Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
zerarm5.elf

Overview

General Information

Sample name:zerarm5.elf
Analysis ID:1628589
MD5:01222e4888ff7f3dead98998bc3ce0e1
SHA1:3b7409f01cda1ac6a8dfae83480faef36759e3f7
SHA256:6da512e859193c326d2e750a5094d80be90874d1ed0d82d9d8c3bcba817a812d
Tags:elfuser-abuse_ch
Infos:

Detection

Score:52
Range:0 - 100

Signatures

Multi AV Scanner detection for submitted file
Sends malformed DNS queries
Detected TCP or UDP traffic on non-standard ports
Executes the "rm" command used to delete files or directories
Sample has stripped symbol table
Sample listens on a socket
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

Joe Sandbox version:42.0.0 Malachite
Analysis ID:1628589
Start date and time:2025-03-03 23:18:09 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 37s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:zerarm5.elf
Detection:MAL
Classification:mal52.troj.linELF@0/0@19/0
Command:/tmp/zerarm5.elf
PID:5460
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
gosh that chinese family at the other table sure ate a lot
Standard Error:
  • system is lnxubuntu20
  • zerarm5.elf (PID: 5460, Parent: 5385, MD5: 5ebfcae4fe2471fcc5695c2394773ff1) Arguments: /tmp/zerarm5.elf
  • dash New Fork (PID: 5506, Parent: 3633)
  • rm (PID: 5506, Parent: 3633, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.fuUtV0YwpV /tmp/tmp.Gy5HaNyi9y /tmp/tmp.NQgla8DWZM
  • dash New Fork (PID: 5507, Parent: 3633)
  • rm (PID: 5507, Parent: 3633, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.fuUtV0YwpV /tmp/tmp.Gy5HaNyi9y /tmp/tmp.NQgla8DWZM
  • cleanup
No yara matches
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: zerarm5.elfVirustotal: Detection: 43%Perma Link
Source: zerarm5.elfReversingLabs: Detection: 44%

Networking

barindex
Source: global trafficDNS traffic detected: malformed DNS query: serisbot.geek. [malformed]
Source: global trafficTCP traffic: 192.168.2.14:39058 -> 46.101.69.129:1440
Source: global trafficTCP traffic: 192.168.2.14:47102 -> 46.19.143.10:1440
Source: global trafficTCP traffic: 192.168.2.14:52412 -> 139.59.207.216:1440
Source: /tmp/zerarm5.elf (PID: 5460)Socket: 127.0.0.1:39148Jump to behavior
Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
Source: unknownUDP traffic detected without corresponding DNS query: 202.61.197.122
Source: unknownUDP traffic detected without corresponding DNS query: 194.36.144.87
Source: unknownUDP traffic detected without corresponding DNS query: 152.53.15.127
Source: unknownUDP traffic detected without corresponding DNS query: 194.36.144.87
Source: unknownUDP traffic detected without corresponding DNS query: 81.169.136.222
Source: unknownUDP traffic detected without corresponding DNS query: 194.36.144.87
Source: unknownUDP traffic detected without corresponding DNS query: 194.36.144.87
Source: unknownUDP traffic detected without corresponding DNS query: 168.235.111.72
Source: unknownUDP traffic detected without corresponding DNS query: 185.181.61.24
Source: unknownUDP traffic detected without corresponding DNS query: 185.181.61.24
Source: unknownUDP traffic detected without corresponding DNS query: 185.181.61.24
Source: unknownUDP traffic detected without corresponding DNS query: 185.181.61.24
Source: unknownUDP traffic detected without corresponding DNS query: 185.181.61.24
Source: unknownUDP traffic detected without corresponding DNS query: 81.169.136.222
Source: unknownUDP traffic detected without corresponding DNS query: 194.36.144.87
Source: unknownUDP traffic detected without corresponding DNS query: 194.36.144.87
Source: unknownUDP traffic detected without corresponding DNS query: 194.36.144.87
Source: unknownUDP traffic detected without corresponding DNS query: 194.36.144.87
Source: unknownUDP traffic detected without corresponding DNS query: 194.36.144.87
Source: global trafficDNS traffic detected: DNS query: serisbot.geek
Source: global trafficDNS traffic detected: DNS query: serisontop.dyn
Source: global trafficDNS traffic detected: DNS query: serisbot.geek. [malformed]
Source: unknownNetwork traffic detected: HTTP traffic on port 37902 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 37902
Source: ELF static info symbol of initial sample.symtab present: no
Source: classification engineClassification label: mal52.troj.linELF@0/0@19/0
Source: /usr/bin/dash (PID: 5506)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.fuUtV0YwpV /tmp/tmp.Gy5HaNyi9y /tmp/tmp.NQgla8DWZMJump to behavior
Source: /usr/bin/dash (PID: 5507)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.fuUtV0YwpV /tmp/tmp.Gy5HaNyi9y /tmp/tmp.NQgla8DWZMJump to behavior
Source: /tmp/zerarm5.elf (PID: 5460)Queries kernel information via 'uname': Jump to behavior
Source: zerarm5.elf, 5460.1.00005569b1e24000.00005569b1f52000.rw-.sdmpBinary or memory string: iU!/etc/qemu-binfmt/arm
Source: zerarm5.elf, 5460.1.00005569b1e24000.00005569b1f52000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/arm
Source: zerarm5.elf, 5460.1.00007ffcde0c2000.00007ffcde0e3000.rw-.sdmpBinary or memory string: /usr/bin/qemu-arm
Source: zerarm5.elf, 5460.1.00007ffcde0c2000.00007ffcde0e3000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-arm/tmp/zerarm5.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/zerarm5.elf
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
File Deletion
OS Credential Dumping11
Security Software Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Standard Port
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Non-Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture2
Application Layer Protocol
Traffic DuplicationData Destruction
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1628589 Sample: zerarm5.elf Startdate: 03/03/2025 Architecture: LINUX Score: 52 18 serisbot.geek. [malformed] 2->18 20 46.19.143.10, 1440, 47102, 47104 PLI-ASCH Switzerland 2->20 22 3 other IPs or domains 2->22 24 Multi AV Scanner detection for submitted file 2->24 8 zerarm5.elf 2->8         started        10 dash rm 2->10         started        12 dash rm 2->12         started        signatures3 26 Sends malformed DNS queries 18->26 process4 process5 14 zerarm5.elf 8->14         started        process6 16 zerarm5.elf 14->16         started       

