Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
skid.arm.elf

Overview

General Information

Sample name:skid.arm.elf
Analysis ID:1427745
MD5:e7b4850c359b3f0f0533ee006d8f94db
SHA1:bfd586e31122c1502f02db0161bc849490c39737
SHA256:9a1e3e788306a30291cab8bf763b78f65ab8c9fc728145ad65cde2ccd0e0c103
Infos:

Detection

Score:48
Range:0 - 100
Whitelisted:false

Signatures

Multi AV Scanner detection for submitted file
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

Analysis Advice

Static ELF header machine description suggests that the sample might not execute correctly on this machine.
All HTTP servers contacted by the sample do not answer. The sample is likely an old dropper which does no longer work.
Non-zero exit code suggests an error during the execution. Lookup the error code for hints.
Static ELF header machine description suggests that the sample might only run correctly on MIPS or ARM architectures.
Joe Sandbox version:40.0.0 Tourmaline
Analysis ID:1427745
Start date and time:2024-04-18 03:51:04 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 10m 42s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:skid.arm.elf
Detection:MAL
Classification:mal48.linELF@0/0@0/0
Cookbook Comments:
  • Analysis time extended to 480s due to sleep detection in submitted sample
Command:/tmp/skid.arm.elf
PID:6240
Exit Code:255
Exit Code Info:
Killed:False
Standard Output:

