Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
i686nk.elf

Overview

General Information

Sample name:i686nk.elf
Analysis ID:1496915
MD5:43c3861c22a3a5d97d57e8e866117fd9
SHA1:db8b737b7258bcf7be202b47a2d47742c13ec821
SHA256:9fdb4d24522d05aaa2064c1bc69887e1e45bae99f0563de4755b593bd18a0b6b
Tags:elf
Infos:

Detection

Mirai
Score:96
Range:0 - 100
Whitelisted:false

Signatures

Antivirus / Scanner detection for submitted sample
Detected Mirai
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Yara detected Mirai
Connects to many ports of the same IP (likely port scanning)
Contains symbols with names commonly found in malware
Machine Learning detection for sample
Sample deletes itself
Detected TCP or UDP traffic on non-standard ports

Classification

Joe Sandbox version:40.0.0 Tourmaline
Analysis ID:1496915
Start date and time:2024-08-21 21:12:23 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 34s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:i686nk.elf
Detection:MAL
Classification:mal96.troj.evad.linELF@0/0@5/0
  • VT rate limit hit for: i686nk.elf
Command:/tmp/i686nk.elf
PID:5808
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
listening to tun0
Standard Error:
  • system is lnxubuntu20
  • i686nk.elf (PID: 5808, Parent: 5733, MD5: 43c3861c22a3a5d97d57e8e866117fd9) Arguments: /tmp/i686nk.elf
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
MiraiMirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.mirai
SourceRuleDescriptionAuthorStrings
i686nk.elfJoeSecurity_Mirai_8Yara detected MiraiJoe Security
    Timestamp:2024-08-21T21:13:28.821695+0200
    SID:2030490
    Severity:1
    Source Port:50348
    Destination Port:51237
    Protocol:TCP
    Classtype:Malware Command and Control Activity Detected
    Timestamp:2024-08-21T21:15:10.226492+0200
    SID:2030490
    Severity:1
    Source Port:50356
    Destination Port:51237
    Protocol:TCP
    Classtype:Malware Command and Control Activity Detected
    Timestamp:2024-08-21T21:13:52.255977+0200
    SID:2030490
    Severity:1
    Source Port:50350
    Destination Port:51237
    Protocol:TCP
    Classtype:Malware Command and Control Activity Detected
    Timestamp:2024-08-21T21:14:44.049283+0200
    SID:2030490
    Severity:1
    Source Port:50354
    Destination Port:51237
    Protocol:TCP
    Classtype:Malware Command and Control Activity Detected
    Timestamp:2024-08-21T21:14:16.645310+0200
    SID:2030490
    Severity:1
    Source Port:50352
    Destination Port:51237
    Protocol:TCP
    Classtype:Malware Command and Control Activity Detected

    Click to jump to signature section

    Show All Signature Results

    AV Detection

    barindex
    Source: i686nk.elfAvira: detected
    Source: i686nk.elfReversingLabs: Detection: 55%
    Source: i686nk.elfJoe Sandbox ML: detected

    Networking

    barindex
    Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.15:50350 -> 185.196.9.5:51237
    Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.15:50348 -> 185.196.9.5:51237
    Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.15:50352 -> 185.196.9.5:51237
    Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.15:50354 -> 185.196.9.5:51237
    Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.15:50356 -> 185.196.9.5:51237
    Source: global trafficTCP traffic: 185.196.9.5 ports 1,2,3,5,7,51237
    Source: global trafficTCP traffic: 192.168.2.15:50348 -> 185.196.9.5:51237
    Source: global trafficDNS traffic detected: DNS query: fdh32fsdfhs.shop

    System Summary

    barindex
    Source: ELF static info symbol of initial sampleName: attack.c
    Source: ELF static info symbol of initial sampleName: attack_get_opt_int
    Source: ELF static info symbol of initial sampleName: attack_get_opt_ip
    Source: ELF static info symbol of initial sampleName: attack_get_opt_str
    Source: ELF static info symbol of initial sampleName: attack_init
    Source: ELF static info symbol of initial sampleName: attack_nudp
    Source: ELF static info symbol of initial sampleName: attack_parse
    Source: ELF static info symbol of initial sampleName: attack_start
    Source: ELF static info symbol of initial sampleName: attack_tcp_ack
    Source: ELF static info symbol of initial sampleName: attack_tcp_bypass
    Source: classification engineClassification label: mal96.troj.evad.linELF@0/0@5/0

    Hooking and other Techniques for Hiding and Protection

    barindex
    Source: /tmp/i686nk.elf (PID: 5808)File: /tmp/i686nk.elfJump to behavior

    Stealing of Sensitive Information

    barindex
    Source: Yara matchFile source: i686nk.elf, type: SAMPLE

    Remote Access Functionality

    barindex
    Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
    Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
    Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
    Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
    Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
    Source: Yara matchFile source: i686nk.elf, type: SAMPLE
    ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
    Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
    File Deletion
    OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
    Non-Standard Port
    Exfiltration Over Other Network MediumAbuse Accessibility Features
    CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
    Non-Application Layer Protocol
    Exfiltration Over BluetoothNetwork Denial of Service
    Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
    Application Layer Protocol
    Automated ExfiltrationData Encrypted for Impact
    No configs have been found
    Hide Legend

    Legend:

    • Process
    • Signature
    • Created File
    • DNS/IP Info
    • Is Dropped
    • Number of created Files
    • Is malicious
    • Internet
    SourceDetectionScannerLabelLink
    i686nk.elf55%ReversingLabsLinux.Trojan.Gafgyt
    i686nk.elf100%AviraEXP/ELF.Gafgyt.D
    i686nk.elf100%Joe Sandbox ML
    No Antivirus matches
    No Antivirus matches
    No Antivirus matches
    NameIPActiveMaliciousAntivirus DetectionReputation
    fdh32fsdfhs.shop
    185.196.9.5
    truetrue
      unknown
      • No. of IPs < 25%
      • 25% < No. of IPs < 50%
      • 50% < No. of IPs < 75%
      • 75% < No. of IPs
      IPDomainCountryFlagASNASN NameMalicious
      185.196.9.5
      fdh32fsdfhs.shopSwitzerland
      42624SIMPLECARRIERCHtrue
      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
      185.196.9.5mips.elfGet hashmaliciousMiraiBrowse
        mipsel.elfGet hashmaliciousMiraiBrowse
          mipselnk.elfGet hashmaliciousMiraiBrowse
            mipsnk.elfGet hashmaliciousMiraiBrowse
              x86_64.elfGet hashmaliciousMiraiBrowse
                arm6.elfGet hashmaliciousMiraiBrowse
                  arm.elfGet hashmaliciousMiraiBrowse
                    arm6nk.elfGet hashmaliciousMiraiBrowse
                      arm7.elfGet hashmaliciousMiraiBrowse
                        arm7nk.elfGet hashmaliciousMiraiBrowse
                          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                          fdh32fsdfhs.shopmips.elfGet hashmaliciousMiraiBrowse
                          • 185.196.9.5
                          mipsel.elfGet hashmaliciousMiraiBrowse
                          • 185.196.9.5
                          mipselnk.elfGet hashmaliciousMiraiBrowse
                          • 185.196.9.5
                          mipsnk.elfGet hashmaliciousMiraiBrowse
                          • 185.196.9.5
                          x86_64.elfGet hashmaliciousMiraiBrowse
                          • 185.196.9.5
                          arm6.elfGet hashmaliciousMiraiBrowse
                          • 185.196.9.5
                          arm.elfGet hashmaliciousMiraiBrowse
                          • 185.196.9.5
                          arm6nk.elfGet hashmaliciousMiraiBrowse
                          • 185.196.9.5
                          arm7.elfGet hashmaliciousMiraiBrowse
                          • 185.196.9.5
                          arm7nk.elfGet hashmaliciousMiraiBrowse
                          • 185.196.9.5
                          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                          SIMPLECARRIERCHmips.elfGet hashmaliciousMiraiBrowse
                          • 185.196.9.5
                          mipsel.elfGet hashmaliciousMiraiBrowse
                          • 185.196.9.5
                          mipselnk.elfGet hashmaliciousMiraiBrowse
                          • 185.196.9.5
                          mipsnk.elfGet hashmaliciousMiraiBrowse
                          • 185.196.9.5
                          x86_64.elfGet hashmaliciousMiraiBrowse
                          • 185.196.9.5
                          arm6.elfGet hashmaliciousMiraiBrowse
                          • 185.196.9.5
                          arm.elfGet hashmaliciousMiraiBrowse
                          • 185.196.9.5
                          arm6nk.elfGet hashmaliciousMiraiBrowse
                          • 185.196.9.5
                          arm7.elfGet hashmaliciousMiraiBrowse
                          • 185.196.9.5
                          arm7nk.elfGet hashmaliciousMiraiBrowse
                          • 185.196.9.5
                          No context
                          No context
                          No created / dropped files found
                          File type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, not stripped
                          Entropy (8bit):6.1919325421782165
                          TrID:
                          • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
                          • ELF Executable and Linkable format (generic) (4004/1) 49.84%
                          File name:i686nk.elf
                          File size:81'891 bytes
                          MD5:43c3861c22a3a5d97d57e8e866117fd9
                          SHA1:db8b737b7258bcf7be202b47a2d47742c13ec821
                          SHA256:9fdb4d24522d05aaa2064c1bc69887e1e45bae99f0563de4755b593bd18a0b6b
                          SHA512:e312a7b3339ff6f45d99e98de854a589124bfb2dc525a5739f876ded503836ac548611b5703139d8768a10dce990b88df92c2ab918921934ea00a2ee10db3e1a
                          SSDEEP:1536:QocpSwIUC+A2QDjGy4Tsqm5AA1KddpUQOlFNpogIM2:QocpSwIUCNray44P5ALXmQsNpoj
                          TLSH:B58328C8D613D5B7DD870E380593F63F4631E8218F6ECD86EB686FA0DA434A5344A726
                          File Content Preview:.ELF........................4...........4. ...(.....................t...t...............t...tu..tu..|...,8...................z...z..................Q.td............................U..S............h........[]...$.............U......=.}...t..1.....z......z.

