Edit tour

Linux Analysis Report
bash.elf

Overview

General Information

Sample name:bash.elf
Analysis ID:1645511
MD5:9ca1dfb0f1ca103a1a1c29b723122a45
SHA1:884048157bb83d5b92c2db7e50b7e58a7164fa73
SHA256:55bcda268f02a70867fb60848a78b4525d0cb20d862fc1e646a34819a66cf581
Tags:elfuser-abuse_ch
Infos:

Detection

Gafgyt
Score:84
Range:0 - 100

Signatures

Antivirus / Scanner detection for submitted sample
Found malware configuration
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Yara detected Gafgyt
Opens /proc/net/* files useful for finding connected devices and routers
Detected TCP or UDP traffic on non-standard ports
Sample and/or dropped files contains symbols with suspicious names
Sample contains strings indicative of BusyBox which embeds multiple Unix commands in a single executable
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Yara signature match

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
Joe Sandbox version:42.0.0 Malachite
Analysis ID:1645511
Start date and time:2025-03-21 21:06:18 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 54s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:bash.elf
Detection:MAL
Classification:mal84.spre.troj.linELF@0/0@0/0
Command:/tmp/bash.elf
PID:6217
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
MAC: 00:50:56:98:91:2C
Standard Error:
  • system is lnxubuntu20
  • bash.elf (PID: 6217, Parent: 6138, MD5: 9ca1dfb0f1ca103a1a1c29b723122a45) Arguments: /tmp/bash.elf
    • bash.elf New Fork (PID: 6218, Parent: 6217)
      • bash.elf New Fork (PID: 6219, Parent: 6218)
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
Bashlite, GafgytBashlite is a malware family which infects Linux systems in order to launch distributed denial-of-service attacks (DDoS). Originally it was also known under the name Bashdoor, but this term now refers to the exploit method used by the malware. It has been used to launch attacks of up to 400 Gbps.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.bashlite
SourceRuleDescriptionAuthorStrings
bash.elfJoeSecurity_GafgytYara detected GafgytJoe Security
    bash.elfLinux_Trojan_Gafgyt_a6a2adb9unknownunknown
    • 0x61c:$a: CC 01 C2 89 55 B4 8B 45 B4 C9 C3 55 48 89 E5 48 81 EC 90 00
    bash.elfLinux_Trojan_Gafgyt_a10161ceunknownunknown
    • 0x4ec7:$a: 45 B0 8B 45 BC 48 63 D0 48 89 D0 48 C1 E0 02 48 8D 14 10 48 8B
    bash.elfLinux_Trojan_Gafgyt_9e9530a7unknownunknown
    • 0x7b08:$a: F6 48 63 FF B8 36 00 00 00 0F 05 48 3D 00 F0 FF FF 48 89 C3
    bash.elfLinux_Trojan_Gafgyt_f3d83a74unknownunknown
    • 0x543:$a: DC 00 74 1B 83 7D E0 0A 75 15 83 7D E4 00 79 0F C7 45 C8 01 00
    Click to see the 16 entries
    SourceRuleDescriptionAuthorStrings
    6217.1.0000000000400000.000000000040c000.r-x.sdmpLinux_Trojan_Gafgyt_a6a2adb9unknownunknown
    • 0x61c:$a: CC 01 C2 89 55 B4 8B 45 B4 C9 C3 55 48 89 E5 48 81 EC 90 00
    6217.1.0000000000400000.000000000040c000.r-x.sdmpLinux_Trojan_Gafgyt_a10161ceunknownunknown
    • 0x4ec7:$a: 45 B0 8B 45 BC 48 63 D0 48 89 D0 48 C1 E0 02 48 8D 14 10 48 8B
    6217.1.0000000000400000.000000000040c000.r-x.sdmpLinux_Trojan_Gafgyt_9e9530a7unknownunknown
    • 0x7b08:$a: F6 48 63 FF B8 36 00 00 00 0F 05 48 3D 00 F0 FF FF 48 89 C3
    6217.1.0000000000400000.000000000040c000.r-x.sdmpLinux_Trojan_Gafgyt_f3d83a74unknownunknown
    • 0x543:$a: DC 00 74 1B 83 7D E0 0A 75 15 83 7D E4 00 79 0F C7 45 C8 01 00
    6217.1.0000000000400000.000000000040c000.r-x.sdmpLinux_Trojan_Gafgyt_807911a2unknownunknown
    • 0x82f7:$a: FE 48 39 F3 0F 94 C2 48 83 F9 FF 0F 94 C0 84 D0 74 16 4B 8D
    Click to see the 35 entries
    No Suricata rule has matched

    Click to jump to signature section

    Show All Signature Results

    AV Detection

    barindex
    Source: bash.elfAvira: detected
    Source: bash.elfMalware Configuration Extractor: Gafgyt {"C2 url": "93.115.172.234:6667"}
    Source: bash.elfVirustotal: Detection: 59%Perma Link
    Source: bash.elfReversingLabs: Detection: 58%

    Spreading

    barindex
    Source: /tmp/bash.elf (PID: 6217)Opens: /proc/net/routeJump to behavior
    Source: global trafficTCP traffic: 192.168.2.23:57290 -> 93.115.172.234:6667
    Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
    Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
    Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
    Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
    Source: unknownTCP traffic detected without corresponding DNS query: 93.115.172.234
    Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
    Source: unknownTCP traffic detected without corresponding DNS query: 93.115.172.234
    Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
    Source: unknownTCP traffic detected without corresponding DNS query: 93.115.172.234
    Source: unknownTCP traffic detected without corresponding DNS query: 93.115.172.234
    Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
    Source: unknownTCP traffic detected without corresponding DNS query: 93.115.172.234
    Source: unknownTCP traffic detected without corresponding DNS query: 93.115.172.234
    Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
    Source: unknownTCP traffic detected without corresponding DNS query: 93.115.172.234
    Source: unknownTCP traffic detected without corresponding DNS query: 93.115.172.234
    Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
    Source: unknownTCP traffic detected without corresponding DNS query: 93.115.172.234
    Source: unknownTCP traffic detected without corresponding DNS query: 93.115.172.234
    Source: unknownTCP traffic detected without corresponding DNS query: 93.115.172.234
    Source: unknownTCP traffic detected without corresponding DNS query: 93.115.172.234
    Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
    Source: unknownTCP traffic detected without corresponding DNS query: 93.115.172.234
    Source: unknownTCP traffic detected without corresponding DNS query: 93.115.172.234
    Source: unknownTCP traffic detected without corresponding DNS query: 93.115.172.234
    Source: unknownTCP traffic detected without corresponding DNS query: 93.115.172.234
    Source: unknownTCP traffic detected without corresponding DNS query: 93.115.172.234
    Source: unknownTCP traffic detected without corresponding DNS query: 93.115.172.234
    Source: unknownTCP traffic detected without corresponding DNS query: 93.115.172.234
    Source: unknownTCP traffic detected without corresponding DNS query: 93.115.172.234
    Source: unknownTCP traffic detected without corresponding DNS query: 93.115.172.234
    Source: unknownTCP traffic detected without corresponding DNS query: 93.115.172.234
    Source: unknownTCP traffic detected without corresponding DNS query: 93.115.172.234
    Source: unknownTCP traffic detected without corresponding DNS query: 93.115.172.234
    Source: unknownTCP traffic detected without corresponding DNS query: 93.115.172.234
    Source: unknownTCP traffic detected without corresponding DNS query: 93.115.172.234
    Source: unknownTCP traffic detected without corresponding DNS query: 93.115.172.234
    Source: unknownTCP traffic detected without corresponding DNS query: 93.115.172.234
    Source: unknownTCP traffic detected without corresponding DNS query: 93.115.172.234
    Source: unknownTCP traffic detected without corresponding DNS query: 93.115.172.234
    Source: unknownTCP traffic detected without corresponding DNS query: 93.115.172.234
    Source: unknownTCP traffic detected without corresponding DNS query: 93.115.172.234
    Source: unknownTCP traffic detected without corresponding DNS query: 93.115.172.234
    Source: unknownTCP traffic detected without corresponding DNS query: 93.115.172.234
    Source: unknownTCP traffic detected without corresponding DNS query: 93.115.172.234
    Source: unknownTCP traffic detected without corresponding DNS query: 93.115.172.234
    Source: unknownTCP traffic detected without corresponding DNS query: 93.115.172.234
    Source: unknownTCP traffic detected without corresponding DNS query: 93.115.172.234
    Source: unknownTCP traffic detected without corresponding DNS query: 93.115.172.234
    Source: unknownTCP traffic detected without corresponding DNS query: 93.115.172.234
    Source: unknownTCP traffic detected without corresponding DNS query: 93.115.172.234
    Source: unknownTCP traffic detected without corresponding DNS query: 93.115.172.234
    Source: unknownTCP traffic detected without corresponding DNS query: 93.115.172.234
    Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443

