Edit tour

Linux Analysis Report
46.19.143.26-mips-2025-03-01T06_09_25.elf

Overview

General Information

Sample name:46.19.143.26-mips-2025-03-01T06_09_25.elf
Analysis ID:1644706
MD5:a618f8a57f8b7816072bfd697a345f50
SHA1:11fa49e2c99138d12e4b266fceba5f73113e0952
SHA256:787da52743cd187df1353d1f85f243cf98d01d65466034d0cbd99900274ba0a2
Tags:elfuser-threatquery
Infos:

Detection

Score:60
Range:0 - 100

Signatures

Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Connects to many ports of the same IP (likely port scanning)
Detected TCP or UDP traffic on non-standard ports
Executes the "rm" command used to delete files or directories
Sample has stripped symbol table
Sample listens on a socket
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
Joe Sandbox version:42.0.0 Malachite
Analysis ID:1644706
Start date and time:2025-03-20 21:17:15 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 26s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:46.19.143.26-mips-2025-03-01T06_09_25.elf
Detection:MAL
Classification:mal60.troj.linELF@0/0@0/0
Command:/tmp/46.19.143.26-mips-2025-03-01T06_09_25.elf
PID:5501
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
For God so loved the world, that he gave his only begotten Son, that whosoever believeth in him should not perish, but have everlasting life
Standard Error:
  • system is lnxubuntu20
  • dash New Fork (PID: 5507, Parent: 3632)
  • rm (PID: 5507, Parent: 3632, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.mEkGBMS8sb /tmp/tmp.qcBubsum5M /tmp/tmp.7pqsYHy482
  • dash New Fork (PID: 5508, Parent: 3632)
  • cat (PID: 5508, Parent: 3632, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /tmp/tmp.mEkGBMS8sb
  • dash New Fork (PID: 5509, Parent: 3632)
  • head (PID: 5509, Parent: 3632, MD5: fd96a67145172477dd57131396fc9608) Arguments: head -n 10
  • dash New Fork (PID: 5510, Parent: 3632)
  • tr (PID: 5510, Parent: 3632, MD5: fbd1402dd9f72d8ebfff00ce7c3a7bb5) Arguments: tr -d \\000-\\011\\013\\014\\016-\\037
  • dash New Fork (PID: 5511, Parent: 3632)
  • cut (PID: 5511, Parent: 3632, MD5: d8ed0ea8f22c0de0f8692d4d9f1759d3) Arguments: cut -c -80
  • dash New Fork (PID: 5512, Parent: 3632)
  • cat (PID: 5512, Parent: 3632, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /tmp/tmp.mEkGBMS8sb
  • dash New Fork (PID: 5513, Parent: 3632)
  • head (PID: 5513, Parent: 3632, MD5: fd96a67145172477dd57131396fc9608) Arguments: head -n 10
  • dash New Fork (PID: 5514, Parent: 3632)
  • tr (PID: 5514, Parent: 3632, MD5: fbd1402dd9f72d8ebfff00ce7c3a7bb5) Arguments: tr -d \\000-\\011\\013\\014\\016-\\037
  • dash New Fork (PID: 5515, Parent: 3632)
  • cut (PID: 5515, Parent: 3632, MD5: d8ed0ea8f22c0de0f8692d4d9f1759d3) Arguments: cut -c -80
  • dash New Fork (PID: 5518, Parent: 3632)
  • rm (PID: 5518, Parent: 3632, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.mEkGBMS8sb /tmp/tmp.qcBubsum5M /tmp/tmp.7pqsYHy482
  • cleanup
No yara matches
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: 46.19.143.26-mips-2025-03-01T06_09_25.elfAvira: detected
Source: 46.19.143.26-mips-2025-03-01T06_09_25.elfReversingLabs: Detection: 16%
Source: unknownHTTPS traffic detected: 54.217.10.153:443 -> 192.168.2.14:34592 version: TLS 1.2

