 20 cb c7 7b 57 02 75 11 37 20 b5 ef 5d aa 47 ee db 38 55 aa 51 2c 2d f4 a1 9f fb 4c d7 c1 b5 8e b3 da 16 36 9e 33 a2 19 df a1 65 ac 1c 2b bf 31 06 ad dc 31 89 76 f4 e5 d7 15 0b a0 64 1c 7c 97 51 a3 06
                                          Data Ascii: |R* {Wu7 ]G8UQ,-L63e+11vd|Q&P;ICGiyb*q6Oh'1[uXVK$!o$~Ms
                                          Nov 1, 2024 06:08:05.403745890 CET386OUTData Raw: 17 03 03 01 71 af 02 b7 0c b8 80 ee 2a fc b6 2a 37 ab 9f 39 01 66 e3 fd 89 d1 9e 86 5b 27 c5 bf d4 04 2b 4c 17 08 03 5e 85 a9 47 54 72 6a 3a 1d 22 20 65 d3 d3 06 b6 21 ed 45 c6 1a 8e 19 7b da 5d d6 89 c0 74 c6 b6 f7 80 90 63 9f c6 0e 92 ae 60 a1
                                          Data Ascii: q**79f['+L^GTrj:" e!E{]tc`Y|c;<HH^)4,6$prSMvk--eS+E<}ZjN(eRT\7Qb'_W;AQ0F[NEdK9
                                          Nov 1, 2024 06:08:05.407049894 CET198OUTData Raw: 17 03 03 00 b5 4d 78 61 ca d0 aa 3e 63 d9 ae 90 2d 32 89 6f 48 ce b6 86 2e 4c 00 58 36 93 bd 9c 47 75 21 74 93 00 5d d1 32 f3 47 64 dd 32 a7 46 c0 67 e5 f2 a8 9c cd cd 1d ee 4a f6 8d 1c 04 e2 77 c4 c7 f5 98 7b 76 3e 7f ed 5e a3 a1 b7 a4 61 e7 56
                                          Data Ascii: Mxa>c-2oH.LX6Gu!t]2Gd2FgJw{v>^aVIl$~U?j9RYW=izG<YI: kjWNb%;H>xE4SLCO
                                          Nov 1, 2024 06:08:06.015183926 CET199INData Raw: 17 03 03 00 b6 55 92 3e 6a 1b db d3 9e c6 69 5e b6 9d 51 7a cb 08 02 2c 11 28 31 33 f6 b1 4f 50 23 db 7e 80 f9 86 ac 8d e9 3f d2 d9 ea 0c c2 2b d9 aa 84 eb 5f 8d 9e 20 43 ff 49 6a 14 5b e5 01 ec 22 70 58 41 c4 66 d3 21 58 13 d7 0b bc 94 58 84 f2
                                          Data Ascii: U>ji^Qz,(13OP#~?+_ CIj["pXAf!XXz>ZW0@"X|1`0l!KIT|)z,W~7{];X2EVhsid2e
                                          Nov 1, 2024 06:08:06.015490055 CET199INData Raw: 17 03 03 00 b6 fb b3 b5 e6 72 90 53 4f 61 91 7e 11 43 9c 2d 56 e1 c9 da c7 95 70 18 24 84 e0 13 09 f1 8a 22 ef 8f 59 fa b1 3b ff c0 f3 0c 06 bf 77 65 ac e3 49 0e 40 8c 41 8f ef 65 c9 b2 36 7f f4 0e 05 3b 23 4e 83 b1 1d 4c 17 53 7b ed dc 99 de 5b
                                          Data Ascii: rSOa~C-Vp$"Y;weI@Ae6;#NLS{[1S&;3V=+.3)[L=0j%E<YPq/)T04sjq|#%*DE-?CuY^"D


