Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
i486.elf

Overview

General Information

Sample name:i486.elf
Analysis ID:1541013
MD5:bd0da6d215821625c85f701133b3d758
SHA1:0b0eca5e58828339727ed228a25e70d98c1a39ed
SHA256:ed9e82f85045eab3ef7c4e42b9c9ac2b85d4b619e7c34398b96b3eefa8f3a884
Tags:elfMiraiuser-abuse_ch
Infos:

Detection

Score:64
Range:0 - 100
Whitelisted:false

Signatures

Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Contains symbols with names commonly found in malware
Machine Learning detection for sample
Detected TCP or UDP traffic on non-standard ports
Found strings indicative of a multi-platform dropper
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Yara signature match

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1541013
Start date and time:2024-10-24 11:32:25 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 23s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:i486.elf
Detection:MAL
Classification:mal64.linELF@0/0@1/0
  • VT rate limit hit for: i486.elf
Command:/tmp/i486.elf
PID:6206
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:

Standard Error:
  • system is lnxubuntu20
  • i486.elf (PID: 6206, Parent: 6122, MD5: bd0da6d215821625c85f701133b3d758) Arguments: /tmp/i486.elf
    • i486.elf New Fork (PID: 6207, Parent: 6206)
      • i486.elf New Fork (PID: 6208, Parent: 6207)
  • cleanup
SourceRuleDescriptionAuthorStrings
i486.elfLinux_Trojan_Mirai_3a56423bunknownunknown
  • 0xb423:$a: 24 1C 8B 44 24 20 0F B6 D0 C1 E8 08 89 54 24 24 89 44 24 20 BA 01 00
i486.elfLinux_Trojan_Mirai_dab39a25unknownunknown
  • 0x9b32:$a: 0E 75 20 50 6A 00 6A 00 6A 00 53 6A 0E FF 74 24 48 68 DD 00
SourceRuleDescriptionAuthorStrings
6206.1.0000000008048000.000000000805a000.r-x.sdmpLinux_Trojan_Mirai_3a56423bunknownunknown
  • 0xb423:$a: 24 1C 8B 44 24 20 0F B6 D0 C1 E8 08 89 54 24 24 89 44 24 20 BA 01 00
6206.1.0000000008048000.000000000805a000.r-x.sdmpLinux_Trojan_Mirai_dab39a25unknownunknown
  • 0x9b32:$a: 0E 75 20 50 6A 00 6A 00 6A 00 53 6A 0E FF 74 24 48 68 DD 00
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: i486.elfReversingLabs: Detection: 13%
Source: i486.elfJoe Sandbox ML: detected
Source: i486.elfString: /lib//sbin//usr//proc//exeself/fd/fd/socket:/proc/proc//exewgetcurlftpmountabcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789/proc/net/tcp/proc//exe/fd//proc//maps/lib/usr/lib
Source: global trafficTCP traffic: 192.168.2.23:50922 -> 193.70.75.42:5555
Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: global trafficDNS traffic detected: DNS query: foxthreatnointel.africa
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443

