Edit tour
Linux
Analysis Report
i686.elf
Overview
General Information
Detection
Mirai, Gafgyt
Score: | 92 |
Range: | 0 - 100 |
Whitelisted: | false |
Signatures
Detected Mirai
Found malware configuration
Malicious sample detected (through community Yara rule)
Suricata IDS alerts for network traffic
Yara detected Gafgyt
Contains symbols with names commonly found in malware
Machine Learning detection for sample
Opens /proc/net/* files useful for finding connected devices and routers
Detected TCP or UDP traffic on non-standard ports
Executes the "rm" command used to delete files or directories
Sample contains strings that are user agent strings indicative of HTTP manipulation
Yara signature match
Classification
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1570182 |
Start date and time: | 2024-12-06 16:27:10 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 48s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultlinuxfilecookbook.jbs |
Analysis system description: | Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11) |
Analysis Mode: | default |
Sample name: | i686.elf |
Detection: | MAL |
Classification: | mal92.spre.troj.linELF@0/0@2/0 |
- VT rate limit hit for: i686.elf
Command: | /tmp/i686.elf |
PID: | 5478 |
Exit Code: | 0 |
Exit Code Info: | |
Killed: | False |
Standard Output: | c2 execed |
Standard Error: |
- system is lnxubuntu20
- dash New Fork (PID: 5483, Parent: 3632)
- dash New Fork (PID: 5484, Parent: 3632)
- dash New Fork (PID: 5485, Parent: 3632)
- dash New Fork (PID: 5486, Parent: 3632)
- dash New Fork (PID: 5487, Parent: 3632)
- dash New Fork (PID: 5488, Parent: 3632)
- dash New Fork (PID: 5489, Parent: 3632)
- dash New Fork (PID: 5490, Parent: 3632)
- dash New Fork (PID: 5491, Parent: 3632)
- dash New Fork (PID: 5492, Parent: 3632)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
Mirai | Mirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world. | No Attribution |
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
Bashlite, Gafgyt | Bashlite is a malware family which infects Linux systems in order to launch distributed denial-of-service attacks (DDoS). Originally it was also known under the name Bashdoor, but this term now refers to the exploit method used by the malware. It has been used to launch attacks of up to 400 Gbps. | No Attribution |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Gafgyt | Yara detected Gafgyt | Joe Security | ||
Linux_Trojan_Mirai_3a56423b | unknown | unknown |
| |
Linux_Trojan_Mirai_dab39a25 | unknown | unknown |
|
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
Linux_Trojan_Mirai_3a56423b | unknown | unknown |
| |
Linux_Trojan_Mirai_dab39a25 | unknown | unknown |
| |
Linux_Trojan_Mirai_3a56423b | unknown | unknown |
| |
Linux_Trojan_Mirai_dab39a25 | unknown | unknown |
|
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-12-06T16:27:49.580162+0100 | 2841335 | 1 | Malware Command and Control Activity Detected | 192.168.2.14 | 36292 | 154.216.18.82 | 9999 | TCP |
2024-12-06T16:28:11.602120+0100 | 2841335 | 1 | Malware Command and Control Activity Detected | 192.168.2.14 | 36294 | 154.216.18.82 | 9999 | TCP |
2024-12-06T16:28:33.646915+0100 | 2841335 | 1 | Malware Command and Control Activity Detected | 192.168.2.14 | 36296 | 154.216.18.82 | 9999 | TCP |
2024-12-06T16:28:55.664578+0100 | 2841335 | 1 | Malware Command and Control Activity Detected | 192.168.2.14 | 36298 | 154.216.18.82 | 9999 | TCP |
2024-12-06T16:29:17.695523+0100 | 2841335 | 1 | Malware Command and Control Activity Detected | 192.168.2.14 | 36300 | 154.216.18.82 | 9999 | TCP |
2024-12-06T16:29:39.729064+0100 | 2841335 | 1 | Malware Command and Control Activity Detected | 192.168.2.14 | 36302 | 154.216.18.82 | 9999 | TCP |
2024-12-06T16:30:01.775304+0100 | 2841335 | 1 | Malware Command and Control Activity Detected | 192.168.2.14 | 36304 | 154.216.18.82 | 9999 | TCP |
2024-12-06T16:30:23.805636+0100 | 2841335 | 1 | Malware Command and Control Activity Detected | 192.168.2.14 | 36306 | 154.216.18.82 | 9999 | TCP |
2024-12-06T16:30:45.852941+0100 | 2841335 | 1 | Malware Command and Control Activity Detected | 192.168.2.14 | 36308 | 154.216.18.82 | 9999 | TCP |
2024-12-06T16:31:07.853641+0100 | 2841335 | 1 | Malware Command and Control Activity Detected | 192.168.2.14 | 36310 | 154.216.18.82 | 9999 | TCP |
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | Malware Configuration Extractor: |
Source: | Joe Sandbox ML: |
Source: | HTTPS traffic detected: |
Spreading |
---|
Source: | Opens: | Jump to behavior |
Networking |
---|
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | TCP traffic: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | DNS traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: |
System Summary |
---|
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Name: |
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Classification label: |
Source: | Rm executable: | Jump to behavior | ||
Source: | Rm executable: | Jump to behavior |
Stealing of Sensitive Information |
---|
Source: | File source: |
Source: | User agent string found: | ||
Source: | User agent string found: | ||
Source: | User agent string found: | ||
Source: | User agent string found: | ||
Source: | User agent string found: | ||
Source: | User agent string found: | ||
Source: | User agent string found: |
Remote Access Functionality |
---|
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | File source: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | Path Interception | Path Interception | 1 File Deletion | OS Credential Dumping | 1 Remote System Discovery | Remote Services | Data from Local System | 1 Data Obfuscation | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Rootkit | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Encrypted Channel | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 1 Non-Standard Port | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 1 Non-Application Layer Protocol | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | Software Packing | LSA Secrets | Internet Connection Discovery | SSH | Keylogging | 2 Application Layer Protocol | Scheduled Transfer | Data Encrypted for Impact |
{"C2 url": "154.216.18.82:9999"}
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Joe Sandbox ML |
⊘No Antivirus matches
⊘No Antivirus matches
⊘No Antivirus matches
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
daisy.ubuntu.com | 162.213.35.25 | true | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
true | unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
54.217.10.153 | unknown | United States | 16509 | AMAZON-02US | false | |
185.125.190.26 | unknown | United Kingdom | 41231 | CANONICAL-ASGB | false | |
154.216.18.82 | unknown | Seychelles | 135357 | SKHT-ASShenzhenKatherineHengTechnologyInformationCo | true |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
54.217.10.153 | Get hash | malicious | Mirai | Browse | ||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Gafgyt | Browse | |||
Get hash | malicious | Gafgyt, Mirai | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Chaos | Browse | |||
Get hash | malicious | Gafgyt, Mirai | Browse | |||
Get hash | malicious | Okiru | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Gafgyt, Mirai | Browse | |||
185.125.190.26 | Get hash | malicious | Mirai, Gafgyt | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Gafgyt | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Gafgyt, Mirai | Browse | |||
Get hash | malicious | Mirai, Okiru | Browse | |||
Get hash | malicious | Gafgyt, Mirai | Browse | |||
Get hash | malicious | Mirai, Okiru | Browse | |||
Get hash | malicious | Gafgyt, Mirai | Browse | |||
154.216.18.82 | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
daisy.ubuntu.com | Get hash | malicious | Mirai, Gafgyt | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Gafgyt | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Gafgyt, Okiru | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
CANONICAL-ASGB | Get hash | malicious | Mirai, Gafgyt | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Gafgyt | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Gafgyt | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Xmrig | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