                          ELF header

                          Class:ELF32
                          Data:2's complement, little endian
                          Version:1 (current)
                          Machine:Intel 80386
                          Version Number:0x1
                          Type:EXEC (Executable file)
                          OS/ABI:UNIX - System V
                          ABI Version:0
                          Entry Point Address:0x8048188
                          Flags:0x0
                          ELF Header Size:52
                          Program Header Offset:52
                          Program Header Size:32
                          Number of Program Headers:4
                          Section Header Offset:63404
                          Section Header Size:40
                          Number of Section Headers:19
                          Header String Table Index:16
                          NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                          NULL0x00x00x00x00x0000
                          .initPROGBITS0x80480b40xb40x1c0x00x6AX001
                          .textPROGBITS0x80480d00xd00xcac90x00x6AX0016
                          .finiPROGBITS0x8054b990xcb990x170x00x6AX001
                          .rodataPROGBITS0x8054bc00xcbc00x19b40x00x2A0032
                          .eh_framePROGBITS0x80575740xe5740x5500x00x3WA004
                          .tbssNOBITS0x8057ac40xeac40x80x00x403WAT004
                          .ctorsPROGBITS0x8057ac40xeac40x80x00x3WA004
                          .dtorsPROGBITS0x8057acc0xeacc0x80x00x3WA004
                          .jcrPROGBITS0x8057ad40xead40x40x00x3WA004
                          .got.pltPROGBITS0x8057ad80xead80xc0x40x3WA004
                          .dataPROGBITS0x8057ae40xeae40x20c0x00x3WA004
                          .bssNOBITS0x8057d000xecf00x30a00x00x3WA0032
                          .stabPROGBITS0x00xecf00xfc0xc0x01404
                          .stabstrSTRTAB0x00xedec0xdb0x00x0001
                          .commentPROGBITS0x00xeec70x85e0x00x0001
                          .shstrtabSTRTAB0x00xf7250x840x00x0001
                          .symtabSYMTAB0x00xfaa40x27b00x100x0182354
                          .strtabSTRTAB0x00x122540x1d8f0x00x0001
                          TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                          LOAD0x00x80480000x80480000xe5740xe5746.21180x5R E0x1000.init .text .fini .rodata
                          LOAD0xe5740x80575740x80575740x77c0x382c4.67870x6RW 0x1000.eh_frame .tbss .ctors .dtors .jcr .got.plt .data .bss
                          TLS0xeac40x8057ac40x8057ac40x00x80.00000x4R 0x4.tbss
                          GNU_STACK0x00x00x00x00x00.00000x6RW 0x4
                          NameVersion Info NameVersion Info File NameSection NameValueSizeSymbol TypeSymbol BindSymbol VisibilityNdx
                          .symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                          .symtab0x80480b40SECTION<unknown>DEFAULT1
                          .symtab0x80480d00SECTION<unknown>DEFAULT2
                          .symtab0x8054b990SECTION<unknown>DEFAULT3
                          .symtab0x8054bc00SECTION<unknown>DEFAULT4
                          .symtab0x80575740SECTION<unknown>DEFAULT5
                          .symtab0x8057ac40SECTION<unknown>DEFAULT6
                          .symtab0x8057ac40SECTION<unknown>DEFAULT7
                          .symtab0x8057acc0SECTION<unknown>DEFAULT8
                          .symtab0x8057ad40SECTION<unknown>DEFAULT9
                          .symtab0x8057ad80SECTION<unknown>DEFAULT10
                          .symtab0x8057ae40SECTION<unknown>DEFAULT11
                          .symtab0x8057d000SECTION<unknown>DEFAULT12
                          .symtab0x00SECTION<unknown>DEFAULT13
                          .symtab0x00SECTION<unknown>DEFAULT14
                          .symtab0x00SECTION<unknown>DEFAULT15
                          C.11.5298.symtab0x8055e4024OBJECT<unknown>DEFAULT4
                          C.112.6576.symtab0x80557c0248OBJECT<unknown>DEFAULT4
                          C.115.6699.symtab0x80553c01024OBJECT<unknown>DEFAULT4
                          C.118.6822.symtab0x80552a0284OBJECT<unknown>DEFAULT4
                          LOCAL_ADDR.symtab0x805a7fc4OBJECT<unknown>DEFAULT12
                          POPBX1.symtab0x805292f0NOTYPE<unknown>DEFAULT2
                          POPBX1.symtab0x805298f0NOTYPE<unknown>DEFAULT2
                          POPBX1.symtab0x80529ef0NOTYPE<unknown>DEFAULT2
                          PUSHBX1.symtab0x805291b0NOTYPE<unknown>DEFAULT2
                          PUSHBX1.symtab0x805297b0NOTYPE<unknown>DEFAULT2
                          PUSHBX1.symtab0x80529db0NOTYPE<unknown>DEFAULT2
                          RESTBX1.symtab0x80528d90NOTYPE<unknown>DEFAULT2
                          SAVEBX1.symtab0x80528cc0NOTYPE<unknown>DEFAULT2
                          _Exit.symtab0x8052f4866FUNC<unknown>DEFAULT2
                          _GLOBAL_OFFSET_TABLE_.symtab0x8057ad80OBJECT<unknown>HIDDEN10
                          _Jv_RegisterClasses.symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                          _L_lock_103.symtab0x805385116FUNC<unknown>DEFAULT2
                          _L_lock_13.symtab0x805413d16FUNC<unknown>DEFAULT2
                          _L_lock_144.symtab0x805417d16FUNC<unknown>DEFAULT2
                          _L_lock_164.symtab0x805419d16FUNC<unknown>DEFAULT2
                          _L_lock_18.symtab0x805381713FUNC<unknown>DEFAULT2
                          _L_lock_18.symtab0x8053e0710FUNC<unknown>DEFAULT2
                          _L_lock_195.symtab0x80541bd13FUNC<unknown>DEFAULT2
                          _L_lock_205.symtab0x8053b4316FUNC<unknown>DEFAULT2
                          _L_lock_216.symtab0x8053b5316FUNC<unknown>DEFAULT2
                          _L_lock_30.symtab0x805414d16FUNC<unknown>DEFAULT2
                          _L_lock_35.symtab0x8053d7510FUNC<unknown>DEFAULT2
                          _L_lock_53.symtab0x805382416FUNC<unknown>DEFAULT2
                          _L_lock_70.symtab0x805272c16FUNC<unknown>DEFAULT2
                          _L_unlock_104.symtab0x805416d16FUNC<unknown>DEFAULT2
                          _L_unlock_113.symtab0x805386113FUNC<unknown>DEFAULT2
                          _L_unlock_156.symtab0x805418d16FUNC<unknown>DEFAULT2
                          _L_unlock_167.symtab0x805273c13FUNC<unknown>DEFAULT2
                          _L_unlock_174.symtab0x80541ad16FUNC<unknown>DEFAULT2
                          _L_unlock_232.symtab0x8053b6313FUNC<unknown>DEFAULT2
                          _L_unlock_239.symtab0x80541ca13FUNC<unknown>DEFAULT2
                          _L_unlock_242.symtab0x8053b7013FUNC<unknown>DEFAULT2
                          _L_unlock_43.symtab0x8053e1110FUNC<unknown>DEFAULT2
                          _L_unlock_65.symtab0x805383416FUNC<unknown>DEFAULT2
                          _L_unlock_65.symtab0x8053d7f10FUNC<unknown>DEFAULT2
                          _L_unlock_82.symtab0x805384413FUNC<unknown>DEFAULT2
                          _L_unlock_88.symtab0x805415d16FUNC<unknown>DEFAULT2
                          _READ.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          _WRITE.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          __CTOR_END__.symtab0x8057ac80OBJECT<unknown>DEFAULT7
                          __CTOR_LIST__.symtab0x8057ac40OBJECT<unknown>DEFAULT7
                          __C_ctype_b.symtab0x8057c004OBJECT<unknown>DEFAULT11
                          __C_ctype_b.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          __C_ctype_b_data.symtab0x8056274768OBJECT<unknown>DEFAULT4
                          __DTOR_END__.symtab0x8057ad00OBJECT<unknown>DEFAULT8
                          __DTOR_LIST__.symtab0x8057acc0OBJECT<unknown>DEFAULT8
                          __EH_FRAME_BEGIN__.symtab0x80575740OBJECT<unknown>DEFAULT5
                          __FRAME_END__.symtab0x8057ac00OBJECT<unknown>DEFAULT5
                          __GI___C_ctype_b.symtab0x8057c004OBJECT<unknown>HIDDEN11
                          __GI___close.symtab0x80528c080FUNC<unknown>HIDDEN2
                          __GI___close_nocancel.symtab0x80528ca27FUNC<unknown>HIDDEN2
                          __GI___ctype_b.symtab0x8057c044OBJECT<unknown>HIDDEN11
                          __GI___errno_location.symtab0x80507fc13FUNC<unknown>HIDDEN2
                          __GI___fcntl_nocancel.symtab0x805017c86FUNC<unknown>HIDDEN2