    System Summary

    barindex
    Source: bash.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_a6a2adb9 Author: unknown
    Source: bash.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_a10161ce Author: unknown
    Source: bash.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_9e9530a7 Author: unknown
    Source: bash.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_f3d83a74 Author: unknown
    Source: bash.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_807911a2 Author: unknown
    Source: bash.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_e0673a90 Author: unknown
    Source: bash.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_821173df Author: unknown
    Source: bash.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_a0a4de11 Author: unknown
    Source: bash.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_d4227dbf Author: unknown
    Source: bash.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_09c3070e Author: unknown
    Source: bash.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_d996d335 Author: unknown
    Source: bash.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_656bf077 Author: unknown
    Source: bash.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_148b91a2 Author: unknown
    Source: bash.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_620087b9 Author: unknown
    Source: bash.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_dd0d6173 Author: unknown
    Source: bash.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_779e142f Author: unknown
    Source: bash.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_cf84c9f2 Author: unknown
    Source: bash.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_33b4111a Author: unknown
    Source: bash.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_32eb0c81 Author: unknown
    Source: bash.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_fb14e81f Author: unknown
    Source: 6217.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a6a2adb9 Author: unknown
    Source: 6217.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a10161ce Author: unknown
    Source: 6217.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 Author: unknown
    Source: 6217.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_f3d83a74 Author: unknown
    Source: 6217.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_807911a2 Author: unknown
    Source: 6217.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_e0673a90 Author: unknown
    Source: 6217.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_821173df Author: unknown
    Source: 6217.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a0a4de11 Author: unknown
    Source: 6217.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf Author: unknown
    Source: 6217.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_09c3070e Author: unknown
    Source: 6217.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d996d335 Author: unknown
    Source: 6217.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_656bf077 Author: unknown
    Source: 6217.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_148b91a2 Author: unknown
    Source: 6217.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 Author: unknown
    Source: 6217.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_dd0d6173 Author: unknown
    Source: 6217.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_779e142f Author: unknown
    Source: 6217.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_cf84c9f2 Author: unknown
    Source: 6217.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a Author: unknown
    Source: 6217.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_32eb0c81 Author: unknown
    Source: 6217.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_fb14e81f Author: unknown
    Source: 6218.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a6a2adb9 Author: unknown
    Source: 6218.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a10161ce Author: unknown
    Source: 6218.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 Author: unknown
    Source: 6218.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_f3d83a74 Author: unknown
    Source: 6218.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_807911a2 Author: unknown
    Source: 6218.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_e0673a90 Author: unknown
    Source: 6218.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_821173df Author: unknown
    Source: 6218.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a0a4de11 Author: unknown
    Source: 6218.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf Author: unknown
    Source: 6218.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_09c3070e Author: unknown
    Source: 6218.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d996d335 Author: unknown
    Source: 6218.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_656bf077 Author: unknown
    Source: 6218.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_148b91a2 Author: unknown
    Source: 6218.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 Author: unknown
    Source: 6218.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_dd0d6173 Author: unknown
    Source: 6218.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_779e142f Author: unknown
    Source: 6218.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_cf84c9f2 Author: unknown
    Source: 6218.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a Author: unknown
    Source: 6218.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_32eb0c81 Author: unknown
    Source: 6218.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_fb14e81f Author: unknown
    Source: bash.elfELF static info symbol of initial sample: passwords
    Source: bash.elfELF static info symbol of initial sample: usernames
    Source: Initial sampleString containing 'busybox' found: /bin/busybox;echo -e '\147\141\171\146\147\164'
    Source: bash.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_a6a2adb9 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = cdd0bb9ce40a000bb86b0c76616fe71fb7dbb87a044ddd778b7a07fdf804b877, id = a6a2adb9-9d54-42d4-abed-5b30d8062e97, last_modified = 2021-09-16
    Source: bash.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_a10161ce os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 77e89011a67a539954358118d41ad3dabde0e69bac2bbb2b2da18eaad427d935, id = a10161ce-62e0-4f60-9de7-bd8caf8618be, last_modified = 2021-09-16
    Source: bash.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_9e9530a7 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = d6ad6512051e87c8c35dc168d82edd071b122d026dce21d39b9782b3d6a01e50, id = 9e9530a7-ad4d-4a44-b764-437b7621052f, last_modified = 2021-09-16
    Source: bash.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_f3d83a74 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 1c5df68501b688905484ed47dc588306828aa7c114644428e22e5021bb39bd4a, id = f3d83a74-2888-435a-9a3c-b7de25084e9a, last_modified = 2021-09-16
    Source: bash.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_807911a2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = f409037091b7372f5a42bbe437316bd11c655e7a5fe1fcf83d1981cb5c4a389f, id = 807911a2-f6ec-4e65-924f-61cb065dafc6, last_modified = 2021-09-16
    Source: bash.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_e0673a90 reference_sample = c5a317d0d8470814ff343ce78ad2428ebb3f036763fcf703a589b6c4d33a3ec6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 6834f65d54bbfb926f986fe2dd72cd30bf9804ed65fcc71c2c848e72350f386a, id = e0673a90-165e-4347-a965-e8d14fdf684b, last_modified = 2021-09-16
    Source: bash.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_821173df reference_sample = de7d1aff222c7d474e1a42b2368885ef16317e8da1ca3a63009bf06376026163, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = c311789e1370227f7be1d87da0c370a905b7f5b4c55cdee0f0474060cc0fc5e4, id = 821173df-6835-41e1-a662-a432abf23431, last_modified = 2021-09-16
    Source: bash.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_a0a4de11 reference_sample = cf1ca1d824c8687e87a5b0275a0e39fa101442b4bbf470859ddda9982f9b3417, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 891cfc6a4c38fb257ada29050e0047bd1301e8f0a6a1a919685b1fcc2960b047, id = a0a4de11-fe65-449f-a990-ad5f18ac66f0, last_modified = 2021-09-16
    Source: bash.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_d4227dbf reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 58c4b1d4d167876b64cfa10f609911a80284180e4db093917fea16fae8ccd4e3, id = d4227dbf-6ab4-4637-a6ba-0e604acaafb4, last_modified = 2021-09-16
    Source: bash.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_09c3070e reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 84fad96b60b297736c149e14de12671ff778bff427ab7684df2c541a6f6d7e7d, id = 09c3070e-4b71-45a0-aa62-0cc6e496644a, last_modified = 2021-09-16
    Source: bash.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_d996d335 reference_sample = b511eacd4b44744c8cf82d1b4a9bc6f1022fe6be7c5d17356b171f727ddc6eda, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = e9ccb8412f32187c309b0e9afcc3a6da21ad2f1ffa251c27f9f720ccb284e3ac, id = d996d335-e049-4052-bf36-6cd07c911a8b, last_modified = 2021-09-16
    Source: bash.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_656bf077 reference_sample = c5a317d0d8470814ff343ce78ad2428ebb3f036763fcf703a589b6c4d33a3ec6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 3ea8ed60190198d5887bb7093975d648a9fd78234827d648a8258008c965b1c1, id = 656bf077-ca0c-4d28-9daa-eb6baafaf467, last_modified = 2021-09-16
    Source: bash.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_148b91a2 reference_sample = d5b2bde0749ff482dc2389971e2ac76c4b1e7b887208a538d5555f0fe6984825, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 0f75090ed840f4601df4e43a2f49f2b32585213f3d86d19fb255d79c21086ba3, id = 148b91a2-ed51-4c2d-9d15-6a48d9ea3e0a, last_modified = 2021-09-16
    Source: bash.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_620087b9 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 06cd7e6eb62352ec2ccb9ed48e58c0583c02fefd137cd048d053ab30b5330307, id = 620087b9-c87d-4752-89e8-ca1c16486b28, last_modified = 2021-09-16
    Source: bash.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_dd0d6173 reference_sample = c5a317d0d8470814ff343ce78ad2428ebb3f036763fcf703a589b6c4d33a3ec6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 5e2cb111c2b712951b71166111d339724b4f52b93f90cb474f1e67598212605f, id = dd0d6173-b863-45cf-9348-3375a4e624cf, last_modified = 2021-09-16
    Source: bash.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_779e142f reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 83377b6fa77fda4544c409487d2d2c1ddcef8f7d4120f49a18888c7536f3969f, id = 779e142f-b867-46e6-b1fb-9105976f42fd, last_modified = 2021-09-16
    Source: bash.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_cf84c9f2 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = bb766b356c3e8706740e3bb9b4a7171d8eb5137e09fc7ab6952412fa55e2dcfc, id = cf84c9f2-7435-4faf-8c5f-d14945ffad7a, last_modified = 2021-09-16
    Source: bash.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_33b4111a reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 9c3b63b9a0f54006bae12abcefdb518904a85f78be573f0780f0a265b12d2d6e, id = 33b4111a-e59e-48db-9d74-34ca44fcd9f5, last_modified = 2021-09-16
    Source: bash.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_32eb0c81 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 7c50ed29e2dd75a6a85afc43f8452794cb787ecd2061f4bf415d7038c14c523f, id = 32eb0c81-25af-4670-ab77-07ea7ce1874a, last_modified = 2021-09-16
    Source: bash.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_fb14e81f severity = 100, os = linux, arch_context = x86, creation_date = 2022-01-05, scan_context = file, memory, reference = 0fd07e6068a721774716eb4940e2c19faef02d5bdacf3b018bf5995fa98a3a27, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 12b430108256bd0f57f48b9dbbea12eba7405c0b3b66a1c4b882647051f1ec52, id = fb14e81f-be2a-4428-9877-958e394a7ae2, last_modified = 2022-01-26
    Source: 6217.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a6a2adb9 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = cdd0bb9ce40a000bb86b0c76616fe71fb7dbb87a044ddd778b7a07fdf804b877, id = a6a2adb9-9d54-42d4-abed-5b30d8062e97, last_modified = 2021-09-16
    Source: 6217.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a10161ce os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 77e89011a67a539954358118d41ad3dabde0e69bac2bbb2b2da18eaad427d935, id = a10161ce-62e0-4f60-9de7-bd8caf8618be, last_modified = 2021-09-16
    Source: 6217.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = d6ad6512051e87c8c35dc168d82edd071b122d026dce21d39b9782b3d6a01e50, id = 9e9530a7-ad4d-4a44-b764-437b7621052f, last_modified = 2021-09-16
    Source: 6217.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_f3d83a74 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 1c5df68501b688905484ed47dc588306828aa7c114644428e22e5021bb39bd4a, id = f3d83a74-2888-435a-9a3c-b7de25084e9a, last_modified = 2021-09-16
    Source: 6217.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_807911a2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = f409037091b7372f5a42bbe437316bd11c655e7a5fe1fcf83d1981cb5c4a389f, id = 807911a2-f6ec-4e65-924f-61cb065dafc6, last_modified = 2021-09-16
    Source: 6217.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_e0673a90 reference_sample = c5a317d0d8470814ff343ce78ad2428ebb3f036763fcf703a589b6c4d33a3ec6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 6834f65d54bbfb926f986fe2dd72cd30bf9804ed65fcc71c2c848e72350f386a, id = e0673a90-165e-4347-a965-e8d14fdf684b, last_modified = 2021-09-16
    Source: 6217.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_821173df reference_sample = de7d1aff222c7d474e1a42b2368885ef16317e8da1ca3a63009bf06376026163, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = c311789e1370227f7be1d87da0c370a905b7f5b4c55cdee0f0474060cc0fc5e4, id = 821173df-6835-41e1-a662-a432abf23431, last_modified = 2021-09-16
    Source: 6217.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a0a4de11 reference_sample = cf1ca1d824c8687e87a5b0275a0e39fa101442b4bbf470859ddda9982f9b3417, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 891cfc6a4c38fb257ada29050e0047bd1301e8f0a6a1a919685b1fcc2960b047, id = a0a4de11-fe65-449f-a990-ad5f18ac66f0, last_modified = 2021-09-16
    Source: 6217.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 58c4b1d4d167876b64cfa10f609911a80284180e4db093917fea16fae8ccd4e3, id = d4227dbf-6ab4-4637-a6ba-0e604acaafb4, last_modified = 2021-09-16
    Source: 6217.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_09c3070e reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 84fad96b60b297736c149e14de12671ff778bff427ab7684df2c541a6f6d7e7d, id = 09c3070e-4b71-45a0-aa62-0cc6e496644a, last_modified = 2021-09-16
    Source: 6217.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d996d335 reference_sample = b511eacd4b44744c8cf82d1b4a9bc6f1022fe6be7c5d17356b171f727ddc6eda, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = e9ccb8412f32187c309b0e9afcc3a6da21ad2f1ffa251c27f9f720ccb284e3ac, id = d996d335-e049-4052-bf36-6cd07c911a8b, last_modified = 2021-09-16
    Source: 6217.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_656bf077 reference_sample = c5a317d0d8470814ff343ce78ad2428ebb3f036763fcf703a589b6c4d33a3ec6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 3ea8ed60190198d5887bb7093975d648a9fd78234827d648a8258008c965b1c1, id = 656bf077-ca0c-4d28-9daa-eb6baafaf467, last_modified = 2021-09-16
    Source: 6217.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_148b91a2 reference_sample = d5b2bde0749ff482dc2389971e2ac76c4b1e7b887208a538d5555f0fe6984825, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 0f75090ed840f4601df4e43a2f49f2b32585213f3d86d19fb255d79c21086ba3, id = 148b91a2-ed51-4c2d-9d15-6a48d9ea3e0a, last_modified = 2021-09-16
    Source: 6217.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 06cd7e6eb62352ec2ccb9ed48e58c0583c02fefd137cd048d053ab30b5330307, id = 620087b9-c87d-4752-89e8-ca1c16486b28, last_modified = 2021-09-16
    Source: 6217.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_dd0d6173 reference_sample = c5a317d0d8470814ff343ce78ad2428ebb3f036763fcf703a589b6c4d33a3ec6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 5e2cb111c2b712951b71166111d339724b4f52b93f90cb474f1e67598212605f, id = dd0d6173-b863-45cf-9348-3375a4e624cf, last_modified = 2021-09-16
    Source: 6217.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_779e142f reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 83377b6fa77fda4544c409487d2d2c1ddcef8f7d4120f49a18888c7536f3969f, id = 779e142f-b867-46e6-b1fb-9105976f42fd, last_modified = 2021-09-16
    Source: 6217.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_cf84c9f2 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = bb766b356c3e8706740e3bb9b4a7171d8eb5137e09fc7ab6952412fa55e2dcfc, id = cf84c9f2-7435-4faf-8c5f-d14945ffad7a, last_modified = 2021-09-16
    Source: 6217.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 9c3b63b9a0f54006bae12abcefdb518904a85f78be573f0780f0a265b12d2d6e, id = 33b4111a-e59e-48db-9d74-34ca44fcd9f5, last_modified = 2021-09-16
    Source: 6217.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_32eb0c81 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 7c50ed29e2dd75a6a85afc43f8452794cb787ecd2061f4bf415d7038c14c523f, id = 32eb0c81-25af-4670-ab77-07ea7ce1874a, last_modified = 2021-09-16
    Source: 6217.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_fb14e81f severity = 100, os = linux, arch_context = x86, creation_date = 2022-01-05, scan_context = file, memory, reference = 0fd07e6068a721774716eb4940e2c19faef02d5bdacf3b018bf5995fa98a3a27, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 12b430108256bd0f57f48b9dbbea12eba7405c0b3b66a1c4b882647051f1ec52, id = fb14e81f-be2a-4428-9877-958e394a7ae2, last_modified = 2022-01-26
    Source: 6218.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a6a2adb9 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = cdd0bb9ce40a000bb86b0c76616fe71fb7dbb87a044ddd778b7a07fdf804b877, id = a6a2adb9-9d54-42d4-abed-5b30d8062e97, last_modified = 2021-09-16
    Source: 6218.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a10161ce os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 77e89011a67a539954358118d41ad3dabde0e69bac2bbb2b2da18eaad427d935, id = a10161ce-62e0-4f60-9de7-bd8caf8618be, last_modified = 2021-09-16
    Source: 6218.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = d6ad6512051e87c8c35dc168d82edd071b122d026dce21d39b9782b3d6a01e50, id = 9e9530a7-ad4d-4a44-b764-437b7621052f, last_modified = 2021-09-16
    Source: 6218.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_f3d83a74 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 1c5df68501b688905484ed47dc588306828aa7c114644428e22e5021bb39bd4a, id = f3d83a74-2888-435a-9a3c-b7de25084e9a, last_modified = 2021-09-16
    Source: 6218.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_807911a2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = f409037091b7372f5a42bbe437316bd11c655e7a5fe1fcf83d1981cb5c4a389f, id = 807911a2-f6ec-4e65-924f-61cb065dafc6, last_modified = 2021-09-16
    Source: 6218.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_e0673a90 reference_sample = c5a317d0d8470814ff343ce78ad2428ebb3f036763fcf703a589b6c4d33a3ec6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 6834f65d54bbfb926f986fe2dd72cd30bf9804ed65fcc71c2c848e72350f386a, id = e0673a90-165e-4347-a965-e8d14fdf684b, last_modified = 2021-09-16
    Source: 6218.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_821173df reference_sample = de7d1aff222c7d474e1a42b2368885ef16317e8da1ca3a63009bf06376026163, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = c311789e1370227f7be1d87da0c370a905b7f5b4c55cdee0f0474060cc0fc5e4, id = 821173df-6835-41e1-a662-a432abf23431, last_modified = 2021-09-16
    Source: 6218.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a0a4de11 reference_sample = cf1ca1d824c8687e87a5b0275a0e39fa101442b4bbf470859ddda9982f9b3417, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 891cfc6a4c38fb257ada29050e0047bd1301e8f0a6a1a919685b1fcc2960b047, id = a0a4de11-fe65-449f-a990-ad5f18ac66f0, last_modified = 2021-09-16
    Source: 6218.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 58c4b1d4d167876b64cfa10f609911a80284180e4db093917fea16fae8ccd4e3, id = d4227dbf-6ab4-4637-a6ba-0e604acaafb4, last_modified = 2021-09-16
    Source: 6218.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_09c3070e reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 84fad96b60b297736c149e14de12671ff778bff427ab7684df2c541a6f6d7e7d, id = 09c3070e-4b71-45a0-aa62-0cc6e496644a, last_modified = 2021-09-16
    Source: 6218.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d996d335 reference_sample = b511eacd4b44744c8cf82d1b4a9bc6f1022fe6be7c5d17356b171f727ddc6eda, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = e9ccb8412f32187c309b0e9afcc3a6da21ad2f1ffa251c27f9f720ccb284e3ac, id = d996d335-e049-4052-bf36-6cd07c911a8b, last_modified = 2021-09-16
    Source: 6218.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_656bf077 reference_sample = c5a317d0d8470814ff343ce78ad2428ebb3f036763fcf703a589b6c4d33a3ec6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 3ea8ed60190198d5887bb7093975d648a9fd78234827d648a8258008c965b1c1, id = 656bf077-ca0c-4d28-9daa-eb6baafaf467, last_modified = 2021-09-16
    Source: 6218.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_148b91a2 reference_sample = d5b2bde0749ff482dc2389971e2ac76c4b1e7b887208a538d5555f0fe6984825, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 0f75090ed840f4601df4e43a2f49f2b32585213f3d86d19fb255d79c21086ba3, id = 148b91a2-ed51-4c2d-9d15-6a48d9ea3e0a, last_modified = 2021-09-16
    Source: 6218.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 06cd7e6eb62352ec2ccb9ed48e58c0583c02fefd137cd048d053ab30b5330307, id = 620087b9-c87d-4752-89e8-ca1c16486b28, last_modified = 2021-09-16
    Source: 6218.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_dd0d6173 reference_sample = c5a317d0d8470814ff343ce78ad2428ebb3f036763fcf703a589b6c4d33a3ec6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 5e2cb111c2b712951b71166111d339724b4f52b93f90cb474f1e67598212605f, id = dd0d6173-b863-45cf-9348-3375a4e624cf, last_modified = 2021-09-16
    Source: 6218.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_779e142f reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 83377b6fa77fda4544c409487d2d2c1ddcef8f7d4120f49a18888c7536f3969f, id = 779e142f-b867-46e6-b1fb-9105976f42fd, last_modified = 2021-09-16
    Source: 6218.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_cf84c9f2 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = bb766b356c3e8706740e3bb9b4a7171d8eb5137e09fc7ab6952412fa55e2dcfc, id = cf84c9f2-7435-4faf-8c5f-d14945ffad7a, last_modified = 2021-09-16
    Source: 6218.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 9c3b63b9a0f54006bae12abcefdb518904a85f78be573f0780f0a265b12d2d6e, id = 33b4111a-e59e-48db-9d74-34ca44fcd9f5, last_modified = 2021-09-16
    Source: 6218.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_32eb0c81 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 7c50ed29e2dd75a6a85afc43f8452794cb787ecd2061f4bf415d7038c14c523f, id = 32eb0c81-25af-4670-ab77-07ea7ce1874a, last_modified = 2021-09-16
    Source: 6218.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_fb14e81f severity = 100, os = linux, arch_context = x86, creation_date = 2022-01-05, scan_context = file, memory, reference = 0fd07e6068a721774716eb4940e2c19faef02d5bdacf3b018bf5995fa98a3a27, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 12b430108256bd0f57f48b9dbbea12eba7405c0b3b66a1c4b882647051f1ec52, id = fb14e81f-be2a-4428-9877-958e394a7ae2, last_modified = 2022-01-26
    Source: classification engineClassification label: mal84.spre.troj.linELF@0/0@0/0
    Source: bash.elfELF static info symbol of initial sample: libc/string/x86_64/memcpy.S
    Source: bash.elfELF static info symbol of initial sample: libc/string/x86_64/mempcpy.S
    Source: bash.elfELF static info symbol of initial sample: libc/string/x86_64/memset.S
    Source: bash.elfELF static info symbol of initial sample: libc/string/x86_64/strchr.S
    Source: bash.elfELF static info symbol of initial sample: libc/string/x86_64/strcpy.S
    Source: bash.elfELF static info symbol of initial sample: libc/string/x86_64/strlen.S
    Source: bash.elfELF static info symbol of initial sample: libc/string/x86_64/strpbrk.S
    Source: bash.elfELF static info symbol of initial sample: libc/string/x86_64/strspn.S
    Source: bash.elfELF static info symbol of initial sample: libc/sysdeps/linux/x86_64/crt1.S
    Source: bash.elfELF static info symbol of initial sample: libc/sysdeps/linux/x86_64/crti.S
    Source: bash.elfELF static info symbol of initial sample: libc/sysdeps/linux/x86_64/crtn.S
    Source: bash.elfELF static info symbol of initial sample: libc/sysdeps/linux/x86_64/vfork.S

