Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
socat.elf

Overview

General Information

Sample name:socat.elf
Analysis ID:1583197
MD5:c50fc2d61fe691e3074a28bddeef2899
SHA1:3ac04b4d25c188b0cf5b8188352d4c1cbc3c09be
SHA256:947d94994555662758c6ad57ec25672e40ce688e135e9b81090d1d58b34392b2
Tags:elfuser-abuse_ch
Infos:

Detection

Score:48
Range:0 - 100
Whitelisted:false

Signatures

Malicious sample detected (through community Yara rule)
Executes the "rm" command used to delete files or directories
Sample has stripped symbol table
Uses the "uname" system call to query kernel version information (possible evasion)
Yara signature match

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1583197
Start date and time:2025-01-02 08:42:08 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 30s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:socat.elf
Detection:MAL
Classification:mal48.linELF@0/0@0/0
Command:/tmp/socat.elf
PID:6209
Exit Code:1
Exit Code Info:
Killed:False
Standard Output:

Standard Error:2025/01/02 01:42:48 socat.elf[6209] E exactly 2 addresses required (there are 0); use option "-h" for help
  • system is lnxubuntu20
  • socat.elf (PID: 6209, Parent: 6126, MD5: 5ebfcae4fe2471fcc5695c2394773ff1) Arguments: /tmp/socat.elf
  • dash New Fork (PID: 6245, Parent: 4334)
  • rm (PID: 6245, Parent: 4334, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.oZwFk6FYK4 /tmp/tmp.BOnvIMenbC /tmp/tmp.Mj6CC1rDaC
  • dash New Fork (PID: 6246, Parent: 4334)
  • rm (PID: 6246, Parent: 4334, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.oZwFk6FYK4 /tmp/tmp.BOnvIMenbC /tmp/tmp.Mj6CC1rDaC
  • cleanup
SourceRuleDescriptionAuthorStrings
socat.elfhacktool_socat_stringsDetects socatSekoia.io
  • 0xacaa6:$: [options] <bi-address> <bi-address>
  • 0xaca06:$: version %s on %s
  • 0xad0fa:$: version %s on %s
  • 0xad918:$: socat_signal():
  • 0xad954:$: socat_signal():
SourceRuleDescriptionAuthorStrings
6209.1.00007f25a8017000.00007f25a80ee000.r-x.sdmphacktool_socat_stringsDetects socatSekoia.io
  • 0xacaa6:$: [options] <bi-address> <bi-address>
  • 0xaca06:$: version %s on %s
  • 0xad0fa:$: version %s on %s
  • 0xad918:$: socat_signal():
  • 0xad954:$: socat_signal():
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: socat.elfString found in binary or memory: http://www.debian.org/Bugs/
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 33606
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 33606 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443

