Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
mippywippy.elf

Overview

General Information

Sample name:mippywippy.elf
Analysis ID:1586279
MD5:a05e765ec261f9aa07dc177255fc13e9
SHA1:ed9f97d1936e214e246310aeedb2d50c76c61f06
SHA256:573e1358379d0a6dede3bd87711abb5928aedeb493e4a2c401ceaf813973f5e1
Tags:elfuser-abuse_ch
Infos:

Detection

Gafgyt, Mirai
Score:80
Range:0 - 100
Whitelisted:false

Signatures

Antivirus / Scanner detection for submitted sample
Malicious sample detected (through community Yara rule)
Yara detected Gafgyt
Yara detected Mirai
Contains symbols with names commonly found in malware
Opens /proc/net/* files useful for finding connected devices and routers
Creates hidden files and/or directories
Detected TCP or UDP traffic on non-standard ports
Enumerates processes within the "proc" file system
Found strings indicative of a multi-platform dropper
Sample contains strings indicative of BusyBox which embeds multiple Unix commands in a single executable
Sample tries to kill a process (SIGKILL)
Suricata IDS alerts with low severity for network traffic
Uses the "uname" system call to query kernel version information (possible evasion)
Yara signature match

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1586279
Start date and time:2025-01-08 23:57:13 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 5m 6s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:mippywippy.elf
Detection:MAL
Classification:mal80.spre.troj.linELF@0/0@2/0
  • VT rate limit hit for: mippywippy.elf
Command:/tmp/mippywippy.elf
PID:5522
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
gosh that chinese family at the other table sure ate alot
Standard Error:
  • system is lnxubuntu20
  • sh (PID: 5526, Parent: 1498, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-rfkill
  • gsd-rfkill (PID: 5526, Parent: 1498, MD5: 88a16a3c0aba1759358c06215ecfb5cc) Arguments: /usr/libexec/gsd-rfkill
  • gdm3 New Fork (PID: 5531, Parent: 1333)
  • Default (PID: 5531, Parent: 1333, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /etc/gdm3/PrimeOff/Default
  • gdm3 New Fork (PID: 5551, Parent: 1333)
  • Default (PID: 5551, Parent: 1333, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /etc/gdm3/PrimeOff/Default
  • systemd New Fork (PID: 5575, Parent: 1)
  • systemd-user-runtime-dir (PID: 5575, Parent: 1, MD5: d55f4b0847f88131dbcfb07435178e54) Arguments: /lib/systemd/systemd-user-runtime-dir stop 127
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
Bashlite, GafgytBashlite is a malware family which infects Linux systems in order to launch distributed denial-of-service attacks (DDoS). Originally it was also known under the name Bashdoor, but this term now refers to the exploit method used by the malware. It has been used to launch attacks of up to 400 Gbps.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.bashlite
NameDescriptionAttributionBlogpost URLsLink
MiraiMirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.mirai
SourceRuleDescriptionAuthorStrings
mippywippy.elfJoeSecurity_GafgytYara detected GafgytJoe Security
    mippywippy.elfJoeSecurity_Mirai_8Yara detected MiraiJoe Security
      mippywippy.elfLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
      • 0x2e44d:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x2e461:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x2e475:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x2e489:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x2e49d:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x2e4b1:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x2e4c5:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x2e4d9:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x2e4ed:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x2e501:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x2e515:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x2e529:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x2e53d:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x2e551:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x2e565:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x2e579:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x2e58d:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x2e5a1:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x2e5b5:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x2e5c9:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x2e5dd:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      mippywippy.elfLinux_Trojan_Gafgyt_ea92cca8unknownunknown
      • 0x2e400:$a: 53 65 6C 66 20 52 65 70 20 46 75 63 6B 69 6E 67 20 4E 65 54 69 53 20 61 6E 64
      • 0x39f9c:$a: 53 65 6C 66 20 52 65 70 20 46 75 63 6B 69 6E 67 20 4E 65 54 69 53 20 61 6E 64
      SourceRuleDescriptionAuthorStrings
      5564.1.00007f1d74400000.00007f1d7443c000.r-x.sdmpJoeSecurity_GafgytYara detected GafgytJoe Security
        5564.1.00007f1d74400000.00007f1d7443c000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
          5564.1.00007f1d74400000.00007f1d7443c000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
          • 0x2e44d:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x2e461:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x2e475:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x2e489:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x2e49d:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x2e4b1:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x2e4c5:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x2e4d9:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x2e4ed:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x2e501:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x2e515:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x2e529:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x2e53d:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x2e551:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x2e565:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x2e579:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x2e58d:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x2e5a1:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x2e5b5:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x2e5c9:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x2e5dd:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          5564.1.00007f1d74400000.00007f1d7443c000.r-x.sdmpLinux_Trojan_Gafgyt_ea92cca8unknownunknown
          • 0x2e400:$a: 53 65 6C 66 20 52 65 70 20 46 75 63 6B 69 6E 67 20 4E 65 54 69 53 20 61 6E 64
          • 0x39f9c:$a: 53 65 6C 66 20 52 65 70 20 46 75 63 6B 69 6E 67 20 4E 65 54 69 53 20 61 6E 64
          5562.1.00007f1d74400000.00007f1d7443c000.r-x.sdmpJoeSecurity_GafgytYara detected GafgytJoe Security
            Click to see the 16 entries
            TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
            2025-01-08T23:58:01.700499+010028484481A Network Trojan was detected192.168.2.1547660154.216.20.706478TCP

            Click to jump to signature section

            Show All Signature Results

            AV Detection

            barindex
            Source: mippywippy.elfAvira: detected

            Spreading

            barindex
            Source: /tmp/mippywippy.elf (PID: 5522)Opens: /proc/net/routeJump to behavior
            Source: mippywippy.elfString: 'shps902i13BzSxLxBxeYHOHO-LUGO7HOHO-U79OLJuYfouyf87NiGGeR69xdSO190Ij1XLOLKIKEEEDDEekjheory98escansh4MDMAfdevalvexscanspcMELTEDNINJAREALZflexsonskidsscanx86MISAKI-U79OLfoAxi102kxeswodjwodjwojMmKiy7f87lfreecookiex86sysgpufrgegesysupdater0DnAzepdNiGGeRD0nks69frgreu0x766f6964NiGGeRd0nks1337gafturasgbsigboa120i3UI49OaF3geaevaiolmao123123aOfurain0n4H34DggTrexewwasads1293194hjXDOthLaLosnggtwget-log1337SoraLOADERSAIAKINAggtq1378bfp919GRB1Q2SAIAKUSOggtr14FaSEXSLAVE1337ggtt1902a3u912u3u4haetrghbr19ju3dSORAojkf120hehahejeje922U2JDJA901F91SlaVLav12helpmedaddthhhhh2wgg9qphbqSlav3Th3seD3viceshzSmYZjYMQ5GbfsoraSoRAxD123LOLiaGv5aA3SoRAxD420LOLinsomni640277SoraBeReppin1337ipcamCache66tlGg9QjUYfouyf876ke3TOKYO3lyEeaXul2dULCVxh93OfjHZ2zTY2gD6MZvKc7KU6rmMkiy6f87lA023UU4U24UIUTheWeekndmioribitchesA5p9TheWeekndsmnblkjpoiAbAdTokyosnebAkiruU8inTznetstatsAlexW9RCAKM20TnewnetwordAyo215WordnloadsBAdAsVWordmanenotyakuzaaBelchWordnetsobpBigN0gg0r420X0102I34fofhasfhiafhoiX19I239124UIUoismDeportedXSHJEHHEIIHWOolsVNwo12DeportedDeportedXkTer0GbA1onry0v03FortniteDownLOLZY0urM0mGaypussyfartlmaojkGrAcEnIgGeRaNnYvdGkqndCOqGeoRBe6BEGuiltyCrownZEuS69s4beBsEQhdHOHO-KSNDOZEuz69sat1234aj93hJ23scanHAalie293z0k2LscanJoshoARMHellInSideayyyGangShitscanJoshoARM5HighFryb1glscanJoshoARM6IWhPyucDbJboatnetzscanJoshoARM7IuYgujeIqnbtbatrtahzexsexscanJoshoM68KJJDUHEWBBBIBscanJoshoMIPSJSDGIEVIVAVIGcKbVkzGOPascanJoshoMPSLccADscanJoshoPPCKAZEN-OIU97chickenxingsscanJoshoSH4yakuskzm8KAZEN-PO78HcleanerscanJoshoSPCKAZEN-U79OLdbeefscanJoshoX86yakuz4c24KETASHI32ddrwelperscanarm5zPnr6HpQj2Kaishi-Iz90Ydeexecscanarm6zdrtfxcgyKatrina32doCP3fVjscanarm7zxcfhuioKsif91je39scanm68kKuasadvrhelperl33t_feetl33tl33tfeetscanmipsKuasaBinsMateeQnOhRk85rscanmpslLOLHHHOHOHBUIeXK20CL12ZnyamezyQBotBladeSPOOKYhikariwasherep4029x91xx32uhj4gbejhwizardzhra.outboatnetdbgcondiheroshimaskid.dbglzrdPownedSecurity69.aresfxlyazsxhyUNSTABLEunstable_is_the_story_of_the_universemoobotjnsd9sdoilayourmomgaeissdfjiougsiojOasisSEGRJIJHFVNHSNHEIHFOSapep999KOWAI-BAdAsVKOWAI-SADjHKipU7Ylairdropmalwareyour_verry_fucking_gayBig-Bro-Brightsefaexecshirololieagle.For-Gai-Mezy0x6axNLcloqkisvspookymythSwergjmioGKILLEJW(IU(JIWERGFJGJWJRGHetrhwewrtheIuFdKssCxzjSDFJIjioOnrYoXd666ewrtkjokethajbdf89wu823AAaasrdgsWsGA4@F6FGhostWuzHere666BOGOMIPSbeastmodedvrHelperbestmodesfc6aJfIuYDemon.xeno-is-godICY-P-0ODIJgSHUIHIfhwrgLhu87VhvQPzlunadakuexecbinTacoBellGodYololigangExecutionorbitclientAmnesiaOwariUnHAnaAWz3hirobbomiorieagledoxxRollielessie.hax.yakuzawordminerminerwordSinixV4hohog0dbu7tuorphicfurasshuhorizonassailantAresKawaiihelperECHOBOTDEMONSkalonJoshodaddyscumakira.akHilixdakuTsunamiestellaSolarrift_-255.NetCayosinOkamiKoshabushidotrojanshiinaReaper.Corona.wrgnuwrijoBOXOFABOXAkaHarioragefibregalilstresserpwstresser.pwcatnetTheCowSaysGoodByedistrubter22269reportbacktelportzyad1234stresser.suTohrujeffspenderbotnetOmnihamlogmirailoversxlk.busyboxxxbusyboxxkawaiiFrostisxj472szHU6FIZTQUPFF1500RGplzjustfuckoffnvitpjelfLoadAmakanotokupdatercum-n-gooblivionVoltages
            Source: global trafficTCP traffic: 192.168.2.15:39584 -> 66.59.198.122:7733
            Source: global trafficTCP traffic: 192.168.2.15:47660 -> 154.216.20.70:6478
            Source: Network trafficSuricata IDS: 2848448 - Severity 1 - ETPRO MALWARE Possible ELF/Various IoT Bot Style Device Checkin (unknown) : 192.168.2.15:47660 -> 154.216.20.70:6478
            Source: unknownTCP traffic detected without corresponding DNS query: 66.59.198.122
            Source: unknownTCP traffic detected without corresponding DNS query: 66.59.198.122
            Source: unknownTCP traffic detected without corresponding DNS query: 66.59.198.122
            Source: unknownTCP traffic detected without corresponding DNS query: 66.59.198.122
            Source: unknownTCP traffic detected without corresponding DNS query: 66.59.198.122
            Source: unknownTCP traffic detected without corresponding DNS query: 66.59.198.122
            Source: unknownTCP traffic detected without corresponding DNS query: 66.59.198.122
            Source: unknownTCP traffic detected without corresponding DNS query: 66.59.198.122
            Source: unknownTCP traffic detected without corresponding DNS query: 66.59.198.122
            Source: unknownTCP traffic detected without corresponding DNS query: 66.59.198.122
            Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.70
            Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.70
            Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.70
            Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.70
            Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
            Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
            Source: global trafficDNS traffic detected: DNS query: daisy.ubuntu.com