SKHT-ASShenzhenKatherineHengTechnologyInformationCo | Get hash | malicious | Mirai, Gafgyt | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Gafgyt | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Gafgyt | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Remcos | Browse |
| ||
AMAZON-02US | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
⊘No context
⊘No context
⊘No created / dropped files found
File type: | |
Entropy (8bit): | 6.2982993388874755 |
TrID: |
|
File name: | i686.elf |
File size: | 80'697 bytes |
MD5: | c39eb100d7867ca81882390ac31f277c |
SHA1: | 5e9775cb88f9278604e5f6ae7bbc7f638f325562 |
SHA256: | 043e6c37078a24861d9d886df3398c8a930da701a3f13d1a65acba3adb3ba92b |
SHA512: | 77afe996fc627a52d47c193b1684ece162267f60cf788d3701f85e257968234335913eb487f08e5bd2c8bc5aca16cf8e19c79c4cbf21c78b7aa3822a4a414527 |
SSDEEP: | 1536:x39YCcP0zWbAtWb4WomRV7Ut31gaBlBir81Je53:dmrP0GAtz7q6lY81M3 |
TLSH: | 3E733A86E353C0B2C8431B7101AB973E4330FD625726AE1AE75CBEB49A339C5745672E |
File Content Preview: | .ELF....................X...4...........4. ...(.....................D...D...............D...Dr..Dr..X....K..........Q.td................................d.......................U......=.s...t..1.....r......r......u........t...$Dr..........s................ |
ELF header | |
---|---|
Class: | |
Data: | |
Version: | |
Machine: | |
Version Number: | |
Type: | |
OS/ABI: | |
ABI Version: | 0 |
Entry Point Address: | |
Flags: | |
ELF Header Size: | 52 |
Program Header Offset: | 52 |
Program Header Size: | 32 |
Number of Program Headers: | 3 |
Section Header Offset: | 66000 |
Section Header Size: | 40 |
Number of Section Headers: | 25 |
Header String Table Index: | 22 |
Name | Type | Address | Offset | Size | EntSize | Flags | Flags Description | Link | Info | Align |
---|---|---|---|---|---|---|---|---|---|---|
NULL | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0 | 0 | 0 | ||
.init | PROGBITS | 0x8048094 | 0x94 | 0x11 | 0x0 | 0x6 | AX | 0 | 0 | 1 |
.text | PROGBITS | 0x80480b0 | 0xb0 | 0xcbac | 0x0 | 0x6 | AX | 0 | 0 | 16 |
.fini | PROGBITS | 0x8054c5c | 0xcc5c | 0xc | 0x0 | 0x6 | AX | 0 | 0 | 1 |
.rodata | PROGBITS | 0x8054c80 | 0xcc80 | 0x15c4 | 0x0 | 0x2 | A | 0 | 0 | 32 |
.eh_frame | PROGBITS | 0x8057244 | 0xe244 | 0x74 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.ctors | PROGBITS | 0x80572b8 | 0xe2b8 | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.dtors | PROGBITS | 0x80572c0 | 0xe2c0 | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.jcr | PROGBITS | 0x80572c8 | 0xe2c8 | 0x4 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.got.plt | PROGBITS | 0x80572cc | 0xe2cc | 0xc | 0x4 | 0x3 | WA | 0 | 0 | 4 |
.data | PROGBITS | 0x80572d8 | 0xe2d8 | 0xc4 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.bss | NOBITS | 0x80573a0 | 0xe39c | 0x4a8c | 0x0 | 0x3 | WA | 0 | 0 | 32 |
.comment | PROGBITS | 0x0 | 0xe39c | 0x9c6 | 0x0 | 0x0 | 0 | 0 | 1 | |
.debug_aranges | PROGBITS | 0x0 | 0xed62 | 0x40 | 0x0 | 0x0 | 0 | 0 | 1 | |
.debug_pubnames | PROGBITS | 0x0 | 0xeda2 | 0x40 | 0x0 | 0x0 | 0 | 0 | 1 | |
.debug_info | PROGBITS | 0x0 | 0xede2 | 0x602 | 0x0 | 0x0 | 0 | 0 | 1 | |
.debug_abbrev | PROGBITS | 0x0 | 0xf3e4 | 0x29a | 0x0 | 0x0 | 0 | 0 | 1 | |
.debug_line | PROGBITS | 0x0 | 0xf67e | 0x1ae | 0x0 | 0x0 | 0 | 0 | 1 | |
.debug_frame | PROGBITS | 0x0 | 0xf82c | 0x80 | 0x0 | 0x0 | 0 | 0 | 4 | |
.debug_str | PROGBITS | 0x0 | 0xf8ac | 0x127 | 0x1 | 0x30 | MS | 0 | 0 | 1 |
.debug_loc | PROGBITS | 0x0 | 0xf9d3 | 0x67e | 0x0 | 0x0 | 0 | 0 | 1 | |
.debug_ranges | PROGBITS | 0x0 | 0x10051 | 0x98 | 0x0 | 0x0 | 0 | 0 | 1 | |
.shstrtab | STRTAB | 0x0 | 0x100e9 | 0xe5 | 0x0 | 0x0 | 0 | 0 | 1 | |
.symtab | SYMTAB | 0x0 | 0x105b8 | 0x20f0 | 0x10 | 0x0 | 24 | 254 | 4 | |
.strtab | STRTAB | 0x0 | 0x126a8 | 0x1491 | 0x0 | 0x0 | 0 | 0 | 1 |
Type | Offset | Virtual Address | Physical Address | File Size | Memory Size | Entropy | Flags | Flags Description | Align | Prog Interpreter | Section Mappings |
---|---|---|---|---|---|---|---|---|---|---|---|
LOAD | 0x0 | 0x8048000 | 0x8048000 | 0xe244 | 0xe244 | 6.4562 | 0x5 | R E | 0x1000 | .init .text .fini .rodata | |
LOAD | 0xe244 | 0x8057244 | 0x8057244 | 0x158 | 0x4be8 | 2.9360 | 0x6 | RW | 0x1000 | .eh_frame .ctors .dtors .jcr .got.plt .data .bss | |
GNU_STACK | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0.0000 | 0x6 | RW | 0x4 |
Name | Version Info Name | Version Info File Name | Section Name | Value | Size | Symbol Type | Symbol Bind | Symbol Visibility | Ndx |
---|---|---|---|---|---|---|---|---|---|
.symtab | 0x0 | 0 | NOTYPE | <unknown> | DEFAULT | SHN_UNDEF | |||
.symtab | 0x8048094 | 0 | SECTION | <unknown> | DEFAULT | 1 | |||
.symtab | 0x80480b0 | 0 | SECTION | <unknown> | DEFAULT | 2 | |||
.symtab | 0x8054c5c | 0 | SECTION | <unknown> | DEFAULT | 3 | |||
.symtab | 0x8054c80 | 0 | SECTION | <unknown> | DEFAULT | 4 | |||
.symtab | 0x8057244 | 0 | SECTION | <unknown> | DEFAULT | 5 | |||
.symtab | 0x80572b8 | 0 | SECTION | <unknown> | DEFAULT | 6 | |||
.symtab | 0x80572c0 | 0 | SECTION | <unknown> | DEFAULT | 7 | |||
.symtab | 0x80572c8 | 0 | SECTION | <unknown> | DEFAULT | 8 | |||
.symtab | 0x80572cc | 0 | SECTION | <unknown> | DEFAULT | 9 | |||
.symtab | 0x80572d8 | 0 | SECTION | <unknown> | DEFAULT | 10 | |||
.symtab | 0x80573a0 | 0 | SECTION | <unknown> | DEFAULT | 11 | |||
.symtab | 0x0 | 0 | SECTION | <unknown> | DEFAULT | 12 | |||
.symtab | 0x0 | 0 | SECTION | <unknown> | DEFAULT | 13 | |||
.symtab | 0x0 | 0 | SECTION | <unknown> | DEFAULT | 14 | |||
.symtab | 0x0 | 0 | SECTION | <unknown> | DEFAULT | 15 | |||
.symtab | 0x0 | 0 | SECTION | <unknown> | DEFAULT | 16 | |||
.symtab | 0x0 | 0 | SECTION | <unknown> | DEFAULT | 17 | |||
.symtab | 0x0 | 0 | SECTION | <unknown> | DEFAULT | 18 | |||
.symtab | 0x0 | 0 | SECTION | <unknown> | DEFAULT | 19 | |||
.symtab | 0x0 | 0 | SECTION | <unknown> | DEFAULT | 20 | |||
.symtab | 0x0 | 0 | SECTION | <unknown> | DEFAULT | 21 | |||
Q | .symtab | 0x80573e0 | 16384 | OBJECT | <unknown> | DEFAULT | 11 | ||
SendHTTPHex | .symtab | 0x804a2fe | 390 | FUNC | <unknown> | DEFAULT | 2 | ||
SendSTDHEX | .symtab | 0x8049b70 | 290 | FUNC | <unknown> | DEFAULT | 2 | ||
SendUDP | .symtab | 0x80493e0 | 842 | FUNC | <unknown> | DEFAULT | 2 | ||
_DYNAMIC | .symtab | 0x0 | 0 | NOTYPE | <unknown> | HIDDEN | SHN_UNDEF | ||
_Exit | .symtab | 0x8050cbc | 21 | FUNC | <unknown> | DEFAULT | 2 | ||
_Exit.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
_GLOBAL_OFFSET_TABLE_ | .symtab | 0x80572cc | 0 | OBJECT | <unknown> | HIDDEN | 9 | ||
_Jv_RegisterClasses | .symtab | 0x0 | 0 | NOTYPE | <unknown> | DEFAULT | SHN_UNDEF | ||
__CTOR_END__ | .symtab | 0x80572bc | 0 | OBJECT | <unknown> | DEFAULT | 6 | ||
__CTOR_LIST__ | .symtab | 0x80572b8 | 0 | OBJECT | <unknown> | DEFAULT | 6 | ||
__DTOR_END__ | .symtab | 0x80572c4 | 0 | OBJECT | <unknown> | DEFAULT | 7 | ||
__DTOR_LIST__ | .symtab | 0x80572c0 | 0 | OBJECT | <unknown> | DEFAULT | 7 | ||
__EH_FRAME_BEGIN__ | .symtab | 0x8057244 | 0 | OBJECT | <unknown> | DEFAULT | 5 | ||
__FRAME_END__ | .symtab | 0x80572b4 | 0 | OBJECT | <unknown> | DEFAULT | 5 | ||
__JCR_END__ | .symtab | 0x80572c8 | 0 | OBJECT | <unknown> | DEFAULT | 8 | ||
__JCR_LIST__ | .symtab | 0x80572c8 | 0 | OBJECT | <unknown> | DEFAULT | 8 | ||
___environ | .symtab | 0x805bc60 | 4 | OBJECT | <unknown> | DEFAULT | 11 | ||
__aio_close | .symtab | 0x804f09c | 5 | FUNC | <unknown> | DEFAULT | 2 | ||
__block_all_sigs | .symtab | 0x804ef3b | 31 | FUNC | <unknown> | DEFAULT | 2 | ||
__block_app_sigs | .symtab | 0x804ef1c | 31 | FUNC | <unknown> | DEFAULT | 2 | ||
__bss_start | .symtab | 0x805739c | 0 | NOTYPE | <unknown> | DEFAULT | SHN_ABS | ||
__clock_gettime | .symtab | 0x80508b0 | 87 | FUNC | <unknown> | DEFAULT | 2 | ||
__copy_tls | .symtab | 0x8050b18 | 96 | FUNC | <unknown> | DEFAULT | 2 | ||
__deregister_frame_info_bases | .symtab | 0x0 | 0 | NOTYPE | <unknown> | DEFAULT | SHN_UNDEF | ||
__dn_expand | .symtab | 0x8051a18 | 222 | FUNC | <unknown> | DEFAULT | 2 | ||
__dns_parse | .symtab | 0x8051af8 | 302 | FUNC | <unknown> | DEFAULT | 2 | ||
__do_cleanup_pop | .symtab | 0x8050840 | 1 | FUNC | <unknown> | DEFAULT | 2 | ||
__do_cleanup_push | .symtab | 0x8050840 | 1 | FUNC | <unknown> | DEFAULT | 2 | ||
__do_global_ctors_aux | .symtab | 0x8054c30 | 0 | FUNC | <unknown> | DEFAULT | 2 | ||
__do_global_dtors_aux | .symtab | 0x80480b0 | 0 | FUNC | <unknown> | DEFAULT | 2 | ||
__dso_handle | .symtab | 0x80572d8 | 0 | OBJECT | <unknown> | HIDDEN | 10 | ||
__environ | .symtab | 0x805bc60 | 4 | OBJECT | <unknown> | DEFAULT | 11 | ||
__environ.