Loading ...

Play interactive tourEdit tour

Linux Analysis Report 1TnmkstVG8

Overview

General Information

Sample Name:1TnmkstVG8
Analysis ID:511513
MD5:2f7ce4fdab3edd7aed014bd5a124c718
SHA1:0b1e76fac74052db6e7a342cdba0f90622100093
SHA256:6597350ca45adfe532bd93ffde9c92d98f2ed1ecedd4d7d73c6dd147b0b613a9
Tags:32elfmiraisparc
Infos:

Detection

Score:48
Range:0 - 100
Whitelisted:false

Signatures

Multi AV Scanner detection for submitted file
Sample has stripped symbol table
Uses the "uname" system call to query kernel version information (possible evasion)
Detected TCP or UDP traffic on non-standard ports
Executes the "rm" command used to delete files or directories

Classification

Analysis Advice

Static ELF header machine description suggests that the sample might not execute correctly on this machine

General Information

Joe Sandbox Version:34.0.0 Boulder Opal
Analysis ID:511513
Start date:29.10.2021
Start time:08:49:09
Joe Sandbox Product:CloudBasic
Overall analysis duration:0h 4m 52s
Hypervisor based Inspection enabled:false
Report type:light
Sample file name:1TnmkstVG8
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Detection:MAL
Classification:mal48.lin@0/1@0/0

Process Tree

  • system is lnxubuntu20
  • 1TnmkstVG8 (PID: 5234, Parent: 5107, MD5: 7dc1c0e23cd5e102bb12e5c29403410e) Arguments: /tmp/1TnmkstVG8
  • dash New Fork (PID: 5250, Parent: 4331)
  • cat (PID: 5250, Parent: 4331, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /tmp/tmp.gtT3aisjF5
  • dash New Fork (PID: 5251, Parent: 4331)
  • head (PID: 5251, Parent: 4331, MD5: fd96a67145172477dd57131396fc9608) Arguments: head -n 10
  • dash New Fork (PID: 5252, Parent: 4331)
  • tr (PID: 5252, Parent: 4331, MD5: fbd1402dd9f72d8ebfff00ce7c3a7bb5) Arguments: tr -d \\000-\\011\\013\\014\\016-\\037
  • dash New Fork (PID: 5253, Parent: 4331)
  • cut (PID: 5253, Parent: 4331, MD5: d8ed0ea8f22c0de0f8692d4d9f1759d3) Arguments: cut -c -80
  • dash New Fork (PID: 5254, Parent: 4331)
  • cat (PID: 5254, Parent: 4331, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /tmp/tmp.gtT3aisjF5
  • dash New Fork (PID: 5255, Parent: 4331)
  • head (PID: 5255, Parent: 4331, MD5: fd96a67145172477dd57131396fc9608) Arguments: head -n 10
  • dash New Fork (PID: 5256, Parent: 4331)
  • tr (PID: 5256, Parent: 4331, MD5: fbd1402dd9f72d8ebfff00ce7c3a7bb5) Arguments: tr -d \\000-\\011\\013\\014\\016-\\037
  • dash New Fork (PID: 5257, Parent: 4331)
  • cut (PID: 5257, Parent: 4331, MD5: d8ed0ea8f22c0de0f8692d4d9f1759d3) Arguments: cut -c -80
  • dash New Fork (PID: 5258, Parent: 4331)
  • rm (PID: 5258, Parent: 4331, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.gtT3aisjF5 /tmp/tmp.0HpvoUv25y /tmp/tmp.kZRxhtfsZX
  • cleanup

Yara Overview

No yara matches

Jbx Signature Overview

Click to jump to signature section

Show All Signature Results

AV Detection:

barindex
Multi AV Scanner detection for submitted fileShow sources
Source: 1TnmkstVG8Virustotal: Detection: 21%Perma Link
Source: 1TnmkstVG8ReversingLabs: Detection: 15%
Source: unknownHTTPS traffic detected: 34.249.145.219:443 -> 192.168.2.23:39244 version: TLS 1.2
Source: global trafficTCP traffic: 192.168.2.23:56596 -> 45.95.169.120:455
Source: unknownNetwork traffic detected: HTTP traffic on port 39244 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39244
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
Source: unknownTCP traffic detected without corresponding DNS query: 189.57.206.167
Source: unknownTCP traffic detected without corresponding DNS query: 189.57.206.167
Source: unknownTCP traffic detected without corresponding DNS query: 37.80.245.107
Source: unknownTCP traffic detected without corresponding DNS query: 37.80.245.107
Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 34.249.145.219
Source: unknownTCP traffic detected without corresponding DNS query: 34.249.145.219
Source: unknownTCP traffic detected without corresponding DNS query: 34.249.145.219
Source: unknownTCP traffic detected without corresponding DNS query: 34.249.145.219
Source: unknownTCP traffic detected without corresponding DNS query: 34.249.145.219
Source: unknownTCP traffic detected without corresponding DNS query: 34.249.145.219
Source: unknownTCP traffic detected without corresponding DNS query: 34.249.145.219
Source: unknownTCP traffic detected without corresponding DNS query: 34.249.145.219
Source: unknownTCP traffic detected without corresponding DNS query: 34.249.145.219
Source: unknownTCP traffic detected without corresponding DNS query: 34.249.145.219
Source: unknownTCP traffic detected without corresponding DNS query: 34.249.145.219
Source: unknownTCP traffic detected without corresponding DNS query: 34.249.145.219
Source: unknownTCP traffic detected without corresponding DNS query: 34.249.145.219
Source: unknownTCP traffic detected without corresponding DNS query: 34.249.145.219
Source: unknownTCP traffic detected without corresponding DNS query: 34.249.145.219
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
Source: unknownTCP traffic detected without corresponding DNS query: 46.244.112.164
Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
Source: motd-news.26.drString found in binary or memory: https://ubuntu.com/blog/microk8s-memory-optimisation
Source: unknownHTTPS traffic detected: 34.249.145.219:443 -> 192.168.2.23:39244 version: TLS 1.2
Source: ELF static info symbol of initial sample.symtab present: no
Source: classification engineClassification label: mal48.lin@0/1@0/0
Source: 1TnmkstVG8Joe Sandbox Cloud Basic: Detection: clean Score: 0Perma Link
Source: /usr/bin/dash (PID: 5258)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.gtT3aisjF5 /tmp/tmp.0HpvoUv25y /tmp/tmp.kZRxhtfsZX
Source: /tmp/1TnmkstVG8 (PID: 5234)Queries kernel information via 'uname':
Source: 1TnmkstVG8, 5234.1.000000004a6d2c84.00000000a49abd7e.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/sparc
Source: 1TnmkstVG8, 5234.1.000000004a6d2c84.00000000a49abd7e.rw-.sdmpBinary or memory string: V!/etc/qemu-binfmt/sparc
Source: 1TnmkstVG8, 5234.1.00000000580ce957.0000000071851ce0.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-sparc/tmp/1TnmkstVG8SUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/1TnmkstVG8
Source: 1TnmkstVG8, 5234.1.00000000580ce957.0000000071851ce0.rw-.sdmpBinary or memory string: /usr/bin/qemu-sparc