System Summary

barindex
Source: i486.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_3a56423b Author: unknown
Source: i486.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_dab39a25 Author: unknown
Source: 6206.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_3a56423b Author: unknown
Source: 6206.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_dab39a25 Author: unknown
Source: ELF static info symbol of initial sampleName: add_attack
Source: ELF static info symbol of initial sampleName: attack_add_pid
Source: ELF static info symbol of initial sampleName: attack_init
Source: ELF static info symbol of initial sampleName: attack_ongoing
Source: ELF static info symbol of initial sampleName: attack_parse
Source: ELF static info symbol of initial sampleName: attack_remove_id
Source: ELF static info symbol of initial sampleName: attack_start
Source: ELF static info symbol of initial sampleName: attack_stop
Source: ELF static info symbol of initial sampleName: attacks_ack
Source: ELF static info symbol of initial sampleName: attacks_gre
Source: i486.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_3a56423b os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 117d6eb47f000c9d475119ca0e6a1b49a91bbbece858758aaa3d7f30d0777d75, id = 3a56423b-c0cf-4483-87e3-552beb40563a, last_modified = 2021-09-16
Source: i486.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_dab39a25 reference_sample = 3e02fb63803110cabde08e809cf4acc1b8fb474ace531959a311858fdd578bab, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 5a628d9af9d6dccf29e78f780bb74a2fa25167954c34d4a1529bdea5ea891ac0, id = dab39a25-852b-441f-86ab-23d945daa62c, last_modified = 2022-01-26
Source: 6206.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_3a56423b os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 117d6eb47f000c9d475119ca0e6a1b49a91bbbece858758aaa3d7f30d0777d75, id = 3a56423b-c0cf-4483-87e3-552beb40563a, last_modified = 2021-09-16
Source: 6206.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_dab39a25 reference_sample = 3e02fb63803110cabde08e809cf4acc1b8fb474ace531959a311858fdd578bab, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 5a628d9af9d6dccf29e78f780bb74a2fa25167954c34d4a1529bdea5ea891ac0, id = dab39a25-852b-441f-86ab-23d945daa62c, last_modified = 2022-01-26
Source: classification engineClassification label: mal64.linELF@0/0@1/0
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity Information1
Scripting
Valid AccountsWindows Management Instrumentation1
Scripting
Path InterceptionDirect Volume AccessOS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Standard Port
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Non-Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture2
Application Layer Protocol
Traffic DuplicationData Destruction
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
SourceDetectionScannerLabelLink
i486.elf13%ReversingLabsLinux.Backdoor.Mirai
i486.elf100%Joe Sandbox ML
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
foxthreatnointel.africa
193.70.75.42
truefalse
    unknown
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    193.70.75.42
    foxthreatnointel.africaFrance
    16276OVHFRfalse
    109.202.202.202
    unknownSwitzerland
    13030INIT7CHfalse
    91.189.91.43
    unknownUnited Kingdom
    41231CANONICAL-ASGBfalse
    91.189.91.42
    unknownUnited Kingdom
    41231CANONICAL-ASGBfalse
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
    • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
    91.189.91.43boatnet.arm5.elfGet hashmaliciousMiraiBrowse
      nsharm6.elfGet hashmaliciousMiraiBrowse
        boatnet.sh4.elfGet hashmaliciousMiraiBrowse
          BoM00gWx1d.elfGet hashmaliciousUnknownBrowse
            hidakibest.ppc.elfGet hashmaliciousGafgyt, MiraiBrowse
              boatnet.arm7.elfGet hashmaliciousMiraiBrowse
                boatnet.arm.elfGet hashmaliciousMiraiBrowse
                  na.elfGet hashmaliciousUnknownBrowse
                    na.elfGet hashmaliciousUnknownBrowse
                      x86_64.elfGet hashmaliciousMirai, MoobotBrowse
                        91.189.91.42boatnet.arm5.elfGet hashmaliciousMiraiBrowse
                          nsharm6.elfGet hashmaliciousMiraiBrowse
                            boatnet.sh4.elfGet hashmaliciousMiraiBrowse
                              BoM00gWx1d.elfGet hashmaliciousUnknownBrowse
                                hidakibest.ppc.elfGet hashmaliciousGafgyt, MiraiBrowse
                                  boatnet.arm7.elfGet hashmaliciousMiraiBrowse
                                    boatnet.arm.elfGet hashmaliciousMiraiBrowse
                                      na.elfGet hashmaliciousUnknownBrowse
                                        na.elfGet hashmaliciousUnknownBrowse
                                          x86_64.elfGet hashmaliciousMirai, MoobotBrowse
                                            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                            foxthreatnointel.africaSecuriteInfo.com.ELF.Mirai-CKB.17654.5746.elfGet hashmaliciousUnknownBrowse
                                            • 178.215.238.42
                                            SecuriteInfo.com.Linux.Siggen.9999.16805.28476.elfGet hashmaliciousUnknownBrowse
                                            • 89.110.102.82
                                            mipsGet hashmaliciousMirai, Gafgyt, OkiruBrowse
                                            • 193.124.33.3
                                            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                            CANONICAL-ASGBboatnet.arm5.elfGet hashmaliciousMiraiBrowse
                                            • 91.189.91.42
                                            na.elfGet hashmaliciousUnknownBrowse
                                            • 185.125.190.26
                                            nsharm6.elfGet hashmaliciousMiraiBrowse
                                            • 91.189.91.42
                                            botnet.mips.elfGet hashmaliciousUnknownBrowse
                                            • 185.125.190.26
                                            boatnet.sh4.elfGet hashmaliciousMiraiBrowse
                                            • 91.189.91.42
                                            bot.arm6.elfGet hashmaliciousMirai, OkiruBrowse
                                            • 185.125.190.26
                                            na.elfGet hashmaliciousUnknownBrowse
                                            • 185.125.190.26
                                            BoM00gWx1d.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            hidakibest.ppc.elfGet hashmaliciousGafgyt, MiraiBrowse
                                            • 91.189.91.42
                                            boatnet.arm7.elfGet hashmaliciousMiraiBrowse
                                            • 91.189.91.42
                                            CANONICAL-ASGBboatnet.arm5.elfGet hashmaliciousMiraiBrowse
                                            • 91.189.91.42
                                            na.elfGet hashmaliciousUnknownBrowse
                                            • 185.125.190.26
                                            nsharm6.elfGet hashmaliciousMiraiBrowse
                                            • 91.189.91.42
                                            botnet.mips.elfGet hashmaliciousUnknownBrowse
                                            • 185.125.190.26
                                            boatnet.sh4.elfGet hashmaliciousMiraiBrowse
                                            • 91.189.91.42
                                            bot.arm6.elfGet hashmaliciousMirai, OkiruBrowse
                                            • 185.125.190.26
                                            na.elfGet hashmaliciousUnknownBrowse
                                            • 185.125.190.26
                                            BoM00gWx1d.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            hidakibest.ppc.elfGet hashmaliciousGafgyt, MiraiBrowse
                                            • 91.189.91.42
                                            boatnet.arm7.elfGet hashmaliciousMiraiBrowse
                                            • 91.189.91.42
                                            OVHFRla.bot.powerpc.elfGet hashmaliciousUnknownBrowse
                                            • 178.32.95.253
                                            Demande de proposition du CPE Les Coquins.pdfGet hashmaliciousUnknownBrowse
                                            • 144.217.158.133
                                            Demande de proposition du CPE Les Coquins.pdfGet hashmaliciousUnknownBrowse
                                            • 144.217.158.133
                                            http://tracking.nod.ro/tracking/click?d=v4CWpEHK8Z1tV13Kq0SNnCz3l4pJsmApRreVnXMqsPjuOlW2erarYEe1nKHryrl0g1Aum4XVcWSRzzL9_ygST87VKk2nbDBhx1QybYWkDoE7f-SCn7T5e0BBYpqLQzpruG7FRHbBYNDPftLgaaLpRJA1Get hashmaliciousUnknownBrowse
                                            • 46.105.88.234
                                            https://us-west-2.protection.sophos.com/?d=site.pro&u=aHR0cHM6Ly9jbGF1ZGlha3J1ZWdlci5zaXRlLnByby8=&i=NThlN2NjYzYyOTljZjkxNGY4YmM1Njkz&t=QTRyTlRXbysvd3IyNERLT1pJYVNuNlAvU0FLMVAyb2pCN053UGFJSWtBST0=&h=dd65eaa7298b4ffebbd13b01dcbd3434&s=AVNPUEhUT0NFTkNSWVBUSVYfWTd0VrJEAZ1PFPx8UNdDDkWk4HVuGeVZrBnJzV7IfgGet hashmaliciousUnknownBrowse
                                            • 51.75.86.98
                                            https://wetransfer.com/downloads/21820466a51be0cc0de4ef5fd28415d320241023112541/61ecbec42424c68f99ca983cd530758a20241023112545/5d3030?t_exp=1729941941&t_lsid=761fb8c4-59e5-4423-a2fe-24d132de0406&t_network=email&t_rid=YXV0aDB8NjcxMjZmN2QzOGFjMDNkYThkOGJmMDM3&t_s=download_link&t_ts=1729682745&utm_campaign=TRN_TDL_01&utm_source=sendgrid&utm_medium=email&trk=TRN_TDL_01Get hashmaliciousUnknownBrowse
                                            • 87.98.227.35
                                            mpsl.elfGet hashmaliciousMiraiBrowse
                                            • 164.133.71.228
                                            https://docdro.id/1KhZgy2Get hashmaliciousUnknownBrowse
                                            • 54.37.79.95
                                            https://zupimages.net/up/24/42/ol13.jpg?d6mSMvU0ZvpGwffnuqPHYMR7NvlxIzVjDfTD4YJjdRSCOccGet hashmaliciousUnknownBrowse
                                            • 51.38.120.206
                                            Doc 784-01965670.exeGet hashmaliciousFormBookBrowse
                                            • 94.23.162.163
                                            INIT7CHboatnet.arm5.elfGet hashmaliciousMiraiBrowse
                                            • 109.202.202.202
                                            nsharm6.elfGet hashmaliciousMiraiBrowse
                                            • 109.202.202.202
                                            boatnet.sh4.elfGet hashmaliciousMiraiBrowse
                                            • 109.202.202.202
                                            BoM00gWx1d.elfGet hashmaliciousUnknownBrowse
                                            • 109.202.202.202
                                            hidakibest.ppc.elfGet hashmaliciousGafgyt, MiraiBrowse
                                            • 109.202.202.202
                                            boatnet.arm7.elfGet hashmaliciousMiraiBrowse
                                            • 109.202.202.202
                                            boatnet.arm.elfGet hashmaliciousMiraiBrowse
                                            • 109.202.202.202
                                            na.elfGet hashmaliciousUnknownBrowse
                                            • 109.202.202.202
                                            na.elfGet hashmaliciousUnknownBrowse
                                            • 109.202.202.202
                                            x86_64.elfGet hashmaliciousMirai, MoobotBrowse
                                            • 109.202.202.202
                                            No context
                                            No context
                                            No created / dropped files found
                                            File type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, with debug_info, not stripped
                                            Entropy (8bit):6.300366753469721
                                            TrID:
                                            • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
                                            • ELF Executable and Linkable format (generic) (4004/1) 49.84%
                                            File name:i486.elf
                                            File size:94'472 bytes
                                            MD5:bd0da6d215821625c85f701133b3d758
                                            SHA1:0b0eca5e58828339727ed228a25e70d98c1a39ed
                                            SHA256:ed9e82f85045eab3ef7c4e42b9c9ac2b85d4b619e7c34398b96b3eefa8f3a884
                                            SHA512:2225e74a305b73ca21971dad73b20725acd0beab179b6b8f3d5963a044d8320edefefebdf1def06e7a62df229d4f0c3b9accac3d4bdafc46dccffebab0002199
                                            SSDEEP:1536:dobXVO9V4z6afHKDaI8PUu3103YkGbrX2G/K0bTvBsmqe:dobgV4Wafqsi3wPmGsmqe
                                            TLSH:E7934B05A351D072D04703B021D3CBA68630EE762769C92FF3587EB5BF35285B2A676E
                                            File Content Preview:.ELF....................d...4....4......4. ...(.....................................................$...09..........Q.td................................t.......................U......=.....t..D...................P......P.......u........t....h.............

