Edit tour

Linux Analysis Report
bimbo-arm5.elf

Overview

General Information

Sample name:bimbo-arm5.elf
Analysis ID:1650886
MD5:f16855dced5f63bef1a367ea0ab056ff
SHA1:fd863c3137aa8491be3c1502fccad0ef4ddaa60c
SHA256:874549d31770071e443e974bf095562ce4a0069b3254e576e229024b39edca6a
Tags:elfuser-abuse_ch
Infos:

Detection

Score:48
Range:0 - 100

Signatures

Multi AV Scanner detection for submitted file
Executes the "rm" command used to delete files or directories
Sample has stripped symbol table
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
Joe Sandbox version:42.0.0 Malachite
Analysis ID:1650886
Start date and time:2025-03-28 06:58:23 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 10m 55s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:bimbo-arm5.elf
Detection:MAL
Classification:mal48.linELF@0/0@0/0
Cookbook Comments:
  • Analysis time extended to 480s due to sleep detection in submitted sample
  • Max analysis timeout: 600s exceeded, the analysis took too long
Command:/tmp/bimbo-arm5.elf
PID:6227
Exit Code:255
Exit Code Info:
Killed:False
Standard Output:

Standard Error:/lib/ld-uClibc.so.0: No such file or directory
  • system is lnxubuntu20
  • bimbo-arm5.elf (PID: 6227, Parent: 6149, MD5: 5ebfcae4fe2471fcc5695c2394773ff1) Arguments: /tmp/bimbo-arm5.elf
  • dash New Fork (PID: 6233, Parent: 4334)
  • rm (PID: 6233, Parent: 4334, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.e54azoWNYQ /tmp/tmp.cCvRFsvgFx /tmp/tmp.FECCFer7zC
  • dash New Fork (PID: 6234, Parent: 4334)
  • cat (PID: 6234, Parent: 4334, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /tmp/tmp.e54azoWNYQ
  • dash New Fork (PID: 6235, Parent: 4334)
  • head (PID: 6235, Parent: 4334, MD5: fd96a67145172477dd57131396fc9608) Arguments: head -n 10
  • dash New Fork (PID: 6236, Parent: 4334)
  • tr (PID: 6236, Parent: 4334, MD5: fbd1402dd9f72d8ebfff00ce7c3a7bb5) Arguments: tr -d \\000-\\011\\013\\014\\016-\\037
  • dash New Fork (PID: 6237, Parent: 4334)
  • cut (PID: 6237, Parent: 4334, MD5: d8ed0ea8f22c0de0f8692d4d9f1759d3) Arguments: cut -c -80
  • dash New Fork (PID: 6238, Parent: 4334)
  • cat (PID: 6238, Parent: 4334, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /tmp/tmp.e54azoWNYQ
  • dash New Fork (PID: 6239, Parent: 4334)
  • head (PID: 6239, Parent: 4334, MD5: fd96a67145172477dd57131396fc9608) Arguments: head -n 10
  • dash New Fork (PID: 6240, Parent: 4334)
  • tr (PID: 6240, Parent: 4334, MD5: fbd1402dd9f72d8ebfff00ce7c3a7bb5) Arguments: tr -d \\000-\\011\\013\\014\\016-\\037
  • dash New Fork (PID: 6241, Parent: 4334)
  • cut (PID: 6241, Parent: 4334, MD5: d8ed0ea8f22c0de0f8692d4d9f1759d3) Arguments: cut -c -80
  • dash New Fork (PID: 6242, Parent: 4334)
  • rm (PID: 6242, Parent: 4334, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.e54azoWNYQ /tmp/tmp.cCvRFsvgFx /tmp/tmp.FECCFer7zC
  • cleanup
No yara matches
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: bimbo-arm5.elfVirustotal: Detection: 34%Perma Link
Source: bimbo-arm5.elfReversingLabs: Detection: 38%
Source: unknownHTTPS traffic detected: 54.171.230.55:443 -> 192.168.2.23:33606 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: bimbo-arm5.elfString found in binary or memory: http://154.213.189.145/icy.sh
Source: bimbo-arm5.elfString found in binary or memory: http://schemas.xmlsoap.org/soap/encoding/
Source: bimbo-arm5.elfString found in binary or memory: http://schemas.xmlsoap.org/soap/envelope/
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 33606
Source: unknownNetwork traffic detected: HTTP traffic on port 33606 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
Source: unknownHTTPS traffic detected: 54.171.230.55:443 -> 192.168.2.23:33606 version: TLS 1.2
Source: ELF static info symbol of initial sample.symtab present: no
Source: classification engineClassification label: mal48.linELF@0/0@0/0
Source: /usr/bin/dash (PID: 6233)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.e54azoWNYQ /tmp/tmp.cCvRFsvgFx /tmp/tmp.FECCFer7zCJump to behavior
Source: /usr/bin/dash (PID: 6242)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.e54azoWNYQ /tmp/tmp.cCvRFsvgFx /tmp/tmp.FECCFer7zCJump to behavior
Source: /tmp/bimbo-arm5.elf (PID: 6227)Queries kernel information via 'uname': Jump to behavior
Source: bimbo-arm5.elf, 6227.1.00007ffc115fa000.00007ffc1161b000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-arm/tmp/bimbo-arm5.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/bimbo-arm5.elf
Source: bimbo-arm5.elf, 6227.1.000055b0be133000.000055b0be261000.rw-.sdmpBinary or memory string: U!/etc/qemu-binfmt/arm
Source: bimbo-arm5.elf, 6227.1.00007ffc115fa000.00007ffc1161b000.rw-.sdmpBinary or memory string: qemu: %s: %s
Source: bimbo-arm5.elf, 6227.1.00007ffc115fa000.00007ffc1161b000.rw-.sdmpBinary or memory string: leqemu: %s: %s
Source: bimbo-arm5.elf, 6227.1.000055b0be133000.000055b0be261000.rw-.sdmpBinary or memory string: Urg.qemu.gdb.arm.sys.regs">
Source: bimbo-arm5.elf, 6227.1.000055b0be133000.000055b0be261000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/arm
Source: bimbo-arm5.elf, 6227.1.00007ffc115fa000.00007ffc1161b000.rw-.sdmpBinary or memory string: /usr/bin/qemu-arm
Source: bimbo-arm5.elf, 6227.1.000055b0be133000.000055b0be261000.rw-.sdmpBinary or memory string: rg.qemu.gdb.arm.sys.regs">
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
File Deletion
OS Credential Dumping11
Security Software Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1650886 Sample: bimbo-arm5.elf Startdate: 28/03/2025 Architecture: LINUX Score: 48 14 109.202.202.202, 80 INIT7CH Switzerland 2->14 16 91.189.91.42, 443 CANONICAL-ASGB United Kingdom 2->16 18 2 other IPs or domains 2->18 20 Multi AV Scanner detection for submitted file 2->20 6 dash rm 2->6         started        8 dash cut 2->8         started        10 dash tr 2->10         started        12 8 other processes 2->12 signatures3 process4

