Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
file-grey.elf

Overview

General Information

Sample name:file-grey.elf
Analysis ID:1583386
MD5:9df07b64a28b61e4c7a9f8c8e8d2a801
SHA1:a3aae326109751edac5145ff1b679f8935177ad7
SHA256:a02eeb92a977c0749f93e6c7959159e68aa3a9e93c77f1fce81dc4b014e7c545
Tags:elfmalwaretrojanuser-Joker
Infos:

Detection

Score:56
Range:0 - 100
Whitelisted:false

Signatures

Multi AV Scanner detection for submitted file
Sample and/or dropped files likely contain functionality related to malicious behavior
Sample tries to persist itself using System V runlevels
Creates hidden files and/or directories
Executes commands using a shell command-line interpreter
Executes the "chmod" command used to modify permissions
Reads CPU information from /sys indicative of miner or evasive malware
Sample and/or dropped files contains symbols with suspicious names
Sample listens on a socket
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1583386
Start date and time:2025-01-02 15:58:05 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 6m 41s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:file-grey.elf
Detection:MAL
Classification:mal56.troj.linELF@0/1@0/0
  • VT rate limit hit for: file-grey.elf
Command:/tmp/file-grey.elf
PID:6220
Exit Code:
Exit Code Info:
Killed:True
Standard Output:

Standard Error:chmod: cannot access 'script/hodin_daemon.sh': No such file or directory
chmod: cannot access 'script/delete_startup.sh': No such file or directory
chmod: cannot access 'script/startup.sh': No such file or directory
cp: cannot stat 'script/hodin_daemon.sh': No such file or directory
cp: cannot stat 'srv_hodin': No such file or directory
cp: cannot stat 'srv_hodin': No such file or directory
  • system is lnxubuntu20
  • file-grey.elf (PID: 6220, Parent: 6137, MD5: 9df07b64a28b61e4c7a9f8c8e8d2a801) Arguments: /tmp/file-grey.elf
    • sh (PID: 6221, Parent: 6220, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "chmod +x script/hodin_daemon.sh"
      • sh New Fork (PID: 6222, Parent: 6221)
      • chmod (PID: 6222, Parent: 6221, MD5: 739483b900c045ae1374d6f53a86a279) Arguments: chmod +x script/hodin_daemon.sh
    • sh (PID: 6223, Parent: 6220, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "chmod +x script/delete_startup.sh"
      • sh New Fork (PID: 6224, Parent: 6223)
      • chmod (PID: 6224, Parent: 6223, MD5: 739483b900c045ae1374d6f53a86a279) Arguments: chmod +x script/delete_startup.sh
    • sh (PID: 6225, Parent: 6220, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "chmod +x script/startup.sh"
      • sh New Fork (PID: 6226, Parent: 6225)
      • chmod (PID: 6226, Parent: 6225, MD5: 739483b900c045ae1374d6f53a86a279) Arguments: chmod +x script/startup.sh
    • sh (PID: 6227, Parent: 6220, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "cp script/hodin_daemon.sh /etc/init.d/"
      • sh New Fork (PID: 6228, Parent: 6227)
      • cp (PID: 6228, Parent: 6227, MD5: 40f10ae7ea3e44218d1a8c306f79c83f) Arguments: cp script/hodin_daemon.sh /etc/init.d/
    • sh (PID: 6229, Parent: 6220, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "cp srv_hodin /usr/bin/"
      • sh New Fork (PID: 6230, Parent: 6229)
      • cp (PID: 6230, Parent: 6229, MD5: 40f10ae7ea3e44218d1a8c306f79c83f) Arguments: cp srv_hodin /usr/bin/
    • sh (PID: 6231, Parent: 6220, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "cp srv_hodin /usr/sbin/"
      • sh New Fork (PID: 6232, Parent: 6231)
      • cp (PID: 6232, Parent: 6231, MD5: 40f10ae7ea3e44218d1a8c306f79c83f) Arguments: cp srv_hodin /usr/sbin/
    • sh (PID: 6233, Parent: 6220, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "ln -s /etc/init.d/hodin_daemon.sh /etc/rc2.d/S88hodin_daemon.sh"
      • sh New Fork (PID: 6234, Parent: 6233)
      • ln (PID: 6234, Parent: 6233, MD5: e933cf05571f62c0157d4e2dfcaea282) Arguments: ln -s /etc/init.d/hodin_daemon.sh /etc/rc2.d/S88hodin_daemon.sh
    • gst-plugin-scanner (PID: 6235, Parent: 6220, MD5: caaae748bd9798d2f4b3d09c94a9e5f4) Arguments: /usr/lib/x86_64-linux-gnu/gstreamer1.0/gstreamer-1.0/gst-plugin-scanner -l /tmp/file-grey.elf
  • cleanup
No yara matches
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: file-grey.elfReversingLabs: Detection: 42%
Source: /usr/lib/x86_64-linux-gnu/gstreamer1.0/gstreamer-1.0/gst-plugin-scanner (PID: 6235)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
Source: /tmp/file-grey.elf (PID: 6220)Socket: 0.0.0.0:4444Jump to behavior
Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: file-grey.elf, 6220.1.000055dd5e110000.000055dd5e551000.rw-.sdmpString found in binary or memory: http://www.clutter-project.org
Source: file-grey.elf, 6220.1.000055dd5e110000.000055dd5e551000.rw-.sdmpString found in binary or memory: http://www.clutter-project.orgadpcmencADPCM
Source: file-grey.elf, 6220.1.000055dd5e110000.000055dd5e551000.rw-.sdmpString found in binary or memory: http://www.freedesktop.org/wiki/Software/Farstream
Source: file-grey.elf, 6220.1.000055dd5e110000.000055dd5e551000.rw-.sdmpString found in binary or memory: http://www.freedesktop.org/wiki/Software/Farstreamapplication/x-rtp
Source: file-grey.elf, 6220.1.000055dd5e110000.000055dd5e551000.rw-.sdmpString found in binary or memory: http://xiph.org
Source: file-grey.elf, 6220.1.000055dd5e110000.000055dd5e551000.rw-.sdmpString found in binary or memory: http://xiph.org)
Source: file-grey.elf, 6220.1.000055dd5e110000.000055dd5e551000.rw-.sdmpString found in binary or memory: http://xiph.org)//xiph.org
Source: file-grey.elf, 6220.1.000055dd5e110000.000055dd5e551000.rw-.sdmpString found in binary or memory: http://xiph.org)audio/x-vorbisapplication/x-ogg-aviapplication/oggapplication/x-ogm-textapplication/
Source: file-grey.elf, 6220.1.000055dd5e110000.000055dd5e551000.rw-.sdmpString found in binary or memory: http://xiph.org)ph.org
Source: file-grey.elf, 6220.1.000055dd5e110000.000055dd5e551000.rw-.sdmpString found in binary or memory: http://xiph.org)xiph.org
Source: registry.x86_64.bin.tmpE9S3Z2.12.drString found in binary or memory: https://launchpad.net/distros/ubuntu/
Source: file-grey.elf, 6220.1.000055dd5e110000.000055dd5e551000.rw-.sdmpString found in binary or memory: https://nice.freedesktop.org/
Source: file-grey.elf, 6220.1.000055dd5e110000.000055dd5e551000.rw-.sdmpString found in binary or memory: https://nice.freedesktop.org/vpxVP8
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443

System Summary

barindex
Source: file-grey.elfELF static info symbol of initial sample: debian_keylogger_init
Source: file-grey.elfELF static info symbol of initial sample: debian_keylogger_utils.c
Source: file-grey.elfELF static info symbol of initial sample: fedora_keylogger_init
Source: file-grey.elfELF static info symbol of initial sample: kali_keylogger_init
Source: file-grey.elfELF static info symbol of initial sample: keylogger
Source: file-grey.elfELF static info symbol of initial sample: keylogger.c
Source: file-grey.elfELF static info symbol of initial sample: keylogger_utils.c
Source: file-grey.elfELF static info symbol of initial sample: mint_keylogger_init
Source: file-grey.elfELF static info symbol of initial sample: ubuntu16_keylogger_init
Source: file-grey.elfELF static info symbol of initial sample: ubuntu18_keylogger_init
Source: file-grey.elfELF static info symbol of initial sample: execute_cmd
Source: file-grey.elfELF static info symbol of initial sample: execute_record_cmd
Source: classification engineClassification label: mal56.troj.linELF@0/1@0/0

