Edit tour

Linux Analysis Report
x86.elf

Overview

General Information

Sample name:x86.elf
Analysis ID:1650530
MD5:c28a6183b0872843f4fcd53473d9f207
SHA1:6e21bd29712dcac4caf0aea03c7b2596f23010aa
SHA256:410d6dcd7357dd10b78d2a969262a9c43a0608442edaef8af483e9802968d3dd
Tags:elfuser-abuse_ch
Infos:

Detection

Mirai
Score:76
Range:0 - 100

Signatures

Antivirus / Scanner detection for submitted sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Yara detected Mirai
Contains symbols with names commonly found in malware
Detected TCP or UDP traffic on non-standard ports
Enumerates processes within the "proc" file system
Sample and/or dropped files contains symbols with suspicious names
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Yara signature match

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
Joe Sandbox version:42.0.0 Malachite
Analysis ID:1650530
Start date and time:2025-03-27 19:52:32 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 33s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:x86.elf
Detection:MAL
Classification:mal76.troj.linELF@0/0@1/0
  • VT rate limit hit for: longvusro.com
Command:/tmp/x86.elf
PID:5504
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
longvusro.com
Standard Error:
  • system is lnxubuntu20
  • x86.elf (PID: 5504, Parent: 5423, MD5: c28a6183b0872843f4fcd53473d9f207) Arguments: /tmp/x86.elf
    • x86.elf New Fork (PID: 5505, Parent: 5504)
      • x86.elf New Fork (PID: 5506, Parent: 5505)
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
MiraiMirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.mirai
SourceRuleDescriptionAuthorStrings
x86.elfJoeSecurity_Mirai_8Yara detected MiraiJoe Security
    x86.elfLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
    • 0xaf78:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xaf8c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xafa0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xafb4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xafc8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xafdc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xaff0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xb004:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xb018:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xb02c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xb040:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xb054:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xb068:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xb07c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xb090:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xb0a4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xb0b8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xb0cc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xb0e0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xb0f4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xb108:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    x86.elfLinux_Trojan_Mirai_122ff2e6unknownunknown
    • 0x7063:$a: 24 EB 15 89 F0 83 C8 01 EB 03 8B 5B 08 3B 43 04 72 F8 8B 4B 0C 89
    x86.elfLinux_Trojan_Mirai_fa48b592unknownunknown
    • 0xa535:$a: 31 C0 BA 01 00 00 00 B9 01 00 00 00 03 04 24 89 D7 31 D2 F7 F7 0F
    x86.elfLinux_Trojan_Mirai_8aa7b5d3unknownunknown
    • 0x6042:$a: 8B 4C 24 14 8B 74 24 0C 8B 5C 24 10 85 C9 74 0D 31 D2 8A 04 1A 88
    SourceRuleDescriptionAuthorStrings
    5504.1.0000000008048000.0000000008054000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
    • 0xaf78:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xaf8c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xafa0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xafb4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xafc8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xafdc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xaff0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xb004:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xb018:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xb02c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xb040:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xb054:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xb068:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xb07c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xb090:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xb0a4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xb0b8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xb0cc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xb0e0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xb0f4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xb108:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    5504.1.0000000008048000.0000000008054000.r-x.sdmpLinux_Trojan_Mirai_122ff2e6unknownunknown
    • 0x7063:$a: 24 EB 15 89 F0 83 C8 01 EB 03 8B 5B 08 3B 43 04 72 F8 8B 4B 0C 89
    5504.1.0000000008048000.0000000008054000.r-x.sdmpLinux_Trojan_Mirai_fa48b592unknownunknown
    • 0xa535:$a: 31 C0 BA 01 00 00 00 B9 01 00 00 00 03 04 24 89 D7 31 D2 F7 F7 0F
    5504.1.0000000008048000.0000000008054000.r-x.sdmpLinux_Trojan_Mirai_8aa7b5d3unknownunknown
    • 0x6042:$a: 8B 4C 24 14 8B 74 24 0C 8B 5C 24 10 85 C9 74 0D 31 D2 8A 04 1A 88
    No Suricata rule has matched

    Click to jump to signature section

    Show All Signature Results

    AV Detection

    barindex
    Source: x86.elfAvira: detected
    Source: x86.elfVirustotal: Detection: 45%Perma Link
    Source: x86.elfReversingLabs: Detection: 52%
    Source: global trafficTCP traffic: 192.168.2.14:39270 -> 103.142.27.125:56999
    Source: global trafficTCP traffic: 192.168.2.14:46540 -> 185.125.190.26:443
    Source: unknownTCP traffic detected without corresponding DNS query: 185.125.190.26
    Source: unknownTCP traffic detected without corresponding DNS query: 185.125.190.26
    Source: global trafficDNS traffic detected: DNS query: longvusro.com
    Source: unknownNetwork traffic detected: HTTP traffic on port 46540 -> 443

    System Summary

    barindex
    Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
    Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_122ff2e6 Author: unknown
    Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_fa48b592 Author: unknown
    Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_8aa7b5d3 Author: unknown
    Source: 5504.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
    Source: 5504.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_122ff2e6 Author: unknown
    Source: 5504.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_fa48b592 Author: unknown
    Source: 5504.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 Author: unknown
    Source: ELF static info symbol of initial sampleName: attack.c
    Source: ELF static info symbol of initial sampleName: attack_get_opt_int
    Source: ELF static info symbol of initial sampleName: attack_get_opt_ip
    Source: ELF static info symbol of initial sampleName: attack_init
    Source: ELF static info symbol of initial sampleName: attack_kill_all
    Source: ELF static info symbol of initial sampleName: attack_method_nudp
    Source: ELF static info symbol of initial sampleName: attack_method_stdhex
    Source: ELF static info symbol of initial sampleName: attack_method_tcp
    Source: ELF static info symbol of initial sampleName: attack_ongoing
    Source: ELF static info symbol of initial sampleName: attack_parse
    Source: x86.elfELF static info symbol of initial sample: hexPayload
    Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
    Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_122ff2e6 reference_sample = c7dd999a033fa3edc1936785b87cd69ce2f5cac5a084ddfaf527a1094e718bc4, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 3c9ffd7537e30a21eefa6c174f801264b92a85a1bc73e34e6dc9e29f84658348, id = 122ff2e6-56e6-4aa8-a3ec-c19d31eb1f80, last_modified = 2021-09-16
    Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_fa48b592 reference_sample = c9e33befeec133720b3ba40bb3cd7f636aad80f72f324c5fe65ac7af271c49ee, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 8838d2752b310dbf7d12f6cf023244aaff4fdf5b55cf1e3b71843210df0fcf88, id = fa48b592-8d80-45af-a3e4-232695b8f5dd, last_modified = 2021-09-16
    Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_8aa7b5d3 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444, id = 8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9, last_modified = 2022-01-26
    Source: 5504.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
    Source: 5504.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_122ff2e6 reference_sample = c7dd999a033fa3edc1936785b87cd69ce2f5cac5a084ddfaf527a1094e718bc4, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 3c9ffd7537e30a21eefa6c174f801264b92a85a1bc73e34e6dc9e29f84658348, id = 122ff2e6-56e6-4aa8-a3ec-c19d31eb1f80, last_modified = 2021-09-16
    Source: 5504.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_fa48b592 reference_sample = c9e33befeec133720b3ba40bb3cd7f636aad80f72f324c5fe65ac7af271c49ee, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 8838d2752b310dbf7d12f6cf023244aaff4fdf5b55cf1e3b71843210df0fcf88, id = fa48b592-8d80-45af-a3e4-232695b8f5dd, last_modified = 2021-09-16
    Source: 5504.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444, id = 8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9, last_modified = 2022-01-26
    Source: classification engineClassification label: mal76.troj.linELF@0/0@1/0
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/3760/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/3761/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/1583/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/2672/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/110/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/3759/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/111/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/112/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/113/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/234/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/1577/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/114/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/235/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/115/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/116/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/117/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/118/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/3630/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/119/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/10/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/917/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/3758/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/11/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/12/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/13/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/14/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/15/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/16/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/17/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/18/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/19/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/1593/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/240/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/120/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/3094/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/121/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/242/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/3406/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/1/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/122/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/243/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/2/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/123/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/244/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/1589/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/3/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/124/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/245/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/1588/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/125/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/4/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/246/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/3402/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/126/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/5/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/247/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/127/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/6/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/248/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/128/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/7/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/249/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/8/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/129/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/800/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/9/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/801/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/803/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/20/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/806/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/21/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/807/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/928/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/22/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/23/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/24/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/25/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/26/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/27/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/28/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/29/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/3420/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/490/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/250/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/130/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/251/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/131/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/252/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/132/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/253/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/254/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/255/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/135/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/256/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/1599/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/257/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/378/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/258/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/3412/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/259/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/30/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/35/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/1371/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/260/cmdlineJump to behavior
    Source: /tmp/x86.elf (PID: 5506)File opened: /proc/261/cmdlineJump to behavior

