Loading ...

Play interactive tourEdit tour

Linux Analysis Report r7jYRiiUEn

Overview

General Information

Sample Name:r7jYRiiUEn
Analysis ID:556567
MD5:1ed6cac04ce64b9f50e82e6639d85a1e
SHA1:d49f7392a81ff968f345c266a87a4435208688fe
SHA256:747514b6ab4d7b4f72aead6a1c15832bb7a38e70f3125f5191a4b1584d4076ac
Tags:32armelfmirai
Infos:

Detection

Score:52
Range:0 - 100
Whitelisted:false

Signatures

Multi AV Scanner detection for submitted file
Sample tries to kill multiple processes (SIGKILL)
Sample has stripped symbol table
Uses the "uname" system call to query kernel version information (possible evasion)
Enumerates processes within the "proc" file system
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Detected TCP or UDP traffic on non-standard ports
Executes the "rm" command used to delete files or directories
Sample listens on a socket
Sample tries to kill a process (SIGKILL)

Classification

Analysis Advice

Static ELF header machine description suggests that the sample might only run correctly on MIPS or ARM architectures
All HTTP servers contacted by the sample do not answer. Likely the sample is an old dropper which does no longer work
Static ELF header machine description suggests that the sample might not execute correctly on this machine

General Information

Joe Sandbox Version:34.0.0 Boulder Opal
Analysis ID:556567
Start date:20.01.2022
Start time:08:57:20
Joe Sandbox Product:CloudBasic
Overall analysis duration:0h 5m 28s
Hypervisor based Inspection enabled:false
Report type:full
Sample file name:r7jYRiiUEn
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Detection:MAL
Classification:mal52.spre.lin@0/1@0/0

Process Tree

  • system is lnxubuntu20
  • dash New Fork (PID: 5205, Parent: 4331)
  • cat (PID: 5205, Parent: 4331, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /tmp/tmp.UGJagif37Z
  • dash New Fork (PID: 5206, Parent: 4331)
  • head (PID: 5206, Parent: 4331, MD5: fd96a67145172477dd57131396fc9608) Arguments: head -n 10
  • dash New Fork (PID: 5207, Parent: 4331)
  • tr (PID: 5207, Parent: 4331, MD5: fbd1402dd9f72d8ebfff00ce7c3a7bb5) Arguments: tr -d \\000-\\011\\013\\014\\016-\\037
  • dash New Fork (PID: 5208, Parent: 4331)
  • cut (PID: 5208, Parent: 4331, MD5: d8ed0ea8f22c0de0f8692d4d9f1759d3) Arguments: cut -c -80
  • dash New Fork (PID: 5209, Parent: 4331)
  • cat (PID: 5209, Parent: 4331, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /tmp/tmp.UGJagif37Z
  • dash New Fork (PID: 5210, Parent: 4331)
  • head (PID: 5210, Parent: 4331, MD5: fd96a67145172477dd57131396fc9608) Arguments: head -n 10
  • dash New Fork (PID: 5211, Parent: 4331)
  • tr (PID: 5211, Parent: 4331, MD5: fbd1402dd9f72d8ebfff00ce7c3a7bb5) Arguments: tr -d \\000-\\011\\013\\014\\016-\\037
  • dash New Fork (PID: 5212, Parent: 4331)
  • cut (PID: 5212, Parent: 4331, MD5: d8ed0ea8f22c0de0f8692d4d9f1759d3) Arguments: cut -c -80
  • dash New Fork (PID: 5214, Parent: 4331)
  • rm (PID: 5214, Parent: 4331, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.UGJagif37Z /tmp/tmp.Bi7lGtHVI6 /tmp/tmp.YUzRYq0ngN
  • r7jYRiiUEn (PID: 5226, Parent: 5107, MD5: 5ebfcae4fe2471fcc5695c2394773ff1) Arguments: /tmp/r7jYRiiUEn
  • cleanup

Yara Overview

No yara matches

Jbx Signature Overview

Click to jump to signature section

Show All Signature Results

AV Detection:

barindex
Multi AV Scanner detection for submitted fileShow sources
Source: r7jYRiiUEnVirustotal: Detection: 47%Perma Link
Source: r7jYRiiUEnReversingLabs: Detection: 58%
Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
Source: global trafficTCP traffic: 192.168.2.23:51412 -> 198.50.242.157:666
Source: /tmp/r7jYRiiUEn (PID: 5228)Socket: 0.0.0.0::0Jump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5228)Socket: 0.0.0.0::53413Jump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5228)Socket: 0.0.0.0::80Jump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5228)Socket: 0.0.0.0::37215Jump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)Socket: 0.0.0.0::0Jump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)Socket: 0.0.0.0::53413Jump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)Socket: 0.0.0.0::80Jump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)Socket: 0.0.0.0::37215Jump to behavior
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: unknownTCP traffic detected without corresponding DNS query: 198.50.242.157
Source: motd-news.19.drString found in binary or memory: https://ubuntu.com/blog/microk8s-memory-optimisation

