Edit tour

Linux Analysis Report
fz5Tmv3Ptj

Overview

General Information

Sample name:fz5Tmv3Ptj
renamed because original name is a hash value
Original sample name:eaac61873d59bd83717155104ba559f3814ed87788788301449432efcb01738a
Analysis ID:1670375
MD5:425cb4110c5744797296f53454fa4286
SHA1:a7a18c6c63cc0f848826baff87c23b6f9c482021
SHA256:eaac61873d59bd83717155104ba559f3814ed87788788301449432efcb01738a
Infos:

Detection

Score:56
Range:0 - 100

Signatures

Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Creates hidden files and/or directories
Executes the "rm" command used to delete files or directories
Sample file is different than original file name gathered from version info
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
Joe Sandbox version:42.0.0 Malachite
Analysis ID:1670375
Start date and time:2025-04-21 17:07:17 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 59s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:fz5Tmv3Ptj
renamed because original name is a hash value
Original Sample Name:eaac61873d59bd83717155104ba559f3814ed87788788301449432efcb01738a
Detection:MAL
Classification:mal56.lin@0/1@0/0
Command:xdg-open "/tmp/fz5Tmv3Ptj"
PID:6231
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:

Standard Error:
  • system is lnxubuntu20
  • exo-open (PID: 6243, Parent: 6231, MD5: 60a307a6a6325e2034eb5cc56bff1abd) Arguments: exo-open /tmp/fz5Tmv3Ptj
    • exo-open New Fork (PID: 6245, Parent: 6243)
    • dbus-launch (PID: 6245, Parent: 6243, MD5: 0b22a45154a51c6121bb1d208d8ab203) Arguments: dbus-launch --autolaunch=ee49dfd4fa47433baee88884e2d7de7c --binary-syntax --close-stderr
    • exo-open New Fork (PID: 6247, Parent: 6243)
      • exo-open New Fork (PID: 6248, Parent: 6247)
      • sh (PID: 6248, Parent: 1860, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh engrampa /tmp/fz5Tmv3Ptj
      • engrampa (PID: 6248, Parent: 1860, MD5: 39fede466e21a42b973e73b62cc7fc09) Arguments: engrampa /tmp/fz5Tmv3Ptj
        • engrampa New Fork (PID: 6253, Parent: 6248)
        • dbus-launch (PID: 6253, Parent: 6248, MD5: 0b22a45154a51c6121bb1d208d8ab203) Arguments: dbus-launch --autolaunch=ee49dfd4fa47433baee88884e2d7de7c --binary-syntax --close-stderr
        • engrampa New Fork (PID: 6261, Parent: 6248)
        • 7z (PID: 6261, Parent: 6248, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: 7z l -slt -bd -y -- /tmp/fz5Tmv3Ptj
        • 7z (PID: 6261, Parent: 6248, MD5: cfe89433a3a8ace0cb1ef30f9d766693) Arguments: /usr/lib/p7zip/7z l -slt -bd -y -- /tmp/fz5Tmv3Ptj
  • dash New Fork (PID: 6290, Parent: 4333)
  • rm (PID: 6290, Parent: 4333, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.AOeGpLHUI5 /tmp/tmp.vGZ2d9AO7Q /tmp/tmp.iWxJLJWJ9l
  • dash New Fork (PID: 6291, Parent: 4333)
  • cat (PID: 6291, Parent: 4333, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /tmp/tmp.AOeGpLHUI5
  • dash New Fork (PID: 6292, Parent: 4333)
  • head (PID: 6292, Parent: 4333, MD5: fd96a67145172477dd57131396fc9608) Arguments: head -n 10
  • dash New Fork (PID: 6293, Parent: 4333)
  • tr (PID: 6293, Parent: 4333, MD5: fbd1402dd9f72d8ebfff00ce7c3a7bb5) Arguments: tr -d \\000-\\011\\013\\014\\016-\\037
  • dash New Fork (PID: 6294, Parent: 4333)
  • cut (PID: 6294, Parent: 4333, MD5: d8ed0ea8f22c0de0f8692d4d9f1759d3) Arguments: cut -c -80
  • dash New Fork (PID: 6295, Parent: 4333)
  • cat (PID: 6295, Parent: 4333, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /tmp/tmp.AOeGpLHUI5
  • dash New Fork (PID: 6296, Parent: 4333)
  • head (PID: 6296, Parent: 4333, MD5: fd96a67145172477dd57131396fc9608) Arguments: head -n 10
  • dash New Fork (PID: 6297, Parent: 4333)
  • tr (PID: 6297, Parent: 4333, MD5: fbd1402dd9f72d8ebfff00ce7c3a7bb5) Arguments: tr -d \\000-\\011\\013\\014\\016-\\037
  • dash New Fork (PID: 6298, Parent: 4333)
  • cut (PID: 6298, Parent: 4333, MD5: d8ed0ea8f22c0de0f8692d4d9f1759d3) Arguments: cut -c -80
  • dash New Fork (PID: 6299, Parent: 4333)
  • rm (PID: 6299, Parent: 4333, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.AOeGpLHUI5 /tmp/tmp.vGZ2d9AO7Q /tmp/tmp.iWxJLJWJ9l
  • cleanup
No yara matches
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: fz5Tmv3PtjAvira: detected
Source: fz5Tmv3PtjVirustotal: Detection: 81%Perma Link
Source: fz5Tmv3PtjReversingLabs: Detection: 63%
Source: unknownHTTPS traffic detected: 54.171.230.55:443 -> 192.168.2.23:33606 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 33606
Source: unknownNetwork traffic detected: HTTP traffic on port 33606 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
Source: unknownHTTPS traffic detected: 54.171.230.55:443 -> 192.168.2.23:33606 version: TLS 1.2
Source: fz5Tmv3PtjBinary or memory string: OriginalFilenameInclude3RECOGNISE6.exe vs fz5Tmv3Ptj
Source: classification engineClassification label: mal56.lin@0/1@0/0
