Edit tour

Linux Analysis Report
bot.i486.elf

Overview

General Information

Sample name:bot.i486.elf
Analysis ID:1671910
MD5:d696effe3fa83dd1daec511187a5554e
SHA1:1f2ee7bf1cefe22ae28052aa6df15306614c51fe
SHA256:4ca24b72cdcb14e1948e01f480dbaf39042f98fb91eeefbb6cdd61a330041177
Tags:elfuser-abuse_ch
Infos:

Detection

Score:60
Range:0 - 100

Signatures

Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Contains symbols with names commonly found in malware
Executes the "rm" command used to delete files or directories
Sample and/or dropped files contains symbols with suspicious names
Yara signature match

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
Joe Sandbox version:42.0.0 Malachite
Analysis ID:1671910
Start date and time:2025-04-23 12:12:28 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 31s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:bot.i486.elf
Detection:MAL
Classification:mal60.linELF@0/0@0/0
Command:/tmp/bot.i486.elf
PID:6232
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:

Standard Error:
  • system is lnxubuntu20
  • bot.i486.elf (PID: 6232, Parent: 6155, MD5: d696effe3fa83dd1daec511187a5554e) Arguments: /tmp/bot.i486.elf
  • dash New Fork (PID: 6288, Parent: 4331)
  • rm (PID: 6288, Parent: 4331, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.Jqw8vI3RPK /tmp/tmp.CADM4lX4xv /tmp/tmp.Wn7iLqPsuo
  • dash New Fork (PID: 6289, Parent: 4331)
  • rm (PID: 6289, Parent: 4331, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.Jqw8vI3RPK /tmp/tmp.CADM4lX4xv /tmp/tmp.Wn7iLqPsuo
  • cleanup
SourceRuleDescriptionAuthorStrings
bot.i486.elfLinux_Trojan_Mirai_3a56423bunknownunknown
  • 0xc0af:$a: 24 1C 8B 44 24 20 0F B6 D0 C1 E8 08 89 54 24 24 89 44 24 20 BA 01 00
SourceRuleDescriptionAuthorStrings
6232.1.0000000008048000.0000000008056000.r-x.sdmpLinux_Trojan_Mirai_3a56423bunknownunknown
  • 0xc0af:$a: 24 1C 8B 44 24 20 0F B6 D0 C1 E8 08 89 54 24 24 89 44 24 20 BA 01 00
6233.1.0000000008048000.0000000008056000.r-x.sdmpLinux_Trojan_Mirai_3a56423bunknownunknown
  • 0xc0af:$a: 24 1C 8B 44 24 20 0F B6 D0 C1 E8 08 89 54 24 24 89 44 24 20 BA 01 00
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: bot.i486.elfReversingLabs: Detection: 13%
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 34.249.145.219
Source: unknownTCP traffic detected without corresponding DNS query: 34.249.145.219
Source: unknownTCP traffic detected without corresponding DNS query: 34.249.145.219
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 34.249.145.219
Source: unknownNetwork traffic detected: HTTP traffic on port 39246 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39246
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443

System Summary

barindex
Source: bot.i486.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_3a56423b Author: unknown
Source: 6232.1.0000000008048000.0000000008056000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_3a56423b Author: unknown
Source: 6233.1.0000000008048000.0000000008056000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_3a56423b Author: unknown
Source: ELF static info symbol of initial sampleName: attack_running
Source: bot.i486.elfELF static info symbol of initial sample: execute_command
Source: bot.i486.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_3a56423b os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 117d6eb47f000c9d475119ca0e6a1b49a91bbbece858758aaa3d7f30d0777d75, id = 3a56423b-c0cf-4483-87e3-552beb40563a, last_modified = 2021-09-16
Source: 6232.1.0000000008048000.0000000008056000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_3a56423b os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 117d6eb47f000c9d475119ca0e6a1b49a91bbbece858758aaa3d7f30d0777d75, id = 3a56423b-c0cf-4483-87e3-552beb40563a, last_modified = 2021-09-16
Source: 6233.1.0000000008048000.0000000008056000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_3a56423b os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 117d6eb47f000c9d475119ca0e6a1b49a91bbbece858758aaa3d7f30d0777d75, id = 3a56423b-c0cf-4483-87e3-552beb40563a, last_modified = 2021-09-16
Source: classification engineClassification label: mal60.linELF@0/0@0/0
Source: /usr/bin/dash (PID: 6288)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.Jqw8vI3RPK /tmp/tmp.CADM4lX4xv /tmp/tmp.Wn7iLqPsuoJump to behavior
Source: /usr/bin/dash (PID: 6289)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.Jqw8vI3RPK /tmp/tmp.CADM4lX4xv /tmp/tmp.Wn7iLqPsuoJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
File Deletion
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1671910 Sample: bot.i486.elf Startdate: 23/04/2025 Architecture: LINUX Score: 60 15 109.202.202.202, 80 INIT7CH Switzerland 2->15 17 91.189.91.42, 443 CANONICAL-ASGB United Kingdom 2->17 19 2 other IPs or domains 2->19 21 Malicious sample detected (through community Yara rule) 2->21 23 Multi AV Scanner detection for submitted file 2->23 25 Contains symbols with names commonly found in malware 2->25 7 bot.i486.elf 2->7         started        9 dash rm 2->9         started        11 dash rm 2->11         started        signatures3 process4 process5 13 bot.i486.elf 7->13         started       
SourceDetectionScannerLabelLink
bot.i486.elf14%ReversingLabs
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

