Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
libsocks5.so

Overview

General Information

Sample name:libsocks5.so
Analysis ID:1589868
MD5:2e1de0479d6c58ad69432064b2868548
SHA1:f19f76af000ce95ea0d18fe5036c60b25d738546
SHA256:aae291ac5767cfe93676dacb67ba50c98d8fd520f5821fb050fd63e38b000b18
Infos:

Detection

Score:48
Range:0 - 100
Whitelisted:false

Signatures

Malicious sample detected (through community Yara rule)
Contains symbols related to standard C library sleeps (sometimes used to evade sandboxing)
Sample and/or dropped files contains symbols with suspicious names
Sample has stripped symbol table
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)
Yara signature match

Classification

Joe Sandbox version:42.0.0 Malachite
Analysis ID:1589868
Start date and time:2025-01-13 09:31:48 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 10m 29s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Run name:Potential for more IOCs and behavior
Analysis Mode:default
Sample name:libsocks5.so
Detection:MAL
Classification:mal48.linSO@0/0@0/0
Cookbook Comments:
  • Analysis time extended to 480s due to sleep detection in submitted sample
Command:/tmp/libsocks5.so
PID:6218
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:

Standard Error:
  • system is lnxubuntu20
  • libsocks5.so (PID: 6218, Parent: 6135, MD5: 2e1de0479d6c58ad69432064b2868548) Arguments: /tmp/libsocks5.so
  • cleanup
SourceRuleDescriptionAuthorStrings
libsocks5.soM_Hunting_Linux_Funchookunknownunknown
  • 0x10eb:$f: funchook_
  • 0x96862:$f: funchook_
  • 0x9687e:$f: funchook_
  • 0x9689e:$f: funchook_
  • 0x968c2:$f: funchook_
  • 0x968f6:$f: funchook_
  • 0x96932:$f: funchook_
  • 0x96972:$f: funchook_
  • 0x96996:$f: funchook_
  • 0x969b6:$f: funchook_
  • 0x969da:$f: funchook_
  • 0x969fc:$f: funchook_
  • 0x96a1a:$f: funchook_
  • 0x9685c:$s1: Enter funchook_create()
  • 0x96878:$s2: Leave funchook_create() => %p
  • 0x96898:$s3: Enter funchook_prepare(%p, %p, %p)
  • 0x968bc:$s4: Leave funchook_prepare(..., [%p->%p],...) => %d
  • 0x9696c:$s5: Enter funchook_install(%p, 0x%x)
  • 0x96990:$s6: Leave funchook_install() => %d
  • 0x969b0:$s7: Enter funchook_uninstall(%p, 0x%x)
  • 0x969d4:$s8: Leave funchook_uninstall() => %d
SourceRuleDescriptionAuthorStrings
6218.1.000000005655a000.0000000056625000.r-x.sdmpM_Hunting_Linux_Funchookunknownunknown
  • 0x10eb:$f: funchook_
  • 0x96862:$f: funchook_
  • 0x9687e:$f: funchook_
  • 0x9689e:$f: funchook_
  • 0x968c2:$f: funchook_
  • 0x968f6:$f: funchook_
  • 0x96932:$f: funchook_
  • 0x96972:$f: funchook_
  • 0x96996:$f: funchook_
  • 0x969b6:$f: funchook_
  • 0x969da:$f: funchook_
  • 0x969fc:$f: funchook_
  • 0x96a1a:$f: funchook_
  • 0x9685c:$s1: Enter funchook_create()
  • 0x96878:$s2: Leave funchook_create() => %p
  • 0x96898:$s3: Enter funchook_prepare(%p, %p, %p)
  • 0x968bc:$s4: Leave funchook_prepare(..., [%p->%p],...) => %d
  • 0x9696c:$s5: Enter funchook_install(%p, 0x%x)
  • 0x96990:$s6: Leave funchook_install() => %d
  • 0x969b0:$s7: Enter funchook_uninstall(%p, 0x%x)
  • 0x969d4:$s8: Leave funchook_uninstall() => %d
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results
Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: libsocks5.soELF static info symbol of initial sample: freeaddrinfo
Source: libsocks5.soELF static info symbol of initial sample: getaddrinfo
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443

