Edit tour

Linux Analysis Report
frosty.arm5.elf

Overview

General Information

Sample name:frosty.arm5.elf
Analysis ID:1648910
MD5:95e11ececeea025ca342cc5c414380f9
SHA1:ede9947bd603742ea467e6fb47db023e13868074
SHA256:429a86088027bf5058d53ba501211336924d2b291c40e71cd6856da74cbe9afe
Tags:elfuser-abuse_ch
Infos:

Detection

Score:48
Range:0 - 100

Signatures

Multi AV Scanner detection for submitted file
Executes the "rm" command used to delete files or directories
Sample has stripped symbol table
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
Joe Sandbox version:42.0.0 Malachite
Analysis ID:1648910
Start date and time:2025-03-26 10:23:54 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 10m 48s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:frosty.arm5.elf
Detection:MAL
Classification:mal48.linELF@0/0@0/0
Cookbook Comments:
  • Analysis time extended to 480s due to sleep detection in submitted sample
  • Max analysis timeout: 600s exceeded, the analysis took too long
Command:/tmp/frosty.arm5.elf
PID:6253
Exit Code:255
Exit Code Info:
Killed:False
Standard Output:

Standard Error:/lib/ld-uClibc.so.0: No such file or directory
  • system is lnxubuntu20
  • frosty.arm5.elf (PID: 6253, Parent: 6175, MD5: 5ebfcae4fe2471fcc5695c2394773ff1) Arguments: /tmp/frosty.arm5.elf
  • dash New Fork (PID: 6310, Parent: 4341)
  • rm (PID: 6310, Parent: 4341, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.Ok8lMVU7ld /tmp/tmp.LJefuUWawn /tmp/tmp.L2eCN24RDj
  • dash New Fork (PID: 6311, Parent: 4341)
  • rm (PID: 6311, Parent: 4341, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.Ok8lMVU7ld /tmp/tmp.LJefuUWawn /tmp/tmp.L2eCN24RDj
  • cleanup
No yara matches
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: frosty.arm5.elfVirustotal: Detection: 31%Perma Link
Source: frosty.arm5.elfReversingLabs: Detection: 38%
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 34.249.145.219
Source: unknownTCP traffic detected without corresponding DNS query: 34.249.145.219
Source: unknownTCP traffic detected without corresponding DNS query: 34.249.145.219
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 34.249.145.219
Source: frosty.arm5.elfString found in binary or memory: http://154.213.189.145/icy.sh
Source: frosty.arm5.elfString found in binary or memory: http://schemas.xmlsoap.org/soap/encoding/
Source: frosty.arm5.elfString found in binary or memory: http://schemas.xmlsoap.org/soap/envelope/
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39254
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 39254 -> 443
Source: ELF static info symbol of initial sample.symtab present: no
Source: classification engineClassification label: mal48.linELF@0/0@0/0
Source: /usr/bin/dash (PID: 6310)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.Ok8lMVU7ld /tmp/tmp.LJefuUWawn /tmp/tmp.L2eCN24RDjJump to behavior
Source: /usr/bin/dash (PID: 6311)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.Ok8lMVU7ld /tmp/tmp.LJefuUWawn /tmp/tmp.L2eCN24RDjJump to behavior
Source: /tmp/frosty.arm5.elf (PID: 6253)Queries kernel information via 'uname': Jump to behavior
Source: frosty.arm5.elf, 6253.1.00007ffde0535000.00007ffde0556000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-arm/tmp/frosty.arm5.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/frosty.arm5.elf
Source: frosty.arm5.elf, 6253.1.000055dd78f42000.000055dd79070000.rw-.sdmpBinary or memory string: U!/etc/qemu-binfmt/arm
Source: frosty.arm5.elf, 6253.1.00007ffde0535000.00007ffde0556000.rw-.sdmpBinary or memory string: qemu: %s: %s
Source: frosty.arm5.elf, 6253.1.00007ffde0535000.00007ffde0556000.rw-.sdmpBinary or memory string: leqemu: %s: %s
Source: frosty.arm5.elf, 6253.1.000055dd78f42000.000055dd79070000.rw-.sdmpBinary or memory string: Urg.qemu.gdb.arm.sys.regs">
Source: frosty.arm5.elf, 6253.1.000055dd78f42000.000055dd79070000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/arm
Source: frosty.arm5.elf, 6253.1.00007ffde0535000.00007ffde0556000.rw-.sdmpBinary or memory string: /usr/bin/qemu-arm
Source: frosty.arm5.elf, 6253.1.000055dd78f42000.000055dd79070000.rw-.sdmpBinary or memory string: rg.qemu.gdb.arm.sys.regs">
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
File Deletion
OS Credential Dumping11
Security Software Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1648910 Sample: frosty.arm5.elf Startdate: 26/03/2025 Architecture: LINUX Score: 48 12 109.202.202.202, 80 INIT7CH Switzerland 2->12 14 91.189.91.42, 443 CANONICAL-ASGB United Kingdom 2->14 16 2 other IPs or domains 2->16 18 Multi AV Scanner detection for submitted file 2->18 6 dash rm 2->6         started        8 dash rm 2->8         started        10 frosty.arm5.elf 2->10         started        signatures3 process4

