Edit tour

Linux Analysis Report
vision.arm7.elf

Overview

General Information

Sample name:vision.arm7.elf
Analysis ID:1670154
MD5:b92cbd95278c495bdd44616e30f188ed
SHA1:63372648337712f561f10cd3080ee7fe561cae51
SHA256:ee2d4c72c0fa67dae13c7cc25fc53d2ccda60a390435f2d0f3de5e69936b6858
Tags:elfupx-decuser-abuse_ch
Infos:

Detection

Mirai
Score:76
Range:0 - 100

Signatures

Antivirus / Scanner detection for submitted sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Yara detected Mirai
Contains symbols with names commonly found in malware
Enumerates processes within the "proc" file system
Found strings indicative of a multi-platform dropper
Sample and/or dropped files contains symbols with suspicious names
Sample contains strings indicative of BusyBox which embeds multiple Unix commands in a single executable
Sample listens on a socket
Sample tries to kill a process (SIGKILL)
Uses the "uname" system call to query kernel version information (possible evasion)
Yara signature match

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
Joe Sandbox version:42.0.0 Malachite
Analysis ID:1670154
Start date and time:2025-04-21 08:02:39 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 55s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:vision.arm7.elf
Detection:MAL
Classification:mal76.troj.linELF@0/0@0/0
  • Skipping network analysis since amount of network traffic is too extensive
Command:/tmp/vision.arm7.elf
PID:5524
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
/bin/busybox AMAIDGQV
Standard Error:
  • system is lnxubuntu20
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
MiraiMirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.mirai
SourceRuleDescriptionAuthorStrings
vision.arm7.elfJoeSecurity_Mirai_8Yara detected MiraiJoe Security
    vision.arm7.elfLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
    • 0x14a9c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x14ab0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x14ac4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x14ad8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x14aec:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x14b00:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x14b14:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x14b28:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x14b3c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x14b50:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x14b64:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x14b78:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x14b8c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x14ba0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x14bb4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x14bc8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x14bdc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x14bf0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x14c04:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x14c18:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x14c2c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    SourceRuleDescriptionAuthorStrings
    5526.1.00007fe980017000.00007fe98002e000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
      5526.1.00007fe980017000.00007fe98002e000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
      • 0x14a9c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x14ab0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x14ac4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x14ad8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x14aec:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x14b00:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x14b14:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x14b28:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x14b3c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x14b50:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x14b64:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x14b78:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x14b8c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x14ba0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x14bb4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x14bc8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x14bdc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x14bf0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x14c04:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x14c18:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x14c2c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      5528.1.00007fe980017000.00007fe98002e000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
        5528.1.00007fe980017000.00007fe98002e000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
        • 0x14a9c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x14ab0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x14ac4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x14ad8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x14aec:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x14b00:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x14b14:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x14b28:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x14b3c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x14b50:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x14b64:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x14b78:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x14b8c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x14ba0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x14bb4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x14bc8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x14bdc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x14bf0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x14c04:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x14c18:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x14c2c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        5530.1.00007fe980017000.00007fe98002e000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
          Click to see the 23 entries
          No Suricata rule has matched

          Click to jump to signature section

          Show All Signature Results

          AV Detection

          barindex
          Source: vision.arm7.elfAvira: detected
          Source: vision.arm7.elfReversingLabs: Detection: 44%
          Source: vision.arm7.elfString: //proc/net/tcp/proc/proc/%d/exe/proc/%s/statusName:%s/bin/busybox/bin/systemd/usr/bintest/tmp/condi/tmp/zxcr9999/tmp/condinetwork/var/condibot/var/zxcr9999/var/CondiBot/var/condinet/bin/watchdog.x86.x86_64.arm.arm5.arm6.arm7.mips.mipsel.sh4.ppcopendir failed/proc/%s/cmdlinenetstatwgettftpftpcurlbusybox
          Source: /tmp/vision.arm7.elf (PID: 5524)Socket: 127.0.0.1:43153Jump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5526)Socket: 127.0.0.1:512Jump to behavior

          System Summary

          barindex
          Source: vision.arm7.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
          Source: 5526.1.00007fe980017000.00007fe98002e000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
          Source: 5528.1.00007fe980017000.00007fe98002e000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
          Source: 5530.1.00007fe980017000.00007fe98002e000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
          Source: 5524.1.00007fe980017000.00007fe98002e000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
          Source: 5587.1.00007fe980017000.00007fe98002e000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
          Source: 5534.1.00007fe980017000.00007fe98002e000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
          Source: 5589.1.00007fe980017000.00007fe98002e000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
          Source: Process Memory Space: vision.arm7.elf PID: 5524, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
          Source: Process Memory Space: vision.arm7.elf PID: 5526, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
          Source: Process Memory Space: vision.arm7.elf PID: 5528, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
          Source: Process Memory Space: vision.arm7.elf PID: 5530, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
          Source: Process Memory Space: vision.arm7.elf PID: 5534, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
          Source: Process Memory Space: vision.arm7.elf PID: 5587, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
          Source: Process Memory Space: vision.arm7.elf PID: 5589, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
          Source: ELF static info symbol of initial sampleName: attack.c
          Source: ELF static info symbol of initial sampleName: attack_game.c
          Source: ELF static info symbol of initial sampleName: attack_game_samp
          Source: ELF static info symbol of initial sampleName: attack_get_opt_int
          Source: ELF static info symbol of initial sampleName: attack_get_opt_ip
          Source: ELF static info symbol of initial sampleName: attack_init
          Source: ELF static info symbol of initial sampleName: attack_method_hexflood
          Source: ELF static info symbol of initial sampleName: attack_method_nudp
          Source: ELF static info symbol of initial sampleName: attack_method_ovh
          Source: ELF static info symbol of initial sampleName: attack_method_raw
          Source: vision.arm7.elfELF static info symbol of initial sample: __gnu_unwind_execute
          Source: Initial sampleString containing 'busybox' found: /bin/busybox
          Source: Initial sampleString containing 'busybox' found: busybox
          Source: Initial sampleString containing 'busybox' found: //proc/net/tcp/proc/proc/%d/exe/proc/%s/statusName:%s/bin/busybox/bin/systemd/usr/bintest/tmp/condi/tmp/zxcr9999/tmp/condinetwork/var/condibot/var/zxcr9999/var/CondiBot/var/condinet/bin/watchdog.x86.x86_64.arm.arm5.arm6.arm7.mips.mipsel.sh4.ppcopendir failed/proc/%s/cmdlinenetstatwgettftpftpcurlbusybox
          Source: /tmp/vision.arm7.elf (PID: 5530)SIGKILL sent: pid: -5530, result: unknownJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5589)SIGKILL sent: pid: 5587, result: successfulJump to behavior
          Source: vision.arm7.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
          Source: 5526.1.00007fe980017000.00007fe98002e000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
          Source: 5528.1.00007fe980017000.00007fe98002e000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
          Source: 5530.1.00007fe980017000.00007fe98002e000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
          Source: 5524.1.00007fe980017000.00007fe98002e000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
          Source: 5587.1.00007fe980017000.00007fe98002e000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
          Source: 5534.1.00007fe980017000.00007fe98002e000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
          Source: 5589.1.00007fe980017000.00007fe98002e000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
          Source: Process Memory Space: vision.arm7.elf PID: 5524, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
          Source: Process Memory Space: vision.arm7.elf PID: 5526, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
          Source: Process Memory Space: vision.arm7.elf PID: 5528, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
          Source: Process Memory Space: vision.arm7.elf PID: 5530, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
          Source: Process Memory Space: vision.arm7.elf PID: 5534, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
          Source: Process Memory Space: vision.arm7.elf PID: 5587, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
          Source: Process Memory Space: vision.arm7.elf PID: 5589, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
          Source: classification engineClassification label: mal76.troj.linELF@0/0@0/0
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/1583/statusJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/1583/cmdlineJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/2672/statusJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/2672/cmdlineJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/110/statusJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/110/cmdlineJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/3759/statusJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/3759/cmdlineJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/111/statusJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/111/cmdlineJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/112/statusJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/112/cmdlineJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/113/statusJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/113/cmdlineJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/234/statusJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/234/cmdlineJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/1577/statusJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/1577/cmdlineJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/114/statusJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/114/cmdlineJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/235/statusJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/235/cmdlineJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/115/statusJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/115/cmdlineJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/116/statusJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/116/cmdlineJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/117/statusJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/117/cmdlineJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/118/statusJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/118/cmdlineJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/119/statusJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/119/cmdlineJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/3756/statusJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/3756/cmdlineJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/3757/statusJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/3757/cmdlineJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/10/statusJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/10/cmdlineJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/917/statusJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/917/cmdlineJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/3758/statusJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/3758/cmdlineJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/11/statusJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/11/cmdlineJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/12/statusJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/12/cmdlineJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/13/statusJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/13/cmdlineJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/14/statusJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/14/cmdlineJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/15/statusJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/15/cmdlineJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/16/statusJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/16/cmdlineJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/17/statusJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/17/cmdlineJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/18/statusJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/18/cmdlineJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/19/statusJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/19/cmdlineJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/1593/statusJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/1593/cmdlineJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/240/statusJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/240/cmdlineJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/120/statusJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/120/cmdlineJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/3094/statusJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/3094/cmdlineJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/121/statusJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/121/cmdlineJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/242/statusJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/242/cmdlineJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/3406/statusJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/3406/cmdlineJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/1/statusJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/1/cmdlineJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/122/statusJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/122/cmdlineJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/243/statusJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/243/cmdlineJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/2/statusJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/2/cmdlineJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/123/statusJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/123/cmdlineJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/244/statusJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/244/cmdlineJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/1589/statusJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/1589/cmdlineJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/3/statusJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/3/cmdlineJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/124/statusJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/124/cmdlineJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/245/statusJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/245/cmdlineJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/1588/statusJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/1588/cmdlineJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/125/statusJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/125/cmdlineJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/4/statusJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/4/cmdlineJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/246/statusJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/246/cmdlineJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/3402/statusJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/3402/cmdlineJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/126/statusJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)File opened: /proc/126/cmdlineJump to behavior
          Source: /tmp/vision.arm7.elf (PID: 5524)Queries kernel information via 'uname': Jump to behavior
          Source: vision.arm7.elf, 5524.1.00005654d6294000.00005654d640b000.rw-.sdmp, vision.arm7.elf, 5526.1.00005654d6294000.00005654d640b000.rw-.sdmp, vision.arm7.elf, 5528.1.00005654d6294000.00005654d640b000.rw-.sdmp, vision.arm7.elf, 5530.1.00005654d6294000.00005654d640b000.rw-.sdmp, vision.arm7.elf, 5534.1.00005654d6294000.00005654d640b000.rw-.sdmp, vision.arm7.elf, 5587.1.00005654d6294000.00005654d640b000.rw-.sdmp, vision.arm7.elf, 5589.1.00005654d6294000.00005654d640b000.rw-.sdmpBinary or memory string: TV!/etc/qemu-binfmt/arm
          Source: vision.arm7.elf, 5524.1.00005654d6294000.00005654d640b000.rw-.sdmp, vision.arm7.elf, 5526.1.00005654d6294000.00005654d640b000.rw-.sdmp, vision.arm7.elf, 5528.1.00005654d6294000.00005654d640b000.rw-.sdmp, vision.arm7.elf, 5530.1.00005654d6294000.00005654d640b000.rw-.sdmp, vision.arm7.elf, 5534.1.00005654d6294000.00005654d640b000.rw-.sdmp, vision.arm7.elf, 5587.1.00005654d6294000.00005654d640b000.rw-.sdmp, vision.arm7.elf, 5589.1.00005654d6294000.00005654d640b000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/arm
          Source: vision.arm7.elf, 5524.1.00007ffc4e57c000.00007ffc4e59d000.rw-.sdmp, vision.arm7.elf, 5526.1.00007ffc4e57c000.00007ffc4e59d000.rw-.sdmp, vision.arm7.elf, 5526.1.00007fe980037000.00007fe98003c000.rw-.sdmp, vision.arm7.elf, 5528.1.00007ffc4e57c000.00007ffc4e59d000.rw-.sdmp, vision.arm7.elf, 5530.1.00007fe980037000.00007fe98003c000.rw-.sdmp, vision.arm7.elf, 5530.1.00007ffc4e57c000.00007ffc4e59d000.rw-.sdmp, vision.arm7.elf, 5534.1.00007ffc4e57c000.00007ffc4e59d000.rw-.sdmp, vision.arm7.elf, 5587.1.00007ffc4e57c000.00007ffc4e59d000.rw-.sdmp, vision.arm7.elf, 5589.1.00007ffc4e57c000.00007ffc4e59d000.rw-.sdmpBinary or memory string: /usr/bin/qemu-arm
          Source: vision.arm7.elf, 5524.1.00007ffc4e57c000.00007ffc4e59d000.rw-.sdmp, vision.arm7.elf, 5526.1.00007ffc4e57c000.00007ffc4e59d000.rw-.sdmp, vision.arm7.elf, 5528.1.00007ffc4e57c000.00007ffc4e59d000.rw-.sdmp, vision.arm7.elf, 5530.1.00007ffc4e57c000.00007ffc4e59d000.rw-.sdmp, vision.arm7.elf, 5534.1.00007ffc4e57c000.00007ffc4e59d000.rw-.sdmp, vision.arm7.elf, 5587.1.00007ffc4e57c000.00007ffc4e59d000.rw-.sdmp, vision.arm7.elf, 5589.1.00007ffc4e57c000.00007ffc4e59d000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-arm/tmp/vision.arm7.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/vision.arm7.elf
          Source: vision.arm7.elf, 5526.1.00007fe980037000.00007fe98003c000.rw-.sdmp, vision.arm7.elf, 5530.1.00007fe980037000.00007fe98003c000.rw-.sdmpBinary or memory string: /usr/bin/qemu-arm/tmp/vision.arm7.elfg/org/gtk/gvfs/exec_spaw/0inux-gnu/xfce4/panel/plugins/libactions.so1412582925actionsAction ButtonsLog out, lock or other system actionson plugin for the Xfce panels and control the brightness of your display