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
bimbo-arm5.elf34%VirustotalBrowse
bimbo-arm5.elf39%ReversingLabsLinux.Trojan.Mirai
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

No contacted domains info
NameSourceMaliciousAntivirus DetectionReputation
http://154.213.189.145/icy.shbimbo-arm5.elffalse
    high
    http://schemas.xmlsoap.org/soap/encoding/bimbo-arm5.elffalse
      high
      http://schemas.xmlsoap.org/soap/envelope/bimbo-arm5.elffalse
        high
        • No. of IPs < 25%
        • 25% < No. of IPs < 50%
        • 50% < No. of IPs < 75%
        • 75% < No. of IPs
        IPDomainCountryFlagASNASN NameMalicious
        54.171.230.55
        unknownUnited States
        16509AMAZON-02USfalse
        109.202.202.202
        unknownSwitzerland
        13030INIT7CHfalse
        91.189.91.43
        unknownUnited Kingdom
        41231CANONICAL-ASGBfalse
        91.189.91.42
        unknownUnited Kingdom
        41231CANONICAL-ASGBfalse
        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
        54.171.230.55na.elfGet hashmaliciousPrometeiBrowse
          na.elfGet hashmaliciousPrometeiBrowse
            meowmips.elfGet hashmaliciousMiraiBrowse
              sync.mips.elfGet hashmaliciousUnknownBrowse
                na.elfGet hashmaliciousPrometeiBrowse
                  Okami.arm6.elfGet hashmaliciousGafgyt, MiraiBrowse
                    na.elfGet hashmaliciousPrometeiBrowse
                      na.elfGet hashmaliciousPrometeiBrowse
                        arm5.elfGet hashmaliciousUnknownBrowse
                          na.elfGet hashmaliciousPrometeiBrowse
                            109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
                            • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
                            91.189.91.43na.elfGet hashmaliciousPrometeiBrowse
                              sshd.elfGet hashmaliciousUnknownBrowse
                                na.elfGet hashmaliciousPrometeiBrowse
                                  na.elfGet hashmaliciousPrometeiBrowse
                                    na.elfGet hashmaliciousPrometeiBrowse
                                      .i.elfGet hashmaliciousUnknownBrowse
                                        na.elfGet hashmaliciousPrometeiBrowse
                                          na.elfGet hashmaliciousPrometeiBrowse
                                            .i.elfGet hashmaliciousUnknownBrowse
                                              na.elfGet hashmaliciousPrometeiBrowse
                                                91.189.91.42na.elfGet hashmaliciousPrometeiBrowse
                                                  sshd.elfGet hashmaliciousUnknownBrowse
                                                    na.elfGet hashmaliciousPrometeiBrowse
                                                      na.elfGet hashmaliciousPrometeiBrowse
                                                        na.elfGet hashmaliciousPrometeiBrowse
                                                          .i.elfGet hashmaliciousUnknownBrowse
                                                            na.elfGet hashmaliciousPrometeiBrowse
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                                .i.elfGet hashmaliciousUnknownBrowse
                                                                  na.elfGet hashmaliciousPrometeiBrowse
                                                                    No context
                                                                    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                    CANONICAL-ASGBna.elfGet hashmaliciousPrometeiBrowse
                                                                    • 91.189.91.42
                                                                    sshd.elfGet hashmaliciousUnknownBrowse
                                                                    • 91.189.91.42
                                                                    na.elfGet hashmaliciousPrometeiBrowse
                                                                    • 91.189.91.42
                                                                    na.elfGet hashmaliciousPrometeiBrowse
                                                                    • 91.189.91.42
                                                                    na.elfGet hashmaliciousPrometeiBrowse
                                                                    • 91.189.91.42
                                                                    .i.elfGet hashmaliciousUnknownBrowse
                                                                    • 91.189.91.42
                                                                    na.elfGet hashmaliciousPrometeiBrowse
                                                                    • 91.189.91.42
                                                                    na.elfGet hashmaliciousPrometeiBrowse
                                                                    • 91.189.91.42
                                                                    .i.elfGet hashmaliciousUnknownBrowse
                                                                    • 91.189.91.42
                                                                    na.elfGet hashmaliciousPrometeiBrowse
                                                                    • 91.189.91.42
                                                                    CANONICAL-ASGBna.elfGet hashmaliciousPrometeiBrowse
                                                                    • 91.189.91.42
                                                                    sshd.elfGet hashmaliciousUnknownBrowse
                                                                    • 91.189.91.42
                                                                    na.elfGet hashmaliciousPrometeiBrowse
                                                                    • 91.189.91.42
                                                                    na.elfGet hashmaliciousPrometeiBrowse
                                                                    • 91.189.91.42
                                                                    na.elfGet hashmaliciousPrometeiBrowse
                                                                    • 91.189.91.42
                                                                    .i.elfGet hashmaliciousUnknownBrowse
                                                                    • 91.189.91.42
                                                                    na.elfGet hashmaliciousPrometeiBrowse
                                                                    • 91.189.91.42
                                                                    na.elfGet hashmaliciousPrometeiBrowse
                                                                    • 91.189.91.42
                                                                    .i.elfGet hashmaliciousUnknownBrowse
                                                                    • 91.189.91.42
                                                                    na.elfGet hashmaliciousPrometeiBrowse
                                                                    • 91.189.91.42
                                                                    AMAZON-02USbimbo-spc.elfGet hashmaliciousUnknownBrowse
                                                                    • 50.112.169.8
