Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
Space.m68k.elf

Overview

General Information

Sample name:Space.m68k.elf
Analysis ID:1581300
MD5:e9d24809ad9478e63a37c116ab4e15d4
SHA1:c584f99e94efefea0cf4342632c2014a12d0d47d
SHA256:2d0a0193b43ea9eadec11d3a16744ffefa7e8c8baae0f24b72ed761f3e20e1bb
Tags:elfuser-abuse_ch
Infos:

Detection

Mirai
Score:72
Range:0 - 100
Whitelisted:false

Signatures

Antivirus / Scanner detection for submitted sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Yara detected Mirai
Detected TCP or UDP traffic on non-standard ports
Enumerates processes within the "proc" file system
Executes the "rm" command used to delete files or directories
Sample contains strings indicative of BusyBox which embeds multiple Unix commands in a single executable
Sample has stripped symbol table
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)
Yara signature match

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1581300
Start date and time:2024-12-27 10:37:35 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 41s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:Space.m68k.elf
Detection:MAL
Classification:mal72.troj.linELF@0/0@0/0
Command:/tmp/Space.m68k.elf
PID:6250
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
lzrd cock fest"/proc/"/exe
Standard Error:
  • system is lnxubuntu20
  • dash New Fork (PID: 6218, Parent: 4332)
  • rm (PID: 6218, Parent: 4332, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.U4kQztPbIV /tmp/tmp.eaYwXZIXVn /tmp/tmp.Uvg70fFH73
  • dash New Fork (PID: 6219, Parent: 4332)
  • cat (PID: 6219, Parent: 4332, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /tmp/tmp.U4kQztPbIV
  • dash New Fork (PID: 6220, Parent: 4332)
  • head (PID: 6220, Parent: 4332, MD5: fd96a67145172477dd57131396fc9608) Arguments: head -n 10
  • dash New Fork (PID: 6221, Parent: 4332)
  • tr (PID: 6221, Parent: 4332, MD5: fbd1402dd9f72d8ebfff00ce7c3a7bb5) Arguments: tr -d \\000-\\011\\013\\014\\016-\\037
  • dash New Fork (PID: 6222, Parent: 4332)
  • cut (PID: 6222, Parent: 4332, MD5: d8ed0ea8f22c0de0f8692d4d9f1759d3) Arguments: cut -c -80
  • dash New Fork (PID: 6223, Parent: 4332)
  • cat (PID: 6223, Parent: 4332, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /tmp/tmp.U4kQztPbIV
  • dash New Fork (PID: 6224, Parent: 4332)
  • head (PID: 6224, Parent: 4332, MD5: fd96a67145172477dd57131396fc9608) Arguments: head -n 10
  • dash New Fork (PID: 6225, Parent: 4332)
  • tr (PID: 6225, Parent: 4332, MD5: fbd1402dd9f72d8ebfff00ce7c3a7bb5) Arguments: tr -d \\000-\\011\\013\\014\\016-\\037
  • dash New Fork (PID: 6226, Parent: 4332)
  • cut (PID: 6226, Parent: 4332, MD5: d8ed0ea8f22c0de0f8692d4d9f1759d3) Arguments: cut -c -80
  • dash New Fork (PID: 6227, Parent: 4332)
  • rm (PID: 6227, Parent: 4332, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.U4kQztPbIV /tmp/tmp.eaYwXZIXVn /tmp/tmp.Uvg70fFH73
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
MiraiMirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.mirai
SourceRuleDescriptionAuthorStrings
Space.m68k.elfJoeSecurity_Mirai_8Yara detected MiraiJoe Security
    Space.m68k.elfLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
    • 0x151af:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x151c3:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x151d7:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x151eb:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x151ff:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x15213:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x15227:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x1523b:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x1524f:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x15263:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x15277:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x1528b:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x1529f:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x152b3:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x152c7:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x152db:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x152ef:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x15303:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x15317:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x1532b:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x1533f:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    SourceRuleDescriptionAuthorStrings
    6254.1.00007fb1ac001000.00007fb1ac019000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
      6254.1.00007fb1ac001000.00007fb1ac019000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
      • 0x151af:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x151c3:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x151d7:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x151eb:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x151ff:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x15213:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x15227:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1523b:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1524f:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x15263:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x15277:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1528b:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1529f:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x152b3:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x152c7:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x152db:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x152ef:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x15303:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x15317:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1532b:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1533f:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      6262.1.00007fb1ac001000.00007fb1ac019000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
        6262.1.00007fb1ac001000.00007fb1ac019000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
        • 0x151af:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x151c3:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x151d7:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x151eb:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x151ff:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x15213:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x15227:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x1523b:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x1524f:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x15263:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x15277:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x1528b:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x1529f:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x152b3:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x152c7:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x152db:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x152ef:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x15303:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x15317:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x1532b:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x1533f:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        6250.1.00007fb1ac001000.00007fb1ac019000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
          Click to see the 11 entries
          No Suricata rule has matched

          Click to jump to signature section

          Show All Signature Results

          AV Detection

          barindex
          Source: Space.m68k.elfAvira: detected
          Source: Space.m68k.elfVirustotal: Detection: 61%Perma Link
          Source: Space.m68k.elfReversingLabs: Detection: 65%
          Source: global trafficTCP traffic: 192.168.2.23:53270 -> 159.100.18.129:3778
          Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
          Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
          Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
          Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
          Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
          Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
          Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
          Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
          Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
          Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
          Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
          Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
          Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
          Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
          Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
          Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
          Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
          Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
          Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
          Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
          Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
          Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
          Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
          Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
          Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
          Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
          Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
          Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
          Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
          Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
          Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
          Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
          Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
          Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
          Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
          Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
          Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
          Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
          Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
          Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
          Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
          Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
          Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
          Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
          Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
          Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
          Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
          Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
          Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
          Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
          Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
          Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
          Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
          Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443

