Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
x86.elf

Overview

General Information

Sample name:x86.elf
Analysis ID:1576201
MD5:3e7577a2fa2cca1c44fd60bc3d67b64a
SHA1:ea0d89cb9b5d0c7b80512732109bbddb092e04b3
SHA256:975e5edf880671ad6b0e9c46f6125313b74c79a01af2596ff462fe44aec15cf4
Tags:elfuser-abuse_ch
Infos:

Detection

Mirai
Score:68
Range:0 - 100
Whitelisted:false

Signatures

Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Yara detected Mirai
Machine Learning detection for sample
Detected TCP or UDP traffic on non-standard ports
Executes the "rm" command used to delete files or directories
Sample contains strings that are user agent strings indicative of HTTP manipulation
Sample has stripped symbol table
Yara signature match

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1576201
Start date and time:2024-12-16 16:28:05 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 5m 1s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:x86.elf
Detection:MAL
Classification:mal68.troj.linELF@0/0@0/0
  • VT rate limit hit for: x86.elf
Command:/tmp/x86.elf
PID:6249
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
Infected
Standard Error:
  • system is lnxubuntu20
  • dash New Fork (PID: 6224, Parent: 4331)
  • rm (PID: 6224, Parent: 4331, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.kQ6IpcnAj6 /tmp/tmp.o46WndApTP /tmp/tmp.AFUl6K9Flp
  • dash New Fork (PID: 6225, Parent: 4331)
  • rm (PID: 6225, Parent: 4331, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.kQ6IpcnAj6 /tmp/tmp.o46WndApTP /tmp/tmp.AFUl6K9Flp
  • x86.elf (PID: 6249, Parent: 6155, MD5: 3e7577a2fa2cca1c44fd60bc3d67b64a) Arguments: /tmp/x86.elf
    • x86.elf New Fork (PID: 6250, Parent: 6249)
      • x86.elf New Fork (PID: 6251, Parent: 6250)
        • x86.elf New Fork (PID: 6252, Parent: 6251)
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
MiraiMirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.mirai
SourceRuleDescriptionAuthorStrings
x86.elfJoeSecurity_Mirai_8Yara detected MiraiJoe Security
    x86.elfLinux_Trojan_Gafgyt_e6d75e6funknownunknown
    • 0x8a3e:$a: 00 00 00 CD 80 C3 8B 54 24 04 8B 4C 24 08 87 D3 B8 5B 00 00 00
    x86.elfLinux_Trojan_Mirai_122ff2e6unknownunknown
    • 0x6df7:$a: 24 EB 15 89 F0 83 C8 01 EB 03 8B 5B 08 3B 43 04 72 F8 8B 4B 0C 89
    x86.elfLinux_Trojan_Mirai_fa48b592unknownunknown
    • 0xbea1:$a: 31 C0 BA 01 00 00 00 B9 01 00 00 00 03 04 24 89 D7 31 D2 F7 F7 0F
    x86.elfLinux_Trojan_Mirai_8aa7b5d3unknownunknown
    • 0x45a2:$a: 8B 4C 24 14 8B 74 24 0C 8B 5C 24 10 85 C9 74 0D 31 D2 8A 04 1A 88
    SourceRuleDescriptionAuthorStrings
    6251.1.0000000008048000.0000000008059000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
      6251.1.0000000008048000.0000000008059000.r-x.sdmpLinux_Trojan_Gafgyt_e6d75e6funknownunknown
      • 0x8a3e:$a: 00 00 00 CD 80 C3 8B 54 24 04 8B 4C 24 08 87 D3 B8 5B 00 00 00
      6251.1.0000000008048000.0000000008059000.r-x.sdmpLinux_Trojan_Mirai_122ff2e6unknownunknown
      • 0x6df7:$a: 24 EB 15 89 F0 83 C8 01 EB 03 8B 5B 08 3B 43 04 72 F8 8B 4B 0C 89
      6251.1.0000000008048000.0000000008059000.r-x.sdmpLinux_Trojan_Mirai_fa48b592unknownunknown
      • 0xbea1:$a: 31 C0 BA 01 00 00 00 B9 01 00 00 00 03 04 24 89 D7 31 D2 F7 F7 0F
      6251.1.0000000008048000.0000000008059000.r-x.sdmpLinux_Trojan_Mirai_8aa7b5d3unknownunknown
      • 0x45a2:$a: 8B 4C 24 14 8B 74 24 0C 8B 5C 24 10 85 C9 74 0D 31 D2 8A 04 1A 88
      Click to see the 10 entries
      No Suricata rule has matched

      Click to jump to signature section

      Show All Signature Results

      AV Detection

      barindex
      Source: x86.elfReversingLabs: Detection: 47%
      Source: x86.elfJoe Sandbox ML: detected
      Source: global trafficTCP traffic: 192.168.2.23:40262 -> 85.239.34.134:6666
      Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
      Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
      Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
      Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
      Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
      Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
      Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
      Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
      Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
      Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
      Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
      Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
      Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
      Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
      Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
      Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
      Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
      Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
      Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
      Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
      Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
      Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
      Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
      Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
      Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
      Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
      Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
      Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
      Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
      Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
      Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
      Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
      Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
      Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
      Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
      Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
      Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
      Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
      Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
      Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
      Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
      Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
      Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
      Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
      Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
      Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
      Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
      Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
      Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
      Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
      Source: x86.elfString found in binary or memory: http://fast.no/support/crawler.asp)
      Source: x86.elfString found in binary or memory: http://feedback.redkolibri.com/
      Source: x86.elfString found in binary or memory: http://www.baidu.com/search/spider.htm)
      Source: x86.elfString found in binary or memory: http://www.baidu.com/search/spider.html)
      Source: x86.elfString found in binary or memory: http://www.billybobbot.com/crawler/)
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 33606
      Source: unknownNetwork traffic detected: HTTP traffic on port 33606 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443

