Create Interactive Tour

Linux Analysis Report
tmips.elf

Overview

General Information

Sample name:tmips.elf
Analysis ID:1647994
MD5:a62f61c5866081796072db6419273e63
SHA1:ca7293833e3096c6240774a50fcf4c079f48dfcd
SHA256:9ee761719e83b4ec4ec1d91da16c5cd232f410ca41bdff7c1b45265cf3b01cdb
Tags:elfuser-abuse_ch
Infos:

Detection

Score:56
Range:0 - 100

Signatures

Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Detected TCP or UDP traffic on non-standard ports
Enumerates processes within the "proc" file system
Executes the "rm" command used to delete files or directories
Sample has stripped symbol table
Sample listens on a socket
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
Joe Sandbox version:42.0.0 Malachite
Analysis ID:1647994
Start date and time:2025-03-25 13:27:27 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 35s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:tmips.elf
Detection:MAL
Classification:mal56.linELF@0/0@0/0
Command:/tmp/tmips.elf
PID:6207
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
a cat is fine too
Standard Error:
  • system is lnxubuntu20
  • tmips.elf (PID: 6207, Parent: 6123, MD5: 0083f1f0e77be34ad27f849842bbb00c) Arguments: /tmp/tmips.elf
  • dash New Fork (PID: 6272, Parent: 4332)
  • rm (PID: 6272, Parent: 4332, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.60vh05HqZm /tmp/tmp.SX1nC8Yp1N /tmp/tmp.XXcbpQPRHq
  • dash New Fork (PID: 6273, Parent: 4332)
  • rm (PID: 6273, Parent: 4332, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.60vh05HqZm /tmp/tmp.SX1nC8Yp1N /tmp/tmp.XXcbpQPRHq
  • cleanup
No yara matches
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: tmips.elfAvira: detected
Source: tmips.elfVirustotal: Detection: 20%Perma Link
Source: tmips.elfReversingLabs: Detection: 22%
Source: global trafficTCP traffic: 192.168.2.23:37692 -> 156.229.232.154:51325
Source: /tmp/tmips.elf (PID: 6207)Socket: 127.0.0.1:51101Jump to behavior
Source: unknownTCP traffic detected without corresponding DNS query: 156.229.232.154
Source: unknownTCP traffic detected without corresponding DNS query: 156.229.232.154
Source: unknownTCP traffic detected without corresponding DNS query: 156.229.232.154
Source: unknownTCP traffic detected without corresponding DNS query: 156.229.232.154
Source: unknownTCP traffic detected without corresponding DNS query: 156.229.232.154
Source: unknownTCP traffic detected without corresponding DNS query: 156.229.232.154
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 156.229.232.154
Source: unknownTCP traffic detected without corresponding DNS query: 156.229.232.154
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 34.249.145.219
Source: unknownTCP traffic detected without corresponding DNS query: 34.249.145.219
Source: unknownTCP traffic detected without corresponding DNS query: 34.249.145.219
Source: unknownTCP traffic detected without corresponding DNS query: 156.229.232.154
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 156.229.232.154
Source: unknownTCP traffic detected without corresponding DNS query: 156.229.232.154
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 156.229.232.154
Source: unknownTCP traffic detected without corresponding DNS query: 156.229.232.154
Source: unknownTCP traffic detected without corresponding DNS query: 34.249.145.219
Source: unknownTCP traffic detected without corresponding DNS query: 156.229.232.154
Source: unknownTCP traffic detected without corresponding DNS query: 156.229.232.154
Source: unknownTCP traffic detected without corresponding DNS query: 156.229.232.154
Source: unknownNetwork traffic detected: HTTP traffic on port 39244 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39244
