Edit tour

Linux Analysis Report
arm.elf

Overview

General Information

Sample name:arm.elf
Analysis ID:1594466
MD5:fc275b45dfc2bac93e56c0790c701b0b
SHA1:077945a1e7aecea4a0e15c913219cac058a3ba8d
SHA256:24867a7e0571e2ec6173d46cf91fc693881a8767a23f1a1c3ab475a7df4d9b21
Tags:elfuser-abuse_ch
Infos:

Detection

Score:48
Range:0 - 100
Whitelisted:false

Signatures

Multi AV Scanner detection for submitted file
Detected TCP or UDP traffic on non-standard ports
Executes commands using a shell command-line interpreter
Executes the "chmod" command used to modify permissions
Executes the "mkdir" command used to create folders
Sample has stripped symbol table
Sample tries to set the executable flag
Sets full permissions to files and/or directories
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
Joe Sandbox version:42.0.0 Malachite
Analysis ID:1594466
Start date and time:2025-01-19 02:17:07 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 45s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:arm.elf
Detection:MAL
Classification:mal48.linELF@0/0@0/0
Command:/tmp/arm.elf
PID:6235
Exit Code:1
Exit Code Info:
Killed:False
Standard Output:
GOLDFISHGANG
Standard Error:
  • system is lnxubuntu20
  • arm.elf (PID: 6235, Parent: 6160, MD5: 5ebfcae4fe2471fcc5695c2394773ff1) Arguments: /tmp/arm.elf
    • arm.elf New Fork (PID: 6237, Parent: 6235)
      • arm.elf New Fork (PID: 6243, Parent: 6237)
        • arm.elf New Fork (PID: 6245, Parent: 6243)
        • sh (PID: 6245, Parent: 6243, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "mkdir /kmxxk3s85u/ && >/kmxxk3s85u/kmxxk3s85u && cd /kmxxk3s85u/ >/dev/null"
          • sh New Fork (PID: 6250, Parent: 6245)
          • mkdir (PID: 6250, Parent: 6245, MD5: 088c9d1df5a28ed16c726eca15964cb7) Arguments: mkdir /kmxxk3s85u/
        • arm.elf New Fork (PID: 6251, Parent: 6243)
        • sh (PID: 6251, Parent: 6243, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "mv /tmp/arm.elf /kmxxk3s85u/kmxxk3s85u && chmod 777 /kmxxk3s85u/kmxxk3s85u >/dev/null"
          • sh New Fork (PID: 6253, Parent: 6251)
          • mv (PID: 6253, Parent: 6251, MD5: 504f0590fa482d4da070a702260e3716) Arguments: mv /tmp/arm.elf /kmxxk3s85u/kmxxk3s85u
          • sh New Fork (PID: 6254, Parent: 6251)
          • chmod (PID: 6254, Parent: 6251, MD5: 739483b900c045ae1374d6f53a86a279) Arguments: chmod 777 /kmxxk3s85u/kmxxk3s85u
  • cleanup
No yara matches
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: arm.elfVirustotal: Detection: 44%Perma Link
Source: arm.elfReversingLabs: Detection: 52%
Source: global trafficTCP traffic: 192.168.2.23:48740 -> 85.239.34.134:5683
Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
Source: ELF static info symbol of initial sample.symtab present: no
Source: classification engineClassification label: mal48.linELF@0/0@0/0
Source: /tmp/arm.elf (PID: 6245)Shell command executed: sh -c "mkdir /kmxxk3s85u/ && >/kmxxk3s85u/kmxxk3s85u && cd /kmxxk3s85u/ >/dev/null"Jump to behavior
Source: /tmp/arm.elf (PID: 6251)Shell command executed: sh -c "mv /tmp/arm.elf /kmxxk3s85u/kmxxk3s85u && chmod 777 /kmxxk3s85u/kmxxk3s85u >/dev/null"Jump to behavior
Source: /bin/sh (PID: 6254)Chmod executable: /usr/bin/chmod -> chmod 777 /kmxxk3s85u/kmxxk3s85uJump to behavior
Source: /bin/sh (PID: 6250)Mkdir executable: /usr/bin/mkdir -> mkdir /kmxxk3s85u/Jump to behavior
Source: /usr/bin/chmod (PID: 6254)File: /kmxxk3s85u/kmxxk3s85u (bits: - usr: rwx grp: rwx all: rwx)Jump to behavior
Source: /bin/sh (PID: 6254)Chmod executable with 777: /usr/bin/chmod -> chmod 777 /kmxxk3s85u/kmxxk3s85uJump to behavior
Source: /tmp/arm.elf (PID: 6235)Queries kernel information via 'uname': Jump to behavior
Source: arm.elf, 6235.1.000055aa1305f000.000055aa1318d000.rw-.sdmp, arm.elf, 6237.1.000055aa1305f000.000055aa1318d000.rw-.sdmpBinary or memory string: U!/etc/qemu-binfmt/arm
Source: arm.elf, 6235.1.00007fff044ff000.00007fff04520000.rw-.sdmp, arm.elf, 6237.1.00007fff044ff000.00007fff04520000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-arm/tmp/arm.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/arm.elf
Source: arm.elf, 6235.1.000055aa1305f000.000055aa1318d000.rw-.sdmp, arm.elf, 6237.1.000055aa1305f000.000055aa1318d000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/arm
Source: arm.elf, 6235.1.00007fff044ff000.00007fff04520000.rw-.sdmp, arm.elf, 6237.1.00007fff044ff000.00007fff04520000.rw-.sdmpBinary or memory string: /usr/bin/qemu-arm
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity Information1
Scripting
Valid AccountsWindows Management Instrumentation1
Scripting
Path Interception2
File and Directory Permissions Modification
OS Credential Dumping11
Security Software Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Standard Port
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1594466 Sample: arm.elf Startdate: 19/01/2025 Architecture: LINUX Score: 48 26 85.239.34.134, 48740, 48742, 48744 RAINBOW-HKRainbownetworklimitedHK Russian Federation 2->26 28 109.202.202.202, 80 INIT7CH Switzerland 2->28 30 2 other IPs or domains 2->30 32 Multi AV Scanner detection for submitted file 2->32 10 arm.elf 2->10         started        signatures3 process4 process5 12 arm.elf 10->12         started        process6 14 arm.elf 12->14         started        process7 16 arm.elf sh 14->16         started        18 arm.elf sh 14->18         started        process8 20 sh mv 16->20         started        22 sh chmod 16->22         started        24 sh mkdir 18->24         started       
SourceDetectionScannerLabelLink
arm.elf44%VirustotalBrowse
arm.elf53%ReversingLabsLinux.Trojan.Mirai
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