    Stealing of Sensitive Information

    barindex
    Source: Yara matchFile source: x86.elf, type: SAMPLE

    Remote Access Functionality

    barindex
    Source: Yara matchFile source: x86.elf, type: SAMPLE
    ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
    Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
    Masquerading
    1
    OS Credential Dumping
    System Service DiscoveryRemote ServicesData from Local System1
    Encrypted Channel
    Exfiltration Over Other Network MediumAbuse Accessibility Features
    CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
    Non-Standard Port
    Exfiltration Over BluetoothNetwork Denial of Service
    Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
    Non-Application Layer Protocol
    Automated ExfiltrationData Encrypted for Impact
    Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture2
    Application Layer Protocol
    Traffic DuplicationData Destruction
    No configs have been found
    Hide Legend

    Legend:

    • Process
    • Signature
    • Created File
    • DNS/IP Info
    • Is Dropped
    • Number of created Files
    • Is malicious
    • Internet
    behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1650530 Sample: x86.elf Startdate: 27/03/2025 Architecture: LINUX Score: 76 14 longvusro.com 103.142.27.125, 39270, 56999 WEBICO-AS-VNWebicoCompanyLimitedVN Viet Nam 2->14 16 185.125.190.26, 443 CANONICAL-ASGB United Kingdom 2->16 18 Malicious sample detected (through community Yara rule) 2->18 20 Antivirus / Scanner detection for submitted sample 2->20 22 Multi AV Scanner detection for submitted file 2->22 24 2 other signatures 2->24 8 x86.elf 2->8         started        signatures3 process4 process5 10 x86.elf 8->10         started        process6 12 x86.elf 10->12         started       

    This section contains all screenshots as thumbnails, including those not shown in the slideshow.


    windows-stand
    SourceDetectionScannerLabelLink
    x86.elf45%VirustotalBrowse
    x86.elf53%ReversingLabsLinux.Backdoor.Mirai
    x86.elf100%AviraEXP/ELF.Mirai.J
    No Antivirus matches
    No Antivirus matches
    No Antivirus matches

    Download Network PCAP: filteredfull

    NameIPActiveMaliciousAntivirus DetectionReputation
    longvusro.com
    103.142.27.125
    truefalse
      unknown
      • No. of IPs < 25%
      • 25% < No. of IPs < 50%
      • 50% < No. of IPs < 75%
      • 75% < No. of IPs
      IPDomainCountryFlagASNASN NameMalicious
      185.125.190.26
      unknownUnited Kingdom
      41231CANONICAL-ASGBfalse
      103.142.27.125
      longvusro.comViet Nam
      135951WEBICO-AS-VNWebicoCompanyLimitedVNfalse
      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
      185.125.190.26na.elfGet hashmaliciousPrometeiBrowse
        na.elfGet hashmaliciousPrometeiBrowse
          SecuriteInfo.com.ELF.Mirai-AXV.27459.929.elfGet hashmaliciousUnknownBrowse
            arm7.elfGet hashmaliciousUnknownBrowse
              arm5.elfGet hashmaliciousUnknownBrowse
                mips.elfGet hashmaliciousUnknownBrowse
                  arm.elfGet hashmaliciousUnknownBrowse
                    na.elfGet hashmaliciousPrometeiBrowse
                      SecuriteInfo.com.Linux.Mirai.4306.30063.19032.elfGet hashmaliciousUnknownBrowse
                        na.elfGet hashmaliciousPrometeiBrowse
                          103.142.27.125debug.dbg.elfGet hashmaliciousMiraiBrowse
                            sh4.elfGet hashmaliciousMiraiBrowse
                              m68k.elfGet hashmaliciousUnknownBrowse
                                debug.dbg.elfGet hashmaliciousMiraiBrowse
                                  ppc.elfGet hashmaliciousMiraiBrowse
                                    spc.elfGet hashmaliciousMiraiBrowse
                                      x86.elfGet hashmaliciousMiraiBrowse
                                        mpsl.elfGet hashmaliciousMiraiBrowse
                                          mips.elfGet hashmaliciousMiraiBrowse
                                            arm.elfGet hashmaliciousUnknownBrowse
                                              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                              longvusro.comdebug.dbg.elfGet hashmaliciousMiraiBrowse
                                              • 103.142.27.125
                                              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                              WEBICO-AS-VNWebicoCompanyLimitedVNdebug.dbg.elfGet hashmaliciousMiraiBrowse
                                              • 103.142.27.125
                                              sh4.elfGet hashmaliciousMiraiBrowse
                                              • 103.142.27.125
                                              m68k.elfGet hashmaliciousUnknownBrowse
                                              • 103.142.27.125
                                              debug.dbg.elfGet hashmaliciousMiraiBrowse
                                              • 103.142.27.125
                                              ppc.elfGet hashmaliciousMiraiBrowse
                                              • 103.142.27.125
                                              spc.elfGet hashmaliciousMiraiBrowse
                                              • 103.142.27.125
                                              x86.elfGet hashmaliciousMiraiBrowse
                                              • 103.142.27.125
                                              mpsl.elfGet hashmaliciousMiraiBrowse
                                              • 103.142.27.125
                                              mips.elfGet hashmaliciousMiraiBrowse
                                              • 103.142.27.125
                                              arm.elfGet hashmaliciousUnknownBrowse
                                              • 103.142.27.125
                                              CANONICAL-ASGBdebug.dbg.elfGet hashmaliciousMiraiBrowse
                                              • 91.189.91.42
                                              na.elfGet hashmaliciousPrometeiBrowse
                                              • 185.125.190.26
                                              na.elfGet hashmaliciousPrometeiBrowse
                                              • 91.189.91.42
                                              na.elfGet hashmaliciousPrometeiBrowse
                                              • 185.125.190.26
                                              SecuriteInfo.com.ELF.Mirai-AXV.27459.929.elfGet hashmaliciousUnknownBrowse
                                              • 185.125.190.26
                                              SecuriteInfo.com.Linux.Mirai.4306.4180.25704.elfGet hashmaliciousUnknownBrowse
                                              • 91.189.91.42
                                              SecuriteInfo.com.Linux.Mirai.2522.31389.24681.elfGet hashmaliciousUnknownBrowse
                                              • 91.189.91.42
                                              na.elfGet hashmaliciousPrometeiBrowse
                                              • 91.189.91.42
                                              arm7.elfGet hashmaliciousUnknownBrowse
                                              • 185.125.190.26
                                              arm5.elfGet hashmaliciousUnknownBrowse
                                              • 185.125.190.26
                                              No context
                                              No context
                                              No created / dropped files found
                                              File type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, not stripped
                                              Entropy (8bit):6.258397154922453
                                              TrID:
                                              • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
                                              • ELF Executable and Linkable format (generic) (4004/1) 49.84%
                                              File name:x86.elf
                                              File size:72'392 bytes
                                              MD5:c28a6183b0872843f4fcd53473d9f207
                                              SHA1:6e21bd29712dcac4caf0aea03c7b2596f23010aa
                                              SHA256:410d6dcd7357dd10b78d2a969262a9c43a0608442edaef8af483e9802968d3dd
                                              SHA512:f00ee2c7eb4e6f9941dd2ed81669751edac8a072bb8ee479234ca1bee077d8231d6e18b2c3c49a08fb60713134edb8c28e0254d312a86b7fa03e1ea0e5025d3c
                                              SSDEEP:1536:KB320J7k6HoELpVQ0ZqcpTzLABgi6+ZrKMdP:o7J7k6I2Q05PcBgi6+Zrb
                                              TLSH:48633A85A363DBB3C8C70B7410E3E7364636F8D6275EDE03E7ADAEB56E421847046249
                                              File Content Preview:.ELF........................4...8.......4. ...(..............................................@...@..|....6..............L...LE..LE..................Q.td............................U..S............h........[]...$.............U......=.G...t..5....pE.....pE.

