Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
Z5VciPA3Nv.elf

Overview

General Information

Sample name:Z5VciPA3Nv.elf
renamed because original name is a hash value
Original sample name:34dcfdc7d4c450f98de26b0c48bc532a2eb42b058bd9244a7ee0059c3bd84873.elf
Analysis ID:1546916
MD5:131a62d1b18a7ce543ccb47e46675c3a
SHA1:908db9882977879b4b731f6ecb0fb32c285f8c22
SHA256:34dcfdc7d4c450f98de26b0c48bc532a2eb42b058bd9244a7ee0059c3bd84873
Tags:elfransomwareSLNYAuser-JAMESWT_MHT
Infos:

Detection

Score:52
Range:0 - 100
Whitelisted:false

Signatures

Multi AV Scanner detection for submitted file
Found Tor onion address
Contains symbols related to standard C library sleeps (sometimes used to evade sandboxing)
ELF contains segments with high entropy indicating compressed/encrypted content
Executes the "rm" command used to delete files or directories
Sample has stripped symbol table
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1546916
Start date and time:2024-11-01 17:42:07 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 10m 28s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:Z5VciPA3Nv.elf
renamed because original name is a hash value
Original Sample Name:34dcfdc7d4c450f98de26b0c48bc532a2eb42b058bd9244a7ee0059c3bd84873.elf
Detection:MAL
Classification:mal52.evad.linELF@0/0@0/0
Cookbook Comments:
  • Analysis time extended to 480s due to sleep detection in submitted sample
  • VT rate limit hit for: Z5VciPA3Nv.elf
Command:/tmp/Z5VciPA3Nv.elf
PID:6228
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
Usage: /tmp/Z5VciPA3Nv.elf /path/to/be/encrypted
Standard Error:
  • system is lnxubuntu20
  • Z5VciPA3Nv.elf (PID: 6228, Parent: 6150, MD5: 131a62d1b18a7ce543ccb47e46675c3a) Arguments: /tmp/Z5VciPA3Nv.elf
  • dash New Fork (PID: 6260, Parent: 4339)
  • rm (PID: 6260, Parent: 4339, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.5LhOIaz2ga /tmp/tmp.ILUnjFCeZL /tmp/tmp.lV2Das7e7n
  • dash New Fork (PID: 6261, Parent: 4339)
  • rm (PID: 6261, Parent: 4339, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.5LhOIaz2ga /tmp/tmp.ILUnjFCeZL /tmp/tmp.lV2Das7e7n
  • cleanup
No yara matches
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: Z5VciPA3Nv.elfReversingLabs: Detection: 44%

Networking

barindex
Source: Z5VciPA3Nv.elf, 6228.1.0000000008048000.000000000805f000.r-x.sdmpString found in binary or memory: http://xzbltrroh4ocknyi7kj2ucjuw63fhyy23dh6lplydl545d33kbygw2id.onion/
Source: Z5VciPA3Nv.elfString found in binary or memory: http://xzbltrroh4ocknyi7kj2ucjuw63fhyy23dh6lplydl545d33kbygw2id.onion/
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: Z5VciPA3Nv.elfString found in binary or memory: http://xzbltrroh4ocknyi7kj2ucjuw63fhyy23dh6lplydl545d33kbygw2id.onion/
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 33606
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 33606 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
Source: ELF static info symbol of initial sample.symtab present: no
Source: classification engineClassification label: mal52.evad.linELF@0/0@0/0
Source: /usr/bin/dash (PID: 6260)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.5LhOIaz2ga /tmp/tmp.ILUnjFCeZL /tmp/tmp.lV2Das7e7nJump to behavior
Source: /usr/bin/dash (PID: 6261)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.5LhOIaz2ga /tmp/tmp.ILUnjFCeZL /tmp/tmp.lV2Das7e7nJump to behavior
Source: Z5VciPA3Nv.elfSubmission file: segment LOAD with 7.4528 entropy (max. 8.0)
Source: ELF symbol in initial sampleSymbol name: sleep
Source: /tmp/Z5VciPA3Nv.elf (PID: 6228)Queries kernel information via 'uname': Jump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
Virtualization/Sandbox Evasion
OS Credential Dumping1
Security Software Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Obfuscated Files or Information
LSASS Memory1
Virtualization/Sandbox Evasion
Remote Desktop ProtocolData from Removable Media1
Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
File Deletion
Security Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Proxy
Automated ExfiltrationData Encrypted for Impact
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1546916 Sample: Z5VciPA3Nv.elf Startdate: 01/11/2024 Architecture: LINUX Score: 52 13 109.202.202.202, 80 INIT7CH Switzerland 2->13 15 91.189.91.42, 443 CANONICAL-ASGB United Kingdom 2->15 17 2 other IPs or domains 2->17 19 Multi AV Scanner detection for submitted file 2->19 21 Found Tor onion address 2->21 6 Z5VciPA3Nv.elf 2->6         started        9 dash rm 2->9         started        11 dash rm 2->11         started        signatures3 process4 signatures5 23 Found Tor onion address 6->23