System Summary

barindex
Source: libsocks5.so, type: SAMPLEMatched rule: M_Hunting_Linux_Funchook Author: unknown
Source: 6218.1.000000005655a000.0000000056625000.r-x.sdmp, type: MEMORYMatched rule: M_Hunting_Linux_Funchook Author: unknown
Source: libsocks5.soELF static info symbol of initial sample: funchook_hook_caller_asm
Source: ELF static info symbol of initial sample.symtab present: no
Source: libsocks5.so, type: SAMPLEMatched rule: M_Hunting_Linux_Funchook =
Source: 6218.1.000000005655a000.0000000056625000.r-x.sdmp, type: MEMORYMatched rule: M_Hunting_Linux_Funchook =
Source: classification engineClassification label: mal48.linSO@0/0@0/0
Source: ELF symbol in initial sampleSymbol name: nanosleep
Source: ELF symbol in initial sampleSymbol name: usleep
Source: /tmp/libsocks5.so (PID: 6218)Queries kernel information via 'uname': Jump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
Masquerading
OS Credential Dumping1
Security Software Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Virtualization/Sandbox Evasion
LSASS Memory1
Virtualization/Sandbox Evasion
Remote Desktop ProtocolData from Removable Media1
Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs
IPDomainCountryFlagASNASN NameMalicious
109.202.202.202
unknownSwitzerland
13030INIT7CHfalse
91.189.91.43
unknownUnited Kingdom
41231CANONICAL-ASGBfalse
91.189.91.42
unknownUnited Kingdom
41231CANONICAL-ASGBfalse
MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
  • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
91.189.91.43g1.elfGet hashmaliciousUnknownBrowse
    na.elfGet hashmaliciousPrometeiBrowse
      g2.elfGet hashmaliciousUnknownBrowse
        arm5.elfGet hashmaliciousMiraiBrowse
          boatnet.spc.elfGet hashmaliciousMiraiBrowse
            boatnet.arm7.elfGet hashmaliciousMiraiBrowse
              boatnet.x86.elfGet hashmaliciousMiraiBrowse
                t1.elfGet hashmaliciousUnknownBrowse
                  t3.elfGet hashmaliciousUnknownBrowse
                    12.elfGet hashmaliciousUnknownBrowse
                      91.189.91.42g1.elfGet hashmaliciousUnknownBrowse
                        na.elfGet hashmaliciousPrometeiBrowse
                          g2.elfGet hashmaliciousUnknownBrowse
                            arm5.elfGet hashmaliciousMiraiBrowse
                              boatnet.spc.elfGet hashmaliciousMiraiBrowse
                                boatnet.arm7.elfGet hashmaliciousMiraiBrowse
                                  boatnet.x86.elfGet hashmaliciousMiraiBrowse
                                    t1.elfGet hashmaliciousUnknownBrowse
                                      t3.elfGet hashmaliciousUnknownBrowse
                                        12.elfGet hashmaliciousUnknownBrowse
                                          No context
                                          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                          CANONICAL-ASGBg1.elfGet hashmaliciousUnknownBrowse
                                          • 91.189.91.42
                                          na.elfGet hashmaliciousPrometeiBrowse
                                          • 91.189.91.42
                                          g2.elfGet hashmaliciousUnknownBrowse
                                          • 91.189.91.42
                                          arm5.elfGet hashmaliciousMiraiBrowse
                                          • 91.189.91.42
                                          t6.elfGet hashmaliciousUnknownBrowse
                                          • 185.125.190.26
                                          boatnet.spc.elfGet hashmaliciousMiraiBrowse
                                          • 91.189.91.42
                                          boatnet.arm7.elfGet hashmaliciousMiraiBrowse
                                          • 91.189.91.42
                                          boatnet.arc.elfGet hashmaliciousMiraiBrowse
                                          • 185.125.190.26
                                          boatnet.arm6.elfGet hashmaliciousMiraiBrowse
                                          • 185.125.190.26
                                          boatnet.x86.elfGet hashmaliciousMiraiBrowse
                                          • 91.189.91.42
                                          CANONICAL-ASGBg1.elfGet hashmaliciousUnknownBrowse
                                          • 91.189.91.42
                                          na.elfGet hashmaliciousPrometeiBrowse
