Edit tour

Linux Analysis Report
sshd.elf

Overview

General Information

Sample name:sshd.elf
Analysis ID:1655118
MD5:d1ec7ed13b58335b0efcb5bc3acacd81
SHA1:5a7fea994a4d0ecb2bc36840af1b94e1a87474e7
SHA256:fadd8a607bda25c51415c8bd8facbe52d48f1ff7893f490e3ed9de84c75e6e6e
Tags:elfuser-abuse_ch
Infos:

Detection

Score:56
Range:0 - 100

Signatures

Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Contains symbols related to standard C library sleeps (sometimes used to evade sandboxing)
Executes the "rm" command used to delete files or directories
Sample contains strings that are potentially command strings
Sample has stripped symbol table
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
Joe Sandbox version:42.0.0 Malachite
Analysis ID:1655118
Start date and time:2025-04-03 00:07:28 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 10m 44s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:sshd.elf
Detection:MAL
Classification:mal56.linELF@0/0@0/0
Cookbook Comments:
  • Analysis time extended to 480s due to sleep detection in submitted sample
Command:/tmp/sshd.elf
PID:6203
Exit Code:255
Exit Code Info:
Killed:False
Standard Output:

Standard Error:/lib/ld-linux-armhf.so.3: No such file or directory
  • system is lnxubuntu20
  • sshd.elf (PID: 6203, Parent: 6125, MD5: 5ebfcae4fe2471fcc5695c2394773ff1) Arguments: /tmp/sshd.elf
  • dash New Fork (PID: 6264, Parent: 4334)
  • rm (PID: 6264, Parent: 4334, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.isgEiRYi0f /tmp/tmp.xNeksbbJWk /tmp/tmp.I0iZJmHMtI
  • dash New Fork (PID: 6265, Parent: 4334)
  • rm (PID: 6265, Parent: 4334, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.isgEiRYi0f /tmp/tmp.xNeksbbJWk /tmp/tmp.I0iZJmHMtI
  • cleanup
No yara matches
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: sshd.elfAvira: detected
Source: sshd.elfVirustotal: Detection: 40%Perma Link
Source: sshd.elfReversingLabs: Detection: 30%
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 34.249.145.219
Source: unknownTCP traffic detected without corresponding DNS query: 34.249.145.219
Source: unknownTCP traffic detected without corresponding DNS query: 34.249.145.219
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 34.249.145.219
Source: sshd.elfELF static info symbol of initial sample: freeaddrinfo
Source: sshd.elfELF static info symbol of initial sample: gai_strerror
Source: sshd.elfELF static info symbol of initial sample: getaddrinfo
Source: sshd.elfELF static info symbol of initial sample: getnameinfo
Source: sshd.elfString found in binary or memory: http://www.openssl.org/support/faq.html
Source: sshd.elfString found in binary or memory: http://www.openssl.org/support/faq.htmlmd_rand.c
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39240
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 39240 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
Source: Initial samplePotential command found: ssh server is locked, please try again %dmin after !!!
Source: Initial samplePotential command found: X11 forwarding
Source: Initial samplePotential command found: X11 forwarding disabled in user configuration file.
Source: Initial samplePotential command found: X11 forwarding disabled in server configuration file.