                                              ELF header

                                              Class:ELF32
                                              Data:2's complement, little endian
                                              Version:1 (current)
                                              Machine:Intel 80386
                                              Version Number:0x1
                                              Type:EXEC (Executable file)
                                              OS/ABI:UNIX - System V
                                              ABI Version:0
                                              Entry Point Address:0x8048184
                                              Flags:0x0
                                              ELF Header Size:52
                                              Program Header Offset:52
                                              Program Header Size:32
                                              Number of Program Headers:4
                                              Section Header Offset:53816
                                              Section Header Size:40
                                              Number of Section Headers:19
                                              Header String Table Index:16
                                              NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                              NULL0x00x00x00x00x0000
                                              .initPROGBITS0x80480b40xb40x1c0x00x6AX001
                                              .textPROGBITS0x80480d00xd00xa9d70x00x6AX0016
                                              .finiPROGBITS0x8052aa70xaaa70x170x00x6AX001
                                              .rodataPROGBITS0x8052ac00xaac00x10500x00x2A004
                                              .eh_framePROGBITS0x80540000xc0000x54c0x00x3WA004
                                              .tbssNOBITS0x805454c0xc54c0x80x00x403WAT004
                                              .ctorsPROGBITS0x805454c0xc54c0x80x00x3WA004
                                              .dtorsPROGBITS0x80545540xc5540x80x00x3WA004
                                              .jcrPROGBITS0x805455c0xc55c0x40x00x3WA004
                                              .got.pltPROGBITS0x80545600xc5600xc0x40x3WA004
                                              .dataPROGBITS0x805456c0xc56c0x2100x00x3WA004
                                              .bssNOBITS0x80547800xc77c0x2f480x00x3WA0032
                                              .stabPROGBITS0x00xc77c0xfc0xc0x01404
                                              .stabstrSTRTAB0x00xc8780xdb0x00x0001
                                              .commentPROGBITS0x00xc9530x85e0x00x0001
                                              .shstrtabSTRTAB0x00xd1b10x840x00x0001
                                              .symtabSYMTAB0x00xd5300x27c00x100x0182324
                                              .strtabSTRTAB0x00xfcf00x1dd80x00x0001
                                              TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                              LOAD0x00x80480000x80480000xbb100xbb106.44530x5R E0x1000.init .text .fini .rodata
                                              LOAD0xc0000x80540000x80540000x77c0x36c84.68570x6RW 0x1000.eh_frame .tbss .ctors .dtors .jcr .got.plt .data .bss
                                              TLS0xc54c0x805454c0x805454c0x00x80.00000x4R 0x4.tbss
                                              GNU_STACK0x00x00x00x00x00.00000x6RW 0x4
                                              NameVersion Info NameVersion Info File NameSection NameValueSizeSymbol TypeSymbol BindSymbol VisibilityNdx
                                              .symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                              .symtab0x80480b40SECTION<unknown>DEFAULT1
                                              .symtab0x80480d00SECTION<unknown>DEFAULT2
                                              .symtab0x8052aa70SECTION<unknown>DEFAULT3
                                              .symtab0x8052ac00SECTION<unknown>DEFAULT4
                                              .symtab0x80540000SECTION<unknown>DEFAULT5
                                              .symtab0x805454c0SECTION<unknown>DEFAULT6
                                              .symtab0x805454c0SECTION<unknown>DEFAULT7
                                              .symtab0x80545540SECTION<unknown>DEFAULT8
                                              .symtab0x805455c0SECTION<unknown>DEFAULT9
                                              .symtab0x80545600SECTION<unknown>DEFAULT10
                                              .symtab0x805456c0SECTION<unknown>DEFAULT11
                                              .symtab0x80547800SECTION<unknown>DEFAULT12
                                              .symtab0x00SECTION<unknown>DEFAULT13
                                              .symtab0x00SECTION<unknown>DEFAULT14
                                              .symtab0x00SECTION<unknown>DEFAULT15
                                              C.11.5136.symtab0x80533dc24OBJECT<unknown>DEFAULT4
                                              LOCAL_ADDR.symtab0x80572bc4OBJECT<unknown>DEFAULT12
                                              POPBX1.symtab0x80508ef0NOTYPE<unknown>DEFAULT2
                                              POPBX1.symtab0x805094f0NOTYPE<unknown>DEFAULT2
                                              POPBX1.symtab0x80509af0NOTYPE<unknown>DEFAULT2
                                              PUSHBX1.symtab0x80508db0NOTYPE<unknown>DEFAULT2
                                              PUSHBX1.symtab0x805093b0NOTYPE<unknown>DEFAULT2
                                              PUSHBX1.symtab0x805099b0NOTYPE<unknown>DEFAULT2
                                              RESTBX1.symtab0x80508990NOTYPE<unknown>DEFAULT2
                                              SAVEBX1.symtab0x805088c0NOTYPE<unknown>DEFAULT2
                                              _Exit.symtab0x8050ea466FUNC<unknown>DEFAULT2
                                              _GLOBAL_OFFSET_TABLE_.symtab0x80545600OBJECT<unknown>HIDDEN10
                                              _Jv_RegisterClasses.symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                              _L_lock_103.symtab0x805178216FUNC<unknown>DEFAULT2
                                              _L_lock_12.symtab0x8051ff316FUNC<unknown>DEFAULT2
                                              _L_lock_140.symtab0x805203316FUNC<unknown>DEFAULT2
                                              _L_lock_160.symtab0x805205316FUNC<unknown>DEFAULT2
                                              _L_lock_17.symtab0x8051cde10FUNC<unknown>DEFAULT2
                                              _L_lock_18.symtab0x805174813FUNC<unknown>DEFAULT2
                                              _L_lock_191.symtab0x805207313FUNC<unknown>DEFAULT2
                                              _L_lock_198.symtab0x8051a5016FUNC<unknown>DEFAULT2
                                              _L_lock_209.symtab0x8051a6016FUNC<unknown>DEFAULT2
                                              _L_lock_29.symtab0x805200316FUNC<unknown>DEFAULT2
                                              _L_lock_32.symtab0x8051c5110FUNC<unknown>DEFAULT2
                                              _L_lock_54.symtab0x805175516FUNC<unknown>DEFAULT2
                                              _L_lock_70.symtab0x80506fc16FUNC<unknown>DEFAULT2
                                              _L_unlock_102.symtab0x805202316FUNC<unknown>DEFAULT2
                                              _L_unlock_113.symtab0x805179213FUNC<unknown>DEFAULT2
                                              _L_unlock_152.symtab0x805204316FUNC<unknown>DEFAULT2
                                              _L_unlock_167.symtab0x805070c13FUNC<unknown>DEFAULT2
                                              _L_unlock_170.symtab0x805206316FUNC<unknown>DEFAULT2
                                              _L_unlock_225.symtab0x8051a7013FUNC<unknown>DEFAULT2
                                              _L_unlock_232.symtab0x805208013FUNC<unknown>DEFAULT2
                                              _L_unlock_235.symtab0x8051a7d13FUNC<unknown>DEFAULT2
                                              _L_unlock_40.symtab0x8051ce810FUNC<unknown>DEFAULT2
                                              _L_unlock_61.symtab0x8051c5b10FUNC<unknown>DEFAULT2
                                              _L_unlock_66.symtab0x805176516FUNC<unknown>DEFAULT2
                                              _L_unlock_83.symtab0x805177513FUNC<unknown>DEFAULT2
                                              _L_unlock_86.symtab0x805201316FUNC<unknown>DEFAULT2
                                              _READ.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              _WRITE.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              __CTOR_END__.symtab0x80545500OBJECT<unknown>DEFAULT7
                                              __CTOR_LIST__.symtab0x805454c0OBJECT<unknown>DEFAULT7
                                              __C_ctype_b.symtab0x805468c4OBJECT<unknown>DEFAULT11
                                              __C_ctype_b.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              __C_ctype_b_data.symtab0x8053810768OBJECT<unknown>DEFAULT4
                                              __DTOR_END__.symtab0x80545580OBJECT<unknown>DEFAULT8
                                              __DTOR_LIST__.symtab0x80545540OBJECT<unknown>DEFAULT8
                                              __EH_FRAME_BEGIN__.symtab0x80540000OBJECT<unknown>DEFAULT5
                                              __FRAME_END__.symtab0x80545480OBJECT<unknown>DEFAULT5
                                              __GI___C_ctype_b.symtab0x805468c4OBJECT<unknown>HIDDEN11
                                              __GI___close.symtab0x805088080FUNC<unknown>HIDDEN2
                                              __GI___close_nocancel.symtab0x805088a27FUNC<unknown>HIDDEN2
                                              __GI___ctype_b.symtab0x80546904OBJECT<unknown>HIDDEN11
                                              __GI___errno_location.symtab0x804e92813FUNC<unknown>HIDDEN2
                                              __GI___fcntl_nocancel.symtab0x804e3e483FUNC<unknown>HIDDEN2
                                              __GI___fgetc_unlocked.symtab0x8052090204FUNC<unknown>HIDDEN2
                                              __GI___libc_close.symtab0x805088080FUNC<unknown>HIDDEN2
                                              __GI___libc_fcntl.symtab0x804e437153FUNC<unknown>HIDDEN2
                                              __GI___libc_open.symtab0x80508d091FUNC<unknown>HIDDEN2
                                              __GI___libc_read.symtab0x805099091FUNC<unknown>HIDDEN2
                                              __GI___libc_write.symtab0x805093091FUNC<unknown>HIDDEN2
                                              __GI___open.symtab0x80508d091FUNC<unknown>HIDDEN2
                                              __GI___open_nocancel.symtab0x80508da33FUNC<unknown>HIDDEN2
                                              __GI___read.symtab0x805099091FUNC<unknown>HIDDEN2
                                              __GI___read_nocancel.symtab0x805099a33FUNC<unknown>HIDDEN2
                                              __GI___sigaddset.symtab0x804ee1432FUNC<unknown>HIDDEN2
                                              __GI___sigdelset.symtab0x804ee3432FUNC<unknown>HIDDEN2
                                              __GI___sigismember.symtab0x804edf036FUNC<unknown>HIDDEN2
                                              __GI___uClibc_fini.symtab0x8050ac356FUNC<unknown>HIDDEN2
                                              __GI___uClibc_init.symtab0x8050b2739FUNC<unknown>HIDDEN2
                                              __GI___write.symtab0x805093091FUNC<unknown>HIDDEN2
                                              __GI___write_nocancel.symtab0x805093a33FUNC<unknown>HIDDEN2
                                              __GI__exit.symtab0x8050ea466FUNC<unknown>HIDDEN2
                                              __GI_abort.symtab0x804fd90191FUNC<unknown>HIDDEN2
                                              __GI_accept.symtab0x804e9f084FUNC<unknown>HIDDEN2
                                              __GI_bind.symtab0x804ea4440FUNC<unknown>HIDDEN2