No contacted domains info
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs
IPDomainCountryFlagASNASN NameMalicious
85.239.34.134
unknownRussian Federation
134121RAINBOW-HKRainbownetworklimitedHKfalse
109.202.202.202
unknownSwitzerland
13030INIT7CHfalse
91.189.91.43
unknownUnited Kingdom
41231CANONICAL-ASGBfalse
91.189.91.42
unknownUnited Kingdom
41231CANONICAL-ASGBfalse
MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
85.239.34.134mips.elfGet hashmaliciousUnknownBrowse
    arm6.elfGet hashmaliciousUnknownBrowse
      arm7.elfGet hashmaliciousUnknownBrowse
        ppc.elfGet hashmaliciousUnknownBrowse
          mips.elfGet hashmaliciousUnknownBrowse
            m68k.elfGet hashmaliciousUnknownBrowse
              sh4.elfGet hashmaliciousUnknownBrowse
                x86.elfGet hashmaliciousUnknownBrowse
                  arm5.elfGet hashmaliciousUnknownBrowse
                    spc.elfGet hashmaliciousUnknownBrowse
                      109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
                      • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
                      91.189.91.43mips.elfGet hashmaliciousUnknownBrowse
                        arm6.elfGet hashmaliciousUnknownBrowse
                          na.elfGet hashmaliciousPrometeiBrowse
                            na.elfGet hashmaliciousPrometeiBrowse
                              bin.sh.elfGet hashmaliciousMiraiBrowse
                                sshd.elfGet hashmaliciousUnknownBrowse
                                  na.elfGet hashmaliciousPrometeiBrowse
                                    sshd.elfGet hashmaliciousUnknownBrowse
                                      Mozi.m.elfGet hashmaliciousMiraiBrowse
                                        na.elfGet hashmaliciousPrometeiBrowse
                                          No context
                                          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                          RAINBOW-HKRainbownetworklimitedHKmips.elfGet hashmaliciousUnknownBrowse
                                          • 85.239.34.134
                                          arm6.elfGet hashmaliciousUnknownBrowse
                                          • 85.239.34.134
                                          arm7.elfGet hashmaliciousUnknownBrowse
                                          • 85.239.34.134
                                          ppc.elfGet hashmaliciousUnknownBrowse
                                          • 85.239.34.134
                                          mips.elfGet hashmaliciousUnknownBrowse
                                          • 85.239.34.134
                                          m68k.elfGet hashmaliciousUnknownBrowse
                                          • 85.239.34.134
                                          sh4.elfGet hashmaliciousUnknownBrowse
                                          • 85.239.34.134
                                          x86.elfGet hashmaliciousUnknownBrowse
                                          • 85.239.34.134
                                          arm5.elfGet hashmaliciousUnknownBrowse
                                          • 85.239.34.134
                                          spc.elfGet hashmaliciousUnknownBrowse
                                          • 85.239.34.134
                                          CANONICAL-ASGBmips.elfGet hashmaliciousUnknownBrowse
                                          • 91.189.91.42
                                          arm6.elfGet hashmaliciousUnknownBrowse
                                          • 91.189.91.42
                                          na.elfGet hashmaliciousPrometeiBrowse
                                          • 91.189.91.42
                                          na.elfGet hashmaliciousPrometeiBrowse
                                          • 91.189.91.42
                                          bin.sh.elfGet hashmaliciousMiraiBrowse
                                          • 91.189.91.42
                                          sshd.elfGet hashmaliciousUnknownBrowse
                                          • 91.189.91.42
                                          na.elfGet hashmaliciousPrometeiBrowse
                                          • 91.189.91.42
                                          sshd.elfGet hashmaliciousUnknownBrowse
                                          • 91.189.91.42
                                          Mozi.m.elfGet hashmaliciousMiraiBrowse
                                          • 91.189.91.42
                                          na.elfGet hashmaliciousPrometeiBrowse
                                          • 91.189.91.42
                                          CANONICAL-ASGBmips.elfGet hashmaliciousUnknownBrowse
                                          • 91.189.91.42
                                          arm6.elfGet hashmaliciousUnknownBrowse
                                          • 91.189.91.42
                                          na.elfGet hashmaliciousPrometeiBrowse
                                          • 91.189.91.42
                                          na.elfGet hashmaliciousPrometeiBrowse
                                          • 91.189.91.42
                                          bin.sh.elfGet hashmaliciousMiraiBrowse
                                          • 91.189.91.42
                                          sshd.elfGet hashmaliciousUnknownBrowse
                                          • 91.189.91.42
                                          na.elfGet hashmaliciousPrometeiBrowse
                                          • 91.189.91.42
                                          sshd.elfGet hashmaliciousUnknownBrowse
                                          • 91.189.91.42
                                          Mozi.m.elfGet hashmaliciousMiraiBrowse
                                          • 91.189.91.42
                                          na.elfGet hashmaliciousPrometeiBrowse
                                          • 91.189.91.42
                                          INIT7CHmips.elfGet hashmaliciousUnknownBrowse
                                          • 109.202.202.202
                                          arm6.elfGet hashmaliciousUnknownBrowse
                                          • 109.202.202.202
                                          na.elfGet hashmaliciousPrometeiBrowse
                                          • 109.202.202.202
                                          na.elfGet hashmaliciousPrometeiBrowse
                                          • 109.202.202.202
                                          bin.sh.elfGet hashmaliciousMiraiBrowse
                                          • 109.202.202.202
                                          sshd.elfGet hashmaliciousUnknownBrowse
                                          • 109.202.202.202
                                          na.elfGet hashmaliciousPrometeiBrowse
                                          • 109.202.202.202
                                          sshd.elfGet hashmaliciousUnknownBrowse
                                          • 109.202.202.202
                                          Mozi.m.elfGet hashmaliciousMiraiBrowse
                                          • 109.202.202.202
                                          na.elfGet hashmaliciousPrometeiBrowse
                                          • 109.202.202.202
                                          No context
                                          No context
                                          No created / dropped files found
                                          File type:ELF 32-bit LSB executable, ARM, version 1 (ARM), statically linked, stripped
                                          Entropy (8bit):6.095490263450198
                                          TrID:
                                          • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                          File name:arm.elf
                                          File size:62'872 bytes
                                          MD5:fc275b45dfc2bac93e56c0790c701b0b
                                          SHA1:077945a1e7aecea4a0e15c913219cac058a3ba8d
                                          SHA256:24867a7e0571e2ec6173d46cf91fc693881a8767a23f1a1c3ab475a7df4d9b21
                                          SHA512:d84f5078184f09bc0dcc5da9d1791eabf9ab843ec7d5a444a679816b295519208f38aac766618f3af8f4068d0c8af4433567bb3a6ca324b3dee56de541778175
                                          SSDEEP:1536:D+2pQgZexe3z0s7mNIvTezb9ghIvxpoV4CrhCWliWWWWWWWWWWWWWpCNOoQ1FHXW:D+2pQgZexe3z0s7EIvTOhIIvb+53FHXW
                                          TLSH:FC534B52B9809752C1E025B7FE0E018C376613FDD1DF72038E65AF2133D79AA0EEA655
                                          File Content Preview:.ELF...a..........(.........4...........4. ...(......................................................... '..........Q.td..................................-...L."....7..........0@-.\P...0....S.0...P@...0... ....R......0...0...........0... ....R..... 0....S