Persistence and Installation Behavior

barindex
Source: /usr/bin/ln (PID: 6234)File: /etc/rc2.d/S88hodin_daemon.sh -> /etc/init.d/hodin_daemon.shJump to behavior
Source: /usr/lib/x86_64-linux-gnu/gstreamer1.0/gstreamer-1.0/gst-plugin-scanner (PID: 6235)Directory: /root/.ladspaJump to behavior
Source: /usr/lib/x86_64-linux-gnu/gstreamer1.0/gstreamer-1.0/gst-plugin-scanner (PID: 6235)Directory: /root/.lv2Jump to behavior
Source: /usr/lib/x86_64-linux-gnu/gstreamer1.0/gstreamer-1.0/gst-plugin-scanner (PID: 6235)Directory: /root/.cacheJump to behavior
Source: /tmp/file-grey.elf (PID: 6221)Shell command executed: sh -c "chmod +x script/hodin_daemon.sh"Jump to behavior
Source: /tmp/file-grey.elf (PID: 6223)Shell command executed: sh -c "chmod +x script/delete_startup.sh"Jump to behavior
Source: /tmp/file-grey.elf (PID: 6225)Shell command executed: sh -c "chmod +x script/startup.sh"Jump to behavior
Source: /tmp/file-grey.elf (PID: 6227)Shell command executed: sh -c "cp script/hodin_daemon.sh /etc/init.d/"Jump to behavior
Source: /tmp/file-grey.elf (PID: 6229)Shell command executed: sh -c "cp srv_hodin /usr/bin/"Jump to behavior
Source: /tmp/file-grey.elf (PID: 6231)Shell command executed: sh -c "cp srv_hodin /usr/sbin/"Jump to behavior
Source: /tmp/file-grey.elf (PID: 6233)Shell command executed: sh -c "ln -s /etc/init.d/hodin_daemon.sh /etc/rc2.d/S88hodin_daemon.sh"Jump to behavior
Source: /bin/sh (PID: 6222)Chmod executable: /usr/bin/chmod -> chmod +x script/hodin_daemon.shJump to behavior
Source: /bin/sh (PID: 6224)Chmod executable: /usr/bin/chmod -> chmod +x script/delete_startup.shJump to behavior
Source: /bin/sh (PID: 6226)Chmod executable: /usr/bin/chmod -> chmod +x script/startup.shJump to behavior
Source: /usr/lib/x86_64-linux-gnu/gstreamer1.0/gstreamer-1.0/gst-plugin-scanner (PID: 6235)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
Source: /tmp/file-grey.elf (PID: 6220)Queries kernel information via 'uname': Jump to behavior
Source: /usr/lib/x86_64-linux-gnu/gstreamer1.0/gstreamer-1.0/gst-plugin-scanner (PID: 6235)Queries kernel information via 'uname': Jump to behavior
Source: file-grey.elf, 6220.1.000055dd5e110000.000055dd5e551000.rw-.sdmpBinary or memory string: Decode VmWare video to raw (RGB) video
Source: file-grey.elf, 6220.1.000055dd5e110000.000055dd5e551000.rw-.sdmpBinary or memory string: libav VMware Screen Codec / VMware Video decoder
Source: file-grey.elf, 6220.1.000055dd5e110000.000055dd5e551000.rw-.sdmpBinary or memory string: VmWare Video Codec plugins
Source: file-grey.elf, 6220.1.000055dd5e110000.000055dd5e551000.rw-.sdmpBinary or memory string: ame=(string)"VMnc\ video\ decoder", klass=(string)Codec/Decoder/Video, description=(string)"Decode\ VmWare\ video\ to\ raw\ \(RGB\)\ video", author=(string)"Michael\ Smith\ \<msmith\@xiph.org\>";
Source: file-grey.elf, 6220.1.000055dd5e110000.000055dd5e551000.rw-.sdmpBinary or memory string: video/x-raw, format=(string){ I420, YV12, Y42B, Y444, I420_10LE, I420_12LE, I422_10LE, I422_12LE, Y444_10LE, Y444_12LE }, width=(int)[ 1, 2147483647 ], height=(int)[ 1, 2147483647 ], framerate=(fraction)[ 0/1, 2147483647/1 ]video/x-raw, format=(string){ I420, Y42B, Y444, YV12 }, framerate=(fraction)[ 0/1, 2147483647/1 ], width=(int)[ 4, 2147483647 ], height=(int)[ 4, 2147483647 ]oss4Open Sound System (OSS) version 4 support for GStreameraudio/x-alaw, rate=(int)[ 1, 192000 ], channels=(int)[ 1, 4096 ]; audio/x-mulaw, rate=(int)[ 1, 192000 ], channels=(int)[ 1, 4096 ]; audio/x-raw, format=(string){ S32LE, S32BE, S24_32LE, S24_32BE, S24LE, S16LE, S16BE, U16LE, U16BE, S8, U8 }, layout=(string)interleaved, rate=(int)[ 1, 192000 ], channels=(int)[ 1, 4096 ]goomGOOM visualization filteraudiomixmatrixAudio matrix mixaudio/x-raw, channels=(int)[ 1, 2147483647 ], layout=(string)interleaved, format=(string){ F32LE, F64LE, S16LE, S32LE }mpegtsdemuxMPEG TS demuxerprivate_%01x_%05xsubpicture_%01x_%05xsubpicture/x-pgs; subpicture/x-dvd; subpicture/x-dvbaudio_%01x_%05xaudio/mpeg, mpegversion=(int)1; audio/mpeg, mpegversion=(int)2, stream-format=(string)adts; audio/mpeg, mpegversion=(int)4, stream-format=(string)loas; audio/x-lpcm, width=(int){ 16, 20, 24 }, rate=(int){ 48000, 96000 }, channels=(int)[ 1, 8 ], dynamic_range=(int)[ 0, 255 ], emphasis=(boolean){ false, true }, mute=(boolean){ false, true }; audio/x-ac3; audio/x-eac3; audio/x-dts; audio/x-opus; audio/x-private-ts-lpcmvideo_%01x_%05xvideo/mpeg, mpegversion=(int){ 1, 2, 4 }, systemstream=(boolean)false; video/x-h264, stream-format=(string)byte-stream, alignment=(string)nal; video/x-h265, stream-format=(string)byte-stream, alignment=(string)nal; video/x-dirac; video/x-cavs; video/x-wmv, wmvversion=(int)3, format=(string)WVC1; image/x-jpcprogram_%udtsdecDecodes DTS audio streamsaudio/x-raw, format=(string)F32LE, layout=(string)interleaved, rate=(int)[ 4000, 96000 ], channels=(int)[ 1, 6 ]audio/x-dts; audio/x-private1-dtssndfileuse libsndfile to read and write various audio formatsaudio/x-ircam; audio/x-nist; audio/x-paris; audio/x-rf64; audio/x-sds; audio/x-svx; audio/x-voc; audio/x-w64; audio/x-xiaudio/x-raw, format=(string){ F32LE, S32LE, S16LE }, layout=(string)interleaved, rate=(int)[ 1, 2147483647 ], channels=(int)[ 1, 2147483647 ]apetagAPEv1/2 tag readershout2Sends data to an icecast server using libshout2application/ogg; audio/ogg; video/ogg; audio/mpeg, mpegversion=(int)1, layer=(int)[ 1, 3 ]; video/webm; audio/webminterplugin for inter-pipeline communicationtext/plainapplication/unknownivtcInverse Telecinevideo/x-raw, format=(string){ I420, Y444, Y42B }, width=(int)[ 1, 2048 ], height=(int)[ 1, 2147483647 ], framerate=(fraction)[ 0/1, 2147483647/1 ]libvisuallibvisual visualization pluginsvmncVmWare Video Codec pluginsvideo/x-vmnc, version=(int)1, framerate=(fraction)[ 0/1, 2147483647/1 ], width=(int)[ 0, 2147483647 ], height=(int)[ 0, 2147483647 ]video/x-raw, format=(string){ RGBx, BGRx, xRGB, x
Source: file-grey.elf, 6220.1.000055dd5e110000.000055dd5e551000.rw-.sdmpBinary or memory string: ame=(string)"libav\ VMware\ Screen\ Codec\ /\ VMware\ Video\ decoder", klass=(string)Codec/Decoder/Video, description=(string)"libav\ vmnc\ decoder", author=(string)"Wim\ Taymans\ \<wim.taymans\@gmail.com\>\,\ Ronald\ Bultje\ \<rbultje\@ronald.bitfreak.net\>\,\ Edward\ Hervey\ \<bilboed\@bilboed.com\>";
Source: file-grey.elf, 6220.1.000055dd5e110000.000055dd5e551000.rw-.sdmpBinary or memory string: Uame=(string)"VMnc\ video\ decoder", klass=(string)Codec/Decoder/Video, description=(string)"Decode\ VmWare\ video\ to\ raw\ \(RGB\)\ video", author=(string)"Michael\ Smith\ \<msmith\@xiph.org\>";
Source: file-grey.elf, 6220.1.000055dd5e110000.000055dd5e551000.rw-.sdmpBinary or memory string: Qlibav VMware Screen Codec / VMware Video decoderdecoder"!libav vp6a decoderer"
Source: file-grey.elf, 6220.1.000055dd5e110000.000055dd5e551000.rw-.sdmpBinary or memory string: U!HOME/.libvisual/actor!plugin151A/usr/lib/x86_64-linux-gnu/gstreamer-1.0/libgstvmnc.so!libgstvmnc.so!vmncdec5!VMnc video decoderer"!Codec/Decoder/VideoQGL Shading Language effects - Sepia Toning Effect Effect"ADecode VmWare video to raw (RGB) video)\ video"
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity Information1
Scripting
Valid AccountsWindows Management Instrumentation1
Scripting
Path Interception11
Masquerading
OS Credential Dumping11
Security Software Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
File and Directory Permissions Modification
LSASS Memory1
System Information Discovery
Remote Desktop ProtocolData from Removable Media1
Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
Hidden Files and Directories
Security Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveSteganographyAutomated ExfiltrationData Encrypted for Impact
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1583386 Sample: file-grey.elf Startdate: 02/01/2025 Architecture: LINUX Score: 56 33 109.202.202.202, 80 INIT7CH Switzerland 2->33 35 91.189.91.42, 443 CANONICAL-ASGB United Kingdom 2->35 37 91.189.91.43, 443 CANONICAL-ASGB United Kingdom 2->37 41 Multi AV Scanner detection for submitted file 2->41 43 Sample and/or dropped files likely contain functionality related to malicious behavior 2->43 8 file-grey.elf 2->8         started        signatures3 process4 process5 10 file-grey.elf sh 8->10         started        12 file-grey.elf sh 8->12         started        14 file-grey.elf sh 8->14         started        16 5 other processes 8->16 process6 18 sh ln 10->18         started        21 sh chmod 12->21         started        23 sh chmod 14->23         started        25 sh chmod 16->25         started        27 sh cp 16->27         started        29 sh cp 16->29         started        31 sh cp 16->31         started        signatures7 39 Sample tries to persist itself using System V runlevels 18->39

