Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
M74QLI3COX.elf

Overview

General Information

Sample name:M74QLI3COX.elf
renamed because original name is a hash value
Original sample name:16f920f318bc3fe46bf66d063153d2ef.elf
Analysis ID:1436495
MD5:16f920f318bc3fe46bf66d063153d2ef
SHA1:0d0af14367b108967a9ad93e182b437c1565d4bf
SHA256:4da76cd7ebfd5412d4681e2f25fcf187863fd15ecc0f952171c841b1290b64b1
Tags:elfmips
Infos:

Detection

Kaiji
Score:56
Range:0 - 100
Whitelisted:false

Signatures

Multi AV Scanner detection for submitted file
Yara detected Kaiji
Executes the "rm" command used to delete files or directories
Sample has stripped symbol table
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

Analysis Advice

Static ELF header machine description suggests that the sample might not execute correctly on this machine.
Non-zero exit code suggests an error during the execution. Lookup the error code for hints.
Static ELF header machine description suggests that the sample might only run correctly on MIPS or ARM architectures.
Joe Sandbox version:40.0.0 Tourmaline
Analysis ID:1436495
Start date and time:2024-05-05 16:43:11 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 23s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:M74QLI3COX.elf
renamed because original name is a hash value
Original Sample Name:16f920f318bc3fe46bf66d063153d2ef.elf
Detection:MAL
Classification:mal56.troj.linELF@0/0@0/0
Command:/tmp/M74QLI3COX.elf
PID:5509
Exit Code:2
Exit Code Info:
Killed:False
Standard Output:

Standard Error:fatal error: sigaction failed

runtime stack:
runtime.throw({0x16f218, 0x10})
C:/Program Files/Go/src/runtime/panic.go:1047 +0x58 fp=0x4000800b38 sp=0x4000800b10 pc=0x54da8
runtime.sysSigaction.func1()
C:/Program Files/Go/src/runtime/os_linux.go:542 +0x50 fp=0x4000800b50 sp=0x4000800b38 pc=0x8ef40
runtime.sysSigaction(0x41, 0x4000800bc0, 0x0)
C:/Program Files/Go/src/runtime/os_linux.go:541 +0x8c fp=0x4000800b80 sp=0x4000800b50 pc=0x512fc
runtime.sigaction(0x41, 0x4000800bc0, 0x0)
C:/Program Files/Go/src/runtime/sigaction.go:15 +0x2c fp=0x4000800ba0 sp=0x4000800b80 pc=0x714e4
runtime.setsig(0x41, 0x73300)
C:/Program Files/Go/src/runtime/os_linux.go:489 +0xb4 fp=0x4000800be8 sp=0x4000800ba0 pc=0x511bc
runtime.initsig(0x0)
C:/Program Files/Go/src/runtime/signal_unix.go:148 +0x34c fp=0x4000800c50 sp=0x4000800be8 pc=0x7280c
runtime.mstartm0()
C:/Program Files/Go/src/runtime/proc.go:1522 +0x7c fp=0x4000800c60 sp=0x4000800c50 pc=0x5c67c
runtime.mstart1()
C:/Program Files/Go/src/runtime/proc.go:1494 +0x98 fp=0x4000800c80 sp=0x4000800c60 pc=0x5c558
runtime.mstart0()
C:/Program Files/Go/src/runtime/proc.go:1455 +0x78 fp=0x4000800ca8 sp=0x4000800c80 pc=0x5c498
runtime.mstart()
C:/Program Files/Go/src/runtime/asm_mips64x.s:88 +0x14 fp=0x4000800cb0 sp=0x4000800ca8 pc=0x9319c