                                              __GI_brk.symtab0x80526e444FUNC<unknown>HIDDEN2
                                              __GI_close.symtab0x805088080FUNC<unknown>HIDDEN2
                                              __GI_closedir.symtab0x804e6ac130FUNC<unknown>HIDDEN2
                                              __GI_config_close.symtab0x805157244FUNC<unknown>HIDDEN2
                                              __GI_config_open.symtab0x805159e44FUNC<unknown>HIDDEN2
                                              __GI_config_read.symtab0x8051308618FUNC<unknown>HIDDEN2
                                              __GI_connect.symtab0x804ea6c84FUNC<unknown>HIDDEN2
                                              __GI_exit.symtab0x80501c093FUNC<unknown>HIDDEN2
                                              __GI_fclose.symtab0x80515cc380FUNC<unknown>HIDDEN2
                                              __GI_fcntl.symtab0x804e437153FUNC<unknown>HIDDEN2
                                              __GI_fflush_unlocked.symtab0x8051e34447FUNC<unknown>HIDDEN2
                                              __GI_fgetc.symtab0x8051bc0145FUNC<unknown>HIDDEN2
                                              __GI_fgetc_unlocked.symtab0x8052090204FUNC<unknown>HIDDEN2
                                              __GI_fgets.symtab0x8051c68118FUNC<unknown>HIDDEN2
                                              __GI_fgets_unlocked.symtab0x805215c94FUNC<unknown>HIDDEN2
                                              __GI_fopen.symtab0x80517a021FUNC<unknown>HIDDEN2
                                              __GI_fork.symtab0x80504f0524FUNC<unknown>HIDDEN2
                                              __GI_fstat.symtab0x8050ee870FUNC<unknown>HIDDEN2
                                              __GI_getc_unlocked.symtab0x8052090204FUNC<unknown>HIDDEN2
                                              __GI_getdtablesize.symtab0x8050fb432FUNC<unknown>HIDDEN2
                                              __GI_getegid.symtab0x8050fd48FUNC<unknown>HIDDEN2
                                              __GI_geteuid.symtab0x8050fdc8FUNC<unknown>HIDDEN2
                                              __GI_getgid.symtab0x8050fe48FUNC<unknown>HIDDEN2
                                              __GI_getpagesize.symtab0x8050fec19FUNC<unknown>HIDDEN2
                                              __GI_getpid.symtab0x805071c49FUNC<unknown>HIDDEN2
                                              __GI_getrlimit.symtab0x805100043FUNC<unknown>HIDDEN2
                                              __GI_getsockname.symtab0x804eac040FUNC<unknown>HIDDEN2
                                              __GI_getuid.symtab0x805102c8FUNC<unknown>HIDDEN2
                                              __GI_inet_addr.symtab0x804e9d031FUNC<unknown>HIDDEN2
                                              __GI_inet_aton.symtab0x8052334148FUNC<unknown>HIDDEN2
                                              __GI_initstate_r.symtab0x8050083155FUNC<unknown>HIDDEN2
                                              __GI_ioctl.symtab0x8052710139FUNC<unknown>HIDDEN2
                                              __GI_isatty.symtab0x80522b827FUNC<unknown>HIDDEN2
                                              __GI_kill.symtab0x804e4d843FUNC<unknown>HIDDEN2
                                              __GI_listen.symtab0x804eb2032FUNC<unknown>HIDDEN2
                                              __GI_lseek64.symtab0x8052a2490FUNC<unknown>HIDDEN2
                                              __GI_memcpy.symtab0x804e95c41FUNC<unknown>HIDDEN2
                                              __GI_memmove.symtab0x80521bc37FUNC<unknown>HIDDEN2
                                              __GI_mempcpy.symtab0x8052a0430FUNC<unknown>HIDDEN2
                                              __GI_memset.symtab0x804e98850FUNC<unknown>HIDDEN2
                                              __GI_mmap.symtab0x8050e2427FUNC<unknown>HIDDEN2
                                              __GI_mremap.symtab0x805103459FUNC<unknown>HIDDEN2
                                              __GI_munmap.symtab0x805107043FUNC<unknown>HIDDEN2
                                              __GI_nanosleep.symtab0x80510c561FUNC<unknown>HIDDEN2
                                              __GI_open.symtab0x80508d091FUNC<unknown>HIDDEN2
                                              __GI_opendir.symtab0x804e7b8132FUNC<unknown>HIDDEN2
                                              __GI_raise.symtab0x8050750100FUNC<unknown>HIDDEN2
                                              __GI_random.symtab0x804fe5866FUNC<unknown>HIDDEN2
                                              __GI_random_r.symtab0x804ff8495FUNC<unknown>HIDDEN2
                                              __GI_read.symtab0x805099091FUNC<unknown>HIDDEN2
                                              __GI_readdir.symtab0x804e8a8127FUNC<unknown>HIDDEN2
                                              __GI_readdir64.symtab0x8051284129FUNC<unknown>HIDDEN2
                                              __GI_readlink.symtab0x804e54047FUNC<unknown>HIDDEN2
                                              __GI_recv.symtab0x804eb4092FUNC<unknown>HIDDEN2
                                              __GI_recvfrom.symtab0x804eb9c108FUNC<unknown>HIDDEN2
                                              __GI_sbrk.symtab0x805110464FUNC<unknown>HIDDEN2
                                              __GI_select.symtab0x804e5a9108FUNC<unknown>HIDDEN2
                                              __GI_send.symtab0x804ec0892FUNC<unknown>HIDDEN2
                                              __GI_sendto.symtab0x804ec64108FUNC<unknown>HIDDEN2
                                              __GI_setsid.symtab0x804e61831FUNC<unknown>HIDDEN2
                                              __GI_setsockopt.symtab0x804ecd056FUNC<unknown>HIDDEN2
                                              __GI_setstate_r.symtab0x805011e161FUNC<unknown>HIDDEN2
                                              __GI_sigaction.symtab0x8050daf80FUNC<unknown>HIDDEN2
                                              __GI_sigaddset.symtab0x804ed3034FUNC<unknown>HIDDEN2
                                              __GI_sigemptyset.symtab0x804ed5420FUNC<unknown>HIDDEN2
                                              __GI_signal.symtab0x804ed68136FUNC<unknown>HIDDEN2
                                              __GI_sigprocmask.symtab0x804e63897FUNC<unknown>HIDDEN2
                                              __GI_sleep.symtab0x80507b4195FUNC<unknown>HIDDEN2
                                              __GI_socket.symtab0x804ed0840FUNC<unknown>HIDDEN2
                                              __GI_srandom_r.symtab0x804ffe3160FUNC<unknown>HIDDEN2
                                              __GI_strchr.symtab0x80521e430FUNC<unknown>HIDDEN2
                                              __GI_strchrnul.symtab0x805220425FUNC<unknown>HIDDEN2
                                              __GI_strcmp.symtab0x805222029FUNC<unknown>HIDDEN2
                                              __GI_strcoll.symtab0x805222029FUNC<unknown>HIDDEN2
                                              __GI_strcspn.symtab0x805225c45FUNC<unknown>HIDDEN2
                                              __GI_strlen.symtab0x804e9bc19FUNC<unknown>HIDDEN2
                                              __GI_strrchr.symtab0x805224026FUNC<unknown>HIDDEN2
                                              __GI_strspn.symtab0x805228c42FUNC<unknown>HIDDEN2
                                              __GI_sysconf.symtab0x80502e4523FUNC<unknown>HIDDEN2
                                              __GI_tcgetattr.symtab0x80522d496FUNC<unknown>HIDDEN2
                                              __GI_time.symtab0x804e69c16FUNC<unknown>HIDDEN2
                                              __GI_times.symtab0x805114416FUNC<unknown>HIDDEN2
                                              __GI_write.symtab0x805093091FUNC<unknown>HIDDEN2
                                              __JCR_END__.symtab0x805455c0OBJECT<unknown>DEFAULT9
                                              __JCR_LIST__.symtab0x805455c0OBJECT<unknown>DEFAULT9
                                              __app_fini.symtab0x8054d544OBJECT<unknown>HIDDEN12
                                              __atexit_lock.symtab0x805466824OBJECT<unknown>DEFAULT11
                                              __bss_start.symtab0x805477c0NOTYPE<unknown>DEFAULTSHN_ABS
                                              __check_one_fd.symtab0x8050afb44FUNC<unknown>DEFAULT2
                                              __close.symtab0x805088080FUNC<unknown>DEFAULT2
                                              __close_nocancel.symtab0x805088a27FUNC<unknown>DEFAULT2
                                              __ctype_b.symtab0x80546904OBJECT<unknown>DEFAULT11
                                              __curbrk.symtab0x80572b84OBJECT<unknown>HIDDEN12
                                              __deregister_frame_info_bases.symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                              __do_global_ctors_aux.symtab0x8052a800FUNC<unknown>DEFAULT2
                                              __do_global_dtors_aux.symtab0x80480e00FUNC<unknown>DEFAULT2
                                              __dso_handle.symtab0x805456c0OBJECT<unknown>HIDDEN11
                                              __environ.symtab0x8054d4c4OBJECT<unknown>DEFAULT12
                                              __errno_location.symtab0x804e92813FUNC<unknown>DEFAULT2
                                              __errno_location.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              __exit_cleanup.symtab0x80547fc4OBJECT<unknown>HIDDEN12
                                              __fcntl_nocancel.symtab0x804e3e483FUNC<unknown>DEFAULT2
                                              __fgetc_unlocked.symtab0x8052090204FUNC<unknown>DEFAULT2
                                              __fini_array_end.symtab0x805454c0NOTYPE<unknown>HIDDEN6
                                              __fini_array_start.symtab0x805454c0NOTYPE<unknown>HIDDEN6
                                              __fork.symtab0x80504f0524FUNC<unknown>DEFAULT2
                                              __fork_generation_pointer.symtab0x80576984OBJECT<unknown>HIDDEN12
                                              __fork_handlers.symtab0x805769c4OBJECT<unknown>HIDDEN12
                                              __fork_lock.symtab0x80548004OBJECT<unknown>HIDDEN12
                                              __get_pc_thunk_bx.symtab0x80480d00FUNC<unknown>HIDDEN2
                                              __getdents.symtab0x8050f30131FUNC<unknown>HIDDEN2
                                              __getdents64.symtab0x805279c280FUNC<unknown>HIDDEN2
                                              __getpagesize.symtab0x8050fec19FUNC<unknown>DEFAULT2
                                              __getpid.symtab0x805071c49FUNC<unknown>DEFAULT2
                                              __h_errno_location.symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                              __init_array_end.symtab0x805454c0NOTYPE<unknown>HIDDEN6
                                              __init_array_start.symtab0x805454c0NOTYPE<unknown>HIDDEN6
                                              __libc_accept.symtab0x804e9f084FUNC<unknown>DEFAULT2
                                              __libc_close.symtab0x805088080FUNC<unknown>DEFAULT2
                                              __libc_connect.symtab0x804ea6c84FUNC<unknown>DEFAULT2
                                              __libc_disable_asynccancel.symtab0x80509ec86FUNC<unknown>HIDDEN2
                                              __libc_enable_asynccancel.symtab0x8050a4279FUNC<unknown>HIDDEN2
                                              __libc_errno.symtab0x04TLS<unknown>HIDDEN6
                                              __libc_fcntl.symtab0x804e437153FUNC<unknown>DEFAULT2
                                              __libc_fork.symtab0x80504f0524FUNC<unknown>DEFAULT2
                                              __libc_h_errno.symtab0x44TLS<unknown>HIDDEN6
                                              __libc_nanosleep.symtab0x80510c561FUNC<unknown>DEFAULT2
                                              __libc_open.symtab0x80508d091FUNC<unknown>DEFAULT2
                                              __libc_read.symtab0x805099091FUNC<unknown>DEFAULT2