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
__errno_location | .symtab | 0x804bb74 | 10 | FUNC | <unknown> | DEFAULT | 2 | ||
__errno_location.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
__expand_heap | .symtab | 0x8051820 | 389 | FUNC | <unknown> | DEFAULT | 2 | ||
__fclose_ca | .symtab | 0x804effc | 9 | FUNC | <unknown> | DEFAULT | 2 | ||
__fclose_ca.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
__fini_array_end | .symtab | 0x80572b8 | 0 | NOTYPE | <unknown> | HIDDEN | 6 | ||
__fini_array_start | .symtab | 0x80572b8 | 0 | NOTYPE | <unknown> | HIDDEN | 6 | ||
__fopen_rb_ca | .symtab | 0x804f008 | 145 | FUNC | <unknown> | DEFAULT | 2 | ||
__fopen_rb_ca.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
__fork_handler | .symtab | 0x804ee0c | 1 | FUNC | <unknown> | DEFAULT | 2 | ||
__fpclassifyl | .symtab | 0x8053edc | 103 | FUNC | <unknown> | DEFAULT | 2 | ||
__fpclassifyl.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
__fsmu8 | .symtab | 0x8056178 | 204 | OBJECT | <unknown> | DEFAULT | 4 | ||
__funcs_on_exit | .symtab | 0x804bb80 | 1 | FUNC | <unknown> | DEFAULT | 2 | ||
__fwritex | .symtab | 0x805210c | 152 | FUNC | <unknown> | DEFAULT | 2 | ||
__get_handler_set | .symtab | 0x8051d90 | 23 | FUNC | <unknown> | DEFAULT | 2 | ||
__h_errno_location | .symtab | 0x804d5a8 | 6 | FUNC | <unknown> | DEFAULT | 2 | ||
__hwcap | .symtab | 0x805bdc0 | 4 | OBJECT | <unknown> | DEFAULT | 11 | ||
__inet_aton | .symtab | 0x804d610 | 234 | FUNC | <unknown> | DEFAULT | 2 | ||
__init_array_end | .symtab | 0x80572b8 | 0 | NOTYPE | <unknown> | HIDDEN | 6 | ||
__init_array_start | .symtab | 0x80572b8 | 0 | NOTYPE | <unknown> | HIDDEN | 6 | ||
__init_ssp | .symtab | 0x804b9f1 | 1 | FUNC | <unknown> | DEFAULT | 2 | ||
__init_tls | .symtab | 0x8050b78 | 324 | FUNC | <unknown> | DEFAULT | 2 | ||
__init_tls.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
__intscan | .symtab | 0x8050ce0 | 1929 | FUNC | <unknown> | DEFAULT | 2 | ||
__isalnum_l | .symtab | 0x8050b10 | 5 | FUNC | <unknown> | DEFAULT | 2 | ||
__isspace | .symtab | 0x8048623 | 44 | FUNC | <unknown> | DEFAULT | 2 | ||
__lctrans | .symtab | 0x8053eb5 | 5 | FUNC | <unknown> | DEFAULT | 2 | ||
__lctrans.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
__lctrans_cur | .symtab | 0x8053eba | 32 | FUNC | <unknown> | DEFAULT | 2 | ||
__lctrans_impl | .symtab | 0x8053eb0 | 5 | FUNC | <unknown> | DEFAULT | 2 | ||
__libc | .symtab | 0x805bde0 | 52 | OBJECT | <unknown> | DEFAULT | 11 | ||
__libc_sigaction | .symtab | 0x8051da7 | 331 | FUNC | <unknown> | DEFAULT | 2 | ||
__libc_start_main | .symtab | 0x804b9f2 | 386 | FUNC | <unknown> | DEFAULT | 2 | ||
__libc_start_main.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
__lock | .symtab | 0x805076b | 52 | FUNC | <unknown> | DEFAULT | 2 | ||
__lock.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
__lockfile | .symtab | 0x8051f65 | 78 | FUNC | <unknown> | DEFAULT | 2 | ||
__lockfile.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
__lookup_ipliteral | .symtab | 0x8051c28 | 357 | FUNC | <unknown> | DEFAULT | 2 | ||
__lookup_name | .symtab | 0x804d98b | 2097 | FUNC | <unknown> | DEFAULT | 2 | ||
__madvise | .symtab | 0x804d0d4 | 33 | FUNC | <unknown> | DEFAULT | 2 | ||
__malloc0 | .symtab | 0x804d060 | 65 | FUNC | <unknown> | DEFAULT | 2 | ||
__memcpy_fwd | .symtab | 0x804fda0 | 0 | NOTYPE | <unknown> | HIDDEN | 2 | ||
__mmap | .symtab | 0x804d0f9 | 162 | FUNC | <unknown> | DEFAULT | 2 | ||
__mremap | .symtab | 0x804d19c | 64 | FUNC | <unknown> | DEFAULT | 2 | ||
__munmap | .symtab | 0x804d1dd | 44 | FUNC | <unknown> | DEFAULT | 2 | ||
__ofl_lock | .symtab | 0x805473d | 22 | FUNC | <unknown> | DEFAULT | 2 | ||
__ofl_unlock | .symtab | 0x805472c | 17 | FUNC | <unknown> | DEFAULT | 2 | ||
__overflow | .symtab | 0x8051fb4 | 108 | FUNC | <unknown> | DEFAULT | 2 | ||
__overflow.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
__progname | .symtab | 0x805b3e0 | 4 | OBJECT | <unknown> | DEFAULT | 11 | ||
__progname_full | .symtab | 0x805b3e4 | 4 | OBJECT | <unknown> | DEFAULT | 11 | ||
__pthread_setcancelstate | .symtab | 0x8050884 | 42 | FUNC | <unknown> | DEFAULT | 2 | ||
__register_frame_info_bases | .symtab | 0x0 | 0 | NOTYPE | <unknown> | DEFAULT | SHN_UNDEF | ||
__res_mkquery | .symtab | 0x804e260 | 387 | FUNC | <unknown> | DEFAULT | 2 | ||
__res_msend | .symtab | 0x804e41e | 1963 | FUNC | <unknown> | DEFAULT | 2 | ||
__restore | .symtab | 0x8054564 | 0 | FUNC | <unknown> | DEFAULT | 2 | ||
__restore_rt | .symtab | 0x805456c | 0 | FUNC | <unknown> | DEFAULT | 2 | ||
__restore_sigs | .symtab | 0x804ef5a | 31 | FUNC | <unknown> | DEFAULT | 2 | ||
__set_thread_area | .symtab | 0x8053dc4 | 0 | FUNC | <unknown> | DEFAULT | 2 | ||
__shgetc | .symtab | 0x80514f0 | 273 | FUNC | <unknown> | DEFAULT | 2 | ||
__shlim | .symtab | 0x8051470 | 118 | FUNC | <unknown> | DEFAULT | 2 | ||
__sigaction | .symtab | 0x8051ef2 | 42 | FUNC | <unknown> | DEFAULT | 2 | ||
__signbitl | .symtab | 0x8053f44 | 35 | FUNC | <unknown> | DEFAULT | 2 | ||
__signbitl.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
__simple_malloc | .symtab | 0x804be50 | 245 | FUNC | <unknown> | DEFAULT | 2 | ||
__static_tls | .symtab | 0x805be1c | 16 | OBJECT | <unknown> | DEFAULT | 11 | ||
__stderr_used | .symtab | 0x805bd90 | 4 | OBJECT | <unknown> | DEFAULT | 11 | ||
__stdin_used | .symtab | 0x805bd90 | 4 | OBJECT | <unknown> | DEFAULT | 11 | ||
__stdio_close | .symtab | 0x804f0a1 | 39 | FUNC | <unknown> | DEFAULT | 2 | ||
__stdio_close.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
__stdio_exit | .symtab | 0x80545c1 | 47 | FUNC | <unknown> | DEFAULT | 2 | ||
__stdio_exit.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
__stdio_exit_needed | .symtab | 0x80545c1 | 47 | FUNC | <unknown> | DEFAULT | 2 | ||
__stdio_read | .symtab | 0x804f0c8 | 155 | FUNC | <unknown> | DEFAULT | 2 | ||
__stdio_read.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
__stdio_seek | .symtab | 0x804f164 | 124 | FUNC | <unknown> | DEFAULT | 2 | ||
__stdio_seek.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
__stdio_write | .symtab | 0x80545f0 | 204 | FUNC | <unknown> | DEFAULT | 2 | ||
__stdio_write.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
__stdout_used | .symtab | 0x805730c | 4 | OBJECT | <unknown> | DEFAULT | 10 | ||
__stdout_write | .symtab | 0x8052020 | 72 | FUNC | <unknown> | DEFAULT | 2 | ||
__stdout_write.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
__stpcpy | .symtab | 0x8053b70 | 131 | FUNC | <unknown> | DEFAULT | 2 | ||
__stpncpy | .symtab | 0x80548a0 | 206 | FUNC | <unknown> | DEFAULT | 2 | ||
__strchrnul | .symtab | 0x804ff00 | 203 | FUNC | <unknown> | DEFAULT | 2 | ||
__strerror_l | .symtab | 0x8053e48 | 74 | FUNC | <unknown> | DEFAULT | 2 | ||
__strtoimax_internal | .symtab | 0x804fc06 | 5 | FUNC | <unknown> | DEFAULT | 2 | ||
__strtol_internal | .symtab | 0x804fbaa | 31 | FUNC | <unknown> | DEFAULT | 2 | ||
__strtoll_internal | .symtab | 0x804fbe5 | 33 | FUNC | <unknown> | DEFAULT | 2 | ||
__strtoul_internal | .symtab | 0x804fbc9 | 28 | FUNC | <unknown> | DEFAULT | 2 | ||
__strtoull_internal | .symtab | 0x804fc0b | 33 | FUNC | <unknown> | DEFAULT | 2 | ||
__strtoumax_internal | .symtab | 0x804fc2c | 5 | FUNC | <unknown> | DEFAULT | 2 | ||
__syscall | .symtab | 0x804bdef | 0 | FUNC | <unknown> | HIDDEN | 2 | ||
__syscall_cp | .symtab | 0x80507a0 | 5 | FUNC | <unknown> | DEFAULT | 2 | ||
__syscall_cp.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
__syscall_cp_c | .symtab | 0x80507a5 | 5 | FUNC | <unknown> | DEFAULT | 2 | ||
__syscall_ret | .symtab | 0x804be20 | 39 | FUNC | <unknown> | DEFAULT | 2 | ||
__sysinfo | .symtab | 0x805be14 | 4 | OBJECT | <unknown> | HIDDEN | 11 | ||
__sysv_signal | .symtab | 0x804ef98 | 98 | FUNC | <unknown> | DEFAULT | 2 | ||
__toread | .symtab | 0x80546bc | 104 | FUNC | <unknown> | DEFAULT | 2 | ||
__toread.