                                          ELF header

                                          Class:ELF32
                                          Data:2's complement, little endian
                                          Version:1 (current)
                                          Machine:ARM
                                          Version Number:0x1
                                          Type:EXEC (Executable file)
                                          OS/ABI:ARM - ABI
                                          ABI Version:0
                                          Entry Point Address:0x8190
                                          Flags:0x202
                                          ELF Header Size:52
                                          Program Header Offset:52
                                          Program Header Size:32
                                          Number of Program Headers:3
                                          Section Header Offset:62352
                                          Section Header Size:40
                                          Number of Section Headers:13
                                          Header String Table Index:12
                                          NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                          NULL0x00x00x00x00x0000
                                          .initPROGBITS0x80940x940x180x00x6AX004
                                          .textPROGBITS0x80b00xb00xdc440x00x6AX0016
                                          .finiPROGBITS0x15cf40xdcf40x140x00x6AX004
                                          .rodataPROGBITS0x15d080xdd080x13800x00x2A004
                                          .eh_framePROGBITS0x180880xf0880x40x00x3WA004
                                          .ctorsPROGBITS0x1808c0xf08c0x80x00x3WA004
                                          .dtorsPROGBITS0x180940xf0940x80x00x3WA004
                                          .jcrPROGBITS0x1809c0xf09c0x40x00x3WA004
                                          .dataPROGBITS0x180a00xf0a00x2800x00x3WA004
                                          .bssNOBITS0x183200xf3200x24880x00x3WA004
                                          .ARM.attributesARM_ATTRIBUTES0x00xf3200x100x00x0001
                                          .shstrtabSTRTAB0x00xf3300x5d0x00x0001
                                          TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                          LOAD0x00x80000x80000xf0880xf0886.12220x5R E0x1000.init .text .fini .rodata
                                          LOAD0xf0880x180880x180880x2980x27203.68870x6RW 0x1000.eh_frame .ctors .dtors .jcr .data .bss
                                          GNU_STACK0x00x00x00x00x00.00000x7RWE0x4