Networking

barindex
Source: global trafficTCP traffic: 209.200.246.178 ports 50749,56190,5102,7680,29486,7679,12016,41763,49722,40237,44859,8080,35086,40217,0,64839,50182,3,26141,54780,30751,5,6,50464,8,47563,52962
Source: global trafficTCP traffic: 192.168.2.14:39854 -> 209.200.246.178:35086
Source: /tmp/46.19.143.26-mips-2025-03-01T06_09_25.elf (PID: 5503)Socket: 127.0.0.1:22448Jump to behavior
Source: unknownTCP traffic detected without corresponding DNS query: 209.200.246.178
Source: unknownTCP traffic detected without corresponding DNS query: 209.200.246.178
Source: unknownTCP traffic detected without corresponding DNS query: 209.200.246.178
Source: unknownTCP traffic detected without corresponding DNS query: 209.200.246.178
Source: unknownTCP traffic detected without corresponding DNS query: 209.200.246.178
Source: unknownTCP traffic detected without corresponding DNS query: 209.200.246.178
Source: unknownTCP traffic detected without corresponding DNS query: 185.125.190.26
Source: unknownTCP traffic detected without corresponding DNS query: 209.200.246.178
Source: unknownTCP traffic detected without corresponding DNS query: 209.200.246.178
Source: unknownTCP traffic detected without corresponding DNS query: 209.200.246.178
Source: unknownTCP traffic detected without corresponding DNS query: 209.200.246.178
Source: unknownTCP traffic detected without corresponding DNS query: 209.200.246.178
Source: unknownTCP traffic detected without corresponding DNS query: 209.200.246.178
Source: unknownTCP traffic detected without corresponding DNS query: 209.200.246.178
Source: unknownTCP traffic detected without corresponding DNS query: 209.200.246.178
Source: unknownTCP traffic detected without corresponding DNS query: 209.200.246.178
Source: unknownTCP traffic detected without corresponding DNS query: 209.200.246.178
Source: unknownTCP traffic detected without corresponding DNS query: 209.200.246.178
Source: unknownTCP traffic detected without corresponding DNS query: 209.200.246.178
Source: unknownTCP traffic detected without corresponding DNS query: 209.200.246.178
Source: unknownTCP traffic detected without corresponding DNS query: 209.200.246.178
Source: unknownTCP traffic detected without corresponding DNS query: 209.200.246.178
Source: unknownTCP traffic detected without corresponding DNS query: 185.125.190.26
Source: unknownTCP traffic detected without corresponding DNS query: 209.200.246.178
Source: unknownTCP traffic detected without corresponding DNS query: 209.200.246.178
Source: unknownTCP traffic detected without corresponding DNS query: 209.200.246.178
Source: unknownTCP traffic detected without corresponding DNS query: 209.200.246.178
Source: unknownTCP traffic detected without corresponding DNS query: 209.200.246.178
Source: unknownTCP traffic detected without corresponding DNS query: 209.200.246.178
Source: unknownTCP traffic detected without corresponding DNS query: 209.200.246.178
Source: unknownTCP traffic detected without corresponding DNS query: 209.200.246.178
Source: unknownTCP traffic detected without corresponding DNS query: 209.200.246.178
Source: unknownTCP traffic detected without corresponding DNS query: 209.200.246.178
Source: unknownTCP traffic detected without corresponding DNS query: 209.200.246.178
Source: unknownTCP traffic detected without corresponding DNS query: 209.200.246.178
Source: unknownTCP traffic detected without corresponding DNS query: 209.200.246.178
Source: unknownTCP traffic detected without corresponding DNS query: 209.200.246.178
Source: unknownTCP traffic detected without corresponding DNS query: 209.200.246.178
Source: unknownTCP traffic detected without corresponding DNS query: 209.200.246.178
Source: unknownTCP traffic detected without corresponding DNS query: 209.200.246.178
Source: unknownTCP traffic detected without corresponding DNS query: 209.200.246.178
Source: unknownTCP traffic detected without corresponding DNS query: 209.200.246.178
Source: unknownTCP traffic detected without corresponding DNS query: 209.200.246.178
Source: unknownTCP traffic detected without corresponding DNS query: 209.200.246.178
Source: unknownTCP traffic detected without corresponding DNS query: 209.200.246.178
Source: unknownTCP traffic detected without corresponding DNS query: 209.200.246.178
Source: unknownTCP traffic detected without corresponding DNS query: 209.200.246.178
Source: unknownTCP traffic detected without corresponding DNS query: 209.200.246.178
Source: unknownTCP traffic detected without corresponding DNS query: 209.200.246.178
Source: unknownTCP traffic detected without corresponding DNS query: 209.200.246.178
Source: 46.19.143.26-mips-2025-03-01T06_09_25.elf, 5501.1.00007f49f0455000.00007f49f045c000.rw-.sdmpString found in binary or memory: http://0/t/wget.sh
Source: unknownNetwork traffic detected: HTTP traffic on port 34592 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 34592
Source: unknownNetwork traffic detected: HTTP traffic on port 46540 -> 443
Source: unknownHTTPS traffic detected: 54.217.10.153:443 -> 192.168.2.14:34592 version: TLS 1.2
Source: ELF static info symbol of initial sample.symtab present: no
Source: classification engineClassification label: mal60.troj.linELF@0/0@0/0
Source: /usr/bin/dash (PID: 5507)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.mEkGBMS8sb /tmp/tmp.qcBubsum5M /tmp/tmp.7pqsYHy482Jump to behavior
Source: /usr/bin/dash (PID: 5518)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.mEkGBMS8sb /tmp/tmp.qcBubsum5M /tmp/tmp.7pqsYHy482Jump to behavior
Source: /tmp/46.19.143.26-mips-2025-03-01T06_09_25.elf (PID: 5501)Queries kernel information via 'uname': Jump to behavior
Source: 46.19.143.26-mips-2025-03-01T06_09_25.elf, 5501.1.00007ffde5480000.00007ffde54a1000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-mips/tmp/46.19.143.26-mips-2025-03-01T06_09_25.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/46.19.143.26-mips-2025-03-01T06_09_25.elf
Source: 46.19.143.26-mips-2025-03-01T06_09_25.elf, 5501.1.000055a0cff1e000.000055a0cffa5000.rw-.sdmpBinary or memory string: U!/etc/qemu-binfmt/mips
Source: 46.19.143.26-mips-2025-03-01T06_09_25.elf, 5501.1.000055a0cff1e000.000055a0cffa5000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/mips
Source: 46.19.143.26-mips-2025-03-01T06_09_25.elf, 5501.1.00007ffde5480000.00007ffde54a1000.rw-.sdmpBinary or memory string: /usr/bin/qemu-mips
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
File Deletion
OS Credential Dumping11
Security Software Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Standard Port
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1644706 Sample: 46.19.143.26-mips-2025-03-0... Startdate: 20/03/2025 Architecture: LINUX Score: 60 17 209.200.246.178, 12016, 26141, 29486 ADDD2NET-INCUS United States 2->17 19 185.125.190.26, 443 CANONICAL-ASGB United Kingdom 2->19 21 54.217.10.153, 34592, 443 AMAZON-02US United States 2->21 23 Antivirus / Scanner detection for submitted sample 2->23 25 Multi AV Scanner detection for submitted file 2->25 27 Connects to many ports of the same IP (likely port scanning) 2->27 7 46.19.143.26-mips-2025-03-01T06_09_25.elf 2->7         started        9 dash rm 2->9         started        11 dash cut 2->11         started        13 8 other processes 2->13 signatures3 process4 process5 15 46.19.143.26-mips-2025-03-01T06_09_25.elf 7->15         started       

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
46.19.143.26-mips-2025-03-01T06_09_25.elf17%ReversingLabsLinux.Trojan.Mirai
46.19.143.26-mips-2025-03-01T06_09_25.elf100%AviraEXP/ELF.Agent.J.8
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

