Edit tour

Linux Analysis Report
aarch64.elf

Overview

General Information

Sample name:aarch64.elf
Analysis ID:1648418
MD5:91f3de04571994ff2a9fd46186d1a270
SHA1:4a7868a426352f15b206367e823ceb5dabd8e491
SHA256:964a917a7ff3e871110dfc6ae644fad1c186cf08641034ef11102e1c1f0c2775
Tags:elfuser-abuse_ch
Infos:

Detection

Score:48
Range:0 - 100

Signatures

Performs DNS TXT record lookups
Uses STUN server to do NAT traversial
Detected TCP or UDP traffic on non-standard ports
Enumerates processes within the "proc" file system
Executes the "rm" command used to delete files or directories
Sample has stripped symbol table
Sample listens on a socket
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
Joe Sandbox version:42.0.0 Malachite
Analysis ID:1648418
Start date and time:2025-03-25 20:27:16 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 38s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:aarch64.elf
Detection:MAL
Classification:mal48.troj.evad.linELF@0/2@2/0
  • VT rate limit hit for: kamru.ru
Command:/tmp/aarch64.elf
PID:6261
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
For God so loved the world
Standard Error:
  • system is lnxubuntu20
  • dash New Fork (PID: 6222, Parent: 4331)
  • rm (PID: 6222, Parent: 4331, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.dB4SH9fV01 /tmp/tmp.Z6A6RO522x /tmp/tmp.4hIIbAkk13
  • dash New Fork (PID: 6223, Parent: 4331)
  • cat (PID: 6223, Parent: 4331, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /tmp/tmp.dB4SH9fV01
  • dash New Fork (PID: 6224, Parent: 4331)
  • head (PID: 6224, Parent: 4331, MD5: fd96a67145172477dd57131396fc9608) Arguments: head -n 10
  • dash New Fork (PID: 6225, Parent: 4331)
  • tr (PID: 6225, Parent: 4331, MD5: fbd1402dd9f72d8ebfff00ce7c3a7bb5) Arguments: tr -d \\000-\\011\\013\\014\\016-\\037
  • dash New Fork (PID: 6226, Parent: 4331)
  • cut (PID: 6226, Parent: 4331, MD5: d8ed0ea8f22c0de0f8692d4d9f1759d3) Arguments: cut -c -80
  • dash New Fork (PID: 6227, Parent: 4331)
  • cat (PID: 6227, Parent: 4331, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /tmp/tmp.dB4SH9fV01
  • dash New Fork (PID: 6228, Parent: 4331)
  • head (PID: 6228, Parent: 4331, MD5: fd96a67145172477dd57131396fc9608) Arguments: head -n 10
  • dash New Fork (PID: 6229, Parent: 4331)
  • tr (PID: 6229, Parent: 4331, MD5: fbd1402dd9f72d8ebfff00ce7c3a7bb5) Arguments: tr -d \\000-\\011\\013\\014\\016-\\037
  • dash New Fork (PID: 6230, Parent: 4331)
  • cut (PID: 6230, Parent: 4331, MD5: d8ed0ea8f22c0de0f8692d4d9f1759d3) Arguments: cut -c -80
  • dash New Fork (PID: 6232, Parent: 4331)
  • rm (PID: 6232, Parent: 4331, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.dB4SH9fV01 /tmp/tmp.Z6A6RO522x /tmp/tmp.4hIIbAkk13
  • aarch64.elf (PID: 6261, Parent: 6154, MD5: 02e8e39e1b46472a60d128a6da84a2b8) Arguments: /tmp/aarch64.elf
  • cleanup
No yara matches
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

