Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
i586.elf

Overview

General Information

Sample name:i586.elf
Analysis ID:1496917
MD5:ed474ab6fe0346a9908523f124fbfe0c
SHA1:ff2dd051c8e7105b9661091abd6291683e15961b
SHA256:64f288eeb0163a2b2ef62305ab153ba2525aa8256972a53dbac200f2ea396b49
Tags:elf
Infos:

Detection

Mirai
Score:100
Range:0 - 100
Whitelisted:false

Signatures

Antivirus / Scanner detection for submitted sample
Detected Mirai
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Yara detected Mirai
Connects to many ports of the same IP (likely port scanning)
Contains symbols with names commonly found in malware
Machine Learning detection for sample
Sample reads /proc/mounts (often used for finding a writable filesystem)
Sample tries to kill multiple processes (SIGKILL)
Detected TCP or UDP traffic on non-standard ports
Executes the "rm" command used to delete files or directories
Sample and/or dropped files contains symbols with suspicious names
Sample contains strings indicative of BusyBox which embeds multiple Unix commands in a single executable
Sample tries to kill a process (SIGKILL)
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)
Yara signature match

Classification

Joe Sandbox version:40.0.0 Tourmaline
Analysis ID:1496917
Start date and time:2024-08-21 21:14:28 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 47s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:i586.elf
Detection:MAL
Classification:mal100.spre.troj.linELF@0/0@11/0
  • VT rate limit hit for: i586.elf
Command:/tmp/i586.elf
PID:5426
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
listening to tun0
Standard Error:
  • system is lnxubuntu20
  • dash New Fork (PID: 5413, Parent: 3578)
  • rm (PID: 5413, Parent: 3578, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.8ujBYUUTak /tmp/tmp.xUGcDLugyr /tmp/tmp.RUd0zcTbnv
  • dash New Fork (PID: 5414, Parent: 3578)
  • rm (PID: 5414, Parent: 3578, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.8ujBYUUTak /tmp/tmp.xUGcDLugyr /tmp/tmp.RUd0zcTbnv
  • i586.elf (PID: 5426, Parent: 5348, MD5: ed474ab6fe0346a9908523f124fbfe0c) Arguments: /tmp/i586.elf
    • i586.elf New Fork (PID: 5427, Parent: 5426)
    • i586.elf New Fork (PID: 5428, Parent: 5426)
  • udisksd New Fork (PID: 5438, Parent: 802)
  • dumpe2fs (PID: 5438, Parent: 802, MD5: 5c66f7d8f7681a40562cf049ad4b72b4) Arguments: dumpe2fs -h /dev/dm-0
  • sh (PID: 5474, Parent: 1588, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-sharing
  • gsd-sharing (PID: 5474, Parent: 1588, MD5: e29d9025d98590fbb69f89fdbd4438b3) Arguments: /usr/libexec/gsd-sharing
  • sh (PID: 5477, Parent: 1588, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-wacom
  • gsd-wacom (PID: 5477, Parent: 1588, MD5: 13778dd1a23a4e94ddc17ac9caa4fcc1) Arguments: /usr/libexec/gsd-wacom
  • systemd New Fork (PID: 5481, Parent: 1)
  • upowerd (PID: 5481, Parent: 1, MD5: 1253eea2fe5fe4017069664284e326cd) Arguments: /usr/lib/upower/upowerd
  • fusermount (PID: 5482, Parent: 2935, MD5: 576a1b135c82bdcbc97a91acea900566) Arguments: fusermount -u -q -z -- /run/user/1000/gvfs
  • sh (PID: 5500, Parent: 1588, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-keyboard
  • gsd-keyboard (PID: 5500, Parent: 1588, MD5: 8e288fd17c80bb0a1148b964b2ac2279) Arguments: /usr/libexec/gsd-keyboard
  • sh (PID: 5524, Parent: 1588, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-print-notifications
  • gsd-print-notifications (PID: 5524, Parent: 1588, MD5: 71539698aa691718cee775d6b9450ae2) Arguments: /usr/libexec/gsd-print-notifications
  • wrapper-2.0 (PID: 5525, Parent: 3147, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libsystray.so 6 12582920 systray "Notification Area" "Area where notification icons appear"
  • sh (PID: 5528, Parent: 1588, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-rfkill
  • gsd-rfkill (PID: 5528, Parent: 1588, MD5: 88a16a3c0aba1759358c06215ecfb5cc) Arguments: /usr/libexec/gsd-rfkill
  • wrapper-2.0 (PID: 5529, Parent: 3147, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libstatusnotifier.so 7 12582921 statusnotifier "Status Notifier Plugin" "Provides a panel area for status notifier items (application indicators)"
  • sh (PID: 5530, Parent: 1588, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-smartcard
  • gsd-smartcard (PID: 5530, Parent: 1588, MD5: ea1fbd7f62e4cd0331eae2ef754ee605) Arguments: /usr/libexec/gsd-smartcard
  • wrapper-2.0 (PID: 5531, Parent: 3147, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libpulseaudio-plugin.so 8 12582922 pulseaudio "PulseAudio Plugin" "Adjust the audio volume of the PulseAudio sound system"
  • sh (PID: 5538, Parent: 1588, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-datetime
  • gsd-datetime (PID: 5538, Parent: 1588, MD5: d80d39745740de37d6634d36e344d4bc) Arguments: /usr/libexec/gsd-datetime
  • wrapper-2.0 (PID: 5542, Parent: 3147, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libxfce4powermanager.so 9 12582923 power-manager-plugin "Power Manager Plugin" "Display the battery levels of your devices and control the brightness of your display"
  • sh (PID: 5543, Parent: 1588, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-media-keys
  • gsd-media-keys (PID: 5543, Parent: 1588, MD5: a425448c135afb4b8bfd79cc0b6b74da) Arguments: /usr/libexec/gsd-media-keys
  • wrapper-2.0 (PID: 5544, Parent: 3147, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libnotification-plugin.so 10 12582924 notification-plugin "Notification Plugin" "Notification plugin for the Xfce panel"
  • sh (PID: 5545, Parent: 1588, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-screensaver-proxy
  • gsd-screensaver-proxy (PID: 5545, Parent: 1588, MD5: 77e309450c87dceee43f1a9e50cc0d02) Arguments: /usr/libexec/gsd-screensaver-proxy
  • wrapper-2.0 (PID: 5546, Parent: 3147, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libactions.so 14 12582925 actions "Action Buttons" "Log out, lock or other system actions"
  • sh (PID: 5547, Parent: 1588, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-a11y-settings
  • gsd-a11y-settings (PID: 5547, Parent: 1588, MD5: 18e243d2cf30ecee7ea89d1462725c5c) Arguments: /usr/libexec/gsd-a11y-settings
  • systemd New Fork (PID: 5548, Parent: 1)
  • upowerd (PID: 5548, Parent: 1, MD5: 1253eea2fe5fe4017069664284e326cd) Arguments: /usr/lib/upower/upowerd
  • sh (PID: 5582, Parent: 1588, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-power
  • gsd-power (PID: 5582, Parent: 1588, MD5: 28b8e1b43c3e7f1db6741ea1ecd978b7) Arguments: /usr/libexec/gsd-power
  • sh (PID: 5587, Parent: 1588, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-sound
  • gsd-sound (PID: 5587, Parent: 1588, MD5: 4c7d3fb993463337b4a0eb5c80c760ee) Arguments: /usr/libexec/gsd-sound
  • sh (PID: 5588, Parent: 1588, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-housekeeping
  • gsd-housekeeping (PID: 5588, Parent: 1588, MD5: b55f3394a84976ddb92a2915e5d76914) Arguments: /usr/libexec/gsd-housekeeping
  • systemd New Fork (PID: 5591, Parent: 1)
  • upowerd (PID: 5591, Parent: 1, MD5: 1253eea2fe5fe4017069664284e326cd) Arguments: /usr/lib/upower/upowerd
  • systemd New Fork (PID: 5631, Parent: 1)
  • upowerd (PID: 5631, Parent: 1, MD5: 1253eea2fe5fe4017069664284e326cd) Arguments: /usr/lib/upower/upowerd
  • systemd New Fork (PID: 5671, Parent: 1)
  • upowerd (PID: 5671, Parent: 1, MD5: 1253eea2fe5fe4017069664284e326cd) Arguments: /usr/lib/upower/upowerd
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
MiraiMirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.mirai
SourceRuleDescriptionAuthorStrings
i586.elfJoeSecurity_Mirai_8Yara detected MiraiJoe Security
    i586.elfLinux_Trojan_Mirai_122ff2e6unknownunknown
    • 0x936b:$a: 24 EB 15 89 F0 83 C8 01 EB 03 8B 5B 08 3B 43 04 72 F8 8B 4B 0C 89
    i586.elfLinux_Trojan_Mirai_fa48b592unknownunknown
    • 0xc929:$a: 31 C0 BA 01 00 00 00 B9 01 00 00 00 03 04 24 89 D7 31 D2 F7 F7 0F
    i586.elfLinux_Trojan_Mirai_8aa7b5d3unknownunknown
    • 0x67b2:$a: 8B 4C 24 14 8B 74 24 0C 8B 5C 24 10 85 C9 74 0D 31 D2 8A 04 1A 88
    SourceRuleDescriptionAuthorStrings
    5426.1.0000000008048000.0000000008058000.r-x.sdmpLinux_Trojan_Mirai_122ff2e6unknownunknown
    • 0x936b:$a: 24 EB 15 89 F0 83 C8 01 EB 03 8B 5B 08 3B 43 04 72 F8 8B 4B 0C 89
    5426.1.0000000008048000.0000000008058000.r-x.sdmpLinux_Trojan_Mirai_fa48b592unknownunknown
    • 0xc929:$a: 31 C0 BA 01 00 00 00 B9 01 00 00 00 03 04 24 89 D7 31 D2 F7 F7 0F
    5426.1.0000000008048000.0000000008058000.r-x.sdmpLinux_Trojan_Mirai_8aa7b5d3unknownunknown
    • 0x67b2:$a: 8B 4C 24 14 8B 74 24 0C 8B 5C 24 10 85 C9 74 0D 31 D2 8A 04 1A 88
    Timestamp:2024-08-21T21:15:34.633226+0200
    SID:2030490
    Severity:1
    Source Port:57496
    Destination Port:51237
    Protocol:TCP
    Classtype:Malware Command and Control Activity Detected
    Timestamp:2024-08-21T21:16:55.552567+0200
    SID:2030490
    Severity:1
    Source Port:57502
    Destination Port:51237
    Protocol:TCP
    Classtype:Malware Command and Control Activity Detected
    Timestamp:2024-08-21T21:18:34.069607+0200
    SID:2030490
    Severity:1
    Source Port:57510
    Destination Port:51237
    Protocol:TCP
    Classtype:Malware Command and Control Activity Detected
    Timestamp:2024-08-21T21:18:05.692978+0200
    SID:2030490
    Severity:1
    Source Port:57508
    Destination Port:51237
    Protocol:TCP
    Classtype:Malware Command and Control Activity Detected
    Timestamp:2024-08-21T21:15:59.038834+0200
    SID:2030490
    Severity:1
    Source Port:57498
    Destination Port:51237
    Protocol:TCP
    Classtype:Malware Command and Control Activity Detected
    Timestamp:2024-08-21T21:17:43.317076+0200
    SID:2030490
    Severity:1
    Source Port:57506
    Destination Port:51237
    Protocol:TCP
    Classtype:Malware Command and Control Activity Detected
    Timestamp:2024-08-21T21:15:10.226277+0200
    SID:2030490
    Severity:1
    Source Port:57494
    Destination Port:51237
    Protocol:TCP
    Classtype:Malware Command and Control Activity Detected
    Timestamp:2024-08-21T21:16:30.169397+0200
    SID:2030490
    Severity:1
    Source Port:57500
    Destination Port:51237
    Protocol:TCP
    Classtype:Malware Command and Control Activity Detected
    Timestamp:2024-08-21T21:17:18.926134+0200
    SID:2030490
    Severity:1
    Source Port:57504
    Destination Port:51237
    Protocol:TCP
    Classtype:Malware Command and Control Activity Detected

    Click to jump to signature section

    Show All Signature Results

    AV Detection

    barindex
    Source: i586.elfAvira: detected
    Source: i586.elfReversingLabs: Detection: 60%
    Source: i586.elfJoe Sandbox ML: detected

    Networking

    barindex
    Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.13:57494 -> 185.196.9.5:51237
    Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.13:57502 -> 185.196.9.5:51237
    Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.13:57498 -> 185.196.9.5:51237
    Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.13:57506 -> 185.196.9.5:51237
    Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.13:57510 -> 185.196.9.5:51237
    Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.13:57500 -> 185.196.9.5:51237
    Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.13:57496 -> 185.196.9.5:51237
    Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.13:57504 -> 185.196.9.5:51237
    Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.13:57508 -> 185.196.9.5:51237
    Source: global trafficTCP traffic: 185.196.9.5 ports 1,2,3,5,7,51237
    Source: global trafficTCP traffic: 192.168.2.13:57494 -> 185.196.9.5:51237
    Source: global trafficTCP traffic: 192.168.2.13:48202 -> 185.125.190.26:443
    Source: unknownTCP traffic detected without corresponding DNS query: 185.125.190.26
    Source: unknownTCP traffic detected without corresponding DNS query: 185.125.190.26
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: global trafficDNS traffic detected: DNS query: fdh32fsdfhs.shop
    Source: global trafficDNS traffic detected: DNS query: daisy.ubuntu.com
    Source: unknownNetwork traffic detected: HTTP traffic on port 48202 -> 443