Source: Initial samplePotential command found: X11 display already set.
Source: Initial samplePotential command found: X11 connection requested.
Source: Initial samplePotential command found: X11 connection from %.200s port %d
Source: Initial samplePotential command found: X11 connection rejected because of wrong authentication.
Source: Initial samplePotential command found: X11 rejected %d i%d/o%d
Source: Initial samplePotential command found: X11 closed %d i%d/o%d
Source: Initial samplePotential command found: X11 inet listener
Source: Initial samplePotential command found: X11 connection uses different authentication protocol.
Source: Initial samplePotential command found: X11 auth data does not match fake data.
Source: Initial samplePotential command found: X11 fake_data_len %d != saved_data_len %d
Source: ELF static info symbol of initial sample.symtab present: no
Source: classification engineClassification label: mal56.linELF@0/0@0/0
Source: /usr/bin/dash (PID: 6264)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.isgEiRYi0f /tmp/tmp.xNeksbbJWk /tmp/tmp.I0iZJmHMtIJump to behavior
Source: /usr/bin/dash (PID: 6265)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.isgEiRYi0f /tmp/tmp.xNeksbbJWk /tmp/tmp.I0iZJmHMtIJump to behavior
Source: ELF symbol in initial sampleSymbol name: usleep
Source: /tmp/sshd.elf (PID: 6203)Queries kernel information via 'uname': Jump to behavior
Source: sshd.elf, 6203.1.0000562d7869f000.0000562d787cd000.rw-.sdmpBinary or memory string: ix-Vrg.qemu.gdb.arm.sys.regs">
Source: sshd.elf, 6203.1.00007ffc99df4000.00007ffc99e15000.rw-.sdmpBinary or memory string: qemu: %s: %s
Source: sshd.elf, 6203.1.00007ffc99df4000.00007ffc99e15000.rw-.sdmpBinary or memory string: leqemu: %s: %s
Source: sshd.elf, 6203.1.00007ffc99df4000.00007ffc99e15000.rw-.sdmpBinary or memory string: wx86_64/usr/bin/qemu-arm/tmp/sshd.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/sshd.elf
Source: sshd.elf, 6203.1.0000562d7869f000.0000562d787cd000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/arm
Source: sshd.elf, 6203.1.00007ffc99df4000.00007ffc99e15000.rw-.sdmpBinary or memory string: /usr/bin/qemu-arm
Source: sshd.elf, 6203.1.0000562d7869f000.0000562d787cd000.rw-.sdmpBinary or memory string: rg.qemu.gdb.arm.sys.regs">
Source: sshd.elf, 6203.1.0000562d7869f000.0000562d787cd000.rw-.sdmpBinary or memory string: ckx-VPekx-VPbkx-V!/etc/qemu-binfmt/arm
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid Accounts1
Command and Scripting Interpreter
Path InterceptionPath Interception1
Virtualization/Sandbox Evasion
OS Credential Dumping11
Security Software Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
File Deletion
LSASS Memory1
Virtualization/Sandbox Evasion
Remote Desktop ProtocolData from Removable Media1
Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1655118 Sample: sshd.elf Startdate: 03/04/2025 Architecture: LINUX Score: 56 12 109.202.202.202, 80 INIT7CH Switzerland 2->12 14 91.189.91.42, 443 CANONICAL-ASGB United Kingdom 2->14 16 2 other IPs or domains 2->16 18 Antivirus / Scanner detection for submitted sample 2->18 20 Multi AV Scanner detection for submitted file 2->20 6 dash rm 2->6         started        8 dash rm 2->8         started        10 sshd.elf 2->10         started        signatures3 process4