            System Summary

            barindex
            Source: mippywippy.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
            Source: mippywippy.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
            Source: 5564.1.00007f1d74400000.00007f1d7443c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
            Source: 5564.1.00007f1d74400000.00007f1d7443c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
            Source: 5522.1.00007f1d74400000.00007f1d7443c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
            Source: 5522.1.00007f1d74400000.00007f1d7443c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
            Source: 5562.1.00007f1d74400000.00007f1d7443c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
            Source: 5562.1.00007f1d74400000.00007f1d7443c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
            Source: Process Memory Space: mippywippy.elf PID: 5522, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
            Source: Process Memory Space: mippywippy.elf PID: 5522, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
            Source: Process Memory Space: mippywippy.elf PID: 5562, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
            Source: Process Memory Space: mippywippy.elf PID: 5562, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
            Source: Process Memory Space: mippywippy.elf PID: 5564, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
            Source: Process Memory Space: mippywippy.elf PID: 5564, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
            Source: ELF static info symbol of initial sampleName: attacks_vector_wabba_jack
            Source: ELF static info symbol of initial sampleName: vseattack
            Source: Initial sampleString containing 'busybox' found: busyboxxx
            Source: Initial sampleString containing 'busybox' found: busyboxx
            Source: Initial sampleString containing 'busybox' found: 'shps902i13BzSxLxBxeYHOHO-LUGO7HOHO-U79OLJuYfouyf87NiGGeR69xdSO190Ij1XLOLKIKEEEDDEekjheory98escansh4MDMAfdevalvexscanspcMELTEDNINJAREALZflexsonskidsscanx86MISAKI-U79OLfoAxi102kxeswodjwodjwojMmKiy7f87lfreecookiex86sysgpufrgegesysupdater0DnAzepdNiGGeRD0nks69frgreu0x766f6964NiGGeRd0nks1337gafturasgbsigboa120i3UI49OaF3geaevaiolmao123123aOfurain0n4H34DggTrexewwasads1293194hjXDOthLaLosnggtwget-log1337SoraLOADERSAIAKINAggtq1378bfp919GRB1Q2SAIAKUSOggtr14FaSEXSLAVE1337ggtt1902a3u912u3u4haetrghbr19ju3dSORAojkf120hehahejeje922U2JDJA901F91SlaVLav12helpmedaddthhhhh2wgg9qphbqSlav3Th3seD3viceshzSmYZjYMQ5GbfsoraSoRAxD123LOLiaGv5aA3SoRAxD420LOLinsomni640277SoraBeReppin1337ipcamCache66tlGg9QjUYfouyf876ke3TOKYO3lyEeaXul2dULCVxh93OfjHZ2zTY2gD6MZvKc7KU6rmMkiy6f87lA023UU4U24UIUTheWeekndmioribitchesA5p9TheWeekndsmnblkjpoiAbAdTokyosnebAkiruU8inTznetstatsAlexW9RCAKM20TnewnetwordAyo215WordnloadsBAdAsVWordmanenotyakuzaaBelchWordnetsobpBigN0gg0r420X0102I34fofhasfhiafhoiX19I239124UIUoismDeportedXSHJEHHEIIHWOolsVNwo12DeportedDeportedXkTer
            Source: /tmp/mippywippy.elf (PID: 5522)SIGKILL sent: pid: 1679, result: successfulJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)SIGKILL sent: pid: 5526, result: successfulJump to behavior
            Source: mippywippy.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
            Source: mippywippy.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
            Source: 5564.1.00007f1d74400000.00007f1d7443c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
            Source: 5564.1.00007f1d74400000.00007f1d7443c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
            Source: 5522.1.00007f1d74400000.00007f1d7443c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
            Source: 5522.1.00007f1d74400000.00007f1d7443c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
            Source: 5562.1.00007f1d74400000.00007f1d7443c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
            Source: 5562.1.00007f1d74400000.00007f1d7443c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
            Source: Process Memory Space: mippywippy.elf PID: 5522, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
            Source: Process Memory Space: mippywippy.elf PID: 5522, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
            Source: Process Memory Space: mippywippy.elf PID: 5562, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
            Source: Process Memory Space: mippywippy.elf PID: 5562, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
            Source: Process Memory Space: mippywippy.elf PID: 5564, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
            Source: Process Memory Space: mippywippy.elf PID: 5564, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
            Source: classification engineClassification label: mal80.spre.troj.linELF@0/0@2/0
            Source: mippywippy.elfELF static info symbol of initial sample: libc/string/mips/memcpy.S
            Source: mippywippy.elfELF static info symbol of initial sample: libc/string/mips/memset.S
            Source: mippywippy.elfELF static info symbol of initial sample: libc/sysdeps/linux/mips/crt1.S
            Source: mippywippy.elfELF static info symbol of initial sample: libc/sysdeps/linux/mips/crti.S
            Source: mippywippy.elfELF static info symbol of initial sample: libc/sysdeps/linux/mips/crtn.S
            Source: mippywippy.elfELF static info symbol of initial sample: libc/sysdeps/linux/mips/pipe.S
            Source: /tmp/mippywippy.elf (PID: 5522)Directory: /tmp/.Jump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)Directory: /tmp/..Jump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)Directory: /tmp/.Jump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)Directory: /tmp/..Jump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/110/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/110/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/231/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/231/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/111/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/111/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/112/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/112/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/233/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/233/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/113/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/113/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/114/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/114/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/235/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/235/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/115/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/115/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/1333/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/1333/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/116/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/116/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/1695/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/117/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/117/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/118/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/118/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/119/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/119/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/911/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/911/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/914/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/914/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/10/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/10/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/917/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/917/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/11/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/11/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/12/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/12/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/13/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/13/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/14/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/14/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/15/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/15/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/16/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/16/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/17/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/17/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/18/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/18/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/19/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/19/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/1591/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/120/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/120/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/121/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/121/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/122/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/122/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/243/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/243/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/2/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/2/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/123/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/123/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/3/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/3/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/124/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/124/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/1588/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/125/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/125/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/4/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/4/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/246/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/246/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/126/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/126/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/5/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/5/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/127/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/127/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/6/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/6/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/1585/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/128/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/128/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/7/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/7/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/129/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/129/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/8/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/8/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/800/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/800/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/3883/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/3883/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/9/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/9/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/802/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/802/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/803/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)File opened: /proc/803/cmdlineJump to behavior
            Source: /tmp/mippywippy.elf (PID: 5522)Queries kernel information via 'uname': Jump to behavior
            Source: mippywippy.elf, 5522.1.0000561ded22b000.0000561ded2d2000.rw-.sdmp, mippywippy.elf, 5562.1.0000561ded22b000.0000561ded2d2000.rw-.sdmp, mippywippy.elf, 5564.1.0000561ded22b000.0000561ded2d2000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/mipsel
            Source: mippywippy.elf, 5522.1.0000561ded22b000.0000561ded2d2000.rw-.sdmp, mippywippy.elf, 5562.1.0000561ded22b000.0000561ded2d2000.rw-.sdmp, mippywippy.elf, 5564.1.0000561ded22b000.0000561ded2d2000.rw-.sdmpBinary or memory string: V!/etc/qemu-binfmt/mipsel
            Source: mippywippy.elf, 5522.1.00007ffec0994000.00007ffec09b5000.rw-.sdmp, mippywippy.elf, 5562.1.00007ffec0994000.00007ffec09b5000.rw-.sdmp, mippywippy.elf, 5564.1.00007ffec0994000.00007ffec09b5000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-mipsel/tmp/mippywippy.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/mippywippy.elf
            Source: mippywippy.elf, 5522.1.00007ffec0994000.00007ffec09b5000.rw-.sdmp, mippywippy.elf, 5562.1.00007ffec0994000.00007ffec09b5000.rw-.sdmp, mippywippy.elf, 5564.1.00007ffec0994000.00007ffec09b5000.rw-.sdmpBinary or memory string: /usr/bin/qemu-mipsel

            Stealing of Sensitive Information

            barindex
            Source: Yara matchFile source: mippywippy.elf, type: SAMPLE
            Source: Yara matchFile source: 5564.1.00007f1d74400000.00007f1d7443c000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5562.1.00007f1d74400000.00007f1d7443c000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5522.1.00007f1d74400000.00007f1d7443c000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: mippywippy.elf, type: SAMPLE
            Source: Yara matchFile source: 5564.1.00007f1d74400000.00007f1d7443c000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5522.1.00007f1d74400000.00007f1d7443c000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5562.1.00007f1d74400000.00007f1d7443c000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: Process Memory Space: mippywippy.elf PID: 5522, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: mippywippy.elf PID: 5562, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: mippywippy.elf PID: 5564, type: MEMORYSTR

            Remote Access Functionality

            barindex
            Source: Yara matchFile source: mippywippy.elf, type: SAMPLE
            Source: Yara matchFile source: 5564.1.00007f1d74400000.00007f1d7443c000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5562.1.00007f1d74400000.00007f1d7443c000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5522.1.00007f1d74400000.00007f1d7443c000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: mippywippy.elf, type: SAMPLE
            Source: Yara matchFile source: 5564.1.00007f1d74400000.00007f1d7443c000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5522.1.00007f1d74400000.00007f1d7443c000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5562.1.00007f1d74400000.00007f1d7443c000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: Process Memory Space: mippywippy.elf PID: 5522, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: mippywippy.elf PID: 5562, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: mippywippy.elf PID: 5564, type: MEMORYSTR
            ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
            Gather Victim Identity Information1
            Scripting
            Valid AccountsWindows Management Instrumentation1
            Scripting
            Path Interception1
            Hidden Files and Directories
            1
            OS Credential Dumping
            11
            Security Software Discovery
            Remote ServicesData from Local System1
            Non-Standard Port
            Exfiltration Over Other Network MediumAbuse Accessibility Features
            CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS Memory1
            Remote System Discovery
            Remote Desktop ProtocolData from Removable Media1
            Non-Application Layer Protocol
            Exfiltration Over BluetoothNetwork Denial of Service
            Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
            Application Layer Protocol
            Automated ExfiltrationData Encrypted for Impact
            No configs have been found
            Hide Legend

            Legend:

            • Process
            • Signature
            • Created File
            • DNS/IP Info
            • Is Dropped
            • Number of created Files
            • Is malicious
            • Internet
            behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1586279 Sample: mippywippy.elf Startdate: 08/01/2025 Architecture: LINUX Score: 80 23 154.216.20.70, 47660, 6478 SKHT-ASShenzhenKatherineHengTechnologyInformationCo Seychelles 2->23 25 66.59.198.122, 39584, 39586, 7733 ATL-CBEYONDUS Reserved 2->25 27 daisy.ubuntu.com 2->27 29 Malicious sample detected (through community Yara rule) 2->29 31 Antivirus / Scanner detection for submitted sample 2->31 33 Yara detected Gafgyt 2->33 35 2 other signatures 2->35 8 mippywippy.elf 2->8         started        11 gnome-session-binary sh gsd-rfkill 2->11         started        13 gdm3 Default 2->13         started        15 2 other processes 2->15 signatures3 process4 signatures5 37 Opens /proc/net/* files useful for finding connected devices and routers 8->37 17 mippywippy.elf 8->17         started        19 mippywippy.elf 8->19         started        process6 process7 21 mippywippy.elf 17->21         started       
            SourceDetectionScannerLabelLink
            mippywippy.elf100%AviraLINUX/Mirai.Gafgyt.
            No Antivirus matches
            No Antivirus matches
            No Antivirus matches
            NameIPActiveMaliciousAntivirus DetectionReputation
            daisy.ubuntu.com
            162.213.35.24
            truefalse
              high
              • No. of IPs < 25%
              • 25% < No. of IPs < 50%
              • 50% < No. of IPs < 75%
              • 75% < No. of IPs
              IPDomainCountryFlagASNASN NameMalicious
              154.216.20.70
              unknownSeychelles
              135357SKHT-ASShenzhenKatherineHengTechnologyInformationCofalse
              66.59.198.122
              unknownReserved
              17184ATL-CBEYONDUSfalse
              No context
              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
              daisy.ubuntu.comboatnet.mpsl.elfGet hashmaliciousMiraiBrowse
              • 162.213.35.24
              boatnet.ppc.elfGet hashmaliciousMiraiBrowse
              • 162.213.35.25
              boatnet.sh4.elfGet hashmaliciousMiraiBrowse
              • 162.213.35.24
              boatnet.arm6.elfGet hashmaliciousMiraiBrowse
              • 162.213.35.24
              boatnet.arm7.elfGet hashmaliciousMiraiBrowse
              • 162.213.35.24
              boatnet.x86.elfGet hashmaliciousMiraiBrowse
              • 162.213.35.24
              fenty.arm6.elfGet hashmaliciousMiraiBrowse
              • 162.213.35.25
              m1.elfGet hashmaliciousUnknownBrowse
              • 162.213.35.24
              gompsl.elfGet hashmaliciousMiraiBrowse
              • 162.213.35.25
              empsl.elfGet hashmaliciousMiraiBrowse
              • 162.213.35.24
              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
              ATL-CBEYONDUSarmv7l.elfGet hashmaliciousUnknownBrowse
              • 173.200.178.217
              botx.arm7.elfGet hashmaliciousMiraiBrowse
              • 72.54.140.80
              xd.mpsl.elfGet hashmaliciousMiraiBrowse
              • 72.16.202.25
              armv5l.elfGet hashmaliciousMiraiBrowse
              • 69.199.235.231
              armv4l.elfGet hashmaliciousMiraiBrowse
              • 69.198.187.233
              nabarm5.elfGet hashmaliciousUnknownBrowse
              • 69.199.34.183
              x86_32.nn.elfGet hashmaliciousMirai, OkiruBrowse
              • 69.199.45.224
              mipsel.nn.elfGet hashmaliciousMirai, OkiruBrowse
              • 50.21.114.195
              la.bot.sh4.elfGet hashmaliciousMiraiBrowse
              • 69.15.59.107
              la.bot.arm5.elfGet hashmaliciousMiraiBrowse
              • 216.192.135.159
              SKHT-ASShenzhenKatherineHengTechnologyInformationCogompsl.elfGet hashmaliciousMiraiBrowse
              • 156.254.70.172
              garm.elfGet hashmaliciousMiraiBrowse
              • 156.241.11.50
              earm5.elfGet hashmaliciousMiraiBrowse
              • 156.254.70.166
              emips.elfGet hashmaliciousMiraiBrowse
              • 156.226.9.162
              LayyB0R.exeGet hashmaliciousRHADAMANTHYSBrowse
              • 154.216.20.162
              aNfqvgu.exeGet hashmaliciousRHADAMANTHYSBrowse
              • 154.216.20.162
              miori.x86.elfGet hashmaliciousUnknownBrowse
              • 45.207.240.67
              Jeffparish.docxGet hashmaliciousUnknownBrowse
              • 154.216.17.193
              wind.m68k.elfGet hashmaliciousMiraiBrowse
              • 154.216.17.34
              wind.sh4.elfGet hashmaliciousMiraiBrowse
              • 154.216.17.34
              No context
              No context
              No created / dropped files found
              File type:ELF 32-bit LSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, not stripped
              Entropy (8bit):5.576692574012536
              TrID:
              • ELF Executable and Linkable format (generic) (4004/1) 100.00%
              File name:mippywippy.elf
              File size:290'917 bytes
              MD5:a05e765ec261f9aa07dc177255fc13e9
              SHA1:ed9f97d1936e214e246310aeedb2d50c76c61f06
              SHA256:573e1358379d0a6dede3bd87711abb5928aedeb493e4a2c401ceaf813973f5e1
              SHA512:98f1127bbe4dd026023e4de66631adecaa1bace659aecbb95823103ed73083a05d244ba668beb7ad6f878edea252db51efb5ed25572b554e8f08c854c6aa09f6
              SSDEEP:3072:PcMmJjecrsAK6YsTn9X6cCWuMhNiJwmIPTBJGXbXi+Nx:PcMm3r26YsT9LDMwmIPTBJGXbXi+Nx
              TLSH:2E5463347E22DA73C45BEEB69AE96942964CE6C70BC4970771F0D01C9BF684E14DBC88
              File Content Preview:.ELF......................@.4...(.......4. ...(........p......@...@...........................@...@...........................G...G......}..........Q.td.................................................QH....<.Q.'!......'.......................<.P.'!... ..