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
Source: ELF static info symbol of initial sample.symtab present: no
Source: classification engineClassification label: mal56.linELF@0/0@0/0
Source: /tmp/tmips.elf (PID: 6211)File opened: /proc/6230/statusJump to behavior
Source: /tmp/tmips.elf (PID: 6211)File opened: /proc/6241/statusJump to behavior
Source: /tmp/tmips.elf (PID: 6211)File opened: /proc/6240/statusJump to behavior
Source: /tmp/tmips.elf (PID: 6211)File opened: /proc/6034/cmdlineJump to behavior
Source: /tmp/tmips.elf (PID: 6211)File opened: /proc/6232/statusJump to behavior
Source: /tmp/tmips.elf (PID: 6211)File opened: /proc/6231/statusJump to behavior
Source: /tmp/tmips.elf (PID: 6211)File opened: /proc/6234/statusJump to behavior
Source: /tmp/tmips.elf (PID: 6211)File opened: /proc/6233/statusJump to behavior
Source: /tmp/tmips.elf (PID: 6211)File opened: /proc/6225/statusJump to behavior
Source: /tmp/tmips.elf (PID: 6211)File opened: /proc/6236/statusJump to behavior
Source: /tmp/tmips.elf (PID: 6211)File opened: /proc/6224/statusJump to behavior
Source: /tmp/tmips.elf (PID: 6211)File opened: /proc/6235/statusJump to behavior
Source: /tmp/tmips.elf (PID: 6211)File opened: /proc/6227/statusJump to behavior
Source: /tmp/tmips.elf (PID: 6211)File opened: /proc/6238/statusJump to behavior
Source: /tmp/tmips.elf (PID: 6211)File opened: /proc/6226/statusJump to behavior
Source: /tmp/tmips.elf (PID: 6211)File opened: /proc/6237/statusJump to behavior
Source: /tmp/tmips.elf (PID: 6211)File opened: /proc/6229/statusJump to behavior
Source: /tmp/tmips.elf (PID: 6211)File opened: /proc/6228/statusJump to behavior
Source: /tmp/tmips.elf (PID: 6211)File opened: /proc/6239/statusJump to behavior
Source: /usr/bin/dash (PID: 6272)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.60vh05HqZm /tmp/tmp.SX1nC8Yp1N /tmp/tmp.XXcbpQPRHqJump to behavior
Source: /usr/bin/dash (PID: 6273)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.60vh05HqZm /tmp/tmp.SX1nC8Yp1N /tmp/tmp.XXcbpQPRHqJump to behavior
Source: /tmp/tmips.elf (PID: 6207)Queries kernel information via 'uname': Jump to behavior
Source: tmips.elf, 6207.1.000056308ffe4000.000056309008c000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/mips
Source: tmips.elf, 6207.1.00007ffea725e000.00007ffea727f000.rw-.sdmpBinary or memory string: /usr/bin/qemu-mips
Source: tmips.elf, 6207.1.00007ffea725e000.00007ffea727f000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-mips/tmp/tmips.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/tmips.elf
Source: tmips.elf, 6207.1.000056308ffe4000.000056309008c000.rw-.sdmpBinary or memory string: 0V!/etc/qemu-binfmt/mips
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
File Deletion
1
OS Credential Dumping
11
Security Software Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Standard Port
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1647994 Sample: tmips.elf Startdate: 25/03/2025 Architecture: LINUX Score: 56 18 156.229.232.154, 37692, 51325 ONL-HKOCEANNETWORKLIMITEDHK Seychelles 2->18 20 109.202.202.202, 80 INIT7CH Switzerland 2->20 22 3 other IPs or domains 2->22 24 Antivirus / Scanner detection for submitted sample 2->24 26 Multi AV Scanner detection for submitted file 2->26 8 tmips.elf 2->8         started        10 dash rm 2->10         started        12 dash rm 2->12         started        signatures3 process4 process5 14 tmips.elf 8->14         started        process6 16 tmips.elf 14->16         started       
SourceDetectionScannerLabelLink
tmips.elf21%VirustotalBrowse
tmips.elf22%ReversingLabsLinux.Trojan.Mirai
tmips.elf100%AviraEXP/ELF.Agent.J.8
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