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
file-grey.elf42%ReversingLabsWin32.Trojan.Generic
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
http://xiph.org)//xiph.org0%Avira URL Cloudsafe
http://xiph.org)xiph.org0%Avira URL Cloudsafe
http://www.freedesktop.org/wiki/Software/Farstreamapplication/x-rtp0%Avira URL Cloudsafe
https://nice.freedesktop.org/0%Avira URL Cloudsafe
http://xiph.org)audio/x-vorbisapplication/x-ogg-aviapplication/oggapplication/x-ogm-textapplication/0%Avira URL Cloudsafe
https://nice.freedesktop.org/vpxVP80%Avira URL Cloudsafe
http://xiph.org)0%Avira URL Cloudsafe
http://www.clutter-project.org0%Avira URL Cloudsafe
http://www.clutter-project.orgadpcmencADPCM0%Avira URL Cloudsafe
http://xiph.org)ph.org0%Avira URL Cloudsafe
http://www.freedesktop.org/wiki/Software/Farstream0%Avira URL Cloudsafe
No contacted domains info
NameSourceMaliciousAntivirus DetectionReputation
https://launchpad.net/distros/ubuntu/registry.x86_64.bin.tmpE9S3Z2.12.drfalse
    high
    http://xiph.org)//xiph.orgfile-grey.elf, 6220.1.000055dd5e110000.000055dd5e551000.rw-.sdmpfalse
    • Avira URL Cloud: safe
    unknown
    http://xiph.org)xiph.orgfile-grey.elf, 6220.1.000055dd5e110000.000055dd5e551000.rw-.sdmpfalse
    • Avira URL Cloud: safe
    unknown
    http://www.freedesktop.org/wiki/Software/Farstreamapplication/x-rtpfile-grey.elf, 6220.1.000055dd5e110000.000055dd5e551000.rw-.sdmpfalse
    • Avira URL Cloud: safe
    unknown
    http://xiph.org)file-grey.elf, 6220.1.000055dd5e110000.000055dd5e551000.rw-.sdmpfalse
    • Avira URL Cloud: safe
    unknown
    http://xiph.org)ph.orgfile-grey.elf, 6220.1.000055dd5e110000.000055dd5e551000.rw-.sdmpfalse
    • Avira URL Cloud: safe
    unknown
    http://xiph.orgfile-grey.elf, 6220.1.000055dd5e110000.000055dd5e551000.rw-.sdmpfalse
      high
      https://nice.freedesktop.org/vpxVP8file-grey.elf, 6220.1.000055dd5e110000.000055dd5e551000.rw-.sdmpfalse
      • Avira URL Cloud: safe
      unknown
      https://nice.freedesktop.org/file-grey.elf, 6220.1.000055dd5e110000.000055dd5e551000.rw-.sdmpfalse
      • Avira URL Cloud: safe
      unknown
      http://www.clutter-project.orgfile-grey.elf, 6220.1.000055dd5e110000.000055dd5e551000.rw-.sdmpfalse
      • Avira URL Cloud: safe
      unknown
      http://www.clutter-project.orgadpcmencADPCMfile-grey.elf, 6220.1.000055dd5e110000.000055dd5e551000.rw-.sdmpfalse
      • Avira URL Cloud: safe
      unknown
      http://xiph.org)audio/x-vorbisapplication/x-ogg-aviapplication/oggapplication/x-ogm-textapplication/file-grey.elf, 6220.1.000055dd5e110000.000055dd5e551000.rw-.sdmpfalse
      • Avira URL Cloud: safe
      unknown
      http://www.freedesktop.org/wiki/Software/Farstreamfile-grey.elf, 6220.1.000055dd5e110000.000055dd5e551000.rw-.sdmpfalse
      • Avira URL Cloud: safe
      unknown
      • No. of IPs < 25%
      • 25% < No. of IPs < 50%
      • 50% < No. of IPs < 75%
      • 75% < No. of IPs
      IPDomainCountryFlagASNASN NameMalicious
      109.202.202.202
      unknownSwitzerland
      13030INIT7CHfalse
      91.189.91.43
      unknownUnited Kingdom
      41231CANONICAL-ASGBfalse
      91.189.91.42
      unknownUnited Kingdom
      41231CANONICAL-ASGBfalse
      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
      109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
      • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
      91.189.91.43Aqua.mips.elfGet hashmaliciousUnknownBrowse
        Aqua.mpsl.elfGet hashmaliciousUnknownBrowse
          DEMONS.mips.elfGet hashmaliciousUnknownBrowse
            i.elfGet hashmaliciousUnknownBrowse
              i.elfGet hashmaliciousUnknownBrowse
                Hilix.arm5.elfGet hashmaliciousMiraiBrowse
                  i586.elfGet hashmaliciousUnknownBrowse
                    x86_64.elfGet hashmaliciousUnknownBrowse
                      socat.elfGet hashmaliciousUnknownBrowse
                        arm5.elfGet hashmaliciousUnknownBrowse
                          91.189.91.42Aqua.mips.elfGet hashmaliciousUnknownBrowse
                            Aqua.mpsl.elfGet hashmaliciousUnknownBrowse
                              DEMONS.mips.elfGet hashmaliciousUnknownBrowse
                                i.elfGet hashmaliciousUnknownBrowse
                                  i.elfGet hashmaliciousUnknownBrowse
                                    Hilix.arm5.elfGet hashmaliciousMiraiBrowse
                                      i586.elfGet hashmaliciousUnknownBrowse
                                        x86_64.elfGet hashmaliciousUnknownBrowse
                                          socat.elfGet hashmaliciousUnknownBrowse
                                            arm5.elfGet hashmaliciousUnknownBrowse
                                              No context
                                              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                              CANONICAL-ASGBAqua.mips.elfGet hashmaliciousUnknownBrowse
                                              • 91.189.91.42
                                              Aqua.mpsl.elfGet hashmaliciousUnknownBrowse
                                              • 91.189.91.42
                                              DEMONS.mips.elfGet hashmaliciousUnknownBrowse
                                              • 91.189.91.42
                                              DEMONS.arm5.elfGet hashmaliciousUnknownBrowse
                                              • 185.125.190.26
                                              DEMONS.arm7.elfGet hashmaliciousMiraiBrowse
                                              • 185.125.190.26
                                              i.elfGet hashmaliciousUnknownBrowse
                                              • 91.189.91.42
                                              i.elfGet hashmaliciousUnknownBrowse
                                              • 91.189.91.42
                                              Hilix.arm5.elfGet hashmaliciousMiraiBrowse
                                              • 91.189.91.42
                                              powerpc.elfGet hashmaliciousUnknownBrowse
                                              • 185.125.190.26
                                              i586.elfGet hashmaliciousUnknownBrowse
                                              • 91.189.91.42
                                              CANONICAL-ASGBAqua.mips.elfGet hashmaliciousUnknownBrowse
                                              • 91.189.91.42
                                              Aqua.mpsl.elfGet hashmaliciousUnknownBrowse
                                              • 91.189.91.42
                                              DEMONS.mips.elfGet hashmaliciousUnknownBrowse