Networking

barindex
Source: unknownDNS query: name: stun.l.google.com
Source: global trafficTCP traffic: 192.168.2.23:52836 -> 156.244.45.113:52962
Source: global trafficUDP traffic: 192.168.2.23:51595 -> 74.125.250.129:19302
Source: /tmp/aarch64.elf (PID: 6263)Socket: 127.0.0.1:22448Jump to behavior
Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.45.113
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.45.113
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.45.113
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.45.113
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.45.113
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.45.113
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.45.113
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.45.113
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.45.113
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.45.113
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.45.113
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.45.113
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.45.113
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.45.113
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.45.113
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.45.113
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.45.113
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.45.113
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.45.113
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.45.113
Source: unknownUDP traffic detected without corresponding DNS query: 208.67.220.220
Source: global trafficDNS traffic detected: DNS query: kamru.ru
Source: global trafficDNS traffic detected: DNS query: stun.l.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
Source: ELF static info symbol of initial sample.symtab present: no
Source: classification engineClassification label: mal48.troj.evad.linELF@0/2@2/0
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/1582/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/3088/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/230/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/110/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/231/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/111/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/232/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/1579/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/112/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/233/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/1699/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/113/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/234/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/1335/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/1698/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/114/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/235/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/1334/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/1576/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/2302/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/115/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/236/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/116/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/237/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/117/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/118/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/910/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/119/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/912/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/10/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/2307/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/11/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/918/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/12/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/13/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/14/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/15/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/16/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/17/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/18/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/1594/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/120/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/121/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/1349/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/1/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/122/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/243/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/123/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/2/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/124/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/3/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/4/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/125/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/126/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/1344/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/1465/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/1586/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/127/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/6/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/248/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/128/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/249/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/1463/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/800/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/9/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/801/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/20/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/21/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/1900/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/22/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/23/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/24/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/25/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/26/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/27/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/28/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/29/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/491/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/250/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/130/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/251/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/252/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/132/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/253/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/254/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/255/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/4509/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/256/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/1599/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/257/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/1477/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/379/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/258/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/1476/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/259/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/1475/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/936/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/30/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/2208/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/35/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/1809/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/1494/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/260/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/261/cmdlineJump to behavior
Source: /tmp/aarch64.elf (PID: 6261)File opened: /proc/141/cmdlineJump to behavior
Source: /usr/bin/dash (PID: 6222)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.dB4SH9fV01 /tmp/tmp.Z6A6RO522x /tmp/tmp.4hIIbAkk13Jump to behavior
Source: /usr/bin/dash (PID: 6232)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.dB4SH9fV01 /tmp/tmp.Z6A6RO522x /tmp/tmp.4hIIbAkk13Jump to behavior
Source: /tmp/aarch64.elf (PID: 6261)Queries kernel information via 'uname': Jump to behavior
Source: aarch64.elf, 6261.1.00005580b51c3000.00005580b528e000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/aarch64
Source: aarch64.elf, 6261.1.00007ffc7dc1f000.00007ffc7dc40000.rw-.sdmpBinary or memory string: Vx86_64/usr/bin/qemu-aarch64/tmp/aarch64.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/aarch64.elf
Source: aarch64.elf, 6261.1.0000000000425000.0000000000432000.rw-.sdmpBinary or memory string: vmware
Source: aarch64.elf, 6261.1.0000000000425000.0000000000432000.rw-.sdmpBinary or memory string: qemu-arm
Source: aarch64.elf, 6261.1.00005580b51c3000.00005580b528e000.rw-.sdmpBinary or memory string: U1/etc/qemu-binfmt/aarch64O
Source: aarch64.elf, 6261.1.0000000000425000.0000000000432000.rw-.sdmpBinary or memory string: BWcDwXR44ZAkzslsN0 a1gCWFxqAHsFWFMWT3YA!a1gAWFxuAXsFWUgBRQAA!a1gAWFxuAXsAWUgKRXgA!a1gAWFxuAXsAWEgJR3IA!a10CWFxuAHsGWVcWQHAA!a10CWFxuAHsGWVcWQHUA!aFwAWF9uA3sGW0gLRgAA!aFwAWFlpG2QBW0gJTwAA!qemu-arm2QBW0gJTwAA!vmware!/bin/bash!/bin/dash!/bin/shh!/proc/mounts!9.9.9.9unts!1.1.1.1!8.8.8.8!8.8.4.4
Source: aarch64.elf, 6261.1.00007ffc7dc1f000.00007ffc7dc40000.rw-.sdmpBinary or memory string: /usr/bin/qemu-aarch64

