Edit tour

Linux Analysis Report
e.dat.elf

Overview

General Information

Sample name:e.dat.elf
Analysis ID:1548703
MD5:64cc86931bab241dcc08db03e659bcc5
SHA1:8ce3f9f92c6533d14ae2c8749936b4c59fcb95c5
SHA256:6ef9a0b6301d737763f6c59ae6d5b3be4cf38941a69517be0f069d0a35f394dd
Tags:elfuser-abuse_ch
Infos:

Detection

Score:48
Range:0 - 100
Whitelisted:false

Signatures

Multi AV Scanner detection for submitted file
Contains symbols related to standard C library sleeps (sometimes used to evade sandboxing)
Executes commands using a shell command-line interpreter
Executes the "touch" command used to create files or modify time stamps
Sample has stripped symbol table
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
Joe Sandbox version:41.0.0 Charoite
Analysis ID:1548703
Start date and time:2024-11-04 19:02:08 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 10m 15s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:e.dat.elf
Detection:MAL
Classification:mal48.linELF@0/0@0/0
Cookbook Comments:
  • Analysis time extended to 480s due to sleep detection in submitted sample
  • VT rate limit hit for: e.dat.elf
Command:/tmp/e.dat.elf
PID:6220
Exit Code:139
Exit Code Info:SIGSEGV (11) Segmentation fault invalid memory reference
Killed:False
Standard Output:

Standard Error:
  • system is lnxubuntu20
  • e.dat.elf (PID: 6220, Parent: 6139, MD5: 64cc86931bab241dcc08db03e659bcc5) Arguments: /tmp/e.dat.elf
    • sh (PID: 6221, Parent: 6220, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "touch a"
      • sh New Fork (PID: 6222, Parent: 6221)
      • touch (PID: 6222, Parent: 6221, MD5: 3859c173f5d3b37be3e531b7c84a9c68) Arguments: touch a
  • cleanup
No yara matches
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: e.dat.elfReversingLabs: Detection: 28%
Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: e.dat.elfString found in binary or memory: https://qtox.github.io
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
Source: ELF static info symbol of initial sample.symtab present: no
Source: classification engineClassification label: mal48.linELF@0/0@0/0
Source: /tmp/e.dat.elf (PID: 6221)Shell command executed: sh -c "touch a"Jump to behavior
Source: /bin/sh (PID: 6222)Touch executable: /usr/bin/touch -> touch aJump to behavior
Source: ELF symbol in initial sampleSymbol name: sleep
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity Information1
Scripting
Valid AccountsWindows Management Instrumentation1
Scripting
Path Interception1
Virtualization/Sandbox Evasion
OS Credential Dumping1
Virtualization/Sandbox Evasion
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Indicator Removal
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1548703 Sample: e.dat.elf Startdate: 04/11/2024 Architecture: LINUX Score: 48 14 109.202.202.202, 80 INIT7CH Switzerland 2->14 16 91.189.91.42, 443 CANONICAL-ASGB United Kingdom 2->16 18 91.189.91.43, 443 CANONICAL-ASGB United Kingdom 2->18 20 Multi AV Scanner detection for submitted file 2->20 8 e.dat.elf 2->8         started        signatures3 process4 process5 10 e.dat.elf sh 8->10         started        process6 12 sh touch 10->12         started       

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
e.dat.elf29%ReversingLabsLinux.Trojan.Generic
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

No contacted domains info
NameSourceMaliciousAntivirus DetectionReputation
https://qtox.github.ioe.dat.elffalse
    unknown
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    109.202.202.202
    unknownSwitzerland
    13030INIT7CHfalse
    91.189.91.43
    unknownUnited Kingdom
    41231CANONICAL-ASGBfalse
    91.189.91.42
    unknownUnited Kingdom
    41231CANONICAL-ASGBfalse
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
    • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
    91.189.91.43nuklear.spc.elfGet hashmaliciousMirai, MoobotBrowse
      linux_arm6.elfGet hashmaliciousChaosBrowse
        nuklear.x86.elfGet hashmaliciousMirai, MoobotBrowse
          nuklear.mips.elfGet hashmaliciousMirai, MoobotBrowse
            main_arm5.elfGet hashmaliciousMiraiBrowse
              linux_arm5.elfGet hashmaliciousChaosBrowse
                linux_mipsel_softfloat.elfGet hashmaliciousChaosBrowse
                  linux_arm7.elfGet hashmaliciousChaosBrowse
                    .i.elfGet hashmaliciousUnknownBrowse
                      .i.elfGet hashmaliciousUnknownBrowse
                        91.189.91.42nuklear.spc.elfGet hashmaliciousMirai, MoobotBrowse
                          linux_arm6.elfGet hashmaliciousChaosBrowse
                            nuklear.x86.elfGet hashmaliciousMirai, MoobotBrowse
                              nuklear.mips.elfGet hashmaliciousMirai, MoobotBrowse
                                main_arm5.elfGet hashmaliciousMiraiBrowse
                                  linux_arm5.elfGet hashmaliciousChaosBrowse
                                    linux_mipsel_softfloat.elfGet hashmaliciousChaosBrowse
                                      linux_arm7.elfGet hashmaliciousChaosBrowse
                                        .i.elfGet hashmaliciousUnknownBrowse
                                          .i.elfGet hashmaliciousUnknownBrowse
                                            No context
                                            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                            CANONICAL-ASGBnuklear.spc.elfGet hashmaliciousMirai, MoobotBrowse
                                            • 91.189.91.42
                                            linux_arm6.elfGet hashmaliciousChaosBrowse
                                            • 91.189.91.42
                                            nuklear.x86.elfGet hashmaliciousMirai, MoobotBrowse
                                            • 91.189.91.42
                                            nuklear.mips.elfGet hashmaliciousMirai, MoobotBrowse
                                            • 91.189.91.42
                                            main_arm5.elfGet hashmaliciousMiraiBrowse
                                            • 91.189.91.42
                                            linux_arm5.elfGet hashmaliciousChaosBrowse
                                            • 91.189.91.42
                                            linux_mipsel_softfloat.elfGet hashmaliciousChaosBrowse
                                            • 91.189.91.42
                                            linux_arm7.elfGet hashmaliciousChaosBrowse
                                            • 91.189.91.42
                                            .i.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            .i.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            CANONICAL-ASGBnuklear.spc.elfGet hashmaliciousMirai, MoobotBrowse
                                            • 91.189.91.42
                                            linux_arm6.elfGet hashmaliciousChaosBrowse
                                            • 91.189.91.42
                                            nuklear.x86.elfGet hashmaliciousMirai, MoobotBrowse
                                            • 91.189.91.42
                                            nuklear.mips.elfGet hashmaliciousMirai, MoobotBrowse
                                            • 91.189.91.42
                                            main_arm5.elfGet hashmaliciousMiraiBrowse
                                            • 91.189.91.42
                                            linux_arm5.elfGet hashmaliciousChaosBrowse
                                            • 91.189.91.42
                                            linux_mipsel_softfloat.elfGet hashmaliciousChaosBrowse
                                            • 91.189.91.42
                                            linux_arm7.elfGet hashmaliciousChaosBrowse
                                            • 91.189.91.42
                                            .i.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            .i.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            INIT7CHnuklear.spc.elfGet hashmaliciousMirai, MoobotBrowse
                                            • 109.202.202.202
                                            linux_arm6.elfGet hashmaliciousChaosBrowse
                                            • 109.202.202.202
                                            nuklear.x86.elfGet hashmaliciousMirai, MoobotBrowse
                                            • 109.202.202.202
                                            nuklear.mips.elfGet hashmaliciousMirai, MoobotBrowse
                                            • 109.202.202.202
                                            main_arm5.elfGet hashmaliciousMiraiBrowse
                                            • 109.202.202.202
                                            linux_arm5.elfGet hashmaliciousChaosBrowse
                                            • 109.202.202.202
                                            linux_mipsel_softfloat.elfGet hashmaliciousChaosBrowse
                                            • 109.202.202.202
                                            linux_arm7.elfGet hashmaliciousChaosBrowse
                                            • 109.202.202.202
                                            .i.elfGet hashmaliciousUnknownBrowse
                                            • 109.202.202.202
                                            .i.elfGet hashmaliciousUnknownBrowse
                                            • 109.202.202.202
                                            No context
                                            No context
                                            No created / dropped files found
                                            File type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, for GNU/Linux 2.6.18, BuildID[sha1]=55bbc9891f55a5fbe794970b3da3b190a94abcc6, stripped
                                            Entropy (8bit):6.254118434413972
                                            TrID:
                                            • ELF Executable and Linkable format (Linux) (4029/14) 49.77%
                                            • ELF Executable and Linkable format (generic) (4004/1) 49.46%
                                            • Lumena CEL bitmap (63/63) 0.78%
                                            File name:e.dat.elf
                                            File size:242'999 bytes
                                            MD5:64cc86931bab241dcc08db03e659bcc5
                                            SHA1:8ce3f9f92c6533d14ae2c8749936b4c59fcb95c5
                                            SHA256:6ef9a0b6301d737763f6c59ae6d5b3be4cf38941a69517be0f069d0a35f394dd
                                            SHA512:8c0cbb7690fd4560817716df37c93fdeb7e722b22480097aaba26654efff85779d719a32bd33e6f313d53682b797095cd251cbe207ad233fe3880f25ffe9f3a3
                                            SSDEEP:6144:D7NIYS51ntUZNzc56IxAhlYddSOazfYsO:fN1AR2HE1xslY/SOa+
                                            TLSH:85345A47F9A758FDDD9BC03556AB563669A2B06803207A3A31C4DF303E52FA06F1DB90
                                            File Content Preview:.ELF..............>.....0[@.....@.......(...........@.8...@.............@.......@.@.....@.@...............................................@.......@...............................................@.......@....................... .......................c....