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
__toread_needs_stdio_exit | .symtab | 0x8054724 | 5 | FUNC | <unknown> | DEFAULT | 2 | ||
__toupper_l | .symtab | 0x804b9de | 18 | FUNC | <unknown> | DEFAULT | 2 | ||
__towrite | .symtab | 0x8052068 | 65 | FUNC | <unknown> | DEFAULT | 2 | ||
__towrite.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
__towrite_needs_stdio_exit | .symtab | 0x80520a9 | 5 | FUNC | <unknown> | DEFAULT | 2 | ||
__udivdi3 | .symtab | 0x8054970 | 326 | FUNC | <unknown> | HIDDEN | 2 | ||
__uflow | .symtab | 0x80520b0 | 54 | FUNC | <unknown> | DEFAULT | 2 | ||
__uflow.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
__umoddi3 | .symtab | 0x8054ac0 | 368 | FUNC | <unknown> | HIDDEN | 2 | ||
__unlock | .symtab | 0x8050724 | 71 | FUNC | <unknown> | DEFAULT | 2 | ||
__unlockfile | .symtab | 0x8051f1c | 73 | FUNC | <unknown> | DEFAULT | 2 | ||
__vdsosym | .symtab | 0x8051610 | 525 | FUNC | <unknown> | DEFAULT | 2 | ||
__vm_wait | .symtab | 0x804d0f8 | 1 | FUNC | <unknown> | DEFAULT | 2 | ||
__vsyscall | .symtab | 0x804bda4 | 0 | FUNC | <unknown> | HIDDEN | 2 | ||
__vsyscall6 | .symtab | 0x804bdd5 | 0 | FUNC | <unknown> | HIDDEN | 2 | ||
__wait | .symtab | 0x80507ac | 148 | FUNC | <unknown> | DEFAULT | 2 | ||
__wait.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
_edata | .symtab | 0x805739c | 0 | NOTYPE | <unknown> | DEFAULT | SHN_ABS | ||
_end | .symtab | 0x805be2c | 0 | NOTYPE | <unknown> | DEFAULT | SHN_ABS | ||
_environ | .symtab | 0x805bc60 | 4 | OBJECT | <unknown> | DEFAULT | 11 | ||
_exit | .symtab | 0x8050994 | 12 | FUNC | <unknown> | DEFAULT | 2 | ||
_exit.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
_fini | .symtab | 0x8054c5c | 0 | NOTYPE | <unknown> | DEFAULT | 3 | ||
_init | .symtab | 0x8048094 | 0 | NOTYPE | <unknown> | DEFAULT | 1 | ||
_pthread_cleanup_pop | .symtab | 0x8050857 | 44 | FUNC | <unknown> | DEFAULT | 2 | ||
_pthread_cleanup_push | .symtab | 0x8050841 | 22 | FUNC | <unknown> | DEFAULT | 2 | ||
_start | .symtab | 0x8048158 | 0 | NOTYPE | <unknown> | DEFAULT | 2 | ||
_start_c | .symtab | 0x8048173 | 35 | FUNC | <unknown> | DEFAULT | 2 | ||
access | .symtab | 0x80509a0 | 27 | FUNC | <unknown> | DEFAULT | 2 | ||
access.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
addrcmp | .symtab | 0x804d7ad | 15 | FUNC | <unknown> | DEFAULT | 2 | ||
all_mask | .symtab | 0x805555c | 8 | OBJECT | <unknown> | DEFAULT | 4 | ||
alloc_fwd | .symtab | 0x804c1b0 | 561 | FUNC | <unknown> | DEFAULT | 2 | ||
alloc_rev | .symtab | 0x804bf50 | 594 | FUNC | <unknown> | DEFAULT | 2 | ||
app_mask | .symtab | 0x8055554 | 8 | OBJECT | <unknown> | DEFAULT | 4 | ||
atoi | .symtab | 0x804f52c | 76 | FUNC | <unknown> | DEFAULT | 2 | ||
atoi.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
bcopy | .symtab | 0x804fc40 | 21 | FUNC | <unknown> | DEFAULT | 2 | ||
bcopy.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
bind | .symtab | 0x80519c4 | 83 | FUNC | <unknown> | DEFAULT | 2 | ||
bind.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
block.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
bot_snoopy.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
brk.1727 | .symtab | 0x805bd80 | 4 | OBJECT | <unknown> | DEFAULT | 11 | ||
bsd_signal | .symtab | 0x804ef98 | 98 | FUNC | <unknown> | DEFAULT | 2 | ||
buf | .symtab | 0x805b850 | 1032 | OBJECT | <unknown> | DEFAULT | 11 | ||
buf.1566 | .symtab | 0x805b834 | 16 | OBJECT | <unknown> | DEFAULT | 11 | ||
builtin_tls | .symtab | 0x805bc64 | 280 | OBJECT | <unknown> | DEFAULT | 11 | ||
bzero | .symtab | 0x804fc60 | 35 | FUNC | <unknown> | DEFAULT | 2 | ||
bzero.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
c | .symtab | 0x8057304 | 4 | OBJECT | <unknown> | DEFAULT | 10 | ||
cgt.1877 | .symtab | 0x805bc5c | 4 | OBJECT | <unknown> | DEFAULT | 11 | ||
chdir | .symtab | 0x80509bc | 23 | FUNC | <unknown> | DEFAULT | 2 | ||
chdir.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
cleanup | .symtab | 0x804e3e4 | 15 | FUNC | <unknown> | DEFAULT | 2 | ||
clock_gettime | .symtab | 0x80508b0 | 87 | FUNC | <unknown> | DEFAULT | 2 | ||
clock_gettime.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
close | .symtab | 0x80509d9 | 57 | FUNC | <unknown> | DEFAULT | 2 | ||
close.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
close_file | .symtab | 0x8054574 | 77 | FUNC | <unknown> | DEFAULT | 2 | ||
commServer | .symtab | 0x80572e0 | 4 | OBJECT | <unknown> | DEFAULT | 10 | ||
completed.4058 | .symtab | 0x80573a0 | 1 | OBJECT | <unknown> | DEFAULT | 11 | ||
connect | .symtab | 0x804d20c | 87 | FUNC | <unknown> | DEFAULT | 2 | ||
connect.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
connectTimeout | .symtab | 0x8048ed2 | 564 | FUNC | <unknown> | DEFAULT | 2 | ||
crt1.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
crtstuff.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
crtstuff.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
csum | .symtab | 0x8049211 | 160 | FUNC | <unknown> | DEFAULT | 2 | ||
cur.1594 | .symtab | 0x805b3f4 | 4 | OBJECT | <unknown> | DEFAULT | 11 | ||
currentServer | .symtab | 0x8057300 | 4 | OBJECT | <unknown> | DEFAULT | 10 | ||
cycle | .symtab | 0x804f60e | 121 | FUNC | <unknown> | DEFAULT | 2 | ||
defpolicy | .symtab | 0x8055498 | 120 | OBJECT | <unknown> | DEFAULT | 4 | ||
dn_expand | .symtab | 0x8051a18 | 222 | FUNC | <unknown> | DEFAULT | 2 | ||
dn_expand.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
dns_parse.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
dns_parse_callback | .symtab | 0x804d82c | 252 | FUNC | <unknown> | DEFAULT | 2 | ||
dummy | .symtab | 0x804b9f0 | 1 | FUNC | <unknown> | DEFAULT | 2 | ||
dummy | .symtab | 0x804bb80 | 1 | FUNC | <unknown> | DEFAULT | 2 | ||
dummy | .symtab | 0x804d0f8 | 1 | FUNC | <unknown> | DEFAULT | 2 | ||
dummy | .symtab | 0x804d1dc | 1 | FUNC | <unknown> | DEFAULT | 2 | ||
dummy | .symtab | 0x804ee0c | 1 | FUNC | <unknown> | DEFAULT | 2 | ||
dummy | .symtab | 0x804f09c | 5 | FUNC | <unknown> | DEFAULT | 2 | ||
dummy | .symtab | 0x8050840 | 1 | FUNC | <unknown> | DEFAULT | 2 | ||
dummy | .symtab | 0x80509d4 | 5 | FUNC | <unknown> | DEFAULT | 2 | ||
dummy | .symtab | 0x8053eb0 | 5 | FUNC | <unknown> | DEFAULT | 2 | ||
dummy1 | .symtab | 0x804b9f1 | 1 | FUNC | <unknown> | DEFAULT | 2 | ||
dummy_file | .symtab | 0x805bd90 | 4 | OBJECT | <unknown> | DEFAULT | 11 | ||
end.1595 | .symtab | 0x805b3f0 | 4 | OBJECT | <unknown> | DEFAULT | 11 | ||
end.3155 | .symtab | 0x805b400 | 4 | OBJECT | <unknown> | DEFAULT | 11 | ||
environ | .symtab | 0x805bc60 | 4 | OBJECT | <unknown> | DEFAULT | 11 | ||
errid | .symtab | 0x8055a10 | 88 | OBJECT | <unknown> | DEFAULT | 4 | ||
errmsg | .symtab | 0x8055a68 | 1804 | OBJECT | <unknown> | DEFAULT | 4 | ||
exit | .symtab | 0x804bb81 | 51 | FUNC | <unknown> | DEFAULT | 2 | ||
exit.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
expand_heap.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
f | .symtab | 0x8057310 | 136 | OBJECT | <unknown> | DEFAULT | 10 | ||
fcntl | .symtab | 0x804bbb4 | 373 | FUNC | <unknown> | DEFAULT | 2 | ||
fcntl.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
fdgets | .symtab | 0x80482f7 | 114 | FUNC | <unknown> | DEFAULT | 2 | ||
fgets | .symtab | 0x804f1e0 | 337 | FUNC | <unknown> | DEFAULT | 2 | ||
fgets.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
fgets_unlocked | .symtab | 0x804f1e0 | 337 | FUNC | <unknown> | DEFAULT | 2 | ||
fmt_u | .symtab | 0x80522c9 | 87 | FUNC | <unknown> | DEFAULT | 2 | ||
fork | .symtab | 0x804ee0d | 138 | FUNC | <unknown> | DEFAULT | 2 | ||
fork.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
fputs | .symtab | 0x80520e8 | 33 | FUNC | <unknown> | DEFAULT | 2 | ||
fputs.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
fputs_unlocked | .symtab | 0x80520e8 | 33 | FUNC | <unknown> | DEFAULT | 2 | ||
frame_dummy | .symtab | 0x8048100 | 0 | FUNC | <unknown> | DEFAULT | 2 | ||
free | .symtab | 0x804c3f0 | 1107 | FUNC | <unknown> | DEFAULT | 2 | ||
frexpl | .symtab | 0x8053f68 | 155 | FUNC | <unknown> | DEFAULT | 2 | ||
frexpl.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