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
frosty.arm5.elf31%VirustotalBrowse
frosty.arm5.elf39%ReversingLabsLinux.Trojan.Mirai
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

No contacted domains info
NameSourceMaliciousAntivirus DetectionReputation
http://154.213.189.145/icy.shfrosty.arm5.elffalse
    high
    http://schemas.xmlsoap.org/soap/encoding/frosty.arm5.elffalse
      high
      http://schemas.xmlsoap.org/soap/envelope/frosty.arm5.elffalse
        high
        • No. of IPs < 25%
        • 25% < No. of IPs < 50%
        • 50% < No. of IPs < 75%
        • 75% < No. of IPs
        IPDomainCountryFlagASNASN NameMalicious
        34.249.145.219
        unknownUnited States
        16509AMAZON-02USfalse
        109.202.202.202
        unknownSwitzerland
        13030INIT7CHfalse
        91.189.91.43
        unknownUnited Kingdom
        41231CANONICAL-ASGBfalse
        91.189.91.42
        unknownUnited Kingdom
        41231CANONICAL-ASGBfalse
        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
        34.249.145.219frosty.mpsl.elfGet hashmaliciousUnknownBrowse
          frosty.mips.elfGet hashmaliciousUnknownBrowse
            GoldAge3ATOmips.elfGet hashmaliciousUnknownBrowse
              GoldAge3ATOsh4.elfGet hashmaliciousUnknownBrowse
                sshd.elfGet hashmaliciousUnknownBrowse
                  na.elfGet hashmaliciousPrometeiBrowse
                    na.elfGet hashmaliciousPrometeiBrowse
                      arm.elfGet hashmaliciousUnknownBrowse
                        na.elfGet hashmaliciousPrometeiBrowse
                          morte.arm7.elfGet hashmaliciousUnknownBrowse
                            109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
                            • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
                            91.189.91.43frosty.mpsl.elfGet hashmaliciousUnknownBrowse
                              frosty.mips.elfGet hashmaliciousUnknownBrowse
                                GoldAge3ATOmips.elfGet hashmaliciousUnknownBrowse
                                  GoldAge3ATOsh4.elfGet hashmaliciousUnknownBrowse
                                    m68k.elfGet hashmaliciousUnknownBrowse
                                      spc.elfGet hashmaliciousUnknownBrowse
                                        na.elfGet hashmaliciousPrometeiBrowse
                                          sshd.elfGet hashmaliciousUnknownBrowse
                                            arm6.elfGet hashmaliciousUnknownBrowse
                                              na.elfGet hashmaliciousPrometeiBrowse
                                                91.189.91.42frosty.mpsl.elfGet hashmaliciousUnknownBrowse
                                                  frosty.mips.elfGet hashmaliciousUnknownBrowse
                                                    GoldAge3ATOmips.elfGet hashmaliciousUnknownBrowse
                                                      GoldAge3ATOsh4.elfGet hashmaliciousUnknownBrowse
                                                        m68k.elfGet hashmaliciousUnknownBrowse
                                                          spc.elfGet hashmaliciousUnknownBrowse
                                                            na.elfGet hashmaliciousPrometeiBrowse
                                                              sshd.elfGet hashmaliciousUnknownBrowse
                                                                arm6.elfGet hashmaliciousUnknownBrowse
                                                                  na.elfGet hashmaliciousPrometeiBrowse
                                                                    No context
                                                                    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                    CANONICAL-ASGBfrosty.mpsl.elfGet hashmaliciousUnknownBrowse
                                                                    • 91.189.91.42
                                                                    frosty.mips.elfGet hashmaliciousUnknownBrowse
                                                                    • 91.189.91.42
                                                                    na.elfGet hashmaliciousPrometeiBrowse
                                                                    • 185.125.190.26
                                                                    GoldAge3ATOmips.elfGet hashmaliciousUnknownBrowse
                                                                    • 91.189.91.42
                                                                    GoldAge3ATOsh4.elfGet hashmaliciousUnknownBrowse
                                                                    • 91.189.91.42
                                                                    m68k.elfGet hashmaliciousUnknownBrowse
                                                                    • 91.189.91.42
                                                                    spc.elfGet hashmaliciousUnknownBrowse
                                                                    • 91.189.91.42
                                                                    na.elfGet hashmaliciousPrometeiBrowse
                                                                    • 91.189.91.42
                                                                    sshd.elfGet hashmaliciousUnknownBrowse
                                                                    • 91.189.91.42
                                                                    na.elfGet hashmaliciousPrometeiBrowse
                                                                    • 185.125.190.26
                                                                    CANONICAL-ASGBfrosty.mpsl.elfGet hashmaliciousUnknownBrowse
                                                                    • 91.189.91.42
                                                                    frosty.mips.elfGet hashmaliciousUnknownBrowse
                                                                    • 91.189.91.42
                                                                    na.elfGet hashmaliciousPrometeiBrowse
                                                                    • 185.125.190.26
                                                                    GoldAge3ATOmips.elfGet hashmaliciousUnknownBrowse
                                                                    • 91.189.91.42
                                                                    GoldAge3ATOsh4.elfGet hashmaliciousUnknownBrowse
                                                                    • 91.189.91.42
                                                                    m68k.elfGet hashmaliciousUnknownBrowse
                                                                    • 91.189.91.42