Source: /usr/bin/exo-open (PID: 6243)Directory: /root/.Xdefaults-galassiaJump to behavior
Source: /usr/bin/exo-open (PID: 6243)Directory: /root/.cacheJump to behavior
Source: /usr/bin/engrampa (PID: 6248)Directory: /root/.Xdefaults-galassiaJump to behavior
Source: /usr/bin/engrampa (PID: 6248)Directory: /usr/share/fonts/.uuidJump to behavior
Source: /usr/bin/engrampa (PID: 6248)Directory: /usr/local/share/fonts/.uuidJump to behavior
Source: /usr/bin/engrampa (PID: 6248)Directory: /root/.local/share/fonts/.uuidJump to behavior
Source: /usr/bin/engrampa (PID: 6248)Directory: /root/.fonts/.uuidJump to behavior
Source: /usr/bin/engrampa (PID: 6248)Directory: /usr/share/fonts/X11/.uuidJump to behavior
Source: /usr/bin/engrampa (PID: 6248)Directory: /usr/share/fonts/cMap/.uuidJump to behavior
Source: /usr/bin/engrampa (PID: 6248)Directory: /usr/share/fonts/cmap/.uuidJump to behavior
Source: /usr/bin/engrampa (PID: 6248)Directory: /usr/share/fonts/opentype/.uuidJump to behavior
Source: /usr/bin/engrampa (PID: 6248)Directory: /usr/share/fonts/truetype/.uuidJump to behavior
Source: /usr/bin/engrampa (PID: 6248)Directory: /usr/share/fonts/type1/.uuidJump to behavior
Source: /usr/bin/engrampa (PID: 6248)Directory: /usr/share/fonts/X11/Type1/.uuidJump to behavior
Source: /usr/bin/engrampa (PID: 6248)Directory: /usr/share/fonts/X11/encodings/.uuidJump to behavior
Source: /usr/bin/engrampa (PID: 6248)Directory: /usr/share/fonts/X11/misc/.uuidJump to behavior
Source: /usr/bin/engrampa (PID: 6248)Directory: /usr/share/fonts/X11/util/.uuidJump to behavior
Source: /usr/bin/engrampa (PID: 6248)Directory: /usr/share/fonts/cmap/adobe-cns1/.uuidJump to behavior
Source: /usr/bin/engrampa (PID: 6248)Directory: /usr/share/fonts/cmap/adobe-gb1/.uuidJump to behavior
Source: /usr/bin/engrampa (PID: 6248)Directory: /usr/share/fonts/cmap/adobe-japan1/.uuidJump to behavior
Source: /usr/bin/engrampa (PID: 6248)Directory: /usr/share/fonts/cmap/adobe-japan2/.uuidJump to behavior
Source: /usr/bin/engrampa (PID: 6248)Directory: /usr/share/fonts/cmap/adobe-korea1/.uuidJump to behavior
Source: /usr/bin/engrampa (PID: 6248)Directory: /usr/share/fonts/opentype/malayalam/.uuidJump to behavior
Source: /usr/bin/engrampa (PID: 6248)Directory: /usr/share/fonts/opentype/mathjax/.uuidJump to behavior
Source: /usr/bin/engrampa (PID: 6248)Directory: /usr/share/fonts/opentype/noto/.uuidJump to behavior
Source: /usr/bin/engrampa (PID: 6248)Directory: /usr/share/fonts/opentype/urw-base35/.uuidJump to behavior
Source: /usr/bin/engrampa (PID: 6248)Directory: /usr/share/fonts/truetype/Gargi/.uuidJump to behavior
Source: /usr/bin/engrampa (PID: 6248)Directory: /usr/share/fonts/truetype/Gubbi/.uuidJump to behavior
Source: /usr/bin/engrampa (PID: 6248)Directory: /usr/share/fonts/truetype/Nakula/.uuidJump to behavior
Source: /usr/bin/engrampa (PID: 6248)Directory: /usr/share/fonts/truetype/Navilu/.uuidJump to behavior
Source: /usr/bin/engrampa (PID: 6248)Directory: /usr/share/fonts/truetype/Sahadeva/.uuidJump to behavior
Source: /usr/bin/engrampa (PID: 6248)Directory: /usr/share/fonts/truetype/Sarai/.uuidJump to behavior
Source: /usr/bin/engrampa (PID: 6248)Directory: /usr/share/fonts/truetype/abyssinica/.uuidJump to behavior
Source: /usr/bin/engrampa (PID: 6248)Directory: /usr/share/fonts/truetype/ancient-scripts/.uuidJump to behavior
Source: /usr/bin/engrampa (PID: 6248)Directory: /usr/share/fonts/truetype/dejavu/.uuidJump to behavior
Source: /usr/bin/engrampa (PID: 6248)Directory: /usr/share/fonts/truetype/droid/.uuidJump to behavior
Source: /usr/bin/engrampa (PID: 6248)Directory: /usr/share/fonts/truetype/fonts-beng-extra/.uuidJump to behavior
Source: /usr/bin/engrampa (PID: 6248)Directory: /usr/share/fonts/truetype/fonts-deva-extra/.uuidJump to behavior
Source: /usr/bin/engrampa (PID: 6248)Directory: /usr/share/fonts/truetype/fonts-gujr-extra/.uuidJump to behavior
Source: /usr/bin/engrampa (PID: 6248)Directory: /usr/share/fonts/truetype/fonts-guru-extra/.uuidJump to behavior
Source: /usr/bin/engrampa (PID: 6248)Directory: /usr/share/fonts/truetype/fonts-kalapi/.uuidJump to behavior
Source: /usr/bin/engrampa (PID: 6248)Directory: /usr/share/fonts/truetype/fonts-orya-extra/.uuidJump to behavior
Source: /usr/bin/engrampa (PID: 6248)Directory: /usr/share/fonts/truetype/fonts-telu-extra/.uuidJump to behavior
Source: /usr/bin/engrampa (PID: 6248)Directory: /usr/share/fonts/truetype/fonts-yrsa-rasa/.uuidJump to behavior
Source: /usr/bin/engrampa (PID: 6248)Directory: /usr/share/fonts/truetype/freefont/.uuidJump to behavior
Source: /usr/bin/engrampa (PID: 6248)Directory: /usr/share/fonts/truetype/kacst/.uuidJump to behavior
Source: /usr/bin/engrampa (PID: 6248)Directory: /usr/share/fonts/truetype/kacst-one/.uuidJump to behavior
Source: /usr/bin/engrampa (PID: 6248)Directory: /usr/share/fonts/truetype/lao/.uuidJump to behavior