HIPS / PFW / Operating System Protection Evasion

barindex
Source: TrafficDNS traffic detected: queries for: kamru.ru
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
File Deletion
1
OS Credential Dumping
11
Security Software Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Standard Port
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Non-Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture2
Application Layer Protocol
Traffic DuplicationData Destruction
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1648418 Sample: aarch64.elf Startdate: 25/03/2025 Architecture: LINUX Score: 48 17 kamru.ru 2->17 19 stun.l.google.com 2->19 21 5 other IPs or domains 2->21 7 dash rm aarch64.elf 2->7         started        9 dash rm 2->9         started        11 dash cut 2->11         started        13 7 other processes 2->13 signatures3 23 Performs DNS TXT record lookups 17->23 25 Uses STUN server to do NAT traversial 19->25 process4 process5 15 aarch64.elf 7->15         started       
SourceDetectionScannerLabelLink
aarch64.elf8%ReversingLabsLinux.Trojan.Mirai
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
stun.l.google.com
74.125.250.129
truefalse
    high
    kamru.ru
    unknown
    unknowntrue
      unknown
      • No. of IPs < 25%
      • 25% < No. of IPs < 50%
      • 50% < No. of IPs < 75%
      • 75% < No. of IPs
      IPDomainCountryFlagASNASN NameMalicious
      156.244.45.113
      unknownSeychelles
      132839POWERLINE-AS-APPOWERLINEDATACENTERHKfalse
      109.202.202.202
      unknownSwitzerland
      13030INIT7CHfalse
      74.125.250.129
      stun.l.google.comUnited States
      15169GOOGLEUSfalse
      91.189.91.43
      unknownUnited Kingdom
      41231CANONICAL-ASGBfalse
      91.189.91.42
      unknownUnited Kingdom
      41231CANONICAL-ASGBfalse
      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
      156.244.45.113kmips.elfGet hashmaliciousUnknownBrowse
        mips.elfGet hashmaliciousUnknownBrowse
          ppc.elfGet hashmaliciousUnknownBrowse
            arm.elfGet hashmaliciousUnknownBrowse
              109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
              • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
              91.189.91.43na.elfGet hashmaliciousPrometeiBrowse
                main_arm7.elfGet hashmaliciousMiraiBrowse
                  main_mpsl.elfGet hashmaliciousMiraiBrowse
                    main_arm6.elfGet hashmaliciousMiraiBrowse
                      na.elfGet hashmaliciousPrometeiBrowse
                        main_x86.elfGet hashmaliciousMiraiBrowse
                          na.elfGet hashmaliciousPrometeiBrowse
                            na.elfGet hashmaliciousPrometeiBrowse
                              boatnet.ppc.elfGet hashmaliciousMiraiBrowse
                                na.elfGet hashmaliciousPrometeiBrowse
                                  91.189.91.42na.elfGet hashmaliciousPrometeiBrowse
                                    main_arm7.elfGet hashmaliciousMiraiBrowse
                                      main_mpsl.elfGet hashmaliciousMiraiBrowse
                                        main_arm6.elfGet hashmaliciousMiraiBrowse
                                          na.elfGet hashmaliciousPrometeiBrowse
                                            main_x86.elfGet hashmaliciousMiraiBrowse
                                              na.elfGet hashmaliciousPrometeiBrowse
                                                na.elfGet hashmaliciousPrometeiBrowse
                                                  boatnet.ppc.elfGet hashmaliciousMiraiBrowse
                                                    na.elfGet hashmaliciousPrometeiBrowse
                                                      No context
                                                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                      CANONICAL-ASGBna.elfGet hashmaliciousPrometeiBrowse
                                                      • 91.189.91.42
                                                      main_arm7.elfGet hashmaliciousMiraiBrowse
                                                      • 91.189.91.42
                                                      main_sh4.elfGet hashmaliciousMiraiBrowse
                                                      • 185.125.190.26
                                                      main_arm5.elfGet hashmaliciousMiraiBrowse
                                                      • 185.125.190.26
                                                      main_mpsl.elfGet hashmaliciousMiraiBrowse
                                                      • 91.189.91.42
                                                      main_arm6.elfGet hashmaliciousMiraiBrowse
                                                      • 91.189.91.42
                                                      na.elfGet hashmaliciousPrometeiBrowse
                                                      • 185.125.190.26