                                                                    bimbo-mips.elfGet hashmaliciousUnknownBrowse
                                                                    • 54.75.118.133
                                                                    na.elfGet hashmaliciousPrometeiBrowse
                                                                    • 54.169.144.97
                                                                    na.elfGet hashmaliciousPrometeiBrowse
                                                                    • 54.171.230.55
                                                                    na.elfGet hashmaliciousPrometeiBrowse
                                                                    • 54.169.144.97
                                                                    na.elfGet hashmaliciousPrometeiBrowse
                                                                    • 54.169.144.97
                                                                    .i.elfGet hashmaliciousUnknownBrowse
                                                                    • 34.249.145.219
                                                                    na.elfGet hashmaliciousPrometeiBrowse
                                                                    • 54.169.144.97
                                                                    na.elfGet hashmaliciousPrometeiBrowse
                                                                    • 54.170.242.139
                                                                    na.elfGet hashmaliciousPrometeiBrowse
                                                                    • 54.170.242.139
                                                                    INIT7CHna.elfGet hashmaliciousPrometeiBrowse
                                                                    • 109.202.202.202
                                                                    sshd.elfGet hashmaliciousUnknownBrowse
                                                                    • 109.202.202.202
                                                                    na.elfGet hashmaliciousPrometeiBrowse
                                                                    • 109.202.202.202
                                                                    na.elfGet hashmaliciousPrometeiBrowse
                                                                    • 109.202.202.202
                                                                    na.elfGet hashmaliciousPrometeiBrowse
                                                                    • 109.202.202.202
                                                                    .i.elfGet hashmaliciousUnknownBrowse
                                                                    • 109.202.202.202
                                                                    na.elfGet hashmaliciousPrometeiBrowse
                                                                    • 109.202.202.202
                                                                    na.elfGet hashmaliciousPrometeiBrowse
                                                                    • 109.202.202.202
                                                                    .i.elfGet hashmaliciousUnknownBrowse
                                                                    • 109.202.202.202
                                                                    na.elfGet hashmaliciousPrometeiBrowse
                                                                    • 109.202.202.202
                                                                    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                    fb4726d465c5f28b84cd6d14cedd13a7bimbo-mips.elfGet hashmaliciousUnknownBrowse
                                                                    • 54.171.230.55
                                                                    na.elfGet hashmaliciousPrometeiBrowse
                                                                    • 54.171.230.55
                                                                    na.elfGet hashmaliciousPrometeiBrowse
                                                                    • 54.171.230.55
                                                                    meowmips.elfGet hashmaliciousMiraiBrowse
                                                                    • 54.171.230.55
                                                                    sync.mips.elfGet hashmaliciousUnknownBrowse
                                                                    • 54.171.230.55
                                                                    bin.sh.elfGet hashmaliciousMiraiBrowse
                                                                    • 54.171.230.55
                                                                    Okami.arm6.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                    • 54.171.230.55
                                                                    Okami.mpsl.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                    • 54.171.230.55
                                                                    sshd.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                    • 54.171.230.55
                                                                    na.elfGet hashmaliciousPrometeiBrowse
                                                                    • 54.171.230.55
                                                                    No context
                                                                    No created / dropped files found
                                                                    File type:ELF 32-bit LSB executable, ARM, version 1 (ARM), dynamically linked, interpreter /lib/ld-uClibc.so.0, stripped
                                                                    Entropy (8bit):6.214912393221814
                                                                    TrID:
                                                                    • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                                                    File name:bimbo-arm5.elf
                                                                    File size:38'104 bytes
                                                                    MD5:f16855dced5f63bef1a367ea0ab056ff
                                                                    SHA1:fd863c3137aa8491be3c1502fccad0ef4ddaa60c
                                                                    SHA256:874549d31770071e443e974bf095562ce4a0069b3254e576e229024b39edca6a
                                                                    SHA512:8a1713fd355992d306ec03035bc8395b3decf4d630cb714c79f6beb09ef84d7f2f745f9beb3b26c24d25107d74bb742d97d2751dabdb149467f3a3fa3ffa9118
                                                                    SSDEEP:768:AVd32ltmLgm8WwqUAMg86nHTtG25q22X3PPW/6Rv7fpiLm/6K/gABo:ALytvbqUu86nI25q7X/u/7m/vgAO
                                                                    TLSH:97033B96BCD29E5AC5E021BABF6E91BD3310A3DCD2CB37038D1457143ACA51E5DB7A04
                                                                    File Content Preview:.ELF...a..........(.....8...4...........4. ...(.........4...4...4...................................................................................................................................................Q.td............................/lib/ld-uCl

