Loading ...

Play interactive tourEdit tour

Linux Analysis Report fVNp9NC9l9

Overview

General Information

Sample Name:fVNp9NC9l9
Analysis ID:491760
MD5:3ad11448f98fc08e6c1107c4327ab97f
SHA1:9c0d1819f9b9292119560e21b8d2ff4c2f66316d
SHA256:40b4a8e91427b81ee97fb43a56edce02dce93f88a6c55ad698c50693fb069f6b
Tags:32elfintel
Infos:

Detection

Mirai
Score:60
Range:0 - 100
Whitelisted:false

Signatures

Multi AV Scanner detection for submitted file
Yara detected Mirai
Opens /proc/net/* files useful for finding connected devices and routers
Sample contains only a LOAD segment without any section mappings
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Detected TCP or UDP traffic on non-standard ports

Classification

Analysis Advice

All HTTP servers contacted by the sample do not answer. Likely the sample is an old dropper which does no longer work

General Information

Joe Sandbox Version:33.0.0 White Diamond
Analysis ID:491760
Start date:27.09.2021
Start time:21:33:29
Joe Sandbox Product:CloudBasic
Overall analysis duration:0h 6m 19s
Hypervisor based Inspection enabled:false
Report type:full
Sample file name:fVNp9NC9l9
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Detection:MAL
Classification:mal60.spre.troj.lin@0/0@0/0

Process Tree

  • system is lnxubuntu20
  • fVNp9NC9l9 (PID: 5220, Parent: 5107, MD5: 3ad11448f98fc08e6c1107c4327ab97f) Arguments: /tmp/fVNp9NC9l9
  • cleanup

Yara Overview

Memory Dumps

SourceRuleDescriptionAuthorStrings
5221.1.000000001a887bdc.00000000531557b5.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
    5220.1.000000001a887bdc.00000000531557b5.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security

      Jbx Signature Overview

      Click to jump to signature section

      Show All Signature Results

      AV Detection:

      barindex
      Multi AV Scanner detection for submitted fileShow sources
      Source: fVNp9NC9l9Virustotal: Detection: 28%Perma Link
      Source: fVNp9NC9l9ReversingLabs: Detection: 46%

      Spreading:

      barindex
      Opens /proc/net/* files useful for finding connected devices and routersShow sources
      Source: /tmp/fVNp9NC9l9 (PID: 5220)Opens: /proc/net/routeJump to behavior
      Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
      Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
      Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
      Source: global trafficTCP traffic: 192.168.2.23:49078 -> 45.142.182.126:666
      Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
      Source: unknownTCP traffic detected without corresponding DNS query: 45.142.182.126
      Source: unknownTCP traffic detected without corresponding DNS query: 45.142.182.126
      Source: unknownTCP traffic detected without corresponding DNS query: 45.142.182.126
      Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
      Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
      Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
      Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
      Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
      Source: unknownTCP traffic detected without corresponding DNS query: 45.142.182.126
      Source: unknownTCP traffic detected without corresponding DNS query: 45.142.182.126
      Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
      Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
      Source: unknownTCP traffic detected without corresponding DNS query: 45.142.182.126
      Source: unknownTCP traffic detected without corresponding DNS query: 45.142.182.126
      Source: unknownTCP traffic detected without corresponding DNS query: 45.142.182.126
      Source: unknownTCP traffic detected without corresponding DNS query: 45.142.182.126
      Source: LOAD without section mappingsProgram segment: 0x8048000
      Source: classification engineClassification label: mal60.spre.troj.lin@0/0@0/0

      Stealing of Sensitive Information:

      barindex
      Yara detected MiraiShow sources
      Source: Yara matchFile source: 5221.1.000000001a887bdc.00000000531557b5.r-x.sdmp, type: MEMORY
      Source: Yara matchFile source: 5220.1.000000001a887bdc.00000000531557b5.r-x.sdmp, type: MEMORY

      Remote Access Functionality:

      barindex
      Yara detected MiraiShow sources
      Source: Yara matchFile source: 5221.1.000000001a887bdc.00000000531557b5.r-x.sdmp, type: MEMORY
      Source: Yara matchFile source: 5220.1.000000001a887bdc.00000000531557b5.r-x.sdmp, type: MEMORY