                                                      na.elfGet hashmaliciousPrometeiBrowse
                                                      • 91.189.91.42
                                                      main_x86.elfGet hashmaliciousMiraiBrowse
                                                      • 91.189.91.42
                                                      na.elfGet hashmaliciousPrometeiBrowse
                                                      • 91.189.91.42
                                                      POWERLINE-AS-APPOWERLINEDATACENTERHKboatnet.m68k.elfGet hashmaliciousMiraiBrowse
                                                      • 156.251.7.175
                                                      boatnet.ppc.elfGet hashmaliciousMiraiBrowse
                                                      • 156.242.206.23
                                                      boatnet.mpsl.elfGet hashmaliciousMiraiBrowse
                                                      • 156.244.234.131
                                                      kmips.elfGet hashmaliciousUnknownBrowse
                                                      • 156.244.44.239
                                                      mpsl.elfGet hashmaliciousUnknownBrowse
                                                      • 156.244.14.93
                                                      payment slip$34566.exeGet hashmaliciousFormBookBrowse
                                                      • 202.165.121.125
                                                      DHL_AWB#6078538091.exeGet hashmaliciousFormBookBrowse
                                                      • 45.202.215.236
                                                      mips.elfGet hashmaliciousUnknownBrowse
                                                      • 156.244.44.239
                                                      mips.elfGet hashmaliciousMiraiBrowse
                                                      • 156.251.7.171
                                                      dlr.x86.elfGet hashmaliciousUnknownBrowse
                                                      • 156.253.227.12
                                                      CANONICAL-ASGBna.elfGet hashmaliciousPrometeiBrowse
                                                      • 91.189.91.42
                                                      main_arm7.elfGet hashmaliciousMiraiBrowse
                                                      • 91.189.91.42
                                                      main_sh4.elfGet hashmaliciousMiraiBrowse
                                                      • 185.125.190.26
                                                      main_arm5.elfGet hashmaliciousMiraiBrowse
                                                      • 185.125.190.26
                                                      main_mpsl.elfGet hashmaliciousMiraiBrowse
                                                      • 91.189.91.42
                                                      main_arm6.elfGet hashmaliciousMiraiBrowse
                                                      • 91.189.91.42
                                                      na.elfGet hashmaliciousPrometeiBrowse
                                                      • 185.125.190.26
                                                      na.elfGet hashmaliciousPrometeiBrowse
                                                      • 91.189.91.42
                                                      main_x86.elfGet hashmaliciousMiraiBrowse
                                                      • 91.189.91.42
                                                      na.elfGet hashmaliciousPrometeiBrowse
                                                      • 91.189.91.42
                                                      INIT7CHna.elfGet hashmaliciousPrometeiBrowse
                                                      • 109.202.202.202
                                                      main_arm7.elfGet hashmaliciousMiraiBrowse
                                                      • 109.202.202.202
                                                      main_mpsl.elfGet hashmaliciousMiraiBrowse
                                                      • 109.202.202.202
                                                      main_arm6.elfGet hashmaliciousMiraiBrowse
                                                      • 109.202.202.202
                                                      na.elfGet hashmaliciousPrometeiBrowse
                                                      • 109.202.202.202
                                                      main_x86.elfGet hashmaliciousMiraiBrowse
                                                      • 109.202.202.202
                                                      na.elfGet hashmaliciousPrometeiBrowse