              ELF header

              Class:ELF32
              Data:2's complement, little endian
              Version:1 (current)
              Machine:MIPS R3000
              Version Number:0x1
              Type:EXEC (Executable file)
              OS/ABI:UNIX - System V
              ABI Version:0
              Entry Point Address:0x4002a0
              Flags:0x1007
              ELF Header Size:52
              Program Header Offset:52
              Program Header Size:32
              Number of Program Headers:4
              Section Header Offset:265512
              Section Header Size:40
              Number of Section Headers:21
              Header String Table Index:18
              NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
              NULL0x00x00x00x00x0000
              .reginfoMIPS_REGINFO0x4000b40xb40x180x180x2A004
              .initPROGBITS0x4000cc0xcc0x8c0x00x6AX004
              .textPROGBITS0x4001600x1600x1ecd00x00x6AX0016
              .finiPROGBITS0x41ee300x1ee300x5c0x00x6AX004
              .rodataPROGBITS0x41ee900x1ee900x1ccfc0x00x2A0016
              .eh_framePROGBITS0x43bb8c0x3bb8c0x40x00x2A004
              .ctorsPROGBITS0x47c0000x3c0000x80x00x3WA004
              .dtorsPROGBITS0x47c0080x3c0080x80x00x3WA004
              .jcrPROGBITS0x47c0100x3c0100x40x00x3WA004
              .data.rel.roPROGBITS0x47c0140x3c0140x4d40x00x3WA004
              .dataPROGBITS0x47c4f00x3c4f00xcf00x00x3WA0016
              .gotPROGBITS0x47d1e00x3d1e00x6000x40x10000003WAp0016
              .sbssNOBITS0x47d7e00x3d7e00x300x00x10000003WAp004
              .bssNOBITS0x47d8100x3d7e00x65700x00x3WA0016
              .commentPROGBITS0x00x3d7e00xd4a0x00x0001
              .mdebug.abi32PROGBITS0xd4a0x3e52a0x00x00x0001
              .pdrPROGBITS0x00x3e52c0x27600x00x0004
              .shstrtabSTRTAB0x00x40c8c0x9a0x00x0001
              .symtabSYMTAB0x00x410700x37300x100x0203674
              .strtabSTRTAB0x00x447a00x28c50x00x0001
              TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
              <unknown>0xb40x4000b40x4000b40x180x180.98340x4R 0x4.reginfo
              LOAD0x00x4000000x4000000x3bb900x3bb905.52390x5R E0x10000.reginfo .init .text .fini .rodata .eh_frame
              LOAD0x3c0000x47c0000x47c0000x17e00x7d804.78160x6RW 0x10000.ctors .dtors .jcr .data.rel.ro .data .got .sbss .bss
              GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
              NameVersion Info NameVersion Info File NameSection NameValueSizeSymbol TypeSymbol BindSymbol VisibilityNdx
              .symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
              .symtab0x4000b40SECTION<unknown>DEFAULT1
              .symtab0x4000cc0SECTION<unknown>DEFAULT2
              .symtab0x4001600SECTION<unknown>DEFAULT3
              .symtab0x41ee300SECTION<unknown>DEFAULT4
              .symtab0x41ee900SECTION<unknown>DEFAULT5
              .symtab0x43bb8c0SECTION<unknown>DEFAULT6
              .symtab0x47c0000SECTION<unknown>DEFAULT7
              .symtab0x47c0080SECTION<unknown>DEFAULT8
              .symtab0x47c0100SECTION<unknown>DEFAULT9
              .symtab0x47c0140SECTION<unknown>DEFAULT10
              .symtab0x47c4f00SECTION<unknown>DEFAULT11
              .symtab0x47d1e00SECTION<unknown>DEFAULT12
              .symtab0x47d7e00SECTION<unknown>DEFAULT13
              .symtab0x47d8100SECTION<unknown>DEFAULT14
              .symtab0x00SECTION<unknown>DEFAULT15
              .symtab0xd4a0SECTION<unknown>DEFAULT16
              .symtab0x00SECTION<unknown>DEFAULT17
              .symtab0x00SECTION<unknown>DEFAULT18
              .symtab0x00SECTION<unknown>DEFAULT19
              .symtab0x00SECTION<unknown>DEFAULT20
              C.172.5856.symtab0x47c01448OBJECT<unknown>DEFAULT10
              C.187.5979.symtab0x47c04444OBJECT<unknown>DEFAULT10
              C.192.6027.symtab0x47c07032OBJECT<unknown>DEFAULT10
              C.196.6063.symtab0x47c0908OBJECT<unknown>DEFAULT10
              C.200.6099.symtab0x47c09812OBJECT<unknown>DEFAULT10
              C.204.6136.symtab0x47c0a424OBJECT<unknown>DEFAULT10
              C.208.6170.symtab0x47c0bc1024OBJECT<unknown>DEFAULT10
              C.212.6216.symtab0x47c4bc16OBJECT<unknown>DEFAULT10
              C.217.6264.symtab0x47c4cc12OBJECT<unknown>DEFAULT10
              C.222.6305.symtab0x47c4d816OBJECT<unknown>DEFAULT10
              KHcommSOCK.symtab0x47d8304OBJECT<unknown>DEFAULT14
              KHserverHACKER.symtab0x47cdb44OBJECT<unknown>DEFAULT11
              KillStructure.symtab0x47c5282012OBJECT<unknown>DEFAULT11
              LOCAL_ADDR.symtab0x47d7e04OBJECT<unknown>DEFAULT13
              Q.symtab0x47d84c16384OBJECT<unknown>DEFAULT14
              Randhex.symtab0x408a4c604FUNC<unknown>DEFAULT3
              Send100UP.symtab0x408800588FUNC<unknown>DEFAULT3
              SendBINARY.symtab0x408ca8844FUNC<unknown>DEFAULT3
              SendKPAC.symtab0x408530720FUNC<unknown>DEFAULT3
              SendOnePacket.symtab0x408314540FUNC<unknown>DEFAULT3
              SendRAPE.symtab0x408ff4896FUNC<unknown>DEFAULT3
              SendSTDHEX.symtab0x409374568FUNC<unknown>DEFAULT3
              SendUDPBYPASS.symtab0x4077c4596FUNC<unknown>DEFAULT3
              WalmartBag.symtab0x407ff4800FUNC<unknown>DEFAULT3
              _GLOBAL_OFFSET_TABLE_.symtab0x47d1e00OBJECT<unknown>DEFAULT12
              _Jv_RegisterClasses.symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
              _READ.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              _WRITE.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              __CTOR_END__.symtab0x47c0040OBJECT<unknown>DEFAULT7
              __CTOR_LIST__.symtab0x47c0000OBJECT<unknown>DEFAULT7
              __C_ctype_b.symtab0x47cde04OBJECT<unknown>DEFAULT11
              __C_ctype_b.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              __C_ctype_b_data.symtab0x43a3b0768OBJECT<unknown>DEFAULT5
              __C_ctype_tolower.symtab0x47d1a04OBJECT<unknown>DEFAULT11
              __C_ctype_tolower.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              __C_ctype_tolower_data.symtab0x43b760768OBJECT<unknown>DEFAULT5
              __C_ctype_toupper.symtab0x47cdf04OBJECT<unknown>DEFAULT11
              __C_ctype_toupper.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              __C_ctype_toupper_data.symtab0x43a6b0768OBJECT<unknown>DEFAULT5
              __DTOR_END__.symtab0x47c00c0OBJECT<unknown>DEFAULT8
              __DTOR_LIST__.symtab0x47c0080OBJECT<unknown>DEFAULT8
              __EH_FRAME_BEGIN__.symtab0x43bb8c0OBJECT<unknown>DEFAULT6
              __FRAME_END__.symtab0x43bb8c0OBJECT<unknown>DEFAULT6
              __GI___C_ctype_b.symtab0x47cde04OBJECT<unknown>HIDDEN11
              __GI___C_ctype_b_data.symtab0x43a3b0768OBJECT<unknown>HIDDEN5
              __GI___C_ctype_tolower.symtab0x47d1a04OBJECT<unknown>HIDDEN11
              __GI___C_ctype_tolower_data.symtab0x43b760768OBJECT<unknown>HIDDEN5
              __GI___C_ctype_toupper.symtab0x47cdf04OBJECT<unknown>HIDDEN11
              __GI___C_ctype_toupper_data.symtab0x43a6b0768OBJECT<unknown>HIDDEN5
              __GI___ctype_b.symtab0x47cde44OBJECT<unknown>HIDDEN11
              __GI___ctype_tolower.symtab0x47d1a44OBJECT<unknown>HIDDEN11
              __GI___ctype_toupper.symtab0x47cdf44OBJECT<unknown>HIDDEN11
              __GI___errno_location.symtab0x41329024FUNC<unknown>HIDDEN3
              __GI___fgetc_unlocked.symtab0x41c090388FUNC<unknown>HIDDEN3
              __GI___glibc_strerror_r.symtab0x415fc068FUNC<unknown>HIDDEN3
              __GI___h_errno_location.symtab0x41af4024FUNC<unknown>HIDDEN3
              __GI___libc_fcntl.symtab0x4124b0136FUNC<unknown>HIDDEN3
              __GI___libc_fcntl64.symtab0x412540104FUNC<unknown>HIDDEN3
              __GI___libc_open.symtab0x412a80124FUNC<unknown>HIDDEN3
              __GI___uClibc_fini.symtab0x419ed0196FUNC<unknown>HIDDEN3
              __GI___uClibc_init.symtab0x41a02c140FUNC<unknown>HIDDEN3
              __GI___xpg_strerror_r.symtab0x416010392FUNC<unknown>HIDDEN3
              __GI__exit.symtab0x4125b080FUNC<unknown>HIDDEN3
              __GI_abort.symtab0x418c20428FUNC<unknown>HIDDEN3
              __GI_atoi.symtab0x4197b028FUNC<unknown>HIDDEN3
              __GI_atol.symtab0x4197b028FUNC<unknown>HIDDEN3
              __GI_bind.symtab0x417c4084FUNC<unknown>HIDDEN3
              __GI_brk.symtab0x41d8d0112FUNC<unknown>HIDDEN3
              __GI_close.symtab0x41266084FUNC<unknown>HIDDEN3
              __GI_closedir.symtab0x412ec0292FUNC<unknown>HIDDEN3
              __GI_connect.symtab0x417ca084FUNC<unknown>HIDDEN3
              __GI_dup2.symtab0x4126c084FUNC<unknown>HIDDEN3
              __GI_endprotoent.symtab0x4167c4176FUNC<unknown>HIDDEN3
              __GI_errno.symtab0x483af04OBJECT<unknown>HIDDEN14
              __GI_execl.symtab0x419b30204FUNC<unknown>HIDDEN3
              __GI_execve.symtab0x41a5c084FUNC<unknown>HIDDEN3
              __GI_exit.symtab0x419a40236FUNC<unknown>HIDDEN3
              __GI_fclose.symtab0x413320512FUNC<unknown>HIDDEN3
              __GI_fcntl.symtab0x4124b0136FUNC<unknown>HIDDEN3
              __GI_fcntl64.symtab0x412540104FUNC<unknown>HIDDEN3
              __GI_fflush_unlocked.symtab0x4153e0628FUNC<unknown>HIDDEN3
              __GI_fgetc_unlocked.symtab0x41c090388FUNC<unknown>HIDDEN3
              __GI_fgets.symtab0x415170216FUNC<unknown>HIDDEN3
              __GI_fgets_unlocked.symtab0x415660268FUNC<unknown>HIDDEN3
              __GI_fopen.symtab0x41352028FUNC<unknown>HIDDEN3
              __GI_fork.symtab0x41272084FUNC<unknown>HIDDEN3
              __GI_fprintf.symtab0x4135a072FUNC<unknown>HIDDEN3
              __GI_fputs_unlocked.symtab0x415770128FUNC<unknown>HIDDEN3
              __GI_fseek.symtab0x41d9a068FUNC<unknown>HIDDEN3
              __GI_fseeko64.symtab0x41d9f0388FUNC<unknown>HIDDEN3
              __GI_fstat.symtab0x41a620140FUNC<unknown>HIDDEN3
              __GI_fwrite_unlocked.symtab0x4157f0280FUNC<unknown>HIDDEN3
              __GI_getc_unlocked.symtab0x41c090388FUNC<unknown>HIDDEN3
              __GI_getdtablesize.symtab0x41278072FUNC<unknown>HIDDEN3
              __GI_getegid.symtab0x41a94088FUNC<unknown>HIDDEN3
              __GI_geteuid.symtab0x4127d088FUNC<unknown>HIDDEN3
              __GI_getgid.symtab0x41a9a084FUNC<unknown>HIDDEN3
              __GI_gethostbyname.symtab0x417760116FUNC<unknown>HIDDEN3
              __GI_gethostbyname_r.symtab0x4177e01108FUNC<unknown>HIDDEN3
              __GI_getpid.symtab0x41283084FUNC<unknown>HIDDEN3
              __GI_getprotobyname_r.symtab0x416b1c408FUNC<unknown>HIDDEN3
              __GI_getprotobynumber_r.symtab0x41695c332FUNC<unknown>HIDDEN3
              __GI_getprotoent_r.symtab0x416480732FUNC<unknown>HIDDEN3
              __GI_getrlimit.symtab0x4128f084FUNC<unknown>HIDDEN3
              __GI_getsockname.symtab0x417d0084FUNC<unknown>HIDDEN3
              __GI_gettimeofday.symtab0x41295084FUNC<unknown>HIDDEN3
              __GI_getuid.symtab0x41aa0084FUNC<unknown>HIDDEN3
              __GI_h_errno.symtab0x483af44OBJECT<unknown>HIDDEN14
              __GI_inet_addr.symtab0x41771072FUNC<unknown>HIDDEN3
              __GI_inet_aton.symtab0x41c8d0280FUNC<unknown>HIDDEN3
              __GI_inet_ntoa.symtab0x4176ec32FUNC<unknown>HIDDEN3
              __GI_inet_ntoa_r.symtab0x417630188FUNC<unknown>HIDDEN3
              __GI_inet_ntop.symtab0x4172d0852FUNC<unknown>HIDDEN3
              __GI_inet_pton.symtab0x416e20700FUNC<unknown>HIDDEN3
              __GI_initstate_r.symtab0x419420328FUNC<unknown>HIDDEN3
              __GI_ioctl.symtab0x4129b0104FUNC<unknown>HIDDEN3
              __GI_isatty.symtab0x4162a060FUNC<unknown>HIDDEN3
              __GI_kill.symtab0x412a2088FUNC<unknown>HIDDEN3
              __GI_lseek64.symtab0x41aa60164FUNC<unknown>HIDDEN3
              __GI_memchr.symtab0x41c220264FUNC<unknown>HIDDEN3
              __GI_memcpy.symtab0x415910308FUNC<unknown>HIDDEN3
              __GI_memmove.symtab0x41c330816FUNC<unknown>HIDDEN3
              __GI_mempcpy.symtab0x41c66076FUNC<unknown>HIDDEN3
              __GI_memrchr.symtab0x41c6b0272FUNC<unknown>HIDDEN3
              __GI_memset.symtab0x415a50144FUNC<unknown>HIDDEN3
              __GI_nanosleep.symtab0x41ab1084FUNC<unknown>HIDDEN3
              __GI_open.symtab0x412a80124FUNC<unknown>HIDDEN3
              __GI_opendir.symtab0x412ff0408FUNC<unknown>HIDDEN3
              __GI_perror.symtab0x41354084FUNC<unknown>HIDDEN3
              __GI_pipe.symtab0x41247064FUNC<unknown>HIDDEN3
              __GI_poll.symtab0x41d94084FUNC<unknown>HIDDEN3
              __GI_raise.symtab0x41d85076FUNC<unknown>HIDDEN3
              __GI_random.symtab0x418df0164FUNC<unknown>HIDDEN3
              __GI_random_r.symtab0x4191fc176FUNC<unknown>HIDDEN3
              __GI_rawmemchr.symtab0x41df10200FUNC<unknown>HIDDEN3
              __GI_read.symtab0x412ba084FUNC<unknown>HIDDEN3
              __GI_readdir.symtab0x413190256FUNC<unknown>HIDDEN3
              __GI_readlink.symtab0x412c0084FUNC<unknown>HIDDEN3
              __GI_recv.symtab0x417de084FUNC<unknown>HIDDEN3
              __GI_recvfrom.symtab0x417e40128FUNC<unknown>HIDDEN3
              __GI_rewind.symtab0x41b100192FUNC<unknown>HIDDEN3
              __GI_sbrk.symtab0x41ab70144FUNC<unknown>HIDDEN3
              __GI_select.symtab0x412c60120FUNC<unknown>HIDDEN3
              __GI_send.symtab0x417ec084FUNC<unknown>HIDDEN3
              __GI_sendto.symtab0x417f20128FUNC<unknown>HIDDEN3
              __GI_setprotoent.symtab0x416874232FUNC<unknown>HIDDEN3
              __GI_setsockopt.symtab0x417fa0120FUNC<unknown>HIDDEN3
              __GI_setstate_r.symtab0x4190c0316FUNC<unknown>HIDDEN3
              __GI_sigaction.symtab0x41a470232FUNC<unknown>HIDDEN3
              __GI_sigaddset.symtab0x418080104FUNC<unknown>HIDDEN3
              __GI_sigemptyset.symtab0x4180f060FUNC<unknown>HIDDEN3
              __GI_signal.symtab0x418130252FUNC<unknown>HIDDEN3
              __GI_sigprocmask.symtab0x412ce0148FUNC<unknown>HIDDEN3
              __GI_sleep.symtab0x419c00564FUNC<unknown>HIDDEN3
              __GI_snprintf.symtab0x4135f068FUNC<unknown>HIDDEN3
              __GI_socket.symtab0x41802084FUNC<unknown>HIDDEN3
              __GI_sprintf.symtab0x41364080FUNC<unknown>HIDDEN3
              __GI_srandom_r.symtab0x4192ac372FUNC<unknown>HIDDEN3
              __GI_strcasecmp.symtab0x41ea80108FUNC<unknown>HIDDEN3
              __GI_strcasestr.symtab0x4161e0152FUNC<unknown>HIDDEN3
              __GI_strchr.symtab0x415ae0256FUNC<unknown>HIDDEN3
              __GI_strcmp.symtab0x415be044FUNC<unknown>HIDDEN3
              __GI_strcoll.symtab0x415be044FUNC<unknown>HIDDEN3
              __GI_strcpy.symtab0x415c1036FUNC<unknown>HIDDEN3
              __GI_strdup.symtab0x41e0f0144FUNC<unknown>HIDDEN3
              __GI_strlen.symtab0x415c40184FUNC<unknown>HIDDEN3
              __GI_strncat.symtab0x41dfe0180FUNC<unknown>HIDDEN3
              __GI_strncpy.symtab0x415d00188FUNC<unknown>HIDDEN3
              __GI_strnlen.symtab0x415dc0256FUNC<unknown>HIDDEN3
              __GI_strpbrk.symtab0x41c89064FUNC<unknown>HIDDEN3
              __GI_strspn.symtab0x41e0a076FUNC<unknown>HIDDEN3
              __GI_strstr.symtab0x415ec0256FUNC<unknown>HIDDEN3
              __GI_strtok.symtab0x41628032FUNC<unknown>HIDDEN3
              __GI_strtok_r.symtab0x41c7c0204FUNC<unknown>HIDDEN3
              __GI_strtol.symtab0x4197d028FUNC<unknown>HIDDEN3
              __GI_tcgetattr.symtab0x4162e0176FUNC<unknown>HIDDEN3
              __GI_time.symtab0x412d8084FUNC<unknown>HIDDEN3
              __GI_times.symtab0x41ac0084FUNC<unknown>HIDDEN3
              __GI_tolower.symtab0x41af0060FUNC<unknown>HIDDEN3
              __GI_toupper.symtab0x412e8060FUNC<unknown>HIDDEN3
              __GI_vfork.symtab0x412de028FUNC<unknown>HIDDEN3
              __GI_vfprintf.symtab0x413d80260FUNC<unknown>HIDDEN3
              __GI_vsnprintf.symtab0x413690260FUNC<unknown>HIDDEN3
              __GI_wait4.symtab0x41ac6088FUNC<unknown>HIDDEN3
              __GI_waitpid.symtab0x412e0028FUNC<unknown>HIDDEN3
              __GI_wcrtomb.symtab0x41af60112FUNC<unknown>HIDDEN3
              __GI_wcsnrtombs.symtab0x41b010228FUNC<unknown>HIDDEN3
              __GI_wcsrtombs.symtab0x41afd064FUNC<unknown>HIDDEN3
              __GI_write.symtab0x412e2084FUNC<unknown>HIDDEN3
              __JCR_END__.symtab0x47c0100OBJECT<unknown>DEFAULT9
