Analysis Report m8XMnec4Vb.elf
Overview
General Information |
---|
Joe Sandbox Version: | 28.0.0 Lapis Lazuli |
Analysis ID: | 185754 |
Start date: | 28.10.2019 |
Start time: | 17:41:19 |
Joe Sandbox Product: | CloudBasic |
Overall analysis duration: | 0h 10m 5s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Sample file name: | m8XMnec4Vb.elf |
Cookbook file name: | defaultlinuxfilecookbook.jbs |
Analysis system description: | Ubuntu Linux 16.04 x64 (Kernel 4.4.0-116, Firefox 59.0, Document Viewer 3.18.2, LibreOffice 5.1.6.2, OpenJDK 1.8.0_171) |
Detection: | MAL |
Classification: | mal48.evad.linELF@0/1@0/0 |
Warnings: | Show All
|
Detection |
---|
Strategy | Score | Range | Reporting | Whitelisted | Detection | |
---|---|---|---|---|---|---|
Threshold | 48 | 0 - 100 | false |
Classification |
---|
Mitre Att&ck Matrix |
---|
Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Exfiltration | Command and Control |
---|---|---|---|---|---|---|---|---|---|---|
Valid Accounts | Windows Remote Management | Winlogon Helper DLL | Port Monitors | File Deletion11 | Credential Dumping | System Service Discovery | Application Deployment Software | Data from Local System | Data Compressed | Data Obfuscation |
Signature Overview |
---|
Click to jump to signature section
System Summary: |
---|
Classification label | Show sources |
Source: | Classification label: |
Persistence and Installation Behavior: |
---|
Changes permissions of common UNIX (system) binary directories | Show sources |
Source: | Chmod directory: |
Executes the "chmod" command used to modify permissions | Show sources |
Source: | Chmod executable: |
Executes the "rm" command used to delete files or directories | Show sources |
Source: | Rm executable: | ||
Source: | Rm executable: |
Sample tries to set the executable flag | Show sources |
Source: | File: |
Writes ELF files to disk | Show sources |
Source: | File written: | Jump to dropped file |
Hooking and other Techniques for Hiding and Protection: |
---|
Sample deletes itself | Show sources |
Source: | File: | ||
Source: | File: |
Runtime Messages |
---|
Command: | /tmp/m8XMnec4Vb.elf |
Exit Code: | 0 |
Exit Code Info: | |
Killed: | False |
Standard Output: | |
Standard Error: |
Behavior Graph |
---|
Yara Overview |
---|
Sigma Overview |
---|
No Sigma rule has matched |
---|
Joe Sandbox View / Context |
---|
Antivirus, Machine Learning and Genetic Malware Detection |
---|
Initial Sample |
---|
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Virustotal | Browse |
Dropped Files |
---|
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Virustotal | Browse |
Domains |
---|
No Antivirus matches |
---|
URLs |
---|
No Antivirus matches |
---|
Startup |
---|
|
Created / dropped Files |
---|
Process: | /bin/cp |
File Type: | |
Size (bytes): | 28832 |
Entropy (8bit): | 4.890459011756629 |
Encrypted: | false |
MD5: | 0017F7B913CE66E4D80F7E78CF830A2B |
SHA1: | F1BF775746A5C882B9EC003617B2A70CF5A5B029 |
SHA-256: | FA0DEFDABD9FD43FE2EF1EC33574EA1AF1290BD3D763FDB2BED443F2BD996D73 |
SHA-512: | FF5DD28BA3F5CE1F85F85FA9B65F9F30FBD300F2CA238CB2713DA7077B7A0A8FF094CFF4D7DE9381726925ABDD9EA065FA75CCD02FA5A816B71A6F91479363C1 |
Malicious: | true |
Antivirus: |
|
Reputation: | low |
Preview: |
|
Domains and IPs |
---|
Static File Info |
---|
General | |
---|---|
File type: | |
Entropy (8bit): | 4.890459011756629 |
TrID: |
|
File name: | m8XMnec4Vb.elf |
File size: | 28832 |
MD5: | 0017f7b913ce66e4d80f7e78cf830a2b |
SHA1: | f1bf775746a5c882b9ec003617b2a70cf5a5b029 |
SHA256: | fa0defdabd9fd43fe2ef1ec33574ea1af1290bd3d763fdb2bed443f2bd996d73 |
SHA512: | ff5dd28ba3f5ce1f85f85fa9b65f9f30fbd300f2ca238cb2713da7077b7a0a8ff094cff4d7de9381726925abdd9ea065fa75ccd02fa5a816b71a6f91479363c1 |
SSDEEP: | 384:D4Vc7TIqaFxrfIyqk/MyV36nk/h0iFHCN7qvUa+BlmYJNZRR5uRh0I:D4gQAsMyOi0iFHCF3zZX5uRh0I |
File Content Preview: | .ELF..............>.....0.@.....@........S..........@.8...@.............@.......@.@.....@.@.....................................8.......8.@.....8.@...............................................@.......@......I.......I........ ..............N.......N`.... |