                                          Download Network PCAP: filteredfull

                                          • Total Packets: 117
                                          • 5683 undefined
                                          • 443 (HTTPS)
                                          • 80 (HTTP)
                                          TimestampSource PortDest PortSource IPDest IP
                                          Jan 19, 2025 02:17:58.233659029 CET487405683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:17:58.238845110 CET56834874085.239.34.134192.168.2.23
                                          Jan 19, 2025 02:17:58.239109039 CET487405683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:17:58.239312887 CET487405683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:17:58.244405985 CET56834874085.239.34.134192.168.2.23
                                          Jan 19, 2025 02:18:00.726000071 CET42836443192.168.2.2391.189.91.43
                                          Jan 19, 2025 02:18:01.494040966 CET4251680192.168.2.23109.202.202.202
                                          Jan 19, 2025 02:18:15.316207886 CET43928443192.168.2.2391.189.91.42
                                          Jan 19, 2025 02:18:27.606484890 CET42836443192.168.2.2391.189.91.43
                                          Jan 19, 2025 02:18:31.697870016 CET4251680192.168.2.23109.202.202.202
                                          Jan 19, 2025 02:18:47.536638975 CET56834874085.239.34.134192.168.2.23
                                          Jan 19, 2025 02:18:47.537055016 CET487405683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:18:47.542115927 CET56834874085.239.34.134192.168.2.23
                                          Jan 19, 2025 02:18:48.540220976 CET487425683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:18:48.545680046 CET56834874285.239.34.134192.168.2.23
                                          Jan 19, 2025 02:18:48.546061039 CET487425683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:18:48.546061039 CET487425683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:18:48.551395893 CET56834874285.239.34.134192.168.2.23
                                          Jan 19, 2025 02:18:50.311358929 CET56834874285.239.34.134192.168.2.23
                                          Jan 19, 2025 02:18:50.311908007 CET487425683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:18:50.317362070 CET56834874285.239.34.134192.168.2.23
                                          Jan 19, 2025 02:18:51.314944029 CET487445683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:18:51.320446014 CET56834874485.239.34.134192.168.2.23
                                          Jan 19, 2025 02:18:51.320724010 CET487445683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:18:51.320786953 CET487445683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:18:51.326118946 CET56834874485.239.34.134192.168.2.23
                                          Jan 19, 2025 02:18:53.092456102 CET56834874485.239.34.134192.168.2.23
                                          Jan 19, 2025 02:18:53.093133926 CET487445683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:18:53.098496914 CET56834874485.239.34.134192.168.2.23
                                          Jan 19, 2025 02:18:54.098033905 CET487465683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:18:54.103470087 CET56834874685.239.34.134192.168.2.23
                                          Jan 19, 2025 02:18:54.103900909 CET487465683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:18:54.103900909 CET487465683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:18:54.109492064 CET56834874685.239.34.134192.168.2.23
                                          Jan 19, 2025 02:18:55.854336977 CET56834874685.239.34.134192.168.2.23
                                          Jan 19, 2025 02:18:55.854624987 CET487465683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:18:55.860120058 CET56834874685.239.34.134192.168.2.23
                                          Jan 19, 2025 02:18:56.270566940 CET43928443192.168.2.2391.189.91.42
                                          Jan 19, 2025 02:18:56.858468056 CET487485683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:18:56.863919973 CET56834874885.239.34.134192.168.2.23
                                          Jan 19, 2025 02:18:56.864192009 CET487485683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:18:56.864192009 CET487485683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:18:56.869342089 CET56834874885.239.34.134192.168.2.23
                                          Jan 19, 2025 02:18:58.644606113 CET56834874885.239.34.134192.168.2.23
                                          Jan 19, 2025 02:18:58.644927979 CET487485683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:18:58.651139975 CET56834874885.239.34.134192.168.2.23
                                          Jan 19, 2025 02:18:59.648907900 CET487505683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:18:59.654510975 CET56834875085.239.34.134192.168.2.23
                                          Jan 19, 2025 02:18:59.654927969 CET487505683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:18:59.654928923 CET487505683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:18:59.660410881 CET56834875085.239.34.134192.168.2.23
                                          Jan 19, 2025 02:19:01.419127941 CET56834875085.239.34.134192.168.2.23