System Summary:

barindex
Sample tries to kill multiple processes (SIGKILL)Show sources
Source: /tmp/r7jYRiiUEn (PID: 5228)SIGKILL sent: pid: 936, result: successfulJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)SIGKILL sent: pid: 936, result: successfulJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)SIGKILL sent: pid: 5228, result: successfulJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)SIGKILL sent: pid: 720, result: successfulJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)SIGKILL sent: pid: 759, result: successfulJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)SIGKILL sent: pid: 788, result: successfulJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)SIGKILL sent: pid: 800, result: successfulJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)SIGKILL sent: pid: 847, result: successfulJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)SIGKILL sent: pid: 884, result: successfulJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)SIGKILL sent: pid: 1334, result: successfulJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)SIGKILL sent: pid: 1335, result: successfulJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)SIGKILL sent: pid: 1860, result: successfulJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)SIGKILL sent: pid: 1872, result: successfulJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)SIGKILL sent: pid: 2096, result: successfulJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)SIGKILL sent: pid: 2097, result: successfulJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)SIGKILL sent: pid: 2102, result: successfulJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)SIGKILL sent: pid: 2180, result: successfulJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)SIGKILL sent: pid: 2208, result: successfulJump to behavior
Source: ELF static info symbol of initial sample.symtab present: no
Source: /tmp/r7jYRiiUEn (PID: 5228)SIGKILL sent: pid: 936, result: successfulJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)SIGKILL sent: pid: 936, result: successfulJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)SIGKILL sent: pid: 5228, result: successfulJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)SIGKILL sent: pid: 720, result: successfulJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)SIGKILL sent: pid: 759, result: successfulJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)SIGKILL sent: pid: 788, result: successfulJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)SIGKILL sent: pid: 800, result: successfulJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)SIGKILL sent: pid: 847, result: successfulJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)SIGKILL sent: pid: 884, result: successfulJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)SIGKILL sent: pid: 1334, result: successfulJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)SIGKILL sent: pid: 1335, result: successfulJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)SIGKILL sent: pid: 1860, result: successfulJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)SIGKILL sent: pid: 1872, result: successfulJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)SIGKILL sent: pid: 2096, result: successfulJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)SIGKILL sent: pid: 2097, result: successfulJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)SIGKILL sent: pid: 2102, result: successfulJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)SIGKILL sent: pid: 2180, result: successfulJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)SIGKILL sent: pid: 2208, result: successfulJump to behavior
Source: classification engineClassification label: mal52.spre.lin@0/1@0/0
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/2033/fdJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/2033/exeJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/1582/fdJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/1582/exeJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/2275/fdJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/1612/fdJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/1612/exeJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/1579/fdJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/1579/exeJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/1699/fdJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/1699/exeJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/1335/fdJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/1335/exeJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/1698/fdJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/1698/exeJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/2028/fdJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/2028/exeJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/1334/fdJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/1334/exeJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/1576/fdJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/1576/exeJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/2302/fdJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/3236/fdJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/2025/fdJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/2025/exeJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/2146/fdJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/2146/exeJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/910/exeJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/912/fdJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/912/fdJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/912/exeJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/759/fdJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/759/fdJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/759/exeJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/517/exeJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/2307/fdJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/918/fdJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/918/fdJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/918/exeJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/5030/fdJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/1594/fdJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/1594/exeJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/2285/fdJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/2281/fdJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/1349/fdJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/1349/exeJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/1/fdJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/1/fdJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/1623/fdJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/1623/exeJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/761/fdJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/761/fdJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/761/exeJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/1622/fdJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/1622/exeJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/884/fdJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/884/fdJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/884/exeJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/1983/fdJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/1983/exeJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/2038/fdJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/2038/exeJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/1586/fdJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/1586/exeJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/1465/fdJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/1465/exeJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/1344/fdJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/1344/exeJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/1860/fdJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/1860/exeJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/1463/fdJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/1463/exeJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/2156/fdJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/2156/exeJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/800/fdJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/800/fdJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/800/exeJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/801/fdJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/801/fdJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/801/exeJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/1629/fdJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/1629/exeJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/1627/fdJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/1627/exeJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/1900/fdJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/1900/exeJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/491/fdJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/491/fdJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/491/exeJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/2294/fdJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/2050/fdJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/2050/exeJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/1877/fdJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/1877/exeJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/772/fdJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/772/fdJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/772/exeJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/1633/fdJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/1633/exeJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/1599/fdJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/1599/exeJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/1632/fdJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/1632/exeJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/1477/fdJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5234)File opened: /proc/1477/exeJump to behavior
Source: /usr/bin/dash (PID: 5214)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.UGJagif37Z /tmp/tmp.Bi7lGtHVI6 /tmp/tmp.YUzRYq0ngNJump to behavior
Source: /tmp/r7jYRiiUEn (PID: 5226)Queries kernel information via 'uname': Jump to behavior
Source: r7jYRiiUEn, 5226.1.0000000096a4e780.0000000014bf517a.rw-.sdmp, r7jYRiiUEn, 5228.1.0000000096a4e780.0000000014bf517a.rw-.sdmp, r7jYRiiUEn, 5229.1.0000000096a4e780.0000000014bf517a.rw-.sdmp, r7jYRiiUEn, 5236.1.0000000096a4e780.0000000014bf517a.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-arm/tmp/r7jYRiiUEnSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/r7jYRiiUEn
Source: r7jYRiiUEn, 5226.1.000000003a75b1d4.0000000000357306.rw-.sdmp, r7jYRiiUEn, 5228.1.000000003a75b1d4.0000000000357306.rw-.sdmp, r7jYRiiUEn, 5229.1.000000003a75b1d4.0000000000357306.rw-.sdmp, r7jYRiiUEn, 5236.1.000000003a75b1d4.0000000000357306.rw-.sdmpBinary or memory string: ~U!/etc/qemu-binfmt/arm
Source: r7jYRiiUEn, 5226.1.000000003a75b1d4.0000000000357306.rw-.sdmp, r7jYRiiUEn, 5228.1.000000003a75b1d4.0000000000357306.rw-.sdmp, r7jYRiiUEn, 5229.1.000000003a75b1d4.0000000000357306.rw-.sdmp, r7jYRiiUEn, 5236.1.000000003a75b1d4.0000000000357306.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/arm
Source: r7jYRiiUEn, 5226.1.0000000096a4e780.0000000014bf517a.rw-.sdmp, r7jYRiiUEn, 5228.1.0000000096a4e780.0000000014bf517a.rw-.sdmp, r7jYRiiUEn, 5229.1.0000000096a4e780.0000000014bf517a.rw-.sdmp, r7jYRiiUEn, 5236.1.0000000096a4e780.0000000014bf517a.rw-.sdmpBinary or memory string: /usr/bin/qemu-arm