                                                                    spc.elfGet hashmaliciousUnknownBrowse
                                                                    • 91.189.91.42
                                                                    na.elfGet hashmaliciousPrometeiBrowse
                                                                    • 91.189.91.42
                                                                    sshd.elfGet hashmaliciousUnknownBrowse
                                                                    • 91.189.91.42
                                                                    na.elfGet hashmaliciousPrometeiBrowse
                                                                    • 185.125.190.26
                                                                    INIT7CHfrosty.mpsl.elfGet hashmaliciousUnknownBrowse
                                                                    • 109.202.202.202
                                                                    frosty.mips.elfGet hashmaliciousUnknownBrowse
                                                                    • 109.202.202.202
                                                                    GoldAge3ATOmips.elfGet hashmaliciousUnknownBrowse
                                                                    • 109.202.202.202
                                                                    GoldAge3ATOsh4.elfGet hashmaliciousUnknownBrowse
                                                                    • 109.202.202.202
                                                                    m68k.elfGet hashmaliciousUnknownBrowse
                                                                    • 109.202.202.202
                                                                    spc.elfGet hashmaliciousUnknownBrowse
                                                                    • 109.202.202.202
                                                                    na.elfGet hashmaliciousPrometeiBrowse
                                                                    • 109.202.202.202
                                                                    sshd.elfGet hashmaliciousUnknownBrowse
                                                                    • 109.202.202.202
                                                                    arm6.elfGet hashmaliciousUnknownBrowse
                                                                    • 109.202.202.202
                                                                    na.elfGet hashmaliciousPrometeiBrowse
                                                                    • 109.202.202.202
                                                                    AMAZON-02UShttp://support.delfi.comGet hashmaliciousUnknownBrowse
                                                                    • 52.217.163.192
                                                                    frosty.x86.elfGet hashmaliciousUnknownBrowse
                                                                    • 52.35.74.183
                                                                    frosty.mpsl.elfGet hashmaliciousUnknownBrowse
                                                                    • 34.249.145.219
                                                                    frosty.mips.elfGet hashmaliciousUnknownBrowse
                                                                    • 34.249.145.219
                                                                    frosty.spc.elfGet hashmaliciousUnknownBrowse
                                                                    • 63.32.132.7
                                                                    na.elfGet hashmaliciousPrometeiBrowse
                                                                    • 54.247.62.1
                                                                    GoldAge3ATOmips.elfGet hashmaliciousUnknownBrowse
                                                                    • 34.249.145.219
                                                                    GoldAge3ATOsh4.elfGet hashmaliciousUnknownBrowse
                                                                    • 34.249.145.219
                                                                    https://document-baol.b12sites.com/Get hashmaliciousUnknownBrowse
                                                                    • 13.249.91.90
                                                                    https://go.skimresources.com/?id=129857X1600501&url=https://gamma.app/docs/Ukibc-egg8llx0v1a6920?mode=present#card-n3aknjh8lm0v6m5Get hashmaliciousHTMLPhisher, Invisible JS, Tycoon2FABrowse
                                                                    • 108.139.47.21
                                                                    No context
                                                                    No context
                                                                    No created / dropped files found
                                                                    File type:ELF 32-bit LSB executable, ARM, version 1 (ARM), dynamically linked, interpreter /lib/ld-uClibc.so.0, stripped
                                                                    Entropy (8bit):6.222355780898086
                                                                    TrID:
                                                                    • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                                                    File name:frosty.arm5.elf
                                                                    File size:36'140 bytes
                                                                    MD5:95e11ececeea025ca342cc5c414380f9
                                                                    SHA1:ede9947bd603742ea467e6fb47db023e13868074
                                                                    SHA256:429a86088027bf5058d53ba501211336924d2b291c40e71cd6856da74cbe9afe
                                                                    SHA512:10cb61cdb819b59527710c27db12880f5ec83c9bc87918f79c84a2c5ed0451a1ec2d5127d4242a8407496ef353c201bed6398c2896c3be2b97aab75b6498a0a9
                                                                    SSDEEP:768:hcffYtfAz/xwqJKfPmmnbenTgGnZ7bX3PGlczUoBxDiLmcCyoSwABo:hNtUeqJwmmnNGZvX/Oc+mcISwAO
                                                                    TLSH:06F20956BCE2CE1AC6D421B6BF1E507D3320A3DCD2CA37039E145B643ACB55E5EA7A04
                                                                    File Content Preview:.ELF...a..........(.....8...4...\.......4. ...(.........4...4...4...................................................................P...P...............T...T...T.......................h...h...h...................Q.td............................/lib/ld-uCl