No contacted domains info
NameSourceMaliciousAntivirus DetectionReputation
http://0/t/wget.sh46.19.143.26-mips-2025-03-01T06_09_25.elf, 5501.1.00007f49f0455000.00007f49f045c000.rw-.sdmpfalse
    high
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    54.217.10.153
    unknownUnited States
    16509AMAZON-02USfalse
    185.125.190.26
    unknownUnited Kingdom
    41231CANONICAL-ASGBfalse
    209.200.246.178
    unknownUnited States
    15244ADDD2NET-INCUStrue
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    54.217.10.153dlr.sh4.elfGet hashmaliciousUnknownBrowse
      i686.elfGet hashmaliciousGafgyt, MiraiBrowse
        miner.elfGet hashmaliciousUnknownBrowse
          psmips.elfGet hashmaliciousUnknownBrowse
            yakuza.m68k.elfGet hashmaliciousGafgyt, MiraiBrowse
              main_x86.elfGet hashmaliciousMiraiBrowse
                jkse.arm7.elfGet hashmaliciousMiraiBrowse
                  re.bot.mips.elfGet hashmaliciousUnknownBrowse
                    45.126.126.33-sora.arm-2025-03-12T01_48_26.elfGet hashmaliciousMiraiBrowse
                      efea6.elfGet hashmaliciousMiraiBrowse
                        185.125.190.26boatnet.spc.elfGet hashmaliciousMiraiBrowse
                          sshd.elfGet hashmaliciousUnknownBrowse
                            hiss.mips.elfGet hashmaliciousUnknownBrowse
                              na.elfGet hashmaliciousPrometeiBrowse
                                na.elfGet hashmaliciousPrometeiBrowse
                                  na.elfGet hashmaliciousPrometeiBrowse
                                    na.elfGet hashmaliciousPrometeiBrowse
                                      Space.arm.elfGet hashmaliciousMiraiBrowse
                                        Space.mips.elfGet hashmaliciousUnknownBrowse
                                          Space.x86_64.elfGet hashmaliciousUnknownBrowse
                                            No context
                                            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                            ADDD2NET-INCUShttps://www.bsdnetworks.com/products/bsd-industrial-5-10-100tx-port-ethernet-switch-mini/Get hashmaliciousUnknownBrowse
                                            • 66.102.133.150
                                            armv6l.elfGet hashmaliciousMiraiBrowse
                                            • 67.210.119.233
                                            na.elfGet hashmaliciousMiraiBrowse
                                            • 67.210.111.101
                                            s390x.elfGet hashmaliciousMioriBrowse
                                            • 209.200.246.150
                                            x86.elfGet hashmaliciousMioriBrowse
                                            • 209.200.246.150
                                            ppc.elfGet hashmaliciousMioriBrowse
                                            • 209.200.246.150
                                            mips.elfGet hashmaliciousMioriBrowse
                                            • 209.200.246.150
                                            ppc64.elfGet hashmaliciousMioriBrowse
                                            • 209.200.246.150
                                            mpsl.elfGet hashmaliciousMioriBrowse
                                            • 209.200.246.150
                                            armv4l.elfGet hashmaliciousMioriBrowse
                                            • 209.200.246.150
                                            CANONICAL-ASGBna.elfGet hashmaliciousPrometeiBrowse
                                            • 91.189.91.42
                                            na.elfGet hashmaliciousPrometeiBrowse
                                            • 91.189.91.42
                                            na.elfGet hashmaliciousPrometeiBrowse
                                            • 91.189.91.42
                                            boatnet.mips.elfGet hashmaliciousMiraiBrowse
                                            • 91.189.91.42
                                            boatnet.arm7.elfGet hashmaliciousMiraiBrowse
                                            • 91.189.91.42
                                            na.elfGet hashmaliciousPrometeiBrowse
                                            • 91.189.91.42
                                            boatnet.m68k.elfGet hashmaliciousMiraiBrowse
                                            • 91.189.91.42
                                            na.elfGet hashmaliciousPrometeiBrowse
                                            • 91.189.91.42
                                            boatnet.mpsl.elfGet hashmaliciousMiraiBrowse
                                            • 91.189.91.42
                                            na.elfGet hashmaliciousPrometeiBrowse
                                            • 91.189.91.42
                                            AMAZON-02USna.elfGet hashmaliciousPrometeiBrowse
                                            • 54.255.164.76
                                            na.elfGet hashmaliciousPrometeiBrowse
                                            • 34.249.145.219
                                            linux_mipsel_softfloat.elfGet hashmaliciousChaosBrowse
                                            • 34.243.160.129
                                            https://emails.certa.in/ls/click?upn=u001.iAjcacKhDdX1J4JfQQ5nTBv8arrhNwbSC7Z7YOpbCzfgf-2F84h8udo2F8ceDYH2vesCwn_GwWzR5CPD3uhhoxi7nJtY0-2BQC5TKRtJEXtldUtgGNIXSt8nXiShm6hsa2YaABYh2TZC0v3L7cn9ITurcFtVWlGPrJKRiGHy55d4ptGe15usxcMP6zq8V3IQhE28-2BM1xOhJcGK0RN4pv-2FEdooxiSuAEwYysS6PaDKeDMM5SJj2o26oYst5kZF78CMofBrxC-2Bi3268dPgaFTamsKxmM-2BD7k4t1pfdYwsonFNKuuXTxy7VSHXUKdlwhQquRpB3peBAlnuvIAbNYmjvW3gwhEzYKRNejWDpA5LmNQWEZU72fo9GCUxILqTTrUrVMZv8YssJOAbKOC7shgIUBR8JCEosIu1LpVzKwthWgcNoeLhwSmbfaEpMRbHIGim8a-2BoUsZet4Get hashmaliciousUnknownBrowse
                                            • 18.238.80.19
                                            boatnet.mips.elfGet hashmaliciousMiraiBrowse
                                            • 34.249.145.219
                                            boatnet.arm7.elfGet hashmaliciousMiraiBrowse
                                            • 34.249.145.219
                                            na.elfGet hashmaliciousPrometeiBrowse
                                            • 54.255.164.76
                                            boatnet.mpsl.elfGet hashmaliciousMiraiBrowse
                                            • 34.249.145.219
                                            https://techresearchs.benchurl.com/c/l?u=12450653&e=199143A&c=163607&&t=0&l=12689B51E&email=VHWZIWwomIKWc0sY%2B8V5agif8GG0Zxj9&seq=1Get hashmaliciousUnknownBrowse
                                            • 54.76.75.65
                                            na.elfGet hashmaliciousPrometeiBrowse
                                            • 34.249.145.219
                                            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                            fb4726d465c5f28b84cd6d14cedd13a7yakuza.m68k.elfGet hashmaliciousGafgyt, MiraiBrowse
                                            • 54.217.10.153
                                            boatnet.m68k.elfGet hashmaliciousMiraiBrowse
                                            • 54.217.10.153
                                            na.elfGet hashmaliciousPrometeiBrowse
                                            • 54.217.10.153
                                            gz55G7deop.elfGet hashmaliciousGafgytBrowse
                                            • 54.217.10.153
                                            fr1iFcTPUY.elfGet hashmaliciousMiraiBrowse
                                            • 54.217.10.153
                                            muAZlKU0hq.elfGet hashmaliciousMiraiBrowse
                                            • 54.217.10.153
                                            M88FIQFvyo.elfGet hashmaliciousMiraiBrowse
                                            • 54.217.10.153
                                            9Iakt8wQQ7.elfGet hashmaliciousGafgytBrowse
                                            • 54.217.10.153
                                            x7Z7EQGweF.elfGet hashmaliciousMiraiBrowse
                                            • 54.217.10.153
                                            g058ub3UiN.elfGet hashmaliciousMiraiBrowse
                                            • 54.217.10.153
                                            No context
                                            No created / dropped files found
                                            File type:ELF 32-bit MSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, stripped
                                            Entropy (8bit):5.45974479181573
                                            TrID:
                                            • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                            File name:46.19.143.26-mips-2025-03-01T06_09_25.elf
                                            File size:85'208 bytes
                                            MD5:a618f8a57f8b7816072bfd697a345f50
                                            SHA1:11fa49e2c99138d12e4b266fceba5f73113e0952
                                            SHA256:787da52743cd187df1353d1f85f243cf98d01d65466034d0cbd99900274ba0a2
                                            SHA512:4342bce39ec4a6b1cfa99b25e79a2286850f549738396b3c580efe579cc9c14d6a2ac35f33fd581a0439d7cf0ff5f081bde8278b1da32d63b9e4d1c4ada80856
                                            SSDEEP:1536:gwKtyU1Q4Rj6JJCS7AQ3r90k1TI+Vh9QoQr5eKIpI:gwKtyU1Q4RjvQ7tVh932rIpI
                                            TLSH:B883FA5E2E719FADF229C33447B74B3297A823D523E1C685D26CD2111F6028EA45FBB4
                                            File Content Preview:.ELF.....................@.`...4..J......4. ...(.............@...@....60..60..............@..E@..E@.......l.........dt.Q............................<...'......!'.......................<...'......!... ....'9... ......................<...'..X...!........'9.