          System Summary

          barindex
          Source: Space.m68k.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
          Source: 6254.1.00007fb1ac001000.00007fb1ac019000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
          Source: 6262.1.00007fb1ac001000.00007fb1ac019000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
          Source: 6250.1.00007fb1ac001000.00007fb1ac019000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
          Source: 6256.1.00007fb1ac001000.00007fb1ac019000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
          Source: Process Memory Space: Space.m68k.elf PID: 6250, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
          Source: Process Memory Space: Space.m68k.elf PID: 6254, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
          Source: Process Memory Space: Space.m68k.elf PID: 6256, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
          Source: Process Memory Space: Space.m68k.elf PID: 6262, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
          Source: Initial sampleString containing 'busybox' found: /bin/busybox
          Source: Initial sampleString containing 'busybox' found: /proc/net/tcp.x86.x86_64.arm.arm5.arm6.arm7.mips.mipsel.sh4.ppc/proc/proc/%d/exe/proc/%s/statusName:%s/bin/busybox/bin/systemd/usr/bintest/tmp/condi/tmp/zxcr9999/tmp/condinetwork/var/condibot/var/zxcr9999/var/CondiBot/var/condinet/bin/watchdog159.100.18.129
          Source: ELF static info symbol of initial sample.symtab present: no
          Source: Space.m68k.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
          Source: 6254.1.00007fb1ac001000.00007fb1ac019000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
          Source: 6262.1.00007fb1ac001000.00007fb1ac019000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
          Source: 6250.1.00007fb1ac001000.00007fb1ac019000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
          Source: 6256.1.00007fb1ac001000.00007fb1ac019000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
          Source: Process Memory Space: Space.m68k.elf PID: 6250, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
          Source: Process Memory Space: Space.m68k.elf PID: 6254, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
          Source: Process Memory Space: Space.m68k.elf PID: 6256, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
          Source: Process Memory Space: Space.m68k.elf PID: 6262, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
          Source: classification engineClassification label: mal72.troj.linELF@0/0@0/0
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/1582/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/3088/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/230/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/110/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/231/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/111/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/232/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/1579/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/112/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/233/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/1699/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/113/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/234/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/1335/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/1698/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/114/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/235/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/1334/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/1576/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/2302/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/115/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/236/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/116/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/237/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/117/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/118/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/910/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/119/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/912/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/10/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/2307/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/11/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/918/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/12/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/13/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/14/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/15/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/16/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/17/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/18/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/1594/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/120/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/121/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/1349/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/1/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/122/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/243/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/123/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/2/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/124/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/3/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/4/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/125/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/126/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/1344/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/1465/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/1586/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/127/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/6/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/248/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/128/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/249/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/1463/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/800/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/9/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/801/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/20/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/21/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/1900/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/22/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/23/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/24/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/25/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/26/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/27/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/28/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/29/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/6257/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/491/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/250/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/130/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/251/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/6250/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/252/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/132/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/253/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/254/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/255/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/256/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/1599/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/257/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/1477/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/379/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/258/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/1476/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/259/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/1475/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/936/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/30/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/2208/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/35/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/1809/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/1494/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/260/statusJump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)File opened: /proc/261/statusJump to behavior
          Source: /usr/bin/dash (PID: 6218)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.U4kQztPbIV /tmp/tmp.eaYwXZIXVn /tmp/tmp.Uvg70fFH73Jump to behavior
          Source: /usr/bin/dash (PID: 6227)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.U4kQztPbIV /tmp/tmp.eaYwXZIXVn /tmp/tmp.Uvg70fFH73Jump to behavior
          Source: /tmp/Space.m68k.elf (PID: 6250)Queries kernel information via 'uname': Jump to behavior
          Source: Space.m68k.elf, 6250.1.0000564b8c2f3000.0000564b8c37b000.rw-.sdmp, Space.m68k.elf, 6254.1.0000564b8c2f3000.0000564b8c357000.rw-.sdmp, Space.m68k.elf, 6256.1.0000564b8c2f3000.0000564b8c357000.rw-.sdmp, Space.m68k.elf, 6262.1.0000564b8c2f3000.0000564b8c37b000.rw-.sdmpBinary or memory string: KV!/etc/qemu-binfmt/m68k
          Source: Space.m68k.elf, 6250.1.00007ffc926e0000.00007ffc92701000.rw-.sdmp, Space.m68k.elf, 6254.1.00007ffc926e0000.00007ffc92701000.rw-.sdmp, Space.m68k.elf, 6256.1.00007ffc926e0000.00007ffc92701000.rw-.sdmp, Space.m68k.elf, 6262.1.00007ffc926e0000.00007ffc92701000.rw-.sdmpBinary or memory string: /usr/bin/qemu-m68k
          Source: Space.m68k.elf, 6250.1.0000564b8c2f3000.0000564b8c37b000.rw-.sdmp, Space.m68k.elf, 6254.1.0000564b8c2f3000.0000564b8c357000.rw-.sdmp, Space.m68k.elf, 6256.1.0000564b8c2f3000.0000564b8c357000.rw-.sdmp, Space.m68k.elf, 6262.1.0000564b8c2f3000.0000564b8c37b000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/m68k
          Source: Space.m68k.elf, 6250.1.00007ffc926e0000.00007ffc92701000.rw-.sdmp, Space.m68k.elf, 6254.1.00007ffc926e0000.00007ffc92701000.rw-.sdmp, Space.m68k.elf, 6256.1.00007ffc926e0000.00007ffc92701000.rw-.sdmp, Space.m68k.elf, 6262.1.00007ffc926e0000.00007ffc92701000.rw-.sdmpBinary or memory string: bx86_64/usr/bin/qemu-m68k/tmp/Space.m68k.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/Space.m68k.elf