No contacted domains info
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs
IPDomainCountryFlagASNASN NameMalicious
34.249.145.219
unknownUnited States
16509AMAZON-02USfalse
109.202.202.202
unknownSwitzerland
13030INIT7CHfalse
91.189.91.43
unknownUnited Kingdom
41231CANONICAL-ASGBfalse
91.189.91.42
unknownUnited Kingdom
41231CANONICAL-ASGBfalse
MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
34.249.145.219meihao.mpsl.elfGet hashmaliciousUnknownBrowse
    na.elfGet hashmaliciousPrometeiBrowse
      bin.sh.elfGet hashmaliciousMiraiBrowse
        na.elfGet hashmaliciousPrometeiBrowse
          na.elfGet hashmaliciousPrometeiBrowse
            na.elfGet hashmaliciousPrometeiBrowse
              na.elfGet hashmaliciousPrometeiBrowse
                .i.elfGet hashmaliciousUnknownBrowse
                  na.elfGet hashmaliciousPrometeiBrowse
                    na.elfGet hashmaliciousPrometeiBrowse
                      109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
                      • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
                      91.189.91.43meihao.mpsl.elfGet hashmaliciousUnknownBrowse
                        meihao.arm6.elfGet hashmaliciousMiraiBrowse
                          meihao.arc.elfGet hashmaliciousMiraiBrowse
                            na.elfGet hashmaliciousPrometeiBrowse
                              na.elfGet hashmaliciousPrometeiBrowse
                                i.elfGet hashmaliciousUnknownBrowse
                                  na.elfGet hashmaliciousPrometeiBrowse
                                    bin.sh.elfGet hashmaliciousMiraiBrowse
                                      na.elfGet hashmaliciousPrometeiBrowse
                                        na.elfGet hashmaliciousPrometeiBrowse
                                          91.189.91.42meihao.mpsl.elfGet hashmaliciousUnknownBrowse
                                            meihao.arm6.elfGet hashmaliciousMiraiBrowse
                                              meihao.arc.elfGet hashmaliciousMiraiBrowse
                                                na.elfGet hashmaliciousPrometeiBrowse
                                                  na.elfGet hashmaliciousPrometeiBrowse
                                                    i.elfGet hashmaliciousUnknownBrowse
                                                      na.elfGet hashmaliciousPrometeiBrowse
                                                        bin.sh.elfGet hashmaliciousMiraiBrowse
                                                          na.elfGet hashmaliciousPrometeiBrowse
                                                            na.elfGet hashmaliciousPrometeiBrowse
                                                              No context
                                                              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                              CANONICAL-ASGBmeihao.mpsl.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              meihao.arm6.elfGet hashmaliciousMiraiBrowse
                                                              • 91.189.91.42
                                                              meihao.arc.elfGet hashmaliciousMiraiBrowse
                                                              • 91.189.91.42
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 91.189.91.42
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 91.189.91.42
                                                              i.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 91.189.91.42
                                                              bin.sh.elfGet hashmaliciousMiraiBrowse
                                                              • 91.189.91.42
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 91.189.91.42
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 185.125.190.26
                                                              CANONICAL-ASGBmeihao.mpsl.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              meihao.arm6.elfGet hashmaliciousMiraiBrowse
                                                              • 91.189.91.42
                                                              meihao.arc.elfGet hashmaliciousMiraiBrowse
                                                              • 91.189.91.42
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 91.189.91.42
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 91.189.91.42
                                                              i.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 91.189.91.42
                                                              bin.sh.elfGet hashmaliciousMiraiBrowse
                                                              • 91.189.91.42
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 91.189.91.42
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 185.125.190.26
                                                              INIT7CHmeihao.mpsl.elfGet hashmaliciousUnknownBrowse
                                                              • 109.202.202.202
                                                              meihao.arm6.elfGet hashmaliciousMiraiBrowse
                                                              • 109.202.202.202
                                                              meihao.arc.elfGet hashmaliciousMiraiBrowse
                                                              • 109.202.202.202
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 109.202.202.202
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 109.202.202.202
                                                              i.elfGet hashmaliciousUnknownBrowse
                                                              • 109.202.202.202
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 109.202.202.202
                                                              bin.sh.elfGet hashmaliciousMiraiBrowse
                                                              • 109.202.202.202
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 109.202.202.202
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 109.202.202.202
                                                              AMAZON-02USmeihao.mpsl.elfGet hashmaliciousMiraiBrowse
                                                              • 54.217.77.5
                                                              meihao.mpsl.elfGet hashmaliciousUnknownBrowse
                                                              • 34.249.145.219
                                                              https://coinrh.com/Get hashmaliciousUnknownBrowse
                                                              • 13.33.21.102
                                                              Modelo3_hcib.vbsGet hashmaliciousUnknownBrowse
                                                              • 3.3.9.1
                                                              https://coinrh.com/Get hashmaliciousUnknownBrowse
                                                              • 13.33.21.102
                                                              spreadsheet.exeGet hashmaliciousFormBookBrowse
                                                              • 13.248.169.48
                                                              https://fromsmash.com/TBlvw0JrK4-ct?e=cmVnaW9uYWxAZm9zdGVyLWdhbWtvLmNvbQ==Get hashmaliciousHTMLPhisherBrowse
                                                              • 18.154.132.127
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 54.171.230.55
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 34.249.145.219
                                                              i.elfGet hashmaliciousUnknownBrowse
                                                              • 54.171.230.55
                                                              No context
                                                              No context
                                                              No created / dropped files found
                                                              File type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, with debug_info, not stripped
                                                              Entropy (8bit):6.268875071580512
                                                              TrID:
                                                              • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
                                                              • ELF Executable and Linkable format (generic) (4004/1) 49.84%
                                                              File name:bot.i486.elf
                                                              File size:76'151 bytes
                                                              MD5:d696effe3fa83dd1daec511187a5554e
                                                              SHA1:1f2ee7bf1cefe22ae28052aa6df15306614c51fe
                                                              SHA256:4ca24b72cdcb14e1948e01f480dbaf39042f98fb91eeefbb6cdd61a330041177
                                                              SHA512:fac3141a357d80497406b708015ce10e0ef0092ed8c4b5dd33b59133378efb2c199d9b0e45e2851aca14d6e47f5f10c2a4a426510a4c25698067e12e3e87ad20
                                                              SSDEEP:1536:kIO/+qAEPI/wqnJofOx9WUH31gT2dy8Gr0E9eFB305:kpPI/wJWq2xO00eFBG
                                                              TLSH:2E734C49F793E4B2C8870B7102ABA7798730ED520725CE1AE31C7FF49E22781B55A61D
                                                              File Content Preview:.ELF....................d...4...........4. ...(.....................0...0...............0...0h..0h..0...x...........Q.td................................t..../..................U......=`i...t..D....................h......h......u........t....h0h...........