                                            ELF header

                                            Class:ELF32
                                            Data:2's complement, big endian
                                            Version:1 (current)
                                            Machine:MIPS R3000
                                            Version Number:0x1
                                            Type:EXEC (Executable file)
                                            OS/ABI:UNIX - System V
                                            ABI Version:0
                                            Entry Point Address:0x400260
                                            Flags:0x1007
                                            ELF Header Size:52
                                            Program Header Offset:52
                                            Program Header Size:32
                                            Number of Program Headers:3
                                            Section Header Offset:84728
                                            Section Header Size:40
                                            Number of Section Headers:12
                                            Header String Table Index:11
                                            NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                            NULL0x00x00x00x00x0000
                                            .initPROGBITS0x4000940x940x8c0x00x6AX004
                                            .textPROGBITS0x4001200x1200x119a00x00x6AX0016
                                            .finiPROGBITS0x411ac00x11ac00x5c0x00x6AX004
                                            .rodataPROGBITS0x411b200x11b200x1b100x00x2A0016
                                            .ctorsPROGBITS0x4540000x140000x80x00x3WA004
                                            .dtorsPROGBITS0x4540080x140080x80x00x3WA004
                                            .dataPROGBITS0x4540200x140200x42c0x00x3WA0016
                                            .gotPROGBITS0x4544500x144500x65c0x40x10000003WAp0016
                                            .sbssNOBITS0x454aac0x14aac0x140x00x10000003WAp004
                                            .bssNOBITS0x454ac00x14aac0x61440x00x3WA0016
                                            .shstrtabSTRTAB0x00x14aac0x490x00x0001
                                            TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                            LOAD0x00x4000000x4000000x136300x136305.62740x5R E0x10000.init .text .fini .rodata
                                            LOAD0x140000x4540000x4540000xaac0x6c043.26710x6RW 0x10000.ctors .dtors .data .got .sbss .bss
                                            GNU_STACK0x00x00x00x00x00.00000x7RWE0x4