goroutine 1 [runnable]:
runtime.main()
C:/Program Files/Go/src/runtime/proc.go:145 fp=0xc00002e7d8 sp=0xc00002e7d8 pc=0x583f8
runtime.goexit()
C:/Program Files/Go/src/runtime/asm_mips64x.s:624 +0x4 fp=0xc00002e7d8 sp=0xc00002e7d8 pc=0x9566c
  • system is lnxubuntu20
  • M74QLI3COX.elf (PID: 5509, Parent: 5435, MD5: bba92fd1c51079d6ff2478396026936a) Arguments: /tmp/M74QLI3COX.elf
  • dash New Fork (PID: 5513, Parent: 3671)
  • rm (PID: 5513, Parent: 3671, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.fZhFj81utJ /tmp/tmp.5BuHKRtIt9 /tmp/tmp.iMWgMwkDqB
  • dash New Fork (PID: 5514, Parent: 3671)
  • cat (PID: 5514, Parent: 3671, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /tmp/tmp.fZhFj81utJ
  • dash New Fork (PID: 5515, Parent: 3671)
  • head (PID: 5515, Parent: 3671, MD5: fd96a67145172477dd57131396fc9608) Arguments: head -n 10
  • dash New Fork (PID: 5516, Parent: 3671)
  • tr (PID: 5516, Parent: 3671, MD5: fbd1402dd9f72d8ebfff00ce7c3a7bb5) Arguments: tr -d \\000-\\011\\013\\014\\016-\\037
  • dash New Fork (PID: 5517, Parent: 3671)
  • cut (PID: 5517, Parent: 3671, MD5: d8ed0ea8f22c0de0f8692d4d9f1759d3) Arguments: cut -c -80
  • dash New Fork (PID: 5518, Parent: 3671)
  • cat (PID: 5518, Parent: 3671, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /tmp/tmp.fZhFj81utJ
  • dash New Fork (PID: 5519, Parent: 3671)
  • head (PID: 5519, Parent: 3671, MD5: fd96a67145172477dd57131396fc9608) Arguments: head -n 10
  • dash New Fork (PID: 5520, Parent: 3671)
  • tr (PID: 5520, Parent: 3671, MD5: fbd1402dd9f72d8ebfff00ce7c3a7bb5) Arguments: tr -d \\000-\\011\\013\\014\\016-\\037
  • dash New Fork (PID: 5521, Parent: 3671)
  • cut (PID: 5521, Parent: 3671, MD5: d8ed0ea8f22c0de0f8692d4d9f1759d3) Arguments: cut -c -80
  • dash New Fork (PID: 5522, Parent: 3671)
  • rm (PID: 5522, Parent: 3671, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.fZhFj81utJ /tmp/tmp.5BuHKRtIt9 /tmp/tmp.iMWgMwkDqB
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
KaijiSurfaced in late April 2020, Intezer describes Kaiji as a DDoS malware written in Go that spreads through SSH brute force attacks. Recovered function names are an English representation of Chinese words, hinting about the origin. The name Kaiji was given by MalwareMustDie based on strings found in samples.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.kaiji
SourceRuleDescriptionAuthorStrings
M74QLI3COX.elfJoeSecurity_Kaiji_1Yara detected KaijiJoe Security
    No Snort rule has matched

    Click to jump to signature section

    Show All Signature Results

    AV Detection

    barindex
    Source: M74QLI3COX.elfReversingLabs: Detection: 18%
    Source: M74QLI3COX.elfVirustotal: Detection: 12%Perma Link
    Source: unknownHTTPS traffic detected: 54.217.10.153:443 -> 192.168.2.15:49566 version: TLS 1.2
    Source: unknownNetwork traffic detected: HTTP traffic on port 49566 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49566
    Source: unknownHTTPS traffic detected: 54.217.10.153:443 -> 192.168.2.15:49566 version: TLS 1.2
    Source: ELF static info symbol of initial sample.symtab present: no
    Source: classification engineClassification label: mal56.troj.linELF@0/0@0/0
    Source: ELF file sectionSubmission: M74QLI3COX.elf
    Source: /usr/bin/dash (PID: 5513)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.fZhFj81utJ /tmp/tmp.5BuHKRtIt9 /tmp/tmp.iMWgMwkDqBJump to behavior
    Source: /usr/bin/dash (PID: 5522)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.fZhFj81utJ /tmp/tmp.5BuHKRtIt9 /tmp/tmp.iMWgMwkDqBJump to behavior
    Source: /tmp/M74QLI3COX.elf (PID: 5509)Queries kernel information via 'uname': Jump to behavior
    Source: M74QLI3COX.elf, 5509.1.00007ffe5854e000.00007ffe5856f000.rw-.sdmpBinary or memory string: /usr/bin/qemu-mips64el
    Source: M74QLI3COX.elf, 5509.1.0000556a496ab000.0000556a49a27000.rw-.sdmpBinary or memory string: ?nIjU1MIPS64R2-generic-mips64-cpu1/etc/qemu-binfmt/mips64elu
    Source: M74QLI3COX.elf, 5509.1.0000556a496ab000.0000556a49a27000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/mips64el
    Source: M74QLI3COX.elf, 5509.1.00007ffe5854e000.00007ffe5856f000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-mips64el/tmp/M74QLI3COX.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/M74QLI3COX.elf