                                            ELF header

                                            Class:ELF64
                                            Data:2's complement, little endian
                                            Version:1 (current)
                                            Machine:Advanced Micro Devices X86-64
                                            Version Number:0x1
                                            Type:EXEC (Executable file)
                                            OS/ABI:UNIX - System V
                                            ABI Version:0
                                            Entry Point Address:0x405b30
                                            Flags:0x0
                                            ELF Header Size:64
                                            Program Header Offset:64
                                            Program Header Size:56
                                            Number of Program Headers:8
                                            Section Header Offset:240680
                                            Section Header Size:64
                                            Number of Section Headers:28
                                            Header String Table Index:27
                                            NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                            NULL0x00x00x00x00x0000
                                            .interpPROGBITS0x4002000x2000x1c0x00x2A001
                                            .note.ABI-tagNOTE0x40021c0x21c0x200x00x2A004
                                            .note.gnu.build-idNOTE0x40023c0x23c0x240x00x2A004
                                            .gnu.hashGNU_HASH0x4002600x2600xa440x00x2A508
                                            .dynsymDYNSYM0x400ca80xca80x24d80x180x2A618
                                            .dynstrSTRTAB0x4031800x31800x1bc00x00x2A001
                                            .gnu.versionVERSYM0x404d400x4d400x3120x20x2A502
                                            .gnu.version_rVERNEED0x4050580x50580x500x00x2A628
                                            .rela.dynRELA0x4050a80x50a80x300x180x2A508
                                            .rela.pltRELA0x4050d80x50d80x6180x180x2A5128
                                            .initPROGBITS0x4056f00x56f00x180x00x6AX004
                                            .pltPROGBITS0x4057080x57080x4200x100x6AX004
                                            .textPROGBITS0x405b300x5b300x283e80x00x6AX0016
                                            .finiPROGBITS0x42df180x2df180xe0x00x6AX004
                                            .rodataPROGBITS0x42df400x2df400x60a80x00x2A0032
                                            .eh_frame_hdrPROGBITS0x433fe80x33fe80xad40x00x2A004
                                            .eh_framePROGBITS0x434ac00x34ac00x3c540x00x2A008
                                            .ctorsPROGBITS0x6390000x390000x100x00x3WA008
                                            .dtorsPROGBITS0x6390100x390100x100x00x3WA008
                                            .jcrPROGBITS0x6390200x390200x80x00x3WA008
                                            .dynamicDYNAMIC0x6390280x390280x1a00x100x3WA608
                                            .gotPROGBITS0x6391c80x391c80x100x80x3WA008
                                            .got.pltPROGBITS0x6391d80x391d80x2200x80x3WA008
                                            .dataPROGBITS0x6394000x394000x17080x00x3WA0032
                                            .bssNOBITS0x63ab200x3ab080x22980x00x3WA0032
                                            .commentPROGBITS0x00x3ab080x2c0x10x30MS001
                                            .shstrtabSTRTAB0x00x3ab340xee0x00x0001
                                            TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                            PHDR0x400x4000400x4000400x1c00x1c01.80310x5R E0x8
                                            INTERP0x2000x4002000x4002000x1c0x1c3.94080x4R 0x1/lib64/ld-linux-x86-64.so.2.interp
                                            LOAD0x00x4000000x4000000x387140x387146.40480x5R E0x200000.interp .note.ABI-tag .note.gnu.build-id .gnu.hash .dynsym .dynstr .gnu.version .gnu.version_r .rela.dyn .rela.plt .init .plt .text .fini .rodata .eh_frame_hdr .eh_frame
                                            LOAD0x390000x6390000x6390000x1b080x3db81.24270x6RW 0x200000.ctors .dtors .jcr .dynamic .got .got.plt .data .bss
                                            DYNAMIC0x390280x6390280x6390280x1a00x1a01.52360x6RW 0x8.dynamic
                                            NOTE0x21c0x40021c0x40021c0x440x443.43360x4R 0x4.note.ABI-tag .note.gnu.build-id
                                            GNU_EH_FRAME0x33fe80x433fe80x433fe80xad40xad45.16610x4R 0x4.eh_frame_hdr
                                            GNU_STACK0x00x00x00x00x00.00000x6RW 0x8
                                            TypeMetaValueTag
                                            DT_NEEDEDsharedliblibpthread.so.00x1
                                            DT_NEEDEDsharedliblibc.so.60x1
                                            DT_INITvalue0x4056f00xc
                                            DT_FINIvalue0x42df180xd
                                            DT_GNU_HASHvalue0x4002600x6ffffef5
                                            DT_STRTABvalue0x4031800x5
                                            DT_SYMTABvalue0x400ca80x6
                                            DT_STRSZbytes71040xa
                                            DT_SYMENTbytes240xb
                                            DT_DEBUGvalue0x00x15
                                            DT_PLTGOTvalue0x6391d80x3
                                            DT_PLTRELSZbytes15600x2
                                            DT_PLTRELpltrelDT_RELA0x14
                                            DT_JMPRELvalue0x4050d80x17
                                            DT_RELAvalue0x4050a80x7
                                            DT_RELASZbytes480x8
                                            DT_RELAENTbytes240x9
                                            DT_VERNEEDvalue0x4050580x6ffffffe
                                            DT_VERNEEDNUMvalue20x6fffffff
                                            DT_VERSYMvalue0x404d400x6ffffff0
                                            DT_NULLvalue0x00x0
                                            NameVersion Info NameVersion Info File NameSection NameValueSizeSymbol TypeSymbol BindSymbol VisibilityNdx
                                            .dynsym0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                            _IO_getcGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                            _IO_putcGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                            _IO_stdin_used.dynsym0x42df404OBJECT<unknown>DEFAULT15
                                            _Jv_RegisterClasses.dynsym0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                            __bss_start.dynsym0x63ab080NOTYPE<unknown>DEFAULTSHN_ABS
                                            __ctype_b_locGLIBC_2.3libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                            __ctype_tolower_locGLIBC_2.3libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                            __cxa_atexitGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                            __data_start.dynsym0x6394000NOTYPE<unknown>DEFAULT24