ftcp | .symtab | 0x804972a | 1094 | FUNC | <unknown> | DEFAULT | 2 | ||
fwrite | .symtab | 0x80521a4 | 115 | FUNC | <unknown> | DEFAULT | 2 | ||
fwrite.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
fwrite_unlocked | .symtab | 0x80521a4 | 115 | FUNC | <unknown> | DEFAULT | 2 | ||
getArch | .symtab | 0x804a60a | 10 | FUNC | <unknown> | DEFAULT | 2 | ||
getHost | .symtab | 0x8048c29 | 55 | FUNC | <unknown> | DEFAULT | 2 | ||
getOurIP | .symtab | 0x8048369 | 540 | FUNC | <unknown> | DEFAULT | 2 | ||
getPortz | .symtab | 0x804a614 | 154 | FUNC | <unknown> | DEFAULT | 2 | ||
getRandomIP | .symtab | 0x80482cb | 44 | FUNC | <unknown> | DEFAULT | 2 | ||
gethostbyname | .symtab | 0x804d264 | 18 | FUNC | <unknown> | DEFAULT | 2 | ||
gethostbyname.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
gethostbyname2 | .symtab | 0x804d278 | 138 | FUNC | <unknown> | DEFAULT | 2 | ||
gethostbyname2.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
gethostbyname2_r | .symtab | 0x804d304 | 507 | FUNC | <unknown> | DEFAULT | 2 | ||
gethostbyname2_r.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
getint | .symtab | 0x8052320 | 37 | FUNC | <unknown> | DEFAULT | 2 | ||
getpid | .symtab | 0x8050a14 | 11 | FUNC | <unknown> | DEFAULT | 2 | ||
getpid.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
getsockname | .symtab | 0x804d500 | 83 | FUNC | <unknown> | DEFAULT | 2 | ||
getsockname.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
getsockopt | .symtab | 0x804d554 | 83 | FUNC | <unknown> | DEFAULT | 2 | ||
getsockopt.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
gotIP | .symtab | 0x80573c4 | 4 | OBJECT | <unknown> | DEFAULT | 11 | ||
h.1776 | .symtab | 0x805b830 | 4 | OBJECT | <unknown> | DEFAULT | 11 | ||
h_errno | .symtab | 0x805be18 | 4 | OBJECT | <unknown> | DEFAULT | 11 | ||
h_errno.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
handler_set | .symtab | 0x805bd88 | 8 | OBJECT | <unknown> | DEFAULT | 11 | ||
heap_lock.3154 | .symtab | 0x805b404 | 8 | OBJECT | <unknown> | DEFAULT | 11 | ||
htonl | .symtab | 0x804d5b0 | 41 | FUNC | <unknown> | DEFAULT | 2 | ||
htonl.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
htons | .symtab | 0x804d5dc | 12 | FUNC | <unknown> | DEFAULT | 2 | ||
htons.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
i.3762 | .symtab | 0x8057308 | 4 | OBJECT | <unknown> | DEFAULT | 10 | ||
if_nametoindex | .symtab | 0x80542c0 | 100 | FUNC | <unknown> | DEFAULT | 2 | ||
if_nametoindex.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
inet_addr | .symtab | 0x804d5e8 | 37 | FUNC | <unknown> | DEFAULT | 2 | ||
inet_addr.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
inet_aton | .symtab | 0x804d610 | 234 | FUNC | <unknown> | DEFAULT | 2 | ||
inet_aton.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
inet_ntoa | .symtab | 0x804d6fc | 53 | FUNC | <unknown> | DEFAULT | 2 | ||
inet_ntoa.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
inet_pton | .symtab | 0x8054324 | 576 | FUNC | <unknown> | DEFAULT | 2 | ||
inet_pton.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
initConnection | .symtab | 0x804b2d3 | 335 | FUNC | <unknown> | DEFAULT | 2 | ||
init_rand | .symtab | 0x8048198 | 112 | FUNC | <unknown> | DEFAULT | 2 | ||
internal.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
intscan.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
ioctl | .symtab | 0x804d0a4 | 48 | FUNC | <unknown> | DEFAULT | 2 | ||
ioctl.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
is_valid_hostname | .symtab | 0x804d7cb | 97 | FUNC | <unknown> | DEFAULT | 2 | ||
isalnum | .symtab | 0x8050aec | 36 | FUNC | <unknown> | DEFAULT | 2 | ||
isalnum.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
isalnum_l | .symtab | 0x8050b10 | 5 | FUNC | <unknown> | DEFAULT | 2 | ||
kill | .symtab | 0x804ef7c | 27 | FUNC | <unknown> | DEFAULT | 2 | ||
kill.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
libc.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
libgcc2.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
libgcc2.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
listFork | .symtab | 0x8049106 | 267 | FUNC | <unknown> | DEFAULT | 2 | ||
lite_malloc.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
lock.1596 | .symtab | 0x805b3e8 | 8 | OBJECT | <unknown> | DEFAULT | 11 | ||
lookup_ipliteral.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
lookup_name.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
macAddress | .symtab | 0x80573d0 | 6 | OBJECT | <unknown> | DEFAULT | 11 | ||
madvise | .symtab | 0x804d0d4 | 33 | FUNC | <unknown> | DEFAULT | 2 | ||
madvise.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
main | .symtab | 0x804b422 | 1448 | FUNC | <unknown> | DEFAULT | 2 | ||
mainCommSock | .symtab | 0x80573c0 | 4 | OBJECT | <unknown> | DEFAULT | 11 | ||
makeIPPacket | .symtab | 0x804935f | 129 | FUNC | <unknown> | DEFAULT | 2 | ||
makeRandomStr | .symtab | 0x8048c60 | 96 | FUNC | <unknown> | DEFAULT | 2 | ||
makevsepacket | .symtab | 0x8049d8d | 144 | FUNC | <unknown> | DEFAULT | 2 | ||
mal | .symtab | 0x805b420 | 1040 | OBJECT | <unknown> | DEFAULT | 11 | ||
malloc | .symtab | 0x804c850 | 1459 | FUNC | <unknown> | DEFAULT | 2 | ||
malloc.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
mbsrtowcs | .symtab | 0x8054004 | 661 | FUNC | <unknown> | DEFAULT | 2 | ||
mbsrtowcs.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
mbstowcs | .symtab | 0x80519a8 | 27 | FUNC | <unknown> | DEFAULT | 2 | ||
mbstowcs.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
memchr | .symtab | 0x804fc90 | 178 | FUNC | <unknown> | DEFAULT | 2 | ||
memchr.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
memcmp | .symtab | 0x804fd50 | 80 | FUNC | <unknown> | DEFAULT | 2 | ||
memcmp.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
memcpy | .symtab | 0x804fda0 | 0 | FUNC | <unknown> | DEFAULT | 2 | ||
memmove | .symtab | 0x804fddc | 0 | FUNC | <unknown> | DEFAULT | 2 | ||
memset | .symtab | 0x804fe10 | 0 | FUNC | <unknown> | DEFAULT | 2 | ||
mmap | .symtab | 0x804d0f9 | 162 | FUNC | <unknown> | DEFAULT | 2 | ||
mmap.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
mmap64 | .symtab | 0x804d0f9 | 162 | FUNC | <unknown> | DEFAULT | 2 | ||
mmap_step.1728 | .symtab | 0x805bd7c | 4 | OBJECT | <unknown> | DEFAULT | 11 | ||
mremap | .symtab | 0x804d19c | 64 | FUNC | <unknown> | DEFAULT | 2 | ||
mremap.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
mtime | .symtab | 0x804e3f3 | 43 | FUNC | <unknown> | DEFAULT | 2 | ||
munmap | .symtab | 0x804d1dd | 44 | FUNC | <unknown> | DEFAULT | 2 | ||
munmap.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
name_from_numeric | .symtab | 0x804d7bc | 15 | FUNC | <unknown> | DEFAULT | 2 | ||
nanosleep | .symtab | 0x8053e1c | 41 | FUNC | <unknown> | DEFAULT | 2 | ||
nanosleep.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
ntohl | .symtab | 0x804e1bc | 41 | FUNC | <unknown> | DEFAULT | 2 | ||
ntohl.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
numpids | .symtab | 0x80573c8 | 8 | OBJECT | <unknown> | DEFAULT | 11 | ||
object.4070 | .symtab | 0x80573a4 | 24 | OBJECT | <unknown> | DEFAULT | 11 | ||
ofl.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
ofl_head | .symtab | 0x805bd94 | 4 | OBJECT | <unknown> | DEFAULT | 11 | ||
ofl_lock | .symtab | 0x805bd98 | 8 | OBJECT | <unknown> | DEFAULT | 11 | ||
open | .symtab | 0x804bd2c | 120 | FUNC | <unknown> | DEFAULT | 2 | ||
open.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
open64 | .symtab | 0x804bd2c | 120 | FUNC | <unknown> | DEFAULT | 2 | ||
ourIP | .symtab | 0x805bda0 | 4 | OBJECT | <unknown> | DEFAULT | 11 | ||
out | .symtab | 0x8052345 | 26 | FUNC | <unknown> | DEFAULT | 2 | ||
p.1232 | .symtab | 0x805bc58 | 4 | OBJECT | <unknown> | DEFAULT | 11 | ||
p.4056 | .symtab | 0x80572dc | 0 | OBJECT | <unknown> | DEFAULT | 10 | ||
pad | .symtab | 0x805235f | 126 | FUNC | <unknown> | DEFAULT | 2 | ||
pids | .symtab | 0x805bda4 | 4 | OBJECT | <unknown> | DEFAULT | 11 | ||
pntz | .symtab | 0x804f578 | 31 | FUNC | <unknown> | DEFAULT | 2 | ||
policyof | .symtab | 0x804d928 | 99 | FUNC | <unknown> | DEFAULT | 2 | ||
poll | .symtab | 0x804eec0 | 43 | FUNC | <unknown> | DEFAULT | 2 | ||
poll.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
