Loading ...

Play interactive tourEdit tour

Linux Analysis Report beamer.x86-20211202-2350

Overview

General Information

Sample Name:beamer.x86-20211202-2350
Analysis ID:533079
MD5:04e178a6fe92b38222e03a4c2e2303e0
SHA1:ba0e9885d263093c13e955cb79cf6e86039d4177
SHA256:1000ab055531e011407b62ff66cc2b122334eb14dc01f56f9487023beeb38f59
Infos:

Detection

Score:52
Range:0 - 100
Whitelisted:false

Signatures

Multi AV Scanner detection for submitted file
Machine Learning detection for sample
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Detected TCP or UDP traffic on non-standard ports
Executes the "rm" command used to delete files or directories
Sample has stripped symbol table
Sample contains strings indicative of BusyBox which embeds multiple Unix commands in a single executable

Classification

Analysis Advice

All HTTP servers contacted by the sample do not answer. Likely the sample is an old dropper which does no longer work

General Information

Joe Sandbox Version:34.0.0 Boulder Opal
Analysis ID:533079
Start date:03.12.2021
Start time:01:01:18
Joe Sandbox Product:CloudBasic
Overall analysis duration:0h 5m 27s
Hypervisor based Inspection enabled:false
Report type:full
Sample file name:beamer.x86-20211202-2350
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Detection:MAL
Classification:mal52.linX86-20211202-2350@0/0@0/0

Process Tree

  • system is lnxubuntu20
  • dash New Fork (PID: 5253, Parent: 4331)
  • rm (PID: 5253, Parent: 4331, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.AlKkHgaC4m /tmp/tmp.GpcnZvv7fC /tmp/tmp.zmqkJtmHaS
  • cleanup

Yara Overview

No yara matches

Jbx Signature Overview

Click to jump to signature section

Show All Signature Results

AV Detection:

barindex
Multi AV Scanner detection for submitted fileShow sources
Source: beamer.x86-20211202-2350Virustotal: Detection: 23%Perma Link
Source: beamer.x86-20211202-2350ReversingLabs: Detection: 31%
Machine Learning detection for sampleShow sources
Source: beamer.x86-20211202-2350Joe Sandbox ML: detected
Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
Source: global trafficTCP traffic: 192.168.2.23:39246 -> 34.249.145.219:443
Source: global trafficTCP traffic: 192.168.2.23:52018 -> 45.134.225.20:544
Source: unknownNetwork traffic detected: HTTP traffic on port 39246 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
Source: unknownTCP traffic detected without corresponding DNS query: 45.134.225.20
Source: unknownTCP traffic detected without corresponding DNS query: 45.134.225.20
Source: unknownTCP traffic detected without corresponding DNS query: 45.134.225.20
Source: unknownTCP traffic detected without corresponding DNS query: 45.134.225.20
Source: unknownTCP traffic detected without corresponding DNS query: 45.134.225.20
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 45.134.225.20
Source: unknownTCP traffic detected without corresponding DNS query: 45.134.225.20
Source: unknownTCP traffic detected without corresponding DNS query: 45.134.225.20
Source: unknownTCP traffic detected without corresponding DNS query: 45.134.225.20
Source: unknownTCP traffic detected without corresponding DNS query: 45.134.225.20
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 34.249.145.219
Source: unknownTCP traffic detected without corresponding DNS query: 34.249.145.219
Source: unknownTCP traffic detected without corresponding DNS query: 34.249.145.219
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 34.249.145.219
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 45.134.225.20
Source: unknownTCP traffic detected without corresponding DNS query: 34.249.145.219
Source: unknownTCP traffic detected without corresponding DNS query: 45.134.225.20
Source: unknownTCP traffic detected without corresponding DNS query: 34.249.145.219
Source: unknownTCP traffic detected without corresponding DNS query: 45.134.225.20
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 45.134.225.20
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 45.134.225.20
Source: unknownTCP traffic detected without corresponding DNS query: 45.134.225.20
Source: unknownTCP traffic detected without corresponding DNS query: 45.134.225.20
Source: unknownTCP traffic detected without corresponding DNS query: 45.134.225.20
Source: unknownTCP traffic detected without corresponding DNS query: 45.134.225.20
Source: unknownTCP traffic detected without corresponding DNS query: 45.134.225.20
Source: unknownTCP traffic detected without corresponding DNS query: 45.134.225.20
Source: unknownTCP traffic detected without corresponding DNS query: 45.134.225.20
Source: unknownTCP traffic detected without corresponding DNS query: 45.134.225.20
Source: ELF static info symbol of initial sample.symtab present: no
Source: Initial sampleString containing 'busybox' found: busybox
Source: Initial sampleString containing 'busybox' found: /proc/%s/maps/tmp/root/mnt/var/run/home/init/usr/bin/usr/sbin/var/wlancont/var/tmp/stainfologinbusyboxdnsrelaybashtelnetdsshdropbearwebhikvisionlibcgi-binconfigdvrappsofia127.0.0.1unknown45.134.225.20lost connection
Source: classification engineClassification label: mal52.linX86-20211202-2350@0/0@0/0
Source: /usr/bin/dash (PID: 5253)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.AlKkHgaC4m /tmp/tmp.GpcnZvv7fC /tmp/tmp.zmqkJtmHaSJump to behavior