                                                                    ELF header

                                                                    Class:ELF32
                                                                    Data:2's complement, little endian
                                                                    Version:1 (current)
                                                                    Machine:ARM
                                                                    Version Number:0x1
                                                                    Type:EXEC (Executable file)
                                                                    OS/ABI:ARM - ABI
                                                                    ABI Version:0
                                                                    Entry Point Address:0x8e38
                                                                    Flags:0x2
                                                                    ELF Header Size:52
                                                                    Program Header Offset:52
                                                                    Program Header Size:32
                                                                    Number of Program Headers:6
                                                                    Section Header Offset:37384
                                                                    Section Header Size:40
                                                                    Number of Section Headers:18
                                                                    Header String Table Index:17
                                                                    NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                                    NULL0x00x00x00x00x0000
                                                                    .interpPROGBITS0x80f40xf40x140x00x2A001
                                                                    .hashHASH0x81080x1080x2200x40x2A304
                                                                    .dynsymDYNSYM0x83280x3280x4300x100x2A414
                                                                    .dynstrSTRTAB0x87580x7580x2250x00x2A001
                                                                    .rel.pltREL0x89800x9800x1780x80x2A374
                                                                    .initPROGBITS0x8af80xaf80x180x00x6AX004
                                                                    .pltPROGBITS0x8b100xb100x2480x40x6AX004
                                                                    .textPROGBITS0x8d580xd580x746c0x00x6AX004
                                                                    .finiPROGBITS0x101c40x81c40x140x00x6AX004
                                                                    .rodataPROGBITS0x101d80x81d80xde40x00x2A004
                                                                    .ctorsPROGBITS0x190000x90000x80x00x3WA004
                                                                    .dtorsPROGBITS0x190080x90080x80x00x3WA004
                                                                    .dynamicDYNAMIC0x190140x90140x980x80x3WA404
                                                                    .gotPROGBITS0x190ac0x90ac0xc80x40x3WA004
                                                                    .dataPROGBITS0x191740x91740x200x00x3WA004
                                                                    .bssNOBITS0x191940x91940x3400x00x3WA004
                                                                    .shstrtabSTRTAB0x00x91940x730x00x0001
                                                                    TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                                    PHDR0x340x80340x80340xc00xc02.16380x5R E0x4
                                                                    INTERP0xf40x80f40x80f40x140x143.68420x4R 0x1/lib/ld-uClibc.so.0.interp
                                                                    LOAD0x00x80000x80000x8fbc0x8fbc6.28290x5R E0x8000.interp .hash .dynsym .dynstr .rel.plt .init .plt .text .fini .rodata
                                                                    LOAD0x90000x190000x190000x1940x4d42.25780x6RW 0x8000.ctors .dtors .dynamic .got .data .bss
                                                                    DYNAMIC0x90140x190140x190140x980x981.89900x6RW 0x4.dynamic
                                                                    GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
                                                                    TypeMetaValueTag
                                                                    DT_NEEDEDsharedliblibc.so.00x1
                                                                    DT_INITvalue0x8af80xc
                                                                    DT_FINIvalue0x101c40xd
                                                                    DT_HASHvalue0x81080x4
                                                                    DT_STRTABvalue0x87580x5
                                                                    DT_SYMTABvalue0x83280x6
                                                                    DT_STRSZbytes5490xa
                                                                    DT_SYMENTbytes160xb
                                                                    DT_DEBUGvalue0x00x15
                                                                    DT_PLTGOTvalue0x190ac0x3
                                                                    DT_PLTRELSZbytes3760x2
                                                                    DT_PLTRELpltrelDT_REL0x14
                                                                    DT_JMPRELvalue0x89800x17
                                                                    DT_NULLvalue0x00x0
                                                                    NameVersion Info NameVersion Info File NameSection NameValueSizeSymbol TypeSymbol BindSymbol VisibilityNdx
                                                                    .dynsym0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                                                    __aeabi_idiv0.dynsym0x101844FUNC<unknown>DEFAULT8
                                                                    __aeabi_ldiv0.dynsym0x101844FUNC<unknown>DEFAULT8
                                                                    __aeabi_uidiv.dynsym0xfec40FUNC<unknown>DEFAULT8
                                                                    __aeabi_uidivmod.dynsym0xffbc24FUNC<unknown>DEFAULT8
                                                                    __bss_end__.dynsym0x194d40NOTYPE<unknown>DEFAULTSHN_ABS
                                                                    __bss_start.dynsym0x191940NOTYPE<unknown>DEFAULTSHN_ABS
