Edit tour

Linux Analysis Report
server.elf

Overview

General Information

Sample name:server.elf
Analysis ID:1672059
MD5:76baf7a9d282c02d28b7f40cbc1bb257
SHA1:28ba72273e005ebd55bcd8d94691c9d12eaa359d
SHA256:0ec46ac50ed81d06f59ca042c3d0695a4dd4899f95cb76aa0ceb4aec43e79d29
Tags:elfuser-abuse_ch
Infos:

Detection

Score:0
Range:0 - 100

Signatures

Executes the "rm" command used to delete files or directories

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
Joe Sandbox version:42.0.0 Malachite
Analysis ID:1672059
Start date and time:2025-04-23 14:47:29 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 26s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:server.elf
Detection:CLEAN
Classification:clean0.linELF@0/0@0/0
Command:/tmp/server.elf
PID:6225
Exit Code:1
Exit Code Info:
Killed:False
Standard Output:

Standard Error:/tmp/server.elf: /lib/x86_64-linux-gnu/libc.so.6: version `GLIBC_2.34' not found (required by /tmp/server.elf)
  • system is lnxubuntu20
  • server.elf (PID: 6225, Parent: 6148, MD5: 76baf7a9d282c02d28b7f40cbc1bb257) Arguments: /tmp/server.elf
  • dash New Fork (PID: 6288, Parent: 4332)
  • rm (PID: 6288, Parent: 4332, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.9ZBT5CLGTa /tmp/tmp.3VYKbNdJHy /tmp/tmp.wQjoavZwO1
  • dash New Fork (PID: 6289, Parent: 4332)
  • rm (PID: 6289, Parent: 4332, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.9ZBT5CLGTa /tmp/tmp.3VYKbNdJHy /tmp/tmp.wQjoavZwO1
  • cleanup
No yara matches
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 34.249.145.219
Source: unknownTCP traffic detected without corresponding DNS query: 34.249.145.219
Source: unknownTCP traffic detected without corresponding DNS query: 34.249.145.219
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 34.249.145.219
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 39248 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39248
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
Source: classification engineClassification label: clean0.linELF@0/0@0/0
Source: /usr/bin/dash (PID: 6288)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.9ZBT5CLGTa /tmp/tmp.3VYKbNdJHy /tmp/tmp.wQjoavZwO1Jump to behavior
Source: /usr/bin/dash (PID: 6289)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.9ZBT5CLGTa /tmp/tmp.3VYKbNdJHy /tmp/tmp.wQjoavZwO1Jump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
File Deletion
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1672059 Sample: server.elf Startdate: 23/04/2025 Architecture: LINUX Score: 0 11 109.202.202.202, 80 INIT7CH Switzerland 2->11 13 91.189.91.42, 443 CANONICAL-ASGB United Kingdom 2->13 15 2 other IPs or domains 2->15 5 dash rm 2->5         started        7 dash rm 2->7         started        9 server.elf 2->9         started        process3
SourceDetectionScannerLabelLink
server.elf3%ReversingLabs
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