Mitre Att&ck Matrix

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionFile Deletion1OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network MediumEncrypted Channel1Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over BluetoothNon-Standard Port1Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationApplication Layer Protocol1Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data

Malware Configuration

No configs have been found

Behavior Graph

Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 533079 Sample: beamer.x86-20211202-2350 Startdate: 03/12/2021 Architecture: LINUX Score: 52 17 109.202.202.202, 80 INIT7CH Switzerland 2->17 19 45.134.225.20, 52018, 52020, 544 DAINTERNATIONALGROUPGB Germany 2->19 21 3 other IPs or domains 2->21 23 Multi AV Scanner detection for submitted file 2->23 25 Machine Learning detection for sample 2->25 7 beamer.x86-20211202-2350 2->7         started        9 dash rm 2->9         started        signatures3 process4 process5 11 beamer.x86-20211202-2350 7->11         started        13 beamer.x86-20211202-2350 7->13         started        15 beamer.x86-20211202-2350 7->15         started       

Antivirus, Machine Learning and Genetic Malware Detection

Initial Sample

SourceDetectionScannerLabelLink
beamer.x86-20211202-235024%VirustotalBrowse
beamer.x86-20211202-235031%ReversingLabsLinux.Trojan.Mirai
beamer.x86-20211202-2350100%Joe Sandbox ML

Dropped Files

No Antivirus matches

Domains

No Antivirus matches

URLs

No Antivirus matches

Domains and IPs

Contacted Domains

No contacted domains info

Contacted IPs

  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs

Public

IPDomainCountryFlagASNASN NameMalicious
45.134.225.20
unknownGermany
203380DAINTERNATIONALGROUPGBfalse
34.249.145.219
unknownUnited States
16509AMAZON-02USfalse
109.202.202.202
unknownSwitzerland
13030INIT7CHfalse
91.189.91.43
unknownUnited Kingdom
41231CANONICAL-ASGBfalse
91.189.91.42
unknownUnited Kingdom
41231CANONICAL-ASGBfalse


Runtime Messages

Command:/tmp/beamer.x86-20211202-2350
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:

Standard Error:

Joe Sandbox View / Context

IPs

MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
45.134.225.20beamer.arm7-20211202-2350Get hashmaliciousBrowse
    beamer.arm-20211202-2350Get hashmaliciousBrowse
      fAS1IqIeKJGet hashmaliciousBrowse
        q6L054nmNPGet hashmaliciousBrowse
          rNroDrxDX8Get hashmaliciousBrowse
            a13lg45BBFGet hashmaliciousBrowse
              HdxaOdBHLyGet hashmaliciousBrowse
                SianBf68nsGet hashmaliciousBrowse
                  j22Vry7PQBGet hashmaliciousBrowse
                    jJ1l2W978wGet hashmaliciousBrowse
                      VSE57F94EuGet hashmaliciousBrowse
                        95dSetGliKGet hashmaliciousBrowse
                          H7MTKzOUncGet hashmaliciousBrowse
                            z0sDGe1HWtGet hashmaliciousBrowse
                              bx8ZRDTbieGet hashmaliciousBrowse
                                HOi5DIja39Get hashmaliciousBrowse
                                  KXcyJaK55aGet hashmaliciousBrowse
                                    beamer.x86Get hashmaliciousBrowse
                                      beamer.armGet hashmaliciousBrowse
                                        34.249.145.219beamer.arm-20211202-2350Get hashmaliciousBrowse
                                          PQPv91RexGGet hashmaliciousBrowse
                                            RIE3BrH6X4Get hashmaliciousBrowse
                                              tlKkI7uWcuGet hashmaliciousBrowse
                                                nbGnA0iX0eGet hashmaliciousBrowse
                                                  VvUgZxfzqGGet hashmaliciousBrowse
                                                    Vc90gP8W1bGet hashmaliciousBrowse
                                                      tJaSWmeCjdGet hashmaliciousBrowse
                                                        2MzNonluPUGet hashmaliciousBrowse
                                                          jew.x86-20211122-1350Get hashmaliciousBrowse
                                                            xwbqdTFD93Get hashmaliciousBrowse
                                                              i686Get hashmaliciousBrowse
                                                                sw10l80cO2Get hashmaliciousBrowse
                                                                  JTHn81Q2S2Get hashmaliciousBrowse
                                                                    SecuriteInfo.com.Linux.BackDoor.Fgt.3841.14881.20899Get hashmaliciousBrowse
                                                                      6ZIiJTDBftGet hashmaliciousBrowse
                                                                        5vYAnApKPHGet hashmaliciousBrowse
                                                                          ByutK666RHGet hashmaliciousBrowse
                                                                            2m6GYRpRq2Get hashmaliciousBrowse
                                                                              NJY9kuGznpGet hashmaliciousBrowse
                                                                                109.202.202.202beamer.arm7-20211202-2350Get hashmaliciousBrowse
                                                                                  beamer.arm-20211202-2350Get hashmaliciousBrowse
                                                                                    a-r.m-4.SakuraGet hashmaliciousBrowse
                                                                                      a-r.m-5.SakuraGet hashmaliciousBrowse
                                                                                        x-8.6-.SakuraGet hashmaliciousBrowse
                                                                                          x-3.2-.SakuraGet hashmaliciousBrowse
                                                                                            Mo7tMkRLVzGet hashmaliciousBrowse
                                                                                              m-p.s-l.SakuraGet hashmaliciousBrowse
                                                                                                m-i.p-s.SakuraGet hashmaliciousBrowse
                                                                                                  mirai.arm7Get hashmaliciousBrowse
                                                                                                    eh.arm7-20211202-2050Get hashmaliciousBrowse
                                                                                                      eh.x86-20211202-2050Get hashmaliciousBrowse
                                                                                                        eh.arm-20211202-2050Get hashmaliciousBrowse
                                                                                                          mirai.armGet hashmaliciousBrowse
                                                                                                            RAyX4iU3dyGet hashmaliciousBrowse
                                                                                                              oeOZvHnuaUGet hashmaliciousBrowse
                                                                                                                nYdomnUtHqGet hashmaliciousBrowse
                                                                                                                  peon7hY4z4Get hashmaliciousBrowse
                                                                                                                    y4yhQj9EffGet hashmaliciousBrowse
                                                                                                                      qHBU9CAlTZGet hashmaliciousBrowse