No contacted domains info
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs
IPDomainCountryFlagASNASN NameMalicious
156.229.232.154
unknownSeychelles
139086ONL-HKOCEANNETWORKLIMITEDHKfalse
34.249.145.219
unknownUnited States
16509AMAZON-02USfalse
109.202.202.202
unknownSwitzerland
13030INIT7CHfalse
91.189.91.43
unknownUnited Kingdom
41231CANONICAL-ASGBfalse
91.189.91.42
unknownUnited Kingdom
41231CANONICAL-ASGBfalse
MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
156.229.232.154gx86.elfGet hashmaliciousUnknownBrowse
    tarm.elfGet hashmaliciousUnknownBrowse
      tarm7.elfGet hashmaliciousMiraiBrowse
        arm.elfGet hashmaliciousUnknownBrowse
          gmips.elfGet hashmaliciousUnknownBrowse
            arm5.elfGet hashmaliciousUnknownBrowse
              garm5.elfGet hashmaliciousUnknownBrowse
                gx86.elfGet hashmaliciousUnknownBrowse
                  garm7.elfGet hashmaliciousMiraiBrowse
                    garm.elfGet hashmaliciousUnknownBrowse
                      34.249.145.219tarm.elfGet hashmaliciousUnknownBrowse
                        na.elfGet hashmaliciousPrometeiBrowse
                          na.elfGet hashmaliciousPrometeiBrowse
                            .i.elfGet hashmaliciousUnknownBrowse
                              na.elfGet hashmaliciousPrometeiBrowse
                                main_m68k.elfGet hashmaliciousMiraiBrowse
                                  mpsl.elfGet hashmaliciousUnknownBrowse
                                    na.elfGet hashmaliciousPrometeiBrowse
                                      na.elfGet hashmaliciousPrometeiBrowse
                                        na.elfGet hashmaliciousPrometeiBrowse
                                          109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
                                          • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
                                          91.189.91.43tarm.elfGet hashmaliciousUnknownBrowse
                                            na.elfGet hashmaliciousPrometeiBrowse
                                              na.elfGet hashmaliciousPrometeiBrowse
                                                na.elfGet hashmaliciousPrometeiBrowse
                                                  na.elfGet hashmaliciousPrometeiBrowse
                                                    sshd.elfGet hashmaliciousUnknownBrowse
                                                      tftp.elfGet hashmaliciousUnknownBrowse
                                                        mips.elfGet hashmaliciousUnknownBrowse
                                                          arm7.elfGet hashmaliciousMiraiBrowse
                                                            Mozi.m.elfGet hashmaliciousUnknownBrowse
                                                              No context
                                                              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                              CANONICAL-ASGBtarm.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 91.189.91.42
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 91.189.91.42
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 91.189.91.42
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 91.189.91.42
                                                              sshd.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              tftp.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              mips.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              arm7.elfGet hashmaliciousMiraiBrowse
                                                              • 91.189.91.42
                                                              Mozi.m.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              INIT7CHtarm.elfGet hashmaliciousUnknownBrowse
                                                              • 109.202.202.202
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 109.202.202.202
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 109.202.202.202
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 109.202.202.202
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 109.202.202.202
                                                              sshd.elfGet hashmaliciousUnknownBrowse
                                                              • 109.202.202.202
                                                              tftp.elfGet hashmaliciousUnknownBrowse
                                                              • 109.202.202.202
                                                              mips.elfGet hashmaliciousUnknownBrowse
                                                              • 109.202.202.202
                                                              arm7.elfGet hashmaliciousMiraiBrowse
                                                              • 109.202.202.202
                                                              Mozi.m.elfGet hashmaliciousUnknownBrowse
                                                              • 109.202.202.202
                                                              ONL-HKOCEANNETWORKLIMITEDHKgx86.elfGet hashmaliciousUnknownBrowse
                                                              • 156.229.232.154
                                                              tarm.elfGet hashmaliciousUnknownBrowse
                                                              • 156.229.232.154
                                                              tarm7.elfGet hashmaliciousMiraiBrowse