              __JCR_LIST__.symtab0x47c0100OBJECT<unknown>DEFAULT9
              __app_fini.symtab0x483adc4OBJECT<unknown>HIDDEN14
              __atexit_lock.symtab0x47d17024OBJECT<unknown>DEFAULT11
              __bsd_signal.symtab0x418130252FUNC<unknown>HIDDEN3
              __bss_start.symtab0x47d7e00NOTYPE<unknown>DEFAULTSHN_ABS
              __check_one_fd.symtab0x419fa4136FUNC<unknown>DEFAULT3
              __ctype_b.symtab0x47cde44OBJECT<unknown>DEFAULT11
              __ctype_tolower.symtab0x47d1a44OBJECT<unknown>DEFAULT11
              __ctype_toupper.symtab0x47cdf44OBJECT<unknown>DEFAULT11
              __curbrk.symtab0x483b204OBJECT<unknown>HIDDEN14
              __data_start.symtab0x47c5100OBJECT<unknown>DEFAULT11
              __decode_answer.symtab0x41e480340FUNC<unknown>HIDDEN3
              __decode_dotted.symtab0x41ec10340FUNC<unknown>HIDDEN3
              __decode_header.symtab0x41e290228FUNC<unknown>HIDDEN3
              __deregister_frame_info.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
              __dns_lookup.symtab0x41c9f02568FUNC<unknown>HIDDEN3
              __do_global_ctors_aux.symtab0x41edc00FUNC<unknown>DEFAULT3
              __do_global_dtors_aux.symtab0x4001600FUNC<unknown>DEFAULT3
              __dso_handle.symtab0x47c4f00OBJECT<unknown>HIDDEN11
              __encode_dotted.symtab0x41eaf0280FUNC<unknown>HIDDEN3
              __encode_header.symtab0x41e180272FUNC<unknown>HIDDEN3
              __encode_question.symtab0x41e380172FUNC<unknown>HIDDEN3
              __environ.symtab0x483ad44OBJECT<unknown>DEFAULT14
              __errno_location.symtab0x41329024FUNC<unknown>DEFAULT3
              __errno_location.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              __exit_cleanup.symtab0x483ac04OBJECT<unknown>HIDDEN14
              __fgetc_unlocked.symtab0x41c090388FUNC<unknown>DEFAULT3
              __fini_array_end.symtab0x47c0000NOTYPE<unknown>HIDDENSHN_ABS
              __fini_array_start.symtab0x47c0000NOTYPE<unknown>HIDDENSHN_ABS
              __get_hosts_byname_r.symtab0x41d7e0104FUNC<unknown>HIDDEN3
              __getdents.symtab0x41a6b0192FUNC<unknown>HIDDEN3
              __getdents64.symtab0x41a770456FUNC<unknown>HIDDEN3
              __glibc_strerror_r.symtab0x415fc068FUNC<unknown>DEFAULT3
              __glibc_strerror_r.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              __h_errno_location.symtab0x41af4024FUNC<unknown>DEFAULT3
              __h_errno_location.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              __heap_alloc.symtab0x4188e0188FUNC<unknown>DEFAULT3
              __heap_alloc_at.symtab0x4189a0184FUNC<unknown>DEFAULT3
              __heap_free.symtab0x418aa8364FUNC<unknown>DEFAULT3
              __heap_link_free_area.symtab0x418a6044FUNC<unknown>DEFAULT3
              __heap_link_free_area_after.symtab0x418a8c28FUNC<unknown>DEFAULT3
              __init_array_end.symtab0x47c0000NOTYPE<unknown>HIDDENSHN_ABS
              __init_array_start.symtab0x47c0000NOTYPE<unknown>HIDDENSHN_ABS
              __initbuf.symtab0x416410112FUNC<unknown>DEFAULT3
              __length_dotted.symtab0x41ed7072FUNC<unknown>HIDDEN3
              __length_question.symtab0x41e43072FUNC<unknown>HIDDEN3
              __libc_close.symtab0x41266084FUNC<unknown>DEFAULT3
              __libc_connect.symtab0x417ca084FUNC<unknown>DEFAULT3
              __libc_creat.symtab0x412afc28FUNC<unknown>DEFAULT3
              __libc_fcntl.symtab0x4124b0136FUNC<unknown>DEFAULT3
              __libc_fcntl64.symtab0x412540104FUNC<unknown>DEFAULT3
              __libc_fork.symtab0x41272084FUNC<unknown>DEFAULT3
              __libc_getpid.symtab0x41283084FUNC<unknown>DEFAULT3
              __libc_lseek64.symtab0x41aa60164FUNC<unknown>DEFAULT3
              __libc_nanosleep.symtab0x41ab1084FUNC<unknown>DEFAULT3
              __libc_open.symtab0x412a80124FUNC<unknown>DEFAULT3
              __libc_poll.symtab0x41d94084FUNC<unknown>DEFAULT3
              __libc_read.symtab0x412ba084FUNC<unknown>DEFAULT3
              __libc_recv.symtab0x417de084FUNC<unknown>DEFAULT3
              __libc_recvfrom.symtab0x417e40128FUNC<unknown>DEFAULT3
              __libc_select.symtab0x412c60120FUNC<unknown>DEFAULT3
              __libc_send.symtab0x417ec084FUNC<unknown>DEFAULT3
              __libc_sendto.symtab0x417f20128FUNC<unknown>DEFAULT3
              __libc_sigaction.symtab0x41a470232FUNC<unknown>DEFAULT3
              __libc_stack_end.symtab0x483ad04OBJECT<unknown>DEFAULT14
              __libc_system.symtab0x419570568FUNC<unknown>DEFAULT3
              __libc_waitpid.symtab0x412e0028FUNC<unknown>DEFAULT3
              __libc_write.symtab0x412e2084FUNC<unknown>DEFAULT3
              __malloc_heap.symtab0x47d0804OBJECT<unknown>DEFAULT11
              __malloc_heap_lock.symtab0x483a9024OBJECT<unknown>DEFAULT14
              __malloc_sbrk_lock.symtab0x483d4c24OBJECT<unknown>DEFAULT14
              __nameserver.symtab0x483d7412OBJECT<unknown>HIDDEN14
              __nameservers.symtab0x47d8004OBJECT<unknown>HIDDEN13
              __open_etc_hosts.symtab0x41e5e0108FUNC<unknown>HIDDEN3
              __open_nameservers.symtab0x41d400984FUNC<unknown>HIDDEN3
              __pagesize.symtab0x483ad84OBJECT<unknown>DEFAULT14
              __preinit_array_end.symtab0x47c0000NOTYPE<unknown>HIDDENSHN_ABS
              __preinit_array_start.symtab0x47c0000NOTYPE<unknown>HIDDENSHN_ABS
              __pthread_initialize_minimal.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
              __pthread_mutex_init.symtab0x419f948FUNC<unknown>DEFAULT3
              __pthread_mutex_lock.symtab0x419f948FUNC<unknown>DEFAULT3
              __pthread_mutex_trylock.symtab0x419f948FUNC<unknown>DEFAULT3
              __pthread_mutex_unlock.symtab0x419f948FUNC<unknown>DEFAULT3
              __pthread_return_0.symtab0x419f948FUNC<unknown>DEFAULT3
              __pthread_return_void.symtab0x419f9c8FUNC<unknown>DEFAULT3
              __raise.symtab0x41d85076FUNC<unknown>HIDDEN3
              __read_etc_hosts_r.symtab0x41e64c1076FUNC<unknown>HIDDEN3
              __register_frame_info.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
              __resolv_lock.symtab0x47d1c024OBJECT<unknown>DEFAULT11
              __rtld_fini.symtab0x483ae04OBJECT<unknown>HIDDEN14
              __searchdomain.symtab0x483d6416OBJECT<unknown>HIDDEN14
              __searchdomains.symtab0x47d8044OBJECT<unknown>HIDDEN13
              __sigaddset.symtab0x41825844FUNC<unknown>DEFAULT3
              __sigdelset.symtab0x41828448FUNC<unknown>DEFAULT3
              __sigismember.symtab0x41823040FUNC<unknown>DEFAULT3
              __start.symtab0x4002a0100FUNC<unknown>DEFAULT3
              __stdin.symtab0x47ce4c4OBJECT<unknown>DEFAULT11
              __stdio_READ.symtab0x41db80140FUNC<unknown>HIDDEN3
              __stdio_WRITE.symtab0x41b1c0280FUNC<unknown>HIDDEN3
              __stdio_adjust_position.symtab0x41dc10320FUNC<unknown>HIDDEN3
              __stdio_fwrite.symtab0x41b2e0472FUNC<unknown>HIDDEN3
              __stdio_init_mutex.symtab0x413bc832FUNC<unknown>HIDDEN3
              __stdio_mutex_initializer.3833.symtab0x43a9c024OBJECT<unknown>DEFAULT5
              __stdio_rfill.symtab0x41dd5088FUNC<unknown>HIDDEN3
              __stdio_seek.symtab0x41dea0112FUNC<unknown>HIDDEN3
              __stdio_trans2r_o.symtab0x41ddb0228FUNC<unknown>HIDDEN3
              __stdio_trans2w_o.symtab0x41b4c0308FUNC<unknown>HIDDEN3
              __stdio_wcommit.symtab0x413d10100FUNC<unknown>HIDDEN3
              __stdout.symtab0x47ce504OBJECT<unknown>DEFAULT11
              __syscall_error.symtab0x41a42072FUNC<unknown>HIDDEN3
              __syscall_error.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              __syscall_fcntl.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              __syscall_fcntl64.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              __syscall_rt_sigaction.symtab0x41a56084FUNC<unknown>HIDDEN3
              __syscall_rt_sigaction.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              __uClibc_fini.symtab0x419ed0196FUNC<unknown>DEFAULT3
              __uClibc_init.symtab0x41a02c140FUNC<unknown>DEFAULT3
              __uClibc_main.symtab0x41a0b8864FUNC<unknown>DEFAULT3
              __uClibc_main.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              __uclibc_progname.symtab0x47d1904OBJECT<unknown>HIDDEN11
              __vfork.symtab0x412de028FUNC<unknown>HIDDEN3
              __xpg_strerror_r.symtab0x416010392FUNC<unknown>DEFAULT3
              __xpg_strerror_r.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              __xstat64_conv.symtab0x41acc0288FUNC<unknown>HIDDEN3
              __xstat_conv.symtab0x41ade0276FUNC<unknown>HIDDEN3
              _adjust_pos.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              _charpad.symtab0x413e90128FUNC<unknown>DEFAULT3
              _cs_funcs.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              _dl_aux_init.symtab0x41d8a044FUNC<unknown>DEFAULT3
              _dl_phdr.symtab0x47d8084OBJECT<unknown>DEFAULT13
              _dl_phnum.symtab0x47d80c4OBJECT<unknown>DEFAULT13
              _edata.symtab0x47d7e00NOTYPE<unknown>DEFAULTSHN_ABS
              _end.symtab0x483d800NOTYPE<unknown>DEFAULTSHN_ABS
              _errno.symtab0x483af04OBJECT<unknown>DEFAULT14
              _exit.symtab0x4125b080FUNC<unknown>DEFAULT3
              _exit.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              _fbss.symtab0x47d7e00NOTYPE<unknown>DEFAULTSHN_ABS
              _fdata.symtab0x47c4f00NOTYPE<unknown>DEFAULT11
              _fini.symtab0x41ee3028FUNC<unknown>DEFAULT4
              _fixed_buffers.symtab0x4818688192OBJECT<unknown>DEFAULT14
              _fopen.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              _fp_out_narrow.symtab0x413f10228FUNC<unknown>DEFAULT3
              _fpmaxtostr.symtab0x41b8402120FUNC<unknown>HIDDEN3
              _fpmaxtostr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              _ftext.symtab0x4001600NOTYPE<unknown>DEFAULT3
              _fwrite.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              _gp.symtab0x4851d00NOTYPE<unknown>DEFAULTSHN_ABS
              _gp_disp.symtab0x00OBJECT<unknown>DEFAULTSHN_UNDEF
              _h_errno.symtab0x483af44OBJECT<unknown>DEFAULT14
              _init.symtab0x4000cc28FUNC<unknown>DEFAULT2
              _load_inttype.symtab0x41b600136FUNC<unknown>HIDDEN3
              _load_inttype.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              _ppfs_init.symtab0x4147a0220FUNC<unknown>HIDDEN3
              _ppfs_init.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              _ppfs_parsespec.symtab0x414b7c1512FUNC<unknown>HIDDEN3
              _ppfs_parsespec.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              _ppfs_prepargs.symtab0x414880100FUNC<unknown>HIDDEN3
              _ppfs_prepargs.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              _ppfs_setargs.symtab0x4148f0544FUNC<unknown>HIDDEN3
              _ppfs_setargs.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              _promoted_size.symtab0x414b10108FUNC<unknown>DEFAULT3
              _pthread_cleanup_pop_restore.symtab0x419f9c8FUNC<unknown>DEFAULT3
              _pthread_cleanup_push_defer.symtab0x419f9c8FUNC<unknown>DEFAULT3
              _rfill.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              _sigintr.symtab0x483ccc128OBJECT<unknown>HIDDEN14
              _stdio.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              _stdio_fopen.symtab0x4137a0880FUNC<unknown>HIDDEN3
              _stdio_init.symtab0x413b10184FUNC<unknown>HIDDEN3
              _stdio_openlist.symtab0x47ce544OBJECT<unknown>DEFAULT11
              _stdio_openlist_add_lock.symtab0x47ce0024OBJECT<unknown>DEFAULT11
              _stdio_openlist_dec_use.symtab0x415250400FUNC<unknown>DEFAULT3
              _stdio_openlist_del_count.symtab0x4818644OBJECT<unknown>DEFAULT14
              _stdio_openlist_del_lock.symtab0x47ce1824OBJECT<unknown>DEFAULT11
              _stdio_openlist_use_count.symtab0x4818604OBJECT<unknown>DEFAULT14
              _stdio_streams.symtab0x47ce58240OBJECT<unknown>DEFAULT11
              _stdio_term.symtab0x413be8284FUNC<unknown>HIDDEN3
              _stdio_user_locking.symtab0x47ce304OBJECT<unknown>DEFAULT11
              _stdlib_strto_l.symtab0x4197f0592FUNC<unknown>HIDDEN3
              _stdlib_strto_l.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              _store_inttype.symtab0x41b69068FUNC<unknown>HIDDEN3
              _store_inttype.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              _string_syserrmsgs.symtab0x43ab302934OBJECT<unknown>HIDDEN5
              _string_syserrmsgs.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              _trans2r.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              _trans2w.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              _uintmaxtostr.symtab0x41b6e0340FUNC<unknown>HIDDEN3
              _uintmaxtostr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              _vfprintf_internal.symtab0x413ff41960FUNC<unknown>HIDDEN3
              _vfprintf_internal.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              _wcommit.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              abort.symtab0x418c20428FUNC<unknown>DEFAULT3
              abort.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              access.symtab0x41260084FUNC<unknown>DEFAULT3
              access.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              acnc.symtab0x40a558372FUNC<unknown>DEFAULT3
              add_entry.symtab0x410ea4200FUNC<unknown>DEFAULT3
              atoi.symtab0x4197b028FUNC<unknown>DEFAULT3
              atol.symtab0x4197b028FUNC<unknown>DEFAULT3
              atol.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              attacks_vector_wabba_jack.symtab0x4060c41104FUNC<unknown>DEFAULT3
              bcopy.symtab0x4161a032FUNC<unknown>DEFAULT3
              bcopy.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              been_there_done_that.symtab0x483ab04OBJECT<unknown>DEFAULT14
              been_there_done_that.2792.symtab0x483ae44OBJECT<unknown>DEFAULT14
              bind.symtab0x417c4084FUNC<unknown>DEFAULT3
              bind.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              blacklist.symtab0x47cd04116OBJECT<unknown>DEFAULT11
              brk.symtab0x41d8d0112FUNC<unknown>DEFAULT3
              brk.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              bsd_signal.symtab0x418130252FUNC<unknown>DEFAULT3
              buf.2613.symtab0x4838a016OBJECT<unknown>DEFAULT14
              buf.4833.symtab0x4838b0460OBJECT<unknown>DEFAULT14
              bzero.symtab0x4161c028FUNC<unknown>DEFAULT3
              bzero.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              c.symtab0x47cdbc4OBJECT<unknown>DEFAULT11
              cal_chksum.symtab0x405c34336FUNC<unknown>DEFAULT3
              calloc.symtab0x4184b0180FUNC<unknown>DEFAULT3
              calloc.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              checksum.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              checksum_generic.symtab0x400310268FUNC<unknown>DEFAULT3
              checksum_tcp_udp.symtab0x40041c572FUNC<unknown>DEFAULT3
              checksum_tcpudp.symtab0x400658572FUNC<unknown>DEFAULT3
              cia_bp.symtab0x47cdb04OBJECT<unknown>DEFAULT11
              clock.symtab0x4132b0108FUNC<unknown>DEFAULT3
              clock.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              close.symtab0x41266084FUNC<unknown>DEFAULT3
              close.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              closedir.symtab0x412ec0292FUNC<unknown>DEFAULT3
              closedir.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              completed.2296.symtab0x47d8101OBJECT<unknown>DEFAULT14
              connect.symtab0x417ca084FUNC<unknown>DEFAULT3
              connect.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              connectTimeout.symtab0x404818828FUNC<unknown>DEFAULT3
              creat.symtab0x412afc28FUNC<unknown>DEFAULT3