Mitre Att&ck Matrix

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionFile Deletion1OS Credential DumpingSecurity Software Discovery11Remote ServicesData from Local SystemExfiltration Over Other Network MediumEncrypted Channel1Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over BluetoothNon-Standard Port1Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationApplication Layer Protocol1Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data

Malware Configuration

No configs have been found

Behavior Graph

Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 511513 Sample: 1TnmkstVG8 Startdate: 29/10/2021 Architecture: LINUX Score: 48 17 189.57.206.167, 23, 45062 TELEFONICABRASILSABR Brazil 2->17 19 109.202.202.202, 80 INIT7CH Switzerland 2->19 21 6 other IPs or domains 2->21 23 Multi AV Scanner detection for submitted file 2->23 7 1TnmkstVG8 2->7         started        9 dash cat 2->9         started        11 dash head 2->11         started        13 7 other processes 2->13 signatures3 process4 process5 15 1TnmkstVG8 7->15         started       

Antivirus, Machine Learning and Genetic Malware Detection

Initial Sample

SourceDetectionScannerLabelLink
1TnmkstVG821%VirustotalBrowse
1TnmkstVG816%ReversingLabsLinux.Trojan.Mirai

Dropped Files

No Antivirus matches

Domains

No Antivirus matches

URLs

No Antivirus matches

Domains and IPs

Contacted Domains

No contacted domains info

URLs from Memory and Binaries

NameSourceMaliciousAntivirus DetectionReputation
https://ubuntu.com/blog/microk8s-memory-optimisationmotd-news.26.drfalse
    high

    Contacted IPs

    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs

    Public

    IPDomainCountryFlagASNASN NameMalicious
    34.249.145.219
    unknownUnited States
    16509AMAZON-02USfalse
    45.95.169.120
    unknownCroatia (LOCAL Name: Hrvatska)
    42864GIGANET-HUGigaNetInternetServiceProviderCoHUfalse
    46.244.112.164
    unknownNetherlands
    51088A2BNLfalse
    109.202.202.202
    unknownSwitzerland
    13030INIT7CHfalse
    189.57.206.167
    unknownBrazil
    10429TELEFONICABRASILSABRfalse
    37.80.245.107
    unknownGermany
    3320DTAGInternetserviceprovideroperationsDEfalse
    91.189.91.43
    unknownUnited Kingdom
    41231CANONICAL-ASGBfalse
    91.189.91.42
    unknownUnited Kingdom
    41231CANONICAL-ASGBfalse


    Runtime Messages

    Command:/tmp/1TnmkstVG8
    Exit Code:0
    Exit Code Info:
    Killed:False
    Standard Output:

    Standard Error:

    Joe Sandbox View / Context

    IPs

    MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
    34.249.145.219gqqrsjn4g8Get hashmaliciousBrowse
      10CV2biW2dGet hashmaliciousBrowse
        r7bQAtiN68Get hashmaliciousBrowse
          3QM8LROaOkGet hashmaliciousBrowse
            75OHlqPaRYGet hashmaliciousBrowse
              0ZDPmKTgifGet hashmaliciousBrowse
                1qQcsK7dthGet hashmaliciousBrowse
                  vCLbAS7aPbGet hashmaliciousBrowse
                    yzui4gwsrFGet hashmaliciousBrowse
                      072FZHiMhsGet hashmaliciousBrowse
                        sjZlfrpuycGet hashmaliciousBrowse
                          cqhVIEs3KrGet hashmaliciousBrowse
                            khoE2I8yerGet hashmaliciousBrowse
                              wvsEoQ0khPGet hashmaliciousBrowse
                                o5WNbxsf8EGet hashmaliciousBrowse
                                  32Get hashmaliciousBrowse
                                    a-r.m-5.SakuraGet hashmaliciousBrowse
                                      NDYfrLSNFWGet hashmaliciousBrowse
                                        m-i.p-s.SakuraGet hashmaliciousBrowse
                                          6Qn1b9fB2CGet hashmaliciousBrowse
                                            45.95.169.120iksM5QEg2jGet hashmaliciousBrowse
                                              109.202.202.202iksM5QEg2jGet hashmaliciousBrowse
                                                lGJEkz80oeGet hashmaliciousBrowse
                                                  roV7kGaVr1Get hashmaliciousBrowse
                                                    SecuriteInfo.com.Linux.Siggen.4218.298.3210Get hashmaliciousBrowse
                                                      uPOWBxniTAGet hashmaliciousBrowse
                                                        qy5unieRgRGet hashmaliciousBrowse
                                                          sAzPpn6mKZGet hashmaliciousBrowse
                                                            AxadDC89j9Get hashmaliciousBrowse
                                                              ZErnXU2XR1Get hashmaliciousBrowse
                                                                sTHJvS5LPJGet hashmaliciousBrowse
                                                                  THzHjYQ4z6Get hashmaliciousBrowse
                                                                    jC0B6sMh1dGet hashmaliciousBrowse
                                                                      JoLmvC65B7Get hashmaliciousBrowse
                                                                        AOaKSm1cijGet hashmaliciousBrowse
                                                                          Mozi.aGet hashmaliciousBrowse
                                                                            ggbMKQDdG2Get hashmaliciousBrowse
                                                                              SecuriteInfo.com.Linux.Siggen.4218.31606.9155Get hashmaliciousBrowse
                                                                                AbriuSDkeLGet hashmaliciousBrowse
                                                                                  xjmPNreY8IGet hashmaliciousBrowse
                                                                                    u7kjf23xQcGet hashmaliciousBrowse
                                                                                      91.189.91.43iksM5QEg2jGet hashmaliciousBrowse
                                                                                        lGJEkz80oeGet hashmaliciousBrowse
                                                                                          roV7kGaVr1Get hashmaliciousBrowse
                                                                                            SecuriteInfo.com.Linux.Siggen.4218.298.3210Get hashmaliciousBrowse
                                                                                              uPOWBxniTAGet hashmaliciousBrowse
                                                                                                qy5unieRgRGet hashmaliciousBrowse
                                                                                                  sAzPpn6mKZGet hashmaliciousBrowse
                                                                                                    AxadDC89j9Get hashmaliciousBrowse
                                                                                                      ZErnXU2XR1Get hashmaliciousBrowse
                                                                                                        sTHJvS5LPJGet hashmaliciousBrowse
                                                                                                          THzHjYQ4z6Get hashmaliciousBrowse
                                                                                                            jC0B6sMh1dGet hashmaliciousBrowse
                                                                                                              JoLmvC65B7Get hashmaliciousBrowse
                                                                                                                AOaKSm1cijGet hashmaliciousBrowse
                                                                                                                  Mozi.aGet hashmaliciousBrowse
                                                                                                                    ggbMKQDdG2Get hashmaliciousBrowse
                                                                                                                      SecuriteInfo.com.Linux.Siggen.4218.31606.9155Get hashmaliciousBrowse
                                                                                                                        AbriuSDkeLGet hashmaliciousBrowse
                                                                                                                          xjmPNreY8IGet hashmaliciousBrowse
                                                                                                                            u7kjf23xQcGet hashmaliciousBrowse