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
Z5VciPA3Nv.elf45%ReversingLabsLinux.Ransomware.Babuk
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
NameSourceMaliciousAntivirus DetectionReputation
http://xzbltrroh4ocknyi7kj2ucjuw63fhyy23dh6lplydl545d33kbygw2id.onion/Z5VciPA3Nv.elftrue
    unknown
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    54.171.230.55
    unknownUnited States
    16509AMAZON-02USfalse
    109.202.202.202
    unknownSwitzerland
    13030INIT7CHfalse
    91.189.91.43
    unknownUnited Kingdom
    41231CANONICAL-ASGBfalse
    91.189.91.42
    unknownUnited Kingdom
    41231CANONICAL-ASGBfalse
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    54.171.230.55mips64.elfGet hashmaliciousGafgyt, MiraiBrowse
      meow.arm7.elfGet hashmaliciousUnknownBrowse
        zmap.ppc.elfGet hashmaliciousMirai, OkiruBrowse
          boatnet.spc.elfGet hashmaliciousMiraiBrowse
            .i.elfGet hashmaliciousUnknownBrowse
              shngijernbh.arm6.elfGet hashmaliciousGafgyt, MiraiBrowse
                linux_mips64el_softfloat.elfGet hashmaliciousChaosBrowse
                  x.rar.elfGet hashmaliciousXmrigBrowse
                    tyo2831qq.arm7.elfGet hashmaliciousGafgyt, MiraiBrowse
                      tyo2831qq.m68k.elfGet hashmaliciousGafgyt, MiraiBrowse
                        109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
                        • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
                        91.189.91.43J5uGzpvcAa.elfGet hashmaliciousUnknownBrowse
                          armv7l.elfGet hashmaliciousGafgyt, MiraiBrowse
                            4l9YKCc7qQ.elfGet hashmaliciousUnknownBrowse
                              mips64.elfGet hashmaliciousGafgyt, MiraiBrowse
                                mips.elfGet hashmaliciousGafgyt, MiraiBrowse
                                  meow.arm7.elfGet hashmaliciousUnknownBrowse
                                    main_arm.elfGet hashmaliciousMiraiBrowse
                                      dlr.x86.elfGet hashmaliciousOkiruBrowse
                                        dlr.ppc.elfGet hashmaliciousUnknownBrowse
                                          zmap.arm.elfGet hashmaliciousMirai, OkiruBrowse
                                            91.189.91.42J5uGzpvcAa.elfGet hashmaliciousUnknownBrowse
                                              armv7l.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                4l9YKCc7qQ.elfGet hashmaliciousUnknownBrowse
                                                  mips64.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                    x86_64.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                      mips.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                        meow.arm7.elfGet hashmaliciousUnknownBrowse
                                                          main_arm.elfGet hashmaliciousMiraiBrowse
                                                            dlr.x86.elfGet hashmaliciousOkiruBrowse
                                                              dlr.ppc.elfGet hashmaliciousUnknownBrowse
                                                                No context
                                                                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                CANONICAL-ASGBi686.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                • 185.125.190.26
                                                                J5uGzpvcAa.elfGet hashmaliciousUnknownBrowse
                                                                • 91.189.91.42
                                                                armv7l.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                • 91.189.91.42
                                                                H5LPetzgXV.elfGet hashmaliciousUnknownBrowse
                                                                • 185.125.190.26
                                                                4l9YKCc7qQ.elfGet hashmaliciousUnknownBrowse
                                                                • 91.189.91.42
                                                                mips64.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                • 91.189.91.42
                                                                x86_64.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                • 91.189.91.42
                                                                mips.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                • 91.189.91.42
                                                                armv5l.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                • 185.125.190.26
                                                                meow.arm7.elfGet hashmaliciousUnknownBrowse
                                                                • 91.189.91.42