              crtstuff.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              crtstuff.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              csum.symtab0x404e78460FUNC<unknown>DEFAULT3
              data_start.symtab0x47c5100OBJECT<unknown>DEFAULT11
              decodea.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              decoded.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              decodeh.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              dl-support.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              dnslookup.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              dup2.symtab0x4126c084FUNC<unknown>DEFAULT3
              dup2.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              encoded.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              encodeh.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              encodeq.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              endprotoent.symtab0x4167c4176FUNC<unknown>DEFAULT3
              environ.symtab0x483ad44OBJECT<unknown>DEFAULT14
              errno.symtab0x483af04OBJECT<unknown>DEFAULT14
              errno.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              estridx.symtab0x43aaa0126OBJECT<unknown>DEFAULT5
              execl.symtab0x419b30204FUNC<unknown>DEFAULT3
              execl.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              execve.symtab0x41a5c084FUNC<unknown>DEFAULT3
              execve.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              exit.symtab0x419a40236FUNC<unknown>DEFAULT3
              exit.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              exp10_table.symtab0x43bab872OBJECT<unknown>DEFAULT5
              fclose.symtab0x413320512FUNC<unknown>DEFAULT3
              fclose.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              fcntl.symtab0x4124b0136FUNC<unknown>DEFAULT3
              fcntl64.symtab0x412540104FUNC<unknown>DEFAULT3
              fd.symtab0x47d7e44OBJECT<unknown>DEFAULT13
              fdgets.symtab0x403df8292FUNC<unknown>DEFAULT3
              fdopen_pids.symtab0x48184c4OBJECT<unknown>DEFAULT14
              fdpclose.symtab0x403b7c636FUNC<unknown>DEFAULT3
              fdpopen.symtab0x4037081140FUNC<unknown>DEFAULT3
              fflush_unlocked.symtab0x4153e0628FUNC<unknown>DEFAULT3
              fflush_unlocked.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              fgetc_unlocked.symtab0x41c090388FUNC<unknown>DEFAULT3
              fgetc_unlocked.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              fgets.symtab0x415170216FUNC<unknown>DEFAULT3
              fgets.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              fgets_unlocked.symtab0x415660268FUNC<unknown>DEFAULT3
              fgets_unlocked.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              findRandIP.symtab0x404dcc172FUNC<unknown>DEFAULT3
              fmt.symtab0x43baa020OBJECT<unknown>DEFAULT5
              fopen.symtab0x41352028FUNC<unknown>DEFAULT3
              fopen.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              fork.symtab0x41272084FUNC<unknown>DEFAULT3
              fork.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              fprintf.symtab0x4135a072FUNC<unknown>DEFAULT3
              fprintf.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              fputs_unlocked.symtab0x415770128FUNC<unknown>DEFAULT3
              fputs_unlocked.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              frame_dummy.symtab0x40021c0FUNC<unknown>DEFAULT3
              free.symtab0x418570396FUNC<unknown>DEFAULT3
              free.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              fseek.symtab0x41d9a068FUNC<unknown>DEFAULT3
              fseeko.symtab0x41d9a068FUNC<unknown>DEFAULT3
              fseeko.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              fseeko64.symtab0x41d9f0388FUNC<unknown>DEFAULT3
              fseeko64.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              fstat.symtab0x41a620140FUNC<unknown>DEFAULT3
              fstat.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              fwrite_unlocked.symtab0x4157f0280FUNC<unknown>DEFAULT3
              fwrite_unlocked.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              getArch.symtab0x40e82856FUNC<unknown>DEFAULT3
              getHost.symtab0x40425c160FUNC<unknown>DEFAULT3
              getOurIP.symtab0x40e4a8896FUNC<unknown>DEFAULT3
              get_hosts_byname_r.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              getc_unlocked.symtab0x41c090388FUNC<unknown>DEFAULT3
              getdents.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              getdents64.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              getdtablesize.symtab0x41278072FUNC<unknown>DEFAULT3
              getdtablesize.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              getegid.symtab0x41a94088FUNC<unknown>DEFAULT3
              getegid.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              geteuid.symtab0x4127d088FUNC<unknown>DEFAULT3
              geteuid.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              getgid.symtab0x41a9a084FUNC<unknown>DEFAULT3
              getgid.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              gethostbyname.symtab0x417760116FUNC<unknown>DEFAULT3
              gethostbyname.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              gethostbyname_r.symtab0x4177e01108FUNC<unknown>DEFAULT3
              gethostbyname_r.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              getpid.symtab0x41283084FUNC<unknown>DEFAULT3
              getpid.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              getppid.symtab0x41289084FUNC<unknown>DEFAULT3
              getppid.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              getproto.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              getprotobyname.symtab0x416cb4116FUNC<unknown>DEFAULT3
              getprotobyname_r.symtab0x416b1c408FUNC<unknown>DEFAULT3
              getprotobynumber.symtab0x416aa8116FUNC<unknown>DEFAULT3
              getprotobynumber_r.symtab0x41695c332FUNC<unknown>DEFAULT3
              getprotoent.symtab0x41675c104FUNC<unknown>DEFAULT3
              getprotoent_r.symtab0x416480732FUNC<unknown>DEFAULT3
              getrlimit.symtab0x4128f084FUNC<unknown>DEFAULT3
              getrlimit.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              getsockname.symtab0x417d0084FUNC<unknown>DEFAULT3
              getsockname.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              getsockopt.symtab0x417d60120FUNC<unknown>DEFAULT3
              getsockopt.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              gettimeofday.symtab0x41295084FUNC<unknown>DEFAULT3
              gettimeofday.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              getuid.symtab0x41aa0084FUNC<unknown>DEFAULT3
              getuid.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              h.4832.symtab0x483a7c20OBJECT<unknown>DEFAULT14
              h_errno.symtab0x483af44OBJECT<unknown>DEFAULT14
              hacks.symtab0x47cda04OBJECT<unknown>DEFAULT11
              hacks2.symtab0x47cda44OBJECT<unknown>DEFAULT11
              hacks3.symtab0x47cda84OBJECT<unknown>DEFAULT11
              hacks4.symtab0x47cdac4OBJECT<unknown>DEFAULT11
              heap_alloc.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              heap_alloc_at.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              heap_free.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              hextable.symtab0x41fff81024OBJECT<unknown>DEFAULT5
              hlt.symtab0x4002fc0NOTYPE<unknown>DEFAULT3
              htonl.symtab0x4163d040FUNC<unknown>DEFAULT3
              htons.symtab0x4163f824FUNC<unknown>DEFAULT3
              i.symtab0x47d7e84OBJECT<unknown>DEFAULT13
              i.4487.symtab0x47cdc04OBJECT<unknown>DEFAULT11
              index.symtab0x415ae0256FUNC<unknown>DEFAULT3
              inet_addr.symtab0x41771072FUNC<unknown>DEFAULT3
              inet_aton.symtab0x41c8d0280FUNC<unknown>DEFAULT3
              inet_aton.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              inet_makeaddr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              inet_ntoa.symtab0x4176ec32FUNC<unknown>DEFAULT3
              inet_ntoa.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              inet_ntoa_r.symtab0x417630188FUNC<unknown>DEFAULT3
              inet_ntop.symtab0x4172d0852FUNC<unknown>DEFAULT3
              inet_ntop4.symtab0x4170dc500FUNC<unknown>DEFAULT3
              inet_pton.symtab0x416e20700FUNC<unknown>DEFAULT3
              inet_pton4.symtab0x416d30240FUNC<unknown>DEFAULT3
              initConnection.symtab0x40e1e4708FUNC<unknown>DEFAULT3
              init_rand.symtab0x4022c4300FUNC<unknown>DEFAULT3
              initfini.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              initfini.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              initial_fa.symtab0x47cf70264OBJECT<unknown>DEFAULT11
              initstate.symtab0x418f44208FUNC<unknown>DEFAULT3
              initstate_r.symtab0x419420328FUNC<unknown>DEFAULT3
              ioctl.symtab0x4129b0104FUNC<unknown>DEFAULT3
              ioctl.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              isatty.symtab0x4162a060FUNC<unknown>DEFAULT3
              isatty.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              kill.symtab0x412a2088FUNC<unknown>DEFAULT3
              kill.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              killdirectories.symtab0x47cd7828OBJECT<unknown>DEFAULT11
              killer.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              killer_kill_by_port.symtab0x4013a03300FUNC<unknown>DEFAULT3
              killer_status.symtab0x47d8404OBJECT<unknown>DEFAULT14
              killerinit.symtab0x400ea4280FUNC<unknown>DEFAULT3
              killerkillbyname.symtab0x400fbc848FUNC<unknown>DEFAULT3
              killerpid.symtab0x47d7ec4OBJECT<unknown>DEFAULT13
              lengthd.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              lengthq.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              libc/string/mips/memcpy.S.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              libc/string/mips/memset.S.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              libc/sysdeps/linux/mips/crt1.S.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              libc/sysdeps/linux/mips/crti.S.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              libc/sysdeps/linux/mips/crtn.S.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              libc/sysdeps/linux/mips/pipe.S.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              listFork.symtab0x404b54632FUNC<unknown>DEFAULT3
              llseek.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              lock_device.symtab0x400a241152FUNC<unknown>DEFAULT3
              lseek64.symtab0x41aa60164FUNC<unknown>DEFAULT3
              macAddress.symtab0x47d8446OBJECT<unknown>DEFAULT14
              main.symtab0x40e8603724FUNC<unknown>DEFAULT3
              main.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              makeIPPacket.symtab0x4051a8296FUNC<unknown>DEFAULT3
              makeRandomStr.symtab0x4043a0268FUNC<unknown>DEFAULT3
              makevsepacket.symtab0x409a40332FUNC<unknown>DEFAULT3
              malloc.symtab0x4182c0492FUNC<unknown>DEFAULT3
              malloc.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              memchr.symtab0x41c220264FUNC<unknown>DEFAULT3
              memchr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              memcpy.symtab0x415910308FUNC<unknown>DEFAULT3
              memmove.symtab0x41c330816FUNC<unknown>DEFAULT3
              memmove.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              mempcpy.symtab0x41c66076FUNC<unknown>DEFAULT3
              mempcpy.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              memrchr.symtab0x41c6b0272FUNC<unknown>DEFAULT3
              memrchr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              memset.symtab0x415a50144FUNC<unknown>DEFAULT3
              mylock.symtab0x47cf5024OBJECT<unknown>DEFAULT11
              mylock.symtab0x47d09024OBJECT<unknown>DEFAULT11
              mylock.symtab0x47d0b024OBJECT<unknown>DEFAULT11
              mylock.symtab0x483b0024OBJECT<unknown>DEFAULT14
              nanosleep.symtab0x41ab1084FUNC<unknown>DEFAULT3
              nanosleep.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              next_start.1065.symtab0x4838704OBJECT<unknown>DEFAULT14
              ngPid.symtab0x47d7f44OBJECT<unknown>DEFAULT13
              ntohl.symtab0x41639040FUNC<unknown>DEFAULT3
              ntohl.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              ntohs.symtab0x4163b824FUNC<unknown>DEFAULT3
              ntop.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              numpids.symtab0x47d8388OBJECT<unknown>DEFAULT14
              object.2349.symtab0x47d81424OBJECT<unknown>DEFAULT14
              open.symtab0x412a80124FUNC<unknown>DEFAULT3
              open.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              openandclose.symtab0x40130c148FUNC<unknown>DEFAULT3
              opendir.symtab0x412ff0408FUNC<unknown>DEFAULT3
              opendir.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              opennameservers.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              ourIP.symtab0x47d7f04OBJECT<unknown>DEFAULT13
              p.2294.symtab0x47c5000OBJECT<unknown>DEFAULT11
              pack.symtab0x405f9c296FUNC<unknown>DEFAULT3
              parseHex.symtab0x403f1c176FUNC<unknown>DEFAULT3
              perror.symtab0x41354084FUNC<unknown>DEFAULT3
              perror.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              pidPath.symtab0x483b30100OBJECT<unknown>DEFAULT14
              pids.symtab0x47d7fc4OBJECT<unknown>DEFAULT13
              pipe.symtab0x41247064FUNC<unknown>DEFAULT3
              poll.symtab0x41d94084FUNC<unknown>DEFAULT3
              poll.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              prctl.symtab0x412b20120FUNC<unknown>DEFAULT3
              prctl.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              prefix.4045.symtab0x43a9f012OBJECT<unknown>DEFAULT5
              print.symtab0x402f101456FUNC<unknown>DEFAULT3
              printchar.symtab0x402984184FUNC<unknown>DEFAULT3
              printi.symtab0x402c78664FUNC<unknown>DEFAULT3
              prints.symtab0x402a3c572FUNC<unknown>DEFAULT3
              processCmd.symtab0x40a88814684FUNC<unknown>DEFAULT3
              proto.symtab0x48388812OBJECT<unknown>DEFAULT14
              proto_stayopen.symtab0x4838944OBJECT<unknown>DEFAULT14
              protof.symtab0x4838844OBJECT<unknown>DEFAULT14
              qual_chars.4050.symtab0x43aa1020OBJECT<unknown>DEFAULT5
              raise.symtab0x41d85076FUNC<unknown>DEFAULT3
              raise.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              rand.symtab0x418dd028FUNC<unknown>DEFAULT3
              rand.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              rand.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              rand__str.symtab0x40f90c372FUNC<unknown>DEFAULT3
              rand_alpha_str.symtab0x40fa80300FUNC<unknown>DEFAULT3
              rand_alphastr.symtab0x4027b4464FUNC<unknown>DEFAULT3
              rand_cmwc.symtab0x4025dc472FUNC<unknown>DEFAULT3
              rand_init.symtab0x40f6f0248FUNC<unknown>DEFAULT3
              rand_next.symtab0x40f7e8292FUNC<unknown>DEFAULT3
              random.symtab0x418df0164FUNC<unknown>DEFAULT3
              random.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              random_poly_info.symtab0x43b71040OBJECT<unknown>DEFAULT5
              random_r.symtab0x4191fc176FUNC<unknown>DEFAULT3
              random_r.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              randtbl.symtab0x47d0c8128OBJECT<unknown>DEFAULT11
              rawmemchr.symtab0x41df10200FUNC<unknown>DEFAULT3