      System Summary

      barindex
      Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_e6d75e6f Author: unknown
      Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_122ff2e6 Author: unknown
      Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_fa48b592 Author: unknown
      Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_8aa7b5d3 Author: unknown
      Source: 6251.1.0000000008048000.0000000008059000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_e6d75e6f Author: unknown
      Source: 6251.1.0000000008048000.0000000008059000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_122ff2e6 Author: unknown
      Source: 6251.1.0000000008048000.0000000008059000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_fa48b592 Author: unknown
      Source: 6251.1.0000000008048000.0000000008059000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 Author: unknown
      Source: 6250.1.0000000008048000.0000000008059000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_e6d75e6f Author: unknown
      Source: 6250.1.0000000008048000.0000000008059000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_122ff2e6 Author: unknown
      Source: 6250.1.0000000008048000.0000000008059000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_fa48b592 Author: unknown
      Source: 6250.1.0000000008048000.0000000008059000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 Author: unknown
      Source: 6249.1.0000000008048000.0000000008059000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_e6d75e6f Author: unknown
      Source: 6249.1.0000000008048000.0000000008059000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_122ff2e6 Author: unknown
      Source: 6249.1.0000000008048000.0000000008059000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_fa48b592 Author: unknown
      Source: 6249.1.0000000008048000.0000000008059000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 Author: unknown
      Source: ELF static info symbol of initial sample.symtab present: no
      Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_e6d75e6f reference_sample = 48b15093f33c18778724c48c34199a420be4beb0d794e36034097806e1521eb8, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = e99805e8917d6526031270b6da5c2f3cc1c8235fed1d47134835a107d0df497c, id = e6d75e6f-aa04-4767-8730-6909958044a7, last_modified = 2021-09-16
      Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_122ff2e6 reference_sample = c7dd999a033fa3edc1936785b87cd69ce2f5cac5a084ddfaf527a1094e718bc4, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 3c9ffd7537e30a21eefa6c174f801264b92a85a1bc73e34e6dc9e29f84658348, id = 122ff2e6-56e6-4aa8-a3ec-c19d31eb1f80, last_modified = 2021-09-16
      Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_fa48b592 reference_sample = c9e33befeec133720b3ba40bb3cd7f636aad80f72f324c5fe65ac7af271c49ee, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 8838d2752b310dbf7d12f6cf023244aaff4fdf5b55cf1e3b71843210df0fcf88, id = fa48b592-8d80-45af-a3e4-232695b8f5dd, last_modified = 2021-09-16
      Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_8aa7b5d3 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444, id = 8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9, last_modified = 2022-01-26
      Source: 6251.1.0000000008048000.0000000008059000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_e6d75e6f reference_sample = 48b15093f33c18778724c48c34199a420be4beb0d794e36034097806e1521eb8, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = e99805e8917d6526031270b6da5c2f3cc1c8235fed1d47134835a107d0df497c, id = e6d75e6f-aa04-4767-8730-6909958044a7, last_modified = 2021-09-16
      Source: 6251.1.0000000008048000.0000000008059000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_122ff2e6 reference_sample = c7dd999a033fa3edc1936785b87cd69ce2f5cac5a084ddfaf527a1094e718bc4, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 3c9ffd7537e30a21eefa6c174f801264b92a85a1bc73e34e6dc9e29f84658348, id = 122ff2e6-56e6-4aa8-a3ec-c19d31eb1f80, last_modified = 2021-09-16
      Source: 6251.1.0000000008048000.0000000008059000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_fa48b592 reference_sample = c9e33befeec133720b3ba40bb3cd7f636aad80f72f324c5fe65ac7af271c49ee, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 8838d2752b310dbf7d12f6cf023244aaff4fdf5b55cf1e3b71843210df0fcf88, id = fa48b592-8d80-45af-a3e4-232695b8f5dd, last_modified = 2021-09-16
      Source: 6251.1.0000000008048000.0000000008059000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444, id = 8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9, last_modified = 2022-01-26
      Source: 6250.1.0000000008048000.0000000008059000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_e6d75e6f reference_sample = 48b15093f33c18778724c48c34199a420be4beb0d794e36034097806e1521eb8, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = e99805e8917d6526031270b6da5c2f3cc1c8235fed1d47134835a107d0df497c, id = e6d75e6f-aa04-4767-8730-6909958044a7, last_modified = 2021-09-16
      Source: 6250.1.0000000008048000.0000000008059000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_122ff2e6 reference_sample = c7dd999a033fa3edc1936785b87cd69ce2f5cac5a084ddfaf527a1094e718bc4, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 3c9ffd7537e30a21eefa6c174f801264b92a85a1bc73e34e6dc9e29f84658348, id = 122ff2e6-56e6-4aa8-a3ec-c19d31eb1f80, last_modified = 2021-09-16
      Source: 6250.1.0000000008048000.0000000008059000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_fa48b592 reference_sample = c9e33befeec133720b3ba40bb3cd7f636aad80f72f324c5fe65ac7af271c49ee, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 8838d2752b310dbf7d12f6cf023244aaff4fdf5b55cf1e3b71843210df0fcf88, id = fa48b592-8d80-45af-a3e4-232695b8f5dd, last_modified = 2021-09-16
      Source: 6250.1.0000000008048000.0000000008059000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444, id = 8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9, last_modified = 2022-01-26
      Source: 6249.1.0000000008048000.0000000008059000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_e6d75e6f reference_sample = 48b15093f33c18778724c48c34199a420be4beb0d794e36034097806e1521eb8, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = e99805e8917d6526031270b6da5c2f3cc1c8235fed1d47134835a107d0df497c, id = e6d75e6f-aa04-4767-8730-6909958044a7, last_modified = 2021-09-16
      Source: 6249.1.0000000008048000.0000000008059000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_122ff2e6 reference_sample = c7dd999a033fa3edc1936785b87cd69ce2f5cac5a084ddfaf527a1094e718bc4, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 3c9ffd7537e30a21eefa6c174f801264b92a85a1bc73e34e6dc9e29f84658348, id = 122ff2e6-56e6-4aa8-a3ec-c19d31eb1f80, last_modified = 2021-09-16
      Source: 6249.1.0000000008048000.0000000008059000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_fa48b592 reference_sample = c9e33befeec133720b3ba40bb3cd7f636aad80f72f324c5fe65ac7af271c49ee, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 8838d2752b310dbf7d12f6cf023244aaff4fdf5b55cf1e3b71843210df0fcf88, id = fa48b592-8d80-45af-a3e4-232695b8f5dd, last_modified = 2021-09-16
      Source: 6249.1.0000000008048000.0000000008059000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444, id = 8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9, last_modified = 2022-01-26
      Source: classification engineClassification label: mal68.troj.linELF@0/0@0/0
      Source: /usr/bin/dash (PID: 6224)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.kQ6IpcnAj6 /tmp/tmp.o46WndApTP /tmp/tmp.AFUl6K9FlpJump to behavior
      Source: /usr/bin/dash (PID: 6225)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.kQ6IpcnAj6 /tmp/tmp.o46WndApTP /tmp/tmp.AFUl6K9FlpJump to behavior