                                                                    __bss_start__.dynsym0x191940NOTYPE<unknown>DEFAULTSHN_ABS
                                                                    __data_start.dynsym0x191740NOTYPE<unknown>DEFAULT17
                                                                    __div0.dynsym0x101844FUNC<unknown>DEFAULT8
                                                                    __end__.dynsym0x194d40NOTYPE<unknown>DEFAULTSHN_ABS
                                                                    __errno_location.dynsym0x8cd432FUNC<unknown>DEFAULTSHN_UNDEF
                                                                    __modsi3.dynsym0x100a0228FUNC<unknown>DEFAULT8
                                                                    __uClibc_main.dynsym0x8c8c488FUNC<unknown>DEFAULTSHN_UNDEF
                                                                    __udivsi3.dynsym0xfec4248FUNC<unknown>DEFAULT8
                                                                    __umodsi3.dynsym0xffd4204FUNC<unknown>DEFAULT8
                                                                    _bss_end__.dynsym0x194d40NOTYPE<unknown>DEFAULTSHN_ABS
                                                                    _edata.dynsym0x191940NOTYPE<unknown>DEFAULTSHN_ABS
                                                                    _end.dynsym0x194d40NOTYPE<unknown>DEFAULTSHN_ABS
                                                                    _start.dynsym0x8e3880FUNC<unknown>DEFAULT8
                                                                    abort.dynsym0x8bf0352FUNC<unknown>DEFAULTSHN_UNDEF
                                                                    accept.dynsym0x8bfc44FUNC<unknown>DEFAULTSHN_UNDEF
                                                                    bind.dynsym0x8c2c44FUNC<unknown>DEFAULTSHN_UNDEF
                                                                    calloc.dynsym0x8c0888FUNC<unknown>DEFAULTSHN_UNDEF
                                                                    clock.dynsym0x8cf852FUNC<unknown>DEFAULTSHN_UNDEF
                                                                    close.dynsym0x8d2844FUNC<unknown>DEFAULTSHN_UNDEF
                                                                    closedir.dynsym0x8d10196FUNC<unknown>DEFAULTSHN_UNDEF
                                                                    connect.dynsym0x8b4844FUNC<unknown>DEFAULTSHN_UNDEF
                                                                    exit.dynsym0x8ce0172FUNC<unknown>DEFAULTSHN_UNDEF
                                                                    fcntl.dynsym0x8d1c116FUNC<unknown>DEFAULTSHN_UNDEF
                                                                    fork.dynsym0x8c8044FUNC<unknown>DEFAULTSHN_UNDEF
                                                                    free.dynsym0x8d34288FUNC<unknown>DEFAULTSHN_UNDEF
                                                                    getpid.dynsym0x8b6c44FUNC<unknown>DEFAULTSHN_UNDEF
                                                                    getppid.dynsym0x8ca444FUNC<unknown>DEFAULTSHN_UNDEF
                                                                    getsockname.dynsym0x8d4c44FUNC<unknown>DEFAULTSHN_UNDEF
                                                                    getsockopt.dynsym0x8cc848FUNC<unknown>DEFAULTSHN_UNDEF
                                                                    inet_addr.dynsym0x8c3836FUNC<unknown>DEFAULTSHN_UNDEF
                                                                    ioctl.dynsym0x8b3080FUNC<unknown>DEFAULTSHN_UNDEF
                                                                    kill.dynsym0x8c2044FUNC<unknown>DEFAULTSHN_UNDEF
                                                                    malloc.dynsym0x8b90400FUNC<unknown>DEFAULTSHN_UNDEF
                                                                    memcpy.dynsym0x8b844FUNC<unknown>DEFAULTSHN_UNDEF
                                                                    memmove.dynsym0x8b604FUNC<unknown>DEFAULTSHN_UNDEF
                                                                    memset.dynsym0x0156FUNC<unknown>DEFAULTSHN_UNDEF
                                                                    open.dynsym0x8cec92FUNC<unknown>DEFAULTSHN_UNDEF
                                                                    opendir.dynsym0x8cbc264FUNC<unknown>DEFAULTSHN_UNDEF
                                                                    prctl.dynsym0x8b7848FUNC<unknown>DEFAULTSHN_UNDEF
                                                                    read.dynsym0x8c5c44FUNC<unknown>DEFAULTSHN_UNDEF
                                                                    readdir.dynsym0x8bcc224FUNC<unknown>DEFAULTSHN_UNDEF
                                                                    readlink.dynsym0x044FUNC<unknown>DEFAULTSHN_UNDEF
                                                                    realloc.dynsym0x8c74312FUNC<unknown>DEFAULTSHN_UNDEF
                                                                    recv.dynsym0x8b3c44FUNC<unknown>DEFAULTSHN_UNDEF
                                                                    recvfrom.dynsym0x8ba852FUNC<unknown>DEFAULTSHN_UNDEF
                                                                    select.dynsym0x8bc048FUNC<unknown>DEFAULTSHN_UNDEF
                                                                    send.dynsym0x8be444FUNC<unknown>DEFAULTSHN_UNDEF
                                                                    sendto.dynsym0x8c6852FUNC<unknown>DEFAULTSHN_UNDEF
                                                                    setsid.dynsym0x8d0444FUNC<unknown>DEFAULTSHN_UNDEF
                                                                    setsockopt.dynsym0x8c4448FUNC<unknown>DEFAULTSHN_UNDEF
                                                                    sigaddset.dynsym0x8bd848FUNC<unknown>DEFAULTSHN_UNDEF
                                                                    sigemptyset.dynsym0x8b5424FUNC<unknown>DEFAULTSHN_UNDEF
                                                                    signal.dynsym0x8c50200FUNC<unknown>DEFAULTSHN_UNDEF
                                                                    sigprocmask.dynsym0x8d4084FUNC<unknown>DEFAULTSHN_UNDEF
                                                                    sleep.dynsym0x8b9c420FUNC<unknown>DEFAULTSHN_UNDEF
                                                                    socket.dynsym0x8bb444FUNC<unknown>DEFAULTSHN_UNDEF
                                                                    srand.dynsym0x8c98148FUNC<unknown>DEFAULTSHN_UNDEF
                                                                    strcpy.dynsym0x8b2428FUNC<unknown>DEFAULTSHN_UNDEF
                                                                    time.dynsym0x8cb044FUNC<unknown>DEFAULTSHN_UNDEF
                                                                    write.dynsym0x8c1444FUNC<unknown>DEFAULTSHN_UNDEF