                                          • 91.189.91.42
                                          g2.elfGet hashmaliciousUnknownBrowse
                                          • 91.189.91.42
                                          arm5.elfGet hashmaliciousMiraiBrowse
                                          • 91.189.91.42
                                          t6.elfGet hashmaliciousUnknownBrowse
                                          • 185.125.190.26
                                          boatnet.spc.elfGet hashmaliciousMiraiBrowse
                                          • 91.189.91.42
                                          boatnet.arm7.elfGet hashmaliciousMiraiBrowse
                                          • 91.189.91.42
                                          boatnet.arc.elfGet hashmaliciousMiraiBrowse
                                          • 185.125.190.26
                                          boatnet.arm6.elfGet hashmaliciousMiraiBrowse
                                          • 185.125.190.26
                                          boatnet.x86.elfGet hashmaliciousMiraiBrowse
                                          • 91.189.91.42
                                          INIT7CHg1.elfGet hashmaliciousUnknownBrowse
                                          • 109.202.202.202
                                          na.elfGet hashmaliciousPrometeiBrowse
                                          • 109.202.202.202
                                          g2.elfGet hashmaliciousUnknownBrowse
                                          • 109.202.202.202
                                          arm5.elfGet hashmaliciousMiraiBrowse
                                          • 109.202.202.202
                                          boatnet.spc.elfGet hashmaliciousMiraiBrowse
                                          • 109.202.202.202
                                          boatnet.arm7.elfGet hashmaliciousMiraiBrowse
                                          • 109.202.202.202
                                          boatnet.x86.elfGet hashmaliciousMiraiBrowse
                                          • 109.202.202.202
                                          t1.elfGet hashmaliciousUnknownBrowse
                                          • 109.202.202.202
                                          t3.elfGet hashmaliciousUnknownBrowse
                                          • 109.202.202.202
                                          12.elfGet hashmaliciousUnknownBrowse
                                          • 109.202.202.202
                                          No context
                                          No context
                                          No created / dropped files found
                                          File type:ELF 32-bit LSB pie executable, Intel 80386, version 1 (SYSV), dynamically linked, interpreter /lib/ld-linux.so.2, for GNU/Linux 2.6.16, stripped
                                          Entropy (8bit):6.340017572899933
                                          TrID:
                                          • ELF Executable and Linkable format (Linux) (4029/14) 49.77%
                                          • ELF Executable and Linkable format (generic) (4004/1) 49.46%
                                          • Lumena CEL bitmap (63/63) 0.78%
                                          File name:libsocks5.so
                                          File size:881'224 bytes
                                          MD5:2e1de0479d6c58ad69432064b2868548
                                          SHA1:f19f76af000ce95ea0d18fe5036c60b25d738546
                                          SHA256:aae291ac5767cfe93676dacb67ba50c98d8fd520f5821fb050fd63e38b000b18
                                          SHA512:7c771685c40ddaa0e0238d57d2a7999bbe0e76492ab42e43161d87161180d05fc724fe834d3d0e3ce5c5b24f5014ef908af7a8701fdc0107c8798384805f776f
                                          SSDEEP:24576:K9T8PEQ/TmSroL9Ao+ueIg4422mFuG6W:KBSropA3YuXW
                                          TLSH:8F150911F691C07AE06262B5418DD177E3619B27407B995BEC8E0C28F7292128E77BFF
                                          File Content Preview:.ELF....................@V..4...pm......4. ...(.........4...4...4....................................................................A...A...............P...P...P.......................`...`...`...O...O..............l...l...l..............................