No contacted domains info
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs
IPDomainCountryFlagASNASN NameMalicious
34.249.145.219
unknownUnited States
16509AMAZON-02USfalse
109.202.202.202
unknownSwitzerland
13030INIT7CHfalse
91.189.91.43
unknownUnited Kingdom
41231CANONICAL-ASGBfalse
91.189.91.42
unknownUnited Kingdom
41231CANONICAL-ASGBfalse
MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
34.249.145.219na.elfGet hashmaliciousPrometeiBrowse
    bot.powerpc-440fp.elfGet hashmaliciousUnknownBrowse
      bot.m68k.elfGet hashmaliciousUnknownBrowse
        bot.i586.elfGet hashmaliciousUnknownBrowse
          staticmips.elfGet hashmaliciousUnknownBrowse
            bot.armv5l.elfGet hashmaliciousUnknownBrowse
              na.elfGet hashmaliciousPrometeiBrowse
                na.elfGet hashmaliciousPrometeiBrowse
                  na.elfGet hashmaliciousPrometeiBrowse
                    na.elfGet hashmaliciousPrometeiBrowse
                      109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
                      • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
                      91.189.91.43na.elfGet hashmaliciousPrometeiBrowse
                        bot.powerpc-440fp.elfGet hashmaliciousUnknownBrowse
                          bot.m68k.elfGet hashmaliciousUnknownBrowse
                            bot.i586.elfGet hashmaliciousUnknownBrowse
                              s.elfGet hashmaliciousUnknownBrowse
                                staticmips.elfGet hashmaliciousUnknownBrowse
                                  bot.armv5l.elfGet hashmaliciousUnknownBrowse
                                    na.elfGet hashmaliciousPrometeiBrowse
                                      na.elfGet hashmaliciousPrometeiBrowse
                                        na.elfGet hashmaliciousPrometeiBrowse
                                          91.189.91.42na.elfGet hashmaliciousPrometeiBrowse
                                            bot.powerpc-440fp.elfGet hashmaliciousUnknownBrowse
                                              bot.m68k.elfGet hashmaliciousUnknownBrowse
                                                bot.i586.elfGet hashmaliciousUnknownBrowse
                                                  s.elfGet hashmaliciousUnknownBrowse
                                                    staticmips.elfGet hashmaliciousUnknownBrowse
                                                      bot.armv5l.elfGet hashmaliciousUnknownBrowse
                                                        na.elfGet hashmaliciousPrometeiBrowse
                                                          na.elfGet hashmaliciousPrometeiBrowse
                                                            na.elfGet hashmaliciousPrometeiBrowse
                                                              No context
                                                              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                              CANONICAL-ASGBna.elfGet hashmaliciousPrometeiBrowse
                                                              • 91.189.91.42
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 185.125.190.26
                                                              bot.powerpc-440fp.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              bot.m68k.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              bot.i586.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              s.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              staticmips.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              bot.armv5l.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 91.189.91.42
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 91.189.91.42
                                                              CANONICAL-ASGBna.elfGet hashmaliciousPrometeiBrowse
                                                              • 91.189.91.42
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 185.125.190.26
                                                              bot.powerpc-440fp.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              bot.m68k.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              bot.i586.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              s.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              staticmips.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              bot.armv5l.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 91.189.91.42
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 91.189.91.42
                                                              INIT7CHna.elfGet hashmaliciousPrometeiBrowse
                                                              • 109.202.202.202
                                                              bot.powerpc-440fp.elfGet hashmaliciousUnknownBrowse
                                                              • 109.202.202.202
                                                              bot.m68k.elfGet hashmaliciousUnknownBrowse
                                                              • 109.202.202.202