                          __GI___fgetc_unlocked.symtab0x80541d8220FUNC<unknown>HIDDEN2
                          __GI___libc_close.symtab0x80528c080FUNC<unknown>HIDDEN2
                          __GI___libc_fcntl.symtab0x80501d2156FUNC<unknown>HIDDEN2
                          __GI___libc_open.symtab0x805291091FUNC<unknown>HIDDEN2
                          __GI___libc_read.symtab0x80529d091FUNC<unknown>HIDDEN2
                          __GI___libc_write.symtab0x805297091FUNC<unknown>HIDDEN2
                          __GI___open.symtab0x805291091FUNC<unknown>HIDDEN2
                          __GI___open_nocancel.symtab0x805291a33FUNC<unknown>HIDDEN2
                          __GI___read.symtab0x80529d091FUNC<unknown>HIDDEN2
                          __GI___read_nocancel.symtab0x80529da33FUNC<unknown>HIDDEN2
                          __GI___sigaddset.symtab0x8050d4032FUNC<unknown>HIDDEN2
                          __GI___sigdelset.symtab0x8050d6032FUNC<unknown>HIDDEN2
                          __GI___sigismember.symtab0x8050d1c36FUNC<unknown>HIDDEN2
                          __GI___uClibc_fini.symtab0x8052b0763FUNC<unknown>HIDDEN2
                          __GI___uClibc_init.symtab0x8052b7a48FUNC<unknown>HIDDEN2
                          __GI___write.symtab0x805297091FUNC<unknown>HIDDEN2
                          __GI___write_nocancel.symtab0x805297a33FUNC<unknown>HIDDEN2
                          __GI__exit.symtab0x8052f4866FUNC<unknown>HIDDEN2
                          __GI_abort.symtab0x8051d60208FUNC<unknown>HIDDEN2
                          __GI_accept.symtab0x80508cc91FUNC<unknown>HIDDEN2
                          __GI_bind.symtab0x805092843FUNC<unknown>HIDDEN2
                          __GI_brk.symtab0x8052e0844FUNC<unknown>HIDDEN2
                          __GI_close.symtab0x80528c080FUNC<unknown>HIDDEN2
                          __GI_closedir.symtab0x805055c138FUNC<unknown>HIDDEN2
                          __GI_config_close.symtab0x805361361FUNC<unknown>HIDDEN2
                          __GI_config_open.symtab0x805365053FUNC<unknown>HIDDEN2
                          __GI_config_read.symtab0x8053384655FUNC<unknown>HIDDEN2
                          __GI_connect.symtab0x805095491FUNC<unknown>HIDDEN2
                          __GI_exit.symtab0x80521b8106FUNC<unknown>HIDDEN2
                          __GI_fclose.symtab0x8053688399FUNC<unknown>HIDDEN2
                          __GI_fcntl.symtab0x80501d2156FUNC<unknown>HIDDEN2
                          __GI_fflush_unlocked.symtab0x8053f65472FUNC<unknown>HIDDEN2
                          __GI_fgetc.symtab0x8053cd8157FUNC<unknown>HIDDEN2
                          __GI_fgetc_unlocked.symtab0x80541d8220FUNC<unknown>HIDDEN2
                          __GI_fgets.symtab0x8053d8c123FUNC<unknown>HIDDEN2
                          __GI_fgets_unlocked.symtab0x80542b4107FUNC<unknown>HIDDEN2
                          __GI_fopen.symtab0x805387024FUNC<unknown>HIDDEN2
                          __GI_fork.symtab0x8052520524FUNC<unknown>HIDDEN2
                          __GI_fstat.symtab0x8052f8c75FUNC<unknown>HIDDEN2
                          __GI_getc_unlocked.symtab0x80541d8220FUNC<unknown>HIDDEN2
                          __GI_getdtablesize.symtab0x805306437FUNC<unknown>HIDDEN2
                          __GI_getegid.symtab0x805308c8FUNC<unknown>HIDDEN2
                          __GI_geteuid.symtab0x80530948FUNC<unknown>HIDDEN2
                          __GI_getgid.symtab0x805309c8FUNC<unknown>HIDDEN2
                          __GI_getpagesize.symtab0x80530a417FUNC<unknown>HIDDEN2
                          __GI_getpid.symtab0x805274c49FUNC<unknown>HIDDEN2
                          __GI_getrlimit.symtab0x80530b843FUNC<unknown>HIDDEN2
                          __GI_getsockname.symtab0x80509b043FUNC<unknown>HIDDEN2
                          __GI_getuid.symtab0x80530e48FUNC<unknown>HIDDEN2
                          __GI_inet_addr.symtab0x80508a437FUNC<unknown>HIDDEN2
                          __GI_inet_aton.symtab0x80544a0148FUNC<unknown>HIDDEN2
                          __GI_initstate_r.symtab0x805207a155FUNC<unknown>HIDDEN2
                          __GI_ioctl.symtab0x8050278142FUNC<unknown>HIDDEN2
                          __GI_isatty.symtab0x805441c29FUNC<unknown>HIDDEN2
                          __GI_kill.symtab0x805030843FUNC<unknown>HIDDEN2
                          __GI_listen.symtab0x8050a1835FUNC<unknown>HIDDEN2
                          __GI_lseek64.symtab0x8054b1885FUNC<unknown>HIDDEN2
                          __GI_memcpy.symtab0x805083041FUNC<unknown>HIDDEN2
                          __GI_memmove.symtab0x805432037FUNC<unknown>HIDDEN2
                          __GI_mempcpy.symtab0x8054af433FUNC<unknown>HIDDEN2
                          __GI_memset.symtab0x805085c50FUNC<unknown>HIDDEN2
                          __GI_mmap.symtab0x8052ec827FUNC<unknown>HIDDEN2
                          __GI_mremap.symtab0x80530ec59FUNC<unknown>HIDDEN2
                          __GI_munmap.symtab0x805312843FUNC<unknown>HIDDEN2
                          __GI_nanosleep.symtab0x805317d61FUNC<unknown>HIDDEN2
                          __GI_open.symtab0x805291091FUNC<unknown>HIDDEN2
                          __GI_opendir.symtab0x805067a137FUNC<unknown>HIDDEN2
                          __GI_raise.symtab0x8052780101FUNC<unknown>HIDDEN2
                          __GI_random.symtab0x8051e3872FUNC<unknown>HIDDEN2
                          __GI_random_r.symtab0x8051f7494FUNC<unknown>HIDDEN2
                          __GI_read.symtab0x80529d091FUNC<unknown>HIDDEN2
                          __GI_readdir.symtab0x8050778132FUNC<unknown>HIDDEN2
                          __GI_readdir64.symtab0x80532fc134FUNC<unknown>HIDDEN2
                          __GI_readlink.symtab0x805037047FUNC<unknown>HIDDEN2
                          __GI_recv.symtab0x8050a3c99FUNC<unknown>HIDDEN2
                          __GI_recvfrom.symtab0x8050aa0115FUNC<unknown>HIDDEN2
                          __GI_sbrk.symtab0x80503a078FUNC<unknown>HIDDEN2
                          __GI_select.symtab0x8050429113FUNC<unknown>HIDDEN2
                          __GI_send.symtab0x8050b1499FUNC<unknown>HIDDEN2
                          __GI_sendto.symtab0x8050b78115FUNC<unknown>HIDDEN2
                          __GI_setsid.symtab0x805049c31FUNC<unknown>HIDDEN2
                          __GI_setsockopt.symtab0x8050bec59FUNC<unknown>HIDDEN2
                          __GI_setstate_r.symtab0x8052115161FUNC<unknown>HIDDEN2
                          __GI_sigaction.symtab0x8052e5381FUNC<unknown>HIDDEN2
                          __GI_sigaddset.symtab0x8050c5434FUNC<unknown>HIDDEN2
                          __GI_sigemptyset.symtab0x8050c7820FUNC<unknown>HIDDEN2
                          __GI_signal.symtab0x8050c8c143FUNC<unknown>HIDDEN2
                          __GI_sigprocmask.symtab0x80504bc101FUNC<unknown>HIDDEN2
                          __GI_sleep.symtab0x80527e8204FUNC<unknown>HIDDEN2
                          __GI_socket.symtab0x8050c2843FUNC<unknown>HIDDEN2
                          __GI_srandom_r.symtab0x8051fd2168FUNC<unknown>HIDDEN2
                          __GI_strchr.symtab0x805434830FUNC<unknown>HIDDEN2
                          __GI_strchrnul.symtab0x805436825FUNC<unknown>HIDDEN2
                          __GI_strcmp.symtab0x805438429FUNC<unknown>HIDDEN2
                          __GI_strcoll.symtab0x805438429FUNC<unknown>HIDDEN2
                          __GI_strcspn.symtab0x80543c048FUNC<unknown>HIDDEN2
                          __GI_strlen.symtab0x805089019FUNC<unknown>HIDDEN2
                          __GI_strrchr.symtab0x80543a426FUNC<unknown>HIDDEN2
                          __GI_strspn.symtab0x80543f042FUNC<unknown>HIDDEN2
                          __GI_sysconf.symtab0x8052301543FUNC<unknown>HIDDEN2
                          __GI_tcgetattr.symtab0x805443c99FUNC<unknown>HIDDEN2
                          __GI_time.symtab0x805052416FUNC<unknown>HIDDEN2
                          __GI_times.symtab0x80531bc16FUNC<unknown>HIDDEN2
                          __GI_unlink.symtab0x805053439FUNC<unknown>HIDDEN2
                          __GI_write.symtab0x805297091FUNC<unknown>HIDDEN2
                          __JCR_END__.symtab0x8057ad40OBJECT<unknown>DEFAULT9
                          __JCR_LIST__.symtab0x8057ad40OBJECT<unknown>DEFAULT9
                          __app_fini.symtab0x80582944OBJECT<unknown>HIDDEN12
                          __atexit_lock.symtab0x8057bdc24OBJECT<unknown>DEFAULT11
                          __bss_start.symtab0x8057cf00NOTYPE<unknown>DEFAULTSHN_ABS