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
zerarm5.elf44%VirustotalBrowse
zerarm5.elf45%ReversingLabsLinux.Backdoor.Mirai
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
serisontop.dyn
139.59.207.216
truefalse
    high
    serisbot.geek
    46.101.69.129
    truefalse
      high
      serisbot.geek. [malformed]
      unknown
      unknownfalse
        high
        • No. of IPs < 25%
        • 25% < No. of IPs < 50%
        • 50% < No. of IPs < 75%
        • 75% < No. of IPs
        IPDomainCountryFlagASNASN NameMalicious
        54.171.230.55
        unknownUnited States
        16509AMAZON-02USfalse
        46.19.143.10
        unknownSwitzerland
        51852PLI-ASCHfalse
        139.59.207.216
        serisontop.dynSingapore
        14061DIGITALOCEAN-ASNUSfalse
        46.101.69.129
        serisbot.geekNetherlands
        14061DIGITALOCEAN-ASNUSfalse
        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
        54.171.230.55na.elfGet hashmaliciousPrometeiBrowse
          yakov.arm5.elfGet hashmaliciousUnknownBrowse
            havoc.x86_64.elfGet hashmaliciousMirai, OkiruBrowse
              tftp.elfGet hashmaliciousUnknownBrowse
                na.elfGet hashmaliciousPrometeiBrowse
                  na.elfGet hashmaliciousPrometeiBrowse
                    na.elfGet hashmaliciousPrometeiBrowse
                      havoc.x86_64.elfGet hashmaliciousMirai, OkiruBrowse
                        na.elfGet hashmaliciousPrometeiBrowse
                          na.elfGet hashmaliciousPrometeiBrowse
                            46.19.143.10zerm68k.elfGet hashmaliciousUnknownBrowse
                              zermips.elfGet hashmaliciousUnknownBrowse
                                zerppc.elfGet hashmaliciousUnknownBrowse
                                  zerarm.elfGet hashmaliciousUnknownBrowse
                                    zermpsl.elfGet hashmaliciousUnknownBrowse
                                      139.59.207.216zerm68k.elfGet hashmaliciousUnknownBrowse
                                        zermips.elfGet hashmaliciousUnknownBrowse
                                          zerppc.elfGet hashmaliciousUnknownBrowse
                                            zerarm.elfGet hashmaliciousUnknownBrowse
                                              zermpsl.elfGet hashmaliciousUnknownBrowse
                                                46.101.69.129zerm68k.elfGet hashmaliciousUnknownBrowse
                                                  zermips.elfGet hashmaliciousUnknownBrowse
                                                    zerppc.elfGet hashmaliciousUnknownBrowse
                                                      zermpsl.elfGet hashmaliciousUnknownBrowse
                                                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                        serisbot.geeknabarm.elfGet hashmaliciousUnknownBrowse
                                                        • 139.59.207.216
                                                        serisontop.dynnklsh4.elfGet hashmaliciousUnknownBrowse
                                                        • 46.101.69.129
                                                        jklarm7.elfGet hashmaliciousUnknownBrowse
                                                        • 46.101.69.129
                                                        nabmips.elfGet hashmaliciousUnknownBrowse
                                                        • 46.19.143.10
                                                        zerm68k.elfGet hashmaliciousUnknownBrowse
                                                        • 46.101.69.129
                                                        splx86.elfGet hashmaliciousUnknownBrowse
                                                        • 46.19.143.10
                                                        nabarm5.elfGet hashmaliciousUnknownBrowse
                                                        • 46.19.143.10
                                                        arm.elfGet hashmaliciousUnknownBrowse
                                                        • 46.19.143.10
                                                        nklmips.elfGet hashmaliciousUnknownBrowse
                                                        • 46.19.143.10
                                                        splm68k.elfGet hashmaliciousUnknownBrowse
                                                        • 139.59.207.216
                                                        nklm68k.elfGet hashmaliciousUnknownBrowse
                                                        • 46.101.69.129
                                                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                        DIGITALOCEAN-ASNUSjklarm7.elfGet hashmaliciousUnknownBrowse
                                                        • 142.93.67.189
                                                        zerm68k.elfGet hashmaliciousUnknownBrowse
                                                        • 46.101.69.129
                                                        nabx86.elfGet hashmaliciousUnknownBrowse
                                                        • 134.209.44.103
                                                        zermips.elfGet hashmaliciousUnknownBrowse
                                                        • 46.101.69.129
                                                        zerppc.elfGet hashmaliciousUnknownBrowse
                                                        • 46.101.69.129
                                                        splspc.elfGet hashmaliciousUnknownBrowse
                                                        • 5.101.107.59
                                                        zerarm.elfGet hashmaliciousUnknownBrowse
                                                        • 139.59.207.216
                                                        zermpsl.elfGet hashmaliciousUnknownBrowse
                                                        • 46.101.69.129
                                                        mips.elfGet hashmaliciousUnknownBrowse
                                                        • 134.123.157.209
                                                        https://r.clickwise.net/pap?k=1608105173.576&b=&a=59c203522ac2d&u=https://cck.soundestlink.com/ce/c/67bef534ae22ecb432c3d1e3/67c5c41e194c9434286453ad/67c5c4385cb1777757b8e775?signature=3baa54ea59dc991acfde7bc84f6d0ec73c999e9aace33fb1b44378837c35311cGet hashmaliciousHTMLPhisherBrowse
                                                        • 206.189.245.37
                                                        DIGITALOCEAN-ASNUSjklarm7.elfGet hashmaliciousUnknownBrowse
                                                        • 142.93.67.189
                                                        zerm68k.elfGet hashmaliciousUnknownBrowse
                                                        • 46.101.69.129
                                                        nabx86.elfGet hashmaliciousUnknownBrowse
                                                        • 134.209.44.103
                                                        zermips.elfGet hashmaliciousUnknownBrowse
                                                        • 46.101.69.129
                                                        zerppc.elfGet hashmaliciousUnknownBrowse
                                                        • 46.101.69.129
                                                        splspc.elfGet hashmaliciousUnknownBrowse
                                                        • 5.101.107.59
                                                        zerarm.elfGet hashmaliciousUnknownBrowse
                                                        • 139.59.207.216
                                                        zermpsl.elfGet hashmaliciousUnknownBrowse
                                                        • 46.101.69.129
                                                        mips.elfGet hashmaliciousUnknownBrowse
                                                        • 134.123.157.209
                                                        https://r.clickwise.net/pap?k=1608105173.576&b=&a=59c203522ac2d&u=https://cck.soundestlink.com/ce/c/67bef534ae22ecb432c3d1e3/67c5c41e194c9434286453ad/67c5c4385cb1777757b8e775?signature=3baa54ea59dc991acfde7bc84f6d0ec73c999e9aace33fb1b44378837c35311cGet hashmaliciousHTMLPhisherBrowse
                                                        • 206.189.245.37
                                                        AMAZON-02USnklsh4.elfGet hashmaliciousUnknownBrowse
                                                        • 18.249.16.144
                                                        splx86.elfGet hashmaliciousUnknownBrowse
                                                        • 54.230.160.54
                                                        arm.elfGet hashmaliciousUnknownBrowse
                                                        • 65.3.44.61
                                                        arm6.elfGet hashmaliciousUnknownBrowse
                                                        • 54.217.10.153
                                                        splm68k.elfGet hashmaliciousUnknownBrowse
                                                        • 35.161.130.87
                                                        rRFQ24A.exeGet hashmaliciousFormBookBrowse
                                                        • 13.248.169.48
                                                        nabarm.elfGet hashmaliciousUnknownBrowse
                                                        • 34.218.254.181
                                                        nklm68k.elfGet hashmaliciousUnknownBrowse
                                                        • 54.192.176.97
                                                        morte.mpsl.elfGet hashmaliciousUnknownBrowse
                                                        • 108.131.187.45
                                                        nklx86.elfGet hashmaliciousUnknownBrowse
                                                        • 52.13.176.254
                                                        PLI-ASCHzerm68k.elfGet hashmaliciousUnknownBrowse
                                                        • 46.19.143.10
                                                        zermips.elfGet hashmaliciousUnknownBrowse
                                                        • 46.19.143.10
                                                        zerppc.elfGet hashmaliciousUnknownBrowse
                                                        • 46.19.143.10
                                                        zerarm.elfGet hashmaliciousUnknownBrowse
                                                        • 46.19.143.10
                                                        zermpsl.elfGet hashmaliciousUnknownBrowse
                                                        • 46.19.143.10
                                                        x.tgz.elfGet hashmaliciousUnknownBrowse
                                                        • 92.118.39.14
                                                        https://konserv-kassa.com/Get hashmaliciousUnknownBrowse
                                                        • 179.43.166.54
                                                        wow.exeGet hashmaliciousAmadey, GhostRat, GuLoader, LummaC Stealer, XWorm, XmrigBrowse
                                                        • 179.43.141.89
                                                        keksec.x86.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                        • 179.43.172.120
                                                        Clienter.dll.dllGet hashmaliciousUnknownBrowse
                                                        • 179.43.182.252
                                                        No context
                                                        No context
                                                        No created / dropped files found
                                                        File type:ELF 32-bit LSB executable, ARM, version 1 (ARM), statically linked, stripped
                                                        Entropy (8bit):5.99945164556782
                                                        TrID:
                                                        • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                                        File name:zerarm5.elf
                                                        File size:50'656 bytes
                                                        MD5:01222e4888ff7f3dead98998bc3ce0e1
                                                        SHA1:3b7409f01cda1ac6a8dfae83480faef36759e3f7
                                                        SHA256:6da512e859193c326d2e750a5094d80be90874d1ed0d82d9d8c3bcba817a812d
                                                        SHA512:df5cb3f793bcb296d350f4938b9f485bf642adfbd6a8acb584ddf87921a71b540399f6ecc1ed0a5af58f3b3c77c335429df4cccc82bb6355fdde59284c927317
                                                        SSDEEP:768:OCOH42owv60g/N9plkG8npl7Rdz5xoOGD8rPm/hDK14yiNq26RM14iN9:6H5oTplZSlfFCD8rm5eRm
                                                        TLSH:3E331895B8C19A13C1D463BAFA6E429C372163F8E2DF7217CD122F51378A81F0EA7651
                                                        File Content Preview:.ELF...a..........(.........4...(.......4. ...(..................... ... ...............$...$...$.......@...........Q.td..................................-...L."...:...........0@-.\P...0....S.0...P@...0... ....R......0...0...........0... ....R..... 0....S

