Create Interactive Tour

Linux Analysis Report
psmips.elf

Overview

General Information

Sample name:psmips.elf
Analysis ID:1644216
MD5:2ef51410690dc12a309cc8b0aa59a294
SHA1:b4b5c0a8ed4d01b637556826afffd87c831ca543
SHA256:f7b791cd1a116eaecf3a2bb4d63077f02e19af185b036058f4f42f24d52979f9
Tags:elfuser-abuse_ch
Infos:

Detection

Score:56
Range:0 - 100

Signatures

Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Enumerates processes within the "proc" file system
Executes commands using a shell command-line interpreter
Executes the "ps" command used to list the status of processes
Executes the "rm" command used to delete files or directories
Reads CPU information from /sys indicative of miner or evasive malware
Reads system information from the proc file system
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
Joe Sandbox version:42.0.0 Malachite
Analysis ID:1644216
Start date and time:2025-03-20 13:06:42 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 36s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:psmips.elf
Detection:MAL
Classification:mal56.linELF@0/0@0/0
  • Report size exceeded maximum capacity and may have missing behavior information.
Command:/tmp/psmips.elf
PID:5481
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:

Standard Error:
  • system is lnxubuntu20
  • psmips.elf (PID: 5481, Parent: 5406, MD5: 0083f1f0e77be34ad27f849842bbb00c) Arguments: /tmp/psmips.elf
    • psmips.elf New Fork (PID: 5483, Parent: 5481)
      • sh (PID: 5489, Parent: 5483, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "ps w"
        • sh New Fork (PID: 5491, Parent: 5489)
        • ps (PID: 5491, Parent: 5489, MD5: ab48054475a6f70f8e7fa847331f3327) Arguments: ps w
      • sh (PID: 5492, Parent: 5483, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "ps w"
        • sh New Fork (PID: 5497, Parent: 5492)
        • ps (PID: 5497, Parent: 5492, MD5: ab48054475a6f70f8e7fa847331f3327) Arguments: ps w
      • sh (PID: 5500, Parent: 5483, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "ps w"
        • sh New Fork (PID: 5502, Parent: 5500)
        • ps (PID: 5502, Parent: 5500, MD5: ab48054475a6f70f8e7fa847331f3327) Arguments: ps w
      • sh (PID: 5511, Parent: 5483, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "ps w"
        • sh New Fork (PID: 5513, Parent: 5511)
        • ps (PID: 5513, Parent: 5511, MD5: ab48054475a6f70f8e7fa847331f3327) Arguments: ps w
      • sh (PID: 5514, Parent: 5483, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "ps w"
        • sh New Fork (PID: 5516, Parent: 5514)
        • ps (PID: 5516, Parent: 5514, MD5: ab48054475a6f70f8e7fa847331f3327) Arguments: ps w
      • sh (PID: 5520, Parent: 5483, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "ps w"
        • sh New Fork (PID: 5522, Parent: 5520)
        • ps (PID: 5522, Parent: 5520, MD5: ab48054475a6f70f8e7fa847331f3327) Arguments: ps w
      • sh (PID: 5541, Parent: 5483, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "ps w"
        • sh New Fork (PID: 5543, Parent: 5541)
        • ps (PID: 5543, Parent: 5541, MD5: ab48054475a6f70f8e7fa847331f3327) Arguments: ps w
      • sh (PID: 5546, Parent: 5483, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "ps w"
        • sh New Fork (PID: 5548, Parent: 5546)
        • ps (PID: 5548, Parent: 5546, MD5: ab48054475a6f70f8e7fa847331f3327) Arguments: ps w
      • sh (PID: 5551, Parent: 5483, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "ps w"
        • sh New Fork (PID: 5557, Parent: 5551)
        • ps (PID: 5557, Parent: 5551, MD5: ab48054475a6f70f8e7fa847331f3327) Arguments: ps w
      • sh (PID: 5558, Parent: 5483, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "ps w"
        • sh New Fork (PID: 5560, Parent: 5558)
        • ps (PID: 5560, Parent: 5558, MD5: ab48054475a6f70f8e7fa847331f3327) Arguments: ps w
      • sh (PID: 5563, Parent: 5483, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "ps w"
        • sh New Fork (PID: 5565, Parent: 5563)
        • ps (PID: 5565, Parent: 5563, MD5: ab48054475a6f70f8e7fa847331f3327) Arguments: ps w
      • sh (PID: 5568, Parent: 5483, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "ps w"
        • sh New Fork (PID: 5570, Parent: 5568)
        • ps (PID: 5570, Parent: 5568, MD5: ab48054475a6f70f8e7fa847331f3327) Arguments: ps w
      • sh (PID: 5571, Parent: 5483, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "ps w"
        • sh New Fork (PID: 5573, Parent: 5571)
        • ps (PID: 5573, Parent: 5571, MD5: ab48054475a6f70f8e7fa847331f3327) Arguments: ps w
      • sh (PID: 5576, Parent: 5483, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "ps w"
        • sh New Fork (PID: 5578, Parent: 5576)
        • ps (PID: 5578, Parent: 5576, MD5: ab48054475a6f70f8e7fa847331f3327) Arguments: ps w
      • sh (PID: 5580, Parent: 5483, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "ps w"
        • sh New Fork (PID: 5586, Parent: 5580)
        • ps (PID: 5586, Parent: 5580, MD5: ab48054475a6f70f8e7fa847331f3327) Arguments: ps w
      • sh (PID: 5589, Parent: 5483, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "ps w"
        • sh New Fork (PID: 5591, Parent: 5589)
        • ps (PID: 5591, Parent: 5589, MD5: ab48054475a6f70f8e7fa847331f3327) Arguments: ps w
      • sh (PID: 5596, Parent: 5483, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "ps w"
        • sh New Fork (PID: 5601, Parent: 5596)
        • ps (PID: 5601, Parent: 5596, MD5: ab48054475a6f70f8e7fa847331f3327) Arguments: ps w
      • sh (PID: 5604, Parent: 5483, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "ps w"
        • sh New Fork (PID: 5606, Parent: 5604)
        • ps (PID: 5606, Parent: 5604, MD5: ab48054475a6f70f8e7fa847331f3327) Arguments: ps w
      • sh (PID: 5607, Parent: 5483, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "ps w"
        • sh New Fork (PID: 5609, Parent: 5607)
        • ps (PID: 5609, Parent: 5607, MD5: ab48054475a6f70f8e7fa847331f3327) Arguments: ps w
      • sh (PID: 5612, Parent: 5483, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "ps w"
        • sh New Fork (PID: 5618, Parent: 5612)
        • ps (PID: 5618, Parent: 5612, MD5: ab48054475a6f70f8e7fa847331f3327) Arguments: ps w
      • sh (PID: 5621, Parent: 5483, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "ps w"
        • sh New Fork (PID: 5623, Parent: 5621)
        • ps (PID: 5623, Parent: 5621, MD5: ab48054475a6f70f8e7fa847331f3327) Arguments: ps w
      • sh (PID: 5624, Parent: 5483, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "ps w"
        • sh New Fork (PID: 5626, Parent: 5624)
        • ps (PID: 5626, Parent: 5624, MD5: ab48054475a6f70f8e7fa847331f3327) Arguments: ps w
      • sh (PID: 5629, Parent: 5483, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "ps w"
        • sh New Fork (PID: 5631, Parent: 5629)
        • ps (PID: 5631, Parent: 5629, MD5: ab48054475a6f70f8e7fa847331f3327) Arguments: ps w
      • sh (PID: 5635, Parent: 5483, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "ps w"
        • sh New Fork (PID: 5641, Parent: 5635)
        • ps (PID: 5641, Parent: 5635, MD5: ab48054475a6f70f8e7fa847331f3327) Arguments: ps w
      • sh (PID: 5642, Parent: 5483, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "ps w"
        • sh New Fork (PID: 5644, Parent: 5642)
        • ps (PID: 5644, Parent: 5642, MD5: ab48054475a6f70f8e7fa847331f3327) Arguments: ps w
      • sh (PID: 5647, Parent: 5483, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "ps w"
        • sh New Fork (PID: 5653, Parent: 5647)
        • ps (PID: 5653, Parent: 5647, MD5: ab48054475a6f70f8e7fa847331f3327) Arguments: ps w
      • sh (PID: 5656, Parent: 5483, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "ps w"
        • sh New Fork (PID: 5658, Parent: 5656)
        • ps (PID: 5658, Parent: 5656, MD5: ab48054475a6f70f8e7fa847331f3327) Arguments: ps w
      • sh (PID: 5683, Parent: 5483, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "ps w"
        • sh New Fork (PID: 5688, Parent: 5683)
        • ps (PID: 5688, Parent: 5683, MD5: ab48054475a6f70f8e7fa847331f3327) Arguments: ps w
      • sh (PID: 5691, Parent: 5483, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "ps w"
        • sh New Fork (PID: 5693, Parent: 5691)
        • ps (PID: 5693, Parent: 5691, MD5: ab48054475a6f70f8e7fa847331f3327) Arguments: ps w
      • sh (PID: 5696, Parent: 5483, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "ps w"
        • sh New Fork (PID: 5698, Parent: 5696)
        • ps (PID: 5698, Parent: 5696, MD5: ab48054475a6f70f8e7fa847331f3327) Arguments: ps w
      • sh (PID: 5699, Parent: 5483, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "ps w"
        • sh New Fork (PID: 5701, Parent: 5699)
        • ps (PID: 5701, Parent: 5699, MD5: ab48054475a6f70f8e7fa847331f3327) Arguments: ps w
      • sh (PID: 5705, Parent: 5483, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "ps w"
        • sh New Fork (PID: 5707, Parent: 5705)
        • ps (PID: 5707, Parent: 5705, MD5: ab48054475a6f70f8e7fa847331f3327) Arguments: ps w
      • sh (PID: 5712, Parent: 5483, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "ps w"
        • sh New Fork (PID: 5714, Parent: 5712)
        • ps (PID: 5714, Parent: 5712, MD5: ab48054475a6f70f8e7fa847331f3327) Arguments: ps w
      • sh (PID: 5715, Parent: 5483, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "ps w"
        • sh New Fork (PID: 5717, Parent: 5715)
        • ps (PID: 5717, Parent: 5715, MD5: ab48054475a6f70f8e7fa847331f3327) Arguments: ps w
      • sh (PID: 5720, Parent: 5483, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "ps w"
        • sh New Fork (PID: 5722, Parent: 5720)
        • ps (PID: 5722, Parent: 5720, MD5: ab48054475a6f70f8e7fa847331f3327) Arguments: ps w
      • sh (PID: 5723, Parent: 5483, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "ps w"
        • sh New Fork (PID: 5725, Parent: 5723)
        • ps (PID: 5725, Parent: 5723, MD5: ab48054475a6f70f8e7fa847331f3327) Arguments: ps w
      • sh (PID: 5728, Parent: 5483, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "ps w"
        • sh New Fork (PID: 5730, Parent: 5728)
        • ps (PID: 5730, Parent: 5728, MD5: ab48054475a6f70f8e7fa847331f3327) Arguments: ps w
  • dash New Fork (PID: 5659, Parent: 3632)
  • rm (PID: 5659, Parent: 3632, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.Y1SlPlfBUT /tmp/tmp.H0mrDkYWQu /tmp/tmp.XAIyeGnwVr
  • dash New Fork (PID: 5660, Parent: 3632)
  • rm (PID: 5660, Parent: 3632, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.Y1SlPlfBUT /tmp/tmp.H0mrDkYWQu /tmp/tmp.XAIyeGnwVr
  • cleanup
No yara matches
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: psmips.elfAvira: detected
Source: psmips.elfVirustotal: Detection: 43%Perma Link
Source: psmips.elfReversingLabs: Detection: 44%
Source: /usr/bin/ps (PID: 5491)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
Source: /usr/bin/ps (PID: 5497)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
Source: /usr/bin/ps (PID: 5502)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
Source: /usr/bin/ps (PID: 5513)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
Source: /usr/bin/ps (PID: 5516)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
Source: /usr/bin/ps (PID: 5522)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
Source: /usr/bin/ps (PID: 5543)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
Source: /usr/bin/ps (PID: 5548)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
Source: /usr/bin/ps (PID: 5557)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
Source: /usr/bin/ps (PID: 5560)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
Source: /usr/bin/ps (PID: 5565)Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/ps (PID: 5570)Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/ps (PID: 5573)Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/ps (PID: 5578)Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/ps (PID: 5586)Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/ps (PID: 5591)Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/ps (PID: 5601)Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/ps (PID: 5606)Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/ps (PID: 5609)Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/ps (PID: 5618)Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/ps (PID: 5623)Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/ps (PID: 5626)Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/ps (PID: 5631)Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/ps (PID: 5641)Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/ps (PID: 5644)Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/ps (PID: 5653)Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/ps (PID: 5658)Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/ps (PID: 5688)Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/ps (PID: 5693)Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/ps (PID: 5698)Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/ps (PID: 5701)Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/ps (PID: 5707)Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/ps (PID: 5714)Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/ps (PID: 5717)Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/ps (PID: 5722)Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/ps (PID: 5725)Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/ps (PID: 5730)Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
Source: unknownNetwork traffic detected: HTTP traffic on port 34592 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 37910
Source: unknownNetwork traffic detected: HTTP traffic on port 37910 -> 443
Source: classification engineClassification label: mal56.linELF@0/0@0/0
Source: psmips.elfELF static info symbol of initial sample: libc/string/mips/memcpy.S
Source: psmips.elfELF static info symbol of initial sample: libc/string/mips/memset.S
Source: psmips.elfELF static info symbol of initial sample: libc/sysdeps/linux/mips/crt1.S
Source: psmips.elfELF static info symbol of initial sample: libc/sysdeps/linux/mips/crti.S
Source: psmips.elfELF static info symbol of initial sample: libc/sysdeps/linux/mips/crtn.S
Source: psmips.elfELF static info symbol of initial sample: libc/sysdeps/linux/mips/pipe.S
Source: /usr/bin/ps (PID: 5560)File opened: /proc/3760/statJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/3760/statusJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/3760/cmdlineJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/3761/statJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/3761/statusJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/3761/cmdlineJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/1583/statJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/1583/statusJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/1583/cmdlineJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/2672/statJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/2672/statusJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/2672/cmdlineJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/110/statJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/110/statusJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/110/cmdlineJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/3759/statJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/3759/statusJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/3759/cmdlineJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/111/statJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/111/statusJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/111/cmdlineJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/112/statJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/112/statusJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/112/cmdlineJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/113/statJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/113/statusJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/113/cmdlineJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/234/statJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/234/statusJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/234/cmdlineJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/1577/statJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/1577/statusJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/1577/cmdlineJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/114/statJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/114/statusJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/114/cmdlineJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/235/statJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/235/statusJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/235/cmdlineJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/115/statJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/115/statusJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/115/cmdlineJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