    Stealing of Sensitive Information

    barindex
    Source: Yara matchFile source: bash.elf, type: SAMPLE

    Remote Access Functionality

    barindex
    Source: Yara matchFile source: bash.elf, type: SAMPLE
    ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
    Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
    Masquerading
    OS Credential Dumping1
    Remote System Discovery
    Remote ServicesData from Local System1
    Encrypted Channel
    Exfiltration Over Other Network MediumAbuse Accessibility Features
    CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
    Non-Standard Port
    Exfiltration Over BluetoothNetwork Denial of Service
    Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
    Application Layer Protocol
    Automated ExfiltrationData Encrypted for Impact
    {
      "C2 url": "93.115.172.234:6667"
    }
    Hide Legend

    Legend:

    • Process
    • Signature
    • Created File
    • DNS/IP Info
    • Is Dropped
    • Number of created Files
    • Is malicious
    • Internet
    behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1645511 Sample: bash.elf Startdate: 21/03/2025 Architecture: LINUX Score: 84 15 93.115.172.234, 57290, 57292, 57294 ALTER-NET-ASZorilorNr11SfGheorgheRO Romania 2->15 17 109.202.202.202, 80 INIT7CH Switzerland 2->17 19 2 other IPs or domains 2->19 21 Found malware configuration 2->21 23 Malicious sample detected (through community Yara rule) 2->23 25 Antivirus / Scanner detection for submitted sample 2->25 27 2 other signatures 2->27 8 bash.elf 2->8         started        signatures3 process4 signatures5 29 Opens /proc/net/* files useful for finding connected devices and routers 8->29 11 bash.elf 8->11         started        process6 process7 13 bash.elf 11->13         started       
    SourceDetectionScannerLabelLink
    bash.elf59%VirustotalBrowse
    bash.elf58%ReversingLabsLinux.Trojan.Gafgyt
    bash.elf100%AviraLINUX/Gafgyt.vka
    No Antivirus matches
    No Antivirus matches
    No Antivirus matches