                                                                                                                              Domains

                                                                                                                              No context

                                                                                                                              ASN

                                                                                                                              MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                                                              GIGANET-HUGigaNetInternetServiceProviderCoHUiksM5QEg2jGet hashmaliciousBrowse
                                                                                                                              • 45.95.169.120
                                                                                                                              RicwIfIHLKGet hashmaliciousBrowse
                                                                                                                              • 45.95.169.115
                                                                                                                              aIY7AxjUMcGet hashmaliciousBrowse
                                                                                                                              • 45.95.169.115
                                                                                                                              DtJmFQxtNCGet hashmaliciousBrowse
                                                                                                                              • 45.95.169.115
                                                                                                                              Wm4CzOCmNYGet hashmaliciousBrowse
                                                                                                                              • 45.95.169.115
                                                                                                                              vunWUzXJvCGet hashmaliciousBrowse
                                                                                                                              • 45.95.169.115
                                                                                                                              52xhBHy9WzGet hashmaliciousBrowse
                                                                                                                              • 45.95.169.115
                                                                                                                              YGvwG0iCDEGet hashmaliciousBrowse
                                                                                                                              • 45.95.169.115
                                                                                                                              dbd5O0RUTqGet hashmaliciousBrowse
                                                                                                                              • 45.95.169.115
                                                                                                                              fHVDVj0pzOGet hashmaliciousBrowse
                                                                                                                              • 45.95.169.115
                                                                                                                              eZPk7Fg5w7Get hashmaliciousBrowse
                                                                                                                              • 45.95.169.115
                                                                                                                              ph5PjoFBpjGet hashmaliciousBrowse
                                                                                                                              • 45.95.169.115
                                                                                                                              xugAk5haatGet hashmaliciousBrowse
                                                                                                                              • 45.95.169.115
                                                                                                                              0jEbWQtzs0Get hashmaliciousBrowse
                                                                                                                              • 45.95.169.115
                                                                                                                              8g3tc5SWwBGet hashmaliciousBrowse
                                                                                                                              • 92.52.211.220
                                                                                                                              7okgnZjK06Get hashmaliciousBrowse
                                                                                                                              • 45.95.169.115
                                                                                                                              D9efs9TYvNGet hashmaliciousBrowse
                                                                                                                              • 45.95.169.115
                                                                                                                              LlE7nUUjmAGet hashmaliciousBrowse
                                                                                                                              • 45.95.169.115
                                                                                                                              3HwsuWd7atGet hashmaliciousBrowse
                                                                                                                              • 45.95.169.115
                                                                                                                              XOg0GKdALNGet hashmaliciousBrowse
                                                                                                                              • 45.95.169.115
                                                                                                                              A2BNLjew.arm5Get hashmaliciousBrowse
                                                                                                                              • 46.244.107.145
                                                                                                                              SecuriteInfo.com.Trojan.DownLoader41.25700.7371.exeGet hashmaliciousBrowse
                                                                                                                              • 46.235.44.240
                                                                                                                              5zLdHcC6nh.exeGet hashmaliciousBrowse
                                                                                                                              • 46.235.40.105
                                                                                                                              http://www.bagchusfotografie.nl/foto/laurentiusdag/me/app.htmlGet hashmaliciousBrowse
                                                                                                                              • 46.235.40.90
                                                                                                                              ElectionInterference_1665557063.xlsGet hashmaliciousBrowse
                                                                                                                              • 46.235.42.55
                                                                                                                              ElectionInterference_1665557063.xlsGet hashmaliciousBrowse
                                                                                                                              • 46.235.42.55
                                                                                                                              ElectionInterference_1051451333.xlsGet hashmaliciousBrowse
                                                                                                                              • 46.235.42.55
                                                                                                                              ElectionInterference_1051451333.xlsGet hashmaliciousBrowse
                                                                                                                              • 46.235.42.55
                                                                                                                              https://abns.co.uk/Get hashmaliciousBrowse
                                                                                                                              • 46.235.40.90
                                                                                                                              over.exeGet hashmaliciousBrowse
                                                                                                                              • 46.235.40.60
                                                                                                                              AMAZON-02USshipping docs 07853 draft CI+PL_pdf.exeGet hashmaliciousBrowse
                                                                                                                              • 52.222.158.116
                                                                                                                              Invoice- 876543456 Oil_Field_Swift_remmitance.docGet hashmaliciousBrowse
                                                                                                                              • 52.216.88.211
                                                                                                                              EE96DF216161F048EE9C50853B018F779D71BCE1498F2.exeGet hashmaliciousBrowse
                                                                                                                              • 52.95.169.4
                                                                                                                              Order No00020212910.exeGet hashmaliciousBrowse
                                                                                                                              • 44.227.76.166
                                                                                                                              rundll32.exeGet hashmaliciousBrowse
                                                                                                                              • 44.227.76.166
                                                                                                                              eBPXhP7TLX.exeGet hashmaliciousBrowse
                                                                                                                              • 3.132.159.158
                                                                                                                              96F34985E744EDAE462B513FD68856056C135078302D8.exeGet hashmaliciousBrowse
                                                                                                                              • 52.95.170.44
                                                                                                                              HELP_DECRYPT.URLGet hashmaliciousBrowse
                                                                                                                              • 18.195.174.160
                                                                                                                              f30dab44e1b3c177c002b35c5e9a933b79345c378dbf4.exeGet hashmaliciousBrowse
                                                                                                                              • 18.190.26.16
                                                                                                                              setup_x86_x64_install.exeGet hashmaliciousBrowse
                                                                                                                              • 52.95.171.40
                                                                                                                              WROO2_Invoice_Copy.vbsGet hashmaliciousBrowse
                                                                                                                              • 52.27.15.250
                                                                                                                              #0012HSJMS.vbsGet hashmaliciousBrowse
                                                                                                                              • 52.27.15.250
                                                                                                                              d7fEnxB3OT.xlsmGet hashmaliciousBrowse
                                                                                                                              • 18.159.149.5
                                                                                                                              wTFR3LK4MoGet hashmaliciousBrowse
                                                                                                                              • 108.158.116.92
                                                                                                                              RFQ - 1100195199 - 1100190914.exeGet hashmaliciousBrowse
                                                                                                                              • 3.122.27.22
                                                                                                                              Port_UETQYDYA_99381,pdf.exeGet hashmaliciousBrowse
                                                                                                                              • 75.2.26.18
                                                                                                                              st2AAeCXsRGet hashmaliciousBrowse
                                                                                                                              • 18.241.247.247
                                                                                                                              yZ7D7o1Z7pGet hashmaliciousBrowse
                                                                                                                              • 18.253.60.84
                                                                                                                              bKHI9UT0D1Get hashmaliciousBrowse
                                                                                                                              • 18.139.219.90
                                                                                                                              IMS211323.xlsxGet hashmaliciousBrowse
                                                                                                                              • 65.9.96.73

                                                                                                                              JA3 Fingerprints

                                                                                                                              MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                                                              fb4726d465c5f28b84cd6d14cedd13a710CV2biW2dGet hashmaliciousBrowse
                                                                                                                              • 34.249.145.219
                                                                                                                              r7bQAtiN68Get hashmaliciousBrowse
                                                                                                                              • 34.249.145.219
                                                                                                                              86wbpLsr78Get hashmaliciousBrowse
                                                                                                                              • 34.249.145.219
                                                                                                                              zYEw8iWwGBGet hashmaliciousBrowse
                                                                                                                              • 34.249.145.219
                                                                                                                              3QM8LROaOkGet hashmaliciousBrowse
                                                                                                                              • 34.249.145.219
                                                                                                                              75OHlqPaRYGet hashmaliciousBrowse
                                                                                                                              • 34.249.145.219
                                                                                                                              S0QgabIiDOGet hashmaliciousBrowse
                                                                                                                              • 34.249.145.219
                                                                                                                              vCLbAS7aPbGet hashmaliciousBrowse
                                                                                                                              • 34.249.145.219
                                                                                                                              yzui4gwsrFGet hashmaliciousBrowse
                                                                                                                              • 34.249.145.219
                                                                                                                              072FZHiMhsGet hashmaliciousBrowse
                                                                                                                              • 34.249.145.219
                                                                                                                              sjZlfrpuycGet hashmaliciousBrowse
                                                                                                                              • 34.249.145.219
                                                                                                                              khoE2I8yerGet hashmaliciousBrowse
                                                                                                                              • 34.249.145.219
                                                                                                                              wvsEoQ0khPGet hashmaliciousBrowse
                                                                                                                              • 34.249.145.219
                                                                                                                              32Get hashmaliciousBrowse
                                                                                                                              • 34.249.145.219
                                                                                                                              a-r.m-5.SakuraGet hashmaliciousBrowse
                                                                                                                              • 34.249.145.219
                                                                                                                              NDYfrLSNFWGet hashmaliciousBrowse
                                                                                                                              • 34.249.145.219
                                                                                                                              m-i.p-s.SakuraGet hashmaliciousBrowse
                                                                                                                              • 34.249.145.219
                                                                                                                              6Qn1b9fB2CGet hashmaliciousBrowse
                                                                                                                              • 34.249.145.219
                                                                                                                              ZSbDircdwCGet hashmaliciousBrowse
                                                                                                                              • 34.249.145.219
                                                                                                                              s0bi9tGet hashmaliciousBrowse
                                                                                                                              • 34.249.145.219