Source: /usr/bin/engrampa (PID: 6248)Directory: /usr/share/fonts/truetype/lato/.uuidJump to behavior
Source: /usr/bin/engrampa (PID: 6248)Directory: /usr/share/fonts/truetype/liberation/.uuidJump to behavior
Source: /usr/bin/engrampa (PID: 6248)Directory: /usr/share/fonts/truetype/liberation2/.uuidJump to behavior
Source: /usr/bin/engrampa (PID: 6248)Directory: /usr/share/fonts/truetype/lohit-assamese/.uuidJump to behavior
Source: /usr/bin/engrampa (PID: 6248)Directory: /usr/share/fonts/truetype/lohit-bengali/.uuidJump to behavior
Source: /usr/bin/engrampa (PID: 6248)Directory: /usr/share/fonts/truetype/lohit-devanagari/.uuidJump to behavior
Source: /usr/bin/engrampa (PID: 6248)Directory: /usr/share/fonts/truetype/lohit-gujarati/.uuidJump to behavior
Source: /usr/bin/engrampa (PID: 6248)Directory: /usr/share/fonts/truetype/lohit-kannada/.uuidJump to behavior
Source: /usr/bin/engrampa (PID: 6248)Directory: /usr/share/fonts/truetype/lohit-malayalam/.uuidJump to behavior
Source: /usr/bin/engrampa (PID: 6248)Directory: /usr/share/fonts/truetype/lohit-oriya/.uuidJump to behavior
Source: /usr/bin/engrampa (PID: 6248)Directory: /usr/share/fonts/truetype/lohit-punjabi/.uuidJump to behavior
Source: /usr/bin/engrampa (PID: 6248)Directory: /usr/share/fonts/truetype/lohit-tamil/.uuidJump to behavior
Source: /usr/bin/engrampa (PID: 6248)Directory: /usr/share/fonts/truetype/lohit-tamil-classical/.uuidJump to behavior
Source: /usr/bin/engrampa (PID: 6248)Directory: /usr/share/fonts/truetype/lohit-telugu/.uuidJump to behavior
Source: /usr/bin/engrampa (PID: 6248)Directory: /usr/share/fonts/truetype/malayalam/.uuidJump to behavior
Source: /usr/bin/engrampa (PID: 6248)Directory: /usr/share/fonts/truetype/noto/.uuidJump to behavior
Source: /usr/bin/engrampa (PID: 6248)Directory: /usr/share/fonts/truetype/openoffice/.uuidJump to behavior
Source: /usr/bin/engrampa (PID: 6248)Directory: /usr/share/fonts/truetype/padauk/.uuidJump to behavior
Source: /usr/bin/engrampa (PID: 6248)Directory: /usr/share/fonts/truetype/pagul/.uuidJump to behavior
Source: /usr/bin/engrampa (PID: 6248)Directory: /usr/share/fonts/truetype/samyak/.uuidJump to behavior
Source: /usr/bin/engrampa (PID: 6248)Directory: /usr/share/fonts/truetype/samyak-fonts/.uuidJump to behavior
Source: /usr/bin/engrampa (PID: 6248)Directory: /usr/share/fonts/truetype/sinhala/.uuidJump to behavior
Source: /usr/bin/engrampa (PID: 6248)Directory: /usr/share/fonts/truetype/tibetan-machine/.uuidJump to behavior
Source: /usr/bin/engrampa (PID: 6248)Directory: /usr/share/fonts/truetype/tlwg/.uuidJump to behavior
Source: /usr/bin/engrampa (PID: 6248)Directory: /usr/share/fonts/truetype/ttf-khmeros-core/.uuidJump to behavior
Source: /usr/bin/engrampa (PID: 6248)Directory: /usr/share/fonts/truetype/ubuntu/.uuidJump to behavior
Source: /usr/bin/engrampa (PID: 6248)Directory: /usr/share/fonts/type1/urw-base35/.uuidJump to behavior
Source: /usr/bin/engrampa (PID: 6248)Directory: /usr/share/fonts/X11/encodings/large/.uuidJump to behavior
Source: /usr/bin/engrampa (PID: 6248)Directory: /root/.cacheJump to behavior
Source: /usr/bin/dash (PID: 6290)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.AOeGpLHUI5 /tmp/tmp.vGZ2d9AO7Q /tmp/tmp.iWxJLJWJ9lJump to behavior
Source: /usr/bin/dash (PID: 6299)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.AOeGpLHUI5 /tmp/tmp.vGZ2d9AO7Q /tmp/tmp.iWxJLJWJ9lJump to behavior
Source: /usr/bin/exo-open (PID: 6243)Queries kernel information via 'uname': Jump to behavior
Source: /usr/bin/dbus-launch (PID: 6245)Queries kernel information via 'uname': Jump to behavior
Source: /usr/bin/engrampa (PID: 6248)Queries kernel information via 'uname': Jump to behavior
Source: /usr/bin/dbus-launch (PID: 6253)Queries kernel information via 'uname': Jump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
Hidden Files and Directories
OS Credential Dumping1
Security Software Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
File Deletion
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1670375 Sample: fz5Tmv3Ptj Startdate: 21/04/2025 Architecture: LINUX Score: 56 27 109.202.202.202, 80 INIT7CH Switzerland 2->27 29 91.189.91.42, 443 CANONICAL-ASGB United Kingdom 2->29 31 2 other IPs or domains 2->31 33 Antivirus / Scanner detection for submitted sample 2->33 35 Multi AV Scanner detection for submitted file 2->35 9 exo-open 2->9         started        11 dash rm 2->11         started        13 dash cat 2->13         started        15 8 other processes 2->15 signatures3 process4 process5 17 exo-open 9->17         started        19 exo-open dbus-launch 9->19         started        process6 21 exo-open sh engrampa 17->21         started        process7 23 engrampa 7z 7z 21->23         started        25 engrampa dbus-launch 21->25         started       