    Download Network PCAP: filteredfull

    No contacted domains info
    NameMaliciousAntivirus DetectionReputation
    93.115.172.234:6667false
      high
      • No. of IPs < 25%
      • 25% < No. of IPs < 50%
      • 50% < No. of IPs < 75%
      • 75% < No. of IPs
      IPDomainCountryFlagASNASN NameMalicious
      93.115.172.234
      unknownRomania
      39531ALTER-NET-ASZorilorNr11SfGheorgheROtrue
      109.202.202.202
      unknownSwitzerland
      13030INIT7CHfalse
      91.189.91.43
      unknownUnited Kingdom
      41231CANONICAL-ASGBfalse
      91.189.91.42
      unknownUnited Kingdom
      41231CANONICAL-ASGBfalse
      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
      93.115.172.234cron.elfGet hashmaliciousGafgytBrowse
        apache2.elfGet hashmaliciousGafgytBrowse
          openssh.elfGet hashmaliciousGafgytBrowse
            pftp.elfGet hashmaliciousGafgytBrowse
              sh.elfGet hashmaliciousGafgytBrowse
                sshd.elfGet hashmaliciousGafgytBrowse
                  ftp.elfGet hashmaliciousGafgytBrowse
                    tftp.elfGet hashmaliciousGafgytBrowse
                      109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
                      • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
                      91.189.91.43cron.elfGet hashmaliciousGafgytBrowse
                        sh.elfGet hashmaliciousGafgytBrowse
                          na.elfGet hashmaliciousPrometeiBrowse
                            sshd.elfGet hashmaliciousUnknownBrowse
                              jwyt4py98x.m68k.elfGet hashmaliciousMiraiBrowse
                                jwyt4py98x.arm7.elfGet hashmaliciousMiraiBrowse
                                  jwyt4py98x.mips.elfGet hashmaliciousMiraiBrowse
                                    na.elfGet hashmaliciousPrometeiBrowse
                                      na.elfGet hashmaliciousPrometeiBrowse
                                        na.elfGet hashmaliciousPrometeiBrowse
                                          91.189.91.42cron.elfGet hashmaliciousGafgytBrowse
                                            sh.elfGet hashmaliciousGafgytBrowse
                                              na.elfGet hashmaliciousPrometeiBrowse
                                                na.elfGet hashmaliciousPrometeiBrowse
                                                  sshd.elfGet hashmaliciousUnknownBrowse
                                                    jwyt4py98x.m68k.elfGet hashmaliciousMiraiBrowse
                                                      jwyt4py98x.arm7.elfGet hashmaliciousMiraiBrowse
                                                        jwyt4py98x.mips.elfGet hashmaliciousMiraiBrowse
                                                          na.elfGet hashmaliciousPrometeiBrowse
                                                            na.elfGet hashmaliciousPrometeiBrowse
                                                              No context
                                                              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                              CANONICAL-ASGBwget.elfGet hashmaliciousGafgytBrowse
                                                              • 185.125.190.26
                                                              cron.elfGet hashmaliciousGafgytBrowse
                                                              • 91.189.91.42
                                                              sh.elfGet hashmaliciousGafgytBrowse
                                                              • 91.189.91.42
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 91.189.91.42
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 91.189.91.42
                                                              sshd.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              jwyt4py98x.m68k.elfGet hashmaliciousMiraiBrowse
                                                              • 91.189.91.42
                                                              x.rar.elfGet hashmaliciousXmrigBrowse
                                                              • 185.125.190.26
                                                              jwyt4py98x.arm7.elfGet hashmaliciousMiraiBrowse
                                                              • 91.189.91.42
                                                              jwyt4py98x.mips.elfGet hashmaliciousMiraiBrowse
                                                              • 91.189.91.42
                                                              CANONICAL-ASGBwget.elfGet hashmaliciousGafgytBrowse
                                                              • 185.125.190.26
                                                              cron.elfGet hashmaliciousGafgytBrowse
                                                              • 91.189.91.42
                                                              sh.elfGet hashmaliciousGafgytBrowse
                                                              • 91.189.91.42
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 91.189.91.42
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 91.189.91.42
                                                              sshd.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              jwyt4py98x.m68k.elfGet hashmaliciousMiraiBrowse
                                                              • 91.189.91.42
                                                              x.rar.elfGet hashmaliciousXmrigBrowse
                                                              • 185.125.190.26
                                                              jwyt4py98x.arm7.elfGet hashmaliciousMiraiBrowse
                                                              • 91.189.91.42
                                                              jwyt4py98x.mips.elfGet hashmaliciousMiraiBrowse
                                                              • 91.189.91.42
                                                              ALTER-NET-ASZorilorNr11SfGheorgheROwget.elfGet hashmaliciousGafgytBrowse
                                                              • 93.115.172.234
                                                              cron.elfGet hashmaliciousGafgytBrowse
                                                              • 93.115.172.234
                                                              apache2.elfGet hashmaliciousGafgytBrowse
                                                              • 93.115.172.234
                                                              openssh.elfGet hashmaliciousGafgytBrowse
                                                              • 93.115.172.234
                                                              pftp.elfGet hashmaliciousGafgytBrowse
                                                              • 93.115.172.234
                                                              sh.elfGet hashmaliciousGafgytBrowse
                                                              • 93.115.172.234
                                                              sshd.elfGet hashmaliciousGafgytBrowse
                                                              • 93.115.172.234
                                                              ftp.elfGet hashmaliciousGafgytBrowse
                                                              • 93.115.172.234
                                                              tftp.elfGet hashmaliciousGafgytBrowse
                                                              • 93.115.172.234
                                                              Ravateb.pdf.exeGet hashmaliciousUnknownBrowse
                                                              • 89.46.233.239
                                                              INIT7CHcron.elfGet hashmaliciousGafgytBrowse
                                                              • 109.202.202.202
                                                              sh.elfGet hashmaliciousGafgytBrowse
                                                              • 109.202.202.202
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 109.202.202.202
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 109.202.202.202
                                                              sshd.elfGet hashmaliciousUnknownBrowse
                                                              • 109.202.202.202
                                                              jwyt4py98x.m68k.elfGet hashmaliciousMiraiBrowse
                                                              • 109.202.202.202
                                                              jwyt4py98x.arm7.elfGet hashmaliciousMiraiBrowse
                                                              • 109.202.202.202
                                                              jwyt4py98x.mips.elfGet hashmaliciousMiraiBrowse
                                                              • 109.202.202.202
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 109.202.202.202
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 109.202.202.202
                                                              No context
                                                              No context
                                                              No created / dropped files found
                                                              File type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, not stripped
                                                              Entropy (8bit):5.685585650805999
                                                              TrID:
                                                              • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                                              File name:bash.elf
                                                              File size:72'787 bytes
                                                              MD5:9ca1dfb0f1ca103a1a1c29b723122a45
                                                              SHA1:884048157bb83d5b92c2db7e50b7e58a7164fa73
                                                              SHA256:55bcda268f02a70867fb60848a78b4525d0cb20d862fc1e646a34819a66cf581
                                                              SHA512:623eea6bcc700770d3fa91fbfaa09da2303abc9300521aa251c9b4618e557366d80bee75f24281046b34279de1b345632a71a78fcc51dc1f5a82db8a2b0810e3
                                                              SSDEEP:1536:xEu1gghuHYty2ivGM9gMA3J1pOwhkyFUZA242tIukEiI:T1go54Pm/3J1pnDFh2Z+a
                                                              TLSH:DC63E82F5252D1FEC09717B526DF9961AC23BC3A0726A1097392BE7D3F359C88D4A342
                                                              File Content Preview:.ELF..............>.......@.....@...................@.8...@.......................@.......@...............................................P.......P.....P........n..............Q.td....................................................H...._....J...H........