                                              __libc_recv.symtab0x804eb4092FUNC<unknown>DEFAULT2
                                              __libc_recvfrom.symtab0x804eb9c108FUNC<unknown>DEFAULT2
                                              __libc_select.symtab0x804e5a9108FUNC<unknown>DEFAULT2
                                              __libc_send.symtab0x804ec0892FUNC<unknown>DEFAULT2
                                              __libc_sendto.symtab0x804ec64108FUNC<unknown>DEFAULT2
                                              __libc_setup_tls.symtab0x805247a513FUNC<unknown>DEFAULT2
                                              __libc_sigaction.symtab0x8050daf80FUNC<unknown>DEFAULT2
                                              __libc_stack_end.symtab0x8054d484OBJECT<unknown>DEFAULT12
                                              __libc_write.symtab0x805093091FUNC<unknown>DEFAULT2
                                              __lll_lock_wait_private.symtab0x80523d040FUNC<unknown>HIDDEN2
                                              __lll_unlock_wake_private.symtab0x805240032FUNC<unknown>HIDDEN2
                                              __malloc_consolidate.symtab0x804fa69379FUNC<unknown>HIDDEN2
                                              __malloc_largebin_index.symtab0x804ee5438FUNC<unknown>DEFAULT2
                                              __malloc_lock.symtab0x805458c24OBJECT<unknown>DEFAULT11
                                              __malloc_state.symtab0x8057320888OBJECT<unknown>DEFAULT12
                                              __malloc_trim.symtab0x804f9ec125FUNC<unknown>DEFAULT2
                                              __nptl_deallocate_tsd.symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                              __nptl_nthreads.symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                              __open.symtab0x80508d091FUNC<unknown>DEFAULT2
                                              __open_nocancel.symtab0x80508da33FUNC<unknown>DEFAULT2
                                              __pagesize.symtab0x8054d504OBJECT<unknown>DEFAULT12
                                              __preinit_array_end.symtab0x805454c0NOTYPE<unknown>HIDDEN6
                                              __preinit_array_start.symtab0x805454c0NOTYPE<unknown>HIDDEN6
                                              __progname.symtab0x80546844OBJECT<unknown>DEFAULT11
                                              __progname_full.symtab0x80546884OBJECT<unknown>DEFAULT11
                                              __pthread_initialize_minimal.symtab0x805267b15FUNC<unknown>DEFAULT2
                                              __pthread_mutex_init.symtab0x8050a973FUNC<unknown>DEFAULT2
                                              __pthread_mutex_lock.symtab0x8050a943FUNC<unknown>DEFAULT2
                                              __pthread_mutex_trylock.symtab0x8050a943FUNC<unknown>DEFAULT2
                                              __pthread_mutex_unlock.symtab0x8050a943FUNC<unknown>DEFAULT2
                                              __pthread_return_0.symtab0x8050a943FUNC<unknown>DEFAULT2
                                              __pthread_unwind.symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                              __read.symtab0x805099091FUNC<unknown>DEFAULT2
                                              __read_nocancel.symtab0x805099a33FUNC<unknown>DEFAULT2
                                              __register_frame_info_bases.symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                              __restore.symtab0x8050da70NOTYPE<unknown>DEFAULT2
                                              __restore_rt.symtab0x8050da00NOTYPE<unknown>DEFAULT2
                                              __rtld_fini.symtab0x8054d584OBJECT<unknown>HIDDEN12
                                              __sigaddset.symtab0x804ee1432FUNC<unknown>DEFAULT2
                                              __sigdelset.symtab0x804ee3432FUNC<unknown>DEFAULT2
                                              __sigismember.symtab0x804edf036FUNC<unknown>DEFAULT2
                                              __socketcall.symtab0x8050e4043FUNC<unknown>HIDDEN2
                                              __socketcall.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              __stdin.symtab0x80546a04OBJECT<unknown>DEFAULT11
                                              __stdio_READ.symtab0x80528b462FUNC<unknown>HIDDEN2
                                              __stdio_WRITE.symtab0x80528f4139FUNC<unknown>HIDDEN2
                                              __stdio_rfill.symtab0x805298037FUNC<unknown>HIDDEN2
                                              __stdio_trans2r_o.symtab0x80529a892FUNC<unknown>HIDDEN2
                                              __stdio_wcommit.symtab0x8051b9837FUNC<unknown>HIDDEN2
                                              __stdout.symtab0x80546a44OBJECT<unknown>DEFAULT11
                                              __syscall_error.symtab0x8050d9015FUNC<unknown>HIDDEN2
                                              __syscall_error.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              __syscall_fcntl.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              __syscall_nanosleep.symtab0x805109c41FUNC<unknown>DEFAULT2
                                              __syscall_rt_sigaction.symtab0x8050e6c53FUNC<unknown>DEFAULT2
                                              __syscall_rt_sigaction.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              __syscall_select.symtab0x804e57057FUNC<unknown>DEFAULT2
                                              __uClibc_fini.symtab0x8050ac356FUNC<unknown>DEFAULT2
                                              __uClibc_init.symtab0x8050b2739FUNC<unknown>DEFAULT2
                                              __uClibc_main.symtab0x8050b4e577FUNC<unknown>DEFAULT2
                                              __uClibc_main.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              __uclibc_progname.symtab0x80546804OBJECT<unknown>HIDDEN11
                                              __write.symtab0x805093091FUNC<unknown>DEFAULT2
                                              __write_nocancel.symtab0x805093a33FUNC<unknown>DEFAULT2
                                              __xstat32_conv.symtab0x80511f7138FUNC<unknown>HIDDEN2
                                              __xstat64_conv.symtab0x8051154163FUNC<unknown>HIDDEN2
                                              _dl_aux_init.symtab0x805268c18FUNC<unknown>DEFAULT2
                                              _dl_nothread_init_static_tls.symtab0x805269e68FUNC<unknown>HIDDEN2
                                              _dl_phdr.symtab0x80576c04OBJECT<unknown>DEFAULT12
                                              _dl_phnum.symtab0x80576c44OBJECT<unknown>DEFAULT12
                                              _dl_tls_dtv_gaps.symtab0x80576b41OBJECT<unknown>DEFAULT12
                                              _dl_tls_dtv_slotinfo_list.symtab0x80576b04OBJECT<unknown>DEFAULT12
                                              _dl_tls_generation.symtab0x80576b84OBJECT<unknown>DEFAULT12
                                              _dl_tls_max_dtv_idx.symtab0x80576a84OBJECT<unknown>DEFAULT12
                                              _dl_tls_setup.symtab0x805244a48FUNC<unknown>DEFAULT2
                                              _dl_tls_static_align.symtab0x80576a44OBJECT<unknown>DEFAULT12
                                              _dl_tls_static_nelem.symtab0x80576bc4OBJECT<unknown>DEFAULT12
                                              _dl_tls_static_size.symtab0x80576ac4OBJECT<unknown>DEFAULT12
                                              _dl_tls_static_used.symtab0x80576a04OBJECT<unknown>DEFAULT12
                                              _edata.symtab0x805477c0NOTYPE<unknown>DEFAULTSHN_ABS
                                              _end.symtab0x80576c80NOTYPE<unknown>DEFAULTSHN_ABS
                                              _exit.symtab0x8050ea466FUNC<unknown>DEFAULT2
                                              _exit.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              _fini.symtab0x8052aa70FUNC<unknown>DEFAULT3
                                              _fixed_buffers.symtab0x8054d7c8192OBJECT<unknown>DEFAULT12
                                              _fopen.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              _init.symtab0x80480b40FUNC<unknown>DEFAULT1
                                              _pthread_cleanup_pop_restore.symtab0x8050aac23FUNC<unknown>DEFAULT2
                                              _pthread_cleanup_push_defer.symtab0x8050a9a18FUNC<unknown>DEFAULT2
                                              _rfill.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              _setjmp.symtab0x8050e0034FUNC<unknown>DEFAULT2
                                              _sigintr.symtab0x80573188OBJECT<unknown>HIDDEN12
                                              _start.symtab0x804818434FUNC<unknown>DEFAULT2
                                              _stdio.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              _stdio_fopen.symtab0x80517b8664FUNC<unknown>HIDDEN2
                                              _stdio_init.symtab0x8051a8c59FUNC<unknown>HIDDEN2
                                              _stdio_openlist.symtab0x80546a84OBJECT<unknown>DEFAULT11
                                              _stdio_openlist_add_lock.symtab0x8054d5c12OBJECT<unknown>DEFAULT12
                                              _stdio_openlist_dec_use.symtab0x8051cf4320FUNC<unknown>HIDDEN2
                                              _stdio_openlist_del_count.symtab0x8054d784OBJECT<unknown>DEFAULT12
                                              _stdio_openlist_del_lock.symtab0x8054d6812OBJECT<unknown>DEFAULT12
                                              _stdio_openlist_use_count.symtab0x8054d744OBJECT<unknown>DEFAULT12
                                              _stdio_streams.symtab0x80546b0204OBJECT<unknown>DEFAULT11
                                              _stdio_term.symtab0x8051ac7208FUNC<unknown>HIDDEN2
                                              _stdio_user_locking.symtab0x80546ac4OBJECT<unknown>DEFAULT11
                                              _trans2r.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              _wcommit.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              abort.symtab0x804fd90191FUNC<unknown>DEFAULT2
                                              abort.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              accept.symtab0x804e9f084FUNC<unknown>DEFAULT2
                                              accept.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              anti_gdb_entry.symtab0x804c6d011FUNC<unknown>DEFAULT2
                                              attack.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              attack_get_opt_int.symtab0x80486a0109FUNC<unknown>DEFAULT2
                                              attack_get_opt_ip.symtab0x8048630101FUNC<unknown>DEFAULT2
                                              attack_init.symtab0x8048710924FUNC<unknown>DEFAULT2
                                              attack_kill_all.symtab0x8048270326FUNC<unknown>DEFAULT2
                                              attack_method_nudp.symtab0x804be201350FUNC<unknown>DEFAULT2
                                              attack_method_stdhex.symtab0x804bb50705FUNC<unknown>DEFAULT2
                                              attack_method_tcp.symtab0x80490201350FUNC<unknown>DEFAULT2
                                              attack_ongoing.symtab0x80547c032OBJECT<unknown>DEFAULT12
                                              attack_parse.symtab0x80483c0613FUNC<unknown>DEFAULT2
                                              attack_start.symtab0x80481b0192FUNC<unknown>DEFAULT2
                                              attack_tcp.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              attack_tcp_ack.symtab0x804a1501471FUNC<unknown>DEFAULT2
                                              attack_tcp_legit.symtab0x804acc01433FUNC<unknown>DEFAULT2
                                              attack_tcp_null.symtab0x804b2601572FUNC<unknown>DEFAULT2
                                              attack_tcp_sack2.symtab0x80495701366FUNC<unknown>DEFAULT2