          Stealing of Sensitive Information

          barindex
          Source: Yara matchFile source: Space.m68k.elf, type: SAMPLE
          Source: Yara matchFile source: 6254.1.00007fb1ac001000.00007fb1ac019000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: 6262.1.00007fb1ac001000.00007fb1ac019000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: 6250.1.00007fb1ac001000.00007fb1ac019000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: 6256.1.00007fb1ac001000.00007fb1ac019000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: Process Memory Space: Space.m68k.elf PID: 6250, type: MEMORYSTR
          Source: Yara matchFile source: Process Memory Space: Space.m68k.elf PID: 6254, type: MEMORYSTR
          Source: Yara matchFile source: Process Memory Space: Space.m68k.elf PID: 6256, type: MEMORYSTR
          Source: Yara matchFile source: Process Memory Space: Space.m68k.elf PID: 6262, type: MEMORYSTR

          Remote Access Functionality

          barindex
          Source: Yara matchFile source: Space.m68k.elf, type: SAMPLE
          Source: Yara matchFile source: 6254.1.00007fb1ac001000.00007fb1ac019000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: 6262.1.00007fb1ac001000.00007fb1ac019000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: 6250.1.00007fb1ac001000.00007fb1ac019000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: 6256.1.00007fb1ac001000.00007fb1ac019000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: Process Memory Space: Space.m68k.elf PID: 6250, type: MEMORYSTR
          Source: Yara matchFile source: Process Memory Space: Space.m68k.elf PID: 6254, type: MEMORYSTR
          Source: Yara matchFile source: Process Memory Space: Space.m68k.elf PID: 6256, type: MEMORYSTR
          Source: Yara matchFile source: Process Memory Space: Space.m68k.elf PID: 6262, type: MEMORYSTR
          ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
          Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
          File Deletion
          1
          OS Credential Dumping
          11
          Security Software Discovery
          Remote ServicesData from Local System1
          Encrypted Channel
          Exfiltration Over Other Network MediumAbuse Accessibility Features
          CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
          Non-Standard Port
          Exfiltration Over BluetoothNetwork Denial of Service
          Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
          Application Layer Protocol
          Automated ExfiltrationData Encrypted for Impact
          No configs have been found
          Hide Legend

          Legend:

          • Process
          • Signature
          • Created File
          • DNS/IP Info
          • Is Dropped
          • Number of created Files
          • Is malicious
          • Internet
          behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1581300 Sample: Space.m68k.elf Startdate: 27/12/2024 Architecture: LINUX Score: 72 26 109.202.202.202, 80 INIT7CH Switzerland 2->26 28 159.100.18.129, 3778, 53270, 53272 DE-FIRSTCOLOwwwfirst-colonetDE Germany 2->28 30 2 other IPs or domains 2->30 32 Malicious sample detected (through community Yara rule) 2->32 34 Antivirus / Scanner detection for submitted sample 2->34 36 Multi AV Scanner detection for submitted file 2->36 38 Yara detected Mirai 2->38 8 dash rm Space.m68k.elf 2->8         started        10 dash rm 2->10         started        12 dash head 2->12         started        14 7 other processes 2->14 signatures3 process4 process5 16 Space.m68k.elf 8->16         started        18 Space.m68k.elf 8->18         started        20 Space.m68k.elf 8->20         started        process6 22 Space.m68k.elf 16->22         started        24 Space.m68k.elf 16->24         started       
          SourceDetectionScannerLabelLink
          Space.m68k.elf62%VirustotalBrowse
          Space.m68k.elf66%ReversingLabsLinux.Backdoor.Mirai
          Space.m68k.elf100%AviraLINUX/Mirai.bonb
          No Antivirus matches
          No Antivirus matches
          No Antivirus matches
          No contacted domains info
          • No. of IPs < 25%
          • 25% < No. of IPs < 50%
          • 50% < No. of IPs < 75%
          • 75% < No. of IPs
          IPDomainCountryFlagASNASN NameMalicious
          159.100.18.129
          unknownGermany
          44066DE-FIRSTCOLOwwwfirst-colonetDEfalse
          109.202.202.202
          unknownSwitzerland
          13030INIT7CHfalse
          91.189.91.43
          unknownUnited Kingdom
          41231CANONICAL-ASGBfalse
          91.189.91.42
          unknownUnited Kingdom
          41231CANONICAL-ASGBfalse
          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
          159.100.18.129Space.x86.elfGet hashmaliciousUnknownBrowse
            Space.ppc.elfGet hashmaliciousUnknownBrowse
              Space.mips.elfGet hashmaliciousUnknownBrowse
                109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
                • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
                91.189.91.43Space.mips.elfGet hashmaliciousUnknownBrowse
                  sh4.nn.elfGet hashmaliciousOkiruBrowse
                    mipsel.nn.elfGet hashmaliciousOkiruBrowse
                      powerpc.nn.elfGet hashmaliciousOkiruBrowse
                        db0fa4b8db0333367e9bda3ab68b8042.mpsl.elfGet hashmaliciousUnknownBrowse
                          RpcSecurity.arm5.elfGet hashmaliciousUnknownBrowse
                            RpcSecurity.arc.elfGet hashmaliciousMiraiBrowse
                              RpcSecurity.sh4.elfGet hashmaliciousUnknownBrowse
                                db0fa4b8db0333367e9bda3ab68b8042.arm5.elfGet hashmaliciousUnknownBrowse
                                  db0fa4b8db0333367e9bda3ab68b8042.ppc.elfGet hashmaliciousUnknownBrowse
                                    91.189.91.42Space.mips.elfGet hashmaliciousUnknownBrowse
                                      sh4.nn.elfGet hashmaliciousOkiruBrowse
                                        mipsel.nn.elfGet hashmaliciousOkiruBrowse
                                          powerpc.nn.elfGet hashmaliciousOkiruBrowse
                                            db0fa4b8db0333367e9bda3ab68b8042.mpsl.elfGet hashmaliciousUnknownBrowse
                                              RpcSecurity.arm5.elfGet hashmaliciousUnknownBrowse
                                                RpcSecurity.arc.elfGet hashmaliciousMiraiBrowse
                                                  RpcSecurity.sh4.elfGet hashmaliciousUnknownBrowse
                                                    db0fa4b8db0333367e9bda3ab68b8042.arm5.elfGet hashmaliciousUnknownBrowse
                                                      db0fa4b8db0333367e9bda3ab68b8042.ppc.elfGet hashmaliciousUnknownBrowse
                                                        No context
                                                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                        CANONICAL-ASGBSpace.mips.elfGet hashmaliciousUnknownBrowse
                                                        • 91.189.91.42
                                                        arm6.nn.elfGet hashmaliciousOkiruBrowse
                                                        • 185.125.190.26
                                                        sh4.nn.elfGet hashmaliciousOkiruBrowse
                                                        • 91.189.91.42
                                                        mipsel.nn.elfGet hashmaliciousOkiruBrowse
                                                        • 91.189.91.42
                                                        powerpc.nn.elfGet hashmaliciousOkiruBrowse
                                                        • 91.189.91.42
                                                        db0fa4b8db0333367e9bda3ab68b8042.mpsl.elfGet hashmaliciousUnknownBrowse
                                                        • 91.189.91.42
                                                        RpcSecurity.arm5.elfGet hashmaliciousUnknownBrowse
                                                        • 91.189.91.42
                                                        RpcSecurity.arm7.elfGet hashmaliciousMiraiBrowse
                                                        • 185.125.190.26
                                                        RpcSecurity.ppc.elfGet hashmaliciousUnknownBrowse
                                                        • 185.125.190.26
                                                        RpcSecurity.arc.elfGet hashmaliciousMiraiBrowse
                                                        • 91.189.91.42
                                                        CANONICAL-ASGBSpace.mips.elfGet hashmaliciousUnknownBrowse
                                                        • 91.189.91.42
                                                        arm6.nn.elfGet hashmaliciousOkiruBrowse
                                                        • 185.125.190.26
                                                        sh4.nn.elfGet hashmaliciousOkiruBrowse
                                                        • 91.189.91.42
                                                        mipsel.nn.elfGet hashmaliciousOkiruBrowse
                                                        • 91.189.91.42
                                                        powerpc.nn.elfGet hashmaliciousOkiruBrowse
                                                        • 91.189.91.42
                                                        db0fa4b8db0333367e9bda3ab68b8042.mpsl.elfGet hashmaliciousUnknownBrowse
                                                        • 91.189.91.42
                                                        RpcSecurity.arm5.elfGet hashmaliciousUnknownBrowse
                                                        • 91.189.91.42
                                                        RpcSecurity.arm7.elfGet hashmaliciousMiraiBrowse
                                                        • 185.125.190.26
                                                        RpcSecurity.ppc.elfGet hashmaliciousUnknownBrowse
                                                        • 185.125.190.26
                                                        RpcSecurity.arc.elfGet hashmaliciousMiraiBrowse
                                                        • 91.189.91.42
                                                        INIT7CHSpace.mips.elfGet hashmaliciousUnknownBrowse
                                                        • 109.202.202.202
                                                        sh4.nn.elfGet hashmaliciousOkiruBrowse
                                                        • 109.202.202.202
                                                        mipsel.nn.elfGet hashmaliciousOkiruBrowse
                                                        • 109.202.202.202
                                                        powerpc.nn.elfGet hashmaliciousOkiruBrowse
                                                        • 109.202.202.202
                                                        db0fa4b8db0333367e9bda3ab68b8042.mpsl.elfGet hashmaliciousUnknownBrowse
                                                        • 109.202.202.202
                                                        RpcSecurity.arm5.elfGet hashmaliciousUnknownBrowse
                                                        • 109.202.202.202
                                                        RpcSecurity.arc.elfGet hashmaliciousMiraiBrowse
                                                        • 109.202.202.202
                                                        RpcSecurity.sh4.elfGet hashmaliciousUnknownBrowse
                                                        • 109.202.202.202
                                                        db0fa4b8db0333367e9bda3ab68b8042.arm5.elfGet hashmaliciousUnknownBrowse
                                                        • 109.202.202.202
                                                        db0fa4b8db0333367e9bda3ab68b8042.ppc.elfGet hashmaliciousUnknownBrowse
                                                        • 109.202.202.202
                                                        DE-FIRSTCOLOwwwfirst-colonetDESpace.x86.elfGet hashmaliciousUnknownBrowse
                                                        • 159.100.18.129
                                                        Space.ppc.elfGet hashmaliciousUnknownBrowse
                                                        • 159.100.18.129
                                                        Space.mips.elfGet hashmaliciousUnknownBrowse
                                                        • 159.100.18.129
                                                        boatnet.ppc.elfGet hashmaliciousMiraiBrowse
                                                        • 159.100.14.33
                                                        boatnet.mpsl.elfGet hashmaliciousMiraiBrowse
                                                        • 159.100.14.33
                                                        boatnet.sh4.elfGet hashmaliciousMiraiBrowse
                                                        • 159.100.14.33
                                                        boatnet.x86.elfGet hashmaliciousMiraiBrowse
                                                        • 159.100.14.33
                                                        boatnet.spc.elfGet hashmaliciousMiraiBrowse
                                                        • 159.100.14.33
                                                        boatnet.mips.elfGet hashmaliciousMiraiBrowse
                                                        • 159.100.14.33
                                                        159.100.14.33-boatnet.arm-2024-12-25T14_31_19.elfGet hashmaliciousMiraiBrowse
                                                        • 159.100.14.33
                                                        No context
                                                        No context
                                                        No created / dropped files found
                                                        File type:ELF 32-bit MSB executable, Motorola m68k, 68020, version 1 (SYSV), statically linked, stripped
                                                        Entropy (8bit):6.273520957499104
                                                        TrID:
                                                        • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                                        File name:Space.m68k.elf
                                                        File size:97'552 bytes
                                                        MD5:e9d24809ad9478e63a37c116ab4e15d4
                                                        SHA1:c584f99e94efefea0cf4342632c2014a12d0d47d
                                                        SHA256:2d0a0193b43ea9eadec11d3a16744ffefa7e8c8baae0f24b72ed761f3e20e1bb
                                                        SHA512:234ebae1745d5759a842c2d36275ca13580c0003ca576328cd2447d745b01732a450fa785e8ccebd596e4fc2e04a16ea26cdaac1551b6b46e1b7d8557642560e
                                                        SSDEEP:1536:BsSFA59vqiGWMD8JnwzV8/EqzabQeuacWjcW0JcWcBl473nipO4WlV/Nk31JFghR:WS6vqiZOJqGbQeuacWjcW0JcWcBS73nV
                                                        TLSH:E29319C7F810ED7EF80BD67748A34D0E7671F2A00A930A326767BA67EC76195141BD82
                                                        File Content Preview:.ELF.......................D...4..{......4. ...(......................x...x....... .......x............x..*....... .dt.Q............................NV..a....da...P N^NuNV..J9...@f>"y.... QJ.g.X.#.....N."y.... QJ.f.A.....J.g.Hy....N.X........@N^NuNV..N^NuN