                                              • 91.189.91.42
                                              DEMONS.arm5.elfGet hashmaliciousUnknownBrowse
                                              • 185.125.190.26
                                              DEMONS.arm7.elfGet hashmaliciousMiraiBrowse
                                              • 185.125.190.26
                                              i.elfGet hashmaliciousUnknownBrowse
                                              • 91.189.91.42
                                              i.elfGet hashmaliciousUnknownBrowse
                                              • 91.189.91.42
                                              Hilix.arm5.elfGet hashmaliciousMiraiBrowse
                                              • 91.189.91.42
                                              powerpc.elfGet hashmaliciousUnknownBrowse
                                              • 185.125.190.26
                                              i586.elfGet hashmaliciousUnknownBrowse
                                              • 91.189.91.42
                                              INIT7CHAqua.mips.elfGet hashmaliciousUnknownBrowse
                                              • 109.202.202.202
                                              Aqua.mpsl.elfGet hashmaliciousUnknownBrowse
                                              • 109.202.202.202
                                              DEMONS.mips.elfGet hashmaliciousUnknownBrowse
                                              • 109.202.202.202
                                              i.elfGet hashmaliciousUnknownBrowse
                                              • 109.202.202.202
                                              i.elfGet hashmaliciousUnknownBrowse
                                              • 109.202.202.202
                                              Hilix.arm5.elfGet hashmaliciousMiraiBrowse
                                              • 109.202.202.202
                                              i586.elfGet hashmaliciousUnknownBrowse
                                              • 109.202.202.202
                                              x86_64.elfGet hashmaliciousUnknownBrowse
                                              • 109.202.202.202
                                              socat.elfGet hashmaliciousUnknownBrowse
                                              • 109.202.202.202
                                              arm5.elfGet hashmaliciousUnknownBrowse
                                              • 109.202.202.202
                                              No context
                                              No context
                                              Process:/tmp/file-grey.elf
                                              File Type:GStreamer binary registry, version 1.12.0
                                              Category:dropped
                                              Size (bytes):79664
                                              Entropy (8bit):5.487370235881576
                                              Encrypted:false
                                              SSDEEP:1536:pbKWoP4sZOKzDSPzKoBdt3afOeWAbOArMN/0Ocskiyg/gQlO6H7xhho:b0gA7skiyofu
                                              MD5:4C60FBB1C270CAB8AA25065D6F77AB5D
                                              SHA1:3CA70D6D627C90F45EA29A7D1745EFDA02EDC03A
                                              SHA-256:45523B7623881E88CE92DA5AA50BE0A4FAA1BC9862EF451E97CB3ADA6A94ABF3
                                              SHA-512:DDC7332FAD733F27EBC64BFF55E95B909CA05D5B636FC74FB6FFC964EE65E379286636643814FDDF486B419D731C46E0134B086BEF2854D0CD3B1DB507CB2FBE
                                              Malicious:false
                                              Reputation:low
                                              Preview:....1.12.0...............................................................................'.`............videorate.Adjusts video frames./usr/lib/x86_64-linux-gnu/gstreamer-1.0/libgstvideorate.so.1.16.2.LGPL.gst-plugins-base.GStreamer Base Plugins (Ubuntu).https://launchpad.net/distros/ubuntu/+source/gst-plugins-base1.0.2019-12-03..GstElementFactory.videorate.........................metadata, long-name=(string)"Video\ rate\ adjuster", klass=(string)Filter/Effect/Video, description=(string)"Drops/duplicates/adjusts\ timestamps\ on\ video\ frames\ to\ make\ a\ perfect\ stream", author=(string)"Wim\ Taymans\ \<wim\@fluendo.com\>";...............sink.video/x-raw(ANY); video/x-bayer(ANY); image/jpeg(ANY); image/png(ANY)..............src.video/x-raw(ANY); video/x-bayer(ANY); image/jpeg(ANY); image/png(ANY)........{.......Rx`............level.Audio level plugin./usr/lib/x86_64-linux-gnu/gstreamer-1.0/libgstlevel.so.1.16.2.LGPL.gst-plugins-good.GStreamer Good Plugins (Ubuntu).https://launchpad.n
                                              File type:ELF 64-bit LSB pie executable, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, for GNU/Linux 3.2.0, BuildID[sha1]=16dde2b99c391271495c20fcf806ec19837098e1, not stripped
                                              Entropy (8bit):5.510166103682835
                                              TrID:
                                              • ELF Executable and Linkable format (Linux) (4029/14) 49.77%
                                              • ELF Executable and Linkable format (generic) (4004/1) 49.46%
                                              • Lumena CEL bitmap (63/63) 0.78%
                                              File name:file-grey.elf
                                              File size:53'920 bytes
                                              MD5:9df07b64a28b61e4c7a9f8c8e8d2a801
                                              SHA1:a3aae326109751edac5145ff1b679f8935177ad7
                                              SHA256:a02eeb92a977c0749f93e6c7959159e68aa3a9e93c77f1fce81dc4b014e7c545
                                              SHA512:1cdda2ae5944c9b38d102b7cbdeee0ad61cc89b4c92d80553f7d7fcd4c9b58245a4417524e10d0d064973936ee4a6cefc0b112c932c55e2899236550364418bf
                                              SSDEEP:1536:9sU7CNr299ggdjVEs3n9DXPtxOnb1Cy4u:yUqr+FdjVT3n9Dt0Cy3
                                              TLSH:7F33B5C0EA808974C1C4D771C8EF6117A8B2FCADC7741B6F1504B53A7D6A2162F2ABB5
                                              File Content Preview:.ELF..............>.............@.......`...........@.8...@.............@.......@.......@.......................................8.......8.......8................................................................................. .............8.......8. ....