Standard Error:/lib/ld-uClibc.so.0: No such file or directory
  • system is lnxubuntu20
  • skid.arm.elf (PID: 6240, Parent: 6160, MD5: 5ebfcae4fe2471fcc5695c2394773ff1) Arguments: /tmp/skid.arm.elf
  • cleanup
No yara matches
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: skid.arm.elfVirustotal: Detection: 8%Perma Link
Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
Source: classification engineClassification label: mal48.linELF@0/0@0/0
Source: skid.arm.elfELF static info symbol of initial sample: libc/sysdeps/linux/arm/crt1.S
Source: skid.arm.elfELF static info symbol of initial sample: libc/sysdeps/linux/arm/crti.S
Source: skid.arm.elfELF static info symbol of initial sample: libc/sysdeps/linux/arm/crtn.S
Source: /tmp/skid.arm.elf (PID: 6240)Queries kernel information via 'uname': Jump to behavior
Source: skid.arm.elf, 6240.1.00007ffde6b1b000.00007ffde6b3c000.rw-.sdmpBinary or memory string: qemu: %s: %s
Source: skid.arm.elf, 6240.1.00007ffde6b1b000.00007ffde6b3c000.rw-.sdmpBinary or memory string: leqemu: %s: %s
Source: skid.arm.elf, 6240.1.0000555d3b697000.0000555d3b7c5000.rw-.sdmpBinary or memory string: pi;]Urg.qemu.gdb.arm.sys.regs">
Source: skid.arm.elf, 6240.1.0000555d3b697000.0000555d3b7c5000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/arm
Source: skid.arm.elf, 6240.1.00007ffde6b1b000.00007ffde6b3c000.rw-.sdmpBinary or memory string: /usr/bin/qemu-arm
Source: skid.arm.elf, 6240.1.00007ffde6b1b000.00007ffde6b3c000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-arm/tmp/skid.arm.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/skid.arm.elf
Source: skid.arm.elf, 6240.1.0000555d3b697000.0000555d3b7c5000.rw-.sdmpBinary or memory string: j;]U!/etc/qemu-binfmt/arm
Source: skid.arm.elf, 6240.1.0000555d3b697000.0000555d3b7c5000.rw-.sdmpBinary or memory string: rg.qemu.gdb.arm.sys.regs">
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionDirect Volume AccessOS Credential Dumping11
Security Software Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
skid.arm.elf8%ReversingLabsLinux.Trojan.ReverseShell
skid.arm.elf8%VirustotalBrowse
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs
IPDomainCountryFlagASNASN NameMalicious
109.202.202.202
unknownSwitzerland
13030INIT7CHfalse
91.189.91.43
unknownUnited Kingdom
41231CANONICAL-ASGBfalse
91.189.91.42
unknownUnited Kingdom
41231CANONICAL-ASGBfalse
MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
109.202.202.202dQV40zAvGT.elfGet hashmaliciousGafgyt, MiraiBrowse
    YgpPblX7Ct.elfGet hashmaliciousGafgyt, MiraiBrowse
      epLN92K8RM.elfGet hashmaliciousMiraiBrowse
        LJTtnwewUQ.elfGet hashmaliciousMiraiBrowse
          NvmCe2XrqN.elfGet hashmaliciousMiraiBrowse
            FwLad7Fxwv.elfGet hashmaliciousMiraiBrowse
              aNeRrtorRm.elfGet hashmaliciousMiraiBrowse
                8BNqPPgBFn.elfGet hashmaliciousMiraiBrowse
                  yVsyTd2tDQ.elfGet hashmaliciousMiraiBrowse
                    nD1z4HgXaM.elfGet hashmaliciousGafgyt, MiraiBrowse
                      91.189.91.43YgpPblX7Ct.elfGet hashmaliciousGafgyt, MiraiBrowse
                        epLN92K8RM.elfGet hashmaliciousMiraiBrowse
                          LJTtnwewUQ.elfGet hashmaliciousMiraiBrowse
                            NvmCe2XrqN.elfGet hashmaliciousMiraiBrowse
                              FwLad7Fxwv.elfGet hashmaliciousMiraiBrowse
                                aNeRrtorRm.elfGet hashmaliciousMiraiBrowse
                                  8BNqPPgBFn.elfGet hashmaliciousMiraiBrowse
                                    yVsyTd2tDQ.elfGet hashmaliciousMiraiBrowse
                                      nD1z4HgXaM.elfGet hashmaliciousGafgyt, MiraiBrowse
                                        wUxE90cdjt.elfGet hashmaliciousGafgyt, MiraiBrowse
                                          91.189.91.42dQV40zAvGT.elfGet hashmaliciousGafgyt, MiraiBrowse
                                            YgpPblX7Ct.elfGet hashmaliciousGafgyt, MiraiBrowse
                                              epLN92K8RM.elfGet hashmaliciousMiraiBrowse
                                                LJTtnwewUQ.elfGet hashmaliciousMiraiBrowse
                                                  NvmCe2XrqN.elfGet hashmaliciousMiraiBrowse
                                                    FwLad7Fxwv.elfGet hashmaliciousMiraiBrowse
                                                      aNeRrtorRm.elfGet hashmaliciousMiraiBrowse
                                                        8BNqPPgBFn.elfGet hashmaliciousMiraiBrowse
                                                          yVsyTd2tDQ.elfGet hashmaliciousMiraiBrowse
                                                            nD1z4HgXaM.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                              No context
                                                              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                              CANONICAL-ASGBdQV40zAvGT.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                              • 91.189.91.42
                                                              YgpPblX7Ct.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                              • 91.189.91.42
                                                              epLN92K8RM.elfGet hashmaliciousMiraiBrowse
                                                              • 91.189.91.42
                                                              LJTtnwewUQ.elfGet hashmaliciousMiraiBrowse
                                                              • 91.189.91.42
                                                              NvmCe2XrqN.elfGet hashmaliciousMiraiBrowse
                                                              • 91.189.91.42
                                                              AkV7DALWTe.elfGet hashmaliciousMiraiBrowse
                                                              • 185.125.190.26
                                                              FwLad7Fxwv.elfGet hashmaliciousMiraiBrowse
                                                              • 91.189.91.42