    System Summary

    barindex
    Source: i586.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_122ff2e6 Author: unknown
    Source: i586.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_fa48b592 Author: unknown
    Source: i586.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_8aa7b5d3 Author: unknown
    Source: 5426.1.0000000008048000.0000000008058000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_122ff2e6 Author: unknown
    Source: 5426.1.0000000008048000.0000000008058000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_fa48b592 Author: unknown
    Source: 5426.1.0000000008048000.0000000008058000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 Author: unknown
    Source: ELF static info symbol of initial sampleName: attack.c
    Source: ELF static info symbol of initial sampleName: attack_get_opt_int
    Source: ELF static info symbol of initial sampleName: attack_get_opt_ip
    Source: ELF static info symbol of initial sampleName: attack_get_opt_str
    Source: ELF static info symbol of initial sampleName: attack_init
    Source: ELF static info symbol of initial sampleName: attack_nudp
    Source: ELF static info symbol of initial sampleName: attack_parse
    Source: ELF static info symbol of initial sampleName: attack_start
    Source: ELF static info symbol of initial sampleName: attack_tcp_ack
    Source: ELF static info symbol of initial sampleName: attack_tcp_bypass
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 793, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 797, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 802, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 1444, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 1475, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 1480, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 1482, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 1588, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 1604, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 1748, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 1751, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 1755, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 1765, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 1804, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 1832, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 1866, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 1872, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 1875, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 1879, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 1881, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 1884, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 1891, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 1906, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 1921, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 1922, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 1925, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 1930, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 1940, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 1944, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 1946, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 1969, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 1982, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 2926, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 2972, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 2974, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 3095, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 3104, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 3117, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 3122, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 3161, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 3162, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 3163, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 3164, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 3165, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 3170, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 3182, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 3208, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 3209, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 3212, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 3225, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 3246, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 3300, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 3310, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 3327, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 3336, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 3342, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 3375, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 3413, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 3420, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 3424, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 3429, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 3434, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 3448, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 3627, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 5474, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 5477, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 5481, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 5500, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 5524, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 5525, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 5528, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 5529, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 5531, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 5541, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 5530, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 5538, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 5542, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 5543, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 5544, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 5545, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 5546, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 5547, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 5548, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 5582, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 5587, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 5588, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 5591, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 5631, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 5671, result: successfulJump to behavior
    Source: i586.elfELF static info symbol of initial sample: scanner.c
    Source: Initial sampleString containing 'busybox' found: /bin/busybox
    Source: Initial sampleString containing 'busybox' found: /proc/self/exe/bin/busybox/proc/%d/etc/systmp.d/proc/%s/lib/systemd/usr/lib/systemd/systemd/usr/lib/openssh/sftp-server/sys/system/dvr/main/usr/mnt/mtd/org/userfs/home/process/net_process/var/tmp/sonia/usr/sbin/usr/bin/mnt/gm/bin/var/Sofia/usr/sbin/sshd/usr/sbin/ntpd/usr/sbin/cupsd/usr/lib/apt/methods/http/usr/sbin/crond/usr/sbin/rsyslogd/usr/sbin/inetd/usr/sbin/dnsmasq/usr/bin/DVRServer/usr/bin/DVRShell/usr/bin/DVRControl/usr/bin/DVRRemoteAgent/usr/bin/DVRNetService/usr/libexec/openssh/sftp-server)]
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 793, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 797, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 802, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 1444, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 1475, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 1480, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 1482, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 1588, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 1604, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 1748, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 1751, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 1755, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 1765, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 1804, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 1832, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 1866, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 1872, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 1875, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 1879, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 1881, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 1884, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 1891, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 1906, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 1921, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 1922, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 1925, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 1930, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 1940, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 1944, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 1946, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 1969, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 1982, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 2926, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 2972, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 2974, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 3095, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 3104, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 3117, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 3122, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 3161, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 3162, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 3163, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 3164, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 3165, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 3170, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 3182, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 3208, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 3209, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 3212, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 3225, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 3246, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 3300, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 3310, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 3327, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 3336, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 3342, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 3375, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 3413, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 3420, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 3424, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 3429, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 3434, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 3448, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 3627, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 5474, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 5477, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 5481, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 5500, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 5524, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 5525, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 5528, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 5529, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 5531, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 5541, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 5530, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 5538, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 5542, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 5543, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 5544, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 5545, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 5546, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 5547, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 5548, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 5582, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 5587, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 5588, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 5591, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 5631, result: successfulJump to behavior
    Source: /tmp/i586.elf (PID: 5427)SIGKILL sent: pid: 5671, result: successfulJump to behavior
    Source: i586.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_122ff2e6 reference_sample = c7dd999a033fa3edc1936785b87cd69ce2f5cac5a084ddfaf527a1094e718bc4, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 3c9ffd7537e30a21eefa6c174f801264b92a85a1bc73e34e6dc9e29f84658348, id = 122ff2e6-56e6-4aa8-a3ec-c19d31eb1f80, last_modified = 2021-09-16
    Source: i586.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_fa48b592 reference_sample = c9e33befeec133720b3ba40bb3cd7f636aad80f72f324c5fe65ac7af271c49ee, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 8838d2752b310dbf7d12f6cf023244aaff4fdf5b55cf1e3b71843210df0fcf88, id = fa48b592-8d80-45af-a3e4-232695b8f5dd, last_modified = 2021-09-16
    Source: i586.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_8aa7b5d3 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444, id = 8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9, last_modified = 2022-01-26
    Source: 5426.1.0000000008048000.0000000008058000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_122ff2e6 reference_sample = c7dd999a033fa3edc1936785b87cd69ce2f5cac5a084ddfaf527a1094e718bc4, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 3c9ffd7537e30a21eefa6c174f801264b92a85a1bc73e34e6dc9e29f84658348, id = 122ff2e6-56e6-4aa8-a3ec-c19d31eb1f80, last_modified = 2021-09-16
    Source: 5426.1.0000000008048000.0000000008058000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_fa48b592 reference_sample = c9e33befeec133720b3ba40bb3cd7f636aad80f72f324c5fe65ac7af271c49ee, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 8838d2752b310dbf7d12f6cf023244aaff4fdf5b55cf1e3b71843210df0fcf88, id = fa48b592-8d80-45af-a3e4-232695b8f5dd, last_modified = 2021-09-16
    Source: 5426.1.0000000008048000.0000000008058000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444, id = 8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9, last_modified = 2022-01-26
    Source: classification engineClassification label: mal100.spre.troj.linELF@0/0@11/0

    Persistence and Installation Behavior

    barindex
    Source: /bin/fusermount (PID: 5482)File: /proc/5482/mountsJump to behavior
    Source: /usr/bin/dash (PID: 5413)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.8ujBYUUTak /tmp/tmp.xUGcDLugyr /tmp/tmp.RUd0zcTbnvJump to behavior
    Source: /usr/bin/dash (PID: 5414)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.8ujBYUUTak /tmp/tmp.xUGcDLugyr /tmp/tmp.RUd0zcTbnvJump to behavior
    Source: /tmp/i586.elf (PID: 5428)Queries kernel information via 'uname': Jump to behavior

    Stealing of Sensitive Information

    barindex
    Source: Yara matchFile source: i586.elf, type: SAMPLE

    Remote Access Functionality

    barindex
    Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
    Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
    Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
    Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
    Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
    Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
    Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
    Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
    Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
    Source: Yara matchFile source: i586.elf, type: SAMPLE
    ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
    Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
    Masquerading
    OS Credential Dumping1
    Security Software Discovery
    Remote ServicesData from Local System1
    Encrypted Channel
    Exfiltration Over Other Network Medium1
    Service Stop
    CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
    File Deletion
    LSASS Memory1
    File and Directory Discovery
    Remote Desktop ProtocolData from Removable Media1
    Non-Standard Port
    Exfiltration Over BluetoothNetwork Denial of Service
    Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
    Non-Application Layer Protocol
    Automated ExfiltrationData Encrypted for Impact
    Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture2
    Application Layer Protocol
    Traffic DuplicationData Destruction
    No configs have been found
    Hide Legend

    Legend:

    • Process
    • Signature
    • Created File
    • DNS/IP Info
    • Is Dropped
    • Number of created Files
    • Is malicious
    • Internet

    This section contains all screenshots as thumbnails, including those not shown in the slideshow.


    windows-stand
    SourceDetectionScannerLabelLink
    i586.elf61%ReversingLabsLinux.Backdoor.Gafgyt
    i586.elf100%AviraEXP/ELF.Gafgyt.D
    i586.elf100%Joe Sandbox ML
    No Antivirus matches
    No Antivirus matches
    No Antivirus matches
    NameIPActiveMaliciousAntivirus DetectionReputation
    daisy.ubuntu.com
    162.213.35.25
    truefalse
      unknown
      fdh32fsdfhs.shop
      185.196.9.5
      truetrue
        unknown
        • No. of IPs < 25%
        • 25% < No. of IPs < 50%
        • 50% < No. of IPs < 75%
        • 75% < No. of IPs
        IPDomainCountryFlagASNASN NameMalicious
        185.125.190.26
        unknownUnited Kingdom
        41231CANONICAL-ASGBfalse
        185.196.9.5
        fdh32fsdfhs.shopSwitzerland
        42624SIMPLECARRIERCHtrue
        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
        185.125.190.26arm6.elfGet hashmaliciousMiraiBrowse
          armnk.elfGet hashmaliciousMiraiBrowse
            arm7.elfGet hashmaliciousTsunamiBrowse
              cyber-ppc.elfGet hashmaliciousUnknownBrowse
                firmware.armv6l.elfGet hashmaliciousUnknownBrowse
                  c.m68k.elfGet hashmaliciousMirai, OkiruBrowse
                    c.mips.elfGet hashmaliciousUnknownBrowse
                      hidakibest.arm5.elfGet hashmaliciousGafgyt, MiraiBrowse
                        jade.arm5.elfGet hashmaliciousMiraiBrowse
                          tarm5.elfGet hashmaliciousUnknownBrowse
                            185.196.9.5i686.elfGet hashmaliciousMiraiBrowse
                              i686nk.elfGet hashmaliciousMiraiBrowse
                                mips.elfGet hashmaliciousMiraiBrowse
                                  mipsel.elfGet hashmaliciousMiraiBrowse
                                    mipselnk.elfGet hashmaliciousMiraiBrowse
                                      mipsnk.elfGet hashmaliciousMiraiBrowse
                                        x86_64.elfGet hashmaliciousMiraiBrowse
                                          arm6.elfGet hashmaliciousMiraiBrowse
                                            arm.elfGet hashmaliciousMiraiBrowse
                                              arm6nk.elfGet hashmaliciousMiraiBrowse
                                                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                daisy.ubuntu.commips.elfGet hashmaliciousMiraiBrowse
                                                • 162.213.35.24
                                                mipsel.elfGet hashmaliciousMiraiBrowse
                                                • 162.213.35.25
                                                arm5.elfGet hashmaliciousUnknownBrowse
                                                • 162.213.35.25
                                                x86_64.elfGet hashmaliciousMiraiBrowse
                                                • 162.213.35.25
                                                arm6.elfGet hashmaliciousMiraiBrowse
                                                • 162.213.35.25
                                                arm.elfGet hashmaliciousMiraiBrowse
                                                • 162.213.35.24
                                                arm7.elfGet hashmaliciousMiraiBrowse
                                                • 162.213.35.24
                                                bin.i586.elfGet hashmaliciousUnknownBrowse
                                                • 162.213.35.24
                                                bin.armv7l.elfGet hashmaliciousUnknownBrowse
                                                • 162.213.35.25
                                                botirc.arm5.elfGet hashmaliciousTsunamiBrowse
                                                • 162.213.35.25
                                                fdh32fsdfhs.shopi686.elfGet hashmaliciousMiraiBrowse
                                                • 185.196.9.5
                                                i686nk.elfGet hashmaliciousMiraiBrowse
                                                • 185.196.9.5
                                                mips.elfGet hashmaliciousMiraiBrowse
                                                • 185.196.9.5
                                                mipsel.elfGet hashmaliciousMiraiBrowse
                                                • 185.196.9.5
                                                mipselnk.elfGet hashmaliciousMiraiBrowse
                                                • 185.196.9.5
                                                mipsnk.elfGet hashmaliciousMiraiBrowse
                                                • 185.196.9.5
                                                x86_64.elfGet hashmaliciousMiraiBrowse
                                                • 185.196.9.5
                                                arm6.elfGet hashmaliciousMiraiBrowse
                                                • 185.196.9.5
                                                arm.elfGet hashmaliciousMiraiBrowse
                                                • 185.196.9.5
                                                arm6nk.elfGet hashmaliciousMiraiBrowse
                                                • 185.196.9.5
                                                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                SIMPLECARRIERCHi686.elfGet hashmaliciousMiraiBrowse
                                                • 185.196.9.5
                                                i686nk.elfGet hashmaliciousMiraiBrowse
                                                • 185.196.9.5
                                                mips.elfGet hashmaliciousMiraiBrowse
                                                • 185.196.9.5
                                                mipsel.elfGet hashmaliciousMiraiBrowse
                                                • 185.196.9.5
                                                mipselnk.elfGet hashmaliciousMiraiBrowse
                                                • 185.196.9.5
                                                mipsnk.elfGet hashmaliciousMiraiBrowse
                                                • 185.196.9.5
                                                x86_64.elfGet hashmaliciousMiraiBrowse
                                                • 185.196.9.5
                                                arm6.elfGet hashmaliciousMiraiBrowse
                                                • 185.196.9.5
                                                arm.elfGet hashmaliciousMiraiBrowse
                                                • 185.196.9.5
                                                arm6nk.elfGet hashmaliciousMiraiBrowse
                                                • 185.196.9.5
                                                CANONICAL-ASGBi686.elfGet hashmaliciousMiraiBrowse
                                                • 91.189.91.42
                                                arm5nk.elfGet hashmaliciousUnknownBrowse
                                                • 91.189.91.42
                                                arm6.elfGet hashmaliciousMiraiBrowse
                                                • 185.125.190.26
                                                arm6nk.elfGet hashmaliciousMiraiBrowse
                                                • 91.189.91.42
                                                armnk.elfGet hashmaliciousMiraiBrowse
                                                • 185.125.190.26
                                                bin.armv4l.elfGet hashmaliciousUnknownBrowse
                                                • 91.189.91.42
                                                bin.armv6l.elfGet hashmaliciousUnknownBrowse
                                                • 91.189.91.42
                                                bin.x86_64.elfGet hashmaliciousUnknownBrowse
                                                • 91.189.91.42
                                                botirc.i686.elfGet hashmaliciousTsunamiBrowse
                                                • 91.189.91.42
                                                botirc.mpsl.elfGet hashmaliciousTsunamiBrowse
                                                • 91.189.91.42
                                                No context
                                                No context
                                                No created / dropped files found
                                                File type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, not stripped
                                                Entropy (8bit):6.313270569331244
                                                TrID:
                                                • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
                                                • ELF Executable and Linkable format (generic) (4004/1) 49.84%
                                                File name:i586.elf
                                                File size:93'479 bytes
                                                MD5:ed474ab6fe0346a9908523f124fbfe0c
                                                SHA1:ff2dd051c8e7105b9661091abd6291683e15961b
                                                SHA256:64f288eeb0163a2b2ef62305ab153ba2525aa8256972a53dbac200f2ea396b49
                                                SHA512:8e21a7edf6e43f6c213a836d16cb54c88f7e02fda9bf44ad76cdf8d5888d4485e3f54d425934c0f215572a863bfed0ad8b33112a71b921ac8a36ddbd86de8ea6
                                                SSDEEP:1536:IsiBuDW71b8+xjQyRvpfV6DBZLIBQXS/H+E/kw69B:I1u671g+xjQnB9SH+6k
                                                TLSH:1E933AC296A3C9FBD4C71B7412B3E73A4632F85A1B6D5B02E36CAFF56E035847149206
                                                File Content Preview:.ELF........................4...........4. ...(.....................\...\...........................D....9..........................................Q.td............................U..S............h....c...[]...$.............U......=`....t..5..............