                          __check_one_fd.symtab0x8052b4652FUNC<unknown>DEFAULT2
                          __close.symtab0x80528c080FUNC<unknown>DEFAULT2
                          __close_nocancel.symtab0x80528ca27FUNC<unknown>DEFAULT2
                          __ctype_b.symtab0x8057c044OBJECT<unknown>DEFAULT11
                          __curbrk.symtab0x805829c4OBJECT<unknown>HIDDEN12
                          __deregister_frame_info_bases.symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                          __do_global_ctors_aux.symtab0x8054b700FUNC<unknown>DEFAULT2
                          __do_global_dtors_aux.symtab0x80480e00FUNC<unknown>DEFAULT2
                          __dso_handle.symtab0x8057ae40OBJECT<unknown>HIDDEN11
                          __environ.symtab0x805828c4OBJECT<unknown>DEFAULT12
                          __errno_location.symtab0x80507fc13FUNC<unknown>DEFAULT2
                          __errno_location.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          __exit_cleanup.symtab0x8057d3c4OBJECT<unknown>HIDDEN12
                          __fcntl_nocancel.symtab0x805017c86FUNC<unknown>DEFAULT2
                          __fgetc_unlocked.symtab0x80541d8220FUNC<unknown>DEFAULT2
                          __fini_array_end.symtab0x8057ac40NOTYPE<unknown>HIDDEN6
                          __fini_array_start.symtab0x8057ac40NOTYPE<unknown>HIDDEN6
                          __fork.symtab0x8052520524FUNC<unknown>DEFAULT2
                          __fork_generation_pointer.symtab0x805ad704OBJECT<unknown>HIDDEN12
                          __fork_handlers.symtab0x805ad744OBJECT<unknown>HIDDEN12
                          __fork_lock.symtab0x8057d404OBJECT<unknown>HIDDEN12
                          __get_pc_thunk_bx.symtab0x80480d00FUNC<unknown>HIDDEN2
                          __getdents.symtab0x8052fd8137FUNC<unknown>HIDDEN2
                          __getdents64.symtab0x805485c281FUNC<unknown>HIDDEN2
                          __getpagesize.symtab0x80530a417FUNC<unknown>DEFAULT2
                          __getpid.symtab0x805274c49FUNC<unknown>DEFAULT2
                          __h_errno_location.symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                          __init_array_end.symtab0x8057ac40NOTYPE<unknown>HIDDEN6
                          __init_array_start.symtab0x8057ac40NOTYPE<unknown>HIDDEN6
                          __libc_accept.symtab0x80508cc91FUNC<unknown>DEFAULT2
                          __libc_close.symtab0x80528c080FUNC<unknown>DEFAULT2
                          __libc_connect.symtab0x805095491FUNC<unknown>DEFAULT2
                          __libc_disable_asynccancel.symtab0x8052a2c86FUNC<unknown>HIDDEN2
                          __libc_enable_asynccancel.symtab0x8052a8284FUNC<unknown>HIDDEN2
                          __libc_errno.symtab0x04TLS<unknown>HIDDEN6
                          __libc_fcntl.symtab0x80501d2156FUNC<unknown>DEFAULT2
                          __libc_fork.symtab0x8052520524FUNC<unknown>DEFAULT2
                          __libc_h_errno.symtab0x44TLS<unknown>HIDDEN6
                          __libc_nanosleep.symtab0x805317d61FUNC<unknown>DEFAULT2
                          __libc_open.symtab0x805291091FUNC<unknown>DEFAULT2
                          __libc_read.symtab0x80529d091FUNC<unknown>DEFAULT2
                          __libc_recv.symtab0x8050a3c99FUNC<unknown>DEFAULT2
                          __libc_recvfrom.symtab0x8050aa0115FUNC<unknown>DEFAULT2
                          __libc_select.symtab0x8050429113FUNC<unknown>DEFAULT2
                          __libc_send.symtab0x8050b1499FUNC<unknown>DEFAULT2
                          __libc_sendto.symtab0x8050b78115FUNC<unknown>DEFAULT2
                          __libc_setup_tls.symtab0x80545ea512FUNC<unknown>DEFAULT2
                          __libc_sigaction.symtab0x8052e5381FUNC<unknown>DEFAULT2
                          __libc_stack_end.symtab0x80582884OBJECT<unknown>DEFAULT12
                          __libc_write.symtab0x805297091FUNC<unknown>DEFAULT2
                          __lll_lock_wait_private.symtab0x805454040FUNC<unknown>HIDDEN2
                          __lll_unlock_wake_private.symtab0x805457032FUNC<unknown>HIDDEN2
                          __malloc_consolidate.symtab0x8051a1d386FUNC<unknown>HIDDEN2
                          __malloc_largebin_index.symtab0x8050d8038FUNC<unknown>DEFAULT2
                          __malloc_lock.symtab0x8057b0024OBJECT<unknown>DEFAULT11
                          __malloc_state.symtab0x805a9f8888OBJECT<unknown>DEFAULT12
                          __malloc_trim.symtab0x8051990141FUNC<unknown>DEFAULT2
                          __nptl_deallocate_tsd.symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                          __nptl_nthreads.symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                          __open.symtab0x805291091FUNC<unknown>DEFAULT2
                          __open_nocancel.symtab0x805291a33FUNC<unknown>DEFAULT2
                          __pagesize.symtab0x80582904OBJECT<unknown>DEFAULT12
                          __preinit_array_end.symtab0x8057ac40NOTYPE<unknown>HIDDEN6
                          __preinit_array_start.symtab0x8057ac40NOTYPE<unknown>HIDDEN6
                          __progname.symtab0x8057bf84OBJECT<unknown>DEFAULT11
                          __progname_full.symtab0x8057bfc4OBJECT<unknown>DEFAULT11
                          __pthread_initialize_minimal.symtab0x80547ea19FUNC<unknown>DEFAULT2
                          __pthread_mutex_init.symtab0x8052adb3FUNC<unknown>DEFAULT2
                          __pthread_mutex_lock.symtab0x8052ad83FUNC<unknown>DEFAULT2
                          __pthread_mutex_trylock.symtab0x8052ad83FUNC<unknown>DEFAULT2
                          __pthread_mutex_unlock.symtab0x8052ad83FUNC<unknown>DEFAULT2
                          __pthread_return_0.symtab0x8052ad83FUNC<unknown>DEFAULT2
                          __pthread_unwind.symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                          __read.symtab0x80529d091FUNC<unknown>DEFAULT2
                          __read_nocancel.symtab0x80529da33FUNC<unknown>DEFAULT2
                          __register_frame_info_bases.symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                          __restore.symtab0x8052e4b0NOTYPE<unknown>DEFAULT2
                          __restore_rt.symtab0x8052e440NOTYPE<unknown>DEFAULT2
                          __rtld_fini.symtab0x80582984OBJECT<unknown>HIDDEN12
                          __sigaddset.symtab0x8050d4032FUNC<unknown>DEFAULT2
                          __sigdelset.symtab0x8050d6032FUNC<unknown>DEFAULT2
                          __sigismember.symtab0x8050d1c36FUNC<unknown>DEFAULT2
                          __socketcall.symtab0x8052ee443FUNC<unknown>HIDDEN2
                          __socketcall.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          __stdin.symtab0x8057c144OBJECT<unknown>DEFAULT11
                          __stdio_READ.symtab0x805497879FUNC<unknown>HIDDEN2
                          __stdio_WRITE.symtab0x80549c8146FUNC<unknown>HIDDEN2
                          __stdio_rfill.symtab0x8054a5c40FUNC<unknown>HIDDEN2
                          __stdio_trans2r_o.symtab0x8054a84111FUNC<unknown>HIDDEN2
                          __stdio_wcommit.symtab0x8053cac43FUNC<unknown>HIDDEN2
                          __stdout.symtab0x8057c184OBJECT<unknown>DEFAULT11
                          __syscall_error.symtab0x8052e3415FUNC<unknown>HIDDEN2
                          __syscall_error.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          __syscall_fcntl.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          __syscall_nanosleep.symtab0x805315441FUNC<unknown>DEFAULT2
                          __syscall_rt_sigaction.symtab0x8052f1053FUNC<unknown>DEFAULT2
                          __syscall_rt_sigaction.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          __syscall_select.symtab0x80503f057FUNC<unknown>DEFAULT2
                          __uClibc_fini.symtab0x8052b0763FUNC<unknown>DEFAULT2
                          __uClibc_init.symtab0x8052b7a48FUNC<unknown>DEFAULT2
                          __uClibc_main.symtab0x8052baa603FUNC<unknown>DEFAULT2
                          __uClibc_main.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          __uclibc_progname.symtab0x8057bf44OBJECT<unknown>HIDDEN11
                          __write.symtab0x805297091FUNC<unknown>DEFAULT2
                          __write_nocancel.symtab0x805297a33FUNC<unknown>DEFAULT2