                                          ELF header

                                          Class:ELF32
                                          Data:2's complement, little endian
                                          Version:1 (current)
                                          Machine:Intel 80386
                                          Version Number:0x1
                                          Type:DYN (Shared object file)
                                          OS/ABI:UNIX - System V
                                          ABI Version:0
                                          Entry Point Address:0x5640
                                          Flags:0x0
                                          ELF Header Size:52
                                          Program Header Offset:52
                                          Program Header Size:32
                                          Number of Program Headers:12
                                          Section Header Offset:879984
                                          Section Header Size:40
                                          Number of Section Headers:31
                                          Header String Table Index:30
                                          NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                          NULL0x00x00x00x00x0000
                                          .interpPROGBITS0x1b40x1b40x130x00x2A001
                                          .note.gnu.propertyNOTE0x1c80x1c80x280x00x2A004
                                          .note.ABI-tagNOTE0x1f00x1f00x200x00x2A004
                                          .hashHASH0x2100x2100x35c0x40x2A604
                                          .gnu.hashGNU_HASH0x56c0x56c0x600x40x2A604
                                          .dynsymDYNSYM0x5cc0x5cc0x7400x100x2A714
                                          .dynstrSTRTAB0xd0c0xd0c0x4740x00x2A001
                                          .gnu.versionVERSYM0x11800x11800xe80x20x2A602
                                          .gnu.version_rVERNEED0x12680x12680x1000x00x2A754
                                          .rel.dynREL0x13680x13680x2b280x80x2A604
                                          .rel.pltREL0x3e900x3e900x2f80x80x42AI6264
                                          .initPROGBITS0x50000x50000x2d0x00x6AX004
                                          .pltPROGBITS0x50300x50300x6000x40x6AX0016
                                          .plt.gotPROGBITS0x56300x56300x100x80x6AX008
                                          .textPROGBITS0x56400x56400x9055e0x00x6AX0016
                                          .finiPROGBITS0x95ba00x95ba00x190x00x6AX004
                                          .rodataPROGBITS0x960000x960000x1dffc0x00x2A0032
                                          .eh_frame_hdrPROGBITS0xb3ffc0xb3ffc0x43cc0x00x2A004
                                          .eh_framePROGBITS0xb83c80xb83c80x12bcc0x00x2A004
                                          .init_arrayINIT_ARRAY0xcc86c0xcb86c0x40x40x3WA004
                                          .ctorsPROGBITS0xcc8700xcb8700x80x00x3WA004
                                          .dtorsPROGBITS0xcc8780xcb8780x80x00x3WA004
                                          .data.rel.roPROGBITS0xcc8800xcb8800x36400x00x3WA0032
                                          .dynamicDYNAMIC0xcfec00xceec00x1080x80x3WA704
                                          .gotPROGBITS0xcffc80xcefc80x1c0x40x3WA004
                                          .got.pltPROGBITS0xd00000xcf0000x1880x40x3WA004
                                          .dataPROGBITS0xd01a00xcf1a00x7ab80x00x3WA0032
                                          .bssNOBITS0xd7c600xd6c580x146900x00x3WA0032
                                          .commentPROGBITS0x00xd6c580x120x10x30MS001
                                          .shstrtabSTRTAB0x00xd6c6a0x1040x00x0001
                                          TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                          PHDR0x340x340x340x1800x1803.02640x4R 0x4
                                          INTERP0x1b40x1b40x1b40x130x133.68190x4R 0x1/lib/ld-linux.so.2.interp
                                          LOAD0x00x00x00x41880x41883.78590x4R 0x1000.interp .note.gnu.property .note.ABI-tag .hash .gnu.hash .dynsym .dynstr .gnu.version .gnu.version_r .rel.dyn .rel.plt
                                          LOAD0x50000x50000x50000x90bb90x90bb96.08460x5R E0x1000.init .plt .plt.got .text .fini
                                          LOAD0x960000x960000x960000x34f940x34f946.50020x4R 0x1000.rodata .eh_frame_hdr .eh_frame
                                          LOAD0xcb86c0xcc86c0xcc86c0xb3ec0x1fa844.47330x6RW 0x1000.init_array .ctors .dtors .data.rel.ro .dynamic .got .got.plt .data .bss
                                          DYNAMIC0xceec00xcfec00xcfec00x1080x1082.76170x6RW 0x4.dynamic
                                          NOTE0x1c80x1c80x1c80x480x482.10500x4R 0x4.note.gnu.property .note.ABI-tag
                                          GNU_PROPERTY0x1c80x1c80x1c80x280x282.20210x4R 0x4.note.gnu.property
                                          GNU_EH_FRAME0xb3ffc0xb3ffc0xb3ffc0x43cc0x43cc6.12430x4R 0x4.eh_frame_hdr
                                          GNU_STACK0x00x00x00x00x00.00000x7RWE0x10
                                          GNU_RELRO0xcb86c0xcc86c0xcc86c0x37940x37944.12300x4R 0x1.init_array .ctors .dtors .data.rel.ro .dynamic .got
                                          TypeMetaValueTag
                                          DT_NEEDEDsharedliblibpthread.so.00x1
                                          DT_NEEDEDsharedliblibdl.so.20x1
                                          DT_NEEDEDsharedliblibrt.so.10x1
                                          DT_NEEDEDsharedliblibc.so.60x1
                                          DT_NEEDEDsharedlibld-linux.so.20x1
                                          DT_INITvalue0x50000xc
                                          DT_FINIvalue0x95ba00xd
