Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
zone.arm64.elf

Overview

General Information

Sample name:zone.arm64.elf
Analysis ID:1546610
MD5:85555f7f531e7cf3508fa991310f7871
SHA1:07d96723e6abd478b2e85d9ddd181197153fdcc4
SHA256:2cb21f2e522ab5ec4b1699320157b0aadea3ead26cbe9c317e7900e7df7b81fc
Tags:elfuser-abuse_ch
Infos:

Detection

Score:24
Range:0 - 100
Whitelisted:false

Signatures

Sample is packed with UPX
ELF contains segments with high entropy indicating compressed/encrypted content
Executes commands using a shell command-line interpreter
Executes the "grep" command used to find patterns in files or piped streams
Reads CPU information from /sys indicative of miner or evasive malware
Reads system information from the proc file system
Sample contains only a LOAD segment without any section mappings
Sample listens on a socket
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1546610
Start date and time:2024-11-01 08:42:12 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 6m 2s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:zone.arm64.elf
Detection:SUS
Classification:sus24.evad.linELF@0/0@2/0
  • Some HTTP raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
Command:/tmp/zone.arm64.elf
PID:5431
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
main:{"arch":"arm64","flags":["L","A","R"],"local":"192.168.2.13","mac":"ecf4bb61ae2f","tag":"","uptime":0,"version":"2.0.30"}[1;40;36m02:43:01 connected to 38.60.221.177:80[0m
[1;40;37m02:43:11 info modified by handshake:{"arch":"arm64","connected":1730446982,"flags":["L","A","R"],"ip":"173.254.250.82","local":"192.168.2.13","mac":"ecf4bb61ae2f_173.254.250.82","tag":"","uptime":0,"version":"2.0.30"}[0m
Standard Error:2024/11/01 02:43:11 [*] get job
2024/11/01 02:43:11 timeout: 2m0s
2024/11/01 02:43:11 timeout: 2m0s
2024/11/01 02:43:11 timeout: 2m0s
2024/11/01 02:43:12 timeout: 2m0s
2024/11/01 02:43:12 timeout: 2m0s
2024/11/01 02:43:12 timeout: 2m0s
  • system is lnxubuntu20
  • zone.arm64.elf (PID: 5431, Parent: 5355, MD5: 02e8e39e1b46472a60d128a6da84a2b8) Arguments: /tmp/zone.arm64.elf
    • zone.arm64.elf (PID: 5436, Parent: 5431, MD5: 02e8e39e1b46472a60d128a6da84a2b8) Arguments: /tmp/zone.arm64.elf -b
      • bash (PID: 5450, Parent: 5436, MD5: 7063c3930affe123baecd3b340f1ad2c) Arguments: /bin/bash -c uptime
      • uptime (PID: 5450, Parent: 5436, MD5: 3ad70d8e33316ac713bf25c2ddf2fb14) Arguments: uptime
      • bash (PID: 5455, Parent: 5436, MD5: 7063c3930affe123baecd3b340f1ad2c) Arguments: bash -c "cat /proc/net/dev |grep ens160 |awk '{print $2}'"
        • bash New Fork (PID: 5461, Parent: 5455)
        • cat (PID: 5461, Parent: 5455, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /proc/net/dev
        • bash New Fork (PID: 5462, Parent: 5455)
        • grep (PID: 5462, Parent: 5455, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep ens160
        • bash New Fork (PID: 5463, Parent: 5455)
        • awk (PID: 5463, Parent: 5455, MD5: 7e9b2ed1272331cfbd2aac2e5eb3f84b) Arguments: awk "{print $2}"
      • bash (PID: 5464, Parent: 5436, MD5: 7063c3930affe123baecd3b340f1ad2c) Arguments: bash -c "cat /proc/net/dev |grep ens160 |awk '{print $10}'"
        • bash New Fork (PID: 5469, Parent: 5464)
        • cat (PID: 5469, Parent: 5464, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /proc/net/dev
        • bash New Fork (PID: 5470, Parent: 5464)
        • grep (PID: 5470, Parent: 5464, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep ens160
        • bash New Fork (PID: 5471, Parent: 5464)
        • awk (PID: 5471, Parent: 5464, MD5: 7e9b2ed1272331cfbd2aac2e5eb3f84b) Arguments: awk "{print $10}"
      • bash (PID: 5529, Parent: 5436, MD5: 7063c3930affe123baecd3b340f1ad2c) Arguments: bash -c "cat /proc/net/dev |grep ens160 |awk '{print $2}'"
        • bash New Fork (PID: 5531, Parent: 5529)
        • cat (PID: 5531, Parent: 5529, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /proc/net/dev
        • bash New Fork (PID: 5532, Parent: 5529)
        • grep (PID: 5532, Parent: 5529, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep ens160
        • bash New Fork (PID: 5533, Parent: 5529)
        • awk (PID: 5533, Parent: 5529, MD5: 7e9b2ed1272331cfbd2aac2e5eb3f84b) Arguments: awk "{print $2}"
      • bash (PID: 5534, Parent: 5436, MD5: 7063c3930affe123baecd3b340f1ad2c) Arguments: bash -c "cat /proc/net/dev |grep ens160 |awk '{print $10}'"
        • bash New Fork (PID: 5536, Parent: 5534)
        • cat (PID: 5536, Parent: 5534, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /proc/net/dev
        • bash New Fork (PID: 5537, Parent: 5534)
        • grep (PID: 5537, Parent: 5534, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep ens160
        • bash New Fork (PID: 5538, Parent: 5534)
        • awk (PID: 5538, Parent: 5534, MD5: 7e9b2ed1272331cfbd2aac2e5eb3f84b) Arguments: awk "{print $10}"
      • bash (PID: 5567, Parent: 5436, MD5: 7063c3930affe123baecd3b340f1ad2c) Arguments: bash -c "cat /proc/net/dev |grep ens160 |awk '{print $2}'"
        • bash New Fork (PID: 5569, Parent: 5567)
        • cat (PID: 5569, Parent: 5567, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /proc/net/dev
        • bash New Fork (PID: 5570, Parent: 5567)
        • grep (PID: 5570, Parent: 5567, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep ens160
        • bash New Fork (PID: 5571, Parent: 5567)
        • awk (PID: 5571, Parent: 5567, MD5: 7e9b2ed1272331cfbd2aac2e5eb3f84b) Arguments: awk "{print $2}"
      • bash (PID: 5572, Parent: 5436, MD5: 7063c3930affe123baecd3b340f1ad2c) Arguments: bash -c "cat /proc/net/dev |grep ens160 |awk '{print $10}'"
        • bash New Fork (PID: 5574, Parent: 5572)
        • cat (PID: 5574, Parent: 5572, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /proc/net/dev
        • bash New Fork (PID: 5575, Parent: 5572)
        • grep (PID: 5575, Parent: 5572, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep ens160
        • bash New Fork (PID: 5576, Parent: 5572)
        • awk (PID: 5576, Parent: 5572, MD5: 7e9b2ed1272331cfbd2aac2e5eb3f84b) Arguments: awk "{print $10}"
  • cleanup
No yara matches
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results
Source: /tmp/zone.arm64.elf (PID: 5436)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
Source: /usr/bin/uptime (PID: 5450)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
Source: /tmp/zone.arm64.elf (PID: 5436)Socket: [::]:14820Jump to behavior
Source: unknownTCP traffic detected without corresponding DNS query: 38.60.221.177
Source: unknownTCP traffic detected without corresponding DNS query: 38.60.221.177
Source: unknownTCP traffic detected without corresponding DNS query: 38.60.221.177
Source: unknownTCP traffic detected without corresponding DNS query: 38.60.221.177
Source: unknownTCP traffic detected without corresponding DNS query: 38.60.221.177
Source: unknownTCP traffic detected without corresponding DNS query: 38.60.221.177
Source: unknownTCP traffic detected without corresponding DNS query: 38.60.221.177
Source: unknownTCP traffic detected without corresponding DNS query: 38.60.221.177
Source: unknownTCP traffic detected without corresponding DNS query: 38.60.221.177
Source: unknownTCP traffic detected without corresponding DNS query: 38.60.221.177
Source: unknownTCP traffic detected without corresponding DNS query: 38.60.221.177
Source: unknownTCP traffic detected without corresponding DNS query: 38.60.221.177
Source: unknownTCP traffic detected without corresponding DNS query: 38.60.221.177
Source: unknownTCP traffic detected without corresponding DNS query: 38.60.221.177
Source: unknownTCP traffic detected without corresponding DNS query: 38.60.221.177
Source: unknownTCP traffic detected without corresponding DNS query: 38.60.221.177
Source: unknownTCP traffic detected without corresponding DNS query: 38.60.221.177
Source: unknownTCP traffic detected without corresponding DNS query: 38.60.221.177
Source: unknownTCP traffic detected without corresponding DNS query: 38.60.221.177
Source: unknownTCP traffic detected without corresponding DNS query: 38.60.221.177
Source: unknownTCP traffic detected without corresponding DNS query: 38.60.221.177
Source: unknownTCP traffic detected without corresponding DNS query: 38.60.221.177
Source: unknownTCP traffic detected without corresponding DNS query: 38.60.221.177
Source: unknownTCP traffic detected without corresponding DNS query: 38.60.221.177
Source: unknownTCP traffic detected without corresponding DNS query: 38.60.221.177
Source: unknownTCP traffic detected without corresponding DNS query: 38.60.221.177
Source: unknownTCP traffic detected without corresponding DNS query: 38.60.221.177
Source: unknownTCP traffic detected without corresponding DNS query: 38.60.221.177
Source: unknownTCP traffic detected without corresponding DNS query: 38.60.221.177
Source: unknownTCP traffic detected without corresponding DNS query: 38.60.221.177
Source: unknownTCP traffic detected without corresponding DNS query: 38.60.221.177
Source: global trafficDNS traffic detected: DNS query: daisy.ubuntu.com
Source: zone.arm64.elfString found in binary or memory: http://upx.sf.net
Source: LOAD without section mappingsProgram segment: 0x10000
Source: classification engineClassification label: sus24.evad.linELF@0/0@2/0