                                                ELF header

                                                Class:ELF32
                                                Data:2's complement, little endian
                                                Version:1 (current)
                                                Machine:Intel 80386
                                                Version Number:0x1
                                                Type:EXEC (Executable file)
                                                OS/ABI:UNIX - System V
                                                ABI Version:0
                                                Entry Point Address:0x8048184
                                                Flags:0x0
                                                ELF Header Size:52
                                                Program Header Offset:52
                                                Program Header Size:32
                                                Number of Program Headers:4
                                                Section Header Offset:71136
                                                Section Header Size:40
                                                Number of Section Headers:19
                                                Header String Table Index:16
                                                NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                NULL0x00x00x00x00x0000
                                                .initPROGBITS0x80480b40xb40x1c0x00x6AX001
                                                .textPROGBITS0x80480d00xd00xce870x00x6AX0016
                                                .finiPROGBITS0x8054f570xcf570x170x00x6AX001
                                                .rodataPROGBITS0x8054f800xcf800x2adc0x00x2A0032
                                                .eh_framePROGBITS0x80580000x100000x5ac0x00x3WA004
                                                .tbssNOBITS0x80585ac0x105ac0x80x00x403WAT004
                                                .ctorsPROGBITS0x80585ac0x105ac0x80x00x3WA004
                                                .dtorsPROGBITS0x80585b40x105b40x80x00x3WA004
                                                .jcrPROGBITS0x80585bc0x105bc0x40x00x3WA004
                                                .got.pltPROGBITS0x80585c00x105c00xc0x40x3WA004
                                                .dataPROGBITS0x80585e00x105e00x2640x00x3WA0032
                                                .bssNOBITS0x80588600x108440x31700x00x3WA0032
                                                .stabPROGBITS0x00x108440xfc0xc0x01404
                                                .stabstrSTRTAB0x00x109400xdb0x00x0001
                                                .commentPROGBITS0x00x10a1b0xb400x00x0001
                                                .shstrtabSTRTAB0x00x1155b0x840x00x0001
                                                .symtabSYMTAB0x00x118d80x30100x100x0182994
                                                .strtabSTRTAB0x00x148e80x243f0x00x0001
                                                TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                LOAD0x00x80480000x80480000xfa5c0xfa5c6.54290x5R E0x1000.init .text .fini .rodata
                                                LOAD0x100000x80580000x80580000x8440x39d04.72160x6RW 0x1000.eh_frame .tbss .ctors .dtors .jcr .got.plt .data .bss
                                                TLS0x105ac0x80585ac0x80585ac0x00x80.00000x4R 0x4.tbss
                                                GNU_STACK0x00x00x00x00x00.00000x6RW 0x4
                                                NameVersion Info NameVersion Info File NameSection NameValueSizeSymbol TypeSymbol BindSymbol VisibilityNdx
                                                .symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                                .symtab0x80480b40SECTION<unknown>DEFAULT1
                                                .symtab0x80480d00SECTION<unknown>DEFAULT2
                                                .symtab0x8054f570SECTION<unknown>DEFAULT3
                                                .symtab0x8054f800SECTION<unknown>DEFAULT4
                                                .symtab0x80580000SECTION<unknown>DEFAULT5
                                                .symtab0x80585ac0SECTION<unknown>DEFAULT6
                                                .symtab0x80585ac0SECTION<unknown>DEFAULT7
                                                .symtab0x80585b40SECTION<unknown>DEFAULT8
                                                .symtab0x80585bc0SECTION<unknown>DEFAULT9
                                                .symtab0x80585c00SECTION<unknown>DEFAULT10
                                                .symtab0x80585e00SECTION<unknown>DEFAULT11
                                                .symtab0x80588600SECTION<unknown>DEFAULT12
                                                .symtab0x00SECTION<unknown>DEFAULT13
                                                .symtab0x00SECTION<unknown>DEFAULT14
                                                .symtab0x00SECTION<unknown>DEFAULT15
                                                C.11.5136.symtab0x805664824OBJECT<unknown>DEFAULT4
                                                C.114.6581.symtab0x8055b80248OBJECT<unknown>DEFAULT4
                                                C.117.6704.symtab0x80557801024OBJECT<unknown>DEFAULT4
                                                C.120.6827.symtab0x8055660284OBJECT<unknown>DEFAULT4
                                                C.123.6950.symtab0x805563028OBJECT<unknown>DEFAULT4
                                                C.2.4971.symtab0x8055f20132OBJECT<unknown>DEFAULT4
                                                C.81.5530.symtab0x8055cc044OBJECT<unknown>DEFAULT4
                                                C.82.5531.symtab0x8055c8036OBJECT<unknown>DEFAULT4
                                                LOCAL_ADDR.symtab0x805b3dc4OBJECT<unknown>DEFAULT12
                                                POPBX1.symtab0x8052dbf0NOTYPE<unknown>DEFAULT2
                                                POPBX1.symtab0x8052e1f0NOTYPE<unknown>DEFAULT2
                                                POPBX1.symtab0x8052e7f0NOTYPE<unknown>DEFAULT2
                                                PUSHBX1.symtab0x8052dab0NOTYPE<unknown>DEFAULT2
                                                PUSHBX1.symtab0x8052e0b0NOTYPE<unknown>DEFAULT2
                                                PUSHBX1.symtab0x8052e6b0NOTYPE<unknown>DEFAULT2
                                                RESTBX1.symtab0x8052d690NOTYPE<unknown>DEFAULT2
                                                SAVEBX1.symtab0x8052d5c0NOTYPE<unknown>DEFAULT2
                                                _Exit.symtab0x80533a066FUNC<unknown>DEFAULT2
                                                _GLOBAL_OFFSET_TABLE_.symtab0x80585c00OBJECT<unknown>HIDDEN10
                                                _Jv_RegisterClasses.symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                                _L_lock_103.symtab0x804f3f616FUNC<unknown>DEFAULT2
                                                _L_lock_12.symtab0x805088316FUNC<unknown>DEFAULT2
                                                _L_lock_140.symtab0x80508c316FUNC<unknown>DEFAULT2
                                                _L_lock_160.symtab0x80508e316FUNC<unknown>DEFAULT2
                                                _L_lock_17.symtab0x80544d610FUNC<unknown>DEFAULT2
                                                _L_lock_18.symtab0x804f3bc13FUNC<unknown>DEFAULT2
                                                _L_lock_191.symtab0x805090313FUNC<unknown>DEFAULT2
                                                _L_lock_198.symtab0x804f79016FUNC<unknown>DEFAULT2
                                                _L_lock_209.symtab0x804f7a016FUNC<unknown>DEFAULT2
                                                _L_lock_29.symtab0x805089316FUNC<unknown>DEFAULT2
                                                _L_lock_32.symtab0x805444910FUNC<unknown>DEFAULT2
                                                _L_lock_34.symtab0x8054cfe13FUNC<unknown>DEFAULT2
                                                _L_lock_54.symtab0x804f3c916FUNC<unknown>DEFAULT2
                                                _L_lock_70.symtab0x8052bcc16FUNC<unknown>DEFAULT2
                                                _L_unlock_101.symtab0x8054d0b10FUNC<unknown>DEFAULT2
                                                _L_unlock_102.symtab0x80508b316FUNC<unknown>DEFAULT2
                                                _L_unlock_113.symtab0x804f40613FUNC<unknown>DEFAULT2
                                                _L_unlock_152.symtab0x80508d316FUNC<unknown>DEFAULT2
                                                _L_unlock_167.symtab0x8052bdc13FUNC<unknown>DEFAULT2
                                                _L_unlock_170.symtab0x80508f316FUNC<unknown>DEFAULT2
                                                _L_unlock_225.symtab0x804f7b013FUNC<unknown>DEFAULT2
                                                _L_unlock_232.symtab0x805091013FUNC<unknown>DEFAULT2
                                                _L_unlock_235.symtab0x804f7bd13FUNC<unknown>DEFAULT2
                                                _L_unlock_40.symtab0x80544e010FUNC<unknown>DEFAULT2
                                                _L_unlock_61.symtab0x805445310FUNC<unknown>DEFAULT2
                                                _L_unlock_66.symtab0x804f3d916FUNC<unknown>DEFAULT2
                                                _L_unlock_83.symtab0x804f3e913FUNC<unknown>DEFAULT2
                                                _L_unlock_86.symtab0x80508a316FUNC<unknown>DEFAULT2
                                                _READ.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                _WRITE.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                __CTOR_END__.symtab0x80585b00OBJECT<unknown>DEFAULT7
                                                __CTOR_LIST__.symtab0x80585ac0OBJECT<unknown>DEFAULT7
                                                __C_ctype_b.symtab0x805883c4OBJECT<unknown>DEFAULT11
                                                __C_ctype_b.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                __C_ctype_b_data.symtab0x8057690768OBJECT<unknown>DEFAULT4
                                                __DTOR_END__.symtab0x80585b80OBJECT<unknown>DEFAULT8
                                                __DTOR_LIST__.symtab0x80585b40OBJECT<unknown>DEFAULT8
                                                __EH_FRAME_BEGIN__.symtab0x80580000OBJECT<unknown>DEFAULT5
                                                __FRAME_END__.symtab0x80585a80OBJECT<unknown>DEFAULT5
                                                __GI___C_ctype_b.symtab0x805883c4OBJECT<unknown>HIDDEN11
                                                __GI___close.symtab0x8052d5080FUNC<unknown>HIDDEN2
                                                __GI___close_nocancel.symtab0x8052d5a27FUNC<unknown>HIDDEN2
                                                __GI___ctype_b.symtab0x80588404OBJECT<unknown>HIDDEN11
                                                __GI___errno_location.symtab0x804f20c13FUNC<unknown>HIDDEN2
                                                __GI___fcntl_nocancel.symtab0x804e97883FUNC<unknown>HIDDEN2
                                                __GI___fgetc_unlocked.symtab0x80544ec204FUNC<unknown>HIDDEN2
                                                __GI___glibc_strerror_r.symtab0x8050b8026FUNC<unknown>HIDDEN2
                                                __GI___libc_close.symtab0x8052d5080FUNC<unknown>HIDDEN2
                                                __GI___libc_fcntl.symtab0x804e9cb153FUNC<unknown>HIDDEN2
                                                __GI___libc_open.symtab0x8052da091FUNC<unknown>HIDDEN2
                                                __GI___libc_read.symtab0x8052e6091FUNC<unknown>HIDDEN2
                                                __GI___libc_write.symtab0x8052e0091FUNC<unknown>HIDDEN2
                                                __GI___open.symtab0x8052da091FUNC<unknown>HIDDEN2
                                                __GI___open_nocancel.symtab0x8052daa33FUNC<unknown>HIDDEN2
                                                __GI___read.symtab0x8052e6091FUNC<unknown>HIDDEN2
                                                __GI___read_nocancel.symtab0x8052e6a33FUNC<unknown>HIDDEN2
                                                __GI___sigaddset.symtab0x805111c32FUNC<unknown>HIDDEN2
                                                __GI___sigdelset.symtab0x805113c32FUNC<unknown>HIDDEN2
                                                __GI___sigismember.symtab0x80510f836FUNC<unknown>HIDDEN2
                                                __GI___uClibc_fini.symtab0x8052f9356FUNC<unknown>HIDDEN2
                                                __GI___uClibc_init.symtab0x8052ff739FUNC<unknown>HIDDEN2
                                                __GI___write.symtab0x8052e0091FUNC<unknown>HIDDEN2
                                                __GI___write_nocancel.symtab0x8052e0a33FUNC<unknown>HIDDEN2
                                                __GI___xpg_strerror_r.symtab0x8050b9c191FUNC<unknown>HIDDEN2
                                                __GI__exit.symtab0x80533a066FUNC<unknown>HIDDEN2
                                                __GI_abort.symtab0x8052098191FUNC<unknown>HIDDEN2
                                                __GI_accept.symtab0x8050cf884FUNC<unknown>HIDDEN2
                                                __GI_atoi.symtab0x80524c817FUNC<unknown>HIDDEN2
                                                __GI_bind.symtab0x8050d4c40FUNC<unknown>HIDDEN2
                                                __GI_brk.symtab0x805326044FUNC<unknown>HIDDEN2
                                                __GI_close.symtab0x8052d5080FUNC<unknown>HIDDEN2
                                                __GI_closedir.symtab0x804ef3c130FUNC<unknown>HIDDEN2
                                                __GI_config_close.symtab0x805392e44FUNC<unknown>HIDDEN2
                                                __GI_config_open.symtab0x805395a44FUNC<unknown>HIDDEN2
                                                __GI_config_read.symtab0x80536c4618FUNC<unknown>HIDDEN2
                                                __GI_connect.symtab0x8050d7484FUNC<unknown>HIDDEN2
                                                __GI_exit.symtab0x805260c93FUNC<unknown>HIDDEN2
                                                __GI_fclose.symtab0x804f240380FUNC<unknown>HIDDEN2
                                                __GI_fcntl.symtab0x804e9cb153FUNC<unknown>HIDDEN2
                                                __GI_fflush_unlocked.symtab0x80506c4447FUNC<unknown>HIDDEN2
                                                __GI_fgetc.symtab0x80543b8145FUNC<unknown>HIDDEN2
                                                __GI_fgetc_unlocked.symtab0x80544ec204FUNC<unknown>HIDDEN2
                                                __GI_fgets.symtab0x8054460118FUNC<unknown>HIDDEN2
                                                __GI_fgets_unlocked.symtab0x80545b894FUNC<unknown>HIDDEN2
                                                __GI_fopen.symtab0x804f41421FUNC<unknown>HIDDEN2
                                                __GI_fork.symtab0x80529c0524FUNC<unknown>HIDDEN2
                                                __GI_fputs_unlocked.symtab0x805092045FUNC<unknown>HIDDEN2
                                                __GI_fseek.symtab0x8054bf024FUNC<unknown>HIDDEN2
                                                __GI_fseeko64.symtab0x8054c08246FUNC<unknown>HIDDEN2
                                                __GI_fstat.symtab0x80533e470FUNC<unknown>HIDDEN2
                                                __GI_fwrite_unlocked.symtab0x8050950111FUNC<unknown>HIDDEN2
                                                __GI_getc_unlocked.symtab0x80544ec204FUNC<unknown>HIDDEN2
                                                __GI_getdtablesize.symtab0x80534b032FUNC<unknown>HIDDEN2
                                                __GI_getegid.symtab0x80534d08FUNC<unknown>HIDDEN2
                                                __GI_geteuid.symtab0x80534d88FUNC<unknown>HIDDEN2
                                                __GI_getgid.symtab0x80534e08FUNC<unknown>HIDDEN2
                                                __GI_getpagesize.symtab0x80534e819FUNC<unknown>HIDDEN2
                                                __GI_getpid.symtab0x8052bec49FUNC<unknown>HIDDEN2
                                                __GI_getrlimit.symtab0x80534fc43FUNC<unknown>HIDDEN2
                                                __GI_getsockname.symtab0x8050dc840FUNC<unknown>HIDDEN2
                                                __GI_getuid.symtab0x80535288FUNC<unknown>HIDDEN2
                                                __GI_inet_addr.symtab0x8050cd831FUNC<unknown>HIDDEN2
                                                __GI_inet_aton.symtab0x8054780148FUNC<unknown>HIDDEN2
                                                __GI_initstate_r.symtab0x805238b155FUNC<unknown>HIDDEN2
                                                __GI_ioctl.symtab0x804ea6c139FUNC<unknown>HIDDEN2
                                                __GI_isatty.symtab0x8050c5c27FUNC<unknown>HIDDEN2
                                                __GI_kill.symtab0x804eaf843FUNC<unknown>HIDDEN2
                                                __GI_listen.symtab0x8050e2832FUNC<unknown>HIDDEN2
                                                __GI_lseek.symtab0x805353047FUNC<unknown>HIDDEN2
                                                __GI_lseek64.symtab0x8054ec890FUNC<unknown>HIDDEN2
                                                __GI_memcpy.symtab0x80509c041FUNC<unknown>HIDDEN2
                                                __GI_memmove.symtab0x80509ec37FUNC<unknown>HIDDEN2
                                                __GI_mempcpy.symtab0x8054ea830FUNC<unknown>HIDDEN2
                                                __GI_memrchr.symtab0x8054670177FUNC<unknown>HIDDEN2
                                                __GI_memset.symtab0x8050a1450FUNC<unknown>HIDDEN2
                                                __GI_mkdir.symtab0x804eb2443FUNC<unknown>HIDDEN2
                                                __GI_mmap.symtab0x805332027FUNC<unknown>HIDDEN2
                                                __GI_mremap.symtab0x805356059FUNC<unknown>HIDDEN2
                                                __GI_munmap.symtab0x805359c43FUNC<unknown>HIDDEN2
                                                __GI_nanosleep.symtab0x80535f161FUNC<unknown>HIDDEN2
                                                __GI_open.symtab0x8052da091FUNC<unknown>HIDDEN2
                                                __GI_opendir.symtab0x804f048132FUNC<unknown>HIDDEN2
                                                __GI_raise.symtab0x8052c20100FUNC<unknown>HIDDEN2
                                                __GI_random.symtab0x805216066FUNC<unknown>HIDDEN2
                                                __GI_random_r.symtab0x805228c95FUNC<unknown>HIDDEN2
                                                __GI_read.symtab0x8052e6091FUNC<unknown>HIDDEN2
                                                __GI_readdir.symtab0x804f138127FUNC<unknown>HIDDEN2
                                                __GI_readdir64.symtab0x8053640129FUNC<unknown>HIDDEN2
                                                __GI_readlink.symtab0x804ebc847FUNC<unknown>HIDDEN2
                                                __GI_recv.symtab0x8050e4892FUNC<unknown>HIDDEN2
                                                __GI_recvfrom.symtab0x8050ea4108FUNC<unknown>HIDDEN2
                                                __GI_sbrk.symtab0x804ebf864FUNC<unknown>HIDDEN2
                                                __GI_select.symtab0x804ec71108FUNC<unknown>HIDDEN2
                                                __GI_send.symtab0x8050f1092FUNC<unknown>HIDDEN2
                                                __GI_sendto.symtab0x8050f6c108FUNC<unknown>HIDDEN2
                                                __GI_setsid.symtab0x804ece031FUNC<unknown>HIDDEN2
                                                __GI_setsockopt.symtab0x8050fd856FUNC<unknown>HIDDEN2
                                                __GI_setstate_r.symtab0x8052426161FUNC<unknown>HIDDEN2
                                                __GI_sigaction.symtab0x80532ab80FUNC<unknown>HIDDEN2
                                                __GI_sigaddset.symtab0x805103834FUNC<unknown>HIDDEN2
                                                __GI_sigemptyset.symtab0x805105c20FUNC<unknown>HIDDEN2
                                                __GI_signal.symtab0x8051070136FUNC<unknown>HIDDEN2
                                                __GI_sigprocmask.symtab0x804ed0097FUNC<unknown>HIDDEN2
                                                __GI_sleep.symtab0x8052c84195FUNC<unknown>HIDDEN2
                                                __GI_snprintf.symtab0x804f42c32FUNC<unknown>HIDDEN2
                                                __GI_socket.symtab0x805101040FUNC<unknown>HIDDEN2
                                                __GI_srandom_r.symtab0x80522eb160FUNC<unknown>HIDDEN2
                                                __GI_stat.symtab0x804ed6470FUNC<unknown>HIDDEN2
                                                __GI_strcat.symtab0x8050a4835FUNC<unknown>HIDDEN2
                                                __GI_strchr.symtab0x805461830FUNC<unknown>HIDDEN2
                                                __GI_strchrnul.symtab0x805463825FUNC<unknown>HIDDEN2
                                                __GI_strcmp.symtab0x8050a6c29FUNC<unknown>HIDDEN2
                                                __GI_strcoll.symtab0x8050a6c29FUNC<unknown>HIDDEN2
                                                __GI_strcspn.symtab0x805472445FUNC<unknown>HIDDEN2
                                                __GI_strlen.symtab0x8050a8c19FUNC<unknown>HIDDEN2
                                                __GI_strnlen.symtab0x8050aa024FUNC<unknown>HIDDEN2
                                                __GI_strrchr.symtab0x805465426FUNC<unknown>HIDDEN2
                                                __GI_strspn.symtab0x805475442FUNC<unknown>HIDDEN2
                                                __GI_strstr.symtab0x8050ab8197FUNC<unknown>HIDDEN2
                                                __GI_strtol.symtab0x80524dc23FUNC<unknown>HIDDEN2
                                                __GI_sysconf.symtab0x8052730523FUNC<unknown>HIDDEN2
                                                __GI_tcgetattr.symtab0x8050c7896FUNC<unknown>HIDDEN2
                                                __GI_time.symtab0x804edac16FUNC<unknown>HIDDEN2
                                                __GI_times.symtab0x805363016FUNC<unknown>HIDDEN2
                                                __GI_uname.symtab0x804ede439FUNC<unknown>HIDDEN2
