Status: Clean
| Category | Package | Started | Completed | Duration | Options | Log(s) | MalScore |
|---|---|---|---|---|---|---|---|
| FILE | 2025-12-08 13:55:52 | 2025-12-08 13:59:58 | 246 seconds | Show Options | Show Analysis Log | 3.5 |
vnc_port=5901
2025-12-08 05:51:54,001 [root] DEBUG: Starting analyzer from: /tmp7_5yn7x6 2025-12-08 05:51:54,002 [root] DEBUG: Storing results at: /tmp/eNwbVgsgtA 2025-12-08 05:51:54,003 [root] DEBUG: Importing auxiliary module "modules.auxiliary.auditd"... 2025-12-08 05:51:54,004 [root] DEBUG: Importing auxiliary module "modules.auxiliary.filecollector"... 2025-12-08 05:51:54,007 [root] DEBUG: Importing auxiliary module "modules.auxiliary.human"... 2025-12-08 05:51:54,008 [root] DEBUG: Importing auxiliary module "modules.auxiliary.screenshots"... 2025-12-08 05:51:54,015 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageChops' 2025-12-08 05:51:54,018 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageDraw' 2025-12-08 05:51:54,035 [root] DEBUG: Importing auxiliary module "modules.auxiliary.sysmon"... 2025-12-08 05:51:54,036 [root] DEBUG: Importing auxiliary module "modules.auxiliary.tracee"... 2025-12-08 05:51:54,037 [root] DEBUG: Initialized auxiliary module "Auditd" 2025-12-08 05:51:54,037 [root] DEBUG: Trying to start auxiliary module "Auditd"... 2025-12-08 05:51:54,037 [root] DEBUG: Started auxiliary module "Auditd" 2025-12-08 05:51:54,038 [modules.auxiliary.filecollector] INFO: FileCollector run started 2025-12-08 05:51:54,041 [modules.auxiliary.filecollector] INFO: FileCollector trying to watch dir sbin 2025-12-08 05:51:54,041 [modules.auxiliary.filecollector] INFO: FileCollector trying to watch dir srv 2025-12-08 05:51:54,042 [modules.auxiliary.filecollector] INFO: FileCollector trying to watch dir media 2025-12-08 05:51:54,042 [modules.auxiliary.filecollector] INFO: FileCollector trying to watch dir libx32 2025-12-08 05:51:54,042 [modules.auxiliary.filecollector] INFO: FileCollector trying to watch dir tmp7_5yn7x6 2025-12-08 05:51:54,043 [modules.auxiliary.filecollector] INFO: FileCollector trying to watch dir etc 2025-12-08 05:51:54,078 [modules.auxiliary.filecollector] INFO: FileCollector trying to watch dir mnt 2025-12-08 05:51:54,078 [modules.auxiliary.filecollector] INFO: FileCollector trying to watch dir tmpij155kl0 2025-12-08 05:51:54,079 [modules.auxiliary.filecollector] INFO: FileCollector trying to watch dir boot 2025-12-08 05:51:54,081 [modules.auxiliary.filecollector] INFO: FileCollector trying to watch dir cdrom 2025-12-08 05:51:54,081 [modules.auxiliary.filecollector] INFO: FileCollector trying to watch dir bin 2025-12-08 05:51:54,082 [modules.auxiliary.filecollector] INFO: FileCollector trying to watch dir root 2025-12-08 05:51:54,084 [modules.auxiliary.filecollector] INFO: FileCollector trying to watch dir opt 2025-12-08 05:51:54,084 [modules.auxiliary.filecollector] INFO: FileCollector trying to watch dir snap 2025-12-08 05:51:54,655 [modules.auxiliary.filecollector] INFO: FileCollector trying to watch dir tmp 2025-12-08 05:51:54,656 [modules.auxiliary.filecollector] INFO: FileCollector trying to watch dir home 2025-12-08 05:51:54,669 [modules.auxiliary.filecollector] INFO: FileCollector trying to watch dir lost+found 2025-12-08 05:51:54,669 [modules.auxiliary.filecollector] INFO: FileCollector trying to watch dir lib32 2025-12-08 05:51:54,669 [modules.auxiliary.filecollector] INFO: FileCollector setup complete 2025-12-08 05:51:55,038 [root] DEBUG: Initialized auxiliary module "FileCollector" 2025-12-08 05:51:55,038 [root] DEBUG: Trying to start auxiliary module "FileCollector"... 