Static ELF Info |
---|
ELF header | |
---|---|
Class: | |
Data: | |
Version: | |
Machine: | |
Version Number: | |
Type: | |
OS/ABI: | |
ABI Version: | |
Entry Point Address: | |
Flags: | |
ELF Header Size: | |
Program Header Offset: | |
Program Header Size: | |
Number of Program Headers: | |
Section Header Offset: | |
Section Header Size: | |
Number of Section Headers: | |
Header String Table Index: |
Sections |
---|
Name | Type | Address | Offset | Size | EntSize | Flags | Flags Description | Link | Info | Align |
---|---|---|---|---|---|---|---|---|---|---|
NULL | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0 | 0 | 0 | ||
.interp | PROGBITS | 0x400238 | 0x238 | 0x1c | 0x0 | 0x2 | A | 0 | 0 | 1 |
.note.ABI-tag | NOTE | 0x400254 | 0x254 | 0x20 | 0x0 | 0x2 | A | 0 | 0 | 4 |
.note.gnu.build-id | NOTE | 0x400274 | 0x274 | 0x24 | 0x0 | 0x2 | A | 0 | 0 | 4 |
.gnu.hash | GNU_HASH | 0x400298 | 0x298 | 0x30 | 0x0 | 0x2 | A | 5 | 0 | 8 |
.dynsym | DYNSYM | 0x4002c8 | 0x2c8 | 0x5b8 | 0x18 | 0x2 | A | 6 | 1 | 8 |
.dynstr | STRTAB | 0x400880 | 0x880 | 0x1be | 0x0 | 0x2 | A | 0 | 0 | 1 |
.gnu.version | VERSYM | 0x400a3e | 0xa3e | 0x7a | 0x2 | 0x2 | A | 5 | 0 | 2 |
.gnu.version_r | VERNEED | 0x400ab8 | 0xab8 | 0x30 | 0x0 | 0x2 | A | 6 | 1 | 8 |
.rela.dyn | RELA | 0x400ae8 | 0xae8 | 0x30 | 0x18 | 0x2 | A | 5 | 0 | 8 |
.rela.plt | RELA | 0x400b18 | 0xb18 | 0x558 | 0x18 | 0x2 | A | 5 | 12 | 8 |
.init | PROGBITS | 0x401070 | 0x1070 | 0x1a | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.plt | PROGBITS | 0x401090 | 0x1090 | 0x3a0 | 0x10 | 0x6 | AX | 0 | 0 | 16 |
.text | PROGBITS | 0x401430 | 0x1430 | 0x2d5c | 0x0 | 0x6 | AX | 0 | 0 | 16 |
.fini | PROGBITS | 0x40418c | 0x418c | 0x9 | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.rodata | PROGBITS | 0x4041a0 | 0x41a0 | 0x268 | 0x0 | 0x2 | A | 0 | 0 | 32 |
.eh_frame_hdr | PROGBITS | 0x404408 | 0x4408 | 0xfc | 0x0 | 0x2 | A | 0 | 0 | 4 |
.eh_frame | PROGBITS | 0x404508 | 0x4508 | 0x40c | 0x0 | 0x2 | A | 0 | 0 | 8 |
.init_array | INIT_ARRAY | 0x604e10 | 0x4e10 | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 8 |
.fini_array | FINI_ARRAY | 0x604e18 | 0x4e18 | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 8 |
.jcr | PROGBITS | 0x604e20 | 0x4e20 | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 8 |
.dynamic | DYNAMIC | 0x604e28 | 0x4e28 | 0x1d0 | 0x10 | 0x3 | WA | 6 | 0 | 8 |
.got | PROGBITS | 0x604ff8 | 0x4ff8 | 0x8 | 0x8 | 0x3 | WA | 0 | 0 | 8 |
.got.plt | PROGBITS | 0x605000 | 0x5000 | 0x1e0 | 0x8 | 0x3 | WA | 0 | 0 | 8 |
.data | PROGBITS | 0x6051e0 | 0x51e0 | 0x4 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.bss | NOBITS | 0x605200 | 0x51e4 | 0x4f8 | 0x0 | 0x3 | WA | 0 | 0 | 32 |
.comment | PROGBITS | 0x0 | 0x51e4 | 0x2c | 0x1 | 0x30 | MS | 0 | 0 | 1 |
.shstrtab | STRTAB | 0x0 | 0x5210 | 0x108 | 0x0 | 0x0 | 0 | 0 | 1 | |
.symtab | SYMTAB | 0x0 | 0x5a98 | 0xe70 | 0x18 | 0x0 | 29 | 50 | 8 | |
.strtab | STRTAB | 0x0 | 0x6908 | 0x798 | 0x0 | 0x0 | 0 | 0 | 1 |
Program Segments |
---|
Type | Offset | Virtual Address | Physical Address | File Size | Memory Size | Flags | Flags Description | Align | Prog Interpreter | Section Mappings |
---|---|---|---|---|---|---|---|---|---|---|
PHDR | 0x40 | 0x400040 | 0x400040 | 0x1f8 | 0x1f8 | 0x5 | R E | 0x8 | ||
INTERP | 0x238 | 0x400238 | 0x400238 | 0x1c | 0x1c | 0x4 | R | 0x1 | /lib64/ld-linux-x86-64.so.2 | .interp |
LOAD | 0x0 | 0x400000 | 0x400000 | 0x4914 | 0x4914 | 0x5 | R E | 0x200000 | .interp .note.ABI-tag .note.gnu.build-id .gnu.hash .dynsym .dynstr .gnu.version .gnu.version_r .rela.dyn .rela.plt .init .plt .text .fini .rodata .eh_frame_hdr .eh_frame | |
LOAD | 0x4e10 | 0x604e10 | 0x604e10 | 0x3d4 | 0x8e8 | 0x6 | RW | 0x200000 | .init_array .fini_array .jcr .dynamic .got .got.plt .data .bss | |
DYNAMIC | 0x4e28 | 0x604e28 | 0x604e28 | 0x1d0 | 0x1d0 | 0x6 | RW | 0x8 | .dynamic | |
NOTE | 0x254 | 0x400254 | 0x400254 | 0x44 | 0x44 | 0x4 | R | 0x4 | .note.ABI-tag .note.gnu.build-id | |