                                              attack_tcp_stomp.symtab0x8049ad01664FUNC<unknown>DEFAULT2
                                              attack_tcp_syn.symtab0x8048ab01391FUNC<unknown>DEFAULT2
                                              attack_tcp_syndata.symtab0x804a7101455FUNC<unknown>DEFAULT2
                                              attack_udp.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              attack_udp_plain.symtab0x804b8a0683FUNC<unknown>DEFAULT2
                                              been_there_done_that.symtab0x80547f81OBJECT<unknown>DEFAULT12
                                              bind.symtab0x804ea4440FUNC<unknown>DEFAULT2
                                              bind.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              brk.symtab0x80526e444FUNC<unknown>DEFAULT2
                                              brk.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              bsd_signal.symtab0x804ed68136FUNC<unknown>DEFAULT2
                                              calloc.symtab0x804f604236FUNC<unknown>DEFAULT2
                                              calloc.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              checksum.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              checksum_generic.symtab0x804c37070FUNC<unknown>DEFAULT2
                                              checksum_tcpudp.symtab0x804c3c0169FUNC<unknown>DEFAULT2
                                              clock.symtab0x804e93834FUNC<unknown>DEFAULT2
                                              clock.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              close.symtab0x805088080FUNC<unknown>DEFAULT2
                                              closedir.symtab0x804e6ac130FUNC<unknown>DEFAULT2
                                              closedir.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              completed.4963.symtab0x80547801OBJECT<unknown>DEFAULT12
                                              connect.symtab0x804ea6c84FUNC<unknown>DEFAULT2
                                              connect.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              crtstuff.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              crtstuff.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              dl-support.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              ensure_single_instance.symtab0x804c6e0311FUNC<unknown>DEFAULT2
                                              environ.symtab0x8054d4c4OBJECT<unknown>DEFAULT12
                                              errno.symtab0x04TLS<unknown>DEFAULT6
                                              errno.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              exit.symtab0x80501c093FUNC<unknown>DEFAULT2
                                              exit.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              fclose.symtab0x80515cc380FUNC<unknown>DEFAULT2
                                              fclose.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              fcntl.symtab0x804e437153FUNC<unknown>DEFAULT2
                                              fd_ctrl.symtab0x80545784OBJECT<unknown>DEFAULT11
                                              fd_serv.symtab0x805457c4OBJECT<unknown>DEFAULT11
                                              fd_to_DIR.symtab0x804e730136FUNC<unknown>DEFAULT2
                                              fdopendir.symtab0x804e83c108FUNC<unknown>DEFAULT2
                                              fflush_unlocked.symtab0x8051e34447FUNC<unknown>DEFAULT2
                                              fflush_unlocked.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              fgetc.symtab0x8051bc0145FUNC<unknown>DEFAULT2
                                              fgetc.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              fgetc_unlocked.symtab0x8052090204FUNC<unknown>DEFAULT2
                                              fgetc_unlocked.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              fgets.symtab0x8051c68118FUNC<unknown>DEFAULT2
                                              fgets.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              fgets_unlocked.symtab0x805215c94FUNC<unknown>DEFAULT2
                                              fgets_unlocked.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              fopen.symtab0x80517a021FUNC<unknown>DEFAULT2
                                              fopen.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              fork.symtab0x80504f0524FUNC<unknown>DEFAULT2
                                              fork.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              fork_handler_pool.symtab0x80548041348OBJECT<unknown>DEFAULT12
                                              frame_dummy.symtab0x80481300FUNC<unknown>DEFAULT2
                                              free.symtab0x804fbe4399FUNC<unknown>DEFAULT2
                                              free.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              fstat.symtab0x8050ee870FUNC<unknown>DEFAULT2
                                              fstat.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              getc.symtab0x8051bc0145FUNC<unknown>DEFAULT2
                                              getc_unlocked.symtab0x8052090204FUNC<unknown>DEFAULT2
                                              getdents.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              getdents64.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              getdtablesize.symtab0x8050fb432FUNC<unknown>DEFAULT2
                                              getdtablesize.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              getegid.symtab0x8050fd48FUNC<unknown>DEFAULT2
                                              getegid.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              geteuid.symtab0x8050fdc8FUNC<unknown>DEFAULT2
                                              geteuid.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              getgid.symtab0x8050fe48FUNC<unknown>DEFAULT2
                                              getgid.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              getpagesize.symtab0x8050fec19FUNC<unknown>DEFAULT2
                                              getpagesize.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              getpid.symtab0x805071c49FUNC<unknown>DEFAULT2
                                              getpid.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              getppid.symtab0x804e4d08FUNC<unknown>DEFAULT2
                                              getppid.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              getrlimit.symtab0x805100043FUNC<unknown>DEFAULT2
                                              getrlimit.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              getsockname.symtab0x804eac040FUNC<unknown>DEFAULT2
                                              getsockname.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              getsockopt.symtab0x804eae856FUNC<unknown>DEFAULT2
                                              getsockopt.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              getuid.symtab0x805102c8FUNC<unknown>DEFAULT2
                                              getuid.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              h_errno.symtab0x44TLS<unknown>DEFAULT6
                                              hexPayload.symtab0x80545744OBJECT<unknown>DEFAULT11
                                              index.symtab0x80521e430FUNC<unknown>DEFAULT2
                                              inet_addr.symtab0x804e9d031FUNC<unknown>DEFAULT2
                                              inet_aton.symtab0x8052334148FUNC<unknown>DEFAULT2
                                              inet_aton.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              inet_makeaddr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              init_static_tls.symtab0x805242042FUNC<unknown>DEFAULT2
                                              initfini.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              initstate.symtab0x804fef185FUNC<unknown>DEFAULT2
                                              initstate_r.symtab0x8050083155FUNC<unknown>DEFAULT2
                                              ioctl.symtab0x8052710139FUNC<unknown>DEFAULT2
                                              ioctl.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              isatty.symtab0x80522b827FUNC<unknown>DEFAULT2
                                              isatty.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              kill.symtab0x804e4d843FUNC<unknown>DEFAULT2
                                              kill.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              killer.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              killer_init.symtab0x804c5f0217FUNC<unknown>DEFAULT2
                                              killer_kill.symtab0x804c47029FUNC<unknown>DEFAULT2
                                              killer_kill_by_port.symtab0x804d9801581FUNC<unknown>DEFAULT2
                                              killer_mirai_exists.symtab0x804c490347FUNC<unknown>DEFAULT2
                                              killer_pid.symtab0x80547e04OBJECT<unknown>DEFAULT12
                                              libc-cancellation.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              libc-tls.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              listen.symtab0x804eb2032FUNC<unknown>DEFAULT2
                                              listen.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              llseek.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              local_bind.4544.symtab0x80545841OBJECT<unknown>DEFAULT11
                                              lseek64.symtab0x8052a2490FUNC<unknown>DEFAULT2
                                              main.symtab0x804c8901856FUNC<unknown>DEFAULT2
                                              main.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              malloc.symtab0x804ee7a1928FUNC<unknown>DEFAULT2
                                              malloc.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              malloc_trim.symtab0x804fd7329FUNC<unknown>DEFAULT2
                                              memcpy.symtab0x804e95c41FUNC<unknown>DEFAULT2
                                              memcpy.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              memmove.symtab0x80521bc37FUNC<unknown>DEFAULT2
                                              memmove.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              mempcpy.symtab0x8052a0430FUNC<unknown>DEFAULT2
                                              mempcpy.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              memset.symtab0x804e98850FUNC<unknown>DEFAULT2
                                              memset.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              methods.symtab0x80547a04OBJECT<unknown>DEFAULT12
                                              methods_len.symtab0x805479c1OBJECT<unknown>DEFAULT12
                                              mmap.symtab0x8050e2427FUNC<unknown>DEFAULT2
                                              mremap.symtab0x805103459FUNC<unknown>DEFAULT2
                                              mremap.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              munmap.symtab0x805107043FUNC<unknown>DEFAULT2
                                              munmap.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              mylock.symtab0x80545a424OBJECT<unknown>DEFAULT11
                                              mylock.symtab0x80545bc24OBJECT<unknown>DEFAULT11
                                              nanosleep.symtab0x80510c561FUNC<unknown>DEFAULT2
                                              nanosleep.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              nprocessors_onln.symtab0x8050220196FUNC<unknown>DEFAULT2
                                              object.4975.symtab0x805478424OBJECT<unknown>DEFAULT12
                                              open.symtab0x80508d091FUNC<unknown>DEFAULT2
                                              opendir.symtab0x804e7b8132FUNC<unknown>DEFAULT2