    Stealing of Sensitive Information

    barindex
    Source: Yara matchFile source: M74QLI3COX.elf, type: SAMPLE

    Remote Access Functionality

    barindex
    Source: Yara matchFile source: M74QLI3COX.elf, type: SAMPLE
    ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
    Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
    File Deletion
    OS Credential Dumping11
    Security Software Discovery
    Remote ServicesData from Local System1
    Encrypted Channel
    Exfiltration Over Other Network MediumAbuse Accessibility Features
    CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
    Application Layer Protocol
    Exfiltration Over BluetoothNetwork Denial of Service
    No configs have been found
    Hide Legend

    Legend:

    • Process
    • Signature
    • Created File
    • DNS/IP Info
    • Is Dropped
    • Number of created Files
    • Is malicious
    • Internet
    behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1436495 Sample: M74QLI3COX.elf Startdate: 05/05/2024 Architecture: LINUX Score: 56 14 54.217.10.153, 443, 49566 AMAZON-02US United States 2->14 16 Multi AV Scanner detection for submitted file 2->16 18 Yara detected Kaiji 2->18 6 dash rm 2->6         started        8 dash cat 2->8         started        10 dash head 2->10         started        12 8 other processes 2->12 signatures3 process4

    This section contains all screenshots as thumbnails, including those not shown in the slideshow.


    windows-stand
    SourceDetectionScannerLabelLink
    M74QLI3COX.elf18%ReversingLabsLinux.Trojan.Ares
    M74QLI3COX.elf13%VirustotalBrowse
    No Antivirus matches
    No Antivirus matches
    No Antivirus matches
    No contacted domains info
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    54.217.10.153
    unknownUnited States
    16509AMAZON-02USfalse
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    54.217.10.153SecuriteInfo.com.Trojan.Linux.GenericKD.28945.18513.11319.elfGet hashmaliciousUnknownBrowse
      SecuriteInfo.com.Linux.Mirai.8362.28225.8588.elfGet hashmaliciousMiraiBrowse
        3l23Ly4zK0.elfGet hashmaliciousMiraiBrowse
          8ce5xGv7Rl.elfGet hashmaliciousMiraiBrowse
            9EYzS8C2Sn.elfGet hashmaliciousMirai, OkiruBrowse
              jDrEk4Z8cP.elfGet hashmaliciousUnknownBrowse
                7AviWAaJMa.elfGet hashmaliciousMiraiBrowse
                  bulus.arm7-20240430-1916.elfGet hashmaliciousMirai, Moobot, OkiruBrowse
                    sora.arm5.elfGet hashmaliciousMiraiBrowse
                      PBh6YIFgSF.elfGet hashmaliciousMiraiBrowse
                        No context
                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                        AMAZON-02UShdqqxiAaUa.elfGet hashmaliciousMiraiBrowse
                        • 54.119.116.90
                        JQf0ehYRnW.elfGet hashmaliciousMiraiBrowse
                        • 18.136.8.182
                        v6KtBJBvIM.elfGet hashmaliciousMiraiBrowse
                        • 13.224.91.140
                        IQU2qqn8AZ.elfGet hashmaliciousMiraiBrowse
                        • 13.113.240.116
                        JCS9ADM3XR.elfGet hashmaliciousMiraiBrowse
                        • 34.249.145.219
                        wlFJIK0tXZ.elfGet hashmaliciousUnknownBrowse
                        • 34.249.145.219
                        77a9MuTMle.elfGet hashmaliciousMiraiBrowse
                        • 34.249.145.219
                        AzlcQuUN0k.elfGet hashmaliciousUnknownBrowse
                        • 34.249.145.219
                        wQT6LP2bum.elfGet hashmaliciousMiraiBrowse
                        • 34.243.160.129
                        9zU9mg84VT.elfGet hashmaliciousUnknownBrowse
                        • 34.249.145.219
                        No context
                        No context
                        No created / dropped files found
                        File type:ELF 64-bit LSB executable, MIPS, MIPS-III version 1 (SYSV), statically linked, Go BuildID=tIdheouc6LQYM4AxlF6J/RIpVyx97yR-Cy8tknSUC/sxGYsJYcW-ER3FYcJGL_/lD73K25NKDaKC7JiK502, stripped
                        Entropy (8bit):5.180745308751407
                        TrID:
                        • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                        File name:M74QLI3COX.elf
                        File size:2'359'296 bytes
                        MD5:16f920f318bc3fe46bf66d063153d2ef
                        SHA1:0d0af14367b108967a9ad93e182b437c1565d4bf
                        SHA256:4da76cd7ebfd5412d4681e2f25fcf187863fd15ecc0f952171c841b1290b64b1
                        SHA512:cdd7c9d95e69e7a1a218c70c3b273e639ebb427ef40a723cbc6e1fc46bb94207e0046110368d12eadd2881cc1093d8996842ac177aeaf5cdd3313ed182fbcb53
                        SSDEEP:24576:KFUgWKX5sgIqJCDhtcgZDBpjzxlVXw8RuMFLGk+Ton7TF0z1v:bKX5R7MDAyxzuM9Gk+27TF0z1
                        TLSH:B7B5E80ABDC16F76C59C037586EE265A23513E495B91032327A4F7B83A7733CAF5B488
                        File Content Preview:.ELF....................8h......@.................. @.8...@.............@.......@.......@...............................................................d.......d..............................................................................................