                                                                CANONICAL-ASGBi686.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                • 185.125.190.26
                                                                J5uGzpvcAa.elfGet hashmaliciousUnknownBrowse
                                                                • 91.189.91.42
                                                                armv7l.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                • 91.189.91.42
                                                                H5LPetzgXV.elfGet hashmaliciousUnknownBrowse
                                                                • 185.125.190.26
                                                                4l9YKCc7qQ.elfGet hashmaliciousUnknownBrowse
                                                                • 91.189.91.42
                                                                mips64.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                • 91.189.91.42
                                                                x86_64.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                • 91.189.91.42
                                                                mips.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                • 91.189.91.42
                                                                armv5l.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                • 185.125.190.26
                                                                meow.arm7.elfGet hashmaliciousUnknownBrowse
                                                                • 91.189.91.42
                                                                AMAZON-02USnPRmTlXhOT.elfGet hashmaliciousUnknownBrowse
                                                                • 34.243.160.129
                                                                Damar Training.pdfGet hashmaliciousHTMLPhisher, Mamba2FABrowse
                                                                • 18.245.31.5
                                                                mips64.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                • 54.171.230.55
                                                                x86_64.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                • 34.249.145.219
                                                                https://u47872954.ct.sendgrid.net/ls/click?upn=u001.fn1BsYIkFXRWxBLF12AvXhKUqktmOI7EPkchHYpa8lb2yJr9vm47Biq1iwhYH4x0W6E6_1tlZTUgFpToOJRvXeJjZ1lQQtiPaV281MW3UjMlmRxOXQrHf3E28Ct8cWw3pFJv8ww35QVlHVAsV9LrE8WJ-2FqWVvVFyUxLS7XbjE4ioBaNzI7Y9AQvglzmjEqljOvLuB-2FqyLAOnwfIZ8a2UOhb0kq4DsltFbCSVl8L5tTVcXPovhejZuw7J5gFYEuhvfLU6jp9IiI6bOp4vutoVple794Svog7VmNTHCQykEIajsBwvsIA9xBhrTaUhPe3riTZOj5RQVgP8LolzHF5ds6ImaI4Q1KNsmEF06CineSoPu7BKGd-2B4IINKzojAY3yUTkdWQLuCwDcmh7vK-2Fm4MQ0xAiPJ-2BNim16FZPVrX44e4DFM1rc1r1ZYN2APdeEIThalu0Ag-2BNzl5TCF9-2F-2B4cIgV-2B8ceF573hvcKOOmdD1jbxRbFryn-2FGT77SPyR6cNo7joqYajHU5-2F1gyPof24NnmOIwvhn7qKr0Ihz3SIWFLubPXV0GdcG6guT-2FBjwN6h83YPSF-2F5Pk0uzrf9DG4ZRnISsjJaazqmdBRAAsyoWwP5iXWDQEfiJXubX9fD-2BREtQifDIoI36c8qvCy5hrOP9aAfzd2djtg-2B8gR7MvgWYCa5sA7wAgdCKrrNRjX7eeAtG5StCtmRi-2BsSO4PCFgsA4QlR8AVRyhdPdKhSYzgA-2F1BCyYmRsFeWn4YzRn0mexGeZM3PwhHAdqlfom16LJGSiVeG98p5ZK5N-2BZQuMTlINorxwlmSmaGarY5x7TUyztB-2Bv8L8gRhXdcDKSzxiMknwYCjp3XaQdwr-2Fp8kePQSl33tJvX1ITAiP7FBhlwoPgNxbRoTwVzl0I2Q2bE71pQB2jeSQldBukVcgJT-2BrmpKQA1GW5-2B59frk-3DGet hashmaliciousUnknownBrowse
                                                                • 18.245.46.10
                                                                meow.arm7.elfGet hashmaliciousUnknownBrowse
                                                                • 54.171.230.55
                                                                file.exeGet hashmaliciousStealc, VidarBrowse
                                                                • 3.168.2.115
                                                                https://u7990385.ct.sendgrid.net/ls/click?upn=u001.oZ6GXC16Ztdw1ob-2F3C5yow-2FsK2YC4S8s269h9OLgp-2FGcQesCtXDXKgCEAF90Sa3OUL2ncGoAKstQjRhddelr-2Bx3frrehyL8aaBbhAx-2Fm3uQTToUZwzw9vU-2BHl4N8-2FbXNOWh47xHSpNswH5B20hFc1rkwm1HkocouB6puE-2FnM91Ea9xIyldie1eyHQvDQGF6-2F1OUGSCOg8K-2Fk8REDXGncryLNWAkNll9tI4svh29XngoJuJcvPHIwWw07juA1Lr687mlf_LZJN6rqeZVHTY7vi7TysfnSOWUsKUPL2t2FWuf1mHJZyRrnfnXk5in-2FtsLaVkEL4z-2F5H1v5rdZCMtKV4-2B7XswPaXSOX44YEil-2BgQ6f1-2BLxpcwnoVslshbeFD8-2FSkDYUL5gsTS7cnhi8iHs4T9b6wzPIbVlUAEwQAwoGeUFJH5x3RAGtspzpDyRWDwHNrMMOluLHeocJQAj7iS1dnS-2B-2Fhpf21Fjpr9lUosnkGJYIkfG0KNsjglBmf2yQvwZsg0Wp706kciqJgB5pqtemV1qFgZLIL2K-2BsyRLGqv3bbeqv6LWX-2Fbn97e4q8h4LdJzfXKTxRJD2tMgj2k7Ls1BdPjLturPdeJvpG2db-2FhwENpXetZR7k21gPz6in5zk7zhcmgIkZssf1WUkdDcjfwIeY2HuQe6EHwacpAnjlFSG7cGBDYbRKnbjWz72QvhesvDQrxGZA-2F-2FwuD5CryGFeRAazVMLU-2FTUgYuXTJzCzL6qav9lYxCC-2Bwx97sSjci4FffUtDhPcIZfKCP-2Ff9rufbc-2FOdTD6VLIHU5lNW4k8Nb-2FWedSu8kS9RXhRxjWAbV4qYK-2F68HLgFHbzOrm6M-2FG6a-2BnVs9TkK9ei8xVDo6cAhkQYCxDYOCBJJC-2BfLWulZgQ85hdg59312Kv6zX2g11nE5GRn-2B6U-2B2tuv67vEmY8CUatMt7UrQHEhVlrPnXi1EamUHW4AGpMQfKBj0GXRdJxG0fD3Zx-2FiIXcDEoi3GhoWLQTKZU-2FWlBKJiyqDLjDXS6qRg1X-2Fsd3R5k7fswdpYLTizSHt12T6-2Bo0IoKg0cyJsPKBfoK9Uleu7f9wgtdH4RtvaMbk9-2Buqhl6zW9NHZET-2BbGJHqyqlBeTSBtTZM6ltHEDZrojb0Lhszq-2BKoSCsuyjzgKAFmmWSRMGxwsXoHHuV8LoFEZjuiOSkTWEP-2FvQ0ZaWfqnp81VXTEktfVY9Xmx-2FaHq5NRH3vqpZc6LNkkSHnpJBPIYA83Mw-3D-3DGet hashmaliciousUnknownBrowse