              rawmemchr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              read.symtab0x412ba084FUNC<unknown>DEFAULT3
              read.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              read_etc_hosts_r.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              readdir.symtab0x413190256FUNC<unknown>DEFAULT3
              readdir.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              readlink.symtab0x412c0084FUNC<unknown>DEFAULT3
              readlink.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              realloc.symtab0x418700472FUNC<unknown>DEFAULT3
              realloc.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              recv.symtab0x417de084FUNC<unknown>DEFAULT3
              recv.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              recvLine.symtab0x4044ac876FUNC<unknown>DEFAULT3
              recvfrom.symtab0x417e40128FUNC<unknown>DEFAULT3
              recvfrom.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              report_kill.symtab0x4008a0388FUNC<unknown>DEFAULT3
              resolv.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              resolv_domain_to_hostname.symtab0x40fbb0360FUNC<unknown>DEFAULT3
              resolv_entries_free.symtab0x410834164FUNC<unknown>DEFAULT3
              resolv_lookup.symtab0x40fe5c2520FUNC<unknown>DEFAULT3
              resolv_skip_name.symtab0x40fd18324FUNC<unknown>DEFAULT3
              rewind.symtab0x41b100192FUNC<unknown>DEFAULT3
              rewind.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              rtcp.symtab0x406e281740FUNC<unknown>DEFAULT3
              sbrk.symtab0x41ab70144FUNC<unknown>DEFAULT3
              sbrk.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              scanPid.symtab0x47d7f84OBJECT<unknown>DEFAULT13
              select.symtab0x412c60120FUNC<unknown>DEFAULT3
              select.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              send.symtab0x417ec084FUNC<unknown>DEFAULT3
              send.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              sendSTD.symtab0x407d14736FUNC<unknown>DEFAULT3
              sendSYNACK.symtab0x4095ac1172FUNC<unknown>DEFAULT3
              sendZgo.symtab0x4074f4720FUNC<unknown>DEFAULT3
              sendto.symtab0x417f20128FUNC<unknown>DEFAULT3
              sendto.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              setprotoent.symtab0x416874232FUNC<unknown>DEFAULT3
              setsockopt.symtab0x417fa0120FUNC<unknown>DEFAULT3
              setsockopt.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              setstate.symtab0x418e94176FUNC<unknown>DEFAULT3
              setstate_r.symtab0x4190c0316FUNC<unknown>DEFAULT3
              sigaction.symtab0x41a470232FUNC<unknown>DEFAULT3
              sigaction.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              sigaddset.symtab0x418080104FUNC<unknown>DEFAULT3
              sigaddset.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              sigempty.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              sigemptyset.symtab0x4180f060FUNC<unknown>DEFAULT3
              signal.symtab0x418130252FUNC<unknown>DEFAULT3
              signal.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              sigprocmask.symtab0x412ce0148FUNC<unknown>DEFAULT3
              sigprocmask.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              sigsetops.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              sleep.symtab0x419c00564FUNC<unknown>DEFAULT3
              sleep.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              snprintf.symtab0x4135f068FUNC<unknown>DEFAULT3
              snprintf.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              snype.symtab0x483b9480OBJECT<unknown>DEFAULT14
              socket.symtab0x41802084FUNC<unknown>DEFAULT3
              socket.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              socket_connect.symtab0x40a6cc444FUNC<unknown>DEFAULT3
              socket_connect_icmp.symtab0x405d84536FUNC<unknown>DEFAULT3
              sockprintf.symtab0x4035b0344FUNC<unknown>DEFAULT3
              spec_and_mask.4049.symtab0x43aa2416OBJECT<unknown>DEFAULT5
              spec_base.4044.symtab0x43a9fc7OBJECT<unknown>DEFAULT5
              spec_chars.4046.symtab0x43aa5021OBJECT<unknown>DEFAULT5
              spec_flags.4045.symtab0x43aa688OBJECT<unknown>DEFAULT5
              spec_or_mask.4048.symtab0x43aa3416OBJECT<unknown>DEFAULT5
              spec_ranges.4047.symtab0x43aa449OBJECT<unknown>DEFAULT5
              sprintf.symtab0x41364080FUNC<unknown>DEFAULT3
              sprintf.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              srand.symtab0x419014172FUNC<unknown>DEFAULT3
              srandom.symtab0x419014172FUNC<unknown>DEFAULT3
              srandom_r.symtab0x4192ac372FUNC<unknown>DEFAULT3
              static_aliases.symtab0x4838804OBJECT<unknown>DEFAULT14
              static_id.symtab0x47d1b02OBJECT<unknown>DEFAULT11
              static_ns.symtab0x483b184OBJECT<unknown>DEFAULT14
              stderr.symtab0x47ce484OBJECT<unknown>DEFAULT11
              stdin.symtab0x47ce404OBJECT<unknown>DEFAULT11
              stdout.symtab0x47ce444OBJECT<unknown>DEFAULT11
              strcasecmp.symtab0x41ea80108FUNC<unknown>DEFAULT3
              strcasecmp.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              strcasestr.symtab0x4161e0152FUNC<unknown>DEFAULT3
              strcasestr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              strchr.symtab0x415ae0256FUNC<unknown>DEFAULT3
              strchr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              strcmp.symtab0x415be044FUNC<unknown>DEFAULT3
              strcmp.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              strcoll.symtab0x415be044FUNC<unknown>DEFAULT3
              strcpy.symtab0x415c1036FUNC<unknown>DEFAULT3
              strcpy.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              strdup.symtab0x41e0f0144FUNC<unknown>DEFAULT3
              strdup.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              strerror_r.symtab0x416010392FUNC<unknown>DEFAULT3
              strlen.symtab0x415c40184FUNC<unknown>DEFAULT3
              strlen.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              strncat.symtab0x41dfe0180FUNC<unknown>DEFAULT3
              strncat.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              strncpy.symtab0x415d00188FUNC<unknown>DEFAULT3
              strncpy.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              strnlen.symtab0x415dc0256FUNC<unknown>DEFAULT3
              strnlen.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              strpbrk.symtab0x41c89064FUNC<unknown>DEFAULT3
              strpbrk.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              strspn.symtab0x41e0a076FUNC<unknown>DEFAULT3
              strspn.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              strstr.symtab0x415ec0256FUNC<unknown>DEFAULT3
              strstr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              strtok.symtab0x41628032FUNC<unknown>DEFAULT3
              strtok.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              strtok_r.symtab0x41c7c0204FUNC<unknown>DEFAULT3
              strtok_r.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              strtol.symtab0x4197d028FUNC<unknown>DEFAULT3
              strtol.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              system.symtab0x419570568FUNC<unknown>DEFAULT3
              system.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              szprintf.symtab0x403538120FUNC<unknown>DEFAULT3
              table.symtab0x483be4232OBJECT<unknown>DEFAULT14
              table.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              table_init.symtab0x4108e01068FUNC<unknown>DEFAULT3
              table_key.symtab0x47cdd04OBJECT<unknown>DEFAULT11
              table_lock_val.symtab0x410d90132FUNC<unknown>DEFAULT3
              table_retrieve_val.symtab0x410e14144FUNC<unknown>DEFAULT3
              table_unlock_val.symtab0x410d0c132FUNC<unknown>DEFAULT3
              tcgetattr.symtab0x4162e0176FUNC<unknown>DEFAULT3
              tcgetattr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              tcpFl00d.symtab0x4065142324FUNC<unknown>DEFAULT3
              tcpcsum.symtab0x405044356FUNC<unknown>DEFAULT3
              time.symtab0x412d8084FUNC<unknown>DEFAULT3
              time.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              times.symtab0x41ac0084FUNC<unknown>DEFAULT3
              times.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              toggle_obf.symtab0x410f6c552FUNC<unknown>DEFAULT3
              tolower.symtab0x41af0060FUNC<unknown>DEFAULT3
              tolower.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              toupper.symtab0x412e8060FUNC<unknown>DEFAULT3
              toupper.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              trim.symtab0x4023f0492FUNC<unknown>DEFAULT3
              type_codes.symtab0x43aa7024OBJECT<unknown>DEFAULT5
              type_sizes.symtab0x43aa8812OBJECT<unknown>DEFAULT5
              udp_flood.symtab0x407a18764FUNC<unknown>DEFAULT3
              udpfl00d.symtab0x4052d02404FUNC<unknown>DEFAULT3
              unknown.1088.symtab0x43ab2014OBJECT<unknown>DEFAULT5
              unsafe_state.symtab0x47d15028OBJECT<unknown>DEFAULT11
              uppercase.symtab0x4042fc164FUNC<unknown>DEFAULT3
              userID.symtab0x47cdb84OBJECT<unknown>DEFAULT11
              usleep.symtab0x419e40144FUNC<unknown>DEFAULT3
              usleep.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              util.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              util_atoi.symtab0x4116c4968FUNC<unknown>DEFAULT3
              util_fdgets.symtab0x41214c320FUNC<unknown>DEFAULT3
              util_isalpha.symtab0x4122f4144FUNC<unknown>DEFAULT3
              util_isdigit.symtab0x412404104FUNC<unknown>DEFAULT3
              util_isspace.symtab0x412384128FUNC<unknown>DEFAULT3
              util_isupper.symtab0x41228c104FUNC<unknown>DEFAULT3
              util_itoa.symtab0x411a8c572FUNC<unknown>DEFAULT3
              util_local_addr.symtab0x411ff8340FUNC<unknown>DEFAULT3
              util_memcpy.symtab0x4115a8164FUNC<unknown>DEFAULT3
              util_memsearch.symtab0x411cc8292FUNC<unknown>DEFAULT3
              util_strcat.symtab0x411500168FUNC<unknown>DEFAULT3
              util_strcmp.symtab0x411354288FUNC<unknown>DEFAULT3
              util_strcpy.symtab0x411474140FUNC<unknown>DEFAULT3
              util_stristr.symtab0x411dec524FUNC<unknown>DEFAULT3
              util_strlen.symtab0x4111a0116FUNC<unknown>DEFAULT3
              util_strncmp.symtab0x411214320FUNC<unknown>DEFAULT3
              util_zero.symtab0x41164c120FUNC<unknown>DEFAULT3
              vfork.symtab0x412de028FUNC<unknown>DEFAULT3
              vfork.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              vfprintf.symtab0x413d80260FUNC<unknown>DEFAULT3
              vfprintf.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              vseattack.symtab0x409b8c2508FUNC<unknown>DEFAULT3
              vsnprintf.symtab0x413690260FUNC<unknown>DEFAULT3
              vsnprintf.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              w.symtab0x48185c4OBJECT<unknown>DEFAULT14
              wait4.symtab0x41ac6088FUNC<unknown>DEFAULT3
              wait4.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              waitpid.symtab0x412e0028FUNC<unknown>DEFAULT3
              waitpid.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              watchdog_maintain.symtab0x402090564FUNC<unknown>DEFAULT3
              watchdog_pid.symtab0x47d8344OBJECT<unknown>DEFAULT14
              wcrtomb.symtab0x41af60112FUNC<unknown>DEFAULT3
              wcrtomb.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              wcsnrtombs.symtab0x41b010228FUNC<unknown>DEFAULT3
              wcsnrtombs.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              wcsrtombs.symtab0x41afd064FUNC<unknown>DEFAULT3
              wcsrtombs.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              whitelist.symtab0x47c5208OBJECT<unknown>DEFAULT11
              wildString.symtab0x403fcc656FUNC<unknown>DEFAULT3
              write.symtab0x412e2084FUNC<unknown>DEFAULT3
              write.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              x.symtab0x4818504OBJECT<unknown>DEFAULT14
              xdigits.3043.symtab0x43b6e417OBJECT<unknown>DEFAULT5
              xstatconv.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
              y.symtab0x4818544OBJECT<unknown>DEFAULT14
              z.symtab0x4818584OBJECT<unknown>DEFAULT14
              zprintf.symtab0x4034c0120FUNC<unknown>DEFAULT3
              TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
              2025-01-08T23:58:01.700499+01002848448ETPRO MALWARE Possible ELF/Various IoT Bot Style Device Checkin (unknown)1192.168.2.1547660154.216.20.706478TCP
              TimestampSource PortDest PortSource IPDest IP
              Jan 8, 2025 23:57:55.311634064 CET395847733192.168.2.1566.59.198.122
              Jan 8, 2025 23:57:55.316495895 CET77333958466.59.198.122192.168.2.15
              Jan 8, 2025 23:57:55.316562891 CET395847733192.168.2.1566.59.198.122
              Jan 8, 2025 23:57:55.322532892 CET395847733192.168.2.1566.59.198.122
              Jan 8, 2025 23:57:55.324054003 CET395847733192.168.2.1566.59.198.122
              Jan 8, 2025 23:57:55.327466011 CET77333958466.59.198.122192.168.2.15
              Jan 8, 2025 23:57:55.370440960 CET77333958466.59.198.122192.168.2.15
              Jan 8, 2025 23:57:55.695990086 CET77333958466.59.198.122192.168.2.15
              Jan 8, 2025 23:57:55.696060896 CET395847733192.168.2.1566.59.198.122
              Jan 8, 2025 23:57:55.728817940 CET395867733192.168.2.1566.59.198.122
              Jan 8, 2025 23:57:55.733609915 CET77333958666.59.198.122192.168.2.15
              Jan 8, 2025 23:57:55.734592915 CET395867733192.168.2.1566.59.198.122
              Jan 8, 2025 23:57:55.753444910 CET395867733192.168.2.1566.59.198.122
              Jan 8, 2025 23:57:55.757982016 CET395867733192.168.2.1566.59.198.122
              Jan 8, 2025 23:57:55.758260965 CET77333958666.59.198.122192.168.2.15
              Jan 8, 2025 23:57:55.806514978 CET77333958666.59.198.122192.168.2.15
              Jan 8, 2025 23:57:56.110125065 CET77333958666.59.198.122192.168.2.15
              Jan 8, 2025 23:57:56.110196114 CET395867733192.168.2.1566.59.198.122
              Jan 8, 2025 23:58:01.690316916 CET476606478192.168.2.15154.216.20.70
              Jan 8, 2025 23:58:01.695171118 CET647847660154.216.20.70192.168.2.15
              Jan 8, 2025 23:58:01.695235968 CET476606478192.168.2.15154.216.20.70
              Jan 8, 2025 23:58:01.695683956 CET476606478192.168.2.15154.216.20.70
              Jan 8, 2025 23:58:01.700458050 CET647847660154.216.20.70192.168.2.15
              Jan 8, 2025 23:58:01.700499058 CET476606478192.168.2.15154.216.20.70
              Jan 8, 2025 23:58:01.705306053 CET647847660154.216.20.70192.168.2.15
              TimestampSource PortDest PortSource IPDest IP
              Jan 9, 2025 00:00:40.775338888 CET5771453192.168.2.151.1.1.1
              Jan 9, 2025 00:00:40.775393963 CET4154853192.168.2.151.1.1.1
              Jan 9, 2025 00:00:40.781919956 CET53415481.1.1.1192.168.2.15
              Jan 9, 2025 00:00:40.782197952 CET53577141.1.1.1192.168.2.15
              TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
              Jan 9, 2025 00:00:40.775338888 CET192.168.2.151.1.1.10x2cabStandard query (0)daisy.ubuntu.comA (IP address)IN (0x0001)false
              Jan 9, 2025 00:00:40.775393963 CET192.168.2.151.1.1.10x26e6Standard query (0)daisy.ubuntu.com28IN (0x0001)false
              TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
              Jan 9, 2025 00:00:40.782197952 CET1.1.1.1192.168.2.150x2cabNo error (0)daisy.ubuntu.com162.213.35.24A (IP address)IN (0x0001)false
              Jan 9, 2025 00:00:40.782197952 CET1.1.1.1192.168.2.150x2cabNo error (0)daisy.ubuntu.com162.213.35.25A (IP address)IN (0x0001)false