System Summary

barindex
Source: socat.elf, type: SAMPLEMatched rule: Detects socat Author: Sekoia.io
Source: 6209.1.00007f25a8017000.00007f25a80ee000.r-x.sdmp, type: MEMORYMatched rule: Detects socat Author: Sekoia.io
Source: ELF static info symbol of initial sample.symtab present: no
Source: socat.elf, type: SAMPLEMatched rule: hacktool_socat_strings author = Sekoia.io, description = Detects socat, creation_date = 2023-12-08, classification = TLP:CLEAR, version = 1.0, id = 7c7e4085-39b2-445e-a9ff-52f21936e714
Source: 6209.1.00007f25a8017000.00007f25a80ee000.r-x.sdmp, type: MEMORYMatched rule: hacktool_socat_strings author = Sekoia.io, description = Detects socat, creation_date = 2023-12-08, classification = TLP:CLEAR, version = 1.0, id = 7c7e4085-39b2-445e-a9ff-52f21936e714
Source: classification engineClassification label: mal48.linELF@0/0@0/0
Source: /usr/bin/dash (PID: 6245)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.oZwFk6FYK4 /tmp/tmp.BOnvIMenbC /tmp/tmp.Mj6CC1rDaCJump to behavior
Source: /usr/bin/dash (PID: 6246)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.oZwFk6FYK4 /tmp/tmp.BOnvIMenbC /tmp/tmp.Mj6CC1rDaCJump to behavior
Source: /tmp/socat.elf (PID: 6209)Queries kernel information via 'uname': Jump to behavior
Source: socat.elf, 6209.1.000055998bbe8000.000055998bd3a000.rw-.sdmpBinary or memory string: U!/etc/qemu-binfmt/arm
Source: socat.elf, 6209.1.00007fffda451000.00007fffda472000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-arm/tmp/socat.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/socat.elf
Source: socat.elf, 6209.1.000055998bbe8000.000055998bd3a000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/arm
Source: socat.elf, 6209.1.00007fffda451000.00007fffda472000.rw-.sdmpBinary or memory string: /usr/bin/qemu-arm
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
File Deletion
OS Credential Dumping11
Security Software Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1583197 Sample: socat.elf Startdate: 02/01/2025 Architecture: LINUX Score: 48 12 109.202.202.202, 80 INIT7CH Switzerland 2->12 14 91.189.91.42, 443 CANONICAL-ASGB United Kingdom 2->14 16 2 other IPs or domains 2->16 18 Malicious sample detected (through community Yara rule) 2->18 6 dash rm 2->6         started        8 dash rm 2->8         started        10 socat.elf 2->10         started        signatures3 process4
SourceDetectionScannerLabelLink
socat.elf0%VirustotalBrowse
socat.elf0%ReversingLabs
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
NameSourceMaliciousAntivirus DetectionReputation
http://www.debian.org/Bugs/socat.elffalse
    high
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    54.171.230.55
    unknownUnited States
    16509AMAZON-02USfalse
    109.202.202.202
    unknownSwitzerland
    13030INIT7CHfalse
    91.189.91.43
    unknownUnited Kingdom
    41231CANONICAL-ASGBfalse
    91.189.91.42
    unknownUnited Kingdom
    41231CANONICAL-ASGBfalse
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    54.171.230.55arm5.elfGet hashmaliciousUnknownBrowse
      bot.mips.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
        emips.elfGet hashmaliciousUnknownBrowse
          i.elfGet hashmaliciousUnknownBrowse
            .i.elfGet hashmaliciousUnknownBrowse
              i.elfGet hashmaliciousUnknownBrowse
                boatnet.arm.elfGet hashmaliciousMiraiBrowse
                  boatnet.arm6.elfGet hashmaliciousMiraiBrowse
                    Aqua.sh4.elfGet hashmaliciousUnknownBrowse
                      boatnet.spc.elfGet hashmaliciousMiraiBrowse
                        109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
                        • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
                        91.189.91.43arm5.elfGet hashmaliciousUnknownBrowse
                          wrjkngh4.elfGet hashmaliciousMiraiBrowse
                            woega6.elfGet hashmaliciousMiraiBrowse
                              arm5.elfGet hashmaliciousMiraiBrowse
                                m68k.elfGet hashmaliciousMiraiBrowse
                                  bot.m68k.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
                                    bot.arm.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
                                      i.elfGet hashmaliciousUnknownBrowse
                                        bot.x86.elfGet hashmaliciousMirai, OkiruBrowse
                                          bot.x86_64.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
                                            91.189.91.42arm5.elfGet hashmaliciousUnknownBrowse
                                              ngwa5.elfGet hashmaliciousMiraiBrowse
                                                wrjkngh4.elfGet hashmaliciousMiraiBrowse
                                                  woega6.elfGet hashmaliciousMiraiBrowse
                                                    arm5.elfGet hashmaliciousMiraiBrowse
                                                      arm6.elfGet hashmaliciousMiraiBrowse