Data Obfuscation

barindex
Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
Source: initial sampleString containing UPX found: $Id: UPX 4.24 Copyright (C) 1996-2024 the UPX Team. All Rights Reserved. $
Source: /tmp/zone.arm64.elf (PID: 5450)Shell command executed: /bin/bash -c uptimeJump to behavior
Source: /usr/bin/bash (PID: 5462)Grep executable: /usr/bin/grep -> grep ens160Jump to behavior
Source: /usr/bin/bash (PID: 5470)Grep executable: /usr/bin/grep -> grep ens160Jump to behavior
Source: /usr/bin/bash (PID: 5532)Grep executable: /usr/bin/grep -> grep ens160Jump to behavior
Source: /usr/bin/bash (PID: 5537)Grep executable: /usr/bin/grep -> grep ens160Jump to behavior
Source: /usr/bin/bash (PID: 5570)Grep executable: /usr/bin/grep -> grep ens160Jump to behavior
Source: /usr/bin/bash (PID: 5575)Grep executable: /usr/bin/grep -> grep ens160Jump to behavior
Source: /tmp/zone.arm64.elf (PID: 5431)Reads from proc file: /proc/statJump to behavior
Source: /tmp/zone.arm64.elf (PID: 5436)Reads from proc file: /proc/statJump to behavior
Source: /tmp/zone.arm64.elf (PID: 5436)Reads from proc file: /proc/sys/net/core/somaxconnJump to behavior
Source: /usr/bin/bash (PID: 5463)Awk executable: /usr/bin/awk -> awk "{print $2}"Jump to behavior
Source: /usr/bin/bash (PID: 5471)Awk executable: /usr/bin/awk -> awk "{print $10}"Jump to behavior
Source: /usr/bin/bash (PID: 5533)Awk executable: /usr/bin/awk -> awk "{print $2}"Jump to behavior
Source: /usr/bin/bash (PID: 5538)Awk executable: /usr/bin/awk -> awk "{print $10}"Jump to behavior
Source: /usr/bin/bash (PID: 5571)Awk executable: /usr/bin/awk -> awk "{print $2}"Jump to behavior
Source: /usr/bin/bash (PID: 5576)Awk executable: /usr/bin/awk -> awk "{print $10}"Jump to behavior
Source: submitted sampleStderr: 2024/11/01 02:43:11 [*] get job2024/11/01 02:43:11 timeout: 2m0s2024/11/01 02:43:11 timeout: 2m0s2024/11/01 02:43:11 timeout: 2m0s2024/11/01 02:43:12 timeout: 2m0s2024/11/01 02:43:12 timeout: 2m0s2024/11/01 02:43:12 timeout: 2m0s: exit code = 0
Source: zone.arm64.elfSubmission file: segment LOAD with 7.8086 entropy (max. 8.0)
Source: zone.arm64.elfSubmission file: segment LOAD with 7.9999 entropy (max. 8.0)
Source: /tmp/zone.arm64.elf (PID: 5436)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
Source: /usr/bin/uptime (PID: 5450)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
Source: /tmp/zone.arm64.elf (PID: 5431)Queries kernel information via 'uname': Jump to behavior
Source: /tmp/zone.arm64.elf (PID: 5436)Queries kernel information via 'uname': Jump to behavior
Source: /bin/bash (PID: 5450)Queries kernel information via 'uname': Jump to behavior
Source: /usr/bin/bash (PID: 5455)Queries kernel information via 'uname': Jump to behavior
Source: /usr/bin/bash (PID: 5464)Queries kernel information via 'uname': Jump to behavior
Source: /usr/bin/bash (PID: 5529)Queries kernel information via 'uname': Jump to behavior
Source: /usr/bin/bash (PID: 5534)Queries kernel information via 'uname': Jump to behavior
Source: /usr/bin/bash (PID: 5567)Queries kernel information via 'uname': Jump to behavior
Source: /usr/bin/bash (PID: 5572)Queries kernel information via 'uname': Jump to behavior
Source: zone.arm64.elf, 5436.1.00005643c5de5000.00005643c6584000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/aarch64
Source: zone.arm64.elf, 5431.1.00007ffc64739000.00007ffc6475a000.rw-.sdmpBinary or memory string: u<x86_64/usr/bin/qemu-aarch64/tmp/zone.arm64.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/zone.arm64.elf
Source: zone.arm64.elf, 5431.1.000055db92fa0000.000055db93717000.rw-.sdmpBinary or memory string: U1/etc/qemu-binfmt/aarch64O
Source: zone.arm64.elf, 5436.1.00005643c5de5000.00005643c6584000.rw-.sdmpBinary or memory string: CV1/etc/qemu-binfmt/aarch64O
Source: zone.arm64.elf, 5431.1.000055db92fa0000.000055db93717000.rw-.sdmpBinary or memory string: Urg.qemu.gdb.arm.sys.regs">
Source: zone.arm64.elf, 5436.1.00007ffe6703a000.00007ffe6705b000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-aarch64/tmp/zone.arm64.elf-bSHELL=/bin/bashSUDO_GID=1000MAIL=/var/mail/rootHOME=/rootSUDO_COMMAND=/bin/bashLANG=en_US.UTF-8USER=rootLOGNAME=rootCOLORTERM=truecolorTERM=xterm-256colorSUDO_UID=1000XAUTHORITY=/run/user/1000/gdm/XauthorityDISPLAY=:1.0PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binSUDO_USER=saturnino =/tmp/zone.arm64.elf/tmp/zone.arm64.elf
Source: zone.arm64.elf, 5436.1.00007fe9fc000000.00007fe9fc080000.rw-.sdmpBinary or memory string: arget SYSTEM "gdb-target.dtd"><feature name="org.qemu.gdb.arm.sys.regs"><reg name="MVFR6_EL1_RESERVED" bitsize="64" group="cp_regs"/><reg name="ESR_EL2" bitsize="64" group="cp_regs"/><reg name="TPIDR_EL3" bitsize="64" group="cp_regs"/><reg name="MV
Source: zone.arm64.elf, 5436.1.00007fea00000000.00007fea00047000.rw-.sdmp, zone.arm64.elf, 5436.1.00005643c5de5000.00005643c6584000.rw-.sdmp, zone.arm64.elf, 5436.1.00007fe9fc000000.00007fe9fc080000.rw-.sdmp, zone.arm64.elf, 5436.1.00007fe9f8000000.00007fe9f8056000.rw-.sdmp, zone.arm64.elf, 5436.1.00007fe9f0000000.00007fe9f0046000.rw-.sdmpBinary or memory string: rg.qemu.gdb.arm.sys.regs">