                                                      • 109.202.202.202
                                                      na.elfGet hashmaliciousPrometeiBrowse
                                                      • 109.202.202.202
                                                      boatnet.ppc.elfGet hashmaliciousMiraiBrowse
                                                      • 109.202.202.202
                                                      na.elfGet hashmaliciousPrometeiBrowse
                                                      • 109.202.202.202
                                                      No context
                                                      No context
                                                      Process:/tmp/aarch64.elf
                                                      File Type:ASCII text, with no line terminators
                                                      Category:dropped
                                                      Size (bytes):17
                                                      Entropy (8bit):3.8521687236032816
                                                      Encrypted:false
                                                      SSDEEP:3:Tg80l:Tg8c
                                                      MD5:6EA4D0DB8D845A86C7B09CF0667A2CB5
                                                      SHA1:CE980AAA61B3974BA1C86B48D56CAA6A2BE3E9A1
                                                      SHA-256:9AA96AD31F9C5CB1D9FAA1939C33156D29F6EB7FF422C58541452493FEA19ECD
                                                      SHA-512:A43E0EF92BDE7860BB256540693113AE6594F12017132F7408425FC03074FFE05121C4320FD6126F66802528583AB7A54D3FABBA3E70EB1D9DABFA816EBAFFD9
                                                      Malicious:false
                                                      Reputation:moderate, very likely benign file
                                                      Preview:/tmp/aarch64.elf.
                                                      Process:/tmp/aarch64.elf
                                                      File Type:ASCII text, with no line terminators
                                                      Category:dropped
                                                      Size (bytes):17
                                                      Entropy (8bit):3.8521687236032816
                                                      Encrypted:false
                                                      SSDEEP:3:Tg80l:Tg8c
                                                      MD5:6EA4D0DB8D845A86C7B09CF0667A2CB5
                                                      SHA1:CE980AAA61B3974BA1C86B48D56CAA6A2BE3E9A1
                                                      SHA-256:9AA96AD31F9C5CB1D9FAA1939C33156D29F6EB7FF422C58541452493FEA19ECD
                                                      SHA-512:A43E0EF92BDE7860BB256540693113AE6594F12017132F7408425FC03074FFE05121C4320FD6126F66802528583AB7A54D3FABBA3E70EB1D9DABFA816EBAFFD9
                                                      Malicious:false
                                                      Reputation:moderate, very likely benign file
                                                      Preview:/tmp/aarch64.elf.
                                                      File type:ELF 64-bit LSB executable, ARM aarch64, version 1 (SYSV), statically linked, stripped
                                                      Entropy (8bit):6.303991824550712
                                                      TrID:
                                                      • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                                      File name:aarch64.elf
                                                      File size:83'840 bytes
                                                      MD5:91f3de04571994ff2a9fd46186d1a270
                                                      SHA1:4a7868a426352f15b206367e823ceb5dabd8e491
                                                      SHA256:964a917a7ff3e871110dfc6ae644fad1c186cf08641034ef11102e1c1f0c2775
                                                      SHA512:9b0fecd05e8c69e19d2a267efbb4a756404e6da3be6538719b601ad7caaa04bf2d51ff7224244b40bb628bf4d5a9b5f0ca433b4f914b5d55c0ab393cf6c9caea
                                                      SSDEEP:1536:Ani48YqLqoEXl2H0+bQxEUsojhBnDWmukNDC:SGYHXm0+bQxEU2muam
                                                      TLSH:24838DB8764F7DA1D3CBD379DE458B72712B74E4C3B192A4BE12432EC0D39AA8AD0541
                                                      File Content Preview:.ELF......................@.....@........D..........@.8...@.......................@.......@......1.......1.......................?.......?B......?B..... ................................?.......?B......?B.............................Q.td...................