                                                              ELF header

                                                              Class:ELF64
                                                              Data:2's complement, little endian
                                                              Version:1 (current)
                                                              Machine:Advanced Micro Devices X86-64
                                                              Version Number:0x1
                                                              Type:EXEC (Executable file)
                                                              OS/ABI:UNIX - System V
                                                              ABI Version:0
                                                              Entry Point Address:0x400194
                                                              Flags:0x0
                                                              ELF Header Size:64
                                                              Program Header Offset:64
                                                              Program Header Size:56
                                                              Number of Program Headers:3
                                                              Section Header Offset:52432
                                                              Section Header Size:64
                                                              Number of Section Headers:15
                                                              Header String Table Index:12
                                                              NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                              NULL0x00x00x00x00x0000
                                                              .initPROGBITS0x4000e80xe80x130x00x6AX001
                                                              .textPROGBITS0x4001000x1000xa3780x00x6AX0016
                                                              .finiPROGBITS0x40a4780xa4780xe0x00x6AX001
                                                              .rodataPROGBITS0x40a4a00xa4a00x1a220x00x2A0032
                                                              .eh_framePROGBITS0x40bec40xbec40x40x00x2A004
                                                              .ctorsPROGBITS0x50c0000xc0000x100x00x3WA008
                                                              .dtorsPROGBITS0x50c0100xc0100x100x00x3WA008
                                                              .jcrPROGBITS0x50c0200xc0200x80x00x3WA008
                                                              .dataPROGBITS0x50c0400xc0400x5100x00x3WA0032
                                                              .bssNOBITS0x50c5600xc5500x68a80x00x3WA0032
                                                              .commentPROGBITS0x00xc5500x71a0x00x0001
                                                              .shstrtabSTRTAB0x00xcc6a0x660x00x0001
                                                              .symtabSYMTAB0x00xd0900x32e80x180x0141778
                                                              .strtabSTRTAB0x00x103780x18db0x00x0001
                                                              TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                              LOAD0x00x4000000x4000000xbec80xbec85.90900x5R E0x100000.init .text .fini .rodata .eh_frame
                                                              LOAD0xc0000x50c0000x50c0000x5500x6e082.20510x6RW 0x100000.ctors .dtors .jcr .data .bss
                                                              GNU_STACK0x00x00x00x00x00.00000x6RW 0x8
                                                              NameVersion Info NameVersion Info File NameSection NameValueSizeSymbol TypeSymbol BindSymbol VisibilityNdx
                                                              .symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                                              .symtab0x4000e80SECTION<unknown>DEFAULT1
                                                              .symtab0x4001000SECTION<unknown>DEFAULT2
                                                              .symtab0x40a4780SECTION<unknown>DEFAULT3
                                                              .symtab0x40a4a00SECTION<unknown>DEFAULT4
                                                              .symtab0x40bec40SECTION<unknown>DEFAULT5
                                                              .symtab0x50c0000SECTION<unknown>DEFAULT6
                                                              .symtab0x50c0100SECTION<unknown>DEFAULT7
                                                              .symtab0x50c0200SECTION<unknown>DEFAULT8
                                                              .symtab0x50c0400SECTION<unknown>DEFAULT9
                                                              .symtab0x50c5600SECTION<unknown>DEFAULT10
                                                              .symtab0x00SECTION<unknown>DEFAULT11
                                                              .symtab0x00SECTION<unknown>DEFAULT12
                                                              .symtab0x00SECTION<unknown>DEFAULT13
                                                              .symtab0x00SECTION<unknown>DEFAULT14
                                                              Q.symtab0x50c5e016384OBJECT<unknown>DEFAULT10
                                                              StartTheLelz.symtab0x4026f36074FUNC<unknown>DEFAULT2
                                                              _Jv_RegisterClasses.symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                                              _WRITE.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              __CTOR_END__.symtab0x50c0080OBJECT<unknown>DEFAULT6
                                                              __CTOR_LIST__.symtab0x50c0000OBJECT<unknown>DEFAULT6
                                                              __C_ctype_b.symtab0x50c1388OBJECT<unknown>DEFAULT9
                                                              __C_ctype_b.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              __C_ctype_b_data.symtab0x40b3a0768OBJECT<unknown>DEFAULT4
                                                              __C_ctype_toupper.symtab0x50c1488OBJECT<unknown>DEFAULT9
                                                              __C_ctype_toupper.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              __C_ctype_toupper_data.symtab0x40b6a0768OBJECT<unknown>DEFAULT4
                                                              __DTOR_END__.symtab0x50c0180OBJECT<unknown>DEFAULT7
                                                              __DTOR_LIST__.symtab0x50c0100OBJECT<unknown>DEFAULT7
                                                              __EH_FRAME_BEGIN__.symtab0x40bec40OBJECT<unknown>DEFAULT5
                                                              __FRAME_END__.symtab0x40bec40OBJECT<unknown>DEFAULT5
                                                              __GI___C_ctype_b.symtab0x50c1388OBJECT<unknown>HIDDEN9
                                                              __GI___C_ctype_b_data.symtab0x40b3a0768OBJECT<unknown>HIDDEN4
                                                              __GI___C_ctype_toupper.symtab0x50c1488OBJECT<unknown>HIDDEN9
                                                              __GI___C_ctype_toupper_data.symtab0x40b6a0768OBJECT<unknown>HIDDEN4
                                                              __GI___ctype_b.symtab0x50c1408OBJECT<unknown>HIDDEN9
                                                              __GI___ctype_toupper.symtab0x50c1508OBJECT<unknown>HIDDEN9
                                                              __GI___errno_location.symtab0x40700c6FUNC<unknown>HIDDEN2
                                                              __GI___fputc_unlocked.symtab0x4071c4192FUNC<unknown>HIDDEN2
                                                              __GI___libc_fcntl.symtab0x406bc8100FUNC<unknown>HIDDEN2
                                                              __GI___libc_lseek.symtab0x40a41045FUNC<unknown>HIDDEN2
                                                              __GI___libc_open.symtab0x406e08106FUNC<unknown>HIDDEN2
                                                              __GI___uClibc_fini.symtab0x40946870FUNC<unknown>HIDDEN2
                                                              __GI___uClibc_init.symtab0x4094e767FUNC<unknown>HIDDEN2
                                                              __GI__exit.symtab0x406c2c42FUNC<unknown>HIDDEN2
                                                              __GI_abort.symtab0x40897c276FUNC<unknown>HIDDEN2
                                                              __GI_atoi.symtab0x408e6018FUNC<unknown>HIDDEN2
                                                              __GI_brk.symtab0x40a07443FUNC<unknown>HIDDEN2
                                                              __GI_chdir.symtab0x406c5838FUNC<unknown>HIDDEN2
                                                              __GI_clock_getres.symtab0x40985c41FUNC<unknown>HIDDEN2
                                                              __GI_close.symtab0x406c8041FUNC<unknown>HIDDEN2
                                                              __GI_connect.symtab0x4079f843FUNC<unknown>HIDDEN2
                                                              __GI_dup2.symtab0x406cac44FUNC<unknown>HIDDEN2
                                                              __GI_errno.symtab0x51267c4OBJECT<unknown>HIDDEN10
                                                              __GI_execl.symtab0x409048287FUNC<unknown>HIDDEN2
                                                              __GI_execve.symtab0x40988838FUNC<unknown>HIDDEN2
                                                              __GI_exit.symtab0x408fec92FUNC<unknown>HIDDEN2
                                                              __GI_fcntl.symtab0x406bc8100FUNC<unknown>HIDDEN2
                                                              __GI_fcntl64.symtab0x406bc8100FUNC<unknown>HIDDEN2
                                                              __GI_fork.symtab0x406cd838FUNC<unknown>HIDDEN2
                                                              __GI_fputs_unlocked.symtab0x40728456FUNC<unknown>HIDDEN2
                                                              __GI_fseek.symtab0x40a0a05FUNC<unknown>HIDDEN2
                                                              __GI_fseeko64.symtab0x40a0a8218FUNC<unknown>HIDDEN2
                                                              __GI_fwrite_unlocked.symtab0x4072bc134FUNC<unknown>HIDDEN2
                                                              __GI_getdtablesize.symtab0x406d0035FUNC<unknown>HIDDEN2
                                                              __GI_getegid.symtab0x4098b038FUNC<unknown>HIDDEN2
                                                              __GI_geteuid.symtab0x4098d838FUNC<unknown>HIDDEN2
                                                              __GI_getgid.symtab0x40990038FUNC<unknown>HIDDEN2
                                                              __GI_getpagesize.symtab0x40992819FUNC<unknown>HIDDEN2
                                                              __GI_getpid.symtab0x406d2438FUNC<unknown>HIDDEN2
                                                              __GI_getrlimit.symtab0x406d4c40FUNC<unknown>HIDDEN2
                                                              __GI_getsockname.symtab0x407a2441FUNC<unknown>HIDDEN2
                                                              __GI_getuid.symtab0x40993c38FUNC<unknown>HIDDEN2
                                                              __GI_h_errno.symtab0x5126804OBJECT<unknown>HIDDEN10
                                                              __GI_inet_addr.symtab0x4079dc28FUNC<unknown>HIDDEN2
                                                              __GI_inet_aton.symtab0x409fbc137FUNC<unknown>HIDDEN2
                                                              __GI_inet_ntoa.symtab0x4079d110FUNC<unknown>HIDDEN2
                                                              __GI_inet_ntoa_r.symtab0x40798477FUNC<unknown>HIDDEN2
                                                              __GI_initstate_r.symtab0x408da7185FUNC<unknown>HIDDEN2
                                                              __GI_ioctl.symtab0x406d74104FUNC<unknown>HIDDEN2
                                                              __GI_isatty.symtab0x4078dc25FUNC<unknown>HIDDEN2
                                                              __GI_kill.symtab0x406ddc44FUNC<unknown>HIDDEN2
                                                              __GI_lseek.symtab0x40a41045FUNC<unknown>HIDDEN2
                                                              __GI_lseek64.symtab0x40a4085FUNC<unknown>HIDDEN2
                                                              __GI_memchr.symtab0x409d7c240FUNC<unknown>HIDDEN2
                                                              __GI_memcpy.symtab0x407350102FUNC<unknown>HIDDEN2
                                                              __GI_mempcpy.symtab0x409d2090FUNC<unknown>HIDDEN2
                                                              __GI_memrchr.symtab0x409e6c237FUNC<unknown>HIDDEN2
                                                              __GI_memset.symtab0x4073c0210FUNC<unknown>HIDDEN2
                                                              __GI_mmap.symtab0x40982c48FUNC<unknown>HIDDEN2
                                                              __GI_munmap.symtab0x40996438FUNC<unknown>HIDDEN2
                                                              __GI_nanosleep.symtab0x40998c38FUNC<unknown>HIDDEN2
                                                              __GI_open.symtab0x406e08106FUNC<unknown>HIDDEN2
                                                              __GI_pipe.symtab0x406e8038FUNC<unknown>HIDDEN2
                                                              __GI_putc_unlocked.symtab0x4071c4192FUNC<unknown>HIDDEN2
                                                              __GI_raise.symtab0x40a04818FUNC<unknown>HIDDEN2
                                                              __GI_random.symtab0x408a9c72FUNC<unknown>HIDDEN2
                                                              __GI_random_r.symtab0x408ca490FUNC<unknown>HIDDEN2
                                                              __GI_rawmemchr.symtab0x40a348190FUNC<unknown>HIDDEN2
                                                              __GI_read.symtab0x406ea839FUNC<unknown>HIDDEN2
                                                              __GI_recv.symtab0x407a8411FUNC<unknown>HIDDEN2
                                                              __GI_recvfrom.symtab0x407a9045FUNC<unknown>HIDDEN2
                                                              __GI_sbrk.symtab0x4099b474FUNC<unknown>HIDDEN2
                                                              __GI_select.symtab0x406ed044FUNC<unknown>HIDDEN2
                                                              __GI_send.symtab0x407ac011FUNC<unknown>HIDDEN2
                                                              __GI_sendto.symtab0x407acc48FUNC<unknown>HIDDEN2
                                                              __GI_setsid.symtab0x406efc38FUNC<unknown>HIDDEN2
                                                              __GI_setsockopt.symtab0x407afc53FUNC<unknown>HIDDEN2
                                                              __GI_setstate_r.symtab0x408bfc168FUNC<unknown>HIDDEN2
                                                              __GI_sigaction.symtab0x40971d247FUNC<unknown>HIDDEN2
                                                              __GI_sigaddset.symtab0x407b6435FUNC<unknown>HIDDEN2
                                                              __GI_sigemptyset.symtab0x407b8820FUNC<unknown>HIDDEN2
                                                              __GI_signal.symtab0x407b9c168FUNC<unknown>HIDDEN2
                                                              __GI_sigprocmask.symtab0x406f2485FUNC<unknown>HIDDEN2
                                                              __GI_sleep.symtab0x409168415FUNC<unknown>HIDDEN2
                                                              __GI_socket.symtab0x407b3447FUNC<unknown>HIDDEN2
                                                              __GI_srandom_r.symtab0x408cfe169FUNC<unknown>HIDDEN2
                                                              __GI_strchr.symtab0x4074a0417FUNC<unknown>HIDDEN2
                                                              __GI_strcpy.symtab0x407650213FUNC<unknown>HIDDEN2
                                                              __GI_strlen.symtab0x407730225FUNC<unknown>HIDDEN2
                                                              __GI_strpbrk.symtab0x40a230140FUNC<unknown>HIDDEN2
                                                              __GI_strspn.symtab0x40a2c0135FUNC<unknown>HIDDEN2
                                                              __GI_strstr.symtab0x407814187FUNC<unknown>HIDDEN2
                                                              __GI_strtok.symtab0x4078d010FUNC<unknown>HIDDEN2
                                                              __GI_strtok_r.symtab0x409f5c94FUNC<unknown>HIDDEN2
                                                              __GI_strtol.symtab0x408e7410FUNC<unknown>HIDDEN2
                                                              __GI_strtoll.symtab0x408e7410FUNC<unknown>HIDDEN2
                                                              __GI_sysconf.symtab0x409308351FUNC<unknown>HIDDEN2
                                                              __GI_tcgetattr.symtab0x4078f8110FUNC<unknown>HIDDEN2
                                                              __GI_time.symtab0x406f7c39FUNC<unknown>HIDDEN2
                                                              __GI_toupper.symtab0x406fec30FUNC<unknown>HIDDEN2
                                                              __GI_vfork.symtab0x406bb021FUNC<unknown>HIDDEN2
                                                              __GI_wait4.symtab0x409a0047FUNC<unknown>HIDDEN2
                                                              __GI_waitpid.symtab0x406fa47FUNC<unknown>HIDDEN2
                                                              __GI_write.symtab0x406fac42FUNC<unknown>HIDDEN2
                                                              __JCR_END__.symtab0x50c0200OBJECT<unknown>DEFAULT8
                                                              __JCR_LIST__.symtab0x50c0200OBJECT<unknown>DEFAULT8
                                                              __app_fini.symtab0x5126688OBJECT<unknown>HIDDEN10
                                                              __atexit_lock.symtab0x50c52040OBJECT<unknown>DEFAULT9
                                                              __bsd_signal.symtab0x407b9c168FUNC<unknown>HIDDEN2
                                                              __bss_start.symtab0x50c5500NOTYPE<unknown>DEFAULTSHN_ABS
                                                              __check_one_fd.symtab0x4094b253FUNC<unknown>DEFAULT2
                                                              __ctype_b.symtab0x50c1408OBJECT<unknown>DEFAULT9
                                                              __ctype_toupper.symtab0x50c1508OBJECT<unknown>DEFAULT9
                                                              __curbrk.symtab0x5126888OBJECT<unknown>HIDDEN10
                                                              __data_start.symtab0x50c0500NOTYPE<unknown>DEFAULT9