                                                        ELF header

                                                        Class:ELF32
                                                        Data:2's complement, big endian
                                                        Version:1 (current)
                                                        Machine:MC68000
                                                        Version Number:0x1
                                                        Type:EXEC (Executable file)
                                                        OS/ABI:UNIX - System V
                                                        ABI Version:0
                                                        Entry Point Address:0x80000144
                                                        Flags:0x0
                                                        ELF Header Size:52
                                                        Program Header Offset:52
                                                        Program Header Size:32
                                                        Number of Program Headers:3
                                                        Section Header Offset:97152
                                                        Section Header Size:40
                                                        Number of Section Headers:10
                                                        Header String Table Index:9
                                                        NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                        NULL0x00x00x00x00x0000
                                                        .initPROGBITS0x800000940x940x140x00x6AX002
                                                        .textPROGBITS0x800000a80xa80x1504a0x00x6AX004
                                                        .finiPROGBITS0x800150f20x150f20xe0x00x6AX002
                                                        .rodataPROGBITS0x800151000x151000x27c30x00x2A002
                                                        .ctorsPROGBITS0x800198c80x178c80x80x00x3WA004
                                                        .dtorsPROGBITS0x800198d00x178d00x80x00x3WA004
                                                        .dataPROGBITS0x800198dc0x178dc0x2640x00x3WA004
                                                        .bssNOBITS0x80019b400x17b400x28180x00x3WA004
                                                        .shstrtabSTRTAB0x00x17b400x3e0x00x0001
                                                        TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                        LOAD0x00x800000000x800000000x178c30x178c36.28900x5R E0x2000.init .text .fini .rodata
                                                        LOAD0x178c80x800198c80x800198c80x2780x2a903.65170x6RW 0x2000.ctors .dtors .data .bss
                                                        GNU_STACK0x00x00x00x00x00.00000x6RW 0x4
                                                        TimestampSource PortDest PortSource IPDest IP
                                                        Dec 27, 2024 10:38:19.803662062 CET532703778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:19.923571110 CET377853270159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:19.923660994 CET532703778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:19.925319910 CET532703778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:20.044950962 CET377853270159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:20.045006990 CET532703778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:20.164946079 CET377853270159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:21.012923956 CET43928443192.168.2.2391.189.91.42
                                                        Dec 27, 2024 10:38:21.182344913 CET377853270159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:21.182497025 CET532703778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:21.182730913 CET532703778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:21.183383942 CET532723778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:21.302944899 CET377853272159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:21.303181887 CET532723778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:21.304229021 CET532723778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:21.424932003 CET377853272159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:21.425261021 CET532723778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:21.545016050 CET377853272159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:22.572072983 CET377853272159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:22.572242975 CET532723778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:22.572326899 CET532723778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:22.572958946 CET532743778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:22.692460060 CET377853274159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:22.692568064 CET532743778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:23.604743004 CET532743778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:23.724273920 CET377853274159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:23.724564075 CET532743778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:23.725596905 CET532743778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:23.845216990 CET377853274159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:23.845513105 CET532743778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:23.965286970 CET377853274159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:24.984491110 CET377853274159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:24.984678030 CET532743778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:24.984745026 CET532743778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:24.985379934 CET532763778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:25.105096102 CET377853276159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:25.105245113 CET532763778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:25.106019974 CET532763778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:25.225667953 CET377853276159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:25.225833893 CET532763778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:25.345727921 CET377853276159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:25.480962038 CET532783778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:25.600503922 CET377853278159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:25.600586891 CET532783778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:25.603364944 CET532783778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:25.722973108 CET377853278159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:25.723131895 CET532783778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:25.842917919 CET377853278159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:26.388262033 CET42836443192.168.2.2391.189.91.43
                                                        Dec 27, 2024 10:38:26.413904905 CET377853276159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:26.414230108 CET532763778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:26.414230108 CET532763778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:26.414854050 CET532803778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:26.534427881 CET377853280159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:26.534759045 CET532803778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:26.535573006 CET532803778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:26.655297995 CET377853280159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:26.655564070 CET532803778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:26.775360107 CET377853280159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:27.896032095 CET377853280159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:27.896192074 CET532803778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:27.896262884 CET532803778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:27.896748066 CET532823778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:28.017811060 CET377853282159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:28.018062115 CET532823778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:28.019329071 CET532823778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:28.138901949 CET377853282159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:28.139230967 CET532823778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:28.179847002 CET4251680192.168.2.23109.202.202.202
                                                        Dec 27, 2024 10:38:28.259032965 CET377853282159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:29.369894028 CET377853282159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:29.370285034 CET532823778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:29.370285034 CET532823778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:29.370691061 CET532843778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:29.490312099 CET377853284159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:29.490659952 CET532843778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:29.491714001 CET532843778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:29.611264944 CET377853284159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:29.611536980 CET532843778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:29.731483936 CET377853284159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:30.795720100 CET377853284159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:30.796046019 CET532843778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:30.796046019 CET532843778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:30.796627998 CET532863778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:30.916276932 CET377853286159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:30.916512966 CET532863778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:30.917504072 CET532863778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:31.037092924 CET377853286159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:31.037425995 CET532863778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:31.157375097 CET377853286159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:32.221843958 CET377853286159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:32.222357035 CET532863778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:32.222357988 CET532863778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:32.222943068 CET532883778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:32.342550039 CET377853288159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:32.342681885 CET532883778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:32.343638897 CET532883778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:32.463181973 CET377853288159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:32.463368893 CET532883778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:32.583132982 CET377853288159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:33.658349037 CET377853288159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:33.658689976 CET532883778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:33.658689976 CET532883778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:33.659305096 CET532903778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:33.778810024 CET377853290159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:33.779004097 CET532903778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:33.780005932 CET532903778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:33.899655104 CET377853290159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:33.900114059 CET532903778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:34.019933939 CET377853290159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:35.083756924 CET377853290159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:35.084197998 CET532903778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:35.084296942 CET532903778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:35.085397959 CET532923778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:35.205353975 CET377853292159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:35.205514908 CET532923778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:35.206445932 CET532923778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:35.326031923 CET377853292159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:35.326167107 CET532923778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:35.445842981 CET377853292159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:35.612739086 CET532783778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:35.732513905 CET377853278159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:36.018551111 CET377853278159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:36.018692017 CET532783778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:36.464998960 CET377853292159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:36.465368032 CET532923778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:36.465466022 CET532923778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:36.466315031 CET532943778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:36.585902929 CET377853294159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:36.586206913 CET532943778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:36.587677002 CET532943778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:36.707248926 CET377853294159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:36.707592964 CET532943778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:36.827383041 CET377853294159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:37.892093897 CET377853294159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:37.892608881 CET532943778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:37.892608881 