                                            __errno_locationGLIBC_2.2.5libpthread.so.0.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                            __gmon_start__.dynsym0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                            __libc_csu_fini.dynsym0x42de202FUNC<unknown>DEFAULT13
                                            __libc_csu_init.dynsym0x42de30137FUNC<unknown>DEFAULT13
                                            __libc_start_mainGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                            __xstat64GLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                            _edata.dynsym0x63ab080NOTYPE<unknown>DEFAULTSHN_ABS
                                            _end.dynsym0x63cdb80NOTYPE<unknown>DEFAULTSHN_ABS
                                            _fini.dynsym0x42df180FUNC<unknown>DEFAULT14
                                            _finit_.dynsym0x40739067FUNC<unknown>DEFAULT13
                                            _init.dynsym0x4056f00FUNC<unknown>DEFAULT11
                                            _init_.dynsym0x4074c099FUNC<unknown>DEFAULT13
                                            _mxml_entity_cb.dynsym0x429020188FUNC<unknown>DEFAULT13
                                            _mxml_global.dynsym0x428ef06FUNC<unknown>DEFAULT13
                                            _mxml_strdupf.dynsym0x42d320147FUNC<unknown>DEFAULT13
                                            _mxml_strlcat.dynsym0x42d100139FUNC<unknown>DEFAULT13
                                            _mxml_strlcpy.dynsym0x42d090102FUNC<unknown>DEFAULT13
                                            _mxml_vstrdupf.dynsym0x42d1f0291FUNC<unknown>DEFAULT13
                                            _remove.dynsym0x4073e010FUNC<unknown>DEFAULT13
                                            _start.dynsym0x405b300FUNC<unknown>DEFAULT13
                                            accessGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                            b_create_node.dynsym0x406660148FUNC<unknown>DEFAULT13
                                            b_free_node.dynsym0x405c8033FUNC<unknown>DEFAULT13
                                            b_gen_readme_file.dynsym0x405f00385FUNC<unknown>DEFAULT13
                                            b_gen_salsa_key.dynsym0x405e30203FUNC<unknown>DEFAULT13
                                            b_get_file_size.dynsym0x405cb043FUNC<unknown>DEFAULT13
                                            b_hex_to_string.dynsym0x406090131FUNC<unknown>DEFAULT13
                                            b_malloc.dynsym0x405df063FUNC<unknown>DEFAULT13
                                            b_mxml_get_text.dynsym0x405c209FUNC<unknown>DEFAULT13
                                            b_queue_pop_node.dynsym0x405ce0113FUNC<unknown>DEFAULT13
                                            b_queue_push_node.dynsym0x405d60129FUNC<unknown>DEFAULT13
                                            b_rename.dynsym0x406700170FUNC<unknown>DEFAULT13
                                            b_rsa_enc.dynsym0x406df01429FUNC<unknown>DEFAULT13
                                            b_skip_some_file.dynsym0x4068a0313FUNC<unknown>DEFAULT13
                                            b_str_to_lower.dynsym0x405c3071FUNC<unknown>DEFAULT13
                                            b_work.dynsym0x4069e01026FUNC<unknown>DEFAULT13
                                            callocGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                            closeGLIBC_2.2.5libpthread.so.0.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                            closedirGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                            cry_thread.dynsym0x4075e0622FUNC<unknown>DEFAULT13
                                            data_start.dynsym0x6394000NOTYPE<unknown>DEFAULT24
                                            exec_cmds.dynsym0x407420146FUNC<unknown>DEFAULT13
                                            exitGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                            fcloseGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                            ferrorGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                            fgetsGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                            fopen64GLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                            fprintfGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                            freadGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                            freeGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                            fseekGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                            ftellGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                            fwriteGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                            g_ext.dynsym0x63cda08OBJECT<unknown>DEFAULT25
                                            get_cry_ext.dynsym0x406120697FUNC<unknown>DEFAULT13
                                            gmtime_rGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                            goto_overlay.dynsym0x4067b0237FUNC<unknown>DEFAULT13
                                            init_xml.dynsym0x4073f033FUNC<unknown>DEFAULT13
                                            kill_all_vms.dynsym0x40663038FUNC<unknown>DEFAULT13
                                            kill_vms.dynsym0x4063e0591FUNC<unknown>DEFAULT13
                                            lseek64GLIBC_2.2.5libpthread.so.0.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                            main.dynsym0x407530169FUNC<unknown>DEFAULT13
                                            mallocGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                            mbedtls_aes_crypt_cbc.dynsym0x41f2a01101FUNC<unknown>DEFAULT13
                                            mbedtls_aes_crypt_cfb128.dynsym0x41f960330FUNC<unknown>DEFAULT13
                                            mbedtls_aes_crypt_cfb8.dynsym0x41f0e0444FUNC<unknown>DEFAULT13
                                            mbedtls_aes_crypt_ctr.dynsym0x41f6f0610FUNC<unknown>DEFAULT13
                                            mbedtls_aes_crypt_ecb.dynsym0x41dc70182FUNC<unknown>DEFAULT13
                                            mbedtls_aes_crypt_ofb.dynsym0x41f000209FUNC<unknown>DEFAULT13
                                            mbedtls_aes_crypt_xts.dynsym0x41fab01557FUNC<unknown>DEFAULT13
                                            mbedtls_aes_free.dynsym0x41dd3018FUNC<unknown>DEFAULT13
                                            mbedtls_aes_init.dynsym0x41d08011FUNC<unknown>DEFAULT13
                                            mbedtls_aes_self_test.dynsym0x4200d03291FUNC<unknown>DEFAULT13
                                            mbedtls_aes_setkey_dec.dynsym0x41ecc0629FUNC<unknown>DEFAULT13
                                            mbedtls_aes_setkey_enc.dynsym0x41dd503773FUNC<unknown>DEFAULT13
                                            mbedtls_aes_xts_free.dynsym0x41efd042FUNC<unknown>DEFAULT13
                                            mbedtls_aes_xts_init.dynsym0x41eca029FUNC<unknown>DEFAULT13
                                            mbedtls_aes_xts_setkey_dec.dynsym0x41ef40139FUNC<unknown>DEFAULT13
                                            mbedtls_aes_xts_setkey_enc.dynsym0x41ec10139FUNC<unknown>DEFAULT13
                                            mbedtls_aesni_crypt_ecb.dynsym0x42413092FUNC<unknown>DEFAULT13
                                            mbedtls_aesni_gcm_mult.dynsym0x424190661FUNC<unknown>DEFAULT13
                                            mbedtls_aesni_has_support.dynsym0x42410047FUNC<unknown>DEFAULT13