                                                              __deregister_frame_info.symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                                              __do_global_ctors_aux.symtab0x40a4400FUNC<unknown>DEFAULT2
                                                              __do_global_dtors_aux.symtab0x4001000FUNC<unknown>DEFAULT2
                                                              __dso_handle.symtab0x50c0400OBJECT<unknown>HIDDEN9
                                                              __environ.symtab0x5126588OBJECT<unknown>DEFAULT10
                                                              __errno_location.symtab0x40700c6FUNC<unknown>DEFAULT2
                                                              __errno_location.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              __exit_cleanup.symtab0x5126488OBJECT<unknown>HIDDEN10
                                                              __fini_array_end.symtab0x50c0000NOTYPE<unknown>HIDDENSHN_ABS
                                                              __fini_array_start.symtab0x50c0000NOTYPE<unknown>HIDDENSHN_ABS
                                                              __fputc_unlocked.symtab0x4071c4192FUNC<unknown>DEFAULT2
                                                              __getpagesize.symtab0x40992819FUNC<unknown>DEFAULT2
                                                              __h_errno_location.symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                                              __init_array_end.symtab0x50c0000NOTYPE<unknown>HIDDENSHN_ABS
                                                              __init_array_start.symtab0x50c0000NOTYPE<unknown>HIDDENSHN_ABS
                                                              __libc_close.symtab0x406c8041FUNC<unknown>DEFAULT2
                                                              __libc_connect.symtab0x4079f843FUNC<unknown>DEFAULT2
                                                              __libc_creat.symtab0x406e7214FUNC<unknown>DEFAULT2
                                                              __libc_fcntl.symtab0x406bc8100FUNC<unknown>DEFAULT2
                                                              __libc_fcntl64.symtab0x406bc8100FUNC<unknown>DEFAULT2
                                                              __libc_fork.symtab0x406cd838FUNC<unknown>DEFAULT2
                                                              __libc_getpid.symtab0x406d2438FUNC<unknown>DEFAULT2
                                                              __libc_lseek.symtab0x40a41045FUNC<unknown>DEFAULT2
                                                              __libc_lseek64.symtab0x40a4085FUNC<unknown>DEFAULT2
                                                              __libc_nanosleep.symtab0x40998c38FUNC<unknown>DEFAULT2
                                                              __libc_open.symtab0x406e08106FUNC<unknown>DEFAULT2
                                                              __libc_read.symtab0x406ea839FUNC<unknown>DEFAULT2
                                                              __libc_recv.symtab0x407a8411FUNC<unknown>DEFAULT2
                                                              __libc_recvfrom.symtab0x407a9045FUNC<unknown>DEFAULT2
                                                              __libc_select.symtab0x406ed044FUNC<unknown>DEFAULT2
                                                              __libc_send.symtab0x407ac011FUNC<unknown>DEFAULT2
                                                              __libc_sendto.symtab0x407acc48FUNC<unknown>DEFAULT2
                                                              __libc_sigaction.symtab0x40971d247FUNC<unknown>DEFAULT2
                                                              __libc_stack_end.symtab0x5126508OBJECT<unknown>DEFAULT10
                                                              __libc_waitpid.symtab0x406fa47FUNC<unknown>DEFAULT2
                                                              __libc_write.symtab0x406fac42FUNC<unknown>DEFAULT2
                                                              __malloc_consolidate.symtab0x408601410FUNC<unknown>HIDDEN2
                                                              __malloc_largebin_index.symtab0x407ca096FUNC<unknown>DEFAULT2
                                                              __malloc_lock.symtab0x50c3a040OBJECT<unknown>DEFAULT9
                                                              __malloc_state.symtab0x5127201752OBJECT<unknown>DEFAULT10
                                                              __malloc_trim.symtab0x408568153FUNC<unknown>DEFAULT2
                                                              __pagesize.symtab0x5126608OBJECT<unknown>DEFAULT10
                                                              __preinit_array_end.symtab0x50c0000NOTYPE<unknown>HIDDENSHN_ABS
                                                              __preinit_array_start.symtab0x50c0000NOTYPE<unknown>HIDDENSHN_ABS
                                                              __pthread_initialize_minimal.symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                                              __pthread_mutex_init.symtab0x4094ae3FUNC<unknown>DEFAULT2
                                                              __pthread_mutex_lock.symtab0x4094ae3FUNC<unknown>DEFAULT2
                                                              __pthread_mutex_trylock.symtab0x4094ae3FUNC<unknown>DEFAULT2
                                                              __pthread_mutex_unlock.symtab0x4094ae3FUNC<unknown>DEFAULT2
                                                              __pthread_return_0.symtab0x4094ae3FUNC<unknown>DEFAULT2
                                                              __pthread_return_void.symtab0x4094b11FUNC<unknown>DEFAULT2
                                                              __raise.symtab0x40a04818FUNC<unknown>HIDDEN2
                                                              __register_frame_info.symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                                              __restore_rt.symtab0x4097140NOTYPE<unknown>DEFAULT2
                                                              __rtld_fini.symtab0x5126708OBJECT<unknown>HIDDEN10
                                                              __sigaddset.symtab0x407c6428FUNC<unknown>DEFAULT2
                                                              __sigdelset.symtab0x407c8030FUNC<unknown>DEFAULT2
                                                              __sigismember.symtab0x407c4432FUNC<unknown>DEFAULT2
                                                              __stdin.symtab0x50c1788OBJECT<unknown>DEFAULT9
                                                              __stdio_WRITE.symtab0x409a30147FUNC<unknown>HIDDEN2
                                                              __stdio_adjust_position.symtab0x40a184133FUNC<unknown>HIDDEN2
                                                              __stdio_fwrite.symtab0x409ac4259FUNC<unknown>HIDDEN2
                                                              __stdio_init_mutex.symtab0x40710315FUNC<unknown>HIDDEN2
                                                              __stdio_mutex_initializer.4280.symtab0x40b9a040OBJECT<unknown>DEFAULT4
                                                              __stdio_seek.symtab0x40a20c31FUNC<unknown>HIDDEN2
                                                              __stdio_trans2w_o.symtab0x409bc8148FUNC<unknown>HIDDEN2
                                                              __stdio_wcommit.symtab0x40719c39FUNC<unknown>HIDDEN2
                                                              __stdout.symtab0x50c1808OBJECT<unknown>DEFAULT9
                                                              __syscall_error.symtab0x40981422FUNC<unknown>HIDDEN2
                                                              __syscall_error.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              __syscall_fcntl.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              __uClibc_fini.symtab0x40946870FUNC<unknown>DEFAULT2
                                                              __uClibc_init.symtab0x4094e767FUNC<unknown>DEFAULT2
                                                              __uClibc_main.symtab0x40952a489FUNC<unknown>DEFAULT2
                                                              __uClibc_main.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              __uclibc_progname.symtab0x50c5488OBJECT<unknown>HIDDEN9
                                                              __vfork.symtab0x406bb021FUNC<unknown>HIDDEN2
                                                              _adjust_pos.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              _cs_funcs.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              _dl_aux_init.symtab0x40a05c23FUNC<unknown>DEFAULT2
                                                              _dl_phdr.symtab0x512df88OBJECT<unknown>DEFAULT10
                                                              _dl_phnum.symtab0x512e008OBJECT<unknown>DEFAULT10
                                                              _edata.symtab0x50c5500NOTYPE<unknown>DEFAULTSHN_ABS
                                                              _end.symtab0x512e080NOTYPE<unknown>DEFAULTSHN_ABS
                                                              _errno.symtab0x51267c4OBJECT<unknown>DEFAULT10
                                                              _exit.symtab0x406c2c42FUNC<unknown>DEFAULT2
                                                              _exit.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              _fini.symtab0x40a4785FUNC<unknown>DEFAULT3
                                                              _fixed_buffers.symtab0x5106208192OBJECT<unknown>DEFAULT10
                                                              _fwrite.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              _h_errno.symtab0x5126804OBJECT<unknown>DEFAULT10
                                                              _init.symtab0x4000e85FUNC<unknown>DEFAULT1
                                                              _pthread_cleanup_pop_restore.symtab0x4094b11FUNC<unknown>DEFAULT2
                                                              _pthread_cleanup_push_defer.symtab0x4094b11FUNC<unknown>DEFAULT2
                                                              _sigintr.symtab0x5126a0128OBJECT<unknown>HIDDEN10
                                                              _start.symtab0x40019442FUNC<unknown>DEFAULT2
                                                              _stdio.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              _stdio_init.symtab0x407098107FUNC<unknown>HIDDEN2
                                                              _stdio_openlist.symtab0x50c1888OBJECT<unknown>DEFAULT9
                                                              _stdio_openlist_add_lock.symtab0x50c1a040OBJECT<unknown>DEFAULT9
                                                              _stdio_openlist_del_count.symtab0x5106044OBJECT<unknown>DEFAULT10
                                                              _stdio_openlist_del_lock.symtab0x50c1e040OBJECT<unknown>DEFAULT9
                                                              _stdio_openlist_use_count.symtab0x5106004OBJECT<unknown>DEFAULT10
                                                              _stdio_streams.symtab0x50c220384OBJECT<unknown>DEFAULT9
                                                              _stdio_term.symtab0x407112135FUNC<unknown>HIDDEN2
                                                              _stdio_user_locking.symtab0x50c2084OBJECT<unknown>DEFAULT9
                                                              _stdlib_strto_l.symtab0x408e80362FUNC<unknown>HIDDEN2
                                                              _stdlib_strto_l.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              _trans2w.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              _uintmaxtostr.symtab0x409c5c187FUNC<unknown>HIDDEN2
                                                              _uintmaxtostr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              _wcommit.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              abort.symtab0x40897c276FUNC<unknown>DEFAULT2
                                                              abort.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              atoi.symtab0x408e6018FUNC<unknown>DEFAULT2
                                                              atoi.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              been_there_done_that.symtab0x5126404OBJECT<unknown>DEFAULT10
                                                              been_there_done_that.3160.symtab0x5126784OBJECT<unknown>DEFAULT10
                                                              brk.symtab0x40a07443FUNC<unknown>DEFAULT2
                                                              brk.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              bsd_signal.symtab0x407b9c168FUNC<unknown>DEFAULT2
                                                              buf.2989.symtab0x51263016OBJECT<unknown>DEFAULT10
                                                              c.symtab0x50c1304OBJECT<unknown>DEFAULT9
                                                              chdir.symtab0x406c5838FUNC<unknown>DEFAULT2
                                                              chdir.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              client.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              clock_getres.symtab0x40985c41FUNC<unknown>DEFAULT2
                                                              clock_getres.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              close.symtab0x406c8041FUNC<unknown>DEFAULT2
                                                              close.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              commServer.symtab0x50c0608OBJECT<unknown>DEFAULT9
                                                              completed.2761.symtab0x50c5601OBJECT<unknown>DEFAULT10
                                                              connect.symtab0x4079f843FUNC<unknown>DEFAULT2
                                                              connect.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              connectTimeout.symtab0x401900572FUNC<unknown>DEFAULT2
                                                              creat.symtab0x406e7214FUNC<unknown>DEFAULT2
                                                              crtstuff.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              crtstuff.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              csum.symtab0x4024fa115FUNC<unknown>DEFAULT2
                                                              currentServer.symtab0x50c0684OBJECT<unknown>DEFAULT9
                                                              data_start.symtab0x50c0500NOTYPE<unknown>DEFAULT9
                                                              dl-support.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              dup2.symtab0x406cac44FUNC<unknown>DEFAULT2
                                                              dup2.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              environ.symtab0x5126588OBJECT<unknown>DEFAULT10
                                                              errno.symtab0x51267c4OBJECT<unknown>DEFAULT10
                                                              errno.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              execl.symtab0x409048287FUNC<unknown>DEFAULT2
                                                              execl.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              execve.symtab0x40988838FUNC<unknown>DEFAULT2
                                                              execve.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              exit.symtab0x408fec92FUNC<unknown>DEFAULT2
                                                              exit.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              fcntl.symtab0x406bc8100FUNC<unknown>DEFAULT2
                                                              fcntl64.symtab0x406bc8100FUNC<unknown>DEFAULT2
                                                              fdgets.symtab0x40113e128FUNC<unknown>DEFAULT2
                                                              fdopen_pids.symtab0x5105e08OBJECT<unknown>DEFAULT10
                                                              fdpclose.symtab0x400fce368FUNC<unknown>DEFAULT2
                                                              fdpopen.symtab0x400df2476FUNC<unknown>DEFAULT2
                                                              fork.symtab0x406cd838FUNC<unknown>DEFAULT2
                                                              fork.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              fputc_unlocked.symtab0x4071c4192FUNC<unknown>DEFAULT2
                                                              fputc_unlocked.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              fputs_unlocked.symtab0x40728456FUNC<unknown>DEFAULT2
                                                              fputs_unlocked.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              frame_dummy.symtab0x4001500FUNC<unknown>DEFAULT2
                                                              free.symtab0x40879b452FUNC<unknown>DEFAULT2
                                                              free.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              fseek.symtab0x40a0a05FUNC<unknown>DEFAULT2
                                                              fseeko.symtab0x40a0a05FUNC<unknown>DEFAULT2
                                                              fseeko.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              fseeko64.symtab0x40a0a8218FUNC<unknown>DEFAULT2
                                                              fseeko64.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              fwrite_unlocked.symtab0x4072bc134FUNC<unknown>DEFAULT2
                                                              fwrite_unlocked.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              getBogos.symtab0x4013c2470FUNC<unknown>DEFAULT2
                                                              getBuild.symtab0x40641111FUNC<unknown>DEFAULT2
                                                              getCores.symtab0x401598153FUNC<unknown>DEFAULT2
                                                              getHost.symtab0x40134665FUNC<unknown>DEFAULT2
                                                              getOurIP.symtab0x40622d484FUNC<unknown>DEFAULT2
                                                              getRandomIP.symtab0x4024cb47FUNC<unknown>DEFAULT2
                                                              getRandomPublicIP.symtab0x4020c61029FUNC<unknown>DEFAULT2
                                                              getdtablesize.symtab0x406d0035FUNC<unknown>DEFAULT2
                                                              getdtablesize.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              getegid.symtab0x4098b038FUNC<unknown>DEFAULT2
                                                              getegid.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              geteuid.symtab0x4098d838FUNC<unknown>DEFAULT2
                                                              geteuid.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              getgid.symtab0x40990038FUNC<unknown>DEFAULT2
                                                              getgid.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              getpagesize.symtab0x40992819FUNC<unknown>DEFAULT2