Source: zone.arm64.elf, 5436.1.00005643c5de5000.00005643c6584000.rw-.sdmpBinary or memory string: CVrg.qemu.gdb.arm.sys.regs">
Source: zone.arm64.elf, 5436.1.00007ffe6703a000.00007ffe6705b000.rw-.sdmpBinary or memory string: /usr/bin/qemu-aarch64
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity Information1
Scripting
Valid Accounts1
Command and Scripting Interpreter
1
Scripting
Path Interception11
Obfuscated Files or Information
OS Credential Dumping11
Security Software Discovery
Remote ServicesData from Local System1
Non-Application Layer Protocol
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS Memory2
System Information Discovery
Remote Desktop ProtocolData from Removable Media1
Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1546610 Sample: zone.arm64.elf Startdate: 01/11/2024 Architecture: LINUX Score: 24 39 38.60.221.177, 52830, 52832, 80 COGENT-174US United States 2->39 41 daisy.ubuntu.com 2->41 43 Sample is packed with UPX 2->43 9 zone.arm64.elf 2->9         started        signatures3 process4 process5 11 zone.arm64.elf zone.arm64.elf 9->11         started        process6 13 zone.arm64.elf bash 11->13         started        15 zone.arm64.elf bash 11->15         started        17 zone.arm64.elf bash 11->17         started        19 4 other processes 11->19 process7 21 bash cat 13->21         started        23 bash grep 13->23         started        25 bash awk 13->25         started        27 bash cat 15->27         started        29 bash grep 15->29         started        31 bash awk 15->31         started        33 bash cat 17->33         started        35 2 other processes 17->35 37 9 other processes 19->37
SourceDetectionScannerLabelLink
zone.arm64.elf3%ReversingLabs
No Antivirus matches
SourceDetectionScannerLabelLink
daisy.ubuntu.com0%VirustotalBrowse
SourceDetectionScannerLabelLink
http://upx.sf.net0%URL Reputationsafe
NameIPActiveMaliciousAntivirus DetectionReputation
daisy.ubuntu.com
162.213.35.24
truefalseunknown
NameSourceMaliciousAntivirus DetectionReputation
http://upx.sf.netzone.arm64.elftrue
  • URL Reputation: safe
unknown
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs
IPDomainCountryFlagASNASN NameMalicious
38.60.221.177
unknownUnited States
174COGENT-174USfalse
No context
MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
daisy.ubuntu.comboatnet.sh4.elfGet hashmaliciousMiraiBrowse
  • 162.213.35.24
mips.elfGet hashmaliciousGafgyt, MiraiBrowse
  • 162.213.35.24
boatnet.x86.elfGet hashmaliciousMiraiBrowse
  • 162.213.35.24
sparc.elfGet hashmaliciousGafgyt, MiraiBrowse
  • 162.213.35.25
boatnet.arm6.elfGet hashmaliciousMiraiBrowse
  • 162.213.35.24
boatnet.ppc.elfGet hashmaliciousMiraiBrowse
  • 162.213.35.24
boatnet.arm7.elfGet hashmaliciousMiraiBrowse
  • 162.213.35.24
mips64.elfGet hashmaliciousGafgyt, MiraiBrowse
  • 162.213.35.25
mipsel.elfGet hashmaliciousGafgyt, MiraiBrowse
  • 162.213.35.24
MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
COGENT-174USVkTNb6p288.exeGet hashmaliciousFormBookBrowse
  • 154.7.176.67
NF_Payment_Ref_FAN930276.exeGet hashmaliciousFormBookBrowse
  • 38.88.82.56
71Ah2iqq3g.dllGet hashmaliciousAmadeyBrowse
  • 45.93.20.135
71Ah2iqq3g.dllGet hashmaliciousAmadeyBrowse
  • 45.93.20.135
1nnlXctdko.dllGet hashmaliciousAmadeyBrowse
  • 45.93.20.135
HT9324-25 1x40HC LDHFCLDEHAM29656 MRSU5087674.exeGet hashmaliciousFormBookBrowse
  • 154.23.181.7
18in SPA-198-2024.exeGet hashmaliciousFormBookBrowse
  • 38.88.82.56
WARUNKI UMOWY-pdf.bat.exeGet hashmaliciousFormBook, GuLoaderBrowse
  • 38.88.82.56
bszYGSIHuU.exeGet hashmaliciousUnknownBrowse
  • 38.180.123.95
819614 - Midways Freight Ltd.xlsmGet hashmaliciousUnknownBrowse
  • 143.244.56.49
No context
No context
No created / dropped files found
File type:ELF 64-bit LSB executable, ARM aarch64, version 1 (SYSV), statically linked, no section header
Entropy (8bit):7.999924606791913
TrID:
  • ELF Executable and Linkable format (generic) (4004/1) 100.00%
File name:zone.arm64.elf
File size:3'024'036 bytes
MD5:85555f7f531e7cf3508fa991310f7871
SHA1:07d96723e6abd478b2e85d9ddd181197153fdcc4
SHA256:2cb21f2e522ab5ec4b1699320157b0aadea3ead26cbe9c317e7900e7df7b81fc
SHA512:ba6202665e1799748e1106d8744cba02bd667b4fca1eaac426ab7e146662050baa7378baa84f74cf17848fb4b57f044d82abc69fb47c071a859f7781dde584bb
SSDEEP:49152:j/1FLWrlQP4FGrdXXiQ3S7Fn+sMqZ49mgwtD5m1mzQXc4tYRuKse//UE3jmdNXss:bXLWrM4k5XS55+x/mziptYRukfTmdN/f
TLSH:E3E53384A9B5156FE28E00F1B1F44AD078069CBD29B935E212393A29C1CEDDB27F61D7
File Content Preview:.ELF......................B.....@...................@.8..................................................%...............................................#.......#..............Q.td......................................................O.UPX!...*........p5X