                                              opendir.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              p.4961.symtab0x80545700OBJECT<unknown>DEFAULT11
                                              parse_config.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              pending_connection.symtab0x80547e41OBJECT<unknown>DEFAULT12
                                              prctl.symtab0x804e50459FUNC<unknown>DEFAULT2
                                              prctl.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              program_invocation_name.symtab0x80546884OBJECT<unknown>DEFAULT11
                                              program_invocation_short_name.symtab0x80546844OBJECT<unknown>DEFAULT11
                                              pseudo_cancel.symtab0x80508a50NOTYPE<unknown>DEFAULT2
                                              pseudo_cancel.symtab0x80508fb0NOTYPE<unknown>DEFAULT2
                                              pseudo_cancel.symtab0x805095b0NOTYPE<unknown>DEFAULT2
                                              pseudo_cancel.symtab0x80509bb0NOTYPE<unknown>DEFAULT2
                                              pseudo_end.symtab0x80508cf0NOTYPE<unknown>DEFAULT2
                                              pseudo_end.symtab0x805092a0NOTYPE<unknown>DEFAULT2
                                              pseudo_end.symtab0x805098a0NOTYPE<unknown>DEFAULT2
                                              pseudo_end.symtab0x80509ea0NOTYPE<unknown>DEFAULT2
                                              raise.symtab0x8050750100FUNC<unknown>DEFAULT2
                                              raise.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              rand.symtab0x804fe505FUNC<unknown>DEFAULT2
                                              rand.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              rand.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              rand_alphastr.symtab0x804d050268FUNC<unknown>DEFAULT2
                                              rand_init.symtab0x804d01063FUNC<unknown>DEFAULT2
                                              rand_next.symtab0x804cfd064FUNC<unknown>DEFAULT2
                                              rand_str.symtab0x804d160218FUNC<unknown>DEFAULT2
                                              random.symtab0x804fe5866FUNC<unknown>DEFAULT2
                                              random.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              random_poly_info.symtab0x80533f410OBJECT<unknown>DEFAULT4
                                              random_r.symtab0x804ff8495FUNC<unknown>DEFAULT2
                                              random_r.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              randtbl.symtab0x80545e8128OBJECT<unknown>DEFAULT11
                                              read.symtab0x805099091FUNC<unknown>DEFAULT2
                                              readdir.symtab0x804e8a8127FUNC<unknown>DEFAULT2
                                              readdir.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              readdir64.symtab0x8051284129FUNC<unknown>DEFAULT2
                                              readdir64.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              readlink.symtab0x804e54047FUNC<unknown>DEFAULT2
                                              readlink.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              realloc.symtab0x804f6f0763FUNC<unknown>DEFAULT2
                                              realloc.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              recv.symtab0x804eb4092FUNC<unknown>DEFAULT2
                                              recv.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              recvfrom.symtab0x804eb9c108FUNC<unknown>DEFAULT2
                                              recvfrom.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              register-atfork.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              resolv.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              resolv_entries_free.symtab0x804d24052FUNC<unknown>DEFAULT2
                                              resolv_lookup.symtab0x804d2801192FUNC<unknown>DEFAULT2
                                              resolve_cnc_addr.symtab0x804c820103FUNC<unknown>DEFAULT2
                                              resolve_func.symtab0x80545804OBJECT<unknown>DEFAULT11
                                              rindex.symtab0x805224026FUNC<unknown>DEFAULT2
                                              sbrk.symtab0x805110464FUNC<unknown>DEFAULT2
                                              sbrk.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              select.symtab0x804e5a9108FUNC<unknown>DEFAULT2
                                              select.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              send.symtab0x804ec0892FUNC<unknown>DEFAULT2
                                              send.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              sendto.symtab0x804ec64108FUNC<unknown>DEFAULT2
                                              sendto.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              setsid.symtab0x804e61831FUNC<unknown>DEFAULT2
                                              setsid.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              setsockopt.symtab0x804ecd056FUNC<unknown>DEFAULT2
                                              setsockopt.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              setstate.symtab0x804fe9a87FUNC<unknown>DEFAULT2
                                              setstate_r.symtab0x805011e161FUNC<unknown>DEFAULT2
                                              sigaction.symtab0x8050daf80FUNC<unknown>DEFAULT2
                                              sigaction.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              sigaddset.symtab0x804ed3034FUNC<unknown>DEFAULT2
                                              sigaddset.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              sigempty.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              sigemptyset.symtab0x804ed5420FUNC<unknown>DEFAULT2
                                              signal.symtab0x804ed68136FUNC<unknown>DEFAULT2
                                              signal.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              sigprocmask.symtab0x804e63897FUNC<unknown>DEFAULT2
                                              sigprocmask.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              sigsetops.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              sleep.symtab0x80507b4195FUNC<unknown>DEFAULT2
                                              sleep.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              socket.symtab0x804ed0840FUNC<unknown>DEFAULT2
                                              socket.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              srand.symtab0x804ff4661FUNC<unknown>DEFAULT2
                                              srandom.symtab0x804ff4661FUNC<unknown>DEFAULT2
                                              srandom_r.symtab0x804ffe3160FUNC<unknown>DEFAULT2
                                              srv_addr.symtab0x80572c016OBJECT<unknown>DEFAULT12
                                              static_dtv.symtab0x8056d7c512OBJECT<unknown>DEFAULT12
                                              static_map.symtab0x805728452OBJECT<unknown>DEFAULT12
                                              static_slotinfo.symtab0x8056f7c776OBJECT<unknown>DEFAULT12
                                              stderr.symtab0x805469c4OBJECT<unknown>DEFAULT11
                                              stdin.symtab0x80546944OBJECT<unknown>DEFAULT11
                                              stdout.symtab0x80546984OBJECT<unknown>DEFAULT11
                                              strchr.symtab0x80521e430FUNC<unknown>DEFAULT2
                                              strchr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              strchrnul.symtab0x805220425FUNC<unknown>DEFAULT2
                                              strchrnul.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              strcmp.symtab0x805222029FUNC<unknown>DEFAULT2
                                              strcmp.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              strcoll.symtab0x805222029FUNC<unknown>DEFAULT2
                                              strcspn.symtab0x805225c45FUNC<unknown>DEFAULT2
                                              strcspn.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              strlen.symtab0x804e9bc19FUNC<unknown>DEFAULT2
                                              strlen.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              strrchr.symtab0x805224026FUNC<unknown>DEFAULT2
                                              strrchr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              strspn.symtab0x805228c42FUNC<unknown>DEFAULT2
                                              strspn.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              sysconf.symtab0x80502e4523FUNC<unknown>DEFAULT2
                                              sysconf.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              table.symtab0x80572e056OBJECT<unknown>DEFAULT12
                                              table.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              table_init.symtab0x804d860274FUNC<unknown>DEFAULT2
                                              table_key.symtab0x80545884OBJECT<unknown>DEFAULT11
                                              table_lock_val.symtab0x804d760114FUNC<unknown>DEFAULT2
                                              table_retrieve_val.symtab0x804d73038FUNC<unknown>DEFAULT2
                                              table_unlock_val.symtab0x804d7e0114FUNC<unknown>DEFAULT2
                                              tcgetattr.symtab0x80522d496FUNC<unknown>DEFAULT2
                                              tcgetattr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              tcp.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              time.symtab0x804e69c16FUNC<unknown>DEFAULT2
                                              time.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              times.symtab0x805114416FUNC<unknown>DEFAULT2
                                              times.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              unsafe_state.symtab0x80545d420OBJECT<unknown>DEFAULT11
                                              update_process.symtab0x804b8901FUNC<unknown>DEFAULT2
                                              util.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              util_atoi.symtab0x804e220245FUNC<unknown>DEFAULT2
                                              util_fdgets.symtab0x804e0d076FUNC<unknown>DEFAULT2
                                              util_isalpha.symtab0x804e09027FUNC<unknown>DEFAULT2
                                              util_isdigit.symtab0x804e0b018FUNC<unknown>DEFAULT2
                                              util_itoa.symtab0x804e320195FUNC<unknown>DEFAULT2
                                              util_local_addr.symtab0x804e120120FUNC<unknown>DEFAULT2
                                              util_memcpy.symtab0x804e04034FUNC<unknown>DEFAULT2
                                              util_strcat.symtab0x804dfd044FUNC<unknown>DEFAULT2
                                              util_strcpy.symtab0x804e00050FUNC<unknown>DEFAULT2
                                              util_stristr.symtab0x804e1a0121FUNC<unknown>DEFAULT2
                                              util_strlen.symtab0x804dfb024FUNC<unknown>DEFAULT2
                                              util_zero.symtab0x804e07026FUNC<unknown>DEFAULT2
                                              w.symtab0x80547f44OBJECT<unknown>DEFAULT12
                                              write.symtab0x805093091FUNC<unknown>DEFAULT2
                                              x.symtab0x80547e84OBJECT<unknown>DEFAULT12
                                              xstatconv.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                              y.symtab0x80547ec4OBJECT<unknown>DEFAULT12
                                              z.symtab0x80547f04OBJECT<unknown>DEFAULT12