          Stealing of Sensitive Information

          barindex
          Source: Yara matchFile source: vision.arm7.elf, type: SAMPLE
          Source: Yara matchFile source: 5526.1.00007fe980017000.00007fe98002e000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: 5528.1.00007fe980017000.00007fe98002e000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: 5530.1.00007fe980017000.00007fe98002e000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: 5524.1.00007fe980017000.00007fe98002e000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: 5587.1.00007fe980017000.00007fe98002e000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: 5534.1.00007fe980017000.00007fe98002e000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: 5589.1.00007fe980017000.00007fe98002e000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: Process Memory Space: vision.arm7.elf PID: 5524, type: MEMORYSTR
          Source: Yara matchFile source: Process Memory Space: vision.arm7.elf PID: 5526, type: MEMORYSTR
          Source: Yara matchFile source: Process Memory Space: vision.arm7.elf PID: 5528, type: MEMORYSTR
          Source: Yara matchFile source: Process Memory Space: vision.arm7.elf PID: 5530, type: MEMORYSTR
          Source: Yara matchFile source: Process Memory Space: vision.arm7.elf PID: 5534, type: MEMORYSTR
          Source: Yara matchFile source: Process Memory Space: vision.arm7.elf PID: 5587, type: MEMORYSTR
          Source: Yara matchFile source: Process Memory Space: vision.arm7.elf PID: 5589, type: MEMORYSTR

          Remote Access Functionality

          barindex
          Source: Yara matchFile source: vision.arm7.elf, type: SAMPLE
          Source: Yara matchFile source: 5526.1.00007fe980017000.00007fe98002e000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: 5528.1.00007fe980017000.00007fe98002e000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: 5530.1.00007fe980017000.00007fe98002e000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: 5524.1.00007fe980017000.00007fe98002e000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: 5587.1.00007fe980017000.00007fe98002e000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: 5534.1.00007fe980017000.00007fe98002e000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: 5589.1.00007fe980017000.00007fe98002e000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: Process Memory Space: vision.arm7.elf PID: 5524, type: MEMORYSTR
          Source: Yara matchFile source: Process Memory Space: vision.arm7.elf PID: 5526, type: MEMORYSTR
          Source: Yara matchFile source: Process Memory Space: vision.arm7.elf PID: 5528, type: MEMORYSTR
          Source: Yara matchFile source: Process Memory Space: vision.arm7.elf PID: 5530, type: MEMORYSTR
          Source: Yara matchFile source: Process Memory Space: vision.arm7.elf PID: 5534, type: MEMORYSTR
          Source: Yara matchFile source: Process Memory Space: vision.arm7.elf PID: 5587, type: MEMORYSTR
          Source: Yara matchFile source: Process Memory Space: vision.arm7.elf PID: 5589, type: MEMORYSTR
          ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
          Gather Victim Identity Information1
          Scripting
          Valid AccountsWindows Management Instrumentation1
          Scripting
          Path Interception1
          Masquerading
          1
          OS Credential Dumping
          11
          Security Software Discovery
          Remote ServicesData from Local SystemData ObfuscationExfiltration Over Other Network MediumAbuse Accessibility Features
          No configs have been found
          Hide Legend

          Legend:

          • Process
          • Signature
          • Created File
          • DNS/IP Info
          • Is Dropped
          • Number of created Files
          • Is malicious
          • Internet
          behaviorgraph top1 signatures2 2 Behavior Graph ID: 1670154 Sample: vision.arm7.elf Startdate: 21/04/2025 Architecture: LINUX Score: 76 24 Malicious sample detected (through community Yara rule) 2->24 26 Antivirus / Scanner detection for submitted sample 2->26 28 Multi AV Scanner detection for submitted file 2->28 30 2 other signatures 2->30 8 vision.arm7.elf 2->8         started        process3 process4 10 vision.arm7.elf 8->10         started        12 vision.arm7.elf 8->12         started        14 vision.arm7.elf 8->14         started        process5 16 vision.arm7.elf 10->16         started        18 vision.arm7.elf 10->18         started        20 vision.arm7.elf 12->20         started        process6 22 vision.arm7.elf 20->22         started       
          SourceDetectionScannerLabelLink
          vision.arm7.elf44%ReversingLabsLinux.Backdoor.Mirai
          vision.arm7.elf100%AviraEXP/ELF.Mirai.Z.A
          No Antivirus matches
          No Antivirus matches
          No Antivirus matches
          No contacted domains info
          No contacted IP infos
          No context
          No context
          No context
          No context
          No context
          No created / dropped files found
          File type:ELF 32-bit LSB executable, ARM, EABI4 version 1 (SYSV), statically linked, with debug_info, not stripped
          Entropy (8bit):6.001269110253761
          TrID:
          • ELF Executable and Linkable format (generic) (4004/1) 100.00%
          File name:vision.arm7.elf
          File size:155'776 bytes
          MD5:b92cbd95278c495bdd44616e30f188ed
          SHA1:63372648337712f561f10cd3080ee7fe561cae51
          SHA256:ee2d4c72c0fa67dae13c7cc25fc53d2ccda60a390435f2d0f3de5e69936b6858
          SHA512:bc775740ba3a826905ac0d6b694e5e1e78b0c90c1481f2ab15d22a80c19d970a3a01a7164296639a90a2e84338b1365a11e1d930b00150f479b54331386f7221
          SSDEEP:3072:UezA+ef1RtApsa1GDzzM0MHFW2PSuOEE5eO1vM/99yWQj:DzA+e3epsa1GDzzRMs2qunE5eONM/99u
          TLSH:7FE33A56E6818B13C0D61775F6EF424633239BA493DB73069928BFF43F8279A0E63905
          File Content Preview:.ELF..............(.........4...T.......4. ...(........p.k...........................................l...l...............p...p...p.......5...............p...p...p..................Q.td..................................-...L..................@-.,@...0....S