                                                              • 156.229.232.154
                                                              arm.elfGet hashmaliciousUnknownBrowse
                                                              • 156.229.232.154
                                                              ppc.elfGet hashmaliciousMiraiBrowse
                                                              • 156.249.107.18
                                                              .5r3fqt67ew531has4231.dbg.elfGet hashmaliciousMirai, Gafgyt, Moobot, OkiruBrowse
                                                              • 156.229.233.104
                                                              .5r3fqt67ew531has4231.x86.elfGet hashmaliciousMirai, Gafgyt, Moobot, OkiruBrowse
                                                              • 156.229.233.104
                                                              FV2025020697808.htmlGet hashmaliciousUnknownBrowse
                                                              • 156.229.228.198
                                                              FV2025020697808.htmlGet hashmaliciousUnknownBrowse
                                                              • 156.229.228.198
                                                              faktura_FV2025020660849.htmlGet hashmaliciousUnknownBrowse
                                                              • 156.229.228.198
                                                              AMAZON-02USSeraphicSecurity_f605c43a4f26313c6228c8fa342de4539f09081dc4e4ffc66e0f5d0a0634e99d.msiGet hashmaliciousUnknownBrowse
                                                              • 52.19.170.97
                                                              tarm.elfGet hashmaliciousUnknownBrowse
                                                              • 34.249.145.219
                                                              http://www.bordgaisenergytheatre.ieGet hashmaliciousUnknownBrowse
                                                              • 52.49.19.13
                                                              tarm7.elfGet hashmaliciousMiraiBrowse
                                                              • 54.171.230.55
                                                              RFQ3252025.exeGet hashmaliciousFormBookBrowse
                                                              • 18.139.62.226
                                                              http://bitly.lc/L2TBqGet hashmaliciousUnknownBrowse
                                                              • 52.85.61.5
                                                              https://techresearchs.benchurl.com/c/l?u=12450653&e=199143A&c=163607&&t=0&l=12689B51E&email=VHWZIWwomIKWc0sY%2B8V5agif8GG0Zxj9&seq=1Get hashmaliciousUnknownBrowse
                                                              • 108.138.106.72
                                                              Quote 09052022.exeGet hashmaliciousFormBookBrowse
                                                              • 13.248.169.48
                                                              https://www.powr.io/form-builder/i/39342486#pageGet hashmaliciousHTMLPhisher, Invisible JS, Tycoon2FABrowse
                                                              • 76.76.21.142
                                                              https://app.storylane.io/share/cllvhddxirl7Get hashmaliciousHTMLPhisher, Invisible JS, Tycoon2FABrowse
                                                              • 3.171.139.22
                                                              No context
                                                              No context
                                                              No created / dropped files found
                                                              File type:ELF 32-bit MSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, stripped
                                                              Entropy (8bit):5.344209917821686
                                                              TrID:
                                                              • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                                              File name:tmips.elf
                                                              File size:76'716 bytes
                                                              MD5:a62f61c5866081796072db6419273e63
                                                              SHA1:ca7293833e3096c6240774a50fcf4c079f48dfcd
                                                              SHA256:9ee761719e83b4ec4ec1d91da16c5cd232f410ca41bdff7c1b45265cf3b01cdb
                                                              SHA512:2015b9228b83233c6fdf9bd46a3a1207cc22eb603d06d075b7fd71c05e6ff9bcdc50d2d8d96b5696bd46106b83171a8872bd991458887235ba6fc1638a465942
                                                              SSDEEP:1536:sAWySOfcSJJkBWS7WSTeSWasSpXNKPfNmehw8s9:0XOfcKkGSpXQPfNw8s9
                                                              TLSH:0B73B51E6E218FEDF769823547B78E21A79C33D227E0C685E29CD6011E7034D645FBA8
                                                              File Content Preview:.ELF.....................@.`...4..)|.....4. ...(.............@...@.....0...0.............. ..E ..E .......k@........dt.Q............................<...'......!'.......................<...'..x...!... ....'9... ......................<...'..H...!........'9.