                                                        ELF header

                                                        Class:ELF32
                                                        Data:2's complement, little endian
                                                        Version:1 (current)
                                                        Machine:ARM
                                                        Version Number:0x1
                                                        Type:EXEC (Executable file)
                                                        OS/ABI:ARM - ABI
                                                        ABI Version:0
                                                        Entry Point Address:0x8190
                                                        Flags:0x2
                                                        ELF Header Size:52
                                                        Program Header Offset:52
                                                        Program Header Size:32
                                                        Number of Program Headers:3
                                                        Section Header Offset:50216
                                                        Section Header Size:40
                                                        Number of Section Headers:11
                                                        Header String Table Index:10
                                                        NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                        NULL0x00x00x00x00x0000
                                                        .initPROGBITS0x80940x940x180x00x6AX004
                                                        .textPROGBITS0x80b00xb00xb9200x00x6AX0016
                                                        .finiPROGBITS0x139d00xb9d00x140x00x6AX004
                                                        .rodataPROGBITS0x139e40xb9e40x83c0x00x2A004
                                                        .ctorsPROGBITS0x1c2240xc2240x80x00x3WA004
                                                        .dtorsPROGBITS0x1c22c0xc22c0x80x00x3WA004
                                                        .jcrPROGBITS0x1c2340xc2340x40x00x3WA004
                                                        .dataPROGBITS0x1c2380xc2380x1ac0x00x3WA004
                                                        .bssNOBITS0x1c3e40xc3e40x2800x00x3WA004
                                                        .shstrtabSTRTAB0x00xc3e40x430x00x0001
                                                        TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                        LOAD0x00x80000x80000xc2200xc2206.03050x5R E0x8000.init .text .fini .rodata
                                                        LOAD0xc2240x1c2240x1c2240x1c00x4402.29200x6RW 0x8000.ctors .dtors .jcr .data .bss
                                                        GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
                                                        TimestampSource PortDest PortSource IPDest IP
                                                        Mar 3, 2025 23:18:54.276906967 CET390581440192.168.2.1446.101.69.129
                                                        Mar 3, 2025 23:18:54.281971931 CET14403905846.101.69.129192.168.2.14
                                                        Mar 3, 2025 23:18:54.282027006 CET390581440192.168.2.1446.101.69.129
                                                        Mar 3, 2025 23:18:54.294945002 CET390581440192.168.2.1446.101.69.129
                                                        Mar 3, 2025 23:18:54.299920082 CET14403905846.101.69.129192.168.2.14
                                                        Mar 3, 2025 23:18:54.299968958 CET390581440192.168.2.1446.101.69.129
                                                        Mar 3, 2025 23:18:54.305067062 CET14403905846.101.69.129192.168.2.14
                                                        Mar 3, 2025 23:19:04.305125952 CET390581440192.168.2.1446.101.69.129
                                                        Mar 3, 2025 23:19:04.310349941 CET14403905846.101.69.129192.168.2.14
                                                        Mar 3, 2025 23:19:04.496052980 CET14403905846.101.69.129192.168.2.14
                                                        Mar 3, 2025 23:19:04.496412039 CET390581440192.168.2.1446.101.69.129
                                                        Mar 3, 2025 23:19:04.501408100 CET14403905846.101.69.129192.168.2.14
                                                        Mar 3, 2025 23:19:05.523865938 CET390601440192.168.2.1446.101.69.129
                                                        Mar 3, 2025 23:19:05.528906107 CET14403906046.101.69.129192.168.2.14
                                                        Mar 3, 2025 23:19:05.528984070 CET390601440192.168.2.1446.101.69.129
                                                        Mar 3, 2025 23:19:05.529959917 CET390601440192.168.2.1446.101.69.129
                                                        Mar 3, 2025 23:19:05.534938097 CET14403906046.101.69.129192.168.2.14
                                                        Mar 3, 2025 23:19:05.534993887 CET390601440192.168.2.1446.101.69.129
                                                        Mar 3, 2025 23:19:05.540071011 CET14403906046.101.69.129192.168.2.14
                                                        Mar 3, 2025 23:19:16.140371084 CET14403906046.101.69.129192.168.2.14
                                                        Mar 3, 2025 23:19:16.141000032 CET390601440192.168.2.1446.101.69.129
                                                        Mar 3, 2025 23:19:16.146029949 CET14403906046.101.69.129192.168.2.14
                                                        Mar 3, 2025 23:19:17.168883085 CET471021440192.168.2.1446.19.143.10
                                                        Mar 3, 2025 23:19:17.173989058 CET14404710246.19.143.10192.168.2.14
                                                        Mar 3, 2025 23:19:17.174101114 CET471021440192.168.2.1446.19.143.10
                                                        Mar 3, 2025 23:19:17.175096989 CET471021440192.168.2.1446.19.143.10