                                                                    Download Network PCAP: filteredfull

                                                                    • Total Packets: 21
                                                                    • 443 (HTTPS)
                                                                    • 80 (HTTP)
                                                                    TimestampSource PortDest PortSource IPDest IP
                                                                    Mar 28, 2025 06:59:12.726788998 CET33606443192.168.2.2354.171.230.55
                                                                    Mar 28, 2025 06:59:12.957456112 CET4433360654.171.230.55192.168.2.23
                                                                    Mar 28, 2025 06:59:15.542387009 CET42836443192.168.2.2391.189.91.43
                                                                    Mar 28, 2025 06:59:16.310467958 CET4251680192.168.2.23109.202.202.202
                                                                    Mar 28, 2025 06:59:16.643731117 CET4433360654.171.230.55192.168.2.23
                                                                    Mar 28, 2025 06:59:16.643793106 CET4433360654.171.230.55192.168.2.23
                                                                    Mar 28, 2025 06:59:16.643824100 CET4433360654.171.230.55192.168.2.23
                                                                    Mar 28, 2025 06:59:16.643855095 CET4433360654.171.230.55192.168.2.23
                                                                    Mar 28, 2025 06:59:16.643883944 CET4433360654.171.230.55192.168.2.23
                                                                    Mar 28, 2025 06:59:16.643918037 CET4433360654.171.230.55192.168.2.23
                                                                    Mar 28, 2025 06:59:16.644104958 CET33606443192.168.2.2354.171.230.55
                                                                    Mar 28, 2025 06:59:16.644104958 CET33606443192.168.2.2354.171.230.55
                                                                    Mar 28, 2025 06:59:16.644104958 CET33606443192.168.2.2354.171.230.55
                                                                    Mar 28, 2025 06:59:16.644104958 CET33606443192.168.2.2354.171.230.55
                                                                    Mar 28, 2025 06:59:16.644104958 CET33606443192.168.2.2354.171.230.55
                                                                    Mar 28, 2025 06:59:16.644104958 CET33606443192.168.2.2354.171.230.55
                                                                    Mar 28, 2025 06:59:16.645289898 CET33606443192.168.2.2354.171.230.55
                                                                    Mar 28, 2025 06:59:16.876789093 CET4433360654.171.230.55192.168.2.23
                                                                    Mar 28, 2025 06:59:16.956070900 CET4433360654.171.230.55192.168.2.23
                                                                    Mar 28, 2025 06:59:16.956167936 CET33606443192.168.2.2354.171.230.55
                                                                    Mar 28, 2025 06:59:16.956507921 CET33606443192.168.2.2354.171.230.55
                                                                    Mar 28, 2025 06:59:17.126115084 CET4433360654.171.230.55192.168.2.23
                                                                    Mar 28, 2025 06:59:17.126176119 CET4433360654.171.230.55192.168.2.23
                                                                    Mar 28, 2025 06:59:17.126230001 CET33606443192.168.2.2354.171.230.55
                                                                    Mar 28, 2025 06:59:17.126230001 CET33606443192.168.2.2354.171.230.55
                                                                    Mar 28, 2025 06:59:17.127938032 CET33606443192.168.2.2354.171.230.55
                                                                    Mar 28, 2025 06:59:17.436100960 CET4433360654.171.230.55192.168.2.23
                                                                    Mar 28, 2025 06:59:17.527303934 CET4433360654.171.230.55192.168.2.23
                                                                    Mar 28, 2025 06:59:17.527360916 CET4433360654.171.230.55192.168.2.23
                                                                    Mar 28, 2025 06:59:17.527550936 CET33606443192.168.2.2354.171.230.55
                                                                    Mar 28, 2025 06:59:17.527550936 CET33606443192.168.2.2354.171.230.55