/116/statJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/116/statusJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/116/cmdlineJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/117/statJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/117/statusJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/117/cmdlineJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/118/statJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/118/statusJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/118/cmdlineJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/119/statJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/119/statusJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/119/cmdlineJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/3752/statJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/3752/statusJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/3752/cmdlineJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/3632/statJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/3632/statusJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/3632/cmdlineJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/10/statJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/10/statusJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/10/cmdlineJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/917/statJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/917/statusJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/917/cmdlineJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/11/statJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/11/statusJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/11/cmdlineJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/12/statJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/12/statusJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/12/cmdlineJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/13/statJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/13/statusJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/13/cmdlineJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/14/statJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/14/statusJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/14/cmdlineJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/15/statJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/15/statusJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/15/cmdlineJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/16/statJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/16/statusJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/16/cmdlineJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/17/statJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/17/statusJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/17/cmdlineJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/18/statJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/18/statusJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/18/cmdlineJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/19/statJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/19/statusJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/19/cmdlineJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/1593/statJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/1593/statusJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/1593/cmdlineJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/240/statJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/240/statusJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/240/cmdlineJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/120/statJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/120/statusJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/120/cmdlineJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/3094/statJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/3094/statusJump to behavior
Source: /usr/bin/ps (PID: 5560)File opened: /proc/3094/cmdlineJump to behavior
Source: /tmp/psmips.elf (PID: 5489)Shell command executed: sh -c "ps w"Jump to behavior
Source: /tmp/psmips.elf (PID: 5492)Shell command executed: sh -c "ps w"Jump to behavior
Source: /tmp/psmips.elf (PID: 5500)Shell command executed: sh -c "ps w"Jump to behavior
Source: /tmp/psmips.elf (PID: 5511)Shell command executed: sh -c "ps w"Jump to behavior
Source: /tmp/psmips.elf (PID: 5514)Shell command executed: sh -c "ps w"Jump to behavior
Source: /tmp/psmips.elf (PID: 5520)Shell command executed: sh -c "ps w"Jump to behavior
Source: /tmp/psmips.elf (PID: 5541)Shell command executed: sh -c "ps w"Jump to behavior
Source: /tmp/psmips.elf (PID: 5546)Shell command executed: sh -c "ps w"Jump to behavior
Source: /tmp/psmips.elf (PID: 5551)Shell command executed: sh -c "ps w"Jump to behavior
Source: /tmp/psmips.elf (PID: 5558)Shell command executed: sh -c "ps w"Jump to behavior
Source: /tmp/psmips.elf (PID: 5563)Shell command executed: sh -c "ps w"
Source: /tmp/psmips.elf (PID: 5568)Shell command executed: sh -c "ps w"
Source: /tmp/psmips.elf (PID: 5571)Shell command executed: sh -c "ps w"
Source: /tmp/psmips.elf (PID: 5576)Shell command executed: sh -c "ps w"
Source: /tmp/psmips.elf (PID: 5580)Shell command executed: sh -c "ps w"
Source: /tmp/psmips.elf (PID: 5589)Shell command executed: sh -c "ps w"
Source: /tmp/psmips.elf (PID: 5596)Shell command executed: sh -c "ps w"
Source: /tmp/psmips.elf (PID: 5604)Shell command executed: sh -c "ps w"
Source: /tmp/psmips.elf (PID: 5607)Shell command executed: sh -c "ps w"
Source: /tmp/psmips.elf (PID: 5612)Shell command executed: sh -c "ps w"
Source: /tmp/psmips.elf (PID: 5621)Shell command executed: sh -c "ps w"
Source: /tmp/psmips.elf (PID: 5624)Shell command executed: sh -c "ps w"
Source: /tmp/psmips.elf (PID: 5629)Shell command executed: sh -c "ps w"
Source: /tmp/psmips.elf (PID: 5635)Shell command executed: sh -c "ps w"
Source: /tmp/psmips.elf (PID: 5642)Shell command executed: sh -c "ps w"
Source: /tmp/psmips.elf (PID: 5647)Shell command executed: sh -c "ps w"
Source: /tmp/psmips.elf (PID: 5656)Shell command executed: sh -c "ps w"
Source: /tmp/psmips.elf (PID: 5683)Shell command executed: sh -c "ps w"
Source: /tmp/psmips.elf (PID: 5691)Shell command executed: sh -c "ps w"
Source: /tmp/psmips.elf (PID: 5696)Shell command executed: sh -c "ps w"
Source: /tmp/psmips.elf (PID: 5699)Shell command executed: sh -c "ps w"
Source: /tmp/psmips.elf (PID: 5705)Shell command executed: sh -c "ps w"
Source: /tmp/psmips.elf (PID: 5712)Shell command executed: sh -c "ps w"
Source: /tmp/psmips.elf (PID: 5715)Shell command executed: sh -c "ps w"
Source: /tmp/psmips.elf (PID: 5720)Shell command executed: sh -c "ps w"
Source: /tmp/psmips.elf (PID: 5723)Shell command executed: sh -c "ps w"
Source: /tmp/psmips.elf (PID: 5728)Shell command executed: sh -c "ps w"
Source: /bin/sh (PID: 5491)Ps executable: /usr/bin/ps -> ps wJump to behavior
Source: /bin/sh (PID: 5497)Ps executable: /usr/bin/ps -> ps wJump to behavior
Source: /bin/sh (PID: 5502)Ps executable: /usr/bin/ps -> ps wJump to behavior
Source: /bin/sh (PID: 5513)Ps executable: /usr/bin/ps -> ps wJump to behavior
Source: /bin/sh (PID: 5516)Ps executable: /usr/bin/ps -> ps wJump to behavior
Source: /bin/sh (PID: 5522)Ps executable: /usr/bin/ps -> ps wJump to behavior
Source: /bin/sh (PID: 5543)Ps executable: /usr/bin/ps -> ps wJump to behavior
Source: /bin/sh (PID: 5548)Ps executable: /usr/bin/ps -> ps wJump to behavior
Source: /bin/sh (PID: 5557)Ps executable: /usr/bin/ps -> ps wJump to behavior
Source: /bin/sh (PID: 5560)Ps executable: /usr/bin/ps -> ps wJump to behavior
Source: /bin/sh (PID: 5565)Ps executable: /usr/bin/ps -> ps w
Source: /bin/sh (PID: 5570)Ps executable: /usr/bin/ps -> ps w
Source: /bin/sh (PID: 5573)Ps executable: /usr/bin/ps -> ps w
Source: /bin/sh (PID: 5578)Ps executable: /usr/bin/ps -> ps w
Source: /bin/sh (PID: 5586)Ps executable: /usr/bin/ps -> ps w
Source: /bin/sh (PID: 5591)Ps executable: /usr/bin/ps -> ps w
Source: /bin/sh (PID: 5601)Ps executable: /usr/bin/ps -> ps w
Source: /bin/sh (PID: 5606)Ps executable: /usr/bin/ps -> ps w
Source: /bin/sh (PID: 5609)Ps executable: /usr/bin/ps -> ps w
Source: /bin/sh (PID: 5618)Ps executable: /usr/bin/ps -> ps w
Source: /bin/sh (PID: 5623)Ps executable: /usr/bin/ps -> ps w
Source: /bin/sh (PID: 5626)Ps executable: /usr/bin/ps -> ps w
Source: /bin/sh (PID: 5631)Ps executable: /usr/bin/ps -> ps w
Source: /bin/sh (PID: 5641)Ps executable: /usr/bin/ps -> ps w
Source: /bin/sh (PID: 5644)Ps executable: /usr/bin/ps -> ps w
Source: /bin/sh (PID: 5653)Ps executable: /usr/bin/ps -> ps w
Source: /bin/sh (PID: 5658)Ps executable: /usr/bin/ps -> ps w
Source: /bin/sh (PID: 5688)Ps executable: /usr/bin/ps -> ps w
Source: /bin/sh (PID: 5693)Ps executable: /usr/bin/ps -> ps w
Source: /bin/sh (PID: 5698)Ps executable: /usr/bin/ps -> ps w
Source: /bin/sh (PID: 5701)Ps executable: /usr/bin/ps -> ps w
Source: /bin/sh (PID: 5707)Ps executable: /usr/bin/ps -> ps w
Source: /bin/sh (PID: 5714)Ps executable: /usr/bin/ps -> ps w
Source: /bin/sh (PID: 5717)Ps executable: /usr/bin/ps -> ps w
Source: /bin/sh (PID: 5722)Ps executable: /usr/bin/ps -> ps w
Source: /bin/sh (PID: 5725)Ps executable: /usr/bin/ps -> ps w
Source: /bin/sh (PID: 5730)Ps executable: /usr/bin/ps -> ps w
Source: /usr/bin/dash (PID: 5659)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.Y1SlPlfBUT /tmp/tmp.H0mrDkYWQu /tmp/tmp.XAIyeGnwVr
Source: /usr/bin/dash (PID: 5660)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.Y1SlPlfBUT /tmp/tmp.H0mrDkYWQu /tmp/tmp.XAIyeGnwVr
Source: /usr/bin/ps (PID: 5491)Reads from proc file: /proc/meminfoJump to behavior
Source: /usr/bin/ps (PID: 5497)Reads from proc file: /proc/meminfoJump to behavior
Source: /usr/bin/ps (PID: 5502)Reads from proc file: /proc/meminfoJump to behavior
Source: /usr/bin/ps (PID: 5513)Reads from proc file: /proc/meminfoJump to behavior
Source: /usr/bin/ps (PID: 5516)Reads from proc file: /proc/meminfoJump to behavior
Source: /usr/bin/ps (PID: 5522)Reads from proc file: /proc/meminfoJump to behavior
Source: /usr/bin/ps (PID: 5543)Reads from proc file: /proc/meminfoJump to behavior
Source: /usr/bin/ps (PID: 5548)Reads from proc file: /proc/meminfoJump to behavior
Source: /usr/bin/ps (PID: 5557)Reads from proc file: /proc/meminfoJump to behavior
Source: /usr/bin/ps (PID: 5560)Reads from proc file: /proc/meminfoJump to behavior
Source: /usr/bin/ps (PID: 5565)Reads from proc file: /proc/meminfo
Source: /usr/bin/ps (PID: 5570)Reads from proc file: /proc/meminfo
Source: /usr/bin/ps (PID: 5573)Reads from proc file: /proc/meminfo
Source: /usr/bin/ps (PID: 5578)Reads from proc file: /proc/meminfo
Source: /usr/bin/ps (PID: 5586)Reads from proc file: /proc/meminfo
Source: /usr/bin/ps (PID: 5591)Reads from proc file: /proc/meminfo
Source: /usr/bin/ps (PID: 5601)Reads from proc file: /proc/meminfo
Source: /usr/bin/ps (PID: 5606)Reads from proc file: /proc/meminfo
Source: /usr/bin/ps (PID: 5609)Reads from proc file: /proc/meminfo
Source: /usr/bin/ps (PID: 5618)Reads from proc file: /proc/meminfo
Source: /usr/bin/ps (PID: 5623)Reads from proc file: /proc/meminfo
Source: /usr/bin/ps (PID: 5626)Reads from proc file: /proc/meminfo
Source: /usr/bin/ps (PID: 5631)Reads from proc file: /proc/meminfo
Source: /usr/bin/ps (PID: 5641)Reads from proc file: /proc/meminfo
Source: /usr/bin/ps (PID: 5644)Reads from proc file: /proc/meminfo
Source: /usr/bin/ps (PID: 5653)Reads from proc file: /proc/meminfo
Source: /usr/bin/ps (PID: 5658)Reads from proc file: /proc/meminfo
Source: /usr/bin/ps (PID: 5688)Reads from proc file: /proc/meminfo
Source: /usr/bin/ps (PID: 5693)Reads from proc file: /proc/meminfo
Source: /usr/bin/ps (PID: 5698)Reads from proc file: /proc/meminfo
Source: /usr/bin/ps (PID: 5701)Reads from proc file: /proc/meminfo
Source: /usr/bin/ps (PID: 5707)Reads from proc file: /proc/meminfo
Source: /usr/bin/ps (PID: 5714)Reads from proc file: /proc/meminfo
Source: /usr/bin/ps (PID: 5717)Reads from proc file: /proc/meminfo
Source: /usr/bin/ps (PID: 5722)Reads from proc file: /proc/meminfo
Source: /usr/bin/ps (PID: 5725)Reads from proc file: /proc/meminfo
Source: /usr/bin/ps (PID: 5730)Reads from proc file: /proc/meminfo
Source: /usr/bin/ps (PID: 5491)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
Source: /usr/bin/ps (PID: 5497)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
Source: /usr/bin/ps (PID: 5502)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
Source: /usr/bin/ps (PID: 5513)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
Source: /usr/bin/ps (PID: 5516)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
Source: /usr/bin/ps (PID: 5522)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
Source: /usr/bin/ps (PID: 5543)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
Source: /usr/bin/ps (PID: 5548)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
Source: /usr/bin/ps (PID: 5557)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
Source: /usr/bin/ps (PID: 5560)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
Source: /usr/bin/ps (PID: 5565)Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/ps (PID: 5570)Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/ps (PID: 5573)Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/ps (PID: 5578)Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/ps (PID: 5586)Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/ps (PID: 5591)Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/ps (PID: 5601)Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/ps (PID: 5606)Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/ps (PID: 5609)Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/ps (PID: 5618)Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/ps (PID: 5623)Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/ps (PID: 5626)Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/ps (PID: 5631)Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/ps (PID: 5641)Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/ps (PID: 5644)Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/ps (PID: 5653)Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/ps (PID: 5658)Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/ps (PID: 5688)Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/ps (PID: 5693)Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/ps (PID: 5698)Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/ps (PID: 5701)Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/ps (PID: 5707)Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/ps (PID: 5714)Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/ps (PID: 5717)Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/ps (PID: 5722)Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/ps (PID: 5725)Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/ps (PID: 5730)Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /tmp/psmips.elf (PID: 5481)Queries kernel information via 'uname': Jump to behavior
Source: psmips.elf, 5481.1.000055c311fc8000.000055c31204f000.rw-.sdmpBinary or memory string: U!/etc/qemu-binfmt/mips
Source: psmips.elf, 5481.1.000055c311fc8000.000055c31204f000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/mips
Source: psmips.elf, 5481.1.00007ffe7eccb000.00007ffe7ecec000.rw-.sdmpBinary or memory string: /usr/bin/qemu-mips
Source: psmips.elf, 5481.1.00007ffe7eccb000.00007ffe7ecec000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-mips/tmp/psmips.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/psmips.elf
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity Information1
Scripting
Valid AccountsWindows Management Instrumentation1
Scripting
Path Interception1
File Deletion
1
OS Credential Dumping
11
Security Software Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS Memory1
Process Discovery
Remote Desktop ProtocolData from Removable Media1
Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account Manager2
System Information Discovery
SMB/Windows Admin SharesData from Network Shared DriveSteganographyAutomated ExfiltrationData Encrypted for Impact
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1644216 Sample: psmips.elf Startdate: 20/03/2025 Architecture: LINUX Score: 56 39 54.171.230.55, 37910, 443 AMAZON-02US United States 2->39 41 54.217.10.153, 443 AMAZON-02US United States 2->41 43 Antivirus / Scanner detection for submitted sample 2->43 45 Multi AV Scanner detection for submitted file 2->45 9 psmips.elf 2->9         started        11 dash rm 2->11         started        13 dash rm 2->13         started        signatures3 process4 process5 15 psmips.elf 9->15         started        process6 17 psmips.elf sh 15->17         started        19 psmips.elf sh 15->19         started        21 psmips.elf sh 15->21         started        23 34 other processes 15->23 process7 25 sh ps 17->25         started        27 sh ps 19->27         started        29 sh ps 21->29         started        31 sh ps 23->31         started        33 sh ps 23->33         started        35 sh ps 23->35         started        37 31 other processes 23->37