CET532943778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:37.893258095 CET532963778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:38.012784004 CET377853296159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:38.013048887 CET532963778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:38.014297009 CET532963778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:38.134310007 CET377853296159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:38.134500980 CET532963778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:38.254379988 CET377853296159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:39.353497028 CET377853296159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:39.353653908 CET532963778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:39.353688955 CET532963778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:39.354295015 CET532983778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:39.473885059 CET377853298159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:39.474061012 CET532983778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:39.475403070 CET532983778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:39.595031977 CET377853298159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:39.595308065 CET532983778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:39.715003967 CET377853298159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:40.733174086 CET377853298159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:40.733455896 CET532983778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:40.733455896 CET532983778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:40.734303951 CET533003778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:40.853857040 CET377853300159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:40.854125977 CET533003778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:40.855555058 CET533003778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:40.975296974 CET377853300159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:40.975578070 CET533003778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:41.095323086 CET377853300159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:42.161026001 CET377853300159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:42.161289930 CET533003778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:42.161381960 CET533003778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:42.162393093 CET533023778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:42.281948090 CET377853302159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:42.282083988 CET533023778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:42.283330917 CET533023778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:42.402822971 CET377853302159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:42.403053999 CET533023778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:42.514044046 CET43928443192.168.2.2391.189.91.42
                                                        Dec 27, 2024 10:38:42.522733927 CET377853302159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:43.632903099 CET377853302159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:43.633160114 CET533023778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:43.633407116 CET533023778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:43.634252071 CET533043778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:43.753865957 CET377853304159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:43.754229069 CET533043778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:43.755610943 CET533043778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:43.875171900 CET377853304159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:43.875677109 CET533043778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:43.995392084 CET377853304159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:45.013676882 CET377853304159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:45.014002085 CET533043778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:45.014002085 CET533043778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:45.014916897 CET533063778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:45.134641886 CET377853306159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:45.134978056 CET533063778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:45.136488914 CET533063778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:45.256217957 CET377853306159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:45.256599903 CET533063778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:45.376559019 CET377853306159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:46.487649918 CET377853306159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:46.487890005 CET533063778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:46.488032103 CET533063778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:46.488673925 CET533083778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:46.608567953 CET377853308159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:46.609098911 CET533083778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:46.610074043 CET533083778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:46.729657888 CET377853308159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:46.730005980 CET533083778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:46.849917889 CET377853308159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:47.960997105 CET377853308159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:47.961231947 CET533083778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:47.961338997 CET533083778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:47.962249041 CET533103778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:48.081861973 CET377853310159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:48.082201958 CET533103778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:48.083241940 CET533103778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:48.202672005 CET377853310159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:48.202833891 CET533103778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:48.322354078 CET377853310159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:49.341661930 CET377853310159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:49.341918945 CET533103778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:49.341990948 CET533103778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:49.342539072 CET533123778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:49.462156057 CET377853312159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:49.462274075 CET533123778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:49.463123083 CET533123778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:49.582743883 CET377853312159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:49.582839966 CET533123778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:49.702277899 CET377853312159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:50.766973972 CET377853312159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:50.767115116 CET533123778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:50.767215967 CET533123778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:50.767760992 CET533143778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:50.888186932 CET377853314159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:50.888442993 CET533143778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:50.889380932 CET533143778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:51.008869886 CET377853314159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:51.009052992 CET533143778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:51.128586054 CET377853314159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:52.193523884 CET377853314159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:52.193680048 CET533143778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:52.193886995 CET533143778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:52.194394112 CET533163778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:52.313895941 CET377853316159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:52.314033985 CET533163778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:52.315053940 CET533163778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:52.435075998 CET377853316159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:52.435230970 CET533163778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:52.554991961 CET377853316159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:52.752530098 CET42836443192.168.2.2391.189.91.43
                                                        Dec 27, 2024 10:38:53.619612932 CET377853316159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:53.619752884 CET533163778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:53.619812965 CET533163778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:53.620532036 CET533183778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:53.740364075 CET377853318159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:53.740469933 CET533183778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:53.741202116 CET533183778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:53.860670090 CET377853318159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:53.860752106 CET533183778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:53.980261087 CET377853318159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:55.010763884 CET377853318159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:55.010912895 CET533183778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:55.010958910 CET533183778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:55.011717081 CET533203778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:55.131242990 CET377853320159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:55.131370068 CET533203778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:55.132230997 CET533203778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:55.251657009 CET377853320159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:55.251714945 CET533203778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:55.371437073 CET377853320159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:56.390110970 CET377853320159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:56.390305996 CET533203778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:56.390351057 CET533203778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:56.390811920 CET533223778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:56.510317087 CET377853322159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:56.510446072 CET533223778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:56.511331081 CET533223778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:56.630736113 CET377853322159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:56.631002903 CET533223778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:56.750524998 CET377853322159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:57.815735102 CET377853322159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:57.815877914 CET533223778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:57.815907955 CET533223778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:57.817060947 CET533243778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:57.936669111 CET377853324159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:57.936772108 CET533243778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:57.937618971 CET533243778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:58.057121992 CET377853324159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:58.057260036 CET533243778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:58.176893950 CET377853324159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:58.895612001 CET4251680192.168.2.23109.202.202.202
                                                        Dec 27, 2024 10:38:59.288741112 CET377853324159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:59.288964033 CET533243778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:59.289068937 CET533243778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:59.289558887 CET533263778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:59.409010887 CET377853326159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:59.409147978 CET533263778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:59.410033941 CET533263778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:59.529586077 CET377853326159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:38:59.529723883 CET533263778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:38:59.649379015 CET377853326159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:39:09.418795109 CET533263778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:39:09.538570881 CET377853326159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:39:09.828351974 CET377853326159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:39:09.828461885 CET533263778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:39:23.468225956 CET43928443192.168.2.2391.189.91.42
                                                        Dec 27, 2024 10:39:36.070563078 CET532783778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:39:36.190032005 CET377853278159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:39:36.476670027 CET377853278159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:39:36.476766109 CET532783778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:40:09.877587080 CET533263778192.168.2.23159.100.18.129
                                                        Dec 27, 2024 10:40:09.998771906 CET377853326159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:40:10.289330006 CET377853326159.100.18.129192.168.2.23
                                                        Dec 27, 2024 10:40:10.289628029 CET533263778192.168.2.23159.100.18.129