                                                                                                                        Domains

                                                                                                                        No context

                                                                                                                        ASN

                                                                                                                        MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                                                        DAINTERNATIONALGROUPGBbeamer.arm7-20211202-2350Get hashmaliciousBrowse
                                                                                                                        • 45.134.225.20
                                                                                                                        beamer.arm-20211202-2350Get hashmaliciousBrowse
                                                                                                                        • 45.134.225.20
                                                                                                                        fAS1IqIeKJGet hashmaliciousBrowse
                                                                                                                        • 45.134.225.20
                                                                                                                        q6L054nmNPGet hashmaliciousBrowse
                                                                                                                        • 45.134.225.20
                                                                                                                        rNroDrxDX8Get hashmaliciousBrowse
                                                                                                                        • 45.134.225.20
                                                                                                                        a13lg45BBFGet hashmaliciousBrowse
                                                                                                                        • 45.134.225.20
                                                                                                                        HdxaOdBHLyGet hashmaliciousBrowse
                                                                                                                        • 45.134.225.20
                                                                                                                        SianBf68nsGet hashmaliciousBrowse
                                                                                                                        • 45.134.225.20
                                                                                                                        j22Vry7PQBGet hashmaliciousBrowse
                                                                                                                        • 45.134.225.20
                                                                                                                        jJ1l2W978wGet hashmaliciousBrowse
                                                                                                                        • 45.134.225.20
                                                                                                                        VSE57F94EuGet hashmaliciousBrowse
                                                                                                                        • 45.134.225.20
                                                                                                                        N6y7A7R9wg.exeGet hashmaliciousBrowse
                                                                                                                        • 45.134.225.35
                                                                                                                        2b0519e3978cea744b220f109077b4b012dc4e9856be8.exeGet hashmaliciousBrowse
                                                                                                                        • 45.134.225.35
                                                                                                                        95dSetGliKGet hashmaliciousBrowse
                                                                                                                        • 45.134.225.20
                                                                                                                        H7MTKzOUncGet hashmaliciousBrowse
                                                                                                                        • 45.134.225.20
                                                                                                                        z0sDGe1HWtGet hashmaliciousBrowse
                                                                                                                        • 45.134.225.20
                                                                                                                        bx8ZRDTbieGet hashmaliciousBrowse
                                                                                                                        • 45.134.225.20
                                                                                                                        HOi5DIja39Get hashmaliciousBrowse
                                                                                                                        • 45.134.225.20
                                                                                                                        KXcyJaK55aGet hashmaliciousBrowse
                                                                                                                        • 45.134.225.20
                                                                                                                        beamer.x86Get hashmaliciousBrowse
                                                                                                                        • 45.134.225.20
                                                                                                                        AMAZON-02USbeamer.arm-20211202-2350Get hashmaliciousBrowse
                                                                                                                        • 34.249.145.219
                                                                                                                        a-r.m-4.SakuraGet hashmaliciousBrowse
                                                                                                                        • 54.171.230.55
                                                                                                                        GenoSec.arm7Get hashmaliciousBrowse
                                                                                                                        • 176.34.166.240
                                                                                                                        S2pmCqOFEf.exeGet hashmaliciousBrowse
                                                                                                                        • 52.216.166.67
                                                                                                                        12.dllGet hashmaliciousBrowse
                                                                                                                        • 13.225.75.74
                                                                                                                        NVTNgwAjOKGet hashmaliciousBrowse
                                                                                                                        • 54.102.91.74
                                                                                                                        lAe63MagsKGet hashmaliciousBrowse
                                                                                                                        • 13.233.103.244
                                                                                                                        GenoSec.x86Get hashmaliciousBrowse
                                                                                                                        • 198.251.137.253
                                                                                                                        HackLoader.exeGet hashmaliciousBrowse
                                                                                                                        • 52.217.109.12
                                                                                                                        mirai.x86Get hashmaliciousBrowse
                                                                                                                        • 44.224.113.150
                                                                                                                        Yoshi.x86-20211202-2050Get hashmaliciousBrowse
                                                                                                                        • 13.52.72.80
                                                                                                                        7009.xlsxGet hashmaliciousBrowse
                                                                                                                        • 13.250.31.113
                                                                                                                        invoice dhl.delivery document and original invoice sign.exeGet hashmaliciousBrowse
                                                                                                                        • 44.227.76.166
                                                                                                                        oeOZvHnuaUGet hashmaliciousBrowse
                                                                                                                        • 54.171.230.55
                                                                                                                        Milleniumbpc.xlsxGet hashmaliciousBrowse
                                                                                                                        • 44.231.165.140
                                                                                                                        PQPv91RexGGet hashmaliciousBrowse
                                                                                                                        • 34.249.145.219
                                                                                                                        WAYBILL 44 7611 9546 - Joao Carlos.exeGet hashmaliciousBrowse
                                                                                                                        • 75.2.115.196
                                                                                                                        HBL No_PZU100035300.xlsxGet hashmaliciousBrowse
                                                                                                                        • 3.64.163.50
                                                                                                                        ufKi6DmWMQCuEb4.exeGet hashmaliciousBrowse
                                                                                                                        • 3.108.154.143
                                                                                                                        yVvATSvedsfMg0l.exeGet hashmaliciousBrowse
                                                                                                                        • 3.64.163.50