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
psmips.elf44%VirustotalBrowse
psmips.elf44%ReversingLabsLinux.Trojan.Mirai
psmips.elf100%AviraLINUX/AVI.Agent.vjxlv
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

No contacted domains info
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs
IPDomainCountryFlagASNASN NameMalicious
54.171.230.55
unknownUnited States
16509AMAZON-02USfalse
54.217.10.153
unknownUnited States
16509AMAZON-02USfalse
MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
54.171.230.55yakuza.mpsl.elfGet hashmaliciousGafgyt, MiraiBrowse
    main_mpsl.elfGet hashmaliciousMiraiBrowse
      i.elfGet hashmaliciousMiraiBrowse
        arc.elfGet hashmaliciousMiraiBrowse
          aarch64.elfGet hashmaliciousMiraiBrowse
            boatnet.m68k.elfGet hashmaliciousMiraiBrowse
              na.elfGet hashmaliciousPrometeiBrowse
                na.elfGet hashmaliciousPrometeiBrowse
                  na.elfGet hashmaliciousPrometeiBrowse
                    na.elfGet hashmaliciousPrometeiBrowse
                      54.217.10.153yakuza.m68k.elfGet hashmaliciousGafgyt, MiraiBrowse
                        main_x86.elfGet hashmaliciousMiraiBrowse
                          jkse.arm7.elfGet hashmaliciousMiraiBrowse
                            re.bot.mips.elfGet hashmaliciousUnknownBrowse
                              45.126.126.33-sora.arm-2025-03-12T01_48_26.elfGet hashmaliciousMiraiBrowse
                                efea6.elfGet hashmaliciousMiraiBrowse
                                  tftp.elfGet hashmaliciousUnknownBrowse
                                    arm6.elfGet hashmaliciousUnknownBrowse
                                      na.elfGet hashmaliciousPrometeiBrowse
                                        nshkarm6.elfGet hashmaliciousUnknownBrowse
                                          No context
                                          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                          AMAZON-02USyakuza.mpsl.elfGet hashmaliciousGafgyt, MiraiBrowse
                                          • 54.171.230.55
                                          yakuza.m68k.elfGet hashmaliciousGafgyt, MiraiBrowse
                                          • 54.217.10.153
                                          https://sharepointsync.zoholandingpage.com/vandpsolutions.com?PO60267SP-20-2025Get hashmaliciousHTMLPhisherBrowse
                                          • 13.249.91.126
                                          yakuza.sh4.elfGet hashmaliciousGafgyt, MiraiBrowse
                                          • 34.249.145.219
                                          na.elfGet hashmaliciousPrometeiBrowse
                                          • 54.255.164.76
                                          .5r3fqt67ew531has4231.mpsl.elfGet hashmaliciousUnknownBrowse
                                          • 34.249.145.219
                                          .5r3fqt67ew531has4231.ppc.elfGet hashmaliciousUnknownBrowse
                                          • 34.249.145.219
                                          http://escogruupo.comGet hashmaliciousUnknownBrowse
                                          • 18.238.55.64
                                          main_m68k.elfGet hashmaliciousMiraiBrowse
                                          • 34.249.145.219
                                          main_x86.elfGet hashmaliciousMiraiBrowse
                                          • 34.249.145.219
                                          AMAZON-02USyakuza.mpsl.elfGet hashmaliciousGafgyt, MiraiBrowse
                                          • 54.171.230.55
                                          yakuza.m68k.elfGet hashmaliciousGafgyt, MiraiBrowse
                                          • 54.217.10.153
                                          https://sharepointsync.zoholandingpage.com/vandpsolutions.com?PO60267SP-20-2025Get hashmaliciousHTMLPhisherBrowse
                                          • 13.249.91.126
                                          yakuza.sh4.elfGet hashmaliciousGafgyt, MiraiBrowse
                                          • 34.249.145.219
                                          na.elfGet hashmaliciousPrometeiBrowse
                                          • 54.255.164.76
                                          .5r3fqt67ew531has4231.mpsl.elfGet hashmaliciousUnknownBrowse
                                          • 34.249.145.219
                                          .5r3fqt67ew531has4231.ppc.elfGet hashmaliciousUnknownBrowse
                                          • 34.249.145.219
                                          http://escogruupo.comGet hashmaliciousUnknownBrowse
                                          • 18.238.55.64
                                          main_m68k.elfGet hashmaliciousMiraiBrowse
                                          • 34.249.145.219
                                          main_x86.elfGet hashmaliciousMiraiBrowse
                                          • 34.249.145.219
                                          No context
                                          No context
                                          No created / dropped files found
                                          File type:ELF 32-bit MSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, not stripped
                                          Entropy (8bit):5.326178579446536
                                          TrID:
                                          • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                          File name:psmips.elf
                                          File size:59'208 bytes
                                          MD5:2ef51410690dc12a309cc8b0aa59a294
                                          SHA1:b4b5c0a8ed4d01b637556826afffd87c831ca543
                                          SHA256:f7b791cd1a116eaecf3a2bb4d63077f02e19af185b036058f4f42f24d52979f9
                                          SHA512:941777907b0c6c8ddb2165587402c04bac028001f72c1f8aaab08b93778fffab59f295ae4f861ce7543ec9b71bee0c831985d397a3c54fd3d92a1510afa282e6
                                          SSDEEP:768:aZ66bi0XFjNGyf0yZdqeYYmU5IcGQE3WjaIKzoMvQyfYute/S:aZ6ii0XJ9+e5mOpGQEGIvQyfYute/S
                                          TLSH:9143D9123A11EFFBE55D82300BF38A3056D576A52E919389F25CEB5C1F226CC1C5E7A4
                                          File Content Preview:.ELF.....................@.....4.........4. ...(....p........@...@...........................@...@.....D...D...............D.D.D.D.D......&.........dt.Q.................................................E.p<...'......!'.......................<...'......!...