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
sshd.elf41%VirustotalBrowse
sshd.elf31%ReversingLabsLinux.Trojan.SSHDoor
sshd.elf100%AviraLINUX/GM.SSHDoor.GB
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

No contacted domains info
NameSourceMaliciousAntivirus DetectionReputation
http://www.openssl.org/support/faq.htmlmd_rand.csshd.elffalse
    high
    http://www.openssl.org/support/faq.htmlsshd.elffalse
      high
      • No. of IPs < 25%
      • 25% < No. of IPs < 50%
      • 50% < No. of IPs < 75%
      • 75% < No. of IPs
      IPDomainCountryFlagASNASN NameMalicious
      34.249.145.219
      unknownUnited States
      16509AMAZON-02USfalse
      109.202.202.202
      unknownSwitzerland
      13030INIT7CHfalse
      91.189.91.43
      unknownUnited Kingdom
      41231CANONICAL-ASGBfalse
      91.189.91.42
      unknownUnited Kingdom
      41231CANONICAL-ASGBfalse
      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
      34.249.145.219xd.x86_64.elfGet hashmaliciousMiraiBrowse
        xd.arm.elfGet hashmaliciousMiraiBrowse
          xd.arm.elfGet hashmaliciousMiraiBrowse
            xd.arm5.elfGet hashmaliciousMiraiBrowse
              na.elfGet hashmaliciousPrometeiBrowse
                na.elfGet hashmaliciousPrometeiBrowse
                  na.elfGet hashmaliciousPrometeiBrowse
                    na.elfGet hashmaliciousPrometeiBrowse
                      na.elfGet hashmaliciousPrometeiBrowse
                        na.elfGet hashmaliciousPrometeiBrowse
                          109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
                          • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
                          91.189.91.43na.elfGet hashmaliciousPrometeiBrowse
                            na.elfGet hashmaliciousPrometeiBrowse
                              xd.arc.elfGet hashmaliciousMiraiBrowse
                                na.elfGet hashmaliciousPrometeiBrowse
                                  xd.arm.elfGet hashmaliciousMiraiBrowse
                                    xd.m68k.elfGet hashmaliciousMiraiBrowse
                                      xd.mips.elfGet hashmaliciousMiraiBrowse
                                        sshd.elfGet hashmaliciousUnknownBrowse
                                          xd.mpsl.elfGet hashmaliciousMiraiBrowse
                                            na.elfGet hashmaliciousPrometeiBrowse
                                              91.189.91.42na.elfGet hashmaliciousPrometeiBrowse
                                                na.elfGet hashmaliciousPrometeiBrowse
                                                  xd.arc.elfGet hashmaliciousMiraiBrowse
                                                    na.elfGet hashmaliciousPrometeiBrowse
                                                      xd.x86_64.elfGet hashmaliciousMiraiBrowse
                                                        xd.arm.elfGet hashmaliciousMiraiBrowse
                                                          xd.m68k.elfGet hashmaliciousMiraiBrowse
                                                            xd.mips.elfGet hashmaliciousMiraiBrowse
                                                              sshd.elfGet hashmaliciousUnknownBrowse
                                                                xd.mpsl.elfGet hashmaliciousMiraiBrowse
                                                                  No context
                                                                  MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                  CANONICAL-ASGBna.elfGet hashmaliciousPrometeiBrowse
                                                                  • 185.125.190.26
                                                                  na.elfGet hashmaliciousPrometeiBrowse
                                                                  • 91.189.91.42
                                                                  na.elfGet hashmaliciousPrometeiBrowse
                                                                  • 91.189.91.42
                                                                  na.elfGet hashmaliciousPrometeiBrowse
                                                                  • 185.125.190.26
                                                                  xd.arc.elfGet hashmaliciousMiraiBrowse
                                                                  • 91.189.91.42
                                                                  na.elfGet hashmaliciousPrometeiBrowse
                                                                  • 91.189.91.42
                                                                  xd.x86_64.elfGet hashmaliciousMiraiBrowse
                                                                  • 162.213.35.25
                                                                  xd.arm.elfGet hashmaliciousMiraiBrowse
                                                                  • 162.213.35.24
                                                                  xd.m68k.elfGet hashmaliciousMiraiBrowse
                                                                  • 162.213.35.24
                                                                  xd.mips.elfGet hashmaliciousMiraiBrowse
                                                                  • 162.213.35.25
                                                                  CANONICAL-ASGBna.elfGet hashmaliciousPrometeiBrowse
                                                                  • 185.125.190.26
                                                                  na.elfGet hashmaliciousPrometeiBrowse
                                                                  • 91.189.91.42
                                                                  na.elfGet hashmaliciousPrometeiBrowse
                                                                  • 91.189.91.42
                                                                  na.elfGet hashmaliciousPrometeiBrowse
                                                                  • 185.125.190.26
                                                                  xd.arc.elfGet hashmaliciousMiraiBrowse
                                                                  • 91.189.91.42
                                                                  na.elfGet hashmaliciousPrometeiBrowse
                                                                  • 91.189.91.42
                                                                  xd.x86_64.elfGet hashmaliciousMiraiBrowse
                                                                  • 162.213.35.25
                                                                  xd.arm.elfGet hashmaliciousMiraiBrowse