          ELF header

          Class:ELF32
          Data:2's complement, little endian
          Version:1 (current)
          Machine:ARM
          Version Number:0x1
          Type:EXEC (Executable file)
          OS/ABI:UNIX - System V
          ABI Version:0
          Entry Point Address:0x8194
          Flags:0x4000002
          ELF Header Size:52
          Program Header Offset:52
          Program Header Size:32
          Number of Program Headers:5
          Section Header Offset:122196
          Section Header Size:40
          Number of Section Headers:29
          Header String Table Index:26
          NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
          NULL0x00x00x00x00x0000
          .initPROGBITS0x80d40xd40x100x00x6AX004
          .textPROGBITS0x80f00xf00x149200x00x6AX0016
          .finiPROGBITS0x1ca100x14a100x100x00x6AX004
          .rodataPROGBITS0x1ca200x14a200x21a80x00x2A008
          .ARM.extabPROGBITS0x1ebc80x16bc80x180x00x2A004
          .ARM.exidxARM_EXIDX0x1ebe00x16be00x1180x00x82AL204
          .eh_framePROGBITS0x270000x170000x40x00x3WA004
          .tbssNOBITS0x270040x170040x80x00x403WAT004
          .init_arrayINIT_ARRAY0x270040x170040x40x00x3WA004
          .fini_arrayFINI_ARRAY0x270080x170080x40x00x3WA004
          .jcrPROGBITS0x2700c0x1700c0x40x00x3WA004
          .gotPROGBITS0x270100x170100xac0x40x3WA004
          .dataPROGBITS0x270bc0x170bc0x2340x00x3WA004
          .bssNOBITS0x272f00x172f00x32a00x00x3WA004
          .commentPROGBITS0x00x172f00xc2e0x00x0001
          .debug_arangesPROGBITS0x00x17f200x1600x00x0008
          .debug_pubnamesPROGBITS0x00x180800x2130x00x0001
          .debug_infoPROGBITS0x00x182930x210b0x00x0001
          .debug_abbrevPROGBITS0x00x1a39e0x6f60x00x0001
          .debug_linePROGBITS0x00x1aa940xf280x00x0001
          .debug_framePROGBITS0x00x1b9bc0x2b80x00x0004
          .debug_strPROGBITS0x00x1bc740x8ca0x10x30MS001
          .debug_locPROGBITS0x00x1c53e0x118f0x00x0001
          .debug_rangesPROGBITS0x00x1d6cd0x5580x00x0001
          .ARM.attributesARM_ATTRIBUTES0x00x1dc250x160x00x0001
          .shstrtabSTRTAB0x00x1dc3b0x1170x00x0001
          .symtabSYMTAB0x00x1e1dc0x53b00x100x0287764
          .strtabSTRTAB0x00x2358c0x2af40x00x0001
          TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
          EXIDX0x16be00x1ebe00x1ebe00x1180x1184.39670x4R 0x4.ARM.exidx
          LOAD0x00x80000x80000x16cf80x16cf86.17270x5R E0x8000.init .text .fini .rodata .ARM.extab .ARM.exidx
          LOAD0x170000x270000x270000x2f00x35904.11410x6RW 0x8000.eh_frame .tbss .init_array .fini_array .jcr .got .data .bss
          TLS0x170040x270040x270040x00x80.00000x4R 0x4.tbss
          GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
          NameVersion Info NameVersion Info File NameSection NameValueSizeSymbol TypeSymbol BindSymbol VisibilityNdx
          .symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
          .symtab0x80d40SECTION<unknown>DEFAULT1
          .symtab0x80f00SECTION<unknown>DEFAULT2
          .symtab0x1ca100SECTION<unknown>DEFAULT3
          .symtab0x1ca200SECTION<unknown>DEFAULT4
          .symtab0x1ebc80SECTION<unknown>DEFAULT5
          .symtab0x1ebe00SECTION<unknown>DEFAULT6
          .symtab0x270000SECTION<unknown>DEFAULT7
          .symtab0x270040SECTION<unknown>DEFAULT8
          .symtab0x270040SECTION<unknown>DEFAULT9
          .symtab0x270080SECTION<unknown>DEFAULT10
          .symtab0x2700c0SECTION<unknown>DEFAULT11
          .symtab0x270100SECTION<unknown>DEFAULT12
          .symtab0x270bc0SECTION<unknown>DEFAULT13
          .symtab0x272f00SECTION<unknown>DEFAULT14
          .symtab0x00SECTION<unknown>DEFAULT15
          .symtab0x00SECTION<unknown>DEFAULT16
          .symtab0x00SECTION<unknown>DEFAULT17
          .symtab0x00SECTION<unknown>DEFAULT18
          .symtab0x00SECTION<unknown>DEFAULT19
          .symtab0x00SECTION<unknown>DEFAULT20
          .symtab0x00SECTION<unknown>DEFAULT21
          .symtab0x00SECTION<unknown>DEFAULT22
          .symtab0x00SECTION<unknown>DEFAULT23
          .symtab0x00SECTION<unknown>DEFAULT24
          .symtab0x00SECTION<unknown>DEFAULT25
          $a.symtab0x80d40NOTYPE<unknown>DEFAULT1
          $a.symtab0x1ca100NOTYPE<unknown>DEFAULT3
          $a.symtab0x80e00NOTYPE<unknown>DEFAULT1
          $a.symtab0x1ca1c0NOTYPE<unknown>DEFAULT3
          $a.symtab0x80f00NOTYPE<unknown>DEFAULT2
          $a.symtab0x81340NOTYPE<unknown>DEFAULT2
          $a.symtab0x81940NOTYPE<unknown>DEFAULT2
          $a.symtab0x81d00NOTYPE<unknown>DEFAULT2
          $a.symtab0x82cc0NOTYPE<unknown>DEFAULT2
          $a.symtab0x84e80NOTYPE<unknown>DEFAULT2
          $a.symtab0x85540NOTYPE<unknown>DEFAULT2
          $a.symtab0x85c40NOTYPE<unknown>DEFAULT2
          $a.symtab0x89080NOTYPE<unknown>DEFAULT2
          $a.symtab0x8c000NOTYPE<unknown>DEFAULT2
          $a.symtab0x91900NOTYPE<unknown>DEFAULT2
          $a.symtab0x983c0NOTYPE<unknown>DEFAULT2
          $a.symtab0x9ee80NOTYPE<unknown>DEFAULT2
          $a.symtab0xa57c0NOTYPE<unknown>DEFAULT2
          $a.symtab0xa81c0NOTYPE<unknown>DEFAULT2
          $a.symtab0xaacc0NOTYPE<unknown>DEFAULT2
          $a.symtab0xad800NOTYPE<unknown>DEFAULT2
          $a.symtab0xb0600NOTYPE<unknown>DEFAULT2
          $a.symtab0xb6e40NOTYPE<unknown>DEFAULT2
          $a.symtab0xb7340NOTYPE<unknown>DEFAULT2
          $a.symtab0xb7d80NOTYPE<unknown>DEFAULT2
          $a.symtab0xba5c0NOTYPE<unknown>DEFAULT2
          $a.symtab0xbab00NOTYPE<unknown>DEFAULT2
          $a.symtab0xbc500NOTYPE<unknown>DEFAULT2
          $a.symtab0xbc680NOTYPE<unknown>DEFAULT2
          $a.symtab0xbcb00NOTYPE<unknown>DEFAULT2
          $a.symtab0xbe000NOTYPE<unknown>DEFAULT2
          $a.symtab0xc0400NOTYPE<unknown>DEFAULT2
          $a.symtab0xc7fc0NOTYPE<unknown>DEFAULT2
          $a.symtab0xc8580NOTYPE<unknown>DEFAULT2
          $a.symtab0xc8c00NOTYPE<unknown>DEFAULT2
          $a.symtab0xc99c0NOTYPE<unknown>DEFAULT2
          $a.symtab0xc9c00NOTYPE<unknown>DEFAULT2
          $a.symtab0xcffc0NOTYPE<unknown>DEFAULT2
          $a.symtab0xd4300NOTYPE<unknown>DEFAULT2
          $a.symtab0xd8640NOTYPE<unknown>DEFAULT2
          $a.symtab0xe6140NOTYPE<unknown>DEFAULT2
          $a.symtab0xe63c0NOTYPE<unknown>DEFAULT2
          $a.symtab0xe6840NOTYPE<unknown>DEFAULT2
          $a.symtab0xe6a80NOTYPE<unknown>DEFAULT2
          $a.symtab0xe6cc0NOTYPE<unknown>DEFAULT2
          $a.symtab0xe8080NOTYPE<unknown>DEFAULT2
          $a.symtab0xe89c0NOTYPE<unknown>DEFAULT2
          $a.symtab0xe9980NOTYPE<unknown>DEFAULT2
          $a.symtab0xeaac0NOTYPE<unknown>DEFAULT2
          $a.symtab0xeac00NOTYPE<unknown>DEFAULT2
          $a.symtab0xeb580NOTYPE<unknown>DEFAULT2
          $a.symtab0xec4c0NOTYPE<unknown>DEFAULT2
          $a.symtab0xec600NOTYPE<unknown>DEFAULT2
          $a.symtab0xed400NOTYPE<unknown>DEFAULT2
          $a.symtab0xed780NOTYPE<unknown>DEFAULT2
          $a.symtab0xedbc0NOTYPE<unknown>DEFAULT2
          $a.symtab0xee400NOTYPE<unknown>DEFAULT2
          $a.symtab0xee800NOTYPE<unknown>DEFAULT2
          $a.symtab0xef0c0NOTYPE<unknown>DEFAULT2
          $a.symtab0xef3c0NOTYPE<unknown>DEFAULT2
          $a.symtab0xf04c0NOTYPE<unknown>DEFAULT2
          $a.symtab0xf11c0NOTYPE<unknown>DEFAULT2
          $a.symtab0xf1e00NOTYPE<unknown>DEFAULT2
          $a.symtab0xf2900NOTYPE<unknown>DEFAULT2
          $a.symtab0xf3780NOTYPE<unknown>DEFAULT2
          $a.symtab0xf3980NOTYPE<unknown>DEFAULT2
          $a.symtab0xf3cc0NOTYPE<unknown>DEFAULT2
          $a.symtab0xf6fc0NOTYPE<unknown>DEFAULT2
          $a.symtab0xf71c0NOTYPE<unknown>DEFAULT2
          $a.symtab0xf7900NOTYPE<unknown>DEFAULT2
          $a.symtab0xf7c00NOTYPE<unknown>DEFAULT2
          $a.symtab0xf7f00NOTYPE<unknown>DEFAULT2
          $a.symtab0xf8c00NOTYPE<unknown>DEFAULT2
          $a.symtab0xfd200NOTYPE<unknown>DEFAULT2
          $a.symtab0xfda00NOTYPE<unknown>DEFAULT2
          $a.symtab0xff040NOTYPE<unknown>DEFAULT2
          $a.symtab0xff340NOTYPE<unknown>DEFAULT2
          $a.symtab0x100780NOTYPE<unknown>DEFAULT2
          $a.symtab0x108440NOTYPE<unknown>DEFAULT2
          $a.symtab0x108e40NOTYPE<unknown>DEFAULT2
          $a.symtab0x109280NOTYPE<unknown>DEFAULT2
          $a.symtab0x10ad80NOTYPE<unknown>DEFAULT2
          $a.symtab0x10b2c0NOTYPE<unknown>DEFAULT2
          $a.symtab0x1109c0NOTYPE<unknown>DEFAULT2
          $a.symtab0x110cc0NOTYPE<unknown>DEFAULT2
          $a.symtab0x111740NOTYPE<unknown>DEFAULT2
          $a.symtab0x112900NOTYPE<unknown>DEFAULT2
          $a.symtab0x115400NOTYPE<unknown>DEFAULT2
          $a.symtab0x118ec0NOTYPE<unknown>DEFAULT2
          $a.symtab0x1198c0NOTYPE<unknown>DEFAULT2
          $a.symtab0x119c40NOTYPE<unknown>DEFAULT2
          $a.symtab0x11a800NOTYPE<unknown>DEFAULT2
          $a.symtab0x11a900NOTYPE<unknown>DEFAULT2
          $a.symtab0x11b300NOTYPE<unknown>DEFAULT2
          $a.symtab0x11b500NOTYPE<unknown>DEFAULT2
          $a.symtab0x11bb00NOTYPE<unknown>DEFAULT2
          $a.symtab0x11cc00NOTYPE<unknown>DEFAULT2
          $a.symtab0x11d8c0NOTYPE<unknown>DEFAULT2
          $a.symtab0x11ddc0NOTYPE<unknown>DEFAULT2
          $a.symtab0x11ed80NOTYPE<unknown>DEFAULT2
          $a.symtab0x11ef00NOTYPE<unknown>DEFAULT2
          $a.symtab0x11ffc0NOTYPE<unknown>DEFAULT2
          $a.symtab0x120200NOTYPE<unknown>DEFAULT2
          $a.symtab0x1209c0NOTYPE<unknown>DEFAULT2
          $a.symtab0x120c40NOTYPE<unknown>DEFAULT2
          $a.symtab0x121080NOTYPE<unknown>DEFAULT2
          $a.symtab0x1217c0NOTYPE<unknown>DEFAULT2
          $a.symtab0x121c00NOTYPE<unknown>DEFAULT2
          $a.symtab0x122040NOTYPE<unknown>DEFAULT2
          $a.symtab0x122780NOTYPE<unknown>DEFAULT2
          $a.symtab0x122bc0NOTYPE<unknown>DEFAULT2
          $a.symtab0x123040NOTYPE<unknown>DEFAULT2
          $a.symtab0x123440NOTYPE<unknown>DEFAULT2
          $a.symtab0x123880NOTYPE<unknown>DEFAULT2
          $a.symtab0x123f80NOTYPE<unknown>DEFAULT2
          $a.symtab0x1243c0NOTYPE<unknown>DEFAULT2
          $a.symtab0x124ac0NOTYPE<unknown>DEFAULT2
          $a.symtab0x124f80NOTYPE<unknown>DEFAULT2
          $a.symtab0x125800NOTYPE<unknown>DEFAULT2
          $a.symtab0x125c80NOTYPE<unknown>DEFAULT2
          $a.symtab0x1260c0NOTYPE<unknown>DEFAULT2
          $a.symtab0x1265c0NOTYPE<unknown>DEFAULT2
          $a.symtab0x126700NOTYPE<unknown>DEFAULT2
          $a.symtab0x127340NOTYPE<unknown>DEFAULT2
          $a.symtab0x127a00NOTYPE<unknown>DEFAULT2
          $a.symtab0x131500NOTYPE<unknown>DEFAULT2
          $a.symtab0x132900NOTYPE<unknown>DEFAULT2
          $a.symtab0x136500NOTYPE<unknown>DEFAULT2
          $a.symtab0x13af00NOTYPE<unknown>DEFAULT2
          $a.symtab0x13b300NOTYPE<unknown>DEFAULT2
          $a.symtab0x13c580NOTYPE<unknown>DEFAULT2
          $a.symtab0x13c700NOTYPE<unknown>DEFAULT2
          $a.symtab0x13d140NOTYPE<unknown>DEFAULT2
          $a.symtab0x13dcc0NOTYPE<unknown>DEFAULT2
          $a.symtab0x13e8c0NOTYPE<unknown>DEFAULT2
          $a.symtab0x13f300NOTYPE<unknown>DEFAULT2
          $a.symtab0x13fc00NOTYPE<unknown>DEFAULT2
          $a.symtab0x140980NOTYPE<unknown>DEFAULT2
          $a.symtab0x141900NOTYPE<unknown>DEFAULT2
          $a.symtab0x1427c0NOTYPE<unknown>DEFAULT2
          $a.symtab0x1429c0NOTYPE<unknown>DEFAULT2
          $a.symtab0x142b80NOTYPE<unknown>DEFAULT2
          $a.symtab0x144900NOTYPE<unknown>DEFAULT2
          $a.symtab0x145540NOTYPE<unknown>DEFAULT2
          $a.symtab0x146a00NOTYPE<unknown>DEFAULT2
          $a.symtab0x14cc40NOTYPE<unknown>DEFAULT2
          $a.symtab0x150900NOTYPE<unknown>DEFAULT2
          $a.symtab0x151280NOTYPE<unknown>DEFAULT2
          $a.symtab0x151700NOTYPE<unknown>DEFAULT2
          $a.symtab0x152600NOTYPE<unknown>DEFAULT2
          $a.symtab0x153940NOTYPE<unknown>DEFAULT2
          $a.symtab0x153ec0NOTYPE<unknown>DEFAULT2
          $a.symtab0x153f40NOTYPE<unknown>DEFAULT2
          $a.symtab0x154240NOTYPE<unknown>DEFAULT2
          $a.symtab0x1547c0NOTYPE<unknown>DEFAULT2
          $a.symtab0x154840NOTYPE<unknown>DEFAULT2
          $a.symtab0x154b40NOTYPE<unknown>DEFAULT2
          $a.symtab0x1550c0NOTYPE<unknown>DEFAULT2
          $a.symtab0x155140NOTYPE<unknown>DEFAULT2
          $a.symtab0x155440NOTYPE<unknown>DEFAULT2
          $a.symtab0x1559c0NOTYPE<unknown>DEFAULT2
          $a.symtab0x155a40NOTYPE<unknown>DEFAULT2
          $a.symtab0x155d00NOTYPE<unknown>DEFAULT2