                                              ELF header

                                              Class:ELF64
                                              Data:2's complement, little endian
                                              Version:1 (current)
                                              Machine:Advanced Micro Devices X86-64
                                              Version Number:0x1
                                              Type:DYN (Shared object file)
                                              OS/ABI:UNIX - System V
                                              ABI Version:0
                                              Entry Point Address:0x1f10
                                              Flags:0x0
                                              ELF Header Size:64
                                              Program Header Offset:64
                                              Program Header Size:56
                                              Number of Program Headers:9
                                              Section Header Offset:52064
                                              Section Header Size:64
                                              Number of Section Headers:29
                                              Header String Table Index:28
                                              NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                              NULL0x00x00x00x00x0000
                                              .interpPROGBITS0x2380x2380x1c0x00x2A001
                                              .note.ABI-tagNOTE0x2540x2540x200x00x2A004
                                              .note.gnu.build-idNOTE0x2740x2740x240x00x2A004
                                              .gnu.hashGNU_HASH0x2980x2980x480x00x2A508
                                              .dynsymDYNSYM0x2e00x2e00x8400x180x2A618
                                              .dynstrSTRTAB0xb200xb200x3d80x00x2A001
                                              .gnu.versionVERSYM0xef80xef80xb00x20x2A502
                                              .gnu.version_rVERNEED0xfa80xfa80x600x00x2A628
                                              .rela.dynRELA0x10080x10080x1080x180x2A508
                                              .rela.pltRELA0x11100x11100x6d80x180x42AI5228
                                              .initPROGBITS0x17e80x17e80x170x00x6AX004
                                              .pltPROGBITS0x18000x18000x4a00x100x6AX0016
                                              .plt.gotPROGBITS0x1ca00x1ca00x80x80x6AX008
                                              .textPROGBITS0x1cb00x1cb00x64c20x00x6AX0016
                                              .finiPROGBITS0x81740x81740x90x00x6AX004
                                              .rodataPROGBITS0x81800x81800x21180x00x2A0016
                                              .eh_frame_hdrPROGBITS0xa2980xa2980x1240x00x2A004
                                              .eh_framePROGBITS0xa3c00xa3c00x5e00x00x2A008
                                              .init_arrayINIT_ARRAY0x20ab380xab380x80x80x3WA008
                                              .fini_arrayFINI_ARRAY0x20ab400xab400x80x80x3WA008
                                              .dynamicDYNAMIC0x20ab480xab480x2300x100x3WA608
                                              .gotPROGBITS0x20ad780xad780x2880x80x3WA008
                                              .dataPROGBITS0x20b0000xb0000x140x00x3WA008
                                              .bssNOBITS0x20b0200xb0140x400x00x3WA0032
                                              .commentPROGBITS0x00xb0140x2b0x10x30MS001
                                              .symtabSYMTAB0x00xb0400x10680x180x027518
                                              .strtabSTRTAB0x00xc0a80x9b40x00x0001
                                              .shstrtabSTRTAB0x00xca5c0xfe0x00x0001
                                              TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                              PHDR0x400x400x400x1f80x1f81.74550x4R 0x8
                                              INTERP0x2380x2380x2380x1c0x1c3.94080x4R 0x1/lib64/ld-linux-x86-64.so.2.interp
                                              LOAD0x00x00x00xa9a00xa9a05.84740x5R E0x200000.interp .note.ABI-tag .note.gnu.build-id .gnu.hash .dynsym .dynstr .gnu.version .gnu.version_r .rela.dyn .rela.plt .init .plt .plt.got .text .fini .rodata .eh_frame_hdr .eh_frame
                                              LOAD0xab380x20ab380x20ab380x4dc0x5281.85810x6RW 0x200000.init_array .fini_array .dynamic .got .data .bss
                                              DYNAMIC0xab480x20ab480x20ab480x2300x2301.56040x6RW 0x8.dynamic
                                              NOTE0x2540x2540x2540x440x443.39670x4R 0x4.note.ABI-tag .note.gnu.build-id
                                              GNU_EH_FRAME0xa2980xa2980xa2980x1240x1244.29030x4R 0x4.eh_frame_hdr
                                              GNU_STACK0x00x00x00x00x00.00000x6RW 0x10
                                              GNU_RELRO0xab380x20ab380x20ab380x4c80x4c81.84200x4R 0x1.init_array .fini_array .dynamic .got
                                              TypeMetaValueTag
                                              DT_NEEDEDsharedliblibgobject-2.0.so.00x1
                                              DT_NEEDEDsharedliblibglib-2.0.so.00x1
                                              DT_NEEDEDsharedliblibgstreamer-1.0.so.00x1
                                              DT_NEEDEDsharedliblibpthread.so.00x1
                                              DT_NEEDEDsharedliblibc.so.60x1
                                              DT_INITvalue0x17e80xc
                                              DT_FINIvalue0x81740xd
                                              DT_INIT_ARRAYvalue0x20ab380x19
                                              DT_INIT_ARRAYSZbytes80x1b
                                              DT_FINI_ARRAYvalue0x20ab400x1a
                                              DT_FINI_ARRAYSZbytes80x1c
                                              DT_GNU_HASHvalue0x2980x6ffffef5
                                              DT_STRTABvalue0xb200x5
                                              DT_SYMTABvalue0x2e00x6
                                              DT_STRSZbytes9840xa
                                              DT_SYMENTbytes240xb
                                              DT_DEBUGvalue0x00x15
                                              DT_PLTGOTvalue0x20ad780x3
                                              DT_PLTRELSZbytes17520x2
                                              DT_PLTRELpltrelDT_RELA0x14
                                              DT_JMPRELvalue0x11100x17
                                              DT_RELAvalue0x10080x7
                                              DT_RELASZbytes2640x8
                                              DT_RELAENTbytes240x9
                                              DT_FLAGSvalue0x80x1e
                                              DT_FLAGS_1value0x80000010x6ffffffb
                                              DT_VERNEEDvalue0xfa80x6ffffffe
                                              DT_VERNEEDNUMvalue20x6fffffff
                                              DT_VERSYMvalue0xef80x6ffffff0
                                              DT_RELACOUNTvalue30x6ffffff9
                                              DT_NULLvalue0x00x0
                                              NameVersion Info NameVersion Info File NameSection NameValueSizeSymbol TypeSymbol BindSymbol VisibilityNdx
                                              .dynsym0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                              _ITM_deregisterTMCloneTable.dynsym0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                              _ITM_registerTMCloneTable.dynsym0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                              __bss_start.dynsym0x20b0140NOTYPE<unknown>DEFAULT24
                                              __cxa_finalizeGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              __errno_locationGLIBC_2.2.5libpthread.so.0.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              __gmon_start__.dynsym0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                              __libc_start_mainGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              __printf_chkGLIBC_2.3.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              __recv_chkGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              __snprintf_chkGLIBC_2.3.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              __stack_chk_failGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              __strncat_chkGLIBC_2.3.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              __syslog_chkGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              __xstatGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              _edata.dynsym0x20b0140NOTYPE<unknown>DEFAULT23
                                              _end.dynsym0x20b0600NOTYPE<unknown>DEFAULT24
                                              _fini.dynsym0x81740FUNC<unknown>DEFAULT15
                                              _init.dynsym0x17e80FUNC<unknown>DEFAULT11
                                              acceptGLIBC_2.2.5libpthread.so.0.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              bindGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              chdirGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              clockGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              error.dynsym0x223057FUNC<unknown>DEFAULT14