                                                              n3l6rOHrCy.elfGet hashmaliciousMiraiBrowse
                                                              • 185.125.190.26
                                                              aNeRrtorRm.elfGet hashmaliciousMiraiBrowse
                                                              • 91.189.91.42
                                                              8BNqPPgBFn.elfGet hashmaliciousMiraiBrowse
                                                              • 91.189.91.42
                                                              CANONICAL-ASGBdQV40zAvGT.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                              • 91.189.91.42
                                                              YgpPblX7Ct.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                              • 91.189.91.42
                                                              epLN92K8RM.elfGet hashmaliciousMiraiBrowse
                                                              • 91.189.91.42
                                                              LJTtnwewUQ.elfGet hashmaliciousMiraiBrowse
                                                              • 91.189.91.42
                                                              NvmCe2XrqN.elfGet hashmaliciousMiraiBrowse
                                                              • 91.189.91.42
                                                              AkV7DALWTe.elfGet hashmaliciousMiraiBrowse
                                                              • 185.125.190.26
                                                              FwLad7Fxwv.elfGet hashmaliciousMiraiBrowse
                                                              • 91.189.91.42
                                                              n3l6rOHrCy.elfGet hashmaliciousMiraiBrowse
                                                              • 185.125.190.26
                                                              aNeRrtorRm.elfGet hashmaliciousMiraiBrowse
                                                              • 91.189.91.42
                                                              8BNqPPgBFn.elfGet hashmaliciousMiraiBrowse
                                                              • 91.189.91.42
                                                              INIT7CHdQV40zAvGT.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                              • 109.202.202.202
                                                              YgpPblX7Ct.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                              • 109.202.202.202
                                                              epLN92K8RM.elfGet hashmaliciousMiraiBrowse
                                                              • 109.202.202.202
                                                              LJTtnwewUQ.elfGet hashmaliciousMiraiBrowse
                                                              • 109.202.202.202
                                                              NvmCe2XrqN.elfGet hashmaliciousMiraiBrowse
                                                              • 109.202.202.202
                                                              FwLad7Fxwv.elfGet hashmaliciousMiraiBrowse
                                                              • 109.202.202.202
                                                              aNeRrtorRm.elfGet hashmaliciousMiraiBrowse
                                                              • 109.202.202.202
                                                              8BNqPPgBFn.elfGet hashmaliciousMiraiBrowse
                                                              • 109.202.202.202
                                                              yVsyTd2tDQ.elfGet hashmaliciousMiraiBrowse
                                                              • 109.202.202.202
                                                              nD1z4HgXaM.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                              • 109.202.202.202
                                                              No context
                                                              No context
                                                              No created / dropped files found
                                                              File type:ELF 32-bit LSB executable, ARM, version 1 (ARM), dynamically linked, interpreter /lib/ld-uClibc.so.0, not stripped
                                                              Entropy (8bit):4.383021780003098
                                                              TrID:
                                                              • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                                              File name:skid.arm.elf
                                                              File size:5'677 bytes
                                                              MD5:e7b4850c359b3f0f0533ee006d8f94db
                                                              SHA1:bfd586e31122c1502f02db0161bc849490c39737
                                                              SHA256:9a1e3e788306a30291cab8bf763b78f65ab8c9fc728145ad65cde2ccd0e0c103
                                                              SHA512:6d0afb5a18878726e1f8f954b52d25589a5c62b6a2ec619b4be0b8ee840035f268a346a5928b3a4b69960cdac16353ee9bd446149aa48863438d2b4f588b157e
                                                              SSDEEP:96:CAXuHBuYrTt/GRURVH/BZQ7zpkAveed0MSc:CSWBuUomVVy0MSc
                                                              TLSH:D0C1124A96D28D2BDCD1233D62DF4F6C7331E88666164727930C98A06E332D55E3374E
                                                              File Content Preview:.ELF...a..........(.....(...4...........4. ...(.........4...4...4...................................................................................................................................................Q.td............................/lib/ld-uCl