                                                                  • 162.213.35.24
                                                                  xd.m68k.elfGet hashmaliciousMiraiBrowse
                                                                  • 162.213.35.24
                                                                  xd.mips.elfGet hashmaliciousMiraiBrowse
                                                                  • 162.213.35.25
                                                                  INIT7CHna.elfGet hashmaliciousPrometeiBrowse
                                                                  • 109.202.202.202
                                                                  na.elfGet hashmaliciousPrometeiBrowse
                                                                  • 109.202.202.202
                                                                  xd.arc.elfGet hashmaliciousMiraiBrowse
                                                                  • 109.202.202.202
                                                                  na.elfGet hashmaliciousPrometeiBrowse
                                                                  • 109.202.202.202
                                                                  sshd.elfGet hashmaliciousUnknownBrowse
                                                                  • 109.202.202.202
                                                                  xd.mpsl.elfGet hashmaliciousMiraiBrowse
                                                                  • 109.202.202.202
                                                                  na.elfGet hashmaliciousPrometeiBrowse
                                                                  • 109.202.202.202
                                                                  xd.i686.elfGet hashmaliciousMiraiBrowse
                                                                  • 109.202.202.202
                                                                  xd.arm.elfGet hashmaliciousMiraiBrowse
                                                                  • 109.202.202.202
                                                                  xd.sh4.elfGet hashmaliciousMiraiBrowse
                                                                  • 109.202.202.202
                                                                  AMAZON-02USna.elfGet hashmaliciousPrometeiBrowse
                                                                  • 54.171.230.55
                                                                  https://microsoft365.craft.me/documentGet hashmaliciousHTMLPhisher, Invisible JS, Tycoon2FABrowse
                                                                  • 108.138.128.125
                                                                  http://found19.z20.web.core.windows.net/werrx01USAHTML/index.htmlGet hashmaliciousUnknownBrowse
                                                                  • 13.226.34.39
                                                                  https://vqr.vc/6ossVvCJoGet hashmaliciousUnknownBrowse
                                                                  • 13.33.252.45
                                                                  https://storage.googleapis.com/kzrzrzrzrzr/wattere.html#/redirect.html?od=1syb67eb1c8583e99_vl_topvl_1544.54qf18g.C0000rjawyf2czq00l_x11480.jawyf%5DM3hoeHE4LTA3YzBjcmM0u6NviGet hashmaliciousPhisherBrowse
                                                                  • 52.88.149.15
                                                                  https://www.earthcam.net/refer/refer.php?h=1&t=ai&a=MjAyMTAzVExPTQ==&u=https://gamma.app/docs/Ikegami-Electronics-USA-Inc-7imknbprp42mt7n?mode=present#card-551p7iq4lgkr821Get hashmaliciousHTMLPhisherBrowse
                                                                  • 108.139.47.114
                                                                  xd.arm.elfGet hashmaliciousMiraiBrowse
                                                                  • 34.243.86.250
                                                                  xd.ppc.elfGet hashmaliciousMiraiBrowse
                                                                  • 34.214.176.97
                                                                  xd.mpsl.elfGet hashmaliciousMiraiBrowse
                                                                  • 18.253.60.87
                                                                  xd.m68k.elfGet hashmaliciousMiraiBrowse
                                                                  • 18.134.87.81
                                                                  No context
                                                                  No context
                                                                  No created / dropped files found
                                                                  File type:ELF 32-bit LSB executable, ARM, EABI5 version 1 (SYSV), dynamically linked, interpreter /lib/ld-linux-armhf.so.3, for GNU/Linux 3.2.0, stripped
                                                                  Entropy (8bit):6.23601133398947
                                                                  TrID:
                                                                  • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                                                  File name:sshd.elf
                                                                  File size:1'110'304 bytes
                                                                  MD5:d1ec7ed13b58335b0efcb5bc3acacd81
                                                                  SHA1:5a7fea994a4d0ecb2bc36840af1b94e1a87474e7
                                                                  SHA256:fadd8a607bda25c51415c8bd8facbe52d48f1ff7893f490e3ed9de84c75e6e6e
                                                                  SHA512:a2152b370498abbbd5c56c5d8ee7fe5307810db3160797a9b50ad3b0729166aed49c51379a278ad88bd2842b85cc49d8adc54f370e6c963847d8cb297a11922e
                                                                  SSDEEP:12288:E8dASOYRNqAJump208iJftl7zmnSrlcaUxQ5TVFQGl9eLtRajZa6ZTxIVD7bLv:E8dbbEO38+TfgRinIVvv
                                                                  TLSH:AD356D56F9808EA2C5D8177BF75D835833134B78D7DEB102CD08672877AB95A0E3B982
                                                                  File Content Preview:.ELF..............(......d..4...p.......4. ...(........p\...\...\.......................4...4...4... ... ...............T...T...T...................................h...h...........................0....m..........................(...(...............p...p..