                                                              ELF header

                                                              Class:ELF32
                                                              Data:2's complement, little endian
                                                              Version:1 (current)
                                                              Machine:Intel 80386
                                                              Version Number:0x1
                                                              Type:EXEC (Executable file)
                                                              OS/ABI:UNIX - System V
                                                              ABI Version:0
                                                              Entry Point Address:0x8048164
                                                              Flags:0x0
                                                              ELF Header Size:52
                                                              Program Header Offset:52
                                                              Program Header Size:32
                                                              Number of Program Headers:3
                                                              Section Header Offset:62856
                                                              Section Header Size:40
                                                              Number of Section Headers:25
                                                              Header String Table Index:22
                                                              NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                              NULL0x00x00x00x00x0000
                                                              .initPROGBITS0x80480940x940x110x00x6AX001
                                                              .textPROGBITS0x80480b00xb00xc7540x00x6AX0016
                                                              .finiPROGBITS0x80548040xc8040xc0x00x6AX001
                                                              .rodataPROGBITS0x80548200xc8200x10100x00x2A0032
                                                              .eh_framePROGBITS0x80568300xd8300x740x00x3WA004
                                                              .ctorsPROGBITS0x80568a40xd8a40x80x00x3WA004
                                                              .dtorsPROGBITS0x80568ac0xd8ac0x80x00x3WA004
                                                              .jcrPROGBITS0x80568b40xd8b40x40x00x3WA004
                                                              .got.pltPROGBITS0x80568b80xd8b80xc0x40x3WA004
                                                              .dataPROGBITS0x80568c40xd8c40x9c0x00x3WA004
                                                              .bssNOBITS0x80569600xd9600x6480x00x3WA0032
                                                              .commentPROGBITS0x00xd9600x8940x00x0001
                                                              .debug_arangesPROGBITS0x00xe1f40x400x00x0001
                                                              .debug_pubnamesPROGBITS0x00xe2340x400x00x0001
                                                              .debug_infoPROGBITS0x00xe2740x60a0x00x0001
                                                              .debug_abbrevPROGBITS0x00xe87e0x2ac0x00x0001
                                                              .debug_linePROGBITS0x00xeb2a0x1900x00x0001
                                                              .debug_framePROGBITS0x00xecbc0x800x00x0004
                                                              .debug_strPROGBITS0x00xed3c0x1270x10x30MS001
                                                              .debug_locPROGBITS0x00xee630x5dd0x00x0001
                                                              .debug_rangesPROGBITS0x00xf4400x600x00x0001
                                                              .shstrtabSTRTAB0x00xf4a00xe50x00x0001
                                                              .symtabSYMTAB0x00xf9700x1d500x100x0242324
                                                              .strtabSTRTAB0x00x116c00x12b70x00x0001
                                                              TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                              LOAD0x00x80480000x80480000xd8300xd8306.41780x5R E0x1000.init .text .fini .rodata
                                                              LOAD0xd8300x80568300x80568300x1300x7782.46990x6RW 0x1000.eh_frame .ctors .dtors .jcr .got.plt .data .bss
                                                              GNU_STACK0x00x00x00x00x00.00000x6RW 0x4
                                                              NameVersion Info NameVersion Info File NameSection NameValueSizeSymbol TypeSymbol BindSymbol VisibilityNdx
                                                              .symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                                              .symtab0x80480940SECTION<unknown>DEFAULT1
                                                              .symtab0x80480b00SECTION<unknown>DEFAULT2
                                                              .symtab0x80548040SECTION<unknown>DEFAULT3
                                                              .symtab0x80548200SECTION<unknown>DEFAULT4
                                                              .symtab0x80568300SECTION<unknown>DEFAULT5
                                                              .symtab0x80568a40SECTION<unknown>DEFAULT6
                                                              .symtab0x80568ac0SECTION<unknown>DEFAULT7
                                                              .symtab0x80568b40SECTION<unknown>DEFAULT8
                                                              .symtab0x80568b80SECTION<unknown>DEFAULT9
                                                              .symtab0x80568c40SECTION<unknown>DEFAULT10
                                                              .symtab0x80569600SECTION<unknown>DEFAULT11
                                                              .symtab0x00SECTION<unknown>DEFAULT12
                                                              .symtab0x00SECTION<unknown>DEFAULT13
                                                              .symtab0x00SECTION<unknown>DEFAULT14
                                                              .symtab0x00SECTION<unknown>DEFAULT15
                                                              .symtab0x00SECTION<unknown>DEFAULT16
                                                              .symtab0x00SECTION<unknown>DEFAULT17
                                                              .symtab0x00SECTION<unknown>DEFAULT18
                                                              .symtab0x00SECTION<unknown>DEFAULT19
                                                              .symtab0x00SECTION<unknown>DEFAULT20
                                                              .symtab0x00SECTION<unknown>DEFAULT21
                                                              _DYNAMIC.symtab0x00NOTYPE<unknown>HIDDENSHN_UNDEF
                                                              _Exit.symtab0x804dd0021FUNC<unknown>DEFAULT2
                                                              _Exit.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              _GLOBAL_OFFSET_TABLE_.symtab0x80568b80OBJECT<unknown>HIDDEN9
                                                              _Jv_RegisterClasses.symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                                              __CTOR_END__.symtab0x80568a80OBJECT<unknown>DEFAULT6
                                                              __CTOR_LIST__.symtab0x80568a40OBJECT<unknown>DEFAULT6
                                                              __DTOR_END__.symtab0x80568b00OBJECT<unknown>DEFAULT7
                                                              __DTOR_LIST__.symtab0x80568ac0OBJECT<unknown>DEFAULT7
                                                              __EH_FRAME_BEGIN__.symtab0x80568300OBJECT<unknown>DEFAULT5
                                                              __FRAME_END__.symtab0x80568a00OBJECT<unknown>DEFAULT5
                                                              __JCR_END__.symtab0x80568b40OBJECT<unknown>DEFAULT8
                                                              __JCR_LIST__.symtab0x80568b40OBJECT<unknown>DEFAULT8
                                                              ___environ.symtab0x8056de44OBJECT<unknown>DEFAULT11
                                                              __aio_close.symtab0x804c2085FUNC<unknown>DEFAULT2
                                                              __block_all_sigs.symtab0x804c0c331FUNC<unknown>DEFAULT2
                                                              __block_app_sigs.symtab0x804c0a431FUNC<unknown>DEFAULT2
                                                              __bss_start.symtab0x80569600NOTYPE<unknown>DEFAULTSHN_ABS
                                                              __clock_gettime.symtab0x804d95887FUNC<unknown>DEFAULT2
                                                              __copy_tls.symtab0x804daf496FUNC<unknown>DEFAULT2
                                                              __deregister_frame_info_bases.symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                                              __dn_expand.symtab0x804eaf8222FUNC<unknown>DEFAULT2
                                                              __dns_parse.symtab0x804ebd8302FUNC<unknown>DEFAULT2
                                                              __do_cleanup_pop.symtab0x804d8e81FUNC<unknown>DEFAULT2
                                                              __do_cleanup_push.symtab0x804d8e81FUNC<unknown>DEFAULT2
                                                              __do_global_ctors_aux.symtab0x80547d00FUNC<unknown>DEFAULT2
                                                              __do_global_dtors_aux.symtab0x80480b00FUNC<unknown>DEFAULT2
                                                              __dso_handle.symtab0x80568c40OBJECT<unknown>HIDDEN10
                                                              __environ.symtab0x8056de44OBJECT<unknown>DEFAULT11
