Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
armhf.elf

Overview

General Information

Sample name:armhf.elf
Analysis ID:1590523
MD5:3f8602925be76474b116cf4b9255aa8d
SHA1:8e667df02d85debe3ad9c7f86716aff6a733cd19
SHA256:bca747b28cbc1fdaea45449dbffceb139cdab55ae7e0a931f07162139526e976
Tags:elfuser-abuse_ch
Infos:

Detection

Score:52
Range:0 - 100
Whitelisted:false

Signatures

Multi AV Scanner detection for submitted file
Contains symbols with names commonly found in malware
Contains symbols related to standard C library sleeps (sometimes used to evade sandboxing)
Sample contains strings that are user agent strings indicative of HTTP manipulation
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

Joe Sandbox version:42.0.0 Malachite
Analysis ID:1590523
Start date and time:2025-01-14 08:26:09 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 10m 23s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:armhf.elf
Detection:MAL
Classification:mal52.linELF@0/0@2/0
Cookbook Comments:
  • Analysis time extended to 480s due to sleep detection in submitted sample
Command:/tmp/armhf.elf
PID:5431
Exit Code:255
Exit Code Info:
Killed:False
Standard Output:

Standard Error:/lib/ld-linux-armhf.so.3: No such file or directory
  • system is lnxubuntu20
  • armhf.elf (PID: 5431, Parent: 5354, MD5: 5ebfcae4fe2471fcc5695c2394773ff1) Arguments: /tmp/armhf.elf
  • cleanup
No yara matches
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: armhf.elfReversingLabs: Detection: 13%
Source: global trafficDNS traffic detected: DNS query: daisy.ubuntu.com