                                                        Mar 3, 2025 23:19:17.180147886 CET14404710246.19.143.10192.168.2.14
                                                        Mar 3, 2025 23:19:17.180221081 CET471021440192.168.2.1446.19.143.10
                                                        Mar 3, 2025 23:19:17.185317039 CET14404710246.19.143.10192.168.2.14
                                                        Mar 3, 2025 23:19:23.464725971 CET37902443192.168.2.1454.171.230.55
                                                        Mar 3, 2025 23:19:23.470319986 CET4433790254.171.230.55192.168.2.14
                                                        Mar 3, 2025 23:19:23.470391035 CET37902443192.168.2.1454.171.230.55
                                                        Mar 3, 2025 23:19:27.794615984 CET14404710246.19.143.10192.168.2.14
                                                        Mar 3, 2025 23:19:27.794867992 CET471021440192.168.2.1446.19.143.10
                                                        Mar 3, 2025 23:19:27.799993992 CET14404710246.19.143.10192.168.2.14
                                                        Mar 3, 2025 23:19:28.821399927 CET471041440192.168.2.1446.19.143.10
                                                        Mar 3, 2025 23:19:28.826941967 CET14404710446.19.143.10192.168.2.14
                                                        Mar 3, 2025 23:19:28.827061892 CET471041440192.168.2.1446.19.143.10
                                                        Mar 3, 2025 23:19:28.828023911 CET471041440192.168.2.1446.19.143.10
                                                        Mar 3, 2025 23:19:28.833456993 CET14404710446.19.143.10192.168.2.14
                                                        Mar 3, 2025 23:19:28.833529949 CET471041440192.168.2.1446.19.143.10
                                                        Mar 3, 2025 23:19:28.838577986 CET14404710446.19.143.10192.168.2.14
                                                        Mar 3, 2025 23:19:39.411561012 CET14404710446.19.143.10192.168.2.14
                                                        Mar 3, 2025 23:19:39.412025928 CET471041440192.168.2.1446.19.143.10
                                                        Mar 3, 2025 23:19:39.417119026 CET14404710446.19.143.10192.168.2.14
                                                        Mar 3, 2025 23:19:40.449440956 CET390661440192.168.2.1446.101.69.129
                                                        Mar 3, 2025 23:19:40.454611063 CET14403906646.101.69.129192.168.2.14
                                                        Mar 3, 2025 23:19:40.454698086 CET390661440192.168.2.1446.101.69.129
                                                        Mar 3, 2025 23:19:40.456132889 CET390661440192.168.2.1446.101.69.129
                                                        Mar 3, 2025 23:19:40.461224079 CET14403906646.101.69.129192.168.2.14
                                                        Mar 3, 2025 23:19:40.461302042 CET390661440192.168.2.1446.101.69.129
                                                        Mar 3, 2025 23:19:40.466397047 CET14403906646.101.69.129192.168.2.14
                                                        Mar 3, 2025 23:19:51.043044090 CET14403906646.101.69.129192.168.2.14
                                                        Mar 3, 2025 23:19:51.043613911 CET390661440192.168.2.1446.101.69.129
                                                        Mar 3, 2025 23:19:51.048960924 CET14403906646.101.69.129192.168.2.14
                                                        Mar 3, 2025 23:19:52.074014902 CET524121440192.168.2.14139.59.207.216
                                                        Mar 3, 2025 23:19:52.080355883 CET144052412139.59.207.216192.168.2.14
                                                        Mar 3, 2025 23:19:52.080477953 CET524121440192.168.2.14139.59.207.216
                                                        Mar 3, 2025 23:19:52.081923962 CET524121440192.168.2.14139.59.207.216
                                                        Mar 3, 2025 23:19:52.088289022 CET144052412139.59.207.216192.168.2.14
                                                        Mar 3, 2025 23:19:52.088363886 CET524121440192.168.2.14139.59.207.216
                                                        Mar 3, 2025 23:19:52.094830990 CET144052412139.59.207.216192.168.2.14
                                                        Mar 3, 2025 23:20:02.728756905 CET144052412139.59.207.216192.168.2.14
                                                        Mar 3, 2025 23:20:02.729207993 CET524121440192.168.2.14139.59.207.216
                                                        Mar 3, 2025 23:20:02.734261990 CET144052412139.59.207.216192.168.2.14
                                                        Mar 3, 2025 23:20:03.751115084 CET524141440192.168.2.14139.59.207.216
                                                        Mar 3, 2025 23:20:03.756186008 CET144052414139.59.207.216192.168.2.14
                                                        Mar 3, 2025 23:20:03.756287098 CET524141440192.168.2.14139.59.207.216
                                                        Mar 3, 2025 23:20:03.757611036 CET524141440192.168.2.14139.59.207.216
                                                        Mar 3, 2025 23:20:03.762607098 CET144052414139.59.207.216192.168.2.14
                                                        Mar 3, 2025 23:20:03.762676954 CET524141440192.168.2.14139.59.207.216
                                                        Mar 3, 2025 23:20:03.767704964 CET144052414139.59.207.216192.168.2.14
                                                        Mar 3, 2025 23:20:13.767390013 CET524141440192.168.2.14139.59.207.216
                                                        Mar 3, 2025 23:20:13.772597075 CET144052414139.59.207.216192.168.2.14
                                                        Mar 3, 2025 23:20:13.973634958 CET144052414139.59.207.216192.168.2.14
                                                        Mar 3, 2025 23:20:13.973814011 CET524141440192.168.2.14139.59.207.216
                                                        Mar 3, 2025 23:20:13.978890896 CET144052414139.59.207.216192.168.2.14