                                                      ELF header

                                                      Class:ELF64
                                                      Data:2's complement, little endian
                                                      Version:1 (current)
                                                      Machine:AArch64
                                                      Version Number:0x1
                                                      Type:EXEC (Executable file)
                                                      OS/ABI:UNIX - System V
                                                      ABI Version:0
                                                      Entry Point Address:0x400910
                                                      Flags:0x0
                                                      ELF Header Size:64
                                                      Program Header Offset:64
                                                      Program Header Size:56
                                                      Number of Program Headers:4
                                                      Section Header Offset:83072
                                                      Section Header Size:64
                                                      Number of Section Headers:12
                                                      Header String Table Index:11
                                                      NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                      NULL0x00x00x00x00x0000
                                                      .initPROGBITS0x4001580x1580x100x00x6AX004
                                                      .textPROGBITS0x4001800x1800x117b00x00x6AX0064
                                                      .finiPROGBITS0x4119300x119300x100x00x6AX004
                                                      .rodataPROGBITS0x4119400x119400x18500x00x2A0016
                                                      .tbssNOBITS0x423f080x13f080x80x00x403WAT004
                                                      .init_arrayINIT_ARRAY0x423f080x13f080x80x80x3WA008
                                                      .fini_arrayFINI_ARRAY0x423f100x13f100x80x80x3WA008
                                                      .gotPROGBITS0x423f180x13f180xd00x80x3WA008
                                                      .dataPROGBITS0x4240000x140000x4280x00x3WA008
                                                      .bssNOBITS0x4244280x144280x7cb80x00x3WA008
                                                      .shstrtabSTRTAB0x00x144280x530x00x0001
                                                      TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                      LOAD0x00x4000000x4000000x131900x131906.53970x5R E0x10000.init .text .fini .rodata
                                                      LOAD0x13f080x423f080x423f080x5200x81d82.81900x6RW 0x10000.tbss .init_array .fini_array .got .data .bss
                                                      TLS0x13f080x423f080x423f080x00x80.00000x4R 0x4.tbss
                                                      GNU_STACK0x00x00x00x00x00.00000x6RW 0x8