                                            ELF header

                                            Class:ELF32
                                            Data:2's complement, little endian
                                            Version:1 (current)
                                            Machine:Intel 80386
                                            Version Number:0x1
                                            Type:EXEC (Executable file)
                                            OS/ABI:UNIX - System V
                                            ABI Version:0
                                            Entry Point Address:0x8048164
                                            Flags:0x0
                                            ELF Header Size:52
                                            Program Header Offset:52
                                            Program Header Size:32
                                            Number of Program Headers:3
                                            Section Header Offset:78848
                                            Section Header Size:40
                                            Number of Section Headers:25
                                            Header String Table Index:22
                                            NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                            NULL0x00x00x00x00x0000
                                            .initPROGBITS0x80480940x940x110x00x6AX001
                                            .textPROGBITS0x80480b00xb00x102b40x00x6AX0016
                                            .finiPROGBITS0x80583640x103640xc0x00x6AX001
                                            .rodataPROGBITS0x80583800x103800x12380x00x2A0032
                                            .eh_framePROGBITS0x805a5b80x115b80x740x00x3WA004
                                            .ctorsPROGBITS0x805a62c0x1162c0x80x00x3WA004
                                            .dtorsPROGBITS0x805a6340x116340x80x00x3WA004
                                            .jcrPROGBITS0x805a63c0x1163c0x40x00x3WA004
                                            .got.pltPROGBITS0x805a6400x116400xc0x40x3WA004
                                            .dataPROGBITS0x805a64c0x1164c0x900x00x3WA004
                                            .bssNOBITS0x805a6e00x116dc0x38080x00x3WA0032
                                            .commentPROGBITS0x00x116dc0x9900x00x0001
                                            .debug_arangesPROGBITS0x00x1206c0x400x00x0001
                                            .debug_pubnamesPROGBITS0x00x120ac0x400x00x0001
                                            .debug_infoPROGBITS0x00x120ec0x60a0x00x0001
                                            .debug_abbrevPROGBITS0x00x126f60x2ac0x00x0001
                                            .debug_linePROGBITS0x00x129a20x1900x00x0001
                                            .debug_framePROGBITS0x00x12b340x800x00x0004
                                            .debug_strPROGBITS0x00x12bb40x1270x10x30MS001
                                            .debug_locPROGBITS0x00x12cdb0x5dd0x00x0001
                                            .debug_rangesPROGBITS0x00x132b80x600x00x0001
                                            .shstrtabSTRTAB0x00x133180xe50x00x0001
                                            .symtabSYMTAB0x00x137e80x23c00x100x0242764
                                            .strtabSTRTAB0x00x15ba80x15600x00x0001
                                            TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                            LOAD0x00x80480000x80480000x115b80x115b86.37280x5R E0x1000.init .text .fini .rodata
                                            LOAD0x115b80x805a5b80x805a5b80x1240x39302.97410x6RW 0x1000.eh_frame .ctors .dtors .jcr .got.plt .data .bss
                                            GNU_STACK0x00x00x00x00x00.00000x6RW 0x4
                                            NameVersion Info NameVersion Info File NameSection NameValueSizeSymbol TypeSymbol BindSymbol VisibilityNdx
                                            .symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                            .symtab0x80480940SECTION<unknown>DEFAULT1
                                            .symtab0x80480b00SECTION<unknown>DEFAULT2
                                            .symtab0x80583640SECTION<unknown>DEFAULT3
                                            .symtab0x80583800SECTION<unknown>DEFAULT4
                                            .symtab0x805a5b80SECTION<unknown>DEFAULT5
                                            .symtab0x805a62c0SECTION<unknown>DEFAULT6
                                            .symtab0x805a6340SECTION<unknown>DEFAULT7
                                            .symtab0x805a63c0SECTION<unknown>DEFAULT8
                                            .symtab0x805a6400SECTION<unknown>DEFAULT9
                                            .symtab0x805a64c0SECTION<unknown>DEFAULT10
                                            .symtab0x805a6e00SECTION<unknown>DEFAULT11
                                            .symtab0x00SECTION<unknown>DEFAULT12
                                            .symtab0x00SECTION<unknown>DEFAULT13
                                            .symtab0x00SECTION<unknown>DEFAULT14
                                            .symtab0x00SECTION<unknown>DEFAULT15
                                            .symtab0x00SECTION<unknown>DEFAULT16
                                            .symtab0x00SECTION<unknown>DEFAULT17
                                            .symtab0x00SECTION<unknown>DEFAULT18
                                            .symtab0x00SECTION<unknown>DEFAULT19
                                            .symtab0x00SECTION<unknown>DEFAULT20
                                            .symtab0x00SECTION<unknown>DEFAULT21
                                            C.0.3074.symtab0x80584c040OBJECT<unknown>DEFAULT4
                                            C.10.3370.symtab0x805877c12OBJECT<unknown>DEFAULT4
                                            C.10.3370.symtab0x80587c416OBJECT<unknown>DEFAULT4
                                            C.10.3370.symtab0x805882512OBJECT<unknown>DEFAULT4
                                            C.11.3371.symtab0x805876820OBJECT<unknown>DEFAULT4
                                            C.11.3371.symtab0x80587ac24OBJECT<unknown>DEFAULT4
                                            C.11.3371.symtab0x805881120OBJECT<unknown>DEFAULT4
                                            C.12.3372.symtab0x805875420OBJECT<unknown>DEFAULT4
                                            C.12.3372.symtab0x805879424OBJECT<unknown>DEFAULT4
                                            C.12.3372.symtab0x80587fd20OBJECT<unknown>DEFAULT4
                                            C.18.3391.symtab0x80587e425OBJECT<unknown>DEFAULT4
                                            C.18.3406.symtab0x805874416OBJECT<unknown>DEFAULT4
                                            C.19.3416.symtab0x805873416OBJECT<unknown>DEFAULT4
                                            C.9.3369.symtab0x805878812OBJECT<unknown>DEFAULT4
                                            C.9.3369.symtab0x80587d416OBJECT<unknown>DEFAULT4
                                            C.9.3369.symtab0x805883112OBJECT<unknown>DEFAULT4
                                            _DYNAMIC.symtab0x00NOTYPE<unknown>HIDDENSHN_UNDEF
                                            _Exit.symtab0x8054da821FUNC<unknown>DEFAULT2
                                            _Exit.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            _GLOBAL_OFFSET_TABLE_.symtab0x805a6400OBJECT<unknown>HIDDEN9
                                            _Jv_RegisterClasses.symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                            __CTOR_END__.symtab0x805a6300OBJECT<unknown>DEFAULT6
                                            __CTOR_LIST__.symtab0x805a62c0OBJECT<unknown>DEFAULT6
                                            __DTOR_END__.symtab0x805a6380OBJECT<unknown>DEFAULT7
                                            __DTOR_LIST__.symtab0x805a6340OBJECT<unknown>DEFAULT7
                                            __EH_FRAME_BEGIN__.symtab0x805a5b80OBJECT<unknown>DEFAULT5
                                            __FRAME_END__.symtab0x805a6280OBJECT<unknown>DEFAULT5
                                            __JCR_END__.symtab0x805a63c0OBJECT<unknown>DEFAULT8
                                            __JCR_LIST__.symtab0x805a63c0OBJECT<unknown>DEFAULT8
                                            ___environ.symtab0x805bc404OBJECT<unknown>DEFAULT11
                                            __aio_close.symtab0x8054a845FUNC<unknown>DEFAULT2
                                            __block_all_sigs.symtab0x8053af731FUNC<unknown>DEFAULT2
                                            __block_app_sigs.symtab0x8053ad831FUNC<unknown>DEFAULT2
                                            __bss_start.symtab0x805a6dc0NOTYPE<unknown>DEFAULTSHN_ABS
                                            __clock_gettime.symtab0x80549a087FUNC<unknown>DEFAULT2
                                            __copy_tls.symtab0x8054c0496FUNC<unknown>DEFAULT2
                                            __deregister_frame_info_bases.symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                            __do_global_ctors_aux.symtab0x80583300FUNC<unknown>DEFAULT2
                                            __do_global_dtors_aux.symtab0x80480b00FUNC<unknown>DEFAULT2
                                            __dso_handle.symtab0x805a64c0OBJECT<unknown>HIDDEN10
                                            __environ.symtab0x805bc404OBJECT<unknown>DEFAULT11