      Mitre Att&ck Matrix

      Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
      Valid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionDirect Volume AccessOS Credential DumpingRemote System Discovery1Remote ServicesData from Local SystemExfiltration Over Other Network MediumEncrypted Channel1Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
      Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over BluetoothNon-Standard Port1Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
      Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationApplication Layer Protocol1Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data

      Malware Configuration

      No configs have been found

      Behavior Graph

      Hide Legend

      Legend:

      • Process
      • Signature
      • Created File
      • DNS/IP Info
      • Is Dropped
      • Number of created Files
      • Is malicious
      • Internet
      behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 491760 Sample: fVNp9NC9l9 Startdate: 27/09/2021 Architecture: LINUX Score: 60 15 45.142.182.126, 49078, 666 XSSERVERNL Germany 2->15 17 109.202.202.202, 80 INIT7CH Switzerland 2->17 19 2 other IPs or domains 2->19 21 Multi AV Scanner detection for submitted file 2->21 23 Yara detected Mirai 2->23 8 fVNp9NC9l9 2->8         started        signatures3 process4 signatures5 25 Opens /proc/net/* files useful for finding connected devices and routers 8->25 11 fVNp9NC9l9 8->11         started        process6 process7 13 fVNp9NC9l9 11->13         started       

      Antivirus, Machine Learning and Genetic Malware Detection

      Initial Sample

      SourceDetectionScannerLabelLink
      fVNp9NC9l928%VirustotalBrowse
      fVNp9NC9l946%ReversingLabsLinux.Trojan.Gafgyt

      Dropped Files

      No Antivirus matches

      Domains

      No Antivirus matches

      URLs

      No Antivirus matches

      Domains and IPs

      Contacted Domains

      No contacted domains info

      Contacted IPs

      • No. of IPs < 25%
      • 25% < No. of IPs < 50%
      • 50% < No. of IPs < 75%
      • 75% < No. of IPs

      Public

      IPDomainCountryFlagASNASN NameMalicious
      45.142.182.126
      unknownGermany
      207959XSSERVERNLfalse
      109.202.202.202
      unknownSwitzerland
      13030INIT7CHfalse
      91.189.91.43
      unknownUnited Kingdom
      41231CANONICAL-ASGBfalse
      91.189.91.42
      unknownUnited Kingdom
      41231CANONICAL-ASGBfalse


      Runtime Messages

      Command:/tmp/fVNp9NC9l9
      Exit Code:0
      Exit Code Info:
      Killed:False
      Standard Output:

      Standard Error:

      Joe Sandbox View / Context

      IPs

      MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
      45.142.182.126cAoLg1WlGiGet hashmaliciousBrowse
        109.202.202.202wlJuLkUpqEGet hashmaliciousBrowse
          cAoLg1WlGiGet hashmaliciousBrowse
            77sa4X7MY2Get hashmaliciousBrowse
              X86_64Get hashmaliciousBrowse
                rrVvnZMcFsGet hashmaliciousBrowse
                  pAu4km62R9Get hashmaliciousBrowse
                    kUFNxyzq7hGet hashmaliciousBrowse
                      QMVi2eFA3OGet hashmaliciousBrowse
                        ZkoBOcJ402Get hashmaliciousBrowse
                          BPJoS4yXO5Get hashmaliciousBrowse
                            ryXG31QpenGet hashmaliciousBrowse
                              V6nVmla0r8Get hashmaliciousBrowse
                                ETZr9gYnOGGet hashmaliciousBrowse
                                  wEA8Sws7MeGet hashmaliciousBrowse
                                    AJ0ZSJ7K36Get hashmaliciousBrowse
                                      fhPeao3t5XGet hashmaliciousBrowse
                                        5ndmU5fZJWGet hashmaliciousBrowse
                                          PoLc6KlROBGet hashmaliciousBrowse
                                            1j9nlon8bLGet hashmaliciousBrowse
                                              oBsSmO47B1Get hashmaliciousBrowse
                                                91.189.91.43wlJuLkUpqEGet hashmaliciousBrowse
                                                  cAoLg1WlGiGet hashmaliciousBrowse
                                                    77sa4X7MY2Get hashmaliciousBrowse
                                                      X86_64Get hashmaliciousBrowse
                                                        rrVvnZMcFsGet hashmaliciousBrowse
                                                          pAu4km62R9Get hashmaliciousBrowse
                                                            kUFNxyzq7hGet hashmaliciousBrowse
                                                              QMVi2eFA3OGet hashmaliciousBrowse
                                                                ZkoBOcJ402Get hashmaliciousBrowse
                                                                  BPJoS4yXO5Get hashmaliciousBrowse
                                                                    ryXG31QpenGet hashmaliciousBrowse
                                                                      V6nVmla0r8Get hashmaliciousBrowse
                                                                        ETZr9gYnOGGet hashmaliciousBrowse
                                                                          wEA8Sws7MeGet hashmaliciousBrowse
                                                                            AJ0ZSJ7K36Get hashmaliciousBrowse
                                                                              fhPeao3t5XGet hashmaliciousBrowse
                                                                                5ndmU5fZJWGet hashmaliciousBrowse
                                                                                  PoLc6KlROBGet hashmaliciousBrowse
                                                                                    1j9nlon8bLGet hashmaliciousBrowse
                                                                                      oBsSmO47B1Get hashmaliciousBrowse
                                                                                        91.189.91.42wlJuLkUpqEGet hashmaliciousBrowse
                                                                                          cAoLg1WlGiGet hashmaliciousBrowse
                                                                                            77sa4X7MY2Get hashmaliciousBrowse
                                                                                              X86_64Get hashmaliciousBrowse
                                                                                                rrVvnZMcFsGet hashmaliciousBrowse
                                                                                                  pAu4km62R9Get hashmaliciousBrowse
                                                                                                    kUFNxyzq7hGet hashmaliciousBrowse
                                                                                                      QMVi2eFA3OGet hashmaliciousBrowse
                                                                                                        ZkoBOcJ402Get hashmaliciousBrowse
                                                                                                          BPJoS4yXO5Get hashmaliciousBrowse
                                                                                                            ryXG31QpenGet hashmaliciousBrowse
                                                                                                              V6nVmla0r8Get hashmaliciousBrowse
                                                                                                                ETZr9gYnOGGet hashmaliciousBrowse
                                                                                                                  wEA8Sws7MeGet hashmaliciousBrowse
                                                                                                                    AJ0ZSJ7K36Get hashmaliciousBrowse
                                                                                                                      fhPeao3t5XGet hashmaliciousBrowse
                                                                                                                        5ndmU5fZJWGet hashmaliciousBrowse
                                                                                                                          PoLc6KlROBGet hashmaliciousBrowse
                                                                                                                            1j9nlon8bLGet hashmaliciousBrowse
                                                                                                                              oBsSmO47B1Get hashmaliciousBrowse