                                            Download Network PCAP: filteredfull

                                            • Total Packets: 81
                                            • 13 Ports have been hidden.
                                            • 443 (HTTPS)
                                            • 5102 undefined
                                            • 7679 undefined
                                            • 7680 undefined
                                            • 8080 undefined
                                            • 12016 undefined
                                            • 26141 undefined
                                            • 29486 undefined
                                            • 30751 undefined
                                            • 35086 undefined
                                            TimestampSource PortDest PortSource IPDest IP
                                            Mar 20, 2025 21:17:56.400311947 CET3985435086192.168.2.14209.200.246.178
                                            Mar 20, 2025 21:17:56.514090061 CET3508639854209.200.246.178192.168.2.14
                                            Mar 20, 2025 21:17:58.407047033 CET5315629486192.168.2.14209.200.246.178
                                            Mar 20, 2025 21:17:58.515537024 CET2948653156209.200.246.178192.168.2.14
                                            Mar 20, 2025 21:18:00.409739017 CET3462464839192.168.2.14209.200.246.178
                                            Mar 20, 2025 21:18:00.424556017 CET34592443192.168.2.1454.217.10.153
                                            Mar 20, 2025 21:18:00.518436909 CET6483934624209.200.246.178192.168.2.14
                                            Mar 20, 2025 21:18:00.661266088 CET4433459254.217.10.153192.168.2.14
                                            Mar 20, 2025 21:18:00.661580086 CET34592443192.168.2.1454.217.10.153
                                            Mar 20, 2025 21:18:00.663053036 CET34592443192.168.2.1454.217.10.153
                                            Mar 20, 2025 21:18:00.896025896 CET4433459254.217.10.153192.168.2.14
                                            Mar 20, 2025 21:18:02.412812948 CET4336440237192.168.2.14209.200.246.178
                                            Mar 20, 2025 21:18:02.527293921 CET4023743364209.200.246.178192.168.2.14
                                            Mar 20, 2025 21:18:03.701464891 CET4433459254.217.10.153192.168.2.14
                                            Mar 20, 2025 21:18:03.701524019 CET4433459254.217.10.153192.168.2.14
                                            Mar 20, 2025 21:18:03.701565027 CET4433459254.217.10.153192.168.2.14
                                            Mar 20, 2025 21:18:03.701603889 CET4433459254.217.10.153192.168.2.14
                                            Mar 20, 2025 21:18:03.701638937 CET4433459254.217.10.153192.168.2.14
                                            Mar 20, 2025 21:18:03.701675892 CET4433459254.217.10.153192.168.2.14
                                            Mar 20, 2025 21:18:03.702147007 CET34592443192.168.2.1454.217.10.153
                                            Mar 20, 2025 21:18:03.702147007 CET34592443192.168.2.1454.217.10.153
                                            Mar 20, 2025 21:18:03.702147007 CET34592443192.168.2.1454.217.10.153
                                            Mar 20, 2025 21:18:03.702147961 CET34592443192.168.2.1454.217.10.153
                                            Mar 20, 2025 21:18:03.702147961 CET34592443192.168.2.1454.217.10.153
                                            Mar 20, 2025 21:18:03.702147961 CET34592443192.168.2.1454.217.10.153
                                            Mar 20, 2025 21:18:03.703403950 CET34592443192.168.2.1454.217.10.153
                                            Mar 20, 2025 21:18:03.936201096 CET4433459254.217.10.153192.168.2.14
                                            Mar 20, 2025 21:18:04.015155077 CET4433459254.217.10.153192.168.2.14
                                            Mar 20, 2025 21:18:04.015592098 CET34592443192.168.2.1454.217.10.153
                                            Mar 20, 2025 21:18:04.015592098 CET34592443192.168.2.1454.217.10.153
                                            Mar 20, 2025 21:18:04.256395102 CET4433459254.217.10.153192.168.2.14
                                            Mar 20, 2025 21:18:04.257788897 CET4433459254.217.10.153192.168.2.14
                                            Mar 20, 2025 21:18:04.257831097 CET4433459254.217.10.153192.168.2.14
                                            Mar 20, 2025 21:18:04.257952929 CET34592443192.168.2.1454.217.10.153
                                            Mar 20, 2025 21:18:04.257953882 CET34592443192.168.2.1454.217.10.153
                                            Mar 20, 2025 21:18:04.259104013 CET34592443192.168.2.1454.217.10.153
                                            Mar 20, 2025 21:18:04.417726994 CET5272426141192.168.2.14209.200.246.178
                                            Mar 20, 2025 21:18:04.495860100 CET4433459254.217.10.153192.168.2.14
                                            Mar 20, 2025 21:18:04.495920897 CET4433459254.217.10.153192.168.2.14
                                            Mar 20, 2025 21:18:04.496083975 CET34592443192.168.2.1454.217.10.153
                                            Mar 20, 2025 21:18:04.496084929 CET34592443192.168.2.1454.217.10.153
                                            Mar 20, 2025 21:18:04.524936914 CET2614152724209.200.246.178192.168.2.14
                                            Mar 20, 2025 21:18:06.423521996 CET5316429486192.168.2.14209.200.246.178
                                            Mar 20, 2025 21:18:06.534734011 CET2948653164209.200.246.178192.168.2.14
                                            Mar 20, 2025 21:18:07.080518007 CET46540443192.168.2.14185.125.190.26
                                            Mar 20, 2025 21:18:08.427403927 CET5316629486192.168.2.14209.200.246.178
                                            Mar 20, 2025 21:18:08.539618969 CET2948653166209.200.246.178192.168.2.14
                                            Mar 20, 2025 21:18:10.432982922 CET5434441763192.168.2.14209.200.246.178
                                            Mar 20, 2025 21:18:10.549746037 CET4176354344209.200.246.178192.168.2.14
                                            Mar 20, 2025 21:18:12.440623999 CET3794050749192.168.2.14209.200.246.178
                                            Mar 20, 2025 21:18:12.554594040 CET5074937940209.200.246.178192.168.2.14