                                                              bot.i586.elfGet hashmaliciousUnknownBrowse
                                                              • 109.202.202.202
                                                              s.elfGet hashmaliciousUnknownBrowse
                                                              • 109.202.202.202
                                                              staticmips.elfGet hashmaliciousUnknownBrowse
                                                              • 109.202.202.202
                                                              bot.armv5l.elfGet hashmaliciousUnknownBrowse
                                                              • 109.202.202.202
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 109.202.202.202
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 109.202.202.202
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 109.202.202.202
                                                              AMAZON-02USna.elfGet hashmaliciousPrometeiBrowse
                                                              • 34.249.145.219
                                                              Ord000283b.exeGet hashmaliciousDarkTortilla, FormBookBrowse
                                                              • 13.248.169.48
                                                              bot.powerpc-440fp.elfGet hashmaliciousUnknownBrowse
                                                              • 34.249.145.219
                                                              bot.m68k.elfGet hashmaliciousUnknownBrowse
                                                              • 34.249.145.219
                                                              bot.armv7l.elfGet hashmaliciousUnknownBrowse
                                                              • 34.254.182.186
                                                              https://afoshaclass.com.br/0/index.xml?nl=YXNmdXJuaXR1cmVAc2VydmljZS1ub3cuY29tGet hashmaliciousScreenConnect ToolBrowse
                                                              • 52.217.226.9
                                                              bot.i586.elfGet hashmaliciousUnknownBrowse
                                                              • 34.249.145.219
                                                              http://linkin.bio/stadtwerke-pforzheimGet hashmaliciousHTMLPhisherBrowse
                                                              • 34.208.167.158
                                                              PO-000171483.exeGet hashmaliciousFormBookBrowse
                                                              • 13.248.169.48
                                                              RFQ_GU0002-Materials-Specifications-Order-pdf.exeGet hashmaliciousPhantom stealerBrowse
                                                              • 3.169.231.129
                                                              No context
                                                              No context
                                                              No created / dropped files found
                                                              File type:ELF 64-bit LSB pie executable, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, BuildID[sha1]=e31462eb383f3efac1c1b952eef6847965593610, for GNU/Linux 3.2.0, not stripped
                                                              Entropy (8bit):3.5468705824754623
                                                              TrID:
                                                              • ELF Executable and Linkable format (Linux) (4029/14) 49.77%
                                                              • ELF Executable and Linkable format (generic) (4004/1) 49.46%
                                                              • Lumena CEL bitmap (63/63) 0.78%
                                                              File name:server.elf
                                                              File size:23'208 bytes
                                                              MD5:76baf7a9d282c02d28b7f40cbc1bb257
                                                              SHA1:28ba72273e005ebd55bcd8d94691c9d12eaa359d
                                                              SHA256:0ec46ac50ed81d06f59ca042c3d0695a4dd4899f95cb76aa0ceb4aec43e79d29
                                                              SHA512:e32ace1af127364a622152e96c34ea96630a55fbc11e289842af3ef9b4d6b4d386801546d3df6303afcc47cf1a3cbcb9cb3f733d01c0c24cd8759244711750d1
                                                              SSDEEP:384:kHy0ZVZm4EemzS+qTxd5AtxgSO34D9vWeUwdVMvmjWVxPVUpm:kJZVreLxdK+jWHWpm
                                                              TLSH:ADA2A42BA6D3CF39ECC0B77815A38634E2B1BCB4DF35911B921451A62A013D84F2AA95
                                                              File Content Preview:.ELF..............>......"......@........R..........@.8...@. ...........@.......@.......@.......................................................................................................................x.......x........................ ....... .....

