Loading ...

Play interactive tourEdit tour

Linux Analysis Report CTKpl4EfIw

Overview

General Information

Sample Name:CTKpl4EfIw
Analysis ID:491781
MD5:abee54d0880d98307d664c8a12d060d2
SHA1:b25744cdc5d79b96b601161da0a358c8325c381e
SHA256:a8e150eebb41bfbb84f75ba3c3bc0662219ca3271af960b9f37b5f532d601f71
Tags:32armelfmirai
Infos:

Detection

Score:60
Range:0 - 100
Whitelisted:false

Signatures

Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Opens /proc/net/* files useful for finding connected devices and routers
Sample has stripped symbol table
Uses the "uname" system call to query kernel version information (possible evasion)
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Detected TCP or UDP traffic on non-standard ports

Classification

Analysis Advice

Static ELF header machine description suggests that the sample might only run correctly on MIPS or ARM architectures
All HTTP servers contacted by the sample do not answer. Likely the sample is an old dropper which does no longer work
Static ELF header machine description suggests that the sample might not execute correctly on this machine

General Information

Joe Sandbox Version:33.0.0 White Diamond
Analysis ID:491781
Start date:27.09.2021
Start time:22:13:21
Joe Sandbox Product:CloudBasic
Overall analysis duration:0h 6m 17s
Hypervisor based Inspection enabled:false
Report type:full
Sample file name:CTKpl4EfIw
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Detection:MAL
Classification:mal60.spre.lin@0/0@0/0

Process Tree

  • system is lnxubuntu20
  • CTKpl4EfIw (PID: 5226, Parent: 5109, MD5: 5ebfcae4fe2471fcc5695c2394773ff1) Arguments: /tmp/CTKpl4EfIw
  • cleanup

Yara Overview

No yara matches

Jbx Signature Overview

Click to jump to signature section

Show All Signature Results

AV Detection:

barindex
Antivirus / Scanner detection for submitted sampleShow sources
Source: CTKpl4EfIwAvira: detected
Multi AV Scanner detection for submitted fileShow sources
Source: CTKpl4EfIwVirustotal: Detection: 38%Perma Link
Source: CTKpl4EfIwReversingLabs: Detection: 44%

Spreading:

barindex
Opens /proc/net/* files useful for finding connected devices and routersShow sources
Source: /tmp/CTKpl4EfIw (PID: 5226)Opens: /proc/net/routeJump to behavior
Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
Source: global trafficTCP traffic: 192.168.2.23:44652 -> 167.114.109.203:6525
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
Source: unknownTCP traffic detected without corresponding DNS query: 167.114.109.203
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 167.114.109.203
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 167.114.109.203
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 167.114.109.203
Source: unknownTCP traffic detected without corresponding DNS query: 167.114.109.203
Source: unknownTCP traffic detected without corresponding DNS query: 167.114.109.203
Source: unknownTCP traffic detected without corresponding DNS query: 167.114.109.203
Source: unknownTCP traffic detected without corresponding DNS query: 167.114.109.203
Source: unknownTCP traffic detected without corresponding DNS query: 167.114.109.203
Source: unknownTCP traffic detected without corresponding DNS query: 167.114.109.203
Source: unknownTCP traffic detected without corresponding DNS query: 167.114.109.203
Source: unknownTCP traffic detected without corresponding DNS query: 167.114.109.203
Source: ELF static info symbol of initial sample.symtab present: no
Source: classification engineClassification label: mal60.spre.lin@0/0@0/0
Source: /tmp/CTKpl4EfIw (PID: 5226)Queries kernel information via 'uname': Jump to behavior
Source: CTKpl4EfIw, 5226.1.0000000010752dbe.0000000046640ae6.rw-.sdmpBinary or memory string: Bx86_64/usr/bin/qemu-arm/tmp/CTKpl4EfIwSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/CTKpl4EfIw
Source: CTKpl4EfIw, 5226.1.0000000019f697fe.000000000893cb70.rw-.sdmpBinary or memory string: U!/etc/qemu-binfmt/arm
Source: CTKpl4EfIw, 5226.1.0000000019f697fe.000000000893cb70.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/arm
Source: CTKpl4EfIw, 5226.1.0000000010752dbe.0000000046640ae6.rw-.sdmpBinary or memory string: /usr/bin/qemu-arm

Mitre Att&ck Matrix

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionDirect Volume AccessOS Credential DumpingSecurity Software Discovery11Remote ServicesData from Local SystemExfiltration Over Other Network MediumEncrypted Channel1Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryRemote System Discovery1Remote Desktop ProtocolData from Removable MediaExfiltration Over BluetoothNon-Standard Port1Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationApplication Layer Protocol1Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data