                                                              __environ.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              __errno_location.symtab0x8048c5c10FUNC<unknown>DEFAULT2
                                                              __errno_location.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              __expand_heap.symtab0x804e900389FUNC<unknown>DEFAULT2
                                                              __fclose_ca.symtab0x804c1689FUNC<unknown>DEFAULT2
                                                              __fclose_ca.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              __fini_array_end.symtab0x80568a40NOTYPE<unknown>HIDDEN6
                                                              __fini_array_start.symtab0x80568a40NOTYPE<unknown>HIDDEN6
                                                              __floatscan.symtab0x8051a108068FUNC<unknown>DEFAULT2
                                                              __fopen_rb_ca.symtab0x804c174145FUNC<unknown>DEFAULT2
                                                              __fopen_rb_ca.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              __fork_handler.symtab0x804bfec1FUNC<unknown>DEFAULT2
                                                              __fpclassifyl.symtab0x8053994103FUNC<unknown>DEFAULT2
                                                              __fpclassifyl.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              __fsmu8.symtab0x8055764204OBJECT<unknown>DEFAULT4
                                                              __funcs_on_exit.symtab0x8048c681FUNC<unknown>DEFAULT2
                                                              __fwritex.symtab0x804f2e0152FUNC<unknown>DEFAULT2
                                                              __get_handler_set.symtab0x804eec423FUNC<unknown>DEFAULT2
                                                              __hwcap.symtab0x8056f404OBJECT<unknown>DEFAULT11
                                                              __inet_aton.symtab0x805400c234FUNC<unknown>DEFAULT2
                                                              __init_array_end.symtab0x80568a40NOTYPE<unknown>HIDDEN6
                                                              __init_array_start.symtab0x80568a40NOTYPE<unknown>HIDDEN6
                                                              __init_ssp.symtab0x8048ad91FUNC<unknown>DEFAULT2
                                                              __init_tls.symtab0x804db54324FUNC<unknown>DEFAULT2
                                                              __init_tls.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              __intscan.symtab0x804dd201929FUNC<unknown>DEFAULT2
                                                              __isalnum_l.symtab0x804daec5FUNC<unknown>DEFAULT2
                                                              __isoc99_sscanf.symtab0x804c57430FUNC<unknown>DEFAULT2
                                                              __isoc99_vfscanf.symtab0x8050d8a2436FUNC<unknown>DEFAULT2
                                                              __isoc99_vsscanf.symtab0x804c69889FUNC<unknown>DEFAULT2
                                                              __lctrans.symtab0x804e8955FUNC<unknown>DEFAULT2
                                                              __lctrans.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              __lctrans_cur.symtab0x804e89a32FUNC<unknown>DEFAULT2
                                                              __lctrans_impl.symtab0x804e8905FUNC<unknown>DEFAULT2
                                                              __libc.symtab0x8056f6052OBJECT<unknown>DEFAULT11
                                                              __libc_sigaction.symtab0x804eedb331FUNC<unknown>DEFAULT2
                                                              __libc_start_main.symtab0x8048ada386FUNC<unknown>DEFAULT2
                                                              __libc_start_main.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              __lock.symtab0x804d81352FUNC<unknown>DEFAULT2
                                                              __lock.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              __lockfile.symtab0x804f09978FUNC<unknown>DEFAULT2
                                                              __lockfile.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              __lookup_ipliteral.symtab0x804ed5c357FUNC<unknown>DEFAULT2
                                                              __lookup_name.symtab0x804a87f2097FUNC<unknown>DEFAULT2
                                                              __lookup_serv.symtab0x804b0b0746FUNC<unknown>DEFAULT2
                                                              __madvise.symtab0x8049f6433FUNC<unknown>DEFAULT2
                                                              __malloc0.symtab0x8049f2065FUNC<unknown>DEFAULT2
                                                              __memcpy_fwd.symtab0x804ced00NOTYPE<unknown>HIDDEN2
                                                              __mmap.symtab0x8049f89162FUNC<unknown>DEFAULT2
                                                              __mremap.symtab0x804a02c64FUNC<unknown>DEFAULT2
                                                              __munmap.symtab0x804a06d44FUNC<unknown>DEFAULT2
                                                              __ofl_lock.symtab0x805442522FUNC<unknown>DEFAULT2
                                                              __ofl_unlock.symtab0x805441417FUNC<unknown>DEFAULT2
                                                              __overflow.symtab0x8054108108FUNC<unknown>DEFAULT2
                                                              __overflow.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              __progname.symtab0x80569844OBJECT<unknown>DEFAULT11
                                                              __progname_full.symtab0x80569884OBJECT<unknown>DEFAULT11
                                                              __pthread_setcancelstate.symtab0x804d92c42FUNC<unknown>DEFAULT2
                                                              __register_frame_info_bases.symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                                              __res_mkquery.symtab0x804b440387FUNC<unknown>DEFAULT2
                                                              __res_msend.symtab0x804b5fe1963FUNC<unknown>DEFAULT2
                                                              __restore.symtab0x80540f80FUNC<unknown>DEFAULT2
                                                              __restore_rt.symtab0x80541000FUNC<unknown>DEFAULT2
                                                              __restore_sigs.symtab0x804c0e231FUNC<unknown>DEFAULT2
                                                              __set_thread_area.symtab0x80517940FUNC<unknown>DEFAULT2
                                                              __shgetc.symtab0x804e530273FUNC<unknown>DEFAULT2
                                                              __shlim.symtab0x804e4b0118FUNC<unknown>DEFAULT2
                                                              __sigaction.symtab0x804f02642FUNC<unknown>DEFAULT2
                                                              __signbitl.symtab0x80539fc35FUNC<unknown>DEFAULT2
                                                              __signbitl.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              __simple_malloc.symtab0x8048d10245FUNC<unknown>DEFAULT2
                                                              __static_tls.symtab0x8056f9816OBJECT<unknown>DEFAULT11
                                                              __stderr_used.symtab0x80568d04OBJECT<unknown>DEFAULT10
                                                              __stdin_used.symtab0x8056f184OBJECT<unknown>DEFAULT11
                                                              __stdio_close.symtab0x804c20d39FUNC<unknown>DEFAULT2
                                                              __stdio_close.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              __stdio_exit.symtab0x80543e547FUNC<unknown>DEFAULT2
                                                              __stdio_exit.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              __stdio_exit_needed.symtab0x80543e547FUNC<unknown>DEFAULT2
                                                              __stdio_read.symtab0x804c234155FUNC<unknown>DEFAULT2
                                                              __stdio_read.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              __stdio_seek.symtab0x804c2d0124FUNC<unknown>DEFAULT2
                                                              __stdio_seek.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              __stdio_write.symtab0x804f0e8204FUNC<unknown>DEFAULT2
                                                              __stdio_write.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              __stdout_used.symtab0x8056f184OBJECT<unknown>DEFAULT11
                                                              __stpcpy.symtab0x8051710131FUNC<unknown>DEFAULT2
                                                              __stpncpy.symtab0x8054440206FUNC<unknown>DEFAULT2
                                                              __strchrnul.symtab0x804d030203FUNC<unknown>DEFAULT2
                                                              __strerror_l.symtab0x804dc9874FUNC<unknown>DEFAULT2
                                                              __string_read.symtab0x804f1b493FUNC<unknown>DEFAULT2
                                                              __string_read.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              __strtoimax_internal.symtab0x804cd865FUNC<unknown>DEFAULT2
                                                              __strtol_internal.symtab0x804cd2a31FUNC<unknown>DEFAULT2
                                                              __strtoll_internal.symtab0x804cd6533FUNC<unknown>DEFAULT2
                                                              __strtoul_internal.symtab0x804cd4928FUNC<unknown>DEFAULT2
                                                              __strtoull_internal.symtab0x804cd8b33FUNC<unknown>DEFAULT2
                                                              __strtoumax_internal.symtab0x804cdac5FUNC<unknown>DEFAULT2