                                            __environ.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            __errno_location.symtab0x8051acc10FUNC<unknown>DEFAULT2
                                            __errno_location.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            __expand_heap.symtab0x8055900389FUNC<unknown>DEFAULT2
                                            __fini_array_end.symtab0x805a62c0NOTYPE<unknown>HIDDEN6
                                            __fini_array_start.symtab0x805a62c0NOTYPE<unknown>HIDDEN6
                                            __fork_handler.symtab0x8053a1c1FUNC<unknown>DEFAULT2
                                            __fpclassifyl.symtab0x8057afc103FUNC<unknown>DEFAULT2
                                            __fpclassifyl.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            __funcs_on_exit.symtab0x8051ad81FUNC<unknown>DEFAULT2
                                            __fwritex.symtab0x8057d60152FUNC<unknown>DEFAULT2
                                            __get_handler_set.symtab0x8055a8823FUNC<unknown>DEFAULT2
                                            __hwcap.symtab0x805de804OBJECT<unknown>DEFAULT11
                                            __inet_aton.symtab0x8053380234FUNC<unknown>DEFAULT2
                                            __init_array_end.symtab0x805a62c0NOTYPE<unknown>HIDDEN6
                                            __init_array_start.symtab0x805a62c0NOTYPE<unknown>HIDDEN6
                                            __init_ssp.symtab0x80519491FUNC<unknown>DEFAULT2
                                            __init_tls.symtab0x8054c64324FUNC<unknown>DEFAULT2
                                            __init_tls.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            __intscan.symtab0x8054dc01929FUNC<unknown>DEFAULT2
                                            __lctrans.symtab0x8057ad55FUNC<unknown>DEFAULT2
                                            __lctrans.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            __lctrans_cur.symtab0x8057ada32FUNC<unknown>DEFAULT2
                                            __lctrans_impl.symtab0x8057ad05FUNC<unknown>DEFAULT2
                                            __libc.symtab0x805dea052OBJECT<unknown>DEFAULT11
                                            __libc_sigaction.symtab0x8055a9f331FUNC<unknown>DEFAULT2
                                            __libc_start_main.symtab0x805194a386FUNC<unknown>DEFAULT2
                                            __libc_start_main.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            __lock.symtab0x805483b52FUNC<unknown>DEFAULT2
                                            __lock.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            __lockfile.symtab0x8057ca178FUNC<unknown>DEFAULT2
                                            __lockfile.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            __madvise.symtab0x805309433FUNC<unknown>DEFAULT2
                                            __malloc0.symtab0x805305065FUNC<unknown>DEFAULT2
                                            __memcpy_fwd.symtab0x8053f500NOTYPE<unknown>HIDDEN2
                                            __mmap.symtab0x80530b9162FUNC<unknown>DEFAULT2
                                            __mremap.symtab0x805315c64FUNC<unknown>DEFAULT2
                                            __munmap.symtab0x805319d44FUNC<unknown>DEFAULT2
                                            __ofl_lock.symtab0x805805122FUNC<unknown>DEFAULT2
                                            __ofl_unlock.symtab0x805804017FUNC<unknown>DEFAULT2
                                            __progname.symtab0x805b7d04OBJECT<unknown>DEFAULT11
                                            __progname_full.symtab0x805b7d44OBJECT<unknown>DEFAULT11
                                            __register_frame_info_bases.symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                            __restore.symtab0x8057c480FUNC<unknown>DEFAULT2
                                            __restore_rt.symtab0x8057c500FUNC<unknown>DEFAULT2
                                            __restore_sigs.symtab0x8053b1631FUNC<unknown>DEFAULT2
                                            __set_thread_area.symtab0x80579e40FUNC<unknown>DEFAULT2
                                            __shgetc.symtab0x80555d0273FUNC<unknown>DEFAULT2
                                            __shlim.symtab0x8055550118FUNC<unknown>DEFAULT2
                                            __sigaction.symtab0x8055bea42FUNC<unknown>DEFAULT2
                                            __signbitl.symtab0x8057b6435FUNC<unknown>DEFAULT2
                                            __signbitl.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            __simple_malloc.symtab0x8051e40245FUNC<unknown>DEFAULT2
                                            __static_tls.symtab0x805ded816OBJECT<unknown>DEFAULT11
                                            __stderr_used.symtab0x805bd704OBJECT<unknown>DEFAULT11
                                            __stdin_used.symtab0x805bd704OBJECT<unknown>DEFAULT11
                                            __stdio_exit.symtab0x8057fc947FUNC<unknown>DEFAULT2
                                            __stdio_exit.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            __stdio_exit_needed.symtab0x8057fc947FUNC<unknown>DEFAULT2
                                            __stdout_used.symtab0x805bd704OBJECT<unknown>DEFAULT11
                                            __stpcpy.symtab0x8057660131FUNC<unknown>DEFAULT2
                                            __stpncpy.symtab0x80576f0206FUNC<unknown>DEFAULT2
                                            __strchrnul.symtab0x80577f0203FUNC<unknown>DEFAULT2
                                            __strerror_l.symtab0x8057a6874FUNC<unknown>DEFAULT2
                                            __strtoimax_internal.symtab0x8053ed25FUNC<unknown>DEFAULT2
                                            __strtol_internal.symtab0x8053e7631FUNC<unknown>DEFAULT2
                                            __strtoll_internal.symtab0x8053eb133FUNC<unknown>DEFAULT2
                                            __strtoul_internal.symtab0x8053e9528FUNC<unknown>DEFAULT2
                                            __strtoull_internal.symtab0x8053ed733FUNC<unknown>DEFAULT2
                                            __strtoumax_internal.symtab0x8053ef85FUNC<unknown>DEFAULT2
                                            __syscall.symtab0x8051d470FUNC<unknown>HIDDEN2
                                            __syscall_cp.symtab0x80548705FUNC<unknown>DEFAULT2
                                            __syscall_cp.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            __syscall_cp_c.symtab0x80548755FUNC<unknown>DEFAULT2
                                            __syscall_ret.symtab0x8051d7039FUNC<unknown>DEFAULT2
                                            __sysinfo.symtab0x805ded44OBJECT<unknown>HIDDEN11
                                            __sysv_signal.symtab0x8053bac98FUNC<unknown>DEFAULT2
                                            __toread.symtab0x8057cf0104FUNC<unknown>DEFAULT2
                                            __toread.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            __toread_needs_stdio_exit.symtab0x8057d585FUNC<unknown>DEFAULT2
                                            __towrite.symtab0x8057ff865FUNC<unknown>DEFAULT2
                                            __towrite.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            __towrite_needs_stdio_exit.symtab0x80580395FUNC<unknown>DEFAULT2
                                            __udivdi3.symtab0x8058070331FUNC<unknown>HIDDEN2
                                            __uflow.symtab0x8055c1454FUNC<unknown>DEFAULT2
                                            __uflow.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            __umoddi3.symtab0x80581c0367FUNC<unknown>HIDDEN2
                                            __unlock.symtab0x80547f471FUNC<unknown>DEFAULT2
                                            __unlockfile.symtab0x8057c5873FUNC<unknown>DEFAULT2
                                            __vdsosym.symtab0x80556f0525FUNC<unknown>DEFAULT2
                                            __vm_wait.symtab0x80530b81FUNC<unknown>DEFAULT2
                                            __vsyscall.symtab0x8051cfc0FUNC<unknown>HIDDEN2
                                            __vsyscall6.symtab0x8051d2d0FUNC<unknown>HIDDEN2
                                            __wait.symtab0x805487c148FUNC<unknown>DEFAULT2
                                            __wait.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            _atoi.symtab0x80510b776FUNC<unknown>DEFAULT2
                                            _edata.symtab0x805a6dc0NOTYPE<unknown>DEFAULTSHN_ABS
                                            _end.symtab0x805dee80NOTYPE<unknown>DEFAULTSHN_ABS
                                            _environ.symtab0x805bc404OBJECT<unknown>DEFAULT11
                                            _fini.symtab0x80583640NOTYPE<unknown>DEFAULT3
                                            _init.symtab0x80480940NOTYPE<unknown>DEFAULT1
                                            _start.symtab0x80481640NOTYPE<unknown>DEFAULT2
                                            _start_c.symtab0x804817f35FUNC<unknown>DEFAULT2
                                            ack.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            add_attack.symtab0x8049af5125FUNC<unknown>DEFAULT2
                                            add_entry.symtab0x805178499FUNC<unknown>DEFAULT2
                                            all_mask.symtab0x80589b48OBJECT<unknown>DEFAULT4