System Summary

barindex
Source: ELF static info symbol of initial sampleName: http_attack
Source: ELF static info symbol of initial sampleName: socket_attack
Source: ELF static info symbol of initial sampleName: syn_attack
Source: ELF static info symbol of initial sampleName: udp_attack
Source: ELF static info symbol of initial sampleName: vse_attack
Source: classification engineClassification label: mal52.linELF@0/0@2/0
Source: ELF symbol in initial sampleSymbol name: sleep
Source: /tmp/armhf.elf (PID: 5431)Queries kernel information via 'uname': Jump to behavior
Source: armhf.elf, 5431.1.00007ffc62130000.00007ffc62151000.rw-.sdmpBinary or memory string: qemu: %s: %s
Source: armhf.elf, 5431.1.00007ffc62130000.00007ffc62151000.rw-.sdmpBinary or memory string: leqemu: %s: %s
Source: armhf.elf, 5431.1.00005610ad3c1000.00005610ad4ef000.rw-.sdmpBinary or memory string: Vrg.qemu.gdb.arm.sys.regs">
Source: armhf.elf, 5431.1.00007ffc62130000.00007ffc62151000.rw-.sdmpBinary or memory string: lx86_64/usr/bin/qemu-arm/tmp/armhf.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/armhf.elf
Source: armhf.elf, 5431.1.00005610ad3c1000.00005610ad4ef000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/arm
Source: armhf.elf, 5431.1.00007ffc62130000.00007ffc62151000.rw-.sdmpBinary or memory string: /usr/bin/qemu-arm
Source: armhf.elf, 5431.1.00005610ad3c1000.00005610ad4ef000.rw-.sdmpBinary or memory string: V!/etc/qemu-binfmt/arm
Source: armhf.elf, 5431.1.00005610ad3c1000.00005610ad4ef000.rw-.sdmpBinary or memory string: rg.qemu.gdb.arm.sys.regs">
Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3
Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:54.0) Gecko/20100101 Firefox/54.0
Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:40.0) Gecko/20100101 Firefox/40.1
Source: Initial sampleUser agent string found: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_6) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/11.1.2 Safari/605.1.15
Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Edge/16.17017
Source: Initial sampleUser agent string found: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
Virtualization/Sandbox Evasion
OS Credential Dumping11
Security Software Discovery
Remote ServicesData from Local System1
Data Obfuscation
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS Memory1
Virtualization/Sandbox Evasion
Remote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
SourceDetectionScannerLabelLink
armhf.elf13%ReversingLabsLinux.Trojan.Mirai
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
daisy.ubuntu.com
162.213.35.25
truefalse
    high
    No contacted IP infos
    No context
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    daisy.ubuntu.comcamp.arm6.elfGet hashmaliciousMiraiBrowse
    • 162.213.35.24
    bin.sh.elfGet hashmaliciousMiraiBrowse
    • 162.213.35.25
    boatnet.ppc.elfGet hashmaliciousMiraiBrowse
    • 162.213.35.24
    boatnet.arm.elfGet hashmaliciousMiraiBrowse
    • 162.213.35.25
    boatnet.arm7.elfGet hashmaliciousMiraiBrowse
    • 162.213.35.25
    boatnet.spc.elfGet hashmaliciousMiraiBrowse
    • 162.213.35.25
    armv6l.elfGet hashmaliciousGafgyt, MiraiBrowse
    • 162.213.35.24
    armv7l.elfGet hashmaliciousGafgyt, MiraiBrowse
    • 162.213.35.24
    mipsel.elfGet hashmaliciousGafgyt, MiraiBrowse
    • 162.213.35.24
    96.62.214.10-boatnet.x86-2025-01-13T13_31_47.elfGet hashmaliciousMiraiBrowse
    • 162.213.35.24
    No context
    No context
    No context
    No created / dropped files found
    File type:ELF 32-bit LSB pie executable, ARM, EABI5 version 1 (SYSV), dynamically linked, interpreter /lib/ld-linux-armhf.so.3, BuildID[sha1]=8cfbde524e5687fff7058eb1236e472295bb1b7b, for GNU/Linux 3.2.0, not stripped
    Entropy (8bit):5.3698340520534344
    TrID:
    • ELF Executable and Linkable format (generic) (4004/1) 100.00%
    File name:armhf.elf
    File size:13'488 bytes
    MD5:3f8602925be76474b116cf4b9255aa8d
    SHA1:8e667df02d85debe3ad9c7f86716aff6a733cd19
    SHA256:bca747b28cbc1fdaea45449dbffceb139cdab55ae7e0a931f07162139526e976
    SHA512:3e45f4a57749a9dccf459d350b69359ce4fc45ebfaf8a69a8fa55182f55e5dde53055563438ee5112f63021175450da7d61c464529abc29eb32ead051e347972
    SSDEEP:192:nBwGIxbwFucX9FopaJRfYXh5pawIUBh7wLr7INMnUQaZ:nhjL+XXI0qLr7pZ
    TLSH:E152D656B29B8D3ACCD4463B05670A794372C0E68D961F1BA10C72B52DD36DCDE26FC8
    File Content Preview:.ELF..............(.....A...4...(0......4. ...(........p................................4...4...4... ... ...............T...T...T.......................................................D...D...D.......................L...L...L.......................p...p..