                                          ELF header

                                          Class:ELF32
                                          Data:2's complement, big endian
                                          Version:1 (current)
                                          Machine:MIPS R3000
                                          Version Number:0x1
                                          Type:EXEC (Executable file)
                                          OS/ABI:UNIX - System V
                                          ABI Version:0
                                          Entry Point Address:0x4002a0
                                          Flags:0x1007
                                          ELF Header Size:52
                                          Program Header Offset:52
                                          Program Header Size:32
                                          Number of Program Headers:4
                                          Section Header Offset:44996
                                          Section Header Size:40
                                          Number of Section Headers:20
                                          Header String Table Index:17
                                          NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                          NULL0x00x00x00x00x0000
                                          .reginfoMIPS_REGINFO0x4000b40xb40x180x180x2A004
                                          .initPROGBITS0x4000cc0xcc0x8c0x00x6AX004
                                          .textPROGBITS0x4001600x1600x7b000x00x6AX0016
                                          .finiPROGBITS0x407c600x7c600x5c0x00x6AX004
                                          .rodataPROGBITS0x407cc00x7cc00x14800x00x2A0016
                                          .eh_framePROGBITS0x4091400x91400x40x00x2A004
                                          .ctorsPROGBITS0x4491440x91440x80x00x3WA004
                                          .dtorsPROGBITS0x44914c0x914c0x80x00x3WA004
                                          .jcrPROGBITS0x4491540x91540x40x00x3WA004
                                          .dataPROGBITS0x4491600x91600x3200x00x3WA0016
                                          .gotPROGBITS0x4494800x94800x2ac0x40x10000003WAp0016
                                          .sbssNOBITS0x44972c0x972c0x80x00x10000003WAp004
                                          .bssNOBITS0x4497400x972c0x20d80x00x3WA0016
                                          .commentPROGBITS0x00x972c0x7860x00x0001
                                          .mdebug.abi32PROGBITS0x7860x9eb20x00x00x0001
                                          .pdrPROGBITS0x00x9eb40x10800x00x0004
                                          .shstrtabSTRTAB0x00xaf340x8d0x00x0001
                                          .symtabSYMTAB0x00xb2e40x1db00x100x0192034
                                          .strtabSTRTAB0x00xd0940x16b40x00x0001
                                          TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                          <unknown>0xb40x4000b40x4000b40x180x180.98340x4R 0x4.reginfo
                                          LOAD0x00x4000000x4000000x91440x91445.41800x5R E0x10000.reginfo .init .text .fini .rodata .eh_frame
                                          LOAD0x91440x4491440x4491440x5e80x26d42.94200x6RW 0x10000.ctors .dtors .jcr .data .got .sbss .bss
                                          GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
                                          NameVersion Info NameVersion Info File NameSection NameValueSizeSymbol TypeSymbol BindSymbol VisibilityNdx
                                          .symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                          .symtab0x4000b40SECTION<unknown>DEFAULT1
                                          .symtab0x4000cc0SECTION<unknown>DEFAULT2
                                          .symtab0x4001600SECTION<unknown>DEFAULT3
                                          .symtab0x407c600SECTION<unknown>DEFAULT4
                                          .symtab0x407cc00SECTION<unknown>DEFAULT5
                                          .symtab0x4091400SECTION<unknown>DEFAULT6
                                          .symtab0x4491440SECTION<unknown>DEFAULT7
                                          .symtab0x44914c0SECTION<unknown>DEFAULT8
                                          .symtab0x4491540SECTION<unknown>DEFAULT9
                                          .symtab0x4491600SECTION<unknown>DEFAULT10
                                          .symtab0x4494800SECTION<unknown>DEFAULT11
                                          .symtab0x44972c0SECTION<unknown>DEFAULT12
                                          .symtab0x4497400SECTION<unknown>DEFAULT13
                                          .symtab0x00SECTION<unknown>DEFAULT14
                                          .symtab0x7860SECTION<unknown>DEFAULT15
                                          .symtab0x00SECTION<unknown>DEFAULT16
                                          .symtab0x00SECTION<unknown>DEFAULT17
                                          .symtab0x00SECTION<unknown>DEFAULT18
                                          .symtab0x00SECTION<unknown>DEFAULT19
                                          _GLOBAL_OFFSET_TABLE_.symtab0x4494800OBJECT<unknown>DEFAULT11
                                          _Jv_RegisterClasses.symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                          _READ.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          _WRITE.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          __CTOR_END__.symtab0x4491480OBJECT<unknown>DEFAULT7
                                          __CTOR_LIST__.symtab0x4491440OBJECT<unknown>DEFAULT7
                                          __C_ctype_b.symtab0x4494204OBJECT<unknown>DEFAULT10
                                          __C_ctype_b.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          __C_ctype_b_data.symtab0x408aa0768OBJECT<unknown>DEFAULT5
                                          __C_ctype_tolower.symtab0x4494304OBJECT<unknown>DEFAULT10
                                          __C_ctype_tolower.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          __C_ctype_tolower_data.symtab0x408da0768OBJECT<unknown>DEFAULT5
                                          __DTOR_END__.symtab0x4491500OBJECT<unknown>DEFAULT8
                                          __DTOR_LIST__.symtab0x44914c0OBJECT<unknown>DEFAULT8
                                          __EH_FRAME_BEGIN__.symtab0x4091400OBJECT<unknown>DEFAULT6
                                          __FRAME_END__.symtab0x4091400OBJECT<unknown>DEFAULT6
                                          __GI___C_ctype_b.symtab0x4494204OBJECT<unknown>HIDDEN10
                                          __GI___C_ctype_b_data.symtab0x408aa0768OBJECT<unknown>HIDDEN5
                                          __GI___C_ctype_tolower.symtab0x4494304OBJECT<unknown>HIDDEN10
                                          __GI___C_ctype_tolower_data.symtab0x408da0768OBJECT<unknown>HIDDEN5
                                          __GI___ctype_b.symtab0x4494244OBJECT<unknown>HIDDEN10
                                          __GI___ctype_tolower.symtab0x4494344OBJECT<unknown>HIDDEN10
                                          __GI___errno_location.symtab0x40098024FUNC<unknown>HIDDEN3
                                          __GI___fgetc_unlocked.symtab0x406950388FUNC<unknown>HIDDEN3
                                          __GI___glibc_strerror_r.symtab0x402d9068FUNC<unknown>HIDDEN3
                                          __GI___libc_fcntl.symtab0x404790136FUNC<unknown>HIDDEN3
                                          __GI___libc_fcntl64.symtab0x404820104FUNC<unknown>HIDDEN3
                                          __GI___libc_open.symtab0x404bf0124FUNC<unknown>HIDDEN3
                                          __GI___uClibc_fini.symtab0x404200196FUNC<unknown>HIDDEN3
                                          __GI___uClibc_init.symtab0x40435c140FUNC<unknown>HIDDEN3
                                          __GI___xpg_strerror_r.symtab0x402de0392FUNC<unknown>HIDDEN3
                                          __GI__exit.symtab0x40489080FUNC<unknown>HIDDEN3
                                          __GI_abort.symtab0x406d80428FUNC<unknown>HIDDEN3
                                          __GI_brk.symtab0x407050112FUNC<unknown>HIDDEN3
                                          __GI_close.symtab0x40086084FUNC<unknown>HIDDEN3
                                          __GI_connect.symtab0x40398084FUNC<unknown>HIDDEN3
                                          __GI_dup2.symtab0x4048e084FUNC<unknown>HIDDEN3
                                          __GI_errno.symtab0x44b7c04OBJECT<unknown>HIDDEN13
                                          __GI_execl.symtab0x4040a0204FUNC<unknown>HIDDEN3
                                          __GI_execve.symtab0x40494084FUNC<unknown>HIDDEN3
                                          __GI_exit.symtab0x406f30236FUNC<unknown>HIDDEN3
                                          __GI_fclose.symtab0x404f20512FUNC<unknown>HIDDEN3
                                          __GI_fcntl.symtab0x404790136FUNC<unknown>HIDDEN3
                                          __GI_fcntl64.symtab0x404820104FUNC<unknown>HIDDEN3
                                          __GI_fdopen.symtab0x405120128FUNC<unknown>HIDDEN3
                                          __GI_fflush_unlocked.symtab0x4066d0628FUNC<unknown>HIDDEN3
                                          __GI_fgetc_unlocked.symtab0x406950388FUNC<unknown>HIDDEN3
                                          __GI_fgets.symtab0x402470216FUNC<unknown>HIDDEN3
                                          __GI_fgets_unlocked.symtab0x402550268FUNC<unknown>HIDDEN3
                                          __GI_fork.symtab0x4008c084FUNC<unknown>HIDDEN3
                                          __GI_fprintf.symtab0x400a0072FUNC<unknown>HIDDEN3
                                          __GI_fputs_unlocked.symtab0x402660128FUNC<unknown>HIDDEN3
                                          __GI_fseek.symtab0x4073c068FUNC<unknown>HIDDEN3
                                          __GI_fseeko64.symtab0x407410388FUNC<unknown>HIDDEN3
                                          __GI_fwrite_unlocked.symtab0x4026e0280FUNC<unknown>HIDDEN3
                                          __GI_getc_unlocked.symtab0x406950388FUNC<unknown>HIDDEN3
                                          __GI_getegid.symtab0x4049a088FUNC<unknown>HIDDEN3
                                          __GI_geteuid.symtab0x404a0088FUNC<unknown>HIDDEN3
                                          __GI_getgid.symtab0x404a6084FUNC<unknown>HIDDEN3
                                          __GI_getpid.symtab0x407a2084FUNC<unknown>HIDDEN3
                                          __GI_getuid.symtab0x404ac084FUNC<unknown>HIDDEN3
                                          __GI_h_errno.symtab0x44b7c44OBJECT<unknown>HIDDEN13
                                          __GI_inet_ntop.symtab0x403620852FUNC<unknown>HIDDEN3
                                          __GI_inet_pton.symtab0x403170700FUNC<unknown>HIDDEN3
                                          __GI_ioctl.symtab0x404b20104FUNC<unknown>HIDDEN3
                                          __GI_isatty.symtab0x402f7060FUNC<unknown>HIDDEN3
                                          __GI_kill.symtab0x407a8088FUNC<unknown>HIDDEN3
                                          __GI_lseek64.symtab0x407ae0168FUNC<unknown>HIDDEN3
                                          __GI_memchr.symtab0x406ae0264FUNC<unknown>HIDDEN3
                                          __GI_memcpy.symtab0x402800308FUNC<unknown>HIDDEN3
                                          __GI_mempcpy.symtab0x406bf076FUNC<unknown>HIDDEN3
                                          __GI_memrchr.symtab0x406c40272FUNC<unknown>HIDDEN3
                                          __GI_memset.symtab0x402940144FUNC<unknown>HIDDEN3
                                          __GI_nanosleep.symtab0x404b9084FUNC<unknown>HIDDEN3
                                          __GI_open.symtab0x404bf0124FUNC<unknown>HIDDEN3
                                          __GI_perror.symtab0x4009a084FUNC<unknown>HIDDEN3
                                          __GI_pipe.symtab0x40475064FUNC<unknown>HIDDEN3
                                          __GI_raise.symtab0x40794076FUNC<unknown>HIDDEN3
                                          __GI_read.symtab0x407b9084FUNC<unknown>HIDDEN3
                                          __GI_sbrk.symtab0x404c90144FUNC<unknown>HIDDEN3
                                          __GI_send.symtab0x4039e084FUNC<unknown>HIDDEN3
                                          __GI_setsid.symtab0x40092084FUNC<unknown>HIDDEN3
                                          __GI_sigaction.symtab0x407110232FUNC<unknown>HIDDEN3
                                          __GI_sigprocmask.symtab0x407260148FUNC<unknown>HIDDEN3
                                          __GI_socket.symtab0x403a4084FUNC<unknown>HIDDEN3
                                          __GI_sprintf.symtab0x4051a080FUNC<unknown>HIDDEN3
                                          __GI_strchr.symtab0x4029d0256FUNC<unknown>HIDDEN3
                                          __GI_strcpy.symtab0x406d5036FUNC<unknown>HIDDEN3
                                          __GI_strlen.symtab0x402ad0184FUNC<unknown>HIDDEN3
                                          __GI_strnlen.symtab0x402b90256FUNC<unknown>HIDDEN3
                                          __GI_strstr.symtab0x402c90256FUNC<unknown>HIDDEN3
                                          __GI_tcgetattr.symtab0x402fb0176FUNC<unknown>HIDDEN3
                                          __GI_tolower.symtab0x404d4060FUNC<unknown>HIDDEN3
                                          __GI_vfprintf.symtab0x401080260FUNC<unknown>HIDDEN3
                                          __GI_vsnprintf.symtab0x4051f0260FUNC<unknown>HIDDEN3
                                          __GI_wait4.symtab0x40730088FUNC<unknown>HIDDEN3
                                          __GI_waitpid.symtab0x404d2028FUNC<unknown>HIDDEN3
                                          __GI_wcrtomb.symtab0x404d80112FUNC<unknown>HIDDEN3
                                          __GI_wcsnrtombs.symtab0x404e30228FUNC<unknown>HIDDEN3
                                          __GI_wcsrtombs.symtab0x404df064FUNC<unknown>HIDDEN3
                                          __GI_write.symtab0x40736084FUNC<unknown>HIDDEN3
                                          __JCR_END__.symtab0x4491540OBJECT<unknown>DEFAULT9
                                          __JCR_LIST__.symtab0x4491540OBJECT<unknown>DEFAULT9
                                          __app_fini.symtab0x44b7ac4OBJECT<unknown>HIDDEN13
                                          __atexit_lock.symtab0x44946024OBJECT<unknown>DEFAULT10
                                          __bss_start.symtab0x44972c0NOTYPE<unknown>DEFAULTSHN_ABS
                                          __check_one_fd.symtab0x4042d4136FUNC<unknown>DEFAULT3
                                          __ctype_b.symtab0x4494244OBJECT<unknown>DEFAULT10
                                          __ctype_tolower.symtab0x4494344OBJECT<unknown>DEFAULT10
                                          __curbrk.symtab0x44b7f04OBJECT<unknown>HIDDEN13
                                          __data_start.symtab0x4491800OBJECT<unknown>DEFAULT10
                                          __deregister_frame_info.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          __do_global_ctors_aux.symtab0x407bf00FUNC<unknown>DEFAULT3
                                          __do_global_dtors_aux.symtab0x4001600FUNC<unknown>DEFAULT3
                                          __dso_handle.symtab0x4491600OBJECT<unknown>HIDDEN10
                                          __environ.symtab0x44b7a44OBJECT<unknown>DEFAULT13
                                          __errno_location.symtab0x40098024FUNC<unknown>DEFAULT3
                                          __errno_location.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          __exit_cleanup.symtab0x44b7e04OBJECT<unknown>HIDDEN13
                                          __fgetc_unlocked.symtab0x406950388FUNC<unknown>DEFAULT3
                                          __fini_array_end.symtab0x4491440NOTYPE<unknown>HIDDENSHN_ABS
                                          __fini_array_start.symtab0x4491440NOTYPE<unknown>HIDDENSHN_ABS
                                          __glibc_strerror_r.symtab0x402d9068FUNC<unknown>DEFAULT3
                                          __glibc_strerror_r.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          __h_errno_location.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          __heap_alloc.symtab0x403e20188FUNC<unknown>DEFAULT3
                                          __heap_free.symtab0x403f28364FUNC<unknown>DEFAULT3
                                          __heap_link_free_area.symtab0x403ee044FUNC<unknown>DEFAULT3
                                          __heap_link_free_area_after.symtab0x403f0c28FUNC<unknown>DEFAULT3
                                          __init_array_end.symtab0x4491440NOTYPE<unknown>HIDDENSHN_ABS
                                          __init_array_start.symtab0x4491440NOTYPE<unknown>HIDDENSHN_ABS
                                          __libc_close.symtab0x40086084FUNC<unknown>DEFAULT3
                                          __libc_connect.symtab0x40398084FUNC<unknown>DEFAULT3
                                          __libc_creat.symtab0x404c6c28FUNC<unknown>DEFAULT3
                                          __libc_fcntl.symtab0x404790136FUNC<unknown>DEFAULT3
                                          __libc_fcntl64.symtab0x404820104FUNC<unknown>DEFAULT3
                                          __libc_fork.symtab0x4008c084FUNC<unknown>DEFAULT3
                                          __libc_getpid.symtab0x407a2084FUNC<unknown>DEFAULT3
                                          __libc_lseek64.symtab0x407ae0168FUNC<unknown>DEFAULT3
                                          __libc_nanosleep.symtab0x404b9084FUNC<unknown>DEFAULT3
                                          __libc_open.symtab0x404bf0124FUNC<unknown>DEFAULT3
                                          __libc_read.symtab0x407b9084FUNC<unknown>DEFAULT3
                                          __libc_send.symtab0x4039e084FUNC<unknown>DEFAULT3
                                          __libc_sigaction.symtab0x407110232FUNC<unknown>DEFAULT3
                                          __libc_stack_end.symtab0x44b7a04OBJECT<unknown>DEFAULT13
                                          __libc_waitpid.symtab0x404d2028FUNC<unknown>DEFAULT3
                                          __libc_write.symtab0x40736084FUNC<unknown>DEFAULT3
                                          __malloc_heap.symtab0x4494004OBJECT<unknown>DEFAULT10
                                          __malloc_heap_lock.symtab0x44b78024OBJECT<unknown>DEFAULT13
                                          __malloc_sbrk_lock.symtab0x44b80024OBJECT<unknown>DEFAULT13
                                          __pagesize.symtab0x44b7a84OBJECT<unknown>DEFAULT13
                                          __preinit_array_end.symtab0x4491440NOTYPE<unknown>HIDDENSHN_ABS
                                          __preinit_array_start.symtab0x4491440NOTYPE<unknown>HIDDENSHN_ABS
                                          __pthread_initialize_minimal.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          __pthread_mutex_init.symtab0x4042c48FUNC<unknown>DEFAULT3
                                          __pthread_mutex_lock.symtab0x4042c48FUNC<unknown>DEFAULT3
                                          __pthread_mutex_trylock.symtab0x4042c48FUNC<unknown>DEFAULT3
                                          __pthread_mutex_unlock.symtab0x4042c48FUNC<unknown>DEFAULT3
                                          __pthread_return_0.symtab0x4042c48FUNC<unknown>DEFAULT3
                                          __pthread_return_void.symtab0x4042cc8FUNC<unknown>DEFAULT3
                                          __raise.symtab0x40794076FUNC<unknown>HIDDEN3
                                          __register_frame_info.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                          __rtld_fini.symtab0x44b7b04OBJECT<unknown>HIDDEN13
                                          __sigaddset.symtab0x4079b844FUNC<unknown>DEFAULT3
                                          __sigdelset.symtab0x4079e448FUNC<unknown>DEFAULT3
                                          __sigismember.symtab0x40799040FUNC<unknown>DEFAULT3
                                          __start.symtab0x4002a0100FUNC<unknown>DEFAULT3
                                          __stdin.symtab0x4491ec4OBJECT<unknown>DEFAULT10
                                          __stdio_READ.symtab0x4075a0140FUNC<unknown>HIDDEN3
                                          __stdio_WRITE.symtab0x405300280FUNC<unknown>HIDDEN3
                                          __stdio_adjust_position.symtab0x407630324FUNC<unknown>HIDDEN3
                                          __stdio_fwrite.symtab0x405790472FUNC<unknown>HIDDEN3
                                          __stdio_init_mutex.symtab0x400ec832FUNC<unknown>HIDDEN3
                                          __stdio_mutex_initializer.3833.symtab0x407d6024OBJECT<unknown>DEFAULT5
                                          __stdio_rfill.symtab0x40778088FUNC<unknown>HIDDEN3
                                          __stdio_seek.symtab0x4078d0112FUNC<unknown>HIDDEN3
                                          __stdio_trans2r_o.symtab0x4077e0228FUNC<unknown>HIDDEN3
                                          __stdio_trans2w_o.symtab0x405970308FUNC<unknown>HIDDEN3
                                          __stdio_wcommit.symtab0x401010100FUNC<unknown>HIDDEN3
                                          __stdout.symtab0x4491f04OBJECT<unknown>DEFAULT10
                                          __syscall_error.symtab0x4070c072FUNC<unknown>HIDDEN3
                                          __syscall_error.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          __syscall_fcntl.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          __syscall_fcntl64.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          __syscall_rt_sigaction.symtab0x40720084FUNC<unknown>HIDDEN3