                                              execvGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              exitGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              fcloseGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              fgetcGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              fgetsGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              fopenGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              forkGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              fputcGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              freadGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              freeGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              freopenGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              fseekGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              ftellGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              fwriteGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              g_error_free.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              g_free.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              g_main_loop_new.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              g_main_loop_quit.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              g_main_loop_run.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              g_main_loop_unref.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              g_print.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              g_printerr.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              g_signal_connect_data.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              getenvGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              gst_bus_add_signal_watch.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              gst_element_get_bus.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              gst_element_set_state.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              gst_init.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              gst_message_parse_buffering.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              gst_message_parse_error.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              gst_object_unref.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              gst_parse_launch.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              listenGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              localtimeGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              mallocGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              memsetGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              openGLIBC_2.2.5libpthread.so.0.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              pcloseGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              perrorGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              popenGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              pthread_createGLIBC_2.2.5libpthread.so.0.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              pthread_exitGLIBC_2.2.5libpthread.so.0.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              pthread_joinGLIBC_2.2.5libpthread.so.0.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              putsGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              readGLIBC_2.2.5libpthread.so.0.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              recvGLIBC_2.2.5libpthread.so.0.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              rewindGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              sendGLIBC_2.2.5libpthread.so.0.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              setbufGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              setsockoptGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              shutdownGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              socketGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              stderrGLIBC_2.2.5libc.so.6.dynsym0x20b0408OBJECT<unknown>DEFAULT24
                                              stdinGLIBC_2.2.5libc.so.6.dynsym0x20b0208OBJECT<unknown>DEFAULT24
                                              stdoutGLIBC_2.2.5libc.so.6.dynsym0x20b0488OBJECT<unknown>DEFAULT24
                                              strcatGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              strerrorGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              strftimeGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              strlenGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              strncpyGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              strstrGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              systemGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              timeGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              umaskGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              .symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                              .symtab0x2380SECTION<unknown>DEFAULT1
                                              GLIBC_2.2.5libc.so.6.symtab0x2540SECTION<unknown>DEFAULT2
                                              .symtab0x2740SECTION<unknown>DEFAULT3
                                              GLIBC_2.2.5libc.so.6.symtab0x2980SECTION<unknown>DEFAULT4
                                              GLIBC_2.2.5libc.so.6.symtab0x2e00SECTION<unknown>DEFAULT5
                                              GLIBC_2.2.5libc.so.6.symtab0xb200SECTION<unknown>DEFAULT6
                                              GLIBC_2.2.5libc.so.6.symtab0xef80SECTION<unknown>DEFAULT7
                                              .symtab0xfa80SECTION<unknown>DEFAULT8
                                              .symtab0x10080SECTION<unknown>DEFAULT9
                                              .symtab0x11100SECTION<unknown>DEFAULT10
                                              .symtab0x17e80SECTION<unknown>DEFAULT11
                                              GLIBC_2.2.5libc.so.6.symtab0x18000SECTION<unknown>DEFAULT12
                                              GLIBC_2.2.5libc.so.6.symtab0x1ca00SECTION<unknown>DEFAULT13
                                              GLIBC_2.2.5libc.so.6.symtab0x1cb00SECTION<unknown>DEFAULT14
                                              GLIBC_2.3.4libc.so.6.symtab0x81740SECTION<unknown>DEFAULT15
                                              .symtab0x81800SECTION<unknown>DEFAULT16
                                              GLIBC_2.2.5libpthread.so.0.symtab0xa2980SECTION<unknown>DEFAULT17
                                              .symtab0xa3c00SECTION<unknown>DEFAULT18
                                              GLIBC_2.2.5libc.so.6.symtab0x20ab380SECTION<unknown>DEFAULT19
                                              GLIBC_2.2.5libc.so.6.symtab0x20ab400SECTION<unknown>DEFAULT20
                                              GLIBC_2.2.5libc.so.6.symtab0x20ab480SECTION<unknown>DEFAULT21
                                              GLIBC_2.2.5libpthread.so.0.symtab0x20ad780SECTION<unknown>DEFAULT22
                                              GLIBC_2.2.5libc.so.6.symtab0x20b0000SECTION<unknown>DEFAULT23
                                              GLIBC_2.2.5libc.so.6.symtab0x20b0200SECTION<unknown>DEFAULT24
                                              GLIBC_2.2.5libc.so.6.symtab0x00SECTION<unknown>DEFAULT25
                                              .symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              Lshift_used.symtab0x3e501466FUNC<unknown>DEFAULT14
                                              Lshift_used_sustainedGLIBC_2.2.5libc.so.6.symtab0x24d01763FUNC<unknown>DEFAULT14
                                              Rshift_used.symtab0x38a01441FUNC<unknown>DEFAULT14
                                              Rshift_used_sustained.symtab0x44101763FUNC<unknown>DEFAULT14
                                              _DYNAMICGLIBC_2.2.5libc.so.6.symtab0x20ab480OBJECT<unknown>DEFAULT21
                                              _GLOBAL_OFFSET_TABLE_GLIBC_2.2.5libc.so.6.symtab0x20ad780OBJECT<unknown>DEFAULT22
                                              _IO_stdin_used.symtab0x81804OBJECT<unknown>DEFAULT16
                                              _ITM_deregisterTMCloneTable.symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                              _ITM_registerTMCloneTable.symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                              __FRAME_END__GLIBC_2.2.5libpthread.so.0.symtab0xa99c0OBJECT<unknown>DEFAULT18
                                              __GNU_EH_FRAME_HDRGLIBC_2.4libc.so.6.symtab0xa2980NOTYPE<unknown>DEFAULT17
                                              __TMC_END__.symtab0x20b0180OBJECT<unknown>HIDDEN23
                                              __bss_start.symtab0x20b0140NOTYPE<unknown>DEFAULT24
                                              __cxa_finalize@@GLIBC_2.2.5.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              __data_start.symtab0x20b0000NOTYPE<unknown>DEFAULT23
                                              __do_global_dtors_auxGLIBC_2.2.5libc.so.6.symtab0x1fd00FUNC<unknown>DEFAULT14
                                              __do_global_dtors_aux_fini_array_entryGLIBC_2.4libc.so.6.symtab0x20ab400OBJECT<unknown>DEFAULT20
                                              __dso_handle.symtab0x20b0080OBJECT<unknown>HIDDEN23
                                              __errno_location@@GLIBC_2.2.5.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              __frame_dummy_init_array_entryGLIBC_2.2.5libc.so.6.symtab0x20ab380OBJECT<unknown>DEFAULT19
                                              __gmon_start__GLIBC_2.3.4libc.so.6.symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                              __init_array_endGLIBC_2.2.5libc.so.6.symtab0x20ab400NOTYPE<unknown>DEFAULT19
                                              __init_array_startGLIBC_2.2.5libc.so.6.symtab0x20ab380NOTYPE<unknown>DEFAULT19
                                              __libc_csu_fini.symtab0x81702FUNC<unknown>DEFAULT14
                                              __libc_csu_init.symtab0x8100101FUNC<unknown>DEFAULT14
                                              __libc_start_main@@GLIBC_2.2.5.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              __printf_chk@@GLIBC_2.3.4GLIBC_2.2.5libc.so.6.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              __recv_chk@@GLIBC_2.4.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              __snprintf_chk@@GLIBC_2.3.4.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              __stack_chk_fail@@GLIBC_2.4.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              __strncat_chk@@GLIBC_2.3.4.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              __syslog_chk@@GLIBC_2.4.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              __xstat@@GLIBC_2.2.5.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              _edata.symtab0x20b0140NOTYPE<unknown>DEFAULT23
                                              _end.symtab0x20b0600NOTYPE<unknown>DEFAULT24
                                              _finiGLIBC_2.2.5libc.so.6.symtab0x81740FUNC<unknown>DEFAULT15
                                              _init.symtab0x17e80FUNC<unknown>DEFAULT11
                                              _startGLIBC_2.2.5libc.so.6.symtab0x1f1043FUNC<unknown>DEFAULT14
                                              accept@@GLIBC_2.2.5.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              bind@@GLIBC_2.2.5.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              cb_messageGLIBC_2.2.5libc.so.6.symtab0x5950289FUNC<unknown>DEFAULT14
                                              chdir@@GLIBC_2.2.5.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              clean_buffer.symtab0x80a024FUNC<unknown>DEFAULT14
