Loading ...

Play interactive tourEdit tour

Linux Analysis Report Y4W4j5QIqD

Overview

General Information

Sample Name:Y4W4j5QIqD
Analysis ID:511517
MD5:ab985a5aa9025467417c596d55665616
SHA1:380b0e55c98f46ea5bcfe251f6e827bb9eccc168
SHA256:871fd4ce9a1123ea4c4846d97d5f547eb29357871bdfedc3a1de5b621189d9f6
Tags:32elfmotorola
Infos:

Detection

Score:48
Range:0 - 100
Whitelisted:false

Signatures

Multi AV Scanner detection for submitted file
Uses the "uname" system call to query kernel version information (possible evasion)
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Detected TCP or UDP traffic on non-standard ports
Sample has stripped symbol table

Classification

Analysis Advice

All HTTP servers contacted by the sample do not answer. Likely the sample is an old dropper which does no longer work
Static ELF header machine description suggests that the sample might not execute correctly on this machine

General Information

Joe Sandbox Version:34.0.0 Boulder Opal
Analysis ID:511517
Start date:29.10.2021
Start time:08:58:22
Joe Sandbox Product:CloudBasic
Overall analysis duration:0h 4m 53s
Hypervisor based Inspection enabled:false
Report type:full
Sample file name:Y4W4j5QIqD
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Detection:MAL
Classification:mal48.lin@0/0@0/0

Process Tree

  • system is lnxubuntu20
  • Y4W4j5QIqD (PID: 5228, Parent: 5114, MD5: cd177594338c77b895ae27c33f8f86cc) Arguments: /tmp/Y4W4j5QIqD
  • cleanup

Yara Overview

No yara matches

Jbx Signature Overview

Click to jump to signature section

Show All Signature Results

AV Detection:

barindex
Multi AV Scanner detection for submitted fileShow sources
Source: Y4W4j5QIqDVirustotal: Detection: 19%Perma Link
Source: Y4W4j5QIqDReversingLabs: Detection: 13%
Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
Source: global trafficTCP traffic: 192.168.2.23:56596 -> 45.95.169.120:455
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
Source: unknownTCP traffic detected without corresponding DNS query: 222.251.163.193
Source: unknownTCP traffic detected without corresponding DNS query: 112.184.140.23
Source: unknownTCP traffic detected without corresponding DNS query: 112.184.140.23
Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
Source: ELF static info symbol of initial sample.symtab present: no
Source: classification engineClassification label: mal48.lin@0/0@0/0
Source: Y4W4j5QIqDJoe Sandbox Cloud Basic: Detection: clean Score: 0Perma Link
Source: /tmp/Y4W4j5QIqD (PID: 5228)Queries kernel information via 'uname': Jump to behavior
Source: Y4W4j5QIqD, 5228.1.0000000015ccc325.00000000f6e28c99.rw-.sdmpBinary or memory string: {U!/etc/qemu-binfmt/m68k
Source: Y4W4j5QIqD, 5228.1.00000000b7ff3933.00000000a3f8a1d0.rw-.sdmpBinary or memory string: /usr/bin/qemu-m68k
Source: Y4W4j5QIqD, 5228.1.0000000015ccc325.00000000f6e28c99.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/m68k
Source: Y4W4j5QIqD, 5228.1.00000000b7ff3933.00000000a3f8a1d0.rw-.sdmpBinary or memory string: `x86_64/usr/bin/qemu-m68k/tmp/Y4W4j5QIqDSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/Y4W4j5QIqD

Mitre Att&ck Matrix

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionDirect Volume AccessOS Credential DumpingSecurity Software Discovery11Remote ServicesData from Local SystemExfiltration Over Other Network MediumEncrypted Channel1Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over BluetoothNon-Standard Port1Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationApplication Layer Protocol1Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data