                                            mbedtls_aesni_inverse_key.dynsym0x4246a0122FUNC<unknown>DEFAULT13
                                            mbedtls_aesni_setkey_enc.dynsym0x424430621FUNC<unknown>DEFAULT13
                                            mbedtls_ctr_drbg_free.dynsym0x414a5047FUNC<unknown>DEFAULT13
                                            mbedtls_ctr_drbg_init.dynsym0x413bc028FUNC<unknown>DEFAULT13
                                            mbedtls_ctr_drbg_random.dynsym0x414cd05FUNC<unknown>DEFAULT13
                                            mbedtls_ctr_drbg_random_with_add.dynsym0x414740655FUNC<unknown>DEFAULT13
                                            mbedtls_ctr_drbg_reseed.dynsym0x4147307FUNC<unknown>DEFAULT13
                                            mbedtls_ctr_drbg_seed.dynsym0x414640234FUNC<unknown>DEFAULT13
                                            mbedtls_ctr_drbg_self_test.dynsym0x414da0950FUNC<unknown>DEFAULT13
                                            mbedtls_ctr_drbg_set_entropy_len.dynsym0x413b405FUNC<unknown>DEFAULT13
                                            mbedtls_ctr_drbg_set_nonce_len.dynsym0x413b5038FUNC<unknown>DEFAULT13
                                            mbedtls_ctr_drbg_set_prediction_resistance.dynsym0x413b304FUNC<unknown>DEFAULT13
                                            mbedtls_ctr_drbg_set_reseed_interval.dynsym0x413b804FUNC<unknown>DEFAULT13
                                            mbedtls_ctr_drbg_update.dynsym0x4149d0117FUNC<unknown>DEFAULT13
                                            mbedtls_ctr_drbg_update_seed_file.dynsym0x415160413FUNC<unknown>DEFAULT13
                                            mbedtls_ctr_drbg_write_seed_file.dynsym0x414ce0181FUNC<unknown>DEFAULT13
                                            mbedtls_entropy_add_source.dynsym0x4193f068FUNC<unknown>DEFAULT13
                                            mbedtls_entropy_free.dynsym0x41948053FUNC<unknown>DEFAULT13
                                            mbedtls_entropy_func.dynsym0x419770373FUNC<unknown>DEFAULT13
                                            mbedtls_entropy_gather.dynsym0x4197605FUNC<unknown>DEFAULT13
                                            mbedtls_entropy_init.dynsym0x4194c0122FUNC<unknown>DEFAULT13
                                            mbedtls_entropy_self_test.dynsym0x419f001515FUNC<unknown>DEFAULT13
                                            mbedtls_entropy_update_manual.dynsym0x419b60246FUNC<unknown>DEFAULT13
                                            mbedtls_entropy_update_seed_file.dynsym0x419c60668FUNC<unknown>DEFAULT13
                                            mbedtls_entropy_write_seed_file.dynsym0x419ab0164FUNC<unknown>DEFAULT13
                                            mbedtls_internal_aes_decrypt.dynsym0x41d0901510FUNC<unknown>DEFAULT13
                                            mbedtls_internal_aes_encrypt.dynsym0x41d6801519FUNC<unknown>DEFAULT13
                                            mbedtls_internal_md5_process.dynsym0x4094c02697FUNC<unknown>DEFAULT13
                                            mbedtls_internal_ripemd160_process.dynsym0x4265606811FUNC<unknown>DEFAULT13
                                            mbedtls_internal_sha1_process.dynsym0x41ad605918FUNC<unknown>DEFAULT13
                                            mbedtls_internal_sha256_process.dynsym0x4248604504FUNC<unknown>DEFAULT13
                                            mbedtls_internal_sha512_process.dynsym0x421be02957FUNC<unknown>DEFAULT13
                                            mbedtls_md.dynsym0x420e90152FUNC<unknown>DEFAULT13
                                            mbedtls_md5.dynsym0x40a420197FUNC<unknown>DEFAULT13
                                            mbedtls_md5_clone.dynsym0x4093f087FUNC<unknown>DEFAULT13
                                            mbedtls_md5_finish.dynsym0x409f50446FUNC<unknown>DEFAULT13
                                            mbedtls_md5_free.dynsym0x40a21018FUNC<unknown>DEFAULT13
                                            mbedtls_md5_info.dynsym0x4313c016OBJECT<unknown>DEFAULT15
                                            mbedtls_md5_init.dynsym0x40948054FUNC<unknown>DEFAULT13
                                            mbedtls_md5_self_test.dynsym0x40a230493FUNC<unknown>DEFAULT13
                                            mbedtls_md5_starts.dynsym0x40945044FUNC<unknown>DEFAULT13
                                            mbedtls_md5_update.dynsym0x40a110247FUNC<unknown>DEFAULT13
                                            mbedtls_md_clone.dynsym0x421420158FUNC<unknown>DEFAULT13
                                            mbedtls_md_file.dynsym0x421710310FUNC<unknown>DEFAULT13
                                            mbedtls_md_finish.dynsym0x420f3085FUNC<unknown>DEFAULT13
                                            mbedtls_md_free.dynsym0x4214c0194FUNC<unknown>DEFAULT13
                                            mbedtls_md_get_name.dynsym0x420e0012FUNC<unknown>DEFAULT13
                                            mbedtls_md_get_size.dynsym0x420de013FUNC<unknown>DEFAULT13
                                            mbedtls_md_get_type.dynsym0x420df012FUNC<unknown>DEFAULT13
                                            mbedtls_md_hmac.dynsym0x4219d0217FUNC<unknown>DEFAULT13
                                            mbedtls_md_hmac_finish.dynsym0x421110196FUNC<unknown>DEFAULT13
                                            mbedtls_md_hmac_reset.dynsym0x4210a0104FUNC<unknown>DEFAULT13
                                            mbedtls_md_hmac_starts.dynsym0x4211e0568FUNC<unknown>DEFAULT13
                                            mbedtls_md_hmac_update.dynsym0x420ff034FUNC<unknown>DEFAULT13
                                            mbedtls_md_info_from_string.dynsym0x421850371FUNC<unknown>DEFAULT13
                                            mbedtls_md_info_from_type.dynsym0x420dc022FUNC<unknown>DEFAULT13
                                            mbedtls_md_init.dynsym0x420e7024FUNC<unknown>DEFAULT13
                                            mbedtls_md_list.dynsym0x420db06FUNC<unknown>DEFAULT13
                                            mbedtls_md_process.dynsym0x420e1085FUNC<unknown>DEFAULT13
                                            mbedtls_md_setup.dynsym0x421590383FUNC<unknown>DEFAULT13
                                            mbedtls_md_starts.dynsym0x421020117FUNC<unknown>DEFAULT13
                                            mbedtls_md_update.dynsym0x420f9085FUNC<unknown>DEFAULT13
                                            mbedtls_mpi_add_abs.dynsym0x40ce60509FUNC<unknown>DEFAULT13
                                            mbedtls_mpi_add_int.dynsym0x40d3c069FUNC<unknown>DEFAULT13
                                            mbedtls_mpi_add_mpi.dynsym0x40d060861FUNC<unknown>DEFAULT13
                                            mbedtls_mpi_bitlen.dynsym0x40a590136FUNC<unknown>DEFAULT13
                                            mbedtls_mpi_cmp_abs.dynsym0x40a620201FUNC<unknown>DEFAULT13
                                            mbedtls_mpi_cmp_int.dynsym0x40bae0231FUNC<unknown>DEFAULT13
                                            mbedtls_mpi_cmp_mpi.dynsym0x40a6f0250FUNC<unknown>DEFAULT13
                                            mbedtls_mpi_copy.dynsym0x40ccc0410FUNC<unknown>DEFAULT13
                                            mbedtls_mpi_div_int.dynsym0x41272069FUNC<unknown>DEFAULT13
                                            mbedtls_mpi_div_mpi.dynsym0x40f7f02442FUNC<unknown>DEFAULT13
                                            mbedtls_mpi_exp_mod.dynsym0x410cc02509FUNC<unknown>DEFAULT13
                                            mbedtls_mpi_fill_random.dynsym0x40c040457FUNC<unknown>DEFAULT13