                                                              ELF header

                                                              Class:ELF64
                                                              Data:2's complement, little endian
                                                              Version:1 (current)
                                                              Machine:Advanced Micro Devices X86-64
                                                              Version Number:0x1
                                                              Type:DYN (Shared object file)
                                                              OS/ABI:UNIX - System V
                                                              ABI Version:0
                                                              Entry Point Address:0x2280
                                                              Flags:0x0
                                                              ELF Header Size:64
                                                              Program Header Offset:64
                                                              Program Header Size:56
                                                              Number of Program Headers:13
                                                              Section Header Offset:21160
                                                              Section Header Size:64
                                                              Number of Section Headers:32
                                                              Header String Table Index:31
                                                              NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                              NULL0x00x00x00x00x0000
                                                              .interpPROGBITS0x3180x3180x1c0x00x2A001
                                                              .note.gnu.propertyNOTE0x3380x3380x200x00x2A008
                                                              .note.gnu.build-idNOTE0x3580x3580x240x00x2A004
                                                              .note.ABI-tagNOTE0x37c0x37c0x200x00x2A004
                                                              .gnu.hashGNU_HASH0x3a00x3a00x340x00x2A608
                                                              .dynsymDYNSYM0x3d80x3d80x4800x180x2A718
                                                              .dynstrSTRTAB0x8580x8580x4510x00x2A001
                                                              .gnu.versionVERSYM0xcaa0xcaa0x600x20x2A602
                                                              .gnu.version_rVERNEED0xd100xd100xa00x00x2A738
                                                              .rela.dynRELA0xdb00xdb00x1680x180x2A608
                                                              .rela.pltRELA0xf180xf180x3600x180x42AI6258
                                                              .initPROGBITS0x20000x20000x170x00x6AX004
                                                              .pltPROGBITS0x20200x20200x2500x100x6AX0016
                                                              .plt.gotPROGBITS0x22700x22700x80x80x6AX008
                                                              .textPROGBITS0x22800x22800xc8b0x00x6AX0016
                                                              .finiPROGBITS0x2f0c0x2f0c0x90x00x6AX004
                                                              .rodataPROGBITS0x30000x30000x24a0x00x2A008
                                                              .eh_frame_hdrPROGBITS0x324c0x324c0x540x00x2A004
                                                              .eh_framePROGBITS0x32a00x32a00x1740x00x2A008
                                                              .gcc_except_tablePROGBITS0x34140x34140x1b0x00x2A001
                                                              .init_arrayINIT_ARRAY0x4d880x3d880x100x80x3WA008
                                                              .fini_arrayFINI_ARRAY0x4d980x3d980x80x80x3WA008
                                                              .dynamicDYNAMIC0x4da00x3da00x2100x100x3WA708
                                                              .gotPROGBITS0x4fb00x3fb00x380x80x3WA008
                                                              .got.pltPROGBITS0x4fe80x3fe80x1380x80x3WA008
                                                              .dataPROGBITS0x51200x41200x180x00x3WA008
                                                              .bssNOBITS0x51400x41380x11880x00x3WA0064
                                                              .commentPROGBITS0x00x41380x1f0x10x30MS001
                                                              .symtabSYMTAB0x00x41580x8400x180x030228
                                                              .strtabSTRTAB0x00x49980x7e20x00x0001
                                                              .shstrtabSTRTAB0x00x517a0x12c0x00x0001
                                                              TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                              PHDR0x400x400x400x2d80x2d81.69660x4R 0x8
                                                              INTERP0x3180x3180x3180x1c0x1c3.94080x4R 0x1/lib64/ld-linux-x86-64.so.2.interp
                                                              LOAD0x00x00x00x12780x12783.29080x4R 0x1000.interp .note.gnu.property .note.gnu.build-id .note.ABI-tag .gnu.hash .dynsym .dynstr .gnu.version .gnu.version_r .rela.dyn .rela.plt
                                                              LOAD0x20000x20000x20000xf150xf155.45120x5R E0x1000.init .plt .plt.got .text .fini
                                                              LOAD0x30000x30000x30000x42f0x42f5.59840x4R 0x1000.rodata .eh_frame_hdr .eh_frame .gcc_except_table
                                                              LOAD0x3d880x4d880x4d880x3b00x15401.69750x6RW 0x1000.init_array .fini_array .dynamic .got .got.plt .data .bss
                                                              DYNAMIC0x3da00x4da00x4da00x2100x2101.53670x6RW 0x8.dynamic
                                                              NOTE0x3380x3380x3380x200x202.05500x4R 0x8.note.gnu.property
                                                              NOTE0x3580x3580x3580x440x443.30840x4R 0x4.note.gnu.build-id .note.ABI-tag
                                                              GNU_PROPERTY0x3380x3380x3380x200x202.05500x4R 0x8.note.gnu.property