                                              clock@@GLIBC_2.2.5.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              completed.7697GLIBC_2.2.5libc.so.6.symtab0x20b0501OBJECT<unknown>DEFAULT24
                                              crtstuff.cGLIBC_2.2.5libc.so.6.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              crtstuff.cGLIBC_2.2.5libc.so.6.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              csock.symtab0x20b0544OBJECT<unknown>DEFAULT24
                                              daemonize.symtab0x7f20381FUNC<unknown>DEFAULT14
                                              data_start.symtab0x20b0000NOTYPE<unknown>DEFAULT23
                                              debian_error.symtab0x202057FUNC<unknown>DEFAULT14
                                              debian_get_kb_device_filename.symtab0x2060358FUNC<unknown>DEFAULT14
                                              debian_keylogger_init.symtab0x22002FUNC<unknown>DEFAULT14
                                              debian_keylogger_utils.cGLIBC_2.2.5libc.so.6.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              deregister_tm_clones.symtab0x1f400FUNC<unknown>DEFAULT14
                                              dispatch_modulesGLIBC_2.2.5libc.so.6.symtab0x6db04450FUNC<unknown>DEFAULT14
                                              error.symtab0x223057FUNC<unknown>DEFAULT14
                                              exec_get_proces_cmdGLIBC_2.2.5libc.so.6.symtab0x4b00613FUNC<unknown>DEFAULT14
                                              execute_cmdGLIBC_2.2.5libc.so.6.symtab0x5ea0444FUNC<unknown>DEFAULT14
                                              execute_record_cmd.symtab0x60601635FUNC<unknown>DEFAULT14
                                              execv@@GLIBC_2.2.5GLIBC_2.4libc.so.6.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              exit@@GLIBC_2.2.5GLIBC_2.2.5libc.so.6.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              fclose@@GLIBC_2.2.5.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              fedora_keylogger_init.symtab0x22202FUNC<unknown>DEFAULT14
                                              fgetc@@GLIBC_2.2.5.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              fgets@@GLIBC_2.2.5.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              fopen@@GLIBC_2.2.5.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              fork@@GLIBC_2.2.5.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              fputc@@GLIBC_2.2.5.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              frame_dummyGLIBC_2.2.5libc.so.6.symtab0x20100FUNC<unknown>DEFAULT14
                                              fread@@GLIBC_2.2.5.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              free@@GLIBC_2.2.5.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              freopen@@GLIBC_2.2.5.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              fseek@@GLIBC_2.2.5GLIBC_2.2.5libc.so.6.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              ftell@@GLIBC_2.2.5.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              fwrite@@GLIBC_2.2.5.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              g_error_free.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              g_freeGLIBC_2.2.5libpthread.so.0.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              g_main_loop_new.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              g_main_loop_quitGLIBC_2.2.5libc.so.6.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              g_main_loop_run.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              g_main_loop_unref.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              g_print.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              g_printerrGLIBC_2.3.4libc.so.6.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              g_signal_connect_data.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              get_kb_device_filename.symtab0x2270598FUNC<unknown>DEFAULT14
                                              getenv@@GLIBC_2.2.5.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              gst_bus_add_signal_watchGLIBC_2.2.5libpthread.so.0.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              gst_element_get_bus.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              gst_element_set_state.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              gst_init.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              gst_message_parse_buffering.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              gst_message_parse_error.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              gst_object_unrefGLIBC_2.2.5libc.so.6.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              gst_parse_launchGLIBC_2.2.5libc.so.6.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              kali_keylogger_init.symtab0x22102FUNC<unknown>DEFAULT14
                                              keylogger.symtab0x2bc03295FUNC<unknown>DEFAULT14
                                              keylogger.cGLIBC_2.2.5libpthread.so.0.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              keylogger_utils.cGLIBC_2.2.5libc.so.6.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              listen@@GLIBC_2.2.5.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              localtime@@GLIBC_2.2.5.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              log_keys.cGLIBC_2.2.5libc.so.6.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              main.symtab0x1cb0598FUNC<unknown>DEFAULT14
                                              malloc@@GLIBC_2.2.5GLIBC_2.2.5libc.so.6.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              memset@@GLIBC_2.2.5GLIBC_2.2.5libpthread.so.0.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              mint_keylogger_init.symtab0x21f02FUNC<unknown>DEFAULT14
                                              on_videoGLIBC_2.2.5libc.so.6.symtab0x20b0104OBJECT<unknown>DEFAULT23
                                              open@@GLIBC_2.2.5.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              pclose@@GLIBC_2.2.5.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              perror@@GLIBC_2.2.5.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              popen@@GLIBC_2.2.5.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              pthread_create@@GLIBC_2.2.5.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              pthread_exit@@GLIBC_2.2.5.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              pthread_join@@GLIBC_2.2.5.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              puts@@GLIBC_2.2.5.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              read@@GLIBC_2.2.5GLIBC_2.2.5libpthread.so.0.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              recv@@GLIBC_2.2.5GLIBC_2.2.5libc.so.6.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              recv_upload.symtab0x66d01751FUNC<unknown>DEFAULT14
                                              register_tm_clonesGLIBC_2.2.5libpthread.so.0.symtab0x1f800FUNC<unknown>DEFAULT14
                                              rewind@@GLIBC_2.2.5.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              send@@GLIBC_2.2.5.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              send_dowloaded_binarie.symtab0x5070739FUNC<unknown>DEFAULT14
                                              send_dowloaded_file.symtab0x5620813FUNC<unknown>DEFAULT14
                                              send_hosts_file.symtab0x5360702FUNC<unknown>DEFAULT14
                                              send_logger_log.symtab0x4d70768FUNC<unknown>DEFAULT14
                                              setbuf@@GLIBC_2.2.5.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              setsockopt@@GLIBC_2.2.5.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              shutdown@@GLIBC_2.2.5.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              sockGLIBC_2.2.5libc.so.6.symtab0x20b0584OBJECT<unknown>DEFAULT24
                                              socket@@GLIBC_2.2.5.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              srv_main.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              start_remote_shellGLIBC_2.2.5libc.so.6.symtab0x5a801055FUNC<unknown>DEFAULT14
                                              stderr@@GLIBC_2.2.5.symtab0x20b0408OBJECT<unknown>DEFAULT24
                                              stdin@@GLIBC_2.2.5.symtab0x20b0208OBJECT<unknown>DEFAULT24
                                              stdout@@GLIBC_2.2.5.symtab0x20b0488OBJECT<unknown>DEFAULT24
                                              strcat@@GLIBC_2.2.5.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              strerror@@GLIBC_2.2.5.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              strftime@@GLIBC_2.2.5.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              strlen@@GLIBC_2.2.5.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              strncpy@@GLIBC_2.2.5.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              strstr@@GLIBC_2.2.5.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              system@@GLIBC_2.2.5.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              time@@GLIBC_2.2.5.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              ubuntu16_keylogger_init.symtab0x21d012FUNC<unknown>DEFAULT14
                                              ubuntu18_keylogger_init.symtab0x21e012FUNC<unknown>DEFAULT14
                                              umask@@GLIBC_2.2.5.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                              utils.cGLIBC_2.2.5libc.so.6.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              wait_time_end.symtab0x80c056FUNC<unknown>DEFAULT14
                                              TimestampSource PortDest PortSource IPDest IP
                                              Jan 2, 2025 15:58:48.630688906 CET43928443192.168.2.2391.189.91.42
                                              Jan 2, 2025 15:58:54.261909008 CET42836443192.168.2.2391.189.91.43
                                              Jan 2, 2025 15:58:55.797689915 CET4251680192.168.2.23109.202.202.202
                                              Jan 2, 2025 15:59:09.619807959 CET43928443192.168.2.2391.189.91.42
                                              Jan 2, 2025 15:59:19.858375072 CET42836443192.168.2.2391.189.91.43
                                              Jan 2, 2025 15:59:26.001493931 CET4251680192.168.2.23109.202.202.202
                                              Jan 2, 2025 15:59:50.574203014 CET43928443192.168.2.2391.189.91.42
                                              Jan 2, 2025 16:00:11.051348925 CET42836443192.168.2.2391.189.91.43