Mitre Att&ck Matrix

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionFile Deletion1OS Credential Dumping1Security Software Discovery11Remote ServicesData from Local SystemExfiltration Over Other Network MediumEncrypted Channel1Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over BluetoothNon-Standard Port1Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationApplication Layer Protocol1Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data

Malware Configuration

No configs have been found

Behavior Graph

Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 556567 Sample: r7jYRiiUEn Startdate: 20/01/2022 Architecture: LINUX Score: 52 28 198.50.242.157, 51412, 666 OVHFR Canada 2->28 30 109.202.202.202, 80 INIT7CH Switzerland 2->30 32 2 other IPs or domains 2->32 36 Multi AV Scanner detection for submitted file 2->36 8 dash rm r7jYRiiUEn 2->8         started        10 dash cat 2->10         started        12 dash head 2->12         started        14 6 other processes 2->14 signatures3 process4 process5 16 r7jYRiiUEn 8->16         started        18 r7jYRiiUEn 8->18         started        21 r7jYRiiUEn 8->21         started        signatures6 23 r7jYRiiUEn 16->23         started        26 r7jYRiiUEn 16->26         started        34 Sample tries to kill multiple processes (SIGKILL) 18->34 process7 signatures8 38 Sample tries to kill multiple processes (SIGKILL) 23->38

Antivirus, Machine Learning and Genetic Malware Detection

Initial Sample

SourceDetectionScannerLabelLink
r7jYRiiUEn48%VirustotalBrowse
r7jYRiiUEn58%ReversingLabsLinux.Trojan.Mirai

Dropped Files

No Antivirus matches

Domains

No Antivirus matches

URLs

No Antivirus matches

Domains and IPs

Contacted Domains

No contacted domains info

URLs from Memory and Binaries

NameSourceMaliciousAntivirus DetectionReputation
https://ubuntu.com/blog/microk8s-memory-optimisationmotd-news.19.drfalse
    high