                                                              ELF header

                                                              Class:ELF32
                                                              Data:2's complement, little endian
                                                              Version:1 (current)
                                                              Machine:ARM
                                                              Version Number:0x1
                                                              Type:EXEC (Executable file)
                                                              OS/ABI:ARM - ABI
                                                              ABI Version:0
                                                              Entry Point Address:0x8528
                                                              Flags:0x202
                                                              ELF Header Size:52
                                                              Program Header Offset:52
                                                              Program Header Size:32
                                                              Number of Program Headers:6
                                                              Section Header Offset:2324
                                                              Section Header Size:40
                                                              Number of Section Headers:23
                                                              Header String Table Index:20
                                                              NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                              NULL0x00x00x00x00x0000
                                                              .interpPROGBITS0x80f40xf40x140x00x2A001
                                                              .hashHASH0x81080x1080x980x40x2A304
                                                              .dynsymDYNSYM0x81a00x1a00x1300x100x2A414
                                                              .dynstrSTRTAB0x82d00x2d00x980x00x2A001
                                                              .rel.pltREL0x83680x3680x480x80x2A374
                                                              .initPROGBITS0x83b00x3b00x180x00x6AX004
                                                              .pltPROGBITS0x83c80x3c80x800x40x6AX004
                                                              .textPROGBITS0x84480x4480x2600x00x6AX004
                                                              .finiPROGBITS0x86a80x6a80x140x00x6AX004
                                                              .rodataPROGBITS0x86bc0x6bc0x200x00x2A004
                                                              .eh_framePROGBITS0x86dc0x6dc0x40x00x2A004
                                                              .ctorsPROGBITS0x106e00x6e00x80x00x3WA004
                                                              .dtorsPROGBITS0x106e80x6e80x80x00x3WA004
                                                              .jcrPROGBITS0x106f00x6f00x40x00x3WA004
                                                              .dynamicDYNAMIC0x106f40x6f40x980x80x3WA404
                                                              .gotPROGBITS0x1078c0x78c0x300x40x3WA004
                                                              .dataPROGBITS0x107bc0x7bc0x140x00x3WA004
                                                              .bssNOBITS0x107d00x7d00x1c0x00x3WA004
                                                              .commentPROGBITS0x00x7d00xa60x00x0001
                                                              .shstrtabSTRTAB0x00x8760x9b0x00x0001
                                                              .symtabSYMTAB0x00xcac0x6a00x100x022794
                                                              .strtabSTRTAB0x00x134c0x2e10x00x0001
                                                              TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                              PHDR0x340x80340x80340xc00xc02.13270x5R E0x4
                                                              INTERP0xf40x80f40x80f40x140x143.68420x4R 0x1/lib/ld-uClibc.so.0.interp
                                                              LOAD0x00x80000x80000x6e00x6e05.01250x5R E0x8000.interp .hash .dynsym .dynstr .rel.plt .init .plt .text .fini .rodata .eh_frame
                                                              LOAD0x6e00x106e00x106e00xf00x10c2.01980x6RW 0x8000.ctors .dtors .jcr .dynamic .got .data .bss
                                                              DYNAMIC0x6f40x106f40x106f40x980x981.79240x6RW 0x4.dynamic
                                                              GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
                                                              TypeMetaValueTag
                                                              DT_NEEDEDsharedliblibc.so.00x1
                                                              DT_INITvalue0x83b00xc
                                                              DT_FINIvalue0x86a80xd
                                                              DT_HASHvalue0x81080x4