                                                        m68k.elfGet hashmaliciousMiraiBrowse
                                                          bot.m68k.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
                                                            bot.arm.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
                                                              i.elfGet hashmaliciousUnknownBrowse
                                                                No context
                                                                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                CANONICAL-ASGBarm5.elfGet hashmaliciousUnknownBrowse
                                                                • 91.189.91.42
                                                                ngwa5.elfGet hashmaliciousMiraiBrowse
                                                                • 91.189.91.42
                                                                wrjkngh4.elfGet hashmaliciousMiraiBrowse
                                                                • 91.189.91.42
                                                                gnjqwpc.elfGet hashmaliciousMiraiBrowse
                                                                • 185.125.190.26
                                                                woega6.elfGet hashmaliciousMiraiBrowse
                                                                • 91.189.91.42
                                                                arm5.elfGet hashmaliciousMiraiBrowse
                                                                • 91.189.91.42
                                                                arm6.elfGet hashmaliciousMiraiBrowse
                                                                • 91.189.91.42
                                                                m68k.elfGet hashmaliciousMiraiBrowse
                                                                • 91.189.91.42
                                                                bot.m68k.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
                                                                • 91.189.91.42
                                                                bot.arm.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
                                                                • 91.189.91.42
                                                                CANONICAL-ASGBarm5.elfGet hashmaliciousUnknownBrowse
                                                                • 91.189.91.42
                                                                ngwa5.elfGet hashmaliciousMiraiBrowse
                                                                • 91.189.91.42
                                                                wrjkngh4.elfGet hashmaliciousMiraiBrowse
                                                                • 91.189.91.42
                                                                gnjqwpc.elfGet hashmaliciousMiraiBrowse
                                                                • 185.125.190.26
                                                                woega6.elfGet hashmaliciousMiraiBrowse
                                                                • 91.189.91.42
                                                                arm5.elfGet hashmaliciousMiraiBrowse
                                                                • 91.189.91.42
                                                                arm6.elfGet hashmaliciousMiraiBrowse
                                                                • 91.189.91.42
                                                                m68k.elfGet hashmaliciousMiraiBrowse
                                                                • 91.189.91.42
                                                                bot.m68k.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
                                                                • 91.189.91.42
                                                                bot.arm.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
                                                                • 91.189.91.42
                                                                AMAZON-02USarm5.elfGet hashmaliciousUnknownBrowse
                                                                • 54.171.230.55
                                                                ngwa5.elfGet hashmaliciousMiraiBrowse
                                                                • 34.249.145.219
                                                                http://www.rr8844.comGet hashmaliciousUnknownBrowse
                                                                • 3.5.146.228
                                                                arm6.elfGet hashmaliciousMiraiBrowse
                                                                • 34.249.145.219