      Stealing of Sensitive Information

      barindex
      Source: Yara matchFile source: x86.elf, type: SAMPLE
      Source: Yara matchFile source: 6251.1.0000000008048000.0000000008059000.r-x.sdmp, type: MEMORY
      Source: Yara matchFile source: 6250.1.0000000008048000.0000000008059000.r-x.sdmp, type: MEMORY
      Source: Yara matchFile source: 6249.1.0000000008048000.0000000008059000.r-x.sdmp, type: MEMORY
      Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/65.0.3325.181 Safari/537.36
      Source: Initial sampleUser agent string found: Opera/9.80 (X11; Linux i686; Ubuntu/14.10) Presto/2.12.388 Version/12.16
      Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows; U; Windows NT 6.1; rv:2.2) Gecko/20110201
      Source: Initial sampleUser agent string found: Opera/9.80 (Windows NT 5.2; U; ru) Presto/2.5.22 Version/10.51
      Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36
      Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; AS; rv:11.0) like Gecko
      Source: Initial sampleUser agent string found: Mozilla/5.0 (Android; Linux armv7l; rv:9.0) Gecko/20111216 Firefox/9.0 Fennec/9.0
      Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 5.1) AppleWebKit/536.5 (KHTML, like Gecko) Chrome/19.0.1084.56 Safari/536.5
      Source: Initial sampleUser agent string found: Opera/9.80 (Windows NT 5.1; U; en) Presto/2.10.229 Version/11.60
      Source: Initial sampleUser agent string found: Mozilla/5.0 (iPad; U; CPU OS 5_1 like Mac OS X) AppleWebKit/531.21.10 (KHTML, like Gecko) Version/4.0.4 Mobile/7B367 Safari/531.21.10 UCBrowser/3.4.3.532
      Source: Initial sampleUser agent string found: Mozilla/5.0 (Nintendo WiiU) AppleWebKit/536.30 (KHTML, like Gecko) NX/3.0.4.2.12 NintendoBrowser/4.3.1.11264.US
      Source: Initial sampleUser agent string found: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.6; rv:25.0) Gecko/20100101 Firefox/25.0
      Source: Initial sampleUser agent string found: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; pl) Opera 11.00
      Source: Initial sampleUser agent string found: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; en) Opera 11.00
      Source: Initial sampleUser agent string found: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; ja) Opera 11.00
      Source: Initial sampleUser agent string found: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; cn) Opera 11.00
      Source: Initial sampleUser agent string found: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; fr) Opera 11.00
      Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/50.0.2661.102 Safari/537.36
      Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:12.0) Gecko/20100101 Firefox/12.0
      Source: Initial sampleUser agent string found: Mozilla/5.0 (X11; U; Linux x86_64; de; rv:1.9.2.8) Gecko/20100723 Ubuntu/10.04 (lucid) Firefox/3.6.8
      Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 5.1; rv:13.0) Gecko/20100101 Firefox/13.0.1
      Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:11.0) Gecko/20100101 Firefox/11.0
      Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:13.0) Gecko/20100101 Firefox/13.0.1
      Source: Initial sampleUser agent string found: Opera/9.80 (Windows NT 5.1; U; en) Presto/2.10.289 Version/12.01
      Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 5.1; rv:5.0.1) Gecko/20100101 Firefox/5.0.1
      Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 6.1; rv:5.0) Gecko/20100101 Firefox/5.02
      Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 6.0) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
      Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/53.0.2785.116 Safari/537.36
      Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/53.0.2785.116 Safari/537.36
      Source: Initial sampleUser agent string found: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/53.0.2785.116 Safari/537.36
      Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/53.0.2785.116 Safari/537.36
      Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/53.0.2785.143 Safari/537.36