                                          Jan 19, 2025 02:19:01.419579029 CET487505683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:19:01.424871922 CET56834875085.239.34.134192.168.2.23
                                          Jan 19, 2025 02:19:02.422962904 CET487525683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:19:02.428621054 CET56834875285.239.34.134192.168.2.23
                                          Jan 19, 2025 02:19:02.428865910 CET487525683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:19:02.428865910 CET487525683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:19:02.434108973 CET56834875285.239.34.134192.168.2.23
                                          Jan 19, 2025 02:19:04.203797102 CET56834875285.239.34.134192.168.2.23
                                          Jan 19, 2025 02:19:04.204201937 CET487525683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:19:04.209533930 CET56834875285.239.34.134192.168.2.23
                                          Jan 19, 2025 02:19:05.208539009 CET487545683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:19:05.214087009 CET56834875485.239.34.134192.168.2.23
                                          Jan 19, 2025 02:19:05.214298964 CET487545683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:19:05.214298964 CET487545683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:19:05.219527006 CET56834875485.239.34.134192.168.2.23
                                          Jan 19, 2025 02:19:06.996797085 CET56834875485.239.34.134192.168.2.23
                                          Jan 19, 2025 02:19:06.997437954 CET487545683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:19:07.002876997 CET56834875485.239.34.134192.168.2.23
                                          Jan 19, 2025 02:19:08.001199007 CET487565683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:19:08.035228014 CET56834875685.239.34.134192.168.2.23
                                          Jan 19, 2025 02:19:08.035396099 CET487565683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:19:08.035691977 CET487565683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:19:08.040987968 CET56834875685.239.34.134192.168.2.23
                                          Jan 19, 2025 02:19:09.793939114 CET56834875685.239.34.134192.168.2.23
                                          Jan 19, 2025 02:19:09.794399023 CET487565683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:19:09.799792051 CET56834875685.239.34.134192.168.2.23
                                          Jan 19, 2025 02:19:10.797404051 CET487585683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:19:10.804083109 CET56834875885.239.34.134192.168.2.23
                                          Jan 19, 2025 02:19:10.804173946 CET487585683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:19:10.804224968 CET487585683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:19:10.809756041 CET56834875885.239.34.134192.168.2.23
                                          Jan 19, 2025 02:19:12.557547092 CET56834875885.239.34.134192.168.2.23
                                          Jan 19, 2025 02:19:12.557847977 CET487585683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:19:12.562875032 CET56834875885.239.34.134192.168.2.23
                                          Jan 19, 2025 02:19:13.561559916 CET487605683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:19:13.566919088 CET56834876085.239.34.134192.168.2.23
                                          Jan 19, 2025 02:19:13.567158937 CET487605683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:19:13.567159891 CET487605683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:19:13.572046995 CET56834876085.239.34.134192.168.2.23
                                          Jan 19, 2025 02:19:15.342585087 CET56834876085.239.34.134192.168.2.23
                                          Jan 19, 2025 02:19:15.342895985 CET487605683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:19:15.349571943 CET56834876085.239.34.134192.168.2.23
                                          Jan 19, 2025 02:19:16.347103119 CET487625683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:19:16.354069948 CET56834876285.239.34.134192.168.2.23
                                          Jan 19, 2025 02:19:16.354151964 CET487625683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:19:16.354151964 CET487625683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:19:16.360872030 CET56834876285.239.34.134192.168.2.23
                                          Jan 19, 2025 02:19:18.106615067 CET56834876285.239.34.134192.168.2.23
                                          Jan 19, 2025 02:19:18.107145071 CET487625683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:19:18.112236023 CET56834876285.239.34.134192.168.2.23
                                          Jan 19, 2025 02:19:19.111907005 CET487645683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:19:19.117130041 CET56834876485.239.34.134192.168.2.23
                                          Jan 19, 2025 02:19:19.117259979 CET487645683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:19:19.117260933 CET487645683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:19:19.122313976 CET56834876485.239.34.134192.168.2.23
                                          Jan 19, 2025 02:19:20.891443968 CET56834876485.239.34.134192.168.2.23
                                          Jan 19, 2025 02:19:20.891935110 CET487645683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:19:20.897088051 CET56834876485.239.34.134192.168.2.23