GNU_EH_FRAME | 0x4408 | 0x404408 | 0x404408 | 0xfc | 0xfc | 0x4 | R | 0x4 | .eh_frame_hdr | |
GNU_STACK | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0x6 | RW | 0x10 | ||
GNU_RELRO | 0x4e10 | 0x604e10 | 0x604e10 | 0x1f0 | 0x1f0 | 0x4 | R | 0x1 | .init_array .fini_array .jcr .dynamic .got |
Dynamic Tags |
---|
Type | Meta | Value | Tag |
---|---|---|---|
DT_NEEDED | sharedlib | libc.so.6 | 0x1 |
DT_INIT | value | 0x401070 | 0xc |
DT_FINI | value | 0x40418c | 0xd |
DT_INIT_ARRAY | value | 0x604e10 | 0x19 |
DT_INIT_ARRAYSZ | bytes | 8 | 0x1b |
DT_FINI_ARRAY | value | 0x604e18 | 0x1a |
DT_FINI_ARRAYSZ | bytes | 8 | 0x1c |
DT_GNU_HASH | value | 0x400298 | 0x6ffffef5 |
DT_STRTAB | value | 0x400880 | 0x5 |
DT_SYMTAB | value | 0x4002c8 | 0x6 |
DT_STRSZ | bytes | 446 | 0xa |
DT_SYMENT | bytes | 24 | 0xb |
DT_DEBUG | value | 0x0 | 0x15 |
DT_PLTGOT | value | 0x605000 | 0x3 |
DT_PLTRELSZ | bytes | 1368 | 0x2 |
DT_PLTREL | pltrel | DT_RELA | 0x14 |
DT_JMPREL | value | 0x400b18 | 0x17 |
DT_RELA | value | 0x400ae8 | 0x7 |
DT_RELASZ | bytes | 48 | 0x8 |
DT_RELAENT | bytes | 24 | 0x9 |
DT_VERNEED | value | 0x400ab8 | 0x6ffffffe |
DT_VERNEEDNUM | value | 1 | 0x6fffffff |
DT_VERSYM | value | 0x400a3e | 0x6ffffff0 |
DT_NULL | value | 0x0 | 0x0 |
Symbols |
---|
Name | Version Info Name | Version Info File Name | Section Name | Value | Size | Symbol Type | Symbol Bind | Symbol Visibility | Ndx |
---|---|---|---|---|---|---|---|---|---|
.dynsym | 0x0 | 0 | NOTYPE | <unknown> | DEFAULT | SHN_UNDEF | |||
__cxa_atexit | GLIBC_2.2.5 | libc.so.6 | .dynsym | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF |
__environ | GLIBC_2.2.5 | libc.so.6 | .dynsym | 0x605200 | 8 | OBJECT | <unknown> | DEFAULT | 25 |
__gmon_start__ | .dynsym | 0x0 | 0 | NOTYPE | <unknown> | DEFAULT | SHN_UNDEF | ||
__libc_start_main | GLIBC_2.2.5 | libc.so.6 | .dynsym | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF |
_environ | GLIBC_2.2.5 | libc.so.6 | .dynsym | 0x605200 | 8 | OBJECT | <unknown> | DEFAULT | 25 |
_exit | GLIBC_2.2.5 | libc.so.6 | .dynsym | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF |
accept | GLIBC_2.2.5 | libc.so.6 | .dynsym | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF |
access | GLIBC_2.2.5 | libc.so.6 | .dynsym | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF |
bind | GLIBC_2.2.5 | libc.so.6 | .dynsym | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF |
bzero | GLIBC_2.2.5 | libc.so.6 | .dynsym | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF |
chdir | GLIBC_2.2.5 | libc.so.6 | .dynsym | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF |
close | GLIBC_2.2.5 | libc.so.6 | .dynsym | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF |
connect | GLIBC_2.2.5 | libc.so.6 | .dynsym | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF |
daemon | GLIBC_2.2.5 | libc.so.6 | .dynsym | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF |
dup2 | GLIBC_2.2.5 | libc.so.6 | .dynsym | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF |
environ | GLIBC_2.2.5 | libc.so.6 | .dynsym | 0x605200 | 8 | OBJECT | <unknown> | DEFAULT | 25 |
execve | GLIBC_2.2.5 | libc.so.6 | .dynsym | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF |
exit | GLIBC_2.2.5 | libc.so.6 | .dynsym | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF |
fork | GLIBC_2.2.5 | libc.so.6 | .dynsym | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF |
free | GLIBC_2.2.5 | libc.so.6 | .dynsym | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF |
getpid | GLIBC_2.2.5 | libc.so.6 | .dynsym | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF |
getuid | GLIBC_2.2.5 | libc.so.6 | .dynsym | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF |
grantpt | GLIBC_2.2.5 | libc.so.6 | .dynsym | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF |
htons | GLIBC_2.2.5 | libc.so.6 | .dynsym | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF |
inet_ntoa | GLIBC_2.2.5 | libc.so.6 | .dynsym | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF |
ioctl | GLIBC_2.2.5 | libc.so.6 | .dynsym | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF |
kill | GLIBC_2.2.5 | libc.so.6 | .dynsym | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF |
listen | GLIBC_2.2.5 | libc.so.6 | .dynsym | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF |
malloc | GLIBC_2.2.5 | libc.so.6 | .dynsym | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF |
memchr | GLIBC_2.2.5 | libc.so.6 | .dynsym | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF |
memcmp | GLIBC_2.2.5 | libc.so.6 | .dynsym | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF |
memcpy | GLIBC_2.14 | libc.so.6 | .dynsym | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF |
memset | GLIBC_2.2.5 | libc.so.6 | .dynsym | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF |
ntohs | GLIBC_2.2.5 | libc.so.6 | .dynsym | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF |
open | GLIBC_2.2.5 | libc.so.6 | .dynsym | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF |
prctl | GLIBC_2.2.5 | libc.so.6 | .dynsym | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF |
ptsname | GLIBC_2.2.5 | libc.so.6 | .dynsym | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF |
rand | GLIBC_2.2.5 | libc.so.6 | .dynsym | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF |
read | GLIBC_2.2.5 | libc.so.6 | .dynsym | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF |
recvfrom | GLIBC_2.2.5 | libc.so.6 | .dynsym | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF |
select | GLIBC_2.2.5 | libc.so.6 | .dynsym | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF |
sendto | GLIBC_2.2.5 | libc.so.6 | .dynsym | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF |
setsid | GLIBC_2.2.5 | libc.so.6 | .dynsym | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF |
setsockopt | GLIBC_2.2.5 | libc.so.6 | .dynsym | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF |
signal | GLIBC_2.2.5 | libc.so.6 | .dynsym | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF |
sleep | GLIBC_2.2.5 | libc.so.6 | .dynsym | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF |
snprintf | GLIBC_2.2.5 | libc.so.6 | .dynsym | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF |
socket | GLIBC_2.2.5 | libc.so.6 | .dynsym | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF |
srand | GLIBC_2.2.5 | libc.so.6 | .dynsym | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF |
strcpy | GLIBC_2.2.5 | libc.so.6 | .dynsym | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF |
strlen | GLIBC_2.2.5 | libc.so.6 | .dynsym | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF |
strncpy | GLIBC_2.2.5 | libc.so.6 | .dynsym | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF |
system | GLIBC_2.2.5 | libc.so.6 | .dynsym | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF |
time | GLIBC_2.2.5 | libc.so.6 | .dynsym | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF |
unlink | GLIBC_2.2.5 | libc.so.6 | .dynsym | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF |
unlockpt | GLIBC_2.2.5 | libc.so.6 | .dynsym | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF |
utimes | GLIBC_2.2.5 | libc.so.6 | .dynsym | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF |
vhangup | GLIBC_2.2.5 | libc.so.6 | .dynsym | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF |
waitpid | GLIBC_2.2.5 | libc.so.6 | .dynsym | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF |
write | GLIBC_2.2.5 | libc.so.6 | .dynsym | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF |
.symtab | 0x0 | 0 | NOTYPE | <unknown> | DEFAULT | SHN_UNDEF | |||
GLIBC_2.2.5 | libc.so.6 | .symtab | 0x400238 | 0 | SECTION | <unknown> | DEFAULT | 1 | |
GLIBC_2.2.5 | libc.so.6 | .symtab | 0x400254 | 0 | SECTION | <unknown> | DEFAULT | 2 | |
GLIBC_2.2.5 | libc.so.6 | .symtab | 0x400274 | 0 | SECTION | <unknown> | DEFAULT | 3 | |
GLIBC_2.2.5 | libc.so.6 | .symtab | 0x400298 | 0 | SECTION | <unknown> | DEFAULT | 4 | |
GLIBC_2.2.5 | libc.so.6 | .symtab | 0x4002c8 | 0 | SECTION | <unknown> | DEFAULT | 5 | |