      Remote Access Functionality

      barindex
      Source: Yara matchFile source: x86.elf, type: SAMPLE
      Source: Yara matchFile source: 6251.1.0000000008048000.0000000008059000.r-x.sdmp, type: MEMORY
      Source: Yara matchFile source: 6250.1.0000000008048000.0000000008059000.r-x.sdmp, type: MEMORY
      Source: Yara matchFile source: 6249.1.0000000008048000.0000000008059000.r-x.sdmp, type: MEMORY
      ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
      Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
      File Deletion
      OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
      Data Obfuscation
      Exfiltration Over Other Network MediumAbuse Accessibility Features
      CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
      Encrypted Channel
      Exfiltration Over BluetoothNetwork Denial of Service
      Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
      Non-Standard Port
      Automated ExfiltrationData Encrypted for Impact
      Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
      Application Layer Protocol
      Traffic DuplicationData Destruction
      No configs have been found
      Hide Legend

      Legend:

      • Process
      • Signature
      • Created File
      • DNS/IP Info
      • Is Dropped
      • Number of created Files
      • Is malicious
      • Internet
      behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1576201 Sample: x86.elf Startdate: 16/12/2024 Architecture: LINUX Score: 68 19 85.239.34.134, 40262, 40266, 40268 RAINBOW-HKRainbownetworklimitedHK Russian Federation 2->19 21 109.202.202.202, 80 INIT7CH Switzerland 2->21 23 3 other IPs or domains 2->23 25 Malicious sample detected (through community Yara rule) 2->25 27 Multi AV Scanner detection for submitted file 2->27 29 Yara detected Mirai 2->29 31 Machine Learning detection for sample 2->31 9 dash rm x86.elf 2->9         started        11 dash rm 2->11         started        signatures3 process4 process5 13 x86.elf 9->13         started        process6 15 x86.elf 13->15         started        process7 17 x86.elf 15->17         started       
      SourceDetectionScannerLabelLink
      x86.elf47%ReversingLabsLinux.Trojan.LnxMirai
      x86.elf100%Joe Sandbox ML
      No Antivirus matches
      No Antivirus matches
      No Antivirus matches
      No contacted domains info
      NameSourceMaliciousAntivirus DetectionReputation
      http://www.baidu.com/search/spider.html)x86.elffalse
        high
        http://www.billybobbot.com/crawler/)x86.elffalse
          high
          http://fast.no/support/crawler.asp)x86.elffalse
            high
            http://feedback.redkolibri.com/x86.elffalse
              high
              http://www.baidu.com/search/spider.htm)x86.elffalse
                high
                • No. of IPs < 25%
                • 25% < No. of IPs < 50%
                • 50% < No. of IPs < 75%
                • 75% < No. of IPs
                IPDomainCountryFlagASNASN NameMalicious
                54.171.230.55
                unknownUnited States
                16509AMAZON-02USfalse
                85.239.34.134
                unknownRussian Federation
                134121RAINBOW-HKRainbownetworklimitedHKfalse
                109.202.202.202
                unknownSwitzerland
                13030INIT7CHfalse
                91.189.91.43
                unknownUnited Kingdom
                41231CANONICAL-ASGBfalse
                91.189.91.42
                unknownUnited Kingdom
                41231CANONICAL-ASGBfalse
                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                54.171.230.55zmap.m68k.elfGet hashmaliciousMirai, OkiruBrowse
                  zmap.arm5.elfGet hashmaliciousOkiruBrowse
                    main_sh4.elfGet hashmaliciousMiraiBrowse
                      main_mips.elfGet hashmaliciousMiraiBrowse
                        main_arm5.elfGet hashmaliciousMiraiBrowse
                          main_sh4.elfGet hashmaliciousMiraiBrowse
                            la.bot.mips.elfGet hashmaliciousMiraiBrowse
                              mipsel.elfGet hashmaliciousMiraiBrowse
                                .i.elfGet hashmaliciousUnknownBrowse
                                  la.bot.arc.elfGet hashmaliciousMiraiBrowse
                                    85.239.34.134mpsl.elfGet hashmaliciousMiraiBrowse
                                      arm5.elfGet hashmaliciousMiraiBrowse
                                        arm5.elfGet hashmaliciousMiraiBrowse
                                          m68k.elfGet hashmaliciousUnknownBrowse
                                            x86.elfGet hashmaliciousUnknownBrowse
                                              arm.elfGet hashmaliciousUnknownBrowse
                                                mpsl.elfGet hashmaliciousUnknownBrowse
                                                  spc.elfGet hashmaliciousUnknownBrowse
                                                    m68k.elfGet hashmaliciousUnknownBrowse
                                                      mips.elfGet hashmaliciousUnknownBrowse
                                                        109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
                                                        • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
                                                        91.189.91.43mpsl.elfGet hashmaliciousMiraiBrowse
                                                          arm5.elfGet hashmaliciousMiraiBrowse
                                                            arm5.elfGet hashmaliciousMiraiBrowse
                                                              zmap.arm7.elfGet hashmaliciousMirai, OkiruBrowse
                                                                skid.mips.elfGet hashmaliciousUnknownBrowse
                                                                  arm.elfGet hashmaliciousUnknownBrowse
                                                                    zmap.m68k.elfGet hashmaliciousMirai, OkiruBrowse
                                                                      zmap.arm5.elfGet hashmaliciousOkiruBrowse
                                                                        zmap.spc.elfGet hashmaliciousMirai, OkiruBrowse
                                                                          main_m68k.elfGet hashmaliciousMiraiBrowse
                                                                            No context
                                                                            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                            RAINBOW-HKRainbownetworklimitedHKmpsl.elfGet hashmaliciousMiraiBrowse
                                                                            • 85.239.34.134
                                                                            arm5.elfGet hashmaliciousMiraiBrowse
                                                                            • 85.239.34.134
                                                                            arm5.elfGet hashmaliciousMiraiBrowse
                                                                            • 85.239.34.134
                                                                            m68k.elfGet hashmaliciousUnknownBrowse
                                                                            • 85.239.34.134
                                                                            x86.elfGet hashmaliciousUnknownBrowse
                                                                            • 85.239.34.134
                                                                            arm.elfGet hashmaliciousUnknownBrowse
                                                                            • 85.239.34.134
                                                                            mpsl.elfGet hashmaliciousUnknownBrowse
                                                                            • 85.239.34.134
                                                                            spc.elfGet hashmaliciousUnknownBrowse