                                                __GI_vsnprintf.symtab0x804f44c172FUNC<unknown>HIDDEN2
                                                __GI_wcrtomb.symtab0x805398863FUNC<unknown>HIDDEN2
                                                __GI_wcsnrtombs.symtab0x80539e4128FUNC<unknown>HIDDEN2
                                                __GI_wcsrtombs.symtab0x80539c827FUNC<unknown>HIDDEN2
                                                __GI_write.symtab0x8052e0091FUNC<unknown>HIDDEN2
                                                __JCR_END__.symtab0x80585bc0OBJECT<unknown>DEFAULT9
                                                __JCR_LIST__.symtab0x80585bc0OBJECT<unknown>DEFAULT9
                                                __app_fini.symtab0x805ae944OBJECT<unknown>HIDDEN12
                                                __atexit_lock.symtab0x805881824OBJECT<unknown>DEFAULT11
                                                __bss_start.symtab0x80588440NOTYPE<unknown>DEFAULTSHN_ABS
                                                __check_one_fd.symtab0x8052fcb44FUNC<unknown>DEFAULT2
                                                __close.symtab0x8052d5080FUNC<unknown>DEFAULT2
                                                __close_nocancel.symtab0x8052d5a27FUNC<unknown>DEFAULT2
                                                __ctype_b.symtab0x80588404OBJECT<unknown>DEFAULT11
                                                __curbrk.symtab0x805ae9c4OBJECT<unknown>HIDDEN12
                                                __deregister_frame_info_bases.symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                                __do_global_ctors_aux.symtab0x8054f300FUNC<unknown>DEFAULT2
                                                __do_global_dtors_aux.symtab0x80480e00FUNC<unknown>DEFAULT2
                                                __dso_handle.symtab0x80585e00OBJECT<unknown>HIDDEN11
                                                __environ.symtab0x805ae8c4OBJECT<unknown>DEFAULT12
                                                __errno_location.symtab0x804f20c13FUNC<unknown>DEFAULT2
                                                __errno_location.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                __exit_cleanup.symtab0x805a93c4OBJECT<unknown>HIDDEN12
                                                __fcntl_nocancel.symtab0x804e97883FUNC<unknown>DEFAULT2
                                                __fgetc_unlocked.symtab0x80544ec204FUNC<unknown>DEFAULT2
                                                __fini_array_end.symtab0x80585ac0NOTYPE<unknown>HIDDEN6
                                                __fini_array_start.symtab0x80585ac0NOTYPE<unknown>HIDDEN6
                                                __fork.symtab0x80529c0524FUNC<unknown>DEFAULT2
                                                __fork_generation_pointer.symtab0x805b9a04OBJECT<unknown>HIDDEN12
                                                __fork_handlers.symtab0x805b9a44OBJECT<unknown>HIDDEN12
                                                __fork_lock.symtab0x805a9404OBJECT<unknown>HIDDEN12
                                                __get_pc_thunk_bx.symtab0x80480d00FUNC<unknown>HIDDEN2
                                                __getdents.symtab0x805342c131FUNC<unknown>HIDDEN2
                                                __getdents64.symtab0x8054ad8280FUNC<unknown>HIDDEN2
                                                __getpagesize.symtab0x80534e819FUNC<unknown>DEFAULT2
                                                __getpid.symtab0x8052bec49FUNC<unknown>DEFAULT2
                                                __glibc_strerror_r.symtab0x8050b8026FUNC<unknown>DEFAULT2
                                                __glibc_strerror_r.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                __h_errno_location.symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                                __init_array_end.symtab0x80585ac0NOTYPE<unknown>HIDDEN6
                                                __init_array_start.symtab0x80585ac0NOTYPE<unknown>HIDDEN6
                                                __libc_accept.symtab0x8050cf884FUNC<unknown>DEFAULT2
                                                __libc_close.symtab0x8052d5080FUNC<unknown>DEFAULT2
                                                __libc_connect.symtab0x8050d7484FUNC<unknown>DEFAULT2
                                                __libc_disable_asynccancel.symtab0x8052ebc86FUNC<unknown>HIDDEN2
                                                __libc_enable_asynccancel.symtab0x8052f1279FUNC<unknown>HIDDEN2
                                                __libc_errno.symtab0x04TLS<unknown>HIDDEN6
                                                __libc_fcntl.symtab0x804e9cb153FUNC<unknown>DEFAULT2
                                                __libc_fork.symtab0x80529c0524FUNC<unknown>DEFAULT2
                                                __libc_h_errno.symtab0x44TLS<unknown>HIDDEN6
                                                __libc_nanosleep.symtab0x80535f161FUNC<unknown>DEFAULT2
                                                __libc_open.symtab0x8052da091FUNC<unknown>DEFAULT2
                                                __libc_read.symtab0x8052e6091FUNC<unknown>DEFAULT2
                                                __libc_recv.symtab0x8050e4892FUNC<unknown>DEFAULT2
                                                __libc_recvfrom.symtab0x8050ea4108FUNC<unknown>DEFAULT2
                                                __libc_select.symtab0x804ec71108FUNC<unknown>DEFAULT2
                                                __libc_send.symtab0x8050f1092FUNC<unknown>DEFAULT2
                                                __libc_sendto.symtab0x8050f6c108FUNC<unknown>DEFAULT2
                                                __libc_setup_tls.symtab0x805486e513FUNC<unknown>DEFAULT2
                                                __libc_sigaction.symtab0x80532ab80FUNC<unknown>DEFAULT2
                                                __libc_stack_end.symtab0x805ae884OBJECT<unknown>DEFAULT12
                                                __libc_write.symtab0x8052e0091FUNC<unknown>DEFAULT2
                                                __lll_lock_wait_private.symtab0x805297040FUNC<unknown>HIDDEN2
                                                __lll_unlock_wake_private.symtab0x80529a032FUNC<unknown>HIDDEN2
                                                __malloc_consolidate.symtab0x8051d71379FUNC<unknown>HIDDEN2
                                                __malloc_largebin_index.symtab0x805115c38FUNC<unknown>DEFAULT2
                                                __malloc_lock.symtab0x805873c24OBJECT<unknown>DEFAULT11
                                                __malloc_state.symtab0x805b628888OBJECT<unknown>DEFAULT12
                                                __malloc_trim.symtab0x8051cf4125FUNC<unknown>DEFAULT2
                                                __nptl_deallocate_tsd.symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                                __nptl_nthreads.symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                                __open.symtab0x8052da091FUNC<unknown>DEFAULT2
                                                __open_nocancel.symtab0x8052daa33FUNC<unknown>DEFAULT2
                                                __pagesize.symtab0x805ae904OBJECT<unknown>DEFAULT12
                                                __preinit_array_end.symtab0x80585ac0NOTYPE<unknown>HIDDEN6
                                                __preinit_array_start.symtab0x80585ac0NOTYPE<unknown>HIDDEN6
                                                __progname.symtab0x80588344OBJECT<unknown>DEFAULT11
                                                __progname_full.symtab0x80588384OBJECT<unknown>DEFAULT11
                                                __pthread_initialize_minimal.symtab0x8054a6f15FUNC<unknown>DEFAULT2
                                                __pthread_mutex_init.symtab0x8052f673FUNC<unknown>DEFAULT2
                                                __pthread_mutex_lock.symtab0x8052f643FUNC<unknown>DEFAULT2
                                                __pthread_mutex_trylock.symtab0x8052f643FUNC<unknown>DEFAULT2
                                                __pthread_mutex_unlock.symtab0x8052f643FUNC<unknown>DEFAULT2
                                                __pthread_return_0.symtab0x8052f643FUNC<unknown>DEFAULT2
                                                __pthread_unwind.symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                                __read.symtab0x8052e6091FUNC<unknown>DEFAULT2
                                                __read_nocancel.symtab0x8052e6a33FUNC<unknown>DEFAULT2
                                                __register_frame_info_bases.symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                                __restore.symtab0x80532a30NOTYPE<unknown>DEFAULT2
                                                __restore_rt.symtab0x805329c0NOTYPE<unknown>DEFAULT2
                                                __rtld_fini.symtab0x805ae984OBJECT<unknown>HIDDEN12
                                                __sigaddset.symtab0x805111c32FUNC<unknown>DEFAULT2
                                                __sigdelset.symtab0x805113c32FUNC<unknown>DEFAULT2
                                                __sigismember.symtab0x80510f836FUNC<unknown>DEFAULT2
                                                __socketcall.symtab0x805333c43FUNC<unknown>HIDDEN2
                                                __socketcall.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                __stdin.symtab0x805865c4OBJECT<unknown>DEFAULT11
                                                __stdio_READ.symtab0x8054d1862FUNC<unknown>HIDDEN2
                                                __stdio_WRITE.symtab0x8053a64139FUNC<unknown>HIDDEN2
                                                __stdio_adjust_position.symtab0x8054d58154FUNC<unknown>HIDDEN2
                                                __stdio_fwrite.symtab0x8053af0232FUNC<unknown>HIDDEN2
                                                __stdio_rfill.symtab0x8054df437FUNC<unknown>HIDDEN2
                                                __stdio_seek.symtab0x8054e7846FUNC<unknown>HIDDEN2
                                                __stdio_trans2r_o.symtab0x8054e1c92FUNC<unknown>HIDDEN2
                                                __stdio_trans2w_o.symtab0x8053bd8154FUNC<unknown>HIDDEN2
                                                __stdio_wcommit.symtab0x804f8d837FUNC<unknown>HIDDEN2
                                                __stdout.symtab0x80586604OBJECT<unknown>DEFAULT11
                                                __syscall_error.symtab0x805328c15FUNC<unknown>HIDDEN2
                                                __syscall_error.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                __syscall_fcntl.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                __syscall_nanosleep.symtab0x80535c841FUNC<unknown>DEFAULT2
                                                __syscall_rt_sigaction.symtab0x805336853FUNC<unknown>DEFAULT2
                                                __syscall_rt_sigaction.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                __syscall_select.symtab0x804ec3857FUNC<unknown>DEFAULT2
                                                __uClibc_fini.symtab0x8052f9356FUNC<unknown>DEFAULT2
                                                __uClibc_init.symtab0x8052ff739FUNC<unknown>DEFAULT2
                                                __uClibc_main.symtab0x805301e577FUNC<unknown>DEFAULT2
                                                __uClibc_main.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                __uclibc_progname.symtab0x80588304OBJECT<unknown>HIDDEN11
                                                __write.symtab0x8052e0091FUNC<unknown>DEFAULT2
                                                __write_nocancel.symtab0x8052e0a33FUNC<unknown>DEFAULT2
                                                __xpg_strerror_r.symtab0x8050b9c191FUNC<unknown>DEFAULT2
                                                __xpg_strerror_r.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                __xstat32_conv.symtab0x804eeaf138FUNC<unknown>HIDDEN2
                                                __xstat64_conv.symtab0x804ee0c163FUNC<unknown>HIDDEN2
                                                _adjust_pos.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                _bss_custom_printf_spec.symtab0x805a92c10OBJECT<unknown>DEFAULT12
                                                _charpad.symtab0x804f90053FUNC<unknown>DEFAULT2
                                                _cs_funcs.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                _custom_printf_arginfo.symtab0x805b5d040OBJECT<unknown>HIDDEN12
                                                _custom_printf_handler.symtab0x805b5f840OBJECT<unknown>HIDDEN12
                                                _custom_printf_spec.symtab0x80587384OBJECT<unknown>HIDDEN11
                                                _dl_aux_init.symtab0x8054a8018FUNC<unknown>DEFAULT2
                                                _dl_nothread_init_static_tls.symtab0x8054a9268FUNC<unknown>HIDDEN2
                                                _dl_phdr.symtab0x805b9c84OBJECT<unknown>DEFAULT12
                                                _dl_phnum.symtab0x805b9cc4OBJECT<unknown>DEFAULT12
                                                _dl_tls_dtv_gaps.symtab0x805b9bc1OBJECT<unknown>DEFAULT12
                                                _dl_tls_dtv_slotinfo_list.symtab0x805b9b84OBJECT<unknown>DEFAULT12
                                                _dl_tls_generation.symtab0x805b9c04OBJECT<unknown>DEFAULT12
                                                _dl_tls_max_dtv_idx.symtab0x805b9b04OBJECT<unknown>DEFAULT12
                                                _dl_tls_setup.symtab0x805483e48FUNC<unknown>DEFAULT2
                                                _dl_tls_static_align.symtab0x805b9ac4OBJECT<unknown>DEFAULT12
                                                _dl_tls_static_nelem.symtab0x805b9c44OBJECT<unknown>DEFAULT12
                                                _dl_tls_static_size.symtab0x805b9b44OBJECT<unknown>DEFAULT12
                                                _dl_tls_static_used.symtab0x805b9a84OBJECT<unknown>DEFAULT12
                                                _edata.symtab0x80588440NOTYPE<unknown>DEFAULTSHN_ABS
                                                _end.symtab0x805b9d00NOTYPE<unknown>DEFAULTSHN_ABS
                                                _exit.symtab0x80533a066FUNC<unknown>DEFAULT2
                                                _exit.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                _fini.symtab0x8054f570FUNC<unknown>DEFAULT3
                                                _fixed_buffers.symtab0x805892c8192OBJECT<unknown>DEFAULT12
                                                _fopen.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                _fp_out_narrow.symtab0x804f93594FUNC<unknown>DEFAULT2
                                                _fpmaxtostr.symtab0x8053df01479FUNC<unknown>HIDDEN2
                                                _fpmaxtostr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                _fwrite.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                _init.symtab0x80480b40FUNC<unknown>DEFAULT1
                                                _load_inttype.symtab0x8053c7486FUNC<unknown>HIDDEN2
                                                _load_inttype.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                _ppfs_init.symtab0x804ff90103FUNC<unknown>HIDDEN2
                                                _ppfs_init.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                _ppfs_parsespec.symtab0x80501751036FUNC<unknown>HIDDEN2
                                                _ppfs_parsespec.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                _ppfs_prepargs.symtab0x804fff857FUNC<unknown>HIDDEN2
                                                _ppfs_prepargs.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                _ppfs_setargs.symtab0x8050034277FUNC<unknown>HIDDEN2
                                                _ppfs_setargs.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                _promoted_size.symtab0x805014c41FUNC<unknown>DEFAULT2
                                                _pthread_cleanup_pop_restore.symtab0x8052f7c23FUNC<unknown>DEFAULT2
                                                _pthread_cleanup_push_defer.symtab0x8052f6a18FUNC<unknown>DEFAULT2
                                                _rfill.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                _setjmp.symtab0x80532fc34FUNC<unknown>DEFAULT2
                                                _sigintr.symtab0x805b6208OBJECT<unknown>HIDDEN12
                                                _start.symtab0x804818434FUNC<unknown>DEFAULT2
                                                _stdio.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                _stdio_fopen.symtab0x804f4f8664FUNC<unknown>HIDDEN2
                                                _stdio_init.symtab0x804f7cc59FUNC<unknown>HIDDEN2
                                                _stdio_openlist.symtab0x80586644OBJECT<unknown>DEFAULT11
                                                _stdio_openlist_add_lock.symtab0x805890c12OBJECT<unknown>DEFAULT12
                                                _stdio_openlist_dec_use.symtab0x8050584320FUNC<unknown>HIDDEN2
                                                _stdio_openlist_del_count.symtab0x80589284OBJECT<unknown>DEFAULT12
                                                _stdio_openlist_del_lock.symtab0x805891812OBJECT<unknown>DEFAULT12
                                                _stdio_openlist_use_count.symtab0x80589244OBJECT<unknown>DEFAULT12
                                                _stdio_streams.symtab0x805866c204OBJECT<unknown>DEFAULT11
                                                _stdio_term.symtab0x804f807208FUNC<unknown>HIDDEN2
                                                _stdio_user_locking.symtab0x80586684OBJECT<unknown>DEFAULT11
                                                _stdlib_strto_l.symtab0x80524f4278FUNC<unknown>HIDDEN2
                                                _stdlib_strto_l.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                _store_inttype.symtab0x8053ccc61FUNC<unknown>HIDDEN2
                                                _store_inttype.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                _string_syserrmsgs.symtab0x80567182906OBJECT<unknown>HIDDEN4
                                                _string_syserrmsgs.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                _trans2r.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                _trans2w.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                _uintmaxtostr.symtab0x8053d0c228FUNC<unknown>HIDDEN2
                                                _uintmaxtostr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                _vfprintf_internal.symtab0x804f9931530FUNC<unknown>HIDDEN2
                                                _vfprintf_internal.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                _wcommit.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                abort.symtab0x8052098191FUNC<unknown>DEFAULT2
                                                abort.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                accept.symtab0x8050cf884FUNC<unknown>DEFAULT2
                                                accept.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                anti_gdb_entry.symtab0x804cc0011FUNC<unknown>DEFAULT2
                                                atoi.symtab0x80524c817FUNC<unknown>DEFAULT2
                                                atol.symtab0x80524c817FUNC<unknown>DEFAULT2
                                                atol.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                attack.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                attack_get_opt_int.symtab0x80485b0109FUNC<unknown>DEFAULT2
                                                attack_get_opt_ip.symtab0x8048540101FUNC<unknown>DEFAULT2
                                                attack_get_opt_str.symtab0x80481b092FUNC<unknown>DEFAULT2
                                                attack_init.symtab0x80486201076FUNC<unknown>DEFAULT2
                                                attack_nudp.symtab0x804c1501350FUNC<unknown>DEFAULT2
                                                attack_parse.symtab0x80482d0613FUNC<unknown>DEFAULT2
                                                attack_start.symtab0x8048210192FUNC<unknown>DEFAULT2
                                                attack_tcp_ack.symtab0x804a4501433FUNC<unknown>DEFAULT2
                                                attack_tcp_bypass.symtab0x804b770840FUNC<unknown>DEFAULT2
                                                attack_tcp_psh.symtab0x8049ea01441FUNC<unknown>DEFAULT2
                                                attack_tcp_stomp.symtab0x804bac01679FUNC<unknown>DEFAULT2
                                                attack_tcp_syn.symtab0x804a9f01350FUNC<unknown>DEFAULT2
                                                attack_tcp_wra.symtab0x804af402082FUNC<unknown>DEFAULT2
                                                attack_udp_an.symtab0x80492c0717FUNC<unknown>DEFAULT2
                                                attack_udp_bypass.symtab0x8049990576FUNC<unknown>DEFAULT2
                                                attack_udp_custom.symtab0x80495901011FUNC<unknown>DEFAULT2
                                                attack_udp_hex.symtab0x8048ff0719FUNC<unknown>DEFAULT2
                                                attack_udp_plain.symtab0x8049bd0718FUNC<unknown>DEFAULT2
                                                attack_udp_random.symtab0x8048a60689FUNC<unknown>DEFAULT2
                                                attack_udp_str.symtab0x8048d20717FUNC<unknown>DEFAULT2
                                                attacks.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                been_there_done_that.symtab0x805a9381OBJECT<unknown>DEFAULT12
                                                bind.symtab0x8050d4c40FUNC<unknown>DEFAULT2
                                                bind.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                brk.symtab0x805326044FUNC<unknown>DEFAULT2
                                                brk.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                bsd_signal.symtab0x8051070136FUNC<unknown>DEFAULT2
                                                calloc.symtab0x805190c236FUNC<unknown>DEFAULT2
                                                calloc.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                checkDevice.symtab0x804cb90110FUNC<unknown>DEFAULT2