GLIBC_2.2.5 | libc.so.6 | .symtab | 0x400880 | 0 | SECTION | <unknown> | DEFAULT | 6 | |
GLIBC_2.2.5 | libc.so.6 | .symtab | 0x400a3e | 0 | SECTION | <unknown> | DEFAULT | 7 | |
GLIBC_2.2.5 | libc.so.6 | .symtab | 0x400ab8 | 0 | SECTION | <unknown> | DEFAULT | 8 | |
GLIBC_2.2.5 | libc.so.6 | .symtab | 0x400ae8 | 0 | SECTION | <unknown> | DEFAULT | 9 | |
GLIBC_2.2.5 | libc.so.6 | .symtab | 0x400b18 | 0 | SECTION | <unknown> | DEFAULT | 10 | |
GLIBC_2.2.5 | libc.so.6 | .symtab | 0x401070 | 0 | SECTION | <unknown> | DEFAULT | 11 | |
GLIBC_2.2.5 | libc.so.6 | .symtab | 0x401090 | 0 | SECTION | <unknown> | DEFAULT | 12 | |
GLIBC_2.2.5 | libc.so.6 | .symtab | 0x401430 | 0 | SECTION | <unknown> | DEFAULT | 13 | |
GLIBC_2.2.5 | libc.so.6 | .symtab | 0x40418c | 0 | SECTION | <unknown> | DEFAULT | 14 | |
GLIBC_2.2.5 | libc.so.6 | .symtab | 0x4041a0 | 0 | SECTION | <unknown> | DEFAULT | 15 | |
GLIBC_2.2.5 | libc.so.6 | .symtab | 0x404408 | 0 | SECTION | <unknown> | DEFAULT | 16 | |
GLIBC_2.2.5 | libc.so.6 | .symtab | 0x404508 | 0 | SECTION | <unknown> | DEFAULT | 17 | |
GLIBC_2.2.5 | libc.so.6 | .symtab | 0x604e10 | 0 | SECTION | <unknown> | DEFAULT | 18 | |
GLIBC_2.2.5 | libc.so.6 | .symtab | 0x604e18 | 0 | SECTION | <unknown> | DEFAULT | 19 | |
GLIBC_2.2.5 | libc.so.6 | .symtab | 0x604e20 | 0 | SECTION | <unknown> | DEFAULT | 20 | |
GLIBC_2.2.5 | libc.so.6 | .symtab | 0x604e28 | 0 | SECTION | <unknown> | DEFAULT | 21 | |
GLIBC_2.2.5 | libc.so.6 | .symtab | 0x604ff8 | 0 | SECTION | <unknown> | DEFAULT | 22 | |
GLIBC_2.2.5 | libc.so.6 | .symtab | 0x605000 | 0 | SECTION | <unknown> | DEFAULT | 23 | |
GLIBC_2.2.5 | libc.so.6 | .symtab | 0x6051e0 | 0 | SECTION | <unknown> | DEFAULT | 24 | |
GLIBC_2.2.5 | libc.so.6 | .symtab | 0x605200 | 0 | SECTION | <unknown> | DEFAULT | 25 | |
GLIBC_2.2.5 | libc.so.6 | .symtab | 0x0 | 0 | SECTION | <unknown> | DEFAULT | 26 | |
GLIBC_2.2.5 | libc.so.6 | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS | |
_DYNAMIC | GLIBC_2.2.5 | libc.so.6 | .symtab | 0x604e28 | 0 | OBJECT | <unknown> | DEFAULT | 21 |
_GLOBAL_OFFSET_TABLE_ | GLIBC_2.2.5 | libc.so.6 | .symtab | 0x605000 | 0 | OBJECT | <unknown> | DEFAULT | 23 |
_IO_stdin_used | .symtab | 0x4041a0 | 4 | OBJECT | <unknown> | DEFAULT | 15 | ||
_ITM_deregisterTMCloneTable | GLIBC_2.2.5 | libc.so.6 | .symtab | 0x0 | 0 | NOTYPE | <unknown> | DEFAULT | SHN_UNDEF |
_ITM_registerTMCloneTable | .symtab | 0x0 | 0 | NOTYPE | <unknown> | DEFAULT | SHN_UNDEF | ||
_Jv_RegisterClasses | .symtab | 0x0 | 0 | NOTYPE | <unknown> | DEFAULT | SHN_UNDEF | ||
__FRAME_END__ | GLIBC_2.2.5 | libc.so.6 | .symtab | 0x404910 | 0 | OBJECT | <unknown> | DEFAULT | 17 |
__JCR_END__ | GLIBC_2.2.5 | libc.so.6 | .symtab | 0x604e20 | 0 | OBJECT | <unknown> | DEFAULT | 20 |
__JCR_LIST__ | GLIBC_2.2.5 | libc.so.6 | .symtab | 0x604e20 | 0 | OBJECT | <unknown> | DEFAULT | 20 |
__TMC_END__ | .symtab | 0x6051e8 | 0 | OBJECT | <unknown> | HIDDEN | 24 | ||
__bss_start | .symtab | 0x6051e4 | 0 | NOTYPE | <unknown> | DEFAULT | 25 | ||
__cxa_atexit@@GLIBC_2.2.5 | .symtab | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
__data_start | .symtab | 0x6051e0 | 0 | NOTYPE | <unknown> | DEFAULT | 24 | ||
__do_global_dtors_aux | GLIBC_2.2.5 | libc.so.6 | .symtab | 0x4014d0 | 0 | FUNC | <unknown> | DEFAULT | 13 |
__do_global_dtors_aux_fini_array_entry | GLIBC_2.14 | libc.so.6 | .symtab | 0x604e18 | 0 | OBJECT | <unknown> | DEFAULT | 19 |
__dso_handle | .symtab | 0x4041a8 | 0 | OBJECT | <unknown> | HIDDEN | 15 | ||
__environ@@GLIBC_2.2.5 | .symtab | 0x605200 | 8 | OBJECT | <unknown> | DEFAULT | 25 | ||
__frame_dummy_init_array_entry | GLIBC_2.2.5 | libc.so.6 | .symtab | 0x604e10 | 0 | OBJECT | <unknown> | DEFAULT | 18 |
__gmon_start__ | .symtab | 0x0 | 0 | NOTYPE | <unknown> | DEFAULT | SHN_UNDEF | ||
__init_array_end | GLIBC_2.2.5 | libc.so.6 | .symtab | 0x604e18 | 0 | NOTYPE | <unknown> | DEFAULT | 18 |
__init_array_start | GLIBC_2.2.5 | libc.so.6 | .symtab | 0x604e10 | 0 | NOTYPE | <unknown> | DEFAULT | 18 |
__libc_csu_fini | GLIBC_2.2.5 | libc.so.6 | .symtab | 0x404160 | 2 | FUNC | <unknown> | DEFAULT | 13 |
__libc_csu_init | .symtab | 0x4040f0 | 101 | FUNC | <unknown> | DEFAULT | 13 | ||
__libc_start_main@@GLIBC_2.2.5 | .symtab | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
_edata | .symtab | 0x6051e4 | 0 | NOTYPE | <unknown> | DEFAULT | 24 | ||