                        ELF header

                        Class:ELF64
                        Data:2's complement, little endian
                        Version:1 (current)
                        Machine:MIPS R3000
                        Version Number:0x1
                        Type:EXEC (Executable file)
                        OS/ABI:UNIX - System V
                        ABI Version:0
                        Entry Point Address:0x96838
                        Flags:0x20000004
                        ELF Header Size:64
                        Program Header Offset:64
                        Program Header Size:56
                        Number of Program Headers:7
                        Section Header Offset:456
                        Section Header Size:64
                        Number of Section Headers:14
                        Header String Table Index:3
                        NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                        NULL0x00x00x00x00x0000
                        .textPROGBITS0x110000x10000x12a4d00x00x6AX008
                        .rodataPROGBITS0x1400000x1300000x593f10x00x2A0032
                        .shstrtabSTRTAB0x00x1894000x980x00x0001
                        .typelinkPROGBITS0x1994a00x1894a00x8d40x00x2A0032
                        .itablinkPROGBITS0x199d800x189d800x2400x00x2A0032
                        .gosymtabPROGBITS0x199fc00x189fc00x00x00x2A001
                        .gopclntabPROGBITS0x199fc00x189fc00x8d0000x00x2A0032
                        .go.buildinfoPROGBITS0x2300000x2200000x1000x00x3WA0016
                        .noptrdataPROGBITS0x2301000x2201000x11dcc0x00x3WA0032
                        .dataPROGBITS0x241ee00x231ee00xc4000x00x3WA0032
                        .bssNOBITS0x24e2e00x23e2e00x2c6800x00x3WA0032
                        .noptrbssNOBITS0x27a9600x26a9600x44300x00x3WA0032
                        .note.go.buildidNOTE0x10f9c0xf9c0x640x00x2A004
                        TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                        PHDR0x400x100400x100400x1880x1881.49620x4R 0x10000
                        NOTE0xf9c0x10f9c0x10f9c0x640x645.29330x4R 0x4.note.go.buildid
                        LOAD0x00x100000x100000x12b4d00x12b4d05.03730x5R E0x10000.text .note.go.buildid
                        LOAD0x1300000x1400000x1400000xe6fc00xe6fc05.28230x4R 0x10000.rodata .typelink .itablink .gosymtab .gopclntab
                        LOAD0x2200000x2300000x2300000x1e2e00x4ed903.94000x6RW 0x10000.go.buildinfo .noptrdata .data .bss .noptrbss
                        GNU_STACK0x00x00x00x00x00.00000x6RW 0x8
                        LOOS+50415800x00x00x00x00x00.00000x2a00 0x8
                        TimestampSource PortDest PortSource IPDest IP
                        May 5, 2024 16:43:53.081012964 CEST4434956654.217.10.153192.168.2.15
                        May 5, 2024 16:43:53.081027031 CEST4434956654.217.10.153192.168.2.15
                        May 5, 2024 16:43:53.081036091 CEST4434956654.217.10.153192.168.2.15
                        May 5, 2024 16:43:53.081046104 CEST4434956654.217.10.153192.168.2.15