                                                              DT_STRTABvalue0x82d00x5
                                                              DT_SYMTABvalue0x81a00x6
                                                              DT_STRSZbytes1520xa
                                                              DT_SYMENTbytes160xb
                                                              DT_DEBUGvalue0x00x15
                                                              DT_PLTGOTvalue0x1078c0x3
                                                              DT_PLTRELSZbytes720x2
                                                              DT_PLTRELpltrelDT_REL0x14
                                                              DT_JMPRELvalue0x83680x17
                                                              DT_NULLvalue0x00x0
                                                              NameVersion Info NameVersion Info File NameSection NameValueSizeSymbol TypeSymbol BindSymbol VisibilityNdx
                                                              .dynsym0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                                              __bss_end__.dynsym0x107ec0NOTYPE<unknown>DEFAULTSHN_ABS
                                                              __bss_start.dynsym0x107d00NOTYPE<unknown>DEFAULTSHN_ABS
                                                              __bss_start__.dynsym0x107d00NOTYPE<unknown>DEFAULTSHN_ABS
                                                              __data_start.dynsym0x107bc0NOTYPE<unknown>DEFAULT17
                                                              __end__.dynsym0x107ec0NOTYPE<unknown>DEFAULTSHN_ABS
                                                              __uClibc_main.dynsym0x8430488FUNC<unknown>DEFAULTSHN_UNDEF
                                                              _bss_end__.dynsym0x107ec0NOTYPE<unknown>DEFAULTSHN_ABS
                                                              _edata.dynsym0x107d00NOTYPE<unknown>DEFAULTSHN_ABS
                                                              _end.dynsym0x107ec0NOTYPE<unknown>DEFAULTSHN_ABS
                                                              _start.dynsym0x852880FUNC<unknown>DEFAULT8
                                                              abort.dynsym0x8418352FUNC<unknown>DEFAULTSHN_UNDEF
                                                              connect.dynsym0x83dc44FUNC<unknown>DEFAULTSHN_UNDEF
                                                              dup2.dynsym0x840044FUNC<unknown>DEFAULTSHN_UNDEF
                                                              execve.dynsym0x83f444FUNC<unknown>DEFAULTSHN_UNDEF
                                                              htons.dynsym0x843c20FUNC<unknown>DEFAULTSHN_UNDEF
                                                              inet_addr.dynsym0x842436FUNC<unknown>DEFAULTSHN_UNDEF
                                                              socket.dynsym0x840c44FUNC<unknown>DEFAULTSHN_UNDEF
                                                              usleep.dynsym0x83e876FUNC<unknown>DEFAULTSHN_UNDEF
                                                              .symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                                              .symtab0x80f40SECTION<unknown>DEFAULT1
                                                              .symtab0x81080SECTION<unknown>DEFAULT2
                                                              .symtab0x81a00SECTION<unknown>DEFAULT3
                                                              .symtab0x82d00SECTION<unknown>DEFAULT4
                                                              .symtab0x83680SECTION<unknown>DEFAULT5
                                                              .symtab0x83b00SECTION<unknown>DEFAULT6
                                                              .symtab0x83c80SECTION<unknown>DEFAULT7
                                                              .symtab0x84480SECTION<unknown>DEFAULT8
                                                              .symtab0x86a80SECTION<unknown>DEFAULT9
                                                              .symtab0x86bc0SECTION<unknown>DEFAULT10
                                                              .symtab0x86dc0SECTION<unknown>DEFAULT11
                                                              .symtab0x106e00SECTION<unknown>DEFAULT12
                                                              .symtab0x106e80SECTION<unknown>DEFAULT13
                                                              .symtab0x106f00SECTION<unknown>DEFAULT14
                                                              .symtab0x106f40SECTION<unknown>DEFAULT15
                                                              .symtab0x1078c0SECTION<unknown>DEFAULT16
                                                              .symtab0x107bc0SECTION<unknown>DEFAULT17
                                                              .symtab0x107d00SECTION<unknown>DEFAULT18
                                                              .symtab0x00SECTION<unknown>DEFAULT19
                                                              .symtab0x00SECTION<unknown>DEFAULT20
                                                              .symtab0x00SECTION<unknown>DEFAULT21