                                          Jan 19, 2025 02:19:21.895095110 CET487665683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:19:21.900223017 CET56834876685.239.34.134192.168.2.23
                                          Jan 19, 2025 02:19:21.900307894 CET487665683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:19:21.900347948 CET487665683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:19:21.905500889 CET56834876685.239.34.134192.168.2.23
                                          Jan 19, 2025 02:19:23.652482033 CET56834876685.239.34.134192.168.2.23
                                          Jan 19, 2025 02:19:23.652751923 CET487665683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:19:23.658108950 CET56834876685.239.34.134192.168.2.23
                                          Jan 19, 2025 02:19:24.655273914 CET487685683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:19:24.660641909 CET56834876885.239.34.134192.168.2.23
                                          Jan 19, 2025 02:19:24.660784960 CET487685683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:19:24.660847902 CET487685683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:19:24.666265965 CET56834876885.239.34.134192.168.2.23
                                          Jan 19, 2025 02:19:26.436433077 CET56834876885.239.34.134192.168.2.23
                                          Jan 19, 2025 02:19:26.436981916 CET487685683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:19:26.442090988 CET56834876885.239.34.134192.168.2.23
                                          Jan 19, 2025 02:19:27.440382004 CET487705683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:19:27.445813894 CET56834877085.239.34.134192.168.2.23
                                          Jan 19, 2025 02:19:27.446010113 CET487705683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:19:27.446046114 CET487705683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:19:27.451059103 CET56834877085.239.34.134192.168.2.23
                                          Jan 19, 2025 02:19:29.200414896 CET56834877085.239.34.134192.168.2.23
                                          Jan 19, 2025 02:19:29.200781107 CET487705683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:19:29.205959082 CET56834877085.239.34.134192.168.2.23
                                          Jan 19, 2025 02:19:30.203800917 CET487725683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:19:30.209116936 CET56834877285.239.34.134192.168.2.23
                                          Jan 19, 2025 02:19:30.209316969 CET487725683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:19:30.209395885 CET487725683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:19:30.214663982 CET56834877285.239.34.134192.168.2.23
                                          Jan 19, 2025 02:19:31.964093924 CET56834877285.239.34.134192.168.2.23
                                          Jan 19, 2025 02:19:31.964533091 CET487725683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:19:31.969480038 CET56834877285.239.34.134192.168.2.23
                                          Jan 19, 2025 02:19:32.967849016 CET487745683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:19:32.973102093 CET56834877485.239.34.134192.168.2.23
                                          Jan 19, 2025 02:19:32.973198891 CET487745683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:19:32.973241091 CET487745683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:19:32.978318930 CET56834877485.239.34.134192.168.2.23
                                          Jan 19, 2025 02:19:34.746556044 CET56834877485.239.34.134192.168.2.23
                                          Jan 19, 2025 02:19:34.747114897 CET487745683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:19:34.752646923 CET56834877485.239.34.134192.168.2.23
                                          Jan 19, 2025 02:19:35.751128912 CET487765683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:19:35.756712914 CET56834877685.239.34.134192.168.2.23
                                          Jan 19, 2025 02:19:35.756998062 CET487765683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:19:35.756998062 CET487765683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:19:35.762331963 CET56834877685.239.34.134192.168.2.23
                                          Jan 19, 2025 02:19:37.512140989 CET56834877685.239.34.134192.168.2.23
                                          Jan 19, 2025 02:19:37.512413025 CET487765683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:19:37.517791033 CET56834877685.239.34.134192.168.2.23
                                          Jan 19, 2025 02:19:38.515022039 CET487785683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:19:38.520519018 CET56834877885.239.34.134192.168.2.23
                                          Jan 19, 2025 02:19:38.520910978 CET487785683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:19:38.520911932 CET487785683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:19:38.526293039 CET56834877885.239.34.134192.168.2.23
                                          Jan 19, 2025 02:19:40.277153015 CET56834877885.239.34.134192.168.2.23
                                          Jan 19, 2025 02:19:40.277692080 CET487785683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:19:40.282828093 CET56834877885.239.34.134192.168.2.23
                                          Jan 19, 2025 02:19:41.282207966 CET487805683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:19:41.288167953 CET56834878085.239.34.134192.168.2.23