                                                        Mar 3, 2025 23:20:15.066188097 CET471121440192.168.2.1446.19.143.10
                                                        Mar 3, 2025 23:20:15.071361065 CET14404711246.19.143.10192.168.2.14
                                                        Mar 3, 2025 23:20:15.071423054 CET471121440192.168.2.1446.19.143.10
                                                        Mar 3, 2025 23:20:15.072244883 CET471121440192.168.2.1446.19.143.10
                                                        Mar 3, 2025 23:20:15.077311039 CET14404711246.19.143.10192.168.2.14
                                                        Mar 3, 2025 23:20:15.077370882 CET471121440192.168.2.1446.19.143.10
                                                        Mar 3, 2025 23:20:15.082576036 CET14404711246.19.143.10192.168.2.14
                                                        Mar 3, 2025 23:20:25.652513981 CET14404711246.19.143.10192.168.2.14
                                                        Mar 3, 2025 23:20:25.653135061 CET471121440192.168.2.1446.19.143.10
                                                        Mar 3, 2025 23:20:25.660098076 CET14404711246.19.143.10192.168.2.14
                                                        Mar 3, 2025 23:20:26.856008053 CET471141440192.168.2.1446.19.143.10
                                                        Mar 3, 2025 23:20:26.861592054 CET14404711446.19.143.10192.168.2.14
                                                        Mar 3, 2025 23:20:26.861753941 CET471141440192.168.2.1446.19.143.10
                                                        Mar 3, 2025 23:20:26.863835096 CET471141440192.168.2.1446.19.143.10
                                                        Mar 3, 2025 23:20:26.869770050 CET14404711446.19.143.10192.168.2.14
                                                        Mar 3, 2025 23:20:26.869919062 CET471141440192.168.2.1446.19.143.10
                                                        Mar 3, 2025 23:20:26.876498938 CET14404711446.19.143.10192.168.2.14
                                                        Mar 3, 2025 23:20:37.418404102 CET14404711446.19.143.10192.168.2.14
                                                        Mar 3, 2025 23:20:37.418876886 CET471141440192.168.2.1446.19.143.10
                                                        Mar 3, 2025 23:20:37.424169064 CET14404711446.19.143.10192.168.2.14
                                                        Mar 3, 2025 23:20:38.458522081 CET471161440192.168.2.1446.19.143.10
                                                        Mar 3, 2025 23:20:38.464658976 CET14404711646.19.143.10192.168.2.14
                                                        Mar 3, 2025 23:20:38.464900017 CET471161440192.168.2.1446.19.143.10
                                                        Mar 3, 2025 23:20:38.467155933 CET471161440192.168.2.1446.19.143.10
                                                        Mar 3, 2025 23:20:38.472146988 CET14404711646.19.143.10192.168.2.14
                                                        Mar 3, 2025 23:20:38.472408056 CET471161440192.168.2.1446.19.143.10
                                                        Mar 3, 2025 23:20:38.477493048 CET14404711646.19.143.10192.168.2.14
                                                        Mar 3, 2025 23:20:49.033947945 CET14404711646.19.143.10192.168.2.14
                                                        Mar 3, 2025 23:20:49.034349918 CET471161440192.168.2.1446.19.143.10
                                                        Mar 3, 2025 23:20:49.041656017 CET14404711646.19.143.10192.168.2.14
                                                        Mar 3, 2025 23:20:50.142807007 CET471181440192.168.2.1446.19.143.10
                                                        Mar 3, 2025 23:20:50.147974968 CET14404711846.19.143.10192.168.2.14
                                                        Mar 3, 2025 23:20:50.148195028 CET471181440192.168.2.1446.19.143.10
                                                        Mar 3, 2025 23:20:50.149550915 CET471181440192.168.2.1446.19.143.10
                                                        Mar 3, 2025 23:20:50.154608965 CET14404711846.19.143.10192.168.2.14
                                                        Mar 3, 2025 23:20:50.154668093 CET471181440192.168.2.1446.19.143.10
                                                        Mar 3, 2025 23:20:50.159790993 CET14404711846.19.143.10192.168.2.14
                                                        TimestampSource PortDest PortSource IPDest IP
                                                        Mar 3, 2025 23:18:54.241439104 CET4821953192.168.2.14202.61.197.122
                                                        Mar 3, 2025 23:18:54.260158062 CET5348219202.61.197.122192.168.2.14
                                                        Mar 3, 2025 23:19:05.499933958 CET4251553192.168.2.14194.36.144.87
                                                        Mar 3, 2025 23:19:05.522893906 CET5342515194.36.144.87192.168.2.14
                                                        Mar 3, 2025 23:19:17.144025087 CET4080553192.168.2.14152.53.15.127
                                                        Mar 3, 2025 23:19:17.168173075 CET5340805152.53.15.127192.168.2.14
                                                        Mar 3, 2025 23:19:28.797338963 CET4285853192.168.2.14194.36.144.87
                                                        Mar 3, 2025 23:19:28.820441008 CET5342858194.36.144.87192.168.2.14
                                                        Mar 3, 2025 23:19:40.416363001 CET4096953192.168.2.1481.169.136.222
                                                        Mar 3, 2025 23:19:40.448143005 CET534096981.169.136.222192.168.2.14
                                                        Mar 3, 2025 23:19:52.048259020 CET3755453192.168.2.14194.36.144.87
                                                        Mar 3, 2025 23:19:52.072805882 CET5337554194.36.144.87192.168.2.14
                                                        Mar 3, 2025 23:20:03.732932091 CET3310853192.168.2.14194.36.144.87