                                                                  ELF header

                                                                  Class:ELF32
                                                                  Data:2's complement, little endian
                                                                  Version:1 (current)
                                                                  Machine:ARM
                                                                  Version Number:0x1
                                                                  Type:EXEC (Executable file)
                                                                  OS/ABI:UNIX - System V
                                                                  ABI Version:0
                                                                  Entry Point Address:0x164f4
                                                                  Flags:0x5000400
                                                                  ELF Header Size:52
                                                                  Program Header Offset:52
                                                                  Program Header Size:32
                                                                  Number of Program Headers:9
                                                                  Section Header Offset:1109104
                                                                  Section Header Size:40
                                                                  Number of Section Headers:30
                                                                  Header String Table Index:29
                                                                  NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                                  NULL0x00x00x00x00x0000
                                                                  .interpPROGBITS0x101540x1540x190x00x2A001
                                                                  .note.ABI-tagNOTE0x101700x1700x200x00x2A004
                                                                  .hashHASH0x101900x1900x7380x40x2A504
                                                                  .gnu.hashGNU_HASH0x108c80x8c80x8300x40x2A504
                                                                  .dynsymDYNSYM0x110f80x10f80x10700x100x2A614
                                                                  .dynstrSTRTAB0x121680x21680x90e0x00x2A001
                                                                  .gnu.versionVERSYM0x12a760x2a760x20e0x20x2A502
                                                                  .gnu.version_rVERNEED0x12c840x2c840xe00x00x2A644
                                                                  .rel.dynREL0x12d640x2d640x380x80x2A504
                                                                  .rel.pltREL0x12d9c0x2d9c0x7680x80x42AI5224
                                                                  .initPROGBITS0x135040x35040xc0x00x6AX004
                                                                  .pltPROGBITS0x135100x35100xb300x40x6AX004
                                                                  .textPROGBITS0x140400x40400xb55940x00x6AX008
                                                                  .finiPROGBITS0xc95d40xb95d40x80x00x6AX004
                                                                  .rodataPROGBITS0xc95e00xb95e00x53f7c0x00x2A008
                                                                  .ARM.exidxARM_EXIDX0x11d55c0x10d55c0x80x00x82AL1304
                                                                  .eh_framePROGBITS0x11d5640x10d5640x40x00x2A004
                                                                  .init_arrayINIT_ARRAY0x12deb40x10deb40x40x40x3WA004
                                                                  .fini_arrayFINI_ARRAY0x12deb80x10deb80x40x40x3WA004
                                                                  .data.rel.roPROGBITS0x12debc0x10debc0x1c0x00x3WA004
                                                                  .dynamicDYNAMIC0x12ded80x10ded80x1280x80x3WA604
                                                                  .gotPROGBITS0x12e0000x10e0000x3d40x40x3WA004
                                                                  .dataPROGBITS0x12e3d40x10e3d40x6100x00x3WA004
                                                                  .bssNOBITS0x12e9e80x10e9e40x62600x00x3WA008
                                                                  .commentPROGBITS0x00x10e9e40x550x10x30MS001
                                                                  .ARM.attributesARM_ATTRIBUTES0x00x10ea390x350x00x0001
                                                                  .miscpathPROGBITS0x00x10ea6e0x00x00x0001
                                                                  .dhsecPROGBITS0x00x10ea6e0x1000x00x0001
                                                                  .shstrtabSTRTAB0x00x10eb6e0x1000x00x0001
                                                                  TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                                  EXIDX0x10d55c0x11d55c0x11d55c0x80x82.40560x4R 0x4.ARM.exidx
                                                                  PHDR0x340x100340x100340x1200x1202.80010x4R 0x4
                                                                  INTERP0x1540x101540x101540x190x194.13370x4R 0x1/lib/ld-linux-armhf.so.3.interp
                                                                  LOAD0x00x100000x100000x10d5680x10d5686.24890x5R E0x10000.interp .note.ABI-tag .hash .gnu.hash .dynsym .dynstr .gnu.version .gnu.version_r .rel.dyn .rel.plt .init .plt .text .fini .rodata .ARM.exidx .eh_frame
                                                                  LOAD0x10deb40x12deb40x12deb40xb300x6d943.73170x6RW 0x10000.init_array .fini_array .data.rel.ro .dynamic .got .data .bss
                                                                  DYNAMIC0x10ded80x12ded80x12ded80x1280x1282.68160x6RW 0x4.dynamic
                                                                  NOTE0x1700x101700x101700x200x201.56130x4R 0x4.note.ABI-tag
                                                                  GNU_STACK0x00x00x00x00x00.00000x6RW 0x10
                                                                  GNU_RELRO0x10deb40x12deb40x12deb40x14c0x14c3.01430x4R 0x1.init_array .fini_array .data.rel.ro .dynamic
                                                                  TypeMetaValueTag
                                                                  DT_NEEDEDsharedliblibrt.so.10x1
                                                                  DT_NEEDEDsharedliblibdl.so.20x1
                                                                  DT_NEEDEDsharedliblibutil.so.10x1
                                                                  DT_NEEDEDsharedliblibcrypt.so.10x1
                                                                  DT_NEEDEDsharedliblibresolv.so.20x1
                                                                  DT_NEEDEDsharedliblibz.so.10x1
                                                                  DT_NEEDEDsharedliblibm.so.60x1
                                                                  DT_NEEDEDsharedliblibc.so.60x1
                                                                  DT_INITvalue0x135040xc
                                                                  DT_FINIvalue0xc95d40xd
                                                                  DT_INIT_ARRAYvalue0x12deb40x19
                                                                  DT_INIT_ARRAYSZbytes40x1b
                                                                  DT_FINI_ARRAYvalue0x12deb80x1a
                                                                  DT_FINI_ARRAYSZbytes40x1c
                                                                  DT_HASHvalue0x101900x4
                                                                  DT_GNU_HASHvalue0x108c80x6ffffef5
                                                                  DT_STRTABvalue0x121680x5
                                                                  DT_SYMTABvalue0x110f80x6
                                                                  DT_STRSZbytes23180xa
                                                                  DT_SYMENTbytes160xb
                                                                  DT_DEBUGvalue0x00x15
                                                                  DT_PLTGOTvalue0x12e0000x3
                                                                  DT_PLTRELSZbytes18960x2
                                                                  DT_PLTRELpltrelDT_REL0x14
                                                                  DT_JMPRELvalue0x12d9c0x17
                                                                  DT_RELvalue0x12d640x11
                                                                  DT_RELSZbytes560x12
                                                                  DT_RELENTbytes80x13
                                                                  DT_VERNEEDvalue0x12c840x6ffffffe
                                                                  DT_VERNEEDNUMvalue40x6fffffff
                                                                  DT_VERSYMvalue0x12a760x6ffffff0