    ELF header

    Class:ELF32
    Data:2's complement, little endian
    Version:1 (current)
    Machine:ARM
    Version Number:0x1
    Type:DYN (Shared object file)
    OS/ABI:UNIX - System V
    ABI Version:0
    Entry Point Address:0xa41
    Flags:0x5000400
    ELF Header Size:52
    Program Header Offset:52
    Program Header Size:32
    Number of Program Headers:9
    Section Header Offset:12328
    Section Header Size:40
    Number of Section Headers:29
    Header String Table Index:28
    NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
    NULL0x00x00x00x00x0000
    .interpPROGBITS0x1540x1540x190x00x2A001
    .note.gnu.build-idNOTE0x1700x1700x240x00x2A004
    .note.ABI-tagNOTE0x1940x1940x200x00x2A004
    .gnu.hashGNU_HASH0x1b40x1b40x180x40x2A504
    .dynsymDYNSYM0x1cc0x1cc0x2a00x100x2A634
    .dynstrSTRTAB0x46c0x46c0x1b60x00x2A001
    .gnu.versionVERSYM0x6220x6220x540x20x2A502
    .gnu.version_rVERNEED0x6780x6780x600x00x2A624
    .rel.dynREL0x6d80x6d80x780x80x2A504
    .rel.pltREL0x7500x7500x1200x80x42AI5214
    .initPROGBITS0x8700x8700xc0x00x6AX004
    .pltPROGBITS0x87c0x87c0x1c40x40x6AX004
    .textPROGBITS0xa400xa400xf0c0x00x6AX004
    .finiPROGBITS0x194c0x194c0x80x00x6AX004
    .rodataPROGBITS0x19540x19540x4440x00x2A004
    .ARM.exidxARM_EXIDX0x1d980x1d980x80x00x82AL1304
    .eh_framePROGBITS0x1da00x1da00x40x00x2A004
    .init_arrayINIT_ARRAY0x11e440x1e440x40x40x3WA004
    .fini_arrayFINI_ARRAY0x11e480x1e480x40x40x3WA004
    .dynamicDYNAMIC0x11e4c0x1e4c0x1000x80x3WA604
    .gotPROGBITS0x11f4c0x1f4c0xb40x40x3WA004
    .dataPROGBITS0x120000x20000x200x00x3WA004
    .bssNOBITS0x120200x20200xc0x00x3WA004
    .commentPROGBITS0x00x20200x2b0x10x30MS001
    .ARM.attributesARM_ATTRIBUTES0x00x204b0x330x00x0001
    .symtabSYMTAB0x00x20800x9d00x100x027954
    .strtabSTRTAB0x00x2a500x4d00x00x0001
    .shstrtabSTRTAB0x00x2f200x1050x00x0001
    TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
    EXIDX0x1d980x1d980x1d980x80x82.40560x4R 0x4.ARM.exidx
    PHDR0x340x340x340x1200x1202.37110x4R 0x4
    INTERP0x1540x1540x1540x190x194.13370x4R 0x1/lib/ld-linux-armhf.so.3.interp
    LOAD0x00x00x00x1da40x1da46.21130x5R E0x10000.interp .note.gnu.build-id .note.ABI-tag .gnu.hash .dynsym .dynstr .gnu.version .gnu.version_r .rel.dyn .rel.plt .init .plt .text .fini .rodata .ARM.exidx .eh_frame
    LOAD0x1e440x11e440x11e440x1dc0x1e82.71330x6RW 0x10000.init_array .fini_array .dynamic .got .data .bss
    DYNAMIC0x1e4c0x11e4c0x11e4c0x1000x1002.70120x6RW 0x4.dynamic
    NOTE0x1700x1700x1700x440x443.31560x4R 0x4.note.gnu.build-id .note.ABI-tag
    GNU_STACK0x00x00x00x00x00.00000x6RW 0x10
    GNU_RELRO0x1e440x11e440x11e440x1bc0x1bc2.60140x4R 0x1.init_array .fini_array .dynamic .got
    TypeMetaValueTag
    DT_NEEDEDsharedliblibc.so.60x1
    DT_NEEDEDsharedlibld-linux-armhf.so.30x1
    DT_INITvalue0x8700xc
    DT_FINIvalue0x194c0xd
    DT_INIT_ARRAYvalue0x11e440x19
    DT_INIT_ARRAYSZbytes40x1b
    DT_FINI_ARRAYvalue0x11e480x1a
    DT_FINI_ARRAYSZbytes40x1c
    DT_GNU_HASHvalue0x1b40x6ffffef5
    DT_STRTABvalue0x46c0x5
    DT_SYMTABvalue0x1cc0x6
    DT_STRSZbytes4380xa
    DT_SYMENTbytes160xb
    DT_DEBUGvalue0x00x15
    DT_PLTGOTvalue0x11f4c0x3
    DT_PLTRELSZbytes2880x2
    DT_PLTRELpltrelDT_REL0x14
    DT_JMPRELvalue0x7500x17
    DT_RELvalue0x6d80x11
    DT_RELSZbytes1200x12
    DT_RELENTbytes80x13
    DT_FLAGSvalue0x80x1e
    DT_FLAGS_1value0x80000010x6ffffffb