          $a.symtab0x156580NOTYPE<unknown>DEFAULT2
          $a.symtab0x157340NOTYPE<unknown>DEFAULT2
          $a.symtab0x157f40NOTYPE<unknown>DEFAULT2
          $a.symtab0x158480NOTYPE<unknown>DEFAULT2
          $a.symtab0x158a00NOTYPE<unknown>DEFAULT2
          $a.symtab0x15c8c0NOTYPE<unknown>DEFAULT2
          $a.symtab0x15d080NOTYPE<unknown>DEFAULT2
          $a.symtab0x15d340NOTYPE<unknown>DEFAULT2
          $a.symtab0x15dbc0NOTYPE<unknown>DEFAULT2
          $a.symtab0x15dc40NOTYPE<unknown>DEFAULT2
          $a.symtab0x15dd00NOTYPE<unknown>DEFAULT2
          $a.symtab0x15de00NOTYPE<unknown>DEFAULT2
          $a.symtab0x15df00NOTYPE<unknown>DEFAULT2
          $a.symtab0x15e300NOTYPE<unknown>DEFAULT2
          $a.symtab0x15e980NOTYPE<unknown>DEFAULT2
          $a.symtab0x15efc0NOTYPE<unknown>DEFAULT2
          $a.symtab0x15f9c0NOTYPE<unknown>DEFAULT2
          $a.symtab0x15fc80NOTYPE<unknown>DEFAULT2
          $a.symtab0x15fdc0NOTYPE<unknown>DEFAULT2
          $a.symtab0x15ff00NOTYPE<unknown>DEFAULT2
          $a.symtab0x160040NOTYPE<unknown>DEFAULT2
          $a.symtab0x1602c0NOTYPE<unknown>DEFAULT2
          $a.symtab0x160640NOTYPE<unknown>DEFAULT2
          $a.symtab0x160a40NOTYPE<unknown>DEFAULT2
          $a.symtab0x160b80NOTYPE<unknown>DEFAULT2
          $a.symtab0x160fc0NOTYPE<unknown>DEFAULT2
          $a.symtab0x1613c0NOTYPE<unknown>DEFAULT2
          $a.symtab0x1617c0NOTYPE<unknown>DEFAULT2
          $a.symtab0x161dc0NOTYPE<unknown>DEFAULT2
          $a.symtab0x162480NOTYPE<unknown>DEFAULT2
          $a.symtab0x1625c0NOTYPE<unknown>DEFAULT2
          $a.symtab0x163d40NOTYPE<unknown>DEFAULT2
          $a.symtab0x164c00NOTYPE<unknown>DEFAULT2
          $a.symtab0x168640NOTYPE<unknown>DEFAULT2
          $a.symtab0x168b80NOTYPE<unknown>DEFAULT2
          $a.symtab0x168dc0NOTYPE<unknown>DEFAULT2
          $a.symtab0x169980NOTYPE<unknown>DEFAULT2
          $a.symtab0x16a740NOTYPE<unknown>DEFAULT2
          $a.symtab0x16bb40NOTYPE<unknown>DEFAULT2
          $a.symtab0x16c900NOTYPE<unknown>DEFAULT2
          $a.symtab0x16d040NOTYPE<unknown>DEFAULT2
          $a.symtab0x16d300NOTYPE<unknown>DEFAULT2
          $a.symtab0x16e8c0NOTYPE<unknown>DEFAULT2
          $a.symtab0x176800NOTYPE<unknown>DEFAULT2
          $a.symtab0x177580NOTYPE<unknown>DEFAULT2
          $a.symtab0x17ec00NOTYPE<unknown>DEFAULT2
          $a.symtab0x17edc0NOTYPE<unknown>DEFAULT2
          $a.symtab0x17f480NOTYPE<unknown>DEFAULT2
          $a.symtab0x180100NOTYPE<unknown>DEFAULT2
          $a.symtab0x182d40NOTYPE<unknown>DEFAULT2
          $a.symtab0x188440NOTYPE<unknown>DEFAULT2
          $a.symtab0x189880NOTYPE<unknown>DEFAULT2
          $a.symtab0x18ac00NOTYPE<unknown>DEFAULT2
          $a.symtab0x18f500NOTYPE<unknown>DEFAULT2
          $a.symtab0x18f600NOTYPE<unknown>DEFAULT2
          $a.symtab0x190500NOTYPE<unknown>DEFAULT2
          $a.symtab0x190740NOTYPE<unknown>DEFAULT2
          $a.symtab0x191540NOTYPE<unknown>DEFAULT2
          $a.symtab0x192440NOTYPE<unknown>DEFAULT2
          $a.symtab0x193300NOTYPE<unknown>DEFAULT2
          $a.symtab0x193540NOTYPE<unknown>DEFAULT2
          $a.symtab0x193980NOTYPE<unknown>DEFAULT2
          $a.symtab0x193e40NOTYPE<unknown>DEFAULT2
          $a.symtab0x194dc0NOTYPE<unknown>DEFAULT2
          $a.symtab0x197340NOTYPE<unknown>DEFAULT2
          $a.symtab0x19ae00NOTYPE<unknown>DEFAULT2
          $a.symtab0x19b580NOTYPE<unknown>DEFAULT2
          $a.symtab0x19bc00NOTYPE<unknown>DEFAULT2
          $a.symtab0x19e140NOTYPE<unknown>DEFAULT2
          $a.symtab0x19e200NOTYPE<unknown>DEFAULT2
          $a.symtab0x19e580NOTYPE<unknown>DEFAULT2
          $a.symtab0x19eb00NOTYPE<unknown>DEFAULT2
          $a.symtab0x19f080NOTYPE<unknown>DEFAULT2
          $a.symtab0x19f140NOTYPE<unknown>DEFAULT2
          $a.symtab0x1a05c0NOTYPE<unknown>DEFAULT2
          $a.symtab0x1a1080NOTYPE<unknown>DEFAULT2
          $a.symtab0x1a1f00NOTYPE<unknown>DEFAULT2
          $a.symtab0x1a2140NOTYPE<unknown>DEFAULT2
          $a.symtab0x1a3f40NOTYPE<unknown>DEFAULT2
          $a.symtab0x1a5b40NOTYPE<unknown>DEFAULT2
          $a.symtab0x1a60c0NOTYPE<unknown>DEFAULT2
          $a.symtab0x1a6d40NOTYPE<unknown>DEFAULT2
          $a.symtab0x1a7040NOTYPE<unknown>DEFAULT2
          $a.symtab0x1a7a80NOTYPE<unknown>DEFAULT2
          $a.symtab0x1a7e40NOTYPE<unknown>DEFAULT2
          $a.symtab0x1a8240NOTYPE<unknown>DEFAULT2
          $a.symtab0x1a8940NOTYPE<unknown>DEFAULT2
          $a.symtab0x1a9d80NOTYPE<unknown>DEFAULT2
          $a.symtab0x1adf40NOTYPE<unknown>DEFAULT2
          $a.symtab0x1b2900NOTYPE<unknown>DEFAULT2
          $a.symtab0x1b3d00NOTYPE<unknown>DEFAULT2
          $a.symtab0x1b4240NOTYPE<unknown>DEFAULT2
          $a.symtab0x1b4c40NOTYPE<unknown>DEFAULT2
          $a.symtab0x1b5100NOTYPE<unknown>DEFAULT2
          $a.symtab0x1b55c0NOTYPE<unknown>DEFAULT2
          $a.symtab0x1b5640NOTYPE<unknown>DEFAULT2
          $a.symtab0x1b5680NOTYPE<unknown>DEFAULT2
          $a.symtab0x1b5940NOTYPE<unknown>DEFAULT2
          $a.symtab0x1b5a00NOTYPE<unknown>DEFAULT2
          $a.symtab0x1b5ac0NOTYPE<unknown>DEFAULT2
          $a.symtab0x1b7cc0NOTYPE<unknown>DEFAULT2
          $a.symtab0x1b91c0NOTYPE<unknown>DEFAULT2
          $a.symtab0x1b9380NOTYPE<unknown>DEFAULT2
          $a.symtab0x1b9980NOTYPE<unknown>DEFAULT2
          $a.symtab0x1ba040NOTYPE<unknown>DEFAULT2
          $a.symtab0x1babc0NOTYPE<unknown>DEFAULT2
          $a.symtab0x1badc0NOTYPE<unknown>DEFAULT2
          $a.symtab0x1bc200NOTYPE<unknown>DEFAULT2
          $a.symtab0x1c1680NOTYPE<unknown>DEFAULT2
          $a.symtab0x1c1700NOTYPE<unknown>DEFAULT2
          $a.symtab0x1c1780NOTYPE<unknown>DEFAULT2
          $a.symtab0x1c1800NOTYPE<unknown>DEFAULT2
          $a.symtab0x1c23c0NOTYPE<unknown>DEFAULT2
          $a.symtab0x1c2800NOTYPE<unknown>DEFAULT2
          $a.symtab0x1c9940NOTYPE<unknown>DEFAULT2
          $a.symtab0x1c9dc0NOTYPE<unknown>DEFAULT2
          $d.symtab0x81280NOTYPE<unknown>DEFAULT2
          $d.symtab0x270080NOTYPE<unknown>DEFAULT10
          $d.symtab0x81800NOTYPE<unknown>DEFAULT2
          $d.symtab0x270040NOTYPE<unknown>DEFAULT9
          $d.symtab0x81c40NOTYPE<unknown>DEFAULT2
          $d.symtab0x82c40NOTYPE<unknown>DEFAULT2
          $d.symtab0x88d80NOTYPE<unknown>DEFAULT2
          $d.symtab0x8be00NOTYPE<unknown>DEFAULT2
          $d.symtab0x1ca900NOTYPE<unknown>DEFAULT4
          $d.symtab0x98380NOTYPE<unknown>DEFAULT2
          $d.symtab0x9ee40NOTYPE<unknown>DEFAULT2
          $d.symtab0xa5780NOTYPE<unknown>DEFAULT2
          $d.symtab0xaac80NOTYPE<unknown>DEFAULT2
          $d.symtab0xad7c0NOTYPE<unknown>DEFAULT2
          $d.symtab0xb05c0NOTYPE<unknown>DEFAULT2
          $d.symtab0xb68c0NOTYPE<unknown>DEFAULT2
          $d.symtab0x270bc0NOTYPE<unknown>DEFAULT13
          $d.symtab0xba140NOTYPE<unknown>DEFAULT2
          $d.symtab0xbaac0NOTYPE<unknown>DEFAULT2
          $d.symtab0xbc380NOTYPE<unknown>DEFAULT2
          $d.symtab0x1d5f80NOTYPE<unknown>DEFAULT4
          $d.symtab0xbc600NOTYPE<unknown>DEFAULT2
          $d.symtab0xbca80NOTYPE<unknown>DEFAULT2
          $d.symtab0xbdf00NOTYPE<unknown>DEFAULT2
          $d.symtab0xc03c0NOTYPE<unknown>DEFAULT2
          $d.symtab0xc7c40NOTYPE<unknown>DEFAULT2
          $d.symtab0x270c00NOTYPE<unknown>DEFAULT13
          $d.symtab0x270c40NOTYPE<unknown>DEFAULT13
          $d.symtab0x270c80NOTYPE<unknown>DEFAULT13
          $d.symtab0x270cc0NOTYPE<unknown>DEFAULT13
          $d.symtab0xc8480NOTYPE<unknown>DEFAULT2
          $d.symtab0xc8b00NOTYPE<unknown>DEFAULT2
          $d.symtab0xc98c0NOTYPE<unknown>DEFAULT2
          $d.symtab0xc9bc0NOTYPE<unknown>DEFAULT2
          $d.symtab0xd4140NOTYPE<unknown>DEFAULT2
          $d.symtab0xd8480NOTYPE<unknown>DEFAULT2
          $d.symtab0xe4c40NOTYPE<unknown>DEFAULT2
          $d.symtab0x270cd0NOTYPE<unknown>DEFAULT13
          $d.symtab0x270ed0NOTYPE<unknown>DEFAULT13
          $d.symtab0x00NOTYPE<unknown>DEFAULT21
          $d.symtab0x200NOTYPE<unknown>DEFAULT21
          $d.symtab0x260NOTYPE<unknown>DEFAULT21
          $d.symtab0xeb500NOTYPE<unknown>DEFAULT2
          $d.symtab0xec3c0NOTYPE<unknown>DEFAULT2
          $d.symtab0xed300NOTYPE<unknown>DEFAULT2
          $d.symtab0xed740NOTYPE<unknown>DEFAULT2
          $d.symtab0xedb80NOTYPE<unknown>DEFAULT2
          $d.symtab0xee380NOTYPE<unknown>DEFAULT2
          $d.symtab0xee7c0NOTYPE<unknown>DEFAULT2
          $d.symtab0xef080NOTYPE<unknown>DEFAULT2
          $d.symtab0xf0300NOTYPE<unknown>DEFAULT2
          $d.symtab0xf1140NOTYPE<unknown>DEFAULT2
          $d.symtab0xf1d40NOTYPE<unknown>DEFAULT2
          $d.symtab0xf2880NOTYPE<unknown>DEFAULT2
          $d.symtab0x1ddd40NOTYPE<unknown>DEFAULT4
          $d.symtab0xf3640NOTYPE<unknown>DEFAULT2
          $d.symtab0xf3940NOTYPE<unknown>DEFAULT2
          $d.symtab0xf3c80NOTYPE<unknown>DEFAULT2
          $d.symtab0xf6ec0NOTYPE<unknown>DEFAULT2
          $d.symtab0xf7800NOTYPE<unknown>DEFAULT2
          $d.symtab0xf8b80NOTYPE<unknown>DEFAULT2
          $d.symtab0xfcec0NOTYPE<unknown>DEFAULT2
          $d.symtab0xfd900NOTYPE<unknown>DEFAULT2
          $d.symtab0xfee80NOTYPE<unknown>DEFAULT2
          $d.symtab0x271080NOTYPE<unknown>DEFAULT13
          $d.symtab0x271040NOTYPE<unknown>DEFAULT13
          $d.symtab0x108200NOTYPE<unknown>DEFAULT2
          $d.symtab0x1de500NOTYPE<unknown>DEFAULT4
          $d.symtab0x10ad40NOTYPE<unknown>DEFAULT2
          $d.symtab0x10b200NOTYPE<unknown>DEFAULT2
          $d.symtab0x1106c0NOTYPE<unknown>DEFAULT2
          $d.symtab0x271ec0NOTYPE<unknown>DEFAULT13
          $d.symtab0x1de580NOTYPE<unknown>DEFAULT4
          $d.symtab0x1116c0NOTYPE<unknown>DEFAULT2
          $d.symtab0x115240NOTYPE<unknown>DEFAULT2
          $d.symtab0x118d40NOTYPE<unknown>DEFAULT2
          $d.symtab0x11a7c0NOTYPE<unknown>DEFAULT2
          $d.symtab0x11d840NOTYPE<unknown>DEFAULT2
          $d.symtab0x11fec0NOTYPE<unknown>DEFAULT2
          $d.symtab0x1dee80NOTYPE<unknown>DEFAULT4
          $d.symtab0x120980NOTYPE<unknown>DEFAULT2
          $d.symtab0x121000NOTYPE<unknown>DEFAULT2
          $d.symtab0x121740NOTYPE<unknown>DEFAULT2
          $d.symtab0x121b80NOTYPE<unknown>DEFAULT2
          $d.symtab0x121fc0NOTYPE<unknown>DEFAULT2
          $d.symtab0x122700NOTYPE<unknown>DEFAULT2
          $d.symtab0x122b40NOTYPE<unknown>DEFAULT2
          $d.symtab0x122fc0NOTYPE<unknown>DEFAULT2
          $d.symtab0x123400NOTYPE<unknown>DEFAULT2
          $d.symtab0x123800NOTYPE<unknown>DEFAULT2
          $d.symtab0x123f00NOTYPE<unknown>DEFAULT2
          $d.symtab0x124340NOTYPE<unknown>DEFAULT2
          $d.symtab0x124a40NOTYPE<unknown>DEFAULT2
          $d.symtab0x124f00NOTYPE<unknown>DEFAULT2
          $d.symtab0x125780NOTYPE<unknown>DEFAULT2
          $d.symtab0x125c00NOTYPE<unknown>DEFAULT2
          $d.symtab0x126040NOTYPE<unknown>DEFAULT2
          $d.symtab0x126580NOTYPE<unknown>DEFAULT2
          $d.symtab0x127280NOTYPE<unknown>DEFAULT2
          $d.symtab0x1312c0NOTYPE<unknown>DEFAULT2
          $d.symtab0x271f00NOTYPE<unknown>DEFAULT13
          $d.symtab0x132740NOTYPE<unknown>DEFAULT2
          $d.symtab0x136300NOTYPE<unknown>DEFAULT2
          $d.symtab0x13ad40NOTYPE<unknown>DEFAULT2
          $d.symtab0x13b280NOTYPE<unknown>DEFAULT2
          $d.symtab0x13c440NOTYPE<unknown>DEFAULT2
          $d.symtab0x272080NOTYPE<unknown>DEFAULT13
          $d.symtab0x13cf80NOTYPE<unknown>DEFAULT2
          $d.symtab0x13db00NOTYPE<unknown>DEFAULT2
          $d.symtab0x13e700NOTYPE<unknown>DEFAULT2
          $d.symtab0x13f140NOTYPE<unknown>DEFAULT2
          $d.symtab0x272200NOTYPE<unknown>DEFAULT13
          $d.symtab0x272b80NOTYPE<unknown>DEFAULT13
          $d.symtab0x13fbc0NOTYPE<unknown>DEFAULT2
          $d.symtab0x1408c0NOTYPE<unknown>DEFAULT2
          $d.symtab0x141800NOTYPE<unknown>DEFAULT2
          $d.symtab0x142700NOTYPE<unknown>DEFAULT2
          $d.symtab0x1ea540NOTYPE<unknown>DEFAULT4
          $d.symtab0x144800NOTYPE<unknown>DEFAULT2
          $d.symtab0x145340NOTYPE<unknown>DEFAULT2
          $d.symtab0x272cc0NOTYPE<unknown>DEFAULT13
          $d.symtab0x1467c0NOTYPE<unknown>DEFAULT2
          $d.symtab0x14c980NOTYPE<unknown>DEFAULT2
          $d.symtab0x150680NOTYPE<unknown>DEFAULT2
          $d.symtab0x152540NOTYPE<unknown>DEFAULT2
          $d.symtab0x153800NOTYPE<unknown>DEFAULT2
          $d.symtab0x153900NOTYPE<unknown>DEFAULT2