Malware Configuration

No configs have been found

Behavior Graph

Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 491781 Sample: CTKpl4EfIw Startdate: 27/09/2021 Architecture: LINUX Score: 60 17 167.114.109.203, 44652, 44654, 44656 OVHFR Canada 2->17 19 109.202.202.202, 80 INIT7CH Switzerland 2->19 21 2 other IPs or domains 2->21 23 Antivirus / Scanner detection for submitted sample 2->23 25 Multi AV Scanner detection for submitted file 2->25 8 CTKpl4EfIw 2->8         started        signatures3 process4 signatures5 27 Opens /proc/net/* files useful for finding connected devices and routers 8->27 11 CTKpl4EfIw 8->11         started        13 CTKpl4EfIw 8->13         started        process6 process7 15 CTKpl4EfIw 11->15         started       

Antivirus, Machine Learning and Genetic Malware Detection

Initial Sample

SourceDetectionScannerLabelLink
CTKpl4EfIw38%VirustotalBrowse
CTKpl4EfIw44%ReversingLabsLinux.Trojan.Gafgyt
CTKpl4EfIw100%AviraLINUX/Gafgyt.opnd

Dropped Files

No Antivirus matches

Domains

No Antivirus matches

URLs

No Antivirus matches

Domains and IPs

Contacted Domains

No contacted domains info

Contacted IPs

  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs

Public

IPDomainCountryFlagASNASN NameMalicious
167.114.109.203
unknownCanada
16276OVHFRfalse
109.202.202.202
unknownSwitzerland
13030INIT7CHfalse
91.189.91.43
unknownUnited Kingdom
41231CANONICAL-ASGBfalse
91.189.91.42
unknownUnited Kingdom
41231CANONICAL-ASGBfalse


Runtime Messages

Command:/tmp/CTKpl4EfIw
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
gosh that chinese family at the other table sure ate alot
Standard Error:

Joe Sandbox View / Context

IPs

MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
167.114.109.203imqksAx51TGet hashmaliciousBrowse
    8eyaMuD9DYGet hashmaliciousBrowse
      tnMrX1z0d5Get hashmaliciousBrowse
        X86_64Get hashmaliciousBrowse
          109.202.202.202imqksAx51TGet hashmaliciousBrowse
            8eyaMuD9DYGet hashmaliciousBrowse
              tnMrX1z0d5Get hashmaliciousBrowse
                H3NaLv48NKGet hashmaliciousBrowse
                  i07CkTx8C4Get hashmaliciousBrowse
                    p22l26A3WuGet hashmaliciousBrowse
                      fVNp9NC9l9Get hashmaliciousBrowse
                        wlJuLkUpqEGet hashmaliciousBrowse
                          cAoLg1WlGiGet hashmaliciousBrowse
                            77sa4X7MY2Get hashmaliciousBrowse
                              X86_64Get hashmaliciousBrowse
                                rrVvnZMcFsGet hashmaliciousBrowse
                                  pAu4km62R9Get hashmaliciousBrowse
                                    kUFNxyzq7hGet hashmaliciousBrowse
                                      QMVi2eFA3OGet hashmaliciousBrowse
                                        ZkoBOcJ402Get hashmaliciousBrowse
                                          BPJoS4yXO5Get hashmaliciousBrowse
                                            ryXG31QpenGet hashmaliciousBrowse
                                              V6nVmla0r8Get hashmaliciousBrowse
                                                ETZr9gYnOGGet hashmaliciousBrowse
                                                  91.189.91.43imqksAx51TGet hashmaliciousBrowse
                                                    8eyaMuD9DYGet hashmaliciousBrowse
                                                      tnMrX1z0d5Get hashmaliciousBrowse
                                                        H3NaLv48NKGet hashmaliciousBrowse
                                                          i07CkTx8C4Get hashmaliciousBrowse
                                                            p22l26A3WuGet hashmaliciousBrowse
                                                              fVNp9NC9l9Get hashmaliciousBrowse
                                                                wlJuLkUpqEGet hashmaliciousBrowse
                                                                  cAoLg1WlGiGet hashmaliciousBrowse
                                                                    77sa4X7MY2Get hashmaliciousBrowse
                                                                      X86_64Get hashmaliciousBrowse
                                                                        rrVvnZMcFsGet hashmaliciousBrowse
                                                                          pAu4km62R9Get hashmaliciousBrowse
                                                                            kUFNxyzq7hGet hashmaliciousBrowse
                                                                              QMVi2eFA3OGet hashmaliciousBrowse
                                                                                ZkoBOcJ402Get hashmaliciousBrowse
                                                                                  BPJoS4yXO5Get hashmaliciousBrowse
                                                                                    ryXG31QpenGet hashmaliciousBrowse
                                                                                      V6nVmla0r8Get hashmaliciousBrowse
                                                                                        ETZr9gYnOGGet hashmaliciousBrowse