                                                                    ELF header

                                                                    Class:ELF32
                                                                    Data:2's complement, little endian
                                                                    Version:1 (current)
                                                                    Machine:ARM
                                                                    Version Number:0x1
                                                                    Type:EXEC (Executable file)
                                                                    OS/ABI:ARM - ABI
                                                                    ABI Version:0
                                                                    Entry Point Address:0x8e38
                                                                    Flags:0x2
                                                                    ELF Header Size:52
                                                                    Program Header Offset:52
                                                                    Program Header Size:32
                                                                    Number of Program Headers:6
                                                                    Section Header Offset:35420
                                                                    Section Header Size:40
                                                                    Number of Section Headers:18
                                                                    Header String Table Index:17
                                                                    NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                                    NULL0x00x00x00x00x0000
                                                                    .interpPROGBITS0x80f40xf40x140x00x2A001
                                                                    .hashHASH0x81080x1080x2200x40x2A304
                                                                    .dynsymDYNSYM0x83280x3280x4300x100x2A414
                                                                    .dynstrSTRTAB0x87580x7580x2250x00x2A001
                                                                    .rel.pltREL0x89800x9800x1780x80x2A374
                                                                    .initPROGBITS0x8af80xaf80x180x00x6AX004
                                                                    .pltPROGBITS0x8b100xb100x2480x40x6AX004
                                                                    .textPROGBITS0x8d580xd580x6d000x00x6AX004
                                                                    .finiPROGBITS0xfa580x7a580x140x00x6AX004
                                                                    .rodataPROGBITS0xfa6c0x7a6c0xde40x00x2A004
                                                                    .ctorsPROGBITS0x188540x88540x80x00x3WA004
                                                                    .dtorsPROGBITS0x1885c0x885c0x80x00x3WA004
                                                                    .dynamicDYNAMIC0x188680x88680x980x80x3WA404
                                                                    .gotPROGBITS0x189000x89000xc80x40x3WA004
                                                                    .dataPROGBITS0x189c80x89c80x200x00x3WA004
                                                                    .bssNOBITS0x189e80x89e80x3400x00x3WA004
                                                                    .shstrtabSTRTAB0x00x89e80x730x00x0001
                                                                    TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                                    PHDR0x340x80340x80340xc00xc02.26290x5R E0x4
                                                                    INTERP0xf40x80f40x80f40x140x143.68420x4R 0x1/lib/ld-uClibc.so.0.interp
                                                                    LOAD0x00x80000x80000x88500x88506.28830x5R E0x8000.interp .hash .dynsym .dynstr .rel.plt .init .plt .text .fini .rodata
                                                                    LOAD0x88540x188540x188540x1940x4d42.24410x6RW 0x8000.ctors .dtors .dynamic .got .data .bss
                                                                    DYNAMIC0x88680x188680x188680x980x981.81270x6RW 0x4.dynamic
                                                                    GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
                                                                    TypeMetaValueTag