                                                check_real_path.symtab0x804c850283FUNC<unknown>DEFAULT2
                                                checksum.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                checksum_generic.symtab0x804c6a070FUNC<unknown>DEFAULT2
                                                checksum_tcpudp.symtab0x804c6f0169FUNC<unknown>DEFAULT2
                                                clock.symtab0x804f21c34FUNC<unknown>DEFAULT2
                                                clock.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                close.symtab0x8052d5080FUNC<unknown>DEFAULT2
                                                closedir.symtab0x804ef3c130FUNC<unknown>DEFAULT2
                                                closedir.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                completed.4963.symtab0x80588601OBJECT<unknown>DEFAULT12
                                                connect.symtab0x8050d7484FUNC<unknown>DEFAULT2
                                                connect.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                crtstuff.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                crtstuff.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                dl-support.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                ensure_single_instance.symtab0x804cc10299FUNC<unknown>DEFAULT2
                                                entries.symtab0x805b3e04OBJECT<unknown>DEFAULT12
                                                environ.symtab0x805ae8c4OBJECT<unknown>DEFAULT12
                                                errno.symtab0x04TLS<unknown>DEFAULT6
                                                errno.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                exit.symtab0x805260c93FUNC<unknown>DEFAULT2
                                                exit.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                exp10_table.symtab0x80579b0156OBJECT<unknown>DEFAULT4
                                                fclose.symtab0x804f240380FUNC<unknown>DEFAULT2
                                                fclose.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                fcntl.symtab0x804e9cb153FUNC<unknown>DEFAULT2
                                                fd_ctrl.symtab0x80585e84OBJECT<unknown>DEFAULT11
                                                fd_serv.symtab0x80585ec4OBJECT<unknown>DEFAULT11
                                                fd_to_DIR.symtab0x804efc0136FUNC<unknown>DEFAULT2
                                                fdopendir.symtab0x804f0cc108FUNC<unknown>DEFAULT2
                                                fflush_unlocked.symtab0x80506c4447FUNC<unknown>DEFAULT2
                                                fflush_unlocked.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                fgetc.symtab0x80543b8145FUNC<unknown>DEFAULT2
                                                fgetc.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                fgetc_unlocked.symtab0x80544ec204FUNC<unknown>DEFAULT2
                                                fgetc_unlocked.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                fgets.symtab0x8054460118FUNC<unknown>DEFAULT2
                                                fgets.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                fgets_unlocked.symtab0x80545b894FUNC<unknown>DEFAULT2
                                                fgets_unlocked.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                fmt.symtab0x805799020OBJECT<unknown>DEFAULT4
                                                fopen.symtab0x804f41421FUNC<unknown>DEFAULT2
                                                fopen.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                fork.symtab0x80529c0524FUNC<unknown>DEFAULT2
                                                fork.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                fork_handler_pool.symtab0x805a9441348OBJECT<unknown>DEFAULT12
                                                fputs_unlocked.symtab0x805092045FUNC<unknown>DEFAULT2
                                                fputs_unlocked.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                frame_dummy.symtab0x80481300FUNC<unknown>DEFAULT2
                                                free.symtab0x8051eec399FUNC<unknown>DEFAULT2
                                                free.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                fseek.symtab0x8054bf024FUNC<unknown>DEFAULT2
                                                fseeko.symtab0x8054bf024FUNC<unknown>DEFAULT2
                                                fseeko.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                fseeko64.symtab0x8054c08246FUNC<unknown>DEFAULT2
                                                fseeko64.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                fstat.symtab0x80533e470FUNC<unknown>DEFAULT2
                                                fstat.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                fwrite_unlocked.symtab0x8050950111FUNC<unknown>DEFAULT2
                                                fwrite_unlocked.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                getc.symtab0x80543b8145FUNC<unknown>DEFAULT2
                                                getc_unlocked.symtab0x80544ec204FUNC<unknown>DEFAULT2
                                                getdents.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                getdents64.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                getdtablesize.symtab0x80534b032FUNC<unknown>DEFAULT2
                                                getdtablesize.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                getegid.symtab0x80534d08FUNC<unknown>DEFAULT2
                                                getegid.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                geteuid.symtab0x80534d88FUNC<unknown>DEFAULT2
                                                geteuid.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                getgid.symtab0x80534e08FUNC<unknown>DEFAULT2
                                                getgid.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                getpagesize.symtab0x80534e819FUNC<unknown>DEFAULT2
                                                getpagesize.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                getpid.symtab0x8052bec49FUNC<unknown>DEFAULT2
                                                getpid.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                getppid.symtab0x804ea648FUNC<unknown>DEFAULT2
                                                getppid.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                getrlimit.symtab0x80534fc43FUNC<unknown>DEFAULT2
                                                getrlimit.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                getsockname.symtab0x8050dc840FUNC<unknown>DEFAULT2
                                                getsockname.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                getsockopt.symtab0x8050df056FUNC<unknown>DEFAULT2
                                                getsockopt.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                getuid.symtab0x80535288FUNC<unknown>DEFAULT2
                                                getuid.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                goodbyeee.symtab0x804c83028FUNC<unknown>DEFAULT2
                                                h_errno.symtab0x44TLS<unknown>DEFAULT6
                                                huawei.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                index.symtab0x805461830FUNC<unknown>DEFAULT2
                                                inet_addr.symtab0x8050cd831FUNC<unknown>DEFAULT2
                                                inet_aton.symtab0x8054780148FUNC<unknown>DEFAULT2
                                                inet_aton.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                inet_makeaddr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                initKiller.symtab0x804c970532FUNC<unknown>DEFAULT2
                                                init_static_tls.symtab0x805481442FUNC<unknown>DEFAULT2
                                                initfini.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                initstate.symtab0x80521f985FUNC<unknown>DEFAULT2
                                                initstate_r.symtab0x805238b155FUNC<unknown>DEFAULT2
                                                ioctl.symtab0x804ea6c139FUNC<unknown>DEFAULT2
                                                ioctl.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                isatty.symtab0x8050c5c27FUNC<unknown>DEFAULT2
                                                isatty.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                kethead.symtab0x805860072OBJECT<unknown>DEFAULT11
                                                kill.symtab0x804eaf843FUNC<unknown>DEFAULT2
                                                kill.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                kill.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                killer_pid.symtab0x80588844OBJECT<unknown>DEFAULT12
                                                libc-cancellation.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                libc-tls.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                listen.symtab0x8050e2832FUNC<unknown>DEFAULT2
                                                listen.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                llseek.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                local_bind.5475.symtab0x80586481OBJECT<unknown>DEFAULT11
                                                lseek.symtab0x805353047FUNC<unknown>DEFAULT2
                                                lseek.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                lseek64.symtab0x8054ec890FUNC<unknown>DEFAULT2
                                                main.symtab0x804cdc02085FUNC<unknown>DEFAULT2
                                                main.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                main_pid.symtab0x805b3e44OBJECT<unknown>DEFAULT12
                                                malloc.symtab0x80511821928FUNC<unknown>DEFAULT2
                                                malloc.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                malloc_trim.symtab0x805207b29FUNC<unknown>DEFAULT2
                                                memcpy.symtab0x80509c041FUNC<unknown>DEFAULT2
                                                memcpy.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                memmove.symtab0x80509ec37FUNC<unknown>DEFAULT2
                                                memmove.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                memory.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                mempcpy.symtab0x8054ea830FUNC<unknown>DEFAULT2
                                                mempcpy.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                memrchr.symtab0x8054670177FUNC<unknown>DEFAULT2
                                                memrchr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                memset.symtab0x8050a1450FUNC<unknown>DEFAULT2
                                                memset.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                methods.symtab0x80588804OBJECT<unknown>DEFAULT12
                                                methods_len.symtab0x805887c1OBJECT<unknown>DEFAULT12
                                                mkdir.symtab0x804eb2443FUNC<unknown>DEFAULT2
                                                mkdir.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                mmap.symtab0x805332027FUNC<unknown>DEFAULT2
                                                mntdir.symtab0x804c7f059FUNC<unknown>DEFAULT2
                                                mount.symtab0x804eb5059FUNC<unknown>DEFAULT2
                                                mount.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                mremap.symtab0x805356059FUNC<unknown>DEFAULT2
                                                mremap.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                munmap.symtab0x805359c43FUNC<unknown>DEFAULT2
                                                munmap.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                mylock.symtab0x805875424OBJECT<unknown>DEFAULT11
                                                mylock.symtab0x805876c24OBJECT<unknown>DEFAULT11
                                                nanosleep.symtab0x80535f161FUNC<unknown>DEFAULT2
                                                nanosleep.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                nprocessors_onln.symtab0x805266c196FUNC<unknown>DEFAULT2
                                                object.4975.symtab0x805886424OBJECT<unknown>DEFAULT12
                                                open.symtab0x8052da091FUNC<unknown>DEFAULT2
                                                opendir.symtab0x804f048132FUNC<unknown>DEFAULT2
                                                opendir.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                p.4961.symtab0x80585e40OBJECT<unknown>DEFAULT11
                                                parse_config.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                pending_connection.symtab0x80588f81OBJECT<unknown>DEFAULT12
                                                prctl.symtab0x804eb8c59FUNC<unknown>DEFAULT2
                                                prctl.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                prefix.6454.symtab0x805667012OBJECT<unknown>DEFAULT4
                                                program_invocation_name.symtab0x80588384OBJECT<unknown>DEFAULT11
                                                program_invocation_short_name.symtab0x80588344OBJECT<unknown>DEFAULT11
                                                pseudo_cancel.symtab0x8052d750NOTYPE<unknown>DEFAULT2
                                                pseudo_cancel.symtab0x8052dcb0NOTYPE<unknown>DEFAULT2
                                                pseudo_cancel.symtab0x8052e2b0NOTYPE<unknown>DEFAULT2
                                                pseudo_cancel.symtab0x8052e8b0NOTYPE<unknown>DEFAULT2
                                                pseudo_end.symtab0x8052d9f0NOTYPE<unknown>DEFAULT2
                                                pseudo_end.symtab0x8052dfa0NOTYPE<unknown>DEFAULT2
                                                pseudo_end.symtab0x8052e5a0NOTYPE<unknown>DEFAULT2
                                                pseudo_end.symtab0x8052eba0NOTYPE<unknown>DEFAULT2
                                                qual_chars.6463.symtab0x805668420OBJECT<unknown>DEFAULT4
                                                raise.symtab0x8052c20100FUNC<unknown>DEFAULT2
                                                raise.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                rand.symtab0x80521585FUNC<unknown>DEFAULT2
                                                rand.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                rand.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                rand_init.symtab0x804d63063FUNC<unknown>DEFAULT2
                                                rand_next.symtab0x804d5f064FUNC<unknown>DEFAULT2
                                                rand_str.symtab0x804d670218FUNC<unknown>DEFAULT2
                                                random.symtab0x805216066FUNC<unknown>DEFAULT2
                                                random.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                random_poly_info.symtab0x805727410OBJECT<unknown>DEFAULT4
                                                random_r.symtab0x805228c95FUNC<unknown>DEFAULT2
                                                random_r.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                randtbl.symtab0x8058798128OBJECT<unknown>DEFAULT11
                                                read.symtab0x8052e6091FUNC<unknown>DEFAULT2
                                                readdir.symtab0x804f138127FUNC<unknown>DEFAULT2
                                                readdir.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                readdir64.symtab0x8053640129FUNC<unknown>DEFAULT2
                                                readdir64.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                readlink.symtab0x804ebc847FUNC<unknown>DEFAULT2
                                                readlink.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                realloc.symtab0x80519f8763FUNC<unknown>DEFAULT2
                                                realloc.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                recv.symtab0x8050e4892FUNC<unknown>DEFAULT2
                                                recv.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                recvfrom.symtab0x8050ea4108FUNC<unknown>DEFAULT2
                                                recvfrom.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                register-atfork.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                resolv.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                resolv_entries_free.symtab0x804d75052FUNC<unknown>DEFAULT2
                                                resolv_lookup.symtab0x804d7901192FUNC<unknown>DEFAULT2
                                                resolve_cnc_addr.symtab0x804cd40126FUNC<unknown>DEFAULT2
                                                resolve_func.symtab0x80585f04OBJECT<unknown>DEFAULT11
                                                rewinddir.symtab0x804f1b882FUNC<unknown>DEFAULT2
                                                rewinddir.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                rindex.symtab0x805465426FUNC<unknown>DEFAULT2
                                                sbrk.symtab0x804ebf864FUNC<unknown>DEFAULT2
                                                sbrk.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                scanner.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                select.symtab0x804ec71108FUNC<unknown>DEFAULT2
                                                select.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                send.symtab0x8050f1092FUNC<unknown>DEFAULT2
                                                send.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                sendto.symtab0x8050f6c108FUNC<unknown>DEFAULT2
                                                sendto.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                setsid.symtab0x804ece031FUNC<unknown>DEFAULT2
                                                setsid.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                setsockopt.symtab0x8050fd856FUNC<unknown>DEFAULT2
                                                setsockopt.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                setstate.symtab0x80521a287FUNC<unknown>DEFAULT2
                                                setstate_r.symtab0x8052426161FUNC<unknown>DEFAULT2
                                                sigaction.symtab0x80532ab80FUNC<unknown>DEFAULT2
                                                sigaction.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                sigaddset.symtab0x805103834FUNC<unknown>DEFAULT2
                                                sigaddset.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                sigempty.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                sigemptyset.symtab0x805105c20FUNC<unknown>DEFAULT2
                                                signal.symtab0x8051070136FUNC<unknown>DEFAULT2
                                                signal.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                sigprocmask.symtab0x804ed0097FUNC<unknown>DEFAULT2
                                                sigprocmask.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                sigsetops.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                sleep.symtab0x8052c84195FUNC<unknown>DEFAULT2
                                                sleep.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                snprintf.symtab0x804f42c32FUNC<unknown>DEFAULT2
                                                snprintf.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                socket.symtab0x805101040FUNC<unknown>DEFAULT2
                                                socket.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                spec_and_mask.6462.symtab0x805669816OBJECT<unknown>DEFAULT4
                                                spec_base.6453.symtab0x805667c7OBJECT<unknown>DEFAULT4
                                                spec_chars.6459.symtab0x80566e821OBJECT<unknown>DEFAULT4
                                                spec_flags.6458.symtab0x80567008OBJECT<unknown>DEFAULT4
                                                spec_or_mask.6461.symtab0x80566a816OBJECT<unknown>DEFAULT4
                                                spec_ranges.6460.symtab0x80566b89OBJECT<unknown>DEFAULT4
                                                srand.symtab0x805224e61FUNC<unknown>DEFAULT2
                                                srandom.symtab0x805224e61FUNC<unknown>DEFAULT2
                                                srandom_r.symtab0x80522eb160FUNC<unknown>DEFAULT2
                                                srv_addr.symtab0x805b3e816OBJECT<unknown>DEFAULT12
                                                stat.symtab0x804ed6470FUNC<unknown>DEFAULT2
                                                stat.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                stat_t.symtab0x80588a088OBJECT<unknown>DEFAULT12
                                                static_dtv.symtab0x805aea0512OBJECT<unknown>DEFAULT12
                                                static_map.symtab0x805b3a852OBJECT<unknown>DEFAULT12
                                                static_slotinfo.symtab0x805b0a0776OBJECT<unknown>DEFAULT12
                                                stderr.symtab0x80586584OBJECT<unknown>DEFAULT11
                                                stdin.symtab0x80586504OBJECT<unknown>DEFAULT11
                                                stdout.symtab0x80586544OBJECT<unknown>DEFAULT11
                                                strcat.symtab0x8050a4835FUNC<unknown>DEFAULT2
                                                strcat.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                strchr.symtab0x805461830FUNC<unknown>DEFAULT2