pop_arg | .symtab | 0x8052218 | 177 | FUNC | <unknown> | DEFAULT | 2 | ||
.symtab | 0x80488b4 | 723 | FUNC | <unknown> | DEFAULT | 2 | |||
printchar | .symtab | 0x804864f | 66 | FUNC | <unknown> | DEFAULT | 2 | ||
printf_core | .symtab | 0x80523dd | 5694 | FUNC | <unknown> | DEFAULT | 2 | ||
printi | .symtab | 0x8048773 | 321 | FUNC | <unknown> | DEFAULT | 2 | ||
prints | .symtab | 0x8048691 | 226 | FUNC | <unknown> | DEFAULT | 2 | ||
processCmd | .symtab | 0x804a6ae | 3109 | FUNC | <unknown> | DEFAULT | 2 | ||
program_invocation_name | .symtab | 0x805b3e4 | 4 | OBJECT | <unknown> | DEFAULT | 11 | ||
program_invocation_short_name | .symtab | 0x805b3e0 | 4 | OBJECT | <unknown> | DEFAULT | 11 | ||
pthread_cleanup_push.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
pthread_setcancelstate | .symtab | 0x8050884 | 42 | FUNC | <unknown> | DEFAULT | 2 | ||
pthread_setcancelstate.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
puts | .symtab | 0x804f334 | 142 | FUNC | <unknown> | DEFAULT | 2 | ||
puts.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
qsort | .symtab | 0x804f873 | 654 | FUNC | <unknown> | DEFAULT | 2 | ||
qsort.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
rand | .symtab | 0x804edcd | 60 | FUNC | <unknown> | DEFAULT | 2 | ||
rand.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
rand_cmwc | .symtab | 0x8048208 | 195 | FUNC | <unknown> | DEFAULT | 2 | ||
read | .symtab | 0x8050a20 | 40 | FUNC | <unknown> | DEFAULT | 2 | ||
read.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
realloc | .symtab | 0x804ce10 | 584 | FUNC | <unknown> | DEFAULT | 2 | ||
recv | .symtab | 0x804e1e8 | 32 | FUNC | <unknown> | DEFAULT | 2 | ||
recv.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
recvLine | .symtab | 0x8048cc0 | 530 | FUNC | <unknown> | DEFAULT | 2 | ||
recvfrom | .symtab | 0x804e208 | 87 | FUNC | <unknown> | DEFAULT | 2 | ||
recvfrom.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
res_mkquery | .symtab | 0x804e260 | 387 | FUNC | <unknown> | DEFAULT | 2 | ||
res_mkquery.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
res_msend.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
sc_clock_gettime | .symtab | 0x8050907 | 95 | FUNC | <unknown> | DEFAULT | 2 | ||
sccp | .symtab | 0x80507a5 | 5 | FUNC | <unknown> | DEFAULT | 2 | ||
scopeof | .symtab | 0x804d734 | 121 | FUNC | <unknown> | DEFAULT | 2 | ||
seed | .symtab | 0x805b848 | 8 | OBJECT | <unknown> | DEFAULT | 11 | ||
select | .symtab | 0x804eeec | 47 | FUNC | <unknown> | DEFAULT | 2 | ||
select.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
send | .symtab | 0x804ebcc | 32 | FUNC | <unknown> | DEFAULT | 2 | ||
send.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
sendHTTPtwo | .symtab | 0x804a484 | 390 | FUNC | <unknown> | DEFAULT | 2 | ||
sendto | .symtab | 0x804ebec | 87 | FUNC | <unknown> | DEFAULT | 2 | ||
sendto.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
setsid | .symtab | 0x8050a48 | 23 | FUNC | <unknown> | DEFAULT | 2 | ||
setsid.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
setsockopt | .symtab | 0x804ec44 | 83 | FUNC | <unknown> | DEFAULT | 2 | ||
setsockopt.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
shgetc.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
shl | .symtab | 0x804f597 | 59 | FUNC | <unknown> | DEFAULT | 2 | ||
shr | .symtab | 0x804f5d2 | 60 | FUNC | <unknown> | DEFAULT | 2 | ||
sift | .symtab | 0x804f687 | 170 | FUNC | <unknown> | DEFAULT | 2 | ||
sigaction | .symtab | 0x8051ef2 | 42 | FUNC | <unknown> | DEFAULT | 2 | ||
sigaction.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
signal | .symtab | 0x804ef98 | 98 | FUNC | <unknown> | DEFAULT | 2 | ||
signal.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
sleep | .symtab | 0x8050a60 | 49 | FUNC | <unknown> | DEFAULT | 2 | ||
sleep.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
sn_write | .symtab | 0x804f4d7 | 51 | FUNC | <unknown> | DEFAULT | 2 | ||
snprintf | .symtab | 0x804f3c4 | 33 | FUNC | <unknown> | DEFAULT | 2 | ||
snprintf.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
socket | .symtab | 0x804ec98 | 287 | FUNC | <unknown> | DEFAULT | 2 | ||
socket.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
socket_connect | .symtab | 0x8049c92 | 251 | FUNC | <unknown> | DEFAULT | 2 | ||
sockprintf | .symtab | 0x8048b87 | 162 | FUNC | <unknown> | DEFAULT | 2 | ||
sprintf | .symtab | 0x804f3e8 | 30 | FUNC | <unknown> | DEFAULT | 2 | ||
sprintf.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
srand | .symtab | 0x804edb8 | 21 | FUNC | <unknown> | DEFAULT | 2 | ||
states | .symtab | 0x80557ec | 464 | OBJECT | <unknown> | DEFAULT | 4 | ||
stdout | .symtab | 0x8055564 | 4 | OBJECT | <unknown> | DEFAULT | 4 | ||
stdout.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
stpcpy | .symtab | 0x8053b70 | 131 | FUNC | <unknown> | DEFAULT | 2 | ||
stpcpy.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
stpncpy | .symtab | 0x80548a0 | 206 | FUNC | <unknown> | DEFAULT | 2 | ||
stpncpy.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
strchr | .symtab | 0x804fed0 | 43 | FUNC | <unknown> | DEFAULT | 2 | ||
strchr.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
strchrnul | .symtab | 0x804ff00 | 203 | FUNC | <unknown> | DEFAULT | 2 | ||
strchrnul.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
strcmp | .symtab | 0x804ffd0 | 43 | FUNC | <unknown> | DEFAULT | 2 | ||
strcmp.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
strcpy | .symtab | 0x8050000 | 31 | FUNC | <unknown> | DEFAULT | 2 | ||
strcpy.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
strcspn | .symtab | 0x8053c00 | 242 | FUNC | <unknown> | DEFAULT | 2 | ||
strcspn.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
strerror | .symtab | 0x8053e92 | 28 | FUNC | <unknown> | DEFAULT | 2 | ||
strerror.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
strerror_l | .symtab | 0x8053e48 | 74 | FUNC | <unknown> | DEFAULT | 2 | ||
strlen | .symtab | 0x8050020 | 81 | FUNC | <unknown> | DEFAULT | 2 | ||
strlen.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
strncmp | .symtab | 0x8050080 | 106 | FUNC | <unknown> | DEFAULT | 2 | ||
strncmp.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
strncpy | .symtab | 0x8054760 | 39 | FUNC | <unknown> | DEFAULT | 2 | ||
strncpy.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
strnlen | .symtab | 0x80500f0 | 61 | FUNC | <unknown> | DEFAULT | 2 | ||
strnlen.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
strspn | .symtab | 0x8053d00 | 193 | FUNC | <unknown> | DEFAULT | 2 | ||
strspn.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
strstr | .symtab | 0x8050130 | 1386 | FUNC | <unknown> | DEFAULT | 2 | ||
strstr.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
strtoimax | .symtab | 0x804fc06 | 5 | FUNC | <unknown> | DEFAULT | 2 | ||
strtok | .symtab | 0x80506a0 | 131 | FUNC | <unknown> | DEFAULT | 2 | ||
strtok.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
strtol | .symtab | 0x804fbaa | 31 | FUNC | <unknown> | DEFAULT | 2 | ||
strtol.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
strtoll | .symtab | 0x804fbe5 | 33 | FUNC | <unknown> | DEFAULT | 2 | ||
strtoul | .symtab | 0x804fbc9 | 28 | FUNC | <unknown> | DEFAULT | 2 | ||
strtoull | .symtab | 0x804fc0b | 33 | FUNC | <unknown> | DEFAULT | 2 | ||
strtoumax | .symtab | 0x804fc2c | 5 | FUNC | <unknown> | DEFAULT | 2 | ||
strtox | .symtab | 0x804fb04 | 166 | FUNC | <unknown> | DEFAULT | 2 | ||
syscall_ret.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
table | .symtab | 0x80555c0 | 257 | OBJECT | <unknown> | DEFAULT | 4 | ||
tcpcsum | .symtab | 0x80492b1 | 174 | FUNC | <unknown> | DEFAULT | 2 | ||
time | .symtab | 0x8050968 | 42 | FUNC | <unknown> | DEFAULT | 2 | ||
time.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
toupper | .symtab | 0x804b9cc | 18 | FUNC | <unknown> | DEFAULT | 2 | ||
toupper.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
toupper_l | .symtab | 0x804b9de | 18 | FUNC | <unknown> | DEFAULT | 2 | ||
trim | .symtab | 0x8048585 | 158 | FUNC | <unknown> | DEFAULT | 2 | ||
trinkle | .symtab | 0x804f731 | 322 | FUNC | <unknown> | DEFAULT | 2 | ||
unmask_done | .symtab | 0x805bd84 | 4 | OBJECT | <unknown> | DEFAULT | 11 | ||