                                              Download Network PCAP: filteredfull

                                              • Total Packets: 19
                                              • 56999 undefined
                                              • 443 (HTTPS)
                                              • 53 (DNS)
                                              TimestampSource PortDest PortSource IPDest IP
                                              Mar 27, 2025 19:53:30.165596008 CET3927056999192.168.2.14103.142.27.125
                                              Mar 27, 2025 19:53:30.484993935 CET5699939270103.142.27.125192.168.2.14
                                              Mar 27, 2025 19:53:30.485048056 CET3927056999192.168.2.14103.142.27.125
                                              Mar 27, 2025 19:53:31.184278011 CET3927056999192.168.2.14103.142.27.125
                                              Mar 27, 2025 19:53:31.498800993 CET5699939270103.142.27.125192.168.2.14
                                              Mar 27, 2025 19:53:31.498975992 CET3927056999192.168.2.14103.142.27.125
                                              Mar 27, 2025 19:53:31.499026060 CET3927056999192.168.2.14103.142.27.125
                                              Mar 27, 2025 19:53:31.813290119 CET5699939270103.142.27.125192.168.2.14
                                              Mar 27, 2025 19:53:31.813508034 CET3927056999192.168.2.14103.142.27.125
                                              Mar 27, 2025 19:53:32.127880096 CET5699939270103.142.27.125192.168.2.14
                                              Mar 27, 2025 19:53:38.031970024 CET46540443192.168.2.14185.125.190.26
                                              Mar 27, 2025 19:53:41.504281044 CET3927056999192.168.2.14103.142.27.125
                                              Mar 27, 2025 19:53:41.818994045 CET5699939270103.142.27.125192.168.2.14
                                              Mar 27, 2025 19:53:41.819017887 CET5699939270103.142.27.125192.168.2.14
                                              Mar 27, 2025 19:53:41.819499016 CET3927056999192.168.2.14103.142.27.125
                                              Mar 27, 2025 19:53:57.389920950 CET5699939270103.142.27.125192.168.2.14
                                              Mar 27, 2025 19:53:57.390135050 CET3927056999192.168.2.14103.142.27.125
                                              Mar 27, 2025 19:54:07.982749939 CET46540443192.168.2.14185.125.190.26
                                              Mar 27, 2025 19:54:12.707385063 CET5699939270103.142.27.125192.168.2.14
                                              Mar 27, 2025 19:54:12.707443953 CET3927056999192.168.2.14103.142.27.125
                                              Mar 27, 2025 19:54:28.023107052 CET5699939270103.142.27.125192.168.2.14
                                              Mar 27, 2025 19:54:28.023236990 CET3927056999192.168.2.14103.142.27.125
                                              Mar 27, 2025 19:54:41.869477987 CET3927056999192.168.2.14103.142.27.125
                                              Mar 27, 2025 19:54:42.183867931 CET5699939270103.142.27.125192.168.2.14
                                              Mar 27, 2025 19:54:42.184102058 CET3927056999192.168.2.14103.142.27.125
                                              Mar 27, 2025 19:54:57.547049999 CET5699939270103.142.27.125192.168.2.14
                                              Mar 27, 2025 19:54:57.547209024 CET3927056999192.168.2.14103.142.27.125
                                              Mar 27, 2025 19:55:12.863071918 CET5699939270103.142.27.125192.168.2.14
                                              Mar 27, 2025 19:55:12.863264084 CET3927056999192.168.2.14103.142.27.125
                                              Mar 27, 2025 19:55:28.179083109 CET5699939270103.142.27.125192.168.2.14
                                              Mar 27, 2025 19:55:28.179228067 CET3927056999192.168.2.14103.142.27.125
                                              TimestampSource PortDest PortSource IPDest IP
                                              Mar 27, 2025 19:53:30.082532883 CET3332953192.168.2.148.8.8.8
                                              Mar 27, 2025 19:53:30.165497065 CET53333298.8.8.8192.168.2.14
                                              TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                              Mar 27, 2025 19:53:30.082532883 CET192.168.2.148.8.8.80xeacbStandard query (0)longvusro.comA (IP address)IN (0x0001)false
                                              TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                              Mar 27, 2025 19:53:30.165497065 CET8.8.8.8192.168.2.140xeacbNo error (0)longvusro.com103.142.27.125A (IP address)IN (0x0001)false

                                              System Behavior

                                              Start time (UTC):18:53:29
                                              Start date (UTC):27/03/2025
                                              Path:/tmp/x86.elf
                                              Arguments:/tmp/x86.elf
                                              File size:72392 bytes
                                              MD5 hash:c28a6183b0872843f4fcd53473d9f207

                                              Start time (UTC):18:53:29
                                              Start date (UTC):27/03/2025
                                              Path:/tmp/x86.elf
                                              Arguments:-
                                              File size:72392 bytes
                                              MD5 hash:c28a6183b0872843f4fcd53473d9f207

                                              Start time (UTC):18:53:29
                                              Start date (UTC):27/03/2025
                                              Path:/tmp/x86.elf
                                              Arguments:-
                                              File size:72392 bytes
                                              MD5 hash:c28a6183b0872843f4fcd53473d9f207