    Contacted IPs

    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs

    Public

    IPDomainCountryFlagASNASN NameMalicious
    109.202.202.202
    unknownSwitzerland
    13030INIT7CHfalse
    198.50.242.157
    unknownCanada
    16276OVHFRfalse
    91.189.91.43
    unknownUnited Kingdom
    41231CANONICAL-ASGBfalse
    91.189.91.42
    unknownUnited Kingdom
    41231CANONICAL-ASGBfalse


    Runtime Messages

    Command:/tmp/r7jYRiiUEn
    Exit Code:0
    Exit Code Info:
    Killed:False
    Standard Output:
    DaddyL33T Infected Your Shit
    Standard Error:

    Joe Sandbox View / Context

    IPs

    MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
    109.202.202.202t60zOeHqDvGet hashmaliciousBrowse
      Josho.x86Get hashmaliciousBrowse
        sRZz4JQ66KGet hashmaliciousBrowse
          tYjozYxSZqGet hashmaliciousBrowse
            a-r.m-4.ISISGet hashmaliciousBrowse
              a-r.m-5.ISISGet hashmaliciousBrowse
                a-r.m-6.ISISGet hashmaliciousBrowse
                  SecuriteInfo.com.ELF.Mirai.XS.15896.15279Get hashmaliciousBrowse
                    a-r.m-7.ISISGet hashmaliciousBrowse
                      i-5.8-6.ISISGet hashmaliciousBrowse
                        m-i.p-s.ISISGet hashmaliciousBrowse
                          m-p.s-l.ISISGet hashmaliciousBrowse
                            s-h.4-.ISISGet hashmaliciousBrowse
                              x-3.2-.ISISGet hashmaliciousBrowse
                                UnHAnaAW.arm5Get hashmaliciousBrowse
                                  UnHAnaAW.arm6Get hashmaliciousBrowse
                                    x-8.6-.ISISGet hashmaliciousBrowse
                                      tokyo.armGet hashmaliciousBrowse
                                        tokyo.arm5Get hashmaliciousBrowse
                                          tokyo.arm6Get hashmaliciousBrowse
                                            198.50.242.157Josho.x86Get hashmaliciousBrowse
                                              91.189.91.43t60zOeHqDvGet hashmaliciousBrowse
                                                Josho.x86Get hashmaliciousBrowse
                                                  sRZz4JQ66KGet hashmaliciousBrowse
                                                    tYjozYxSZqGet hashmaliciousBrowse
                                                      a-r.m-4.ISISGet hashmaliciousBrowse
                                                        a-r.m-5.ISISGet hashmaliciousBrowse
                                                          a-r.m-6.ISISGet hashmaliciousBrowse
                                                            SecuriteInfo.com.ELF.Mirai.XS.15896.15279Get hashmaliciousBrowse
                                                              a-r.m-7.ISISGet hashmaliciousBrowse
                                                                i-5.8-6.ISISGet hashmaliciousBrowse
                                                                  m-i.p-s.ISISGet hashmaliciousBrowse
                                                                    m-p.s-l.ISISGet hashmaliciousBrowse
                                                                      s-h.4-.ISISGet hashmaliciousBrowse
                                                                        x-3.2-.ISISGet hashmaliciousBrowse
                                                                          UnHAnaAW.arm5Get hashmaliciousBrowse
                                                                            UnHAnaAW.arm6Get hashmaliciousBrowse
                                                                              x-8.6-.ISISGet hashmaliciousBrowse
                                                                                tokyo.armGet hashmaliciousBrowse
                                                                                  tokyo.arm5Get hashmaliciousBrowse
                                                                                    tokyo.arm6Get hashmaliciousBrowse