ELF header

Class:ELF64
Data:2's complement, little endian
Version:1 (current)
Machine:AArch64
Version Number:0x1
Type:EXEC (Executable file)
OS/ABI:UNIX - System V
ABI Version:0
Entry Point Address:0x1420fd4
Flags:0x0
ELF Header Size:64
Program Header Offset:64
Program Header Size:56
Number of Program Headers:3
Section Header Offset:0
Section Header Size:0
Number of Section Headers:0
Header String Table Index:0
TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
LOAD0x00x100000x100000x10000x11225007.80860x6RW 0x10000
LOAD0x00x11400000x11400000x2e239a0x2e239a7.99990x5R E0x10000
GNU_STACK0x00x00x00x00x00.00000x6RW 0x8
TimestampSource PortDest PortSource IPDest IP
Nov 1, 2024 08:43:01.428533077 CET5283080192.168.2.1338.60.221.177
Nov 1, 2024 08:43:01.433595896 CET805283038.60.221.177192.168.2.13
Nov 1, 2024 08:43:01.433734894 CET5283080192.168.2.1338.60.221.177
Nov 1, 2024 08:43:01.457101107 CET5283080192.168.2.1338.60.221.177
Nov 1, 2024 08:43:01.462286949 CET805283038.60.221.177192.168.2.13
Nov 1, 2024 08:43:02.326260090 CET805283038.60.221.177192.168.2.13
Nov 1, 2024 08:43:02.326356888 CET5283080192.168.2.1338.60.221.177
Nov 1, 2024 08:43:02.354688883 CET5283080192.168.2.1338.60.221.177
Nov 1, 2024 08:43:02.359549046 CET805283038.60.221.177192.168.2.13
Nov 1, 2024 08:43:02.377877951 CET5283080192.168.2.1338.60.221.177
Nov 1, 2024 08:43:02.382885933 CET805283038.60.221.177192.168.2.13
Nov 1, 2024 08:43:02.648370981 CET805283038.60.221.177192.168.2.13
Nov 1, 2024 08:43:02.648468018 CET5283080192.168.2.1338.60.221.177
Nov 1, 2024 08:43:12.394334078 CET5283080192.168.2.1338.60.221.177
Nov 1, 2024 08:43:12.396416903 CET5283080192.168.2.1338.60.221.177
Nov 1, 2024 08:43:12.398457050 CET5283080192.168.2.1338.60.221.177
Nov 1, 2024 08:43:12.399246931 CET805283038.60.221.177192.168.2.13
Nov 1, 2024 08:43:12.401191950 CET805283038.60.221.177192.168.2.13
Nov 1, 2024 08:43:12.403199911 CET805283038.60.221.177192.168.2.13
Nov 1, 2024 08:43:12.993077993 CET805283038.60.221.177192.168.2.13
Nov 1, 2024 08:43:12.993190050 CET805283038.60.221.177192.168.2.13
Nov 1, 2024 08:43:12.993341923 CET805283038.60.221.177192.168.2.13
Nov 1, 2024 08:43:12.993347883 CET5283080192.168.2.1338.60.221.177
Nov 1, 2024 08:43:12.993349075 CET5283080192.168.2.1338.60.221.177
Nov 1, 2024 08:43:12.993453026 CET5283080192.168.2.1338.60.221.177
Nov 1, 2024 08:43:13.020824909 CET5283080192.168.2.1338.60.221.177
Nov 1, 2024 08:43:13.025650024 CET805283038.60.221.177192.168.2.13
Nov 1, 2024 08:43:28.118350029 CET5283080192.168.2.1338.60.221.177
Nov 1, 2024 08:43:28.123162985 CET805283038.60.221.177192.168.2.13
Nov 1, 2024 08:43:43.222465992 CET5283080192.168.2.1338.60.221.177
Nov 1, 2024 08:43:43.227391005 CET805283038.60.221.177192.168.2.13
Nov 1, 2024 08:43:58.326351881 CET5283080192.168.2.1338.60.221.177
Nov 1, 2024 08:43:58.331290960 CET805283038.60.221.177192.168.2.13
Nov 1, 2024 08:44:13.430383921 CET5283080192.168.2.1338.60.221.177
Nov 1, 2024 08:44:13.435303926 CET805283038.60.221.177192.168.2.13
Nov 1, 2024 08:44:28.534411907 CET5283080192.168.2.1338.60.221.177
Nov 1, 2024 08:44:28.539376974 CET805283038.60.221.177192.168.2.13
Nov 1, 2024 08:44:43.638390064 CET5283080192.168.2.1338.60.221.177
Nov 1, 2024 08:44:43.643385887 CET805283038.60.221.177192.168.2.13
Nov 1, 2024 08:44:58.742386103 CET5283080192.168.2.1338.60.221.177
Nov 1, 2024 08:44:58.747273922 CET805283038.60.221.177192.168.2.13
Nov 1, 2024 08:45:13.029228926 CET5283080192.168.2.1338.60.221.177
Nov 1, 2024 08:45:13.030805111 CET5283080192.168.2.1338.60.221.177
Nov 1, 2024 08:45:13.034178972 CET805283038.60.221.177192.168.2.13
Nov 1, 2024 08:45:13.035824060 CET805283038.60.221.177192.168.2.13
Nov 1, 2024 08:45:13.035864115 CET5283080192.168.2.1338.60.221.177
Nov 1, 2024 08:45:42.380745888 CET5283280192.168.2.1338.60.221.177
Nov 1, 2024 08:45:42.385691881 CET805283238.60.221.177192.168.2.13
Nov 1, 2024 08:45:42.385785103 CET5283280192.168.2.1338.60.221.177
Nov 1, 2024 08:45:42.387382984 CET5283280192.168.2.1338.60.221.177
Nov 1, 2024 08:45:42.392157078 CET805283238.60.221.177192.168.2.13
Nov 1, 2024 08:45:43.278137922 CET805283238.60.221.177192.168.2.13
Nov 1, 2024 08:45:43.278326988 CET5283280192.168.2.1338.60.221.177
Nov 1, 2024 08:45:43.288996935 CET5283280192.168.2.1338.60.221.177
Nov 1, 2024 08:45:43.293814898 CET805283238.60.221.177192.168.2.13
Nov 1, 2024 08:45:43.614928961 CET5283280192.168.2.1338.60.221.177
Nov 1, 2024 08:45:43.621012926 CET805283238.60.221.177192.168.2.13
Nov 1, 2024 08:45:43.621072054 CET5283280192.168.2.1338.60.221.177
TimestampSource PortDest PortSource IPDest IP
Nov 1, 2024 08:45:46.653598070 CET5641453192.168.2.138.8.8.8