useragents | .symtab | 0x80572e4 | 28 | OBJECT | <unknown> | DEFAULT | 10 | ||
usleep | .symtab | 0x8050a94 | 47 | FUNC | <unknown> | DEFAULT | 2 | ||
usleep.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
vdso.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
vfprintf | .symtab | 0x8053a1b | 333 | FUNC | <unknown> | DEFAULT | 2 | ||
vfprintf.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
vseattack | .symtab | 0x8049e1d | 1249 | FUNC | <unknown> | DEFAULT | 2 | ||
vsnprintf | .symtab | 0x804f408 | 207 | FUNC | <unknown> | DEFAULT | 2 | ||
vsnprintf.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
vsprintf | .symtab | 0x804f50c | 29 | FUNC | <unknown> | DEFAULT | 2 | ||
vsprintf.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
waitpid | .symtab | 0x804ee98 | 40 | FUNC | <unknown> | DEFAULT | 2 | ||
waitpid.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
wcrtomb | .symtab | 0x8054788 | 270 | FUNC | <unknown> | DEFAULT | 2 | ||
wcrtomb.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
wctomb | .symtab | 0x805429c | 33 | FUNC | <unknown> | DEFAULT | 2 | ||
wctomb.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
write | .symtab | 0x8050ac4 | 40 | FUNC | <unknown> | DEFAULT | 2 | ||
write.c | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | ||
xdigits | .symtab | 0x80559bc | 16 | OBJECT | <unknown> | DEFAULT | 4 |
Timestamp | SID | Signature | Severity | Source IP | Source Port | Dest IP | Dest Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-12-06T16:27:49.580162+0100 | 2841335 | ETPRO MALWARE ELF/Mirai Variant CnC Checkin | 1 | 192.168.2.14 | 36292 | 154.216.18.82 | 9999 | TCP |
2024-12-06T16:28:11.602120+0100 | 2841335 | ETPRO MALWARE ELF/Mirai Variant CnC Checkin | 1 | 192.168.2.14 | 36294 | 154.216.18.82 | 9999 | TCP |
2024-12-06T16:28:33.646915+0100 | 2841335 | ETPRO MALWARE ELF/Mirai Variant CnC Checkin | 1 | 192.168.2.14 | 36296 | 154.216.18.82 | 9999 | TCP |
2024-12-06T16:28:55.664578+0100 | 2841335 | ETPRO MALWARE ELF/Mirai Variant CnC Checkin | 1 | 192.168.2.14 | 36298 | 154.216.18.82 | 9999 | TCP |
2024-12-06T16:29:17.695523+0100 | 2841335 | ETPRO MALWARE ELF/Mirai Variant CnC Checkin | 1 | 192.168.2.14 | 36300 | 154.216.18.82 | 9999 | TCP |
2024-12-06T16:29:39.729064+0100 | 2841335 | ETPRO MALWARE ELF/Mirai Variant CnC Checkin | 1 | 192.168.2.14 | 36302 | 154.216.18.82 | 9999 | TCP |
2024-12-06T16:30:01.775304+0100 | 2841335 | ETPRO MALWARE ELF/Mirai Variant CnC Checkin | 1 | 192.168.2.14 | 36304 | 154.216.18.82 | 9999 | TCP |
2024-12-06T16:30:23.805636+0100 | 2841335 | ETPRO MALWARE ELF/Mirai Variant CnC Checkin | 1 | 192.168.2.14 | 36306 | 154.216.18.82 | 9999 | TCP |
2024-12-06T16:30:45.852941+0100 | 2841335 | ETPRO MALWARE ELF/Mirai Variant CnC Checkin | 1 | 192.168.2.14 | 36308 | 154.216.18.82 | 9999 | TCP |
2024-12-06T16:31:07.853641+0100 | 2841335 | ETPRO MALWARE ELF/Mirai Variant CnC Checkin | 1 | 192.168.2.14 | 36310 | 154.216.18.82 | 9999 | TCP |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Dec 6, 2024 16:27:49.459479094 CET | 36292 | 9999 | 192.168.2.14 | 154.216.18.82 |
Dec 6, 2024 16:27:49.579946995 CET | 9999 | 36292 | 154.216.18.82 | 192.168.2.14 |
Dec 6, 2024 16:27:49.580049992 CET | 36292 | 9999 | 192.168.2.14 | 154.216.18.82 |
Dec 6, 2024 16:27:49.580162048 CET | 36292 | 9999 | 192.168.2.14 | 154.216.18.82 |
Dec 6, 2024 16:27:49.700584888 CET | 9999 | 36292 | 154.216.18.82 | 192.168.2.14 |
Dec 6, 2024 16:27:53.361591101 CET | 443 | 34592 | 54.217.10.153 | 192.168.2.14 |
Dec 6, 2024 16:27:53.361610889 CET | 443 | 34592 | 54.217.10.153 | 192.168.2.14 |
Dec 6, 2024 16:27:53.361622095 CET | 443 | 34592 | 54.217.10.153 | 192.168.2.14 |
Dec 6, 2024 16:27:53.362019062 CET | 34592 | 443 | 192.168.2.14 | 54.217.10.153 |
Dec 6, 2024 16:27:53.362019062 CET | 34592 | 443 | 192.168.2.14 | 54.217.10.153 |
Dec 6, 2024 16:27:53.362056017 CET | 34592 | 443 | 192.168.2.14 | 54.217.10.153 |
Dec 6, 2024 16:27:53.363056898 CET | 34592 | 443 | 192.168.2.14 | 54.217.10.153 |
Dec 6, 2024 16:27:53.482850075 CET | 443 | 34592 | 54.217.10.153 | 192.168.2.14 |
Dec 6, 2024 16:27:53.756567955 CET | 443 | 34592 | 54.217.10.153 | 192.168.2.14 |
Dec 6, 2024 16:27:53.756759882 CET | 34592 | 443 | 192.168.2.14 | 54.217.10.153 |
Dec 6, 2024 16:27:53.756923914 CET | 34592 | 443 | 192.168.2.14 | 54.217.10.153 |
Dec 6, 2024 16:27:53.876728058 CET | 443 | 34592 | 54.217.10.153 | 192.168.2.14 |
Dec 6, 2024 16:27:54.156168938 CET | 443 | 34592 | 54.217.10.153 | 192.168.2.14 |
Dec 6, 2024 16:27:54.156435966 CET | 34592 | 443 | 192.168.2.14 | 54.217.10.153 |
Dec 6, 2024 16:27:54.157386065 CET | 34592 | 443 | 192.168.2.14 | 54.217.10.153 |
Dec 6, 2024 16:27:54.277535915 CET | 443 | 34592 | 54.217.10.153 | 192.168.2.14 |
Dec 6, 2024 16:27:54.277582884 CET | 34592 | 443 | 192.168.2.14 | 54.217.10.153 |
Dec 6, 2024 16:27:59.646449089 CET | 46540 | 443 | 192.168.2.14 | 185.125.190.26 |
Dec 6, 2024 16:28:11.479500055 CET | 9999 | 36292 | 154.216.18.82 | 192.168.2.14 |
Dec 6, 2024 16:28:11.479871988 CET | 36292 | 9999 | 192.168.2.14 | 154.216.18.82 |
Dec 6, 2024 16:28:11.479921103 CET | 36294 | 9999 | 192.168.2.14 | 154.216.18.82 |
Dec 6, 2024 16:28:11.601669073 CET | 9999 | 36292 | 154.216.18.82 | 192.168.2.14 |
Dec 6, 2024 16:28:11.601682901 CET | 9999 | 36294 | 154.216.18.82 | 192.168.2.14 |
Dec 6, 2024 16:28:11.602051020 CET | 36294 | 9999 | 192.168.2.14 | 154.216.18.82 |
Dec 6, 2024 16:28:11.602119923 CET | 36294 | 9999 | 192.168.2.14 | 154.216.18.82 |
Dec 6, 2024 16:28:11.721972942 CET | 9999 | 36294 | 154.216.18.82 | 192.168.2.14 |
Dec 6, 2024 16:28:30.365175962 CET | 46540 | 443 | 192.168.2.14 | 185.125.190.26 |
Dec 6, 2024 16:28:33.526726961 CET | 9999 | 36294 | 154.216.18.82 | 192.168.2.14 |
Dec 6, 2024 16:28:33.526899099 CET | 36294 | 9999 | 192.168.2.14 | 154.216.18.82 |
Dec 6, 2024 16:28:33.526942968 CET | 36296 | 9999 | 192.168.2.14 | 154.216.18.82 |
Dec 6, 2024 16:28:33.646672964 CET | 9999 | 36294 | 154.216.18.82 | 192.168.2.14 |
Dec 6, 2024 16:28:33.646722078 CET | 9999 | 36296 | 154.216.18.82 | 192.168.2.14 |
Dec 6, 2024 16:28:33.646807909 CET | 36296 | 9999 | 192.168.2.14 | 154.216.18.82 |
Dec 6, 2024 16:28:33.646914959 CET | 36296 | 9999 | 192.168.2.14 | 154.216.18.82 |
Dec 6, 2024 16:28:33.767635107 CET | 9999 | 36296 | 154.216.18.82 | 192.168.2.14 |
Dec 6, 2024 16:28:55.542771101 CET | 9999 | 36296 | 154.216.18.82 | 192.168.2.14 |
Dec 6, 2024 16:28:55.543049097 CET | 36298 | 9999 | 192.168.2.14 | 154.216.18.82 |
Dec 6, 2024 16:28:55.543049097 CET | 36296 | 9999 | 192.168.2.14 | 154.216.18.82 |
Dec 6, 2024 16:28:55.664277077 CET | 9999 | 36298 | 154.216.18.82 | 192.168.2.14 |
Dec 6, 2024 16:28:55.664304972 CET | 9999 | 36296 | 154.216.18.82 | 192.168.2.14 |
Dec 6, 2024 16:28:55.664472103 CET | 36298 | 9999 | 192.168.2.14 | 154.216.18.82 |
Dec 6, 2024 16:28:55.664577961 CET | 36298 | 9999 | 192.168.2.14 | 154.216.18.82 |
Dec 6, 2024 16:28:55.784281969 CET | 9999 | 36298 | 154.216.18.82 | 192.168.2.14 |
Dec 6, 2024 16:29:17.574711084 CET | 9999 | 36298 | 154.216.18.82 | 192.168.2.14 |
Dec 6, 2024 16:29:17.575031042 CET | 36298 | 9999 | 192.168.2.14 | 154.216.18.82 |
Dec 6, 2024 16:29:17.575140953 CET | 36300 | 9999 | 192.168.2.14 | 154.216.18.82 |
Dec 6, 2024 16:29:17.695137024 CET | 9999 | 36298 | 154.216.18.82 | 192.168.2.14 |
Dec 6, 2024 16:29:17.695179939 CET | 9999 | 36300 | 154.216.18.82 | 192.168.2.14 |
Dec 6, 2024 16:29:17.695389986 CET | 36300 | 9999 | 192.168.2.14 | 154.216.18.82 |
Dec 6, 2024 16:29:17.695523024 CET | 36300 | 9999 | 192.168.2.14 | 154.216.18.82 |
Dec 6, 2024 16:29:17.816210985 CET | 9999 | 36300 | 154.216.18.82 | 192.168.2.14 |
Dec 6, 2024 16:29:39.606173992 CET | 9999 | 36300 | 154.216.18.82 | 192.168.2.14 |
Dec 6, 2024 16:29:39.606575966 CET | 36300 | 9999 | 192.168.2.14 | 154.216.18.82 |
Dec 6, 2024 16:29:39.606650114 CET | 36302 | 9999 | 192.168.2.14 | 154.216.18.82 |
Dec 6, 2024 16:29:39.728837967 CET | 9999 | 36300 | 154.216.18.82 | 192.168.2.14 |
Dec 6, 2024 16:29:39.728853941 CET | 9999 | 36302 | 154.216.18.82 | 192.168.2.14 |
Dec 6, 2024 16:29:39.728965044 CET | 36302 | 9999 | 192.168.2.14 | 154.216.18.82 |
Dec 6, 2024 16:29:39.729063988 CET | 36302 | 9999 | 192.168.2.14 | 154.216.18.82 |