                                                                                                                        JA3 Fingerprints

                                                                                                                        No context

                                                                                                                        Dropped Files

                                                                                                                        No context

                                                                                                                        Created / dropped Files

                                                                                                                        No created / dropped files found

                                                                                                                        Static File Info

                                                                                                                        General

                                                                                                                        File type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, stripped
                                                                                                                        Entropy (8bit):6.469954580077168
                                                                                                                        TrID:
                                                                                                                        • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
                                                                                                                        • ELF Executable and Linkable format (generic) (4004/1) 49.84%
                                                                                                                        File name:beamer.x86-20211202-2350
                                                                                                                        File size:42164
                                                                                                                        MD5:04e178a6fe92b38222e03a4c2e2303e0
                                                                                                                        SHA1:ba0e9885d263093c13e955cb79cf6e86039d4177
                                                                                                                        SHA256:1000ab055531e011407b62ff66cc2b122334eb14dc01f56f9487023beeb38f59
                                                                                                                        SHA512:a698ac1122eeed10d8785d6543bb9fcab3b99a99ead80f69b1a6b04594c9681272d1b8a95d016fc0239b8cc60f1f2633884703bcabbce1c35df6c6816ed5679c
                                                                                                                        SSDEEP:768:fDQqegtrUdSHBnMslsWcBUxUBCFJoTR3CjeYnBnCLMiZ8USCIy:7QqegtIdShZIBfBC8DYnJuMiTSC
                                                                                                                        File Content Preview:.ELF....................d...4...$.......4. ...(.............................................. ... .......(..........Q.td............................U..S.......w....h....3...[]...$.............U......=.#...t..5....$ .....$ ......u........t....h............

                                                                                                                        Static ELF Info

                                                                                                                        ELF header

                                                                                                                        Class:ELF32
                                                                                                                        Data:2's complement, little endian
                                                                                                                        Version:1 (current)
                                                                                                                        Machine:Intel 80386
                                                                                                                        Version Number:0x1
                                                                                                                        Type:EXEC (Executable file)
                                                                                                                        OS/ABI:UNIX - System V
                                                                                                                        ABI Version:0
                                                                                                                        Entry Point Address:0x8048164
                                                                                                                        Flags:0x0
                                                                                                                        ELF Header Size:52
                                                                                                                        Program Header Offset:52
                                                                                                                        Program Header Size:32
                                                                                                                        Number of Program Headers:3
                                                                                                                        Section Header Offset:41764
                                                                                                                        Section Header Size:40
                                                                                                                        Number of Section Headers:10
                                                                                                                        Header String Table Index:9

                                                                                                                        Sections

                                                                                                                        NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                                                                                        NULL0x00x00x00x00x0000
                                                                                                                        .initPROGBITS0x80480940x940x1c0x00x6AX001
                                                                                                                        .textPROGBITS0x80480b00xb00x82560x00x6AX0016
                                                                                                                        .finiPROGBITS0x80503060x83060x170x00x6AX001
                                                                                                                        .rodataPROGBITS0x80503200x83200x19fc0x00x2A0032
                                                                                                                        .ctorsPROGBITS0x80520000xa0000x80x00x3WA004
                                                                                                                        .dtorsPROGBITS0x80520080xa0080x80x00x3WA004
                                                                                                                        .dataPROGBITS0x80520200xa0200x2c40x00x3WA0032
                                                                                                                        .bssNOBITS0x80523000xa2e40x25a00x00x3WA0032
                                                                                                                        .shstrtabSTRTAB0x00xa2e40x3e0x00x0001

                                                                                                                        Program Segments

                                                                                                                        TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                                                                                        LOAD0x00x80480000x80480000x9d1c0x9d1c4.17610x5R E0x1000.init .text .fini .rodata
                                                                                                                        LOAD0xa0000x80520000x80520000x2e40x28a02.61490x6RW 0x1000.ctors .dtors .data .bss
                                                                                                                        GNU_STACK0x00x00x00x00x00.00000x6RW 0x4