                                                              __syscall.symtab0x8048ce70FUNC<unknown>HIDDEN2
                                                              __syscall_cp.symtab0x804d8485FUNC<unknown>DEFAULT2
                                                              __syscall_cp.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              __syscall_cp_c.symtab0x804d84d5FUNC<unknown>DEFAULT2
                                                              __syscall_ret.symtab0x804e65039FUNC<unknown>DEFAULT2
                                                              __sysinfo.symtab0x8056f944OBJECT<unknown>HIDDEN11
                                                              __sysv_signal.symtab0x804c10498FUNC<unknown>DEFAULT2
                                                              __toread.symtab0x8054174104FUNC<unknown>DEFAULT2
                                                              __toread.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              __toread_needs_stdio_exit.symtab0x80541dc5FUNC<unknown>DEFAULT2
                                                              __towrite.symtab0x80541e465FUNC<unknown>DEFAULT2
                                                              __towrite.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              __towrite_needs_stdio_exit.symtab0x80542255FUNC<unknown>DEFAULT2
                                                              __udivdi3.symtab0x8054510331FUNC<unknown>HIDDEN2
                                                              __uflow.symtab0x804f21454FUNC<unknown>DEFAULT2
                                                              __uflow.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              __umoddi3.symtab0x8054660367FUNC<unknown>HIDDEN2
                                                              __unlock.symtab0x804d7cc71FUNC<unknown>DEFAULT2
                                                              __unlockfile.symtab0x804f05073FUNC<unknown>DEFAULT2
                                                              __vdsosym.symtab0x804e680525FUNC<unknown>DEFAULT2
                                                              __vm_wait.symtab0x8049f881FUNC<unknown>DEFAULT2
                                                              __vsyscall.symtab0x8048c9c0FUNC<unknown>HIDDEN2
                                                              __vsyscall6.symtab0x8048ccd0FUNC<unknown>HIDDEN2
                                                              __wait.symtab0x804d854148FUNC<unknown>DEFAULT2
                                                              __wait.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              _edata.symtab0x80569600NOTYPE<unknown>DEFAULTSHN_ABS
                                                              _end.symtab0x8056fa80NOTYPE<unknown>DEFAULTSHN_ABS
                                                              _environ.symtab0x8056de44OBJECT<unknown>DEFAULT11
                                                              _fini.symtab0x80548040NOTYPE<unknown>DEFAULT3
                                                              _init.symtab0x80480940NOTYPE<unknown>DEFAULT1
                                                              _pthread_cleanup_pop.symtab0x804d8ff44FUNC<unknown>DEFAULT2
                                                              _pthread_cleanup_push.symtab0x804d8e922FUNC<unknown>DEFAULT2
                                                              _start.symtab0x80481640NOTYPE<unknown>DEFAULT2
                                                              _start_c.symtab0x804817f35FUNC<unknown>DEFAULT2
                                                              addrcmp.symtab0x804a6a115FUNC<unknown>DEFAULT2
                                                              all_mask.symtab0x80549e88OBJECT<unknown>DEFAULT4
                                                              alloc_fwd.symtab0x8049070561FUNC<unknown>DEFAULT2
                                                              alloc_rev.symtab0x8048e10594FUNC<unknown>DEFAULT2
                                                              app_mask.symtab0x80549e08OBJECT<unknown>DEFAULT4
                                                              arg_n.symtab0x8050d7026FUNC<unknown>DEFAULT2
                                                              attack_running.symtab0x80569804OBJECT<unknown>DEFAULT11
                                                              authenticate.symtab0x8048611157FUNC<unknown>DEFAULT2
                                                              bind.symtab0x804eaa483FUNC<unknown>DEFAULT2
                                                              bind.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              block.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              bot.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              brk.1727.symtab0x8056f044OBJECT<unknown>DEFAULT11
                                                              bsd_signal.symtab0x804c10498FUNC<unknown>DEFAULT2
                                                              buf.symtab0x8056dd88OBJECT<unknown>DEFAULT11
                                                              builtin_tls.symtab0x8056de8280OBJECT<unknown>DEFAULT11
                                                              calloc.symtab0x804e8c063FUNC<unknown>DEFAULT2
                                                              calloc.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              cgt.1877.symtab0x8056de04OBJECT<unknown>DEFAULT11
                                                              cleanup.symtab0x804b5c415FUNC<unknown>DEFAULT2
                                                              cleanup.symtab0x80481a443FUNC<unknown>DEFAULT2
                                                              clock_gettime.symtab0x804d95887FUNC<unknown>DEFAULT2
                                                              clock_gettime.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              close.symtab0x804da4157FUNC<unknown>DEFAULT2
                                                              close.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              close_file.symtab0x805439877FUNC<unknown>DEFAULT2
                                                              completed.4058.symtab0x80569601OBJECT<unknown>DEFAULT11
                                                              connect.symtab0x804a09c87FUNC<unknown>DEFAULT2
                                                              connect.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              copysignl.symtab0x8053a2076FUNC<unknown>DEFAULT2
                                                              copysignl.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              crt1.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              crtstuff.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              crtstuff.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              cur.1594.symtab0x80569984OBJECT<unknown>DEFAULT11
                                                              cycle.symtab0x804c78e121FUNC<unknown>DEFAULT2
                                                              defpolicy.symtab0x805490c120OBJECT<unknown>DEFAULT4
                                                              dn_expand.symtab0x804eaf8222FUNC<unknown>DEFAULT2
                                                              dn_expand.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              dns_parse.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              dns_parse_callback.symtab0x804a720252FUNC<unknown>DEFAULT2
                                                              do_read.symtab0x804c6f15FUNC<unknown>DEFAULT2
                                                              dummy.symtab0x8048ad81FUNC<unknown>DEFAULT2
                                                              dummy.symtab0x8048c681FUNC<unknown>DEFAULT2
                                                              dummy.symtab0x8049f881FUNC<unknown>DEFAULT2
                                                              dummy.symtab0x804a06c1FUNC<unknown>DEFAULT2
                                                              dummy.symtab0x804bfec1FUNC<unknown>DEFAULT2
                                                              dummy.symtab0x804c2085FUNC<unknown>DEFAULT2
                                                              dummy.symtab0x804d8e81FUNC<unknown>DEFAULT2
                                                              dummy.symtab0x804da3c5FUNC<unknown>DEFAULT2
                                                              dummy.symtab0x804e8905FUNC<unknown>DEFAULT2
                                                              dummy1.symtab0x8048ad91FUNC<unknown>DEFAULT2
                                                              dummy_file.symtab0x8056f184OBJECT<unknown>DEFAULT11
                                                              end.1595.symtab0x80569944OBJECT<unknown>DEFAULT11
                                                              end.3155.symtab0x80569a04OBJECT<unknown>DEFAULT11
                                                              environ.symtab0x8056de44OBJECT<unknown>DEFAULT11
                                                              errid.symtab0x8054a1488OBJECT<unknown>DEFAULT4
                                                              errmsg.symtab0x8054a6c1804OBJECT<unknown>DEFAULT4
                                                              execute_command.symtab0x804842e254FUNC<unknown>DEFAULT2
                                                              exit.symtab0x8048c6951FUNC<unknown>DEFAULT2
                                                              exit.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              expand_heap.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              f.symtab0x80568d4136OBJECT<unknown>DEFAULT10
                                                              fabs.symtab0x8053a6c0FUNC<unknown>DEFAULT2
                                                              fgets.symtab0x804c34c337FUNC<unknown>DEFAULT2
                                                              fgets.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              fgets_unlocked.symtab0x804c34c337FUNC<unknown>DEFAULT2
                                                              floatscan.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              fmodl.symtab0x8053a740FUNC<unknown>DEFAULT2