Dec 6, 2024 16:29:39.853058100 CET | 9999 | 36302 | 154.216.18.82 | 192.168.2.14 |
Dec 6, 2024 16:30:01.654143095 CET | 9999 | 36302 | 154.216.18.82 | 192.168.2.14 |
Dec 6, 2024 16:30:01.654306889 CET | 36302 | 9999 | 192.168.2.14 | 154.216.18.82 |
Dec 6, 2024 16:30:01.654328108 CET | 36304 | 9999 | 192.168.2.14 | 154.216.18.82 |
Dec 6, 2024 16:30:01.775032997 CET | 9999 | 36302 | 154.216.18.82 | 192.168.2.14 |
Dec 6, 2024 16:30:01.775048018 CET | 9999 | 36304 | 154.216.18.82 | 192.168.2.14 |
Dec 6, 2024 16:30:01.775219917 CET | 36304 | 9999 | 192.168.2.14 | 154.216.18.82 |
Dec 6, 2024 16:30:01.775304079 CET | 36304 | 9999 | 192.168.2.14 | 154.216.18.82 |
Dec 6, 2024 16:30:01.897761106 CET | 9999 | 36304 | 154.216.18.82 | 192.168.2.14 |
Dec 6, 2024 16:30:23.685323954 CET | 9999 | 36304 | 154.216.18.82 | 192.168.2.14 |
Dec 6, 2024 16:30:23.685594082 CET | 36304 | 9999 | 192.168.2.14 | 154.216.18.82 |
Dec 6, 2024 16:30:23.685620070 CET | 36306 | 9999 | 192.168.2.14 | 154.216.18.82 |
Dec 6, 2024 16:30:23.805483103 CET | 9999 | 36304 | 154.216.18.82 | 192.168.2.14 |
Dec 6, 2024 16:30:23.805512905 CET | 9999 | 36306 | 154.216.18.82 | 192.168.2.14 |
Dec 6, 2024 16:30:23.805577040 CET | 36306 | 9999 | 192.168.2.14 | 154.216.18.82 |
Dec 6, 2024 16:30:23.805635929 CET | 36306 | 9999 | 192.168.2.14 | 154.216.18.82 |
Dec 6, 2024 16:30:23.925539970 CET | 9999 | 36306 | 154.216.18.82 | 192.168.2.14 |
Dec 6, 2024 16:30:45.732431889 CET | 9999 | 36306 | 154.216.18.82 | 192.168.2.14 |
Dec 6, 2024 16:30:45.732755899 CET | 36308 | 9999 | 192.168.2.14 | 154.216.18.82 |
Dec 6, 2024 16:30:45.732765913 CET | 36306 | 9999 | 192.168.2.14 | 154.216.18.82 |
Dec 6, 2024 16:30:45.852765083 CET | 9999 | 36306 | 154.216.18.82 | 192.168.2.14 |
Dec 6, 2024 16:30:45.852782011 CET | 9999 | 36308 | 154.216.18.82 | 192.168.2.14 |
Dec 6, 2024 16:30:45.852941036 CET | 36308 | 9999 | 192.168.2.14 | 154.216.18.82 |
Dec 6, 2024 16:30:45.852941036 CET | 36308 | 9999 | 192.168.2.14 | 154.216.18.82 |
Dec 6, 2024 16:30:45.972806931 CET | 9999 | 36308 | 154.216.18.82 | 192.168.2.14 |
Dec 6, 2024 16:31:07.732821941 CET | 9999 | 36308 | 154.216.18.82 | 192.168.2.14 |
Dec 6, 2024 16:31:07.733299971 CET | 36308 | 9999 | 192.168.2.14 | 154.216.18.82 |
Dec 6, 2024 16:31:07.733300924 CET | 36310 | 9999 | 192.168.2.14 | 154.216.18.82 |
Dec 6, 2024 16:31:07.853372097 CET | 9999 | 36308 | 154.216.18.82 | 192.168.2.14 |
Dec 6, 2024 16:31:07.853385925 CET | 9999 | 36310 | 154.216.18.82 | 192.168.2.14 |
Dec 6, 2024 16:31:07.853554010 CET | 36310 | 9999 | 192.168.2.14 | 154.216.18.82 |
Dec 6, 2024 16:31:07.853641033 CET | 36310 | 9999 | 192.168.2.14 | 154.216.18.82 |
Dec 6, 2024 16:31:07.973376989 CET | 9999 | 36310 | 154.216.18.82 | 192.168.2.14 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Dec 6, 2024 16:30:33.966078997 CET | 38057 | 53 | 192.168.2.14 | 8.8.8.8 |
Dec 6, 2024 16:30:33.966154099 CET | 40140 | 53 | 192.168.2.14 | 8.8.8.8 |
Dec 6, 2024 16:30:34.088855028 CET | 53 | 40140 | 8.8.8.8 | 192.168.2.14 |
Dec 6, 2024 16:30:34.100761890 CET | 53 | 38057 | 8.8.8.8 | 192.168.2.14 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Dec 6, 2024 16:30:33.966078997 CET | 192.168.2.14 | 8.8.8.8 | 0xc225 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 6, 2024 16:30:33.966154099 CET | 192.168.2.14 | 8.8.8.8 | 0xa376 | Standard query (0) | 28 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Dec 6, 2024 16:30:34.100761890 CET | 8.8.8.8 | 192.168.2.14 | 0xc225 | No error (0) | 162.213.35.25 | A (IP address) | IN (0x0001) | false | ||
Dec 6, 2024 16:30:34.100761890 CET | 8.8.8.8 | 192.168.2.14 | 0xc225 | No error (0) | 162.213.35.24 | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Source Port | Dest IP | Dest Port | Subject | Issuer | Not Before | Not After | JA3 SSL Client Fingerprint | JA3 SSL Client Digest |
---|---|---|---|---|---|---|---|---|---|---|
Dec 6, 2024 16:27:53.361622095 CET | 54.217.10.153 | 443 | 192.168.2.14 | 34592 | CN=motd.ubuntu.com CN=R11, O=Let's Encrypt, C=US | CN=R11, O=Let's Encrypt, C=US CN=ISRG Root X1, O=Internet Security Research Group, C=US | Mon Oct 21 10:21:37 CEST 2024 Wed Mar 13 01:00:00 CET 2024 | Sun Jan 19 09:21:36 CET 2025 Sat Mar 13 00:59:59 CET 2027 | ||
CN=R11, O=Let's Encrypt, C=US | CN=ISRG Root X1, O=Internet Security Research Group, C=US | Wed Mar 13 01:00:00 CET 2024 | Sat Mar 13 00:59:59 CET 2027 |
System Behavior
Start time (UTC): | 15:27:48 |
Start date (UTC): | 06/12/2024 |
Path: | /tmp/i686.elf |
Arguments: | /tmp/i686.elf |
File size: | 80697 bytes |
MD5 hash: | c39eb100d7867ca81882390ac31f277c |
Start time (UTC): | 15:27:48 |
Start date (UTC): | 06/12/2024 |
Path: | /tmp/i686.elf |
Arguments: | - |
File size: | 80697 bytes |
MD5 hash: | c39eb100d7867ca81882390ac31f277c |
Start time (UTC): | 15:27:48 |
Start date (UTC): | 06/12/2024 |
Path: | /tmp/i686.elf |
Arguments: | - |
File size: | 80697 bytes |
MD5 hash: | c39eb100d7867ca81882390ac31f277c |
Start time (UTC): | 15:27:53 |
Start date (UTC): | 06/12/2024 |
Path: | /usr/bin/dash |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 15:27:53 |
Start date (UTC): | 06/12/2024 |
Path: | /usr/bin/rm |
Arguments: | rm -f /tmp/tmp.YhuJwgbtVy /tmp/tmp.fbT3pxxVQj /tmp/tmp.bEIoIZXjgH |
File size: | 72056 bytes |
MD5 hash: | aa2b5496fdbfd88e38791ab81f90b95b |
Start time (UTC): | 15:27:53 |
Start date (UTC): | 06/12/2024 |
Path: | /usr/bin/dash |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 15:27:53 |
Start date (UTC): | 06/12/2024 |
Path: | /usr/bin/cat |
Arguments: | cat /tmp/tmp.YhuJwgbtVy |
File size: | 43416 bytes |
MD5 hash: | 7e9d213e404ad3bb82e4ebb2e1f2c1b3 |
Start time (UTC): | 15:27:53 |
Start date (UTC): | 06/12/2024 |
Path: | /usr/bin/dash |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 15:27:53 |
Start date (UTC): | 06/12/2024 |
Path: | /usr/bin/head |
Arguments: | head -n 10 |
File size: | 47480 bytes |
MD5 hash: | fd96a67145172477dd57131396fc9608 |
Start time (UTC): | 15:27:53 |
Start date (UTC): | 06/12/2024 |
Path: | /usr/bin/dash |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 15:27:53 |
Start date (UTC): | 06/12/2024 |
Path: | /usr/bin/tr |
Arguments: | tr -d \\000-\\011\\013\\014\\016-\\037 |
File size: | 51544 bytes |
MD5 hash: | fbd1402dd9f72d8ebfff00ce7c3a7bb5 |
Start time (UTC): | 15:27:53 |
Start date (UTC): | 06/12/2024 |
Path: | /usr/bin/dash |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 15:27:53 |
Start date (UTC): | 06/12/2024 |
Path: | /usr/bin/cut |
Arguments: | cut -c -80 |
File size: | 47480 bytes |
MD5 hash: | d8ed0ea8f22c0de0f8692d4d9f1759d3 |
Start time (UTC): | 15:27:53 |
Start date (UTC): | 06/12/2024 |
Path: | /usr/bin/dash |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 15:27:53 |
Start date (UTC): | 06/12/2024 |
Path: | /usr/bin/cat |
Arguments: | cat /tmp/tmp.YhuJwgbtVy |
File size: | 43416 bytes |
MD5 hash: | 7e9d213e404ad3bb82e4ebb2e1f2c1b3 |
Start time (UTC): | 15:27:53 |
Start date (UTC): | 06/12/2024 |
Path: | /usr/bin/dash |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 15:27:53 |
Start date (UTC): | 06/12/2024 |
Path: | /usr/bin/head |
Arguments: | head -n 10 |
File size: | 47480 bytes |
MD5 hash: | fd96a67145172477dd57131396fc9608 |
Start time (UTC): | 15:27:53 |
Start date (UTC): | 06/12/2024 |
Path: | /usr/bin/dash |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 15:27:53 |
Start date (UTC): | 06/12/2024 |
Path: | /usr/bin/tr |
Arguments: | tr -d \\000-\\011\\013\\014\\016-\\037 |
File size: | 51544 bytes |
MD5 hash: | fbd1402dd9f72d8ebfff00ce7c3a7bb5 |
Start time (UTC): | 15:27:53 |
Start date (UTC): | 06/12/2024 |
Path: | /usr/bin/dash |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 15:27:53 |
Start date (UTC): | 06/12/2024 |
Path: | /usr/bin/cut |
Arguments: | cut -c -80 |
File size: | 47480 bytes |
MD5 hash: | d8ed0ea8f22c0de0f8692d4d9f1759d3 |
Start time (UTC): | 15:27:53 |
Start date (UTC): | 06/12/2024 |
Path: | /usr/bin/dash |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 15:27:53 |
Start date (UTC): | 06/12/2024 |
Path: | /usr/bin/rm |
Arguments: | rm -f /tmp/tmp.YhuJwgbtVy /tmp/tmp.fbT3pxxVQj /tmp/tmp.bEIoIZXjgH |
File size: | 72056 bytes |
MD5 hash: | aa2b5496fdbfd88e38791ab81f90b95b |