                                                              .symtab0x00SECTION<unknown>DEFAULT22
                                                              $a.symtab0x83b00NOTYPE<unknown>DEFAULT6
                                                              $a.symtab0x86a80NOTYPE<unknown>DEFAULT9
                                                              $a.symtab0x84480NOTYPE<unknown>DEFAULT8
                                                              $a.symtab0x84c00NOTYPE<unknown>DEFAULT8
                                                              $a.symtab0x86b40NOTYPE<unknown>DEFAULT9
                                                              $a.symtab0x85200NOTYPE<unknown>DEFAULT8
                                                              $a.symtab0x83bc0NOTYPE<unknown>DEFAULT6
                                                              $a.symtab0x866c0NOTYPE<unknown>DEFAULT8
                                                              $a.symtab0x86a00NOTYPE<unknown>DEFAULT8
                                                              $a.symtab0x83c00NOTYPE<unknown>DEFAULT6
                                                              $a.symtab0x83c40NOTYPE<unknown>DEFAULT6
                                                              $a.symtab0x86b80NOTYPE<unknown>DEFAULT9
                                                              $a.symtab0x85280NOTYPE<unknown>DEFAULT8
                                                              $a.symtab0x85640NOTYPE<unknown>DEFAULT8
                                                              $a.symtab0x864c0NOTYPE<unknown>DEFAULT8
                                                              $d.symtab0x106e00NOTYPE<unknown>DEFAULT12
                                                              $d.symtab0x106e80NOTYPE<unknown>DEFAULT13
                                                              $d.symtab0x107c40NOTYPE<unknown>DEFAULT17
                                                              $d.symtab0x84b00NOTYPE<unknown>DEFAULT8
                                                              $d.symtab0x850c0NOTYPE<unknown>DEFAULT8
                                                              $d.symtab0x869c0NOTYPE<unknown>DEFAULT8
                                                              $d.symtab0x107c80NOTYPE<unknown>DEFAULT17
                                                              $d.symtab0x85580NOTYPE<unknown>DEFAULT8
                                                              $d.symtab0x86c40NOTYPE<unknown>DEFAULT10
                                                              $d.symtab0x86400NOTYPE<unknown>DEFAULT8
                                                              C.1.3111.symtab0x86c48OBJECT<unknown>DEFAULT10
                                                              _DYNAMIC.symtab0x106f40OBJECT<unknown>HIDDEN15
                                                              _GLOBAL_OFFSET_TABLE_.symtab0x1078c0OBJECT<unknown>HIDDEN16
                                                              _Jv_RegisterClasses.symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                                              __CTOR_END__.symtab0x106e40OBJECT<unknown>DEFAULT12
                                                              __CTOR_LIST__.symtab0x106e00OBJECT<unknown>DEFAULT12
                                                              __DTOR_END__.symtab0x106ec0OBJECT<unknown>DEFAULT13
                                                              __DTOR_LIST__.symtab0x106e80OBJECT<unknown>DEFAULT13
                                                              __EH_FRAME_BEGIN__.symtab0x86dc0OBJECT<unknown>DEFAULT11
                                                              __FRAME_END__.symtab0x86dc0OBJECT<unknown>DEFAULT11
                                                              __JCR_END__.symtab0x106f00OBJECT<unknown>DEFAULT14
                                                              __JCR_LIST__.symtab0x106f00OBJECT<unknown>DEFAULT14
                                                              __bss_end__.symtab0x107ec0NOTYPE<unknown>DEFAULTSHN_ABS
                                                              __bss_start.symtab0x107d00NOTYPE<unknown>DEFAULTSHN_ABS
                                                              __bss_start__.symtab0x107d00NOTYPE<unknown>DEFAULTSHN_ABS
                                                              __data_start.symtab0x107bc0NOTYPE<unknown>DEFAULT17
                                                              __deregister_frame_info.symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                                              __do_global_ctors_aux.symtab0x866c0FUNC<unknown>DEFAULT8
                                                              __do_global_dtors_aux.symtab0x84480FUNC<unknown>DEFAULT8
                                                              __dso_handle.symtab0x107c00OBJECT<unknown>HIDDEN17
                                                              __end__.symtab0x107ec0NOTYPE<unknown>DEFAULTSHN_ABS
                                                              __register_frame_info.symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                                              __uClibc_main.symtab0x8430488FUNC<unknown>DEFAULTSHN_UNDEF