                                                                                          Domains

                                                                                          No context

                                                                                          ASN

                                                                                          MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                          OVHFRimqksAx51TGet hashmaliciousBrowse
                                                                                          • 167.114.109.203
                                                                                          8eyaMuD9DYGet hashmaliciousBrowse
                                                                                          • 167.114.109.203
                                                                                          tnMrX1z0d5Get hashmaliciousBrowse
                                                                                          • 167.114.109.203
                                                                                          X86_64Get hashmaliciousBrowse
                                                                                          • 167.114.109.203
                                                                                          2mdb3OG6FM.exeGet hashmaliciousBrowse
                                                                                          • 51.255.34.79
                                                                                          GRUPO MARI#U00d1O OBRAS Y SERVICIOS, SL Oferta 2709212890.exeGet hashmaliciousBrowse
                                                                                          • 37.59.226.120
                                                                                          ZFb3RmLJzoGet hashmaliciousBrowse
                                                                                          • 51.70.255.217
                                                                                          Sht1aYGDIXGet hashmaliciousBrowse
                                                                                          • 51.178.244.189
                                                                                          nDHL_Shipment_Notification_1231413385_Notification_1231413385_september2021.exeGet hashmaliciousBrowse
                                                                                          • 178.32.63.50
                                                                                          DHL_Shipment_Notification_1231413385_Notification_1231413385_september2021.exeGet hashmaliciousBrowse
                                                                                          • 178.32.63.50
                                                                                          Lrs8NGx6VM.exeGet hashmaliciousBrowse
                                                                                          • 164.132.171.176
                                                                                          Claim-838392655-09242021.xlsGet hashmaliciousBrowse
                                                                                          • 51.89.115.111
                                                                                          2PzMc3x4WP.exeGet hashmaliciousBrowse
                                                                                          • 87.98.153.120
                                                                                          e5jVcbuCo5.exeGet hashmaliciousBrowse
                                                                                          • 176.31.32.199
                                                                                          i7qUJCnMz0.exeGet hashmaliciousBrowse
                                                                                          • 176.31.32.199
                                                                                          zsChlwJrkj.exeGet hashmaliciousBrowse
                                                                                          • 176.31.32.199
                                                                                          claim.xlsGet hashmaliciousBrowse
                                                                                          • 51.89.115.111
                                                                                          9uHCz7MrjF.exeGet hashmaliciousBrowse
                                                                                          • 176.31.32.199
                                                                                          J1IYv644YS.exeGet hashmaliciousBrowse
                                                                                          • 51.254.69.209
                                                                                          b3astmode.arm7Get hashmaliciousBrowse
                                                                                          • 37.187.28.233
                                                                                          INIT7CHimqksAx51TGet hashmaliciousBrowse
                                                                                          • 109.202.202.202
                                                                                          8eyaMuD9DYGet hashmaliciousBrowse
                                                                                          • 109.202.202.202
                                                                                          tnMrX1z0d5Get hashmaliciousBrowse
                                                                                          • 109.202.202.202
                                                                                          H3NaLv48NKGet hashmaliciousBrowse
                                                                                          • 109.202.202.202
                                                                                          i07CkTx8C4Get hashmaliciousBrowse
                                                                                          • 109.202.202.202
                                                                                          p22l26A3WuGet hashmaliciousBrowse
                                                                                          • 109.202.202.202
                                                                                          fVNp9NC9l9Get hashmaliciousBrowse
                                                                                          • 109.202.202.202
                                                                                          wlJuLkUpqEGet hashmaliciousBrowse
                                                                                          • 109.202.202.202
                                                                                          cAoLg1WlGiGet hashmaliciousBrowse
                                                                                          • 109.202.202.202
                                                                                          77sa4X7MY2Get hashmaliciousBrowse
                                                                                          • 109.202.202.202
                                                                                          X86_64Get hashmaliciousBrowse
                                                                                          • 109.202.202.202
                                                                                          rrVvnZMcFsGet hashmaliciousBrowse
                                                                                          • 109.202.202.202
                                                                                          pAu4km62R9Get hashmaliciousBrowse
                                                                                          • 109.202.202.202
                                                                                          kUFNxyzq7hGet hashmaliciousBrowse
                                                                                          • 109.202.202.202
                                                                                          QMVi2eFA3OGet hashmaliciousBrowse
                                                                                          • 109.202.202.202
                                                                                          ZkoBOcJ402Get hashmaliciousBrowse
                                                                                          • 109.202.202.202
                                                                                          BPJoS4yXO5Get hashmaliciousBrowse
                                                                                          • 109.202.202.202
                                                                                          ryXG31QpenGet hashmaliciousBrowse
                                                                                          • 109.202.202.202
                                                                                          V6nVmla0r8Get hashmaliciousBrowse
                                                                                          • 109.202.202.202
                                                                                          ETZr9gYnOGGet hashmaliciousBrowse
                                                                                          • 109.202.202.202