                                          DT_INIT_ARRAYvalue0xcc86c0x19
                                          DT_INIT_ARRAYSZbytes40x1b
                                          DT_HASHvalue0x2100x4
                                          DT_GNU_HASHvalue0x56c0x6ffffef5
                                          DT_STRTABvalue0xd0c0x5
                                          DT_SYMTABvalue0x5cc0x6
                                          DT_STRSZbytes11400xa
                                          DT_SYMENTbytes160xb
                                          DT_DEBUGvalue0x00x15
                                          DT_PLTGOTvalue0xd00000x3
                                          DT_PLTRELSZbytes7600x2
                                          DT_PLTRELpltrelDT_REL0x14
                                          DT_JMPRELvalue0x3e900x17
                                          DT_RELvalue0x13680x11
                                          DT_RELSZbytes110480x12
                                          DT_RELENTbytes80x13
                                          DT_FLAGS_1value0x80000000x6ffffffb
                                          DT_VERNEEDvalue0x12680x6ffffffe
                                          DT_VERNEEDNUMvalue50x6fffffff
                                          DT_VERSYMvalue0x11800x6ffffff0
                                          DT_RELCOUNTvalue13740x6ffffffa
                                          DT_NULLvalue0x00x0
                                          NameVersion Info NameVersion Info File NameSection NameValueSizeSymbol TypeSymbol BindSymbol VisibilityNdx
                                          .dynsym0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                          _IO_stdin_used.dynsym0x960044OBJECT<unknown>DEFAULT17
                                          _ITM_deregisterTMCloneTable.dynsym0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                          _ITM_registerTMCloneTable.dynsym0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                          __bss_start.dynsym0xd7c580NOTYPE<unknown>DEFAULT28
                                          __cxa_finalizeGLIBC_2.1.3libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          __data_start.dynsym0xd01a00NOTYPE<unknown>DEFAULT27
                                          __errno_locationGLIBC_2.0libpthread.so.0.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          __gmon_start__.dynsym0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                          __libc_csu_fini.dynsym0x95b401FUNC<unknown>DEFAULT15
                                          __libc_csu_init.dynsym0x95ae093FUNC<unknown>DEFAULT15
                                          __libc_start_mainGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          __prognameGLIBC_2.0libc.so.6.dynsym0x00OBJECT<unknown>DEFAULTSHN_UNDEF
                                          __sysv_signalGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          __xstatGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          _edata.dynsym0xd7c580NOTYPE<unknown>DEFAULT27
                                          _end.dynsym0xec2f00NOTYPE<unknown>DEFAULT28
                                          _fini.dynsym0x95ba00FUNC<unknown>DEFAULT16
                                          _fp_hw.dynsym0x960004OBJECT<unknown>DEFAULT17
                                          _init.dynsym0x50000FUNC<unknown>DEFAULT12
                                          _r_debugGLIBC_2.0ld-linux.so.2.dynsym0x00OBJECT<unknown>DEFAULTSHN_UNDEF
                                          _start.dynsym0x56400FUNC<unknown>DEFAULT15
                                          acceptGLIBC_2.0libpthread.so.0.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          bindGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          callocGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          clock_gettimeGLIBC_2.2librt.so.1.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          closeGLIBC_2.0libpthread.so.0.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          closedirGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          connectGLIBC_2.0libpthread.so.0.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          data_start.dynsym0xd01a00NOTYPE<unknown>DEFAULT27
                                          dlsymGLIBC_2.0libdl.so.2.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          fcloseGLIBC_2.1libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          fcntlGLIBC_2.0libpthread.so.0.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          ferrorGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          fflushGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          fgetcGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          fgetposGLIBC_2.2libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          fgetsGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          fopenGLIBC_2.1libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          fputcGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          freadGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          freeGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          freeaddrinfoGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          fseekGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          fsetposGLIBC_2.2libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          ftellGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          funchook_hook_caller_asm.dynsym0xc4f031FUNC<unknown>DEFAULT15