                                                                            • 85.239.34.134
                                                                            m68k.elfGet hashmaliciousUnknownBrowse
                                                                            • 85.239.34.134
                                                                            mips.elfGet hashmaliciousUnknownBrowse
                                                                            • 85.239.34.134
                                                                            AMAZON-02USKjECqzXLWp.lnkGet hashmaliciousRHADAMANTHYSBrowse
                                                                            • 3.6.122.107
                                                                            cey4VIyGKh.lnkGet hashmaliciousRHADAMANTHYSBrowse
                                                                            • 3.6.30.85
                                                                            GdGXG0bnxH.exeGet hashmaliciousUnknownBrowse
                                                                            • 185.166.143.50
                                                                            https://clickme.thryv.com/ls/click?upn=u001.5dsdCa4YiGVzoib36gWoSL813n1NSUgoHlh-2FH8jVXE55TTo10JYMDP3MpP9biJ-2BivxRElKJfGcSf3Wm0bk6-2BuL6x9TaALAI-2BL1qw1Dee2Qg-3DwH82_lUpiXeYCZ5wahax4fkypnG65rENS0eHcuXkODr9BV8nkC0Nc6-2BAihSf0cmYNntTLO4SyowozBXe6Qe-2Bbp-2FFF3a1FIQOXuBqEKUpfXMQ5PPxSuhMxN-2FGKw6aVp7-2FrJaFsaK3MxWcXiB-2FQGWayulE8-2FtCvMhmv4KaADpZ-2B0qQmLVPxqh24uJt9FaNBQBIm1l70gJHtveQ3b-2FplaZ4NS9-2FFv9-2FcAZ4BnOdGLbd-2BNZzE9Ba47yxwqIyGzlJ-2BmDN57eM41CachqUTFf5upDlE1JEwIy6eZ7t9nvf-2Fc9lQV8qupSe0IpWj5cFkfBjNJ9myaj1i3KCzGOXUSk-2F4E-2FHX-2BkuwdmqzU7u2OKMrHZeEXOJLiSw-3D#CGet hashmaliciousUnknownBrowse
                                                                            • 108.158.75.84
                                                                            https://simatantincendi.weebly.com/Get hashmaliciousHTMLPhisherBrowse
                                                                            • 44.235.253.37
                                                                            zmap.m68k.elfGet hashmaliciousMirai, OkiruBrowse
                                                                            • 54.171.230.55
                                                                            zmap.arm5.elfGet hashmaliciousOkiruBrowse
                                                                            • 54.171.230.55
                                                                            REQUEST FOR QUOTATION 1307-RFQ.exeGet hashmaliciousMassLogger RATBrowse
                                                                            • 18.141.10.107
                                                                            https://eu.onamoc.comano.us/XaFJNdmNsY0JUVzZrd09aZnpEZk9LNXJHSFV1RTlrbFdPMXQ5dzRKTHV4dEdpUEhTM1I1MCszdjdWWm54V01kSEhOSlpOSFpjMUlsaFNTc0l3eXhVeWl3TGVjWm14bGMxUFkzWWFkVUQvbUlNMGEza0pnOFFCK3N4TDBlc3RyYWJkSE9xVU9ETG5TU1lHQkZwdStVdXhGMzdoQzltdFAwRnc0WTJuMmF3Q1VkTzdMb0lwNXhqOFQ3eGRtK0ZuQUpydjMxSWdnPT0tLUFPWFdqaFhtRnVKaEhNK20tLUlJNFZwQjNETFQyTk1iL0UxMUxBTGc9PQ==?cid=300477933Get hashmaliciousKnowBe4Browse
                                                                            • 13.227.8.37
                                                                            https://login.corp-internal.org/17058d3d8656ed69?l=27Get hashmaliciousUnknownBrowse
                                                                            • 52.216.58.145
                                                                            INIT7CHmpsl.elfGet hashmaliciousMiraiBrowse
                                                                            • 109.202.202.202
                                                                            arm5.elfGet hashmaliciousMiraiBrowse
                                                                            • 109.202.202.202
                                                                            arm5.elfGet hashmaliciousMiraiBrowse
                                                                            • 109.202.202.202
                                                                            zmap.arm7.elfGet hashmaliciousMirai, OkiruBrowse
                                                                            • 109.202.202.202
                                                                            skid.mips.elfGet hashmaliciousUnknownBrowse
                                                                            • 109.202.202.202
                                                                            arm.elfGet hashmaliciousUnknownBrowse
                                                                            • 109.202.202.202
                                                                            zmap.m68k.elfGet hashmaliciousMirai, OkiruBrowse
                                                                            • 109.202.202.202
                                                                            zmap.arm5.elfGet hashmaliciousOkiruBrowse
                                                                            • 109.202.202.202
                                                                            zmap.spc.elfGet hashmaliciousMirai, OkiruBrowse
                                                                            • 109.202.202.202
                                                                            main_m68k.elfGet hashmaliciousMiraiBrowse
                                                                            • 109.202.202.202
                                                                            No context
                                                                            No context
                                                                            No created / dropped files found
                                                                            File type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, stripped
                                                                            Entropy (8bit):6.687948783383679
                                                                            TrID:
                                                                            • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
                                                                            • ELF Executable and Linkable format (generic) (4004/1) 49.84%
                                                                            File name:x86.elf
                                                                            File size:68'452 bytes
                                                                            MD5:3e7577a2fa2cca1c44fd60bc3d67b64a
                                                                            SHA1:ea0d89cb9b5d0c7b80512732109bbddb092e04b3
                                                                            SHA256:975e5edf880671ad6b0e9c46f6125313b74c79a01af2596ff462fe44aec15cf4
                                                                            SHA512:2b4682c22b7993faacb5a50edf5e998532427e68657ffb656a665febe776b94f5376daac5e45b506df3b41e844894d8787c192e60fc9d1975bb255051ea8c367
                                                                            SSDEEP:1536:whkcvHWfVSOjBvKWJZWwNkZVCFGVcSCi/SJIDcNeqpzI5h5knx:wBOdvHRNkrGYDcNe2I5h5mx
                                                                            TLSH:E463AECFE6C3D5B5D95201722162BF37D732DA2740A99243E3D42D25DC22632EB0BAC9
                                                                            File Content Preview:.ELF........................4...4.......4. ...(.........................................................|z..............|...|...|...................Q.td............................U..S............h........[]...$.............U......=.....t..5..............