          $d.symtab0x154200NOTYPE<unknown>DEFAULT2
          $d.symtab0x154b00NOTYPE<unknown>DEFAULT2
          $d.symtab0x155400NOTYPE<unknown>DEFAULT2
          $d.symtab0x1572c0NOTYPE<unknown>DEFAULT2
          $d.symtab0x157e00NOTYPE<unknown>DEFAULT2
          $d.symtab0x158400NOTYPE<unknown>DEFAULT2
          $d.symtab0x158940NOTYPE<unknown>DEFAULT2
          $d.symtab0x15c400NOTYPE<unknown>DEFAULT2
          $d.symtab0x272e40NOTYPE<unknown>DEFAULT13
          $d.symtab0x15d000NOTYPE<unknown>DEFAULT2
          $d.symtab0x15d300NOTYPE<unknown>DEFAULT2
          $d.symtab0x15db00NOTYPE<unknown>DEFAULT2
          $d.symtab0x15e2c0NOTYPE<unknown>DEFAULT2
          $d.symtab0x15e900NOTYPE<unknown>DEFAULT2
          $d.symtab0x15ef80NOTYPE<unknown>DEFAULT2
          $d.symtab0x15f980NOTYPE<unknown>DEFAULT2
          $d.symtab0x160240NOTYPE<unknown>DEFAULT2
          $d.symtab0x160600NOTYPE<unknown>DEFAULT2
          $d.symtab0x160a00NOTYPE<unknown>DEFAULT2
          $d.symtab0x160f80NOTYPE<unknown>DEFAULT2
          $d.symtab0x161380NOTYPE<unknown>DEFAULT2
          $d.symtab0x161780NOTYPE<unknown>DEFAULT2
          $d.symtab0x161d40NOTYPE<unknown>DEFAULT2
          $d.symtab0x162400NOTYPE<unknown>DEFAULT2
          $d.symtab0x164ac0NOTYPE<unknown>DEFAULT2
          $d.symtab0x1685c0NOTYPE<unknown>DEFAULT2
          $d.symtab0x169940NOTYPE<unknown>DEFAULT2
          $d.symtab0x16a700NOTYPE<unknown>DEFAULT2
          $d.symtab0x16c8c0NOTYPE<unknown>DEFAULT2
          $d.symtab0x176600NOTYPE<unknown>DEFAULT2
          $d.symtab0x1eb000NOTYPE<unknown>DEFAULT4
          $d.symtab0x177540NOTYPE<unknown>DEFAULT2
          $d.symtab0x17eb00NOTYPE<unknown>DEFAULT2
          $d.symtab0x17f400NOTYPE<unknown>DEFAULT2
          $d.symtab0x182b40NOTYPE<unknown>DEFAULT2
          $d.symtab0x1eb680NOTYPE<unknown>DEFAULT4
          $d.symtab0x188300NOTYPE<unknown>DEFAULT2
          $d.symtab0x1eb940NOTYPE<unknown>DEFAULT4
          $d.symtab0x18aac0NOTYPE<unknown>DEFAULT2
          $d.symtab0x190480NOTYPE<unknown>DEFAULT2
          $d.symtab0x1914c0NOTYPE<unknown>DEFAULT2
          $d.symtab0x1923c0NOTYPE<unknown>DEFAULT2
          $d.symtab0x193280NOTYPE<unknown>DEFAULT2
          $d.symtab0x194d40NOTYPE<unknown>DEFAULT2
          $d.symtab0x197240NOTYPE<unknown>DEFAULT2
          $d.symtab0x19ac80NOTYPE<unknown>DEFAULT2
          $d.symtab0x19b400NOTYPE<unknown>DEFAULT2
          $d.symtab0x19bb00NOTYPE<unknown>DEFAULT2
          $d.symtab0x19dec0NOTYPE<unknown>DEFAULT2
          $d.symtab0x19e4c0NOTYPE<unknown>DEFAULT2
          $d.symtab0x19efc0NOTYPE<unknown>DEFAULT2
          $d.symtab0x1a0540NOTYPE<unknown>DEFAULT2
          $d.symtab0x1a1000NOTYPE<unknown>DEFAULT2
          $d.symtab0x1a1e40NOTYPE<unknown>DEFAULT2
          $d.symtab0x1a5b00NOTYPE<unknown>DEFAULT2
          $d.symtab0x1a6d00NOTYPE<unknown>DEFAULT2
          $d.symtab0x1a7a40NOTYPE<unknown>DEFAULT2
          $d.symtab0x1a8900NOTYPE<unknown>DEFAULT2
          $d.symtab0x2c0NOTYPE<unknown>DEFAULT21
          $d.symtab0x4c0NOTYPE<unknown>DEFAULT21
          $d.symtab0x530NOTYPE<unknown>DEFAULT21
          $d.symtab0x1b7b00NOTYPE<unknown>DEFAULT2
          $d.symtab0x1c1580NOTYPE<unknown>DEFAULT2
          $d.symtab0x580NOTYPE<unknown>DEFAULT21
          $d.symtab0x00NOTYPE<unknown>DEFAULT23
          $d.symtab0x23c0NOTYPE<unknown>DEFAULT21
          $d.symtab0xe390NOTYPE<unknown>DEFAULT23
          $d.symtab0x270fc0NOTYPE<unknown>DEFAULT13
          $d.symtab0x1dad20NOTYPE<unknown>DEFAULT4
          C.1.4385.symtab0x1d5f832OBJECT<unknown>DEFAULT4
          C.11.5548.symtab0x1eac412OBJECT<unknown>DEFAULT4
          C.5.4489.symtab0x1ca9012OBJECT<unknown>DEFAULT4
          C.5.5083.symtab0x1ddd424OBJECT<unknown>DEFAULT4
          C.7.5370.symtab0x1ead012OBJECT<unknown>DEFAULT4
          C.7.6078.symtab0x1ddf812OBJECT<unknown>DEFAULT4
          C.7.6109.symtab0x1de2812OBJECT<unknown>DEFAULT4
          C.7.6182.symtab0x1de0412OBJECT<unknown>DEFAULT4
          C.7.6365.symtab0x1dedc12OBJECT<unknown>DEFAULT4
          C.8.6110.symtab0x1de1c12OBJECT<unknown>DEFAULT4
          C.9.6119.symtab0x1de1012OBJECT<unknown>DEFAULT4
          LOCAL_ADDR.symtab0x29e0c4OBJECT<unknown>DEFAULT14
          Laligned.symtab0x11b780NOTYPE<unknown>DEFAULT2
          Llastword.symtab0x11b940NOTYPE<unknown>DEFAULT2
          _Exit.symtab0x15e30104FUNC<unknown>DEFAULT2
          _GLOBAL_OFFSET_TABLE_.symtab0x270100OBJECT<unknown>HIDDEN12
          _Jv_RegisterClasses.symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
          _READ.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
          _Unwind_Complete.symtab0x1b5644FUNC<unknown>HIDDEN2
          _Unwind_DeleteException.symtab0x1b56844FUNC<unknown>HIDDEN2
          _Unwind_ForcedUnwind.symtab0x1c21836FUNC<unknown>HIDDEN2
          _Unwind_GetCFA.symtab0x1b55c8FUNC<unknown>HIDDEN2
          _Unwind_GetDataRelBase.symtab0x1b5a012FUNC<unknown>HIDDEN2
          _Unwind_GetLanguageSpecificData.symtab0x1c23c68FUNC<unknown>HIDDEN2
          _Unwind_GetRegionStart.symtab0x1c9dc52FUNC<unknown>HIDDEN2
          _Unwind_GetTextRelBase.symtab0x1b59412FUNC<unknown>HIDDEN2
          _Unwind_RaiseException.symtab0x1c1ac36FUNC<unknown>HIDDEN2
          _Unwind_Resume.symtab0x1c1d036FUNC<unknown>HIDDEN2
          _Unwind_Resume_or_Rethrow.symtab0x1c1f436FUNC<unknown>HIDDEN2
          _Unwind_VRS_Get.symtab0x1b4c476FUNC<unknown>HIDDEN2
          _Unwind_VRS_Pop.symtab0x1badc324FUNC<unknown>HIDDEN2
          _Unwind_VRS_Set.symtab0x1b51076FUNC<unknown>HIDDEN2
          _WRITE.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
          __C_ctype_b.symtab0x270fc4OBJECT<unknown>DEFAULT13
          __C_ctype_b.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
          __C_ctype_b_data.symtab0x1dad2768OBJECT<unknown>DEFAULT4
          __EH_FRAME_BEGIN__.symtab0x270000OBJECT<unknown>DEFAULT7
          __FRAME_END__.symtab0x270000OBJECT<unknown>DEFAULT7
          __GI___C_ctype_b.symtab0x270fc4OBJECT<unknown>HIDDEN13
          __GI___close.symtab0x153b0100FUNC<unknown>HIDDEN2
          __GI___close_nocancel.symtab0x1539424FUNC<unknown>HIDDEN2
          __GI___ctype_b.symtab0x271004OBJECT<unknown>HIDDEN13
          __GI___errno_location.symtab0xf37832FUNC<unknown>HIDDEN2
          __GI___fcntl_nocancel.symtab0xeac0152FUNC<unknown>HIDDEN2
          __GI___fgetc_unlocked.symtab0x18988300FUNC<unknown>HIDDEN2
          __GI___glibc_strerror_r.symtab0x11ed824FUNC<unknown>HIDDEN2
          __GI___libc_close.symtab0x153b0100FUNC<unknown>HIDDEN2
          __GI___libc_fcntl.symtab0xeb58244FUNC<unknown>HIDDEN2
          __GI___libc_open.symtab0x15440100FUNC<unknown>HIDDEN2
          __GI___libc_read.symtab0x15560100FUNC<unknown>HIDDEN2
          __GI___libc_write.symtab0x154d0100FUNC<unknown>HIDDEN2
          __GI___open.symtab0x15440100FUNC<unknown>HIDDEN2
          __GI___open_nocancel.symtab0x1542424FUNC<unknown>HIDDEN2
          __GI___read.symtab0x15560100FUNC<unknown>HIDDEN2
          __GI___read_nocancel.symtab0x1554424FUNC<unknown>HIDDEN2
          __GI___sigaddset.symtab0x1275836FUNC<unknown>HIDDEN2
          __GI___sigdelset.symtab0x1277c36FUNC<unknown>HIDDEN2
          __GI___sigismember.symtab0x1273436FUNC<unknown>HIDDEN2
          __GI___uClibc_fini.symtab0x15778124FUNC<unknown>HIDDEN2
          __GI___uClibc_init.symtab0x1584888FUNC<unknown>HIDDEN2
          __GI___write.symtab0x154d0100FUNC<unknown>HIDDEN2
          __GI___write_nocancel.symtab0x154b424FUNC<unknown>HIDDEN2
          __GI___xpg_strerror_r.symtab0x11ef0268FUNC<unknown>HIDDEN2
          __GI__exit.symtab0x15e30104FUNC<unknown>HIDDEN2
          __GI_abort.symtab0x13b30296FUNC<unknown>HIDDEN2
          __GI_accept.symtab0x12108116FUNC<unknown>HIDDEN2
          __GI_atoi.symtab0x1427c32FUNC<unknown>HIDDEN2
          __GI_bind.symtab0x1217c68FUNC<unknown>HIDDEN2
          __GI_brk.symtab0x19eb088FUNC<unknown>HIDDEN2
          __GI_close.symtab0x153b0100FUNC<unknown>HIDDEN2
          __GI_closedir.symtab0xef3c272FUNC<unknown>HIDDEN2
          __GI_config_close.symtab0x167e852FUNC<unknown>HIDDEN2
          __GI_config_open.symtab0x1681c72FUNC<unknown>HIDDEN2
          __GI_config_read.symtab0x164c0808FUNC<unknown>HIDDEN2
          __GI_connect.symtab0x12204116FUNC<unknown>HIDDEN2
          __GI_exit.symtab0x14490196FUNC<unknown>HIDDEN2
          __GI_fclose.symtab0xf3cc816FUNC<unknown>HIDDEN2
          __GI_fcntl.symtab0xeb58244FUNC<unknown>HIDDEN2
          __GI_fflush_unlocked.symtab0x11540940FUNC<unknown>HIDDEN2
          __GI_fgetc.symtab0x18844324FUNC<unknown>HIDDEN2
          __GI_fgetc_unlocked.symtab0x18988300FUNC<unknown>HIDDEN2
          __GI_fgets.symtab0x11174284FUNC<unknown>HIDDEN2
          __GI_fgets_unlocked.symtab0x118ec160FUNC<unknown>HIDDEN2
          __GI_fopen.symtab0xf6fc32FUNC<unknown>HIDDEN2
          __GI_fork.symtab0x14cc4972FUNC<unknown>HIDDEN2
          __GI_fprintf.symtab0xf79048FUNC<unknown>HIDDEN2
          __GI_fputs_unlocked.symtab0x1198c56FUNC<unknown>HIDDEN2
          __GI_fseek.symtab0x1a1f036FUNC<unknown>HIDDEN2
          __GI_fseeko64.symtab0x1a3f4448FUNC<unknown>HIDDEN2
          __GI_fstat.symtab0x15e98100FUNC<unknown>HIDDEN2
          __GI_fwrite_unlocked.symtab0x119c4188FUNC<unknown>HIDDEN2
          __GI_getc_unlocked.symtab0x18988300FUNC<unknown>HIDDEN2
          __GI_getdtablesize.symtab0x15f9c44FUNC<unknown>HIDDEN2
          __GI_getegid.symtab0x15fc820FUNC<unknown>HIDDEN2
          __GI_geteuid.symtab0x15fdc20FUNC<unknown>HIDDEN2
          __GI_getgid.symtab0x15ff020FUNC<unknown>HIDDEN2
          __GI_getpagesize.symtab0x1600440FUNC<unknown>HIDDEN2
          __GI_getpid.symtab0x1512872FUNC<unknown>HIDDEN2
          __GI_getrlimit.symtab0x1602c56FUNC<unknown>HIDDEN2
          __GI_getsockname.symtab0x1227868FUNC<unknown>HIDDEN2
          __GI_gettimeofday.symtab0x1606464FUNC<unknown>HIDDEN2
          __GI_getuid.symtab0x160a420FUNC<unknown>HIDDEN2
          __GI_inet_addr.symtab0x1209c40FUNC<unknown>HIDDEN2
          __GI_inet_aton.symtab0x193e4248FUNC<unknown>HIDDEN2
          __GI_initstate_r.symtab0x14098248FUNC<unknown>HIDDEN2
          __GI_ioctl.symtab0xec60224FUNC<unknown>HIDDEN2
          __GI_isatty.symtab0x11ffc36FUNC<unknown>HIDDEN2
          __GI_kill.symtab0xed4056FUNC<unknown>HIDDEN2
          __GI_listen.symtab0x1230464FUNC<unknown>HIDDEN2
          __GI_lseek64.symtab0x1a824112FUNC<unknown>HIDDEN2
          __GI_mbrtowc.symtab0x1a05c172FUNC<unknown>HIDDEN2
          __GI_mbsnrtowcs.symtab0x1a108232FUNC<unknown>HIDDEN2
          __GI_memchr.symtab0x18f60240FUNC<unknown>HIDDEN2
          __GI_memcpy.symtab0x11a804FUNC<unknown>HIDDEN2
          __GI_memmove.symtab0x18f504FUNC<unknown>HIDDEN2
          __GI_mempcpy.symtab0x1905036FUNC<unknown>HIDDEN2
          __GI_memrchr.symtab0x19074224FUNC<unknown>HIDDEN2
          __GI_memset.symtab0x11a90156FUNC<unknown>HIDDEN2
          __GI_mmap.symtab0x15c8c124FUNC<unknown>HIDDEN2
          __GI_mremap.symtab0x160b868FUNC<unknown>HIDDEN2
          __GI_munmap.symtab0x160fc64FUNC<unknown>HIDDEN2
          __GI_nanosleep.symtab0x1617c96FUNC<unknown>HIDDEN2
          __GI_open.symtab0x15440100FUNC<unknown>HIDDEN2
          __GI_opendir.symtab0xf11c196FUNC<unknown>HIDDEN2
          __GI_perror.symtab0xf71c116FUNC<unknown>HIDDEN2
          __GI_raise.symtab0x15170240FUNC<unknown>HIDDEN2
          __GI_random.symtab0x13c70164FUNC<unknown>HIDDEN2
          __GI_random_r.symtab0x13f30144FUNC<unknown>HIDDEN2
          __GI_read.symtab0x15560100FUNC<unknown>HIDDEN2
          __GI_readdir.symtab0xf290232FUNC<unknown>HIDDEN2
          __GI_readdir64.symtab0x163d4236FUNC<unknown>HIDDEN2
          __GI_recv.symtab0x12388112FUNC<unknown>HIDDEN2
          __GI_sbrk.symtab0x161dc108FUNC<unknown>HIDDEN2
          __GI_select.symtab0xedbc132FUNC<unknown>HIDDEN2
          __GI_send.symtab0x1243c112FUNC<unknown>HIDDEN2
          __GI_sendto.symtab0x124f8136FUNC<unknown>HIDDEN2
          __GI_setsid.symtab0xee4064FUNC<unknown>HIDDEN2
          __GI_setsockopt.symtab0x1258072FUNC<unknown>HIDDEN2
          __GI_setstate_r.symtab0x14190236FUNC<unknown>HIDDEN2
          __GI_sigaction.symtab0x15d34136FUNC<unknown>HIDDEN2
          __GI_sigaddset.symtab0x1260c80FUNC<unknown>HIDDEN2
          __GI_sigemptyset.symtab0x1265c20FUNC<unknown>HIDDEN2
          __GI_signal.symtab0x12670196FUNC<unknown>HIDDEN2