                                            mbedtls_mpi_free.dynsym0x40b8b064FUNC<unknown>DEFAULT13
                                            mbedtls_mpi_gcd.dynsym0x40d9401160FUNC<unknown>DEFAULT13
                                            mbedtls_mpi_gen_prime.dynsym0x4121001560FUNC<unknown>DEFAULT13
                                            mbedtls_mpi_get_bit.dynsym0x40a51043FUNC<unknown>DEFAULT13
                                            mbedtls_mpi_grow.dynsym0x40b760162FUNC<unknown>DEFAULT13
                                            mbedtls_mpi_init.dynsym0x40a4f023FUNC<unknown>DEFAULT13
                                            mbedtls_mpi_inv_mod.dynsym0x4103b02306FUNC<unknown>DEFAULT13
                                            mbedtls_mpi_is_prime_ext.dynsym0x412030197FUNC<unknown>DEFAULT13
                                            mbedtls_mpi_lsb.dynsym0x40a54076FUNC<unknown>DEFAULT13
                                            mbedtls_mpi_lset.dynsym0x40bdf0216FUNC<unknown>DEFAULT13
                                            mbedtls_mpi_lt_mpi_ct.dynsym0x40a7f0226FUNC<unknown>DEFAULT13
                                            mbedtls_mpi_mod_int.dynsym0x40a8e0168FUNC<unknown>DEFAULT13
                                            mbedtls_mpi_mod_mpi.dynsym0x410180556FUNC<unknown>DEFAULT13
                                            mbedtls_mpi_mul_int.dynsym0x40e8001346FUNC<unknown>DEFAULT13
                                            mbedtls_mpi_mul_mpi.dynsym0x40ed501807FUNC<unknown>DEFAULT13
                                            mbedtls_mpi_random.dynsym0x40d580950FUNC<unknown>DEFAULT13
                                            mbedtls_mpi_read_binary.dynsym0x40c460698FUNC<unknown>DEFAULT13
                                            mbedtls_mpi_read_binary_le.dynsym0x40c720408FUNC<unknown>DEFAULT13
                                            mbedtls_mpi_read_file.dynsym0x40e680370FUNC<unknown>DEFAULT13
                                            mbedtls_mpi_read_string.dynsym0x40ddd02218FUNC<unknown>DEFAULT13
                                            mbedtls_mpi_safe_cond_assign.dynsym0x40bbd0530FUNC<unknown>DEFAULT13
                                            mbedtls_mpi_safe_cond_swap.dynsym0x40cae0473FUNC<unknown>DEFAULT13
                                            mbedtls_mpi_self_test.dynsym0x4127701621FUNC<unknown>DEFAULT13
                                            mbedtls_mpi_set_bit.dynsym0x40b810154FUNC<unknown>DEFAULT13
                                            mbedtls_mpi_shift_l.dynsym0x40c8c0542FUNC<unknown>DEFAULT13
                                            mbedtls_mpi_shift_r.dynsym0x40d410368FUNC<unknown>DEFAULT13
                                            mbedtls_mpi_shrink.dynsym0x40bed0353FUNC<unknown>DEFAULT13
                                            mbedtls_mpi_size.dynsym0x40b8f0136FUNC<unknown>DEFAULT13
                                            mbedtls_mpi_sub_abs.dynsym0x40c210586FUNC<unknown>DEFAULT13
                                            mbedtls_mpi_sub_int.dynsym0x40f7a069FUNC<unknown>DEFAULT13
                                            mbedtls_mpi_sub_mpi.dynsym0x40f460823FUNC<unknown>DEFAULT13
                                            mbedtls_mpi_swap.dynsym0x40b73043FUNC<unknown>DEFAULT13
                                            mbedtls_mpi_write_binary.dynsym0x40ab70216FUNC<unknown>DEFAULT13
                                            mbedtls_mpi_write_binary_le.dynsym0x40ac50202FUNC<unknown>DEFAULT13
                                            mbedtls_mpi_write_file.dynsym0x412dd01858FUNC<unknown>DEFAULT13
                                            mbedtls_mpi_write_string.dynsym0x4135201550FUNC<unknown>DEFAULT13
                                            mbedtls_oid_get_attr_short_name.dynsym0x41ac10102FUNC<unknown>DEFAULT13
                                            mbedtls_oid_get_certificate_policies.dynsym0x41aac0102FUNC<unknown>DEFAULT13
                                            mbedtls_oid_get_cipher_alg.dynsym0x41a890102FUNC<unknown>DEFAULT13
                                            mbedtls_oid_get_ec_grp.dynsym0x41a900102FUNC<unknown>DEFAULT13
                                            mbedtls_oid_get_extended_key_usage.dynsym0x41ab30102FUNC<unknown>DEFAULT13
                                            mbedtls_oid_get_md_alg.dynsym0x41a820102FUNC<unknown>DEFAULT13
                                            mbedtls_oid_get_md_hmac.dynsym0x41a7b0102FUNC<unknown>DEFAULT13
                                            mbedtls_oid_get_numeric_string.dynsym0x41a630270FUNC<unknown>DEFAULT13
                                            mbedtls_oid_get_oid_by_ec_grp.dynsym0x41a59077FUNC<unknown>DEFAULT13
                                            mbedtls_oid_get_oid_by_md.dynsym0x41a5e077FUNC<unknown>DEFAULT13
                                            mbedtls_oid_get_oid_by_pk_alg.dynsym0x41a54077FUNC<unknown>DEFAULT13
                                            mbedtls_oid_get_oid_by_sig_alg.dynsym0x41a4f069FUNC<unknown>DEFAULT13
                                            mbedtls_oid_get_pk_alg.dynsym0x41a970102FUNC<unknown>DEFAULT13
                                            mbedtls_oid_get_pkcs12_pbe_alg.dynsym0x41a740102FUNC<unknown>DEFAULT13
                                            mbedtls_oid_get_sig_alg.dynsym0x41a9e0102FUNC<unknown>DEFAULT13
                                            mbedtls_oid_get_sig_alg_desc.dynsym0x41aa50102FUNC<unknown>DEFAULT13
                                            mbedtls_oid_get_x509_ext_type.dynsym0x41aba0102FUNC<unknown>DEFAULT13
                                            mbedtls_platform_entropy_poll.dynsym0x41cb50151FUNC<unknown>DEFAULT13
                                            mbedtls_platform_gmtime_r.dynsym0x4153205FUNC<unknown>DEFAULT13
                                            mbedtls_platform_zeroize.dynsym0x41530030FUNC<unknown>DEFAULT13
                                            mbedtls_ripemd160.dynsym0x428400205FUNC<unknown>DEFAULT13
                                            mbedtls_ripemd160_clone.dynsym0x42648093FUNC<unknown>DEFAULT13
                                            mbedtls_ripemd160_finish.dynsym0x428120728FUNC<unknown>DEFAULT13
                                            mbedtls_ripemd160_free.dynsym0x42810018FUNC<unknown>DEFAULT13
                                            mbedtls_ripemd160_info.dynsym0x4313d016OBJECT<unknown>DEFAULT15
                                            mbedtls_ripemd160_init.dynsym0x42652054FUNC<unknown>DEFAULT13
                                            mbedtls_ripemd160_self_test.dynsym0x4284d0541FUNC<unknown>DEFAULT13
                                            mbedtls_ripemd160_starts.dynsym0x4264e051FUNC<unknown>DEFAULT13
                                            mbedtls_ripemd160_update.dynsym0x428000247FUNC<unknown>DEFAULT13
                                            mbedtls_rsa_check_privkey.dynsym0x4186d0290FUNC<unknown>DEFAULT13
                                            mbedtls_rsa_check_pub_priv.dynsym0x418c60186FUNC<unknown>DEFAULT13
                                            mbedtls_rsa_check_pubkey.dynsym0x416a30127FUNC<unknown>DEFAULT13
                                            mbedtls_rsa_complete.dynsym0x417d20797FUNC<unknown>DEFAULT13
                                            mbedtls_rsa_copy.dynsym0x415420389FUNC<unknown>DEFAULT13
                                            mbedtls_rsa_deduce_crt.dynsym0x423ae0236FUNC<unknown>DEFAULT13
                                            mbedtls_rsa_deduce_primes.dynsym0x423d20991FUNC<unknown>DEFAULT13