                                                                            ELF header

                                                                            Class:ELF32
                                                                            Data:2's complement, little endian
                                                                            Version:1 (current)
                                                                            Machine:Intel 80386
                                                                            Version Number:0x1
                                                                            Type:EXEC (Executable file)
                                                                            OS/ABI:UNIX - System V
                                                                            ABI Version:0
                                                                            Entry Point Address:0x8048184
                                                                            Flags:0x0
                                                                            ELF Header Size:52
                                                                            Program Header Offset:52
                                                                            Program Header Size:32
                                                                            Number of Program Headers:4
                                                                            Section Header Offset:67892
                                                                            Section Header Size:40
                                                                            Number of Section Headers:14
                                                                            Header String Table Index:13
                                                                            NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                                            NULL0x00x00x00x00x0000
                                                                            .initPROGBITS0x80480b40xb40x1c0x00x6AX001
                                                                            .textPROGBITS0x80480d00xd00xccb70x00x6AX0016
                                                                            .finiPROGBITS0x8054d870xcd870x170x00x6AX001
                                                                            .rodataPROGBITS0x8054da00xcda00x33300x00x2A0032
                                                                            .eh_framePROGBITS0x80590d00x100d00x5ac0x00x3WA004
                                                                            .tbssNOBITS0x805967c0x1067c0x80x00x403WAT004
                                                                            .ctorsPROGBITS0x805967c0x1067c0x80x00x3WA004
                                                                            .dtorsPROGBITS0x80596840x106840x80x00x3WA004
                                                                            .jcrPROGBITS0x805968c0x1068c0x40x00x3WA004
                                                                            .got.pltPROGBITS0x80596900x106900xc0x40x3WA004
                                                                            .dataPROGBITS0x805969c0x1069c0x23c0x00x3WA004
                                                                            .bssNOBITS0x80598e00x108d80x726c0x00x3WA0032
                                                                            .shstrtabSTRTAB0x00x108d80x5c0x00x0001
                                                                            TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                                            LOAD0x00x80480000x80480000x100d00x100d06.72980x5R E0x1000.init .text .fini .rodata
                                                                            LOAD0x100d00x80590d00x80590d00x8080x7a7c4.69000x6RW 0x1000.eh_frame .tbss .ctors .dtors .jcr .got.plt .data .bss
                                                                            TLS0x1067c0x805967c0x805967c0x00x80.00000x4R 0x4.tbss
                                                                            GNU_STACK0x00x00x00x00x00.00000x6RW 0x4
                                                                            TimestampSource PortDest PortSource IPDest IP
                                                                            Dec 16, 2024 16:28:49.632133007 CET4433360654.171.230.55192.168.2.23
                                                                            Dec 16, 2024 16:28:49.632647038 CET33606443192.168.2.2354.171.230.55
                                                                            Dec 16, 2024 16:28:49.752603054 CET4433360654.171.230.55192.168.2.23
                                                                            Dec 16, 2024 16:28:51.887558937 CET43928443192.168.2.2391.189.91.42
                                                                            Dec 16, 2024 16:28:51.988992929 CET402626666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:28:52.115067005 CET66664026285.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:28:52.115164995 CET402626666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:28:52.115303040 CET402626666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:28:52.235161066 CET66664026285.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:28:53.290080070 CET66664026285.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:28:53.290180922 CET402626666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:28:53.290330887 CET66664026285.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:28:53.290404081 CET402626666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:28:53.417084932 CET66664026285.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:28:57.262862921 CET42836443192.168.2.2391.189.91.43
                                                                            Dec 16, 2024 16:28:58.542680979 CET4251680192.168.2.23109.202.202.202
                                                                            Dec 16, 2024 16:29:02.293190002 CET402666666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:29:02.414972067 CET66664026685.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:29:02.415261984 CET402666666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:29:02.415349960 CET402666666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:29:02.537616014 CET66664026685.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:29:03.559693098 CET66664026685.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:29:03.559845924 CET66664026685.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:29:03.559880018 CET402666666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:29:03.559926987 CET402666666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:29:03.680301905 CET66664026685.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:29:12.563847065 CET402686666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:29:12.683723927 CET66664026885.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:29:12.683856964 CET402686666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:29:12.683923960 CET402686666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:29:12.804362059 CET66664026885.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:29:12.876807928 CET43928443192.168.2.2391.189.91.42
                                                                            Dec 16, 2024 16:29:13.839173079 CET66664026885.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:29:13.839360952 CET402686666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:29:13.839397907 CET66664026885.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:29:13.839504004 CET402686666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:29:13.959446907 CET66664026885.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:29:22.843421936 CET402706666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:29:22.963860989 CET66664027085.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:29:22.964060068 CET402706666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:29:22.964137077 CET402706666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:29:23.084202051 CET66664027085.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:29:23.115453959 CET42836443192.168.2.2391.189.91.43
                                                                            Dec 16, 2024 16:29:24.104110956 CET66664027085.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:29:24.104254961 CET66664027085.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:29:24.104284048 CET402706666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:29:24.104346037 CET402706666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:29:24.224548101 CET66664027085.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:29:29.258558035 CET4251680192.168.2.23109.202.202.202
                                                                            Dec 16, 2024 16:29:33.108005047 CET402726666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:29:33.228034019 CET66664027285.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:29:33.228257895 CET402726666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:29:33.228257895 CET402726666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:29:33.349446058 CET66664027285.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:29:34.373917103 CET66664027285.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:29:34.374001980 CET66664027285.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:29:34.374166012 CET402726666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:29:34.374258041 CET402726666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:29:34.494143963 CET66664027285.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:29:43.379188061 CET402746666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:29:43.499408007 CET66664027485.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:29:43.499574900 CET402746666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:29:43.499619961 CET402746666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:29:43.619565010 CET66664027485.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:29:44.664551973 CET66664027485.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:29:44.664628029 CET66664027485.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:29:44.664729118 CET402746666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:29:44.664761066 CET402746666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:29:44.784682035 CET66664027485.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:29:53.670257092 CET402766666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:29:53.790672064 CET66664027685.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:29:53.790873051 CET402766666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:29:53.790941000 CET402766666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:29:53.831106901 CET43928443192.168.2.2391.189.91.42