    DT_VERNEEDvalue0x6780x6ffffffe
    DT_VERNEEDNUMvalue20x6fffffff
    DT_VERSYMvalue0x6220x6ffffff0
    DT_RELCOUNTvalue100x6ffffffa
    DT_NULLvalue0x00x0
    NameVersion Info NameVersion Info File NameSection NameValueSizeSymbol TypeSymbol BindSymbol VisibilityNdx
    .dynsym0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
    .dynsym0x8700SECTION<unknown>DEFAULT11
    .dynsym0x120000SECTION<unknown>DEFAULT22
    _ITM_deregisterTMCloneTable.dynsym0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
    _ITM_registerTMCloneTable.dynsym0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
    __cxa_finalizeGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    __gmon_start__.dynsym0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
    __isoc99_sscanfGLIBC_2.7libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    __libc_start_mainGLIBC_2.34libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    __stack_chk_failGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    __stack_chk_guardGLIBC_2.4ld-linux-armhf.so.3.dynsym0x00OBJECT<unknown>DEFAULTSHN_UNDEF
    abortGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    chdirGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    closeGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    connectGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    exitGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    forkGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    freeGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    htonlGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    htonsGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    inet_addrGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    inet_ntoaGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    inet_ptonGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    mallocGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    memsetGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    pthread_cancelGLIBC_2.34libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    pthread_createGLIBC_2.34libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    randGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    recvGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    sendGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    sendtoGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    setsidGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    setsockoptGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    sleepGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    snprintfGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    socketGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    srandGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    strcmpGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    strlenGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    strncmpGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    timeGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    umaskGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
    .symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
    .symtab0x1540SECTION<unknown>DEFAULT1
    .symtab0x1700SECTION<unknown>DEFAULT2
    GLIBC_2.34libc.so.6.symtab0x1940SECTION<unknown>DEFAULT3
    GLIBC_2.4libc.so.6.symtab0x1b40SECTION<unknown>DEFAULT4
    GLIBC_2.4libc.so.6.symtab0x1cc0SECTION<unknown>DEFAULT5