                                                                    DT_NEEDEDsharedliblibc.so.00x1
                                                                    DT_INITvalue0x8af80xc
                                                                    DT_FINIvalue0xfa580xd
                                                                    DT_HASHvalue0x81080x4
                                                                    DT_STRTABvalue0x87580x5
                                                                    DT_SYMTABvalue0x83280x6
                                                                    DT_STRSZbytes5490xa
                                                                    DT_SYMENTbytes160xb
                                                                    DT_DEBUGvalue0x00x15
                                                                    DT_PLTGOTvalue0x189000x3
                                                                    DT_PLTRELSZbytes3760x2
                                                                    DT_PLTRELpltrelDT_REL0x14
                                                                    DT_JMPRELvalue0x89800x17
                                                                    DT_NULLvalue0x00x0
                                                                    NameVersion Info NameVersion Info File NameSection NameValueSizeSymbol TypeSymbol BindSymbol VisibilityNdx
                                                                    .dynsym0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                                                    __aeabi_idiv0.dynsym0xfa184FUNC<unknown>DEFAULT8
                                                                    __aeabi_ldiv0.dynsym0xfa184FUNC<unknown>DEFAULT8
                                                                    __aeabi_uidiv.dynsym0xf7580FUNC<unknown>DEFAULT8
                                                                    __aeabi_uidivmod.dynsym0xf85024FUNC<unknown>DEFAULT8
                                                                    __bss_end__.dynsym0x18d280NOTYPE<unknown>DEFAULTSHN_ABS
                                                                    __bss_start.dynsym0x189e80NOTYPE<unknown>DEFAULTSHN_ABS
                                                                    __bss_start__.dynsym0x189e80NOTYPE<unknown>DEFAULTSHN_ABS
                                                                    __data_start.dynsym0x189c80NOTYPE<unknown>DEFAULT17
                                                                    __div0.dynsym0xfa184FUNC<unknown>DEFAULT8
                                                                    __end__.dynsym0x18d280NOTYPE<unknown>DEFAULTSHN_ABS
                                                                    __errno_location.dynsym0x8cd432FUNC<unknown>DEFAULTSHN_UNDEF
                                                                    __modsi3.dynsym0xf934228FUNC<unknown>DEFAULT8
                                                                    __uClibc_main.dynsym0x8c8c488FUNC<unknown>DEFAULTSHN_UNDEF
                                                                    __udivsi3.dynsym0xf758248FUNC<unknown>DEFAULT8
                                                                    __umodsi3.dynsym0xf868204FUNC<unknown>DEFAULT8
                                                                    _bss_end__.dynsym0x18d280NOTYPE<unknown>DEFAULTSHN_ABS
                                                                    _edata.dynsym0x189e80NOTYPE<unknown>DEFAULTSHN_ABS
                                                                    _end.dynsym0x18d280NOTYPE<unknown>DEFAULTSHN_ABS
                                                                    _start.dynsym0x8e3880FUNC<unknown>DEFAULT8
                                                                    abort.dynsym0x8bf0352FUNC<unknown>DEFAULTSHN_UNDEF
                                                                    accept.dynsym0x8bfc44FUNC<unknown>DEFAULTSHN_UNDEF
                                                                    bind.dynsym0x8c2c44FUNC<unknown>DEFAULTSHN_UNDEF
                                                                    calloc.dynsym0x8c0888FUNC<unknown>DEFAULTSHN_UNDEF
                                                                    clock.dynsym0x8cf852FUNC<unknown>DEFAULTSHN_UNDEF
                                                                    close.dynsym0x8d2844FUNC<unknown>DEFAULTSHN_UNDEF
                                                                    closedir.dynsym0x8d10196FUNC<unknown>DEFAULTSHN_UNDEF