                        May 5, 2024 16:43:53.081056118 CEST4434956654.217.10.153192.168.2.15
                        May 5, 2024 16:43:53.081059933 CEST49566443192.168.2.1554.217.10.153
                        May 5, 2024 16:43:53.081065893 CEST4434956654.217.10.153192.168.2.15
                        May 5, 2024 16:43:53.081094027 CEST49566443192.168.2.1554.217.10.153
                        May 5, 2024 16:43:53.081094027 CEST49566443192.168.2.1554.217.10.153
                        May 5, 2024 16:43:53.081094027 CEST49566443192.168.2.1554.217.10.153
                        May 5, 2024 16:43:53.081094027 CEST49566443192.168.2.1554.217.10.153
                        May 5, 2024 16:43:53.081094027 CEST49566443192.168.2.1554.217.10.153
                        May 5, 2024 16:43:53.081813097 CEST49566443192.168.2.1554.217.10.153
                        May 5, 2024 16:43:53.271338940 CEST4434956654.217.10.153192.168.2.15
                        May 5, 2024 16:43:53.299829006 CEST4434956654.217.10.153192.168.2.15
                        May 5, 2024 16:43:53.299880028 CEST49566443192.168.2.1554.217.10.153
                        May 5, 2024 16:43:53.299943924 CEST49566443192.168.2.1554.217.10.153
                        May 5, 2024 16:43:53.503626108 CEST4434956654.217.10.153192.168.2.15
                        May 5, 2024 16:43:53.503638029 CEST4434956654.217.10.153192.168.2.15
                        May 5, 2024 16:43:53.503693104 CEST49566443192.168.2.1554.217.10.153
                        May 5, 2024 16:43:53.503693104 CEST49566443192.168.2.1554.217.10.153
                        May 5, 2024 16:43:53.504503012 CEST49566443192.168.2.1554.217.10.153
                        May 5, 2024 16:43:53.701574087 CEST4434956654.217.10.153192.168.2.15
                        May 5, 2024 16:43:53.701591969 CEST4434956654.217.10.153192.168.2.15
                        May 5, 2024 16:43:53.701734066 CEST49566443192.168.2.1554.217.10.153
                        May 5, 2024 16:43:53.701850891 CEST49566443192.168.2.1554.217.10.153
                        TimestampSource IPSource PortDest IPDest PortSubjectIssuerNot BeforeNot AfterJA3 SSL Client FingerprintJA3 SSL Client Digest
                        May 5, 2024 16:43:53.081065893 CEST54.217.10.153443192.168.2.1549566CN=motd.ubuntu.com CN=R3, O=Let's Encrypt, C=USCN=R3, O=Let's Encrypt, C=US CN=ISRG Root X1, O=Internet Security Research Group, C=USThu Mar 07 10:27:55 CET 2024 Fri Sep 04 02:00:00 CEST 2020Wed Jun 05 11:27:54 CEST 2024 Mon Sep 15 18:00:00 CEST 2025
                        CN=R3, O=Let's Encrypt, C=USCN=ISRG Root X1, O=Internet Security Research Group, C=USFri Sep 04 02:00:00 CEST 2020Mon Sep 15 18:00:00 CEST 2025

                        System Behavior

                        Start time (UTC):14:43:49
                        Start date (UTC):05/05/2024
                        Path:/tmp/M74QLI3COX.elf
                        Arguments:/tmp/M74QLI3COX.elf
                        File size:5822264 bytes
                        MD5 hash:bba92fd1c51079d6ff2478396026936a