                                                                                                                              Dropped Files

                                                                                                                              No context

                                                                                                                              Created / dropped Files

                                                                                                                              /var/cache/motd-news
                                                                                                                              Process:/usr/bin/cut
                                                                                                                              File Type:ASCII text
                                                                                                                              Category:dropped
                                                                                                                              Size (bytes):191
                                                                                                                              Entropy (8bit):4.515771857099866
                                                                                                                              Encrypted:false
                                                                                                                              SSDEEP:3:P2lnI+5MsqqzNLz+FRNScHUBfRau95++sZzR5woLB1Fh0VTGTl/X5kURn:OZ8uNLzDc0pR75+9Zz/woFmIT52URn
                                                                                                                              MD5:DD514F892B5F93ED615D366E58AC58AF
                                                                                                                              SHA1:BA75EDB3C2232CC260BC187F604DC8F25AA72C11
                                                                                                                              SHA-256:F40D0DCE6E83DF74109FEF5E68E51CC255727783EEAE04C3E34677E23F7552CF
                                                                                                                              SHA-512:9150BDE63F6C4850C5340D8877892B4D9BBF9EBDC98CDCF557A93FA304C1222CEE446418F5BE2ACCDBF38393778AFA5D4F3EDCB37A47BF57D3A4B2DEAD42A2D0
                                                                                                                              Malicious:false
                                                                                                                              Reputation:moderate, very likely benign file
                                                                                                                              Preview: * Super-optimized for small spaces - read how we shrank the memory. footprint of MicroK8s to make it the smallest full K8s around... https://ubuntu.com/blog/microk8s-memory-optimisation.

                                                                                                                              Static File Info

                                                                                                                              General

                                                                                                                              File type:ELF 32-bit MSB executable, SPARC, version 1 (SYSV), statically linked, stripped
                                                                                                                              Entropy (8bit):6.100479824147886
                                                                                                                              TrID:
                                                                                                                              • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                                                                                                              File name:1TnmkstVG8
                                                                                                                              File size:38344
                                                                                                                              MD5:2f7ce4fdab3edd7aed014bd5a124c718
                                                                                                                              SHA1:0b1e76fac74052db6e7a342cdba0f90622100093
                                                                                                                              SHA256:6597350ca45adfe532bd93ffde9c92d98f2ed1ecedd4d7d73c6dd147b0b613a9
                                                                                                                              SHA512:3ccfd7025235684ef7663b204620b372536a484a10695705a1e0cb6aaa9af6baddc9f4fb7889a6f34394f2223a15031e5312917b9491535a4e63d0bca6aac98c
                                                                                                                              SSDEEP:384:scwxATYTY/41v0pvRFU+preqdBrF6wleRlJT0nJ2JMjP5:scwxAEM9RO+l8t4Nh
                                                                                                                              File Content Preview:.ELF...........................4...8.....4. ...(..........................................................!.........dt.Q................................@..(....@..y................#.....c...`.....!..... ,..@.....".........`......$ ,.. ,..@...........`....

                                                                                                                              Static ELF Info

                                                                                                                              ELF header

                                                                                                                              Class:ELF32
                                                                                                                              Data:2's complement, big endian
                                                                                                                              Version:1 (current)
                                                                                                                              Machine:Sparc
                                                                                                                              Version Number:0x1
                                                                                                                              Type:EXEC (Executable file)
                                                                                                                              OS/ABI:UNIX - System V
                                                                                                                              ABI Version:0
                                                                                                                              Entry Point Address:0x101a4
                                                                                                                              Flags:0x0
                                                                                                                              ELF Header Size:52
                                                                                                                              Program Header Offset:52
                                                                                                                              Program Header Size:32
                                                                                                                              Number of Program Headers:3
                                                                                                                              Section Header Offset:37944
                                                                                                                              Section Header Size:40
                                                                                                                              Number of Section Headers:10
                                                                                                                              Header String Table Index:9

                                                                                                                              Sections

                                                                                                                              NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                                                                                              NULL0x00x00x00x00x0000
                                                                                                                              .initPROGBITS0x100940x940x1c0x00x6AX004
                                                                                                                              .textPROGBITS0x100b00xb00x7a1c0x00x6AX004
                                                                                                                              .finiPROGBITS0x17acc0x7acc0x140x00x6AX004
                                                                                                                              .rodataPROGBITS0x17ae00x7ae00x5300x00x2A008
                                                                                                                              .ctorsPROGBITS0x280140x80140x80x00x3WA004
                                                                                                                              .dtorsPROGBITS0x2801c0x801c0x80x00x3WA004
                                                                                                                              .dataPROGBITS0x280280x80280x13d00x00x3WA008
                                                                                                                              .bssNOBITS0x293f80x93f80xdb00x00x3WA008
                                                                                                                              .shstrtabSTRTAB0x00x93f80x3e0x00x0001