                                                strchr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                strchrnul.symtab0x805463825FUNC<unknown>DEFAULT2
                                                strchrnul.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                strcmp.symtab0x8050a6c29FUNC<unknown>DEFAULT2
                                                strcmp.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                strcoll.symtab0x8050a6c29FUNC<unknown>DEFAULT2
                                                strcspn.symtab0x805472445FUNC<unknown>DEFAULT2
                                                strcspn.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                strerror_r.symtab0x8050b9c191FUNC<unknown>DEFAULT2
                                                strlen.symtab0x8050a8c19FUNC<unknown>DEFAULT2
                                                strlen.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                strnlen.symtab0x8050aa024FUNC<unknown>DEFAULT2
                                                strnlen.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                strrchr.symtab0x805465426FUNC<unknown>DEFAULT2
                                                strrchr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                strspn.symtab0x805475442FUNC<unknown>DEFAULT2
                                                strspn.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                strstr.symtab0x8050ab8197FUNC<unknown>DEFAULT2
                                                strstr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                strtol.symtab0x80524dc23FUNC<unknown>DEFAULT2
                                                strtol.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                sysconf.symtab0x8052730523FUNC<unknown>DEFAULT2
                                                sysconf.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                table.symtab0x805b400464OBJECT<unknown>DEFAULT12
                                                table.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                table_init.symtab0x804dd702524FUNC<unknown>DEFAULT2
                                                table_key.symtab0x805864c4OBJECT<unknown>DEFAULT11
                                                table_lock_val.symtab0x804dc70114FUNC<unknown>DEFAULT2
                                                table_retrieve_val.symtab0x804dc4038FUNC<unknown>DEFAULT2
                                                table_unlock_val.symtab0x804dcf0114FUNC<unknown>DEFAULT2
                                                tcgetattr.symtab0x8050c7896FUNC<unknown>DEFAULT2
                                                tcgetattr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                time.symtab0x804edac16FUNC<unknown>DEFAULT2
                                                time.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                times.symtab0x805363016FUNC<unknown>DEFAULT2
                                                times.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                type_codes.symtab0x80566c424OBJECT<unknown>DEFAULT4
                                                type_sizes.symtab0x80566dc12OBJECT<unknown>DEFAULT4
                                                umount.symtab0x804edbc39FUNC<unknown>DEFAULT2
                                                umount.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                uname.symtab0x804ede439FUNC<unknown>DEFAULT2
                                                uname.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                unknown.1474.symtab0x805670814OBJECT<unknown>DEFAULT4
                                                unsafe_state.symtab0x805878420OBJECT<unknown>DEFAULT11
                                                usleep.symtab0x805293c47FUNC<unknown>DEFAULT2
                                                usleep.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                util.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                util_atoi.symtab0x804e800245FUNC<unknown>DEFAULT2
                                                util_local_addr.symtab0x804e900120FUNC<unknown>DEFAULT2
                                                util_memcpy.symtab0x804e7b034FUNC<unknown>DEFAULT2
                                                util_strcpy.symtab0x804e77050FUNC<unknown>DEFAULT2
                                                util_strlen.symtab0x804e75024FUNC<unknown>DEFAULT2
                                                util_zero.symtab0x804e7e026FUNC<unknown>DEFAULT2
                                                validateMnt.symtab0x804c7a076FUNC<unknown>DEFAULT2
                                                vsnprintf.symtab0x804f44c172FUNC<unknown>DEFAULT2
                                                vsnprintf.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                w.symtab0x80589084OBJECT<unknown>DEFAULT12
                                                wcrtomb.symtab0x805398863FUNC<unknown>DEFAULT2
                                                wcrtomb.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                wcsnrtombs.symtab0x80539e4128FUNC<unknown>DEFAULT2
                                                wcsnrtombs.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                wcsrtombs.symtab0x80539c827FUNC<unknown>DEFAULT2
                                                wcsrtombs.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                write.symtab0x8052e0091FUNC<unknown>DEFAULT2
                                                x.symtab0x80588fc4OBJECT<unknown>DEFAULT12
                                                xstatconv.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                y.symtab0x80589004OBJECT<unknown>DEFAULT12
                                                z.symtab0x80589044OBJECT<unknown>DEFAULT12
                                                TimestampProtocolSIDSignatureSeveritySource PortDest PortSource IPDest IP
                                                2024-08-21T21:15:34.633226+0200TCP2030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)15749651237192.168.2.13185.196.9.5
                                                2024-08-21T21:16:55.552567+0200TCP2030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)15750251237192.168.2.13185.196.9.5
                                                2024-08-21T21:18:34.069607+0200TCP2030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)15751051237192.168.2.13185.196.9.5
                                                2024-08-21T21:18:05.692978+0200TCP2030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)15750851237192.168.2.13185.196.9.5
                                                2024-08-21T21:15:59.038834+0200TCP2030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)15749851237192.168.2.13185.196.9.5
                                                2024-08-21T21:17:43.317076+0200TCP2030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)15750651237192.168.2.13185.196.9.5
                                                2024-08-21T21:15:10.226277+0200TCP2030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)15749451237192.168.2.13185.196.9.5
                                                2024-08-21T21:16:30.169397+0200TCP2030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)15750051237192.168.2.13185.196.9.5
                                                2024-08-21T21:17:18.926134+0200TCP2030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)15750451237192.168.2.13185.196.9.5
                                                TimestampSource PortDest PortSource IPDest IP
                                                Aug 21, 2024 21:15:10.221314907 CEST5749451237192.168.2.13185.196.9.5
                                                Aug 21, 2024 21:15:10.226191998 CEST5123757494185.196.9.5192.168.2.13
                                                Aug 21, 2024 21:15:10.226250887 CEST5749451237192.168.2.13185.196.9.5
                                                Aug 21, 2024 21:15:10.226277113 CEST5749451237192.168.2.13185.196.9.5
                                                Aug 21, 2024 21:15:10.231112003 CEST5123757494185.196.9.5192.168.2.13
                                                Aug 21, 2024 21:15:18.673048019 CEST48202443192.168.2.13185.125.190.26
                                                Aug 21, 2024 21:15:20.232940912 CEST5749451237192.168.2.13185.196.9.5
                                                Aug 21, 2024 21:15:20.237912893 CEST5123757494185.196.9.5192.168.2.13
                                                Aug 21, 2024 21:15:31.620004892 CEST5123757494185.196.9.5192.168.2.13
                                                Aug 21, 2024 21:15:31.620099068 CEST5749451237192.168.2.13185.196.9.5
                                                Aug 21, 2024 21:15:31.624953985 CEST5123757494185.196.9.5192.168.2.13
                                                Aug 21, 2024 21:15:34.628304005 CEST5749651237192.168.2.13185.196.9.5
                                                Aug 21, 2024 21:15:34.633171082 CEST5123757496185.196.9.5192.168.2.13
                                                Aug 21, 2024 21:15:34.633213043 CEST5749651237192.168.2.13185.196.9.5
                                                Aug 21, 2024 21:15:34.633225918 CEST5749651237192.168.2.13185.196.9.5
                                                Aug 21, 2024 21:15:34.638096094 CEST5123757496185.196.9.5192.168.2.13
                                                Aug 21, 2024 21:15:49.648904085 CEST48202443192.168.2.13185.125.190.26
                                                Aug 21, 2024 21:15:56.025719881 CEST5123757496185.196.9.5192.168.2.13
                                                Aug 21, 2024 21:15:56.025895119 CEST5749651237192.168.2.13185.196.9.5
                                                Aug 21, 2024 21:15:56.030690908 CEST5123757496185.196.9.5192.168.2.13
                                                Aug 21, 2024 21:15:59.033983946 CEST5749851237192.168.2.13185.196.9.5
                                                Aug 21, 2024 21:15:59.038760900 CEST5123757498185.196.9.5192.168.2.13
                                                Aug 21, 2024 21:15:59.038822889 CEST5749851237192.168.2.13185.196.9.5
                                                Aug 21, 2024 21:15:59.038834095 CEST5749851237192.168.2.13185.196.9.5
                                                Aug 21, 2024 21:15:59.043589115 CEST5123757498185.196.9.5192.168.2.13
                                                Aug 21, 2024 21:16:20.449049950 CEST5123757498185.196.9.5192.168.2.13
                                                Aug 21, 2024 21:16:20.449168921 CEST5749851237192.168.2.13185.196.9.5
                                                Aug 21, 2024 21:16:20.454483032 CEST5123757498185.196.9.5192.168.2.13
                                                Aug 21, 2024 21:16:30.164328098 CEST5750051237192.168.2.13185.196.9.5
                                                Aug 21, 2024 21:16:30.169316053 CEST5123757500185.196.9.5192.168.2.13
                                                Aug 21, 2024 21:16:30.169368029 CEST5750051237192.168.2.13185.196.9.5
                                                Aug 21, 2024 21:16:30.169397116 CEST5750051237192.168.2.13185.196.9.5
                                                Aug 21, 2024 21:16:30.174196005 CEST5123757500185.196.9.5192.168.2.13
                                                Aug 21, 2024 21:16:40.178625107 CEST5750051237192.168.2.13185.196.9.5
                                                Aug 21, 2024 21:16:40.183646917 CEST5123757500185.196.9.5192.168.2.13
                                                Aug 21, 2024 21:16:51.539432049 CEST5123757500185.196.9.5192.168.2.13
                                                Aug 21, 2024 21:16:51.539510012 CEST5750051237192.168.2.13185.196.9.5
                                                Aug 21, 2024 21:16:51.545558929 CEST5123757500185.196.9.5192.168.2.13
                                                Aug 21, 2024 21:16:55.547491074 CEST5750251237192.168.2.13185.196.9.5
                                                Aug 21, 2024 21:16:55.552421093 CEST5123757502185.196.9.5192.168.2.13
                                                Aug 21, 2024 21:16:55.552521944 CEST5750251237192.168.2.13185.196.9.5
                                                Aug 21, 2024 21:16:55.552567005 CEST5750251237192.168.2.13185.196.9.5
                                                Aug 21, 2024 21:16:55.557370901 CEST5123757502185.196.9.5192.168.2.13
                                                Aug 21, 2024 21:17:16.912379980 CEST5123757502185.196.9.5192.168.2.13
                                                Aug 21, 2024 21:17:16.912530899 CEST5750251237192.168.2.13185.196.9.5
                                                Aug 21, 2024 21:17:16.917402029 CEST5123757502185.196.9.5192.168.2.13
                                                Aug 21, 2024 21:17:18.920717001 CEST5750451237192.168.2.13185.196.9.5
                                                Aug 21, 2024 21:17:18.925996065 CEST5123757504185.196.9.5192.168.2.13
                                                Aug 21, 2024 21:17:18.926084042 CEST5750451237192.168.2.13185.196.9.5
                                                Aug 21, 2024 21:17:18.926134109 CEST5750451237192.168.2.13185.196.9.5
                                                Aug 21, 2024 21:17:18.930902958 CEST5123757504185.196.9.5192.168.2.13
                                                Aug 21, 2024 21:17:40.304049969 CEST5123757504185.196.9.5192.168.2.13
                                                Aug 21, 2024 21:17:40.304212093 CEST5750451237192.168.2.13185.196.9.5
                                                Aug 21, 2024 21:17:40.309591055 CEST5123757504185.196.9.5192.168.2.13
                                                Aug 21, 2024 21:17:43.312155008 CEST5750651237192.168.2.13185.196.9.5
                                                Aug 21, 2024 21:17:43.316941023 CEST5123757506185.196.9.5192.168.2.13
                                                Aug 21, 2024 21:17:43.317024946 CEST5750651237192.168.2.13185.196.9.5
                                                Aug 21, 2024 21:17:43.317075968 CEST5750651237192.168.2.13185.196.9.5
                                                Aug 21, 2024 21:17:43.322150946 CEST5123757506185.196.9.5192.168.2.13
                                                Aug 21, 2024 21:17:53.324836969 CEST5750651237192.168.2.13185.196.9.5
                                                Aug 21, 2024 21:17:53.536813021 CEST5750651237192.168.2.13185.196.9.5
                                                Aug 21, 2024 21:17:53.607316017 CEST5123757506185.196.9.5192.168.2.13
                                                Aug 21, 2024 21:17:53.607383013 CEST5123757506185.196.9.5192.168.2.13
                                                Aug 21, 2024 21:18:04.679857016 CEST5123757506185.196.9.5192.168.2.13
                                                Aug 21, 2024 21:18:04.680010080 CEST5750651237192.168.2.13185.196.9.5
                                                Aug 21, 2024 21:18:04.684988022 CEST5123757506185.196.9.5192.168.2.13
                                                Aug 21, 2024 21:18:05.687870979 CEST5750851237192.168.2.13185.196.9.5
                                                Aug 21, 2024 21:18:05.692889929 CEST5123757508185.196.9.5192.168.2.13
                                                Aug 21, 2024 21:18:05.692955017 CEST5750851237192.168.2.13185.196.9.5
                                                Aug 21, 2024 21:18:05.692977905 CEST5750851237192.168.2.13185.196.9.5
                                                Aug 21, 2024 21:18:05.697706938 CEST5123757508185.196.9.5192.168.2.13
                                                Aug 21, 2024 21:18:27.055005074 CEST5123757508185.196.9.5192.168.2.13
                                                Aug 21, 2024 21:18:27.055310011 CEST5750851237192.168.2.13185.196.9.5
                                                Aug 21, 2024 21:18:27.060156107 CEST5123757508185.196.9.5192.168.2.13
                                                Aug 21, 2024 21:18:34.064095974 CEST5751051237192.168.2.13185.196.9.5
                                                Aug 21, 2024 21:18:34.069464922 CEST5123757510185.196.9.5192.168.2.13
                                                Aug 21, 2024 21:18:34.069555044 CEST5751051237192.168.2.13185.196.9.5
                                                Aug 21, 2024 21:18:34.069607019 CEST5751051237192.168.2.13185.196.9.5
                                                Aug 21, 2024 21:18:34.074435949 CEST5123757510185.196.9.5192.168.2.13
                                                TimestampSource PortDest PortSource IPDest IP
                                                Aug 21, 2024 21:15:09.159653902 CEST5117653192.168.2.138.8.8.8
                                                Aug 21, 2024 21:15:10.221213102 CEST53511768.8.8.8192.168.2.13
                                                Aug 21, 2024 21:15:34.620959997 CEST3710053192.168.2.138.8.8.8
                                                Aug 21, 2024 21:15:34.628215075 CEST53371008.8.8.8192.168.2.13
                                                Aug 21, 2024 21:15:59.027084112 CEST4927653192.168.2.138.8.8.8
                                                Aug 21, 2024 21:15:59.033853054 CEST53492768.8.8.8192.168.2.13
                                                Aug 21, 2024 21:16:29.450007915 CEST3759653192.168.2.138.8.8.8
                                                Aug 21, 2024 21:16:30.164212942 CEST53375968.8.8.8192.168.2.13
                                                Aug 21, 2024 21:16:55.540755033 CEST5603753192.168.2.138.8.8.8
                                                Aug 21, 2024 21:16:55.547324896 CEST53560378.8.8.8192.168.2.13
                                                Aug 21, 2024 21:17:18.913636923 CEST5105353192.168.2.138.8.8.8
                                                Aug 21, 2024 21:17:18.920612097 CEST53510538.8.8.8192.168.2.13
                                                Aug 21, 2024 21:17:43.305525064 CEST5406253192.168.2.138.8.8.8
                                                Aug 21, 2024 21:17:43.311975956 CEST53540628.8.8.8192.168.2.13
                                                Aug 21, 2024 21:17:52.903769970 CEST3703653192.168.2.131.1.1.1
                                                Aug 21, 2024 21:17:52.903815985 CEST4582053192.168.2.131.1.1.1
                                                Aug 21, 2024 21:17:53.609823942 CEST53458201.1.1.1192.168.2.13
                                                Aug 21, 2024 21:17:53.624320984 CEST53370361.1.1.1192.168.2.13
                                                Aug 21, 2024 21:18:05.681055069 CEST3445953192.168.2.138.8.8.8
                                                Aug 21, 2024 21:18:05.687783957 CEST53344598.8.8.8192.168.2.13
                                                Aug 21, 2024 21:18:34.056695938 CEST5801253192.168.2.138.8.8.8
                                                Aug 21, 2024 21:18:34.063937902 CEST53580128.8.8.8192.168.2.13
                                                TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                                Aug 21, 2024 21:15:09.159653902 CEST192.168.2.138.8.8.80x2b56Standard query (0)fdh32fsdfhs.shopA (IP address)IN (0x0001)false
                                                Aug 21, 2024 21:15:34.620959997 CEST192.168.2.138.8.8.80xcd4bStandard query (0)fdh32fsdfhs.shopA (IP address)IN (0x0001)false
                                                Aug 21, 2024 21:15:59.027084112 CEST192.168.2.138.8.8.80xb9abStandard query (0)fdh32fsdfhs.shopA (IP address)IN (0x0001)false
                                                Aug 21, 2024 21:16:29.450007915 CEST192.168.2.138.8.8.80xea68Standard query (0)fdh32fsdfhs.shopA (IP address)IN (0x0001)false
                                                Aug 21, 2024 21:16:55.540755033 CEST192.168.2.138.8.8.80xb578Standard query (0)fdh32fsdfhs.shopA (IP address)IN (0x0001)false
                                                Aug 21, 2024 21:17:18.913636923 CEST192.168.2.138.8.8.80xc35aStandard query (0)fdh32fsdfhs.shopA (IP address)IN (0x0001)false
                                                Aug 21, 2024 21:17:43.305525064 CEST192.168.2.138.8.8.80x15b3Standard query (0)fdh32fsdfhs.shopA (IP address)IN (0x0001)false
                                                Aug 21, 2024 21:17:52.903769970 CEST192.168.2.131.1.1.10xe1c2Standard query (0)daisy.ubuntu.comA (IP address)IN (0x0001)false
                                                Aug 21, 2024 21:17:52.903815985 CEST192.168.2.131.1.1.10xd0cfStandard query (0)daisy.ubuntu.com28IN (0x0001)false
                                                Aug 21, 2024 21:18:05.681055069 CEST192.168.2.138.8.8.80x5fc9Standard query (0)fdh32fsdfhs.shopA (IP address)IN (0x0001)false
                                                Aug 21, 2024 21:18:34.056695938 CEST192.168.2.138.8.8.80xdf2aStandard query (0)fdh32fsdfhs.shopA (IP address)IN (0x0001)false
                                                TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                                Aug 21, 2024 21:15:10.221213102 CEST8.8.8.8192.168.2.130x2b56No error (0)fdh32fsdfhs.shop185.196.9.5A (IP address)IN (0x0001)false
                                                Aug 21, 2024 21:15:34.628215075 CEST8.8.8.8192.168.2.130xcd4bNo error (0)fdh32fsdfhs.shop185.196.9.5A (IP address)IN (0x0001)false
                                                Aug 21, 2024 21:15:59.033853054 CEST8.8.8.8192.168.2.130xb9abNo error (0)fdh32fsdfhs.shop185.196.9.5A (IP address)IN (0x0001)false
                                                Aug 21, 2024 21:16:30.164212942 CEST8.8.8.8192.168.2.130xea68No error (0)fdh32fsdfhs.shop185.196.9.5A (IP address)IN (0x0001)false
                                                Aug 21, 2024 21:16:55.547324896 CEST8.8.8.8192.168.2.130xb578No error (0)fdh32fsdfhs.shop185.196.9.5A (IP address)IN (0x0001)false
                                                Aug 21, 2024 21:17:18.920612097 CEST8.8.8.8192.168.2.130xc35aNo error (0)fdh32fsdfhs.shop185.196.9.5A (IP address)IN (0x0001)false
                                                Aug 21, 2024 21:17:43.311975956 CEST8.8.8.8192.168.2.130x15b3No error (0)fdh32fsdfhs.shop185.196.9.5A (IP address)IN (0x0001)false
                                                Aug 21, 2024 21:17:53.624320984 CEST1.1.1.1192.168.2.130xe1c2No error (0)daisy.ubuntu.com162.213.35.25A (IP address)IN (0x0001)false
                                                Aug 21, 2024 21:17:53.624320984 CEST1.1.1.1192.168.2.130xe1c2No error (0)daisy.ubuntu.com162.213.35.24A (IP address)IN (0x0001)false
                                                Aug 21, 2024 21:18:05.687783957 CEST8.8.8.8192.168.2.130x5fc9No error (0)fdh32fsdfhs.shop185.196.9.5A (IP address)IN (0x0001)false
                                                Aug 21, 2024 21:18:34.063937902 CEST8.8.8.8192.168.2.130xdf2aNo error (0)fdh32fsdfhs.shop185.196.9.5A (IP address)IN (0x0001)false