_end | .symtab | 0x6056f8 | 0 | NOTYPE | <unknown> | DEFAULT | 25 | ||
_exit@@GLIBC_2.2.5 | .symtab | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
_fini | .symtab | 0x40418c | 0 | FUNC | <unknown> | DEFAULT | 14 | ||
_init | .symtab | 0x401070 | 0 | FUNC | <unknown> | DEFAULT | 11 | ||
_start | .symtab | 0x401430 | 0 | FUNC | <unknown> | DEFAULT | 13 | ||
a.c | GLIBC_2.2.5 | libc.so.6 | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS |
accept@@GLIBC_2.2.5 | .symtab | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
access@@GLIBC_2.2.5 | .symtab | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
argv0 | .symtab | 0x605210 | 8 | OBJECT | <unknown> | DEFAULT | 25 | ||
atexit | .symtab | 0x404170 | 26 | FUNC | <unknown> | HIDDEN | 13 | ||
b | .symtab | 0x4027a1 | 222 | FUNC | <unknown> | DEFAULT | 13 | ||
bind@@GLIBC_2.2.5 | .symtab | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
bzero@@GLIBC_2.2.5 | .symtab | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
cfg | .symtab | 0x605360 | 548 | OBJECT | <unknown> | DEFAULT | 25 | ||
chdir@@GLIBC_2.2.5 | .symtab | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
close@@GLIBC_2.2.5 | .symtab | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
completed.6342 | .symtab | 0x605208 | 1 | OBJECT | <unknown> | DEFAULT | 25 | ||
connect@@GLIBC_2.2.5 | .symtab | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
cread | .symtab | 0x4017ba | 90 | FUNC | <unknown> | DEFAULT | 13 | ||
crtstuff.c | GLIBC_2.2.5 | libc.so.6 | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS |
crtstuff.c | GLIBC_2.2.5 | libc.so.6 | .symtab | 0x0 | 0 | FILE | <unknown> | DEFAULT | SHN_ABS |
crypt_ctx | .symtab | 0x6055a0 | 258 | OBJECT | <unknown> | DEFAULT | 25 | ||
cwrite | .symtab | 0x401722 | 152 | FUNC | <unknown> | DEFAULT | 13 | ||
daemon@@GLIBC_2.2.5 | .symtab | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
data_start | .symtab | 0x6051e0 | 0 | NOTYPE | <unknown> | DEFAULT | 24 | ||
decrypt_ctx | GLIBC_2.2.5 | libc.so.6 | .symtab | 0x605240 | 258 | OBJECT | <unknown> | DEFAULT | 25 |
deregister_tm_clones | GLIBC_2.2.5 | libc.so.6 | .symtab | 0x401460 | 0 | FUNC | <unknown> | DEFAULT | 13 |
dup2@@GLIBC_2.2.5 | .symtab | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
environ@@GLIBC_2.2.5 | .symtab | 0x605200 | 8 | OBJECT | <unknown> | DEFAULT | 25 | ||
execve@@GLIBC_2.2.5 | .symtab | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
exit@@GLIBC_2.2.5 | .symtab | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
fork@@GLIBC_2.2.5 | .symtab | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
frame_dummy | GLIBC_2.2.5 | libc.so.6 | .symtab | 0x4014f0 | 0 | FUNC | <unknown> | DEFAULT | 13 |
free@@GLIBC_2.2.5 | GLIBC_2.2.5 | libc.so.6 | .symtab | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF |
getpid@@GLIBC_2.2.5 | .symtab | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
getshell | .symtab | 0x4028c5 | 2321 | FUNC | <unknown> | DEFAULT | 13 | ||
getuid@@GLIBC_2.2.5 | .symtab | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
godpid | .symtab | 0x605344 | 4 | OBJECT | <unknown> | DEFAULT | 25 | ||
grantpt@@GLIBC_2.2.5 | .symtab | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
htons@@GLIBC_2.2.5 | .symtab | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
inet_ntoa@@GLIBC_2.2.5 | .symtab | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
init_signal | GLIBC_2.2.5 | libc.so.6 | .symtab | 0x4018a8 | 32 | FUNC | <unknown> | DEFAULT | 13 |
ioctl@@GLIBC_2.2.5 | .symtab | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
kill@@GLIBC_2.2.5 | .symtab | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
listen@@GLIBC_2.2.5 | .symtab | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