                                                              ELF header

                                                              Class:ELF32
                                                              Data:2's complement, big endian
                                                              Version:1 (current)
                                                              Machine:MIPS R3000
                                                              Version Number:0x1
                                                              Type:EXEC (Executable file)
                                                              OS/ABI:UNIX - System V
                                                              ABI Version:0
                                                              Entry Point Address:0x400260
                                                              Flags:0x1007
                                                              ELF Header Size:52
                                                              Program Header Offset:52
                                                              Program Header Size:32
                                                              Number of Program Headers:3
                                                              Section Header Offset:76156
                                                              Section Header Size:40
                                                              Number of Section Headers:14
                                                              Header String Table Index:13
                                                              NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                              NULL0x00x00x00x00x0000
                                                              .initPROGBITS0x4000940x940x8c0x00x6AX004
                                                              .textPROGBITS0x4001200x1200x102b00x00x6AX0016
                                                              .finiPROGBITS0x4103d00x103d00x5c0x00x6AX004
                                                              .rodataPROGBITS0x4104300x104300x14000x00x2A0016
                                                              .ctorsPROGBITS0x4520000x120000x80x00x3WA004
                                                              .dtorsPROGBITS0x4520080x120080x80x00x3WA004
                                                              .data.rel.roPROGBITS0x4520140x120140x40x00x3WA004
                                                              .dataPROGBITS0x4520200x120200x4200x00x3WA0016
                                                              .gotPROGBITS0x4524400x124400x4d80x40x10000003WAp0016
                                                              .sbssNOBITS0x4529180x129180x280x00x10000003WAp004
                                                              .bssNOBITS0x4529400x129180x62000x00x3WA0016
                                                              .mdebug.abi32PROGBITS0xb2e0x129180x00x00x0001
                                                              .shstrtabSTRTAB0x00x129180x640x00x0001
                                                              TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                              LOAD0x00x4000000x4000000x118300x118305.46650x5R E0x10000.init .text .fini .rodata
                                                              LOAD0x120000x4520000x4520000x9180x6b404.13120x6RW 0x10000.ctors .dtors .data.rel.ro .data .got .sbss .bss
                                                              GNU_STACK0x00x00x00x00x00.00000x7RWE0x4