                                                                    Mar 28, 2025 06:59:30.644656897 CET43928443192.168.2.2391.189.91.42
                                                                    Mar 28, 2025 06:59:42.930478096 CET42836443192.168.2.2391.189.91.43
                                                                    Mar 28, 2025 06:59:47.025804996 CET4251680192.168.2.23109.202.202.202
                                                                    Mar 28, 2025 07:00:11.598753929 CET43928443192.168.2.2391.189.91.42
                                                                    TimestampSource IPSource PortDest IPDest PortSubjectIssuerNot BeforeNot AfterJA3 SSL Client FingerprintJA3 SSL Client Digest
                                                                    Mar 28, 2025 06:59:16.643918037 CET54.171.230.55443192.168.2.2333606CN=motd.ubuntu.com CN=R10, O=Let's Encrypt, C=USCN=R10, O=Let's Encrypt, C=US CN=ISRG Root X1, O=Internet Security Research Group, C=USSat Mar 22 09:18:05 CET 2025 Wed Mar 13 01:00:00 CET 2024Fri Jun 20 10:18:04 CEST 2025 Sat Mar 13 00:59:59 CET 2027771,4866-4867-4865-49196-49200-163-159-52393-52392-52394-49327-49325-49315-49311-49245-49249-49239-49235-49195-49199-162-158-49326-49324-49314-49310-49244-49248-49238-49234-49188-49192-107-106-49267-49271-196-195-49187-49191-103-64-49266-49270-190-189-49162-49172-57-56-136-135-49161-49171-51-50-69-68-157-49313-49309-49233-156-49312-49308-49232-61-192-60-186-53-132-47-65-255,0-11-10-35-22-23-13-43-45-51,29-23-30-25-24,0-1-2fb4726d465c5f28b84cd6d14cedd13a7
                                                                    CN=R10, O=Let's Encrypt, C=USCN=ISRG Root X1, O=Internet Security Research Group, C=USWed Mar 13 01:00:00 CET 2024Sat Mar 13 00:59:59 CET 2027

                                                                    System Behavior

                                                                    Start time (UTC):05:59:13
                                                                    Start date (UTC):28/03/2025
                                                                    Path:/tmp/bimbo-arm5.elf
                                                                    Arguments:/tmp/bimbo-arm5.elf
                                                                    File size:4956856 bytes
                                                                    MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                                    Start time (UTC):05:59:16
                                                                    Start date (UTC):28/03/2025
                                                                    Path:/usr/bin/dash
                                                                    Arguments:-
                                                                    File size:129816 bytes
                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                    Start time (UTC):05:59:16
                                                                    Start date (UTC):28/03/2025
                                                                    Path:/usr/bin/rm
                                                                    Arguments:rm -f /tmp/tmp.e54azoWNYQ /tmp/tmp.cCvRFsvgFx /tmp/tmp.FECCFer7zC
                                                                    File size:72056 bytes
                                                                    MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                                                    Start time (UTC):05:59:16
                                                                    Start date (UTC):28/03/2025
                                                                    Path:/usr/bin/dash
                                                                    Arguments:-
                                                                    File size:129816 bytes
                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                    Start time (UTC):05:59:16
                                                                    Start date (UTC):28/03/2025
                                                                    Path:/usr/bin/cat
                                                                    Arguments:cat /tmp/tmp.e54azoWNYQ
                                                                    File size:43416 bytes
                                                                    MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