                                                                                      Domains

                                                                                      No context

                                                                                      ASN

                                                                                      MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                      INIT7CHt60zOeHqDvGet hashmaliciousBrowse
                                                                                      • 109.202.202.202
                                                                                      Josho.x86Get hashmaliciousBrowse
                                                                                      • 109.202.202.202
                                                                                      sRZz4JQ66KGet hashmaliciousBrowse
                                                                                      • 109.202.202.202
                                                                                      tYjozYxSZqGet hashmaliciousBrowse
                                                                                      • 109.202.202.202
                                                                                      a-r.m-4.ISISGet hashmaliciousBrowse
                                                                                      • 109.202.202.202
                                                                                      a-r.m-5.ISISGet hashmaliciousBrowse
                                                                                      • 109.202.202.202
                                                                                      a-r.m-6.ISISGet hashmaliciousBrowse
                                                                                      • 109.202.202.202
                                                                                      SecuriteInfo.com.ELF.Mirai.XS.15896.15279Get hashmaliciousBrowse
                                                                                      • 109.202.202.202
                                                                                      a-r.m-7.ISISGet hashmaliciousBrowse
                                                                                      • 109.202.202.202
                                                                                      i-5.8-6.ISISGet hashmaliciousBrowse
                                                                                      • 109.202.202.202
                                                                                      m-i.p-s.ISISGet hashmaliciousBrowse
                                                                                      • 109.202.202.202
                                                                                      m-p.s-l.ISISGet hashmaliciousBrowse
                                                                                      • 109.202.202.202
                                                                                      s-h.4-.ISISGet hashmaliciousBrowse
                                                                                      • 109.202.202.202
                                                                                      x-3.2-.ISISGet hashmaliciousBrowse
                                                                                      • 109.202.202.202
                                                                                      UnHAnaAW.arm5Get hashmaliciousBrowse
                                                                                      • 109.202.202.202
                                                                                      UnHAnaAW.arm6Get hashmaliciousBrowse
                                                                                      • 109.202.202.202
                                                                                      x-8.6-.ISISGet hashmaliciousBrowse
                                                                                      • 109.202.202.202
                                                                                      tokyo.armGet hashmaliciousBrowse
                                                                                      • 109.202.202.202
                                                                                      tokyo.arm5Get hashmaliciousBrowse
                                                                                      • 109.202.202.202
                                                                                      tokyo.arm6Get hashmaliciousBrowse
                                                                                      • 109.202.202.202
                                                                                      OVHFRJosho.x86Get hashmaliciousBrowse
                                                                                      • 198.50.242.157
                                                                                      2k7GDMVeXP.dllGet hashmaliciousBrowse
                                                                                      • 54.38.242.185
                                                                                      fcZINN0PI1.dllGet hashmaliciousBrowse
                                                                                      • 54.38.242.185
                                                                                      B0OiokCj3u.dllGet hashmaliciousBrowse
                                                                                      • 54.38.242.185
                                                                                      6LTeMOAy5Z.dllGet hashmaliciousBrowse
                                                                                      • 54.38.242.185
                                                                                      qyRCSMzFKy.dllGet hashmaliciousBrowse
                                                                                      • 54.38.242.185
                                                                                      NBC-INV-099834.exeGet hashmaliciousBrowse
                                                                                      • 37.187.180.144
                                                                                      V5dn32NKTC.exeGet hashmaliciousBrowse
                                                                                      • 51.254.27.112
                                                                                      uW6c5twHB3.dllGet hashmaliciousBrowse
                                                                                      • 54.38.242.185
                                                                                      NNjq08PWTp.dllGet hashmaliciousBrowse
                                                                                      • 54.38.242.185
                                                                                      75Up9knhHV.dllGet hashmaliciousBrowse
                                                                                      • 54.38.242.185
                                                                                      J0KMiDX4BF.dllGet hashmaliciousBrowse
                                                                                      • 54.38.242.185
                                                                                      DyN2QqaMfu.dllGet hashmaliciousBrowse
                                                                                      • 54.38.242.185
                                                                                      v0d4L8cRB4.dllGet hashmaliciousBrowse
                                                                                      • 54.38.242.185
                                                                                      mJEcAGljX5.dllGet hashmaliciousBrowse
                                                                                      • 54.38.242.185
                                                                                      QEdDci1dHJ.dllGet hashmaliciousBrowse
                                                                                      • 54.38.242.185
                                                                                      vHz2Or74EH.dllGet hashmaliciousBrowse
                                                                                      • 54.38.242.185
                                                                                      TCukZcOa.dllGet hashmaliciousBrowse
                                                                                      • 54.38.242.185
                                                                                      n1zBrIn67t.exeGet hashmaliciousBrowse
                                                                                      • 145.239.208.100
                                                                                      0E144C258913A35001FD23C3413005C90E7BC35BE3BAF.exeGet hashmaliciousBrowse
                                                                                      • 51.91.13.105

                                                                                      JA3 Fingerprints

                                                                                      No context

                                                                                      Dropped Files

                                                                                      No context

                                                                                      Created / dropped Files

                                                                                      /var/cache/motd-news
                                                                                      Process:/usr/bin/cut
                                                                                      File Type:ASCII text
                                                                                      Category:dropped
                                                                                      Size (bytes):191
                                                                                      Entropy (8bit):4.515771857099866
                                                                                      Encrypted:false
                                                                                      SSDEEP:3:P2lnI+5MsqqzNLz+FRNScHUBfRau95++sZzR5woLB1Fh0VTGTl/X5kURn:OZ8uNLzDc0pR75+9Zz/woFmIT52URn
                                                                                      MD5:DD514F892B5F93ED615D366E58AC58AF
                                                                                      SHA1:BA75EDB3C2232CC260BC187F604DC8F25AA72C11
                                                                                      SHA-256:F40D0DCE6E83DF74109FEF5E68E51CC255727783EEAE04C3E34677E23F7552CF
                                                                                      SHA-512:9150BDE63F6C4850C5340D8877892B4D9BBF9EBDC98CDCF557A93FA304C1222CEE446418F5BE2ACCDBF38393778AFA5D4F3EDCB37A47BF57D3A4B2DEAD42A2D0
                                                                                      Malicious:false
                                                                                      Reputation:moderate, very likely benign file
                                                                                      Preview: * Super-optimized for small spaces - read how we shrank the memory. footprint of MicroK8s to make it the smallest full K8s around... https://ubuntu.com/blog/microk8s-memory-optimisation.