                                            mbedtls_rsa_deduce_private_exponent.dynsym0x423bd0333FUNC<unknown>DEFAULT13
                                            mbedtls_rsa_export.dynsym0x415cf0383FUNC<unknown>DEFAULT13
                                            mbedtls_rsa_export_crt.dynsym0x415bf0247FUNC<unknown>DEFAULT13
                                            mbedtls_rsa_export_raw.dynsym0x415e70457FUNC<unknown>DEFAULT13
                                            mbedtls_rsa_free.dynsym0x415340162FUNC<unknown>DEFAULT13
                                            mbedtls_rsa_gen_key.dynsym0x4188001106FUNC<unknown>DEFAULT13
                                            mbedtls_rsa_get_len.dynsym0x4153305FUNC<unknown>DEFAULT13
                                            mbedtls_rsa_import.dynsym0x415b10224FUNC<unknown>DEFAULT13
                                            mbedtls_rsa_import_raw.dynsym0x415a10242FUNC<unknown>DEFAULT13
                                            mbedtls_rsa_init.dynsym0x41583011FUNC<unknown>DEFAULT13
                                            mbedtls_rsa_pkcs1_decrypt.dynsym0x4185f058FUNC<unknown>DEFAULT13
                                            mbedtls_rsa_pkcs1_encrypt.dynsym0x418d20812FUNC<unknown>DEFAULT13
                                            mbedtls_rsa_pkcs1_sign.dynsym0x41863086FUNC<unknown>DEFAULT13
                                            mbedtls_rsa_pkcs1_verify.dynsym0x41869055FUNC<unknown>DEFAULT13
                                            mbedtls_rsa_private.dynsym0x416ab01889FUNC<unknown>DEFAULT13
                                            mbedtls_rsa_public.dynsym0x416170255FUNC<unknown>DEFAULT13
                                            mbedtls_rsa_rsaes_oaep_decrypt.dynsym0x417a30748FUNC<unknown>DEFAULT13
                                            mbedtls_rsa_rsaes_oaep_encrypt.dynsym0x416800550FUNC<unknown>DEFAULT13
                                            mbedtls_rsa_rsaes_pkcs1_v15_decrypt.dynsym0x4176d0862FUNC<unknown>DEFAULT13
                                            mbedtls_rsa_rsaes_pkcs1_v15_encrypt.dynsym0x4166b0335FUNC<unknown>DEFAULT13
                                            mbedtls_rsa_rsassa_pkcs1_v15_sign.dynsym0x417220341FUNC<unknown>DEFAULT13
                                            mbedtls_rsa_rsassa_pkcs1_v15_verify.dynsym0x416270309FUNC<unknown>DEFAULT13
                                            mbedtls_rsa_rsassa_pss_sign.dynsym0x4176a031FUNC<unknown>DEFAULT13
                                            mbedtls_rsa_rsassa_pss_sign_ext.dynsym0x4176c05FUNC<unknown>DEFAULT13
                                            mbedtls_rsa_rsassa_pss_verify.dynsym0x4182f023FUNC<unknown>DEFAULT13
                                            mbedtls_rsa_rsassa_pss_verify_ext.dynsym0x4163b0764FUNC<unknown>DEFAULT13
                                            mbedtls_rsa_self_test.dynsym0x419050928FUNC<unknown>DEFAULT13
                                            mbedtls_rsa_set_padding.dynsym0x4155b097FUNC<unknown>DEFAULT13
                                            mbedtls_rsa_validate_crt.dynsym0x4234e0563FUNC<unknown>DEFAULT13
                                            mbedtls_rsa_validate_params.dynsym0x423720952FUNC<unknown>DEFAULT13
                                            mbedtls_sha1.dynsym0x41ca80205FUNC<unknown>DEFAULT13
                                            mbedtls_sha1_clone.dynsym0x41ac8093FUNC<unknown>DEFAULT13
                                            mbedtls_sha1_finish.dynsym0x41c480478FUNC<unknown>DEFAULT13
                                            mbedtls_sha1_free.dynsym0x41c76018FUNC<unknown>DEFAULT13
                                            mbedtls_sha1_info.dynsym0x4313e016OBJECT<unknown>DEFAULT15
                                            mbedtls_sha1_init.dynsym0x41ad2054FUNC<unknown>DEFAULT13
                                            mbedtls_sha1_self_test.dynsym0x41c780763FUNC<unknown>DEFAULT13
                                            mbedtls_sha1_starts.dynsym0x41ace051FUNC<unknown>DEFAULT13
                                            mbedtls_sha1_update.dynsym0x41c660247FUNC<unknown>DEFAULT13
                                            mbedtls_sha224_info.dynsym0x4313f016OBJECT<unknown>DEFAULT15
                                            mbedtls_sha256.dynsym0x426280497FUNC<unknown>DEFAULT13
                                            mbedtls_sha256_clone.dynsym0x424720109FUNC<unknown>DEFAULT13
                                            mbedtls_sha256_finish.dynsym0x425a00574FUNC<unknown>DEFAULT13
                                            mbedtls_sha256_free.dynsym0x425d4018FUNC<unknown>DEFAULT13
                                            mbedtls_sha256_info.dynsym0x43140016OBJECT<unknown>DEFAULT15
                                            mbedtls_sha256_init.dynsym0x42482054FUNC<unknown>DEFAULT13
                                            mbedtls_sha256_self_test.dynsym0x425d601297FUNC<unknown>DEFAULT13
                                            mbedtls_sha256_starts.dynsym0x424790142FUNC<unknown>DEFAULT13
                                            mbedtls_sha256_update.dynsym0x425c40247FUNC<unknown>DEFAULT13
                                            mbedtls_sha384_info.dynsym0x43141016OBJECT<unknown>DEFAULT15
                                            mbedtls_sha512.dynsym0x423270617FUNC<unknown>DEFAULT13
                                            mbedtls_sha512_clone.dynsym0x421ab09FUNC<unknown>DEFAULT13
                                            mbedtls_sha512_finish.dynsym0x4227701070FUNC<unknown>DEFAULT13
                                            mbedtls_sha512_free.dynsym0x422cb018FUNC<unknown>DEFAULT13
                                            mbedtls_sha512_info.dynsym0x43142016OBJECT<unknown>DEFAULT15
                                            mbedtls_sha512_init.dynsym0x421bd011FUNC<unknown>DEFAULT13
                                            mbedtls_sha512_self_test.dynsym0x422cd01439FUNC<unknown>DEFAULT13
                                            mbedtls_sha512_starts.dynsym0x421ac0265FUNC<unknown>DEFAULT13
                                            mbedtls_sha512_update.dynsym0x422ba0263FUNC<unknown>DEFAULT13
                                            memcmpGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                            memcpyGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                            memmoveGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                            memsetGLIBC_2.2.5libc.so.6.dynsym0x4057380FUNC<unknown>DEFAULTSHN_UNDEF
                                            mxmlAdd.dynsym0x42d6c0397FUNC<unknown>DEFAULT13
                                            mxmlDelete.dynsym0x42d5a0231FUNC<unknown>DEFAULT13
                                            mxmlElementDeleteAttr.dynsym0x429580177FUNC<unknown>DEFAULT13
                                            mxmlElementGetAttr.dynsym0x429260114FUNC<unknown>DEFAULT13
                                            mxmlElementGetAttrByIndex.dynsym0x4291f073FUNC<unknown>DEFAULT13
                                            mxmlElementGetAttrCount.dynsym0x42924019FUNC<unknown>DEFAULT13
                                            mxmlElementSetAttr.dynsym0x429500118FUNC<unknown>DEFAULT13
                                            mxmlElementSetAttrf.dynsym0x4293e0277FUNC<unknown>DEFAULT13
                                            mxmlEntityAddCallback.dynsym0x4291b059FUNC<unknown>DEFAULT13
                                            mxmlEntityGetName.dynsym0x42900022FUNC<unknown>DEFAULT13
                                            mxmlEntityGetValue.dynsym0x4290e096FUNC<unknown>DEFAULT13
                                            mxmlEntityRemoveCallback.dynsym0x429140105FUNC<unknown>DEFAULT13