                                                              Download Network PCAP: filteredfull

                                                              • Total Packets: 26
                                                              • 51325 undefined
                                                              • 443 (HTTPS)
                                                              • 80 (HTTP)
                                                              TimestampSource PortDest PortSource IPDest IP
                                                              Mar 25, 2025 13:28:11.167505026 CET3769251325192.168.2.23156.229.232.154
                                                              Mar 25, 2025 13:28:11.337513924 CET5132537692156.229.232.154192.168.2.23
                                                              Mar 25, 2025 13:28:11.337657928 CET3769251325192.168.2.23156.229.232.154
                                                              Mar 25, 2025 13:28:12.170348883 CET3769251325192.168.2.23156.229.232.154
                                                              Mar 25, 2025 13:28:12.338922977 CET5132537692156.229.232.154192.168.2.23
                                                              Mar 25, 2025 13:28:12.339222908 CET3769251325192.168.2.23156.229.232.154
                                                              Mar 25, 2025 13:28:12.342665911 CET3769251325192.168.2.23156.229.232.154
                                                              Mar 25, 2025 13:28:12.512063026 CET5132537692156.229.232.154192.168.2.23
                                                              Mar 25, 2025 13:28:12.512223005 CET3769251325192.168.2.23156.229.232.154
                                                              Mar 25, 2025 13:28:12.680780888 CET5132537692156.229.232.154192.168.2.23
                                                              Mar 25, 2025 13:28:14.761961937 CET42836443192.168.2.2391.189.91.43
                                                              Mar 25, 2025 13:28:16.297774076 CET4251680192.168.2.23109.202.202.202
                                                              Mar 25, 2025 13:28:22.345084906 CET3769251325192.168.2.23156.229.232.154
                                                              Mar 25, 2025 13:28:22.514024973 CET5132537692156.229.232.154192.168.2.23
                                                              Mar 25, 2025 13:28:22.514050007 CET5132537692156.229.232.154192.168.2.23
                                                              Mar 25, 2025 13:28:22.514134884 CET3769251325192.168.2.23156.229.232.154
                                                              Mar 25, 2025 13:28:30.631781101 CET43928443192.168.2.2391.189.91.42
                                                              Mar 25, 2025 13:28:35.101587057 CET39244443192.168.2.2334.249.145.219
                                                              Mar 25, 2025 13:28:35.101636887 CET4433924434.249.145.219192.168.2.23
                                                              Mar 25, 2025 13:28:35.101702929 CET39244443192.168.2.2334.249.145.219
                                                              Mar 25, 2025 13:28:35.102412939 CET39244443192.168.2.2334.249.145.219
                                                              Mar 25, 2025 13:28:35.102432013 CET4433924434.249.145.219192.168.2.23
                                                              Mar 25, 2025 13:28:37.707191944 CET5132537692156.229.232.154192.168.2.23
                                                              Mar 25, 2025 13:28:37.707279921 CET3769251325192.168.2.23156.229.232.154
                                                              Mar 25, 2025 13:28:40.870625019 CET42836443192.168.2.2391.189.91.43
                                                              Mar 25, 2025 13:28:47.013592958 CET4251680192.168.2.23109.202.202.202
                                                              Mar 25, 2025 13:28:52.876194000 CET5132537692156.229.232.154192.168.2.23
                                                              Mar 25, 2025 13:28:52.876271963 CET3769251325192.168.2.23156.229.232.154
                                                              Mar 25, 2025 13:29:08.045593023 CET5132537692156.229.232.154192.168.2.23
                                                              Mar 25, 2025 13:29:08.045701981 CET3769251325192.168.2.23156.229.232.154
                                                              Mar 25, 2025 13:29:11.586189985 CET43928443192.168.2.2391.189.91.42
                                                              Mar 25, 2025 13:29:22.556917906 CET3769251325192.168.2.23156.229.232.154
                                                              Mar 25, 2025 13:29:22.733388901 CET5132537692156.229.232.154192.168.2.23
                                                              Mar 25, 2025 13:29:22.733505011 CET3769251325192.168.2.23156.229.232.154
                                                              Mar 25, 2025 13:29:35.094475985 CET39244443192.168.2.2334.249.145.219
                                                              Mar 25, 2025 13:29:35.140265942 CET4433924434.249.145.219192.168.2.23
                                                              Mar 25, 2025 13:29:37.931485891 CET5132537692156.229.232.154192.168.2.23
                                                              Mar 25, 2025 13:29:37.931632042 CET3769251325192.168.2.23156.229.232.154
                                                              Mar 25, 2025 13:29:53.100440025 CET5132537692156.229.232.154192.168.2.23
                                                              Mar 25, 2025 13:29:53.100574970 CET3769251325192.168.2.23156.229.232.154
                                                              Mar 25, 2025 13:30:08.270859003 CET5132537692156.229.232.154192.168.2.23
                                                              Mar 25, 2025 13:30:08.271014929 CET3769251325192.168.2.23156.229.232.154
                                                              Mar 25, 2025 13:30:13.840627909 CET4433924434.249.145.219192.168.2.23

                                                              System Behavior

                                                              Start time (UTC):12:28:10
                                                              Start date (UTC):25/03/2025
                                                              Path:/tmp/tmips.elf
                                                              Arguments:-
                                                              File size:5777432 bytes
                                                              MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                                              Start time (UTC):12:28:10
                                                              Start date (UTC):25/03/2025
                                                              Path:/tmp/tmips.elf
                                                              Arguments:-
                                                              File size:5777432 bytes
                                                              MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                                              Start time (UTC):12:29:34
                                                              Start date (UTC):25/03/2025
                                                              Path:/usr/bin/dash
                                                              Arguments:-
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):12:29:34
                                                              Start date (UTC):25/03/2025
                                                              Path:/usr/bin/rm
                                                              Arguments:rm -f /tmp/tmp.60vh05HqZm /tmp/tmp.SX1nC8Yp1N /tmp/tmp.XXcbpQPRHq
                                                              File size:72056 bytes
                                                              MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                                              Start time (UTC):12:29:34
                                                              Start date (UTC):25/03/2025
                                                              Path:/usr/bin/dash
                                                              Arguments:-
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):12:29:34
                                                              Start date (UTC):25/03/2025
                                                              Path:/usr/bin/rm
                                                              Arguments:rm -f /tmp/tmp.60vh05HqZm /tmp/tmp.SX1nC8Yp1N /tmp/tmp.XXcbpQPRHq
                                                              File size:72056 bytes
                                                              MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b