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
fz5Tmv3Ptj82%VirustotalBrowse
fz5Tmv3Ptj63%ReversingLabsWin32.Infostealer.Pony
fz5Tmv3Ptj100%AviraHEUR/AGEN.1335043
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

No contacted domains info
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs
IPDomainCountryFlagASNASN NameMalicious
54.171.230.55
unknownUnited States
16509AMAZON-02USfalse
109.202.202.202
unknownSwitzerland
13030INIT7CHfalse
91.189.91.43
unknownUnited Kingdom
41231CANONICAL-ASGBfalse
91.189.91.42
unknownUnited Kingdom
41231CANONICAL-ASGBfalse
MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
54.171.230.55na.elfGet hashmaliciousPrometeiBrowse
    mpsl.elfGet hashmaliciousUnknownBrowse
      arm5.elfGet hashmaliciousUnknownBrowse
        na.elfGet hashmaliciousPrometeiBrowse
          sshd.elfGet hashmaliciousUnknownBrowse
            mpsl.elfGet hashmaliciousMiraiBrowse
              na.elfGet hashmaliciousPrometeiBrowse
                na.elfGet hashmaliciousPrometeiBrowse
                  na.elfGet hashmaliciousPrometeiBrowse
                    na.elfGet hashmaliciousPrometeiBrowse
                      109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
                      • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
                      91.189.91.43na.elfGet hashmaliciousPrometeiBrowse
                        mpsl.elfGet hashmaliciousUnknownBrowse
                          na.elfGet hashmaliciousPrometeiBrowse
                            na.elfGet hashmaliciousPrometeiBrowse
                              arm7.elfGet hashmaliciousUnknownBrowse
                                na.elfGet hashmaliciousPrometeiBrowse
                                  sh4.elfGet hashmaliciousUnknownBrowse
                                    na.elfGet hashmaliciousPrometeiBrowse
                                      na.elfGet hashmaliciousPrometeiBrowse
                                        sshd.elfGet hashmaliciousUnknownBrowse
                                          91.189.91.42na.elfGet hashmaliciousPrometeiBrowse
                                            mpsl.elfGet hashmaliciousUnknownBrowse
                                              na.elfGet hashmaliciousPrometeiBrowse
                                                na.elfGet hashmaliciousPrometeiBrowse
                                                  arm7.elfGet hashmaliciousUnknownBrowse
                                                    na.elfGet hashmaliciousPrometeiBrowse
                                                      sh4.elfGet hashmaliciousUnknownBrowse
                                                        na.elfGet hashmaliciousPrometeiBrowse
                                                          na.elfGet hashmaliciousPrometeiBrowse
                                                            sshd.elfGet hashmaliciousUnknownBrowse
                                                              No context
                                                              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                              CANONICAL-ASGBna.elfGet hashmaliciousPrometeiBrowse
                                                              • 91.189.91.42
                                                              mpsl.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 91.189.91.42
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 91.189.91.42
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 185.125.190.26
                                                              arm5.elfGet hashmaliciousUnknownBrowse
                                                              • 185.125.190.26
                                                              arm7.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 91.189.91.42
                                                              sh4.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 91.189.91.42
                                                              CANONICAL-ASGBna.elfGet hashmaliciousPrometeiBrowse
                                                              • 91.189.91.42
                                                              mpsl.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 91.189.91.42
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 91.189.91.42
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 185.125.190.26
                                                              arm5.elfGet hashmaliciousUnknownBrowse
                                                              • 185.125.190.26
                                                              arm7.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 91.189.91.42
                                                              sh4.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 91.189.91.42
                                                              AMAZON-02UShttp://url7554.impulseup.com/ls/click?upn=u001.9-2FTADgI74e2OWE2P3fvtm3ks0lxIlIFyP5IwbLoDgBuxxxaTOIUzJMW49-2B9jqW6yELBC1ZQRMe6TWLgjPYTu0LiDQ0w3txTcOK6-2FV2ifPZbRaLIwmmOQ1GMQC9dU6RWb2aeLLtDeODHngY3VjjXvJO6oKDlYY-2FrsIGLii2s3kEKAZFDtf-2BL31aMPuCVwlwPCr7PEQRptcwz1QBhdaSd2LGMdK1VJSRTe40dM32Z7Jz2jBBbK0UwZYo0lLPRxihoyt5eczvkRV2tuefWun26R7i639CvHIPVt6rH7EVtY4Yq4-2BX81bSKNRYMont-2BURzxOXvIrvc-2FmXDxBQFquNv8hCg-3D-3DPxtu_kuLj0dlFrLQsusO5Mbu6XvxpF4v8Jh1YKIsyjo7kzqXHRNE-2FOEVeSM0JICDQ5Tjy3bDgrl5OEVa68odvHNoZBJ6QfGYxcZ7BcXQ0WuvBPrC4VIuEfyEiZxZfLfZFvQ5wdhpAQB1fL-2FQ-2FmD3MevXlsgh-2FpnZWiDIriKQI8exmRbTtK9cjB1NJ40PcJ-2B0p5yN6nYDdiFYbxlYib2Opu1bSYg-3D-3DGet hashmaliciousHTMLPhisherBrowse
                                                              • 54.188.148.71
                                                              https://meksygroup.com/konsole/xneelo/#talk@gofuckyourselfscammer.comGet hashmaliciousHTMLPhisherBrowse
                                                              • 3.168.132.91
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 34.245.175.187
                                                              mpsl.elfGet hashmaliciousUnknownBrowse
                                                              • 54.171.230.55
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 34.249.145.219
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 34.245.175.187
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 54.247.62.1
                                                              arm5.elfGet hashmaliciousUnknownBrowse