                                            mxmlFindElement.dynsym0x4287c01289FUNC<unknown>DEFAULT13
                                            mxmlFindPath.dynsym0x428cd0469FUNC<unknown>DEFAULT13
                                            mxmlGetRefCount.dynsym0x42d3c012FUNC<unknown>DEFAULT13
                                            mxmlLoadFd.dynsym0x42b64052FUNC<unknown>DEFAULT13
                                            mxmlLoadFile.dynsym0x42b63016FUNC<unknown>DEFAULT13
                                            mxmlLoadString.dynsym0x42b60035FUNC<unknown>DEFAULT13
                                            mxmlNewCDATA.dynsym0x42dc4076FUNC<unknown>DEFAULT13
                                            mxmlNewCustom.dynsym0x42db0058FUNC<unknown>DEFAULT13
                                            mxmlNewElement.dynsym0x42dbf069FUNC<unknown>DEFAULT13
                                            mxmlNewInteger.dynsym0x42dae023FUNC<unknown>DEFAULT13
                                            mxmlNewOpaque.dynsym0x42dba072FUNC<unknown>DEFAULT13
                                            mxmlNewOpaquef.dynsym0x42da20184FUNC<unknown>DEFAULT13
                                            mxmlNewReal.dynsym0x42d9f039FUNC<unknown>DEFAULT13
                                            mxmlNewText.dynsym0x42db4088FUNC<unknown>DEFAULT13
                                            mxmlNewTextf.dynsym0x42d910219FUNC<unknown>DEFAULT13
                                            mxmlNewXML.dynsym0x42dc9086FUNC<unknown>DEFAULT13
                                            mxmlRelease.dynsym0x42d69041FUNC<unknown>DEFAULT13
                                            mxmlRemove.dynsym0x42d3d0102FUNC<unknown>DEFAULT13
                                            mxmlRetain.dynsym0x42d44021FUNC<unknown>DEFAULT13
                                            mxmlSAXLoadFd.dynsym0x42b5c052FUNC<unknown>DEFAULT13
                                            mxmlSAXLoadFile.dynsym0x42b5b016FUNC<unknown>DEFAULT13
                                            mxmlSAXLoadString.dynsym0x42b58035FUNC<unknown>DEFAULT13
                                            mxmlSaveAllocString.dynsym0x42cf30342FUNC<unknown>DEFAULT13
                                            mxmlSaveFd.dynsym0x42cd10193FUNC<unknown>DEFAULT13
                                            mxmlSaveFile.dynsym0x42cde0119FUNC<unknown>DEFAULT13
                                            mxmlSaveString.dynsym0x42ce60198FUNC<unknown>DEFAULT13
                                            mxmlSetCustomHandlers.dynsym0x42972054FUNC<unknown>DEFAULT13
                                            mxmlSetErrorCallback.dynsym0x42971014FUNC<unknown>DEFAULT13
                                            mxmlSetWrapMargin.dynsym0x42970016FUNC<unknown>DEFAULT13
                                            mxmlWalkNext.dynsym0x4286f0100FUNC<unknown>DEFAULT13
                                            mxmlWalkPrev.dynsym0x42876084FUNC<unknown>DEFAULT13
                                            mxml_error.dynsym0x428f00255FUNC<unknown>DEFAULT13
                                            mxml_ignore_cb.dynsym0x428eb06FUNC<unknown>DEFAULT13
                                            mxml_integer_cb.dynsym0x428ec06FUNC<unknown>DEFAULT13
                                            mxml_opaque_cb.dynsym0x428ed06FUNC<unknown>DEFAULT13
                                            mxml_real_cb.dynsym0x428ee06FUNC<unknown>DEFAULT13
                                            mxml_root.dynsym0x63cd988OBJECT<unknown>DEFAULT25
                                            my_strdup.dynsym0x42d19087FUNC<unknown>DEFAULT13
                                            open64GLIBC_2.2.5libpthread.so.0.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                            opendirGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                            pcloseGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                            popenGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                            printfGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                            pthread_createGLIBC_2.2.5libpthread.so.0.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                            pthread_joinGLIBC_2.2.5libpthread.so.0.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                            pthread_mutex_initGLIBC_2.2.5libpthread.so.0.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                            pthread_mutex_lockGLIBC_2.2.5libpthread.so.0.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                            pthread_mutex_unlockGLIBC_2.2.5libpthread.so.0.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                            putcharGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                            putsGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                            randGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                            readGLIBC_2.2.5libpthread.so.0.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                            readdir64GLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                            reallocGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                            removeGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                            renameGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                            s20_crypt.dynsym0x4086d0442FUNC<unknown>DEFAULT13
                                            self_path.dynsym0x63cd908OBJECT<unknown>DEFAULT25
                                            sem_initGLIBC_2.2.5libpthread.so.0.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                            sem_postGLIBC_2.2.5libpthread.so.0.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                            sem_waitGLIBC_2.2.5libpthread.so.0.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                            sleepGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                            snprintfGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                            sprintfGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                            stderrGLIBC_2.2.5libc.so.6.dynsym0x63ab208OBJECT<unknown>DEFAULT25
                                            strcatGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                            strchrGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                            strcmpGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                            strcpyGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                            strlenGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                            strrchrGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                            strstrGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                            strtodGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                            strtolGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                            t_key.dynsym0x63cda88OBJECT<unknown>DEFAULT25
                                            t_rsa_key.dynsym0x63cdb08OBJECT<unknown>DEFAULT25
                                            vsnprintfGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                            walk_thread.dynsym0x407850449FUNC<unknown>DEFAULT13
                                            writeGLIBC_2.2.5libpthread.so.0.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                            xml_buff.dynsym0x6394205000OBJECT<unknown>DEFAULT24