                                                                    Start time (UTC):05:59:16
                                                                    Start date (UTC):28/03/2025
                                                                    Path:/usr/bin/dash
                                                                    Arguments:-
                                                                    File size:129816 bytes
                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                    Start time (UTC):05:59:16
                                                                    Start date (UTC):28/03/2025
                                                                    Path:/usr/bin/head
                                                                    Arguments:head -n 10
                                                                    File size:47480 bytes
                                                                    MD5 hash:fd96a67145172477dd57131396fc9608

                                                                    Start time (UTC):05:59:16
                                                                    Start date (UTC):28/03/2025
                                                                    Path:/usr/bin/dash
                                                                    Arguments:-
                                                                    File size:129816 bytes
                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                    Start time (UTC):05:59:16
                                                                    Start date (UTC):28/03/2025
                                                                    Path:/usr/bin/tr
                                                                    Arguments:tr -d \\000-\\011\\013\\014\\016-\\037
                                                                    File size:51544 bytes
                                                                    MD5 hash:fbd1402dd9f72d8ebfff00ce7c3a7bb5

                                                                    Start time (UTC):05:59:16
                                                                    Start date (UTC):28/03/2025
                                                                    Path:/usr/bin/dash
                                                                    Arguments:-
                                                                    File size:129816 bytes
                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                    Start time (UTC):05:59:16
                                                                    Start date (UTC):28/03/2025
                                                                    Path:/usr/bin/cut
                                                                    Arguments:cut -c -80
                                                                    File size:47480 bytes
                                                                    MD5 hash:d8ed0ea8f22c0de0f8692d4d9f1759d3

                                                                    Start time (UTC):05:59:16
                                                                    Start date (UTC):28/03/2025
                                                                    Path:/usr/bin/dash
                                                                    Arguments:-
                                                                    File size:129816 bytes
                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                    Start time (UTC):05:59:16
                                                                    Start date (UTC):28/03/2025
                                                                    Path:/usr/bin/cat
                                                                    Arguments:cat /tmp/tmp.e54azoWNYQ
                                                                    File size:43416 bytes
                                                                    MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

                                                                    Start time (UTC):05:59:16
                                                                    Start date (UTC):28/03/2025
                                                                    Path:/usr/bin/dash
                                                                    Arguments:-
                                                                    File size:129816 bytes
                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                    Start time (UTC):05:59:16
                                                                    Start date (UTC):28/03/2025
                                                                    Path:/usr/bin/head
                                                                    Arguments:head -n 10
                                                                    File size:47480 bytes
                                                                    MD5 hash:fd96a67145172477dd57131396fc9608

                                                                    Start time (UTC):05:59:16
                                                                    Start date (UTC):28/03/2025
                                                                    Path:/usr/bin/dash
                                                                    Arguments:-
                                                                    File size:129816 bytes
                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                    Start time (UTC):05:59:16
                                                                    Start date (UTC):28/03/2025
                                                                    Path:/usr/bin/tr
                                                                    Arguments:tr -d \\000-\\011\\013\\014\\016-\\037
                                                                    File size:51544 bytes
                                                                    MD5 hash:fbd1402dd9f72d8ebfff00ce7c3a7bb5

                                                                    Start time (UTC):05:59:16
                                                                    Start date (UTC):28/03/2025
                                                                    Path:/usr/bin/dash
                                                                    Arguments:-
                                                                    File size:129816 bytes
                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                    Start time (UTC):05:59:16
                                                                    Start date (UTC):28/03/2025
                                                                    Path:/usr/bin/cut
                                                                    Arguments:cut -c -80
                                                                    File size:47480 bytes
                                                                    MD5 hash:d8ed0ea8f22c0de0f8692d4d9f1759d3

                                                                    Start time (UTC):05:59:16
                                                                    Start date (UTC):28/03/2025
                                                                    Path:/usr/bin/dash
                                                                    Arguments:-
                                                                    File size:129816 bytes
                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                    Start time (UTC):05:59:16
                                                                    Start date (UTC):28/03/2025
                                                                    Path:/usr/bin/rm
                                                                    Arguments:rm -f /tmp/tmp.e54azoWNYQ /tmp/tmp.cCvRFsvgFx /tmp/tmp.FECCFer7zC
                                                                    File size:72056 bytes
                                                                    MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b