                                          Session IDSource IPSource PortDestination IPDestination Port
                                          1192.168.2.233934238.60.221.17780
                                          TimestampBytes transferredDirectionData
                                          Nov 1, 2024 06:10:35.383233070 CET255OUTData Raw: 16 03 01 00 ee 01 00 00 ea 03 03 4c 9d 88 72 6a b0 58 5c 9d 3d 96 43 23 33 73 ae 51 a2 f3 04 15 61 bb c2 f8 0c 6c bb 03 43 21 60 20 50 80 1b 06 4e 9f 4c d6 10 cb ab f6 5e 1d e1 b2 4d ab 9c 9e 5a 6d ae f7 a1 33 10 2b 40 d2 19 87 00 26 cc a9 cc a8
                                          Data Ascii: LrjX\=C#3sQalC!` PNL^MZm3+@&+/,0/5{+3&$ OD-`Z{9>,~jIs
                                          Nov 1, 2024 06:10:36.329771042 CET1230INData Raw: 16 03 03 00 7a 02 00 00 76 03 03 7b 31 23 5d 53 9c 6e 95 cd 33 97 85 5e 3c c6 ba 4a cf 3b 34 96 42 cb 03 89 1a c9 51 3b 40 72 91 20 50 80 1b 06 4e 9f 4c d6 10 cb ab f6 5e 1d e1 b2 4d ab 9c 9e 5a 6d ae f7 a1 33 10 2b 40 d2 19 87 13 03 00 00 2e 00
                                          Data Ascii: zv{1#]Sn3^<J;4BQ;@r PNL^MZm3+@.+3$ \"3zeXb;3_3=2~(aG@;~n[JPEO)y2US`y(^NSqw[zWj%5z!(
                                          Nov 1, 2024 06:10:36.336493015 CET76OUTData Raw: 14 03 03 00 01 01 17 03 03 00 35 83 0d cc 9a 02 63 51 90 7e 6a 7f 9e df 33 ef cc 2b 82 48 15 da 93 11 df 40 d8 3a 64 12 39 f3 96 7e 8d b5 d0 ea 86 2b ee 97 48 13 75 a3 b5 e3 68 06 71 52 57 93
                                          Data Ascii: 5cQ~j3+H@:d9~+HuhqRW


                                          System Behavior

                                          Start time (UTC):05:07:52
                                          Start date (UTC):01/11/2024
                                          Path:/tmp/zone.i686.elf
                                          Arguments:/tmp/zone.i686.elf
                                          File size:3136268 bytes
                                          MD5 hash:7c5af0d55f90e9090314da8046588691

                                          Start time (UTC):05:07:52
                                          Start date (UTC):01/11/2024
                                          Path:/tmp/zone.i686.elf
                                          Arguments:-
                                          File size:3136268 bytes
                                          MD5 hash:7c5af0d55f90e9090314da8046588691

                                          Start time (UTC):05:07:52
                                          Start date (UTC):01/11/2024
                                          Path:/tmp/zone.i686.elf
                                          Arguments:/tmp/zone.i686.elf -b
                                          File size:3136268 bytes
                                          MD5 hash:7c5af0d55f90e9090314da8046588691

                                          Start time (UTC):05:07:53
                                          Start date (UTC):01/11/2024
                                          Path:/tmp/zone.i686.elf
                                          Arguments:-
                                          File size:3136268 bytes
                                          MD5 hash:7c5af0d55f90e9090314da8046588691

                                          Start time (UTC):05:07:53
                                          Start date (UTC):01/11/2024
                                          Path:/bin/bash
                                          Arguments:/bin/bash -c uptime
                                          File size:1183448 bytes
                                          MD5 hash:7063c3930affe123baecd3b340f1ad2c

                                          Start time (UTC):05:07:53
                                          Start date (UTC):01/11/2024
                                          Path:/usr/bin/uptime
                                          Arguments:uptime
                                          File size:14568 bytes
                                          MD5 hash:3ad70d8e33316ac713bf25c2ddf2fb14

                                          Start time (UTC):05:07:53
                                          Start date (UTC):01/11/2024
                                          Path:/tmp/zone.i686.elf
                                          Arguments:-
                                          File size:3136268 bytes
                                          MD5 hash:7c5af0d55f90e9090314da8046588691

                                          Start time (UTC):05:07:53
                                          Start date (UTC):01/11/2024
                                          Path:/usr/bin/bash
                                          Arguments:bash -c "cat /proc/net/dev |grep ens160 |awk '{print $2}'"
                                          File size:1183448 bytes
                                          MD5 hash:7063c3930affe123baecd3b340f1ad2c