                                            alloc_fwd.symtab0x80521a0561FUNC<unknown>DEFAULT2
                                            alloc_rev.symtab0x8051f40594FUNC<unknown>DEFAULT2
                                            app_mask.symtab0x80589ac8OBJECT<unknown>DEFAULT4
                                            atoi.symtab0x8053d8476FUNC<unknown>DEFAULT2
                                            atoi.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            attack_add_pid.symtab0x804949a69FUNC<unknown>DEFAULT2
                                            attack_init.symtab0x80492b8229FUNC<unknown>DEFAULT2
                                            attack_ongoing.symtab0x805a74080OBJECT<unknown>DEFAULT11
                                            attack_parse.symtab0x804952a772FUNC<unknown>DEFAULT2
                                            attack_remove_id.symtab0x80494df75FUNC<unknown>DEFAULT2
                                            attack_start.symtab0x804982e268FUNC<unknown>DEFAULT2
                                            attack_stop.symtab0x804939d253FUNC<unknown>DEFAULT2
                                            attacks_ack.symtab0x804a0241379FUNC<unknown>DEFAULT2
                                            attacks_gre.symtab0x804a5881117FUNC<unknown>DEFAULT2
                                            attacks_icmp.symtab0x804a9e81022FUNC<unknown>DEFAULT2
                                            attacks_raknet.symtab0x804ade81797FUNC<unknown>DEFAULT2
                                            attacks_rand.symtab0x804b4f01078FUNC<unknown>DEFAULT2
                                            attacks_socket.symtab0x804b9811371FUNC<unknown>DEFAULT2
                                            attacks_std.symtab0x804bedc1120FUNC<unknown>DEFAULT2
                                            attacks_stomp.symtab0x804c33c2131FUNC<unknown>DEFAULT2
                                            attacks_syn.symtab0x804cb901778FUNC<unknown>DEFAULT2
                                            attacks_tfo.symtab0x804d2841834FUNC<unknown>DEFAULT2
                                            attacks_udp.symtab0x804d9b01414FUNC<unknown>DEFAULT2
                                            attacks_vse.symtab0x804df381387FUNC<unknown>DEFAULT2
                                            attacks_wra.symtab0x804e4a41778FUNC<unknown>DEFAULT2
                                            authenticate.symtab0x8048b4b264FUNC<unknown>DEFAULT2
                                            bind.symtab0x80531cc83FUNC<unknown>DEFAULT2
                                            bind.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            block.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            brk.1727.symtab0x805bd604OBJECT<unknown>DEFAULT11
                                            bsd_signal.symtab0x8053bac98FUNC<unknown>DEFAULT2
                                            builtin_tls.symtab0x805bc44280OBJECT<unknown>DEFAULT11
                                            calloc.symtab0x8051e0063FUNC<unknown>DEFAULT2
                                            calloc.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            cgt.1877.symtab0x805bc3c4OBJECT<unknown>DEFAULT11
                                            check_conn.symtab0x804b92889FUNC<unknown>DEFAULT2
                                            check_proc.symtab0x804f529545FUNC<unknown>DEFAULT2
                                            checksum.symtab0x804f820141FUNC<unknown>DEFAULT2
                                            checksum.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            clock.symtab0x805494c81FUNC<unknown>DEFAULT2
                                            clock.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            clock_gettime.symtab0x80549a087FUNC<unknown>DEFAULT2
                                            clock_gettime.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            close.symtab0x8054a8957FUNC<unknown>DEFAULT2
                                            close.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            close_file.symtab0x8057f7c77FUNC<unknown>DEFAULT2
                                            closedir.symtab0x805187034FUNC<unknown>DEFAULT2
                                            closedir.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            cnc_ports.symtab0x805a65816OBJECT<unknown>DEFAULT10
                                            command_parse.symtab0x80481a4655FUNC<unknown>DEFAULT2
                                            completed.4058.symtab0x805a6e01OBJECT<unknown>DEFAULT11
                                            conn.symtab0x805bd808368OBJECT<unknown>DEFAULT11
                                            connect.symtab0x805322087FUNC<unknown>DEFAULT2
                                            connect.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            crt1.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            crtstuff.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            crtstuff.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            cur.1594.symtab0x805b7e44OBJECT<unknown>DEFAULT11
                                            dummy.symtab0x80519481FUNC<unknown>DEFAULT2
                                            dummy.symtab0x8051ad81FUNC<unknown>DEFAULT2
                                            dummy.symtab0x80530b81FUNC<unknown>DEFAULT2
                                            dummy.symtab0x805319c1FUNC<unknown>DEFAULT2
                                            dummy.symtab0x8053a1c1FUNC<unknown>DEFAULT2
                                            dummy.symtab0x8054a845FUNC<unknown>DEFAULT2
                                            dummy.symtab0x8057ad05FUNC<unknown>DEFAULT2
                                            dummy1.symtab0x80519491FUNC<unknown>DEFAULT2
                                            dummy_file.symtab0x805bd704OBJECT<unknown>DEFAULT11
                                            dup2.symtab0x8054ac432FUNC<unknown>DEFAULT2
                                            dup2.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            end.1595.symtab0x805b7e04OBJECT<unknown>DEFAULT11
                                            end.3155.symtab0x805b8004OBJECT<unknown>DEFAULT11
                                            environ.symtab0x805bc404OBJECT<unknown>DEFAULT11
                                            errid.symtab0x8058e5088OBJECT<unknown>DEFAULT4
                                            errmsg.symtab0x8058ea81804OBJECT<unknown>DEFAULT4
                                            esi_fd.symtab0x805a6684OBJECT<unknown>DEFAULT10
                                            exe_access.symtab0x804f298279FUNC<unknown>DEFAULT2
                                            execve.symtab0x80539f833FUNC<unknown>DEFAULT2
                                            execve.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            exit.symtab0x8051ad951FUNC<unknown>DEFAULT2
                                            exit.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            expand_heap.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            fcntl.symtab0x8051b0c373FUNC<unknown>DEFAULT2
                                            fcntl.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            fmt_u.symtab0x8055cfd87FUNC<unknown>DEFAULT2
                                            fork.symtab0x8053a1d138FUNC<unknown>DEFAULT2
                                            fork.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            frame_dummy.symtab0x80481100FUNC<unknown>DEFAULT2
                                            free.symtab0x80523e01107FUNC<unknown>DEFAULT2
                                            free_opts.symtab0x8049b7286FUNC<unknown>DEFAULT2
                                            frexpl.symtab0x8057b88155FUNC<unknown>DEFAULT2
                                            frexpl.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            fwrite.symtab0x8057df8115FUNC<unknown>DEFAULT2
                                            fwrite.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            fwrite_unlocked.symtab0x8057df8115FUNC<unknown>DEFAULT2
                                            get_local_addr.symtab0x8051471157FUNC<unknown>DEFAULT2
                                            getint.symtab0x8055d5437FUNC<unknown>DEFAULT2
                                            getpid.symtab0x8054ae411FUNC<unknown>DEFAULT2
                                            getpid.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            getppid.symtab0x8054af011FUNC<unknown>DEFAULT2
                                            getppid.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            getsockname.symtab0x805327883FUNC<unknown>DEFAULT2
                                            getsockname.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            getsockopt.symtab0x80532cc83FUNC<unknown>DEFAULT2
                                            getsockopt.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            gre.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            handler_set.symtab0x805bd688OBJECT<unknown>DEFAULT11
                                            head.symtab0x805a7904OBJECT<unknown>DEFAULT11
                                            heap_lock.3154.symtab0x805b8048OBJECT<unknown>DEFAULT11
                                            htonl.symtab0x805332041FUNC<unknown>DEFAULT2
                                            htonl.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            htons.symtab0x805334c12FUNC<unknown>DEFAULT2
                                            htons.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            icmp.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            inet_addr.symtab0x805335837FUNC<unknown>DEFAULT2