                                            Mar 20, 2025 21:18:14.448025942 CET4678447563192.168.2.14209.200.246.178
                                            Mar 20, 2025 21:18:14.560844898 CET4756346784209.200.246.178192.168.2.14
                                            Mar 20, 2025 21:18:16.452464104 CET5331250182192.168.2.14209.200.246.178
                                            Mar 20, 2025 21:18:16.564572096 CET5018253312209.200.246.178192.168.2.14
                                            Mar 20, 2025 21:18:18.457432032 CET361267680192.168.2.14209.200.246.178
                                            Mar 20, 2025 21:18:18.573534012 CET768036126209.200.246.178192.168.2.14
                                            Mar 20, 2025 21:18:20.468904972 CET5331650182192.168.2.14209.200.246.178
                                            Mar 20, 2025 21:18:20.579519987 CET5018253316209.200.246.178192.168.2.14
                                            Mar 20, 2025 21:18:22.475280046 CET367608080192.168.2.14209.200.246.178
                                            Mar 20, 2025 21:18:22.586697102 CET808036760209.200.246.178192.168.2.14
                                            Mar 20, 2025 21:18:24.480396032 CET5350644859192.168.2.14209.200.246.178
                                            Mar 20, 2025 21:18:24.594861984 CET4485953506209.200.246.178192.168.2.14
                                            Mar 20, 2025 21:18:26.484636068 CET3782854780192.168.2.14209.200.246.178
                                            Mar 20, 2025 21:18:26.597599983 CET5478037828209.200.246.178192.168.2.14
                                            Mar 20, 2025 21:18:28.489310026 CET4679847563192.168.2.14209.200.246.178
                                            Mar 20, 2025 21:18:28.601181984 CET4756346798209.200.246.178192.168.2.14
                                            Mar 20, 2025 21:18:30.495356083 CET361387680192.168.2.14209.200.246.178
                                            Mar 20, 2025 21:18:30.606883049 CET768036138209.200.246.178192.168.2.14
                                            Mar 20, 2025 21:18:32.501946926 CET3989035086192.168.2.14209.200.246.178
                                            Mar 20, 2025 21:18:32.614094973 CET3508639890209.200.246.178192.168.2.14
                                            Mar 20, 2025 21:18:34.507039070 CET5333050182192.168.2.14209.200.246.178
                                            Mar 20, 2025 21:18:34.619405985 CET5018253330209.200.246.178192.168.2.14
                                            Mar 20, 2025 21:18:36.511693001 CET4680647563192.168.2.14209.200.246.178
                                            Mar 20, 2025 21:18:36.628496885 CET4756346806209.200.246.178192.168.2.14
                                            Mar 20, 2025 21:18:37.287239075 CET46540443192.168.2.14185.125.190.26
                                            Mar 20, 2025 21:18:38.516813993 CET3796650749192.168.2.14209.200.246.178
                                            Mar 20, 2025 21:18:38.630233049 CET5074937966209.200.246.178192.168.2.14
                                            Mar 20, 2025 21:18:40.521049976 CET4966040217192.168.2.14209.200.246.178
                                            Mar 20, 2025 21:18:40.636394024 CET4021749660209.200.246.178192.168.2.14
                                            Mar 20, 2025 21:18:42.524847984 CET4159250464192.168.2.14209.200.246.178
                                            Mar 20, 2025 21:18:42.639252901 CET5046441592209.200.246.178192.168.2.14
                                            Mar 20, 2025 21:18:44.529911041 CET5022230751192.168.2.14209.200.246.178
                                            Mar 20, 2025 21:18:44.642431974 CET3075150222209.200.246.178192.168.2.14
                                            Mar 20, 2025 21:18:46.538758039 CET4471052962192.168.2.14209.200.246.178
                                            Mar 20, 2025 21:18:46.649003983 CET5296244710209.200.246.178192.168.2.14
                                            Mar 20, 2025 21:18:48.544547081 CET5276826141192.168.2.14209.200.246.178
                                            Mar 20, 2025 21:18:48.655869961 CET2614152768209.200.246.178192.168.2.14
                                            Mar 20, 2025 21:18:50.550224066 CET362467679192.168.2.14209.200.246.178
                                            Mar 20, 2025 21:18:50.664563894 CET767936246209.200.246.178192.168.2.14
                                            Mar 20, 2025 21:18:52.555202007 CET5277226141192.168.2.14209.200.246.178
                                            Mar 20, 2025 21:18:52.671298981 CET2614152772209.200.246.178192.168.2.14
                                            Mar 20, 2025 21:18:54.559994936 CET4471852962192.168.2.14209.200.246.178
                                            Mar 20, 2025 21:18:54.678879976 CET5296244718209.200.246.178192.168.2.14
                                            Mar 20, 2025 21:18:56.563885927 CET360945102192.168.2.14209.200.246.178
                                            Mar 20, 2025 21:18:56.679842949 CET510236094209.200.246.178192.168.2.14
                                            Mar 20, 2025 21:18:58.567564011 CET3798650749192.168.2.14209.200.246.178
                                            Mar 20, 2025 21:18:58.678620100 CET5074937986209.200.246.178192.168.2.14
                                            Mar 20, 2025 21:19:00.571930885 CET4342240237192.168.2.14209.200.246.178
                                            Mar 20, 2025 21:19:00.685543060 CET4023743422209.200.246.178192.168.2.14
                                            Mar 20, 2025 21:19:02.576114893 CET368008080192.168.2.14209.200.246.178
                                            Mar 20, 2025 21:19:02.688519001 CET808036800209.200.246.178192.168.2.14
                                            Mar 20, 2025 21:19:04.580281973 CET4823056190192.168.2.14209.200.246.178
                                            Mar 20, 2025 21:19:04.691941023 CET5619048230209.200.246.178192.168.2.14
                                            Mar 20, 2025 21:19:06.586071014 CET368048080192.168.2.14209.200.246.178
                                            Mar 20, 2025 21:19:06.697841883 CET808036804209.200.246.178192.168.2.14
                                            Mar 20, 2025 21:19:08.591279030 CET3469264839192.168.2.14209.200.246.178
                                            Mar 20, 2025 21:19:08.704355001 CET6483934692209.200.246.178192.168.2.14
                                            Mar 20, 2025 21:19:10.599050045 CET5440441763192.168.2.14209.200.246.178
                                            Mar 20, 2025 21:19:10.709379911 CET4176354404209.200.246.178192.168.2.14