                                                                                                                        Network Behavior

                                                                                                                        Network Port Distribution

                                                                                                                        TCP Packets

                                                                                                                        TimestampSource PortDest PortSource IPDest IP
                                                                                                                        Dec 3, 2021 01:02:03.713726997 CET52018544192.168.2.2345.134.225.20
                                                                                                                        Dec 3, 2021 01:02:03.741457939 CET5445201845.134.225.20192.168.2.23
                                                                                                                        Dec 3, 2021 01:02:03.741532087 CET52018544192.168.2.2345.134.225.20
                                                                                                                        Dec 3, 2021 01:02:03.741556883 CET52018544192.168.2.2345.134.225.20
                                                                                                                        Dec 3, 2021 01:02:03.769165993 CET5445201845.134.225.20192.168.2.23
                                                                                                                        Dec 3, 2021 01:02:03.769198895 CET5445201845.134.225.20192.168.2.23
                                                                                                                        Dec 3, 2021 01:02:03.769251108 CET52018544192.168.2.2345.134.225.20
                                                                                                                        Dec 3, 2021 01:02:03.769290924 CET52018544192.168.2.2345.134.225.20
                                                                                                                        Dec 3, 2021 01:02:03.796756983 CET5445201845.134.225.20192.168.2.23
                                                                                                                        Dec 3, 2021 01:02:04.652885914 CET42836443192.168.2.2391.189.91.43
                                                                                                                        Dec 3, 2021 01:02:04.652993917 CET4251680192.168.2.23109.202.202.202
                                                                                                                        Dec 3, 2021 01:02:04.769454002 CET52020544192.168.2.2345.134.225.20
                                                                                                                        Dec 3, 2021 01:02:04.797152042 CET5445202045.134.225.20192.168.2.23
                                                                                                                        Dec 3, 2021 01:02:04.797265053 CET52020544192.168.2.2345.134.225.20
                                                                                                                        Dec 3, 2021 01:02:04.797352076 CET52020544192.168.2.2345.134.225.20
                                                                                                                        Dec 3, 2021 01:02:04.825161934 CET5445202045.134.225.20192.168.2.23
                                                                                                                        Dec 3, 2021 01:02:04.825382948 CET52020544192.168.2.2345.134.225.20
                                                                                                                        Dec 3, 2021 01:02:04.853236914 CET5445202045.134.225.20192.168.2.23
                                                                                                                        Dec 3, 2021 01:02:19.853104115 CET5445202045.134.225.20192.168.2.23
                                                                                                                        Dec 3, 2021 01:02:19.853360891 CET52020544192.168.2.2345.134.225.20
                                                                                                                        Dec 3, 2021 01:02:20.268871069 CET43928443192.168.2.2391.189.91.42
                                                                                                                        Dec 3, 2021 01:02:25.998893023 CET39246443192.168.2.2334.249.145.219
                                                                                                                        Dec 3, 2021 01:02:27.021008015 CET39246443192.168.2.2334.249.145.219
                                                                                                                        Dec 3, 2021 01:02:29.036896944 CET39246443192.168.2.2334.249.145.219
                                                                                                                        Dec 3, 2021 01:02:30.508909941 CET42836443192.168.2.2391.189.91.43
                                                                                                                        Dec 3, 2021 01:02:33.068954945 CET39246443192.168.2.2334.249.145.219
                                                                                                                        Dec 3, 2021 01:02:34.604963064 CET4251680192.168.2.23109.202.202.202
                                                                                                                        Dec 3, 2021 01:02:34.881095886 CET5445202045.134.225.20192.168.2.23
                                                                                                                        Dec 3, 2021 01:02:34.881218910 CET52020544192.168.2.2345.134.225.20
                                                                                                                        Dec 3, 2021 01:02:41.260885000 CET39246443192.168.2.2334.249.145.219
                                                                                                                        Dec 3, 2021 01:02:44.828872919 CET52020544192.168.2.2345.134.225.20
                                                                                                                        Dec 3, 2021 01:02:44.856843948 CET5445202045.134.225.20192.168.2.23
                                                                                                                        Dec 3, 2021 01:02:57.388839960 CET39246443192.168.2.2334.249.145.219
                                                                                                                        Dec 3, 2021 01:02:59.891980886 CET5445202045.134.225.20192.168.2.23
                                                                                                                        Dec 3, 2021 01:02:59.892126083 CET52020544192.168.2.2345.134.225.20
                                                                                                                        Dec 3, 2021 01:03:01.228825092 CET43928443192.168.2.2391.189.91.42
                                                                                                                        Dec 3, 2021 01:03:14.932059050 CET5445202045.134.225.20192.168.2.23
                                                                                                                        Dec 3, 2021 01:03:14.932248116 CET52020544192.168.2.2345.134.225.20
                                                                                                                        Dec 3, 2021 01:03:21.708774090 CET42836443192.168.2.2391.189.91.43
                                                                                                                        Dec 3, 2021 01:03:29.972131968 CET5445202045.134.225.20192.168.2.23
                                                                                                                        Dec 3, 2021 01:03:29.972275972 CET52020544192.168.2.2345.134.225.20
                                                                                                                        Dec 3, 2021 01:03:44.876784086 CET52020544192.168.2.2345.134.225.20
                                                                                                                        Dec 3, 2021 01:03:44.904932976 CET5445202045.134.225.20192.168.2.23
                                                                                                                        Dec 3, 2021 01:03:59.923870087 CET5445202045.134.225.20192.168.2.23
                                                                                                                        Dec 3, 2021 01:03:59.923993111 CET52020544192.168.2.2345.134.225.20
                                                                                                                        Dec 3, 2021 01:04:14.964004993 CET5445202045.134.225.20192.168.2.23
                                                                                                                        Dec 3, 2021 01:04:14.964142084 CET52020544192.168.2.2345.134.225.20
                                                                                                                        Dec 3, 2021 01:04:30.003947020 CET5445202045.134.225.20192.168.2.23
                                                                                                                        Dec 3, 2021 01:04:30.004060984 CET52020544192.168.2.2345.134.225.20
                                                                                                                        Dec 3, 2021 01:04:44.924628019 CET52020544192.168.2.2345.134.225.20
                                                                                                                        Dec 3, 2021 01:04:44.952501059 CET5445202045.134.225.20192.168.2.23
                                                                                                                        Dec 3, 2021 01:04:59.956001043 CET5445202045.134.225.20192.168.2.23
                                                                                                                        Dec 3, 2021 01:04:59.956279039 CET52020544192.168.2.2345.134.225.20
                                                                                                                        Dec 3, 2021 01:05:14.995980024 CET5445202045.134.225.20192.168.2.23
                                                                                                                        Dec 3, 2021 01:05:14.996109962 CET52020544192.168.2.2345.134.225.20
                                                                                                                        Dec 3, 2021 01:05:30.036056995 CET5445202045.134.225.20192.168.2.23
                                                                                                                        Dec 3, 2021 01:05:30.036411047 CET52020544192.168.2.2345.134.225.20