                                            inet_addr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            inet_aton.symtab0x8053380234FUNC<unknown>DEFAULT2
                                            inet_aton.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            inet_ntop.symtab0x805346c582FUNC<unknown>DEFAULT2
                                            inet_ntop.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            intscan.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            kill.symtab0x8053b3827FUNC<unknown>DEFAULT2
                                            kill.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            killer.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            killer_add_process.symtab0x804ec6d67FUNC<unknown>DEFAULT2
                                            killer_check_paths.symtab0x804eb98144FUNC<unknown>DEFAULT2
                                            killer_find_realpath.symtab0x804ecb0109FUNC<unknown>DEFAULT2
                                            killer_pid.symtab0x805a7004OBJECT<unknown>DEFAULT11
                                            killer_realpath.symtab0x805a7c04096OBJECT<unknown>DEFAULT11
                                            killer_shoot_list.symtab0x804ed1d438FUNC<unknown>DEFAULT2
                                            killer_start.symtab0x804eed3962FUNC<unknown>DEFAULT2
                                            killer_vanish_list.symtab0x804ec2869FUNC<unknown>DEFAULT2
                                            libc.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            libgcc2.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            libgcc2.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            listen.symtab0x80536b483FUNC<unknown>DEFAULT2
                                            listen.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            lite_malloc.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            lock.1596.symtab0x805b7d88OBJECT<unknown>DEFAULT11
                                            locker.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            locker_find.symtab0x804f3af111FUNC<unknown>DEFAULT2
                                            locker_getpids.symtab0x804f49c141FUNC<unknown>DEFAULT2
                                            locker_init.symtab0x804f74a211FUNC<unknown>DEFAULT2
                                            locker_insert.symtab0x804f41e126FUNC<unknown>DEFAULT2
                                            locker_pid.symtab0x805a6fc4OBJECT<unknown>DEFAULT11
                                            locker_process.symtab0x8048e2f127FUNC<unknown>DEFAULT2
                                            locker_status.symtab0x805a7041OBJECT<unknown>DEFAULT11
                                            madvise.symtab0x805309433FUNC<unknown>DEFAULT2
                                            madvise.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            main.symtab0x804903f631FUNC<unknown>DEFAULT2
                                            main.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            main_check_connection.symtab0x804883e157FUNC<unknown>DEFAULT2
                                            main_disconnect_connection.symtab0x80488db111FUNC<unknown>DEFAULT2
                                            main_handle_connection.symtab0x8048c53426FUNC<unknown>DEFAULT2
                                            main_make_connection.symtab0x80484331035FUNC<unknown>DEFAULT2
                                            main_read_connection.symtab0x8048af586FUNC<unknown>DEFAULT2
                                            main_read_data.symtab0x804894a350FUNC<unknown>DEFAULT2
                                            mal.symtab0x805b8201040OBJECT<unknown>DEFAULT11
                                            malloc.symtab0x80528401459FUNC<unknown>DEFAULT2
                                            malloc.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            memchr.symtab0x80575a0178FUNC<unknown>DEFAULT2
                                            memchr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            memcmp.symtab0x8053f0080FUNC<unknown>DEFAULT2
                                            memcmp.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            memcpy.symtab0x8053f500FUNC<unknown>DEFAULT2
                                            memmove.symtab0x8053f8c0FUNC<unknown>DEFAULT2
                                            memset.symtab0x8053fc00FUNC<unknown>DEFAULT2
                                            methods.symtab0x805a7244OBJECT<unknown>DEFAULT11
                                            methods_len.symtab0x805a7201OBJECT<unknown>DEFAULT11
                                            mmap.symtab0x80530b9162FUNC<unknown>DEFAULT2
                                            mmap.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            mmap64.symtab0x80530b9162FUNC<unknown>DEFAULT2
                                            mmap_step.1728.symtab0x805bd5c4OBJECT<unknown>DEFAULT11
                                            mremap.symtab0x805315c64FUNC<unknown>DEFAULT2
                                            mremap.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            munmap.symtab0x805319d44FUNC<unknown>DEFAULT2
                                            munmap.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            nanosleep.symtab0x8057a3c41FUNC<unknown>DEFAULT2
                                            nanosleep.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            ntohl.symtab0x805370841FUNC<unknown>DEFAULT2
                                            ntohl.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            ntohs.symtab0x805373412FUNC<unknown>DEFAULT2
                                            ntohs.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            number.symtab0x805a6544OBJECT<unknown>DEFAULT10
                                            number.symtab0x805a66c4OBJECT<unknown>DEFAULT10
                                            number.symtab0x805a6704OBJECT<unknown>DEFAULT10
                                            number.symtab0x805a6744OBJECT<unknown>DEFAULT10
                                            number.symtab0x805a6784OBJECT<unknown>DEFAULT10
                                            number.symtab0x805a67c4OBJECT<unknown>DEFAULT10
                                            number.symtab0x805a6804OBJECT<unknown>DEFAULT10
                                            number.symtab0x805a6844OBJECT<unknown>DEFAULT10
                                            number.symtab0x805a6884OBJECT<unknown>DEFAULT10
                                            number.symtab0x805a68c4OBJECT<unknown>DEFAULT10
                                            number.symtab0x805a6904OBJECT<unknown>DEFAULT10
                                            number.symtab0x805a6944OBJECT<unknown>DEFAULT10
                                            number.symtab0x805a6984OBJECT<unknown>DEFAULT10
                                            number.symtab0x805a69c4OBJECT<unknown>DEFAULT10
                                            number.symtab0x805a6a04OBJECT<unknown>DEFAULT10
                                            number.symtab0x805a6a44OBJECT<unknown>DEFAULT10
                                            number.symtab0x805a6a84OBJECT<unknown>DEFAULT10
                                            number.symtab0x805a6ac4OBJECT<unknown>DEFAULT10
                                            number.symtab0x805a6b04OBJECT<unknown>DEFAULT10
                                            number.symtab0x805a6b44OBJECT<unknown>DEFAULT10
                                            number.symtab0x805a6b84OBJECT<unknown>DEFAULT10
                                            number.symtab0x805a6bc4OBJECT<unknown>DEFAULT10
                                            number.symtab0x805a6c04OBJECT<unknown>DEFAULT10
                                            number.symtab0x805a6c44OBJECT<unknown>DEFAULT10
                                            object.4070.symtab0x805a6e424OBJECT<unknown>DEFAULT11
                                            ofl.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            ofl_head.symtab0x805bd744OBJECT<unknown>DEFAULT11
                                            ofl_lock.symtab0x805bd788OBJECT<unknown>DEFAULT11
                                            open.symtab0x8051c84120FUNC<unknown>DEFAULT2
                                            open.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            open64.symtab0x8051c84120FUNC<unknown>DEFAULT2
                                            opendir.symtab0x805189469FUNC<unknown>DEFAULT2
                                            opendir.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            options_hex.symtab0x80499eb266FUNC<unknown>DEFAULT2
                                            options_int.symtab0x804999190FUNC<unknown>DEFAULT2
                                            options_str.symtab0x804993a87FUNC<unknown>DEFAULT2
                                            out.symtab0x8055d7926FUNC<unknown>DEFAULT2
                                            p.1232.symtab0x805bc384OBJECT<unknown>DEFAULT11
                                            p.4056.symtab0x805a6500OBJECT<unknown>DEFAULT10
                                            pad.symtab0x8055d93126FUNC<unknown>DEFAULT2
                                            parse.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            pipe.symtab0x8054afc23FUNC<unknown>DEFAULT2
                                            pipe.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            pop_arg.symtab0x8055c4c177FUNC<unknown>DEFAULT2