                                          __syscall_rt_sigaction.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          __uClibc_fini.symtab0x404200196FUNC<unknown>DEFAULT3
                                          __uClibc_init.symtab0x40435c140FUNC<unknown>DEFAULT3
                                          __uClibc_main.symtab0x4043e8864FUNC<unknown>DEFAULT3
                                          __uClibc_main.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          __uclibc_progname.symtab0x4494104OBJECT<unknown>HIDDEN10
                                          __xpg_strerror_r.symtab0x402de0392FUNC<unknown>DEFAULT3
                                          __xpg_strerror_r.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          _adjust_pos.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          _charpad.symtab0x401190128FUNC<unknown>DEFAULT3
                                          _cs_funcs.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          _dl_aux_init.symtab0x40702044FUNC<unknown>DEFAULT3
                                          _dl_phdr.symtab0x44972c4OBJECT<unknown>DEFAULT12
                                          _dl_phnum.symtab0x4497304OBJECT<unknown>DEFAULT12
                                          _edata.symtab0x44972c0NOTYPE<unknown>DEFAULTSHN_ABS
                                          _end.symtab0x44b8180NOTYPE<unknown>DEFAULTSHN_ABS
                                          _errno.symtab0x44b7c04OBJECT<unknown>DEFAULT13
                                          _exit.symtab0x40489080FUNC<unknown>DEFAULT3
                                          _exit.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          _fbss.symtab0x44972c0NOTYPE<unknown>DEFAULTSHN_ABS
                                          _fdata.symtab0x4491600NOTYPE<unknown>DEFAULT10
                                          _fini.symtab0x407c6028FUNC<unknown>DEFAULT4
                                          _fixed_buffers.symtab0x4497788192OBJECT<unknown>DEFAULT13
                                          _fopen.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          _fp_out_narrow.symtab0x401210228FUNC<unknown>DEFAULT3
                                          _fpmaxtostr.symtab0x405cf02120FUNC<unknown>HIDDEN3
                                          _fpmaxtostr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          _ftext.symtab0x4001600NOTYPE<unknown>DEFAULT3
                                          _fwrite.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          _gp.symtab0x4514700NOTYPE<unknown>DEFAULTSHN_ABS
                                          _gp_disp.symtab0x00OBJECT<unknown>DEFAULTSHN_UNDEF
                                          _h_errno.symtab0x44b7c44OBJECT<unknown>DEFAULT13
                                          _init.symtab0x4000cc28FUNC<unknown>DEFAULT2
                                          _load_inttype.symtab0x405ab0136FUNC<unknown>HIDDEN3
                                          _load_inttype.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          _ppfs_init.symtab0x401aa0220FUNC<unknown>HIDDEN3
                                          _ppfs_init.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          _ppfs_parsespec.symtab0x401e7c1512FUNC<unknown>HIDDEN3
                                          _ppfs_parsespec.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          _ppfs_prepargs.symtab0x401b80100FUNC<unknown>HIDDEN3
                                          _ppfs_prepargs.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          _ppfs_setargs.symtab0x401bf0540FUNC<unknown>HIDDEN3
                                          _ppfs_setargs.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          _promoted_size.symtab0x401e10108FUNC<unknown>DEFAULT3
                                          _pthread_cleanup_pop_restore.symtab0x4042cc8FUNC<unknown>DEFAULT3
                                          _pthread_cleanup_push_defer.symtab0x4042cc8FUNC<unknown>DEFAULT3
                                          _rfill.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          _stdio.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          _stdio_fopen.symtab0x405420880FUNC<unknown>HIDDEN3
                                          _stdio_init.symtab0x400e10184FUNC<unknown>HIDDEN3
                                          _stdio_openlist.symtab0x4491f44OBJECT<unknown>DEFAULT10
                                          _stdio_openlist_add_lock.symtab0x4491a024OBJECT<unknown>DEFAULT10
                                          _stdio_openlist_dec_use.symtab0x406540400FUNC<unknown>DEFAULT3
                                          _stdio_openlist_del_count.symtab0x4497744OBJECT<unknown>DEFAULT13
                                          _stdio_openlist_del_lock.symtab0x4491b824OBJECT<unknown>DEFAULT10
                                          _stdio_openlist_use_count.symtab0x4497704OBJECT<unknown>DEFAULT13
                                          _stdio_streams.symtab0x4491f8240OBJECT<unknown>DEFAULT10
                                          _stdio_term.symtab0x400ee8284FUNC<unknown>HIDDEN3
                                          _stdio_user_locking.symtab0x4491d04OBJECT<unknown>DEFAULT10
                                          _store_inttype.symtab0x405b4068FUNC<unknown>HIDDEN3
                                          _store_inttype.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          _string_syserrmsgs.symtab0x407ed02934OBJECT<unknown>HIDDEN5
                                          _string_syserrmsgs.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          _trans2r.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          _trans2w.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          _uintmaxtostr.symtab0x405b90340FUNC<unknown>HIDDEN3
                                          _uintmaxtostr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          _vfprintf_internal.symtab0x4012f41960FUNC<unknown>HIDDEN3
                                          _vfprintf_internal.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          _wcommit.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          abort.symtab0x406d80428FUNC<unknown>DEFAULT3
                                          abort.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          been_there_done_that.symtab0x44b7d04OBJECT<unknown>DEFAULT13
                                          been_there_done_that.2792.symtab0x44b7b44OBJECT<unknown>DEFAULT13
                                          blacklist.symtab0x44919012OBJECT<unknown>DEFAULT10
                                          brk.symtab0x407050112FUNC<unknown>DEFAULT3
                                          brk.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          close.symtab0x40086084FUNC<unknown>DEFAULT3
                                          close.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          completed.2296.symtab0x4497401OBJECT<unknown>DEFAULT13
                                          connect.symtab0x40398084FUNC<unknown>DEFAULT3
                                          connect.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          creat.symtab0x404c6c28FUNC<unknown>DEFAULT3
                                          crtstuff.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          crtstuff.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          data_start.symtab0x4491800OBJECT<unknown>DEFAULT10
                                          dl-support.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          dup2.symtab0x4048e084FUNC<unknown>DEFAULT3
                                          dup2.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          environ.symtab0x44b7a44OBJECT<unknown>DEFAULT13
                                          errno.symtab0x44b7c04OBJECT<unknown>DEFAULT13
                                          errno.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          estridx.symtab0x407e40126OBJECT<unknown>DEFAULT5
                                          execl.symtab0x4040a0204FUNC<unknown>DEFAULT3
                                          execl.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          execve.symtab0x40494084FUNC<unknown>DEFAULT3
                                          execve.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          exit.symtab0x406f30236FUNC<unknown>DEFAULT3
                                          exit.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          exp10_table.symtab0x4090f872OBJECT<unknown>DEFAULT5
                                          fclose.symtab0x404f20512FUNC<unknown>DEFAULT3
                                          fclose.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          fcntl.symtab0x404790136FUNC<unknown>DEFAULT3
                                          fcntl64.symtab0x404820104FUNC<unknown>DEFAULT3
                                          fdopen.symtab0x405120128FUNC<unknown>DEFAULT3
                                          fdopen.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          fflush_unlocked.symtab0x4066d0628FUNC<unknown>DEFAULT3
                                          fflush_unlocked.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          fgetc_unlocked.symtab0x406950388FUNC<unknown>DEFAULT3
                                          fgetc_unlocked.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          fgets.symtab0x402470216FUNC<unknown>DEFAULT3
                                          fgets.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          fgets_unlocked.symtab0x402550268FUNC<unknown>DEFAULT3
                                          fgets_unlocked.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          fmt.symtab0x4090e020OBJECT<unknown>DEFAULT5
                                          fork.symtab0x4008c084FUNC<unknown>DEFAULT3
                                          fork.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          fprintf.symtab0x400a0072FUNC<unknown>DEFAULT3
                                          fprintf.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          fputs_unlocked.symtab0x402660128FUNC<unknown>DEFAULT3
                                          fputs_unlocked.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          frame_dummy.symtab0x40021c0FUNC<unknown>DEFAULT3
                                          free.symtab0x403c90396FUNC<unknown>DEFAULT3
                                          free.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          fseek.symtab0x4073c068FUNC<unknown>DEFAULT3
                                          fseeko.symtab0x4073c068FUNC<unknown>DEFAULT3
                                          fseeko.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          fseeko64.symtab0x407410388FUNC<unknown>DEFAULT3
                                          fseeko64.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          fwrite_unlocked.symtab0x4026e0280FUNC<unknown>DEFAULT3
                                          fwrite_unlocked.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          getc_unlocked.symtab0x406950388FUNC<unknown>DEFAULT3
                                          getegid.symtab0x4049a088FUNC<unknown>DEFAULT3
                                          getegid.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          geteuid.symtab0x404a0088FUNC<unknown>DEFAULT3
                                          geteuid.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          getgid.symtab0x404a6084FUNC<unknown>DEFAULT3
                                          getgid.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          getpid.symtab0x407a2084FUNC<unknown>DEFAULT3
                                          getpid.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          getuid.symtab0x404ac084FUNC<unknown>DEFAULT3
                                          getuid.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          h_errno.symtab0x44b7c44OBJECT<unknown>DEFAULT13
                                          heap_alloc.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          heap_free.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          hlt.symtab0x4002fc0NOTYPE<unknown>DEFAULT3
                                          htonl.symtab0x4030708FUNC<unknown>DEFAULT3
                                          htons.symtab0x4030788FUNC<unknown>DEFAULT3
                                          index.symtab0x4029d0256FUNC<unknown>DEFAULT3
                                          inet_ntop.symtab0x403620852FUNC<unknown>DEFAULT3
                                          inet_ntop4.symtab0x40342c500FUNC<unknown>DEFAULT3
                                          inet_pton.symtab0x403170700FUNC<unknown>DEFAULT3
                                          inet_pton4.symtab0x403080240FUNC<unknown>DEFAULT3
                                          initfini.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          initfini.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          initial_fa.symtab0x4492f0264OBJECT<unknown>DEFAULT10
                                          ioctl.symtab0x404b20104FUNC<unknown>DEFAULT3
                                          ioctl.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          is_blacklisted.symtab0x4004cc200FUNC<unknown>DEFAULT3
                                          isatty.symtab0x402f7060FUNC<unknown>DEFAULT3
                                          isatty.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          kill.symtab0x407a8088FUNC<unknown>DEFAULT3
                                          kill.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          libc/string/mips/memcpy.S.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          libc/string/mips/memset.S.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          libc/sysdeps/linux/mips/crt1.S.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          libc/sysdeps/linux/mips/crti.S.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          libc/sysdeps/linux/mips/crtn.S.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          libc/sysdeps/linux/mips/pipe.S.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          llseek.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          lseek64.symtab0x407ae0168FUNC<unknown>DEFAULT3
                                          main.symtab0x40077c220FUNC<unknown>DEFAULT3
                                          malloc.symtab0x403aa0492FUNC<unknown>DEFAULT3
                                          malloc.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          memchr.symtab0x406ae0264FUNC<unknown>DEFAULT3
                                          memchr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          memcpy.symtab0x402800308FUNC<unknown>DEFAULT3
                                          mempcpy.symtab0x406bf076FUNC<unknown>DEFAULT3
                                          mempcpy.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          memrchr.symtab0x406c40272FUNC<unknown>DEFAULT3
                                          memrchr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          memset.symtab0x402940144FUNC<unknown>DEFAULT3
                                          monitor_processes.symtab0x400594488FUNC<unknown>DEFAULT3
                                          mylock.symtab0x44944024OBJECT<unknown>DEFAULT10
                                          nanosleep.symtab0x404b9084FUNC<unknown>DEFAULT3
                                          nanosleep.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          ntohl.symtab0x4030608FUNC<unknown>DEFAULT3
                                          ntohl.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          ntohs.symtab0x4030688FUNC<unknown>DEFAULT3
                                          ntop.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          object.2349.symtab0x44974424OBJECT<unknown>DEFAULT13
                                          open.symtab0x404bf0124FUNC<unknown>DEFAULT3
                                          open.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          p.2294.symtab0x4491700OBJECT<unknown>DEFAULT10
                                          pclose.symtab0x400a50324FUNC<unknown>DEFAULT3
                                          perror.symtab0x4009a084FUNC<unknown>DEFAULT3
                                          perror.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          pipe.symtab0x40475064FUNC<unknown>DEFAULT3
                                          popen.symtab0x400b94636FUNC<unknown>DEFAULT3
                                          popen.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          popen_list.symtab0x4497604OBJECT<unknown>DEFAULT13
                                          prefix.4045.symtab0x407d9012OBJECT<unknown>DEFAULT5
                                          ps.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          qual_chars.4050.symtab0x407db020OBJECT<unknown>DEFAULT5
                                          raise.symtab0x40794076FUNC<unknown>DEFAULT3
                                          raise.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          read.symtab0x407b9084FUNC<unknown>DEFAULT3
                                          read.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          sbrk.symtab0x404c90144FUNC<unknown>DEFAULT3
                                          sbrk.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          send.symtab0x4039e084FUNC<unknown>DEFAULT3
                                          send.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          send_to_server.symtab0x400310444FUNC<unknown>DEFAULT3
                                          setsid.symtab0x40092084FUNC<unknown>DEFAULT3
                                          setsid.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          sigaction.symtab0x407110232FUNC<unknown>DEFAULT3
                                          sigaction.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          sigprocmask.symtab0x407260148FUNC<unknown>DEFAULT3
                                          sigprocmask.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          sigsetops.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          socket.symtab0x403a4084FUNC<unknown>DEFAULT3
                                          socket.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          spec_and_mask.4049.symtab0x407dc416OBJECT<unknown>DEFAULT5
                                          spec_base.4044.symtab0x407d9c7OBJECT<unknown>DEFAULT5
                                          spec_chars.4046.symtab0x407df021OBJECT<unknown>DEFAULT5
                                          spec_flags.4045.symtab0x407e088OBJECT<unknown>DEFAULT5
                                          spec_or_mask.4048.symtab0x407dd416OBJECT<unknown>DEFAULT5
                                          spec_ranges.4047.symtab0x407de49OBJECT<unknown>DEFAULT5
                                          sprintf.symtab0x4051a080FUNC<unknown>DEFAULT3
                                          sprintf.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          stderr.symtab0x4491e84OBJECT<unknown>DEFAULT10
                                          stdin.symtab0x4491e04OBJECT<unknown>DEFAULT10
                                          stdout.symtab0x4491e44OBJECT<unknown>DEFAULT10
                                          strchr.symtab0x4029d0256FUNC<unknown>DEFAULT3
                                          strchr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          strcpy.symtab0x406d5036FUNC<unknown>DEFAULT3
                                          strcpy.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          strerror_r.symtab0x402de0392FUNC<unknown>DEFAULT3
                                          strlen.symtab0x402ad0184FUNC<unknown>DEFAULT3
                                          strlen.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          strnlen.symtab0x402b90256FUNC<unknown>DEFAULT3
                                          strnlen.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          strstr.symtab0x402c90256FUNC<unknown>DEFAULT3
                                          strstr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          tcgetattr.symtab0x402fb0176FUNC<unknown>DEFAULT3
                                          tcgetattr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          tolower.symtab0x404d4060FUNC<unknown>DEFAULT3
                                          tolower.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          type_codes.symtab0x407e1024OBJECT<unknown>DEFAULT5
                                          type_sizes.symtab0x407e2812OBJECT<unknown>DEFAULT5
                                          unknown.1088.symtab0x407ec014OBJECT<unknown>DEFAULT5
                                          usleep.symtab0x404170144FUNC<unknown>DEFAULT3
                                          usleep.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          vfprintf.symtab0x401080260FUNC<unknown>DEFAULT3
                                          vfprintf.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          vsnprintf.symtab0x4051f0260FUNC<unknown>DEFAULT3
                                          vsnprintf.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          wait4.symtab0x40730088FUNC<unknown>DEFAULT3
                                          wait4.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          waitpid.symtab0x404d2028FUNC<unknown>DEFAULT3
                                          waitpid.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          wcrtomb.symtab0x404d80112FUNC<unknown>DEFAULT3
                                          wcrtomb.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          wcsnrtombs.symtab0x404e30228FUNC<unknown>DEFAULT3
                                          wcsnrtombs.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          wcsrtombs.symtab0x404df064FUNC<unknown>DEFAULT3
                                          wcsrtombs.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          write.symtab0x40736084FUNC<unknown>DEFAULT3
                                          write.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                          xdigits.3043.symtab0x408a6417OBJECT<unknown>DEFAULT5