                                                                  DT_NULLvalue0x00x0
                                                                  NameVersion Info NameVersion Info File NameSection NameValueSizeSymbol TypeSymbol BindSymbol VisibilityNdx
                                                                  .dynsym0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                                                  _ITM_deregisterTMCloneTable.dynsym0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                                                  _ITM_registerTMCloneTable.dynsym0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                                                  __assert_failGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  __b64_ntop.dynsym0x655f8284FUNC<unknown>DEFAULT13
                                                                  __b64_pton.dynsym0x65714472FUNC<unknown>DEFAULT13
                                                                  __ctype_b_locGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  __ctype_tolower_locGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  __environGLIBC_2.4libc.so.6.dynsym0x12e9ec4OBJECT<unknown>DEFAULT24
                                                                  __errno_locationGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  __explicit_bzero_chkGLIBC_2.25libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  __fprintf_chkGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  __fxstatGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  __fxstat64GLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  __gmon_start__.dynsym0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                                                  __isoc99_sscanfGLIBC_2.7libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  __libc_start_mainGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  __lxstat64GLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  __memcpy_chkGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  __memmove_chkGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  __memset_chkGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  __poll_chkGLIBC_2.16libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  __printf_chkGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  __prognameGLIBC_2.4libc.so.6.dynsym0x12e9e84OBJECT<unknown>DEFAULT24
                                                                  __read_chkGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  __realpath_chkGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  __snprintf_chkGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  __sprintf_chkGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  __strcat_chkGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  __strcpy_chkGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  __strncpy_chkGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  __syslog_chkGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  __vasprintf_chkGLIBC_2.8libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  __vsnprintf_chkGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  __xstat64GLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  _exitGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  abortGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  acceptGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  accessGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  alarmGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  atoiGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  bindGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  callocGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  cfsetispeedGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  cfsetospeedGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  chdirGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  chmodGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  chownGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  chrootGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  clock_gettimeGLIBC_2.4librt.so.1.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  closeGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  closedirGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  closelogGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  connectGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  cryptGLIBC_2.4libcrypt.so.1.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  ctimeGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  daemonGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  deflate.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  deflateEnd.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  deflateInit_.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  dirfdGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  dirnameGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  dupGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  dup2GLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  endgrentGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  endpwent.dynsym0xc7f8840FUNC<unknown>DEFAULT13
                                                                  environGLIBC_2.4libc.so.6.dynsym0x12e9ec4OBJECT<unknown>DEFAULT24
                                                                  error.dynsym0x3f2c444FUNC<unknown>DEFAULT13
                                                                  execlGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  execvGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  execveGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  exitGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  fchmodGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  fchownGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  fcloseGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  fcntl64GLIBC_2.28libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  fdopenGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  feofGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  ferrorGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  fflushGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  fgetcGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  fgetpwent_r.dynsym0xc79cc52FUNC<unknown>DEFAULT13
                                                                  fgetsGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  filenoGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  flockGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  fopenGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  fopen64GLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  forkGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  fprintfGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  fputcGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  fputsGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  freadGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  freeGLIBC_2.4libc.so.6.dynsym0x138e40FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  freeaddrinfoGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  fscanfGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  fseekGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  fstatvfs64GLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  fsyncGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  ftellGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  ftruncate64GLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  futimesGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  fwriteGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  gai_strerrorGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  getaddrinfoGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  getcwdGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  getegidGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  getenvGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  geteuidGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  getgidGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  getgrgidGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  getgrnamGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  getgrouplistGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  getgroupsGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  gethostnameGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  getnameinfoGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  getpeernameGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  getpgidGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  getpidGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  getppidGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  getpw.dynsym0xc7ee4140FUNC<unknown>DEFAULT13
                                                                  getpwentGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  getpwent_r.dynsym0xc7fb0144FUNC<unknown>DEFAULT13
                                                                  getpwnam.dynsym0xc7e7c52FUNC<unknown>DEFAULT13
                                                                  getpwnam_r.dynsym0xc7adc168FUNC<unknown>DEFAULT13
                                                                  getpwuid.dynsym0xc7e1452FUNC<unknown>DEFAULT13
                                                                  getpwuid_r.dynsym0xc7cd4160FUNC<unknown>DEFAULT13