          __GI_sigprocmask.symtab0xee80140FUNC<unknown>HIDDEN2
          __GI_sleep.symtab0x15260300FUNC<unknown>HIDDEN2
          __GI_snprintf.symtab0xf7c048FUNC<unknown>HIDDEN2
          __GI_socket.symtab0x125c868FUNC<unknown>HIDDEN2
          __GI_srandom_r.symtab0x13fc0216FUNC<unknown>HIDDEN2
          __GI_sscanf.symtab0x1109c48FUNC<unknown>HIDDEN2
          __GI_strchr.symtab0x19154240FUNC<unknown>HIDDEN2
          __GI_strchrnul.symtab0x19244236FUNC<unknown>HIDDEN2
          __GI_strcmp.symtab0x11b3028FUNC<unknown>HIDDEN2
          __GI_strcoll.symtab0x11b3028FUNC<unknown>HIDDEN2
          __GI_strcpy.symtab0x1933036FUNC<unknown>HIDDEN2
          __GI_strcspn.symtab0x1935468FUNC<unknown>HIDDEN2
          __GI_strlen.symtab0x11b5096FUNC<unknown>HIDDEN2
          __GI_strncmp.symtab0x11bb0272FUNC<unknown>HIDDEN2
          __GI_strnlen.symtab0x11cc0204FUNC<unknown>HIDDEN2
          __GI_strrchr.symtab0x11d8c80FUNC<unknown>HIDDEN2
          __GI_strspn.symtab0x1939876FUNC<unknown>HIDDEN2
          __GI_strstr.symtab0x11ddc252FUNC<unknown>HIDDEN2
          __GI_strtol.symtab0x1429c28FUNC<unknown>HIDDEN2
          __GI_sysconf.symtab0x146a01572FUNC<unknown>HIDDEN2
          __GI_tcgetattr.symtab0x12020124FUNC<unknown>HIDDEN2
          __GI_time.symtab0xef0c48FUNC<unknown>HIDDEN2
          __GI_times.symtab0x1624820FUNC<unknown>HIDDEN2
          __GI_ungetc.symtab0x1a214480FUNC<unknown>HIDDEN2
          __GI_vfprintf.symtab0xff34324FUNC<unknown>HIDDEN2
          __GI_vfscanf.symtab0x177581896FUNC<unknown>HIDDEN2
          __GI_vsnprintf.symtab0xf7f0208FUNC<unknown>HIDDEN2
          __GI_vsscanf.symtab0x110cc168FUNC<unknown>HIDDEN2
          __GI_wcrtomb.symtab0x1686484FUNC<unknown>HIDDEN2
          __GI_wcsnrtombs.symtab0x168dc188FUNC<unknown>HIDDEN2
          __GI_wcsrtombs.symtab0x168b836FUNC<unknown>HIDDEN2
          __GI_write.symtab0x154d0100FUNC<unknown>HIDDEN2
          __JCR_END__.symtab0x2700c0OBJECT<unknown>DEFAULT11
          __JCR_LIST__.symtab0x2700c0OBJECT<unknown>DEFAULT11
          ___Unwind_ForcedUnwind.symtab0x1c21836FUNC<unknown>HIDDEN2
          ___Unwind_RaiseException.symtab0x1c1ac36FUNC<unknown>HIDDEN2
          ___Unwind_Resume.symtab0x1c1d036FUNC<unknown>HIDDEN2
          ___Unwind_Resume_or_Rethrow.symtab0x1c1f436FUNC<unknown>HIDDEN2
          __adddf3.symtab0x1a9e4784FUNC<unknown>HIDDEN2
          __aeabi_cdcmpeq.symtab0x1b34024FUNC<unknown>HIDDEN2
          __aeabi_cdcmple.symtab0x1b34024FUNC<unknown>HIDDEN2
          __aeabi_cdrcmple.symtab0x1b32452FUNC<unknown>HIDDEN2
          __aeabi_d2f.symtab0x1b424160FUNC<unknown>HIDDEN2
          __aeabi_d2uiz.symtab0x1b3d084FUNC<unknown>HIDDEN2
          __aeabi_dadd.symtab0x1a9e4784FUNC<unknown>HIDDEN2
          __aeabi_dcmpeq.symtab0x1b35824FUNC<unknown>HIDDEN2
          __aeabi_dcmpge.symtab0x1b3a024FUNC<unknown>HIDDEN2
          __aeabi_dcmpgt.symtab0x1b3b824FUNC<unknown>HIDDEN2
          __aeabi_dcmple.symtab0x1b38824FUNC<unknown>HIDDEN2
          __aeabi_dcmplt.symtab0x1b37024FUNC<unknown>HIDDEN2
          __aeabi_ddiv.symtab0x1b084524FUNC<unknown>HIDDEN2
          __aeabi_dmul.symtab0x1adf4656FUNC<unknown>HIDDEN2
          __aeabi_drsub.symtab0x1a9d80FUNC<unknown>HIDDEN2
          __aeabi_dsub.symtab0x1a9e0788FUNC<unknown>HIDDEN2
          __aeabi_f2d.symtab0x1ad4064FUNC<unknown>HIDDEN2
          __aeabi_i2d.symtab0x1ad1840FUNC<unknown>HIDDEN2
          __aeabi_idiv.symtab0x1a8940FUNC<unknown>HIDDEN2
          __aeabi_idivmod.symtab0x1a9c024FUNC<unknown>HIDDEN2
          __aeabi_l2d.symtab0x1ad9496FUNC<unknown>HIDDEN2
          __aeabi_read_tp.symtab0x15de08FUNC<unknown>DEFAULT2
          __aeabi_ui2d.symtab0x1acf436FUNC<unknown>HIDDEN2
          __aeabi_uidiv.symtab0xe9980FUNC<unknown>HIDDEN2
          __aeabi_uidivmod.symtab0xea9424FUNC<unknown>HIDDEN2
          __aeabi_ul2d.symtab0x1ad80116FUNC<unknown>HIDDEN2
          __aeabi_unwind_cpp_pr0.symtab0x1c1788FUNC<unknown>HIDDEN2
          __aeabi_unwind_cpp_pr1.symtab0x1c1708FUNC<unknown>HIDDEN2
          __aeabi_unwind_cpp_pr2.symtab0x1c1688FUNC<unknown>HIDDEN2
          __app_fini.symtab0x298b44OBJECT<unknown>HIDDEN14
          __atexit_lock.symtab0x272cc24OBJECT<unknown>DEFAULT13
          __bss_end__.symtab0x2a5900NOTYPE<unknown>DEFAULTSHN_ABS
          __bss_start.symtab0x272f00NOTYPE<unknown>DEFAULTSHN_ABS
          __bss_start__.symtab0x272f00NOTYPE<unknown>DEFAULTSHN_ABS
          __check_one_fd.symtab0x157f484FUNC<unknown>DEFAULT2
          __close.symtab0x153b0100FUNC<unknown>DEFAULT2
          __close_nocancel.symtab0x1539424FUNC<unknown>DEFAULT2
          __cmpdf2.symtab0x1b2a0132FUNC<unknown>HIDDEN2
          __ctype_b.symtab0x271004OBJECT<unknown>DEFAULT13
          __curbrk.symtab0x29df84OBJECT<unknown>HIDDEN14
          __cxa_begin_cleanup.symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
          __cxa_call_unexpected.symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
          __cxa_type_match.symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
          __data_start.symtab0x270bc0NOTYPE<unknown>DEFAULT13
          __default_rt_sa_restorer.symtab0x15dd40FUNC<unknown>DEFAULT2
          __default_sa_restorer.symtab0x15dc80FUNC<unknown>DEFAULT2
          __deregister_frame_info.symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
          __div0.symtab0xeaac20FUNC<unknown>HIDDEN2
          __divdf3.symtab0x1b084524FUNC<unknown>HIDDEN2
          __divsi3.symtab0x1a894300FUNC<unknown>HIDDEN2
          __do_global_dtors_aux.symtab0x80f00FUNC<unknown>DEFAULT2
          __do_global_dtors_aux_fini_array_entry.symtab0x270080OBJECT<unknown>DEFAULT10
          __end__.symtab0x2a5900NOTYPE<unknown>DEFAULTSHN_ABS
          __environ.symtab0x298ac4OBJECT<unknown>DEFAULT14
          __eqdf2.symtab0x1b2a0132FUNC<unknown>HIDDEN2
          __errno_location.symtab0xf37832FUNC<unknown>DEFAULT2
          __errno_location.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
          __exidx_end.symtab0x1ecf80NOTYPE<unknown>DEFAULTSHN_ABS
          __exidx_start.symtab0x1ebe00NOTYPE<unknown>DEFAULTSHN_ABS
          __exit_cleanup.symtab0x2935c4OBJECT<unknown>HIDDEN14
          __extendsfdf2.symtab0x1ad4064FUNC<unknown>HIDDEN2
          __fcntl_nocancel.symtab0xeac0152FUNC<unknown>DEFAULT2
          __fgetc_unlocked.symtab0x18988300FUNC<unknown>DEFAULT2
          __fini_array_end.symtab0x2700c0NOTYPE<unknown>HIDDEN10
          __fini_array_start.symtab0x270080NOTYPE<unknown>HIDDEN10
          __fixunsdfsi.symtab0x1b3d084FUNC<unknown>HIDDEN2
          __floatdidf.symtab0x1ad9496FUNC<unknown>HIDDEN2
          __floatsidf.symtab0x1ad1840FUNC<unknown>HIDDEN2
          __floatundidf.symtab0x1ad80116FUNC<unknown>HIDDEN2
          __floatunsidf.symtab0x1acf436FUNC<unknown>HIDDEN2
          __fork.symtab0x14cc4972FUNC<unknown>DEFAULT2
          __fork_generation_pointer.symtab0x2a55c4OBJECT<unknown>HIDDEN14
          __fork_handlers.symtab0x2a5604OBJECT<unknown>HIDDEN14
          __fork_lock.symtab0x293604OBJECT<unknown>HIDDEN14
          __frame_dummy_init_array_entry.symtab0x270040OBJECT<unknown>DEFAULT9
          __gedf2.symtab0x1b290148FUNC<unknown>HIDDEN2
          __getdents.symtab0x15efc160FUNC<unknown>HIDDEN2
          __getdents64.symtab0x19f14328FUNC<unknown>HIDDEN2
          __getpagesize.symtab0x1600440FUNC<unknown>DEFAULT2
          __getpid.symtab0x1512872FUNC<unknown>DEFAULT2
          __glibc_strerror_r.symtab0x11ed824FUNC<unknown>DEFAULT2
          __glibc_strerror_r.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
          __gnu_Unwind_Find_exidx.symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
          __gnu_Unwind_ForcedUnwind.symtab0x1b91c28FUNC<unknown>HIDDEN2
          __gnu_Unwind_RaiseException.symtab0x1ba04184FUNC<unknown>HIDDEN2
          __gnu_Unwind_Restore_VFP.symtab0x1c19c0FUNC<unknown>HIDDEN2
          __gnu_Unwind_Resume.symtab0x1b998108FUNC<unknown>HIDDEN2
          __gnu_Unwind_Resume_or_Rethrow.symtab0x1babc32FUNC<unknown>HIDDEN2
          __gnu_Unwind_Save_VFP.symtab0x1c1a40FUNC<unknown>HIDDEN2
          __gnu_unwind_execute.symtab0x1c2801812FUNC<unknown>HIDDEN2
          __gnu_unwind_frame.symtab0x1c99472FUNC<unknown>HIDDEN2
          __gnu_unwind_pr_common.symtab0x1bc201352FUNC<unknown>DEFAULT2
          __gtdf2.symtab0x1b290148FUNC<unknown>HIDDEN2
          __h_errno_location.symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
          __init_array_end.symtab0x270080NOTYPE<unknown>HIDDEN9
          __init_array_start.symtab0x270040NOTYPE<unknown>HIDDEN9
          __init_scan_cookie.symtab0x17edc108FUNC<unknown>HIDDEN2
          __ledf2.symtab0x1b298140FUNC<unknown>HIDDEN2
          __libc_accept.symtab0x12108116FUNC<unknown>DEFAULT2
          __libc_close.symtab0x153b0100FUNC<unknown>DEFAULT2
          __libc_connect.symtab0x12204116FUNC<unknown>DEFAULT2
          __libc_disable_asynccancel.symtab0x155d0136FUNC<unknown>HIDDEN2
          __libc_enable_asynccancel.symtab0x15658220FUNC<unknown>HIDDEN2
          __libc_errno.symtab0x04TLS<unknown>HIDDEN8
          __libc_fcntl.symtab0xeb58244FUNC<unknown>DEFAULT2
          __libc_fork.symtab0x14cc4972FUNC<unknown>DEFAULT2
          __libc_h_errno.symtab0x44TLS<unknown>HIDDEN8
          __libc_multiple_threads.symtab0x2a5644OBJECT<unknown>HIDDEN14
          __libc_nanosleep.symtab0x1617c96FUNC<unknown>DEFAULT2
          __libc_open.symtab0x15440100FUNC<unknown>DEFAULT2
          __libc_read.symtab0x15560100FUNC<unknown>DEFAULT2
          __libc_recv.symtab0x12388112FUNC<unknown>DEFAULT2
          __libc_select.symtab0xedbc132FUNC<unknown>DEFAULT2
          __libc_send.symtab0x1243c112FUNC<unknown>DEFAULT2
          __libc_sendto.symtab0x124f8136FUNC<unknown>DEFAULT2
          __libc_setup_tls.symtab0x19be4560FUNC<unknown>DEFAULT2
          __libc_sigaction.symtab0x15d34136FUNC<unknown>DEFAULT2
          __libc_stack_end.symtab0x298a84OBJECT<unknown>DEFAULT14
          __libc_write.symtab0x154d0100FUNC<unknown>DEFAULT2
          __lll_lock_wait_private.symtab0x15090152FUNC<unknown>HIDDEN2
          __ltdf2.symtab0x1b298140FUNC<unknown>HIDDEN2
          __malloc_consolidate.symtab0x13700436FUNC<unknown>HIDDEN2
          __malloc_largebin_index.symtab0x127a0120FUNC<unknown>DEFAULT2
          __malloc_lock.symtab0x271f024OBJECT<unknown>DEFAULT13
          __malloc_state.symtab0x2a1e4888OBJECT<unknown>DEFAULT14
          __malloc_trim.symtab0x13650176FUNC<unknown>DEFAULT2
          __muldf3.symtab0x1adf4656FUNC<unknown>HIDDEN2
          __nedf2.symtab0x1b2a0132FUNC<unknown>HIDDEN2
          __nptl_deallocate_tsd.symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
          __nptl_nthreads.symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
          __open.symtab0x15440100FUNC<unknown>DEFAULT2
          __open_nocancel.symtab0x1542424FUNC<unknown>DEFAULT2
          __pagesize.symtab0x298b04OBJECT<unknown>DEFAULT14
          __preinit_array_end.symtab0x270040NOTYPE<unknown>HIDDEN8
          __preinit_array_start.symtab0x270040NOTYPE<unknown>HIDDEN8
          __progname.symtab0x272e84OBJECT<unknown>DEFAULT13
          __progname_full.symtab0x272ec4OBJECT<unknown>DEFAULT13
          __psfs_do_numeric.symtab0x182d41392FUNC<unknown>HIDDEN2
          __psfs_do_numeric.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
          __psfs_parse_spec.symtab0x18010708FUNC<unknown>HIDDEN2
          __psfs_parse_spec.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
          __pthread_initialize_minimal.symtab0x19e1412FUNC<unknown>DEFAULT2
          __pthread_mutex_init.symtab0x1573c8FUNC<unknown>DEFAULT2
          __pthread_mutex_lock.symtab0x157348FUNC<unknown>DEFAULT2
          __pthread_mutex_trylock.symtab0x157348FUNC<unknown>DEFAULT2
          __pthread_mutex_unlock.symtab0x157348FUNC<unknown>DEFAULT2
          __pthread_return_0.symtab0x157348FUNC<unknown>DEFAULT2
          __pthread_unwind.symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
          __read.symtab0x15560100FUNC<unknown>DEFAULT2
          __read_nocancel.symtab0x1554424FUNC<unknown>DEFAULT2
          __register_frame_info.symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
          __restore_core_regs.symtab0x1c18028FUNC<unknown>HIDDEN2
          __rtld_fini.symtab0x298b84OBJECT<unknown>HIDDEN14
          __scan_cookie.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
          __scan_getc.symtab0x17f48132FUNC<unknown>HIDDEN2