Nov 1, 2024 08:45:46.653642893 CET5219253192.168.2.138.8.8.8
Nov 1, 2024 08:45:46.660173893 CET53521928.8.8.8192.168.2.13
Nov 1, 2024 08:45:46.660326958 CET53564148.8.8.8192.168.2.13
TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
Nov 1, 2024 08:45:46.653598070 CET192.168.2.138.8.8.80x718aStandard query (0)daisy.ubuntu.comA (IP address)IN (0x0001)false
Nov 1, 2024 08:45:46.653642893 CET192.168.2.138.8.8.80xdc51Standard query (0)daisy.ubuntu.com28IN (0x0001)false
TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
Nov 1, 2024 08:45:46.660326958 CET8.8.8.8192.168.2.130x718aNo error (0)daisy.ubuntu.com162.213.35.24A (IP address)IN (0x0001)false
Nov 1, 2024 08:45:46.660326958 CET8.8.8.8192.168.2.130x718aNo error (0)daisy.ubuntu.com162.213.35.25A (IP address)IN (0x0001)false
Session IDSource IPSource PortDestination IPDestination Port
0192.168.2.135283038.60.221.17780
TimestampBytes transferredDirectionData
Nov 1, 2024 08:43:01.457101107 CET255OUTData Raw: 16 03 01 00 ee 01 00 00 ea 03 03 86 8a 5f 49 63 53 67 72 45 c9 fb df ed 20 75 f3 05 bd 75 31 82 52 7d 68 ff 86 41 b4 2b bd 92 2d 20 15 ab c6 96 a3 7a f0 1d 3d 2f 52 14 55 41 5f 1b 25 e2 18 53 03 f4 a0 86 7b 72 c8 67 30 ba 01 9c 00 26 c0 2b c0 2f
Data Ascii: _IcSgrE uu1R}hA+- z=/RUA_%S{rg0&+/,0/5{+3&$ 8.)g5wPO,7b
Nov 1, 2024 08:43:02.326260090 CET1230INData Raw: 16 03 03 00 7a 02 00 00 76 03 03 56 e4 09 25 af e4 e8 5f c2 eb 4d 88 dd 6c f6 b0 96 e1 95 2a 86 47 e8 47 c3 b3 d2 8c a4 f7 7e a3 20 15 ab c6 96 a3 7a f0 1d 3d 2f 52 14 55 41 5f 1b 25 e2 18 53 03 f4 a0 86 7b 72 c8 67 30 ba 01 9c 13 01 00 00 2e 00
Data Ascii: zvV%_Ml*GG~ z=/RUA_%S{rg0.+3$ w81N]@z'RvQ&<]{OTB@]XisLH8RB1KnS>6.O`TW{Na\(@E[ux_;?tAh$'
Nov 1, 2024 08:43:02.354688883 CET76OUTData Raw: 14 03 03 00 01 01 17 03 03 00 35 81 68 dc 00 01 2e 85 28 0c ec 25 93 c6 8d 8a 98 1d bd 81 ac 5c e8 03 f8 3a 6b 35 4d fa a2 eb 82 ff fd b7 a7 9d 8e 17 c5 7c 27 eb 6a 36 2c c1 81 87 b5 33 17 e8
Data Ascii: 5h.(%\:k5M|'j6,3
Nov 1, 2024 08:43:02.377877951 CET215OUTData Raw: 17 03 03 00 c6 2c 77 79 aa 49 58 6d 40 8d 9e 18 2d 5d 5e 56 35 b4 5d b0 95 f0 46 ac 00 5f ae 9d c1 2c 6f f9 0d 4f 71 5d e1 03 0c c0 e3 f5 8e 88 83 d3 31 79 2d 9b af 29 75 aa b1 5e a5 b4 03 23 be de 61 c8 85 8d db ea 5f 23 2b 13 7f 32 78 40 15 0b
Data Ascii: ,wyIXm@-]^V5]F_,oOq]1y-)u^#a_#+2x@eG; wt[`$Hy07-b[+LdrTUXH}[Nz>kIT.v'0x,%0k#2g?@hN
Nov 1, 2024 08:43:02.648370981 CET237INData Raw: 17 03 03 00 dc 6d e3 0f 3f b1 1b 64 16 72 04 b4 ea 8f 10 10 03 6d ff 02 84 b7 c8 c8 f1 2c c5 f5 8c a4 16 02 ba f0 31 da 94 81 5d 91 c7 8c 2b 54 51 76 6b 15 b4 f2 73 16 5d 1c 1d 25 f6 b8 36 8f 6f ee 43 d7 2b c7 a6 6e 30 00 fe af 68 d3 b0 aa 79 b6
Data Ascii: m?drm,1]+TQvks]%6oC+n0hyfkR?i^#:"_|J/:K\oH^Q%G&a++u&`}YiubwlcrfB0@x+ND`x(caj#n-
Nov 1, 2024 08:43:12.394334078 CET196OUTData Raw: 17 03 03 00 b3 58 fd c0 24 f7 9c aa 0c 3f fb 5a 92 91 f7 98 5a a8 5a 83 9d f5 40 d6 c5 45 7c 77 30 9d a7 bd 99 5a 16 7e 38 37 05 57 ba de 02 f8 b5 65 2d 92 82 f6 db 3b 48 20 53 f2 9a 55 e3 95 7e b7 94 5c 08 e7 65 c2 04 52 64 27 e7 54 c5 c8 33 58
Data Ascii: X$?ZZZ@E|w0Z~87We-;H SU~\eRd'T3X*!h~L<N\hA+v$^$v2j-RxlHI^L+*$4t
Nov 1, 2024 08:43:12.396416903 CET388OUTData Raw: 17 03 03 01 73 ea cf 60 a3 63 fa aa 4d 6f dc 1e 38 f9 44 cc 44 0d 48 92 c7 e2 8b 63 cc c6 3d f9 43 e2 7a 66 74 f3 ed e2 c2 31 81 f0 8f 5c 5e 04 ae 19 49 2b 56 5f 9e 14 d6 d3 82 61 57 94 85 da 71 a9 0b 8f e3 32 01 f7 62 56 9a 7e 08 c2 4e de 1c c4
Data Ascii: s`cMo8DDHc=Czft1\^I+V_aWq2bV~N1)OzxoW}?C}7`K%'G,i#(=|a-%m7U>wIi$#5VrZLKA/2.XZdtf3P[QW
Nov 1, 2024 08:43:12.398457050 CET198OUTData Raw: 17 03 03 00 b5 8c 4d ba b2 66 3f 82 d3 e9 af 11 1e 32 02 1b 87 64 e0 cb 50 8e b8 84 6b 39 53 94 f6 a8 f7 e1 02 44 1d 37 e1 a7 b6 5a d0 6d 86 92 b3 72 6d d5 39 d8 56 e0 2f 0d 83 76 0a 0c e5 c4 f4 72 74 58 b4 06 ab b7 b8 da 39 92 fe 28 7c a6 0e 90
Data Ascii: Mf?2dPk9SD7Zmrm9V/vrtX9(|=,=xGj0=Q!%QiXpX%caa|@Ly2eLgVT+/|Vy\X<g=lGf
Nov 1, 2024 08:43:12.993077993 CET199INData Raw: 17 03 03 00 b6 dc c2 4f d4 a6 45 83 ba a9 61 c8 63 c0 04 4c b1 10 4e 09 ec 5d 16 ca bb 94 99 ed ba ab b6 0b 65 78 79 61 5b 9a 86 8f b1 b9 b6 fa a1 35 09 d2 9d 85 95 7c cb 9b 6f 3d e4 cb e2 1d 72 5a a2 1d 53 b9 61 9b b5 ae a2 e3 bf 75 f1 b5 33 0c
Data Ascii: OEacLN]exya[5|o=rZSau3G$%8>)&'S1>U(k:r1bLs6(s2Mj0)#)\z
Nov 1, 2024 08:43:12.993190050 CET317INData Raw: 17 03 03 01 2c 25 f8 74 40 eb 06 61 00 08 0a 54 bf df 73 75 4d 17 30 8e f3 b3 37 67 86 ad 10 8d 43 86 49 02 44 4e 23 ef 5e d4 31 b7 7f 16 66 9a 80 ef 40 fb b9 22 1a e7 42 0a 90 8c 8e 54 6c 83 f9 e0 5c 23 39 c1 ce e8 7b 00 47 7e c7 6f 86 6a 71 51
Data Ascii: ,%t@aTsuM07gCIDN#^1f@"BTl\#9{G~ojqQ2[;E!}KWj25h<b&8Zq5@5LyXelC6t$Vc7jwf5g5b =B?-Nik7/fo?OBHb