Malware Configuration

No configs have been found

Behavior Graph

Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet

Antivirus, Machine Learning and Genetic Malware Detection

Initial Sample

SourceDetectionScannerLabelLink
Y4W4j5QIqD20%VirustotalBrowse
Y4W4j5QIqD14%ReversingLabsLinux.Trojan.Mirai

Dropped Files

No Antivirus matches

Domains

No Antivirus matches

URLs

No Antivirus matches

Domains and IPs

Contacted Domains

No contacted domains info

Contacted IPs

  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs

Public

IPDomainCountryFlagASNASN NameMalicious
222.251.163.193
unknownKorea Republic of
23563VITSSEN-SUWON-AS-KRTbroadSuwonBroadcastingCorporationKfalse
45.95.169.120
unknownCroatia (LOCAL Name: Hrvatska)
42864GIGANET-HUGigaNetInternetServiceProviderCoHUfalse
112.184.140.23
unknownKorea Republic of
4766KIXS-AS-KRKoreaTelecomKRfalse
109.202.202.202
unknownSwitzerland
13030INIT7CHfalse
91.189.91.43
unknownUnited Kingdom
41231CANONICAL-ASGBfalse
91.189.91.42
unknownUnited Kingdom
41231CANONICAL-ASGBfalse


Runtime Messages

Command:/tmp/Y4W4j5QIqD
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:

Standard Error:

Joe Sandbox View / Context

IPs

MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
45.95.169.1201TnmkstVG8Get hashmaliciousBrowse
    iksM5QEg2jGet hashmaliciousBrowse
      109.202.202.2021TnmkstVG8Get hashmaliciousBrowse
        iksM5QEg2jGet hashmaliciousBrowse
          lGJEkz80oeGet hashmaliciousBrowse
            roV7kGaVr1Get hashmaliciousBrowse
              SecuriteInfo.com.Linux.Siggen.4218.298.3210Get hashmaliciousBrowse
                uPOWBxniTAGet hashmaliciousBrowse
                  qy5unieRgRGet hashmaliciousBrowse
                    sAzPpn6mKZGet hashmaliciousBrowse
                      AxadDC89j9Get hashmaliciousBrowse
                        ZErnXU2XR1Get hashmaliciousBrowse
                          sTHJvS5LPJGet hashmaliciousBrowse
                            THzHjYQ4z6Get hashmaliciousBrowse
                              jC0B6sMh1dGet hashmaliciousBrowse
                                JoLmvC65B7Get hashmaliciousBrowse
                                  AOaKSm1cijGet hashmaliciousBrowse
                                    Mozi.aGet hashmaliciousBrowse
                                      ggbMKQDdG2Get hashmaliciousBrowse
                                        SecuriteInfo.com.Linux.Siggen.4218.31606.9155Get hashmaliciousBrowse
                                          AbriuSDkeLGet hashmaliciousBrowse
                                            xjmPNreY8IGet hashmaliciousBrowse
                                              91.189.91.431TnmkstVG8Get hashmaliciousBrowse
                                                iksM5QEg2jGet hashmaliciousBrowse
                                                  lGJEkz80oeGet hashmaliciousBrowse
                                                    roV7kGaVr1Get hashmaliciousBrowse
                                                      SecuriteInfo.com.Linux.Siggen.4218.298.3210Get hashmaliciousBrowse
                                                        uPOWBxniTAGet hashmaliciousBrowse
                                                          qy5unieRgRGet hashmaliciousBrowse
                                                            sAzPpn6mKZGet hashmaliciousBrowse
                                                              AxadDC89j9Get hashmaliciousBrowse
                                                                ZErnXU2XR1Get hashmaliciousBrowse
                                                                  sTHJvS5LPJGet hashmaliciousBrowse
                                                                    THzHjYQ4z6Get hashmaliciousBrowse
                                                                      jC0B6sMh1dGet hashmaliciousBrowse
                                                                        JoLmvC65B7Get hashmaliciousBrowse
                                                                          AOaKSm1cijGet hashmaliciousBrowse
                                                                            Mozi.aGet hashmaliciousBrowse
                                                                              ggbMKQDdG2Get hashmaliciousBrowse
                                                                                SecuriteInfo.com.Linux.Siggen.4218.31606.9155Get hashmaliciousBrowse
                                                                                  AbriuSDkeLGet hashmaliciousBrowse
                                                                                    xjmPNreY8IGet hashmaliciousBrowse