                                            prctl.symtab0x8051d9895FUNC<unknown>DEFAULT2
                                            prctl.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            printf_core.symtab0x8055e115694FUNC<unknown>DEFAULT2
                                            profiles.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            program_invocation_name.symtab0x805b7d44OBJECT<unknown>DEFAULT11
                                            program_invocation_short_name.symtab0x805b7d04OBJECT<unknown>DEFAULT11
                                            pthread_sigmask.symtab0x805491057FUNC<unknown>DEFAULT2
                                            pthread_sigmask.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            raknet.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            rand.symtab0x80539b960FUNC<unknown>DEFAULT2
                                            rand.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            rand.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            rand.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            rand_domain.symtab0x804fbf1134FUNC<unknown>DEFAULT2
                                            rand_init.symtab0x804fb3c77FUNC<unknown>DEFAULT2
                                            rand_next.symtab0x804fb89104FUNC<unknown>DEFAULT2
                                            rand_num.symtab0x804fc7748FUNC<unknown>DEFAULT2
                                            rand_str.symtab0x804fca796FUNC<unknown>DEFAULT2
                                            read.symtab0x8054b1440FUNC<unknown>DEFAULT2
                                            read.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            readdir.symtab0x80518dc108FUNC<unknown>DEFAULT2
                                            readdir.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            readdir64.symtab0x80518dc108FUNC<unknown>DEFAULT2
                                            readlink.symtab0x8054b3c33FUNC<unknown>DEFAULT2
                                            readlink.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            realloc.symtab0x8052e00584FUNC<unknown>DEFAULT2
                                            recv.symtab0x805374032FUNC<unknown>DEFAULT2
                                            recv.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            recvfrom.symtab0x805376087FUNC<unknown>DEFAULT2
                                            recvfrom.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            resolv_domain_to_hostname.symtab0x804fd08125FUNC<unknown>DEFAULT2
                                            resolv_entries_free.symtab0x80504a756FUNC<unknown>DEFAULT2
                                            resolv_lookup.symtab0x804fe101687FUNC<unknown>DEFAULT2
                                            resolv_skip_name.symtab0x804fd85139FUNC<unknown>DEFAULT2
                                            resolver.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            root.symtab0x805a7a04OBJECT<unknown>DEFAULT11
                                            sc_clock_gettime.symtab0x80549f795FUNC<unknown>DEFAULT2
                                            sccp.symtab0x80548755FUNC<unknown>DEFAULT2
                                            seed.symtab0x805bc308OBJECT<unknown>DEFAULT11
                                            select.symtab0x8053aa847FUNC<unknown>DEFAULT2
                                            select.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            select_profile.symtab0x8049bc81115FUNC<unknown>DEFAULT2
                                            send.symtab0x80537b832FUNC<unknown>DEFAULT2
                                            send.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            send_heartbeat.symtab0x8048aa877FUNC<unknown>DEFAULT2
                                            sendto.symtab0x80537d887FUNC<unknown>DEFAULT2
                                            sendto.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            setsid.symtab0x8054b6023FUNC<unknown>DEFAULT2
                                            setsid.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            setsockopt.symtab0x805383083FUNC<unknown>DEFAULT2
                                            setsockopt.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            shgetc.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            sigaction.symtab0x8055bea42FUNC<unknown>DEFAULT2
                                            sigaction.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            sigaddset.symtab0x8053b5468FUNC<unknown>DEFAULT2
                                            sigaddset.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            sigemptyset.symtab0x8053b9820FUNC<unknown>DEFAULT2
                                            sigemptyset.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            signal.symtab0x8053bac98FUNC<unknown>DEFAULT2
                                            signal.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            sigprocmask.symtab0x8053c1046FUNC<unknown>DEFAULT2
                                            sigprocmask.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            single_instance.symtab0x8048eae401FUNC<unknown>DEFAULT2
                                            sleep.symtab0x8054b7849FUNC<unknown>DEFAULT2
                                            sleep.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            sn_write.symtab0x8053d4f51FUNC<unknown>DEFAULT2
                                            snprintf.symtab0x8053c5c33FUNC<unknown>DEFAULT2
                                            snprintf.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            socket.symtab0x8053884287FUNC<unknown>DEFAULT2
                                            socket.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            socket.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            srand.symtab0x80539a421FUNC<unknown>DEFAULT2
                                            start_killer_pid.symtab0x8048dfd50FUNC<unknown>DEFAULT2
                                            stat.symtab0x8053c4027FUNC<unknown>DEFAULT2
                                            stat.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            stat64.symtab0x8053c4027FUNC<unknown>DEFAULT2
                                            states.symtab0x8058c2c464OBJECT<unknown>DEFAULT4
                                            std.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            stomp.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            stpcpy.symtab0x8057660131FUNC<unknown>DEFAULT2
                                            stpcpy.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            stpncpy.symtab0x80576f0206FUNC<unknown>DEFAULT2
                                            stpncpy.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            strchr.symtab0x80577c043FUNC<unknown>DEFAULT2
                                            strchr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            strchrnul.symtab0x80577f0203FUNC<unknown>DEFAULT2
                                            strchrnul.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            strcmp.symtab0x80578c043FUNC<unknown>DEFAULT2
                                            strcmp.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            strcpy.symtab0x805408031FUNC<unknown>DEFAULT2
                                            strcpy.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            strcspn.symtab0x80578f0242FUNC<unknown>DEFAULT2
                                            strcspn.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            strerror.symtab0x8057ab228FUNC<unknown>DEFAULT2
                                            strerror.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            strerror_l.symtab0x8057a6874FUNC<unknown>DEFAULT2
                                            strlen.symtab0x80540a081FUNC<unknown>DEFAULT2
                                            strlen.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            strncpy.symtab0x805410039FUNC<unknown>DEFAULT2
                                            strncpy.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            strspn.symtab0x8054130193FUNC<unknown>DEFAULT2
                                            strspn.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            strstr.symtab0x80542001386FUNC<unknown>DEFAULT2
                                            strstr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            strtoimax.symtab0x8053ed25FUNC<unknown>DEFAULT2
                                            strtok.symtab0x8054770131FUNC<unknown>DEFAULT2
                                            strtok.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            strtol.symtab0x8053e7631FUNC<unknown>DEFAULT2
                                            strtol.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            strtoll.symtab0x8053eb133FUNC<unknown>DEFAULT2
                                            strtoul.symtab0x8053e9528FUNC<unknown>DEFAULT2
                                            strtoull.symtab0x8053ed733FUNC<unknown>DEFAULT2
                                            strtoumax.symtab0x8053ef85FUNC<unknown>DEFAULT2
                                            strtox.symtab0x8053dd0166FUNC<unknown>DEFAULT2
                                            syn.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            syscall_ret.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            table.symtab0x8058a00257OBJECT<unknown>DEFAULT4