                                                        Mar 3, 2025 23:20:03.750072956 CET5333108194.36.144.87192.168.2.14
                                                        Mar 3, 2025 23:20:14.977488041 CET6048853192.168.2.14168.235.111.72
                                                        Mar 3, 2025 23:20:15.065411091 CET5360488168.235.111.72192.168.2.14
                                                        Mar 3, 2025 23:20:26.657794952 CET4768453192.168.2.14185.181.61.24
                                                        Mar 3, 2025 23:20:26.695194960 CET5347684185.181.61.24192.168.2.14
                                                        Mar 3, 2025 23:20:26.697205067 CET3723453192.168.2.14185.181.61.24
                                                        Mar 3, 2025 23:20:26.734970093 CET5337234185.181.61.24192.168.2.14
                                                        Mar 3, 2025 23:20:26.736967087 CET5347453192.168.2.14185.181.61.24
                                                        Mar 3, 2025 23:20:26.774571896 CET5353474185.181.61.24192.168.2.14
                                                        Mar 3, 2025 23:20:26.776484013 CET5788153192.168.2.14185.181.61.24
                                                        Mar 3, 2025 23:20:26.815037012 CET5357881185.181.61.24192.168.2.14
                                                        Mar 3, 2025 23:20:26.817179918 CET5943853192.168.2.14185.181.61.24
                                                        Mar 3, 2025 23:20:26.854784966 CET5359438185.181.61.24192.168.2.14
                                                        Mar 3, 2025 23:20:38.424520016 CET4401153192.168.2.1481.169.136.222
                                                        Mar 3, 2025 23:20:38.456310987 CET534401181.169.136.222192.168.2.14
                                                        Mar 3, 2025 23:20:50.038331985 CET3807453192.168.2.14194.36.144.87
                                                        Mar 3, 2025 23:20:50.055531979 CET5338074194.36.144.87192.168.2.14
                                                        Mar 3, 2025 23:20:50.057050943 CET4935853192.168.2.14194.36.144.87
                                                        Mar 3, 2025 23:20:50.074053049 CET5349358194.36.144.87192.168.2.14
                                                        Mar 3, 2025 23:20:50.075501919 CET5675353192.168.2.14194.36.144.87
                                                        Mar 3, 2025 23:20:50.098850012 CET5356753194.36.144.87192.168.2.14
                                                        Mar 3, 2025 23:20:50.100460052 CET3734653192.168.2.14194.36.144.87
                                                        Mar 3, 2025 23:20:50.117714882 CET5337346194.36.144.87192.168.2.14
                                                        Mar 3, 2025 23:20:50.119246006 CET4933653192.168.2.14194.36.144.87
                                                        Mar 3, 2025 23:20:50.142013073 CET5349336194.36.144.87192.168.2.14
                                                        TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                                        Mar 3, 2025 23:18:54.241439104 CET192.168.2.14202.61.197.1220x63d3Standard query (0)serisbot.geekA (IP address)IN (0x0001)false
                                                        Mar 3, 2025 23:19:05.499933958 CET192.168.2.14194.36.144.870x9955Standard query (0)serisbot.geekA (IP address)IN (0x0001)false
                                                        Mar 3, 2025 23:19:17.144025087 CET192.168.2.14152.53.15.1270xf09fStandard query (0)serisbot.geekA (IP address)IN (0x0001)false
                                                        Mar 3, 2025 23:19:28.797338963 CET192.168.2.14194.36.144.870xce7cStandard query (0)serisbot.geekA (IP address)IN (0x0001)false
                                                        Mar 3, 2025 23:19:40.416363001 CET192.168.2.1481.169.136.2220x3eecStandard query (0)serisbot.geekA (IP address)IN (0x0001)false
                                                        Mar 3, 2025 23:19:52.048259020 CET192.168.2.14194.36.144.870xfed1Standard query (0)serisbot.geekA (IP address)IN (0x0001)false
                                                        Mar 3, 2025 23:20:03.732932091 CET192.168.2.14194.36.144.870x3ee5Standard query (0)serisbot.geekA (IP address)IN (0x0001)false
                                                        Mar 3, 2025 23:20:14.977488041 CET192.168.2.14168.235.111.720x26b8Standard query (0)serisontop.dynA (IP address)IN (0x0001)false
                                                        Mar 3, 2025 23:20:26.657794952 CET192.168.2.14185.181.61.240x8c28Standard query (0)serisbot.geek. [malformed]256298false
                                                        Mar 3, 2025 23:20:26.697205067 CET192.168.2.14185.181.61.240x8c28Standard query (0)serisbot.geek. [malformed]256298false
                                                        Mar 3, 2025 23:20:26.736967087 CET192.168.2.14185.181.61.240x8c28Standard query (0)serisbot.geek. [malformed]256298false
                                                        Mar 3, 2025 23:20:26.776484013 CET192.168.2.14185.181.61.240x8c28Standard query (0)serisbot.geek. [malformed]256298false
                                                        Mar 3, 2025 23:20:26.817179918 CET192.168.2.14185.181.61.240x8c28Standard query (0)serisbot.geek. [malformed]256298false
                                                        Mar 3, 2025 23:20:38.424520016 CET192.168.2.1481.169.136.2220xf243Standard query (0)serisontop.dynA (IP address)IN (0x0001)false
                                                        Mar 3, 2025 23:20:50.038331985 CET192.168.2.14194.36.144.870x1de4Standard query (0)serisbot.geek. [malformed]256322false
                                                        Mar 3, 2025 23:20:50.057050943 CET192.168.2.14194.36.144.870x1de4Standard query (0)serisbot.geek. [malformed]256322false
                                                        Mar 3, 2025 23:20:50.075501919 CET192.168.2.14194.36.144.870x1de4Standard query (0)serisbot.geek. [malformed]256322false
                                                        Mar 3, 2025 23:20:50.100460052 CET192.168.2.14194.36.144.870x1de4Standard query (0)serisbot.geek. [malformed]256322false