                                          Start time (UTC):05:07:53
                                          Start date (UTC):01/11/2024
                                          Path:/usr/bin/bash
                                          Arguments:-
                                          File size:1183448 bytes
                                          MD5 hash:7063c3930affe123baecd3b340f1ad2c

                                          Start time (UTC):05:07:53
                                          Start date (UTC):01/11/2024
                                          Path:/usr/bin/cat
                                          Arguments:cat /proc/net/dev
                                          File size:43416 bytes
                                          MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

                                          Start time (UTC):05:07:53
                                          Start date (UTC):01/11/2024
                                          Path:/usr/bin/bash
                                          Arguments:-
                                          File size:1183448 bytes
                                          MD5 hash:7063c3930affe123baecd3b340f1ad2c

                                          Start time (UTC):05:07:53
                                          Start date (UTC):01/11/2024
                                          Path:/usr/bin/grep
                                          Arguments:grep ens160
                                          File size:199136 bytes
                                          MD5 hash:1e6ebb9dd094f774478f72727bdba0f5

                                          Start time (UTC):05:07:53
                                          Start date (UTC):01/11/2024
                                          Path:/usr/bin/bash
                                          Arguments:-
                                          File size:1183448 bytes
                                          MD5 hash:7063c3930affe123baecd3b340f1ad2c

                                          Start time (UTC):05:07:53
                                          Start date (UTC):01/11/2024
                                          Path:/usr/bin/awk
                                          Arguments:awk "{print $2}"
                                          File size:711136 bytes
                                          MD5 hash:7e9b2ed1272331cfbd2aac2e5eb3f84b

                                          Start time (UTC):05:07:53
                                          Start date (UTC):01/11/2024
                                          Path:/tmp/zone.i686.elf
                                          Arguments:-
                                          File size:3136268 bytes
                                          MD5 hash:7c5af0d55f90e9090314da8046588691

                                          Start time (UTC):05:07:53
                                          Start date (UTC):01/11/2024
                                          Path:/usr/bin/bash
                                          Arguments:bash -c "cat /proc/net/dev |grep ens160 |awk '{print $10}'"
                                          File size:1183448 bytes
                                          MD5 hash:7063c3930affe123baecd3b340f1ad2c

                                          Start time (UTC):05:07:53
                                          Start date (UTC):01/11/2024
                                          Path:/usr/bin/bash
                                          Arguments:-
                                          File size:1183448 bytes
                                          MD5 hash:7063c3930affe123baecd3b340f1ad2c

                                          Start time (UTC):05:07:53
                                          Start date (UTC):01/11/2024
                                          Path:/usr/bin/cat
                                          Arguments:cat /proc/net/dev
                                          File size:43416 bytes
                                          MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

                                          Start time (UTC):05:07:53
                                          Start date (UTC):01/11/2024
                                          Path:/usr/bin/bash
                                          Arguments:-
                                          File size:1183448 bytes
                                          MD5 hash:7063c3930affe123baecd3b340f1ad2c

                                          Start time (UTC):05:07:53
                                          Start date (UTC):01/11/2024
                                          Path:/usr/bin/grep
                                          Arguments:grep ens160
                                          File size:199136 bytes
                                          MD5 hash:1e6ebb9dd094f774478f72727bdba0f5

                                          Start time (UTC):05:07:53
                                          Start date (UTC):01/11/2024
                                          Path:/usr/bin/bash
                                          Arguments:-
                                          File size:1183448 bytes
                                          MD5 hash:7063c3930affe123baecd3b340f1ad2c

                                          Start time (UTC):05:07:53
                                          Start date (UTC):01/11/2024
                                          Path:/usr/bin/awk
                                          Arguments:awk "{print $10}"
                                          File size:711136 bytes
                                          MD5 hash:7e9b2ed1272331cfbd2aac2e5eb3f84b

                                          Start time (UTC):05:08:53
                                          Start date (UTC):01/11/2024
                                          Path:/tmp/zone.i686.elf
                                          Arguments:-
                                          File size:3136268 bytes
                                          MD5 hash:7c5af0d55f90e9090314da8046588691

                                          Start time (UTC):05:08:53
                                          Start date (UTC):01/11/2024
                                          Path:/usr/bin/bash
                                          Arguments:bash -c "cat /proc/net/dev |grep ens160 |awk '{print $2}'"
                                          File size:1183448 bytes
                                          MD5 hash:7063c3930affe123baecd3b340f1ad2c