          __scan_ungetc.symtab0x17fcc68FUNC<unknown>HIDDEN2
          __sigaddset.symtab0x1275836FUNC<unknown>DEFAULT2
          __sigdelset.symtab0x1277c36FUNC<unknown>DEFAULT2
          __sigismember.symtab0x1273436FUNC<unknown>DEFAULT2
          __sigjmp_save.symtab0x1a7e464FUNC<unknown>HIDDEN2
          __sigsetjmp.symtab0x19f0812FUNC<unknown>DEFAULT2
          __stdin.symtab0x271144OBJECT<unknown>DEFAULT13
          __stdio_READ.symtab0x1a5b488FUNC<unknown>HIDDEN2
          __stdio_WRITE.symtab0x16998220FUNC<unknown>HIDDEN2
          __stdio_adjust_position.symtab0x1a60c200FUNC<unknown>HIDDEN2
          __stdio_fwrite.symtab0x16a74320FUNC<unknown>HIDDEN2
          __stdio_rfill.symtab0x1a6d448FUNC<unknown>HIDDEN2
          __stdio_seek.symtab0x1a7a860FUNC<unknown>HIDDEN2
          __stdio_trans2r_o.symtab0x1a704164FUNC<unknown>HIDDEN2
          __stdio_trans2w_o.symtab0x16bb4220FUNC<unknown>HIDDEN2
          __stdio_wcommit.symtab0xff0448FUNC<unknown>HIDDEN2
          __stdout.symtab0x271184OBJECT<unknown>DEFAULT13
          __strtofpmax.symtab0x19734940FUNC<unknown>HIDDEN2
          __strtofpmax.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
          __subdf3.symtab0x1a9e0788FUNC<unknown>HIDDEN2
          __sys_accept.symtab0x120c468FUNC<unknown>DEFAULT2
          __sys_connect.symtab0x121c068FUNC<unknown>DEFAULT2
          __sys_recv.symtab0x1234468FUNC<unknown>DEFAULT2
          __sys_send.symtab0x123f868FUNC<unknown>DEFAULT2
          __sys_sendto.symtab0x124ac76FUNC<unknown>DEFAULT2
          __syscall_error.symtab0x15d0844FUNC<unknown>HIDDEN2
          __syscall_error.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
          __syscall_fcntl.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
          __syscall_nanosleep.symtab0x1613c64FUNC<unknown>DEFAULT2
          __syscall_rt_sigaction.symtab0x15df064FUNC<unknown>DEFAULT2
          __syscall_rt_sigaction.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
          __syscall_select.symtab0xed7868FUNC<unknown>DEFAULT2
          __tls_get_addr.symtab0x19bc036FUNC<unknown>DEFAULT2
          __truncdfsf2.symtab0x1b424160FUNC<unknown>HIDDEN2
          __uClibc_fini.symtab0x15778124FUNC<unknown>DEFAULT2
          __uClibc_init.symtab0x1584888FUNC<unknown>DEFAULT2
          __uClibc_main.symtab0x158a01004FUNC<unknown>DEFAULT2
          __uClibc_main.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
          __uclibc_progname.symtab0x272e44OBJECT<unknown>HIDDEN13
          __udivsi3.symtab0xe998252FUNC<unknown>HIDDEN2
          __write.symtab0x154d0100FUNC<unknown>DEFAULT2
          __write_nocancel.symtab0x154b424FUNC<unknown>DEFAULT2
          __xpg_strerror_r.symtab0x11ef0268FUNC<unknown>DEFAULT2
          __xpg_strerror_r.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
          __xstat32_conv.symtab0x16328172FUNC<unknown>HIDDEN2
          __xstat64_conv.symtab0x1625c204FUNC<unknown>HIDDEN2
          _adjust_pos.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
          _bss_custom_printf_spec.symtab0x2934c10OBJECT<unknown>DEFAULT14
          _bss_end__.symtab0x2a5900NOTYPE<unknown>DEFAULTSHN_ABS
          _charpad.symtab0x1007884FUNC<unknown>DEFAULT2
          _cs_funcs.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
          _custom_printf_arginfo.symtab0x2a18c40OBJECT<unknown>HIDDEN14
          _custom_printf_handler.symtab0x2a1b440OBJECT<unknown>HIDDEN14
          _custom_printf_spec.symtab0x271ec4OBJECT<unknown>HIDDEN13
          _dl_aux_init.symtab0x19e2056FUNC<unknown>DEFAULT2
          _dl_nothread_init_static_tls.symtab0x19e5888FUNC<unknown>HIDDEN2
          _dl_phdr.symtab0x2a5884OBJECT<unknown>DEFAULT14
          _dl_phnum.symtab0x2a58c4OBJECT<unknown>DEFAULT14
          _dl_tls_dtv_gaps.symtab0x2a57c1OBJECT<unknown>DEFAULT14
          _dl_tls_dtv_slotinfo_list.symtab0x2a5784OBJECT<unknown>DEFAULT14
          _dl_tls_generation.symtab0x2a5804OBJECT<unknown>DEFAULT14
          _dl_tls_max_dtv_idx.symtab0x2a5704OBJECT<unknown>DEFAULT14
          _dl_tls_setup.symtab0x19b58104FUNC<unknown>DEFAULT2
          _dl_tls_static_align.symtab0x2a56c4OBJECT<unknown>DEFAULT14
          _dl_tls_static_nelem.symtab0x2a5844OBJECT<unknown>DEFAULT14
          _dl_tls_static_size.symtab0x2a5744OBJECT<unknown>DEFAULT14
          _dl_tls_static_used.symtab0x2a5684OBJECT<unknown>DEFAULT14
          _edata.symtab0x272f00NOTYPE<unknown>DEFAULTSHN_ABS
          _end.symtab0x2a5900NOTYPE<unknown>DEFAULTSHN_ABS
          _exit.symtab0x15e30104FUNC<unknown>DEFAULT2
          _exit.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
          _fini.symtab0x1ca100FUNC<unknown>DEFAULT3
          _fixed_buffers.symtab0x2734c8192OBJECT<unknown>DEFAULT14
          _fopen.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
          _fp_out_narrow.symtab0x100cc132FUNC<unknown>DEFAULT2
          _fpmaxtostr.symtab0x16e8c2036FUNC<unknown>HIDDEN2
          _fpmaxtostr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
          _fwrite.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
          _init.symtab0x80d40FUNC<unknown>DEFAULT1
          _load_inttype.symtab0x16c90116FUNC<unknown>HIDDEN2
          _load_inttype.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
          _memcpy.symtab0x18ac00FUNC<unknown>HIDDEN2
          _ppfs_init.symtab0x10844160FUNC<unknown>HIDDEN2
          _ppfs_init.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
          _ppfs_parsespec.symtab0x10b2c1392FUNC<unknown>HIDDEN2
          _ppfs_parsespec.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
          _ppfs_prepargs.symtab0x108e468FUNC<unknown>HIDDEN2
          _ppfs_prepargs.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
          _ppfs_setargs.symtab0x10928432FUNC<unknown>HIDDEN2
          _ppfs_setargs.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
          _promoted_size.symtab0x10ad884FUNC<unknown>DEFAULT2
          _pthread_cleanup_pop_restore.symtab0x1574c44FUNC<unknown>DEFAULT2
          _pthread_cleanup_push_defer.symtab0x157448FUNC<unknown>DEFAULT2
          _rfill.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
          _setjmp.symtab0x15dbc8FUNC<unknown>DEFAULT2
          _sigintr.symtab0x2a1dc8OBJECT<unknown>HIDDEN14
          _start.symtab0x81940FUNC<unknown>DEFAULT2
          _stdio.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
          _stdio_fopen.symtab0xf8c01120FUNC<unknown>HIDDEN2
          _stdio_init.symtab0xfd20128FUNC<unknown>HIDDEN2
          _stdio_openlist.symtab0x2711c4OBJECT<unknown>DEFAULT13
          _stdio_openlist_add_lock.symtab0x2732c12OBJECT<unknown>DEFAULT14
          _stdio_openlist_dec_use.symtab0x11290688FUNC<unknown>HIDDEN2
          _stdio_openlist_del_count.symtab0x273484OBJECT<unknown>DEFAULT14
          _stdio_openlist_del_lock.symtab0x2733812OBJECT<unknown>DEFAULT14
          _stdio_openlist_use_count.symtab0x273444OBJECT<unknown>DEFAULT14
          _stdio_streams.symtab0x27120204OBJECT<unknown>DEFAULT13
          _stdio_term.symtab0xfda0356FUNC<unknown>HIDDEN2
          _stdio_user_locking.symtab0x271044OBJECT<unknown>DEFAULT13
          _stdlib_strto_l.symtab0x142b8472FUNC<unknown>HIDDEN2
          _stdlib_strto_l.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
          _stdlib_strto_ll.symtab0x194dc600FUNC<unknown>HIDDEN2
          _stdlib_strto_ll.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
          _store_inttype.symtab0x16d0444FUNC<unknown>HIDDEN2
          _store_inttype.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
          _string_syserrmsgs.symtab0x1def82906OBJECT<unknown>HIDDEN4
          _string_syserrmsgs.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
          _trans2r.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
          _trans2w.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
          _uintmaxtostr.symtab0x16d30348FUNC<unknown>HIDDEN2
          _uintmaxtostr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
          _vfprintf_internal.symtab0x101501780FUNC<unknown>HIDDEN2
          _vfprintf_internal.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
          _wcommit.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
          abort.symtab0x13b30296FUNC<unknown>DEFAULT2
          abort.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
          accept.symtab0x12108116FUNC<unknown>DEFAULT2
          accept.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
          anti_gdb_entry.symtab0xbc5024FUNC<unknown>DEFAULT2
          atoi.symtab0x1427c32FUNC<unknown>DEFAULT2
          atol.symtab0x1427c32FUNC<unknown>DEFAULT2
          atol.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
          attack.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
          attack_game.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
          attack_game_samp.symtab0x8908760FUNC<unknown>DEFAULT2
          attack_get_opt_int.symtab0x8554112FUNC<unknown>DEFAULT2
          attack_get_opt_ip.symtab0x84e8108FUNC<unknown>DEFAULT2
          attack_init.symtab0x85c4836FUNC<unknown>DEFAULT2
          attack_method_hexflood.symtab0xa81c688FUNC<unknown>DEFAULT2
          attack_method_nudp.symtab0xb0601668FUNC<unknown>DEFAULT2
          attack_method_ovh.symtab0x983c1708FUNC<unknown>DEFAULT2
          attack_method_raw.symtab0x9ee81684FUNC<unknown>DEFAULT2
          attack_method_std.symtab0xa57c672FUNC<unknown>DEFAULT2
          attack_method_stdhex.symtab0xad80736FUNC<unknown>DEFAULT2
          attack_method_synflood.symtab0x8c001424FUNC<unknown>DEFAULT2
          attack_method_tcp.symtab0x91901708FUNC<unknown>DEFAULT2
          attack_method_udphex.symtab0xaacc692FUNC<unknown>DEFAULT2
          attack_parse.symtab0x82cc540FUNC<unknown>DEFAULT2
          attack_start.symtab0x81d0252FUNC<unknown>DEFAULT2
          attack_tcp.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
          attack_udp.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
          been_there_done_that.symtab0x293584OBJECT<unknown>DEFAULT14
          bind.symtab0x1217c68FUNC<unknown>DEFAULT2
          bind.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
          brk.symtab0x19eb088FUNC<unknown>DEFAULT2
          brk.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
          bsd_signal.symtab0x12670196FUNC<unknown>DEFAULT2
          calloc.symtab0x13150320FUNC<unknown>DEFAULT2
          calloc.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
          chacha_block.symtab0xc9c01596FUNC<unknown>DEFAULT2
          chacha_key.symtab0x270cd32OBJECT<unknown>DEFAULT13
          chacha_nonce.symtab0x270ed12OBJECT<unknown>DEFAULT13
          checksum.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
          checksum_generic.symtab0xb6e480FUNC<unknown>DEFAULT2
          checksum_tcpudp.symtab0xb734164FUNC<unknown>DEFAULT2
          clock.symtab0xf39852FUNC<unknown>DEFAULT2
          clock.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
          close.symtab0x153b0100FUNC<unknown>DEFAULT2
          closedir.symtab0xef3c272FUNC<unknown>DEFAULT2
          closedir.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
          completed.5105.symtab0x272f01OBJECT<unknown>DEFAULT14
          connect.symtab0x12204116FUNC<unknown>DEFAULT2
          connect.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
          crtstuff.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
          crtstuff.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
          decpt_str.symtab0x1eb482OBJECT<unknown>DEFAULT4
          dl-support.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
          ensure_single_instance.symtab0xbcb0336FUNC<unknown>DEFAULT2
          environ.symtab0x298ac4OBJECT<unknown>DEFAULT14
          errno.symtab0x04TLS<unknown>DEFAULT8
          errno.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
          exit.symtab0x14490196FUNC<unknown>DEFAULT2
          exit.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
          exp10_table.symtab0x1eb0072OBJECT<unknown>DEFAULT4
          fclose.symtab0xf3cc816FUNC<unknown>DEFAULT2
          fclose.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
          fcntl.symtab0xeb58244FUNC<unknown>DEFAULT2
          Skipped network analysis since the amount of network traffic is too extensive. Please download the PCAP and check manually.