    .symtab0x46c0SECTION<unknown>DEFAULT6
    GLIBC_2.4libc.so.6.symtab0x6220SECTION<unknown>DEFAULT7
    GLIBC_2.4libc.so.6.symtab0x6780SECTION<unknown>DEFAULT8
    GLIBC_2.4ld-linux-armhf.so.3.symtab0x6d80SECTION<unknown>DEFAULT9
    GLIBC_2.4libc.so.6.symtab0x7500SECTION<unknown>DEFAULT10
    GLIBC_2.4libc.so.6.symtab0x8700SECTION<unknown>DEFAULT11
    GLIBC_2.4libc.so.6.symtab0x87c0SECTION<unknown>DEFAULT12
    GLIBC_2.4libc.so.6.symtab0xa400SECTION<unknown>DEFAULT13
    GLIBC_2.4libc.so.6.symtab0x194c0SECTION<unknown>DEFAULT14
    GLIBC_2.4libc.so.6.symtab0x19540SECTION<unknown>DEFAULT15
    GLIBC_2.4libc.so.6.symtab0x1d980SECTION<unknown>DEFAULT16
    GLIBC_2.4libc.so.6.symtab0x1da00SECTION<unknown>DEFAULT17
    .symtab0x11e440SECTION<unknown>DEFAULT18
    GLIBC_2.4libc.so.6.symtab0x11e480SECTION<unknown>DEFAULT19
    GLIBC_2.4libc.so.6.symtab0x11e4c0SECTION<unknown>DEFAULT20
    GLIBC_2.4libc.so.6.symtab0x11f4c0SECTION<unknown>DEFAULT21
    GLIBC_2.4libc.so.6.symtab0x120000SECTION<unknown>DEFAULT22
    GLIBC_2.4libc.so.6.symtab0x120200SECTION<unknown>DEFAULT23
    GLIBC_2.7libc.so.6.symtab0x00SECTION<unknown>DEFAULT24
    GLIBC_2.4libc.so.6.symtab0x00SECTION<unknown>DEFAULT25
    .symtab0x00FILE<unknown>DEFAULTSHN_ABS
    $aGLIBC_2.34libc.so.6.symtab0xa740NOTYPE<unknown>DEFAULT13
    $aGLIBC_2.4libc.so.6.symtab0x8700NOTYPE<unknown>DEFAULT11
    $aGLIBC_2.4libc.so.6.symtab0x194c0NOTYPE<unknown>DEFAULT14
    $aGLIBC_2.4libc.so.6.symtab0x8780NOTYPE<unknown>DEFAULT11
    $a.symtab0x19500NOTYPE<unknown>DEFAULT14
    $a.symtab0x87c0NOTYPE<unknown>DEFAULT12
    $a.symtab0x8900NOTYPE<unknown>DEFAULT12
    $dGLIBC_2.34libc.so.6.symtab0x1940NOTYPE<unknown>DEFAULT3
    $dGLIBC_2.4libc.so.6.symtab0xa6c0NOTYPE<unknown>DEFAULT13
    $dGLIBC_2.4libc.so.6.symtab0x1d980NOTYPE<unknown>DEFAULT16
    $d.symtab0x19540NOTYPE<unknown>DEFAULT15
    $dGLIBC_2.4libc.so.6.symtab0x120000NOTYPE<unknown>DEFAULT22
    $dGLIBC_2.4libc.so.6.symtab0xa900NOTYPE<unknown>DEFAULT13
    $d.symtab0x19580NOTYPE<unknown>DEFAULT15
    $d.symtab0xab40NOTYPE<unknown>DEFAULT13
    $d.symtab0xae80NOTYPE<unknown>DEFAULT13
    $d.symtab0x120040NOTYPE<unknown>DEFAULT22
    $d.symtab0xb240NOTYPE<unknown>DEFAULT13
    $d.symtab0x11e480NOTYPE<unknown>DEFAULT19
    $d.symtab0x11e440NOTYPE<unknown>DEFAULT18
    $d.symtab0x120200NOTYPE<unknown>DEFAULT23
    $d.symtab0x19e80NOTYPE<unknown>DEFAULT15
    $d.symtab0xbac0NOTYPE<unknown>DEFAULT13
    $d.symtab0xc580NOTYPE<unknown>DEFAULT13
    $d.symtab0xd080NOTYPE<unknown>DEFAULT13
    $d.symtab0x109c0NOTYPE<unknown>DEFAULT13
    $d.symtab0x120080NOTYPE<unknown>DEFAULT22
    $d.symtab0x12e00NOTYPE<unknown>DEFAULT13
    $d.symtab0x16980NOTYPE<unknown>DEFAULT13
    $d.symtab0x193c0NOTYPE<unknown>DEFAULT13
    $d.symtab0x120240NOTYPE<unknown>DEFAULT23
    $d.symtab0x1d080NOTYPE<unknown>DEFAULT15
    $d.symtab0x1da00NOTYPE<unknown>DEFAULT17
    $d.symtab0x88c0NOTYPE<unknown>DEFAULT12
    $tGLIBC_2.4libc.so.6.symtab0xa400NOTYPE<unknown>DEFAULT13
    $t.symtab0xa980NOTYPE<unknown>DEFAULT13
    $t.symtab0xac40NOTYPE<unknown>DEFAULT13
    $t.symtab0xaf80NOTYPE<unknown>DEFAULT13
    $t.symtab0xb380NOTYPE<unknown>DEFAULT13
    $t.symtab0xb3c0NOTYPE<unknown>DEFAULT13
    $t.symtab0xbb00NOTYPE<unknown>DEFAULT13
    $t.symtab0xc640NOTYPE<unknown>DEFAULT13
    $t.symtab0xd180NOTYPE<unknown>DEFAULT13
    $t.symtab0x10ac0NOTYPE<unknown>DEFAULT13