                                                                            Dec 16, 2024 16:29:53.911370993 CET66664027685.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:29:54.958811998 CET66664027685.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:29:54.958884954 CET66664027685.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:29:54.959028006 CET402766666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:29:54.959126949 CET402766666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:29:55.079257011 CET66664027685.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:30:03.963264942 CET402786666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:30:04.083300114 CET66664027885.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:30:04.083544016 CET402786666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:30:04.083595991 CET402786666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:30:04.203615904 CET66664027885.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:30:05.283525944 CET66664027885.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:30:05.283582926 CET66664027885.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:30:05.283710957 CET402786666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:30:05.283797979 CET402786666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:30:05.404042006 CET66664027885.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:30:14.290209055 CET402806666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:30:14.308192968 CET42836443192.168.2.2391.189.91.43
                                                                            Dec 16, 2024 16:30:14.410665035 CET66664028085.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:30:14.410880089 CET402806666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:30:14.410965919 CET402806666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:30:14.531405926 CET66664028085.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:30:15.588788986 CET66664028085.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:30:15.588843107 CET66664028085.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:30:15.589039087 CET402806666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:30:15.589131117 CET402806666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:30:15.710588932 CET66664028085.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:30:24.594589949 CET402826666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:30:24.714662075 CET66664028285.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:30:24.714879990 CET402826666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:30:24.714915991 CET402826666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:30:24.834784031 CET66664028285.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:30:25.902148008 CET66664028285.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:30:25.902261972 CET66664028285.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:30:25.902543068 CET402826666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:30:25.902652025 CET402826666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:30:26.023422003 CET66664028285.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:30:34.908035040 CET402846666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:30:35.028639078 CET66664028485.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:30:35.028795958 CET402846666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:30:35.937298059 CET402846666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:30:36.057805061 CET66664028485.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:30:36.058002949 CET402846666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:30:36.058046103 CET402846666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:30:36.178350925 CET66664028485.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:30:37.259922028 CET66664028485.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:30:37.259974957 CET66664028485.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:30:37.260189056 CET402846666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:30:37.260284901 CET402846666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:30:37.380276918 CET66664028485.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:30:46.264403105 CET402866666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:30:46.387568951 CET66664028685.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:30:46.387836933 CET402866666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:30:46.387950897 CET402866666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:30:46.507750988 CET66664028685.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:30:47.537755966 CET66664028685.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:30:47.537781954 CET66664028685.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:30:47.538002014 CET402866666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:30:47.538116932 CET402866666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:30:47.661658049 CET66664028685.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:30:56.542819023 CET402886666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:30:56.664367914 CET66664028885.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:30:56.664619923 CET402886666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:30:56.664710045 CET402886666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:30:56.784847975 CET66664028885.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:30:57.837428093 CET66664028885.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:30:57.837464094 CET66664028885.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:30:57.837578058 CET402886666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:30:57.837719917 CET402886666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:30:57.957570076 CET66664028885.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:31:06.841741085 CET402906666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:31:06.962218046 CET66664029085.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:31:06.962507010 CET402906666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:31:06.962507010 CET402906666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:31:07.082617998 CET66664029085.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:31:08.137588978 CET66664029085.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:31:08.137617111 CET66664029085.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:31:08.137876987 CET402906666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:31:08.138041973 CET402906666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:31:08.257905960 CET66664029085.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:31:17.143137932 CET402926666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:31:17.263215065 CET66664029285.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:31:17.263418913 CET402926666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:31:17.263484955 CET402926666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:31:17.384893894 CET66664029285.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:31:18.421607971 CET66664029285.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:31:18.421808004 CET402926666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:31:18.422979116 CET66664029285.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:31:18.423067093 CET402926666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:31:18.543018103 CET66664029285.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:31:27.427086115 CET402946666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:31:27.547271013 CET66664029485.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:31:27.547477007 CET402946666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:31:27.547477007 CET402946666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:31:27.667352915 CET66664029485.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:31:28.693425894 CET66664029485.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:31:28.693506002 CET66664029485.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:31:28.693614960 CET402946666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:31:28.693754911 CET402946666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:31:28.813766956 CET66664029485.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:31:37.697258949 CET402966666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:31:37.819211006 CET66664029685.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:31:37.819303036 CET402966666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:31:37.819417953 CET402966666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:31:37.943038940 CET66664029685.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:31:38.964862108 CET66664029685.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:31:38.965095997 CET402966666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:31:38.965440035 CET66664029685.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:31:38.965504885 CET402966666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:31:39.085294962 CET66664029685.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:31:47.969805002 CET402986666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:31:48.089692116 CET66664029885.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:31:48.090018988 CET402986666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:31:48.090116024 CET402986666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:31:48.209892035 CET66664029885.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:31:49.237128019 CET66664029885.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:31:49.237267971 CET402986666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:31:49.237472057 CET66664029885.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:31:49.237586021 CET402986666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:31:49.357393026 CET66664029885.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:31:58.241101980 CET403006666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:31:58.361037970 CET66664030085.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:31:58.361207008 CET403006666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:31:58.361227036 CET403006666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:31:58.482258081 CET66664030085.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:31:59.507770061 CET66664030085.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:31:59.507993937 CET403006666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:31:59.508080959 CET66664030085.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:31:59.508147001 CET403006666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:31:59.628020048 CET66664030085.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:32:08.512377977 CET403026666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:32:08.632361889 CET66664030285.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:32:08.632646084 CET403026666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:32:08.632839918 CET403026666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:32:08.752778053 CET66664030285.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:32:09.782682896 CET66664030285.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:32:09.782749891 CET66664030285.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:32:09.782969952 CET403026666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:32:09.783056974 CET403026666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:32:09.903275013 CET66664030285.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:32:18.788001060 CET403046666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:32:18.908109903 CET66664030485.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:32:18.908521891 CET403046666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:32:18.908618927 CET403046666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:32:19.028413057 CET66664030485.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:32:20.066682100 CET66664030485.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:32:20.066759109 CET66664030485.239.34.134192.168.2.23
                                                                            Dec 16, 2024 16:32:20.066951990 CET403046666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:32:20.066951990 CET403046666192.168.2.2385.239.34.134
                                                                            Dec 16, 2024 16:32:20.188851118 CET66664030485.239.34.134192.168.2.23