                                                              • 34.243.160.129
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 34.249.145.219
                                                              Bank Details.exeGet hashmaliciousFormBookBrowse
                                                              • 13.248.169.48
                                                              INIT7CHna.elfGet hashmaliciousPrometeiBrowse
                                                              • 109.202.202.202
                                                              mpsl.elfGet hashmaliciousUnknownBrowse
                                                              • 109.202.202.202
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 109.202.202.202
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 109.202.202.202
                                                              arm7.elfGet hashmaliciousUnknownBrowse
                                                              • 109.202.202.202
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 109.202.202.202
                                                              sh4.elfGet hashmaliciousUnknownBrowse
                                                              • 109.202.202.202
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 109.202.202.202
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 109.202.202.202
                                                              sshd.elfGet hashmaliciousUnknownBrowse
                                                              • 109.202.202.202
                                                              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                              fb4726d465c5f28b84cd6d14cedd13a7na.elfGet hashmaliciousPrometeiBrowse
                                                              • 54.171.230.55
                                                              mpsl.elfGet hashmaliciousUnknownBrowse
                                                              • 54.171.230.55
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 54.171.230.55
                                                              sshd.elfGet hashmaliciousUnknownBrowse
                                                              • 54.171.230.55
                                                              x86.elfGet hashmaliciousMiraiBrowse
                                                              • 54.171.230.55
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 54.171.230.55
                                                              i-5.8-6.Sakura.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                              • 54.171.230.55
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 54.171.230.55
                                                              b9cpju.sh4.elfGet hashmaliciousMiraiBrowse
                                                              • 54.171.230.55
                                                              4omzl4.mips.elfGet hashmaliciousMiraiBrowse
                                                              • 54.171.230.55
                                                              No context
                                                              Process:/usr/bin/engrampa
                                                              File Type:data
                                                              Category:dropped
                                                              Size (bytes):2
                                                              Entropy (8bit):0.0
                                                              Encrypted:false
                                                              SSDEEP:3::
                                                              MD5:C4103F122D27677C9DB144CAE1394A66
                                                              SHA1:1489F923C4DCA729178B3E3233458550D8DDDF29
                                                              SHA-256:96A296D224F285C67BEE93C30F8A309157F0DAA35DC5B87E410B78630A09CFC7
                                                              SHA-512:5EA71DC6D0B4F57BF39AADD07C208C35F06CD2BAC5FDE210397F70DE11D439C62EC1CDF3183758865FD387FCEA0BADA2F6C37A4A17851DD1D78FEFE6F204EE54
                                                              Malicious:false
                                                              Reputation:moderate, very likely benign file
                                                              Preview:..
                                                              File type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                              Entropy (8bit):6.758281702285964
                                                              TrID:
                                                              • Win32 Executable (generic) a (10002005/4) 99.96%
                                                              • Generic Win/DOS Executable (2004/3) 0.02%
                                                              • DOS Executable Generic (2002/1) 0.02%
                                                              • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
                                                              File name:fz5Tmv3Ptj
                                                              File size:569'344 bytes
                                                              MD5:425cb4110c5744797296f53454fa4286
                                                              SHA1:a7a18c6c63cc0f848826baff87c23b6f9c482021
                                                              SHA256:eaac61873d59bd83717155104ba559f3814ed87788788301449432efcb01738a
                                                              SHA512:464d0d10effd2dff46a458a2cc6ec5e324c5e67c5ac821f555ca2a147d74333ea2c084ca5480776b6e137db4eef75093e892890eb1e427f86e015388b203fd91
                                                              SSDEEP:12288:4/dEOVfH6MzGjqxCIqre59iyp8dqvKgnzjWi:4mOVfaMzGjDvAiyp8Rg
                                                              TLSH:1BC401C56222D2F6F5F5A2B0C728C8E598C5633B6D12359331B8572FE05AA0A5D38F1F
                                                              File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.............i...i...i...d...i.Rich..i.................PE..L.....&?.....................@....................@........................