                                                              getpagesize.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              getpid.symtab0x406d2438FUNC<unknown>DEFAULT2
                                                              getpid.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              getrlimit.symtab0x406d4c40FUNC<unknown>DEFAULT2
                                                              getrlimit.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              getrlimit64.symtab0x406d4c40FUNC<unknown>DEFAULT2
                                                              getsockname.symtab0x407a2441FUNC<unknown>DEFAULT2
                                                              getsockname.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              getsockopt.symtab0x407a5050FUNC<unknown>DEFAULT2
                                                              getsockopt.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              getuid.symtab0x40993c38FUNC<unknown>DEFAULT2
                                                              getuid.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              gotIP.symtab0x50c5c44OBJECT<unknown>DEFAULT10
                                                              h_errno.symtab0x5126804OBJECT<unknown>DEFAULT10
                                                              hextable.symtab0x40a5402048OBJECT<unknown>DEFAULT4
                                                              htonl.symtab0x4079705FUNC<unknown>DEFAULT2
                                                              htons.symtab0x4079688FUNC<unknown>DEFAULT2
                                                              i.4536.symtab0x50c1344OBJECT<unknown>DEFAULT9
                                                              index.symtab0x4074a0417FUNC<unknown>DEFAULT2
                                                              inet_addr.symtab0x4079dc28FUNC<unknown>DEFAULT2
                                                              inet_aton.symtab0x409fbc137FUNC<unknown>DEFAULT2
                                                              inet_aton.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              inet_makeaddr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              inet_ntoa.symtab0x4079d110FUNC<unknown>DEFAULT2
                                                              inet_ntoa.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              inet_ntoa_r.symtab0x40798477FUNC<unknown>DEFAULT2
                                                              initConnection.symtab0x406103298FUNC<unknown>DEFAULT2
                                                              init_rand.symtab0x4001c0125FUNC<unknown>DEFAULT2
                                                              initfini.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              initstate.symtab0x408b46110FUNC<unknown>DEFAULT2
                                                              initstate_r.symtab0x408da7185FUNC<unknown>DEFAULT2
                                                              ioctl.symtab0x406d74104FUNC<unknown>DEFAULT2
                                                              ioctl.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              ipState.symtab0x50c5d65OBJECT<unknown>DEFAULT10
                                                              isatty.symtab0x4078dc25FUNC<unknown>DEFAULT2
                                                              isatty.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              isspace.symtab0x406fd818FUNC<unknown>DEFAULT2
                                                              isspace.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              kill.symtab0x406ddc44FUNC<unknown>DEFAULT2
                                                              kill.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              libc/string/x86_64/memcpy.S.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              libc/string/x86_64/mempcpy.S.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              libc/string/x86_64/memset.S.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              libc/string/x86_64/strchr.S.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              libc/string/x86_64/strcpy.S.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              libc/string/x86_64/strlen.S.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              libc/string/x86_64/strpbrk.S.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              libc/string/x86_64/strspn.S.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              libc/sysdeps/linux/x86_64/crt1.S.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              libc/sysdeps/linux/x86_64/crti.S.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              libc/sysdeps/linux/x86_64/crtn.S.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              libc/sysdeps/linux/x86_64/vfork.S.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              listFork.symtab0x401b3c201FUNC<unknown>DEFAULT2
                                                              llseek.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              lseek.symtab0x40a41045FUNC<unknown>DEFAULT2
                                                              lseek.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              lseek64.symtab0x40a4085FUNC<unknown>DEFAULT2
                                                              macAddress.symtab0x50c5d06OBJECT<unknown>DEFAULT10
                                                              main.symtab0x40641c1939FUNC<unknown>DEFAULT2
                                                              mainCommSock.symtab0x50c5c04OBJECT<unknown>DEFAULT10
                                                              makeIPPacket.symtab0x40262c153FUNC<unknown>DEFAULT2
                                                              makeRandomStr.symtab0x401631109FUNC<unknown>DEFAULT2
                                                              malloc.symtab0x407d002149FUNC<unknown>DEFAULT2
                                                              malloc.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              malloc_trim.symtab0x40895f28FUNC<unknown>DEFAULT2
                                                              matchPrompt.symtab0x401d23345FUNC<unknown>DEFAULT2
                                                              memchr.symtab0x409d7c240FUNC<unknown>DEFAULT2
                                                              memchr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              memcpy.symtab0x407350102FUNC<unknown>DEFAULT2
                                                              mempcpy.symtab0x409d2090FUNC<unknown>DEFAULT2
                                                              memrchr.symtab0x409e6c237FUNC<unknown>DEFAULT2
                                                              memrchr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              memset.symtab0x4073c0210FUNC<unknown>DEFAULT2
                                                              mmap.symtab0x40982c48FUNC<unknown>DEFAULT2
                                                              mmap.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              munmap.symtab0x40996438FUNC<unknown>DEFAULT2
                                                              munmap.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              mylock.symtab0x50c3e040OBJECT<unknown>DEFAULT9
                                                              mylock.symtab0x50c42040OBJECT<unknown>DEFAULT9
                                                              nanosleep.symtab0x40998c38FUNC<unknown>DEFAULT2
                                                              nanosleep.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              negotiate.symtab0x401c05286FUNC<unknown>DEFAULT2
                                                              next_start.1440.symtab0x5126208OBJECT<unknown>DEFAULT10
                                                              ntohl.symtab0x40797d5FUNC<unknown>DEFAULT2
                                                              ntohl.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              ntohs.symtab0x4079758FUNC<unknown>DEFAULT2
                                                              numpids.symtab0x50c5c88OBJECT<unknown>DEFAULT10
                                                              object.2814.symtab0x50c58048OBJECT<unknown>DEFAULT10
                                                              open.symtab0x406e08106FUNC<unknown>DEFAULT2
                                                              open.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              ourIP.symtab0x5126904OBJECT<unknown>DEFAULT10
                                                              p.2759.symtab0x50c0480OBJECT<unknown>DEFAULT9
                                                              parseHex.symtab0x4011be84FUNC<unknown>DEFAULT2
                                                              passwords.symtab0x50c0c0112OBJECT<unknown>DEFAULT9
                                                              pids.symtab0x5126988OBJECT<unknown>DEFAULT10
                                                              pipe.symtab0x406e8038FUNC<unknown>DEFAULT2
                                                              pipe.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              print.symtab0x4006271085FUNC<unknown>DEFAULT2
                                                              printchar.symtab0x4003bd75FUNC<unknown>DEFAULT2
                                                              printi.symtab0x4004e7320FUNC<unknown>DEFAULT2
                                                              prints.symtab0x400408223FUNC<unknown>DEFAULT2
                                                              processCmd.symtab0x4052a43679FUNC<unknown>DEFAULT2
                                                              putc_unlocked.symtab0x4071c4192FUNC<unknown>DEFAULT2
                                                              puts.symtab0x407014130FUNC<unknown>DEFAULT2
                                                              puts.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              raise.symtab0x40a04818FUNC<unknown>DEFAULT2
                                                              raise.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              rand.symtab0x408a9011FUNC<unknown>DEFAULT2
                                                              rand.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              rand_cmwc.symtab0x40023d179FUNC<unknown>DEFAULT2
                                                              random.symtab0x408a9c72FUNC<unknown>DEFAULT2
                                                              random.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              random_poly_info.symtab0x40b9e040OBJECT<unknown>DEFAULT4
                                                              random_r.symtab0x408ca490FUNC<unknown>DEFAULT2
                                                              random_r.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              randtbl.symtab0x50c4a0128OBJECT<unknown>DEFAULT9
                                                              rawmemchr.symtab0x40a348190FUNC<unknown>DEFAULT2
                                                              rawmemchr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              read.symtab0x406ea839FUNC<unknown>DEFAULT2
                                                              read.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              readUntil.symtab0x401e7c586FUNC<unknown>DEFAULT2
                                                              recv.symtab0x407a8411FUNC<unknown>DEFAULT2
                                                              recv.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              recvLine.symtab0x40169e610FUNC<unknown>DEFAULT2
                                                              recvfrom.symtab0x407a9045FUNC<unknown>DEFAULT2
                                                              recvfrom.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              sbrk.symtab0x4099b474FUNC<unknown>DEFAULT2
                                                              sbrk.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              scanPid.symtab0x5126944OBJECT<unknown>DEFAULT10
                                                              sclose.symtab0x4026c546FUNC<unknown>DEFAULT2
                                                              select.symtab0x406ed044FUNC<unknown>DEFAULT2
                                                              select.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              send.symtab0x407ac011FUNC<unknown>DEFAULT2
                                                              send.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              sendHOLD.symtab0x404e011187FUNC<unknown>DEFAULT2
                                                              sendJUNK.symtab0x4049e31054FUNC<unknown>DEFAULT2
                                                              sendTCP.symtab0x40438c1623FUNC<unknown>DEFAULT2
                                                              sendUDP.symtab0x403ead1247FUNC<unknown>DEFAULT2
                                                              sendto.symtab0x407acc48FUNC<unknown>DEFAULT2
                                                              sendto.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              setsid.symtab0x406efc38FUNC<unknown>DEFAULT2
                                                              setsid.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              setsockopt.symtab0x407afc53FUNC<unknown>DEFAULT2
                                                              setsockopt.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              setstate.symtab0x408ae498FUNC<unknown>DEFAULT2
                                                              setstate_r.symtab0x408bfc168FUNC<unknown>DEFAULT2
                                                              sigaction.symtab0x40971d247FUNC<unknown>DEFAULT2
                                                              sigaction.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              sigaddset.symtab0x407b6435FUNC<unknown>DEFAULT2
                                                              sigaddset.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              sigempty.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              sigemptyset.symtab0x407b8820FUNC<unknown>DEFAULT2
                                                              signal.symtab0x407b9c168FUNC<unknown>DEFAULT2
                                                              signal.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              sigprocmask.symtab0x406f2485FUNC<unknown>DEFAULT2
                                                              sigprocmask.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              sigsetops.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              sleep.symtab0x409168415FUNC<unknown>DEFAULT2
                                                              sleep.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              socket.symtab0x407b3447FUNC<unknown>DEFAULT2
                                                              socket.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              sockprintf.symtab0x400c2c454FUNC<unknown>DEFAULT2
                                                              srand.symtab0x408bb472FUNC<unknown>DEFAULT2
                                                              srandom.symtab0x408bb472FUNC<unknown>DEFAULT2
                                                              srandom_r.symtab0x408cfe169FUNC<unknown>DEFAULT2
                                                              stderr.symtab0x50c1708OBJECT<unknown>DEFAULT9
                                                              stdin.symtab0x50c1608OBJECT<unknown>DEFAULT9
                                                              stdout.symtab0x50c1688OBJECT<unknown>DEFAULT9
                                                              strchr.symtab0x4074a0417FUNC<unknown>DEFAULT2
                                                              strcpy.symtab0x407650213FUNC<unknown>DEFAULT2
                                                              strlen.symtab0x407730225FUNC<unknown>DEFAULT2
                                                              strpbrk.symtab0x40a230140FUNC<unknown>DEFAULT2
                                                              strspn.symtab0x40a2c0135FUNC<unknown>DEFAULT2
                                                              strstr.symtab0x407814187FUNC<unknown>DEFAULT2
                                                              strstr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              strtoimax.symtab0x408e7410FUNC<unknown>DEFAULT2
                                                              strtok.symtab0x4078d010FUNC<unknown>DEFAULT2
                                                              strtok.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              strtok_r.symtab0x409f5c94FUNC<unknown>DEFAULT2
                                                              strtok_r.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              strtol.symtab0x408e7410FUNC<unknown>DEFAULT2
                                                              strtol.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              strtoll.symtab0x408e7410FUNC<unknown>DEFAULT2
                                                              sysconf.symtab0x409308351FUNC<unknown>DEFAULT2
                                                              sysconf.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              szprintf.symtab0x400b47229FUNC<unknown>DEFAULT2
                                                              tcgetattr.symtab0x4078f8110FUNC<unknown>DEFAULT2
                                                              tcgetattr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              tcpcsum.symtab0x40256d191FUNC<unknown>DEFAULT2
                                                              time.symtab0x406f7c39FUNC<unknown>DEFAULT2
                                                              time.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              toupper.symtab0x406fec30FUNC<unknown>DEFAULT2
                                                              toupper.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              trim.symtab0x4002f0205FUNC<unknown>DEFAULT2
                                                              unsafe_state.symtab0x50c46048OBJECT<unknown>DEFAULT9
                                                              uppercase.symtab0x40138759FUNC<unknown>DEFAULT2
                                                              usernames.symtab0x50c08048OBJECT<unknown>DEFAULT9
                                                              vfork.symtab0x406bb021FUNC<unknown>DEFAULT2
                                                              wait4.symtab0x409a0047FUNC<unknown>DEFAULT2
                                                              wait4.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              waitpid.symtab0x406fa47FUNC<unknown>DEFAULT2
                                                              waitpid.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              wildString.symtab0x401212308FUNC<unknown>DEFAULT2
                                                              write.symtab0x406fac42FUNC<unknown>DEFAULT2
                                                              write.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              zprintf.symtab0x400a64227FUNC<unknown>DEFAULT2