                          __xstat32_conv.symtab0x805326f138FUNC<unknown>HIDDEN2
                          __xstat64_conv.symtab0x80531cc163FUNC<unknown>HIDDEN2
                          _dl_aux_init.symtab0x805480018FUNC<unknown>DEFAULT2
                          _dl_nothread_init_static_tls.symtab0x805481274FUNC<unknown>HIDDEN2
                          _dl_phdr.symtab0x805ad984OBJECT<unknown>DEFAULT12
                          _dl_phnum.symtab0x805ad9c4OBJECT<unknown>DEFAULT12
                          _dl_tls_dtv_gaps.symtab0x805ad8c1OBJECT<unknown>DEFAULT12
                          _dl_tls_dtv_slotinfo_list.symtab0x805ad884OBJECT<unknown>DEFAULT12
                          _dl_tls_generation.symtab0x805ad904OBJECT<unknown>DEFAULT12
                          _dl_tls_max_dtv_idx.symtab0x805ad804OBJECT<unknown>DEFAULT12
                          _dl_tls_setup.symtab0x80545ba48FUNC<unknown>DEFAULT2
                          _dl_tls_static_align.symtab0x805ad7c4OBJECT<unknown>DEFAULT12
                          _dl_tls_static_nelem.symtab0x805ad944OBJECT<unknown>DEFAULT12
                          _dl_tls_static_size.symtab0x805ad844OBJECT<unknown>DEFAULT12
                          _dl_tls_static_used.symtab0x805ad784OBJECT<unknown>DEFAULT12
                          _edata.symtab0x8057cf00NOTYPE<unknown>DEFAULTSHN_ABS
                          _end.symtab0x805ada00NOTYPE<unknown>DEFAULTSHN_ABS
                          _exit.symtab0x8052f4866FUNC<unknown>DEFAULT2
                          _exit.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          _fini.symtab0x8054b990FUNC<unknown>DEFAULT3
                          _fixed_buffers.symtab0x80582c08192OBJECT<unknown>DEFAULT12
                          _fopen.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          _init.symtab0x80480b40FUNC<unknown>DEFAULT1
                          _pthread_cleanup_pop_restore.symtab0x8052af023FUNC<unknown>DEFAULT2
                          _pthread_cleanup_push_defer.symtab0x8052ade18FUNC<unknown>DEFAULT2
                          _rfill.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          _setjmp.symtab0x8052ea434FUNC<unknown>DEFAULT2
                          _sigintr.symtab0x805a9f08OBJECT<unknown>HIDDEN12
                          _start.symtab0x804818834FUNC<unknown>DEFAULT2
                          _stdio.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          _stdio_fopen.symtab0x8053888699FUNC<unknown>HIDDEN2
                          _stdio_init.symtab0x8053b8080FUNC<unknown>HIDDEN2
                          _stdio_openlist.symtab0x8057c1c4OBJECT<unknown>DEFAULT11
                          _stdio_openlist_add_lock.symtab0x80582a012OBJECT<unknown>DEFAULT12
                          _stdio_openlist_dec_use.symtab0x8053e1c329FUNC<unknown>HIDDEN2
                          _stdio_openlist_del_count.symtab0x80582bc4OBJECT<unknown>DEFAULT12
                          _stdio_openlist_del_lock.symtab0x80582ac12OBJECT<unknown>DEFAULT12
                          _stdio_openlist_use_count.symtab0x80582b84OBJECT<unknown>DEFAULT12
                          _stdio_streams.symtab0x8057c24204OBJECT<unknown>DEFAULT11
                          _stdio_term.symtab0x8053bd0218FUNC<unknown>HIDDEN2
                          _stdio_user_locking.symtab0x8057c204OBJECT<unknown>DEFAULT11
                          _trans2r.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          _wcommit.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          abort.symtab0x8051d60208FUNC<unknown>DEFAULT2
                          abort.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          accept.symtab0x80508cc91FUNC<unknown>DEFAULT2
                          accept.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          anti_gdb_entry.symtab0x804dfd011FUNC<unknown>DEFAULT2
                          attack.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          attack_get_opt_int.symtab0x80485b0120FUNC<unknown>DEFAULT2
                          attack_get_opt_ip.symtab0x8048540112FUNC<unknown>DEFAULT2
                          attack_get_opt_str.symtab0x80481b092FUNC<unknown>DEFAULT2
                          attack_init.symtab0x80486301274FUNC<unknown>DEFAULT2
                          attack_nudp.symtab0x804d0701856FUNC<unknown>DEFAULT2
                          attack_parse.symtab0x80482e0602FUNC<unknown>DEFAULT2
                          attack_start.symtab0x8048210208FUNC<unknown>DEFAULT2
                          attack_tcp_ack.symtab0x804ae801797FUNC<unknown>DEFAULT2
                          attack_tcp_bypass.symtab0x804c520912FUNC<unknown>DEFAULT2
                          attack_tcp_psh.symtab0x804a7501839FUNC<unknown>DEFAULT2
                          attack_tcp_stomp.symtab0x804c8b01979FUNC<unknown>DEFAULT2
                          attack_tcp_syn.symtab0x804b5901653FUNC<unknown>DEFAULT2
                          attack_tcp_wra.symtab0x804bc102315FUNC<unknown>DEFAULT2
                          attack_udp_an.symtab0x80498001088FUNC<unknown>DEFAULT2
                          attack_udp_bypass.symtab0x804a0e0645FUNC<unknown>DEFAULT2
                          attack_udp_custom.symtab0x8049c401179FUNC<unknown>DEFAULT2
                          attack_udp_hex.symtab0x80493d01065FUNC<unknown>DEFAULT2
                          attack_udp_plain.symtab0x804a370987FUNC<unknown>DEFAULT2
                          attack_udp_random.symtab0x8048b301113FUNC<unknown>DEFAULT2
                          attack_udp_str.symtab0x8048f901088FUNC<unknown>DEFAULT2
                          attacks.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          been_there_done_that.symtab0x8057d381OBJECT<unknown>DEFAULT12
                          bind.symtab0x805092843FUNC<unknown>DEFAULT2
                          bind.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          brk.symtab0x8052e0844FUNC<unknown>DEFAULT2
                          brk.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          bsd_signal.symtab0x8050c8c143FUNC<unknown>DEFAULT2
                          calloc.symtab0x8051560245FUNC<unknown>DEFAULT2
                          calloc.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          checksum.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          checksum_generic.symtab0x804d7b064FUNC<unknown>DEFAULT2
                          checksum_tcpudp.symtab0x804d7f0149FUNC<unknown>DEFAULT2
                          clock.symtab0x805080c36FUNC<unknown>DEFAULT2
                          clock.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          close.symtab0x80528c080FUNC<unknown>DEFAULT2
                          closedir.symtab0x805055c138FUNC<unknown>DEFAULT2
                          closedir.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          completed.4963.symtab0x8057d001OBJECT<unknown>DEFAULT12
                          connect.symtab0x805095491FUNC<unknown>DEFAULT2
                          connect.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          crtstuff.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          crtstuff.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          dl-support.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          ensure_single_instance.symtab0x804dfe0387FUNC<unknown>DEFAULT2
                          entries.symtab0x805a8004OBJECT<unknown>DEFAULT12
                          environ.symtab0x805828c4OBJECT<unknown>DEFAULT12
                          errno.symtab0x04TLS<unknown>DEFAULT6
                          errno.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          exit.symtab0x80521b8106FUNC<unknown>DEFAULT2
                          exit.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          fclose.symtab0x8053688399FUNC<unknown>DEFAULT2
                          fclose.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          fcntl.symtab0x80501d2156FUNC<unknown>DEFAULT2
                          fd_ctrl.symtab0x8057aec4OBJECT<unknown>DEFAULT11
                          fd_serv.symtab0x8057af04OBJECT<unknown>DEFAULT11
                          fd_to_DIR.symtab0x80505e8146FUNC<unknown>DEFAULT2
                          fdopendir.symtab0x8050703114FUNC<unknown>DEFAULT2
                          fflush_unlocked.symtab0x8053f65472FUNC<unknown>DEFAULT2
                          fflush_unlocked.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          fgetc.symtab0x8053cd8157FUNC<unknown>DEFAULT2
                          fgetc.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          fgetc_unlocked.symtab0x80541d8220FUNC<unknown>DEFAULT2