                                            Download Network PCAP: filteredfull

                                            • Total Packets: 7
                                            • 443 (HTTPS)
                                            • 80 (HTTP)
                                            TimestampSource PortDest PortSource IPDest IP
                                            Nov 4, 2024 19:02:47.709270000 CET43928443192.168.2.2391.189.91.42
                                            Nov 4, 2024 19:02:53.340668917 CET42836443192.168.2.2391.189.91.43
                                            Nov 4, 2024 19:02:54.620605946 CET4251680192.168.2.23109.202.202.202
                                            Nov 4, 2024 19:03:07.674571037 CET43928443192.168.2.2391.189.91.42
                                            Nov 4, 2024 19:03:19.960882902 CET42836443192.168.2.2391.189.91.43
                                            Nov 4, 2024 19:03:24.056360006 CET4251680192.168.2.23109.202.202.202
                                            Nov 4, 2024 19:03:48.629069090 CET43928443192.168.2.2391.189.91.42

                                            System Behavior

                                            Start time (UTC):18:02:45
                                            Start date (UTC):04/11/2024
                                            Path:/tmp/e.dat.elf
                                            Arguments:/tmp/e.dat.elf
                                            File size:242999 bytes
                                            MD5 hash:64cc86931bab241dcc08db03e659bcc5

                                            Start time (UTC):18:02:45
                                            Start date (UTC):04/11/2024
                                            Path:/tmp/e.dat.elf
                                            Arguments:-
                                            File size:242999 bytes
                                            MD5 hash:64cc86931bab241dcc08db03e659bcc5

                                            Start time (UTC):18:02:45
                                            Start date (UTC):04/11/2024
                                            Path:/bin/sh
                                            Arguments:sh -c "touch a"
                                            File size:129816 bytes
                                            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                            Start time (UTC):18:02:45
                                            Start date (UTC):04/11/2024
                                            Path:/bin/sh
                                            Arguments:-
                                            File size:129816 bytes
                                            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                            Start time (UTC):18:02:45
                                            Start date (UTC):04/11/2024
                                            Path:/usr/bin/touch
                                            Arguments:touch a
                                            File size:100728 bytes
                                            MD5 hash:3859c173f5d3b37be3e531b7c84a9c68