                                                              fmt_u.symtab0x804f49d87FUNC<unknown>DEFAULT2
                                                              fork.symtab0x804bfed138FUNC<unknown>DEFAULT2
                                                              fork.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              fputc.symtab0x804f24c148FUNC<unknown>DEFAULT2
                                                              fputc.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              frame_dummy.symtab0x80481100FUNC<unknown>DEFAULT2
                                                              free.symtab0x80492b01107FUNC<unknown>DEFAULT2
                                                              freeaddrinfo.symtab0x804a0f45FUNC<unknown>DEFAULT2
                                                              freeaddrinfo.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              frexpl.symtab0x8053a88155FUNC<unknown>DEFAULT2
                                                              frexpl.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              fwrite.symtab0x804f378115FUNC<unknown>DEFAULT2
                                                              fwrite.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              fwrite_unlocked.symtab0x804f378115FUNC<unknown>DEFAULT2
                                                              getaddrinfo.symtab0x804a0fc691FUNC<unknown>DEFAULT2
                                                              getaddrinfo.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              getint.symtab0x804f4f437FUNC<unknown>DEFAULT2
                                                              getsockname.symtab0x804ed0883FUNC<unknown>DEFAULT2
                                                              getsockname.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              handle_connection.symtab0x80487c7305FUNC<unknown>DEFAULT2
                                                              handler_set.symtab0x8056f0c8OBJECT<unknown>DEFAULT11
                                                              heap_lock.3154.symtab0x80569a48OBJECT<unknown>DEFAULT11
                                                              htonl.symtab0x804a3b041FUNC<unknown>DEFAULT2
                                                              htonl.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              htons.symtab0x804a3dc12FUNC<unknown>DEFAULT2
                                                              htons.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              if_nametoindex.symtab0x8053fa8100FUNC<unknown>DEFAULT2
                                                              if_nametoindex.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              inet_aton.symtab0x805400c234FUNC<unknown>DEFAULT2
                                                              inet_aton.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              inet_pton.symtab0x804a3e8576FUNC<unknown>DEFAULT2
                                                              inet_pton.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              internal.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              internal_state.2886.symtab0x8056f144OBJECT<unknown>DEFAULT11
                                                              intscan.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              ioctl.symtab0x805425848FUNC<unknown>DEFAULT2
                                                              ioctl.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              is_valid_hostname.symtab0x804a6bf97FUNC<unknown>DEFAULT2
                                                              isalnum.symtab0x804dac836FUNC<unknown>DEFAULT2
                                                              isalnum.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              isalnum_l.symtab0x804daec5FUNC<unknown>DEFAULT2
                                                              last_heartbeat.symtab0x805697c4OBJECT<unknown>DEFAULT11
                                                              ldexp.symtab0x8053b240FUNC<unknown>DEFAULT2
                                                              ldexpl.symtab0x8053b700FUNC<unknown>DEFAULT2
                                                              libc.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              libgcc2.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              libgcc2.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              lite_malloc.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              lock.1596.symtab0x805698c8OBJECT<unknown>DEFAULT11
                                                              lookup_ipliteral.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              lookup_name.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              lookup_serv.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              madvise.symtab0x8049f6433FUNC<unknown>DEFAULT2
                                                              madvise.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              main.symtab0x80488f8480FUNC<unknown>DEFAULT2
                                                              mal.symtab0x80569c01040OBJECT<unknown>DEFAULT11
                                                              malloc.symtab0x80497101459FUNC<unknown>DEFAULT2
                                                              malloc.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              mbrtowc.symtab0x8053bb0291FUNC<unknown>DEFAULT2
                                                              mbrtowc.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              mbsinit.symtab0x8053cd422FUNC<unknown>DEFAULT2
                                                              mbsinit.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              mbsrtowcs.symtab0x8053cec661FUNC<unknown>DEFAULT2
                                                              mbsrtowcs.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              mbstowcs.symtab0x804ea8827FUNC<unknown>DEFAULT2
                                                              mbstowcs.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              memchr.symtab0x804cdc0178FUNC<unknown>DEFAULT2
                                                              memchr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              memcmp.symtab0x804ce8080FUNC<unknown>DEFAULT2
                                                              memcmp.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              memcpy.symtab0x804ced00FUNC<unknown>DEFAULT2
                                                              memmove.symtab0x804cf0c0FUNC<unknown>DEFAULT2
                                                              memset.symtab0x804cf400FUNC<unknown>DEFAULT2
                                                              mmap.symtab0x8049f89162FUNC<unknown>DEFAULT2
                                                              mmap.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              mmap64.symtab0x8049f89162FUNC<unknown>DEFAULT2
                                                              mmap_step.1728.symtab0x8056f004OBJECT<unknown>DEFAULT11
                                                              mremap.symtab0x804a02c64FUNC<unknown>DEFAULT2
                                                              mremap.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              mtime.symtab0x804b5d343FUNC<unknown>DEFAULT2
                                                              munmap.symtab0x804a06d44FUNC<unknown>DEFAULT2
                                                              munmap.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              name_from_numeric.symtab0x804a6b015FUNC<unknown>DEFAULT2
                                                              nanosleep.symtab0x80517ec41FUNC<unknown>DEFAULT2
                                                              nanosleep.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              ntohl.symtab0x804b39c41FUNC<unknown>DEFAULT2
                                                              ntohl.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              object.4070.symtab0x805696424OBJECT<unknown>DEFAULT11
                                                              ofl.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              ofl_head.symtab0x8056f1c4OBJECT<unknown>DEFAULT11
                                                              ofl_lock.symtab0x8056f208OBJECT<unknown>DEFAULT11
                                                              out.symtab0x804f51926FUNC<unknown>DEFAULT2
                                                              p.4056.symtab0x80568c80OBJECT<unknown>DEFAULT10
                                                              p10s.2571.symtab0x805570032OBJECT<unknown>DEFAULT4
                                                              pad.symtab0x804f533126FUNC<unknown>DEFAULT2
                                                              perror.symtab0x804c4a0173FUNC<unknown>DEFAULT2
                                                              perror.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              pntz.symtab0x804c6f831FUNC<unknown>DEFAULT2
                                                              policyof.symtab0x804a81c99FUNC<unknown>DEFAULT2
                                                              poll.symtab0x804c07843FUNC<unknown>DEFAULT2
                                                              poll.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              pop_arg.symtab0x804f3ec177FUNC<unknown>DEFAULT2
                                                              printf_core.symtab0x804f5b15694FUNC<unknown>DEFAULT2
                                                              program_invocation_name.symtab0x80569884OBJECT<unknown>DEFAULT11
                                                              program_invocation_short_name.symtab0x80569844OBJECT<unknown>DEFAULT11
                                                              pthread_cleanup_push.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              pthread_setcancelstate.symtab0x804d92c42FUNC<unknown>DEFAULT2