                                                        System Behavior

                                                        Start time (UTC):09:38:15
                                                        Start date (UTC):27/12/2024
                                                        Path:/usr/bin/dash
                                                        Arguments:-
                                                        File size:129816 bytes
                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                        Start time (UTC):09:38:15
                                                        Start date (UTC):27/12/2024
                                                        Path:/usr/bin/rm
                                                        Arguments:rm -f /tmp/tmp.U4kQztPbIV /tmp/tmp.eaYwXZIXVn /tmp/tmp.Uvg70fFH73
                                                        File size:72056 bytes
                                                        MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                                        Start time (UTC):09:38:15
                                                        Start date (UTC):27/12/2024
                                                        Path:/usr/bin/dash
                                                        Arguments:-
                                                        File size:129816 bytes
                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                        Start time (UTC):09:38:15
                                                        Start date (UTC):27/12/2024
                                                        Path:/usr/bin/cat
                                                        Arguments:cat /tmp/tmp.U4kQztPbIV
                                                        File size:43416 bytes
                                                        MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

                                                        Start time (UTC):09:38:15
                                                        Start date (UTC):27/12/2024
                                                        Path:/usr/bin/dash
                                                        Arguments:-
                                                        File size:129816 bytes
                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                        Start time (UTC):09:38:15
                                                        Start date (UTC):27/12/2024
                                                        Path:/usr/bin/head
                                                        Arguments:head -n 10
                                                        File size:47480 bytes
                                                        MD5 hash:fd96a67145172477dd57131396fc9608