                                                                                      Domains

                                                                                      No context

                                                                                      ASN

                                                                                      MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                      VITSSEN-SUWON-AS-KRTbroadSuwonBroadcastingCorporationK1alzsODTFeGet hashmaliciousBrowse
                                                                                      • 218.209.212.14
                                                                                      notabotnet.x86Get hashmaliciousBrowse
                                                                                      • 121.254.0.118
                                                                                      7EY5YH1w9qGet hashmaliciousBrowse
                                                                                      • 222.251.160.6
                                                                                      dark.86_64Get hashmaliciousBrowse
                                                                                      • 114.108.48.64
                                                                                      2YrqtABAvtGet hashmaliciousBrowse
                                                                                      • 218.209.89.138
                                                                                      hoho.x86Get hashmaliciousBrowse
                                                                                      • 114.108.48.79
                                                                                      1isequal9.x86Get hashmaliciousBrowse
                                                                                      • 222.251.255.72
                                                                                      S6DNzkh376Get hashmaliciousBrowse
                                                                                      • 114.108.48.35
                                                                                      1isequal9.x86Get hashmaliciousBrowse
                                                                                      • 121.254.0.152
                                                                                      WCBzD1NEZsGet hashmaliciousBrowse
                                                                                      • 114.108.24.66
                                                                                      cUfweIWt2xGet hashmaliciousBrowse
                                                                                      • 114.108.12.62
                                                                                      VGi1EK6T17Get hashmaliciousBrowse
                                                                                      • 121.254.0.152
                                                                                      SecuriteInfo.com.Trojan.Kronos.21.31435.exeGet hashmaliciousBrowse
                                                                                      • 114.108.58.201
                                                                                      6d0000.exeGet hashmaliciousBrowse
                                                                                      • 114.108.58.201
                                                                                      mssecsvc.exeGet hashmaliciousBrowse
                                                                                      • 218.209.174.90
                                                                                      GIGANET-HUGigaNetInternetServiceProviderCoHU1TnmkstVG8Get hashmaliciousBrowse
                                                                                      • 45.95.169.120
                                                                                      iksM5QEg2jGet hashmaliciousBrowse
                                                                                      • 45.95.169.120
                                                                                      RicwIfIHLKGet hashmaliciousBrowse
                                                                                      • 45.95.169.115
                                                                                      aIY7AxjUMcGet hashmaliciousBrowse
                                                                                      • 45.95.169.115
                                                                                      DtJmFQxtNCGet hashmaliciousBrowse
                                                                                      • 45.95.169.115
                                                                                      Wm4CzOCmNYGet hashmaliciousBrowse
                                                                                      • 45.95.169.115
                                                                                      vunWUzXJvCGet hashmaliciousBrowse
                                                                                      • 45.95.169.115
                                                                                      52xhBHy9WzGet hashmaliciousBrowse
                                                                                      • 45.95.169.115
                                                                                      YGvwG0iCDEGet hashmaliciousBrowse
                                                                                      • 45.95.169.115
                                                                                      dbd5O0RUTqGet hashmaliciousBrowse
                                                                                      • 45.95.169.115
                                                                                      fHVDVj0pzOGet hashmaliciousBrowse
                                                                                      • 45.95.169.115
                                                                                      eZPk7Fg5w7Get hashmaliciousBrowse