                                                                • 35.163.144.222
                                                                nNX5KYQRhg.exeGet hashmaliciousNeconydBrowse
                                                                • 52.34.198.229
                                                                bd0wJGTae5.exeGet hashmaliciousNeconydBrowse
                                                                • 52.34.198.229
                                                                INIT7CHJ5uGzpvcAa.elfGet hashmaliciousUnknownBrowse
                                                                • 109.202.202.202
                                                                armv7l.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                • 109.202.202.202
                                                                4l9YKCc7qQ.elfGet hashmaliciousUnknownBrowse
                                                                • 109.202.202.202
                                                                mips64.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                • 109.202.202.202
                                                                x86_64.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                • 109.202.202.202
                                                                mips.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                • 109.202.202.202
                                                                meow.arm7.elfGet hashmaliciousUnknownBrowse
                                                                • 109.202.202.202
                                                                main_arm.elfGet hashmaliciousMiraiBrowse
                                                                • 109.202.202.202
                                                                dlr.x86.elfGet hashmaliciousOkiruBrowse
                                                                • 109.202.202.202
                                                                dlr.ppc.elfGet hashmaliciousUnknownBrowse
                                                                • 109.202.202.202
                                                                No context
                                                                No context
                                                                No created / dropped files found
                                                                File type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), dynamically linked, interpreter /lib/ld-linux.so.2, for GNU/Linux 2.6.18, BuildID[sha1]=691f92a4dd16e0fdb066e938bca031b7777f7f71, stripped
                                                                Entropy (8bit):5.7441959730501235
                                                                TrID:
                                                                • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
                                                                • ELF Executable and Linkable format (generic) (4004/1) 49.84%
                                                                File name:Z5VciPA3Nv.elf
                                                                File size:98'600 bytes
                                                                MD5:131a62d1b18a7ce543ccb47e46675c3a
                                                                SHA1:908db9882977879b4b731f6ecb0fb32c285f8c22
                                                                SHA256:34dcfdc7d4c450f98de26b0c48bc532a2eb42b058bd9244a7ee0059c3bd84873
                                                                SHA512:949eebcdbbebf7ac155712ff652938855b76a9241ac1eb436f643f008292dbb7ba82c7a867dd253db813e66230774ad8c0a89b84ac94f07a65a3da99159d7b0e
                                                                SSDEEP:3072:azFUCo7tESuKtyo6+64pvG5/eNthr/XzuKHUE7L6eK32Z1mFl6Aw:a2C/DYzV7L6eKbFl6Aw
                                                                TLSH:AFA3B63EA75241BBD0E3A632C50AF0BBD7027672919A565BB7085D2CD33E5C397A8307
                                                                File Content Preview:.ELF........................4...x|......4. ...(.........4...4...4.......................4...4...4....................................d...d...............p..........@...|...............4p..4...4.......................H...H...H...D...D...........P.td.L.....