Session IDSource IPSource PortDestination IPDestination Port
1192.168.2.135283238.60.221.17780
TimestampBytes transferredDirectionData
Nov 1, 2024 08:45:42.387382984 CET255OUTData Raw: 16 03 01 00 ee 01 00 00 ea 03 03 d2 93 b1 00 9c c7 0c b7 1b a7 bd c3 14 c0 ff 46 43 48 75 c2 e2 33 e4 b2 1f 3f cb 60 69 89 b9 2a 20 bf 6d 77 3d a6 00 51 33 66 8e db 31 a4 ef 9e e2 83 59 77 04 da 90 61 6c 63 59 d0 07 86 9b 6b 8a 00 26 c0 2b c0 2f
Data Ascii: FCHu3?`i* mw=Q3f1YwalcYk&+/,0/5{+3&$ GMU_e=/0G
Nov 1, 2024 08:45:43.278137922 CET1230INData Raw: 16 03 03 00 7a 02 00 00 76 03 03 45 52 ec 4d c1 7a 3d 16 5b 92 bd 97 c8 20 75 1c 61 02 b0 54 be bf 85 b0 79 32 16 a8 0d d4 a0 82 20 bf 6d 77 3d a6 00 51 33 66 8e db 31 a4 ef 9e e2 83 59 77 04 da 90 61 6c 63 59 d0 07 86 9b 6b 8a 13 01 00 00 2e 00
Data Ascii: zvERMz=[ uaTy2 mw=Q3f1YwalcYk.+3$ yw8$'7N=6>Y</WHi)y8xr8@4GS+N ]sAHyB=)o'&&|s@3U-lLyz
Nov 1, 2024 08:45:43.288996935 CET76OUTData Raw: 14 03 03 00 01 01 17 03 03 00 35 52 a0 d1 83 c9 a2 6f 3a 36 0a 7a 38 70 9c 0c 19 e9 25 95 6a b8 0c 2e 6d 7e 4b 87 f8 7e 80 92 07 4c eb 1c 9c 03 1e 8a df bf 5a 36 3d 3b ee 13 96 a7 3f c7 a4 2a
Data Ascii: 5Ro:6z8p%j.m~K~LZ6=;?*