                                                              pthread_setcancelstate.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              qsort.symtab0x804c9f3654FUNC<unknown>DEFAULT2
                                                              qsort.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              rand.symtab0x804bfad60FUNC<unknown>DEFAULT2
                                                              rand.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              realloc.symtab0x8049cd0584FUNC<unknown>DEFAULT2
                                                              recv.symtab0x804b3c832FUNC<unknown>DEFAULT2
                                                              recv.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              recvfrom.symtab0x804b3e887FUNC<unknown>DEFAULT2
                                                              recvfrom.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              register_bot.symtab0x80486ae281FUNC<unknown>DEFAULT2
                                                              res_mkquery.symtab0x804b440387FUNC<unknown>DEFAULT2
                                                              res_mkquery.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              res_msend.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              sc_clock_gettime.symtab0x804d9af95FUNC<unknown>DEFAULT2
                                                              scalbln.symtab0x8053b250FUNC<unknown>DEFAULT2
                                                              scalblnl.symtab0x8053b710FUNC<unknown>DEFAULT2
                                                              scalbn.symtab0x8053b260FUNC<unknown>DEFAULT2
                                                              scalbnl.symtab0x8053b720FUNC<unknown>DEFAULT2
                                                              scanexp.symtab0x8051820483FUNC<unknown>DEFAULT2
                                                              sccp.symtab0x804d84d5FUNC<unknown>DEFAULT2
                                                              scopeof.symtab0x804a628121FUNC<unknown>DEFAULT2
                                                              seed.symtab0x8056dd08OBJECT<unknown>DEFAULT11
                                                              send.symtab0x804bdac32FUNC<unknown>DEFAULT2
                                                              send.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              send_heartbeat.symtab0x80481cf46FUNC<unknown>DEFAULT2
                                                              sendto.symtab0x804bdcc87FUNC<unknown>DEFAULT2
                                                              sendto.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              setsid.symtab0x804da7c23FUNC<unknown>DEFAULT2
                                                              setsid.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              setsockopt.symtab0x804be2483FUNC<unknown>DEFAULT2
                                                              setsockopt.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              shgetc.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              shl.symtab0x804c71759FUNC<unknown>DEFAULT2
                                                              shr.symtab0x804c75260FUNC<unknown>DEFAULT2
                                                              sift.symtab0x804c807170FUNC<unknown>DEFAULT2
                                                              sigaction.symtab0x804f02642FUNC<unknown>DEFAULT2
                                                              sigaction.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              signal.symtab0x804c10498FUNC<unknown>DEFAULT2
                                                              signal.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              sleep.symtab0x804da9449FUNC<unknown>DEFAULT2
                                                              sleep.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              sn_write.symtab0x804c66351FUNC<unknown>DEFAULT2
                                                              snprintf.symtab0x804c55033FUNC<unknown>DEFAULT2
                                                              snprintf.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              sock.symtab0x80568cc4OBJECT<unknown>DEFAULT10
                                                              socket.symtab0x804be78287FUNC<unknown>DEFAULT2
                                                              socket.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              srand.symtab0x804bf9821FUNC<unknown>DEFAULT2
                                                              sscanf.symtab0x804c57430FUNC<unknown>DEFAULT2
                                                              sscanf.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              states.symtab0x80553cc464OBJECT<unknown>DEFAULT4
                                                              stderr.symtab0x80549f04OBJECT<unknown>DEFAULT4
                                                              stderr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              store_int.symtab0x8050d3c52FUNC<unknown>DEFAULT2
                                                              stpcpy.symtab0x8051710131FUNC<unknown>DEFAULT2
                                                              stpcpy.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              stpncpy.symtab0x8054440206FUNC<unknown>DEFAULT2
                                                              stpncpy.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              strchr.symtab0x804d00043FUNC<unknown>DEFAULT2
                                                              strchr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              strchrnul.symtab0x804d030203FUNC<unknown>DEFAULT2
                                                              strchrnul.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              strcmp.symtab0x804d10043FUNC<unknown>DEFAULT2
                                                              strcmp.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              strcpy.symtab0x804d13031FUNC<unknown>DEFAULT2
                                                              strcpy.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              strerror.symtab0x804dce228FUNC<unknown>DEFAULT2
                                                              strerror.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              strerror_l.symtab0x804dc9874FUNC<unknown>DEFAULT2
                                                              strlen.symtab0x804d15081FUNC<unknown>DEFAULT2
                                                              strlen.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              strncmp.symtab0x804d1b0106FUNC<unknown>DEFAULT2
                                                              strncmp.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              strncpy.symtab0x805423039FUNC<unknown>DEFAULT2
                                                              strncpy.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              strnlen.symtab0x804d22061FUNC<unknown>DEFAULT2
                                                              strnlen.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              strstr.symtab0x804d2601386FUNC<unknown>DEFAULT2
                                                              strstr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              strtoimax.symtab0x804cd865FUNC<unknown>DEFAULT2
                                                              strtol.symtab0x804cd2a31FUNC<unknown>DEFAULT2
                                                              strtol.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              strtoll.symtab0x804cd6533FUNC<unknown>DEFAULT2
                                                              strtoul.symtab0x804cd4928FUNC<unknown>DEFAULT2
                                                              strtoull.symtab0x804cd8b33FUNC<unknown>DEFAULT2
                                                              strtoumax.symtab0x804cdac5FUNC<unknown>DEFAULT2
                                                              strtox.symtab0x804cc84166FUNC<unknown>DEFAULT2
                                                              syscall_ret.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              table.symtab0x80551a0257OBJECT<unknown>DEFAULT4
                                                              time.symtab0x804da1042FUNC<unknown>DEFAULT2
                                                              time.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              trinkle.symtab0x804c8b1322FUNC<unknown>DEFAULT2
                                                              try_connect.symtab0x804852c229FUNC<unknown>DEFAULT2
                                                              udp_flood.symtab0x80481fd561FUNC<unknown>DEFAULT2
                                                              unmask_done.symtab0x8056f084OBJECT<unknown>DEFAULT11
                                                              vdso.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              vfprintf.symtab0x8050bef333FUNC<unknown>DEFAULT2
                                                              vfprintf.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              vfscanf.symtab0x8050d8a2436FUNC<unknown>DEFAULT2
                                                              vfscanf.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              vsnprintf.symtab0x804c594207FUNC<unknown>DEFAULT2
                                                              vsnprintf.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              vsscanf.symtab0x804c69889FUNC<unknown>DEFAULT2
                                                              vsscanf.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              wcrtomb.symtab0x8054288270FUNC<unknown>DEFAULT2
                                                              wcrtomb.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              wctomb.symtab0x8053f8433FUNC<unknown>DEFAULT2
                                                              wctomb.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              xdigits.symtab0x805559c16OBJECT<unknown>DEFAULT4