                                                                ELF header

                                                                Class:ELF32
                                                                Data:2's complement, little endian
                                                                Version:1 (current)
                                                                Machine:Intel 80386
                                                                Version Number:0x1
                                                                Type:EXEC (Executable file)
                                                                OS/ABI:UNIX - System V
                                                                ABI Version:0
                                                                Entry Point Address:0x8049ad0
                                                                Flags:0x0
                                                                ELF Header Size:52
                                                                Program Header Offset:52
                                                                Program Header Size:32
                                                                Number of Program Headers:8
                                                                Section Header Offset:97400
                                                                Section Header Size:40
                                                                Number of Section Headers:30
                                                                Header String Table Index:29
                                                                NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                                NULL0x00x00x00x00x0000
                                                                .interpPROGBITS0x80481340x1340x130x00x2A001
                                                                .note.ABI-tagNOTE0x80481480x1480x200x00x2A004
                                                                .note.gnu.build-idNOTE0x80481680x1680x240x00x2A004
                                                                .gnu.hashGNU_HASH0x804818c0x18c0x300x40x2A504
                                                                .dynsymDYNSYM0x80481bc0x1bc0x6a00x100x2A614
                                                                .dynstrSTRTAB0x804885c0x85c0x7550x00x2A001
                                                                .gnu.versionVERSYM0x8048fb20xfb20xd40x20x2A502
                                                                .gnu.version_rVERNEED0x80490880x10880xe00x00x2A644
                                                                .rel.dynREL0x80491680x11680x400x80x2A504
                                                                .rel.pltREL0x80491a80x11a80x2f80x80x2A5124
                                                                .initPROGBITS0x80494a00x14a00x300x00x6AX004
                                                                .pltPROGBITS0x80494d00x14d00x6000x40x6AX004
                                                                .textPROGBITS0x8049ad00x1ad00x10c5c0x00x6AX0016
                                                                .finiPROGBITS0x805a72c0x1272c0x1c0x00x6AX004
                                                                .rodataPROGBITS0x805a7600x127600x25390x00x2A0032
                                                                .eh_frame_hdrPROGBITS0x805cc9c0x14c9c0x3bc0x00x2A004
                                                                .eh_framePROGBITS0x805d0580x150580x12100x00x2A004
                                                                .gcc_except_tablePROGBITS0x805e2680x162680x2440x00x2A004
                                                                .ctorsPROGBITS0x805f0000x170000x180x00x3WA004
                                                                .dtorsPROGBITS0x805f0180x170180x80x00x3WA004
                                                                .jcrPROGBITS0x805f0200x170200x40x00x3WA004
                                                                .data.rel.roPROGBITS0x805f0240x170240x100x00x3WA004
                                                                .dynamicDYNAMIC0x805f0340x170340xe00x80x3WA604
                                                                .gotPROGBITS0x805f1140x171140x240x40x3WA004
                                                                .got.pltPROGBITS0x805f1380x171380x1880x40x3WA004
                                                                .dataPROGBITS0x805f2c00x172c00x8800x00x3WA0032
                                                                .bssNOBITS0x805fb400x17b400x3c0x00x3WA008
                                                                .commentPROGBITS0x00x17b400x2d0x10x30MS001
                                                                .shstrtabSTRTAB0x00x17b6d0x10b0x00x0001
                                                                TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                                PHDR0x340x80480340x80480340x1000x1002.98380x5R E0x4
                                                                INTERP0x1340x80481340x80481340x130x133.68190x4R 0x1/lib/ld-linux.so.2.interp
                                                                LOAD0x00x80480000x80480000x164ac0x164ac5.76040x5R E0x1000.interp .note.ABI-tag .note.gnu.build-id .gnu.hash .dynsym .dynstr .gnu.version .gnu.version_r .rel.dyn .rel.plt .init .plt .text .fini .rodata .eh_frame_hdr .eh_frame .gcc_except_table
                                                                LOAD0x170000x805f0000x805f0000xb400xb7c7.45280x6RW 0x1000.ctors .dtors .jcr .data.rel.ro .dynamic .got .got.plt .data .bss
                                                                DYNAMIC0x170340x805f0340x805f0340xe00xe02.95310x6RW 0x4.dynamic
                                                                NOTE0x1480x80481480x80481480x440x443.49240x4R 0x4.note.ABI-tag .note.gnu.build-id
                                                                GNU_EH_FRAME0x14c9c0x805cc9c0x805cc9c0x3bc0x3bc5.08770x4R 0x4.eh_frame_hdr
                                                                GNU_STACK0x00x00x00x00x00.00000x6RW 0x4
                                                                TypeMetaValueTag
                                                                DT_NEEDEDsharedliblibstdc++.so.60x1
                                                                DT_NEEDEDsharedliblibgcc_s.so.10x1
                                                                DT_NEEDEDsharedliblibpthread.so.00x1
                                                                DT_NEEDEDsharedliblibc.so.60x1
                                                                DT_INITvalue0x80494a00xc
                                                                DT_FINIvalue0x805a72c0xd