                                                        Mar 3, 2025 23:20:50.119246006 CET192.168.2.14194.36.144.870x1de4Standard query (0)serisbot.geek. [malformed]256322false
                                                        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                                        Mar 3, 2025 23:18:54.260158062 CET202.61.197.122192.168.2.140x63d3No error (0)serisbot.geek46.101.69.129A (IP address)IN (0x0001)false
                                                        Mar 3, 2025 23:18:54.260158062 CET202.61.197.122192.168.2.140x63d3No error (0)serisbot.geek46.19.143.10A (IP address)IN (0x0001)false
                                                        Mar 3, 2025 23:18:54.260158062 CET202.61.197.122192.168.2.140x63d3No error (0)serisbot.geek139.59.207.216A (IP address)IN (0x0001)false
                                                        Mar 3, 2025 23:19:05.522893906 CET194.36.144.87192.168.2.140x9955No error (0)serisbot.geek46.101.69.129A (IP address)IN (0x0001)false
                                                        Mar 3, 2025 23:19:05.522893906 CET194.36.144.87192.168.2.140x9955No error (0)serisbot.geek139.59.207.216A (IP address)IN (0x0001)false
                                                        Mar 3, 2025 23:19:05.522893906 CET194.36.144.87192.168.2.140x9955No error (0)serisbot.geek46.19.143.10A (IP address)IN (0x0001)false
                                                        Mar 3, 2025 23:19:17.168173075 CET152.53.15.127192.168.2.140xf09fNo error (0)serisbot.geek139.59.207.216A (IP address)IN (0x0001)false
                                                        Mar 3, 2025 23:19:17.168173075 CET152.53.15.127192.168.2.140xf09fNo error (0)serisbot.geek46.19.143.10A (IP address)IN (0x0001)false
                                                        Mar 3, 2025 23:19:17.168173075 CET152.53.15.127192.168.2.140xf09fNo error (0)serisbot.geek46.101.69.129A (IP address)IN (0x0001)false
                                                        Mar 3, 2025 23:19:28.820441008 CET194.36.144.87192.168.2.140xce7cNo error (0)serisbot.geek139.59.207.216A (IP address)IN (0x0001)false
                                                        Mar 3, 2025 23:19:28.820441008 CET194.36.144.87192.168.2.140xce7cNo error (0)serisbot.geek46.19.143.10A (IP address)IN (0x0001)false
                                                        Mar 3, 2025 23:19:28.820441008 CET194.36.144.87192.168.2.140xce7cNo error (0)serisbot.geek46.101.69.129A (IP address)IN (0x0001)false
                                                        Mar 3, 2025 23:19:40.448143005 CET81.169.136.222192.168.2.140x3eecNo error (0)serisbot.geek46.101.69.129A (IP address)IN (0x0001)false
                                                        Mar 3, 2025 23:19:40.448143005 CET81.169.136.222192.168.2.140x3eecNo error (0)serisbot.geek46.19.143.10A (IP address)IN (0x0001)false
                                                        Mar 3, 2025 23:19:40.448143005 CET81.169.136.222192.168.2.140x3eecNo error (0)serisbot.geek139.59.207.216A (IP address)IN (0x0001)false
                                                        Mar 3, 2025 23:19:52.072805882 CET194.36.144.87192.168.2.140xfed1No error (0)serisbot.geek46.19.143.10A (IP address)IN (0x0001)false
                                                        Mar 3, 2025 23:19:52.072805882 CET194.36.144.87192.168.2.140xfed1No error (0)serisbot.geek46.101.69.129A (IP address)IN (0x0001)false
                                                        Mar 3, 2025 23:19:52.072805882 CET194.36.144.87192.168.2.140xfed1No error (0)serisbot.geek139.59.207.216A (IP address)IN (0x0001)false
                                                        Mar 3, 2025 23:20:03.750072956 CET194.36.144.87192.168.2.140x3ee5No error (0)serisbot.geek46.101.69.129A (IP address)IN (0x0001)false
                                                        Mar 3, 2025 23:20:03.750072956 CET194.36.144.87192.168.2.140x3ee5No error (0)serisbot.geek139.59.207.216A (IP address)IN (0x0001)false
                                                        Mar 3, 2025 23:20:03.750072956 CET194.36.144.87192.168.2.140x3ee5No error (0)serisbot.geek46.19.143.10A (IP address)IN (0x0001)false
                                                        Mar 3, 2025 23:20:15.065411091 CET168.235.111.72192.168.2.140x26b8No error (0)serisontop.dyn139.59.207.216A (IP address)IN (0x0001)false
                                                        Mar 3, 2025 23:20:15.065411091 CET168.235.111.72192.168.2.140x26b8No error (0)serisontop.dyn46.101.69.129A (IP address)IN (0x0001)false
                                                        Mar 3, 2025 23:20:15.065411091 CET168.235.111.72192.168.2.140x26b8No error (0)serisontop.dyn46.19.143.10A (IP address)IN (0x0001)false
                                                        Mar 3, 2025 23:20:38.456310987 CET81.169.136.222192.168.2.140xf243No error (0)serisontop.dyn139.59.207.216A (IP address)IN (0x0001)false
                                                        Mar 3, 2025 23:20:38.456310987 CET81.169.136.222192.168.2.140xf243No error (0)serisontop.dyn46.19.143.10A (IP address)IN (0x0001)false
                                                        Mar 3, 2025 23:20:38.456310987 CET81.169.136.222192.168.2.140xf243No error (0)serisontop.dyn46.101.69.129A (IP address)IN (0x0001)false
                                                        Mar 3, 2025 23:20:50.055531979 CET194.36.144.87192.168.2.140x1de4Format error (1)serisbot.geek. [malformed]nonenone256322false
                                                        Mar 3, 2025 23:20:50.074053049 CET194.36.144.87192.168.2.140x1de4Format error (1)serisbot.geek. [malformed]nonenone256322false
                                                        Mar 3, 2025 23:20:50.098850012 CET194.36.144.87192.168.2.140x1de4Format error (1)serisbot.geek. [malformed]nonenone256322false
                                                        Mar 3, 2025 23:20:50.117714882 CET194.36.144.87192.168.2.140x1de4Format error (1)serisbot.geek. [malformed]nonenone256322false
                                                        Mar 3, 2025 23:20:50.142013073 CET194.36.144.87192.168.2.140x1de4Format error (1)serisbot.geek. [malformed]nonenone256322false