                                                              _bss_end__.symtab0x107ec0NOTYPE<unknown>DEFAULTSHN_ABS
                                                              _edata.symtab0x107d00NOTYPE<unknown>DEFAULTSHN_ABS
                                                              _end.symtab0x107ec0NOTYPE<unknown>DEFAULTSHN_ABS
                                                              _fini.symtab0x86a84FUNC<unknown>DEFAULT9
                                                              _init.symtab0x83b04FUNC<unknown>DEFAULT6
                                                              _start.symtab0x852880FUNC<unknown>DEFAULT8
                                                              abort.symtab0x8418352FUNC<unknown>DEFAULTSHN_UNDEF
                                                              call___do_global_ctors_aux.symtab0x86a00FUNC<unknown>DEFAULT8
                                                              call___do_global_dtors_aux.symtab0x84c00FUNC<unknown>DEFAULT8
                                                              call_frame_dummy.symtab0x85200FUNC<unknown>DEFAULT8
                                                              completed.2555.symtab0x107d01OBJECT<unknown>DEFAULT18
                                                              connect.symtab0x83dc44FUNC<unknown>DEFAULTSHN_UNDEF
                                                              crtstuff.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              crtstuff.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              data_start.symtab0x107c80NOTYPE<unknown>DEFAULT17
                                                              dup2.symtab0x840044FUNC<unknown>DEFAULTSHN_UNDEF
                                                              execve.symtab0x83f444FUNC<unknown>DEFAULTSHN_UNDEF
                                                              force_to_data.symtab0x107bc0OBJECT<unknown>DEFAULT17
                                                              force_to_data.symtab0x107cc0OBJECT<unknown>DEFAULT17
                                                              frame_dummy.symtab0x84c80FUNC<unknown>DEFAULT8
                                                              htons.symtab0x843c20FUNC<unknown>DEFAULTSHN_UNDEF
                                                              inet_addr.symtab0x842436FUNC<unknown>DEFAULTSHN_UNDEF
                                                              initfini.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              initfini.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              libc/sysdeps/linux/arm/crt1.S.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              libc/sysdeps/linux/arm/crti.S.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              libc/sysdeps/linux/arm/crtn.S.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              main.symtab0x864c32FUNC<unknown>DEFAULT8
                                                              main.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              object.2636.symtab0x107d424OBJECT<unknown>DEFAULT18
                                                              p.2553.symtab0x107c40OBJECT<unknown>DEFAULT17
                                                              rev_shell.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                              shell.symtab0x8564232FUNC<unknown>DEFAULT8
                                                              socket.symtab0x840c44FUNC<unknown>DEFAULTSHN_UNDEF
                                                              usleep.symtab0x83e876FUNC<unknown>DEFAULTSHN_UNDEF
                                                              TimestampSource PortDest PortSource IPDest IP
                                                              Apr 18, 2024 03:51:52.246522903 CEST43928443192.168.2.2391.189.91.42
                                                              Apr 18, 2024 03:51:57.621834993 CEST42836443192.168.2.2391.189.91.43
                                                              Apr 18, 2024 03:51:58.389694929 CEST4251680192.168.2.23109.202.202.202
                                                              Apr 18, 2024 03:52:12.468211889 CEST43928443192.168.2.2391.189.91.42
                                                              Apr 18, 2024 03:52:24.754456043 CEST42836443192.168.2.2391.189.91.43
                                                              Apr 18, 2024 03:52:28.849968910 CEST4251680192.168.2.23109.202.202.202
                                                              Apr 18, 2024 03:52:53.422574043 CEST43928443192.168.2.2391.189.91.42

                                                              System Behavior

                                                              Start time (UTC):01:51:52
                                                              Start date (UTC):18/04/2024
                                                              Path:/tmp/skid.arm.elf
                                                              Arguments:/tmp/skid.arm.elf
                                                              File size:4956856 bytes
                                                              MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1