                                                              Download Network PCAP: filteredfull

                                                              • Total Packets: 21
                                                              • 443 (HTTPS)
                                                              • 80 (HTTP)
                                                              TimestampSource PortDest PortSource IPDest IP
                                                              Apr 21, 2025 17:07:58.269366980 CEST33606443192.168.2.2354.171.230.55
                                                              Apr 21, 2025 17:08:01.660895109 CEST33606443192.168.2.2354.171.230.55
                                                              Apr 21, 2025 17:08:01.660902023 CEST43928443192.168.2.2391.189.91.42
                                                              Apr 21, 2025 17:08:07.292207956 CEST42836443192.168.2.2391.189.91.43
                                                              Apr 21, 2025 17:08:08.316126108 CEST33606443192.168.2.2354.171.230.55
                                                              Apr 21, 2025 17:08:08.828018904 CEST4251680192.168.2.23109.202.202.202
                                                              Apr 21, 2025 17:08:21.626446009 CEST33606443192.168.2.2354.171.230.55
                                                              Apr 21, 2025 17:08:21.904217958 CEST4433360654.171.230.55192.168.2.23
                                                              Apr 21, 2025 17:08:22.138397932 CEST43928443192.168.2.2391.189.91.42
                                                              Apr 21, 2025 17:08:26.303143978 CEST4433360654.171.230.55192.168.2.23
                                                              Apr 21, 2025 17:08:26.303164959 CEST4433360654.171.230.55192.168.2.23
                                                              Apr 21, 2025 17:08:26.303175926 CEST4433360654.171.230.55192.168.2.23
                                                              Apr 21, 2025 17:08:26.303522110 CEST33606443192.168.2.2354.171.230.55
                                                              Apr 21, 2025 17:08:26.303522110 CEST33606443192.168.2.2354.171.230.55
                                                              Apr 21, 2025 17:08:26.303522110 CEST33606443192.168.2.2354.171.230.55
                                                              Apr 21, 2025 17:08:26.306871891 CEST33606443192.168.2.2354.171.230.55
                                                              Apr 21, 2025 17:08:26.614006042 CEST4433360654.171.230.55192.168.2.23
                                                              Apr 21, 2025 17:08:26.777890921 CEST4433360654.171.230.55192.168.2.23
                                                              Apr 21, 2025 17:08:26.778208017 CEST33606443192.168.2.2354.171.230.55
                                                              Apr 21, 2025 17:08:26.778431892 CEST33606443192.168.2.2354.171.230.55
                                                              Apr 21, 2025 17:08:27.094388008 CEST4433360654.171.230.55192.168.2.23
                                                              Apr 21, 2025 17:08:27.097636938 CEST4433360654.171.230.55192.168.2.23
                                                              Apr 21, 2025 17:08:27.097843885 CEST33606443192.168.2.2354.171.230.55
                                                              Apr 21, 2025 17:08:27.100064039 CEST33606443192.168.2.2354.171.230.55
                                                              Apr 21, 2025 17:08:27.415862083 CEST4433360654.171.230.55192.168.2.23
                                                              Apr 21, 2025 17:08:27.415879011 CEST4433360654.171.230.55192.168.2.23
                                                              Apr 21, 2025 17:08:27.415982962 CEST33606443192.168.2.2354.171.230.55
                                                              Apr 21, 2025 17:08:27.415982962 CEST33606443192.168.2.2354.171.230.55
                                                              Apr 21, 2025 17:08:34.424689054 CEST42836443192.168.2.2391.189.91.43
                                                              Apr 21, 2025 17:08:38.520102024 CEST4251680192.168.2.23109.202.202.202
                                                              Apr 21, 2025 17:09:03.092904091 CEST43928443192.168.2.2391.189.91.42
                                                              TimestampSource IPSource PortDest IPDest PortSubjectIssuerNot BeforeNot AfterJA3 SSL Client FingerprintJA3 SSL Client Digest
                                                              Apr 21, 2025 17:08:26.303175926 CEST54.171.230.55443192.168.2.2333606CN=motd.ubuntu.com CN=R10, O=Let's Encrypt, C=USCN=R10, O=Let's Encrypt, C=US CN=ISRG Root X1, O=Internet Security Research Group, C=USSat Mar 22 09:18:05 CET 2025 Wed Mar 13 01:00:00 CET 2024Fri Jun 20 10:18:04 CEST 2025 Sat Mar 13 00:59:59 CET 2027771,4866-4867-4865-49196-49200-163-159-52393-52392-52394-49327-49325-49315-49311-49245-49249-49239-49235-49195-49199-162-158-49326-49324-49314-49310-49244-49248-49238-49234-49188-49192-107-106-49267-49271-196-195-49187-49191-103-64-49266-49270-190-189-49162-49172-57-56-136-135-49161-49171-51-50-69-68-157-49313-49309-49233-156-49312-49308-49232-61-192-60-186-53-132-47-65-255,0-11-10-35-22-23-13-43-45-51,29-23-30-25-24,0-1-2fb4726d465c5f28b84cd6d14cedd13a7
                                                              CN=R10, O=Let's Encrypt, C=USCN=ISRG Root X1, O=Internet Security Research Group, C=USWed Mar 13 01:00:00 CET 2024Sat Mar 13 00:59:59 CET 2027