                          fgetc_unlocked.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          fgets.symtab0x8053d8c123FUNC<unknown>DEFAULT2
                          fgets.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          fgets_unlocked.symtab0x80542b4107FUNC<unknown>DEFAULT2
                          fgets_unlocked.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          fopen.symtab0x805387024FUNC<unknown>DEFAULT2
                          fopen.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          fork.symtab0x8052520524FUNC<unknown>DEFAULT2
                          fork.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          fork_handler_pool.symtab0x8057d441348OBJECT<unknown>DEFAULT12
                          frame_dummy.symtab0x80481300FUNC<unknown>DEFAULT2
                          free.symtab0x8051b9f415FUNC<unknown>DEFAULT2
                          free.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          fstat.symtab0x8052f8c75FUNC<unknown>DEFAULT2
                          fstat.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          getc.symtab0x8053cd8157FUNC<unknown>DEFAULT2
                          getc_unlocked.symtab0x80541d8220FUNC<unknown>DEFAULT2
                          getdents.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          getdents64.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          getdtablesize.symtab0x805306437FUNC<unknown>DEFAULT2
                          getdtablesize.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          getegid.symtab0x805308c8FUNC<unknown>DEFAULT2
                          getegid.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          geteuid.symtab0x80530948FUNC<unknown>DEFAULT2
                          geteuid.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          getgid.symtab0x805309c8FUNC<unknown>DEFAULT2
                          getgid.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          getpagesize.symtab0x80530a417FUNC<unknown>DEFAULT2
                          getpagesize.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          getpid.symtab0x805274c49FUNC<unknown>DEFAULT2
                          getpid.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          getppid.symtab0x80502708FUNC<unknown>DEFAULT2
                          getppid.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          getrlimit.symtab0x80530b843FUNC<unknown>DEFAULT2
                          getrlimit.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          getsockname.symtab0x80509b043FUNC<unknown>DEFAULT2
                          getsockname.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          getsockopt.symtab0x80509dc59FUNC<unknown>DEFAULT2
                          getsockopt.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          getuid.symtab0x80530e48FUNC<unknown>DEFAULT2
                          getuid.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          h_errno.symtab0x44TLS<unknown>DEFAULT6
                          index.symtab0x805434830FUNC<unknown>DEFAULT2
                          inet_addr.symtab0x80508a437FUNC<unknown>DEFAULT2
                          inet_aton.symtab0x80544a0148FUNC<unknown>DEFAULT2
                          inet_aton.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          inet_makeaddr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          init_static_tls.symtab0x805459042FUNC<unknown>DEFAULT2
                          initfini.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          initstate.symtab0x8051ed987FUNC<unknown>DEFAULT2
                          initstate_r.symtab0x805207a155FUNC<unknown>DEFAULT2
                          ioctl.symtab0x8050278142FUNC<unknown>DEFAULT2
                          ioctl.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          isatty.symtab0x805441c29FUNC<unknown>DEFAULT2
                          isatty.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          kill.symtab0x805030843FUNC<unknown>DEFAULT2
                          kill.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          killer.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          killer_kill_by_port.symtab0x804d8901849FUNC<unknown>DEFAULT2
                          libc-cancellation.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          libc-tls.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          listen.symtab0x8050a1835FUNC<unknown>DEFAULT2
                          listen.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          llseek.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          local_bind.4695.symtab0x8057af81OBJECT<unknown>DEFAULT11
                          lseek64.symtab0x8054b1885FUNC<unknown>DEFAULT2
                          main.symtab0x804e2002031FUNC<unknown>DEFAULT2
                          main.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          main_pid.symtab0x805a8044OBJECT<unknown>DEFAULT12
                          malloc.symtab0x8050da61975FUNC<unknown>DEFAULT2
                          malloc.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          malloc_trim.symtab0x8051d3e34FUNC<unknown>DEFAULT2
                          memcpy.symtab0x805083041FUNC<unknown>DEFAULT2
                          memcpy.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          memmove.symtab0x805432037FUNC<unknown>DEFAULT2
                          memmove.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          memory.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          mempcpy.symtab0x8054af433FUNC<unknown>DEFAULT2
                          mempcpy.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          memset.symtab0x805085c50FUNC<unknown>DEFAULT2
                          memset.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          methods.symtab0x8057d204OBJECT<unknown>DEFAULT12
                          methods_len.symtab0x8057d1c1OBJECT<unknown>DEFAULT12
                          mmap.symtab0x8052ec827FUNC<unknown>DEFAULT2
                          mremap.symtab0x80530ec59FUNC<unknown>DEFAULT2
                          mremap.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          munmap.symtab0x805312843FUNC<unknown>DEFAULT2
                          munmap.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          mylock.symtab0x8057b1824OBJECT<unknown>DEFAULT11
                          mylock.symtab0x8057b3024OBJECT<unknown>DEFAULT11
                          nanosleep.symtab0x805317d61FUNC<unknown>DEFAULT2
                          nanosleep.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          nprocessors_onln.symtab0x8052224221FUNC<unknown>DEFAULT2
                          object.4975.symtab0x8057d0424OBJECT<unknown>DEFAULT12
                          open.symtab0x805291091FUNC<unknown>DEFAULT2
                          opendir.symtab0x805067a137FUNC<unknown>DEFAULT2
                          opendir.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          p.4961.symtab0x8057ae80OBJECT<unknown>DEFAULT11
                          parse_config.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          pending_connection.symtab0x8057d241OBJECT<unknown>DEFAULT12
                          prctl.symtab0x805033459FUNC<unknown>DEFAULT2
                          prctl.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          program_invocation_name.symtab0x8057bfc4OBJECT<unknown>DEFAULT11
                          program_invocation_short_name.symtab0x8057bf84OBJECT<unknown>DEFAULT11
                          pseudo_cancel.symtab0x80528e50NOTYPE<unknown>DEFAULT2
                          pseudo_cancel.symtab0x805293b0NOTYPE<unknown>DEFAULT2
                          pseudo_cancel.symtab0x805299b0NOTYPE<unknown>DEFAULT2
                          pseudo_cancel.symtab0x80529fb0NOTYPE<unknown>DEFAULT2
                          pseudo_end.symtab0x805290f0NOTYPE<unknown>DEFAULT2
                          pseudo_end.symtab0x805296a0NOTYPE<unknown>DEFAULT2
                          pseudo_end.symtab0x80529ca0NOTYPE<unknown>DEFAULT2
                          pseudo_end.symtab0x8052a2a0NOTYPE<unknown>DEFAULT2
                          raise.symtab0x8052780101FUNC<unknown>DEFAULT2
                          raise.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          rand.symtab0x8051e305FUNC<unknown>DEFAULT2