                                                        Start time (UTC):09:38:15
                                                        Start date (UTC):27/12/2024
                                                        Path:/usr/bin/dash
                                                        Arguments:-
                                                        File size:129816 bytes
                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                        Start time (UTC):09:38:15
                                                        Start date (UTC):27/12/2024
                                                        Path:/usr/bin/tr
                                                        Arguments:tr -d \\000-\\011\\013\\014\\016-\\037
                                                        File size:51544 bytes
                                                        MD5 hash:fbd1402dd9f72d8ebfff00ce7c3a7bb5

                                                        Start time (UTC):09:38:15
                                                        Start date (UTC):27/12/2024
                                                        Path:/usr/bin/dash
                                                        Arguments:-
                                                        File size:129816 bytes
                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                        Start time (UTC):09:38:15
                                                        Start date (UTC):27/12/2024
                                                        Path:/usr/bin/cut
                                                        Arguments:cut -c -80
                                                        File size:47480 bytes
                                                        MD5 hash:d8ed0ea8f22c0de0f8692d4d9f1759d3

                                                        Start time (UTC):09:38:15
                                                        Start date (UTC):27/12/2024
                                                        Path:/usr/bin/dash
                                                        Arguments:-
                                                        File size:129816 bytes
                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                        Start time (UTC):09:38:15
                                                        Start date (UTC):27/12/2024
                                                        Path:/usr/bin/cat
                                                        Arguments:cat /tmp/tmp.U4kQztPbIV
                                                        File size:43416 bytes
                                                        MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

                                                        Start time (UTC):09:38:15
                                                        Start date (UTC):27/12/2024
                                                        Path:/usr/bin/dash
                                                        Arguments:-
                                                        File size:129816 bytes
                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                        Start time (UTC):09:38:15
                                                        Start date (UTC):27/12/2024
                                                        Path:/usr/bin/head
                                                        Arguments:head -n 10
                                                        File size:47480 bytes
                                                        MD5 hash:fd96a67145172477dd57131396fc9608

                                                        Start time (UTC):09:38:15
                                                        Start date (UTC):27/12/2024
                                                        Path:/usr/bin/dash
                                                        Arguments:-
                                                        File size:129816 bytes
                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                        Start time (UTC):09:38:15
                                                        Start date (UTC):27/12/2024
                                                        Path:/usr/bin/tr
                                                        Arguments:tr -d \\000-\\011\\013\\014\\016-\\037
                                                        File size:51544 bytes
                                                        MD5 hash:fbd1402dd9f72d8ebfff00ce7c3a7bb5

                                                        Start time (UTC):09:38:15
                                                        Start date (UTC):27/12/2024
                                                        Path:/usr/bin/dash
                                                        Arguments:-
                                                        File size:129816 bytes
                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                        Start time (UTC):09:38:15
                                                        Start date (UTC):27/12/2024
                                                        Path:/usr/bin/cut
                                                        Arguments:cut -c -80
                                                        File size:47480 bytes
                                                        MD5 hash:d8ed0ea8f22c0de0f8692d4d9f1759d3

                                                        Start time (UTC):09:38:15
                                                        Start date (UTC):27/12/2024
                                                        Path:/usr/bin/dash
                                                        Arguments:-
                                                        File size:129816 bytes
                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                        Start time (UTC):09:38:15
                                                        Start date (UTC):27/12/2024
                                                        Path:/usr/bin/rm
                                                        Arguments:rm -f /tmp/tmp.U4kQztPbIV /tmp/tmp.eaYwXZIXVn /tmp/tmp.Uvg70fFH73
                                                        File size:72056 bytes
                                                        MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                                        Start time (UTC):09:38:18
                                                        Start date (UTC):27/12/2024
                                                        Path:/tmp/Space.m68k.elf
                                                        Arguments:/tmp/Space.m68k.elf
                                                        File size:4463432 bytes
                                                        MD5 hash:cd177594338c77b895ae27c33f8f86cc

                                                        Start time (UTC):09:38:18
                                                        Start date (UTC):27/12/2024
                                                        Path:/tmp/Space.m68k.elf
                                                        Arguments:-
                                                        File size:4463432 bytes
                                                        MD5 hash:cd177594338c77b895ae27c33f8f86cc

                                                        Start time (UTC):09:38:18
                                                        Start date (UTC):27/12/2024
                                                        Path:/tmp/Space.m68k.elf
                                                        Arguments:-
                                                        File size:4463432 bytes
                                                        MD5 hash:cd177594338c77b895ae27c33f8f86cc

                                                        Start time (UTC):09:38:18
                                                        Start date (UTC):27/12/2024
                                                        Path:/tmp/Space.m68k.elf
                                                        Arguments:-
                                                        File size:4463432 bytes
                                                        MD5 hash:cd177594338c77b895ae27c33f8f86cc

                                                        Start time (UTC):09:38:24
                                                        Start date (UTC):27/12/2024
                                                        Path:/tmp/Space.m68k.elf
                                                        Arguments:-
                                                        File size:4463432 bytes
                                                        MD5 hash:cd177594338c77b895ae27c33f8f86cc

                                                        Start time (UTC):09:38:24
                                                        Start date (UTC):27/12/2024
                                                        Path:/tmp/Space.m68k.elf
                                                        Arguments:-
                                                        File size:4463432 bytes
                                                        MD5 hash:cd177594338c77b895ae27c33f8f86cc