              System Behavior

              Start time (UTC):22:57:52
              Start date (UTC):08/01/2025
              Path:/tmp/mippywippy.elf
              Arguments:/tmp/mippywippy.elf
              File size:5773336 bytes
              MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

              Start time (UTC):22:58:00
              Start date (UTC):08/01/2025
              Path:/tmp/mippywippy.elf
              Arguments:-
              File size:5773336 bytes
              MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

              Start time (UTC):22:58:00
              Start date (UTC):08/01/2025
              Path:/tmp/mippywippy.elf
              Arguments:-
              File size:5773336 bytes
              MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

              Start time (UTC):22:58:00
              Start date (UTC):08/01/2025
              Path:/tmp/mippywippy.elf
              Arguments:-
              File size:5773336 bytes
              MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

              Start time (UTC):22:57:54
              Start date (UTC):08/01/2025
              Path:/usr/libexec/gnome-session-binary
              Arguments:-
              File size:334664 bytes
              MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

              Start time (UTC):22:57:54
              Start date (UTC):08/01/2025
              Path:/bin/sh
              Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-rfkill
              File size:129816 bytes
              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

              Start time (UTC):22:57:54
              Start date (UTC):08/01/2025
              Path:/usr/libexec/gsd-rfkill
              Arguments:/usr/libexec/gsd-rfkill
              File size:51808 bytes
              MD5 hash:88a16a3c0aba1759358c06215ecfb5cc

              Start time (UTC):22:57:54
              Start date (UTC):08/01/2025
              Path:/usr/sbin/gdm3
              Arguments:-
              File size:453296 bytes
              MD5 hash:2492e2d8d34f9377e3e530a61a15674f

              Start time (UTC):22:57:54
              Start date (UTC):08/01/2025
              Path:/etc/gdm3/PrimeOff/Default
              Arguments:/etc/gdm3/PrimeOff/Default
              File size:129816 bytes
              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

              Start time (UTC):22:57:54
              Start date (UTC):08/01/2025
              Path:/usr/sbin/gdm3
              Arguments:-
              File size:453296 bytes
              MD5 hash:2492e2d8d34f9377e3e530a61a15674f

              Start time (UTC):22:57:54
              Start date (UTC):08/01/2025
              Path:/etc/gdm3/PrimeOff/Default
              Arguments:/etc/gdm3/PrimeOff/Default
              File size:129816 bytes
              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

              Start time (UTC):22:58:04
              Start date (UTC):08/01/2025
              Path:/usr/lib/systemd/systemd
              Arguments:-
              File size:1620224 bytes
              MD5 hash:9b2bec7092a40488108543f9334aab75

              Start time (UTC):22:58:04
              Start date (UTC):08/01/2025
              Path:/lib/systemd/systemd-user-runtime-dir
              Arguments:/lib/systemd/systemd-user-runtime-dir stop 127
              File size:22672 bytes
              MD5 hash:d55f4b0847f88131dbcfb07435178e54