                                                                                          JA3 Fingerprints

                                                                                          No context

                                                                                          Dropped Files

                                                                                          No context

                                                                                          Created / dropped Files

                                                                                          No created / dropped files found

                                                                                          Static File Info

                                                                                          General

                                                                                          File type:ELF 32-bit LSB executable, ARM, version 1 (ARM), statically linked, stripped
                                                                                          Entropy (8bit):6.019182865076585
                                                                                          TrID:
                                                                                          • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                                                                          File name:CTKpl4EfIw
                                                                                          File size:90612
                                                                                          MD5:abee54d0880d98307d664c8a12d060d2
                                                                                          SHA1:b25744cdc5d79b96b601161da0a358c8325c381e
                                                                                          SHA256:a8e150eebb41bfbb84f75ba3c3bc0662219ca3271af960b9f37b5f532d601f71
                                                                                          SHA512:37a029df1dbffebf79a9d490b2f619e59b38c365de6b6685dd80b5fa4be3285ff635ad153437d1ae1ccaed397f6f170ed1c1e938c5b9ce5e57dc180abf7b4484
                                                                                          SSDEEP:1536:dmjnaOU7w+N62KBfISGHFxBpqRP/1yoQt/NeOCOlCvV4bb:7OR+N62w5GHFERPcFNerKbb
                                                                                          File Content Preview:.ELF...a..........(.........4...._......4. ...(......................L...L...............P...P...P.......h..........Q.td..................................-...L."....H..........0@-.\P...0....S.0...P@...0... ....R......0...0...........0... ....R..... 0....S

                                                                                          Static ELF Info

                                                                                          ELF header

                                                                                          Class:ELF32
                                                                                          Data:2's complement, little endian
                                                                                          Version:1 (current)
                                                                                          Machine:ARM
                                                                                          Version Number:0x1
                                                                                          Type:EXEC (Executable file)
                                                                                          OS/ABI:ARM - ABI
                                                                                          ABI Version:0
                                                                                          Entry Point Address:0x8190
                                                                                          Flags:0x202
                                                                                          ELF Header Size:52
                                                                                          Program Header Offset:52
                                                                                          Program Header Size:32
                                                                                          Number of Program Headers:3
                                                                                          Section Header Offset:90092
                                                                                          Section Header Size:40
                                                                                          Number of Section Headers:13
                                                                                          Header String Table Index:12

                                                                                          Sections

                                                                                          NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                                                          NULL0x00x00x00x00x0000
                                                                                          .initPROGBITS0x80940x940x180x00x6AX004
                                                                                          .textPROGBITS0x80b00xb00x1235c0x00x6AX0016
                                                                                          .finiPROGBITS0x1a40c0x1240c0x140x00x6AX004
                                                                                          .rodataPROGBITS0x1a4200x124200x28680x00x2A004
                                                                                          .eh_framePROGBITS0x1cc880x14c880x40x00x2A004
                                                                                          .ctorsPROGBITS0x250000x150000x80x00x3WA004
                                                                                          .dtorsPROGBITS0x250080x150080x80x00x3WA004
                                                                                          .jcrPROGBITS0x250100x150100x40x00x3WA004
                                                                                          .dataPROGBITS0x250140x150140x3ac0x00x3WA004
                                                                                          .bssNOBITS0x253c00x153c00x64580x00x3WA004
                                                                                          .commentPROGBITS0x00x153c00xbd40x00x0001
                                                                                          .shstrtabSTRTAB0x00x15f940x560x00x0001

                                                                                          Program Segments

                                                                                          TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                                                          LOAD0x00x80000x80000x14c8c0x14c8c3.53460x5R E0x8000.init .text .fini .rodata .eh_frame
                                                                                          LOAD0x150000x250000x250000x3c00x68181.65270x6RW 0x8000.ctors .dtors .jcr .data .bss
                                                                                          GNU_STACK0x00x00x00x00x00.00000x7RWE0x4