                                                                                                                              Program Segments

                                                                                                                              TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                                                                                              LOAD0x00x100000x100000x80100x80103.51250x5R E0x10000.init .text .fini .rodata
                                                                                                                              LOAD0x80140x280140x280140x13e40x21941.75740x6RW 0x10000.ctors .dtors .data .bss
                                                                                                                              GNU_STACK0x00x00x00x00x00.00000x6RW 0x4

                                                                                                                              Network Behavior

                                                                                                                              Network Port Distribution

                                                                                                                              TCP Packets

                                                                                                                              TimestampSource PortDest PortSource IPDest IP
                                                                                                                              Oct 29, 2021 08:49:51.233458042 CEST56596455192.168.2.2345.95.169.120
                                                                                                                              Oct 29, 2021 08:49:52.254165888 CEST56596455192.168.2.2345.95.169.120
                                                                                                                              Oct 29, 2021 08:49:53.470083952 CEST42836443192.168.2.2391.189.91.43
                                                                                                                              Oct 29, 2021 08:49:54.238035917 CEST4251680192.168.2.23109.202.202.202
                                                                                                                              Oct 29, 2021 08:49:54.270015955 CEST56596455192.168.2.2345.95.169.120
                                                                                                                              Oct 29, 2021 08:49:58.333842993 CEST56596455192.168.2.2345.95.169.120
                                                                                                                              Oct 29, 2021 08:50:02.579926014 CEST2345062189.57.206.167192.168.2.23
                                                                                                                              Oct 29, 2021 08:50:02.580113888 CEST2345062189.57.206.167192.168.2.23
                                                                                                                              Oct 29, 2021 08:50:02.580205917 CEST4506223192.168.2.23189.57.206.167
                                                                                                                              Oct 29, 2021 08:50:02.580256939 CEST4506223192.168.2.23189.57.206.167
                                                                                                                              Oct 29, 2021 08:50:03.311676979 CEST234745637.80.245.107192.168.2.23
                                                                                                                              Oct 29, 2021 08:50:03.311985970 CEST4745623192.168.2.2337.80.245.107
                                                                                                                              Oct 29, 2021 08:50:03.319192886 CEST234745637.80.245.107192.168.2.23
                                                                                                                              Oct 29, 2021 08:50:03.319333076 CEST4745623192.168.2.2337.80.245.107
                                                                                                                              Oct 29, 2021 08:50:06.525520086 CEST56596455192.168.2.2345.95.169.120
                                                                                                                              Oct 29, 2021 08:50:08.573417902 CEST43928443192.168.2.2391.189.91.42
                                                                                                                              Oct 29, 2021 08:50:16.160259962 CEST39244443192.168.2.2334.249.145.219
                                                                                                                              Oct 29, 2021 08:50:16.205056906 CEST4433924434.249.145.219192.168.2.23
                                                                                                                              Oct 29, 2021 08:50:16.205240965 CEST39244443192.168.2.2334.249.145.219
                                                                                                                              Oct 29, 2021 08:50:16.205849886 CEST39244443192.168.2.2334.249.145.219
                                                                                                                              Oct 29, 2021 08:50:16.249986887 CEST4433924434.249.145.219192.168.2.23
                                                                                                                              Oct 29, 2021 08:50:16.251286983 CEST4433924434.249.145.219192.168.2.23
                                                                                                                              Oct 29, 2021 08:50:16.251306057 CEST4433924434.249.145.219192.168.2.23
                                                                                                                              Oct 29, 2021 08:50:16.251370907 CEST4433924434.249.145.219192.168.2.23
                                                                                                                              Oct 29, 2021 08:50:16.251374006 CEST39244443192.168.2.2334.249.145.219
                                                                                                                              Oct 29, 2021 08:50:16.251384974 CEST4433924434.249.145.219192.168.2.23
                                                                                                                              Oct 29, 2021 08:50:16.251399994 CEST39244443192.168.2.2334.249.145.219
                                                                                                                              Oct 29, 2021 08:50:16.251410961 CEST39244443192.168.2.2334.249.145.219
                                                                                                                              Oct 29, 2021 08:50:16.251435041 CEST39244443192.168.2.2334.249.145.219
                                                                                                                              Oct 29, 2021 08:50:16.252171040 CEST4433924434.249.145.219192.168.2.23
                                                                                                                              Oct 29, 2021 08:50:16.252213955 CEST39244443192.168.2.2334.249.145.219
                                                                                                                              Oct 29, 2021 08:50:16.254503012 CEST39244443192.168.2.2334.249.145.219
                                                                                                                              Oct 29, 2021 08:50:16.299272060 CEST4433924434.249.145.219192.168.2.23
                                                                                                                              Oct 29, 2021 08:50:16.299439907 CEST39244443192.168.2.2334.249.145.219
                                                                                                                              Oct 29, 2021 08:50:16.299820900 CEST39244443192.168.2.2334.249.145.219
                                                                                                                              Oct 29, 2021 08:50:16.345458984 CEST4433924434.249.145.219192.168.2.23
                                                                                                                              Oct 29, 2021 08:50:16.345611095 CEST39244443192.168.2.2334.249.145.219
                                                                                                                              Oct 29, 2021 08:50:16.347381115 CEST39244443192.168.2.2334.249.145.219
                                                                                                                              Oct 29, 2021 08:50:16.393722057 CEST4433924434.249.145.219192.168.2.23
                                                                                                                              Oct 29, 2021 08:50:16.393734932 CEST4433924434.249.145.219192.168.2.23
                                                                                                                              Oct 29, 2021 08:50:16.393800020 CEST39244443192.168.2.2334.249.145.219
                                                                                                                              Oct 29, 2021 08:50:16.393822908 CEST39244443192.168.2.2334.249.145.219
                                                                                                                              Oct 29, 2021 08:50:20.860939026 CEST42836443192.168.2.2391.189.91.43
                                                                                                                              Oct 29, 2021 08:50:22.652750015 CEST56596455192.168.2.2345.95.169.120
                                                                                                                              Oct 29, 2021 08:50:24.956691027 CEST4251680192.168.2.23109.202.202.202
                                                                                                                              Oct 29, 2021 08:50:49.531693935 CEST43928443192.168.2.2391.189.91.42
                                                                                                                              Oct 29, 2021 08:50:55.675467014 CEST56596455192.168.2.2345.95.169.120
                                                                                                                              Oct 29, 2021 08:50:55.709491014 CEST4555659645.95.169.120192.168.2.23
                                                                                                                              Oct 29, 2021 08:50:55.710903883 CEST56600455192.168.2.2345.95.169.120
                                                                                                                              Oct 29, 2021 08:50:55.749160051 CEST4555660045.95.169.120192.168.2.23
                                                                                                                              Oct 29, 2021 08:50:55.749802113 CEST56602455192.168.2.2345.95.169.120
                                                                                                                              Oct 29, 2021 08:50:56.763346910 CEST56602455192.168.2.2345.95.169.120
                                                                                                                              Oct 29, 2021 08:50:57.466229916 CEST234510446.244.112.164192.168.2.23
                                                                                                                              Oct 29, 2021 08:50:57.466480970 CEST4510423192.168.2.2346.244.112.164
                                                                                                                              Oct 29, 2021 08:50:58.779268980 CEST56602455192.168.2.2345.95.169.120
                                                                                                                              Oct 29, 2021 08:51:02.843082905 CEST56602455192.168.2.2345.95.169.120
                                                                                                                              Oct 29, 2021 08:51:11.034754992 CEST56602455192.168.2.2345.95.169.120
                                                                                                                              Oct 29, 2021 08:51:27.162185907 CEST56602455192.168.2.2345.95.169.120
                                                                                                                              Oct 29, 2021 08:51:27.195202112 CEST4555660245.95.169.120192.168.2.23
                                                                                                                              Oct 29, 2021 08:51:27.195672989 CEST56606455192.168.2.2345.95.169.120
                                                                                                                              Oct 29, 2021 08:51:27.229099989 CEST4555660645.95.169.120192.168.2.23
                                                                                                                              Oct 29, 2021 08:51:27.229629993 CEST56608455192.168.2.2345.95.169.120
                                                                                                                              Oct 29, 2021 08:51:27.262991905 CEST4555660845.95.169.120192.168.2.23
                                                                                                                              Oct 29, 2021 08:51:27.263380051 CEST56610455192.168.2.2345.95.169.120
                                                                                                                              Oct 29, 2021 08:51:27.296152115 CEST4555661045.95.169.120192.168.2.23