                                                                                                                                Domains

                                                                                                                                No context

                                                                                                                                ASN

                                                                                                                                MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                                                                CANONICAL-ASGBwlJuLkUpqEGet hashmaliciousBrowse
                                                                                                                                • 91.189.91.42
                                                                                                                                cAoLg1WlGiGet hashmaliciousBrowse
                                                                                                                                • 91.189.91.42
                                                                                                                                77sa4X7MY2Get hashmaliciousBrowse
                                                                                                                                • 91.189.91.42
                                                                                                                                X86_64Get hashmaliciousBrowse
                                                                                                                                • 91.189.91.42
                                                                                                                                rrVvnZMcFsGet hashmaliciousBrowse
                                                                                                                                • 91.189.91.42
                                                                                                                                pAu4km62R9Get hashmaliciousBrowse
                                                                                                                                • 91.189.91.42
                                                                                                                                kUFNxyzq7hGet hashmaliciousBrowse
                                                                                                                                • 91.189.91.42
                                                                                                                                QMVi2eFA3OGet hashmaliciousBrowse
                                                                                                                                • 91.189.91.42
                                                                                                                                ZkoBOcJ402Get hashmaliciousBrowse
                                                                                                                                • 91.189.91.42
                                                                                                                                BPJoS4yXO5Get hashmaliciousBrowse
                                                                                                                                • 91.189.91.42
                                                                                                                                ryXG31QpenGet hashmaliciousBrowse
                                                                                                                                • 91.189.91.42
                                                                                                                                V6nVmla0r8Get hashmaliciousBrowse
                                                                                                                                • 91.189.91.42
                                                                                                                                ETZr9gYnOGGet hashmaliciousBrowse
                                                                                                                                • 91.189.91.42
                                                                                                                                wEA8Sws7MeGet hashmaliciousBrowse
                                                                                                                                • 91.189.91.42
                                                                                                                                AJ0ZSJ7K36Get hashmaliciousBrowse
                                                                                                                                • 91.189.91.42
                                                                                                                                fhPeao3t5XGet hashmaliciousBrowse
                                                                                                                                • 91.189.91.42
                                                                                                                                5ndmU5fZJWGet hashmaliciousBrowse
                                                                                                                                • 91.189.91.42
                                                                                                                                PoLc6KlROBGet hashmaliciousBrowse
                                                                                                                                • 91.189.91.42
                                                                                                                                1j9nlon8bLGet hashmaliciousBrowse
                                                                                                                                • 91.189.91.42
                                                                                                                                oBsSmO47B1Get hashmaliciousBrowse
                                                                                                                                • 91.189.91.42
                                                                                                                                INIT7CHwlJuLkUpqEGet hashmaliciousBrowse
                                                                                                                                • 109.202.202.202
                                                                                                                                cAoLg1WlGiGet hashmaliciousBrowse
                                                                                                                                • 109.202.202.202
                                                                                                                                77sa4X7MY2Get hashmaliciousBrowse
                                                                                                                                • 109.202.202.202
                                                                                                                                X86_64Get hashmaliciousBrowse
                                                                                                                                • 109.202.202.202
                                                                                                                                rrVvnZMcFsGet hashmaliciousBrowse
                                                                                                                                • 109.202.202.202
                                                                                                                                pAu4km62R9Get hashmaliciousBrowse
                                                                                                                                • 109.202.202.202
                                                                                                                                kUFNxyzq7hGet hashmaliciousBrowse
                                                                                                                                • 109.202.202.202
                                                                                                                                QMVi2eFA3OGet hashmaliciousBrowse
                                                                                                                                • 109.202.202.202
                                                                                                                                ZkoBOcJ402Get hashmaliciousBrowse
                                                                                                                                • 109.202.202.202
                                                                                                                                BPJoS4yXO5Get hashmaliciousBrowse
                                                                                                                                • 109.202.202.202
                                                                                                                                ryXG31QpenGet hashmaliciousBrowse
                                                                                                                                • 109.202.202.202
                                                                                                                                V6nVmla0r8Get hashmaliciousBrowse
                                                                                                                                • 109.202.202.202
                                                                                                                                ETZr9gYnOGGet hashmaliciousBrowse
                                                                                                                                • 109.202.202.202
                                                                                                                                wEA8Sws7MeGet hashmaliciousBrowse
                                                                                                                                • 109.202.202.202
                                                                                                                                AJ0ZSJ7K36Get hashmaliciousBrowse
                                                                                                                                • 109.202.202.202
                                                                                                                                fhPeao3t5XGet hashmaliciousBrowse
                                                                                                                                • 109.202.202.202
                                                                                                                                5ndmU5fZJWGet hashmaliciousBrowse
                                                                                                                                • 109.202.202.202
                                                                                                                                PoLc6KlROBGet hashmaliciousBrowse
                                                                                                                                • 109.202.202.202
                                                                                                                                1j9nlon8bLGet hashmaliciousBrowse
                                                                                                                                • 109.202.202.202
                                                                                                                                oBsSmO47B1Get hashmaliciousBrowse
                                                                                                                                • 109.202.202.202
                                                                                                                                XSSERVERNLcAoLg1WlGiGet hashmaliciousBrowse
                                                                                                                                • 45.142.182.126
                                                                                                                                FQp7hNtN.exeGet hashmaliciousBrowse
                                                                                                                                • 195.62.33.67
                                                                                                                                https://waverpyramid.com/?email=carlos.machado.pereira@novobanco.ptGet hashmaliciousBrowse
                                                                                                                                • 195.62.46.177
                                                                                                                                https://waverpyramid.com/?email=carlos.machado.pereira@novobanco.ptGet hashmaliciousBrowse
                                                                                                                                • 195.62.46.177
                                                                                                                                https://tepe365-my.sharepoint.com/:b:/g/personal/bobbiewalden_workingenvironments_co_uk/EXJ3AG5SfktLpjPFRCFQUYwBsF4BUG6lJPv1ZdKpkhUsXg?e=4%3aMCOEiT&at=9Get hashmaliciousBrowse
                                                                                                                                • 195.62.46.180