                                                                            System Behavior

                                                                            Start time (UTC):15:28:48
                                                                            Start date (UTC):16/12/2024
                                                                            Path:/usr/bin/dash
                                                                            Arguments:-
                                                                            File size:129816 bytes
                                                                            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                            Start time (UTC):15:28:48
                                                                            Start date (UTC):16/12/2024
                                                                            Path:/usr/bin/rm
                                                                            Arguments:rm -f /tmp/tmp.kQ6IpcnAj6 /tmp/tmp.o46WndApTP /tmp/tmp.AFUl6K9Flp
                                                                            File size:72056 bytes
                                                                            MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                                                            Start time (UTC):15:28:48
                                                                            Start date (UTC):16/12/2024
                                                                            Path:/usr/bin/dash
                                                                            Arguments:-
                                                                            File size:129816 bytes
                                                                            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                            Start time (UTC):15:28:48
                                                                            Start date (UTC):16/12/2024
                                                                            Path:/usr/bin/rm
                                                                            Arguments:rm -f /tmp/tmp.kQ6IpcnAj6 /tmp/tmp.o46WndApTP /tmp/tmp.AFUl6K9Flp
                                                                            File size:72056 bytes
                                                                            MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                                                            Start time (UTC):15:28:51
                                                                            Start date (UTC):16/12/2024
                                                                            Path:/tmp/x86.elf
                                                                            Arguments:/tmp/x86.elf
                                                                            File size:68452 bytes
                                                                            MD5 hash:3e7577a2fa2cca1c44fd60bc3d67b64a

                                                                            Start time (UTC):15:28:51
                                                                            Start date (UTC):16/12/2024
                                                                            Path:/tmp/x86.elf
                                                                            Arguments:-
                                                                            File size:68452 bytes
                                                                            MD5 hash:3e7577a2fa2cca1c44fd60bc3d67b64a

                                                                            Start time (UTC):15:28:51
                                                                            Start date (UTC):16/12/2024
                                                                            Path:/tmp/x86.elf
                                                                            Arguments:-
                                                                            File size:68452 bytes
                                                                            MD5 hash:3e7577a2fa2cca1c44fd60bc3d67b64a

                                                                            Start time (UTC):15:28:51
                                                                            Start date (UTC):16/12/2024
                                                                            Path:/tmp/x86.elf
                                                                            Arguments:-
                                                                            File size:68452 bytes
                                                                            MD5 hash:3e7577a2fa2cca1c44fd60bc3d67b64a