                                                                    connect.dynsym0x8b4844FUNC<unknown>DEFAULTSHN_UNDEF
                                                                    exit.dynsym0x8ce0172FUNC<unknown>DEFAULTSHN_UNDEF
                                                                    fcntl.dynsym0x8d1c116FUNC<unknown>DEFAULTSHN_UNDEF
                                                                    fork.dynsym0x8c8044FUNC<unknown>DEFAULTSHN_UNDEF
                                                                    free.dynsym0x8d34288FUNC<unknown>DEFAULTSHN_UNDEF
                                                                    getpid.dynsym0x8b6c44FUNC<unknown>DEFAULTSHN_UNDEF
                                                                    getppid.dynsym0x8ca444FUNC<unknown>DEFAULTSHN_UNDEF
                                                                    getsockname.dynsym0x8d4c44FUNC<unknown>DEFAULTSHN_UNDEF
                                                                    getsockopt.dynsym0x8cc848FUNC<unknown>DEFAULTSHN_UNDEF
                                                                    inet_addr.dynsym0x8c3836FUNC<unknown>DEFAULTSHN_UNDEF
                                                                    ioctl.dynsym0x8b3080FUNC<unknown>DEFAULTSHN_UNDEF
                                                                    kill.dynsym0x8c2044FUNC<unknown>DEFAULTSHN_UNDEF
                                                                    malloc.dynsym0x8b90400FUNC<unknown>DEFAULTSHN_UNDEF
                                                                    memcpy.dynsym0x8b844FUNC<unknown>DEFAULTSHN_UNDEF
                                                                    memmove.dynsym0x8b604FUNC<unknown>DEFAULTSHN_UNDEF
                                                                    memset.dynsym0x0156FUNC<unknown>DEFAULTSHN_UNDEF
                                                                    open.dynsym0x8cec92FUNC<unknown>DEFAULTSHN_UNDEF
                                                                    opendir.dynsym0x8cbc264FUNC<unknown>DEFAULTSHN_UNDEF
                                                                    prctl.dynsym0x8b7848FUNC<unknown>DEFAULTSHN_UNDEF
                                                                    read.dynsym0x8c5c44FUNC<unknown>DEFAULTSHN_UNDEF
                                                                    readdir.dynsym0x8bcc224FUNC<unknown>DEFAULTSHN_UNDEF
                                                                    readlink.dynsym0x044FUNC<unknown>DEFAULTSHN_UNDEF
                                                                    realloc.dynsym0x8c74312FUNC<unknown>DEFAULTSHN_UNDEF
                                                                    recv.dynsym0x8b3c44FUNC<unknown>DEFAULTSHN_UNDEF
                                                                    recvfrom.dynsym0x8ba852FUNC<unknown>DEFAULTSHN_UNDEF
                                                                    select.dynsym0x8bc048FUNC<unknown>DEFAULTSHN_UNDEF
                                                                    send.dynsym0x8be444FUNC<unknown>DEFAULTSHN_UNDEF
                                                                    sendto.dynsym0x8c6852FUNC<unknown>DEFAULTSHN_UNDEF
                                                                    setsid.dynsym0x8d0444FUNC<unknown>DEFAULTSHN_UNDEF
                                                                    setsockopt.dynsym0x8c4448FUNC<unknown>DEFAULTSHN_UNDEF
                                                                    sigaddset.dynsym0x8bd848FUNC<unknown>DEFAULTSHN_UNDEF
                                                                    sigemptyset.dynsym0x8b5424FUNC<unknown>DEFAULTSHN_UNDEF
                                                                    signal.dynsym0x8c50200FUNC<unknown>DEFAULTSHN_UNDEF
                                                                    sigprocmask.dynsym0x8d4084FUNC<unknown>DEFAULTSHN_UNDEF
                                                                    sleep.dynsym0x8b9c420FUNC<unknown>DEFAULTSHN_UNDEF
                                                                    socket.dynsym0x8bb444FUNC<unknown>DEFAULTSHN_UNDEF
                                                                    srand.dynsym0x8c98148FUNC<unknown>DEFAULTSHN_UNDEF
                                                                    strcpy.dynsym0x8b2428FUNC<unknown>DEFAULTSHN_UNDEF
                                                                    time.dynsym0x8cb044FUNC<unknown>DEFAULTSHN_UNDEF
                                                                    write.dynsym0x8c1444FUNC<unknown>DEFAULTSHN_UNDEF