                                                                                                                                JA3 Fingerprints

                                                                                                                                No context

                                                                                                                                Dropped Files

                                                                                                                                No context

                                                                                                                                Created / dropped Files

                                                                                                                                No created / dropped files found

                                                                                                                                Static File Info

                                                                                                                                General

                                                                                                                                File type:ELF 32-bit LSB executable, Intel 80386, version 1 (GNU/Linux), statically linked, stripped
                                                                                                                                Entropy (8bit):7.9515207570063025
                                                                                                                                TrID:
                                                                                                                                • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
                                                                                                                                • ELF Executable and Linkable format (generic) (4004/1) 49.84%
                                                                                                                                File name:fVNp9NC9l9
                                                                                                                                File size:34108
                                                                                                                                MD5:3ad11448f98fc08e6c1107c4327ab97f
                                                                                                                                SHA1:9c0d1819f9b9292119560e21b8d2ff4c2f66316d
                                                                                                                                SHA256:40b4a8e91427b81ee97fb43a56edce02dce93f88a6c55ad698c50693fb069f6b
                                                                                                                                SHA512:ff879410a10cf41d7e6e36a53f03144bf86430e4da7f8601db78b370cb37e8a223aa2c415da1f526eaaf3ad412bcccadaff49ea8e399ba2cf5d91545c507e070
                                                                                                                                SSDEEP:768:eyIuM3Lc1tCjtmSPI6QfSxDBY1T0B1Ki9VVDkekKnnbcuyD7UryqK:Rm3Lc/Cjfya9BYV81Ki9HASnouy8mqK
                                                                                                                                File Content Preview:.ELF....................P...4...........4. ...(.....................D...D................................)..........Q.td.............................4.IYTS..........T...T......U..........?..k.I/.j....\.d*nlz.ed..8.H........{....Ax..m.....M..w.f1...F.$v.C.

                                                                                                                                Static ELF Info

                                                                                                                                ELF header

                                                                                                                                Class:ELF32
                                                                                                                                Data:2's complement, little endian
                                                                                                                                Version:1 (current)
                                                                                                                                Machine:Intel 80386
                                                                                                                                Version Number:0x1
                                                                                                                                Type:EXEC (Executable file)
                                                                                                                                OS/ABI:UNIX - Linux
                                                                                                                                ABI Version:0
                                                                                                                                Entry Point Address:0x804f250
                                                                                                                                Flags:0x0
                                                                                                                                ELF Header Size:52
                                                                                                                                Program Header Offset:52
                                                                                                                                Program Header Size:32
                                                                                                                                Number of Program Headers:3
                                                                                                                                Section Header Offset:0
                                                                                                                                Section Header Size:40
                                                                                                                                Number of Section Headers:0
                                                                                                                                Header String Table Index:0

                                                                                                                                Program Segments

                                                                                                                                TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                                                                                                LOAD0x00x80480000x80480000x84440x84444.08680x5R E0x1000
                                                                                                                                LOAD0x00x80510000x80510000x00x129e40.00000x6RW 0x1000
                                                                                                                                GNU_STACK0x00x00x00x00x00.00000x6RW 0x4