                                                        System Behavior

                                                        Start time (UTC):22:18:53
                                                        Start date (UTC):03/03/2025
                                                        Path:/tmp/zerarm5.elf
                                                        Arguments:/tmp/zerarm5.elf
                                                        File size:4956856 bytes
                                                        MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                        Start time (UTC):22:18:53
                                                        Start date (UTC):03/03/2025
                                                        Path:/tmp/zerarm5.elf
                                                        Arguments:-
                                                        File size:4956856 bytes
                                                        MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                        Start time (UTC):22:18:53
                                                        Start date (UTC):03/03/2025
                                                        Path:/tmp/zerarm5.elf
                                                        Arguments:-
                                                        File size:4956856 bytes
                                                        MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                        Start time (UTC):22:19:23
                                                        Start date (UTC):03/03/2025
                                                        Path:/usr/bin/dash
                                                        Arguments:-
                                                        File size:129816 bytes
                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                        Start time (UTC):22:19:23
                                                        Start date (UTC):03/03/2025
                                                        Path:/usr/bin/rm
                                                        Arguments:rm -f /tmp/tmp.fuUtV0YwpV /tmp/tmp.Gy5HaNyi9y /tmp/tmp.NQgla8DWZM
                                                        File size:72056 bytes
                                                        MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                                        Start time (UTC):22:19:23
                                                        Start date (UTC):03/03/2025
                                                        Path:/usr/bin/dash
                                                        Arguments:-
                                                        File size:129816 bytes
                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                        Start time (UTC):22:19:23
                                                        Start date (UTC):03/03/2025
                                                        Path:/usr/bin/rm
                                                        Arguments:rm -f /tmp/tmp.fuUtV0YwpV /tmp/tmp.Gy5HaNyi9y /tmp/tmp.NQgla8DWZM
                                                        File size:72056 bytes
                                                        MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b