                                          Jan 19, 2025 02:19:41.288382053 CET487805683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:19:41.288465023 CET487805683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:19:41.293962955 CET56834878085.239.34.134192.168.2.23
                                          Jan 19, 2025 02:19:43.043436050 CET56834878085.239.34.134192.168.2.23
                                          Jan 19, 2025 02:19:43.043812990 CET487805683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:19:43.049276114 CET56834878085.239.34.134192.168.2.23
                                          Jan 19, 2025 02:19:44.048517942 CET487825683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:19:44.054332972 CET56834878285.239.34.134192.168.2.23
                                          Jan 19, 2025 02:19:44.054548979 CET487825683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:19:44.054548979 CET487825683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:19:44.059566975 CET56834878285.239.34.134192.168.2.23
                                          Jan 19, 2025 02:19:45.828054905 CET56834878285.239.34.134192.168.2.23
                                          Jan 19, 2025 02:19:45.828784943 CET487825683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:19:45.833801985 CET56834878285.239.34.134192.168.2.23
                                          Jan 19, 2025 02:19:46.832628012 CET487845683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:19:46.838377953 CET56834878485.239.34.134192.168.2.23
                                          Jan 19, 2025 02:19:46.838609934 CET487845683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:19:46.838609934 CET487845683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:19:46.844525099 CET56834878485.239.34.134192.168.2.23
                                          Jan 19, 2025 02:19:48.589992046 CET56834878485.239.34.134192.168.2.23
                                          Jan 19, 2025 02:19:48.590406895 CET487845683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:19:48.595880985 CET56834878485.239.34.134192.168.2.23
                                          Jan 19, 2025 02:19:49.594419003 CET487865683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:19:49.599898100 CET56834878685.239.34.134192.168.2.23
                                          Jan 19, 2025 02:19:49.599994898 CET487865683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:19:49.600218058 CET487865683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:19:49.605227947 CET56834878685.239.34.134192.168.2.23
                                          Jan 19, 2025 02:19:51.359107971 CET56834878685.239.34.134192.168.2.23
                                          Jan 19, 2025 02:19:51.359631062 CET487865683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:19:51.364732981 CET56834878685.239.34.134192.168.2.23
                                          Jan 19, 2025 02:19:52.362787962 CET487885683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:19:52.368187904 CET56834878885.239.34.134192.168.2.23
                                          Jan 19, 2025 02:19:52.368510962 CET487885683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:19:52.368511915 CET487885683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:19:52.373846054 CET56834878885.239.34.134192.168.2.23
                                          Jan 19, 2025 02:19:54.140178919 CET56834878885.239.34.134192.168.2.23
                                          Jan 19, 2025 02:19:54.140501022 CET487885683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:19:54.145349979 CET56834878885.239.34.134192.168.2.23
                                          Jan 19, 2025 02:19:55.145251036 CET487905683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:19:55.150345087 CET56834879085.239.34.134192.168.2.23
                                          Jan 19, 2025 02:19:55.150542021 CET487905683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:19:55.150695086 CET487905683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:19:55.155642033 CET56834879085.239.34.134192.168.2.23
                                          Jan 19, 2025 02:19:56.904546976 CET56834879085.239.34.134192.168.2.23
                                          Jan 19, 2025 02:19:56.905302048 CET487905683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:19:56.910789967 CET56834879085.239.34.134192.168.2.23
                                          Jan 19, 2025 02:19:57.910954952 CET487925683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:19:57.917046070 CET56834879285.239.34.134192.168.2.23
                                          Jan 19, 2025 02:19:57.917460918 CET487925683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:19:57.917460918 CET487925683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:19:57.923043013 CET56834879285.239.34.134192.168.2.23
                                          Jan 19, 2025 02:19:59.685117006 CET56834879285.239.34.134192.168.2.23
                                          Jan 19, 2025 02:19:59.685517073 CET487925683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:19:59.691801071 CET56834879285.239.34.134192.168.2.23
                                          Jan 19, 2025 02:20:00.688782930 CET487945683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:20:00.695070028 CET56834879485.239.34.134192.168.2.23
                                          Jan 19, 2025 02:20:00.695211887 CET487945683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:20:00.695211887 CET487945683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:20:00.700479031 CET56834879485.239.34.134192.168.2.23