                          rand.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          rand.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          rand_init.symtab0x804ea3066FUNC<unknown>DEFAULT2
                          rand_next.symtab0x804e9f064FUNC<unknown>DEFAULT2
                          rand_str.symtab0x804ea80220FUNC<unknown>DEFAULT2
                          random.symtab0x8051e3872FUNC<unknown>DEFAULT2
                          random.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          random_poly_info.symtab0x8055e5810OBJECT<unknown>DEFAULT4
                          random_r.symtab0x8051f7494FUNC<unknown>DEFAULT2
                          random_r.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          randtbl.symtab0x8057b5c128OBJECT<unknown>DEFAULT11
                          read.symtab0x80529d091FUNC<unknown>DEFAULT2
                          readdir.symtab0x8050778132FUNC<unknown>DEFAULT2
                          readdir.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          readdir64.symtab0x80532fc134FUNC<unknown>DEFAULT2
                          readdir64.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          readlink.symtab0x805037047FUNC<unknown>DEFAULT2
                          readlink.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          realloc.symtab0x8051658824FUNC<unknown>DEFAULT2
                          realloc.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          recv.symtab0x8050a3c99FUNC<unknown>DEFAULT2
                          recv.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          recvfrom.symtab0x8050aa0115FUNC<unknown>DEFAULT2
                          recvfrom.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          register-atfork.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          resolv.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          resolv_entries_free.symtab0x804eb6045FUNC<unknown>DEFAULT2
                          resolv_lookup.symtab0x804eb901281FUNC<unknown>DEFAULT2
                          resolve_cnc_addr.symtab0x804e170134FUNC<unknown>DEFAULT2
                          resolve_func.symtab0x8057af44OBJECT<unknown>DEFAULT11
                          rindex.symtab0x80543a426FUNC<unknown>DEFAULT2
                          sbrk.symtab0x80503a078FUNC<unknown>DEFAULT2
                          sbrk.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          select.symtab0x8050429113FUNC<unknown>DEFAULT2
                          select.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          send.symtab0x8050b1499FUNC<unknown>DEFAULT2
                          send.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          sendto.symtab0x8050b78115FUNC<unknown>DEFAULT2
                          sendto.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          setsid.symtab0x805049c31FUNC<unknown>DEFAULT2
                          setsid.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          setsockopt.symtab0x8050bec59FUNC<unknown>DEFAULT2
                          setsockopt.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          setstate.symtab0x8051e8089FUNC<unknown>DEFAULT2
                          setstate_r.symtab0x8052115161FUNC<unknown>DEFAULT2
                          sigaction.symtab0x8052e5381FUNC<unknown>DEFAULT2
                          sigaction.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          sigaddset.symtab0x8050c5434FUNC<unknown>DEFAULT2
                          sigaddset.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          sigempty.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          sigemptyset.symtab0x8050c7820FUNC<unknown>DEFAULT2
                          signal.symtab0x8050c8c143FUNC<unknown>DEFAULT2
                          signal.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          sigprocmask.symtab0x80504bc101FUNC<unknown>DEFAULT2
                          sigprocmask.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          sigsetops.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          sleep.symtab0x80527e8204FUNC<unknown>DEFAULT2
                          sleep.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          socket.symtab0x8050c2843FUNC<unknown>DEFAULT2
                          socket.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          srand.symtab0x8051f3067FUNC<unknown>DEFAULT2
                          srandom.symtab0x8051f3067FUNC<unknown>DEFAULT2
                          srandom_r.symtab0x8051fd2168FUNC<unknown>DEFAULT2
                          srv_addr.symtab0x805a80816OBJECT<unknown>DEFAULT12
                          static_dtv.symtab0x805a2c0512OBJECT<unknown>DEFAULT12
                          static_map.symtab0x805a7c852OBJECT<unknown>DEFAULT12
                          static_slotinfo.symtab0x805a4c0776OBJECT<unknown>DEFAULT12
                          stderr.symtab0x8057c104OBJECT<unknown>DEFAULT11
                          stdin.symtab0x8057c084OBJECT<unknown>DEFAULT11
                          stdout.symtab0x8057c0c4OBJECT<unknown>DEFAULT11
                          strchr.symtab0x805434830FUNC<unknown>DEFAULT2
                          strchr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          strchrnul.symtab0x805436825FUNC<unknown>DEFAULT2
                          strchrnul.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          strcmp.symtab0x805438429FUNC<unknown>DEFAULT2
                          strcmp.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          strcoll.symtab0x805438429FUNC<unknown>DEFAULT2
                          strcspn.symtab0x80543c048FUNC<unknown>DEFAULT2
                          strcspn.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          strlen.symtab0x805089019FUNC<unknown>DEFAULT2
                          strlen.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          strrchr.symtab0x80543a426FUNC<unknown>DEFAULT2
                          strrchr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          strspn.symtab0x80543f042FUNC<unknown>DEFAULT2
                          strspn.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          sysconf.symtab0x8052301543FUNC<unknown>DEFAULT2
                          sysconf.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          table.symtab0x805a820464OBJECT<unknown>DEFAULT12
                          table.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          table_init.symtab0x804f1b02977FUNC<unknown>DEFAULT2
                          table_key.symtab0x8057afc4OBJECT<unknown>DEFAULT11
                          table_lock_val.symtab0x804f0d0104FUNC<unknown>DEFAULT2
                          table_retrieve_val.symtab0x804f0a034FUNC<unknown>DEFAULT2
                          table_unlock_val.symtab0x804f140104FUNC<unknown>DEFAULT2
                          tcgetattr.symtab0x805443c99FUNC<unknown>DEFAULT2
                          tcgetattr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          time.symtab0x805052416FUNC<unknown>DEFAULT2
                          time.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          times.symtab0x80531bc16FUNC<unknown>DEFAULT2
                          times.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          unlink.symtab0x805053439FUNC<unknown>DEFAULT2
                          unlink.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          unsafe_state.symtab0x8057b4820OBJECT<unknown>DEFAULT11
                          util.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          util_atoi.symtab0x804fe10264FUNC<unknown>DEFAULT2
                          util_fdgets.symtab0x804ff2082FUNC<unknown>DEFAULT2
                          util_itoa.symtab0x80500a0220FUNC<unknown>DEFAULT2
                          util_local_addr.symtab0x804ff80145FUNC<unknown>DEFAULT2
                          util_memcpy.symtab0x804fdc037FUNC<unknown>DEFAULT2
                          util_strcpy.symtab0x804fd8059FUNC<unknown>DEFAULT2
                          util_stristr.symtab0x8050020128FUNC<unknown>DEFAULT2
                          util_strlen.symtab0x804fd6027FUNC<unknown>DEFAULT2
                          util_zero.symtab0x804fdf029FUNC<unknown>DEFAULT2
                          w.symtab0x8057d344OBJECT<unknown>DEFAULT12
                          write.symtab0x805297091FUNC<unknown>DEFAULT2
                          x.symtab0x8057d284OBJECT<unknown>DEFAULT12
                          xstatconv.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                          y.symtab0x8057d2c4OBJECT<unknown>DEFAULT12