                                                                DT_GNU_HASHvalue0x804818c0x6ffffef5
                                                                DT_STRTABvalue0x804885c0x5
                                                                DT_SYMTABvalue0x80481bc0x6
                                                                DT_STRSZbytes18770xa
                                                                DT_SYMENTbytes160xb
                                                                DT_DEBUGvalue0x00x15
                                                                DT_PLTGOTvalue0x805f1380x3
                                                                DT_PLTRELSZbytes7600x2
                                                                DT_PLTRELpltrelDT_REL0x14
                                                                DT_JMPRELvalue0x80491a80x17
                                                                DT_RELvalue0x80491680x11
                                                                DT_RELSZbytes640x12
                                                                DT_RELENTbytes80x13
                                                                DT_VERNEEDvalue0x80490880x6ffffffe
                                                                DT_VERNEEDNUMvalue40x6fffffff
                                                                DT_VERSYMvalue0x8048fb20x6ffffff0
                                                                DT_NULLvalue0x00x0
                                                                NameVersion Info NameVersion Info File NameSection NameValueSizeSymbol TypeSymbol BindSymbol VisibilityNdx
                                                                .dynsym0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                                                _IO_stdin_used.dynsym0x805a7644OBJECT<unknown>DEFAULT15
                                                                _Jv_RegisterClasses.dynsym0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                                                _Unwind_ResumeGCC_3.0libgcc_s.so.1.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                _ZNKSs17find_first_not_ofEPKcjGLIBCXX_3.4libstdc++.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                _ZNKSs4findEPKcjGLIBCXX_3.4libstdc++.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                _ZNKSs4sizeEvGLIBCXX_3.4libstdc++.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                _ZNKSs5c_strEvGLIBCXX_3.4libstdc++.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                _ZNKSs6lengthEvGLIBCXX_3.4libstdc++.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                _ZNKSs6substrEjjGLIBCXX_3.4libstdc++.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                _ZNKSt9basic_iosIcSt11char_traitsIcEEcvPvEvGLIBCXX_3.4libstdc++.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                _ZNSaIcEC1EvGLIBCXX_3.4libstdc++.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                _ZNSaIcED1EvGLIBCXX_3.4libstdc++.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                _ZNSolsEPFRSoS_EGLIBCXX_3.4libstdc++.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                _ZNSolsEiGLIBCXX_3.4libstdc++.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                _ZNSs6appendEPKcGLIBCXX_3.4libstdc++.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                _ZNSs6appendEPKcjGLIBCXX_3.4libstdc++.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                _ZNSs6appendERKSsGLIBCXX_3.4libstdc++.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                _ZNSs7reserveEjGLIBCXX_3.4libstdc++.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                _ZNSsC1EPKcRKSaIcEGLIBCXX_3.4libstdc++.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                _ZNSsC1ERKSsGLIBCXX_3.4libstdc++.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                _ZNSsC1EvGLIBCXX_3.4libstdc++.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                _ZNSsD1EvGLIBCXX_3.4libstdc++.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                _ZNSsaSERKSsGLIBCXX_3.4libstdc++.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                _ZNSspLEPKcGLIBCXX_3.4libstdc++.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                _ZNSt13runtime_errorC1ERKSsGLIBCXX_3.4libstdc++.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                _ZNSt13runtime_errorD1EvGLIBCXX_3.4libstdc++.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                _ZNSt18basic_stringstreamIcSt11char_traitsIcESaIcEEC1ERKSsSt13_Ios_OpenmodeGLIBCXX_3.4libstdc++.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                _ZNSt18basic_stringstreamIcSt11char_traitsIcESaIcEED1EvGLIBCXX_3.4libstdc++.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                _ZNSt8ios_base4InitC1EvGLIBCXX_3.4libstdc++.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                _ZNSt8ios_base4InitD1EvGLIBCXX_3.4libstdc++.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                _ZSt17__throw_bad_allocvGLIBCXX_3.4libstdc++.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                _ZSt20__throw_length_errorPKcGLIBCXX_3.4libstdc++.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                _ZSt4cerrGLIBCXX_3.4libstdc++.so.6.dynsym0x00OBJECT<unknown>DEFAULTSHN_UNDEF
                                                                _ZSt4coutGLIBCXX_3.4libstdc++.so.6.dynsym0x00OBJECT<unknown>DEFAULTSHN_UNDEF
                                                                _ZSt4endlIcSt11char_traitsIcEERSt13basic_ostreamIT_T0_ES6_GLIBCXX_3.4libstdc++.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                _ZSt7getlineIcSt11char_traitsIcESaIcEERSt13basic_istreamIT_T0_ES7_RSbIS4_S5_T1_EGLIBCXX_3.4libstdc++.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                _ZSt9terminatevGLIBCXX_3.4libstdc++.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                _ZStlsISt11char_traitsIcEERSt13basic_ostreamIcT_ES5_PKcGLIBCXX_3.4libstdc++.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                _ZStlsIcSt11char_traitsIcESaIcEERSt13basic_ostreamIT_T0_ES7_RKSbIS4_S5_T1_EGLIBCXX_3.4libstdc++.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                _ZStplIcSt11char_traitsIcESaIcEESbIT_T0_T1_EPKS3_RKS6_.dynsym0x804ac58162FUNC<unknown>DEFAULT13
                                                                _ZTISt13runtime_errorGLIBCXX_3.4libstdc++.so.6.dynsym0x00OBJECT<unknown>DEFAULTSHN_UNDEF