                                                                  getsidGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  getsocknameGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  getsockoptGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  getspnamGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  gettimeofdayGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  getuidGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  inet_ntoaGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  inet_ntopGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  inflate.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  inflateEnd.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  inflateInit_.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  initgroupsGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  innetgrGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  ioctlGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  isspaceGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  killGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  linkGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  listenGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  localtimeGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  localtime_rGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  loginGLIBC_2.4libutil.so.1.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  logoutGLIBC_2.4libutil.so.1.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  logwtmpGLIBC_2.4libutil.so.1.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  lseek64GLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  mallocGLIBC_2.4libc.so.6.dynsym0x13c440FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  memchrGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  memcmpGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  memcpyGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  memmoveGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  memsetGLIBC_2.4libc.so.6.dynsym0x138000FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  mkdirGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  mkdtemp.dynsym0x66ea036FUNC<unknown>DEFAULT13
                                                                  mkstemp64.dynsym0x66e8c12FUNC<unknown>DEFAULT13
                                                                  mkstemps64.dynsym0x66e988FUNC<unknown>DEFAULT13
                                                                  openGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  open64GLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  opendirGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  openlogGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  openptyGLIBC_2.4libutil.so.1.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  pcloseGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  perrorGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  pipeGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  pollGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  popenGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  prctlGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  printfGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  putcharGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  putpwent.dynsym0xc8310112FUNC<unknown>DEFAULT13
                                                                  putsGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  qsortGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  raiseGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  randGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  readGLIBC_2.4libc.so.6.dynsym0x138fc0FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  readdir64GLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  readlinkGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  reallocGLIBC_2.4libc.so.6.dynsym0x13ed80FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  reallocarrayGLIBC_2.26libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  recvmsgGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  removeGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  renameGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  rewindGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  rmdirGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  selectGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  sendmsgGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  setegidGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  setenvGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  seteuidGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  setgidGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  setgroupsGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  setlogin.dynsym0x653d88FUNC<unknown>DEFAULT13
                                                                  setpwent.dynsym0xc7f7024FUNC<unknown>DEFAULT13
                                                                  setresgidGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  setresuidGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  setrlimit64GLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  setsidGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  setsockoptGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  setuidGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  shutdownGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  sigactionGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  sigaddsetGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  sigemptysetGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  signalGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  sigprocmaskGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  snprintfGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  socketGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  socketpairGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  sprintfGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  srandGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  sscanfGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  statvfs64GLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  stderrGLIBC_2.4libc.so.6.dynsym0x12e9f84OBJECT<unknown>DEFAULT24
                                                                  stdinGLIBC_2.4libc.so.6.dynsym0x12e9f04OBJECT<unknown>DEFAULT24
                                                                  stdoutGLIBC_2.4libc.so.6.dynsym0x12e9f44OBJECT<unknown>DEFAULT24
                                                                  strcasecmpGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  strchrGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  strcmpGLIBC_2.4libc.so.6.dynsym0x13fbc0FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  strcpyGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  strcspnGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  strdupGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  strerrorGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  strftimeGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  strlenGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  strncasecmpGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  strncmpGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  strncpyGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  strpbrkGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  strrchrGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  strsepGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  strspnGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  strstrGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  strtodGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  strtokGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  strtok_rGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  strtolGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  strtollGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  strtoulGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  symlinkGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  syscallGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  sysconfGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  sysinfoGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  systemGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  tcgetattrGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  tcsendbreakGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  tcsetattrGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  timeGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  truncate64GLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  ttynameGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  umaskGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  uncompress.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  unlinkGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  unsetenvGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  usleepGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  utimesGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  vfprintfGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  vsnprintfGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  waitpidGLIBC_2.4libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                  writeGLIBC_2.4libc.so.6.dynsym0x139080FUNC<unknown>DEFAULTSHN_UNDEF