                                          Download Network PCAP: filteredfull

                                          TimestampSource PortDest PortSource IPDest IP
                                          Mar 20, 2025 13:07:25.867618084 CET34592443192.168.2.1454.217.10.153
                                          Mar 20, 2025 13:07:54.444633961 CET37910443192.168.2.1454.171.230.55
                                          Mar 20, 2025 13:07:54.444696903 CET4433791054.171.230.55192.168.2.14
                                          Mar 20, 2025 13:07:54.444752932 CET37910443192.168.2.1454.171.230.55
                                          Mar 20, 2025 13:07:54.462749958 CET37910443192.168.2.1454.171.230.55
                                          Mar 20, 2025 13:07:54.462779999 CET4433791054.171.230.55192.168.2.14
                                          Mar 20, 2025 13:08:54.442821980 CET37910443192.168.2.1454.171.230.55
                                          Mar 20, 2025 13:08:54.488318920 CET4433791054.171.230.55192.168.2.14
                                          Mar 20, 2025 13:09:28.837861061 CET4433791054.171.230.55192.168.2.14

                                          System Behavior

                                          Start time (UTC):12:07:24
                                          Start date (UTC):20/03/2025
                                          Path:/tmp/psmips.elf
                                          Arguments:/tmp/psmips.elf
                                          File size:5777432 bytes
                                          MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                          Start time (UTC):12:07:24
                                          Start date (UTC):20/03/2025
                                          Path:/tmp/psmips.elf
                                          Arguments:-
                                          File size:5777432 bytes
                                          MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                          Start time (UTC):12:07:24
                                          Start date (UTC):20/03/2025
                                          Path:/tmp/psmips.elf
                                          Arguments:-
                                          File size:5777432 bytes
                                          MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                          Start time (UTC):12:07:24
                                          Start date (UTC):20/03/2025
                                          Path:/bin/sh
                                          Arguments:sh -c "ps w"
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                          Start time (UTC):12:07:24
                                          Start date (UTC):20/03/2025
                                          Path:/bin/sh
                                          Arguments:-
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                          Start time (UTC):12:07:24
                                          Start date (UTC):20/03/2025
                                          Path:/usr/bin/ps
                                          Arguments:ps w
                                          File size:137688 bytes
                                          MD5 hash:ab48054475a6f70f8e7fa847331f3327

                                          Start time (UTC):12:07:27
                                          Start date (UTC):20/03/2025
                                          Path:/tmp/psmips.elf
                                          Arguments:-
                                          File size:5777432 bytes
                                          MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                          Start time (UTC):12:07:27
                                          Start date (UTC):20/03/2025
                                          Path:/bin/sh
                                          Arguments:sh -c "ps w"
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                          Start time (UTC):12:07:27
                                          Start date (UTC):20/03/2025
                                          Path:/bin/sh
                                          Arguments:-
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                          Start time (UTC):12:07:27
                                          Start date (UTC):20/03/2025
                                          Path:/usr/bin/ps
                                          Arguments:ps w
                                          File size:137688 bytes
                                          MD5 hash:ab48054475a6f70f8e7fa847331f3327

                                          Start time (UTC):12:07:31
                                          Start date (UTC):20/03/2025
                                          Path:/tmp/psmips.elf
                                          Arguments:-
                                          File size:5777432 bytes
                                          MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                          Start time (UTC):12:07:31
                                          Start date (UTC):20/03/2025
                                          Path:/bin/sh
                                          Arguments:sh -c "ps w"
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                          Start time (UTC):12:07:31
                                          Start date (UTC):20/03/2025
                                          Path:/bin/sh
                                          Arguments:-
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                          Start time (UTC):12:07:31
                                          Start date (UTC):20/03/2025
                                          Path:/usr/bin/ps
                                          Arguments:ps w
                                          File size:137688 bytes
                                          MD5 hash:ab48054475a6f70f8e7fa847331f3327

                                          Start time (UTC):12:07:34
                                          Start date (UTC):20/03/2025
                                          Path:/tmp/psmips.elf
                                          Arguments:-
                                          File size:5777432 bytes
                                          MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                          Start time (UTC):12:07:34
                                          Start date (UTC):20/03/2025
                                          Path:/bin/sh
                                          Arguments:sh -c "ps w"
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                          Start time (UTC):12:07:34
                                          Start date (UTC):20/03/2025
                                          Path:/bin/sh
                                          Arguments:-
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                          Start time (UTC):12:07:34
                                          Start date (UTC):20/03/2025
                                          Path:/usr/bin/ps
                                          Arguments:ps w
                                          File size:137688 bytes
                                          MD5 hash:ab48054475a6f70f8e7fa847331f3327

                                          Start time (UTC):12:07:38
                                          Start date (UTC):20/03/2025
                                          Path:/tmp/psmips.elf
                                          Arguments:-
                                          File size:5777432 bytes
                                          MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                          Start time (UTC):12:07:38
                                          Start date (UTC):20/03/2025
                                          Path:/bin/sh
                                          Arguments:sh -c "ps w"
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                          Start time (UTC):12:07:38
                                          Start date (UTC):20/03/2025
                                          Path:/bin/sh
                                          Arguments:-
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                          Start time (UTC):12:07:38
                                          Start date (UTC):20/03/2025
                                          Path:/usr/bin/ps
                                          Arguments:ps w
                                          File size:137688 bytes
                                          MD5 hash:ab48054475a6f70f8e7fa847331f3327

                                          Start time (UTC):12:07:41
                                          Start date (UTC):20/03/2025
                                          Path:/tmp/psmips.elf
                                          Arguments:-
                                          File size:5777432 bytes
                                          MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                          Start time (UTC):12:07:41
                                          Start date (UTC):20/03/2025
                                          Path:/bin/sh
                                          Arguments:sh -c "ps w"
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                          Start time (UTC):12:07:41
                                          Start date (UTC):20/03/2025
                                          Path:/bin/sh
                                          Arguments:-
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                          Start time (UTC):12:07:41
                                          Start date (UTC):20/03/2025
                                          Path:/usr/bin/ps
                                          Arguments:ps w
                                          File size:137688 bytes
                                          MD5 hash:ab48054475a6f70f8e7fa847331f3327