                                                                                                                              HTTPS Packets

                                                                                                                              TimestampSource IPSource PortDest IPDest PortSubjectIssuerNot BeforeNot AfterJA3 SSL Client FingerprintJA3 SSL Client Digest
                                                                                                                              Oct 29, 2021 08:50:16.252171040 CEST34.249.145.219443192.168.2.2339244CN=motd.ubuntu.com CN=R3, O=Let's Encrypt, C=US CN=ISRG Root X1, O=Internet Security Research Group, C=USCN=R3, O=Let's Encrypt, C=US CN=ISRG Root X1, O=Internet Security Research Group, C=US CN=DST Root CA X3, O=Digital Signature Trust Co.Tue Sep 07 13:50:45 CEST 2021 Fri Sep 04 02:00:00 CEST 2020 Wed Jan 20 20:14:03 CET 2021Mon Dec 06 12:50:44 CET 2021 Mon Sep 15 18:00:00 CEST 2025 Mon Sep 30 20:14:03 CEST 2024771,4866-4867-4865-49196-49200-163-159-52393-52392-52394-49327-49325-49315-49311-49245-49249-49239-49235-49195-49199-162-158-49326-49324-49314-49310-49244-49248-49238-49234-49188-49192-107-106-49267-49271-196-195-49187-49191-103-64-49266-49270-190-189-49162-49172-57-56-136-135-49161-49171-51-50-69-68-157-49313-49309-49233-156-49312-49308-49232-61-192-60-186-53-132-47-65-255,0-11-10-35-22-23-13-43-45-51,29-23-30-25-24,0-1-2fb4726d465c5f28b84cd6d14cedd13a7
                                                                                                                              CN=R3, O=Let's Encrypt, C=USCN=ISRG Root X1, O=Internet Security Research Group, C=USFri Sep 04 02:00:00 CEST 2020Mon Sep 15 18:00:00 CEST 2025
                                                                                                                              CN=ISRG Root X1, O=Internet Security Research Group, C=USCN=DST Root CA X3, O=Digital Signature Trust Co.Wed Jan 20 20:14:03 CET 2021Mon Sep 30 20:14:03 CEST 2024

                                                                                                                              System Behavior

                                                                                                                              General

                                                                                                                              Start time:08:49:50
                                                                                                                              Start date:29/10/2021
                                                                                                                              Path:/tmp/1TnmkstVG8
                                                                                                                              Arguments:/tmp/1TnmkstVG8
                                                                                                                              File size:4379400 bytes
                                                                                                                              MD5 hash:7dc1c0e23cd5e102bb12e5c29403410e

                                                                                                                              General

                                                                                                                              Start time:08:49:50
                                                                                                                              Start date:29/10/2021
                                                                                                                              Path:/tmp/1TnmkstVG8
                                                                                                                              Arguments:n/a
                                                                                                                              File size:4379400 bytes
                                                                                                                              MD5 hash:7dc1c0e23cd5e102bb12e5c29403410e