                                                              System Behavior

                                                              Start time (UTC):15:07:59
                                                              Start date (UTC):21/04/2025
                                                              Path:/usr/bin/exo-open
                                                              Arguments:exo-open /tmp/fz5Tmv3Ptj
                                                              File size:27264 bytes
                                                              MD5 hash:60a307a6a6325e2034eb5cc56bff1abd

                                                              Start time (UTC):15:07:59
                                                              Start date (UTC):21/04/2025
                                                              Path:/usr/bin/exo-open
                                                              Arguments:-
                                                              File size:27264 bytes
                                                              MD5 hash:60a307a6a6325e2034eb5cc56bff1abd

                                                              Start time (UTC):15:07:59
                                                              Start date (UTC):21/04/2025
                                                              Path:/usr/bin/dbus-launch
                                                              Arguments:dbus-launch --autolaunch=ee49dfd4fa47433baee88884e2d7de7c --binary-syntax --close-stderr
                                                              File size:34960 bytes
                                                              MD5 hash:0b22a45154a51c6121bb1d208d8ab203

                                                              Start time (UTC):15:07:59
                                                              Start date (UTC):21/04/2025
                                                              Path:/usr/bin/exo-open
                                                              Arguments:-
                                                              File size:27264 bytes
                                                              MD5 hash:60a307a6a6325e2034eb5cc56bff1abd

                                                              Start time (UTC):15:07:59
                                                              Start date (UTC):21/04/2025
                                                              Path:/usr/bin/exo-open
                                                              Arguments:-
                                                              File size:27264 bytes
                                                              MD5 hash:60a307a6a6325e2034eb5cc56bff1abd

                                                              Start time (UTC):15:07:59
                                                              Start date (UTC):21/04/2025
                                                              Path:/bin/sh
                                                              Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh engrampa /tmp/fz5Tmv3Ptj
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):15:07:59
                                                              Start date (UTC):21/04/2025
                                                              Path:/usr/bin/engrampa
                                                              Arguments:engrampa /tmp/fz5Tmv3Ptj
                                                              File size:492616 bytes
                                                              MD5 hash:39fede466e21a42b973e73b62cc7fc09

                                                              Start time (UTC):15:08:00
                                                              Start date (UTC):21/04/2025
                                                              Path:/usr/bin/engrampa
                                                              Arguments:-
                                                              File size:492616 bytes
                                                              MD5 hash:39fede466e21a42b973e73b62cc7fc09

                                                              Start time (UTC):15:08:00
                                                              Start date (UTC):21/04/2025
                                                              Path:/usr/bin/dbus-launch
                                                              Arguments:dbus-launch --autolaunch=ee49dfd4fa47433baee88884e2d7de7c --binary-syntax --close-stderr
                                                              File size:34960 bytes
                                                              MD5 hash:0b22a45154a51c6121bb1d208d8ab203

                                                              Start time (UTC):15:08:02
                                                              Start date (UTC):21/04/2025
                                                              Path:/usr/bin/engrampa
                                                              Arguments:-
                                                              File size:492616 bytes
                                                              MD5 hash:39fede466e21a42b973e73b62cc7fc09