                                                                _ZdlPvGLIBCXX_3.4libstdc++.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                _ZnwjGLIBCXX_3.4libstdc++.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                __cxa_allocate_exceptionCXXABI_1.3libstdc++.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                __cxa_atexitGLIBC_2.1.3libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                __cxa_begin_catchCXXABI_1.3libstdc++.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                __cxa_end_catchCXXABI_1.3libstdc++.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                __cxa_free_exceptionCXXABI_1.3libstdc++.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                __cxa_rethrowCXXABI_1.3libstdc++.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                __cxa_throwCXXABI_1.3libstdc++.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                __gmon_start__.dynsym0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                                                __gxx_personality_v0CXXABI_1.3libstdc++.so.6.dynsym0x8049a100FUNC<unknown>DEFAULTSHN_UNDEF
                                                                __libc_start_mainGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                __lxstatGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                __xstat64GLIBC_2.2libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                atoiGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                closedirGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                difftimeGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                exitGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                fcloseGLIBC_2.1libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                fflushGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                fgetsGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                fopenGLIBC_2.1libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                fprintfGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                freadGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                freeGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                fseekGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                fwriteGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                mallocGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                memcpyGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                memsetGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                opendirGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                pcloseGLIBC_2.1libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                popenGLIBC_2.1libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                prctlGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                printfGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                pthread_cancelGLIBC_2.0libpthread.so.0.dynsym0x8049aa00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                pthread_cond_broadcastGLIBC_2.3.2libpthread.so.0.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                pthread_cond_initGLIBC_2.3.2libpthread.so.0.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                pthread_cond_signalGLIBC_2.3.2libpthread.so.0.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                pthread_cond_waitGLIBC_2.3.2libpthread.so.0.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                pthread_createGLIBC_2.1libpthread.so.0.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                pthread_detachGLIBC_2.0libpthread.so.0.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                pthread_killGLIBC_2.0libpthread.so.0.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                pthread_mutex_initGLIBC_2.0libpthread.so.0.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                pthread_mutex_lockGLIBC_2.0libpthread.so.0.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                pthread_mutex_unlockGLIBC_2.0libpthread.so.0.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                putcharGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                putsGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                readdirGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                renameGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                sigactionGLIBC_2.0libpthread.so.0.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                sigemptysetGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                sleepGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                snprintfGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                sprintfGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                stderrGLIBC_2.0libc.so.6.dynsym0x00OBJECT<unknown>DEFAULTSHN_UNDEF
                                                                strcatGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                strcmpGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                strcpyGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                strlenGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                strstrGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                sysconfGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                systemGLIBC_2.0libpthread.so.0.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                timeGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                TimestampSource PortDest PortSource IPDest IP
                                                                Nov 1, 2024 17:42:55.397742033 CET43928443192.168.2.2391.189.91.42
                                                                Nov 1, 2024 17:43:01.029082060 CET42836443192.168.2.2391.189.91.43
                                                                Nov 1, 2024 17:43:02.052798986 CET4251680192.168.2.23109.202.202.202
                                                                Nov 1, 2024 17:43:16.130795956 CET43928443192.168.2.2391.189.91.42
                                                                Nov 1, 2024 17:43:25.190982103 CET33606443192.168.2.2354.171.230.55
                                                                Nov 1, 2024 17:43:25.196443081 CET4433360654.171.230.55192.168.2.23
                                                                Nov 1, 2024 17:43:25.196511030 CET33606443192.168.2.2354.171.230.55
                                                                Nov 1, 2024 17:43:28.417088985 CET42836443192.168.2.2391.189.91.43
                                                                Nov 1, 2024 17:43:32.512665033 CET4251680192.168.2.23109.202.202.202
                                                                Nov 1, 2024 17:43:57.085110903 CET43928443192.168.2.2391.189.91.42