                                                                                      Static File Info

                                                                                      General

                                                                                      File type:ELF 32-bit LSB executable, ARM, version 1 (ARM), statically linked, stripped
                                                                                      Entropy (8bit):5.909624831937935
                                                                                      TrID:
                                                                                      • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                                                                      File name:r7jYRiiUEn
                                                                                      File size:48900
                                                                                      MD5:1ed6cac04ce64b9f50e82e6639d85a1e
                                                                                      SHA1:d49f7392a81ff968f345c266a87a4435208688fe
                                                                                      SHA256:747514b6ab4d7b4f72aead6a1c15832bb7a38e70f3125f5191a4b1584d4076ac
                                                                                      SHA512:02a68837324dcdc6f50c7c1ee3552cfe608208a225322c6e8f4944f8603f1bc08452f19dd02a175cc17bb27bc738a0a3f68476a911741fab3f1ec46c9aac2a8c
                                                                                      SSDEEP:768:cS6POfCRi9bfR1YORAgKPjg0JN/mYBdohJXGb0TE5jQ4vwq+IPNOb7u2bqlsS:APOHJfvTM8YBn5jRvwFbqW
                                                                                      File Content Preview:.ELF...a..........(.........4...t.......4. ...(.....................................................(...`...........Q.td..................................-...L."...B+..........0@-.\P...0....S.0...P@...0... ....R......0...0...........0... ....R..... 0....S

                                                                                      Static ELF Info

                                                                                      ELF header

                                                                                      Class:ELF32
                                                                                      Data:2's complement, little endian
                                                                                      Version:1 (current)
                                                                                      Machine:ARM
                                                                                      Version Number:0x1
                                                                                      Type:EXEC (Executable file)
                                                                                      OS/ABI:ARM - ABI
                                                                                      ABI Version:0
                                                                                      Entry Point Address:0x8190
                                                                                      Flags:0x202
                                                                                      ELF Header Size:52
                                                                                      Program Header Offset:52
                                                                                      Program Header Size:32
                                                                                      Number of Program Headers:3
                                                                                      Section Header Offset:48500
                                                                                      Section Header Size:40
                                                                                      Number of Section Headers:10
                                                                                      Header String Table Index:9

                                                                                      Sections

                                                                                      NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                                                      NULL0x00x00x00x00x0000
                                                                                      .initPROGBITS0x80940x940x180x00x6AX004
                                                                                      .textPROGBITS0x80b00xb00xad400x00x6AX0016
                                                                                      .finiPROGBITS0x12df00xadf00x140x00x6AX004
                                                                                      .rodataPROGBITS0x12e040xae040xd040x00x2A004
                                                                                      .ctorsPROGBITS0x1bb0c0xbb0c0x80x00x3WA004
                                                                                      .dtorsPROGBITS0x1bb140xbb140x80x00x3WA004
                                                                                      .dataPROGBITS0x1bb200xbb200x2140x00x3WA004
                                                                                      .bssNOBITS0x1bd340xbd340x2380x00x3WA004
                                                                                      .shstrtabSTRTAB0x00xbd340x3e0x00x0001

                                                                                      Program Segments

                                                                                      TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                                                      LOAD0x00x80000x80000xbb080xbb083.11900x5R E0x8000.init .text .fini .rodata
                                                                                      LOAD0xbb0c0x1bb0c0x1bb0c0x2280x4601.60490x6RW 0x8000.ctors .dtors .data .bss
                                                                                      GNU_STACK0x00x00x00x00x00.00000x7RWE0x4