                                                                                                                        System Behavior

                                                                                                                        General

                                                                                                                        Start time:01:02:02
                                                                                                                        Start date:03/12/2021
                                                                                                                        Path:/tmp/beamer.x86-20211202-2350
                                                                                                                        Arguments:/tmp/beamer.x86-20211202-2350
                                                                                                                        File size:42164 bytes
                                                                                                                        MD5 hash:04e178a6fe92b38222e03a4c2e2303e0

                                                                                                                        General

                                                                                                                        Start time:01:02:02
                                                                                                                        Start date:03/12/2021
                                                                                                                        Path:/tmp/beamer.x86-20211202-2350
                                                                                                                        Arguments:n/a
                                                                                                                        File size:42164 bytes
                                                                                                                        MD5 hash:04e178a6fe92b38222e03a4c2e2303e0

                                                                                                                        General

                                                                                                                        Start time:01:02:02
                                                                                                                        Start date:03/12/2021
                                                                                                                        Path:/tmp/beamer.x86-20211202-2350
                                                                                                                        Arguments:n/a
                                                                                                                        File size:42164 bytes
                                                                                                                        MD5 hash:04e178a6fe92b38222e03a4c2e2303e0

                                                                                                                        General

                                                                                                                        Start time:01:02:02
                                                                                                                        Start date:03/12/2021
                                                                                                                        Path:/tmp/beamer.x86-20211202-2350
                                                                                                                        Arguments:n/a
                                                                                                                        File size:42164 bytes
                                                                                                                        MD5 hash:04e178a6fe92b38222e03a4c2e2303e0

                                                                                                                        General

                                                                                                                        Start time:01:03:25
                                                                                                                        Start date:03/12/2021
                                                                                                                        Path:/usr/bin/dash
                                                                                                                        Arguments:n/a
                                                                                                                        File size:129816 bytes
                                                                                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                        General

                                                                                                                        Start time:01:03:25
                                                                                                                        Start date:03/12/2021
                                                                                                                        Path:/usr/bin/rm
                                                                                                                        Arguments:rm -f /tmp/tmp.AlKkHgaC4m /tmp/tmp.GpcnZvv7fC /tmp/tmp.zmqkJtmHaS
                                                                                                                        File size:72056 bytes
                                                                                                                        MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b