                                                System Behavior

                                                Start time (UTC):19:15:00
                                                Start date (UTC):21/08/2024
                                                Path:/usr/bin/dash
                                                Arguments:-
                                                File size:129816 bytes
                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                Start time (UTC):19:15:00
                                                Start date (UTC):21/08/2024
                                                Path:/usr/bin/rm
                                                Arguments:rm -f /tmp/tmp.8ujBYUUTak /tmp/tmp.xUGcDLugyr /tmp/tmp.RUd0zcTbnv
                                                File size:72056 bytes
                                                MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                                Start time (UTC):19:15:00
                                                Start date (UTC):21/08/2024
                                                Path:/usr/bin/dash
                                                Arguments:-
                                                File size:129816 bytes
                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                Start time (UTC):19:15:00
                                                Start date (UTC):21/08/2024
                                                Path:/usr/bin/rm
                                                Arguments:rm -f /tmp/tmp.8ujBYUUTak /tmp/tmp.xUGcDLugyr /tmp/tmp.RUd0zcTbnv
                                                File size:72056 bytes
                                                MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                                Start time (UTC):19:15:08
                                                Start date (UTC):21/08/2024
                                                Path:/tmp/i586.elf
                                                Arguments:/tmp/i586.elf
                                                File size:93479 bytes
                                                MD5 hash:ed474ab6fe0346a9908523f124fbfe0c

                                                Start time (UTC):19:15:08
                                                Start date (UTC):21/08/2024
                                                Path:/tmp/i586.elf
                                                Arguments:-
                                                File size:93479 bytes
                                                MD5 hash:ed474ab6fe0346a9908523f124fbfe0c

                                                Start time (UTC):19:15:08
                                                Start date (UTC):21/08/2024
                                                Path:/tmp/i586.elf
                                                Arguments:-
                                                File size:93479 bytes
                                                MD5 hash:ed474ab6fe0346a9908523f124fbfe0c

                                                Start time (UTC):19:15:08
                                                Start date (UTC):21/08/2024
                                                Path:/usr/lib/udisks2/udisksd
                                                Arguments:-
                                                File size:483056 bytes
                                                MD5 hash:1d7ae439cc3d82fa6b127671ce037a24

                                                Start time (UTC):19:15:08
                                                Start date (UTC):21/08/2024
                                                Path:/usr/sbin/dumpe2fs
                                                Arguments:dumpe2fs -h /dev/dm-0
                                                File size:31112 bytes
                                                MD5 hash:5c66f7d8f7681a40562cf049ad4b72b4

                                                Start time (UTC):19:15:08
                                                Start date (UTC):21/08/2024
                                                Path:/usr/libexec/gnome-session-binary
                                                Arguments:-
                                                File size:334664 bytes
                                                MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

                                                Start time (UTC):19:15:08
                                                Start date (UTC):21/08/2024
                                                Path:/bin/sh
                                                Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-sharing
                                                File size:129816 bytes
                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                Start time (UTC):19:15:08
                                                Start date (UTC):21/08/2024
                                                Path:/usr/libexec/gsd-sharing
                                                Arguments:/usr/libexec/gsd-sharing
                                                File size:35424 bytes
                                                MD5 hash:e29d9025d98590fbb69f89fdbd4438b3