                                                              GNU_EH_FRAME0x324c0x324c0x324c0x540x543.55540x4R 0x4.eh_frame_hdr
                                                              GNU_STACK0x00x00x00x00x00.00000x6RW 0x10
                                                              GNU_RELRO0x3d880x4d880x4d880x2780x2781.44050x4R 0x1.init_array .fini_array .dynamic .got
                                                              TypeMetaValueTag
                                                              DT_NEEDEDsharedliblibsqlite3.so.00x1
                                                              DT_NEEDEDsharedliblibstdc++.so.60x1
                                                              DT_NEEDEDsharedliblibgcc_s.so.10x1
                                                              DT_NEEDEDsharedliblibc.so.60x1
                                                              DT_INITvalue0x20000xc
                                                              DT_FINIvalue0x2f0c0xd
                                                              DT_INIT_ARRAYvalue0x4d880x19
                                                              DT_INIT_ARRAYSZbytes160x1b
                                                              DT_FINI_ARRAYvalue0x4d980x1a
                                                              DT_FINI_ARRAYSZbytes80x1c
                                                              DT_GNU_HASHvalue0x3a00x6ffffef5
                                                              DT_STRTABvalue0x8580x5
                                                              DT_SYMTABvalue0x3d80x6
                                                              DT_STRSZbytes11050xa
                                                              DT_SYMENTbytes240xb
                                                              DT_DEBUGvalue0x00x15
                                                              DT_PLTGOTvalue0x4fe80x3
                                                              DT_PLTRELSZbytes8640x2
                                                              DT_PLTRELpltrelDT_RELA0x14
                                                              DT_JMPRELvalue0xf180x17
                                                              DT_RELAvalue0xdb00x7
                                                              DT_RELASZbytes3600x8
                                                              DT_RELAENTbytes240x9
                                                              DT_FLAGS_1value0x80000000x6ffffffb
                                                              DT_VERNEEDvalue0xd100x6ffffffe
                                                              DT_VERNEEDNUMvalue30x6fffffff
                                                              DT_VERSYMvalue0xcaa0x6ffffff0
                                                              DT_RELACOUNTvalue40x6ffffff9
                                                              DT_NULLvalue0x00x0
                                                              NameVersion Info NameVersion Info File NameSection NameValueSizeSymbol TypeSymbol BindSymbol VisibilityNdx
                                                              .dynsym0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                                              _ITM_deregisterTMCloneTable.dynsym0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                                              _ITM_registerTMCloneTable.dynsym0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                                              _Unwind_ResumeGCC_3.0libgcc_s.so.1.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                              _ZNKSt7__cxx1112basic_stringIcSt11char_traitsIcESaIcEE5c_strEvGLIBCXX_3.4.21libstdc++.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                              _ZNSolsEPFRSoS_EGLIBCXX_3.4libstdc++.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                              _ZNSolsEiGLIBCXX_3.4libstdc++.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                              _ZNSt7__cxx1112basic_stringIcSt11char_traitsIcESaIcEE6appendEPKcmGLIBCXX_3.4.21libstdc++.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                              _ZNSt7__cxx1112basic_stringIcSt11char_traitsIcESaIcEEC1ERKS4_GLIBCXX_3.4.21libstdc++.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                              _ZNSt7__cxx1112basic_stringIcSt11char_traitsIcESaIcEEC1EvGLIBCXX_3.4.21libstdc++.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                              _ZNSt7__cxx1112basic_stringIcSt11char_traitsIcESaIcEED1EvGLIBCXX_3.4.21libstdc++.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                              _ZNSt8ios_base4InitC1EvGLIBCXX_3.4libstdc++.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                              _ZNSt8ios_base4InitD1EvGLIBCXX_3.4libstdc++.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                              _ZSt4coutGLIBCXX_3.4libstdc++.so.6.dynsym0x5180272OBJECT<unknown>DEFAULT27
                                                              _ZSt4endlIcSt11char_traitsIcEERSt13basic_ostreamIT_T0_ES6_GLIBCXX_3.4libstdc++.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                              _ZStlsISt11char_traitsIcEERSt13basic_ostreamIcT_ES5_PKcGLIBCXX_3.4libstdc++.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                              _ZStlsIcSt11char_traitsIcESaIcEERSt13basic_ostreamIT_T0_ES7_RKNSt7__cxx1112basic_stringIS4_S5_T1_EEGLIBCXX_3.4.21libstdc++.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                              __cxa_atexitGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                              __cxa_finalizeGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                              __gmon_start__.dynsym0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                                              __gxx_personality_v0CXXABI_1.3libstdc++.