                        Start time (UTC):14:43:52
                        Start date (UTC):05/05/2024
                        Path:/usr/bin/dash
                        Arguments:-
                        File size:129816 bytes
                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                        Start time (UTC):14:43:52
                        Start date (UTC):05/05/2024
                        Path:/usr/bin/rm
                        Arguments:rm -f /tmp/tmp.fZhFj81utJ /tmp/tmp.5BuHKRtIt9 /tmp/tmp.iMWgMwkDqB
                        File size:72056 bytes
                        MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                        Start time (UTC):14:43:52
                        Start date (UTC):05/05/2024
                        Path:/usr/bin/dash
                        Arguments:-
                        File size:129816 bytes
                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                        Start time (UTC):14:43:52
                        Start date (UTC):05/05/2024
                        Path:/usr/bin/cat
                        Arguments:cat /tmp/tmp.fZhFj81utJ
                        File size:43416 bytes
                        MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

                        Start time (UTC):14:43:52
                        Start date (UTC):05/05/2024
                        Path:/usr/bin/dash
                        Arguments:-
                        File size:129816 bytes
                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                        Start time (UTC):14:43:52
                        Start date (UTC):05/05/2024
                        Path:/usr/bin/head
                        Arguments:head -n 10
                        File size:47480 bytes
                        MD5 hash:fd96a67145172477dd57131396fc9608

                        Start time (UTC):14:43:52
                        Start date (UTC):05/05/2024
                        Path:/usr/bin/dash
                        Arguments:-
                        File size:129816 bytes
                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                        Start time (UTC):14:43:52
                        Start date (UTC):05/05/2024
                        Path:/usr/bin/tr
                        Arguments:tr -d \\000-\\011\\013\\014\\016-\\037
                        File size:51544 bytes
                        MD5 hash:fbd1402dd9f72d8ebfff00ce7c3a7bb5

                        Start time (UTC):14:43:52
                        Start date (UTC):05/05/2024
                        Path:/usr/bin/dash
                        Arguments:-
                        File size:129816 bytes
                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                        Start time (UTC):14:43:52
                        Start date (UTC):05/05/2024
                        Path:/usr/bin/cut
                        Arguments:cut -c -80
                        File size:47480 bytes
                        MD5 hash:d8ed0ea8f22c0de0f8692d4d9f1759d3

                        Start time (UTC):14:43:52
                        Start date (UTC):05/05/2024
                        Path:/usr/bin/dash
                        Arguments:-
                        File size:129816 bytes
                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                        Start time (UTC):14:43:52
                        Start date (UTC):05/05/2024
                        Path:/usr/bin/cat
                        Arguments:cat /tmp/tmp.fZhFj81utJ
                        File size:43416 bytes
                        MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

                        Start time (UTC):14:43:52
                        Start date (UTC):05/05/2024
                        Path:/usr/bin/dash
                        Arguments:-
                        File size:129816 bytes
                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                        Start time (UTC):14:43:52
                        Start date (UTC):05/05/2024
                        Path:/usr/bin/head
                        Arguments:head -n 10
                        File size:47480 bytes
                        MD5 hash:fd96a67145172477dd57131396fc9608

                        Start time (UTC):14:43:52
                        Start date (UTC):05/05/2024
                        Path:/usr/bin/dash
                        Arguments:-
                        File size:129816 bytes
                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                        Start time (UTC):14:43:52
                        Start date (UTC):05/05/2024
                        Path:/usr/bin/tr
                        Arguments:tr -d \\000-\\011\\013\\014\\016-\\037
                        File size:51544 bytes
                        MD5 hash:fbd1402dd9f72d8ebfff00ce7c3a7bb5

                        Start time (UTC):14:43:52
                        Start date (UTC):05/05/2024
                        Path:/usr/bin/dash
                        Arguments:-
                        File size:129816 bytes
                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                        Start time (UTC):14:43:52
                        Start date (UTC):05/05/2024
                        Path:/usr/bin/cut
                        Arguments:cut -c -80
                        File size:47480 bytes
                        MD5 hash:d8ed0ea8f22c0de0f8692d4d9f1759d3

                        Start time (UTC):14:43:52
                        Start date (UTC):05/05/2024
                        Path:/usr/bin/dash
                        Arguments:-
                        File size:129816 bytes
                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                        Start time (UTC):14:43:52
                        Start date (UTC):05/05/2024
                        Path:/usr/bin/rm
                        Arguments:rm -f /tmp/tmp.fZhFj81utJ /tmp/tmp.5BuHKRtIt9 /tmp/tmp.iMWgMwkDqB
                        File size:72056 bytes
                        MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b