                                              System Behavior

                                              Start time (UTC):14:58:45
                                              Start date (UTC):02/01/2025
                                              Path:/tmp/file-grey.elf
                                              Arguments:/tmp/file-grey.elf
                                              File size:53920 bytes
                                              MD5 hash:9df07b64a28b61e4c7a9f8c8e8d2a801

                                              Start time (UTC):14:58:45
                                              Start date (UTC):02/01/2025
                                              Path:/tmp/file-grey.elf
                                              Arguments:-
                                              File size:53920 bytes
                                              MD5 hash:9df07b64a28b61e4c7a9f8c8e8d2a801

                                              Start time (UTC):14:58:45
                                              Start date (UTC):02/01/2025
                                              Path:/bin/sh
                                              Arguments:sh -c "chmod +x script/hodin_daemon.sh"
                                              File size:129816 bytes
                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                              Start time (UTC):14:58:45
                                              Start date (UTC):02/01/2025
                                              Path:/bin/sh
                                              Arguments:-
                                              File size:129816 bytes
                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                              Start time (UTC):14:58:45
                                              Start date (UTC):02/01/2025
                                              Path:/usr/bin/chmod
                                              Arguments:chmod +x script/hodin_daemon.sh
                                              File size:63864 bytes
                                              MD5 hash:739483b900c045ae1374d6f53a86a279

                                              Start time (UTC):14:58:45
                                              Start date (UTC):02/01/2025
                                              Path:/tmp/file-grey.elf
                                              Arguments:-
                                              File size:53920 bytes
                                              MD5 hash:9df07b64a28b61e4c7a9f8c8e8d2a801

                                              Start time (UTC):14:58:45
                                              Start date (UTC):02/01/2025
                                              Path:/bin/sh
                                              Arguments:sh -c "chmod +x script/delete_startup.sh"
                                              File size:129816 bytes
                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                              Start time (UTC):14:58:45
                                              Start date (UTC):02/01/2025
                                              Path:/bin/sh
                                              Arguments:-
                                              File size:129816 bytes
                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                              Start time (UTC):14:58:45
                                              Start date (UTC):02/01/2025
                                              Path:/usr/bin/chmod
                                              Arguments:chmod +x script/delete_startup.sh
                                              File size:63864 bytes
                                              MD5 hash:739483b900c045ae1374d6f53a86a279

                                              Start time (UTC):14:58:45
                                              Start date (UTC):02/01/2025
                                              Path:/tmp/file-grey.elf
                                              Arguments:-
                                              File size:53920 bytes
                                              MD5 hash:9df07b64a28b61e4c7a9f8c8e8d2a801

                                              Start time (UTC):14:58:45
                                              Start date (UTC):02/01/2025
                                              Path:/bin/sh
                                              Arguments:sh -c "chmod +x script/startup.sh"
                                              File size:129816 bytes
                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                              Start time (UTC):14:58:45
                                              Start date (UTC):02/01/2025
                                              Path:/bin/sh
                                              Arguments:-
                                              File size:129816 bytes
                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                              Start time (UTC):14:58:45
                                              Start date (UTC):02/01/2025
                                              Path:/usr/bin/chmod
                                              Arguments:chmod +x script/startup.sh
                                              File size:63864 bytes
                                              MD5 hash:739483b900c045ae1374d6f53a86a279

                                              Start time (UTC):14:58:46
                                              Start date (UTC):02/01/2025
                                              Path:/tmp/file-grey.elf
                                              Arguments:-
                                              File size:53920 bytes
                                              MD5 hash:9df07b64a28b61e4c7a9f8c8e8d2a801

                                              Start time (UTC):14:58:46
                                              Start date (UTC):02/01/2025
                                              Path:/bin/sh
                                              Arguments:sh -c "cp script/hodin_daemon.sh /etc/init.d/"
                                              File size:129816 bytes
                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                              Start time (UTC):14:58:46
                                              Start date (UTC):02/01/2025
                                              Path:/bin/sh
                                              Arguments:-
                                              File size:129816 bytes
                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                              Start time (UTC):14:58:46
                                              Start date (UTC):02/01/2025
                                              Path:/usr/bin/cp
                                              Arguments:cp script/hodin_daemon.sh /etc/init.d/
                                              File size:153976 bytes
                                              MD5 hash:40f10ae7ea3e44218d1a8c306f79c83f

                                              Start time (UTC):14:58:46
                                              Start date (UTC):02/01/2025
                                              Path:/tmp/file-grey.elf
                                              Arguments:-
                                              File size:53920 bytes
                                              MD5 hash:9df07b64a28b61e4c7a9f8c8e8d2a801

                                              Start time (UTC):14:58:46
                                              Start date (UTC):02/01/2025
                                              Path:/bin/sh
                                              Arguments:sh -c "cp srv_hodin /usr/bin/"
                                              File size:129816 bytes
                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                              Start time (UTC):14:58:46
                                              Start date (UTC):02/01/2025
                                              Path:/bin/sh
                                              Arguments:-
                                              File size:129816 bytes
                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                              Start time (UTC):14:58:46
                                              Start date (UTC):02/01/2025
                                              Path:/usr/bin/cp
                                              Arguments:cp srv_hodin /usr/bin/
                                              File size:153976 bytes
                                              MD5 hash:40f10ae7ea3e44218d1a8c306f79c83f

                                              Start time (UTC):14:58:46
                                              Start date (UTC):02/01/2025
                                              Path:/tmp/file-grey.elf
                                              Arguments:-
                                              File size:53920 bytes
                                              MD5 hash:9df07b64a28b61e4c7a9f8c8e8d2a801

                                              Start time (UTC):14:58:46
                                              Start date (UTC):02/01/2025
                                              Path:/bin/sh
                                              Arguments:sh -c "cp srv_hodin /usr/sbin/"
                                              File size:129816 bytes
                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                              Start time (UTC):14:58:46
                                              Start date (UTC):02/01/2025
                                              Path:/bin/sh
                                              Arguments:-
                                              File size:129816 bytes
                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                              Start time (UTC):14:58:46
                                              Start date (UTC):02/01/2025
                                              Path:/usr/bin/cp
                                              Arguments:cp srv_hodin /usr/sbin/
                                              File size:153976 bytes
                                              MD5 hash:40f10ae7ea3e44218d1a8c306f79c83f

                                              Start time (UTC):14:58:46
                                              Start date (UTC):02/01/2025
                                              Path:/tmp/file-grey.elf
                                              Arguments:-
                                              File size:53920 bytes
                                              MD5 hash:9df07b64a28b61e4c7a9f8c8e8d2a801

                                              Start time (UTC):14:58:46
                                              Start date (UTC):02/01/2025
                                              Path:/bin/sh
                                              Arguments:sh -c "ln -s /etc/init.d/hodin_daemon.sh /etc/rc2.d/S88hodin_daemon.sh"
                                              File size:129816 bytes
                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                              Start time (UTC):14:58:46
                                              Start date (UTC):02/01/2025
                                              Path:/bin/sh
                                              Arguments:-
                                              File size:129816 bytes
                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                              Start time (UTC):14:58:46
                                              Start date (UTC):02/01/2025
                                              Path:/usr/bin/ln
                                              Arguments:ln -s /etc/init.d/hodin_daemon.sh /etc/rc2.d/S88hodin_daemon.sh
                                              File size:76160 bytes
                                              MD5 hash:e933cf05571f62c0157d4e2dfcaea282

                                              Start time (UTC):14:58:46
                                              Start date (UTC):02/01/2025
                                              Path:/tmp/file-grey.elf
                                              Arguments:-
                                              File size:53920 bytes
                                              MD5 hash:9df07b64a28b61e4c7a9f8c8e8d2a801

                                              Start time (UTC):14:58:46
                                              Start date (UTC):02/01/2025
                                              Path:/usr/lib/x86_64-linux-gnu/gstreamer1.0/gstreamer-1.0/gst-plugin-scanner
                                              Arguments:/usr/lib/x86_64-linux-gnu/gstreamer1.0/gstreamer-1.0/gst-plugin-scanner -l /tmp/file-grey.elf
                                              File size:14488 bytes
                                              MD5 hash:caaae748bd9798d2f4b3d09c94a9e5f4