                                                                                      • 45.95.169.115
                                                                                      ph5PjoFBpjGet hashmaliciousBrowse
                                                                                      • 45.95.169.115
                                                                                      xugAk5haatGet hashmaliciousBrowse
                                                                                      • 45.95.169.115
                                                                                      0jEbWQtzs0Get hashmaliciousBrowse
                                                                                      • 45.95.169.115
                                                                                      8g3tc5SWwBGet hashmaliciousBrowse
                                                                                      • 92.52.211.220
                                                                                      7okgnZjK06Get hashmaliciousBrowse
                                                                                      • 45.95.169.115
                                                                                      D9efs9TYvNGet hashmaliciousBrowse
                                                                                      • 45.95.169.115
                                                                                      LlE7nUUjmAGet hashmaliciousBrowse
                                                                                      • 45.95.169.115
                                                                                      3HwsuWd7atGet hashmaliciousBrowse
                                                                                      • 45.95.169.115
                                                                                      KIXS-AS-KRKoreaTelecomKRBsNj9o1U0P.exeGet hashmaliciousBrowse
                                                                                      • 211.229.47.232
                                                                                      rdvL5Vuyg7.exeGet hashmaliciousBrowse
                                                                                      • 203.228.9.102
                                                                                      AY5uCs0HrY.exeGet hashmaliciousBrowse
                                                                                      • 121.136.102.4
                                                                                      9JVjZ8tdvF.exeGet hashmaliciousBrowse
                                                                                      • 121.136.102.4
                                                                                      LCgNoeCOl6Get hashmaliciousBrowse
                                                                                      • 121.145.187.125
                                                                                      RgHOcm1miq.exeGet hashmaliciousBrowse
                                                                                      • 220.125.1.129
                                                                                      3D6Ztnqg66.exeGet hashmaliciousBrowse
                                                                                      • 203.228.9.102
                                                                                      wannacry.exeGet hashmaliciousBrowse
                                                                                      • 175.211.53.106
                                                                                      PO#202110223.exeGet hashmaliciousBrowse
                                                                                      • 183.111.242.26
                                                                                      st2AAeCXsRGet hashmaliciousBrowse
                                                                                      • 119.196.59.40
                                                                                      bKHI9UT0D1Get hashmaliciousBrowse
                                                                                      • 59.1.165.25
                                                                                      1S80No4PTVGet hashmaliciousBrowse
                                                                                      • 112.160.41.41
                                                                                      eNrYzJWFvBGet hashmaliciousBrowse
                                                                                      • 210.183.92.150
                                                                                      pLoEhdXNms.exeGet hashmaliciousBrowse
                                                                                      • 14.51.96.70
                                                                                      XTLR18yv0F.exeGet hashmaliciousBrowse
                                                                                      • 121.136.102.4
                                                                                      mdOr6C8jJpGet hashmaliciousBrowse
                                                                                      • 59.22.201.202
                                                                                      en94piXmL6Get hashmaliciousBrowse
                                                                                      • 210.179.35.113
                                                                                      wRmHCEnowIGet hashmaliciousBrowse
                                                                                      • 118.49.17.164
                                                                                      5BfhgIXvAyGet hashmaliciousBrowse
                                                                                      • 119.205.33.74
                                                                                      HCyigyiCAHGet hashmaliciousBrowse
                                                                                      • 125.145.135.186