          System Behavior

          Start time (UTC):06:03:37
          Start date (UTC):21/04/2025
          Path:/tmp/vision.arm7.elf
          Arguments:/tmp/vision.arm7.elf
          File size:4956856 bytes
          MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

          Start time (UTC):06:03:38
          Start date (UTC):21/04/2025
          Path:/tmp/vision.arm7.elf
          Arguments:-
          File size:4956856 bytes
          MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

          Start time (UTC):06:03:38
          Start date (UTC):21/04/2025
          Path:/tmp/vision.arm7.elf
          Arguments:-
          File size:4956856 bytes
          MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

          Start time (UTC):06:03:40
          Start date (UTC):21/04/2025
          Path:/tmp/vision.arm7.elf
          Arguments:-
          File size:4956856 bytes
          MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

          Start time (UTC):06:03:44
          Start date (UTC):21/04/2025
          Path:/tmp/vision.arm7.elf
          Arguments:-
          File size:4956856 bytes
          MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

          Start time (UTC):06:03:50
          Start date (UTC):21/04/2025
          Path:/tmp/vision.arm7.elf
          Arguments:-
          File size:4956856 bytes
          MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

          Start time (UTC):06:04:47
          Start date (UTC):21/04/2025
          Path:/tmp/vision.arm7.elf
          Arguments:-
          File size:4956856 bytes
          MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

          Start time (UTC):06:04:47
          Start date (UTC):21/04/2025
          Path:/tmp/vision.arm7.elf
          Arguments:-
          File size:4956856 bytes
          MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1