                                                                  Download Network PCAP: filteredfull

                                                                  • Total Packets: 10
                                                                  • 443 (HTTPS)
                                                                  • 80 (HTTP)
                                                                  TimestampSource PortDest PortSource IPDest IP
                                                                  Apr 3, 2025 00:08:19.611969948 CEST42836443192.168.2.2391.189.91.43
                                                                  Apr 3, 2025 00:08:20.380147934 CEST4251680192.168.2.23109.202.202.202
                                                                  Apr 3, 2025 00:08:35.482290030 CEST43928443192.168.2.2391.189.91.42
                                                                  Apr 3, 2025 00:08:36.778835058 CEST39240443192.168.2.2334.249.145.219
                                                                  Apr 3, 2025 00:08:36.778923988 CEST4433924034.249.145.219192.168.2.23
                                                                  Apr 3, 2025 00:08:36.779381990 CEST39240443192.168.2.2334.249.145.219
                                                                  Apr 3, 2025 00:08:36.779546022 CEST39240443192.168.2.2334.249.145.219
                                                                  Apr 3, 2025 00:08:36.779587030 CEST4433924034.249.145.219192.168.2.23
                                                                  Apr 3, 2025 00:08:45.720592022 CEST42836443192.168.2.2391.189.91.43
                                                                  Apr 3, 2025 00:08:49.816351891 CEST4251680192.168.2.23109.202.202.202
                                                                  Apr 3, 2025 00:09:16.436899900 CEST43928443192.168.2.2391.189.91.42
                                                                  Apr 3, 2025 00:09:36.771879911 CEST39240443192.168.2.2334.249.145.219
                                                                  Apr 3, 2025 00:09:36.812304020 CEST4433924034.249.145.219192.168.2.23

                                                                  System Behavior

                                                                  Start time (UTC):22:08:16
                                                                  Start date (UTC):02/04/2025
                                                                  Path:/tmp/sshd.elf
                                                                  Arguments:/tmp/sshd.elf
                                                                  File size:4956856 bytes
                                                                  MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                                  Start time (UTC):22:09:36
                                                                  Start date (UTC):02/04/2025
                                                                  Path:/usr/bin/dash
                                                                  Arguments:-
                                                                  File size:129816 bytes
                                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                  Start time (UTC):22:09:36
                                                                  Start date (UTC):02/04/2025
                                                                  Path:/usr/bin/rm
                                                                  Arguments:rm -f /tmp/tmp.isgEiRYi0f /tmp/tmp.xNeksbbJWk /tmp/tmp.I0iZJmHMtI
                                                                  File size:72056 bytes
                                                                  MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                                                  Start time (UTC):22:09:36
                                                                  Start date (UTC):02/04/2025
                                                                  Path:/usr/bin/dash
                                                                  Arguments:-
                                                                  File size:129816 bytes
                                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                  Start time (UTC):22:09:36
                                                                  Start date (UTC):02/04/2025
                                                                  Path:/usr/bin/rm
                                                                  Arguments:rm -f /tmp/tmp.isgEiRYi0f /tmp/tmp.xNeksbbJWk /tmp/tmp.I0iZJmHMtI
                                                                  File size:72056 bytes
                                                                  MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b