                                          Start time (UTC):12:07:43
                                          Start date (UTC):20/03/2025
                                          Path:/tmp/psmips.elf
                                          Arguments:-
                                          File size:5777432 bytes
                                          MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                          Start time (UTC):12:07:43
                                          Start date (UTC):20/03/2025
                                          Path:/bin/sh
                                          Arguments:sh -c "ps w"
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                          Start time (UTC):12:07:43
                                          Start date (UTC):20/03/2025
                                          Path:/bin/sh
                                          Arguments:-
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                          Start time (UTC):12:07:43
                                          Start date (UTC):20/03/2025
                                          Path:/usr/bin/ps
                                          Arguments:ps w
                                          File size:137688 bytes
                                          MD5 hash:ab48054475a6f70f8e7fa847331f3327

                                          Start time (UTC):12:07:46
                                          Start date (UTC):20/03/2025
                                          Path:/tmp/psmips.elf
                                          Arguments:-
                                          File size:5777432 bytes
                                          MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                          Start time (UTC):12:07:46
                                          Start date (UTC):20/03/2025
                                          Path:/bin/sh
                                          Arguments:sh -c "ps w"
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                          Start time (UTC):12:07:46
                                          Start date (UTC):20/03/2025
                                          Path:/bin/sh
                                          Arguments:-
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                          Start time (UTC):12:07:46
                                          Start date (UTC):20/03/2025
                                          Path:/usr/bin/ps
                                          Arguments:ps w
                                          File size:137688 bytes
                                          MD5 hash:ab48054475a6f70f8e7fa847331f3327

                                          Start time (UTC):12:07:49
                                          Start date (UTC):20/03/2025
                                          Path:/tmp/psmips.elf
                                          Arguments:-
                                          File size:5777432 bytes
                                          MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                          Start time (UTC):12:07:49
                                          Start date (UTC):20/03/2025
                                          Path:/bin/sh
                                          Arguments:sh -c "ps w"
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                          Start time (UTC):12:07:49
                                          Start date (UTC):20/03/2025
                                          Path:/bin/sh
                                          Arguments:-
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                          Start time (UTC):12:07:49
                                          Start date (UTC):20/03/2025
                                          Path:/usr/bin/ps
                                          Arguments:ps w
                                          File size:137688 bytes
                                          MD5 hash:ab48054475a6f70f8e7fa847331f3327

                                          Start time (UTC):12:07:52
                                          Start date (UTC):20/03/2025
                                          Path:/tmp/psmips.elf
                                          Arguments:-
                                          File size:5777432 bytes
                                          MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                          Start time (UTC):12:07:53
                                          Start date (UTC):20/03/2025
                                          Path:/bin/sh
                                          Arguments:sh -c "ps w"
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                          Start time (UTC):12:07:53
                                          Start date (UTC):20/03/2025
                                          Path:/bin/sh
                                          Arguments:-
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                          Start time (UTC):12:07:53
                                          Start date (UTC):20/03/2025
                                          Path:/usr/bin/ps
                                          Arguments:ps w
                                          File size:137688 bytes
                                          MD5 hash:ab48054475a6f70f8e7fa847331f3327