                                                                                                                              General

                                                                                                                              Start time:08:50:15
                                                                                                                              Start date:29/10/2021
                                                                                                                              Path:/usr/bin/dash
                                                                                                                              Arguments:n/a
                                                                                                                              File size:129816 bytes
                                                                                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                              General

                                                                                                                              Start time:08:50:15
                                                                                                                              Start date:29/10/2021
                                                                                                                              Path:/usr/bin/cat
                                                                                                                              Arguments:cat /tmp/tmp.gtT3aisjF5
                                                                                                                              File size:43416 bytes
                                                                                                                              MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

                                                                                                                              General

                                                                                                                              Start time:08:50:15
                                                                                                                              Start date:29/10/2021
                                                                                                                              Path:/usr/bin/dash
                                                                                                                              Arguments:n/a
                                                                                                                              File size:129816 bytes
                                                                                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                              General

                                                                                                                              Start time:08:50:15
                                                                                                                              Start date:29/10/2021
                                                                                                                              Path:/usr/bin/head
                                                                                                                              Arguments:head -n 10
                                                                                                                              File size:47480 bytes
                                                                                                                              MD5 hash:fd96a67145172477dd57131396fc9608

                                                                                                                              General

                                                                                                                              Start time:08:50:15
                                                                                                                              Start date:29/10/2021
                                                                                                                              Path:/usr/bin/dash
                                                                                                                              Arguments:n/a
                                                                                                                              File size:129816 bytes
                                                                                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                              General

                                                                                                                              Start time:08:50:15
                                                                                                                              Start date:29/10/2021
                                                                                                                              Path:/usr/bin/tr
                                                                                                                              Arguments:tr -d \\000-\\011\\013\\014\\016-\\037
                                                                                                                              File size:51544 bytes
                                                                                                                              MD5 hash:fbd1402dd9f72d8ebfff00ce7c3a7bb5

                                                                                                                              General

                                                                                                                              Start time:08:50:15
                                                                                                                              Start date:29/10/2021
                                                                                                                              Path:/usr/bin/dash
                                                                                                                              Arguments:n/a
                                                                                                                              File size:129816 bytes
                                                                                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                              General

                                                                                                                              Start time:08:50:15
                                                                                                                              Start date:29/10/2021
                                                                                                                              Path:/usr/bin/cut
                                                                                                                              Arguments:cut -c -80
                                                                                                                              File size:47480 bytes
                                                                                                                              MD5 hash:d8ed0ea8f22c0de0f8692d4d9f1759d3

                                                                                                                              General

                                                                                                                              Start time:08:50:15
                                                                                                                              Start date:29/10/2021
                                                                                                                              Path:/usr/bin/dash
                                                                                                                              Arguments:n/a
                                                                                                                              File size:129816 bytes
                                                                                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                              General

                                                                                                                              Start time:08:50:15
                                                                                                                              Start date:29/10/2021
                                                                                                                              Path:/usr/bin/cat
                                                                                                                              Arguments:cat /tmp/tmp.gtT3aisjF5
                                                                                                                              File size:43416 bytes
                                                                                                                              MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

                                                                                                                              General

                                                                                                                              Start time:08:50:15
                                                                                                                              Start date:29/10/2021
                                                                                                                              Path:/usr/bin/dash
                                                                                                                              Arguments:n/a
                                                                                                                              File size:129816 bytes
                                                                                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                              General

                                                                                                                              Start time:08:50:15
                                                                                                                              Start date:29/10/2021
                                                                                                                              Path:/usr/bin/head
                                                                                                                              Arguments:head -n 10
                                                                                                                              File size:47480 bytes
                                                                                                                              MD5 hash:fd96a67145172477dd57131396fc9608

                                                                                                                              General

                                                                                                                              Start time:08:50:15
                                                                                                                              Start date:29/10/2021
                                                                                                                              Path:/usr/bin/dash
                                                                                                                              Arguments:n/a
                                                                                                                              File size:129816 bytes
                                                                                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                              General

                                                                                                                              Start time:08:50:15
                                                                                                                              Start date:29/10/2021
                                                                                                                              Path:/usr/bin/tr
                                                                                                                              Arguments:tr -d \\000-\\011\\013\\014\\016-\\037
                                                                                                                              File size:51544 bytes
                                                                                                                              MD5 hash:fbd1402dd9f72d8ebfff00ce7c3a7bb5

                                                                                                                              General

                                                                                                                              Start time:08:50:15
                                                                                                                              Start date:29/10/2021
                                                                                                                              Path:/usr/bin/dash
                                                                                                                              Arguments:n/a
                                                                                                                              File size:129816 bytes
                                                                                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                              General

                                                                                                                              Start time:08:50:15
                                                                                                                              Start date:29/10/2021
                                                                                                                              Path:/usr/bin/cut
                                                                                                                              Arguments:cut -c -80
                                                                                                                              File size:47480 bytes
                                                                                                                              MD5 hash:d8ed0ea8f22c0de0f8692d4d9f1759d3

                                                                                                                              General

                                                                                                                              Start time:08:50:15
                                                                                                                              Start date:29/10/2021
                                                                                                                              Path:/usr/bin/dash
                                                                                                                              Arguments:n/a
                                                                                                                              File size:129816 bytes
                                                                                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                              General

                                                                                                                              Start time:08:50:15
                                                                                                                              Start date:29/10/2021
                                                                                                                              Path:/usr/bin/rm
                                                                                                                              Arguments:rm -f /tmp/tmp.gtT3aisjF5 /tmp/tmp.0HpvoUv25y /tmp/tmp.kZRxhtfsZX
                                                                                                                              File size:72056 bytes
                                                                                                                              MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b