    $t.symtab0x12f40NOTYPE<unknown>DEFAULT13
    $t.symtab0x17780NOTYPE<unknown>DEFAULT13
    Scrt1.oGLIBC_2.4libc.so.6.symtab0x00FILE<unknown>DEFAULTSHN_ABS
    _DYNAMIC.symtab0x11e4c0OBJECT<unknown>DEFAULTSHN_ABS
    _GLOBAL_OFFSET_TABLE_.symtab0x11f4c0OBJECT<unknown>DEFAULTSHN_ABS
    _IO_stdin_used.symtab0x19544OBJECT<unknown>DEFAULT15
    _ITM_deregisterTMCloneTable.symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
    _ITM_registerTMCloneTable.symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
    __FRAME_END__.symtab0x1da00OBJECT<unknown>DEFAULT17
    __TMC_END__.symtab0x120200OBJECT<unknown>HIDDEN22
    __abi_tagGLIBC_2.4libc.so.6.symtab0x19432OBJECT<unknown>DEFAULT3
    __bss_end__.symtab0x1202c0NOTYPE<unknown>DEFAULT23
    __bss_start.symtab0x120200NOTYPE<unknown>DEFAULT23
    __bss_start__.symtab0x120200NOTYPE<unknown>DEFAULT23
    __cxa_finalize@GLIBC_2.4.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
    __data_start.symtab0x120000NOTYPE<unknown>DEFAULT22
    __do_global_dtors_aux.symtab0xaf90FUNC<unknown>DEFAULT13
    __do_global_dtors_aux_fini_array_entry.symtab0x11e480OBJECT<unknown>DEFAULT19
    __dso_handle.symtab0x120040OBJECT<unknown>HIDDEN22
    __end__.symtab0x1202c0NOTYPE<unknown>DEFAULT23
    __frame_dummy_init_array_entry.symtab0x11e440OBJECT<unknown>DEFAULT18
    __gmon_start__.symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
    __isoc99_sscanf@GLIBC_2.7.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
    __libc_start_main@GLIBC_2.34.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
    __stack_chk_fail@GLIBC_2.4.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
    __stack_chk_guard@GLIBC_2.4.symtab0x00OBJECT<unknown>DEFAULTSHN_UNDEF
    _bss_end__.symtab0x1202c0NOTYPE<unknown>DEFAULT23
    _edata.symtab0x120200NOTYPE<unknown>DEFAULT22
    _end.symtab0x1202c0NOTYPE<unknown>DEFAULT23
    _fini.symtab0x194c0FUNC<unknown>HIDDEN14
    _init.symtab0x8700FUNC<unknown>HIDDEN11
    _start.symtab0xa410FUNC<unknown>DEFAULT13
    abort@GLIBC_2.4.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
    all_implied_fbits.symtab0x19580OBJECT<unknown>DEFAULT15
    all_implied_fbits.symtab0x1d080OBJECT<unknown>DEFAULT15
    bot.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
    call_weak_fnGLIBC_2.4libc.so.6.symtab0xa740FUNC<unknown>DEFAULT13
    chdir@GLIBC_2.4.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
    close@GLIBC_2.4.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
    completed.0.symtab0x120201OBJECT<unknown>DEFAULT23
    connect@GLIBC_2.4.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
    crti.oGLIBC_2.4libc.so.6.symtab0x00FILE<unknown>DEFAULTSHN_ABS
    crtn.oGLIBC_2.4libc.so.6.symtab0x00FILE<unknown>DEFAULTSHN_ABS
    crtstuff.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
    crtstuff.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
    daemonize.symtab0xb3d116FUNC<unknown>DEFAULT13
    data_start.symtab0x120000NOTYPE<unknown>DEFAULT22
    deregister_tm_clones.symtab0xa990FUNC<unknown>DEFAULT13
    exit@GLIBC_2.4.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
    fork@GLIBC_2.4.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
    frame_dummy.symtab0xb390FUNC<unknown>DEFAULT13
    free@GLIBC_2.4.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
    handle_command.symtab0x12f51156FUNC<unknown>DEFAULT13
    htonl@GLIBC_2.4.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