System Behavior

Start time (UTC):07:42:59
Start date (UTC):01/11/2024
Path:/tmp/zone.arm64.elf
Arguments:/tmp/zone.arm64.elf
File size:5706200 bytes
MD5 hash:02e8e39e1b46472a60d128a6da84a2b8

Start time (UTC):07:42:59
Start date (UTC):01/11/2024
Path:/tmp/zone.arm64.elf
Arguments:-
File size:5706200 bytes
MD5 hash:02e8e39e1b46472a60d128a6da84a2b8

Start time (UTC):07:42:59
Start date (UTC):01/11/2024
Path:/tmp/zone.arm64.elf
Arguments:/tmp/zone.arm64.elf -b
File size:5706200 bytes
MD5 hash:02e8e39e1b46472a60d128a6da84a2b8

Start time (UTC):07:43:00
Start date (UTC):01/11/2024
Path:/tmp/zone.arm64.elf
Arguments:-
File size:5706200 bytes
MD5 hash:02e8e39e1b46472a60d128a6da84a2b8

Start time (UTC):07:43:00
Start date (UTC):01/11/2024
Path:/bin/bash
Arguments:/bin/bash -c uptime
File size:1183448 bytes
MD5 hash:7063c3930affe123baecd3b340f1ad2c

Start time (UTC):07:43:00
Start date (UTC):01/11/2024
Path:/usr/bin/uptime
Arguments:uptime
File size:14568 bytes
MD5 hash:3ad70d8e33316ac713bf25c2ddf2fb14

Start time (UTC):07:43:00
Start date (UTC):01/11/2024
Path:/tmp/zone.arm64.elf
Arguments:-
File size:5706200 bytes
MD5 hash:02e8e39e1b46472a60d128a6da84a2b8

Start time (UTC):07:43:00
Start date (UTC):01/11/2024
Path:/usr/bin/bash
Arguments:bash -c "cat /proc/net/dev |grep ens160 |awk '{print $2}'"
File size:1183448 bytes
MD5 hash:7063c3930affe123baecd3b340f1ad2c

Start time (UTC):07:43:01
Start date (UTC):01/11/2024
Path:/usr/bin/bash
Arguments:-
File size:1183448 bytes
MD5 hash:7063c3930affe123baecd3b340f1ad2c

Start time (UTC):07:43:01
Start date (UTC):01/11/2024
Path:/usr/bin/cat
Arguments:cat /proc/net/dev
File size:43416 bytes
MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

Start time (UTC):07:43:01
Start date (UTC):01/11/2024
Path:/usr/bin/bash
Arguments:-
File size:1183448 bytes
MD5 hash:7063c3930affe123baecd3b340f1ad2c

Start time (UTC):07:43:01
Start date (UTC):01/11/2024
Path:/usr/bin/grep
Arguments:grep ens160
File size:199136 bytes
MD5 hash:1e6ebb9dd094f774478f72727bdba0f5

Start time (UTC):07:43:01
Start date (UTC):01/11/2024
Path:/usr/bin/bash
Arguments:-
File size:1183448 bytes
MD5 hash:7063c3930affe123baecd3b340f1ad2c

Start time (UTC):07:43:01
Start date (UTC):01/11/2024
Path:/usr/bin/awk
Arguments:awk "{print $2}"
File size:711136 bytes
MD5 hash:7e9b2ed1272331cfbd2aac2e5eb3f84b

Start time (UTC):07:43:01
Start date (UTC):01/11/2024
Path:/tmp/zone.arm64.elf
Arguments:-
File size:5706200 bytes
MD5 hash:02e8e39e1b46472a60d128a6da84a2b8

Start time (UTC):07:43:01
Start date (UTC):01/11/2024
Path:/usr/bin/bash
Arguments:bash -c "cat /proc/net/dev |grep ens160 |awk '{print $10}'"
File size:1183448 bytes
MD5 hash:7063c3930affe123baecd3b340f1ad2c

Start time (UTC):07:43:01
Start date (UTC):01/11/2024
Path:/usr/bin/bash
Arguments:-
File size:1183448 bytes
MD5 hash:7063c3930affe123baecd3b340f1ad2c

Start time (UTC):07:43:01
Start date (UTC):01/11/2024
Path:/usr/bin/cat
Arguments:cat /proc/net/dev
File size:43416 bytes
MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

Start time (UTC):07:43:01
Start date (UTC):01/11/2024
Path:/usr/bin/bash
Arguments:-
File size:1183448 bytes
MD5 hash:7063c3930affe123baecd3b340f1ad2c

Start time (UTC):07:43:01
Start date (UTC):01/11/2024
Path:/usr/bin/grep
Arguments:grep ens160
File size:199136 bytes
MD5 hash:1e6ebb9dd094f774478f72727bdba0f5

Start time (UTC):07:43:01
Start date (UTC):01/11/2024
Path:/usr/bin/bash
Arguments:-
File size:1183448 bytes
MD5 hash:7063c3930affe123baecd3b340f1ad2c

Start time (UTC):07:43:01
Start date (UTC):01/11/2024
Path:/usr/bin/awk
Arguments:awk "{print $10}"
File size:711136 bytes
MD5 hash:7e9b2ed1272331cfbd2aac2e5eb3f84b

Start time (UTC):07:44:01
Start date (UTC):01/11/2024
Path:/tmp/zone.arm64.elf
Arguments:-
File size:5706200 bytes
MD5 hash:02e8e39e1b46472a60d128a6da84a2b8

Start time (UTC):07:44:01
Start date (UTC):01/11/2024
Path:/usr/bin/bash
Arguments:bash -c "cat /proc/net/dev |grep ens160 |awk '{print $2}'"
File size:1183448 bytes
MD5 hash:7063c3930affe123baecd3b340f1ad2c

Start time (UTC):07:44:01
Start date (UTC):01/11/2024
Path:/usr/bin/bash
Arguments:-
File size:1183448 bytes
MD5 hash:7063c3930affe123baecd3b340f1ad2c