2025-12-08 05:51:55,038 [root] DEBUG: Started auxiliary module "FileCollector" 2025-12-08 05:51:55,038 [modules.auxiliary.human] DEBUG: Human init complete 2025-12-08 05:51:55,038 [root] DEBUG: Initialized auxiliary module "Human" 2025-12-08 05:51:55,039 [root] DEBUG: Trying to start auxiliary module "Human"... 2025-12-08 05:51:55,039 [root] DEBUG: Started auxiliary module "Human" 2025-12-08 05:51:55,039 [root] DEBUG: Initialized auxiliary module "Screenshots" 2025-12-08 05:51:55,039 [root] DEBUG: Trying to start auxiliary module "Screenshots"... 2025-12-08 05:51:55,039 [root] DEBUG: Started auxiliary module "Screenshots" 2025-12-08 05:51:55,039 [root] DEBUG: Initialized auxiliary module "Sysmon" 2025-12-08 05:51:55,039 [root] DEBUG: Trying to start auxiliary module "Sysmon"... 2025-12-08 05:51:55,052 [root] DEBUG: Started auxiliary module "Sysmon" 2025-12-08 05:51:55,052 [modules.auxiliary.tracee] INFO: docker start 2025-12-08 05:51:55,052 [root] DEBUG: Initialized auxiliary module "Docker" 2025-12-08 05:51:55,052 [root] DEBUG: Trying to start auxiliary module "Docker"... 2025-12-08 05:51:55,079 [modules.auxiliary.tracee] DEBUG: Starting docker container 2025-12-08 05:51:55,091 [modules.auxiliary.tracee] DEBUG: Attempt to remove Tracee container if it exists. 2025-12-08 05:51:55,091 [modules.auxiliary.tracee] DEBUG: sudo docker run --name tracee -d --pid=host --cgroupns=host --privileged -v /etc/os-release:/etc/os-release-host:ro -v /tmp7_5yn7x6/tracee-artifacts/:/tmp/tracee/out/host -v /var/run:/var/run:ro -v /tmp7_5yn7x6/modules/auxiliary/tracee:/policy aquasec/tracee:latest --output json --output option:parse-arguments,exec-env,exec-hash --policy /policy/policy.yml --cache cache-type=mem --cache mem-cache-size=1024 --capture bpf --capture module --capture write --signatures-dir=/policy/signatures --signatures-dir=./signatures 2025-12-08 05:51:55,317 [modules.auxiliary.tracee] DEBUG: Docker container started: b28f4776bc6b1056293688ce9296767adf7d2e3f59c2007e58b451931bd722ba 2025-12-08 05:51:55,319 [lib.common.results] INFO: File /bin/sh-shim size is 125688, Max size: 100000000 2025-12-08 05:52:05,334 [lib.common.results] INFO: File /tmp7_5yn7x6/tracee-artifacts/write.dev-14.inode-33363 size is 34, Max size: 100000000 2025-12-08 05:52:05,351 [modules.auxiliary.tracee] INFO: Try to stream 2025-12-08 05:52:05,352 [modules.auxiliary.tracee] INFO: <lib.common.results.NetlogFile object at 0x7fbe3d520ee0> 2025-12-08 05:52:05,353 [modules.auxiliary.tracee] INFO: Streamstart 2025-12-08 05:52:05,353 [root] DEBUG: Started auxiliary module "Docker" 2025-12-08 05:52:05,355 [lib.core.packages] INFO: sh -c 2025-12-08 05:52:05,356 [lib.core.packages] INFO: Process will start with strace + sh-shim for Tracee's scope 2025-12-08 05:52:05,356 [lib.core.packages] INFO: sudo strace -v -o /dev/stderr -s 800 -ttf /bin/sh-shim -c "sh -c /tmp/file" 2025-12-08 05:52:05,357 [lib.core.packages] INFO: Process started 2025-12-08 05:52:05,357 [root] INFO: Added new process to list with pid: 2173 2025-12-08 05:52:05,358 [root] INFO: New child process detected: 2175 2025-12-08 05:52:05,359 [root] ERROR: Could not read memory range 7f0538974000-7f0538982000: [Errno 5] Input/output error 2025-12-08 05:52:05,360 [root] ERROR: Could not read memory range 7ffe0ce98000-7ffe0ce9c000: [Errno 5] Input/output error 2025-12-08 05:52:05,360 [lib.common.results] INFO: File /tmp/eNwbVgsgtA/memory/2175.dmp size is 958464, Max size: 100000000 2025-12-08 05:52:05,365 [root] INFO: Added new process to list with pid: 2175 2025-12-08 05:52:05,538 [lib.common.results] INFO: File /tmp7_5yn7x6/diamorphine.ko size is 0, Max size: 100000000 2025-12-08 05:52:05,543 [lib.common.results] INFO: File /tmp7_5yn7x6/tracee-artifacts/write.dev-14.inode-26411 size is 16061, Max size: 100000000 2025-12-08 05:52:05,563 [lib.common.results] INFO: File /tmp7_5yn7x6/diamorphine.ko size is 4096, Max size: 100000000 2025-12-08 05:52:05,565 [lib.common.results] INFO: File /tmp7_5yn7x6/diamorphine.ko size is 8192, Max size: 100000000 2025-12-08 05:52:05,567 [lib.common.results] INFO: File /tmp7_5yn7x6/tracee-artifacts/write.dev-8388611.inode-2490508 size is 11888, Max size: 100000000 2025-12-08 05:52:05,611 [lib.common.results] INFO: File /tmp7_5yn7x6/tracee-artifacts/write.dev-14.inode-33385 size is 77, Max size: 100000000 2025-12-08 05:52:05,617 [root] INFO: New child process detected: 2176 2025-12-08 05:52:05,665 [root] ERROR: Could not read memory range 7fff967a9000-7fff967ad000: [Errno 5] Input/output error 2025-12-08 05:52:05,666 [lib.common.results] INFO: File /tmp/eNwbVgsgtA/memory/2176.dmp size is 19468288, Max size: 100000000 2025-12-08 05:52:05,747 [root] INFO: Added new process to list with pid: 2176 2025-12-08 05:52:05,747 [root] INFO: New child process detected: 2179 2025-12-08 05:52:05,750 [root] ERROR: Could not read memory range 7ffd105f0000-7ffd105f4000: [Errno 5] Input/output error 2025-12-08 05:52:05,750 [lib.common.results] INFO: File /tmp/eNwbVgsgtA/memory/2179.dmp size is 2523136, Max size: 100000000 2025-12-08 05:52:05,762 [root] INFO: Added new process to list with pid: 2179 2025-12-08 05:52:05,763 [root] INFO: New child process detected: 2180 2025-12-08 05:52:05,765 [root] ERROR: Could not read memory range 7ffc2d5f4000-7ffc2d5f8000: [Errno 5] Input/output error 2025-12-08 05:52:05,765 [lib.common.results] INFO: File /tmp/eNwbVgsgtA/memory/2180.dmp size is 2523136, Max size: 100000000 2025-12-08 05:52:05,778 [root] INFO: Added new process to list with pid: 2180 2025-12-08 05:52:05,778 [root] INFO: New child process detected: 2181 2025-12-08 05:52:05,780 [root] ERROR: Could not read memory range 7ffcfc93f000-7ffcfc943000: [Errno 5] Input/output error 2025-12-08 05:52:05,781 [lib.common.results] INFO: File /tmp/eNwbVgsgtA/memory/2181.dmp size is 2433024, Max size: 100000000 2025-12-08 05:52:05,793 [root] INFO: Added new process to list with pid: 2181 2025-12-08 05:52:05,793 [root] INFO: New child process detected: 2182 2025-12-08 05:52:05,795 [root] ERROR: Could not read memory range 7ffd4d52d000-7ffd4d531000: [Errno 5] Input/output error 2025-12-08 05:52:05,795 [lib.common.results] INFO: File /tmp/eNwbVgsgtA/memory/2182.dmp