                                            table.symtab0x805de4040OBJECT<unknown>DEFAULT11
                                            table.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            table_init.symtab0x805165c88FUNC<unknown>DEFAULT2
                                            table_key.symtab0x805a6c816OBJECT<unknown>DEFAULT10
                                            table_lock_val.symtab0x80516e953FUNC<unknown>DEFAULT2
                                            table_retrieve_val.symtab0x805171e102FUNC<unknown>DEFAULT2
                                            table_unlock_val.symtab0x80516b453FUNC<unknown>DEFAULT2
                                            tcp.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            tcp_checksum.symtab0x804fa6a209FUNC<unknown>DEFAULT2
                                            tcp_kill_port.symtab0x80504e01631FUNC<unknown>DEFAULT2
                                            tfo.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            time.symtab0x8054a5842FUNC<unknown>DEFAULT2
                                            time.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            toggle_obf.symtab0x80517e7137FUNC<unknown>DEFAULT2
                                            udp.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            udp4_checksum.symtab0x804f8ad445FUNC<unknown>DEFAULT2
                                            unmask_done.symtab0x805bd644OBJECT<unknown>DEFAULT11
                                            usleep.symtab0x8054bac47FUNC<unknown>DEFAULT2
                                            usleep.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            util.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            util_atoi.symtab0x8051103424FUNC<unknown>DEFAULT2
                                            util_fdgets.symtab0x805150e129FUNC<unknown>DEFAULT2
                                            util_isalpha.symtab0x80515bc57FUNC<unknown>DEFAULT2
                                            util_isdigit.symtab0x805162e45FUNC<unknown>DEFAULT2
                                            util_isspace.symtab0x80515f557FUNC<unknown>DEFAULT2
                                            util_isupper.symtab0x805158f45FUNC<unknown>DEFAULT2
                                            util_itoa.symtab0x80512ab253FUNC<unknown>DEFAULT2
                                            util_memcmp.symtab0x8050b40106FUNC<unknown>DEFAULT2
                                            util_memcpy.symtab0x805106647FUNC<unknown>DEFAULT2
                                            util_memset.symtab0x8050c2a36FUNC<unknown>DEFAULT2
                                            util_readlink.symtab0x8050c4e570FUNC<unknown>DEFAULT2
                                            util_startswith.symtab0x8050e8863FUNC<unknown>DEFAULT2
                                            util_strcat.symtab0x805103a44FUNC<unknown>DEFAULT2
                                            util_strcmp.symtab0x8050fa1106FUNC<unknown>DEFAULT2
                                            util_strcpy.symtab0x805100b47FUNC<unknown>DEFAULT2
                                            util_strdup.symtab0x8050ec764FUNC<unknown>DEFAULT2
                                            util_stristr.symtab0x80513a8201FUNC<unknown>DEFAULT2
                                            util_strlen.symtab0x8050f0740FUNC<unknown>DEFAULT2
                                            util_strncmp.symtab0x8050f2f114FUNC<unknown>DEFAULT2
                                            util_strstr.symtab0x8050baa128FUNC<unknown>DEFAULT2
                                            util_zero.symtab0x805109534FUNC<unknown>DEFAULT2
                                            vdso.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            vfprintf.symtab0x805744f333FUNC<unknown>DEFAULT2
                                            vfprintf.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            vse.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            vsnprintf.symtab0x8053c80207FUNC<unknown>DEFAULT2
                                            vsnprintf.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            w.symtab0x805b7cc4OBJECT<unknown>DEFAULT11
                                            wcrtomb.symtab0x8057e6c270FUNC<unknown>DEFAULT2
                                            wcrtomb.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            wctomb.symtab0x8057c2433FUNC<unknown>DEFAULT2
                                            wctomb.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            wra.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            write.symtab0x8054bdc40FUNC<unknown>DEFAULT2
                                            write.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                            x.symtab0x805b7c04OBJECT<unknown>DEFAULT11
                                            xdigits.symtab0x8058dfc16OBJECT<unknown>DEFAULT4
                                            y.symtab0x805b7c44OBJECT<unknown>DEFAULT11
                                            z.symtab0x805b7c84OBJECT<unknown>DEFAULT11
                                            TimestampSource PortDest PortSource IPDest IP
                                            Oct 24, 2024 11:33:04.460598946 CEST43928443192.168.2.2391.189.91.42
                                            Oct 24, 2024 11:33:06.090667963 CEST509225555192.168.2.23193.70.75.42
                                            Oct 24, 2024 11:33:06.097945929 CEST555550922193.70.75.42192.168.2.23
                                            Oct 24, 2024 11:33:06.098016977 CEST509225555192.168.2.23193.70.75.42
                                            Oct 24, 2024 11:33:08.099093914 CEST509225555192.168.2.23193.70.75.42
                                            Oct 24, 2024 11:33:08.104418039 CEST555550922193.70.75.42192.168.2.23
                                            Oct 24, 2024 11:33:08.104461908 CEST509225555192.168.2.23193.70.75.42
                                            Oct 24, 2024 11:33:08.109770060 CEST555550922193.70.75.42192.168.2.23
                                            Oct 24, 2024 11:33:09.835799932 CEST42836443192.168.2.2391.189.91.43
                                            Oct 24, 2024 11:33:11.371615887 CEST4251680192.168.2.23109.202.202.202
                                            Oct 24, 2024 11:33:26.217397928 CEST43928443192.168.2.2391.189.91.42
                                            Oct 24, 2024 11:33:36.456248045 CEST42836443192.168.2.2391.189.91.43
                                            Oct 24, 2024 11:33:42.599384069 CEST4251680192.168.2.23109.202.202.202
                                            Oct 24, 2024 11:34:07.171858072 CEST43928443192.168.2.2391.189.91.42
                                            Oct 24, 2024 11:35:08.191968918 CEST509225555192.168.2.23193.70.75.42
                                            Oct 24, 2024 11:35:08.197491884 CEST555550922193.70.75.42192.168.2.23
                                            Oct 24, 2024 11:35:08.506351948 CEST555550922193.70.75.42192.168.2.23
                                            Oct 24, 2024 11:35:08.506609917 CEST509225555192.168.2.23193.70.75.42
                                            TimestampSource PortDest PortSource IPDest IP
                                            Oct 24, 2024 11:33:06.081237078 CEST3816053192.168.2.238.8.8.8
                                            Oct 24, 2024 11:33:06.090548038 CEST53381608.8.8.8192.168.2.23
                                            TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                            Oct 24, 2024 11:33:06.081237078 CEST192.168.2.238.8.8.80x52b7Standard query (0)foxthreatnointel.africaA (IP address)IN (0x0001)false
                                            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                            Oct 24, 2024 11:33:06.090548038 CEST8.8.8.8192.168.2.230x52b7No error (0)foxthreatnointel.africa193.70.75.42A (IP address)IN (0x0001)false
                                            Oct 24, 2024 11:33:06.090548038 CEST8.8.8.8192.168.2.230x52b7No error (0)foxthreatnointel.africa178.215.238.10A (IP address)IN (0x0001)false
                                            Oct 24, 2024 11:33:06.090548038 CEST8.8.8.8192.168.2.230x52b7No error (0)foxthreatnointel.africa141.94.169.35A (IP address)IN (0x0001)false

                                            System Behavior

                                            Start time (UTC):09:33:04
                                            Start date (UTC):24/10/2024
                                            Path:/tmp/i486.elf
                                            Arguments:/tmp/i486.elf
                                            File size:94472 bytes
                                            MD5 hash:bd0da6d215821625c85f701133b3d758

                                            Start time (UTC):09:33:04
                                            Start date (UTC):24/10/2024
                                            Path:/tmp/i486.elf
                                            Arguments:-
                                            File size:94472 bytes
                                            MD5 hash:bd0da6d215821625c85f701133b3d758

                                            Start time (UTC):09:33:04
                                            Start date (UTC):24/10/2024
                                            Path:/tmp/i486.elf
                                            Arguments:-
                                            File size:94472 bytes
                                            MD5 hash:bd0da6d215821625c85f701133b3d758