                          z.symtab0x8057d304OBJECT<unknown>DEFAULT12
                          TimestampProtocolSIDSignatureSeveritySource PortDest PortSource IPDest IP
                          2024-08-21T21:13:28.821695+0200TCP2030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)15034851237192.168.2.15185.196.9.5
                          2024-08-21T21:15:10.226492+0200TCP2030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)15035651237192.168.2.15185.196.9.5
                          2024-08-21T21:13:52.255977+0200TCP2030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)15035051237192.168.2.15185.196.9.5
                          2024-08-21T21:14:44.049283+0200TCP2030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)15035451237192.168.2.15185.196.9.5
                          2024-08-21T21:14:16.645310+0200TCP2030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)15035251237192.168.2.15185.196.9.5
                          TimestampSource PortDest PortSource IPDest IP
                          Aug 21, 2024 21:13:28.816837072 CEST5034851237192.168.2.15185.196.9.5
                          Aug 21, 2024 21:13:28.821623087 CEST5123750348185.196.9.5192.168.2.15
                          Aug 21, 2024 21:13:28.821672916 CEST5034851237192.168.2.15185.196.9.5
                          Aug 21, 2024 21:13:28.821695089 CEST5034851237192.168.2.15185.196.9.5
                          Aug 21, 2024 21:13:28.826587915 CEST5123750348185.196.9.5192.168.2.15
                          Aug 21, 2024 21:13:38.828313112 CEST5034851237192.168.2.15185.196.9.5
                          Aug 21, 2024 21:13:38.833621979 CEST5123750348185.196.9.5192.168.2.15
                          Aug 21, 2024 21:13:50.241295099 CEST5123750348185.196.9.5192.168.2.15
                          Aug 21, 2024 21:13:50.241431952 CEST5034851237192.168.2.15185.196.9.5
                          Aug 21, 2024 21:13:50.246315956 CEST5123750348185.196.9.5192.168.2.15
                          Aug 21, 2024 21:13:52.250958920 CEST5035051237192.168.2.15185.196.9.5
                          Aug 21, 2024 21:13:52.255816936 CEST5123750350185.196.9.5192.168.2.15
                          Aug 21, 2024 21:13:52.255906105 CEST5035051237192.168.2.15185.196.9.5
                          Aug 21, 2024 21:13:52.255976915 CEST5035051237192.168.2.15185.196.9.5
                          Aug 21, 2024 21:13:52.260821104 CEST5123750350185.196.9.5192.168.2.15
                          Aug 21, 2024 21:14:13.630184889 CEST5123750350185.196.9.5192.168.2.15
                          Aug 21, 2024 21:14:13.630403996 CEST5035051237192.168.2.15185.196.9.5
                          Aug 21, 2024 21:14:13.635355949 CEST5123750350185.196.9.5192.168.2.15
                          Aug 21, 2024 21:14:16.640239000 CEST5035251237192.168.2.15185.196.9.5
                          Aug 21, 2024 21:14:16.645186901 CEST5123750352185.196.9.5192.168.2.15
                          Aug 21, 2024 21:14:16.645246029 CEST5035251237192.168.2.15185.196.9.5
                          Aug 21, 2024 21:14:16.645309925 CEST5035251237192.168.2.15185.196.9.5
                          Aug 21, 2024 21:14:16.650347948 CEST5123750352185.196.9.5192.168.2.15
                          Aug 21, 2024 21:14:38.035939932 CEST5123750352185.196.9.5192.168.2.15
                          Aug 21, 2024 21:14:38.036138058 CEST5035251237192.168.2.15185.196.9.5
                          Aug 21, 2024 21:14:38.041134119 CEST5123750352185.196.9.5192.168.2.15
                          Aug 21, 2024 21:14:44.044389963 CEST5035451237192.168.2.15185.196.9.5
                          Aug 21, 2024 21:14:44.049213886 CEST5123750354185.196.9.5192.168.2.15
                          Aug 21, 2024 21:14:44.049266100 CEST5035451237192.168.2.15185.196.9.5
                          Aug 21, 2024 21:14:44.049283028 CEST5035451237192.168.2.15185.196.9.5
                          Aug 21, 2024 21:14:44.054176092 CEST5123750354185.196.9.5192.168.2.15
                          Aug 21, 2024 21:14:54.059169054 CEST5035451237192.168.2.15185.196.9.5
                          Aug 21, 2024 21:14:54.066226959 CEST5123750354185.196.9.5192.168.2.15
                          Aug 21, 2024 21:15:05.448456049 CEST5123750354185.196.9.5192.168.2.15
                          Aug 21, 2024 21:15:05.448918104 CEST5035451237192.168.2.15185.196.9.5
                          Aug 21, 2024 21:15:05.453969002 CEST5123750354185.196.9.5192.168.2.15
                          Aug 21, 2024 21:15:10.221545935 CEST5035651237192.168.2.15185.196.9.5
                          Aug 21, 2024 21:15:10.226319075 CEST5123750356185.196.9.5192.168.2.15
                          Aug 21, 2024 21:15:10.226418972 CEST5035651237192.168.2.15185.196.9.5
                          Aug 21, 2024 21:15:10.226491928 CEST5035651237192.168.2.15185.196.9.5
                          Aug 21, 2024 21:15:10.231300116 CEST5123750356185.196.9.5192.168.2.15
                          Aug 21, 2024 21:15:31.633548975 CEST5123750356185.196.9.5192.168.2.15
                          Aug 21, 2024 21:15:31.633718967 CEST5035651237192.168.2.15185.196.9.5
                          Aug 21, 2024 21:15:31.638602972 CEST5123750356185.196.9.5192.168.2.15
                          TimestampSource PortDest PortSource IPDest IP
                          Aug 21, 2024 21:13:28.809834957 CEST3534753192.168.2.158.8.8.8
                          Aug 21, 2024 21:13:28.816746950 CEST53353478.8.8.8192.168.2.15
                          Aug 21, 2024 21:13:52.243552923 CEST3451553192.168.2.158.8.8.8
                          Aug 21, 2024 21:13:52.250792027 CEST53345158.8.8.8192.168.2.15
                          Aug 21, 2024 21:14:16.632580996 CEST5344353192.168.2.158.8.8.8
                          Aug 21, 2024 21:14:16.640080929 CEST53534438.8.8.8192.168.2.15
                          Aug 21, 2024 21:14:44.037415981 CEST3862153192.168.2.158.8.8.8
                          Aug 21, 2024 21:14:44.044303894 CEST53386218.8.8.8192.168.2.15
                          Aug 21, 2024 21:15:09.450587988 CEST4760553192.168.2.158.8.8.8
                          Aug 21, 2024 21:15:10.221234083 CEST53476058.8.8.8192.168.2.15
                          TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                          Aug 21, 2024 21:13:28.809834957 CEST192.168.2.158.8.8.80x79f7Standard query (0)fdh32fsdfhs.shopA (IP address)IN (0x0001)false
                          Aug 21, 2024 21:13:52.243552923 CEST192.168.2.158.8.8.80x5c02Standard query (0)fdh32fsdfhs.shopA (IP address)IN (0x0001)false
                          Aug 21, 2024 21:14:16.632580996 CEST192.168.2.158.8.8.80x8f0fStandard query (0)fdh32fsdfhs.shopA (IP address)IN (0x0001)false
                          Aug 21, 2024 21:14:44.037415981 CEST192.168.2.158.8.8.80xef60Standard query (0)fdh32fsdfhs.shopA (IP address)IN (0x0001)false
                          Aug 21, 2024 21:15:09.450587988 CEST192.168.2.158.8.8.80xd729Standard query (0)fdh32fsdfhs.shopA (IP address)IN (0x0001)false
                          TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                          Aug 21, 2024 21:13:28.816746950 CEST8.8.8.8192.168.2.150x79f7No error (0)fdh32fsdfhs.shop185.196.9.5A (IP address)IN (0x0001)false
                          Aug 21, 2024 21:13:52.250792027 CEST8.8.8.8192.168.2.150x5c02No error (0)fdh32fsdfhs.shop185.196.9.5A (IP address)IN (0x0001)false
                          Aug 21, 2024 21:14:16.640080929 CEST8.8.8.8192.168.2.150x8f0fNo error (0)fdh32fsdfhs.shop185.196.9.5A (IP address)IN (0x0001)false
                          Aug 21, 2024 21:14:44.044303894 CEST8.8.8.8192.168.2.150xef60No error (0)fdh32fsdfhs.shop185.196.9.5A (IP address)IN (0x0001)false
                          Aug 21, 2024 21:15:10.221234083 CEST8.8.8.8192.168.2.150xd729No error (0)fdh32fsdfhs.shop185.196.9.5A (IP address)IN (0x0001)false

                          System Behavior

                          Start time (UTC):19:13:27
                          Start date (UTC):21/08/2024
                          Path:/tmp/i686nk.elf
                          Arguments:/tmp/i686nk.elf
                          File size:81891 bytes
                          MD5 hash:43c3861c22a3a5d97d57e8e866117fd9

                          Start time (UTC):19:13:27
                          Start date (UTC):21/08/2024
                          Path:/tmp/i686nk.elf
                          Arguments:-
                          File size:81891 bytes
                          MD5 hash:43c3861c22a3a5d97d57e8e866117fd9