Start time (UTC):07:44:01
Start date (UTC):01/11/2024
Path:/usr/bin/cat
Arguments:cat /proc/net/dev
File size:43416 bytes
MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

Start time (UTC):07:44:01
Start date (UTC):01/11/2024
Path:/usr/bin/bash
Arguments:-
File size:1183448 bytes
MD5 hash:7063c3930affe123baecd3b340f1ad2c

Start time (UTC):07:44:01
Start date (UTC):01/11/2024
Path:/usr/bin/grep
Arguments:grep ens160
File size:199136 bytes
MD5 hash:1e6ebb9dd094f774478f72727bdba0f5

Start time (UTC):07:44:01
Start date (UTC):01/11/2024
Path:/usr/bin/bash
Arguments:-
File size:1183448 bytes
MD5 hash:7063c3930affe123baecd3b340f1ad2c

Start time (UTC):07:44:01
Start date (UTC):01/11/2024
Path:/usr/bin/awk
Arguments:awk "{print $2}"
File size:711136 bytes
MD5 hash:7e9b2ed1272331cfbd2aac2e5eb3f84b

Start time (UTC):07:44:01
Start date (UTC):01/11/2024
Path:/tmp/zone.arm64.elf
Arguments:-
File size:5706200 bytes
MD5 hash:02e8e39e1b46472a60d128a6da84a2b8

Start time (UTC):07:44:01
Start date (UTC):01/11/2024
Path:/usr/bin/bash
Arguments:bash -c "cat /proc/net/dev |grep ens160 |awk '{print $10}'"
File size:1183448 bytes
MD5 hash:7063c3930affe123baecd3b340f1ad2c

Start time (UTC):07:44:01
Start date (UTC):01/11/2024
Path:/usr/bin/bash
Arguments:-
File size:1183448 bytes
MD5 hash:7063c3930affe123baecd3b340f1ad2c

Start time (UTC):07:44:01
Start date (UTC):01/11/2024
Path:/usr/bin/cat
Arguments:cat /proc/net/dev
File size:43416 bytes
MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

Start time (UTC):07:44:01
Start date (UTC):01/11/2024
Path:/usr/bin/bash
Arguments:-
File size:1183448 bytes
MD5 hash:7063c3930affe123baecd3b340f1ad2c

Start time (UTC):07:44:01
Start date (UTC):01/11/2024
Path:/usr/bin/grep
Arguments:grep ens160
File size:199136 bytes
MD5 hash:1e6ebb9dd094f774478f72727bdba0f5

Start time (UTC):07:44:01
Start date (UTC):01/11/2024
Path:/usr/bin/bash
Arguments:-
File size:1183448 bytes
MD5 hash:7063c3930affe123baecd3b340f1ad2c

Start time (UTC):07:44:01
Start date (UTC):01/11/2024
Path:/usr/bin/awk
Arguments:awk "{print $10}"
File size:711136 bytes
MD5 hash:7e9b2ed1272331cfbd2aac2e5eb3f84b

Start time (UTC):07:45:01
Start date (UTC):01/11/2024
Path:/tmp/zone.arm64.elf
Arguments:-
File size:5706200 bytes
MD5 hash:02e8e39e1b46472a60d128a6da84a2b8

Start time (UTC):07:45:01
Start date (UTC):01/11/2024
Path:/usr/bin/bash
Arguments:bash -c "cat /proc/net/dev |grep ens160 |awk '{print $2}'"
File size:1183448 bytes
MD5 hash:7063c3930affe123baecd3b340f1ad2c

Start time (UTC):07:45:01
Start date (UTC):01/11/2024
Path:/usr/bin/bash
Arguments:-
File size:1183448 bytes
MD5 hash:7063c3930affe123baecd3b340f1ad2c

Start time (UTC):07:45:01
Start date (UTC):01/11/2024
Path:/usr/bin/cat
Arguments:cat /proc/net/dev
File size:43416 bytes
MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

Start time (UTC):07:45:01
Start date (UTC):01/11/2024
Path:/usr/bin/bash
Arguments:-
File size:1183448 bytes
MD5 hash:7063c3930affe123baecd3b340f1ad2c

Start time (UTC):07:45:01
Start date (UTC):01/11/2024
Path:/usr/bin/grep
Arguments:grep ens160
File size:199136 bytes
MD5 hash:1e6ebb9dd094f774478f72727bdba0f5

Start time (UTC):07:45:01
Start date (UTC):01/11/2024
Path:/usr/bin/bash
Arguments:-
File size:1183448 bytes
MD5 hash:7063c3930affe123baecd3b340f1ad2c

Start time (UTC):07:45:01
Start date (UTC):01/11/2024
Path:/usr/bin/awk
Arguments:awk "{print $2}"
File size:711136 bytes
MD5 hash:7e9b2ed1272331cfbd2aac2e5eb3f84b

Start time (UTC):07:45:01
Start date (UTC):01/11/2024
Path:/tmp/zone.arm64.elf
Arguments:-
File size:5706200 bytes
MD5 hash:02e8e39e1b46472a60d128a6da84a2b8

Start time (UTC):07:45:01
Start date (UTC):01/11/2024
Path:/usr/bin/bash
Arguments:bash -c "cat /proc/net/dev |grep ens160 |awk '{print $10}'"
File size:1183448 bytes
MD5 hash:7063c3930affe123baecd3b340f1ad2c

Start time (UTC):07:45:01
Start date (UTC):01/11/2024
Path:/usr/bin/bash
Arguments:-
File size:1183448 bytes
MD5 hash:7063c3930affe123baecd3b340f1ad2c

Start time (UTC):07:45:01
Start date (UTC):01/11/2024
Path:/usr/bin/cat
Arguments:cat /proc/net/dev
File size:43416 bytes
MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

Start time (UTC):07:45:01
Start date (UTC):01/11/2024
Path:/usr/bin/bash
Arguments:-
File size:1183448 bytes
MD5 hash:7063c3930affe123baecd3b340f1ad2c

Start time (UTC):07:45:01
Start date (UTC):01/11/2024
Path:/usr/bin/grep
Arguments:grep ens160
File size:199136 bytes
MD5 hash:1e6ebb9dd094f774478f72727bdba0f5

Start time (UTC):07:45:01
Start date (UTC):01/11/2024
Path:/usr/bin/bash
Arguments:-
File size:1183448 bytes
MD5 hash:7063c3930affe123baecd3b340f1ad2c

Start time (UTC):07:45:01
Start date (UTC):01/11/2024
Path:/usr/bin/awk
Arguments:awk "{print $10}"
File size:711136 bytes
MD5 hash:7e9b2ed1272331cfbd2aac2e5eb3f84b