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                              __isoc99_sscanfGLIBC_2.7libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                              __libc_start_mainGLIBC_2.34libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                              acceptGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                              bindGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                              closeGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                              fprintfGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                              fwriteGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                              htonsGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                              listenGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                              printfGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                              putcharGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                              putsGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                              recvGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                              snprintfGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                              socketGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                              sqlite3_close.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                              sqlite3_exec.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                              sqlite3_free.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                              sqlite3_libversion.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                              sqlite3_open.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                              stderrGLIBC_2.2.5libc.so.6.dynsym0x52a08OBJECT<unknown>DEFAULT27
                                                              stdoutGLIBC_2.2.5libc.so.6.dynsym0x51408OBJECT<unknown>DEFAULT27
                                                              strcmpGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                              strlenGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                              strncpyGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                              strsepGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                              strtokGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                              .symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                                              GLIBC_2.2.5libc.so.6.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              DW.ref.__gxx_personality_v0GLIBC_2.2.5libc.so.6.symtab0x51308OBJECT<unknown>HIDDEN26
                                                              Scrt1.oGLIBC_2.2.5libc.so.6.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              _DYNAMICGLIBC_2.7libc.so.6.symtab0x4da00OBJECT<unknown>DEFAULT23
                                                              _GLOBAL_OFFSET_TABLE_GLIBCXX_3.4libstdc++.so.6.symtab0x4fe80OBJECT<unknown>DEFAULT25
                                                              _GLOBAL__sub_I_dnamGLIBC_2.2.5libc.so.6.symtab0x2ef621FUNC<unknown>DEFAULT15
                                                              _IO_stdin_usedGLIBC_2.2.5libc.so.6.symtab0x30004OBJECT<unknown>DEFAULT17
                                                              _ITM_deregisterTMCloneTable.symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                                              _ITM_registerTMCloneTable.symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                                              _Unwind_Resume@GCC_3.0.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                              _Z12check_stringPc.symtab0x24f31663FUNC<unknown>DEFAULT15
                                                              _Z12split_bufferNSt7__cxx1112basic_stringIcSt11char_traitsIcESaIcEEE.symtab0x2b72132FUNC<unknown>DEFAULT15
                                                              _Z41__static_initialization_and_destruction_0iiGLIBCXX_3.4.21libstdc++.so.6.symtab0x2ea482FUNC<unknown>DEFAULT15
                                                              _ZL8callbackPviPPcS1_GLIBC_2.2.5libc.so.6.symtab0x2369394FUNC<unknown>DEFAULT15
                                                              _ZNKSt7__cxx1112basic_stringIcSt11char_traitsIcESaIcEE5c_strEv@GLIBCXX_3.4.21CXXABI_1.3libstdc++.so.6.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                              _ZNSolsEPFRSoS_E@GLIBCXX_3.4.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                              _ZNSolsEi@GLIBCXX_3.4.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                              _ZNSt7__cxx1112basic_stringIcSt11char_traitsIcESaIcEE6appendEPKcm@GLIBCXX_3.4.21.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                              _ZNSt7__cxx1112basic_stringIcSt11char_traitsIcESaIcEEC1ERKS4_@GLIBCXX_3.4.21.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                              _ZNSt7__cxx1112basic_stringIcSt11char_traitsIcESaIcEEC1Ev@GLIBCXX_3.4.21.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                              _ZNSt7__cxx1112basic_stringIcSt11char_traitsIcESaIcEED1Ev@GLIBCXX_3.4.21GLIBCXX_3.4libstdc++.so.6.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                              _ZNSt8ios_base4InitC1Ev@GLIBCXX_3.4.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                              _ZNSt8ios_base4InitD1Ev@GLIBCXX_3.4.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                              _ZSt4cout@GLIBCXX_3.4.symtab0x5180272OBJECT<unknown>DEFAULT27
                                                              _ZSt4endlIcSt11char_traitsIcEERSt13basic_ostreamIT_T0_ES6_@GLIBCXX_3.4.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                              _ZStL8__ioinit.symtab0x62c01OBJECT<unknown>DEFAULT27
                                                              _ZStlsISt11char_traitsIcEERSt13basic_ostreamIcT_ES5_PKc@GLIBCXX_3.4.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                              _ZStlsIcSt11char_traitsIcESaIcEERSt13basic_ostreamIT_T0_ES7_RKNSt7__cxx1112basic_stringIS4_S5_T1_EE@GLIBCXX_3.4.21.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                              __FRAME_END__.symtab0x34100OBJECT<unknown>DEFAULT19
                                                              __GNU_EH_FRAME_HDRGLIBCXX_3.4.21libstdc++.so.6.symtab0x324c0NOTYPE<unknown>DEFAULT18
                                                              __TMC_END__.symtab0x51380OBJECT<unknown>HIDDEN26