size is 2539520, Max size: 100000000 2025-12-08 05:52:05,808 [root] INFO: Added new process to list with pid: 2182 2025-12-08 05:52:05,808 [root] INFO: New child process detected: 2183 2025-12-08 05:52:05,835 [root] ERROR: Could not read memory range 7ffd26529000-7ffd2652d000: [Errno 5] Input/output error 2025-12-08 05:52:05,835 [lib.common.results] INFO: File /tmp/eNwbVgsgtA/memory/2183.dmp size is 17481728, Max size: 100000000 2025-12-08 05:52:05,909 [root] INFO: Added new process to list with pid: 2183 2025-12-08 05:52:06,160 [root] INFO: New child process detected: 2187 2025-12-08 05:52:06,178 [root] ERROR: Could not read memory range 7ffd2c7dd000-7ffd2c7e1000: [Errno 5] Input/output error 2025-12-08 05:52:06,178 [lib.common.results] INFO: File /tmp/eNwbVgsgtA/memory/2187.dmp size is 17014784, Max size: 100000000 2025-12-08 05:52:06,251 [root] INFO: Added new process to list with pid: 2187 2025-12-08 05:52:08,356 [modules.auxiliary.tracee] INFO: <lib.common.results.NetlogFile object at 0x7fbe3d520ee0> 2025-12-08 05:52:08,385 [modules.auxiliary.tracee] INFO: CONTAINER ID IMAGE COMMAND CREATED STATUS PORTS NAMES b28f4776bc6b aquasec/tracee:latest "/tracee/entrypoint.…" 13 seconds ago Up 13 seconds tracee 2025-12-08 05:52:08,407 [modules.auxiliary.tracee] INFO: sudo tail +1f /var/lib/docker/containers/b28f4776bc6b1056293688ce9296767adf7d2e3f59c2007e58b451931bd722ba/b28f4776bc6b1056293688ce9296767adf7d2e3f59c2007e58b451931bd722ba-json.log 2025-12-08 05:52:08,763 [root] INFO: New child process detected: 2208 2025-12-08 05:52:08,778 [root] ERROR: Could not read memory range 7ffecb56e000-7ffecb572000: [Errno 5] Input/output error 2025-12-08 05:52:08,780 [lib.common.results] INFO: File /tmp/eNwbVgsgtA/memory/2208.dmp size is 4304896, Max size: 100000000 2025-12-08 05:52:08,810 [root] INFO: Added new process to list with pid: 2208 2025-12-08 05:52:08,954 [lib.common.results] INFO: File /tmp7_5yn7x6/diamorphine-invisible.txt size is 3443, Max size: 100000000
| Name | Label | Manager | Started On | Shutdown On |
|---|---|---|---|---|
| ubuntu22.04-64bit-1 | ubuntu22.04-64bit-1 | KVM | 2025-12-08 13:55:52 | 2025-12-08 13:59:58 |
| File Name |
file
|
|---|---|
| File Type | ELF 64-bit LSB pie executable, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, BuildID[sha1]=93ec5a89bd51e49699d8943e8f18e1a98953e793, for GNU/Linux 3.2.0, not stripped |
| File Size | 33288 bytes |
| MD5 | ca881b8404292613c9c07a3cdcbd8d0d |
| SHA1 | 2972c0d4d86b797970050944fa23d444c6bc35c7 |
| SHA256 | f7ce60e49214f3d587e9ed26a1d3a9814552a9e00048f8c538d2cb91a46c1281 [VT] [MWDB] [Bazaar] |
| SHA3-384 | d51278a94f8cbdaa967255f12680948b424f3494bcda85c204bf862d29a02ec646ead53157c937e155f88238e3bb413d |
| CRC32 | 09450E13 |
| TLSH | T19BE2517741D5FEEACF281934804633308DBDBE474774C35ABB8438A927E72909E189B9 |
| Ssdeep | 384:f1EhUMkc0/QAJsDVX43eVUH7XAV6OcLyNDjRSqF9km:GhUMkc0oACDRO7XA9xjwKKm |
| File Strings BinGraph Vba2Graph |
No hosts contacted.
No domains contacted.
No hosts contacted.
No TCP connections recorded.
No UDP connections recorded.
No domains contacted.
No HTTP(s) requests performed.
No SMTP traffic performed.
No IRC requests performed.
No ICMP traffic performed.
No CIF Results
No Suricata Alerts
No Suricata TLS
No Suricata HTTP