                                                                                                                                Network Behavior

                                                                                                                                Network Port Distribution

                                                                                                                                TCP Packets

                                                                                                                                TimestampSource PortDest PortSource IPDest IP
                                                                                                                                Sep 27, 2021 21:34:11.307121038 CEST49078666192.168.2.2345.142.182.126
                                                                                                                                Sep 27, 2021 21:34:11.336841106 CEST6664907845.142.182.126192.168.2.23
                                                                                                                                Sep 27, 2021 21:34:11.337037086 CEST49078666192.168.2.2345.142.182.126
                                                                                                                                Sep 27, 2021 21:34:11.337081909 CEST49078666192.168.2.2345.142.182.126
                                                                                                                                Sep 27, 2021 21:34:11.368654966 CEST6664907845.142.182.126192.168.2.23
                                                                                                                                Sep 27, 2021 21:34:12.886091948 CEST42836443192.168.2.2391.189.91.43
                                                                                                                                Sep 27, 2021 21:34:13.654074907 CEST4251680192.168.2.23109.202.202.202
                                                                                                                                Sep 27, 2021 21:34:28.244738102 CEST43928443192.168.2.2391.189.91.42
                                                                                                                                Sep 27, 2021 21:34:38.483761072 CEST42836443192.168.2.2391.189.91.43
                                                                                                                                Sep 27, 2021 21:34:44.627091885 CEST4251680192.168.2.23109.202.202.202
                                                                                                                                Sep 27, 2021 21:34:53.205741882 CEST6664907845.142.182.126192.168.2.23
                                                                                                                                Sep 27, 2021 21:34:53.205972910 CEST49078666192.168.2.2345.142.182.126
                                                                                                                                Sep 27, 2021 21:34:53.235960960 CEST6664907845.142.182.126192.168.2.23
                                                                                                                                Sep 27, 2021 21:34:53.236119986 CEST49078666192.168.2.2345.142.182.126
                                                                                                                                Sep 27, 2021 21:35:09.200719118 CEST43928443192.168.2.2391.189.91.42
                                                                                                                                Sep 27, 2021 21:35:29.678694010 CEST42836443192.168.2.2391.189.91.43
                                                                                                                                Sep 27, 2021 21:35:53.210470915 CEST6664907845.142.182.126192.168.2.23
                                                                                                                                Sep 27, 2021 21:35:53.210639000 CEST49078666192.168.2.2345.142.182.126
                                                                                                                                Sep 27, 2021 21:35:53.240113974 CEST6664907845.142.182.126192.168.2.23
                                                                                                                                Sep 27, 2021 21:35:53.240251064 CEST49078666192.168.2.2345.142.182.126
                                                                                                                                Sep 27, 2021 21:36:53.214468956 CEST6664907845.142.182.126192.168.2.23
                                                                                                                                Sep 27, 2021 21:36:53.214574099 CEST49078666192.168.2.2345.142.182.126
                                                                                                                                Sep 27, 2021 21:36:53.243738890 CEST6664907845.142.182.126192.168.2.23
                                                                                                                                Sep 27, 2021 21:36:53.243804932 CEST49078666192.168.2.2345.142.182.126

                                                                                                                                System Behavior

                                                                                                                                General

                                                                                                                                Start time:21:34:09
                                                                                                                                Start date:27/09/2021
                                                                                                                                Path:/tmp/fVNp9NC9l9
                                                                                                                                Arguments:/tmp/fVNp9NC9l9
                                                                                                                                File size:34108 bytes
                                                                                                                                MD5 hash:3ad11448f98fc08e6c1107c4327ab97f

                                                                                                                                General

                                                                                                                                Start time:21:34:10
                                                                                                                                Start date:27/09/2021
                                                                                                                                Path:/tmp/fVNp9NC9l9
                                                                                                                                Arguments:n/a
                                                                                                                                File size:34108 bytes
                                                                                                                                MD5 hash:3ad11448f98fc08e6c1107c4327ab97f

                                                                                                                                General

                                                                                                                                Start time:21:34:10
                                                                                                                                Start date:27/09/2021
                                                                                                                                Path:/tmp/fVNp9NC9l9
                                                                                                                                Arguments:n/a
                                                                                                                                File size:34108 bytes
                                                                                                                                MD5 hash:3ad11448f98fc08e6c1107c4327ab97f