                                                              Start time (UTC):15:08:02
                                                              Start date (UTC):21/04/2025
                                                              Path:/usr/bin/7z
                                                              Arguments:7z l -slt -bd -y -- /tmp/fz5Tmv3Ptj
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):15:08:02
                                                              Start date (UTC):21/04/2025
                                                              Path:/usr/lib/p7zip/7z
                                                              Arguments:/usr/lib/p7zip/7z l -slt -bd -y -- /tmp/fz5Tmv3Ptj
                                                              File size:601776 bytes
                                                              MD5 hash:cfe89433a3a8ace0cb1ef30f9d766693

                                                              Start time (UTC):15:08:25
                                                              Start date (UTC):21/04/2025
                                                              Path:/usr/bin/dash
                                                              Arguments:-
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):15:08:25
                                                              Start date (UTC):21/04/2025
                                                              Path:/usr/bin/rm
                                                              Arguments:rm -f /tmp/tmp.AOeGpLHUI5 /tmp/tmp.vGZ2d9AO7Q /tmp/tmp.iWxJLJWJ9l
                                                              File size:72056 bytes
                                                              MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                                              Start time (UTC):15:08:25
                                                              Start date (UTC):21/04/2025
                                                              Path:/usr/bin/dash
                                                              Arguments:-
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):15:08:25
                                                              Start date (UTC):21/04/2025
                                                              Path:/usr/bin/cat
                                                              Arguments:cat /tmp/tmp.AOeGpLHUI5
                                                              File size:43416 bytes
                                                              MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

                                                              Start time (UTC):15:08:25
                                                              Start date (UTC):21/04/2025
                                                              Path:/usr/bin/dash
                                                              Arguments:-
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):15:08:25
                                                              Start date (UTC):21/04/2025
                                                              Path:/usr/bin/head
                                                              Arguments:head -n 10
                                                              File size:47480 bytes
                                                              MD5 hash:fd96a67145172477dd57131396fc9608

                                                              Start time (UTC):15:08:25
                                                              Start date (UTC):21/04/2025
                                                              Path:/usr/bin/dash
                                                              Arguments:-
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):15:08:25
                                                              Start date (UTC):21/04/2025
                                                              Path:/usr/bin/tr
                                                              Arguments:tr -d \\000-\\011\\013\\014\\016-\\037
                                                              File size:51544 bytes
                                                              MD5 hash:fbd1402dd9f72d8ebfff00ce7c3a7bb5

                                                              Start time (UTC):15:08:25
                                                              Start date (UTC):21/04/2025
                                                              Path:/usr/bin/dash
                                                              Arguments:-
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):15:08:25
                                                              Start date (UTC):21/04/2025
                                                              Path:/usr/bin/cut
                                                              Arguments:cut -c -80
                                                              File size:47480 bytes
                                                              MD5 hash:d8ed0ea8f22c0de0f8692d4d9f1759d3

                                                              Start time (UTC):15:08:26
                                                              Start date (UTC):21/04/2025
                                                              Path:/usr/bin/dash
                                                              Arguments:-
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):15:08:26
                                                              Start date (UTC):21/04/2025
                                                              Path:/usr/bin/cat
                                                              Arguments:cat /tmp/tmp.AOeGpLHUI5
                                                              File size:43416 bytes
                                                              MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

                                                              Start time (UTC):15:08:26
                                                              Start date (UTC):21/04/2025
                                                              Path:/usr/bin/dash
                                                              Arguments:-
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):15:08:26
                                                              Start date (UTC):21/04/2025
                                                              Path:/usr/bin/head
                                                              Arguments:head -n 10
                                                              File size:47480 bytes
                                                              MD5 hash:fd96a67145172477dd57131396fc9608

                                                              Start time (UTC):15:08:26
                                                              Start date (UTC):21/04/2025
                                                              Path:/usr/bin/dash
                                                              Arguments:-
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):15:08:26
                                                              Start date (UTC):21/04/2025
                                                              Path:/usr/bin/tr
                                                              Arguments:tr -d \\000-\\011\\013\\014\\016-\\037
                                                              File size:51544 bytes
                                                              MD5 hash:fbd1402dd9f72d8ebfff00ce7c3a7bb5

                                                              Start time (UTC):15:08:26
                                                              Start date (UTC):21/04/2025
                                                              Path:/usr/bin/dash
                                                              Arguments:-
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):15:08:26
                                                              Start date (UTC):21/04/2025
                                                              Path:/usr/bin/cut
                                                              Arguments:cut -c -80
                                                              File size:47480 bytes
                                                              MD5 hash:d8ed0ea8f22c0de0f8692d4d9f1759d3

                                                              Start time (UTC):15:08:26
                                                              Start date (UTC):21/04/2025
                                                              Path:/usr/bin/dash
                                                              Arguments:-
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):15:08:26
                                                              Start date (UTC):21/04/2025
                                                              Path:/usr/bin/rm
                                                              Arguments:rm -f /tmp/tmp.AOeGpLHUI5 /tmp/tmp.vGZ2d9AO7Q /tmp/tmp.iWxJLJWJ9l
                                                              File size:72056 bytes
                                                              MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b