logon | .symtab | 0x402292 | 118 | FUNC | <unknown> | DEFAULT | 13 | ||
main | .symtab | 0x403e2e | 702 | FUNC | <unknown> | DEFAULT | 13 | ||
malloc@@GLIBC_2.2.5 | .symtab | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
memchr@@GLIBC_2.2.5 | .symtab | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
memcmp@@GLIBC_2.2.5 | .symtab | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
memcpy@@GLIBC_2.14 | .symtab | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
memset@@GLIBC_2.2.5 | .symtab | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
mon | GLIBC_2.2.5 | libc.so.6 | .symtab | 0x401b48 | 169 | FUNC | <unknown> | DEFAULT | 13 |
ntohs@@GLIBC_2.2.5 | .symtab | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
on_terminate | GLIBC_2.2.5 | libc.so.6 | .symtab | 0x401896 | 18 | FUNC | <unknown> | DEFAULT | 13 |
open@@GLIBC_2.2.5 | .symtab | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
open_tty | GLIBC_2.2.5 | libc.so.6 | .symtab | 0x401a67 | 86 | FUNC | <unknown> | DEFAULT | 13 |
packet_loop | .symtab | 0x402308 | 1177 | FUNC | <unknown> | DEFAULT | 13 | ||
pid_path | .symtab | 0x6056c0 | 50 | OBJECT | <unknown> | DEFAULT | 25 | ||
prctl@@GLIBC_2.2.5 | .symtab | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
ptsname@@GLIBC_2.2.5 | GLIBC_2.2.5 | libc.so.6 | .symtab | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF |
pty | GLIBC_2.2.5 | libc.so.6 | .symtab | 0x605220 | 4 | OBJECT | <unknown> | DEFAULT | 25 |
ptym_open | .symtab | 0x4018f8 | 197 | FUNC | <unknown> | DEFAULT | 13 | ||
ptys_open | .symtab | 0x4019bd | 170 | FUNC | <unknown> | DEFAULT | 13 | ||
rand@@GLIBC_2.2.5 | .symtab | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
rc4 | .symtab | 0x401625 | 253 | FUNC | <unknown> | DEFAULT | 13 | ||
rc4_init | .symtab | 0x40154f | 214 | FUNC | <unknown> | DEFAULT | 13 | ||
read@@GLIBC_2.2.5 | .symtab | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
recvfrom@@GLIBC_2.2.5 | .symtab | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
register_tm_clones | GLIBC_2.2.5 | libc.so.6 | .symtab | 0x401490 | 0 | FUNC | <unknown> | DEFAULT | 13 |
remove_pid | GLIBC_2.2.5 | libc.so.6 | .symtab | 0x401814 | 26 | FUNC | <unknown> | DEFAULT | 13 |
select@@GLIBC_2.2.5 | .symtab | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
sendto@@GLIBC_2.2.5 | .symtab | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
set_proc_name | .symtab | 0x401bf1 | 626 | FUNC | <unknown> | DEFAULT | 13 | ||
setsid@@GLIBC_2.2.5 | .symtab | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
setsockopt@@GLIBC_2.2.5 | .symtab | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
setup_time | GLIBC_2.2.5 | libc.so.6 | .symtab | 0x40182e | 65 | FUNC | <unknown> | DEFAULT | 13 |
shell | .symtab | 0x4031d6 | 3160 | FUNC | <unknown> | DEFAULT | 13 | ||
sig_child | .symtab | 0x4018c8 | 48 | FUNC | <unknown> | DEFAULT | 13 | ||
signal@@GLIBC_2.2.5 | .symtab | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
sleep@@GLIBC_2.2.5 | .symtab | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
snprintf@@GLIBC_2.2.5 | .symtab | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
socket@@GLIBC_2.2.5 | .symtab | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
srand@@GLIBC_2.2.5 | .symtab | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
strcpy@@GLIBC_2.2.5 | .symtab | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
strlen@@GLIBC_2.2.5 | .symtab | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
strncpy@@GLIBC_2.2.5 | GLIBC_2.2.5 | libc.so.6 | .symtab | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF |
system@@GLIBC_2.2.5 | .symtab | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
terminate | GLIBC_2.2.5 | libc.so.6 | .symtab | 0x40186f | 39 | FUNC | <unknown> | DEFAULT | 13 |
time@@GLIBC_2.2.5 | .symtab | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
to_open | .symtab | 0x401e63 | 1071 | FUNC | <unknown> | DEFAULT | 13 | ||
try_link | GLIBC_2.2.5 | libc.so.6 | .symtab | 0x401abd | 139 | FUNC | <unknown> | DEFAULT | 13 |