                                                              __abi_tagGLIBC_2.2.5libc.so.6.symtab0x37c32OBJECT<unknown>DEFAULT4
                                                              __bss_start.symtab0x51380NOTYPE<unknown>DEFAULT27
                                                              __cxa_atexit@GLIBC_2.2.5.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                              __cxa_finalize@GLIBC_2.2.5GLIBCXX_3.4libstdc++.so.6.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                              __data_start.symtab0x51200NOTYPE<unknown>DEFAULT26
                                                              __do_global_dtors_auxGLIBC_2.2.5libc.so.6.symtab0x23200FUNC<unknown>DEFAULT15
                                                              __do_global_dtors_aux_fini_array_entryGLIBCXX_3.4.21libstdc++.so.6.symtab0x4d980OBJECT<unknown>DEFAULT22
                                                              __dso_handleGLIBC_2.2.5libc.so.6.symtab0x51280OBJECT<unknown>HIDDEN26
                                                              __frame_dummy_init_array_entryGLIBC_2.2.5libc.so.6.symtab0x4d880OBJECT<unknown>DEFAULT21
                                                              __gmon_start__.symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                                              __gxx_personality_v0@CXXABI_1.3.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                              __isoc99_sscanf@GLIBC_2.7.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                              __libc_start_main@GLIBC_2.34GLIBCXX_3.4libstdc++.so.6.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                              _edataGLIBC_2.2.5libc.so.6.symtab0x51380NOTYPE<unknown>DEFAULT26
                                                              _end.symtab0x62c80NOTYPE<unknown>DEFAULT27
                                                              _finiGLIBC_2.2.5libc.so.6.symtab0x2f0c0FUNC<unknown>HIDDEN16
                                                              _init.symtab0x20000FUNC<unknown>HIDDEN12
                                                              _start.symtab0x228034FUNC<unknown>DEFAULT15
                                                              accept@GLIBC_2.2.5GLIBCXX_3.4libstdc++.so.6.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                              bind@GLIBC_2.2.5GLIBCXX_3.4.21libstdc++.so.6.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                              close@GLIBC_2.2.5.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                              completed.0GLIBC_2.2.5libc.so.6.symtab0x52a81OBJECT<unknown>DEFAULT27
                                                              crtstuff.cGLIBCXX_3.4.21libstdc++.so.6.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              crtstuff.cGLIBC_2.34libc.so.6.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              data_startGLIBC_2.2.5libc.so.6.symtab0x51200NOTYPE<unknown>DEFAULT26
                                                              deregister_tm_clonesGLIBC_2.2.5libc.so.6.symtab0x22b00FUNC<unknown>DEFAULT15
                                                              dnam.symtab0x52c01024OBJECT<unknown>DEFAULT27
                                                              fprintf@GLIBC_2.2.5.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                              frame_dummyGLIBCXX_3.4.21libstdc++.so.6.symtab0x23600FUNC<unknown>DEFAULT15
                                                              fwrite@GLIBC_2.2.5.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                              htons@GLIBC_2.2.5GLIBC_2.2.5libc.so.6.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                              id.symtab0x56c01024OBJECT<unknown>DEFAULT27
                                                              listen@GLIBC_2.2.5.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                              mainGCC_3.0libgcc_s.so.1.symtab0x2bf6686FUNC<unknown>DEFAULT15
                                                              printf@GLIBC_2.2.5GLIBCXX_3.4libstdc++.so.6.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                              putchar@GLIBC_2.2.5.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                              puts@GLIBC_2.2.5.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                              recv@GLIBC_2.2.5GLIBC_2.2.5libc.so.6.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                              register_tm_clonesGLIBC_2.2.5libc.so.6.symtab0x22e00FUNC<unknown>DEFAULT15
                                                              sensoridGLIBC_2.2.5libc.so.6.symtab0x5ec01024OBJECT<unknown>DEFAULT27
                                                              server.cppGLIBCXX_3.4libstdc++.so.6.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              snprintf@GLIBC_2.2.5.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                              socket@GLIBC_2.2.5GLIBC_2.2.5libc.so.6.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                              sqlite3_close.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                              sqlite3_exec.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                              sqlite3_free.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                              sqlite3_libversion.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                              sqlite3_open.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                              stationid.symtab0x5ac01024OBJECT<unknown>DEFAULT27
                                                              stderr@GLIBC_2.2.5.symtab0x52a08OBJECT<unknown>DEFAULT27
                                                              stdout@GLIBC_2.2.5.symtab0x51408OBJECT<unknown>DEFAULT27
                                                              strcmp@GLIBC_2.2.5.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                              strlen@GLIBC_2.2.5.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                              strncpy@GLIBC_2.2.5GLIBC_2.2.5libc.so.6.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                              strsep@GLIBC_2.2.5GLIBC_2.2.5libc.so.6.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                              strtok@GLIBC_2.2.5.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF

                                                              Download Network PCAP: filteredfull

                                                              • Total Packets: 11
                                                              • 443 (HTTPS)
                                                              • 80 (HTTP)
                                                              TimestampSource PortDest PortSource IPDest IP
                                                              Apr 23, 2025 14:48:14.782681942 CEST43928443192.168.2.2391.189.91.42
                                                              Apr 23, 2025 14:48:20.157924891 CEST42836443192.168.2.2391.189.91.43
                                                              Apr 23, 2025 14:48:21.949712992 CEST4251680192.168.2.23109.202.202.202
                                                              Apr 23, 2025 14:48:35.362337112 CEST39248443192.168.2.2334.249.145.219
                                                              Apr 23, 2025 14:48:35.362394094 CEST4433924834.249.145.219192.168.2.23
                                                              Apr 23, 2025 14:48:35.362643003 CEST39248443192.168.2.2334.249.145.219
                                                              Apr 23, 2025 14:48:35.362854958 CEST39248443192.168.2.2334.249.145.219
                                                              Apr 23, 2025 14:48:35.362867117 CEST4433924834.249.145.219192.168.2.23
                                                              Apr 23, 2025 14:48:36.283725023 CEST43928443192.168.2.2391.189.91.42
                                                              Apr 23, 2025 14:48:46.522399902 CEST42836443192.168.2.2391.189.91.43
                                                              Apr 23, 2025 14:48:52.665431023 CEST4251680192.168.2.23109.202.202.202
                                                              Apr 23, 2025 14:49:17.238078117 CEST43928443192.168.2.2391.189.91.42
                                                              Apr 23, 2025 14:49:35.354824066 CEST39248443192.168.2.2334.249.145.219
                                                              Apr 23, 2025 14:49:35.396313906 CEST4433924834.249.145.219192.168.2.23
                                                              Apr 23, 2025 14:50:16.464035034 CEST4433924834.249.145.219192.168.2.23

                                                              System Behavior

                                                              Start time (UTC):12:48:12
                                                              Start date (UTC):23/04/2025
                                                              Path:/tmp/server.elf
                                                              Arguments:/tmp/server.elf
                                                              File size:23208 bytes
                                                              MD5 hash:76baf7a9d282c02d28b7f40cbc1bb257

                                                              Start time (UTC):12:49:34
                                                              Start date (UTC):23/04/2025
                                                              Path:/usr/bin/dash
                                                              Arguments:-
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):12:49:34
                                                              Start date (UTC):23/04/2025
                                                              Path:/usr/bin/rm
                                                              Arguments:rm -f /tmp/tmp.9ZBT5CLGTa /tmp/tmp.3VYKbNdJHy /tmp/tmp.wQjoavZwO1
                                                              File size:72056 bytes
                                                              MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                                              Start time (UTC):12:49:34
                                                              Start date (UTC):23/04/2025
                                                              Path:/usr/bin/dash
                                                              Arguments:-
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):12:49:34
                                                              Start date (UTC):23/04/2025
                                                              Path:/usr/bin/rm
                                                              Arguments:rm -f /tmp/tmp.9ZBT5CLGTa /tmp/tmp.3VYKbNdJHy /tmp/tmp.wQjoavZwO1
                                                              File size:72056 bytes
                                                              MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b