                                                                https://bitl.to/3Y0BGet hashmaliciousCAPTCHA Scam ClickFixBrowse
                                                                • 18.245.31.129
                                                                bot.mips.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
                                                                • 54.171.230.55
                                                                emips.elfGet hashmaliciousUnknownBrowse
                                                                • 54.171.230.55
                                                                loligang.m68k.elfGet hashmaliciousMiraiBrowse
                                                                • 34.249.145.219
                                                                loligang.arm.elfGet hashmaliciousMiraiBrowse
                                                                • 18.253.227.163
                                                                loligang.sh4.elfGet hashmaliciousMiraiBrowse
                                                                • 99.79.71.158
                                                                INIT7CHarm5.elfGet hashmaliciousUnknownBrowse
                                                                • 109.202.202.202
                                                                ngwa5.elfGet hashmaliciousMiraiBrowse
                                                                • 109.202.202.202
                                                                wrjkngh4.elfGet hashmaliciousMiraiBrowse
                                                                • 109.202.202.202
                                                                woega6.elfGet hashmaliciousMiraiBrowse
                                                                • 109.202.202.202
                                                                arm5.elfGet hashmaliciousMiraiBrowse
                                                                • 109.202.202.202
                                                                arm6.elfGet hashmaliciousMiraiBrowse
                                                                • 109.202.202.202
                                                                m68k.elfGet hashmaliciousMiraiBrowse
                                                                • 109.202.202.202
                                                                bot.m68k.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
                                                                • 109.202.202.202
                                                                bot.arm.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
                                                                • 109.202.202.202
                                                                i.elfGet hashmaliciousUnknownBrowse
                                                                • 109.202.202.202
                                                                No context
                                                                No context
                                                                No created / dropped files found
                                                                File type:ELF 32-bit LSB executable, ARM, EABI5 version 1 (SYSV), statically linked, for GNU/Linux 2.6.26, BuildID[sha1]=5ed3ef54ea34c566de4ff593ef0d4ef3c79459fd, stripped
                                                                Entropy (8bit):6.071840292742399
                                                                TrID:
                                                                • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                                                File name:socat.elf
                                                                File size:885'248 bytes
                                                                MD5:c50fc2d61fe691e3074a28bddeef2899
                                                                SHA1:3ac04b4d25c188b0cf5b8188352d4c1cbc3c09be
                                                                SHA256:947d94994555662758c6ad57ec25672e40ce688e135e9b81090d1d58b34392b2
                                                                SHA512:8c20a61a7dfe56d31204e396b8bd5b5c33ab6b47290e02b37adc25b45277a8fceff14f8a8895a8546a551e3af09f944cd0bffcce31254c49fcaa2b74b4792357
                                                                SSDEEP:24576:3rgP6o33iqsKqWX0BMi6xvxJi+7AlFXFmNi:9zAv9ElFp
                                                                TLSH:70156D88F9514B66CAE072F9FB5D42CD33170BB5E3F631169D245B203BC6E9A0E3A251
                                                                File Content Preview:.ELF..............(.....P...4....}......4. ...(........p.]..........H...H...........................hf..hf...............p...p...p..................................D...D................p...p...p......0...........Q.td.......................................