                                                Start time (UTC):19:15:08
                                                Start date (UTC):21/08/2024
                                                Path:/usr/libexec/gnome-session-binary
                                                Arguments:-
                                                File size:334664 bytes
                                                MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

                                                Start time (UTC):19:15:08
                                                Start date (UTC):21/08/2024
                                                Path:/bin/sh
                                                Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-wacom
                                                File size:129816 bytes
                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                Start time (UTC):19:15:08
                                                Start date (UTC):21/08/2024
                                                Path:/usr/libexec/gsd-wacom
                                                Arguments:/usr/libexec/gsd-wacom
                                                File size:39520 bytes
                                                MD5 hash:13778dd1a23a4e94ddc17ac9caa4fcc1

                                                Start time (UTC):19:15:08
                                                Start date (UTC):21/08/2024
                                                Path:/usr/lib/systemd/systemd
                                                Arguments:-
                                                File size:1620224 bytes
                                                MD5 hash:9b2bec7092a40488108543f9334aab75

                                                Start time (UTC):19:15:08
                                                Start date (UTC):21/08/2024
                                                Path:/usr/lib/upower/upowerd
                                                Arguments:/usr/lib/upower/upowerd
                                                File size:260328 bytes
                                                MD5 hash:1253eea2fe5fe4017069664284e326cd

                                                Start time (UTC):19:15:08
                                                Start date (UTC):21/08/2024
                                                Path:/usr/libexec/gvfsd-fuse
                                                Arguments:-
                                                File size:47632 bytes
                                                MD5 hash:d18fbf1cbf8eb57b17fac48b7b4be933

                                                Start time (UTC):19:15:08
                                                Start date (UTC):21/08/2024
                                                Path:/bin/fusermount
                                                Arguments:fusermount -u -q -z -- /run/user/1000/gvfs
                                                File size:39144 bytes
                                                MD5 hash:576a1b135c82bdcbc97a91acea900566

                                                Start time (UTC):19:15:08
                                                Start date (UTC):21/08/2024
                                                Path:/usr/libexec/gnome-session-binary
                                                Arguments:-
                                                File size:334664 bytes
                                                MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

                                                Start time (UTC):19:15:08
                                                Start date (UTC):21/08/2024
                                                Path:/bin/sh
                                                Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-keyboard
                                                File size:129816 bytes
                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                Start time (UTC):19:15:08
                                                Start date (UTC):21/08/2024
                                                Path:/usr/libexec/gsd-keyboard
                                                Arguments:/usr/libexec/gsd-keyboard
                                                File size:39760 bytes
                                                MD5 hash:8e288fd17c80bb0a1148b964b2ac2279

                                                Start time (UTC):19:15:08
                                                Start date (UTC):21/08/2024
                                                Path:/usr/libexec/gnome-session-binary
                                                Arguments:-
                                                File size:334664 bytes
                                                MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

                                                Start time (UTC):19:15:08
                                                Start date (UTC):21/08/2024
                                                Path:/bin/sh
                                                Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-print-notifications
                                                File size:129816 bytes
                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                Start time (UTC):19:15:08
                                                Start date (UTC):21/08/2024
                                                Path:/usr/libexec/gsd-print-notifications
                                                Arguments:/usr/libexec/gsd-print-notifications
                                                File size:51840 bytes
                                                MD5 hash:71539698aa691718cee775d6b9450ae2

                                                Start time (UTC):19:15:08
                                                Start date (UTC):21/08/2024
                                                Path:/usr/bin/xfce4-panel
                                                Arguments:-
                                                File size:375768 bytes
                                                MD5 hash:a15b657c7d54ac1385f1f15004ea6784

                                                Start time (UTC):19:15:08
                                                Start date (UTC):21/08/2024
                                                Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
                                                Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libsystray.so 6 12582920 systray "Notification Area" "Area where notification icons appear"
                                                File size:35136 bytes
                                                MD5 hash:ac0b8a906f359a8ae102244738682e76

                                                Start time (UTC):19:15:08
                                                Start date (UTC):21/08/2024
                                                Path:/usr/libexec/gnome-session-binary
                                                Arguments:-
                                                File size:334664 bytes
                                                MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

                                                Start time (UTC):19:15:08
                                                Start date (UTC):21/08/2024
                                                Path:/bin/sh
                                                Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-rfkill
                                                File size:129816 bytes
                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                Start time (UTC):19:15:08
                                                Start date (UTC):21/08/2024
                                                Path:/usr/libexec/gsd-rfkill
                                                Arguments:/usr/libexec/gsd-rfkill
                                                File size:51808 bytes
                                                MD5 hash:88a16a3c0aba1759358c06215ecfb5cc
                                                Start time (UTC):19:15:08
                                                Start date (UTC):21/08/2024
                                                Path:/usr/bin/xfce4-panel
                                                Arguments:-
                                                File size:375768 bytes
                                                MD5 hash:a15b657c7d54ac1385f1f15004ea6784

                                                Start time (UTC):19:15:08
                                                Start date (UTC):21/08/2024
                                                Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
                                                Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libstatusnotifier.so 7 12582921 statusnotifier "Status Notifier Plugin" "Provides a panel area for status notifier items (application indicators)"
                                                File size:35136 bytes
                                                MD5 hash:ac0b8a906f359a8ae102244738682e76

                                                Start time (UTC):19:15:08
                                                Start date (UTC):21/08/2024
                                                Path:/usr/libexec/gnome-session-binary
                                                Arguments:-
                                                File size:334664 bytes
                                                MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

                                                Start time (UTC):19:15:08
                                                Start date (UTC):21/08/2024
                                                Path:/bin/sh
                                                Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-smartcard
                                                File size:129816 bytes
                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                Start time (UTC):19:15:08
                                                Start date (UTC):21/08/2024
                                                Path:/usr/libexec/gsd-smartcard
                                                Arguments:/usr/libexec/gsd-smartcard
                                                File size:109152 bytes
                                                MD5 hash:ea1fbd7f62e4cd0331eae2ef754ee605

                                                Start time (UTC):19:15:08
                                                Start date (UTC):21/08/2024
                                                Path:/usr/bin/xfce4-panel
                                                Arguments:-
                                                File size:375768 bytes
                                                MD5 hash:a15b657c7d54ac1385f1f15004ea6784

                                                Start time (UTC):19:15:08
                                                Start date (UTC):21/08/2024
                                                Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
                                                Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libpulseaudio-plugin.so 8 12582922 pulseaudio "PulseAudio Plugin" "Adjust the audio volume of the PulseAudio sound system"
                                                File size:35136 bytes
                                                MD5 hash:ac0b8a906f359a8ae102244738682e76

                                                Start time (UTC):19:15:08
                                                Start date (UTC):21/08/2024
                                                Path:/usr/libexec/gnome-session-binary
                                                Arguments:-
                                                File size:334664 bytes
                                                MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

                                                Start time (UTC):19:15:08
                                                Start date (UTC):21/08/2024
                                                Path:/bin/sh
                                                Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-datetime
                                                File size:129816 bytes
                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                Start time (UTC):19:15:08
                                                Start date (UTC):21/08/2024
                                                Path:/usr/libexec/gsd-datetime
                                                Arguments:/usr/libexec/gsd-datetime
                                                File size:76736 bytes
                                                MD5 hash:d80d39745740de37d6634d36e344d4bc

                                                Start time (UTC):19:15:08
                                                Start date (UTC):21/08/2024
                                                Path:/usr/bin/xfce4-panel
                                                Arguments:-
                                                File size:375768 bytes
                                                MD5 hash:a15b657c7d54ac1385f1f15004ea6784

                                                Start time (UTC):19:15:08
                                                Start date (UTC):21/08/2024
                                                Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
                                                Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libxfce4powermanager.so 9 12582923 power-manager-plugin "Power Manager Plugin" "Display the battery levels of your devices and control the brightness of your display"
                                                File size:35136 bytes
                                                MD5 hash:ac0b8a906f359a8ae102244738682e76

                                                Start time (UTC):19:15:08
                                                Start date (UTC):21/08/2024
                                                Path:/usr/libexec/gnome-session-binary
                                                Arguments:-
                                                File size:334664 bytes
                                                MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

                                                Start time (UTC):19:15:08
                                                Start date (UTC):21/08/2024
                                                Path:/bin/sh
                                                Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-media-keys
                                                File size:129816 bytes
                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                Start time (UTC):19:15:09
                                                Start date (UTC):21/08/2024
                                                Path:/usr/libexec/gsd-media-keys
                                                Arguments:/usr/libexec/gsd-media-keys
                                                File size:232936 bytes
                                                MD5 hash:a425448c135afb4b8bfd79cc0b6b74da

                                                Start time (UTC):19:15:08
                                                Start date (UTC):21/08/2024
                                                Path:/usr/bin/xfce4-panel
                                                Arguments:-
                                                File size:375768 bytes
                                                MD5 hash:a15b657c7d54ac1385f1f15004ea6784

                                                Start time (UTC):19:15:08
                                                Start date (UTC):21/08/2024
                                                Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
                                                Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libnotification-plugin.so 10 12582924 notification-plugin "Notification Plugin" "Notification plugin for the Xfce panel"
                                                File size:35136 bytes
                                                MD5 hash:ac0b8a906f359a8ae102244738682e76

                                                Start time (UTC):19:15:08
                                                Start date (UTC):21/08/2024
                                                Path:/usr/libexec/gnome-session-binary
                                                Arguments:-
                                                File size:334664 bytes
                                                MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

                                                Start time (UTC):19:15:08
                                                Start date (UTC):21/08/2024
                                                Path:/bin/sh
                                                Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-screensaver-proxy
                                                File size:129816 bytes
                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                Start time (UTC):19:15:09
                                                Start date (UTC):21/08/2024
                                                Path:/usr/libexec/gsd-screensaver-proxy
                                                Arguments:/usr/libexec/gsd-screensaver-proxy
                                                File size:27232 bytes
                                                MD5 hash:77e309450c87dceee43f1a9e50cc0d02

                                                Start time (UTC):19:15:08
                                                Start date (UTC):21/08/2024
                                                Path:/usr/bin/xfce4-panel
                                                Arguments:-
                                                File size:375768 bytes
                                                MD5 hash:a15b657c7d54ac1385f1f15004ea6784

                                                Start time (UTC):19:15:08
                                                Start date (UTC):21/08/2024
                                                Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
                                                Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libactions.so 14 12582925 actions "Action Buttons" "Log out, lock or other system actions"
                                                File size:35136 bytes
                                                MD5 hash:ac0b8a906f359a8ae102244738682e76

                                                Start time (UTC):19:15:09
                                                Start date (UTC):21/08/2024
                                                Path:/usr/libexec/gnome-session-binary
                                                Arguments:-
                                                File size:334664 bytes
                                                MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

                                                Start time (UTC):19:15:09
                                                Start date (UTC):21/08/2024
                                                Path:/bin/sh
                                                Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-a11y-settings
                                                File size:129816 bytes
                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                Start time (UTC):19:15:09
                                                Start date (UTC):21/08/2024
                                                Path:/usr/libexec/gsd-a11y-settings
                                                Arguments:/usr/libexec/gsd-a11y-settings
                                                File size:23056 bytes
                                                MD5 hash:18e243d2cf30ecee7ea89d1462725c5c

                                                Start time (UTC):19:15:09
                                                Start date (UTC):21/08/2024
                                                Path:/usr/lib/systemd/systemd
                                                Arguments:-
                                                File size:1620224 bytes
                                                MD5 hash:9b2bec7092a40488108543f9334aab75

                                                Start time (UTC):19:15:09
                                                Start date (UTC):21/08/2024
                                                Path:/usr/lib/upower/upowerd
                                                Arguments:/usr/lib/upower/upowerd
                                                File size:260328 bytes
                                                MD5 hash:1253eea2fe5fe4017069664284e326cd

                                                Start time (UTC):19:15:09
                                                Start date (UTC):21/08/2024
                                                Path:/usr/libexec/gnome-session-binary
                                                Arguments:-
                                                File size:334664 bytes
                                                MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

                                                Start time (UTC):19:15:09
                                                Start date (UTC):21/08/2024
                                                Path:/bin/sh
                                                Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-power
                                                File size:129816 bytes
                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                Start time (UTC):19:15:09
                                                Start date (UTC):21/08/2024
                                                Path:/usr/libexec/gsd-power
                                                Arguments:/usr/libexec/gsd-power
                                                File size:88672 bytes
                                                MD5 hash:28b8e1b43c3e7f1db6741ea1ecd978b7

                                                Start time (UTC):19:15:09
                                                Start date (UTC):21/08/2024
                                                Path:/usr/libexec/gnome-session-binary
                                                Arguments:-
                                                File size:334664 bytes
                                                MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

                                                Start time (UTC):19:15:09
                                                Start date (UTC):21/08/2024
                                                Path:/bin/sh
                                                Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-sound
                                                File size:129816 bytes
                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                Start time (UTC):19:15:09
                                                Start date (UTC):21/08/2024
                                                Path:/usr/libexec/gsd-sound
                                                Arguments:/usr/libexec/gsd-sound
                                                File size:31248 bytes
                                                MD5 hash:4c7d3fb993463337b4a0eb5c80c760ee

                                                Start time (UTC):19:15:09
                                                Start date (UTC):21/08/2024
                                                Path:/usr/libexec/gnome-session-binary
                                                Arguments:-
                                                File size:334664 bytes
                                                MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

                                                Start time (UTC):19:15:09
                                                Start date (UTC):21/08/2024
                                                Path:/bin/sh
                                                Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-housekeeping
                                                File size:129816 bytes
                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                Start time (UTC):19:15:09
                                                Start date (UTC):21/08/2024
                                                Path:/usr/libexec/gsd-housekeeping
                                                Arguments:/usr/libexec/gsd-housekeeping
                                                File size:51840 bytes
                                                MD5 hash:b55f3394a84976ddb92a2915e5d76914

                                                Start time (UTC):19:15:09
                                                Start date (UTC):21/08/2024
                                                Path:/usr/lib/systemd/systemd
                                                Arguments:-
                                                File size:1620224 bytes
                                                MD5 hash:9b2bec7092a40488108543f9334aab75

                                                Start time (UTC):19:15:09
                                                Start date (UTC):21/08/2024
                                                Path:/usr/lib/upower/upowerd
                                                Arguments:/usr/lib/upower/upowerd
                                                File size:260328 bytes
                                                MD5 hash:1253eea2fe5fe4017069664284e326cd

                                                Start time (UTC):19:15:09
                                                Start date (UTC):21/08/2024
                                                Path:/usr/lib/systemd/systemd
                                                Arguments:-
                                                File size:1620224 bytes
                                                MD5 hash:9b2bec7092a40488108543f9334aab75

                                                Start time (UTC):19:15:09
                                                Start date (UTC):21/08/2024
                                                Path:/usr/lib/upower/upowerd
                                                Arguments:/usr/lib/upower/upowerd
                                                File size:260328 bytes
                                                MD5 hash:1253eea2fe5fe4017069664284e326cd

                                                Start time (UTC):19:15:10
                                                Start date (UTC):21/08/2024
                                                Path:/usr/lib/systemd/systemd
                                                Arguments:-
                                                File size:1620224 bytes
                                                MD5 hash:9b2bec7092a40488108543f9334aab75

                                                Start time (UTC):19:15:10
                                                Start date (UTC):21/08/2024
                                                Path:/usr/lib/upower/upowerd
                                                Arguments:/usr/lib/upower/upowerd
                                                File size:260328 bytes
                                                MD5 hash:1253eea2fe5fe4017069664284e326cd