                                                                                      Network Behavior

                                                                                      Network Port Distribution

                                                                                      TCP Packets

                                                                                      TimestampSource PortDest PortSource IPDest IP
                                                                                      Jan 20, 2022 08:58:05.733897924 CET4251680192.168.2.23109.202.202.202
                                                                                      Jan 20, 2022 08:58:06.542356014 CET51412666192.168.2.23198.50.242.157
                                                                                      Jan 20, 2022 08:58:06.646383047 CET66651412198.50.242.157192.168.2.23
                                                                                      Jan 20, 2022 08:58:06.646466970 CET51412666192.168.2.23198.50.242.157
                                                                                      Jan 20, 2022 08:58:06.646775007 CET51412666192.168.2.23198.50.242.157
                                                                                      Jan 20, 2022 08:58:06.750659943 CET66651412198.50.242.157192.168.2.23
                                                                                      Jan 20, 2022 08:58:06.750755072 CET51412666192.168.2.23198.50.242.157
                                                                                      Jan 20, 2022 08:58:06.854737997 CET66651412198.50.242.157192.168.2.23
                                                                                      Jan 20, 2022 08:58:16.656754017 CET51412666192.168.2.23198.50.242.157
                                                                                      Jan 20, 2022 08:58:16.760716915 CET66651412198.50.242.157192.168.2.23
                                                                                      Jan 20, 2022 08:58:16.760783911 CET66651412198.50.242.157192.168.2.23
                                                                                      Jan 20, 2022 08:58:16.761133909 CET51412666192.168.2.23198.50.242.157
                                                                                      Jan 20, 2022 08:58:19.557334900 CET43928443192.168.2.2391.189.91.42
                                                                                      Jan 20, 2022 08:58:31.844700098 CET42836443192.168.2.2391.189.91.43
                                                                                      Jan 20, 2022 08:58:31.875442028 CET66651412198.50.242.157192.168.2.23
                                                                                      Jan 20, 2022 08:58:31.875602961 CET51412666192.168.2.23198.50.242.157
                                                                                      Jan 20, 2022 08:58:35.940525055 CET4251680192.168.2.23109.202.202.202
                                                                                      Jan 20, 2022 08:58:46.979392052 CET66651412198.50.242.157192.168.2.23
                                                                                      Jan 20, 2022 08:58:46.979576111 CET51412666192.168.2.23198.50.242.157
                                                                                      Jan 20, 2022 08:59:00.515325069 CET43928443192.168.2.2391.189.91.42
                                                                                      Jan 20, 2022 08:59:02.083705902 CET66651412198.50.242.157192.168.2.23
                                                                                      Jan 20, 2022 08:59:02.083872080 CET51412666192.168.2.23198.50.242.157
                                                                                      Jan 20, 2022 08:59:16.811497927 CET51412666192.168.2.23198.50.242.157
                                                                                      Jan 20, 2022 08:59:16.916068077 CET66651412198.50.242.157192.168.2.23
                                                                                      Jan 20, 2022 08:59:16.916235924 CET51412666192.168.2.23198.50.242.157
                                                                                      Jan 20, 2022 08:59:32.036247969 CET66651412198.50.242.157192.168.2.23
                                                                                      Jan 20, 2022 08:59:32.036418915 CET51412666192.168.2.23198.50.242.157
                                                                                      Jan 20, 2022 08:59:47.140258074 CET66651412198.50.242.157192.168.2.23
                                                                                      Jan 20, 2022 08:59:47.140362978 CET51412666192.168.2.23198.50.242.157
                                                                                      Jan 20, 2022 09:00:02.244261980 CET66651412198.50.242.157192.168.2.23
                                                                                      Jan 20, 2022 09:00:02.244440079 CET51412666192.168.2.23198.50.242.157
                                                                                      Jan 20, 2022 09:00:16.967714071 CET51412666192.168.2.23198.50.242.157
                                                                                      Jan 20, 2022 09:00:17.071757078 CET66651412198.50.242.157192.168.2.23
                                                                                      Jan 20, 2022 09:00:17.071944952 CET51412666192.168.2.23198.50.242.157

                                                                                      System Behavior

                                                                                      General

                                                                                      Start time:08:58:01
                                                                                      Start date:20/01/2022
                                                                                      Path:/usr/bin/dash
                                                                                      Arguments:n/a
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      General

                                                                                      Start time:08:58:01
                                                                                      Start date:20/01/2022
                                                                                      Path:/usr/bin/cat
                                                                                      Arguments:cat /tmp/tmp.UGJagif37Z
                                                                                      File size:43416 bytes
                                                                                      MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

                                                                                      General

                                                                                      Start time:08:58:01
                                                                                      Start date:20/01/2022
                                                                                      Path:/usr/bin/dash
                                                                                      Arguments:n/a
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      General

                                                                                      Start time:08:58:01
                                                                                      Start date:20/01/2022
                                                                                      Path:/usr/bin/head
                                                                                      Arguments:head -n 10
                                                                                      File size:47480 bytes
                                                                                      MD5 hash:fd96a67145172477dd57131396fc9608

                                                                                      General

                                                                                      Start time:08:58:01
                                                                                      Start date:20/01/2022
                                                                                      Path:/usr/bin/dash
                                                                                      Arguments:n/a
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      General

                                                                                      Start time:08:58:01
                                                                                      Start date:20/01/2022
                                                                                      Path:/usr/bin/tr
                                                                                      Arguments:tr -d \\000-\\011\\013\\014\\016-\\037
                                                                                      File size:51544 bytes
                                                                                      MD5 hash:fbd1402dd9f72d8ebfff00ce7c3a7bb5