                                                                ELF header

                                                                Class:ELF32
                                                                Data:2's complement, little endian
                                                                Version:1 (current)
                                                                Machine:ARM
                                                                Version Number:0x1
                                                                Type:EXEC (Executable file)
                                                                OS/ABI:UNIX - System V
                                                                ABI Version:0
                                                                Entry Point Address:0x8150
                                                                Flags:0x5000002
                                                                ELF Header Size:52
                                                                Program Header Offset:52
                                                                Program Header Size:32
                                                                Number of Program Headers:6
                                                                Section Header Offset:884128
                                                                Section Header Size:40
                                                                Number of Section Headers:28
                                                                Header String Table Index:27
                                                                NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                                NULL0x00x00x00x00x0000
                                                                .note.ABI-tagNOTE0x80f40xf40x200x00x2A004
                                                                .note.gnu.build-idNOTE0x81140x1140x240x00x2A004
                                                                .initPROGBITS0x81380x1380x100x00x6AX004
                                                                .textPROGBITS0x81500x1500xab6d80x00x6AX0016
                                                                __libc_freeres_fnPROGBITS0xb38280xab8280xe980x00x6AX004
                                                                __libc_thread_freeres_fnPROGBITS0xb46c00xac6c00x500x00x6AX004
                                                                .finiPROGBITS0xb47100xac7100xc0x00x6AX004
                                                                .rodataPROGBITS0xb47200xac7200x2928c0x00x2A008
                                                                __libc_subfreeresPROGBITS0xdd9ac0xd59ac0x500x00x2A004
                                                                __libc_atexitPROGBITS0xdd9fc0xd59fc0x40x00x2A004
                                                                __libc_thread_subfreeresPROGBITS0xdda000xd5a000x40x00x2A004
                                                                .ARM.extabPROGBITS0xdda040xd5a040x3180x00x2A004
                                                                .ARM.exidxARM_EXIDX0xddd1c0xd5d1c0x9480x00x82AL404
                                                                .eh_framePROGBITS0xde6640xd66640x40x00x2A004
                                                                .tdataPROGBITS0xe70000xd70000x140x00x403WAT004
                                                                .tbssNOBITS0xe70140xd70140x1c0x00x403WAT004
                                                                .init_arrayINIT_ARRAY0xe70140xd70140x40x00x3WA004
                                                                .fini_arrayFINI_ARRAY0xe70180xd70180x80x00x3WA004
                                                                .jcrPROGBITS0xe70200xd70200x40x00x3WA004
                                                                .data.rel.roPROGBITS0xe70240xd70240x340x00x3WA004
                                                                .gotPROGBITS0xe70580xd70580x780x40x3WA004
                                                                .dataPROGBITS0xe70d00xd70d00xb2c0x00x3WA008
                                                                .bssNOBITS0xe7c000xd7bfc0x422b80x00x3WA008
                                                                __libc_freeres_ptrsNOBITS0x129eb80xd7bfc0x380x00x3WA004
                                                                .commentPROGBITS0x00xd7bfc0x390x10x30MS001
                                                                .ARM.attributesARM_ATTRIBUTES0x00xd7c350x2a0x00x0001
                                                                .shstrtabSTRTAB0x00xd7c5f0x13e0x00x0001
                                                                TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                                EXIDX0xd5d1c0xddd1c0xddd1c0x9480x9485.54500x4R 0x4.ARM.exidx
                                                                LOAD0x00x80000x80000xd66680xd66686.08890x5R E0x8000.note.ABI-tag .note.gnu.build-id .init .text __libc_freeres_fn __libc_thread_freeres_fn .fini .rodata __libc_subfreeres __libc_atexit __libc_thread_subfreeres .ARM.extab .ARM.exidx .eh_frame
                                                                LOAD0xd70000xe70000xe70000xbfc0x42ef03.40020x6RW 0x8000.tdata .tbss .init_array .fini_array .jcr .data.rel.ro .got .data .bss __libc_freeres_ptrs
                                                                NOTE0xf40x80f40x80f40x440x443.45190x4R 0x4.note.ABI-tag .note.gnu.build-id
                                                                TLS0xd70000xe70000xe70000x140x302.66100x4R 0x4.tdata .tbss
                                                                GNU_STACK0x00x00x00x00x00.00000x6RW 0x4
                                                                TimestampSource PortDest PortSource IPDest IP
                                                                Jan 2, 2025 08:42:51.520436049 CET43928443192.168.2.2391.189.91.42
                                                                Jan 2, 2025 08:42:56.895814896 CET42836443192.168.2.2391.189.91.43
                                                                Jan 2, 2025 08:42:58.431497097 CET4251680192.168.2.23109.202.202.202
                                                                Jan 2, 2025 08:43:11.997698069 CET43928443192.168.2.2391.189.91.42
                                                                Jan 2, 2025 08:43:20.865699053 CET33606443192.168.2.2354.171.230.55
                                                                Jan 2, 2025 08:43:20.870738983 CET4433360654.171.230.55192.168.2.23
                                                                Jan 2, 2025 08:43:20.870815039 CET33606443192.168.2.2354.171.230.55
                                                                Jan 2, 2025 08:43:24.283900976 CET42836443192.168.2.2391.189.91.43
                                                                Jan 2, 2025 08:43:28.379337072 CET4251680192.168.2.23109.202.202.202
                                                                Jan 2, 2025 08:43:52.952006102 CET43928443192.168.2.2391.189.91.42

                                                                System Behavior

                                                                Start time (UTC):07:42:48
                                                                Start date (UTC):02/01/2025
                                                                Path:/tmp/socat.elf
                                                                Arguments:/tmp/socat.elf
                                                                File size:4956856 bytes
                                                                MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                                Start time (UTC):07:43:20
                                                                Start date (UTC):02/01/2025
                                                                Path:/usr/bin/dash
                                                                Arguments:-
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):07:43:20
                                                                Start date (UTC):02/01/2025
                                                                Path:/usr/bin/rm
                                                                Arguments:rm -f /tmp/tmp.oZwFk6FYK4 /tmp/tmp.BOnvIMenbC /tmp/tmp.Mj6CC1rDaC
                                                                File size:72056 bytes
                                                                MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                                                Start time (UTC):07:43:20
                                                                Start date (UTC):02/01/2025
                                                                Path:/usr/bin/dash
                                                                Arguments:-
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):07:43:20
                                                                Start date (UTC):02/01/2025
                                                                Path:/usr/bin/rm
                                                                Arguments:rm -f /tmp/tmp.oZwFk6FYK4 /tmp/tmp.BOnvIMenbC /tmp/tmp.Mj6CC1rDaC
                                                                File size:72056 bytes
                                                                MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b