                                          Start time (UTC):05:08:53
                                          Start date (UTC):01/11/2024
                                          Path:/usr/bin/bash
                                          Arguments:-
                                          File size:1183448 bytes
                                          MD5 hash:7063c3930affe123baecd3b340f1ad2c

                                          Start time (UTC):05:08:53
                                          Start date (UTC):01/11/2024
                                          Path:/usr/bin/cat
                                          Arguments:cat /proc/net/dev
                                          File size:43416 bytes
                                          MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

                                          Start time (UTC):05:08:53
                                          Start date (UTC):01/11/2024
                                          Path:/usr/bin/bash
                                          Arguments:-
                                          File size:1183448 bytes
                                          MD5 hash:7063c3930affe123baecd3b340f1ad2c

                                          Start time (UTC):05:08:53
                                          Start date (UTC):01/11/2024
                                          Path:/usr/bin/grep
                                          Arguments:grep ens160
                                          File size:199136 bytes
                                          MD5 hash:1e6ebb9dd094f774478f72727bdba0f5

                                          Start time (UTC):05:08:53
                                          Start date (UTC):01/11/2024
                                          Path:/usr/bin/bash
                                          Arguments:-
                                          File size:1183448 bytes
                                          MD5 hash:7063c3930affe123baecd3b340f1ad2c

                                          Start time (UTC):05:08:53
                                          Start date (UTC):01/11/2024
                                          Path:/usr/bin/awk
                                          Arguments:awk "{print $2}"
                                          File size:711136 bytes
                                          MD5 hash:7e9b2ed1272331cfbd2aac2e5eb3f84b

                                          Start time (UTC):05:08:53
                                          Start date (UTC):01/11/2024
                                          Path:/tmp/zone.i686.elf
                                          Arguments:-
                                          File size:3136268 bytes
                                          MD5 hash:7c5af0d55f90e9090314da8046588691

                                          Start time (UTC):05:08:53
                                          Start date (UTC):01/11/2024
                                          Path:/usr/bin/bash
                                          Arguments:bash -c "cat /proc/net/dev |grep ens160 |awk '{print $10}'"
                                          File size:1183448 bytes
                                          MD5 hash:7063c3930affe123baecd3b340f1ad2c

                                          Start time (UTC):05:08:53
                                          Start date (UTC):01/11/2024
                                          Path:/usr/bin/bash
                                          Arguments:-
                                          File size:1183448 bytes
                                          MD5 hash:7063c3930affe123baecd3b340f1ad2c

                                          Start time (UTC):05:08:53
                                          Start date (UTC):01/11/2024
                                          Path:/usr/bin/cat
                                          Arguments:cat /proc/net/dev
                                          File size:43416 bytes
                                          MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

                                          Start time (UTC):05:08:53
                                          Start date (UTC):01/11/2024
                                          Path:/usr/bin/bash
                                          Arguments:-
                                          File size:1183448 bytes
                                          MD5 hash:7063c3930affe123baecd3b340f1ad2c

                                          Start time (UTC):05:08:53
                                          Start date (UTC):01/11/2024
                                          Path:/usr/bin/grep
                                          Arguments:grep ens160
                                          File size:199136 bytes
                                          MD5 hash:1e6ebb9dd094f774478f72727bdba0f5

                                          Start time (UTC):05:08:53
                                          Start date (UTC):01/11/2024
                                          Path:/usr/bin/bash
                                          Arguments:-
                                          File size:1183448 bytes
                                          MD5 hash:7063c3930affe123baecd3b340f1ad2c

                                          Start time (UTC):05:08:53
                                          Start date (UTC):01/11/2024
                                          Path:/usr/bin/awk
                                          Arguments:awk "{print $10}"
                                          File size:711136 bytes
                                          MD5 hash:7e9b2ed1272331cfbd2aac2e5eb3f84b

                                          Start time (UTC):05:09:53
                                          Start date (UTC):01/11/2024
                                          Path:/tmp/zone.i686.elf
                                          Arguments:-
                                          File size:3136268 bytes
                                          MD5 hash:7c5af0d55f90e9090314da8046588691