                                                                System Behavior

                                                                Start time (UTC):16:42:53
                                                                Start date (UTC):01/11/2024
                                                                Path:/tmp/Z5VciPA3Nv.elf
                                                                Arguments:/tmp/Z5VciPA3Nv.elf
                                                                File size:98600 bytes
                                                                MD5 hash:131a62d1b18a7ce543ccb47e46675c3a

                                                                Start time (UTC):16:43:24
                                                                Start date (UTC):01/11/2024
                                                                Path:/usr/bin/dash
                                                                Arguments:-
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):16:43:24
                                                                Start date (UTC):01/11/2024
                                                                Path:/usr/bin/rm
                                                                Arguments:rm -f /tmp/tmp.5LhOIaz2ga /tmp/tmp.ILUnjFCeZL /tmp/tmp.lV2Das7e7n
                                                                File size:72056 bytes
                                                                MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                                                Start time (UTC):16:43:24
                                                                Start date (UTC):01/11/2024
                                                                Path:/usr/bin/dash
                                                                Arguments:-
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):16:43:24
                                                                Start date (UTC):01/11/2024
                                                                Path:/usr/bin/rm
                                                                Arguments:rm -f /tmp/tmp.5LhOIaz2ga /tmp/tmp.ILUnjFCeZL /tmp/tmp.lV2Das7e7n
                                                                File size:72056 bytes
                                                                MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b