                                                                    Download Network PCAP: filteredfull

                                                                    • Total Packets: 11
                                                                    • 443 (HTTPS)
                                                                    • 80 (HTTP)
                                                                    TimestampSource PortDest PortSource IPDest IP
                                                                    Mar 26, 2025 10:24:52.177160025 CET43928443192.168.2.2391.189.91.42
                                                                    Mar 26, 2025 10:24:56.784594059 CET4251680192.168.2.23109.202.202.202
                                                                    Mar 26, 2025 10:24:57.552486897 CET42836443192.168.2.2391.189.91.43
                                                                    Mar 26, 2025 10:25:01.181366920 CET39254443192.168.2.2334.249.145.219
                                                                    Mar 26, 2025 10:25:01.181406975 CET4433925434.249.145.219192.168.2.23
                                                                    Mar 26, 2025 10:25:01.181642056 CET39254443192.168.2.2334.249.145.219
                                                                    Mar 26, 2025 10:25:01.182094097 CET39254443192.168.2.2334.249.145.219
                                                                    Mar 26, 2025 10:25:01.182117939 CET4433925434.249.145.219192.168.2.23
                                                                    Mar 26, 2025 10:25:12.398469925 CET43928443192.168.2.2391.189.91.42
                                                                    Mar 26, 2025 10:25:24.684776068 CET42836443192.168.2.2391.189.91.43
                                                                    Mar 26, 2025 10:25:26.732578993 CET4251680192.168.2.23109.202.202.202
                                                                    Mar 26, 2025 10:25:53.352925062 CET43928443192.168.2.2391.189.91.42
                                                                    Mar 26, 2025 10:26:01.173718929 CET39254443192.168.2.2334.249.145.219
                                                                    Mar 26, 2025 10:26:01.216276884 CET4433925434.249.145.219192.168.2.23

                                                                    System Behavior

                                                                    Start time (UTC):09:24:51
                                                                    Start date (UTC):26/03/2025
                                                                    Path:/tmp/frosty.arm5.elf
                                                                    Arguments:/tmp/frosty.arm5.elf
                                                                    File size:4956856 bytes
                                                                    MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                                    Start time (UTC):09:26:00
                                                                    Start date (UTC):26/03/2025
                                                                    Path:/usr/bin/dash
                                                                    Arguments:-
                                                                    File size:129816 bytes
                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                    Start time (UTC):09:26:00
                                                                    Start date (UTC):26/03/2025
                                                                    Path:/usr/bin/rm
                                                                    Arguments:rm -f /tmp/tmp.Ok8lMVU7ld /tmp/tmp.LJefuUWawn /tmp/tmp.L2eCN24RDj
                                                                    File size:72056 bytes
                                                                    MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                                                    Start time (UTC):09:26:00
                                                                    Start date (UTC):26/03/2025
                                                                    Path:/usr/bin/dash
                                                                    Arguments:-
                                                                    File size:129816 bytes
                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                    Start time (UTC):09:26:00
                                                                    Start date (UTC):26/03/2025
                                                                    Path:/usr/bin/rm
                                                                    Arguments:rm -f /tmp/tmp.Ok8lMVU7ld /tmp/tmp.LJefuUWawn /tmp/tmp.L2eCN24RDj
                                                                    File size:72056 bytes
                                                                    MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b