                                          Start time (UTC):05:09:53
                                          Start date (UTC):01/11/2024
                                          Path:/usr/bin/bash
                                          Arguments:bash -c "cat /proc/net/dev |grep ens160 |awk '{print $2}'"
                                          File size:1183448 bytes
                                          MD5 hash:7063c3930affe123baecd3b340f1ad2c

                                          Start time (UTC):05:09:53
                                          Start date (UTC):01/11/2024
                                          Path:/usr/bin/bash
                                          Arguments:-
                                          File size:1183448 bytes
                                          MD5 hash:7063c3930affe123baecd3b340f1ad2c

                                          Start time (UTC):05:09:53
                                          Start date (UTC):01/11/2024
                                          Path:/usr/bin/cat
                                          Arguments:cat /proc/net/dev
                                          File size:43416 bytes
                                          MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

                                          Start time (UTC):05:09:53
                                          Start date (UTC):01/11/2024
                                          Path:/usr/bin/bash
                                          Arguments:-
                                          File size:1183448 bytes
                                          MD5 hash:7063c3930affe123baecd3b340f1ad2c

                                          Start time (UTC):05:09:53
                                          Start date (UTC):01/11/2024
                                          Path:/usr/bin/grep
                                          Arguments:grep ens160
                                          File size:199136 bytes
                                          MD5 hash:1e6ebb9dd094f774478f72727bdba0f5

                                          Start time (UTC):05:09:53
                                          Start date (UTC):01/11/2024
                                          Path:/usr/bin/bash
                                          Arguments:-
                                          File size:1183448 bytes
                                          MD5 hash:7063c3930affe123baecd3b340f1ad2c

                                          Start time (UTC):05:09:53
                                          Start date (UTC):01/11/2024
                                          Path:/usr/bin/awk
                                          Arguments:awk "{print $2}"
                                          File size:711136 bytes
                                          MD5 hash:7e9b2ed1272331cfbd2aac2e5eb3f84b

                                          Start time (UTC):05:09:54
                                          Start date (UTC):01/11/2024
                                          Path:/tmp/zone.i686.elf
                                          Arguments:-
                                          File size:3136268 bytes
                                          MD5 hash:7c5af0d55f90e9090314da8046588691

                                          Start time (UTC):05:09:54
                                          Start date (UTC):01/11/2024
                                          Path:/usr/bin/bash
                                          Arguments:bash -c "cat /proc/net/dev |grep ens160 |awk '{print $10}'"
                                          File size:1183448 bytes
                                          MD5 hash:7063c3930affe123baecd3b340f1ad2c

                                          Start time (UTC):05:09:54
                                          Start date (UTC):01/11/2024
                                          Path:/usr/bin/bash
                                          Arguments:-
                                          File size:1183448 bytes
                                          MD5 hash:7063c3930affe123baecd3b340f1ad2c

                                          Start time (UTC):05:09:54
                                          Start date (UTC):01/11/2024
                                          Path:/usr/bin/cat
                                          Arguments:cat /proc/net/dev
                                          File size:43416 bytes
                                          MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

                                          Start time (UTC):05:09:54
                                          Start date (UTC):01/11/2024
                                          Path:/usr/bin/bash
                                          Arguments:-
                                          File size:1183448 bytes
                                          MD5 hash:7063c3930affe123baecd3b340f1ad2c

                                          Start time (UTC):05:09:54
                                          Start date (UTC):01/11/2024
                                          Path:/usr/bin/grep
                                          Arguments:grep ens160
                                          File size:199136 bytes
                                          MD5 hash:1e6ebb9dd094f774478f72727bdba0f5

                                          Start time (UTC):05:09:54
                                          Start date (UTC):01/11/2024
                                          Path:/usr/bin/bash
                                          Arguments:-
                                          File size:1183448 bytes
                                          MD5 hash:7063c3930affe123baecd3b340f1ad2c

                                          Start time (UTC):05:09:54
                                          Start date (UTC):01/11/2024
                                          Path:/usr/bin/awk
                                          Arguments:awk "{print $10}"
                                          File size:711136 bytes
                                          MD5 hash:7e9b2ed1272331cfbd2aac2e5eb3f84b