                                          Start time (UTC):12:07:56
                                          Start date (UTC):20/03/2025
                                          Path:/tmp/psmips.elf
                                          Arguments:-
                                          File size:5777432 bytes
                                          MD5 hash:0083f1f0e77be34ad27f849842bbb00c
                                          Start time (UTC):12:07:56
                                          Start date (UTC):20/03/2025
                                          Path:/bin/sh
                                          Arguments:sh -c "ps w"
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
                                          Start time (UTC):12:07:56
                                          Start date (UTC):20/03/2025
                                          Path:/bin/sh
                                          Arguments:-
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
                                          Start time (UTC):12:07:56
                                          Start date (UTC):20/03/2025
                                          Path:/usr/bin/ps
                                          Arguments:ps w
                                          File size:137688 bytes
                                          MD5 hash:ab48054475a6f70f8e7fa847331f3327
                                          Start time (UTC):12:07:59
                                          Start date (UTC):20/03/2025
                                          Path:/tmp/psmips.elf
                                          Arguments:-
                                          File size:5777432 bytes
                                          MD5 hash:0083f1f0e77be34ad27f849842bbb00c
                                          Start time (UTC):12:07:59
                                          Start date (UTC):20/03/2025
                                          Path:/bin/sh
                                          Arguments:sh -c "ps w"
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
                                          Start time (UTC):12:07:59
                                          Start date (UTC):20/03/2025
                                          Path:/bin/sh
                                          Arguments:-
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
                                          Start time (UTC):12:07:59
                                          Start date (UTC):20/03/2025
                                          Path:/usr/bin/ps
                                          Arguments:ps w
                                          File size:137688 bytes
                                          MD5 hash:ab48054475a6f70f8e7fa847331f3327
                                          Start time (UTC):12:08:02
                                          Start date (UTC):20/03/2025
                                          Path:/tmp/psmips.elf
                                          Arguments:-
                                          File size:5777432 bytes
                                          MD5 hash:0083f1f0e77be34ad27f849842bbb00c
                                          Start time (UTC):12:08:02
                                          Start date (UTC):20/03/2025
                                          Path:/bin/sh
                                          Arguments:sh -c "ps w"
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
                                          Start time (UTC):12:08:02
                                          Start date (UTC):20/03/2025
                                          Path:/bin/sh
                                          Arguments:-
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
                                          Start time (UTC):12:08:02
                                          Start date (UTC):20/03/2025
                                          Path:/usr/bin/ps
                                          Arguments:ps w
                                          File size:137688 bytes
                                          MD5 hash:ab48054475a6f70f8e7fa847331f3327
                                          Start time (UTC):12:08:05
                                          Start date (UTC):20/03/2025
                                          Path:/tmp/psmips.elf
                                          Arguments:-
                                          File size:5777432 bytes
                                          MD5 hash:0083f1f0e77be34ad27f849842bbb00c
                                          Start time (UTC):12:08:05
                                          Start date (UTC):20/03/2025
                                          Path:/bin/sh
                                          Arguments:sh -c "ps w"
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
                                          Start time (UTC):12:08:05
                                          Start date (UTC):20/03/2025
                                          Path:/bin/sh
                                          Arguments:-
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
                                          Start time (UTC):12:08:05
                                          Start date (UTC):20/03/2025
                                          Path:/usr/bin/ps
                                          Arguments:ps w
                                          File size:137688 bytes
                                          MD5 hash:ab48054475a6f70f8e7fa847331f3327
                                          Start time (UTC):12:08:08
                                          Start date (UTC):20/03/2025
                                          Path:/tmp/psmips.elf
                                          Arguments:-
                                          File size:5777432 bytes
                                          MD5 hash:0083f1f0e77be34ad27f849842bbb00c
                                          Start time (UTC):12:08:08
                                          Start date (UTC):20/03/2025
                                          Path:/bin/sh
                                          Arguments:sh -c "ps w"
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
                                          Start time (UTC):12:08:08
                                          Start date (UTC):20/03/2025
                                          Path:/bin/sh
                                          Arguments:-
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
                                          Start time (UTC):12:08:08
                                          Start date (UTC):20/03/2025
                                          Path:/usr/bin/ps
                                          Arguments:ps w
                                          File size:137688 bytes
                                          MD5 hash:ab48054475a6f70f8e7fa847331f3327
                                          Start time (UTC):12:08:12
                                          Start date (UTC):20/03/2025
                                          Path:/tmp/psmips.elf
                                          Arguments:-
                                          File size:5777432 bytes
                                          MD5 hash:0083f1f0e77be34ad27f849842bbb00c
                                          Start time (UTC):12:08:12
                                          Start date (UTC):20/03/2025
                                          Path:/bin/sh
                                          Arguments:sh -c "ps w"
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
                                          Start time (UTC):12:08:12
                                          Start date (UTC):20/03/2025
                                          Path:/bin/sh
                                          Arguments:-
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
                                          Start time (UTC):12:08:12
                                          Start date (UTC):20/03/2025
                                          Path:/usr/bin/ps
                                          Arguments:ps w
                                          File size:137688 bytes
                                          MD5 hash:ab48054475a6f70f8e7fa847331f3327
                                          Start time (UTC):12:08:16
                                          Start date (UTC):20/03/2025
                                          Path:/tmp/psmips.elf
                                          Arguments:-
                                          File size:5777432 bytes
                                          MD5 hash:0083f1f0e77be34ad27f849842bbb00c
                                          Start time (UTC):12:08:16
                                          Start date (UTC):20/03/2025
                                          Path:/bin/sh
                                          Arguments:sh -c "ps w"
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
                                          Start time (UTC):12:08:16
                                          Start date (UTC):20/03/2025
                                          Path:/bin/sh
                                          Arguments:-
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
                                          Start time (UTC):12:08:16
                                          Start date (UTC):20/03/2025
                                          Path:/usr/bin/ps
                                          Arguments:ps w
                                          File size:137688 bytes
                                          MD5 hash:ab48054475a6f70f8e7fa847331f3327
                                          Start time (UTC):12:08:20
                                          Start date (UTC):20/03/2025
                                          Path:/tmp/psmips.elf
                                          Arguments:-
                                          File size:5777432 bytes
                                          MD5 hash:0083f1f0e77be34ad27f849842bbb00c
                                          Start time (UTC):12:08:20
                                          Start date (UTC):20/03/2025
                                          Path:/bin/sh
                                          Arguments:sh -c "ps w"
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
                                          Start time (UTC):12:08:20
                                          Start date (UTC):20/03/2025
                                          Path:/bin/sh
                                          Arguments:-
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
                                          Start time (UTC):12:08:20
                                          Start date (UTC):20/03/2025
                                          Path:/usr/bin/ps
                                          Arguments:ps w
                                          File size:137688 bytes
                                          MD5 hash:ab48054475a6f70f8e7fa847331f3327
                                          Start time (UTC):12:08:23
                                          Start date (UTC):20/03/2025
                                          Path:/tmp/psmips.elf
                                          Arguments:-
                                          File size:5777432 bytes
                                          MD5 hash:0083f1f0e77be34ad27f849842bbb00c
                                          Start time (UTC):12:08:23
                                          Start date (UTC):20/03/2025
                                          Path:/bin/sh
                                          Arguments:sh -c "ps w"
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
                                          Start time (UTC):12:08:23
                                          Start date (UTC):20/03/2025
                                          Path:/bin/sh
                                          Arguments:-
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
                                          Start time (UTC):12:08:23
                                          Start date (UTC):20/03/2025
                                          Path:/usr/bin/ps
                                          Arguments:ps w
                                          File size:137688 bytes
                                          MD5 hash:ab48054475a6f70f8e7fa847331f3327
                                          Start time (UTC):12:08:27
                                          Start date (UTC):20/03/2025
                                          Path:/tmp/psmips.elf
                                          Arguments:-
                                          File size:5777432 bytes
                                          MD5 hash:0083f1f0e77be34ad27f849842bbb00c
                                          Start time (UTC):12:08:27
                                          Start date (UTC):20/03/2025
                                          Path:/bin/sh
                                          Arguments:sh -c "ps w"
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
                                          Start time (UTC):12:08:27
                                          Start date (UTC):20/03/2025
                                          Path:/bin/sh
                                          Arguments:-
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
                                          Start time (UTC):12:08:27
                                          Start date (UTC):20/03/2025
                                          Path:/usr/bin/ps
                                          Arguments:ps w
                                          File size:137688 bytes
                                          MD5 hash:ab48054475a6f70f8e7fa847331f3327
                                          Start time (UTC):12:08:30
                                          Start date (UTC):20/03/2025
                                          Path:/tmp/psmips.elf
                                          Arguments:-
                                          File size:5777432 bytes
                                          MD5 hash:0083f1f0e77be34ad27f849842bbb00c
                                          Start time (UTC):12:08:30
                                          Start date (UTC):20/03/2025
                                          Path:/bin/sh
                                          Arguments:sh -c "ps w"
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
                                          Start time (UTC):12:08:30
                                          Start date (UTC):20/03/2025
                                          Path:/bin/sh
                                          Arguments:-
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
                                          Start time (UTC):12:08:30
                                          Start date (UTC):20/03/2025
                                          Path:/usr/bin/ps
                                          Arguments:ps w
                                          File size:137688 bytes
                                          MD5 hash:ab48054475a6f70f8e7fa847331f3327
                                          Start time (UTC):12:08:33
                                          Start date (UTC):20/03/2025
                                          Path:/tmp/psmips.elf
                                          Arguments:-
                                          File size:5777432 bytes
                                          MD5 hash:0083f1f0e77be34ad27f849842bbb00c
                                          Start time (UTC):12:08:33
                                          Start date (UTC):20/03/2025
                                          Path:/bin/sh
                                          Arguments:sh -c "ps w"
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
                                          Start time (UTC):12:08:33
                                          Start date (UTC):20/03/2025
                                          Path:/bin/sh
                                          Arguments:-
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
                                          Start time (UTC):12:08:33
                                          Start date (UTC):20/03/2025
                                          Path:/usr/bin/ps
                                          Arguments:ps w
                                          File size:137688 bytes
                                          MD5 hash:ab48054475a6f70f8e7fa847331f3327
                                          Start time (UTC):12:08:36
                                          Start date (UTC):20/03/2025
                                          Path:/tmp/psmips.elf
                                          Arguments:-
                                          File size:5777432 bytes
                                          MD5 hash:0083f1f0e77be34ad27f849842bbb00c
                                          Start time (UTC):12:08:36
                                          Start date (UTC):20/03/2025
                                          Path:/bin/sh
                                          Arguments:sh -c "ps w"
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
                                          Start time (UTC):12:08:36
                                          Start date (UTC):20/03/2025
                                          Path:/bin/sh
                                          Arguments:-
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
                                          Start time (UTC):12:08:36
                                          Start date (UTC):20/03/2025
                                          Path:/usr/bin/ps
                                          Arguments:ps w
                                          File size:137688 bytes
                                          MD5 hash:ab48054475a6f70f8e7fa847331f3327
                                          Start time (UTC):12:08:40
                                          Start date (UTC):20/03/2025
                                          Path:/tmp/psmips.elf
                                          Arguments:-
                                          File size:5777432 bytes
                                          MD5 hash:0083f1f0e77be34ad27f849842bbb00c
                                          Start time (UTC):12:08:40
                                          Start date (UTC):20/03/2025
                                          Path:/bin/sh
                                          Arguments:sh -c "ps w"
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
                                          Start time (UTC):12:08:40
                                          Start date (UTC):20/03/2025
                                          Path:/bin/sh
                                          Arguments:-
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
                                          Start time (UTC):12:08:40
                                          Start date (UTC):20/03/2025
                                          Path:/usr/bin/ps
                                          Arguments:ps w
                                          File size:137688 bytes
                                          MD5 hash:ab48054475a6f70f8e7fa847331f3327
                                          Start time (UTC):12:08:43
                                          Start date (UTC):20/03/2025
                                          Path:/tmp/psmips.elf
                                          Arguments:-
                                          File size:5777432 bytes
                                          MD5 hash:0083f1f0e77be34ad27f849842bbb00c
                                          Start time (UTC):12:08:43
                                          Start date (UTC):20/03/2025
                                          Path:/bin/sh
                                          Arguments:sh -c "ps w"
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
                                          Start time (UTC):12:08:43
                                          Start date (UTC):20/03/2025
                                          Path:/bin/sh
                                          Arguments:-
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
                                          Start time (UTC):12:08:43
                                          Start date (UTC):20/03/2025
                                          Path:/usr/bin/ps
                                          Arguments:ps w
                                          File size:137688 bytes
                                          MD5 hash:ab48054475a6f70f8e7fa847331f3327
                                          Start time (UTC):12:08:48
                                          Start date (UTC):20/03/2025
                                          Path:/tmp/psmips.elf
                                          Arguments:-
                                          File size:5777432 bytes
                                          MD5 hash:0083f1f0e77be34ad27f849842bbb00c
                                          Start time (UTC):12:08:48
                                          Start date (UTC):20/03/2025
                                          Path:/bin/sh
                                          Arguments:sh -c "ps w"
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
                                          Start time (UTC):12:08:48
                                          Start date (UTC):20/03/2025
                                          Path:/bin/sh
                                          Arguments:-
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
                                          Start time (UTC):12:08:48
                                          Start date (UTC):20/03/2025
                                          Path:/usr/bin/ps
                                          Arguments:ps w
                                          File size:137688 bytes
                                          MD5 hash:ab48054475a6f70f8e7fa847331f3327
                                          Start time (UTC):12:08:52
                                          Start date (UTC):20/03/2025
                                          Path:/tmp/psmips.elf
                                          Arguments:-
                                          File size:5777432 bytes
                                          MD5 hash:0083f1f0e77be34ad27f849842bbb00c
                                          Start time (UTC):12:08:52
                                          Start date (UTC):20/03/2025
                                          Path:/bin/sh
                                          Arguments:sh -c "ps w"
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
                                          Start time (UTC):12:08:52
                                          Start date (UTC):20/03/2025
                                          Path:/bin/sh
                                          Arguments:-
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
                                          Start time (UTC):12:08:52
                                          Start date (UTC):20/03/2025
                                          Path:/usr/bin/ps
                                          Arguments:ps w
                                          File size:137688 bytes
                                          MD5 hash:ab48054475a6f70f8e7fa847331f3327
                                          Start time (UTC):12:08:56
                                          Start date (UTC):20/03/2025
                                          Path:/tmp/psmips.elf
                                          Arguments:-
                                          File size:5777432 bytes
                                          MD5 hash:0083f1f0e77be34ad27f849842bbb00c
                                          Start time (UTC):12:08:56
                                          Start date (UTC):20/03/2025
                                          Path:/bin/sh
                                          Arguments:sh -c "ps w"
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
                                          Start time (UTC):12:08:56
                                          Start date (UTC):20/03/2025
                                          Path:/bin/sh
                                          Arguments:-
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
                                          Start time (UTC):12:08:56
                                          Start date (UTC):20/03/2025
                                          Path:/usr/bin/ps
                                          Arguments:ps w
                                          File size:137688 bytes
                                          MD5 hash:ab48054475a6f70f8e7fa847331f3327
                                          Start time (UTC):12:09:00
                                          Start date (UTC):20/03/2025
                                          Path:/tmp/psmips.elf
                                          Arguments:-
                                          File size:5777432 bytes
                                          MD5 hash:0083f1f0e77be34ad27f849842bbb00c
                                          Start time (UTC):12:09:00
                                          Start date (UTC):20/03/2025
                                          Path:/bin/sh
                                          Arguments:sh -c "ps w"
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
                                          Start time (UTC):12:09:00
                                          Start date (UTC):20/03/2025
                                          Path:/bin/sh
                                          Arguments:-
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
                                          Start time (UTC):12:09:00
                                          Start date (UTC):20/03/2025
                                          Path:/usr/bin/ps
                                          Arguments:ps w
                                          File size:137688 bytes
                                          MD5 hash:ab48054475a6f70f8e7fa847331f3327
                                          Start time (UTC):12:09:04
                                          Start date (UTC):20/03/2025
                                          Path:/tmp/psmips.elf
                                          Arguments:-
                                          File size:5777432 bytes
                                          MD5 hash:0083f1f0e77be34ad27f849842bbb00c
                                          Start time (UTC):12:09:04
                                          Start date (UTC):20/03/2025
                                          Path:/bin/sh
                                          Arguments:sh -c "ps w"
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
                                          Start time (UTC):12:09:04
                                          Start date (UTC):20/03/2025
                                          Path:/bin/sh
                                          Arguments:-
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
                                          Start time (UTC):12:09:04
                                          Start date (UTC):20/03/2025
                                          Path:/usr/bin/ps
                                          Arguments:ps w
                                          File size:137688 bytes
                                          MD5 hash:ab48054475a6f70f8e7fa847331f3327
                                          Start time (UTC):12:09:08
                                          Start date (UTC):20/03/2025
                                          Path:/tmp/psmips.elf
                                          Arguments:-
                                          File size:5777432 bytes
                                          MD5 hash:0083f1f0e77be34ad27f849842bbb00c
                                          Start time (UTC):12:09:08
                                          Start date (UTC):20/03/2025
                                          Path:/bin/sh
                                          Arguments:sh -c "ps w"
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
                                          Start time (UTC):12:09:08
                                          Start date (UTC):20/03/2025
                                          Path:/bin/sh
                                          Arguments:-
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
                                          Start time (UTC):12:09:08
                                          Start date (UTC):20/03/2025
                                          Path:/usr/bin/ps
                                          Arguments:ps w
                                          File size:137688 bytes
                                          MD5 hash:ab48054475a6f70f8e7fa847331f3327
                                          Start time (UTC):12:09:11
                                          Start date (UTC):20/03/2025
                                          Path:/tmp/psmips.elf
                                          Arguments:-
                                          File size:5777432 bytes
                                          MD5 hash:0083f1f0e77be34ad27f849842bbb00c
                                          Start time (UTC):12:09:11
                                          Start date (UTC):20/03/2025
                                          Path:/bin/sh
                                          Arguments:sh -c "ps w"
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
                                          Start time (UTC):12:09:11
                                          Start date (UTC):20/03/2025
                                          Path:/bin/sh
                                          Arguments:-
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
                                          Start time (UTC):12:09:11
                                          Start date (UTC):20/03/2025
                                          Path:/usr/bin/ps
                                          Arguments:ps w
                                          File size:137688 bytes
                                          MD5 hash:ab48054475a6f70f8e7fa847331f3327
                                          Start time (UTC):12:09:14
                                          Start date (UTC):20/03/2025
                                          Path:/tmp/psmips.elf
                                          Arguments:-
                                          File size:5777432 bytes
                                          MD5 hash:0083f1f0e77be34ad27f849842bbb00c
                                          Start time (UTC):12:09:14
                                          Start date (UTC):20/03/2025
                                          Path:/bin/sh
                                          Arguments:sh -c "ps w"
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
                                          Start time (UTC):12:09:14
                                          Start date (UTC):20/03/2025
                                          Path:/bin/sh
                                          Arguments:-
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
                                          Start time (UTC):12:09:14
                                          Start date (UTC):20/03/2025
                                          Path:/usr/bin/ps
                                          Arguments:ps w
                                          File size:137688 bytes
                                          MD5 hash:ab48054475a6f70f8e7fa847331f3327
                                          Start time (UTC):12:09:17
                                          Start date (UTC):20/03/2025
                                          Path:/tmp/psmips.elf
                                          Arguments:-
                                          File size:5777432 bytes
                                          MD5 hash:0083f1f0e77be34ad27f849842bbb00c
                                          Start time (UTC):12:09:17
                                          Start date (UTC):20/03/2025
                                          Path:/bin/sh
                                          Arguments:sh -c "ps w"
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
                                          Start time (UTC):12:09:17
                                          Start date (UTC):20/03/2025
                                          Path:/bin/sh
                                          Arguments:-
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
                                          Start time (UTC):12:09:17
                                          Start date (UTC):20/03/2025
                                          Path:/usr/bin/ps
                                          Arguments:ps w
                                          File size:137688 bytes
                                          MD5 hash:ab48054475a6f70f8e7fa847331f3327
                                          Start time (UTC):12:09:20
                                          Start date (UTC):20/03/2025
                                          Path:/tmp/psmips.elf
                                          Arguments:-
                                          File size:5777432 bytes
                                          MD5 hash:0083f1f0e77be34ad27f849842bbb00c
                                          Start time (UTC):12:09:20
                                          Start date (UTC):20/03/2025
                                          Path:/bin/sh
                                          Arguments:sh -c "ps w"
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
                                          Start time (UTC):12:09:20
                                          Start date (UTC):20/03/2025
                                          Path:/bin/sh
                                          Arguments:-
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
                                          Start time (UTC):12:09:20
                                          Start date (UTC):20/03/2025
                                          Path:/usr/bin/ps
                                          Arguments:ps w
                                          File size:137688 bytes
                                          MD5 hash:ab48054475a6f70f8e7fa847331f3327
                                          Start time (UTC):12:09:23
                                          Start date (UTC):20/03/2025
                                          Path:/tmp/psmips.elf
                                          Arguments:-
                                          File size:5777432 bytes
                                          MD5 hash:0083f1f0e77be34ad27f849842bbb00c
                                          Start time (UTC):12:09:23
                                          Start date (UTC):20/03/2025
                                          Path:/bin/sh
                                          Arguments:sh -c "ps w"
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
                                          Start time (UTC):12:09:23
                                          Start date (UTC):20/03/2025
                                          Path:/bin/sh
                                          Arguments:-
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
                                          Start time (UTC):12:09:23
                                          Start date (UTC):20/03/2025
                                          Path:/usr/bin/ps
                                          Arguments:ps w
                                          File size:137688 bytes
                                          MD5 hash:ab48054475a6f70f8e7fa847331f3327
                                          Start time (UTC):12:09:26
                                          Start date (UTC):20/03/2025
                                          Path:/tmp/psmips.elf
                                          Arguments:-
                                          File size:5777432 bytes
                                          MD5 hash:0083f1f0e77be34ad27f849842bbb00c
                                          Start time (UTC):12:09:26
                                          Start date (UTC):20/03/2025
                                          Path:/bin/sh
                                          Arguments:sh -c "ps w"
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
                                          Start time (UTC):12:09:26
                                          Start date (UTC):20/03/2025
                                          Path:/bin/sh
                                          Arguments:-
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
                                          Start time (UTC):12:09:26
                                          Start date (UTC):20/03/2025
                                          Path:/usr/bin/ps
                                          Arguments:ps w
                                          File size:137688 bytes
                                          MD5 hash:ab48054475a6f70f8e7fa847331f3327
                                          Start time (UTC):12:08:53
                                          Start date (UTC):20/03/2025
                                          Path:/usr/bin/dash
                                          Arguments:-
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
                                          Start time (UTC):12:08:53
                                          Start date (UTC):20/03/2025
                                          Path:/usr/bin/rm
                                          Arguments:rm -f /tmp/tmp.Y1SlPlfBUT /tmp/tmp.H0mrDkYWQu /tmp/tmp.XAIyeGnwVr
                                          File size:72056 bytes
                                          MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b
                                          Start time (UTC):12:08:53
                                          Start date (UTC):20/03/2025
                                          Path:/usr/bin/dash
                                          Arguments:-
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
                                          Start time (UTC):12:08:53
                                          Start date (UTC):20/03/2025
                                          Path:/usr/bin/rm
                                          Arguments:rm -f /tmp/tmp.Y1SlPlfBUT /tmp/tmp.H0mrDkYWQu /tmp/tmp.XAIyeGnwVr
                                          File size:72056 bytes
                                          MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b