                                                                                      General

                                                                                      Start time:08:58:01
                                                                                      Start date:20/01/2022
                                                                                      Path:/usr/bin/dash
                                                                                      Arguments:n/a
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      General

                                                                                      Start time:08:58:01
                                                                                      Start date:20/01/2022
                                                                                      Path:/usr/bin/cut
                                                                                      Arguments:cut -c -80
                                                                                      File size:47480 bytes
                                                                                      MD5 hash:d8ed0ea8f22c0de0f8692d4d9f1759d3

                                                                                      General

                                                                                      Start time:08:58:01
                                                                                      Start date:20/01/2022
                                                                                      Path:/usr/bin/dash
                                                                                      Arguments:n/a
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      General

                                                                                      Start time:08:58:01
                                                                                      Start date:20/01/2022
                                                                                      Path:/usr/bin/cat
                                                                                      Arguments:cat /tmp/tmp.UGJagif37Z
                                                                                      File size:43416 bytes
                                                                                      MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

                                                                                      General

                                                                                      Start time:08:58:01
                                                                                      Start date:20/01/2022
                                                                                      Path:/usr/bin/dash
                                                                                      Arguments:n/a
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      General

                                                                                      Start time:08:58:01
                                                                                      Start date:20/01/2022
                                                                                      Path:/usr/bin/head
                                                                                      Arguments:head -n 10
                                                                                      File size:47480 bytes
                                                                                      MD5 hash:fd96a67145172477dd57131396fc9608

                                                                                      General

                                                                                      Start time:08:58:01
                                                                                      Start date:20/01/2022
                                                                                      Path:/usr/bin/dash
                                                                                      Arguments:n/a
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      General

                                                                                      Start time:08:58:01
                                                                                      Start date:20/01/2022
                                                                                      Path:/usr/bin/tr
                                                                                      Arguments:tr -d \\000-\\011\\013\\014\\016-\\037
                                                                                      File size:51544 bytes
                                                                                      MD5 hash:fbd1402dd9f72d8ebfff00ce7c3a7bb5

                                                                                      General

                                                                                      Start time:08:58:01
                                                                                      Start date:20/01/2022
                                                                                      Path:/usr/bin/dash
                                                                                      Arguments:n/a
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      General

                                                                                      Start time:08:58:01
                                                                                      Start date:20/01/2022
                                                                                      Path:/usr/bin/cut
                                                                                      Arguments:cut -c -80
                                                                                      File size:47480 bytes
                                                                                      MD5 hash:d8ed0ea8f22c0de0f8692d4d9f1759d3

                                                                                      General

                                                                                      Start time:08:58:01
                                                                                      Start date:20/01/2022
                                                                                      Path:/usr/bin/dash
                                                                                      Arguments:n/a
                                                                                      File size:129816 bytes
                                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                      General

                                                                                      Start time:08:58:01
                                                                                      Start date:20/01/2022
                                                                                      Path:/usr/bin/rm
                                                                                      Arguments:rm -f /tmp/tmp.UGJagif37Z /tmp/tmp.Bi7lGtHVI6 /tmp/tmp.YUzRYq0ngN
                                                                                      File size:72056 bytes
                                                                                      MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                                                                      General

                                                                                      Start time:08:58:04
                                                                                      Start date:20/01/2022
                                                                                      Path:/tmp/r7jYRiiUEn
                                                                                      Arguments:/tmp/r7jYRiiUEn
                                                                                      File size:4956856 bytes
                                                                                      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                                                      General

                                                                                      Start time:08:58:05
                                                                                      Start date:20/01/2022
                                                                                      Path:/tmp/r7jYRiiUEn
                                                                                      Arguments:n/a
                                                                                      File size:4956856 bytes
                                                                                      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                                                      General

                                                                                      Start time:08:58:05
                                                                                      Start date:20/01/2022
                                                                                      Path:/tmp/r7jYRiiUEn
                                                                                      Arguments:n/a
                                                                                      File size:4956856 bytes
                                                                                      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                                                      General

                                                                                      Start time:08:58:05
                                                                                      Start date:20/01/2022
                                                                                      Path:/tmp/r7jYRiiUEn
                                                                                      Arguments:n/a
                                                                                      File size:4956856 bytes
                                                                                      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                                                      General

                                                                                      Start time:08:58:05
                                                                                      Start date:20/01/2022
                                                                                      Path:/tmp/r7jYRiiUEn
                                                                                      Arguments:n/a
                                                                                      File size:4956856 bytes
                                                                                      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                                                      General

                                                                                      Start time:08:58:05
                                                                                      Start date:20/01/2022
                                                                                      Path:/tmp/r7jYRiiUEn
                                                                                      Arguments:n/a
                                                                                      File size:4956856 bytes
                                                                                      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1