                                          fwriteGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          getaddrinfoGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          getpidGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          getsocknameGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          getsockoptGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          gmtime_rGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          htonsGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          inet_ntopGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          inet_ptonGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          listenGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          memcmpGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          memcpyGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          memmoveGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          memsetGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          mmapGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          mprotectGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          munmapGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          nanosleepGLIBC_2.0libpthread.so.0.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          opendirGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          pollGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          printfGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          program_invocation_short_nameGLIBC_2.0libc.so.6.dynsym0x00OBJECT<unknown>DEFAULTSHN_UNDEF
                                          pthread_attr_destroyGLIBC_2.0libpthread.so.0.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          pthread_attr_initGLIBC_2.1libpthread.so.0.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          pthread_attr_setstacksizeGLIBC_2.1libpthread.so.0.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          pthread_createGLIBC_2.1libpthread.so.0.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          pthread_detachGLIBC_2.0libpthread.so.0.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          ptraceGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          putcharGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          putsGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          randGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          readGLIBC_2.0libpthread.so.0.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          readdirGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          readlinkGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          reallocGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          realpathGLIBC_2.3libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          recvGLIBC_2.0libpthread.so.0.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          recvfromGLIBC_2.0libpthread.so.0.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          regcompGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          regexecGLIBC_2.3.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          regfreeGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          removeGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          renameGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          selectGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          sendGLIBC_2.0libpthread.so.0.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          setbufGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          setsockoptGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          shutdownGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          snprintfGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          socketGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          sprintfGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          sscanfGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          strchrGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          strcmpGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          strerrorGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          strerror_rGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          strlenGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          strncmpGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          strncpyGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          strstrGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          strtokGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          strtoulGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          sysconfGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          timeGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          usleepGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          vfprintfGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          vsnprintfGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          waitpidGLIBC_2.0libpthread.so.0.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          writeGLIBC_2.0libpthread.so.0.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          TimestampSource PortDest PortSource IPDest IP
                                          Jan 13, 2025 09:32:33.196398020 CET42836443192.168.2.2391.189.91.43
                                          Jan 13, 2025 09:32:34.732043982 CET4251680192.168.2.23109.202.202.202
                                          Jan 13, 2025 09:32:48.042081118 CET43928443192.168.2.2391.189.91.42
                                          Jan 13, 2025 09:33:00.328273058 CET42836443192.168.2.2391.189.91.43
                                          Jan 13, 2025 09:33:04.423835039 CET4251680192.168.2.23109.202.202.202
                                          Jan 13, 2025 09:33:28.996047020 CET43928443192.168.2.2391.189.91.42

                                          System Behavior

                                          Start time (UTC):08:32:28
                                          Start date (UTC):13/01/2025
                                          Path:/tmp/libsocks5.so
                                          Arguments:/tmp/libsocks5.so
                                          File size:881224 bytes
                                          MD5 hash:2e1de0479d6c58ad69432064b2868548