                                          System Behavior

                                          Start time (UTC):01:17:57
                                          Start date (UTC):19/01/2025
                                          Path:/tmp/arm.elf
                                          Arguments:/tmp/arm.elf
                                          File size:4956856 bytes
                                          MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                          Start time (UTC):01:17:57
                                          Start date (UTC):19/01/2025
                                          Path:/tmp/arm.elf
                                          Arguments:-
                                          File size:4956856 bytes
                                          MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                          Start time (UTC):01:17:57
                                          Start date (UTC):19/01/2025
                                          Path:/tmp/arm.elf
                                          Arguments:-
                                          File size:4956856 bytes
                                          MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                          Start time (UTC):01:17:57
                                          Start date (UTC):19/01/2025
                                          Path:/tmp/arm.elf
                                          Arguments:-
                                          File size:4956856 bytes
                                          MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                          Start time (UTC):01:17:57
                                          Start date (UTC):19/01/2025
                                          Path:/bin/sh
                                          Arguments:sh -c "mkdir /kmxxk3s85u/ && >/kmxxk3s85u/kmxxk3s85u && cd /kmxxk3s85u/ >/dev/null"
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                          Start time (UTC):01:17:57
                                          Start date (UTC):19/01/2025
                                          Path:/bin/sh
                                          Arguments:-
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                          Start time (UTC):01:17:57
                                          Start date (UTC):19/01/2025
                                          Path:/usr/bin/mkdir
                                          Arguments:mkdir /kmxxk3s85u/
                                          File size:88408 bytes
                                          MD5 hash:088c9d1df5a28ed16c726eca15964cb7

                                          Start time (UTC):01:17:57
                                          Start date (UTC):19/01/2025
                                          Path:/tmp/arm.elf
                                          Arguments:-
                                          File size:4956856 bytes
                                          MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                          Start time (UTC):01:17:57
                                          Start date (UTC):19/01/2025
                                          Path:/bin/sh
                                          Arguments:sh -c "mv /tmp/arm.elf /kmxxk3s85u/kmxxk3s85u && chmod 777 /kmxxk3s85u/kmxxk3s85u >/dev/null"
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                          Start time (UTC):01:17:57
                                          Start date (UTC):19/01/2025
                                          Path:/bin/sh
                                          Arguments:-
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                          Start time (UTC):01:17:57
                                          Start date (UTC):19/01/2025
                                          Path:/usr/bin/mv
                                          Arguments:mv /tmp/arm.elf /kmxxk3s85u/kmxxk3s85u
                                          File size:149888 bytes
                                          MD5 hash:504f0590fa482d4da070a702260e3716

                                          Start time (UTC):01:17:57
                                          Start date (UTC):19/01/2025
                                          Path:/bin/sh
                                          Arguments:-
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                          Start time (UTC):01:17:57
                                          Start date (UTC):19/01/2025
                                          Path:/usr/bin/chmod
                                          Arguments:chmod 777 /kmxxk3s85u/kmxxk3s85u
                                          File size:63864 bytes
                                          MD5 hash:739483b900c045ae1374d6f53a86a279