                                                                                      JA3 Fingerprints

                                                                                      No context

                                                                                      Dropped Files

                                                                                      No context

                                                                                      Created / dropped Files

                                                                                      No created / dropped files found

                                                                                      Static File Info

                                                                                      General

                                                                                      File type:ELF 32-bit MSB executable, Motorola m68k, 68020, version 1 (SYSV), statically linked, stripped
                                                                                      Entropy (8bit):6.256461527210843
                                                                                      TrID:
                                                                                      • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                                                                      File name:Y4W4j5QIqD
                                                                                      File size:31984
                                                                                      MD5:ab985a5aa9025467417c596d55665616
                                                                                      SHA1:380b0e55c98f46ea5bcfe251f6e827bb9eccc168
                                                                                      SHA256:871fd4ce9a1123ea4c4846d97d5f547eb29357871bdfedc3a1de5b621189d9f6
                                                                                      SHA512:c15924a116409293864bebedc1f8ac32c0606da57a3a8841dbdd1181ca4f22fec04876c6164ed3f11d695eb78199dd7cd56a95ebf767e6ae2e8ad567152770fa
                                                                                      SSDEEP:384:+pKH2Vg4Y3sPfMYHdJ8HASC4xv/Hsh+mUH90EV4JZBIA:mmZ38fPH8dx84mUdxV4JAA
                                                                                      File Content Preview:.ELF.......................D...4..{`.....4. ...(......................g>..g>...... .......gD...D...D......!|...... .dt.Q............................NV..a....da...atN^NuNV..J9... f>"y...\ QJ.g.X.#....\N."y...\ QJ.f.A.....J.g.Hy..g@N.X........ N^NuNV..N^NuN

                                                                                      Static ELF Info

                                                                                      ELF header

                                                                                      Class:ELF32
                                                                                      Data:2's complement, big endian
                                                                                      Version:1 (current)
                                                                                      Machine:MC68000
                                                                                      Version Number:0x1
                                                                                      Type:EXEC (Executable file)
                                                                                      OS/ABI:UNIX - System V
                                                                                      ABI Version:0
                                                                                      Entry Point Address:0x80000144
                                                                                      Flags:0x0
                                                                                      ELF Header Size:52
                                                                                      Program Header Offset:52
                                                                                      Program Header Size:32
                                                                                      Number of Program Headers:3
                                                                                      Section Header Offset:31584
                                                                                      Section Header Size:40
                                                                                      Number of Section Headers:10
                                                                                      Header String Table Index:9

                                                                                      Sections

                                                                                      NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                                                      NULL0x00x00x00x00x0000
                                                                                      .initPROGBITS0x800000940x940x140x00x6AX002
                                                                                      .textPROGBITS0x800000a80xa80x619e0x00x6AX004
                                                                                      .finiPROGBITS0x800062460x62460xe0x00x6AX002
                                                                                      .rodataPROGBITS0x800062540x62540x4ea0x00x2A002
                                                                                      .ctorsPROGBITS0x800087440x67440x80x00x3WA004
                                                                                      .dtorsPROGBITS0x8000874c0x674c0x80x00x3WA004
                                                                                      .dataPROGBITS0x800087580x67580x13c80x00x3WA004
                                                                                      .bssNOBITS0x80009b200x7b200xda00x00x3WA004
                                                                                      .shstrtabSTRTAB0x00x7b200x3e0x00x0001

                                                                                      Program Segments

                                                                                      TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                                                      LOAD0x00x800000000x800000000x673e0x673e3.91260x5R E0x2000.init .text .fini .rodata
                                                                                      LOAD0x67440x800087440x800087440x13dc0x217c1.74140x6RW 0x2000.ctors .dtors .data .bss
                                                                                      GNU_STACK0x00x00x00x00x00.00000x6RW 0x4