                                                      Download Network PCAP: filteredfull

                                                      • Total Packets: 30
                                                      • 52962 undefined
                                                      • 19302 undefined
                                                      • 443 (HTTPS)
                                                      • 80 (HTTP)
                                                      • 53 (DNS)
                                                      TimestampSource PortDest PortSource IPDest IP
                                                      Mar 25, 2025 20:28:02.472704887 CET43928443192.168.2.2391.189.91.42
                                                      Mar 25, 2025 20:28:04.237615108 CET5283652962192.168.2.23156.244.45.113
                                                      Mar 25, 2025 20:28:04.401314974 CET5296252836156.244.45.113192.168.2.23
                                                      Mar 25, 2025 20:28:04.403978109 CET5283652962192.168.2.23156.244.45.113
                                                      Mar 25, 2025 20:28:04.566622972 CET5296252836156.244.45.113192.168.2.23
                                                      Mar 25, 2025 20:28:04.566853046 CET5283652962192.168.2.23156.244.45.113
                                                      Mar 25, 2025 20:28:04.729290962 CET5296252836156.244.45.113192.168.2.23
                                                      Mar 25, 2025 20:28:04.729516983 CET5283652962192.168.2.23156.244.45.113
                                                      Mar 25, 2025 20:28:05.637424946 CET5283652962192.168.2.23156.244.45.113
                                                      Mar 25, 2025 20:28:05.798089981 CET5296252836156.244.45.113192.168.2.23
                                                      Mar 25, 2025 20:28:07.848015070 CET42836443192.168.2.2391.189.91.43
                                                      Mar 25, 2025 20:28:09.639827967 CET4251680192.168.2.23109.202.202.202
                                                      Mar 25, 2025 20:28:10.117980003 CET5296252836156.244.45.113192.168.2.23
                                                      Mar 25, 2025 20:28:10.118232012 CET5283652962192.168.2.23156.244.45.113
                                                      Mar 25, 2025 20:28:22.438014030 CET43928443192.168.2.2391.189.91.42
                                                      Mar 25, 2025 20:28:25.131747007 CET5283652962192.168.2.23156.244.45.113
                                                      Mar 25, 2025 20:28:25.296272039 CET5296252836156.244.45.113192.168.2.23
                                                      Mar 25, 2025 20:28:25.296542883 CET5283652962192.168.2.23156.244.45.113
                                                      Mar 25, 2025 20:28:25.473489046 CET5296252836156.244.45.113192.168.2.23
                                                      Mar 25, 2025 20:28:34.724291086 CET42836443192.168.2.2391.189.91.43
                                                      Mar 25, 2025 20:28:40.867451906 CET4251680192.168.2.23109.202.202.202
                                                      Mar 25, 2025 20:28:43.011207104 CET5283652962192.168.2.23156.244.45.113
                                                      Mar 25, 2025 20:28:43.176039934 CET5296252836156.244.45.113192.168.2.23
                                                      Mar 25, 2025 20:28:43.176156998 CET5283652962192.168.2.23156.244.45.113
                                                      Mar 25, 2025 20:28:43.619189978 CET5283652962192.168.2.23156.244.45.113
                                                      Mar 25, 2025 20:28:43.780806065 CET5296252836156.244.45.113192.168.2.23
                                                      Mar 25, 2025 20:29:00.994498014 CET5283652962192.168.2.23156.244.45.113
                                                      Mar 25, 2025 20:29:01.157305002 CET5296252836156.244.45.113192.168.2.23
                                                      Mar 25, 2025 20:29:01.157438993 CET5283652962192.168.2.23156.244.45.113
                                                      Mar 25, 2025 20:29:01.323000908 CET5296252836156.244.45.113192.168.2.23
                                                      Mar 25, 2025 20:29:03.392347097 CET43928443192.168.2.2391.189.91.42
                                                      Mar 25, 2025 20:29:19.475142956 CET5283652962192.168.2.23156.244.45.113
                                                      Mar 25, 2025 20:29:19.638097048 CET5296252836156.244.45.113192.168.2.23
                                                      Mar 25, 2025 20:29:19.638329983 CET5283652962192.168.2.23156.244.45.113
                                                      Mar 25, 2025 20:29:19.801024914 CET5296252836156.244.45.113192.168.2.23
                                                      Mar 25, 2025 20:29:25.257111073 CET5296252836156.244.45.113192.168.2.23
                                                      Mar 25, 2025 20:29:25.257401943 CET5283652962192.168.2.23156.244.45.113
                                                      Mar 25, 2025 20:29:40.271503925 CET5283652962192.168.2.23156.244.45.113
                                                      Mar 25, 2025 20:29:40.432048082 CET5296252836156.244.45.113192.168.2.23
                                                      Mar 25, 2025 20:29:40.432365894 CET5283652962192.168.2.23156.244.45.113
                                                      Mar 25, 2025 20:29:40.597476959 CET5296252836156.244.45.113192.168.2.23
                                                      Mar 25, 2025 20:29:59.600382090 CET5283652962192.168.2.23156.244.45.113
                                                      Mar 25, 2025 20:29:59.760864019 CET5296252836156.244.45.113192.168.2.23
                                                      Mar 25, 2025 20:29:59.761173010 CET5283652962192.168.2.23156.244.45.113
                                                      Mar 25, 2025 20:29:59.922952890 CET5296252836156.244.45.113192.168.2.23
                                                      TimestampSource PortDest PortSource IPDest IP
                                                      Mar 25, 2025 20:28:04.054425001 CET4686953192.168.2.23208.67.220.220
                                                      Mar 25, 2025 20:28:04.235938072 CET5346869208.67.220.220192.168.2.23
                                                      Mar 25, 2025 20:28:05.425718069 CET5997153192.168.2.238.8.4.4
                                                      Mar 25, 2025 20:28:05.531322956 CET53599718.8.4.4192.168.2.23
                                                      Mar 25, 2025 20:28:05.532274961 CET5159519302192.168.2.2374.125.250.129
                                                      Mar 25, 2025 20:28:05.635978937 CET193025159574.125.250.129192.168.2.23
                                                      TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                                      Mar 25, 2025 20:28:04.054425001 CET192.168.2.23208.67.220.2200xf773Standard query (0)kamru.ru16IN (0x0001)false
                                                      Mar 25, 2025 20:28:05.425718069 CET192.168.2.238.8.4.40xcd82Standard query (0)stun.l.google.comA (IP address)IN (0x0001)false
                                                      TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                                      Mar 25, 2025 20:28:04.235938072 CET208.67.220.220192.168.2.230xf773No error (0)kamru.ruTXT (Text strings)IN (0x0001)false
                                                      Mar 25, 2025 20:28:05.531322956 CET8.8.4.4192.168.2.230xcd82No error (0)stun.l.google.com74.125.250.129A (IP address)IN (0x0001)false