                                            Mar 20, 2025 21:19:12.605704069 CET5355444859192.168.2.14209.200.246.178
                                            Mar 20, 2025 21:19:12.719634056 CET4485953554209.200.246.178192.168.2.14
                                            Mar 20, 2025 21:19:14.611031055 CET5323229486192.168.2.14209.200.246.178
                                            Mar 20, 2025 21:19:14.725776911 CET2948653232209.200.246.178192.168.2.14
                                            Mar 20, 2025 21:19:16.617263079 CET3343412016192.168.2.14209.200.246.178
                                            Mar 20, 2025 21:19:16.728980064 CET1201633434209.200.246.178192.168.2.14
                                            Mar 20, 2025 21:19:18.622982025 CET5279826141192.168.2.14209.200.246.178
                                            Mar 20, 2025 21:19:18.736041069 CET2614152798209.200.246.178192.168.2.14
                                            Mar 20, 2025 21:19:20.628535986 CET5323829486192.168.2.14209.200.246.178
                                            Mar 20, 2025 21:19:20.743305922 CET2948653238209.200.246.178192.168.2.14
                                            Mar 20, 2025 21:19:22.633876085 CET361205102192.168.2.14209.200.246.178
                                            Mar 20, 2025 21:19:22.746184111 CET510236120209.200.246.178192.168.2.14
                                            Mar 20, 2025 21:19:24.639858961 CET4366049722192.168.2.14209.200.246.178
                                            Mar 20, 2025 21:19:24.751821995 CET4972243660209.200.246.178192.168.2.14
                                            Mar 20, 2025 21:19:26.645906925 CET4163650464192.168.2.14209.200.246.178
                                            Mar 20, 2025 21:19:26.758333921 CET5046441636209.200.246.178192.168.2.14
                                            Mar 20, 2025 21:19:28.651671886 CET4685847563192.168.2.14209.200.246.178
                                            Mar 20, 2025 21:19:28.763418913 CET4756346858209.200.246.178192.168.2.14
                                            Mar 20, 2025 21:19:30.659543991 CET4475452962192.168.2.14209.200.246.178
                                            Mar 20, 2025 21:19:30.771327019 CET5296244754209.200.246.178192.168.2.14
                                            Mar 20, 2025 21:19:32.664901972 CET5325029486192.168.2.14209.200.246.178
                                            Mar 20, 2025 21:19:32.780029058 CET2948653250209.200.246.178192.168.2.14
                                            Mar 20, 2025 21:19:34.669693947 CET3345212016192.168.2.14209.200.246.178
                                            Mar 20, 2025 21:19:34.783025026 CET1201633452209.200.246.178192.168.2.14
                                            Mar 20, 2025 21:19:36.675069094 CET5281626141192.168.2.14209.200.246.178
                                            Mar 20, 2025 21:19:36.790180922 CET2614152816209.200.246.178192.168.2.14
                                            Mar 20, 2025 21:19:38.679896116 CET3995635086192.168.2.14209.200.246.178
                                            Mar 20, 2025 21:19:38.791893959 CET3508639956209.200.246.178192.168.2.14
                                            Mar 20, 2025 21:19:40.685882092 CET3345812016192.168.2.14209.200.246.178
                                            Mar 20, 2025 21:19:40.801697016 CET1201633458209.200.246.178192.168.2.14
                                            Mar 20, 2025 21:19:42.693399906 CET368408080192.168.2.14209.200.246.178
                                            Mar 20, 2025 21:19:42.802845001 CET808036840209.200.246.178192.168.2.14
                                            Mar 20, 2025 21:19:44.698256969 CET4476852962192.168.2.14209.200.246.178
                                            Mar 20, 2025 21:19:44.814630985 CET5296244768209.200.246.178192.168.2.14
                                            Mar 20, 2025 21:19:46.704960108 CET4972640217192.168.2.14209.200.246.178
                                            Mar 20, 2025 21:19:46.816246033 CET4021749726209.200.246.178192.168.2.14
                                            Mar 20, 2025 21:19:48.711216927 CET361465102192.168.2.14209.200.246.178
                                            Mar 20, 2025 21:19:48.820673943 CET510236146209.200.246.178192.168.2.14
                                            Mar 20, 2025 21:19:50.717463017 CET5326829486192.168.2.14209.200.246.178
                                            Mar 20, 2025 21:19:50.830132008 CET2948653268209.200.246.178192.168.2.14
                                            Mar 20, 2025 21:19:52.723957062 CET4347440237192.168.2.14209.200.246.178
                                            Mar 20, 2025 21:19:52.835045099 CET4023743474209.200.246.178192.168.2.14
                                            Mar 20, 2025 21:19:54.731256008 CET5444841763192.168.2.14209.200.246.178
                                            Mar 20, 2025 21:19:54.843422890 CET4176354448209.200.246.178192.168.2.14
                                            Mar 20, 2025 21:19:56.736648083 CET3347412016192.168.2.14209.200.246.178
                                            Mar 20, 2025 21:19:56.847273111 CET1201633474209.200.246.178192.168.2.14
                                            Mar 20, 2025 21:19:58.742814064 CET5341450182192.168.2.14209.200.246.178
                                            Mar 20, 2025 21:19:58.857625961 CET5018253414209.200.246.178192.168.2.14
                                            TimestampSource IPSource PortDest IPDest PortSubjectIssuerNot BeforeNot AfterJA3 SSL Client FingerprintJA3 SSL Client Digest
                                            Mar 20, 2025 21:18:03.701675892 CET54.217.10.153443192.168.2.1434592CN=motd.ubuntu.com CN=R11, O=Let's Encrypt, C=USCN=R11, O=Let's Encrypt, C=US CN=ISRG Root X1, O=Internet Security Research Group, C=USSun Jan 05 09:21:36 CET 2025 Wed Mar 13 01:00:00 CET 2024Sat Apr 05 10:21:35 CEST 2025 Sat Mar 13 00:59:59 CET 2027771,4866-4867-4865-49196-49200-163-159-52393-52392-52394-49327-49325-49315-49311-49245-49249-49239-49235-49195-49199-162-158-49326-49324-49314-49310-49244-49248-49238-49234-49188-49192-107-106-49267-49271-196-195-49187-49191-103-64-49266-49270-190-189-49162-49172-57-56-136-135-49161-49171-51-50-69-68-157-49313-49309-49233-156-49312-49308-49232-61-192-60-186-53-132-47-65-255,0-11-10-35-22-23-13-43-45-51,29-23-30-25-24,0-1-2fb4726d465c5f28b84cd6d14cedd13a7
                                            CN=R11, O=Let's Encrypt, C=USCN=ISRG Root X1, O=Internet Security Research Group, C=USWed Mar 13 01:00:00 CET 2024Sat Mar 13 00:59:59 CET 2027