tty | .symtab | 0x605348 | 4 | OBJECT | <unknown> | DEFAULT | 25 | ||
unlink@@GLIBC_2.2.5 | GLIBC_2.2.5 | libc.so.6 | .symtab | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF |
unlockpt@@GLIBC_2.2.5 | .symtab | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
utimes@@GLIBC_2.2.5 | .symtab | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
vhangup@@GLIBC_2.2.5 | .symtab | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
w | .symtab | 0x40287f | 70 | FUNC | <unknown> | DEFAULT | 13 | ||
waitpid@@GLIBC_2.2.5 | .symtab | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
write@@GLIBC_2.2.5 | .symtab | 0x0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
xchg | .symtab | 0x401520 | 47 | FUNC | <unknown> | DEFAULT | 13 |
Network Behavior |
---|
Network Port Distribution |
---|
UDP Packets |
---|
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 28, 2019 17:42:16.240053892 CET | 59560 | 53 | 192.168.2.20 | 8.8.8.8 |
Oct 28, 2019 17:42:16.240307093 CET | 47449 | 53 | 192.168.2.20 | 8.8.8.8 |
Oct 28, 2019 17:42:16.253628016 CET | 53 | 59560 | 8.8.8.8 | 192.168.2.20 |
Oct 28, 2019 17:42:16.254373074 CET | 53 | 47449 | 8.8.8.8 | 192.168.2.20 |
System Behavior |
---|
General |
---|
Start time: | 17:42:04 |
Start date: | 28/10/2019 |
Path: | /tmp/m8XMnec4Vb.elf |
Arguments: | /tmp/m8XMnec4Vb.elf |
File size: | 28832 bytes |
MD5 hash: | 0017f7b913ce66e4d80f7e78cf830a2b |
General |
---|
Start time: | 17:42:04 |
Start date: | 28/10/2019 |
Path: | /tmp/m8XMnec4Vb.elf |
Arguments: | n/a |
File size: | 28832 bytes |
MD5 hash: | 0017f7b913ce66e4d80f7e78cf830a2b |
General |
---|
Start time: | 17:42:04 |
Start date: | 28/10/2019 |
Path: | /bin/dash |
Arguments: | sh -c "/bin/rm -f /dev/shm/kdmtmpflush;/bin/cp /tmp/m8XMnec4Vb.elf /dev/shm/kdmtmpflush && /bin/chmod 755 /dev/shm/kdmtmpflush && /dev/shm/kdmtmpflush --init && /bin/rm -f /dev/shm/kdmtmpflush" |
File size: | 154072 bytes |
MD5 hash: | e02ea3c3450d44126c46d658fa9e654c |
General |
---|
Start time: | 17:42:04 |
Start date: | 28/10/2019 |
Path: | /bin/dash |
Arguments: | n/a |
File size: | 154072 bytes |
MD5 hash: | e02ea3c3450d44126c46d658fa9e654c |
General |
---|
Start time: | 17:42:04 |
Start date: | 28/10/2019 |
Path: | /bin/rm |
Arguments: | /bin/rm -f /dev/shm/kdmtmpflush |
File size: | 60272 bytes |
MD5 hash: | b79876063d894c449856cca508ecca7f |
General |
---|
Start time: | 17:42:04 |
Start date: | 28/10/2019 |
Path: | /bin/dash |
Arguments: | n/a |
File size: | 154072 bytes |
MD5 hash: | e02ea3c3450d44126c46d658fa9e654c |
General |
---|
Start time: | 17:42:04 |
Start date: | 28/10/2019 |
Path: | /bin/cp |
Arguments: | /bin/cp /tmp/m8XMnec4Vb.elf /dev/shm/kdmtmpflush |
File size: | 151024 bytes |
MD5 hash: | b9c85244be9733bc79eca588db7bf306 |
General |
---|
Start time: | 17:42:04 |
Start date: | 28/10/2019 |
Path: | /bin/dash |
Arguments: | n/a |
File size: | 154072 bytes |
MD5 hash: | e02ea3c3450d44126c46d658fa9e654c |
General |
---|
Start time: | 17:42:04 |
Start date: | 28/10/2019 |
Path: | /bin/chmod |
Arguments: | /bin/chmod 755 /dev/shm/kdmtmpflush |
File size: | 56112 bytes |
MD5 hash: | 32c8c7318223ebc5b934a78cfc153d6f |
General |
---|
Start time: | 17:42:04 |
Start date: | 28/10/2019 |
Path: | /bin/dash |
Arguments: | n/a |
File size: | 154072 bytes |
MD5 hash: | e02ea3c3450d44126c46d658fa9e654c |
General |
---|
Start time: | 17:42:04 |
Start date: | 28/10/2019 |
Path: | /dev/shm/kdmtmpflush |
Arguments: | /dev/shm/kdmtmpflush --init |
File size: | 0 bytes |
MD5 hash: | unknown |
General |
---|
Start time: | 17:42:04 |
Start date: | 28/10/2019 |
Path: | /dev/shm/kdmtmpflush |
Arguments: | n/a |
File size: | 0 bytes |
MD5 hash: | unknown |
General |
---|
Start time: | 17:42:04 |
Start date: | 28/10/2019 |
Path: | /bin/dash |
Arguments: | n/a |
File size: | 154072 bytes |
MD5 hash: | e02ea3c3450d44126c46d658fa9e654c |
General |
---|
Start time: | 17:42:04 |
Start date: | 28/10/2019 |
Path: | /bin/rm |
Arguments: | /bin/rm -f /dev/shm/kdmtmpflush |
File size: | 60272 bytes |
MD5 hash: | b79876063d894c449856cca508ecca7f |