                                                      System Behavior

                                                      Start time (UTC):19:27:56
                                                      Start date (UTC):25/03/2025
                                                      Path:/usr/bin/dash
                                                      Arguments:-
                                                      File size:129816 bytes
                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                      Start time (UTC):19:27:56
                                                      Start date (UTC):25/03/2025
                                                      Path:/usr/bin/rm
                                                      Arguments:rm -f /tmp/tmp.dB4SH9fV01 /tmp/tmp.Z6A6RO522x /tmp/tmp.4hIIbAkk13
                                                      File size:72056 bytes
                                                      MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                                      Start time (UTC):19:27:56
                                                      Start date (UTC):25/03/2025
                                                      Path:/usr/bin/dash
                                                      Arguments:-
                                                      File size:129816 bytes
                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                      Start time (UTC):19:27:56
                                                      Start date (UTC):25/03/2025
                                                      Path:/usr/bin/cat
                                                      Arguments:cat /tmp/tmp.dB4SH9fV01
                                                      File size:43416 bytes
                                                      MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

                                                      Start time (UTC):19:27:56
                                                      Start date (UTC):25/03/2025
                                                      Path:/usr/bin/dash
                                                      Arguments:-
                                                      File size:129816 bytes
                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                      Start time (UTC):19:27:56
                                                      Start date (UTC):25/03/2025
                                                      Path:/usr/bin/head
                                                      Arguments:head -n 10
                                                      File size:47480 bytes
                                                      MD5 hash:fd96a67145172477dd57131396fc9608

                                                      Start time (UTC):19:27:56
                                                      Start date (UTC):25/03/2025
                                                      Path:/usr/bin/dash
                                                      Arguments:-
                                                      File size:129816 bytes
                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                      Start time (UTC):19:27:56
                                                      Start date (UTC):25/03/2025
                                                      Path:/usr/bin/tr
                                                      Arguments:tr -d \\000-\\011\\013\\014\\016-\\037
                                                      File size:51544 bytes
                                                      MD5 hash:fbd1402dd9f72d8ebfff00ce7c3a7bb5

                                                      Start time (UTC):19:27:56
                                                      Start date (UTC):25/03/2025
                                                      Path:/usr/bin/dash
                                                      Arguments:-
                                                      File size:129816 bytes
                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                      Start time (UTC):19:27:56
                                                      Start date (UTC):25/03/2025
                                                      Path:/usr/bin/cut
                                                      Arguments:cut -c -80
                                                      File size:47480 bytes
                                                      MD5 hash:d8ed0ea8f22c0de0f8692d4d9f1759d3

                                                      Start time (UTC):19:27:56
                                                      Start date (UTC):25/03/2025
                                                      Path:/usr/bin/dash
                                                      Arguments:-
                                                      File size:129816 bytes
                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                      Start time (UTC):19:27:56
                                                      Start date (UTC):25/03/2025
                                                      Path:/usr/bin/cat
                                                      Arguments:cat /tmp/tmp.dB4SH9fV01
                                                      File size:43416 bytes
                                                      MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

                                                      Start time (UTC):19:27:56
                                                      Start date (UTC):25/03/2025
                                                      Path:/usr/bin/dash
                                                      Arguments:-
                                                      File size:129816 bytes
                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                      Start time (UTC):19:27:56
                                                      Start date (UTC):25/03/2025
                                                      Path:/usr/bin/head
                                                      Arguments:head -n 10
                                                      File size:47480 bytes
                                                      MD5 hash:fd96a67145172477dd57131396fc9608

                                                      Start time (UTC):19:27:56
                                                      Start date (UTC):25/03/2025
                                                      Path:/usr/bin/dash
                                                      Arguments:-
                                                      File size:129816 bytes
                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                      Start time (UTC):19:27:56
                                                      Start date (UTC):25/03/2025
                                                      Path:/usr/bin/tr
                                                      Arguments:tr -d \\000-\\011\\013\\014\\016-\\037
                                                      File size:51544 bytes
                                                      MD5 hash:fbd1402dd9f72d8ebfff00ce7c3a7bb5

                                                      Start time (UTC):19:27:56
                                                      Start date (UTC):25/03/2025
                                                      Path:/usr/bin/dash
                                                      Arguments:-
                                                      File size:129816 bytes
                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                      Start time (UTC):19:27:56
                                                      Start date (UTC):25/03/2025
                                                      Path:/usr/bin/cut
                                                      Arguments:cut -c -80
                                                      File size:47480 bytes
                                                      MD5 hash:d8ed0ea8f22c0de0f8692d4d9f1759d3

                                                      Start time (UTC):19:27:57
                                                      Start date (UTC):25/03/2025
                                                      Path:/usr/bin/dash
                                                      Arguments:-
                                                      File size:129816 bytes
                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                      Start time (UTC):19:27:57
                                                      Start date (UTC):25/03/2025
                                                      Path:/usr/bin/rm
                                                      Arguments:rm -f /tmp/tmp.dB4SH9fV01 /tmp/tmp.Z6A6RO522x /tmp/tmp.4hIIbAkk13
                                                      File size:72056 bytes
                                                      MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                                      Start time (UTC):19:28:02
                                                      Start date (UTC):25/03/2025
                                                      Path:/tmp/aarch64.elf
                                                      Arguments:-
                                                      File size:5706200 bytes
                                                      MD5 hash:02e8e39e1b46472a60d128a6da84a2b8