                                                              Download Network PCAP: filteredfull

                                                              • Total Packets: 50
                                                              • 6667 undefined
                                                              • 443 (HTTPS)
                                                              • 80 (HTTP)
                                                              TimestampSource PortDest PortSource IPDest IP
                                                              Mar 21, 2025 21:06:59.898962021 CET43928443192.168.2.2391.189.91.42
                                                              Mar 21, 2025 21:07:00.905654907 CET572906667192.168.2.2393.115.172.234
                                                              Mar 21, 2025 21:07:01.079627037 CET66675729093.115.172.234192.168.2.23
                                                              Mar 21, 2025 21:07:05.274060965 CET42836443192.168.2.2391.189.91.43
                                                              Mar 21, 2025 21:07:06.081254959 CET572926667192.168.2.2393.115.172.234
                                                              Mar 21, 2025 21:07:06.252233982 CET66675729293.115.172.234192.168.2.23
                                                              Mar 21, 2025 21:07:06.809834957 CET4251680192.168.2.23109.202.202.202
                                                              Mar 21, 2025 21:07:11.253842115 CET572946667192.168.2.2393.115.172.234
                                                              Mar 21, 2025 21:07:11.424370050 CET66675729493.115.172.234192.168.2.23
                                                              Mar 21, 2025 21:07:16.426245928 CET572966667192.168.2.2393.115.172.234
                                                              Mar 21, 2025 21:07:16.597584963 CET66675729693.115.172.234192.168.2.23
                                                              Mar 21, 2025 21:07:21.399841070 CET43928443192.168.2.2391.189.91.42
                                                              Mar 21, 2025 21:07:21.599821091 CET572986667192.168.2.2393.115.172.234
                                                              Mar 21, 2025 21:07:21.773895979 CET66675729893.115.172.234192.168.2.23
                                                              Mar 21, 2025 21:07:26.775561094 CET573006667192.168.2.2393.115.172.234
                                                              Mar 21, 2025 21:07:26.941294909 CET66675730093.115.172.234192.168.2.23
                                                              Mar 21, 2025 21:07:31.638329983 CET42836443192.168.2.2391.189.91.43
                                                              Mar 21, 2025 21:07:31.943304062 CET573026667192.168.2.2393.115.172.234
                                                              Mar 21, 2025 21:07:32.124069929 CET66675730293.115.172.234192.168.2.23
                                                              Mar 21, 2025 21:07:37.125161886 CET573046667192.168.2.2393.115.172.234
                                                              Mar 21, 2025 21:07:37.297072887 CET66675730493.115.172.234192.168.2.23
                                                              Mar 21, 2025 21:07:37.781438112 CET4251680192.168.2.23109.202.202.202
                                                              Mar 21, 2025 21:07:42.298250914 CET573066667192.168.2.2393.115.172.234
                                                              Mar 21, 2025 21:07:42.466049910 CET66675730693.115.172.234192.168.2.23
                                                              Mar 21, 2025 21:07:47.466948032 CET573086667192.168.2.2393.115.172.234
                                                              Mar 21, 2025 21:07:47.633301973 CET66675730893.115.172.234192.168.2.23
                                                              Mar 21, 2025 21:07:52.634879112 CET573106667192.168.2.2393.115.172.234
                                                              Mar 21, 2025 21:07:52.805409908 CET66675731093.115.172.234192.168.2.23
                                                              Mar 21, 2025 21:07:57.806721926 CET573126667192.168.2.2393.115.172.234
                                                              Mar 21, 2025 21:07:57.973233938 CET66675731293.115.172.234192.168.2.23
                                                              Mar 21, 2025 21:08:02.354006052 CET43928443192.168.2.2391.189.91.42
                                                              Mar 21, 2025 21:08:02.974214077 CET573146667192.168.2.2393.115.172.234
                                                              Mar 21, 2025 21:08:03.148490906 CET66675731493.115.172.234192.168.2.23
                                                              Mar 21, 2025 21:08:08.149646997 CET573166667192.168.2.2393.115.172.234
                                                              Mar 21, 2025 21:08:08.319583893 CET66675731693.115.172.234192.168.2.23
                                                              Mar 21, 2025 21:08:13.320751905 CET573186667192.168.2.2393.115.172.234
                                                              Mar 21, 2025 21:08:13.493052959 CET66675731893.115.172.234192.168.2.23
                                                              Mar 21, 2025 21:08:18.494263887 CET573206667192.168.2.2393.115.172.234
                                                              Mar 21, 2025 21:08:18.664012909 CET66675732093.115.172.234192.168.2.23
                                                              Mar 21, 2025 21:08:23.665425062 CET573226667192.168.2.2393.115.172.234
                                                              Mar 21, 2025 21:08:24.686866045 CET573226667192.168.2.2393.115.172.234
                                                              Mar 21, 2025 21:08:24.861939907 CET66675732293.115.172.234192.168.2.23
                                                              Mar 21, 2025 21:08:29.863775015 CET573246667192.168.2.2393.115.172.234
                                                              Mar 21, 2025 21:08:30.028166056 CET66675732493.115.172.234192.168.2.23
                                                              Mar 21, 2025 21:08:35.029684067 CET573266667192.168.2.2393.115.172.234
                                                              Mar 21, 2025 21:08:35.201349020 CET66675732693.115.172.234192.168.2.23
                                                              Mar 21, 2025 21:08:40.202889919 CET573286667192.168.2.2393.115.172.234
                                                              Mar 21, 2025 21:08:40.373908997 CET66675732893.115.172.234192.168.2.23
                                                              Mar 21, 2025 21:08:45.375958920 CET573306667192.168.2.2393.115.172.234
                                                              Mar 21, 2025 21:08:45.551532030 CET66675733093.115.172.234192.168.2.23
                                                              Mar 21, 2025 21:08:50.553652048 CET573326667192.168.2.2393.115.172.234
                                                              Mar 21, 2025 21:08:50.717361927 CET66675733293.115.172.234192.168.2.23
                                                              Mar 21, 2025 21:08:55.719857931 CET573346667192.168.2.2393.115.172.234
                                                              Mar 21, 2025 21:08:55.892601967 CET66675733493.115.172.234192.168.2.23
                                                              Mar 21, 2025 21:09:00.894301891 CET573366667192.168.2.2393.115.172.234
                                                              Mar 21, 2025 21:09:01.064687014 CET66675733693.115.172.234192.168.2.23
                                                              Mar 21, 2025 21:09:06.066090107 CET573386667192.168.2.2393.115.172.234
                                                              Mar 21, 2025 21:09:06.232095957 CET66675733893.115.172.234192.168.2.23
                                                              Mar 21, 2025 21:09:11.233551025 CET573406667192.168.2.2393.115.172.234
                                                              Mar 21, 2025 21:09:11.401031971 CET66675734093.115.172.234192.168.2.23
                                                              Mar 21, 2025 21:09:16.402344942 CET573426667192.168.2.2393.115.172.234
                                                              Mar 21, 2025 21:09:16.566621065 CET66675734293.115.172.234192.168.2.23
                                                              Mar 21, 2025 21:09:21.568855047 CET573446667192.168.2.2393.115.172.234
                                                              Mar 21, 2025 21:09:21.741092920 CET66675734493.115.172.234192.168.2.23
                                                              Mar 21, 2025 21:09:26.742048025 CET573466667192.168.2.2393.115.172.234
                                                              Mar 21, 2025 21:09:26.913024902 CET66675734693.115.172.234192.168.2.23
                                                              Mar 21, 2025 21:09:31.914165974 CET573486667192.168.2.2393.115.172.234
                                                              Mar 21, 2025 21:09:32.084243059 CET66675734893.115.172.234192.168.2.23
                                                              Mar 21, 2025 21:09:37.085401058 CET573506667192.168.2.2393.115.172.234
                                                              Mar 21, 2025 21:09:37.256757021 CET66675735093.115.172.234192.168.2.23
                                                              Mar 21, 2025 21:09:42.257728100 CET573526667192.168.2.2393.115.172.234
                                                              Mar 21, 2025 21:09:42.433604002 CET66675735293.115.172.234192.168.2.23
                                                              Mar 21, 2025 21:09:47.434632063 CET573546667192.168.2.2393.115.172.234
                                                              Mar 21, 2025 21:09:47.609963894 CET66675735493.115.172.234192.168.2.23
                                                              Mar 21, 2025 21:09:52.611659050 CET573566667192.168.2.2393.115.172.234
                                                              Mar 21, 2025 21:09:52.776000023 CET66675735693.115.172.234192.168.2.23
                                                              Mar 21, 2025 21:09:57.777582884 CET573586667192.168.2.2393.115.172.234
                                                              Mar 21, 2025 21:09:57.950973988 CET66675735893.115.172.234192.168.2.23
                                                              Mar 21, 2025 21:10:02.952337980 CET573606667192.168.2.2393.115.172.234
                                                              Mar 21, 2025 21:10:03.128463984 CET66675736093.115.172.234192.168.2.23
                                                              Mar 21, 2025 21:10:08.130440950 CET573626667192.168.2.2393.115.172.234
                                                              Mar 21, 2025 21:10:08.302966118 CET66675736293.115.172.234192.168.2.23
                                                              Mar 21, 2025 21:10:13.304579973 CET573646667192.168.2.2393.115.172.234
                                                              Mar 21, 2025 21:10:13.477433920 CET66675736493.115.172.234192.168.2.23
                                                              Mar 21, 2025 21:10:18.479116917 CET573666667192.168.2.2393.115.172.234
                                                              Mar 21, 2025 21:10:18.650913954 CET66675736693.115.172.234192.168.2.23
                                                              Mar 21, 2025 21:10:23.654010057 CET573686667192.168.2.2393.115.172.234
                                                              Mar 21, 2025 21:10:23.823858976 CET66675736893.115.172.234192.168.2.23
                                                              Mar 21, 2025 21:10:28.825867891 CET573706667192.168.2.2393.115.172.234
                                                              Mar 21, 2025 21:10:29.000849009 CET66675737093.115.172.234192.168.2.23
                                                              Mar 21, 2025 21:10:34.002367020 CET573726667192.168.2.2393.115.172.234
                                                              Mar 21, 2025 21:10:34.177782059 CET66675737293.115.172.234192.168.2.23

                                                              System Behavior

                                                              Start time (UTC):20:06:59
                                                              Start date (UTC):21/03/2025
                                                              Path:/tmp/bash.elf
                                                              Arguments:/tmp/bash.elf
                                                              File size:72787 bytes
                                                              MD5 hash:9ca1dfb0f1ca103a1a1c29b723122a45

                                                              Start time (UTC):20:06:59
                                                              Start date (UTC):21/03/2025
                                                              Path:/tmp/bash.elf
                                                              Arguments:-
                                                              File size:72787 bytes
                                                              MD5 hash:9ca1dfb0f1ca103a1a1c29b723122a45

                                                              Start time (UTC):20:06:59
                                                              Start date (UTC):21/03/2025
                                                              Path:/tmp/bash.elf
                                                              Arguments:-
                                                              File size:72787 bytes
                                                              MD5 hash:9ca1dfb0f1ca103a1a1c29b723122a45