                                            System Behavior

                                            Start time (UTC):20:17:55
                                            Start date (UTC):20/03/2025
                                            Path:/tmp/46.19.143.26-mips-2025-03-01T06_09_25.elf
                                            Arguments:/tmp/46.19.143.26-mips-2025-03-01T06_09_25.elf
                                            File size:5777432 bytes
                                            MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                            Start time (UTC):20:17:55
                                            Start date (UTC):20/03/2025
                                            Path:/tmp/46.19.143.26-mips-2025-03-01T06_09_25.elf
                                            Arguments:-
                                            File size:5777432 bytes
                                            MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                            Start time (UTC):20:18:03
                                            Start date (UTC):20/03/2025
                                            Path:/usr/bin/dash
                                            Arguments:-
                                            File size:129816 bytes
                                            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                            Start time (UTC):20:18:03
                                            Start date (UTC):20/03/2025
                                            Path:/usr/bin/rm
                                            Arguments:rm -f /tmp/tmp.mEkGBMS8sb /tmp/tmp.qcBubsum5M /tmp/tmp.7pqsYHy482
                                            File size:72056 bytes
                                            MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                            Start time (UTC):20:18:03
                                            Start date (UTC):20/03/2025
                                            Path:/usr/bin/dash
                                            Arguments:-
                                            File size:129816 bytes
                                            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                            Start time (UTC):20:18:03
                                            Start date (UTC):20/03/2025
                                            Path:/usr/bin/cat
                                            Arguments:cat /tmp/tmp.mEkGBMS8sb
                                            File size:43416 bytes
                                            MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

                                            Start time (UTC):20:18:03
                                            Start date (UTC):20/03/2025
                                            Path:/usr/bin/dash
                                            Arguments:-
                                            File size:129816 bytes
                                            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                            Start time (UTC):20:18:03
                                            Start date (UTC):20/03/2025
                                            Path:/usr/bin/head
                                            Arguments:head -n 10
                                            File size:47480 bytes
                                            MD5 hash:fd96a67145172477dd57131396fc9608

                                            Start time (UTC):20:18:03
                                            Start date (UTC):20/03/2025
                                            Path:/usr/bin/dash
                                            Arguments:-
                                            File size:129816 bytes
                                            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                            Start time (UTC):20:18:03
                                            Start date (UTC):20/03/2025
                                            Path:/usr/bin/tr
                                            Arguments:tr -d \\000-\\011\\013\\014\\016-\\037
                                            File size:51544 bytes
                                            MD5 hash:fbd1402dd9f72d8ebfff00ce7c3a7bb5

                                            Start time (UTC):20:18:03
                                            Start date (UTC):20/03/2025
                                            Path:/usr/bin/dash
                                            Arguments:-
                                            File size:129816 bytes
                                            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                            Start time (UTC):20:18:03
                                            Start date (UTC):20/03/2025
                                            Path:/usr/bin/cut
                                            Arguments:cut -c -80
                                            File size:47480 bytes
                                            MD5 hash:d8ed0ea8f22c0de0f8692d4d9f1759d3

                                            Start time (UTC):20:18:03
                                            Start date (UTC):20/03/2025
                                            Path:/usr/bin/dash
                                            Arguments:-
                                            File size:129816 bytes
                                            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                            Start time (UTC):20:18:03
                                            Start date (UTC):20/03/2025
                                            Path:/usr/bin/cat
                                            Arguments:cat /tmp/tmp.mEkGBMS8sb
                                            File size:43416 bytes
                                            MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

                                            Start time (UTC):20:18:03
                                            Start date (UTC):20/03/2025
                                            Path:/usr/bin/dash
                                            Arguments:-
                                            File size:129816 bytes
                                            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                            Start time (UTC):20:18:03
                                            Start date (UTC):20/03/2025
                                            Path:/usr/bin/head
                                            Arguments:head -n 10
                                            File size:47480 bytes
                                            MD5 hash:fd96a67145172477dd57131396fc9608

                                            Start time (UTC):20:18:03
                                            Start date (UTC):20/03/2025
                                            Path:/usr/bin/dash
                                            Arguments:-
                                            File size:129816 bytes
                                            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                            Start time (UTC):20:18:03
                                            Start date (UTC):20/03/2025
                                            Path:/usr/bin/tr
                                            Arguments:tr -d \\000-\\011\\013\\014\\016-\\037
                                            File size:51544 bytes
                                            MD5 hash:fbd1402dd9f72d8ebfff00ce7c3a7bb5

                                            Start time (UTC):20:18:03
                                            Start date (UTC):20/03/2025
                                            Path:/usr/bin/dash
                                            Arguments:-
                                            File size:129816 bytes
                                            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                            Start time (UTC):20:18:03
                                            Start date (UTC):20/03/2025
                                            Path:/usr/bin/cut
                                            Arguments:cut -c -80
                                            File size:47480 bytes
                                            MD5 hash:d8ed0ea8f22c0de0f8692d4d9f1759d3

                                            Start time (UTC):20:18:03
                                            Start date (UTC):20/03/2025
                                            Path:/usr/bin/dash
                                            Arguments:-
                                            File size:129816 bytes
                                            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                            Start time (UTC):20:18:03
                                            Start date (UTC):20/03/2025
                                            Path:/usr/bin/rm
                                            Arguments:rm -f /tmp/tmp.mEkGBMS8sb /tmp/tmp.qcBubsum5M /tmp/tmp.7pqsYHy482
                                            File size:72056 bytes
                                            MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b