                                                                                          Network Behavior

                                                                                          Network Port Distribution

                                                                                          TCP Packets

                                                                                          TimestampSource PortDest PortSource IPDest IP
                                                                                          Sep 27, 2021 22:14:05.299822092 CEST446526525192.168.2.23167.114.109.203
                                                                                          Sep 27, 2021 22:14:05.418617010 CEST652544652167.114.109.203192.168.2.23
                                                                                          Sep 27, 2021 22:14:05.763891935 CEST42836443192.168.2.2391.189.91.43
                                                                                          Sep 27, 2021 22:14:06.531950951 CEST4251680192.168.2.23109.202.202.202
                                                                                          Sep 27, 2021 22:14:20.866801977 CEST43928443192.168.2.2391.189.91.42
                                                                                          Sep 27, 2021 22:14:25.419044018 CEST446546525192.168.2.23167.114.109.203
                                                                                          Sep 27, 2021 22:14:25.549026966 CEST652544654167.114.109.203192.168.2.23
                                                                                          Sep 27, 2021 22:14:33.153830051 CEST42836443192.168.2.2391.189.91.43
                                                                                          Sep 27, 2021 22:14:37.249605894 CEST4251680192.168.2.23109.202.202.202
                                                                                          Sep 27, 2021 22:14:45.549021006 CEST446566525192.168.2.23167.114.109.203
                                                                                          Sep 27, 2021 22:14:45.678860903 CEST652544656167.114.109.203192.168.2.23
                                                                                          Sep 27, 2021 22:15:01.823754072 CEST43928443192.168.2.2391.189.91.42
                                                                                          Sep 27, 2021 22:15:05.678739071 CEST446586525192.168.2.23167.114.109.203
                                                                                          Sep 27, 2021 22:15:05.795362949 CEST652544658167.114.109.203192.168.2.23
                                                                                          Sep 27, 2021 22:15:25.795514107 CEST446606525192.168.2.23167.114.109.203
                                                                                          Sep 27, 2021 22:15:25.911576033 CEST652544660167.114.109.203192.168.2.23
                                                                                          Sep 27, 2021 22:15:45.911614895 CEST446626525192.168.2.23167.114.109.203
                                                                                          Sep 27, 2021 22:15:46.940206051 CEST446626525192.168.2.23167.114.109.203
                                                                                          Sep 27, 2021 22:15:47.060653925 CEST652544662167.114.109.203192.168.2.23
                                                                                          Sep 27, 2021 22:16:07.060726881 CEST446646525192.168.2.23167.114.109.203
                                                                                          Sep 27, 2021 22:16:07.175436020 CEST652544664167.114.109.203192.168.2.23
                                                                                          Sep 27, 2021 22:16:27.175282955 CEST446666525192.168.2.23167.114.109.203
                                                                                          Sep 27, 2021 22:16:27.294646978 CEST652544666167.114.109.203192.168.2.23
                                                                                          Sep 27, 2021 22:16:47.294645071 CEST446686525192.168.2.23167.114.109.203
                                                                                          Sep 27, 2021 22:16:47.410669088 CEST652544668167.114.109.203192.168.2.23
                                                                                          Sep 27, 2021 22:17:07.410588026 CEST446706525192.168.2.23167.114.109.203
                                                                                          Sep 27, 2021 22:17:07.529918909 CEST652544670167.114.109.203192.168.2.23
                                                                                          Sep 27, 2021 22:17:27.530201912 CEST446726525192.168.2.23167.114.109.203
                                                                                          Sep 27, 2021 22:17:27.647788048 CEST652544672167.114.109.203192.168.2.23

                                                                                          System Behavior

                                                                                          General

                                                                                          Start time:22:14:04
                                                                                          Start date:27/09/2021
                                                                                          Path:/tmp/CTKpl4EfIw
                                                                                          Arguments:/tmp/CTKpl4EfIw
                                                                                          File size:4956856 bytes
                                                                                          MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                                                          General

                                                                                          Start time:22:14:04
                                                                                          Start date:27/09/2021
                                                                                          Path:/tmp/CTKpl4EfIw
                                                                                          Arguments:n/a
                                                                                          File size:4956856 bytes
                                                                                          MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                                                          General

                                                                                          Start time:22:14:04
                                                                                          Start date:27/09/2021
                                                                                          Path:/tmp/CTKpl4EfIw
                                                                                          Arguments:n/a
                                                                                          File size:4956856 bytes
                                                                                          MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                                                          General

                                                                                          Start time:22:14:04
                                                                                          Start date:27/09/2021
                                                                                          Path:/tmp/CTKpl4EfIw
                                                                                          Arguments:n/a
                                                                                          File size:4956856 bytes
                                                                                          MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1