                                                              Download Network PCAP: filteredfull

                                                              • Total Packets: 11
                                                              • 443 (HTTPS)
                                                              • 80 (HTTP)
                                                              TimestampSource PortDest PortSource IPDest IP
                                                              Apr 23, 2025 12:13:16.899507046 CEST43928443192.168.2.2391.189.91.42
                                                              Apr 23, 2025 12:13:22.275063992 CEST42836443192.168.2.2391.189.91.43
                                                              Apr 23, 2025 12:13:23.810628891 CEST4251680192.168.2.23109.202.202.202
                                                              Apr 23, 2025 12:13:35.570827007 CEST39246443192.168.2.2334.249.145.219
                                                              Apr 23, 2025 12:13:35.570883036 CEST4433924634.249.145.219192.168.2.23
                                                              Apr 23, 2025 12:13:35.570995092 CEST39246443192.168.2.2334.249.145.219
                                                              Apr 23, 2025 12:13:35.571640015 CEST39246443192.168.2.2334.249.145.219
                                                              Apr 23, 2025 12:13:35.571655035 CEST4433924634.249.145.219192.168.2.23
                                                              Apr 23, 2025 12:13:38.400681019 CEST43928443192.168.2.2391.189.91.42
                                                              Apr 23, 2025 12:13:48.639292002 CEST42836443192.168.2.2391.189.91.43
                                                              Apr 23, 2025 12:13:54.782521963 CEST4251680192.168.2.23109.202.202.202
                                                              Apr 23, 2025 12:14:19.355130911 CEST43928443192.168.2.2391.189.91.42
                                                              Apr 23, 2025 12:14:35.563343048 CEST39246443192.168.2.2334.249.145.219
                                                              Apr 23, 2025 12:14:35.608264923 CEST4433924634.249.145.219192.168.2.23
                                                              Apr 23, 2025 12:15:18.121892929 CEST4433924634.249.145.219192.168.2.23

                                                              System Behavior

                                                              Start time (UTC):10:13:14
                                                              Start date (UTC):23/04/2025
                                                              Path:/tmp/bot.i486.elf
                                                              Arguments:/tmp/bot.i486.elf
                                                              File size:76151 bytes
                                                              MD5 hash:d696effe3fa83dd1daec511187a5554e

                                                              Start time (UTC):10:13:14
                                                              Start date (UTC):23/04/2025
                                                              Path:/tmp/bot.i486.elf
                                                              Arguments:-
                                                              File size:76151 bytes
                                                              MD5 hash:d696effe3fa83dd1daec511187a5554e
                                                              Start time (UTC):10:14:34
                                                              Start date (UTC):23/04/2025
                                                              Path:/usr/bin/dash
                                                              Arguments:-
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):10:14:34
                                                              Start date (UTC):23/04/2025
                                                              Path:/usr/bin/rm
                                                              Arguments:rm -f /tmp/tmp.Jqw8vI3RPK /tmp/tmp.CADM4lX4xv /tmp/tmp.Wn7iLqPsuo
                                                              File size:72056 bytes
                                                              MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                                              Start time (UTC):10:14:34
                                                              Start date (UTC):23/04/2025
                                                              Path:/usr/bin/dash
                                                              Arguments:-
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):10:14:34
                                                              Start date (UTC):23/04/2025
                                                              Path:/usr/bin/rm
                                                              Arguments:rm -f /tmp/tmp.Jqw8vI3RPK /tmp/tmp.CADM4lX4xv /tmp/tmp.Wn7iLqPsuo
                                                              File size:72056 bytes
                                                              MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b