    htons@GLIBC_2.4.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
    http_attack.symtab0x1109492FUNC<unknown>DEFAULT13
    inet_addr@GLIBC_2.4.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
    inet_ntoa@GLIBC_2.4.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
    inet_pton@GLIBC_2.4.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
    main.symtab0x1779468FUNC<unknown>DEFAULT13
    malloc@GLIBC_2.4.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
    memset@GLIBC_2.4.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
    params.1.symtab0x120244OBJECT<unknown>DEFAULT23
    pthread_cancel@GLIBC_2.34.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
    pthread_create@GLIBC_2.34.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
    rand@GLIBC_2.4.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
    recv@GLIBC_2.4.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
    register_tm_clones.symtab0xac50FUNC<unknown>DEFAULT13
    send@GLIBC_2.4.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
    sendto@GLIBC_2.4.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
    setsid@GLIBC_2.4.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
    setsockopt@GLIBC_2.4.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
    sleep@GLIBC_2.4.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
    snprintf@GLIBC_2.4.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
    socket@GLIBC_2.4.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
    socket_attack.symtab0x10ad92FUNC<unknown>DEFAULT13
    srand@GLIBC_2.4.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
    strcmp@GLIBC_2.4.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
    strlen@GLIBC_2.4.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
    strncmp@GLIBC_2.4.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
    syn_attack.symtab0xd19916FUNC<unknown>DEFAULT13
    threads.0.symtab0x120284OBJECT<unknown>DEFAULT23
    time@GLIBC_2.4.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
    udp_attack.symtab0xbb1180FUNC<unknown>DEFAULT13
    umask@GLIBC_2.4.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
    vse_attack.symtab0xc65180FUNC<unknown>DEFAULT13
    TimestampSource PortDest PortSource IPDest IP
    Jan 14, 2025 08:29:37.566682100 CET5909653192.168.2.138.8.8.8
    Jan 14, 2025 08:29:37.566682100 CET6092453192.168.2.138.8.8.8
    Jan 14, 2025 08:29:37.573209047 CET53590968.8.8.8192.168.2.13
    Jan 14, 2025 08:29:37.573313951 CET53609248.8.8.8192.168.2.13
    TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
    Jan 14, 2025 08:29:37.566682100 CET192.168.2.138.8.8.80xf15dStandard query (0)daisy.ubuntu.comA (IP address)IN (0x0001)false
    Jan 14, 2025 08:29:37.566682100 CET192.168.2.138.8.8.80x7786Standard query (0)daisy.ubuntu.com28IN (0x0001)false
    TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
    Jan 14, 2025 08:29:37.573209047 CET8.8.8.8192.168.2.130xf15dNo error (0)daisy.ubuntu.com162.213.35.25A (IP address)IN (0x0001)false
    Jan 14, 2025 08:29:37.573209047 CET8.8.8.8192.168.2.130xf15dNo error (0)daisy.ubuntu.com162.213.35.24A (IP address)IN (0x0001)false

    System Behavior

    Start time (UTC):07:26:51
    Start date (UTC):14/01/2025
    Path:/tmp/armhf.elf
    Arguments:/tmp/armhf.elf
    File size:4956856 bytes
    MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1