                                                                                      Network Behavior

                                                                                      Network Port Distribution

                                                                                      TCP Packets

                                                                                      TimestampSource PortDest PortSource IPDest IP
                                                                                      Oct 29, 2021 08:59:03.843120098 CEST56596455192.168.2.2345.95.169.120
                                                                                      Oct 29, 2021 08:59:04.844420910 CEST56596455192.168.2.2345.95.169.120
                                                                                      Oct 29, 2021 08:59:06.540363073 CEST42836443192.168.2.2391.189.91.43
                                                                                      Oct 29, 2021 08:59:06.860343933 CEST56596455192.168.2.2345.95.169.120
                                                                                      Oct 29, 2021 08:59:07.308387041 CEST4251680192.168.2.23109.202.202.202
                                                                                      Oct 29, 2021 08:59:10.892070055 CEST56596455192.168.2.2345.95.169.120
                                                                                      Oct 29, 2021 08:59:14.532814980 CEST2335354222.251.163.193192.168.2.23
                                                                                      Oct 29, 2021 08:59:14.533090115 CEST3535423192.168.2.23222.251.163.193
                                                                                      Oct 29, 2021 08:59:16.573110104 CEST2332818112.184.140.23192.168.2.23
                                                                                      Oct 29, 2021 08:59:16.573160887 CEST2332818112.184.140.23192.168.2.23
                                                                                      Oct 29, 2021 08:59:16.573427916 CEST3281823192.168.2.23112.184.140.23
                                                                                      Oct 29, 2021 08:59:16.573497057 CEST3281823192.168.2.23112.184.140.23
                                                                                      Oct 29, 2021 08:59:19.083771944 CEST56596455192.168.2.2345.95.169.120
                                                                                      Oct 29, 2021 08:59:21.387674093 CEST43928443192.168.2.2391.189.91.42
                                                                                      Oct 29, 2021 08:59:33.674957037 CEST42836443192.168.2.2391.189.91.43
                                                                                      Oct 29, 2021 08:59:35.210834026 CEST56596455192.168.2.2345.95.169.120
                                                                                      Oct 29, 2021 08:59:37.770710945 CEST4251680192.168.2.23109.202.202.202
                                                                                      Oct 29, 2021 09:00:02.345303059 CEST43928443192.168.2.2391.189.91.42
                                                                                      Oct 29, 2021 09:00:08.489057064 CEST56596455192.168.2.2345.95.169.120
                                                                                      Oct 29, 2021 09:00:08.522960901 CEST4555659645.95.169.120192.168.2.23
                                                                                      Oct 29, 2021 09:00:13.524277925 CEST56598455192.168.2.2345.95.169.120
                                                                                      Oct 29, 2021 09:00:13.557718992 CEST4555659845.95.169.120192.168.2.23
                                                                                      Oct 29, 2021 09:00:18.558258057 CEST56600455192.168.2.2345.95.169.120
                                                                                      Oct 29, 2021 09:00:18.591723919 CEST4555660045.95.169.120192.168.2.23
                                                                                      Oct 29, 2021 09:00:23.592143059 CEST56602455192.168.2.2345.95.169.120
                                                                                      Oct 29, 2021 09:00:23.625606060 CEST4555660245.95.169.120192.168.2.23
                                                                                      Oct 29, 2021 09:00:28.626125097 CEST56604455192.168.2.2345.95.169.120
                                                                                      Oct 29, 2021 09:00:29.639887094 CEST56604455192.168.2.2345.95.169.120
                                                                                      Oct 29, 2021 09:00:29.673708916 CEST4555660445.95.169.120192.168.2.23
                                                                                      Oct 29, 2021 09:00:34.674118996 CEST56608455192.168.2.2345.95.169.120
                                                                                      Oct 29, 2021 09:00:35.687602043 CEST56608455192.168.2.2345.95.169.120
                                                                                      Oct 29, 2021 09:00:37.703474998 CEST56608455192.168.2.2345.95.169.120
                                                                                      Oct 29, 2021 09:00:37.736776114 CEST4555660845.95.169.120192.168.2.23

                                                                                      System Behavior

                                                                                      General

                                                                                      Start time:08:59:02
                                                                                      Start date:29/10/2021
                                                                                      Path:/tmp/Y4W4j5QIqD
                                                                                      Arguments:/tmp/Y4W4j5QIqD
                                                                                      File size:4463432 bytes
                                                                                      MD5 hash:cd177594338c77b895ae27c33f8f86cc

                                                                                      General

                                                                                      Start time:08:59:02
                                                                                      Start date:29/10/2021
                                                                                      Path:/tmp/Y4W4j5QIqD
                                                                                      Arguments:n/a
                                                                                      File size:4463432 bytes
                                                                                      MD5 hash:cd177594338c77b895ae27c33f8f86cc